Jump to content

Recommended Posts

Posted

we have recently moved over to smoothwall. currently all ipads are talking to smoothwall but they are not authenticated ie smoothwall sees them as unathnticated devices.

On our old system we would setup the configure proxy on the ipads and add the user details in there. but this dosnt seam to be working for smoothwall

 

so how do we authenticate who is using the ipads so they get the right policy and for reporting. i have tried using the smoothwall browser but there instrustions dont help just keep getting errors 

 

any help please 

Posted

iv tried this we are using mosyle. everytime i try we get invalid smoothwall config.

 

im not sure if we are ment to use MS tenant id or smoothwall but i cant find one under account info or see any tab saying Tenant Management

 

<dict>
    <key>SmoothwallSerialNumber</key>
    <string>*************</string>

    <key>SmoothwallTenantID</key>
    <string>microsoft tent id </string>

    <key>SSOProvider</key>
    <string>Microsoftk</string>
</dict>
 

Posted

According to the article, this is the information that should be entered:
Moysle
<dict>
<key>SmoothwallSerialNumber</key>
<string></string>
<key>SmoothwallTenantID</key>
<string></string>
<key>UserID</key>
<string>%ManagedAppleId%</string>
<key>UniqueDeviceID</key>
<string>%UUID%</string>
</dict>

 

If you don't have tenants set up in Smoothwall, just remove that line.

Posted

im not sure if im correct on this, all our ipads use one Apple ID. Is there a way to get the students to SSO through the browser, as these iPads are used all across the school by different students they swap classes 2-3 times a day   

Posted

You should probably elaborate a bit more on what your setup looks like.
Do you have an On Premise Smoothwall?
What system do you use for auth?
How do students log in and out?

Posted

we have on-premises

we use there idex directory to sync the AD

they currently dont log in to the ipads.

 

the ipads are currently unathenticated device on smoothwall, only seen as ip address 

all ipads use one apple id.

 

we have 16 ipads for students to use around the school and 32 ipads for staff use 

Posted

If you have just switched to Smoothwall, you should contact your Smoothwall contact, so that they can properly look at your needs.
Maybe switch to Smoothwall Cloud Filter with Azure login?

  • Like 1
  • 4 weeks later...
Posted
On 21/05/2026 at 10:06, sharrpea said:

we have on-premises

we use there idex directory to sync the AD

they currently dont log in to the ipads.

 

the ipads are currently unathenticated device on smoothwall, only seen as ip address 

all ipads use one apple id.

 

we have 16 ipads for students to use around the school and 32 ipads for staff use 

Just stumbled across this as we're getting a few more devices in and trying to get our smoothwall setup correct. I shall point out that if you've got 16 ipads and not authenticated, you're not complying with KCSIE so could land yourselves in trouble unless you're manually logging each one out so you know who has what device and when.

 

Not worth me raising another topic on this so I'll basically just hijack this ;)

 

Google school, Smoothwall hybrid (onsite appliance and Cloud). Mosyle free MDM.

Ipads don't use any account as they're managed.

Currently the 3 or so ipads used are either used only by named staff, or if used by students strictly signed in/out so we can track them if needed.

With the expansion now, I have further ocked down with Safari removed and Smoothwall Browser "installed" and that's the bit I can't get my head around and the documentation is diabolical from Mosyle's perspective blindly pointing people at the usual nonsensical Github pages.

So yes, I can see we need a plist, no I don't understand what it should do or how to get Mosyle to actually push that alongside.

And then as ipads get passed from pillar to post, can we set anything like usage timeouts so they log out after 5 minutes etc?

 

An alternative is to use Smoothwall authentication policies - if an unauthenticated device on a certain network connects, any connection to the internet forces a login via smoothwall's SSL login page and all is good, but that's something I'd rather not faff with if possible. 

 

I keep seeing references to "SSO working alongside either Google or MS" which usually seems to link back to ASM, however I can't see any mention of that in our ASM, and that intrigues me massively as it would be *awesome* if we could get them to log into things like Google Drive.

 

 

 

Posted

With the ipad client, that's not really intended for use with "class trolley" style ipads unless they are in apple's shared ipad mode: really this is needed to get good auth. You have to have kids logging in to their ipads.

 

If you don't - filtering via on-prem with a login page is probably your best bet.

Posted
21 minutes ago, tom_newton said:

With the ipad client, that's not really intended for use with "class trolley" style ipads unless they are in apple's shared ipad mode: really this is needed to get good auth. You have to have kids logging in to their ipads.

 

If you don't - filtering via on-prem with a login page is probably your best bet.

Ah shared ipad mode, that's a bell ringing!

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...