sharrpea Posted May 20 Posted May 20 we have recently moved over to smoothwall. currently all ipads are talking to smoothwall but they are not authenticated ie smoothwall sees them as unathnticated devices. On our old system we would setup the configure proxy on the ipads and add the user details in there. but this dosnt seam to be working for smoothwall so how do we authenticate who is using the ipads so they get the right policy and for reporting. i have tried using the smoothwall browser but there instrustions dont help just keep getting errors any help please
Joeloman Posted May 21 Posted May 21 For this to work you need an MDM system. Have you checked this article? https://kb.smoothwall.com/hc/en-us/articles/4404006049810-Install-Smoothwall-Browser-on-iPadOS-and-iOS-devices
sharrpea Posted May 21 Author Posted May 21 iv tried this we are using mosyle. everytime i try we get invalid smoothwall config. im not sure if we are ment to use MS tenant id or smoothwall but i cant find one under account info or see any tab saying Tenant Management <dict> <key>SmoothwallSerialNumber</key> <string>*************</string> <key>SmoothwallTenantID</key> <string>microsoft tent id </string> <key>SSOProvider</key> <string>Microsoftk</string> </dict>
Joeloman Posted May 21 Posted May 21 According to the article, this is the information that should be entered: Moysle <dict> <key>SmoothwallSerialNumber</key> <string></string> <key>SmoothwallTenantID</key> <string></string> <key>UserID</key> <string>%ManagedAppleId%</string> <key>UniqueDeviceID</key> <string>%UUID%</string> </dict> If you don't have tenants set up in Smoothwall, just remove that line.
Joeloman Posted May 21 Posted May 21 It is <key>UserID</key> that retrieves the information of the person who is logged in.
sharrpea Posted May 21 Author Posted May 21 im not sure if im correct on this, all our ipads use one Apple ID. Is there a way to get the students to SSO through the browser, as these iPads are used all across the school by different students they swap classes 2-3 times a day
Joeloman Posted May 21 Posted May 21 You should probably elaborate a bit more on what your setup looks like. Do you have an On Premise Smoothwall? What system do you use for auth? How do students log in and out?
sharrpea Posted May 21 Author Posted May 21 we have on-premises we use there idex directory to sync the AD they currently dont log in to the ipads. the ipads are currently unathenticated device on smoothwall, only seen as ip address all ipads use one apple id. we have 16 ipads for students to use around the school and 32 ipads for staff use
Joeloman Posted May 21 Posted May 21 If you have just switched to Smoothwall, you should contact your Smoothwall contact, so that they can properly look at your needs. Maybe switch to Smoothwall Cloud Filter with Azure login? 1
synaesthesia Posted June 18 Posted June 18 On 21/05/2026 at 10:06, sharrpea said: we have on-premises we use there idex directory to sync the AD they currently dont log in to the ipads. the ipads are currently unathenticated device on smoothwall, only seen as ip address all ipads use one apple id. we have 16 ipads for students to use around the school and 32 ipads for staff use Just stumbled across this as we're getting a few more devices in and trying to get our smoothwall setup correct. I shall point out that if you've got 16 ipads and not authenticated, you're not complying with KCSIE so could land yourselves in trouble unless you're manually logging each one out so you know who has what device and when. Not worth me raising another topic on this so I'll basically just hijack this Google school, Smoothwall hybrid (onsite appliance and Cloud). Mosyle free MDM. Ipads don't use any account as they're managed. Currently the 3 or so ipads used are either used only by named staff, or if used by students strictly signed in/out so we can track them if needed. With the expansion now, I have further ocked down with Safari removed and Smoothwall Browser "installed" and that's the bit I can't get my head around and the documentation is diabolical from Mosyle's perspective blindly pointing people at the usual nonsensical Github pages. So yes, I can see we need a plist, no I don't understand what it should do or how to get Mosyle to actually push that alongside. And then as ipads get passed from pillar to post, can we set anything like usage timeouts so they log out after 5 minutes etc? An alternative is to use Smoothwall authentication policies - if an unauthenticated device on a certain network connects, any connection to the internet forces a login via smoothwall's SSL login page and all is good, but that's something I'd rather not faff with if possible. I keep seeing references to "SSO working alongside either Google or MS" which usually seems to link back to ASM, however I can't see any mention of that in our ASM, and that intrigues me massively as it would be *awesome* if we could get them to log into things like Google Drive.
tom_newton Posted June 18 Posted June 18 With the ipad client, that's not really intended for use with "class trolley" style ipads unless they are in apple's shared ipad mode: really this is needed to get good auth. You have to have kids logging in to their ipads. If you don't - filtering via on-prem with a login page is probably your best bet.
synaesthesia Posted June 18 Posted June 18 21 minutes ago, tom_newton said: With the ipad client, that's not really intended for use with "class trolley" style ipads unless they are in apple's shared ipad mode: really this is needed to get good auth. You have to have kids logging in to their ipads. If you don't - filtering via on-prem with a login page is probably your best bet. Ah shared ipad mode, that's a bell ringing!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now