Jump to content

Recommended Posts

Posted

We have a problem with School Guardian; Our students are divided into yeargroup OUs under an "All Students" OU in AD. We've mapped our "All Students" OU to a "Students" group in Guardian and this appears to work fine for most of the kids, but according to the logs, a lot are going through as "unauthenticated ips" and as a result, not all the filtering rules applicable to students are being applied. Any ideas why they would be in this category? How can I force Guardian to pick up their correct group? Any help appreciated!

Kath

Posted

What sort of authentication are you using (guardian/authentication/settings)?

Are the students' usernames being picked up OK?

What do the auth diags say (services/authentication/control)?

 

Sorry for all the questions, but auth stuff is always trickiest to troubleshoot :)

 

Tom

Posted

Wow! That was quick - thanks for getting back to me!

 

What sort of authentication are you using (guardian/authentication/settings)?

 

LDAP

Authentication = Microsoft Active Directory type = Kerberos

 

Are the students' usernames being picked up OK?

 

Yes, I see their AD usernames in the web filter log even when they are going through in the unauthorised ip category

What do the auth diags say (services/authentication/control)?

 

Manual control current status = RUNNING

 

Authentication service = RUNNING

Primary LDAP Server Resolves = OPEN

Secondary LDAP Server Resolves = N/A

Primary LDAP Server Connection = OPEN

Secondary LDAP Server Connection = N/A

Authentication Service Local Connection = OPEN

Authentication Service LDAP Server Connection = OPEN

Can list groups on LDAP Server = OPEN

Sorry for all the questions, but auth stuff is always trickiest to troubleshoot :)

Tom

 

No problem, appreciate the help! This is driving me nuts!

Kath

Posted

Kath - good news is you seem to have it set up perfectly. Bad news is, this means I don't know why it is misbehaving. I bet it's something trivial tho :)

 

Let me open a support ticket for you and I will get one of the lads to give you a tinkle later today. Sorry I can't be a bit more useful ;)

 

Tom

  • Thanks 1
Posted
Kath - good news is you seem to have it set up perfectly. Bad news is, this means I don't know why it is misbehaving. I bet it's something trivial tho :)

 

Let me open a support ticket for you and I will get one of the lads to give you a tinkle later today. Sorry I can't be a bit more useful ;)

 

Tom

 

Cheers! Glad I'm not just being a complete numpty - look forward to hearing from them.

 

Kath

Posted

Could it be the nested OUs?

 

I may be wrong but maybe you need to add all the users into a single group on the AD something like student filtering and then link that group to the smoothwall group.

 

I can't remember if this was my problem or if it was nested groups that i had an issue with.

  • 3 weeks later...
Posted

Similar issue to Kath's.

 

Evaluating School Guardian and Network Guardian. I am using Active Directory authentication - NTLM Identification (Terminal Services compatibility mode) w/the Blue Star next to them. If I use the NTLM Identification (Terminal Services compatibility mode) w/o the Blue Star Dansguardian errors out.

 

My issue - I am using Groups, no OU's - but in the case of my ID - I am a member of Domain Admin, a departmental group, and a general staff group. I can't figure out which group it actually pulls from. Restrictions for my Domain Admin groups are less restrictive (actually using some Allow rules to override Block rules for general staff), but I am getting restricted based on the general staff group.

 

Are there rules for how groups are handled with mutiple groups? Do I need to create another group that is for Smoothwall mappings only (don't want to go that way - it is far less transparent). None of these groups are nested.

 

Thanks,

 

Scott

Posted
As far as i am aware school guardian doesn't work with nested groups. I created a group for all my pupil users and then added them to it. Then i created a group in School guardian and linked it to the AD group i created.
Posted
As far as i am aware school guardian doesn't work with nested groups. I created a group for all my pupil users and then added them to it. Then i created a group in School guardian and linked it to the AD group i created.

 

I hope this isn't the case.... Tom would you clarify please.

 

We are thinking about moving to School Guardian soon, but our AD is setup so that there is a Students OU with Year group OUs nested within that. It is set this to make managing the students, creating distribution lists etc, is nice and easy. I would hope that School Gaurdian would be able to see the nested OUs and use them as groups for itself.

Posted
Have you checked under guardian/auth/settings that the unauthenticated IP's group is set to no rather than yes? Simple i know and i'm sure you have checked it but sounds like the issue.
Posted
I hope this isn't the case.... Tom would you clarify please.

 

We are thinking about moving to School Guardian soon, but our AD is setup so that there is a Students OU with Year group OUs nested within that. It is set this to make managing the students, creating distribution lists etc, is nice and easy. I would hope that School Gaurdian would be able to see the nested OUs and use them as groups for itself.

 

You can authenticate users within the specified OU or a sub OU, mine are all organised in separate containers too. My groups are all held within a single OU and my groups setting points to that. You can't use the OU itself as the group.

Posted
You can authenticate users within the specified OU or a sub OU, mine are all organised in separate containers too. My groups are all held within a single OU and my groups setting points to that. You can't use the OU itself as the group.

 

So whilst it will happily authenticate the users in the sub OUs, you still have to create the groups on School Gaurdian..... bit of a faff, but do-able.... Feature Request Tom?

Posted
So whilst it will happily authenticate the users in the sub OUs, you still have to create the groups on School Gaurdian..... bit of a faff, but do-able.... Feature Request Tom?

 

No, it reads the groups from AD depending on where you point the group path, these then show up to be used on SG, it just needs a search path to find them.

 

The groups found under the search path are listed on the groups page. You will need the users in an AD group even if at minimum it's using the default domain users group.

Posted
No, it reads the groups from AD depending on where you point the group path, these then show up to be used on SG, it just needs a search path to find them.

 

The groups found under the search path are listed on the groups page. You will need the users in an AD group even if at minimum it's using the default domain users group.

 

Ahhh, I see. That makes sense now. That's not a probnlem then as they are in groups in their year groups as well as in OUs of their year groups.

Posted

Hey guys, sorry for the delay catching up to this. Best practice for handling AD groups with a smoothwall web filter is:

 

- Create in AD separate groups for the separate policy groups you want in the SW, so an AD group Year7, Year8, Year9 etc. and put those in their own OU.

 

- Set the group search root to be the OU above (ou=mygroups,dc=domain,dc=local for example)

 

- Include the groups you want (Authentication > Include Groups)

 

- Rename and map the groups to the smoothwall groups (Authentication > Groups)

 

Handling of multiple group memberships isn't something that can be easily done, and it would make things too complicated to debug what user was getting which group anyway. Doing the above, and making sure each user is only in one group is the best way to do things.

 

If you're trying to get NTLM Authentication rather than NTLM Identification working, and it's not, there are a couple of extra AD integration steps that need to be addressed. Basically, as NTLM Authentication checks the users' usernames and passwords with AD, the smoothwall itself needs to join the domain as a member server. Hence the user you specify on the System > Authentication > Settings page needs to be a domain admin, have a windows 2000 style user logon name ([email protected], top box of account tab) and password expiry turned off. Best to create a new user for the smoothwall rather than use Administrator or any other existing admin account. You also need to check that the smoothwall is using the AD DNS servers at the top of Networking > Interfaces and that AD DNS has a reverse lookup zone for the subnet in which the smoothwall and AD servers reside.

 

Hope this is clear, still quite early in the day for this kind of thing :( Give me a shout if you need help, my number is below.

 

Ta,

 

Rob.

  • Thanks 1
Posted (edited)
Check an account which is showing up as unauthenticated I bet you will find the AD user settings are not completed all users should have a windows 2000 style user logon name ([email protected], top box of account tab). As Rob mentioned just above this is needed for both admin and users who are going to be browsing via smoothwall. Edited by paul
  • Thanks 1
Posted
Yes, you're right (apart from the fact that I'm not Tom, but whilst he's on holiday I may as well be... :) ) however we've recently added a little ticky box on Services > Authentication > Settings > Advanced called "SAM Account Name" that should allow you to authenticate users that don't have the aforementioned username type. Check with support if you've any queries around this, as I haven't had chance to try it out myself. Having said that, make sure anyway that the user you are using to connect to AD on the auth settings page has both types of username.
  • 4 weeks later...
Posted

I've had the same problem and thanks to this post and a few calls, I found that quite a few of my users didn't have post 2000 user@domain login field. Sorted it out with an Active directory utility (Ad Infinitum) this afternoon and now I'm getting domain users in the correct smoothwall groups using NTLM identification :)

 

Phew! - I should have check my user accounts a little more carefully...

  • Thanks 1
Posted
I've had the same problem and thanks to this post and a few calls, I found that quite a few of my users didn't have post 2000 user@domain login field. Sorted it out with an Active directory utility (Ad Infinitum) this afternoon and now I'm getting domain users in the correct smoothwall groups using NTLM identification :)

 

Phew! - I should have check my user accounts a little more carefully...

I had that the other morning thinking hmmmm why are these handfull being banned as its no internet for unauthenticated and that was why, added the @domain.com bit in and its fine now no issues.

  • 4 weeks later...
Posted
I've had the same problem and thanks to this post and a few calls, I found that quite a few of my users didn't have post 2000 user@domain login field. Sorted it out with an Active directory utility (Ad Infinitum) this afternoon and now I'm getting domain users in the correct smoothwall groups using NTLM identification :)

 

Just solve my own problem with this and just a tip for using Ad Infinitum, as it took me a while to suss this out.

 

Manage Objects

Manage: Users

Select from: OU

Task: Set a property

Locate the user(s) you want to change

Property to set: UPN

Property value: %username%@domain.foo

  • 10 months later...
Posted

Hi guys,

I'm coming up against the same problem in Network Guardian 2008. Our usernames are in the format firstinitial.lastname (e.g. f.nurk for Fred Nurk), and in Active Directory that appears as:

 

User logon name:
f.nurk                  @domain.ext

where @domain.ext is in the drop-down box.

 

If I understand correctly, what you guys are doing is changing the User logon name to '[email protected]', which would look like this:

 

User logon name:
[email protected]       @domain.ext

 

Have I got that right? If so, doesn't their username display as '[email protected]@domain.ext'?

 

Thanks for any help you can provide.

 

Cheers,

Daniel

Posted
Hi guys,

I'm coming up against the same problem in Network Guardian 2008. Our usernames are in the format firstinitial.lastname (e.g. f.nurk for Fred Nurk), and in Active Directory that appears as:

 

User logon name:
f.nurk                  @domain.ext

where @domain.ext is in the drop-down box.

 

Cheers,

Daniel

 

That should already be correct. I've attached an example shot of an old account from our AD, which is setup ok for smoothwall. Where the username is

student1

 

See below...

user.png

Posted

I don't see anything immediately wrong, but then I havent had my coffee yet. Let me get some nice kenyan stuff in the pot, and i'll grab RF, and have a look at this.

 

Sorry I didn't get chance to sort this yesterday evening.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...