DSapseid Posted June 15, 2009 Posted June 15, 2009 I have just bought smoothwall SchoolGuardian and have got it all installed nicely but i cant get the damn LDAP connection working properly I am 90% sure i have my settings correct but and have applied the changes and rebooted the server. Settings i have got are below: primary server : .internal.manhood.sussex.sch.uk secondary server : .internal.manhood.sussex.sch.uk kerberos realm: INTERNAL.MANHOOD.SUSSEX.SCH.UK server user: [email protected] LDAP Port: 389 User root: OU=Manhood Community College,DC=Internal,DC=Manhood,DC=Sussex,DC=sch,DC=uk The OU Manhood Community College is my top level OU in ad. What have i got wrong?? Cheers Dan
rob_f Posted June 15, 2009 Posted June 15, 2009 Instead of the administrator user, try creating a new user who is a domain admin (and hasn't got the password set to expire). The administrator user often does not have a windows 2000 style user@domain login name. Hence cannot be used in this step. If you find that your users don't have this style login name (on the accounts tab of their account properties), tick the "use SAM account name" underneath advanced. However the user in this first step in connecting to the directory must have both style usernames. Hope this helps, if not feel free to let me know! Rob.
DSapseid Posted June 15, 2009 Author Posted June 15, 2009 Hi Rob, I have created a new account called smoothwall and changed it but it still wont connect. On the Authentication -> Control page the only ones that are running are 'Authentication Service' and 'Authentication Service Local'. All the others are closed! Cheers Dan
krisd32 Posted June 15, 2009 Posted June 15, 2009 is the time set the same on the smoothwall box? this will stop communication between active directory and smoothwall. 1
DSapseid Posted June 15, 2009 Author Posted June 15, 2009 the time is an hour fast but whenever i change it and then reboot it resets itself!!!
krisd32 Posted June 15, 2009 Posted June 15, 2009 Yeah i have this issue but don't generally need to restart it too often only when the updates are applied. just need to remember that it needs resetting everytime. have you tried it with the correct time? does it help with the issue at all?
mounters Posted June 15, 2009 Posted June 15, 2009 Have you configured the system to get the time with ntp. Under system » preferences » time make sure you have set the correct time zone and then tick the box to enable network time retrieval. Get the time set correctly first, otherwise you'll never get Kerberos to work. 1
DSapseid Posted June 15, 2009 Author Posted June 15, 2009 I have set the time manually and still no luck
DSapseid Posted June 15, 2009 Author Posted June 15, 2009 All working now i hadnt set the dns servers on the internal nic :o
rob_f Posted June 15, 2009 Posted June 15, 2009 Check to see if your time settings are the same as attached. Set them as this, click save, then "get time now". Hopefully that should make it always right. If running on a virtualisation platform, you may want to increase the network time retrieval frequency if you are seeing gradual time skew issues.
tom_newton Posted June 15, 2009 Posted June 15, 2009 Thanks folks - you seem to have managed to sort things before my coffee kicked in! Does sound like a GMT/DST issue if you are an hour out... what does the BIOS think it is doing? For other "smaller" timing issues, Smoothie will shortly be changed to grab an ntp update on boot.
DSapseid Posted June 16, 2009 Author Posted June 16, 2009 Right after getting this problem fixed yesterday i now have another! I have set the filtering rules to be block everything for all groups but its still letting you through (im typing this now going through it when i supposedly have blocked all web traffic!) I have attached a screenshot of my filtering rules, as you can see i have disabled all of them apart from the block everything for all groups one. I only did this to see if the rules were overlapping and having a fight. I have set the proxy correct in ie. Any ideas??
rob_f Posted June 16, 2009 Posted June 16, 2009 Are you perhaps in the network administrators group which by default is unfiltered - see Guardian > Authentication > Settings toward the bottom of the page. Do you see your browsing in the logs (Information > Realtime > Web Filter or Information > Logs > Web Filter) and if so does it say "Exception" or similar next to it? This would again indicate the above. No log entries would mean you're not using the filter at all. HTH, Rob. 1
krisd32 Posted June 16, 2009 Posted June 16, 2009 Have you created groups in AD to map accross to the filter? i'm not at the high school today but i can send you over a manual that i created when i set all my stuff up if you want.
mounters Posted June 16, 2009 Posted June 16, 2009 Go to here services » authentication » include groups and select the appropriate user groups you want to include. Then go here services » authentication » groups and map the LDAP groups to the smoothwall group. This will ensure that all your users are mapping to the appropriate smoothwall group.
DSapseid Posted June 16, 2009 Author Posted June 16, 2009 Excellent it was the authentication settings at the bottom of the page all is now working I have just had an argument with some pupils as they cant play games anymore :D Teacher loved it though means they have to stay on task BOFH me?? ....... never Cheers for all the help
DSapseid Posted June 18, 2009 Author Posted June 18, 2009 Yep you guessed it another problem!! 90% of my users are appearing as unauthenticated ip's when they get the block page instead of staff or students. I have set up groups called staff and students that match with my ad groups called all staff and all students. Why is it doing this?? Oh just another quick thing how can i redirect a webpage to another?? I use a websearch page that provides with income so i want to redirect google/yahoo/ask etc to this page Sorry for all the questions but my exchange server is dying so i am having such a fun time!!! Cheers Dan
krisd32 Posted June 18, 2009 Posted June 18, 2009 What authentication type are you using? NTLM? go to gaurdian then authentication in the gui and check the settings in there.
DSapseid Posted June 18, 2009 Author Posted June 18, 2009 im using 'NTLM Identification (Terminal Services compatibility mode)' is this the right one to be using??
krisd32 Posted June 18, 2009 Posted June 18, 2009 I'm just using ntlm identification. it should be ok i suppose. what about the groups down at the bottom of the page for the web proxy allow. what are your settings in there?
DSapseid Posted June 18, 2009 Author Posted June 18, 2009 attached is a screen shot of my authentication settings. I have only set the unauthenticated one to be filtered as instead of no as i was getting winged at that they couldn't get onto any site!
tom_newton Posted June 18, 2009 Posted June 18, 2009 Dan, Is there anything different about these 90%? It seems like they are not getting the NTLM challenge. Definitely *unathenticated ips* and not default users? As for redirecting search - look at your custom categories, and create one of type "content security" - the URL security rules in there allow you to use regular expressions to redirect user requests.
DSapseid Posted June 18, 2009 Author Posted June 18, 2009 Hi Tom, Attached is a screen shot of the block page i get logged in as my test student. There is nothing different about the users at all, it is affecting staff and students though so they are obviously different! Dan
DMcCoy Posted June 18, 2009 Posted June 18, 2009 Hi Tom, Attached is a screen shot of the block page i get logged in as my test student. There is nothing different about the users at all, it is affecting staff and students though so they are obviously different! Dan Have you restarted the smoothwall box? Sometimes ours stops being able to authenticate NTLM, I assume it's something to do with the machine account password expiring in AD. Looking at the auth messages in the system log would be a lot more use for diagnostics.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now