ICTNUT Posted November 9, 2009 Posted November 9, 2009 Hello people, as the title suggests we have a smoothwall content filter and we are also using a bluesockt wireless setup. What I want to know id if anyone has setup thier smoothwall to allow bluesocket web access but still have it filtered? OUr setup is as follows: BlueSocket : LDAP / Radius authentication using web portal for login information or machine based authentication. Smoothwall : LDAP / AD authentication (not at the office but I think ident with terminal services) I can get the wireless clients to connect to the network and authenticate no problem this issue is that a username and password is NOT being password to the smoothwall and content filtering fails so user are unable to browse. How to setup smoothwall so that the wireless clients can surf the web but still be filtered? Answers on a post card please......
Ric_ Posted November 9, 2009 Posted November 9, 2009 It works for me... my users are using NTLM pass-thru to AD authentication. Mobile Gaurdian is now being used to set proxy details too. Of course, these are managed computers. I've got to set up the whole captive-portal style thing and I'm leaning towards AD auth through a web page... the users will then get passed to a VLAN which I'll put through a specific port on my UTM and just filter ALL the traffic.
ICTNUT Posted November 10, 2009 Author Posted November 10, 2009 Ric_: Where are you setting the NTLM pass-thru as I am sure if I can do this it will all work also but I must be blind as I cannot see where it is set?
ssiruuk2 Posted November 10, 2009 Posted November 10, 2009 Ric_: Where are you setting the NTLM pass-thru as I am sure if I can do this it will all work also but I must be blind as I cannot see where it is set? If your using ident in terminal services compat mode aren't you already using NTLM ? If your wirless users are on unmanaged machines you will have to use either the ssl login page option or rely on the pop up window that the smoothwall will give your users if it can't authenticate them automatically. I found both these worked fine with Windows clients but Mac did not get on well at all (SSL login didn't work and the pop up window was a bit flakey sometimes repeatedly asking for credentials when clicking on links) - for now our guest wirless are not authenticated as a result.
Ric_ Posted November 10, 2009 Posted November 10, 2009 Ric_: Where are you setting the NTLM pass-thru as I am sure if I can do this it will all work also but I must be blind as I cannot see where it is set? On your Bluesecure controller, go to 'User Authentication' -> 'Authentication Server' -> 'Create... Transparent NTLM Windows Authentication' Fill in the relevant domain controller details and in the drop down box named 'or using LDAP/Active Directory server' simply select your AD authentication settings. It's all in the BlueSocket training materials that are available off the support pages of their website (along with lots of other good stuff ). 1
ICTNUT Posted November 11, 2009 Author Posted November 11, 2009 (edited) It works for me... my users are using NTLM pass-thru to AD authentication. Mobile Gaurdian is now being used to set proxy details too. Of course, these are managed computers. I've got to set up the whole captive-portal style thing and I'm leaning towards AD auth through a web page... the users will then get passed to a VLAN which I'll put through a specific port on my UTM and just filter ALL the traffic. I have setup AD (transparent NTLM) auth through the SSL web page on the bluesocket and authentication works (these are unmanaged laptops and mobile devices). On the status page for the bluesocket I can see the users that have authenticated but they cannot surf, Smoothwall is still coming back with unknown username or password and tries to stick them in the unatuhenticated users which I have setup as a default block everything. See that the bluesocket bit is ok I will assume that there is still something I need to do on the smoothwall.... Edited November 11, 2009 by ICTNUT typo
Ric_ Posted November 11, 2009 Posted November 11, 2009 Are you using the Smoothie as a transparent proxy? IIRC a transparent proxy cannot authenticate users. This is why I plan to do it the why I describe above. Dump the unmanaged devices onto a different VLAN with only access to the Smoothie box and then tell Smoothie to act as a transparent proxy on that VLAN, applying a strict filtering policy.
ICTNUT Posted November 11, 2009 Author Posted November 11, 2009 Are you using the Smoothie as a transparent proxy? IIRC a transparent proxy cannot authenticate users. This is why I plan to do it the why I describe above. Dump the unmanaged devices onto a different VLAN with only access to the Smoothie box and then tell Smoothie to act as a transparent proxy on that VLAN, applying a strict filtering policy. Nope not using smootie as a transparent proxy, using NTLM Identification (Terminal Services compatibility mode) So my next question would be how do you have the smoothie setup with more than one authentication method? We do want to be able to log all the kids and thier access and would like to do the same for the wireless access but if that is not possible just making sure that the wirless internet access is filtered (strict) would suffice.
tom_newton Posted November 11, 2009 Posted November 11, 2009 Oz, you can only use a single authtype at the moment (though this is changing). Call me (back Friday) or RobF (0113 3874181, in Tomorrow all day AFAIK) and we'll have a poke about. 1
Ric_ Posted November 12, 2009 Posted November 12, 2009 @ICTNUT: If the users are on unmangaed machines, will NTLM (or other types of) authentication work? If Smoothie acts as a transparent proxy, you will log all the IPs of the users and you can cross reference that with your ClueSocket logs. A PITA but you can still find those little darlings that are looking for pr0n.
ICTNUT Posted November 12, 2009 Author Posted November 12, 2009 @ICTNUT: If the users are on unmangaed machines, will NTLM (or other types of) authentication work? If Smoothie acts as a transparent proxy, you will log all the IPs of the users and you can cross reference that with your ClueSocket logs. A PITA but you can still find those little darlings that are looking for pr0n. Hmm thats a good point, I have a script that runs which will only allow a single logon instance for any student or staff with the time, date, IP, and pc name being logged to a central database so finding out who did what is not really going to be that much of an issue. I will have a play and let you know.
ICTNUT Posted November 12, 2009 Author Posted November 12, 2009 Where on the smoothie do we set transparent proxy then......?
Ric_ Posted November 12, 2009 Posted November 12, 2009 Where on the smoothie do we set transparent proxy then......? Gaurdian -> Web Proxy Just give me remote access to your systems and I'll set it up for you shall I?
ICTNUT Posted November 12, 2009 Author Posted November 12, 2009 Error - NTLM in Terminal Services compatibility mode cannot be used with 'Transparent' enabled Which one should I set it to then? Ident by IP??
ICTNUT Posted November 12, 2009 Author Posted November 12, 2009 Just thinking about this if I go into transparent mode I will then loose all the groups that have been setup through AD authentication and then loose the filter groups that have been setup as these are based on AD group membership. Effectively this will drop the whole back to just a single level, single filter policy proxy, am I thinking correctly on this?
Ric_ Posted November 12, 2009 Posted November 12, 2009 (edited) Now I remember why I hadn't set this up now If you think it through, if the client thinks there is no proxy there (transparent) it isn't going to pass the auth to it. Hence, Smoothie thinks it's a stoopid setup and won't let you do it. What the clever people at Smoothwall should do, is allow you to turn transparent proxy on for a particular port and assign a filetering policy to transparent traffic. Nudge nudge wink wink guys! EDIT - Of course, you could just turn on the transparent proxy feature that the BlueSecure unit has... you'll find that in the role settings Oz Edited November 12, 2009 by Ric_
ICTNUT Posted November 12, 2009 Author Posted November 12, 2009 I second that ! Hmm will have to stay with the way it is at the moment then and not allow web access via wireless. Hmm me thinks I could possible allow a loopback via the bluesocket to our SSL VPN and get the students to logon to one of our Terminal Services boxes and get access that way, long winded yes but if they really need access I geuess they will use it.
ICTNUT Posted November 12, 2009 Author Posted November 12, 2009 looking at the bluesocket now, i think i did already try it on there and it would not work but let me give it a go.
DMcCoy Posted November 12, 2009 Posted November 12, 2009 Now I remember why I hadn't set this up now If you think it through, if the client thinks there is no proxy there (transparent) it isn't going to pass the auth to it. Hence, Smoothie thinks it's a stoopid setup and won't let you do it. What the clever people at Smoothwall should do, is allow you to turn transparent proxy on for a particular port and assign a filetering policy to transparent traffic. Nudge nudge wink wink guys! EDIT - Of course, you could just turn on the transparent proxy feature that the BlueSecure unit has... you'll find that in the role settings Oz The problem with multiple authentication methods is that it's passed (AIUI anyway) from the guardian process to Squid, using whatever methods are available on squid. Using multiple methods would need another instance of squid which may put too high a load on the system and would be quite complex to set up.
ICTNUT Posted November 12, 2009 Author Posted November 12, 2009 Nope did not work. Put BlueSocket into transparent mode on the guests role (the user I am using does go into theis role) and left the smoothie as it is, no go on the web.
Ric_ Posted November 12, 2009 Posted November 12, 2009 @ICTNUT: Did you tick the 'Perform transparent proxy request translation on the BSC.' box?
ICTNUT Posted November 12, 2009 Author Posted November 12, 2009 @ICTNUT: Did you tick the 'Perform transparent proxy request translation on the BSC.' box? Yes I did
Ric_ Posted November 12, 2009 Posted November 12, 2009 @ICTNUT: So is it simply not working or are you getting a denied page off of Smoothie? (If so, what does it say?)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now