Jump to content

Recommended Posts

Posted

Is anyone here using Smoothwall with Citrix or terminal server clients?

 

 

We have had our Smoothwall setup to use NTLM authentication as this was the only way to support TS users. We have also had some location groups setup so we could turn the internet on or off in rooms, this has been working for our thin clients and normal Windows clients. On friday this stopped working in the rooms with thin clients and when I called Smoothwall they told me that it's not possible to manage thin client internet this way.

 

 

I'm a bit confused as we've had it working has anyone else got their Smoothwall setup to allow them to ban thin client devices? (Or am I just going mad)

 

Thanks.

Posted

Would have to know a bit more about your situation.

The "per room" stuff is identified by hostname or IP - so long as your thin devices are browsing from an identified IP (even if it is DHCP, as long as you have the hostname constant and with a reverse dns lookup..) thats fine. Indeed if this is the case, all methods of authentication should work, not just those marked "terminal services" (which basically means it reauthenticates each session, rather than caching an IP/username pair for any amount of time).

 

If you let me know your ticket number (or PM me your details) I will have it looked into further.

 

Tom

Posted

If you're using internet exploder in a TS environment, I wouldn't see this being possible as the client IP will be that of the TS and not the TC (so you'd identify the TS). I can't say I've ever had it working (though I would certainly like it to). If there is a way, it would be great if someone could pass the info on.

 

Cheers

 

Will

Posted
If you're using internet exploder in a TS environment, I wouldn't see this being possible as the client IP will be that of the TS and not the TC (so you'd identify the TS). I can't say I've ever had it working (though I would certainly like it to). If there is a way, it would be great if someone could pass the info on.

 

Cheers

 

Will

 

 

Yes that's what I always thought i'm aware that the Citrix box generates the traffic but as I'm sure I've seen this working I was thinking that maybe NTLM was allowing Smoothwall to know what client a user was using as Citrix shows the clientname.

Posted

That looks like the one, or -> Virtual IP addressing in Citrix Presentation Server 4.0

 

I'd suggest it's a good idea in general, but obviously doubles up your IP address space (i.e. 1 IP per thin client + 1 IP client session) - not really read into any other potential implications.

 

Did you ask this on tek-tips too ? (Citrix solutions - Unique IP address for each client) Set up a VPN for them!? That'll learn you to stray from the 'geek :)

Posted

Now here's a question, if you're assigning your sessions unique IPs how do you know which session IP is in which room? Do you have a server-per-room?

 

I'm intrigued as to how it worked before... didn't you say on another thread (or it might have been to nile) that it stopped working when you turned on HTTPS interception? Does it start working again if you turn that off?

 

Thanks!

 

 

Rob.

Posted
That looks like the one, or -> Virtual IP addressing in Citrix Presentation Server 4.0

 

I'd suggest it's a good idea in general, but obviously doubles up your IP address space (i.e. 1 IP per thin client + 1 IP client session) - not really read into any other potential implications.

 

Did you ask this on tek-tips too ? (Citrix solutions - Unique IP address for each client) Set up a VPN for them!? That'll learn you to stray from the 'geek

 

 

Yes I suppose as you say one issue will be using twice as many IP's.

 

Yes I thought i'd cast my net over Tek-Tips as well, caught cheating ;)

 

 

 

Now here's a question, if you're assigning your sessions unique IPs how do you know which session IP is in which room? Do you have a server-per-room?

 

I'm intrigued as to how it worked before... didn't you say on another thread (or it might have been to nile) that it stopped working when you turned on HTTPS interception? Does it start working again if you turn that off?

 

Thanks!

 

 

I'm starting to doubt myself now but myself and the IT Manager saw this working and the students were complaining as they couldn't get on the internet in lesson. We turned off the HTTPS interception but it didn't solve the issue.

Posted
Shame I don't have Citrix... apparently Virtual IP is in 2008R2, but as it's 64 bit, I've got no chance of going to that any time soon due to older curric software. The IP allocation per session is also an interesting hurdle, it doesn't look like there's a way to specify IP range per clientname (unless you could do this by script?). I wonder whether we could create an addon for IE that would put in an x-forwarded-for header with the clientname resolved to IP (or just clientname may do), and whether smoothwall could use this for client machine identification?
Posted (edited)

Fiddler Web Debugger - Script Samples

 

Looks like there's a way to add header's to IE requests... it also looks like it may be able to use .NET system calls, so may be able to pick up clientname. Haven't really got time to look at it at present, but if no one else does, I'll look in the New Year.

 

[edit]Looks like fiddler's a proxy that would run on the local machine, so may not be suitable. I'll keep looking through![/edit]

Edited by Willott
addition
Posted
Now here's a question, if you're assigning your sessions unique IPs how do you know which session IP is in which room? Do you have a server-per-room?

 

I'm intrigued as to how it worked before... didn't you say on another thread (or it might have been to nile) that it stopped working when you turned on HTTPS interception? Does it start working again if you turn that off?

 

Thanks!

 

 

Rob.

 

 

 

We've been having a think about it and all we can come up with is that we were somehow blocking a server IP so it gave the impression that it was working but it wouldn't of been working per location.

 

 

I'll have a think about the virtual IP option but as stated above it might not be possible to map a particular IP to a virtual IP so you know which client is on which V IP. I've got a feeling it is though but it will take some reading.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...