Jump to content

Recommended Posts

Posted

We have a Server 2003 r2 DC and a Watchguard Firebox Firewall but currently we have no way to audit internet use on a per AD user basis. Our firewalls log server does support logging web use via Active Directory user name but we are currently struggling to get it to work correctly and even when we do have it setup I still won't be entirely happy with doing it that way as users will have to login as per usual to AD and then they'll have to manually authenticate against our firewall if they want to access the internet. Ideally users would only need to login once as usual with no need to authenticate again to get out onto the net but we'd still be able to see what sites every user has visited per AD user name.

 

I'm wondering what other options we might have and if they may work better than using our firewalls log server? We're not running squid at the moment but I suspect that might be able to do what we want? If we did use squid, would users have to manually authenticate against it before they can access the internet or can this be automated?

Posted

Hi

 

I run a danguardian box with indentd on the windows clients which records who is on. It works a treat but does take a bit of work to get it how you want it but it will run on a 2 gig old pc with a gig of ram and a new hand drive and the rest is time to set it up.

 

Richard

Posted

"indentd"? Is that a typo? Have you got a link to its homepage? I presuming its free?

 

If we were to use i(n)dentd, would users have to autheticate to access the web or is this a single sign-on solution?

 

Is indentd tied to dansguardian or will we be able to use it alongside our existing firewall?

 

If you found any useful guides to getting this app setup I'd be grateful for any links you can provide

 

Thanks!

Posted

SpuffMonkey:

 

This script sounds interesting and could be the easiest solution- where can I find it? Whats it called?

 

Smoothwall sounds great and I know its got lots of fans on here but replacing our hardware fw is a last resort- certainly at least until our current firewall license expires. I would however be interested to hear from anyone who has used both a Watchguard Firebox firewall and smoothwall to get comments on how they compare- ease of setup and maintainance etc. as we may decide to switch in the future?

Guest monkeyx
Posted

We use Squid, as it allows for user and group AD integration. We then use sarg for analysing usage.

 

We did use Squid/Dansguardian in the past and may go back to that combination as it worked well. Dansgaurdian did not integrate as well with AD groups as I remember though.

 

Tim

Posted

You could use smoothie *with* your WG if you felt that way inclined.

I doubt identd will help - it sounds to me like your wg is already identifying users - which is what identd is for. Is that right? If it is identifying users we are 99% of the way there :)

Posted

Tom:

 

No, our WG FW is totally unaware of AD users and groups until users log into its web gui and authenticate against it. Otherwise we can only see info about MACs and IP addresses etc. which is no use if you're trying to pinpoint what a student was looking at a certain time. However this has been a right royal pain to setup and we haven't got it to work properly just yet.

 

Monkeyx:

 

OK so you can do this with squid. When your users log on, do they have to authenticate manually with squid before they can browse the web or does it provide a single sign-on AD user/group aware web monitoring solution when setup correctly? Is this difficult to get working?

Posted

ittech:

 

I presume you are referring to inetlogger.vbs that is linked at the bottom of the thread you linked to? I forgot to mention that another requirement is that the logging system is it would ideally be browser independent as well as 'single sign-on' as I'm under the impression that inetlogger.vbs would only log pages visited under IE, which we do keep installed but I have zero respect for as a browser. Most machines also have FF installed and a fair few have Chrome on too so we would have to uninstall any 'alternate' browsers if inetlogger was to be any use.

Posted

I'm trying to get hold of this script so that i can have a go at running at our school...however, i can't find a working copy.

 

There is a thread with a link to download it as a .zip file, but i've done this about 5 times, and used various bits of software to unzip it...each time it doesnt work.

 

There's also a thread with the code of this said script pasted into it. I copied the code, and pasted it into my own script...but there LOADS of things which needed changing...so much so that i abandoned it.

 

Anyone got a working copy of this script which they could e mail me?

 

Many thanks

 

Aaron

Guest monkeyx
Posted
Tom:

 

Monkeyx:

 

OK so you can do this with squid. When your users log on, do they have to authenticate manually with squid before they can browse the web or does it provide a single sign-on AD user/group aware web monitoring solution when setup correctly? Is this difficult to get working?

 

 

Our squid setup is fully AD integrated, ie no username or password needs be entered as long as you are logged into our domain. The users AD name is recorded in the squid log.

 

Websites and file types are blocked for users based on their AD group. The blocking of sites and file types is done via webmin and all of our support team can do this very easily.

 

Setting up squid for AD is well documented on the squid website and support forums. But if this is your fist *nix project then it is not a beginners project either. It tooks me ages to the AD groups working properly! But now it I am kicking myself that I missed the obvious!

 

The sarg reporting is great to show usage, when we get requests to show the web history of users.

 

Tim

Posted

Hi Monkeyx!

 

Thanks for that - squid definitely sounds like the best solution in that case.

 

I've been a Linux user since '96 but its only in the last couple of years I've started playing with it for setting up servers. I don't know a whole lot about AD but I expect setting this up should teach me a thing or two about both.

 

I'm presuming that once I have this setup correctly, we could install any browser (any being IE 6/7/8, FF, Chrome and maybe even Opera) and web traffic would be logged?

 

Chrome is installed on very few machines but what if a user used its 'incognito browsing' mode? Would squid still register sites visited in that mode?

Guest monkeyx
Posted

I know there squid works with all versions of IE and Firefox.

 

Not tested with Opera. I know that Chrome has issues with some version of squid, so you would need to be on at 2.7 build of squid.

 

You can also redirect all port 80 and 443 traffic through squid via your router to stop people by passing etc.

 

Tim

Posted

I would advise against using ident. I found that using ident causes quite a delay in loading a page sometimes because it has to wait for the ident response before fetching the page. We use dansguardian and squid to integrate AD. Tho be carefull because if you dont setup any encryption then passwords are transmitted between squid and ad in clear text meaning you can actuarly use a packet sniffer to capture passwords.

 

If your looking for just a way to log pages accessed install a new box after your current just for auditing purposes. Ive used endian for this in the past its free and has ad integration and its pretty easy to setup.

 

We also found you can assign different filtering levels to staff children and administrators

 

Hope this helps

Squeeky

  • 2 weeks later...
Posted

What model no of Watch Guard Firebox are you using?

I currently am running two types. The Firebox X Edge e-Series X20e and Firebox X Core e-Series X550e both with Version 11.2 Software across three schools.

 

I have one set of rules that covers the whole school, pupils and teachers alike which is not ideal. Once I get back to school for the new term I will be setting up and using Single Sign On (SSO) which is within the Watch Guard. This will then allow me to make different sets of rules for different groups i.e. pupils and teachers and the works on your AD authentication within your domain. It’s a two part install with SSO agent and SSO client, the agent is install on your domain and the client on you Pc’s. This gets around having to authenticate twice.

 

Once this is done you know who has logged on where, now you can set up an internet logging server/service. I have been told it will take up a fair bit of space when running so just bare that in mind.

 

I will be back to work on Tuesday/Wednesday this coming week and can scan and give you the set up instruction if you wish.

Posted
I would be careful with Identd its not ideal, we used it in a Coucil and I found I could just create a local user account and pretend that I was the Chief Exec in the logs.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...