Jump to content

Recommended Posts

Posted

Good morning all,

 

The network I inherited has iTunes blocked, i have added a few URL's to the unfiltered list but this doesnt seem to have helped. Apparently it used to work but doesnt now.

 

Does anyone have an idea how I can get this working? We have some iPads that need setting up and apps installing.

 

Thanks

Posted (edited)

I use Squid on Linux, but here are my user-agent headers which need to go through:

iTunes oscpd QuickTime GCSL GCSP InetURL/1.0 AppleCoreMedia

 

Here' are the URLs

.apple.com .gcsp.cddbp.net .icloud.com ax.phobos.apple.com.edgesuite.net .mzstatic.com .verisign.com

Edited by jinnantonnixx
  • Thanks 1
Posted (edited)

iPad apps are OK here. I use ACLs to define the headers and URLs, then use Squid's http_access rules to combine the header ACL with URL ACLs. This works OK.

On the URLs, have you wild-carded the URLs?

 

e.g., in Squid,

.gcsp.cddbp.net

means

*.gcsp.cddbp.net

Edited by jinnantonnixx
Posted

If you are using Smoothwall, Please configure the following:

 

Browse to Web proxy > Authentication > Exceptions

 

Add the following categories to Auth exceptions:

 

SSL/CRL

Software Updates

Authentication Exceptions

iTunes

 

Save.

 

Browse to Guardian > Web Filter > Policy Wizard

 

Create a policy with the following conditions:

 

Who: Everyone

What: Authentication Exceptions, SSL/CRL, Software Updates, itunes

Action: Whitelist

Where: Everywhere

When: Always

Action: Enabled

 

Confirm and save this rule.

 

Browse to Guardian > Web Filter > Policies

 

Move the policy you created up the table until it is above any block or blanket block in place for the group Unauthenticated IPs. You may have this group in a policy folder in position 2 in the table by default if you did not have Unauthenticated IPs allowed to use the web proxy prior to migrating. If this is a fresh install please check whether Unauthenticated IPs is included in the aforementioned policy folder.

 

Please then edit the 'Recommended security rules' content modification category group and remove 'IE remote code execution'.

 

Save and restart the web proxy.

  • Thanks 2
Posted
If you are using Smoothwall, Please configure the following:

 

Browse to Web proxy > Authentication > Exceptions

 

Add the following categories to Auth exceptions:

 

SSL/CRL

Software Updates

Authentication Exceptions

iTunes

 

Save.

 

Browse to Guardian > Web Filter > Policy Wizard

 

Create a policy with the following conditions:

 

Who: Everyone

What: Authentication Exceptions, SSL/CRL, Software Updates, itunes

Action: Whitelist

Where: Everywhere

When: Always

Action: Enabled

 

Confirm and save this rule.

 

Browse to Guardian > Web Filter > Policies

 

Move the policy you created up the table until it is above any block or blanket block in place for the group Unauthenticated IPs. You may have this group in a policy folder in position 2 in the table by default if you did not have Unauthenticated IPs allowed to use the web proxy prior to migrating. If this is a fresh install please check whether Unauthenticated IPs is included in the aforementioned policy folder.

 

Please then edit the 'Recommended security rules' content modification category group and remove 'IE remote code execution'.

 

Save and restart the web proxy.

 

That's kinda what I said ;).

 

Kidding, obviously.

Posted (edited)
If you are using Smoothwall, Please configure the following:

 

Browse to Web proxy > Authentication > Exceptions

 

Add the following categories to Auth exceptions:

 

SSL/CRL

Software Updates

Authentication Exceptions

iTunes

 

Save.

 

Browse to Guardian > Web Filter > Policy Wizard

 

Create a policy with the following conditions:

 

Who: Everyone

What: Authentication Exceptions, SSL/CRL, Software Updates, itunes

Action: Whitelist

Where: Everywhere

When: Always

Action: Enabled

 

Confirm and save this rule.

 

Browse to Guardian > Web Filter > Policies

 

Move the policy you created up the table until it is above any block or blanket block in place for the group Unauthenticated IPs. You may have this group in a policy folder in position 2 in the table by default if you did not have Unauthenticated IPs allowed to use the web proxy prior to migrating. If this is a fresh install please check whether Unauthenticated IPs is included in the aforementioned policy folder.

 

Please then edit the 'Recommended security rules' content modification category group and remove 'IE remote code execution'.

 

Save and restart the web proxy.

 

cheers i have followed this and i am still having the issue with installing app updates

 

additionally i have noticed that i can browse the store on my phone but not on an ipad :(

 

edit: btw i moved the policy to the very top to ensure it would work but nada

Edited by One_Minute_Hero
Posted (edited)

I think you might need to restart the proxy (not the entire box) to make it work.

 

If not, ring 08701 999500. It's what they are there for!

 

Edit: I see that Alex actually put that anyway.

Edited by Tsonga
Posted
I think you might need to restart the proxy (not the entire box) to make it work.

 

If not, ring 08701 999500. It's what they are there for!

 

Edit: I see that Alex actually put that anyway.

 

i did this morning lol, awaiting a call back

 

just to test i disabled the openDNS filters for 10 minutes to see if anything was getting blocked there....still same.

Posted

Yea smoothwall blocks it unless you have it setup right.

 

To do a very quick test, use a machine with a static IP (yours?). Add the IP into the exception list (you will need to change to port 801 on LAN settings) and see if it works then. With these settings it allows the machine with that IP to bore a hole straight through smoothwall. This will at least confirm it is smoothwall as the guilty party.

Posted
If I remember correctly I setup a policy in smoothwall to allow itunes and had the same result. Was only when policy was near the top of priorities did it work. Even smoothwall support couldnt say why it needed to be there. Think I have mine 3rd in list just below ntlm exceptions
Posted
Yea smoothwall blocks it unless you have it setup right.

 

To do a very quick test, use a machine with a static IP (yours?). Add the IP into the exception list (you will need to change to port 801 on LAN settings) and see if it works then. With these settings it allows the machine with that IP to bore a hole straight through smoothwall. This will at least confirm it is smoothwall as the guilty party.

 

iTunes seems to be working ok on my PC with the exception

Posted
iTunes seems to be working ok on my PC with the exception

 

That confirms that it is smoothwall playing silly buggers. I'd ring smoothwall back and insist on speaking with someone, you know EXACTLY what you are trying to achieve and for them its a 5 min job. Download their teamviewer client and be good to go. Either take your IP out of the exception or have another machine to hand for testing :).

Posted (edited)
That confirms that it is smoothwall playing silly buggers. I'd ring smoothwall back and insist on speaking with someone, you know EXACTLY what you are trying to achieve and for them its a 5 min job. Download their teamviewer client and be good to go. Either take your IP out of the exception or have another machine to hand for testing :).

 

when i last phoned on friday (just before i left) i was told it had been escalated. am just awaiting office hours and will call again. cheers

Edited by One_Minute_Hero
Posted
If you are using Smoothwall, Please configure the following:

 

Browse to Web proxy > Authentication > Exceptions

 

Add the following categories to Auth exceptions:

 

SSL/CRL

Software Updates

Authentication Exceptions

iTunes

 

Save.

 

Browse to Guardian > Web Filter > Policy Wizard

 

Create a policy with the following conditions:

 

Who: Everyone

What: Authentication Exceptions, SSL/CRL, Software Updates, itunes

Action: Whitelist

Where: Everywhere

When: Always

Action: Enabled

 

Confirm and save this rule.

 

Browse to Guardian > Web Filter > Policies

 

Move the policy you created up the table until it is above any block or blanket block in place for the group Unauthenticated IPs. You may have this group in a policy folder in position 2 in the table by default if you did not have Unauthenticated IPs allowed to use the web proxy prior to migrating. If this is a fresh install please check whether Unauthenticated IPs is included in the aforementioned policy folder.

 

Please then edit the 'Recommended security rules' content modification category group and remove 'IE remote code execution'.

 

Save and restart the web proxy.

 

 

i missed this step :(

 

working now

 

thanks all

  • Thanks 1
Posted
Yes, the WHITELIST action is vitally important - this is a commonly misunderstood configuration. Whitelisting bypasses content scanning and any content modification rules which can interfere with the iTunes traffic which explains why it doesn't work with an 'Allow' rule but does with a Whitelist rule.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...