One_Minute_Hero Posted February 8, 2013 Posted February 8, 2013 Good morning all, The network I inherited has iTunes blocked, i have added a few URL's to the unfiltered list but this doesnt seem to have helped. Apparently it used to work but doesnt now. Does anyone have an idea how I can get this working? We have some iPads that need setting up and apps installing. Thanks
jinnantonnixx Posted February 8, 2013 Posted February 8, 2013 (edited) I use Squid on Linux, but here are my user-agent headers which need to go through: iTunes oscpd QuickTime GCSL GCSP InetURL/1.0 AppleCoreMedia Here' are the URLs .apple.com .gcsp.cddbp.net .icloud.com ax.phobos.apple.com.edgesuite.net .mzstatic.com .verisign.com Edited February 8, 2013 by jinnantonnixx 1
Tsonga Posted February 8, 2013 Posted February 8, 2013 What filtering system do you use? If its smoothie they have an entire content category just for itunes, they have many many urls. 1
X-13 Posted February 8, 2013 Posted February 8, 2013 Apparently it used to work but doesnt now. Used to work or "Used to work"? There's a difference.
One_Minute_Hero Posted February 8, 2013 Author Posted February 8, 2013 cheers just testing the domains that @jinnantonnixx suggested it seems that OPENDNS is blocking them. just waiting the 3 mins now. also we are using smoothwall and will checkout the category for them, cheers @Tsonga
One_Minute_Hero Posted February 8, 2013 Author Posted February 8, 2013 Getting there now. I can browser iTunes on the iPad now just cant download apps still get the "Cannot connect to iTunes store"
jinnantonnixx Posted February 8, 2013 Posted February 8, 2013 (edited) iPad apps are OK here. I use ACLs to define the headers and URLs, then use Squid's http_access rules to combine the header ACL with URL ACLs. This works OK. On the URLs, have you wild-carded the URLs? e.g., in Squid, .gcsp.cddbp.net means *.gcsp.cddbp.net Edited February 8, 2013 by jinnantonnixx
AMLinington Posted February 8, 2013 Posted February 8, 2013 If you are using Smoothwall, Please configure the following: Browse to Web proxy > Authentication > Exceptions Add the following categories to Auth exceptions: SSL/CRL Software Updates Authentication Exceptions iTunes Save. Browse to Guardian > Web Filter > Policy Wizard Create a policy with the following conditions: Who: Everyone What: Authentication Exceptions, SSL/CRL, Software Updates, itunes Action: Whitelist Where: Everywhere When: Always Action: Enabled Confirm and save this rule. Browse to Guardian > Web Filter > Policies Move the policy you created up the table until it is above any block or blanket block in place for the group Unauthenticated IPs. You may have this group in a policy folder in position 2 in the table by default if you did not have Unauthenticated IPs allowed to use the web proxy prior to migrating. If this is a fresh install please check whether Unauthenticated IPs is included in the aforementioned policy folder. Please then edit the 'Recommended security rules' content modification category group and remove 'IE remote code execution'. Save and restart the web proxy. 2
Tsonga Posted February 8, 2013 Posted February 8, 2013 If you are using Smoothwall, Please configure the following: Browse to Web proxy > Authentication > Exceptions Add the following categories to Auth exceptions: SSL/CRL Software Updates Authentication Exceptions iTunes Save. Browse to Guardian > Web Filter > Policy Wizard Create a policy with the following conditions: Who: Everyone What: Authentication Exceptions, SSL/CRL, Software Updates, itunes Action: Whitelist Where: Everywhere When: Always Action: Enabled Confirm and save this rule. Browse to Guardian > Web Filter > Policies Move the policy you created up the table until it is above any block or blanket block in place for the group Unauthenticated IPs. You may have this group in a policy folder in position 2 in the table by default if you did not have Unauthenticated IPs allowed to use the web proxy prior to migrating. If this is a fresh install please check whether Unauthenticated IPs is included in the aforementioned policy folder. Please then edit the 'Recommended security rules' content modification category group and remove 'IE remote code execution'. Save and restart the web proxy. That's kinda what I said . Kidding, obviously.
One_Minute_Hero Posted February 8, 2013 Author Posted February 8, 2013 (edited) If you are using Smoothwall, Please configure the following: Browse to Web proxy > Authentication > Exceptions Add the following categories to Auth exceptions: SSL/CRL Software Updates Authentication Exceptions iTunes Save. Browse to Guardian > Web Filter > Policy Wizard Create a policy with the following conditions: Who: Everyone What: Authentication Exceptions, SSL/CRL, Software Updates, itunes Action: Whitelist Where: Everywhere When: Always Action: Enabled Confirm and save this rule. Browse to Guardian > Web Filter > Policies Move the policy you created up the table until it is above any block or blanket block in place for the group Unauthenticated IPs. You may have this group in a policy folder in position 2 in the table by default if you did not have Unauthenticated IPs allowed to use the web proxy prior to migrating. If this is a fresh install please check whether Unauthenticated IPs is included in the aforementioned policy folder. Please then edit the 'Recommended security rules' content modification category group and remove 'IE remote code execution'. Save and restart the web proxy. cheers i have followed this and i am still having the issue with installing app updates additionally i have noticed that i can browse the store on my phone but not on an ipad edit: btw i moved the policy to the very top to ensure it would work but nada Edited February 8, 2013 by One_Minute_Hero
Tsonga Posted February 8, 2013 Posted February 8, 2013 (edited) I think you might need to restart the proxy (not the entire box) to make it work. If not, ring 08701 999500. It's what they are there for! Edit: I see that Alex actually put that anyway. Edited February 8, 2013 by Tsonga
One_Minute_Hero Posted February 8, 2013 Author Posted February 8, 2013 I think you might need to restart the proxy (not the entire box) to make it work. If not, ring 08701 999500. It's what they are there for! Edit: I see that Alex actually put that anyway. i did this morning lol, awaiting a call back just to test i disabled the openDNS filters for 10 minutes to see if anything was getting blocked there....still same.
Tsonga Posted February 8, 2013 Posted February 8, 2013 Yea smoothwall blocks it unless you have it setup right. To do a very quick test, use a machine with a static IP (yours?). Add the IP into the exception list (you will need to change to port 801 on LAN settings) and see if it works then. With these settings it allows the machine with that IP to bore a hole straight through smoothwall. This will at least confirm it is smoothwall as the guilty party.
andyfield Posted February 8, 2013 Posted February 8, 2013 If I remember correctly I setup a policy in smoothwall to allow itunes and had the same result. Was only when policy was near the top of priorities did it work. Even smoothwall support couldnt say why it needed to be there. Think I have mine 3rd in list just below ntlm exceptions
One_Minute_Hero Posted February 8, 2013 Author Posted February 8, 2013 Yea smoothwall blocks it unless you have it setup right. To do a very quick test, use a machine with a static IP (yours?). Add the IP into the exception list (you will need to change to port 801 on LAN settings) and see if it works then. With these settings it allows the machine with that IP to bore a hole straight through smoothwall. This will at least confirm it is smoothwall as the guilty party. iTunes seems to be working ok on my PC with the exception
Tsonga Posted February 8, 2013 Posted February 8, 2013 iTunes seems to be working ok on my PC with the exception That confirms that it is smoothwall playing silly buggers. I'd ring smoothwall back and insist on speaking with someone, you know EXACTLY what you are trying to achieve and for them its a 5 min job. Download their teamviewer client and be good to go. Either take your IP out of the exception or have another machine to hand for testing .
One_Minute_Hero Posted February 11, 2013 Author Posted February 11, 2013 (edited) That confirms that it is smoothwall playing silly buggers. I'd ring smoothwall back and insist on speaking with someone, you know EXACTLY what you are trying to achieve and for them its a 5 min job. Download their teamviewer client and be good to go. Either take your IP out of the exception or have another machine to hand for testing . when i last phoned on friday (just before i left) i was told it had been escalated. am just awaiting office hours and will call again. cheers Edited February 11, 2013 by One_Minute_Hero
One_Minute_Hero Posted February 11, 2013 Author Posted February 11, 2013 If you are using Smoothwall, Please configure the following: Browse to Web proxy > Authentication > Exceptions Add the following categories to Auth exceptions: SSL/CRL Software Updates Authentication Exceptions iTunes Save. Browse to Guardian > Web Filter > Policy Wizard Create a policy with the following conditions: Who: Everyone What: Authentication Exceptions, SSL/CRL, Software Updates, itunes Action: Whitelist Where: Everywhere When: Always Action: Enabled Confirm and save this rule. Browse to Guardian > Web Filter > Policies Move the policy you created up the table until it is above any block or blanket block in place for the group Unauthenticated IPs. You may have this group in a policy folder in position 2 in the table by default if you did not have Unauthenticated IPs allowed to use the web proxy prior to migrating. If this is a fresh install please check whether Unauthenticated IPs is included in the aforementioned policy folder. Please then edit the 'Recommended security rules' content modification category group and remove 'IE remote code execution'. Save and restart the web proxy. i missed this step working now thanks all 1
AMLinington Posted February 11, 2013 Posted February 11, 2013 Yes, the WHITELIST action is vitally important - this is a commonly misunderstood configuration. Whitelisting bypasses content scanning and any content modification rules which can interfere with the iTunes traffic which explains why it doesn't work with an 'Allow' rule but does with a Whitelist rule. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now