Jump to content

ibpalle

Smoothwall Staff
  • Posts

    1,661
  • Joined

Everything posted by ibpalle

  1. First option: Go to Reports - reports - custom. Add the details for name, description and location. Find the reports in the Guardian 3 folder called 'IP Activity and Domain activity' and add it to the included sections. Select both and group them. In the parameters section set the IP Activity as the feeder and press the update button in the customize reports section at the top. The layout will change slightly. Change the display top to a suitable number, the group to Guests. Enter the advanced option and select denied in the request status. Move down to the domain activity report and set the top to a suitable number of entries. Press create report and try to run it for a suitable timeframe. This will give you the top blocked IPs list and then a report on the top blocked domains for each IP. 2nd report This will be a report run for a single IP. In custom add the 'Individual User' report. In the options, set the group and select denied in the request status. Go to the Export tab and select IP address. You can run this report by IP address. 3rd and closest to what you want. However, this can be a massive report if you run this with a top value of say 500. You will get up to 500 IPs and then up to 500 log extract reports with 500 entries in each. Add the IP activity and Individual user report section and group them. Select feeder to be IP Activity and update. Set top number and denied status. Create the report and run it.
  2. I would only use one if at all. The content filtering works fine on Youtube provided https inspection or you are using the cloud filter so inappropriate content will be detected by the Smoothwall filter. Conversely, using the moderate or strict policies for youtube use Youtubes own policies, which you cannot control.
  3. Is the quota policy above the block policy? Did you create a special group or just use the username and the default quota?
  4. Some have begun using the quota action for DSL users. Create a group for the DSL users and then create a policy for them towards the top of the policy list with the action 'Limit to quota'. Set the categories you allow them to override blocks on in the what column. If a DSL goes to a site in one of those categories, they will see a block page with button to override the block for a certain time (set in the quota definition). This gives them the block info and a stop before they decide if they really want to continue. Obviously only add categories you feel are OK for them to see - not categories like malware etc.
  5. If you see it blocked but with no reason for the block, try adding it to a do not filter policy instead of allow.
  6. Correct. You can actually have just the redirect to SSL login - iDex users wont see it as Smoothwall already knows who they are. Others will be asked to login manually.
  7. If you are seeing kerberos it means a proxy is using kerberos via redirect as an auth method. Devices on power but with no users logged into them will be showing as hostnames. If you have updated iDex to 2.3.5 from software.smoothwall.com I would suggest trying without Kerberos. Use core authentication and see if that holds up - should give you a much cleaner user activity list.
  8. Are the hostname logins actually iDex logins? Normally hostnames are not reported by iDex logins. They can be seen for RADIUS accounting in some cases. Check the user activity list for the method of login.
  9. A combination of cloud filter extension for cloud directories, iDex and RADIUS for AD accounts on both BYOD and domain devices should hopefully cover most bases for transparent authentication of all devices/
  10. From https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365 Option 1: Authenticate your device or application directly with a Microsoft 365 or Office 365 mailbox, and send mail using SMTP AUTH client submission Note This option isn't compatible with Security defaults in Microsoft Entra ID. We recommend using Modern Authentication when connecting with our service. For more information about OAuth, see Authenticate an IMAP, POP or SMTP connection using OAuth. You must also verify that SMTP AUTH is enabled for the mailbox being used. SMTP AUTH is disabled for organizations created after January 2020 but can be enabled per-mailbox. For more information, see Enable or disable authenticated client SMTP submission (SMTP AUTH) in Exchange Online. Although SMTP AUTH is available now, we announced Exchange Online will permanently remove support for Basic authentication with Client Submission (SMTP AUTH) in September 2025. We strongly encourage customers to move away from using Basic authentication with SMTP AUTH as soon as possible. For more Information about alternative options, please see our announcement here- https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-online-to-retire-basic-auth-for-client-submission-smtp/ba-p/4114750 So no changes yet to SMTP access.
  11. @Gobstopper - The login happens on the device and is not sent to the Smoothwall on-prem so it isn't aware of the user. Look into using our cloud filter extension - that will get the login from the OS and map the users correctly. It is part of the license so have a chat with the account manager - they will pass you on to a tech contact that can assist if you are interested in trying this out.
  12. Just an aside, moving AD above iDex allows thew AD group mappings to be used, rather than the iDex group mappings. Before iDex agent 2.3.5 there were cases of group mapping lookup failing. The user activity should show iDex user info still incoming?
  13. Check user activity in services - authentication or take a look at reports - realtime - system and select authentiocation from the section dropdown. You should see RADIUS logins in both places ideally. Smoothall only use accounting for logins - it does not need to do authentication. On NPS or WIFI controller, you can forward or send accounting directly to Smoothwall. Authentication only works for AD connections but lookup does work for Google and Azure so if you can find a way to get RADIUS authentication working for those accounts, accounting sent to Smoothwall should give the correct user/group lookup result.
  14. You should consider using iDex and core auth to avoid having to use auth exceptions. They are very annoying
  15. When BYOD optimisations are enabled: The system uses an alternate mechanism to handle BYOD connects and disconnects which is more robust. Users that disconnect remain logged in until the nightly login purge. The automatic prefixing of BYOD usernames with the correct DOMAIN requires that an IDexAgent is used and has performed a sync of groups and users. We recommend enabling this option by default - it will be enabled by default on new installs.
  16. Enable the auditing of traffic in the network - settings - advanced section and you can see all traffic arriving and leaving the Smoothwall in the realtime firewall viewer.
  17. Good analysis, just a note - enabling the IDS feature on LAN and BYOD interfaces on the Smoothwall can give you some of the same information, not with a fancy report though.
  18. I'd take a look at what you need from the firewall - we (Smoothwall) rarely find that our customers need more than what our firewall can provide. You will need to prioritise based on those requirements - what part is the most important in your situation. Filtering wise I don't think there is a real contest, especially with the new cloud filter option that comes with the Smoothwall license.
  19. Just an aside, the ovpn file generated by the Smoothwall configurator should work with other OpenVPN clients too - I haven't tested it recently though. https://openvpn.net/client/client-connect-vpn-for-windows/
  20. The problem status gives this result on a search: Most application errors, like (0xc00000e5), are usually related to the application being unable to access a required system file. Therefore, run the application as an administrator, which grants it administrative access to system files. You need to right-click on the app and select Run as administrator. Not certain how that would apply here.
  21. Is the TAP device installed in the network interfaces?
  22. Running Windows 11 and the SSL VPN client with no issues here.
  23. 600 is the recommended value. Are you seeing entries in the list below? If you see a system being double filtered, check this list to see if the IP is there and also check that the client is receiving the configuration correctly. https://kb.smoothwall.com/hc/en-us/articles/360016413920
  24. Could have been part of our template settings - in any case, any group you can delete in the services - authentication - groups section is just a normal group. The only ones that are built in are 'Banned users, Default users and Unauthenticated IPs. Default users will be users where the Smoothwall knows the username but not the group. Unauthenticated will be where Smoothwall only has the IP.
  25. Just a note regarding a post in here - on the Smoothwall, in the advanced proxy settings, adding port 8443 to the 'Also allow these ports' is only needed when proxy settings are used on the clients. With transparent proxy, make sure that port 8443 is allowed outgoing in the firewall.
×
×
  • Create New...