Jump to content

ibpalle

Smoothwall Staff
  • Posts

    1,661
  • Joined

Everything posted by ibpalle

  1. I haven't tested this so not certain it will work - I'm also not a shark with regular expressions so.. In a custom category, create a regular expression in URL patterns to identify those URLs and put that in a do not filter policy - this will avoid certificate inspection for those URLs that trigger the cert ID mismatch. Once the URL is changed to the real one, filtering will kick in again.
  2. Check to see if the logs show the access was blocked - when on Youtube the blockpage sometimes doesn't show for some reason.
  3. Do not think QUIC is the issue here - is the diagnostic for the cloud filter extension looking different in the chrome and the edge browser?
  4. But you can have the SSL login page as the auth option as well. Users that authenticate via RADIUS wont get the redirect to the login page as they are already authenticated but users that have not, will see it.
  5. Also this. Overview and explanation of the categories and signatures. https://kb.smoothwall.com/hc/en-us/articles/11206334266268
  6. The error 'The Server certificate did not match the domain name' means that the domain in the address that's being visited does not match the ID value for the address in the certificate. There could be a new redirect in place or other issue that causes this mismatch. When speaking to them, show them the screenshot and the certificate information.
  7. This looks like the Youtube strict or moderate content mod is put in place. Try to disable that and see if the video can then be shown.
  8. Thanks for the feedback - support has had a backlog quite a bit bigger than previous years - again! We are expanding there - again! Just as a reminder, the kb.smoothwall.com site has a whole section on the cloud filter with the most recent install and diagnostics instructions.
  9. The mappings should be separate for each system if the setup is as you describe. Mappings on one will not affect anything on the others. If there are no mappings then users end up as default users, which is the default behaviour when the filter knows your username but not your group membership so that's expected. However you then say this makes the other site mappings ineffective ... 1: unless there is replication going on settings are separate. 2: For some reason the cloud filter extension has been installed on the other sites using the cloud filter serial from the first site
  10. On each smoothwall box, you make the group mappings in the services - authentication - directories. In the portal, you make those mappings in the admin - smoothwall groups section. Each site, even though looking at the same directory, should be able to make their own group mappings in the directory.
  11. So the group mappings you make on the 'first' smoothwall box is being replicated to all the others but you still have separate cloud configs for all sites, as in a cloud serial and separate portal for each site? If group mappings are replicated, they need to be standardised so you use the same groups on all sites - one local Smoothwall group can be mapped to multiple directory OUs or groups so make all the student group mappings on the first smoothwall for all sites, same with the other groups.
  12. The group and UOs should stay the same - Smoothwall does not change anything in Azure so unsure what you mean when you say Smoothwall has stolen users. Each Smoothwall and cloud config combination should have their own group mappings - they all just connect to the same directory. Is there any replication going on between Smoothwalls?
  13. Is there anything not working on your Office 365 products? Any service that you can't use? 503 is gateway timeout so no reply to the request. It may simply not be available any more. Certainly doesn't look like the host has a TCP 443 service running.
  14. No updated tool like this yet - I'll ask around but I think those sites are defunct by now.
  15. Here is a new KB about the recent category changes: https://kb.smoothwall.com/hc/en-us/articles/11206334266268 Good reference when you have questions.
  16. From the description it sounds like there is a physical connection between the 2 LANs. DHCP discovery is done using broadcasts that are not subnet specific so the only way this could happen is if DHCP discovery broadcasts for LAN 1 are also seen on LAN 2, which requires a physical connection between the 2, Smoothwall does not pass broadcasts between subnets.
  17. Whether it's blocked or not depends on the policy the object is used in - just a clarification. The top item should cover everything related to the category, as I understand it. The individual item categories are for specific allow or block policies. There may be exceptions but that is the general idea.
  18. Caught me a bit off guard as well. A few tips regarding the new categorisation style. [Depreciated] categories can be de-selected from policies and objects. When you see a category that can be expanded like the News category. The top item in the expanded list covers the entire category - all other items are specific to a service, application and/or a site. News 0/25 News Aljazeera Arirang TV News Korea Axios BBC Bloomberg Etc Going to take a while to get used to - most categories are the named the same. Mainly the organisation is different.
  19. Notifications are setup on the on-prem Smoothwall. The cloud portal generates alerts only for cloud filter extension clients. You'll find the safeguarding notifications in reports - safeguarding - notifications.
  20. The weekly and monthly summary shows a list of categories and the number of breaches but not the details - the daily notification will show the full details of each breach. You can setup notifications for any or all categories together.
  21. That's what it looks like in htop - in top you would see a single process at 100+%. AFAIK here you see the individual threads. Naming is confusing in these apps sometimes.
  22. Core auth works by using the login information already present - normally provided by iDex agent, login scripts or RADIUS. For anyone still using ntlm or kerberos for proxy authentication, I'd recommend moving to iDex agent and core auth.
  23. The 407 issue is authentication problems. The proxy is likely still using ntlm or Kerberos. Check that the directory connection is still working, time is right etc. The recategorisation is not being rolled out yet - soon though.
  24. I have stated using caching with min size 10MB and max size 250 MB - the intent is to cache larger files and not bother with smaller ones but I haven't done any testing on the performance as such, it just sounds like a reasonable thing to do
×
×
  • Create New...