Jump to content

ibpalle

Smoothwall Staff
  • Posts

    1,661
  • Joined

Everything posted by ibpalle

  1. Plus one for iDex. Active proxy auth is a problem as so many apps and third party software use http and https these days and none of them have any support for proxy authentication. The Smoothwall is connected to your AD - it should not matter if one DC disappears for a while, the AD connection should still work, everything else being equal, so definitely something not quite right. Take a look at using iDex as well or instead of - it's worth it.
  2. With apps and software using HTTPS it's often HTTPS inspection that gets in the way. Applications often do not use certificate validation via CA, sometimes they just use pinned certificates, which causes them to break when subjected to HTTPS inspection.
  3. The trigger for the safeguarding alert is the categorisation, not the blocked or allowed status. You would get the same safeguarding alerts regardless of block status. Safeguarding does not care if the access was blocked or not.
  4. Its a bogus error and we need to update the test. Opening smoothwall.com gives a 203 (or similar) redirect now. No error but in the test itself.
  5. I'd recommend opening a support case for this. The mappings are supposed to be picked up both by cloud and connect if all other elements are in place.
  6. The only thing Smoothwall needs is RADIUS accounting so the way you are using it the way to do it when you need advanced features that the NPS allows you to have. The BYOD settings on Smoothwall allows the Smoothwall to work as a simple RADIUS auth and accounting service for AD accounts but the only thing required for the Smoothwall to log a user in, is the RADIUS accounting message. The legacy method mentioned in the Maiden update notes is the ability for the Smoothwall to use RADIUS as a directory service (Rarely used hence the removal)
  7. Maiden and Leeds are in a bit of a parallel course at the moment and I have no set date for general release of Maiden. We needed the a kernel features due to UEFY only in a new appliance so Maiden is used on those but bug fixes are currently applied to both - Leeds-63 corresponds to Maiden-4 or 5 I believe.
  8. The reinstall is quick - you can transfer settings from the existing install during the process but do take a full backup before you start. The appliance should boot from an inserted USB drive if present so download the latest ISO from https://software.smoothwall.com/ - get the serial from the dashboard page, burn image to USB, insert the USB and reboot the Smoothwall. Monitor and keyboard needs to be attached. Go through the install steps and select to carry over the settings from the previous install. Once done, you should be up and running again with the same settings - the root password needs to be set again if I remember correctly. The whole process should take less than 15 mins
  9. The RADIUS accounting that is referred to as a legacy service is one of the directory methods, not the ability to serve as a RADIUS auth and acc service, which is set under the BYOD header in services - authentication. The CA warning will be gone tomorrow. The check in the UI runs overnight.
  10. Outgoing traffic to the 5228 port needs to be available for the user If using proxy settings the port needs to be allowed as an additional web port in the web proxy settings advanced section. If client is behind a transparent proxy, the port needs to be allowed outgoing on the firewall.
  11. The [email protected] email is available for direct submissions afair. You can also add a domain/URL to the Smoothwall categories locally.
  12. I have updated this KB to include the LogonExclusion information.
  13. Without HTTPS inspection, the full URL is not available to the filter. It can only see the domain part - which is likely why the Smoothwall can't block a specific URL in the classroom. If HTTPS inspection can be enabled you can try that or another option is to use our cloud filter extension which is an extension to browsers. The filtering by the extension is not reliant on HTTPS inspection as the filtering happens in the browser, not on the proxy. Talk to your account manager if interested. It's part of the license and a great new tool in the filter toolbox.
  14. Smoothwall does not know if content is paid for or not and it doesn't care really. It just cares about the content. If it gets blocked due to inappropriate content, you will have a URL you can allow.
  15. First find out why it's blocked. What's on the blockpage? What is the reason for the block? Use the Vimeo category we have created in the blocklist under multimedia for an allow policy is one option but may not help depending on why it's getting blocked so find that out first.
  16. We have a category for Vimeo - I would assume this needs to be not blocked as well as categories like Audio/Video. We do have a downloadable list of all the categories in our blocklist that you can find here: https://kb.smoothwall.com/hc/en-us/articles/360004511520 - take a look at the multimedia section. This is updated daily so it's a good idea to take a look every 3-4 months in case there are new categories that would be beneficial to use. Is there any difference to a VOD service and the rest of Vimeo?
  17. Then stay away from the console - it was just a suggestion in case you were comfortable with that. Any IDS policies active? You can find them in the Services » Intrusion system » IDS section. Not likely but worth a look.
  18. Yes raise it with support and let them have a look. Also check routing in your setup - make sure only the external connection has a gateway and that any internal routes are put in the network - routing - subnets section. If you want to dig a bit on your own, on the console you can use tools like 'ethtool' to check status of the interfaces and 'wget' can be used as well to test downloads directly to the Smoothwall.
  19. Interesting but..... Any major difference you are aware of in the settings from May compared to the setting you were using before the restore? Was this a backup restore or a system snapshot?
  20. And was the method iDex client for the logins you saw? The reason I keep asking this is that I would not expect iDex client logins to follow the timeout value but it's been a while since I have used it so I could be wrong. As for alerts - what alerts are you talking about - I am assuming safeguarding notifications? Those notifications are based on the safeguarding rulesets in our blocklist. If you have a site that you would consider to be Porn for example but Smoothwall does not categorise it as such, add it to the Porn category so it can be included in the Adult category alerts in notification for example. You can add content to the standard categories in the guardian - policy objects - categories.
  21. Your directory is irrelevant in a sense - at least for the iDex client. It takes the username of the logged in user, if it can find it and use that. With iDex clients browsing, do you see any iDex client logins in the services - authentication - user activity?
  22. The iDex client has built-in identification and attaches user/group info to all requests going to the Smoothwall. They should show as 'iDex client' logins in the method column in the services - authentication - user activity list. If you redirect the system to a normal proxy, not the iDex client, there will be no logins from the iDex client. When you see the clients logged in to the Smoothwall, in the user activity list mentioned above, what is the method for the login?
  23. The reports - realtime - system and select authentication from the section drop down list. You can see the static logs in the logs menu as well. It sounds like the login follows the timeout of 10m - is that the value set in the services - authentication - settings for the global timeout? The login is done when the iDex client interface gets traffic. Could it be that the device is not actually sending traffic via the proxy settings and thus the login times out? If you browse after a logout, does a new login appear?
  24. It sounds like you maybe forgot to set the proxy to localhost:8080 after installing the software (iDex client) on the 10.15 devices?
  25. The QUIC content modification policy is good but won't work if the browser is already in QUIC mode. Ideally you will need to block QUIC on the firewall level too.
×
×
  • Create New...