-
Posts
240 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rob_f
-
I think Tom was looking at this last week. He's off getting married now though for three weeks - i'll see if i can find out for you what can be done. Thanks! Rob.
-
Smoothwall SSL login doesn't work with TS/Citrix
rob_f replied to cookie_monster's topic in Network and Classroom Management
AFAIK SSL login operates at a lower level of the stack, so just operates on IPs unfortunately. I've asked the guys to take a closer look at this to see if there's another way. Cookie_monster - you might want to try proxy authentication (will prompt for password, but not on a webpage like SSL login) or i seem to remember there is some way in citrix to assign a unique virtual IP to each user session? Thanks, Rob. -
FYI, we're looking into this now for you Smoothie folks. Rob.
-
FYI, PMed a solution which CN confirms works.. If anyone else needs this please let me know. Rob.
- 11 replies
-
- 2
-
-
- authentication
- domain
-
(and 1 more)
Tagged with:
-
Hi gatt, just left the office for the day, as tom may have too. Give me a call in the morning if you're free and we'll try and work out what's going on. 0870 1 999 500 opt 1. Thanks! Rob.
-
You should be able to get the latest build from SmoothWall | Software Download with your serial number. If you can wait, there is a new SP4 update rollup ISO out in the next week or so - not sure on the exact timing. As for the settings, create an archive in System > Maintenance > Archives including all the configuration things (aside from Ethernet: this includes MAC addresses so won't work on your new system). Save and backup that, then download it by ticking it and select download. Then install as usual (better off not restoring config during install, just do a "normal" install), set IPs and passwords, register, get all the latest updates installed, then go to the same archives page and upload the .tar.gz you downloaded from the old system. Tick that then click restore and it'll let you choose which bits you want to get. Any problemos feel free to drop me or support a bell. Ta! Rob.
-
Good stuff Well, not the errors, but the response! Also good to see that was support! = fantastic and not support != fantastic (weak friday afternoon excuse for a joke for all those codemonkeys out there...) Rob.
-
Hey - you could try a serial cable on the console to see what it's up to, details in the manual but should be 9600-8-N-1, or failing that please give support a call. If the box has been off for a while it may be doing a filesystem consistency check. Although I would have expected it to have finished by now Thanks! Rob.
-
In that situation you could enable the "use sam account name" option to avoid having to change any UPNs within AD.
-
Smoothwall Network Guardian Negatives?
rob_f replied to mb2k01's topic in Internet Related/Filtering/Firewall
If you're using proxy.pac files/auto-dectection you may get occasional issues with IE cached proxy results (i.e. it thought the proxy wasn't there for a second, so it decided not to use it again). https://support.smoothwall.net/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=263 is your friend - specifically the GPO User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable caching of Auto-Proxy scripts. -
Hmm, that's strange. Just tried now and it's ok. Give it another go and if it's not working i'll get someone to call you. RE netbios name, it should be what you see in the domain box on windows PCs when you login - it is by default the leftmost portion of the DNS domain name and won't contain any dots.
-
That looks generally OK. Do you perhaps have a funny netbios name for your network? I say funny, I think it assumes that it is "INTERNAL" based on your LDAP context above. I'd be inclined to force it to whatever it needs to be under the advanced settings on the auth settings page. Also, do all your users have username@domain style login names on their account tab in AD? If not, either get them created with something like ADinfinitum or whatever it's called, or tick the Use SAM Account Name in the same advanced auth settings section. Failing that, feel free to give support a call. We all love a good AD query Rob.
-
Ah yes, good advice! Of course SmoothWall don't have a DT department, so we'll have to risk it....
-
Ditto, just make sure you give it a good clean to get rid of all the bits, preferably with a compressed air duster can thing.
-
Ooops, only just seen this post! Generally you'll get better SmoothWall responses in the security or internet related/filtering forums. At least they're the ones we watch more than the others! To do this you'd need to put in a usual block for either the audio/video category for the students, or a custom block for youtube.com (and googlevideo.com and video.google.com!) Then put in a custom allow for students to get to youtube.com/get_video and possibly googlevideo.com/videoplayback This should then only allow pages that embed videos to get to it, without allowing students to browse the site directly. Hope this helps, feel free to get in touch if you need more info. Rob.
-
Are you perhaps in the network administrators group which by default is unfiltered - see Guardian > Authentication > Settings toward the bottom of the page. Do you see your browsing in the logs (Information > Realtime > Web Filter or Information > Logs > Web Filter) and if so does it say "Exception" or similar next to it? This would again indicate the above. No log entries would mean you're not using the filter at all. HTH, Rob.
-
Check to see if your time settings are the same as attached. Set them as this, click save, then "get time now". Hopefully that should make it always right. If running on a virtualisation platform, you may want to increase the network time retrieval frequency if you are seeing gradual time skew issues.
-
Instead of the administrator user, try creating a new user who is a domain admin (and hasn't got the password set to expire). The administrator user often does not have a windows 2000 style user@domain login name. Hence cannot be used in this step. If you find that your users don't have this style login name (on the accounts tab of their account properties), tick the "use SAM account name" underneath advanced. However the user in this first step in connecting to the directory must have both style usernames. Hope this helps, if not feel free to let me know! Rob.
-
Took me bloody ages to find this thread, then again I wasn't looking particularly hard. Had a fantastic time, hope to do the same next year - good to meet you all and get up to hijinks... Of which Ric_ should have some interesting evidence. Took the day off today as I wouldn't have been particularly effective in the office, good opportunity to catch up bedwise from only 3 hours sleep. Cheers again everyone! Rob.
- 238 replies
-
- 2009
- conference
-
(and 1 more)
Tagged with:
-
SmoothWall and Proxy Sites
rob_f replied to Netwacky87's topic in Internet Related/Filtering/Firewall
Hi guys, sorry for the delay getting back to you on this. If users are getting mapped to "default users" in usually means that the lookup to active directory hasn't returned any groups that are mapped on the SW. This may also in rare cases be because you have the user mapped to multiple SW groups that are conflicting in some way. Best way to sort is to make sure that each user is in only one group that is mapped on the SW. Most people will facilitate this by making sw_staff, sw_year7, sw_year8 etc groups in AD, and then map one-to-one on the SW itself. Makes things a bit easier to manage. As for blocking proxies, it does sound like there isn't a blocking issue per se but more of a group assignment problem. Just to summarise anyway, to block proxies: - ensure the "web proxies" category is ticked to be blocked on the content and url filter. - ensure on the "per group settings" page that you are blocking invalid HTTPS certificates for the required groups. - it will help if you also have "deep URL inspection" turned on on the per group settings page. - when you get the FP2 update next week, turn on "SSL Interception" and push out the certificate of the SmoothWall via AD/zenworks/manually to do all the usual filtering rules on HTTPS content. Any problems, please feel free to give us a call. Thanks, Rob. -
Copy a VMware ESXi Snapshot into workstation?
rob_f replied to ranj's topic in Thin Client and Virtual Machines
When you create a snapshot, it "forks" the VM and starts recording the differences to the pre-snapshot state as separate disk and memory delta files. The general use of snapshots is that you snapshot something to test to see if something works, but don't leave that snapshot active for any sustained period of time (either commit the change or rollback the snapshot). Otherwise, and certainly with transactional systems like databases, mailservers etc., you wouldn't be able to roll back the snapshot anyway as you'd lose all the data written to disk between the point you snapshot and now(). In your situation, you should be able to get what you need by leaving it in its snapshotted state for now, power off the VM, and only copy the .vmx, .nvram and .vmdks over, not taking the snapshot files. Then turn it back on. Once you are certain that you have the old stuff you need, I'd seriously consider committing the snapshot to flatten it to one vmdk on ESXi. When you have it on Workstation you should just be able to add the .vmx into your local inventory, but if not - create a new VM exactly the same and instead of creating a disk for it, point it at the .vmdk from your ESXi. I believe that Workstation and ESXi in their latest versions have the same format vmdks. Hope this both helps and makes sense, almost time to put my bed to brain Rob. -
Installing Smoothwall Network Guardian s/w
rob_f replied to Zourous's topic in Internet Related/Filtering/Firewall
I believe the trick with the R200s is to set the CD onto port A and the HDD on B, although please check with smoothwall support if this doesn't work for you, or i'm too slow replying ;-) Rob. -
Rather than blocking on URL/IP address we put in some rules to catch any clone of ILoveIM. Not sure how effective it is as I don't know too many of the IPs to test, but Zoom7000 requested this so would be interested if he has some feedback.
-
Smoothwall - Network Guardian Temp Bypass Feature
rob_f replied to Macinator's topic in Internet Related/Filtering/Firewall
Yes, because the temporary bypass and add to whitelist features are effectively changing the filter policy, they require smoothwall admin users, as set in System > Administration > Passwords / Administrative Users. In here you can set specific roles for the users, so you can give them just the ability to unblock sites or temporary bypass. HTH, Rob. -
Smoothwall - School Guardian Eval
rob_f replied to Macinator's topic in Internet Related/Filtering/Firewall
btw, the settings- files that are 10 bytes should contain just: ENABLE=no you can check this by doing "cat settings-2" for example.
