Jump to content

educontractor

Members
  • Posts

    23
  • Joined

  • Last visited

Reputation

5 Neutral

About educontractor

Personal Information

  • Occupation
    IT Contractor
  • Location
    Huddersfield
  1. All sorted thanks to the kindness of a fellow Edugeek. :-)
  2. Hello, Very late to this particular party, but we've inherited a school with lots and lots of these Dell Latitude 3190's supplied by the DfE. The link that I have been provided to access the BIOS passwords from Computacenter no longer works. I'm wondering if anybody would be so kind as to DM me the BIOS password or bypass technique so that I can reimage these? TIA.
  3. Hi guys, Just reporting back that we've solved it. The issue wasn't actually with Smoothwall - it was a combination of JAMF and Mac OS. So we knew that we were pushing proxy settings from JAMF, but I'd assumed (wrongly) that the fact we could enter proxy settings manually when logged in as an admin would override these. Put simply - it doesn't! This explained why (a) the authentication precursor was being passed to the proxy (JAMF didn't have the exceptions right) and (b) why changing the proxy settings to different proxies with different authentication types made no difference whatsoever! With the correct exceptions and using a proxy with Core Authentication the issue is entirely resolved. Thank you all for your valuable assistance!
  4. Just a thought, and I don't know if this is even possible, but if I were to assign the Macs IP addresses within a specific range, could the Smoothwall be configured to assume authentication to a particular group based on the source IP? Alternatively, is there any way of stopping the kerberos pre-pend being added even when no proxy is set?
  5. Seemingly not. The kerberos bit even gets added onto this, which the proxy then tries to resolve. It's as though the OS is sending it to the proxy whether I like it or not, i.e. ignoring the proxy exceptions and the "ignore simple hostnames" part.
  6. For completeness: Adding the simple hostname to HOSTS allowed it to PING without appending the DNS suffix, but the browsing behaviour is identical. Why doesn't it prepend all URL's with smoothwall:813/? Certain ones like the BBC and Microsoft part-load just without images (when I look at the live reporting for my IP I can see calls to the CDN's have the smoothwall:813 added to the front of them, hence why the images aren't loading)
  7. I did, yes. I checked it to be sure and it's definitely ticked for both options.
  8. It can, but possibly only because it's appending the DNS suffix. I'll try adding the simple hostname to the HOSTS file and see if that makes a difference. Apologies for all the ludicrous McCarthyite redactions on the screenshots as well. If it was my site / data I'd be happy to post unedited, but as I'm a contractor I'm being extra cautious.
  9. Thank you again for your ongoing assistance - I really appreciate it. My heart leapt when I read your post - it seemed such a logical solution but, alas, the issue remains (see screenshot). I have requested a ticket with Smoothwall, but I feel that it must be something simple that I'm missing. After all, hundreds of PC's and iPads are concurrently browsing the internet with any issue whatsoever.
  10. Again, thank you for this. I had thought that I had configured it this way, but perhaps I've made a mistake. I wonder if you'd be so kind as to cast your eye over the attached screenshots, and see if I'm missing anything obvious?
  11. Thank you, that's very helpful. I did try enabling a few different proxy ports with different auth methods including a redirect to a login page, but continued to get the above behaviour. Likewise the port/proxy configured for Core Authentication shows the same behaviour... Just to confirm - is the bypass you describe the one set on the clients?
  12. Hello, We have a strange problem. Replaced a bunch of older Mac minis running El Capitan with some M1 based ones running Big Sur. They have the intermediate SSL certificate installed, and trusted. They are using a Proxy configuration that allows Kerberos / NTLM authentication, but falls back to a sane group - Secondary Students for a device that doesn't authenticate. Since the PERL script that authenticates Macs isn't compatible with Big Sur, we assumed this would be fine. The browsing behaviour is strange, though. Some sites e.g. Google, BBC load but the images are blocked. Looking at realtime monitoring of the Web Filter for these sites shows that attempts are being made to download the images through their respective CDN but these requests aren't blocked. Weirder still is that other sites have their URL rewritten, naturally enough resulting in a 504 error as the proxy can't display them. e.g. https://www.yahoo.com is rewritten to http://smoothwall:813/?https://www.yahoo.com/ There isn't a content modification rule that is being applied so does anyone have an inkling as to what's happening here?
  13. Thank you. I originally started that before realising it was HTTPS inspection causing the issue. I had the category created and placed into the web filter as an exceptions list. I must have made a mistake - need to check my work. Thanks for all your help.
  14. Thank you both. The above instructions, in essence are what I have done. I wasn't sure if removing the *. from the Sophos instructions (as is required to save the category in Smoothwall) would in effect apply a wildcard for hosts and subdomains, or it it would instead refer only to the specific URL entered. My rule sits atop all the other inspection policies, so I must have made a mistake. I'll check my work. Thanks again!
  15. Hello all, We've been asked to assist with installing the new cloud (i.e. not Sophos Central) version of Sophos antivirus into a secondary school using a Smoothwall appliance for filtering and monitoring. The web-installer fails, and looking at the logs it fails because the root certificates are invalid when connecting to Sophos' servers to actually download the installer. Sure enough, when we bypass HTTPS inspection on the Smoothwall for the workstation we're testing, the installer downloads and the process completes as expected. However, we can't disable HTTPS inspection for the whole network, even if just for the duration of the install (for obvious reasons). So instead, we added the URL's on this list: https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/DomainsPorts.html To a category, and created a bypass for HTTPS content inspection based on this. This does not work. When we monitor web filter traffic from our IP (to make sure that the URL's match the ones we added to the bypass) we can see URL's that should match the rule for HTTPS inspection bypass. I was wondering if it's because I cannot add wildcard-type subdomains to the category on Smoothwall (unless there's a trick that evades me), despite the Sophos guide requiring them? If anyone has solved this issue, I'd be grateful for any pointers. I know that Smoothwall and Sophos are popular within schools, so hopeful somebody else has trodden this path and resolved the issue! Thank you!
×
×
  • Create New...