Jump to content

RobMason

Members
  • Posts

    41
  • Joined

Everything posted by RobMason

  1. If you drop me a PM with your case number I can make sure it is being looked at for you, Thanks, Rob
  2. Drop me a PM with your contact details and I will give you some information, Thanks, Rob
  3. Good Morning, We are aware of an isolated issue with customers on Lightspeed filter 5 and are working to resolve it ASAP. Thanks, Rob
  4. Afternoon all, Just to confirm, this has been raised with Google (to the best of our ability) as our proxy IPs should be on their whitelists. It looks like something at their end has changed. I will update you all when I have any news and in the meantime can only apologise for the inconvenience Thanks
  5. I have not seen this before and will get one of our NOC guys to have a look as well as raising it with Netsweeper just in case, is it still happening this morning? Can you drop me a PM with some contact details so someone can get in touch, Thanks,
  6. Morning All, All websites will first hit the default group and then be redirected to the correct group, URLs such as bbc.co.uk should not be unblocked in the default group as users will be able to access them without being authenticated. Only CDNs, website resources etc should be unblocked in default. If you are struggling just drop me a PM and I will ask someone to give you a call.
  7. Assuming your WSUS is hosted on a server I would say not to bother proxying it, if this is the case then it should just be whitelisted on the FortiGate. Internal connections should also not be proxied. Thanks,
  8. Morning All, Just to confirm, we can choose to not decrypt SSL for custom proxy ports if that is what you prefer. As people have mentioned it is better suited for visitor networks where you are not as bothered about keyword control and don't want to ask users to install a certificate. Thanks, Rob
  9. Good Morning, It sounds like something isn't 100% correct as even with none of the configuration tick boxes selected the whoami.asp page should report the correct user logged into the machine. This of course assumes you are testing from a client machine rather than the server itself. Microsoft implement security so the server cannot test against itself. If you are testing from a client my guess would be you have anonymous authentication enabled within IIS. You can check this by going to the website you are using (probably authportal) and then selecting the authportal application opening Authentication within the feature view. It should look like this (click to expand); I will follow this up with a PM, Thanks,
  10. Morning All, Firstly apologies to anyone waiting for a PM reply, spent the last 2 weeks upgrading LS filters and haven't had chance to get on here. Expect a reply today. RE Chromebooks, the best solution currently (assuming you use Google auth) is to install the Netsweeper Chrome plugin, this will fully report the user logged in to the Chromebook to the Netsweeper Webadmin. The next problem is making sure those users exist on the Webadmin. At the moment we have to upload those users via CSV file so will need you to export from GSUITE (or similar) and provide us with a list. Google auth integration is one of the items on the roadmap Dave mentioned earlier and we are working with Netsweeper to achieve this as fast as possible. As all your main LAN traffic uses specific proxy ports (generally 31280,) as an additional security measure we block 80/443 using the Fortigate. The Chrome plugin means that traffic actually uses 80/443 meaning our advice is to have the Chromebooks on one range so we can whitelist them on the Fortigate. This doesn't have to be the case, but in the event a pupil machine ends up without proxy settings we would rather they can't get to the internet unfiltered. For those that don't use Google auth and also don't want unauthenticated filtering so long as the Chromebooks can communicate with the IIS server you can use NTLM to authenticate with your AD, in this case we would just use the standard proxy port instead of the plugin. Just a final note on BYOD, the above also applies. If unauthenticated filtering is not sufficient you can just use NTLM to authenticate via AD. Hope that helps, Rob
  11. Correct, the restore process caused some DB corruption, we have added another step in the process where Lightspeed will check our restore file before we apply it to the new box. Thanks,
  12. Evening All, @mavhc To answer your questions, 1) NTLM is the mechanism used to allow transparent authentication, this assumes you are using an NTLM supported browser. Any unsupported browser should result in a generic authentication pop up. If for any reason this is not working for you drop me a PM with more details and I can get one of the guys to take a look. The client will still need the proxy specifying one way or another. 2)A transparent proxy is currently not possible due to them not scaling large enough to cope with the ever increasing speeds without removing load balanced HA. 3)Explicit proxies will not be affected by TLS 1.3, only transparent solutions will struggle to decrypt SSL and may need modification. That being said with any major change we (and our suppliers) test our products to reduce any impact on you guys. Hope that helps, Thanks,
  13. @Blue_Cookeh No, it looks like the correct permission template has not been applied. Please can you PM me the account you use to login to Netsweeper and I will sort it now.
  14. Hi, MDM and Google Apps will be fine as we ensure communication is allowed via both Netsweeper and the firewall. We can always relax the firewall whilst your setup is completed and then once you are happy start to put restrictions back in place. Have you had your pre-migration appointment where you have chance to raise any queries? If you PM me your school details I will find out what I can, Thanks,
  15. Good Morning, No worries, it can be a little confusing but glad you have got it sorted. It is correct that you cannot add a FortiClient profile as that only applies to the full license version rather than the free version downloaded from the internet. We are currently running through a development cycle in order to bring the full version of FortiClient to our customers. If you are interested send me a PM and we can have a chat. Thanks, Rob
×
×
  • Create New...