Jump to content

Recommended Posts

Posted

We have recently switched to IDEX for our auth method in a bid to try and find out why our filtering on our smoothwall falls over every 45 to 60 mins, between the hours of 9am and 3pm every day. The only way to get round this is to restart the entire smoothwall.

 

In Authentication we are seeing a lot of "No group information found for username: NT AUTHORITY\ANONYMOUS LOGON"

 

Is there a way to stop this from happening?

Posted
We have recently switched to IDEX for our auth method in a bid to try and find out why our filtering on our smoothwall falls over every 45 to 60 mins, between the hours of 9am and 3pm every day. The only way to get round this is to restart the entire smoothwall.

 

In Authentication we are seeing a lot of "No group information found for username: NT AUTHORITY\ANONYMOUS LOGON"

 

Is there a way to stop this from happening?

 

idex client or idex agent?

Posted
Are your smoothwall groups mapped. Had something similar a couple of days agos and the smoothwall AD directory mappings had disappeared
Yep directory groups are mapped. Part of me thinks it's the computer accounts.
Posted
Have you did the required changes to the group policy for all your dc's and installed it on all dcs?

 

https://kb.smoothwall.com/hc/en-us/articles/360007256160-Smoothwall-Filter-Firewall-Installing-IDex-Agent-on-Your-Domain-Controller

 

I've not done the Group Policy changes, instead, ive been on and manually installed the agent and checked the reg. Smoothwall even added into the registry LogonExclusion = ANONYMOUS LOGON.

Posted
I've not done the Group Policy changes, instead, ive been on and manually installed the agent and checked the reg. Smoothwall even added into the registry LogonExclusion = ANONYMOUS LOGON.

 

the group policy stuff is required so the smoothwall agent can detect logins from the logs. thats probably why youre getting unknown users

 

it doesnt pull a database it populates as people login from what i understand

Posted (edited)

Update on this.. Smoothwall is still giving anonymous logon messages though it is different machines everytime the entire network of PCs are restarted.

 

I've been through the DCs and changed the Registry value of RestrictAnonymous to 1 which is found at HKLM\System\CurrrentControlSet\Control\LSA and checked the event logs of the DCs.

 

The group mappings are correct as i've checked those in Smoothwall as this particular user is being assigned STAFF access.

 

Could it be that the Anon accounts mean that the Windows Logon for that user could be borked? I mean why is only happening on some machines but the rest are fine? If the PC is restarted, the error goes away. Could it be that the DCs are either too slow to identify the user account when the user logs on or could it be that the smoothwall is unable to process those particular user accounts so even though the correct user is logged on the PC, smoothwall is struggling with the log on process sees the account as Anonymous?

Edited by timbo343
Posted

So, it would appear that the NT Auth\Anon user is random.

 

I logged on to a computer with a test account (test1) and the web filter real time logs showed the user and the correct group mapping.

 

Suddenly this machine then started showing NT auth\anon user in the web filter logs and gave Default Users access to the net. I did nothing on the PC, other than continue to browse, it's like Smoothwall has either timed out or smoothwall is unable to map the directories together.

 

Then after a while, the web filter showed test1 with the correct group mappings, the NT Auth\Anon user which was shown disappeared - the same thing happened on other random machines.

 

Im not sure if this is due to an update or if there is an issue with the box.

Posted
You have got your auth type on your proxy changed to "core auth" in web proxy -> authentication. If you haven't got the correct auth type in the proxy the existence of the agents on the DCs is irrelevant. Also doesn't have to just be DCs you can put the agent on file servers too. We had to do this due to dreaded laptops being hibernated with a login event off site. This way if the users pull a file their auth record gets refreshed too.
Posted
You have got your auth type on your proxy changed to "core auth" in web proxy -> authentication. If you haven't got the correct auth type in the proxy the existence of the agents on the DCs is irrelevant. Also doesn't have to just be DCs you can put the agent on file servers too. We had to do this due to dreaded laptops being hibernated with a login event off site. This way if the users pull a file their auth record gets refreshed too.
Our Auth is definitely set to Core Auth [emoji1303]

 

Ah! Looks like the idex might have it sit on all our servers that host file shares.. great!

 

Will give this a go and see if it stops the NT Auth\Anon error.

Posted
Installing the IdexAgent on our File Servers has made no difference. On a room of 30 machines we are getting 2 random machines fail with Anonymous logons. Logging the users off and back on works however some machines that have logged on the user without any issues, suddenly start getting Anonymous Logon errors.
Posted

When using the newest iDex agent 2 from https://software.smoothwall.com/ - once installed, you can add an exclusion parameter to the registry for the idea agent to exclude certain usernames. Open regedit and find the iDex agent parameter folder in Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IdexAgent. Add a new string value called 'LogonExclusions'.

 

Add usernames into the string in a comma seperated list: NT AUTHORITY\ANONYMOUS LOGON,DOMAIN\Service_account

 

And restart the iDex agent service. This will need to be done on all agent installs.

Posted
When using the newest iDex agent 2 from https://software.smoothwall.com/ - once installed, you can add an exclusion parameter to the registry for the idea agent to exclude certain usernames. Open regedit and find the iDex agent parameter folder in Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IdexAgent. Add a new string value called 'LogonExclusions'.

 

Add usernames into the string in a comma seperated list: NT AUTHORITY\ANONYMOUS LOGON,DOMAIN\Service_account

 

And restart the iDex agent service. This will need to be done on all agent installs.

 

Thanks @ibpalle, I shall try it.

 

One of your support engineers told me to add the reg edit last week however only told me to put in ANONYMOUS LOGON.

 

What i dont understand is the attached images:

 

Capture_anon time out2.PNG

 

Capture_anon time out.PNG

 

Why would we suddenly get an authenticated user and then it would switch to ANONYMOUS LOGON and then switch back?

Posted
When using the newest iDex agent 2 from https://software.smoothwall.com/ - once installed, you can add an exclusion parameter to the registry for the idea agent to exclude certain usernames. Open regedit and find the iDex agent parameter folder in Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IdexAgent. Add a new string value called 'LogonExclusions'.

 

Add usernames into the string in a comma seperated list: NT AUTHORITY\ANONYMOUS LOGON,DOMAIN\Service_account

 

And restart the iDex agent service. This will need to be done on all agent installs.

 

This hasn't worked and still getting the errors - this only shows when we use CoreAuth. Using Negotiate Kerberos / NTLM doesn't give these issues.

 

The Smoothwall Support engineer has told me to contact MS Support and i'm more inclined to post something on TechNet but honestly I don't know what on earth I'm asking for help with because to me this issue is with the Smoothwall and not my domain or DCs.

Posted

I'm sure this has already been covered, but for sanity sake I'll ask if a few of the basics have been checked:

 

The idex agent has been installed on all your DCs.

 

A smoothwall access rule has been setup to allow the idex port (TCP 2948) from the DCs.

 

Windows firewall isn't blocking said port from DCs to smoothwall.

 

All the DCs policy is set to audit successful account login events and successful login events.

 

When installing the idex agent on your DCs, did you specify the host by name or IP?

Is replication all good between DCs if you have a DNS record locally for the smoothwall and it can be resolved from each DC?

 

You've mentioned the file server, are there any service accounts running on it, and if so could you add a $ to end end of the account name so idex ignores it (or could this be causing it?).

 

Have you installed the idex client (not agent) on any machines where multiple users login simultaneously such as RD session hosts?

 

When you manually sync idex from the DCs using syncaddatanow (or whatever the exe is in program files) do they each report back successfully sent data?

 

Have you enabled verbose logging?

https://kb.smoothwall.com/hc/en-us/articles/360002135744-Turning-on-the-Diagnostics-for-the-IDex-Agent

And if so, does it give you any clues?

 

I'm guessing the idex directory in services is reporting back the correct numbers of users and groups?

  • Thanks 2
Posted (edited)

The idex agent has been installed on all your DCs.

- Check [emoji818]

 

A smoothwall access rule has been setup to allow the idex port (TCP 2948) from the DCs.

- Check [emoji818], smothwall checked this

 

Windows firewall isn't blocking said port from DCs to smoothwall.

- Windows firewall disabled for testing [emoji818]

 

All the DCs policy is set to audit successful account login events and successful login events.

- check [emoji818]

 

When installing the idex agent on your DCs, did you specify the host by name or IP?

- Yep, also checked in the registry [emoji818]

 

Is replication all good between DCs if you have a DNS record locally for the smoothwall and it can be resolved from each DC?

- Yep, checked [emoji818]

 

You've mentioned the file server, are there any service accounts running on it, and if so could you add a $ to end end of the account name so idex ignores it (or could this be causing it?).

 

 

Have you installed the idex client (not agent) on any machines where multiple users login simultaneously such as RD session hosts?

- we dont allow users to have multiple logins simultaneously like fast user switching [emoji818]

 

When you manually sync idex from the DCs using syncaddatanow (or whatever the exe is in program files) do they each report back successfully sent data?

- i dont know about this command [emoji848]. Sending data to the smoothwall complete (around 1188 users to the cache)

 

Have you enabled verbose logging?

 

https://kb.smoothwall.com/hc/e...Diagnostics-for-the-IDex-Agent

- will enable this tomorrow!

 

And if so, does it give you any clues?

- thank you!

 

I'm guessing the idex directory in services is reporting back the correct numbers of users and groups

- not seen this before in Smoothwall [emoji848] - ah, under the diagnostics for the idex... [emoji848]

Edited by timbo343
Posted

With the last bit under services > directories > idex if you hit diagnose I'm guessing the number of groups/users looks correct?

 

Also all the user groups are mapped to local ones in the directory?

Posted
With the last bit under services > directories > idex if you hit diagnose I'm guessing the number of groups/users looks correct?

 

Also all the user groups are mapped to local ones in the directory?

382 AD groups

3281 ad users reported on the Smoothwall.

1 group map and 1 group - which seems a bit wrong

 

I was told by smoothwall that the Idex Directory wasnt needed and that it would look at the AD directory instead.

Posted (edited)
Okay, so ive run RoSP against my DCs and for a big fat red X next to the 2 audit policies on 2 of the DCs.

 

[ATTACH]66442[/ATTACH]

Disabling the policies, waiting for the DCs to sync from AD, confirm changes via RoSP.. then turn the policies back on fixed the red X issue in RoSP.

 

Also found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa

> scenoapplylegacyauditpolicy was set to 1 on 2 of the DCs. I set this back to 0 as this entry wasn't listed on the other DCs.

Edited by timbo343
Posted
Thanks @ibpalle

 

Why would we suddenly get an authenticated user and then it would switch to ANONYMOUS LOGON and then switch back?

 

If there is a service running on the client system that triggers a domain account login for the Anonymous account from that IP and then later, the user accesses a file share or in some other way triggers a domain account login, then the user switches back. Also take note that any authentication exceptions from the proxy - authentication - exception section will still cause access to those destinations to be logged without username. In general, if no active proxy login methods are in use auth exceptions can be removed.

Posted
We are no longer getting the NT AUTH\Anonymous Logon messages on the Smoothwall. The registry entry LogonExclusions = NT AUTHORY\ANONYMOUS LOGON and fixing the group policy has helped.
  • Thanks 1
Posted
Just to confirm that we've been having the same issues as timbo343 since the return to school in September - no idea why, no config changes etc. After the same support from Smoothwall, the LogonExclusions = nt authority\anonymous logon has sorted the issue. I will continue testing over the coming days to see if we have any further issues with misidentification.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...