This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Filtering - Device OS not recognized / device-specific authentication not working

Hello community,

i have a problem with my apple ios devices.

 

As standard we use basic authentication fed by ms active directory groups.

So users usually have to type username and password of their ad-accounts.

 

Now we would like to let our apple ios devices online without authentication because the network where they come from is already secure and the devices have certificates and so on.

 

I wanted to use device-specific authentication and added ios devices with no authentication to the global web filtering lower right part.

Nothing happens and the devices still get their pop-ups.

 

As i understand this function the UTM should be aware what kind of devices tries to establish the connection.

So the device under it´s ip should be seen in the logs as device="4" for iOS-Device.

 

While checking the logs i saw, that all devices are regarded to as device="0" (unknown).

 

Am i missing a function anywhere? Why isn´t the UTM not device aware?

 

Maybe you can help...

 

ThanX

 

Marc

 

PS:

 

SG550

9.510-5

 

 

 

     


This thread was automatically locked due to age.
Parents Reply Children
  • Device detection uses a combination of TCP packet signatures and other factors. User-agent is used as a secondary factor where TCP signatures do not provide enough information.

    TCP packet signatures have the advantage of being able to determine very quickly on every connection and work even on encrypted (SSL/TLS/HTTPS) traffic. But User-agent is only visible for HTTP traffic, not HTTPS. Where we are relying on secondary factors that cannot be evaluated on every flow, we rely more heavily on storing/caching device information on a per-IP basis, which can sometimes lead to incorrect assessments persisting.

    A major area where TCP signatures are not distinct enough is with recent versions of Apple's operating systems. User-agent is critical right now for distinguishing between iOS and MacOS.

  • Thx, RichBaldry for the for the detailed explanation.
    So i activate for Macos and Ios to the same device-specific authentication ;-)

    Br McWolle

    Sophos Certified Engineer (SCE)
    Sophos Certified Architect (SCA)