Device: Sophos UTM9 running firmware 9.510-5
Issue: When I switch on the Web Filter and configure the Base Policy everything works as it should. I can access the sites I need and block the sites I don’t need. However, when I create a new policy that I wish to apply to a user / group, I cannot get it to work no matter what I try.
We have approx. 100 users / computers in the business and the end result would be that I would like to limit / block internet access either by specific user or by group.
For this example I am using an active directory network profile called “Training”. The internal network IP address on the computer the user is logged onto is 10.253.1.194
Here are a number of screenshots from the UTM of the Web Protection setup:
I have created a “Block All” policy as a test and I have added the “training” user to apply the policy to. The “training” user was added to the policy from Definitions & Users → Users & Groups
When I go to youtube.com on the computer, this is the entry that appears on the Live Log:
2018:10:26-17:53:32 cc-utm02-2 httpproxy[5664]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.253.1.194" dstip="216.58.209.110" user="" group="" ad_domain="" statuscode="301" cached="0" profile="REF_HttProContaInterNetwo (Carroll Cuisine Web Filter Policy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0x1894d200" url="http://youtube.com/" referer="" error="" authtime="0" dnstime="185" cattime="29841" avscantime="0" fullreqtime="73617" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko" exceptions="" category="147" reputation="trusted" categoryname="Streaming Media"
I saw on another post that I may have to install a certificate so I installed the HTTPS CA Certificate on the computer and restarted it. This certificate was downloaded from Web Protection → Filtering Options → HTTPS CAs → Download
For some reason after installing the cert, youtube is not appearing on the live log? So I went to a different site(bbc.co.uk) and this is how the entry appears:
2018:10:26-18:50:42 cc-utm02-2 httpproxy[5664]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.253.1.194" dstip="35.156.134.252" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_HttProContaInterNetwo (Carroll Cuisine Web Filter Policy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="1277" request="0x181fd200" url="www.bbc.co.uk/.../config referer="http://www.bbc.com/" error="" authtime="0" dnstime="234" cattime="29075" avscantime="0" fullreqtime="115000" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko" exceptions="" category="134" reputation="neutral" categoryname="General News" content-type="application/javascript" application="bbc" app-id="1213"
Am I correct that the entry in the log showing user="" group="" ad_domain="" means the UTM is not registering the logged in user account from the computer that is accessing the internet and if now, can anyone offer advise as to why or how to fix this?
When I use the Policy Test tool on the UTM, this is the result showing that the website passes through the base policy rather than the Policy to block access:
I have looked at a number of other posts with similar issues and I am unsure what I am doing wrong or if there is some link between the UTM and our Active Directory not working correctly.
Any help or suggestions would be greatly appreciated. Or if I can provide any further details / information please let me know.
Thanks in advance,
Niall
This thread was automatically locked due to age.