This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issues using authentication based web filtering!

Hello all!

I am a security engineer and I(ve worked with cyberoam UTMs before, but it seems that I lost it some where ! I am trying to setup a filtering policy based on authenticated users.

So I added a user, I downloaded the client autehtication program, then I added the policy. The policy simply does not work if I don't put it on any, and it seems working if I test it with the policy helpdesk...I am lost please help!

Thx in advance.



This thread was automatically locked due to age.
  • Just to confirm, it is the Sophos authentication agent you are using on the machine?
    Is this machine still inside the LAN?
    Can this user access the userportal? If so download a fresh copy of the SAA and install it.
    Can you also provide screen shots of the config you have setup for web filtering?
  • Hello,

    Sorry to respond late.

    YES I use the Sophos authentication agent that we can download under client authentication program.

    YES the machine is always inside the LAN

    For the user portal I don't know since am not using it

    For the config:

  • Thanks for the update. Just to clarify are you saying that this rule will only work when you remove LAN and put ANY in the allowed networks?
  • Hello Emily,

    Thank you for your time and effort I really appreciate it!

    The thing is when I add a Policy it will not work unless the Users/Group is Any (Tag 3 in the following picture)

    If I put a name that policy will not work even if in policy help desk it tells me that is working!

    Case Scenario:

    Let's say I wanna allow a website for a particular user:

    1-I create the policy

    2-I specify the user for which I want the policy to be enforced

    3-I add the website to the "allowed website" list

    4-I activate the policy

    When I check in the policy helpdesk It says that that particular website is allowed for that particular user

    PS: Sophos recognize the user since in the network usage the user is represented with it's given username using Sophos Authentication Agent

    Best regards.