This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Strange issue with Sophos UTM Web Protection

Hi,

Firstly, I have got to admit, getting here was quite a challenge. It would appear that the Astaro forums have gone now, and this is it's replacement. I can't say that my experience from this new replacement has been good, the overall feel to this isn't very user friendly, just my opinion. Good were the days where you could easily log-on to a forum and start a new thread, where as now, with this replacement, you have to work out how to actually log-on and then join a group before you can create a question... what?!!

Going off topic here, I'll get to the reason why I am here today. For a while now, I have had an intermittent issue with Web Protection and Active Directory SSO authentication, where all web access is blocked. This occurrence only occurs after either a restart of the Sophos UTM or by a restart of ALL domain controllers. This issue only affects devices which use a profile with Active Directory SSO authentication set as the default. I have discovered that when this issue occurs, if I simply visit the eBay website, all web access is restored. If I do not visit the eBay website, all web access is denied by Sophos Web Protection. Web access appears to be fine when using Agent/Browser authentication, this issue does not affect devices which use a profile with Agent/Browser authentication set as the default.

I really don't know what is going on here, the issue has been on-going for some time now and it is getting quite annoying now. Has anybody else experienced this strange anomaly? 

Regards,
Richard



This thread was automatically locked due to age.
Parents
  • I think SWeissflog has it right. Don't let IE 'Automatically detect settings.' My guess is that IE goes into Proxy mode when it requests certain sites and that the authentication is then handled in Standard mode just as it is when clients use your PAC file.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Since "automatically detect" is the default for I.E (and other browsers also use IE's settings) the easiest would be create option 252 in your DHCP scope with the url to the wpad or pac file. No client changes needed. Then the "automatically detect settings" becomes exactly what you want. Regardless of what network they're on, road warrior won't get the DHCP option and his automatically detect will allow his browser to surf the internet at home without a proxy. Users in the office will get the DHCP option and be forced through the proxy. You can then use group policy to prevent users from making browser proxy changes, thus leaving it always "automatically detect"

    All of this works perfect for me since my UTM implementation.

Reply
  • Since "automatically detect" is the default for I.E (and other browsers also use IE's settings) the easiest would be create option 252 in your DHCP scope with the url to the wpad or pac file. No client changes needed. Then the "automatically detect settings" becomes exactly what you want. Regardless of what network they're on, road warrior won't get the DHCP option and his automatically detect will allow his browser to surf the internet at home without a proxy. Users in the office will get the DHCP option and be forced through the proxy. You can then use group policy to prevent users from making browser proxy changes, thus leaving it always "automatically detect"

    All of this works perfect for me since my UTM implementation.

Children
  • Agreed, rsenio - I'm also a fan of Standard mode in the office.  Some folks just want to use Transparent though.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA