<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>AD authentication</title><link>https://community.sophos.com/web-appliance/f/discussions/104226/ad-authentication</link><description>Hi, quite new to Web Appliance. We use Firefox and have IP based authentication on at the moment. I believe AD auth is better but hear that only IE supports it, any ideas etc? Want to make sure I cover all angles before just turning AD auth on. 
 Many</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: AD authentication</title><link>https://community.sophos.com/thread/379644?ContentTypeID=1</link><pubDate>Wed, 25 Jul 2018 05:15:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9376ec97-7b75-458c-8ac0-88617fcef806</guid><dc:creator>zk1</dc:creator><description>&lt;p&gt;Thanks again, much appreciated.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: AD authentication</title><link>https://community.sophos.com/thread/379578?ContentTypeID=1</link><pubDate>Tue, 24 Jul 2018 10:37:37 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c6324c6f-d686-4e29-b08e-6455b8aca639</guid><dc:creator>Red_Warrior</dc:creator><description>&lt;p&gt;Most welcome,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If you are referring to pushing out proxy setting via gpo for ff.. Maybe something like this would help&amp;nbsp;&lt;a href="https://helpdesk.webtitan.com/support/solutions/articles/4000083786-configuring-firefox-proxy-settings-via-gpo"&gt;https://helpdesk.webtitan.com/support/solutions/articles/4000083786-configuring-firefox-proxy-settings-via-gpo&lt;/a&gt;&amp;nbsp;but this involves building your own msi and deploying the pre-configured binary&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Generally I would recommend pushing out via dhcp / .pac file for more configuration options&amp;nbsp; (ie exclusions lists, dns/hostname look ups you can detect if the client is onsite vs offsite .. .etc)&amp;nbsp; Its a little more difficult.. Unfortunately support can help much in creating a .pac file.. (if you need one done for you just talk to your account manager for professional services)&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;However I do have another lovely KB that should help.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;NOTE:&lt;/p&gt;
&lt;p&gt;(if your in transparent or bridge mode) theres no need for browser settings, just configure the lan router/wccp device to direct 80/443 from network x .. to appliance and then omit the appliance so that it can get out the gateway to the internet.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;ELSE:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://findproxyforurl.com/pac-functions/"&gt;http://findproxyforurl.com/pac-functions&lt;/a&gt;&amp;nbsp; &amp;nbsp;(see the examples here to they are very good)&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/38784"&gt;https://community.sophos.com/kb/en-us/38784&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/38787"&gt;https://community.sophos.com/kb/en-us/38787&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/38783"&gt;https://community.sophos.com/kb/en-us/38783&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/38788"&gt;https://community.sophos.com/kb/en-us/38788&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/38784"&gt;https://community.sophos.com/kb/en-us/38784&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: AD authentication</title><link>https://community.sophos.com/thread/379491?ContentTypeID=1</link><pubDate>Mon, 23 Jul 2018 14:54:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e6b76eb0-731d-40e5-be99-4af1ce2ea575</guid><dc:creator>zk1</dc:creator><description>&lt;p&gt;Thanks Red Warrior!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Re the Firefox config, do you know if it can be done centrally / via policy or similar (so as not to manually configure hundreds of desktops)?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: AD authentication</title><link>https://community.sophos.com/thread/379477?ContentTypeID=1</link><pubDate>Mon, 23 Jul 2018 12:21:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:733cf832-19ca-4a3f-96a1-dfb4d91c30a3</guid><dc:creator>Red_Warrior</dc:creator><description>&lt;p&gt;Hi Zk1&lt;/p&gt;
&lt;p&gt;The SWA officially supports FF, chrome, IE and Safari via SSO... there are some requirements and best practices..&amp;nbsp; &amp;nbsp;Please see my KB here for everything you need to know&amp;nbsp;&lt;a href="/kb/en-us/126599"&gt;https://community.sophos.com/kb/en-us/126599&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;for thinks like public wifi I generally recommend deploying a separate appliance generally without an authentication policy .. then lock it down via a generic default policy.&amp;nbsp; &amp;nbsp;this will ensure your not mixing public and private traffic.&amp;nbsp; the VM is included so theres no additional costs.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>