Solved

Sonicwall NSA 2400 Content Filtering for Groups issue

Posted on 2010-11-22
7
1,417 Views
Last Modified: 2012-05-10
Dear Experts,

We deployed Sonicwall NSA 2400 appliance in order to take advantage of Content Filtering per groups.
I`ve noticed that in order for CFS to work properly when SSO Agent checks which user is logged in to machine (Windows Firewall needs to be disabled). I applied a GPO to disable Windows Firewall. Sometimes GPO doesn't apply properly, so I have batch files that users can run in case GPO doesn't apply.
I have 3 groups for Content Filtering:
Full Access (most of categories allowed)
Regular Access
Limited Access

While Full Access is the group with the most rights, I still do not want this group to stream music or access youtube. Therefore I created the 4th Group- "Full Access w Streaming"
Default policy is the most restrictive so if SSo Agent can't verify the user name vs Group, then no websites are accessible.
The problem recently is that from time to time SSO agent can't determine the user logged in to the machine and therefore applies Default policy. I have SSo Agent running on two separate boxes....
I checked that Windows Firewall is disabled, also looked at Symantec logs (nothing found in SEP logs), verified that even IPv6 is disabled.
When I log in to the Sonicwall appliance and look at User Status, I see that form time to time Users are applied with "Default" policy and that other policies (which should be aplied to them, "Full Access" well, they somehow do not apply).
So far the work around that I found is to disconnect the User`s session directly from Sonicwall -> Users then have user log off and log back in. I'm not sure why this is happening, what else should I be looking for ?
Anyway to refresh the SSO Agent session without me having to login to the appliance and disconnect the user (sometimes logging the user off or restarting PC doesn't help, until I manually disconnect the user from Sonicwall). i understand that restarting the PC should take care of it, but somehow Sonicwall hangs on to it and even after restart the "Default" policy is still applied.
I spoke with Sonicwall as SSo Agent kept throughing in errors that relate to Windows Firewall being enabled, but that was the only solution that Sonicwall provided.... I know that Windows Firewall is disabled and Sonicwall are unable to offer anotehr solution or a workaround...

Any ideas are greatly appreciated...
0
Comment
Question by:technomic
  • 3
  • 3
7 Comments
 
LVL 33

Expert Comment

by:digitap
Comment Utility
i'm sure you've updated to the latest release of the sonicwall firmeware...what version are you at?
0
 
LVL 2

Author Comment

by:technomic
Comment Utility
NSA 2400 has firmware ver. 5.5.2.1-5o
Directory Connector ver. 3.2.2

SOnicwall has a newer firmware update ver 5.6 it is an early release though. So, i guess if I don't find a better way to fix it, i will consider installing an early release firmware.
0
 
LVL 33

Accepted Solution

by:
digitap earned 500 total points
Comment Utility
something i discovered this week that didn't know is "early release" does not mean beata release.  the early release means there is functionality within the firmware that hasn't been enabled, but they have relased fixes as part of the firmware as well.  everything has been tested.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 2

Author Comment

by:technomic
Comment Utility
in that case, I will give that a shot and see what happens. It maybe a couple of days before I can update the firmware....
0
 
LVL 2

Author Closing Comment

by:technomic
Comment Utility
Unfortunately I'm yet to find an opening to do a firmware update, therefore I am closing the question for now and awarding the points...
0
 
LVL 33

Expert Comment

by:digitap
Comment Utility
i appreciate that.  when you do the update, report back and let us know how it went.
0
 

Expert Comment

by:PaidToSki
Comment Utility
I would like to add a comment to this.  I have extensively tested and successfully deployed the SSO capability in my environment.  I have an NSA 4500 running SonicOS Enhanced 5.6.0.11-61o.  I am using the SonicWall Directory Connector version 3.4.55.

For my Query Source, I use DC Security Logs & NETAPI.  In order to use DC logs, all you need to do is enable logging via your DC GPO for logon/logoff success/failure.

I made the mistake of using the "Probing" feature in the SSO setup on the SonicWall.  Don't use it, it will basically do more harm than good.

I don't disable the firewall on local workstations, but rather push a GPO that opens the UDP and TCP port numbers that the SSO agent communicates over (it's all in the documentation from SonciWall) and any other services you need to open.

I also have deployed (2) SSO Directory Connect servers for redundancy.  I have found in my environment with 190 Windows XP/7 workstation, DC Audit logs & NETAPI are the most accurate and reliable forms of LDAP authentication.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now