Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Web Security: HTTP/HTTPS/FTP, IM/P2P, Web Filtering and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-09-2010, 09:05 PM
Member
 
Join Date: Feb 2010
Posts: 31
Default Active Directory - Bypass Web Filtering

I have a need to allow certain exceptions to the web content filtering. I am not seeing this intuitively (I can't access Active Directory with granularity - only "Active Directory Users").

Anyone?
Reply With Quote
  #2 (permalink)  
Old 02-10-2010, 08:24 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 6,999
Default

I think no one has responded because it's not clear what you're trying to accomplish. There is total granularity with content filtering, so maybe you could elaborate a little on who and what you want to block and allow?

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #3 (permalink)  
Old 02-10-2010, 10:20 PM
Member
 
Join Date: Feb 2010
Posts: 31
Default

I'm just trying to have two groups from Active Directory - one that is subject to filtered internet and another that is not. Right now, I have everyone up and running on the filtered set but don't see how to configure the unfiltered set.
Reply With Quote
  #4 (permalink)  
Old 02-11-2010, 05:59 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 6,999
Default

We recommend that one always have the default definition (the one behind 'Web Security >> HTTP/S') be the most-restrictive one.

For each access, the Astaro will process the defined 'HTTP/S Profiles' in sequence until it finds one for which the access qualifies, and will not consider any succeeding Profiles affter that one. If an access doesn't qualify for any Profile, it is handled by the default above.

Inside a Profile, Astaro will process the Filter Assignments until it finds one for which the access qualifies, and will not consider any succeeding Filter Assignments after that one. If it doesn't qualify for any Assignments, the 'Fallback Action' for that Profile will be applied.

Since you have AD, you will want to run the Proxy in AD-SSO mode and, if you haven't already done so, push out a GPO to force all browsers to point at the Astaro Proxy ('Internal (Address)') on port 8080. Once you've done this, create a group definition in the Astaro based on the "unfiltered internet" group in AD and use that in a Filter Assignement for wide-open access.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:41 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.