Web Host Chat
Bringing Hosts & Customers together since 2001
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Advertising
User Information
»REGISTER NOW!

Go Back   Web Host Chat > Hardware, Software, Internet and Film > Software > Linux / Unix
Reply
 
LinkBack Thread Tools
Old 23rd June 2008   #1 (permalink)
Join Date: Apr 2005
Posts: 1,297
Jon-NC is on a distinguished road
Squid Question

Hello,

We have a slight problem with a customer’s Websense web filtering software. The reporting feature on Websense cannot individually distinguish users on a Terminal Services server.

We have been advised by Websense to put a squid proxy (or ISA proxy *spits*) in between the Terminal Servers and forward all communications onto the Websense server.

Would this be easy enough for a Linux novice? I have already setup squid in which is working as a proxy fine. I imagine that I may need to add some form of NAT or IPTABLES stuff to forward on all proxy traffic to the Websense server?

Any tips in what to search for would be cool; I'm a little out of my depth on this Linux stuff. :P

Cheers,

Jon
__________________
Jon Rohan

Please note: My views are my own and not those of the company I work for.
__________________
Web Host - VIP Member
Jon-NC is offline   Reply With Quote
Old 23rd June 2008   #2 (permalink)
I am Staff at
Wise Hosting
About My Company!

Certified Host
wise's Avatar
Join Date: Nov 2005
Location: Scotland
Posts: 387
wise is on a distinguished road
websense has a citrix agent you can install on each server that will distinguish the users - Im sure you can put this on your terminal servers.

What version of websense are you using?
__________________
Web Host - Certified Member
wise is offline   Reply With Quote
Old 23rd June 2008   #3 (permalink)
Join Date: Apr 2005
Posts: 1,297
Jon-NC is on a distinguished road
For some reason (I dont know the exact reason) the Citrix agent won't work. It could be due to the version of Citrix our customer is running.
__________________
Jon Rohan

Please note: My views are my own and not those of the company I work for.
__________________
Web Host - VIP Member
Jon-NC is offline   Reply With Quote
Old 24th June 2008   #4 (permalink)
I am Staff at
Websense
About My Company!

Certified Host
Join Date: Aug 2005
Posts: 368
Schumie is on a distinguished road
Without my Websense hat on (as I deal with the Software as a Service, as opposed to on-premise) but as I understand it, if you drop in a squid proxy (pretty easy to do) and if it can drop in as the gateway for these boxes, a few iptables rules to redirect port 80 traffic, or alternatively set the group policy for proxying through the squid box, it should be relatively simple.

I'm not sure how it differentiates on the users though
__________________
Web Host - Certified Member
Schumie is offline   Reply With Quote
Old 24th June 2008   #5 (permalink)
Join Date: Apr 2005
Posts: 1,297
Jon-NC is on a distinguished road
The reason we can't use the citirx agent is because citrix isn't used. :O

I'm not sure how squid will differentiate the users either.
__________________
Jon Rohan

Please note: My views are my own and not those of the company I work for.
__________________
Web Host - VIP Member
Jon-NC is offline   Reply With Quote
Old 24th June 2008   #6 (permalink)
I am Staff at
Websense
About My Company!

Certified Host
Join Date: Aug 2005
Posts: 368
Schumie is on a distinguished road
Hmmm.. I've asked the question internally as I'm quite interested knowing how it does the user seperation now
__________________
Web Host - Certified Member
Schumie is offline   Reply With Quote
Old 24th June 2008   #7 (permalink)
I am Staff at
Wise Hosting
About My Company!

Certified Host
wise's Avatar
Join Date: Nov 2005
Location: Scotland
Posts: 387
wise is on a distinguished road
As far as Im aware it wont differentiate the users - its been a couple of years since dealing with websense enterprises etc, so they may have added something. The remote agent they developed for citrix was specifically for the reason you are needing it and I had thought they could also be put on TS too ... are you using ISA server under websense ?
__________________
Web Host - Certified Member
wise is offline   Reply With Quote
Old 24th June 2008   #8 (permalink)
I am Staff at
Websense
About My Company!

Certified Host
Join Date: Aug 2005
Posts: 368
Schumie is on a distinguished road
I've just spoken with one of the chaps, so it does need a proxy server in place, and the browser passes user credentials, that's how it's able to differentiate

You can also enable manual authentication as well, so that if the user credentials aren't passed the users will be forced to authenticate before browsing.

Integration with Squid seems pretty straight forward, and if you need any help the support chaps are always here to give guidance
__________________
Steve Wright
Websense Hosted Security
For EMail and Web content
__________________
Web Host - Certified Member
Schumie is offline   Reply With Quote
Old 24th June 2008   #9 (permalink)
Join Date: Apr 2005
Posts: 1,297
Jon-NC is on a distinguished road
Cheers guys. It appears that the powers to be are going to put Windows 2003 with ISA in instead. .

Less work for me to do I suppose. I'll let some poor sod deal with ISA.
__________________
Jon Rohan

Please note: My views are my own and not those of the company I work for.
__________________
Web Host - VIP Member
Jon-NC is offline   Reply With Quote
Old 24th June 2008   #10 (permalink)
I am Staff at
Bashton Ltd
About My Company!

Certified Host
Join Date: Apr 2005
Location: Manchester
Posts: 218
samb is on a distinguished road
When ISA server fails to perform as required, please feel free to refer them to us for a proper Squid setup
__________________
Web Host - Certified Member
samb is offline   Reply With Quote
Old 24th June 2008   #11 (permalink)
Join Date: Apr 2005
Posts: 1,297
Jon-NC is on a distinguished road
hehe. Unfortunately it is up to the account manager and client IT contact. Neither have really used Linux and therefore would rather have ISA.

The joys of having a separate sales team.
__________________
Jon Rohan

Please note: My views are my own and not those of the company I work for.
__________________
Web Host - VIP Member
Jon-NC is offline   Reply With Quote
Old 24th June 2008   #12 (permalink)
I am Staff at
ACS
About My Company!

Certified Host
Join Date: Aug 2006
Location: North Yorkshire
Age: 23
Posts: 241
fov is on a distinguished road
Whats wrong with ISA?
Ive never had any real issues but then ive only had it in a small network.
__________________
Web Host - Certified Member
fov is offline   Reply With Quote
Old 25th June 2008   #13 (permalink)
I am Staff at
Wise Hosting
About My Company!

Certified Host
wise's Avatar
Join Date: Nov 2005
Location: Scotland
Posts: 387
wise is on a distinguished road
websense sitting on top of ISA is a standard setup and works quite well ..
__________________
Web Host - Certified Member
wise is offline   Reply With Quote
Old 25th June 2008   #14 (permalink)
I am Staff at
Websense
About My Company!

Certified Host
Join Date: Aug 2005
Posts: 368
Schumie is on a distinguished road
.. wait until version 7 is released and you might not need an external proxy server
__________________
Steve Wright
Websense Hosted Security
For EMail and Web content
__________________
Web Host - Certified Member
Schumie is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Tax question eddie Business and Technical Advice 18 3rd November 2006 01:58 PM
question on 1&1.co.uk Plz mature_student Shared and Reseller Web Hosting 5 6th August 2005 03:31 AM
For those that question everything.... richard General Chit Chat & Discussion 0 17th February 2003 04:27 AM
A question rchosts Shared and Reseller Web Hosting 6 28th January 2003 09:57 PM


Some great companies!


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0