+ Reply to Thread
Results 1 to 14 of 14

Thread: Squid Question

  1. #1
    B61
    no reviews yet. Post Review
    Certified VIP Host
    I have made 1666 posts
    114 posts within 6 months
    Contact Me, Company profile
    JonRohan is on a distinguished road

    Squid Question

    Hello,

    We have a slight problem with a customer’s Websense web filtering software. The reporting feature on Websense cannot individually distinguish users on a Terminal Services server.

    We have been advised by Websense to put a squid proxy (or ISA proxy *spits*) in between the Terminal Servers and forward all communications onto the Websense server.

    Would this be easy enough for a Linux novice? I have already setup squid in which is working as a proxy fine. I imagine that I may need to add some form of NAT or IPTABLES stuff to forward on all proxy traffic to the Websense server?

    Any tips in what to search for would be cool; I'm a little out of my depth on this Linux stuff. :P

    Cheers,

    Jon
    Jon Rohan

    Please note: My views are my own and not those of the company I work for.

  2. #2
    Wise Hosting
    no reviews yet. Post Review
    Certified Standard Host
    I have made 810 posts
    131 posts within 6 months
    Contact Me, Company profile
    wise is on a distinguished road
    websense has a citrix agent you can install on each server that will distinguish the users - Im sure you can put this on your terminal servers.

    What version of websense are you using?
    Brian Box
    Wise Talk | Wise Hosting | wisevps | follow us on twitter

  3. #3
    B61
    no reviews yet. Post Review
    Certified VIP Host
    I have made 1666 posts
    114 posts within 6 months
    Contact Me, Company profile
    JonRohan is on a distinguished road
    For some reason (I dont know the exact reason) the Citrix agent won't work. It could be due to the version of Citrix our customer is running.
    Jon Rohan

    Please note: My views are my own and not those of the company I work for.

  4. #4
    Certified Standard Host
    I have made 781 posts
    142 posts within 6 months
    Contact Me, Company profile
    Schumie is on a distinguished road
    Without my Websense hat on (as I deal with the Software as a Service, as opposed to on-premise) but as I understand it, if you drop in a squid proxy (pretty easy to do) and if it can drop in as the gateway for these boxes, a few iptables rules to redirect port 80 traffic, or alternatively set the group policy for proxying through the squid box, it should be relatively simple.

    I'm not sure how it differentiates on the users though

  5. #5
    B61
    no reviews yet. Post Review
    Certified VIP Host
    I have made 1666 posts
    114 posts within 6 months
    Contact Me, Company profile
    JonRohan is on a distinguished road
    The reason we can't use the citirx agent is because citrix isn't used. :O

    I'm not sure how squid will differentiate the users either.
    Jon Rohan

    Please note: My views are my own and not those of the company I work for.

  6. #6
    Certified Standard Host
    I have made 781 posts
    142 posts within 6 months
    Contact Me, Company profile
    Schumie is on a distinguished road
    Hmmm.. I've asked the question internally as I'm quite interested knowing how it does the user seperation now

  7. #7
    Wise Hosting
    no reviews yet. Post Review
    Certified Standard Host
    I have made 810 posts
    131 posts within 6 months
    Contact Me, Company profile
    wise is on a distinguished road
    As far as Im aware it wont differentiate the users - its been a couple of years since dealing with websense enterprises etc, so they may have added something. The remote agent they developed for citrix was specifically for the reason you are needing it and I had thought they could also be put on TS too ... are you using ISA server under websense ?
    Brian Box
    Wise Talk | Wise Hosting | wisevps | follow us on twitter

  8. #8
    Certified Standard Host
    I have made 781 posts
    142 posts within 6 months
    Contact Me, Company profile
    Schumie is on a distinguished road
    I've just spoken with one of the chaps, so it does need a proxy server in place, and the browser passes user credentials, that's how it's able to differentiate

    You can also enable manual authentication as well, so that if the user credentials aren't passed the users will be forced to authenticate before browsing.

    Integration with Squid seems pretty straight forward, and if you need any help the support chaps are always here to give guidance

  9. #9
    B61
    no reviews yet. Post Review
    Certified VIP Host
    I have made 1666 posts
    114 posts within 6 months
    Contact Me, Company profile
    JonRohan is on a distinguished road
    Cheers guys. It appears that the powers to be are going to put Windows 2003 with ISA in instead. .

    Less work for me to do I suppose. I'll let some poor sod deal with ISA.
    Jon Rohan

    Please note: My views are my own and not those of the company I work for.

  10. #10
    Bashton Ltd
    no reviews yet. Post Review
    Certified Standard Host
    I have made 365 posts
    48 posts within 6 months
    Contact Me, Company profile
    samb is on a distinguished road
    When ISA server fails to perform as required, please feel free to refer them to us for a proper Squid setup

  11. #11
    B61
    no reviews yet. Post Review
    Certified VIP Host
    I have made 1666 posts
    114 posts within 6 months
    Contact Me, Company profile
    JonRohan is on a distinguished road
    hehe. Unfortunately it is up to the account manager and client IT contact. Neither have really used Linux and therefore would rather have ISA.

    The joys of having a separate sales team.
    Jon Rohan

    Please note: My views are my own and not those of the company I work for.

  12. #12
    fov
    fov is offline
    ACS
    no reviews yet. Post Review
    Certified Standard Host
    I have made 628 posts
    178 posts within 6 months
    Contact Me, Company profile
    fov is on a distinguished road
    Whats wrong with ISA?
    Ive never had any real issues but then ive only had it in a small network.

  13. #13
    Wise Hosting
    no reviews yet. Post Review
    Certified Standard Host
    I have made 810 posts
    131 posts within 6 months
    Contact Me, Company profile
    wise is on a distinguished road
    websense sitting on top of ISA is a standard setup and works quite well ..
    Brian Box
    Wise Talk | Wise Hosting | wisevps | follow us on twitter

  14. #14
    Certified Standard Host
    I have made 781 posts
    142 posts within 6 months
    Contact Me, Company profile
    Schumie is on a distinguished road
    .. wait until version 7 is released and you might not need an external proxy server

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Tax question
    By eddie in forum Business and Technical Advice
    Replies: 18
    Last Post: 3rd November 2006, 01:58 PM
  2. question on 1&1.co.uk Plz
    By mature_student in forum Shared and Reseller Web Hosting
    Replies: 5
    Last Post: 6th August 2005, 03:31 AM
  3. For those that question everything....
    By richard in forum General Chit Chat & Discussion
    Replies: 0
    Last Post: 17th February 2003, 04:27 AM
  4. A question
    By rchosts in forum Shared and Reseller Web Hosting
    Replies: 6
    Last Post: 28th January 2003, 09:57 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Content Relevant URLs by vBSEO 3.5.0 RC2