Doing transparent user identification myself

rated by 0 users
Answered (Verified) This post has 1 verified answer | 5 Replies | 1 Follower

Top 500 Contributor
9 Posts
lochii posted on 6 Aug 2012 5:42 AM

Hi there, 

We've just installed the web filter in an environment which is predominantly Apple, being that there are no Microsoft active directory servers, no Novel eDirectory servers, nor any RADUS Servers.

We have the necessary information in realtime, mapping users to IP addresses, which we'd like to feed to the web filter in the same way that the transparent user identification agents do.

Is there a mechanism for doing this? or an API which I can point our developers at?

Our of desperation, we considered using the RADIUS agent and sending fake requests/responses through it such to build up the user map, there must be a better way than this!

Thanks an advance

Dave.  

Answered (Verified) Verified Answer

Top 500 Contributor
9 Posts
Verified by lochii

I'm afraid we can't change to AD simply because websense don't have an open interface for user identification!

Nontransparent user identification is problematic in that it breaks background updating processes (such as apple / linux software updating), though with the apples we do at least have WISPR so an opportunity to present them with (yet another) logon dialogue!

Thanks for your help, I think our radius idea was better (send fake requests and replies through the radius agent, fooling it into thinking that the employee is logging on via radius)

Dave.

 

|

All Replies

Top 500 Contributor
9 Posts

I should add that we have an LDAP server against which we need to identify these users, since the policy is by user and not machine (users are hot-desking all the time) . We have full control of this environment such that we can capture these logon events and feed them somewhere, maintaining our own user map. 

|
Top 10 Contributor
2,443 Posts
Editor
Moderator
The Websense Content Gateway does have LDAP support. But there is no transparent LDAP agent of a similar nature to DC Agent/Logon Agent.

JACOB SLOAN, CCNA, WCSE

 

|
Top 500 Contributor
9 Posts

Thanks,

Unfortunately we don't have the content gateway, we use the EIMServer of the web filtering service, we have many offices around the world, each with a firewall communicating with the EIMServer, we can't support a design where any trafifc would be going through a central location like a content gateway,  we already have a list of usernames and IP addresses which is updated each time an employee logs in or out globally, we just need a way of pushing this ourselves to the filtering module. 

Can somebody from websense please comment on this? is the interface between the transparent user identification agents and the filtering module proprietary? or is it based on standards based protocols that we can use to update the filtering service ourselves? 

|
Top 10 Contributor
2,443 Posts
Editor
Moderator

lochii:
is the interface between the transparent user identification agents and the filtering module proprietary?

Yes it is.

lochii:
or is it based on standards based protocols that we can use to update the filtering service ourselves?

Sorry, no.

The only way you'll be able to get user identification for the Filter Service is using the 'Prompt for Manual Authentication" settings from within the User Identification settings.  But, that's not transparent.

Your best choice is to drop LDAP and go with Active Directory instead.

JACOB SLOAN, CCNA, WCSE

 

|
Top 500 Contributor
9 Posts
Verified by lochii

I'm afraid we can't change to AD simply because websense don't have an open interface for user identification!

Nontransparent user identification is problematic in that it breaks background updating processes (such as apple / linux software updating), though with the apples we do at least have WISPR so an opportunity to present them with (yet another) logon dialogue!

Thanks for your help, I think our radius idea was better (send fake requests and replies through the radius agent, fooling it into thinking that the employee is logging on via radius)

Dave.

 

|
Page 1 of 1 (6 items)