Trustwave and Cybereason Merge to Form Global MDR Powerhouse for Unparalleled Cybersecurity Value. Learn More

Trustwave and Cybereason Merge to Form Global MDR Powerhouse for Unparalleled Cybersecurity Value. Learn More

Services
Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

Database Security

Prevent unauthorized access and exceed compliance requirements.

Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Solutions
BY TOPIC
Microsoft Security
Unlock the full power of Microsoft Security
Offensive Security
Solutions to maximize your security ROI
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Partners
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats
Loading...
Loading...

HOWTO: User not filtered properly

Expand / Collapse


This article applies to:

  • Web Filter

Question:

  • Requests from a user are not being filtered as expected. What are the steps to troubleshoot this situation?

Procedure:

Run an active profile lookup on the IP that is not being filtered properly and note what Group they are currently being filtered under.

Groups:

Is the user in the expected group?

  1. If the user EXISTS in the expected group:
    • On the ruleset in the active profile lookup, confirm that the site in question is set to the appropriate level:
      • Block: Site will be blocked unless an allow exists which will take precedence.
      • Allow: Should always take precedence.
      • Pass: Does nothing other than allows the traffic to pass. If the site is in multiple categories and one is set to block, the site would then be blocked.
  2. If the user IS NOT in the expected group:

LDAP:

  1. Is the user being filtered via LDAP?
    • If so, confirm that the system in question has the authenticat program running.
    • You can check by looking in the windows Task Manager and searching for an instance of Authenticat.
    • You can also check (if installed via a service) if the program is running as a service.
      • Run services.msc (windows key + R) and search for the M86 Authenticator service
    • Are multiple instances of the M86 authenticator running? Multiple instances can cause inconsistent filtering results, because all instances will attempt to bind to the same port, but only one instance can bind at a time.
      • Multiple instances can be caused by GPO or batch files.
  2. Is the Domain marked as inactive?
    • If the domain was recently rebooted, you may need to re-activate the domain.
    • If you experience errors when attempting to activate the domain, contact Trustwave TAC.

To contact Trustwave about this article or to request support:


Rate this Article:
     

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.