EXALogo colour Help

Initial SurfProtect Setup

Initial SurfProtect Setup

Introduction

SurfProtect’s cloud-based HTTPS filtering feature requires that all devices on your network trust Exa. This document provides guidance to enable this across your network, however, should you require any additional help then please do not hesitate to contact our dedicated Support Team on 0345 145 1234 or by emailing support

Certificate Setup

A certificate published by Exa needs to be installed on each device within your network. This can be done on a per machine basis, however we have detailed how to deploy the necessary certificate using various management tools below.

Note: for all customers using our connectivity, we recommend setting your DNS forwarders to:

    • 82.219.4.28
    • 82.219.4.29

Individual Machine Installation

Legacy Individual Machine Installation

Installation Verification

You can check whether the certificate is being successfully trusted by visiting the SurfProtect Certificate Status page

This page will automatically detect the location you’re browsing from so it can present a certificate signed by the authority you’ve trusted during negotiation of the secure HTTPS connection.

If your browser shows that the connection is safe then this validation serves as proof that the service certificate is trusted.

If you don’t already have SurfProtect configured to transparently decrypt all web traffic you can test decryption by configuring your browser to use proxy.quantum.exa-networks.co.uk on port 3128.

AD Configuration

SurfProtect Quantum integrates with Active Directory to provide ‘per user’ policy filtering and reporting. To achieve this, your AD data needs to be imported to SurfProtect. This document provides guidance on this process, however, should you require any additional help then please do not hesitate to contact our dedicated Technical Support Team on 0345 145 1234 or by emailing support

Note: If you do not want to enact the AD integration feature of SurfProtect Quantum, or do not have an AD server, you do not need to perform the following steps.

This will prevent these devices accessing any website belonging to a restricted SurfProtect category, or any website that you have added to your blocked list.

Why Synchronise your Active Directory data with SurfProtect?

Individual users are represented in Active Directory by a unique user account and by membership to an arbitrary number of group accounts. With Active Directory integration enabled, SurfProtect can apply different filtering policies to unique users as well as group accounts. SurfProtect also uses the information from the data synchronisation to display the real names of your users to enrich the data provided by our data analytics panel.

Windows Active Directory

SSO is achieved with Active Directory by requesting a user’s information from the web browser whenever a web resource is requested by a machine in your school’s local domain.

Running the below script will establish trust between your school’s domain controller and our proxy servers. This means that when a user requests access to a website, the web browser will be able to communicate with the domain controller to identify the individual and provide SurfProtect with trusted proof of who that person is. As a result, SurfProtect can then filter the web request according to that individual’s filtering profile, and record their online activity.

As SSO requires direct authentication against our proxy servers, Active Directory SSO requires web browsers to be configured with explicit proxy settings. Fortunately, these settings can be pushed to all Windows devices by creating a Group Policy Object; using this mechanism also helps to prevent settings from being manually changed by students.

Mixed Environments

If your school uses devices outside of your AD domain, such as iPads and Chromebooks, which are not managed as part of your local domain, individual user filtering and identification will not be possible on Quantum.

These devices will still receive transparent SurfProtect filtering when connected to your school’s network, however, user identity information and profile matching will not be enacted and weblogs will not be populated with user or machine identities. 

SurfProtect Quantum+ allows schools to configure non-domain devices to authenticate via a Captive Portal which allows us to track users and log traffic against usernames. If this is something you’re interested in please contact your Account Manager via 0345 145 1234. 

If you are using Quantum you can finish the set up here, for Quantum+ follow the below steps.

Quantum+ Setup

Suggested Next Read

Related Help Articles

ISPA Testing

The Exa Foundation

Contact us

Sales

Sales

Office hours

Monday: 8:30am – 5pm
Tuesday: 8:30am – 5pm
Wednesday: 8:30am – 5pm
Thursday: 8:30am – 5pm
Friday: 8:30am – 5pm
Saturday: Closed
Sunday: Closed

Technical Support

Contact us

Email: helpdesk@exa.net.uk
Phone: 0345 145 1234

Office hours

Monday: 8am – 6pm
Tuesday: 8am – 6pm
Wednesday: 8am – 6pm
Thursday: 8am – 6pm
Friday: 8am – 6pm
Saturday: 10am – 4pm
Sunday: 10am – 4pm