Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Justin_Hickey
Collaborator

User Identification gone haywire on Mobile Manager   

This is kind of an interesting situation that I thought I would share and ask advice on. I have a Mobile Device Manager from MobileIron which proxies certain traffic from our supported mobile phones. The phones automatically log into the MDM with user creds behind the scenes. This is a newer service we provide. 


I got complaints that the phones could not get to iTunes. Upon looking at the logs I saw that the traffic had identified several userids associated with the same stream of traffic. The firewall denies this traffic because someone in that list of users is not allowed to get to iTunes. At that point all access to itunes from that host is blocked. 

I could write a policy higher up that allows this appliance to most websites unrestricted but I'd rather craft some kind of exception to the user identification process for this rule. Just curious how you, my checkmates, might handle this. 

Thanks, 

Justin

0 Kudos
2 Replies
Vladimir
Champion
Champion

Justin,

Can you check if the traffic from MDM proxy has "X-Forwarded-For" tags configured?

If yes, I would expect CP to be able to differentiate the streams and am interested to know if it is not the case.

Thanks,

Vladimir

Justin_Hickey
Collaborator

I gave up on it. Ran out of time. I just created a policy to exclude this device from URL filtering. Thanks for the response though.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events