This problem affects schools whose file server:
- Has two network cards installed (one for the LAN and a second for the ISDN/ADSL connection).
- Is running either Symantec I-Gear or Symantec Web Security software.
- Is running Windows NT, 2K or 2003 server.
Problem:
The Symantec software makes the file server appear as a normal authenticating proxy server, asking you to login when you start up Internet Explorer. However this is not the case, and the Symantec software is acting more as a firewall.
Rather than allowing authentication via the command line or within a script (as in wget commands), the Symantec software returns an html window for you to complete. As processes on KB are automated this effectively blocks any ‘talkback’.
There are no apparent settings (such as a white list) in the Symantec software to allow a specific IP address unauthorised access, either you have this authentication on for all users, or not at all.
Note:
The Symantec software runs as a service within windows and this is where it is turned off.(Start | Programs | Administrative Tools | Services). To stop the service completely, change the start-up type to either manual or disabled.
Solution - Windows 2K or 2003 Server
Set the server up as a Router in Start | Programs | Administrative Tools | Routing and Remote Access. Then by setting the KnowledgeBox gateway to be the server IP address, and the KnowledgeBox proxy server to be the upstream proxy, the request will bypass the Symantec software using the schools upstream proxy server. You will probably have to contact the schools ISP to obtain the upstream proxy IP address.
Solution - Windows NT
If the server is running NT server, there is no facility to set the server up as a router. Therefore the school needs to turn the software off or install a different firewall software package. Under Windows NT, the Symantec software often runs in conjunction with Microsoft Proxy for which there is no specific service, thus turning it off can be difficult. If your server is running Windows NT, KnowledgeBox would be able to advise on a solution.