Jump to content

Recommended Posts

Posted
It's very popular across the pond and it's gaining more of a foothold over here. It's got a reputation for being very good value for money for smaller deployments. I've used it a couple of times and it seems quietly competent and has features more than comparable with the bigger players
Posted
We have got it installed here since Easter this year. Works very very well really impressed. Excellent value for money. We run our Byod network through it using there captive portal. Pm me if you want to ask any questions
  • Thanks 1
Posted
We've recently added iBoss to our portfolio. Really impressed with the solution. As mentioned above, its huge in America and has the majority of school using their solution. If you would like some more information, a play on a virtual box, webex or even loan a box for your site let me know and I will put you in touch with one of the sales team here.
Posted

iboss uses a layer-2 bridge (like a dumb switch) for filtering which means there is no proxy bottleneck, and it sees all 131,000+ TCP and UDP. The latter means that together with it’s inbuilt layer-7 app controls and the additional threat management license it is able to detect and block true zero day threats based on behaviour based analysis. It also properly manages SSL traffic, with selective inspection/decryption able to handle the expected increase in decryption required once Google goes SSL-only this Summer.

 

In terms of the deployment, like all true SWG appliances, iboss is designed to operate behind a firewall, be it your existing or LA solution or the dedicated iboss firewall appliance. This offers full gigabit throughput as well as fully integrating into the single reporting engine across all iboss products. Finally there is full mobile security/MDM for iOS, Chromebook, Android, OS X etc

 

I understand that they have recently replaced a number of Smoothwall and Bloxx installations and the customers have found the iboss to be easier to use, creates less false positives, and much faster on high speed (100Mbps +) networks. PM me for further details on these and also some key wins against Lightspeed.

 

Happy to give you a web demo of the product, or arrange an onsite eval.

  • Thanks 1
Posted

I understand that they have recently replaced a number of Smoothwall and Bloxx installations and the customers have found the iboss to be easier to use, creates less false positives, and much faster on high speed (100Mbps +) networks. PM me for further details on these and also some key wins against Lightspeed.

 

 

Very interested, although still in contract with smoohwall. I note "faster on 100Mbs + networks" and would have thought the opposite was true as lightspeed/smoothwall are proxy/cache servers which presumably save bandwidth. Does iboss cache content too?

Posted
Very interested, although still in contract with smoohwall. I note "faster on 100Mbs + networks" and would have thought the opposite was true as lightspeed/smoothwall are proxy/cache servers which presumably save bandwidth. Does iboss cache content too?

 

Caching is very much a technology of yesteryear as more content is now dynamic, streamed, or encrypted etc (remember the mighty CachePilot that was once everywhere, now collecting dust in a closet near you).

 

In terms of using a proxy server there are a number of issues, for example products that are based on squid struggle with throughput in excess of 2-300Mbps due to the nature of this piece of software. If you start to add on other services on the same box such as dynamic categorisation, reporting etc and then ask it to do this for 2-3000 devices on a typical large secondary network you can see where the bottlenecks start to come into play. The other major issue with using a proxy is that they can only control traffic that plays nicely with them, meaning that things like malware/ or proxy avoidance tools (ultrasurf, TOR etc) that often use obscure UDP ports have to be controlled at the firewall.

 

HTH, Richard @ iboss UK

  • Thanks 3
Posted
We use iBoss Here and really like it. Had a nightmare with the people carrying out the install though. PM me if you want any more details.
Posted
We use iBoss Here and really like it. Had a nightmare with the people carrying out the install though. PM me if you want any more details.

@techie08, sorry about your experience. As we continue to build market share here in the UK, we are getting more reseller partners through our certified technical training so there are now lots of really good options for installation assistance. Add to that we are happy to provide unmetered support to our EDU customers as part of the product then you should now be covered moving forward.

 

I think one of my colleagues is going to check in with you to see if there is anything else we can help with.

 

Cheers, Richard

Posted

We've used it here for about a year. Its very good, we didn't directly buy it, it came as part of our region center package (region center provide our inet connection, video conferencing, backup, mail filtering etc).

 

We had an issue few months ago where the kids had got through the filter using hotspot shield (HSS) and tunnel bear. We spoke with the region center about it and we upgraded to the latest version of iBoss (which caused a few issues, reports stopped working) but they have everything sorted now and working like a champ including blocking HSS traffic.

Posted
Bear in mind that whilst proxying might be older tech, with encrypted traffic you are always going to need to proxy to get any sort of granular filtering. Even those who claim to be non-proxy based (eg lightspeed) have this caveat.
Posted (edited)
I'm just waiting for confirmation from @rpmoore about iBoss being at the next ANME meeting on the 25th June - I'll post again if/when they confirm, all ANME members will receive an invitation to the meeting, so it could be a good way of seeing what they've got to offer... Edited by RichCowell
  • Thanks 1
Posted (edited)

@tom_newton is of course correct. In order to do man in the middle SSL decryption, a proxy is required to handle the mechanics of certificate exchange - you can't bend the laws of physics.

 

iboss natively uses a Layer-2 bridge for filtering TCP and UDP traffic which runs at wire speed. We then do selective decryption based on the domain category, and only traffic that needs to be decrypted is then diverted onto the proxy. We have a couple of patents around our proxy to overcome the speed limitations of the standard squid offering.

 

It is reckoned that SSL traffic will grow from the current 40% level to as much as 70% (according to Gartner), so selective decrypt provides all the benefits without the performance and speed overheads.

@RichCowell - looking forward to the ANME meeting, i'll get the papers over to you later today. I'll bring my demo kit with me if anyone wants a look through the product over a cuppa.

 

Cheers, Richard

Edited by rpmoore
Posted
Where is this park hall hotel?

 

Just off the Charnock Richard Services on the M6 in Lancashire...

 

We're hoping to arrange meetings in other areas in the next 12 months (looking at the London area / Midlands / South Coast atm)...

 

The meeting locations are based on member locations, so the best way to know where to put the meetings on next is as member numbers grow in those areas... We've also got a member referral competition running atm - more info on our website - Association of Network Managers in Education ANME

Posted
How does lightspeed manage SSL ?

 

As far as I am aware, LS does not offer selective SSL decryption, and you have to either decrypt ALL SSL or none. To avoid a massive bottleneck, particularly on larger installations LS tend to specify an external load balancer to divert specific SSL traffic to a separate proxy appliance.

 

iboss automatically diverts SSL traffic from the L2 bridge onto internal proxy for decryption based on the selective policy.

 

cheers, Richard

Posted
@tom_newton is of course correct. In order to do man in the middle SSL decryption, a proxy is required to handle the mechanics of certificate exchange - you can't bend the laws of physics.

 

iboss natively uses a Layer-2 bridge for filtering TCP and UDP traffic which runs at wire speed. We then do selective decryption based on the domain category, and only traffic that needs to be decrypted is then diverted onto the proxy. We have a couple of patents around our proxy to overcome the speed limitations of the standard squid offering.

 

It is reckoned that SSL traffic will grow from the current 40% level to as much as 70% (according to Gartner), so selective decrypt provides all the benefits without the performance and speed overheads.

@RichCowell - looking forward to the ANME meeting, i'll get the papers over to you later today. I'll bring my demo kit with me if anyone wants a look through the product over a cuppa.

 

Cheers, Richard

 

Suspect 100% SSL is not far away. Then you end up relying on a domain list(!) to do your dirty work. If facebook, google, and microsoft are on the decrypt list, you may end up proxying 60-70% of your traffic. See also: square one, back to.

 

I hate the internet ;)

Posted
So if I'm thinking correctly (sorry if OT) Smoothwall at the moment cannot decrypt BYOD SSL as it needs the cert installing on the client instead of MITM taking place on the appliance ? Where as iBoss and LS can ? (iBoss sounds interesting if it just does selective inspection)
Posted
From the comments above, it seems as though in order to decrypt and inspect SSL traffic, you will ALWAYS need a proxy, so in the case of non-proxy solutions, you are relying on Black/White lists for your SSL filtering? SW on the other hand has the capacity to do it, just subject to the installation of certs. Looks like iBoss relies on an internal proxy to decrypt so I suspect this isn't 'out of the box' or 'Apple: Just works' - you will still likely be faced with complex exceptions in either case. Depends whether the SSL with iBoss is included or separate. Worth seeing it in action AND looking at how the policies are configured.
Posted
So if I'm thinking correctly (sorry if OT) Smoothwall at the moment cannot decrypt BYOD SSL as it needs the cert installing on the client instead of MITM taking place on the appliance ? Where as iBoss and LS can ? (iBoss sounds interesting if it just does selective inspection)

 

All 3 systems have the same answer for SSL traffic: MITM it with a proxy. All 3 need certs pushing to the client for this. All 3 can optionally not MITM some traffic. Iboss can optionally not even proxy some traffic.

Posted

Thanks @tom_newton you took the words from my mouth, and yes we don't proxy traffic by default :cool:

@caffrey back to your question, to do SSL MITM decryption generally requires the session to be proxied with the inherent certificate issues; however iboss have another cunning feature for windows PC's. Our EdgeScan client performs the SSL decrption within the Windows TCP/IP stack, both removing the certificate problem as well as offloading the SSL decryption onto the endpoint workstations :)

 

Cheers, Richard

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...