Jump to content

Recommended Posts

Posted (edited)

This is an old thread started in February 2013 and contains information that may no longer be relevant - View the latest threads about internet filtering

 

 

Alternative title: URL List filtering vs in line filtering.

 

I am evaluating filtering systems again. I have used Smoothwall before and find it pretty good, and I know how keen people around here are about it. However the quotes I have currently, put a LightSpeed rocket substantially cheaper than a SmoothWall guardian appliance. If I sell SmoothWall to the powers that be, it would have to be on the quality of the filtering. I see the theoretical advantages of in-line filtering, but I see some merit in LightSpeed's response that analysing pages centrally and sending out a URL list is more efficient and allows for more through analysis of the pages. Ultimately it is the results that matter, but I am not sure we have the resources to do our own trial of the the options, so I am very interested in the results of anyone who has.

 

Has anyone done any trials recently comparing Smoothwall against Lightspeed, or any URL list based filtering against in-line?

Edited by ZeroHour
Posted
Have both companies in, demo the kit, look at all options, pro and con both, make a recommendation, if both come out equal, then write a report and leave it to your powers that be and absolve yourself from the responsibility of choosing that particular piece of kit.
  • Thanks 1
Posted
Bear in mind that URL list filtering is not the same as dynamic content analysis. Smoothwall Dynamic content analysis can analyse a page it has never seen before that is not a member of any known URL list and categorise it based on the content potentially preventing access to inappropriate content. This even works on 'safe' sites like 'Yahoo' that might have inappropriate news feed headers or adverts. So you may like to compare the filtering features and the pros and cons of each type of filtering as part of your report.
Posted

Smoothwall's dynamic filtering is one of the best around. Simpler filters such as RM's SafetyNet let stuff through where smoothwall looks at the content and recognises a dodgy page without being told the URL. I'm not sure where Lightspeed fits in on that scale.

 

Like all filters, Smoothie may require some training so that it doesn't block that key trustworthy (hopefully) site that someone on SLT needs to access.

Posted

IMHO, URL based filtering isn't good enough anymore.

 

Content changes so fast online, and there's so many pokey corners of the internet, that keeping up with that is close to impossible.

 

I did a fairly rigorous test of various filters at my last school (bear in mind this was ~5 years ago) and ended up going with smoothwall.

 

However anything without a dynamic analysis portion was way too easily defeatable. Yeah, a dynamic filter takes a bit longer to configure and get your head round how it categories stuff - but the benefits are humongous.

  • Thanks 1
Posted
Interesting and timely topic. We are currently using Untangle and had nothing but trouble, possibly due to hardware issues. I am looking at Smoothwall and Lightspeed. Lightspeed is significantly cheaper. We are doing a demo this week to see how it all goes so will be interested to see the results.
Posted

Simple test. Ask them to filter a big dynamic website like Edugeek. The forums in particular is quite a good test as we often discuss things out of context of what a dumb url filter would be looking for, :)

 

Also check what, if at all, they can do about HTTPS filtering.

Posted
Very interesting topic as we're also currently looking at these same two options. We currently have a sonicwall which is pretty useless for web filtering in terms of policy definition, reporting and support, although we may keep it as a firewall.
Posted

One thing to always remember with these is that they do not turn up ready for your school. After we had smoothie installed I was tinkering for weeks getting it working just how I wanted it....which in turn might be miles off how you want it. Regardless of solution you go with, be patient with it.

 

The smoothwall box is awesome, but I must say their support is slipping. They take forever to get back to you, however, they are awesome when they do.

  • Thanks 2
Posted
We are working on improving the 'Out of the box' rulesets available to schools and we have several projects in the pipeline to support zero-touch installs so keep your ear to the ground.
Posted
Alternative title: URL List filtering vs in line filtering.

 

I am evaluating filtering systems again. I have used Smoothwall before and find it pretty good, and I know how keen people around here are about it. However the quotes I have currently, put a LightSpeed rocket substantially cheaper than a SmoothWall guardian appliance. If I sell SmoothWall to the powers that be, it would have to be on the quality of the filtering. I see the theoretical advantages of in-line filtering, but I see some merit in LightSpeed's response that analysing pages centrally and sending out a URL list is more efficient and allows for more through analysis of the pages. Ultimately it is the results that matter, but I am not sure we have the resources to do our own trial of the the options, so I am very interested in the results of anyone who has.

 

Has anyone done any trials recently comparing Smoothwall against Lightspeed, or any URL list based filtering against in-line?

 

 

+1 for Lightspeed here. We've done a lot of testing with them and the product is great.

 

Lightspeed pre-filters images.google.com which quite a few content filtering systems don't by "x'ing" out any images which shouldn't be shown.

 

We're about to launch a hosted version of their product and bundle it in with our hosted virtualised Fortigate security solution to give additional security / content filtering. We looked at quite a few systems and Lightspeed is a) cost effective b) scalable c) integrates with Apple, Android and Windows MDM and D) we've not been able to get an inappropriate image through it so far.

 

Dave

  • Thanks 2
Posted (edited)

We have had Smoothwall for 3 years, have been trialling lightspeed for 3 weeks and are moving to lightspeed.

 

It's easier to use, requires far less administration time and despite not having dynamic content filtering still blocks everything it needs to block, and allows what we want it to allow. Make the default rule block and if the page / URL hasn't been manually checked and categorised by a human being it simply gets blocked, then listed to be categorised.

 

People may criticise this method but the truth is we have seen it and it works.

 

Lightspeed also whitelists the sites I want, unlike Smoothwall which still touches the traffic and manipulates it which is frustrating.

 

Not that Smoothwall isn't good at what it does, I just think that Lightspeed seems more refined :)

 

Edit: forgot to mention my big campus, could prove to be very useful going forward and is bundled with the lightspeed filter

Edited by RTFM
  • Thanks 3
Posted

Hi guys,

 

If you dont mind me asking how much are we talking about smoothwall costing ???

I have someone coming to promote this product to me on Thursday at 1100 and just want a comparison

to see if its a good deal or not, I have been talking to websense for the last 2 weeks but they still

wont tell me how much it will be.

Posted
Hi guys,

 

If you dont mind me asking how much are we talking about smoothwall costing ???

I have someone coming to promote this product to me on Thursday at 1100 and just want a comparison

to see if its a good deal or not, I have been talking to websense for the last 2 weeks but they still

wont tell me how much it will be.

 

I won't say what our quotes have been for lightspeed, Smoothwall, bloxx and sonic wall but they are all much of a muchness. Your best getting prices and trials for a variety of UTM devices, filters and firewalls and making your own mind up. You'll know what's a good price when you get all the quotes and see the products :)

Posted
One thing no one has mentioned is after sales support. How do both company's compare?

 

Good point.

 

Smoothwall support used to be very quick and very knowledgable. More recently support response has been much slower than it used to be, once you speak to someone they know the product well. You'll find a couple of threads on the forums regarding this, with responses from Smoothwall regarding this.

 

Over the time I have had lightspeed I have rung support a few times both to ask questions / test the knowledgeability of them as well as check response times. They have been very good.

 

That isn't me trying to talk down Smoothwall by the way, it's a well known issue currently which I'm sure they are trying to address.

Posted
unlike Smoothwall which still touches the traffic and manipulates it which is frustrating.

 

 

If you put the rules in the right place and order it is completely unmolested and managed just logged we have a number of sites that go through and are just logged and nothing else is done to them for very particular reasons its all about how its setup and how you set it all to process rules and the info its given.

 

I'm with @Domino, simple lists of The Good, Bad or Ugly are old technology, the Internet is changing and saying if we haven't seen that page we block it is not benefiting teaching and learning which is the key here its being obstructive, you might as well make staff do there research at home and give you the website they want the kids to be on and just stick that in a proxy list as only allow traffic to these sites and make your own up ala early 2000s style with ISA lists! That will save you a lot of money if you take that stance, or even just turn the net off really....

 

Dynamic analysis is the future sites change that much especially as they become more dynamic in style with new developments in the web so yes a site may have been good to look at last week when a human reviewed it but what stopped it becoming filled with adverts for enlargements or patches and creams (I'm sure you know what I am meaning)? Dynamic analysis would go ooh thats not right and do something about it from what you have said is a guy looked at it said its Edu-Safe and passed it on and the first you know is little Johnny is looking at Katie Price with a lack of clothes and a complaint from a parent.

Posted

It is worth pointing out that Smoothwall does not rely solely on Dynamic content analysis, we also have a blocklist team who compose and manage URL lists, so the smoothwall does filter based on URL lists as well as dynamic content analysis. There are several other componants of filtering that Smoothwall includes too although you would be best to ask your sales representative to explain these when you have the demonstration as it is easier to see than for me to explain.

 

RTFM's post is interesting because there are 3 ways to allow a site - 'Allow' which still applies content modification, 'Whitelist' which bypasses all content modification and 'Allow by default' where you don't tell the smoothwall what to do either way and let it decide based on DCA.

 

As others have said, the best thing to do is to trial some solutions and see which works best for your setup.

  • Thanks 1
Posted

Regarding the whitelisting of sites, Smoothwall support have been remoted in, looked at an issue with a whitelisted site being manipulated, tested this through guardian then through squid and admitted that the site was being manipulated by guardian despite the fact it was in a whitelisted category........

 

Take from that what you will.

Posted
Has anyone done any trials recently comparing Smoothwall against Lightspeed

 

I've previously (a couple of years ago) used SmoothWall, and we've just had a Lightspeed server installed here (replacing another server that just fell over dead one morning). The Lightspeed server seems resonable so far, if a little heavy-handed with filtering, and sites can be catagorised somewhat haphazardly - lots of Chinese language resources seem to be classed as "adult", for instance. Lightspeed uses a user client installable on workstations to give data about who is currently logged on to which machine (although you can have a web-based login too), and that user agent has made a couple of our Windows 7 machines bluescreen. It seems to install okay after reimaging, though, so maybe it's just some random incompatability with something else.

 

Smoothwall can be run as a virtual machine, so you don't have to run another dedicated bit of hardware, although Lightspeed does seem to do quite a nice line in mobile device management systems (I haven't tried it out yet, and it is a little pricy (£20) per device compared with Meraki's system (£0)).

  • Thanks 1
Posted
Lightspeed uses a user client installable on workstations to give data about who is currently logged on to which machine (although you can have a web-based login too), and that user agent has made a couple of our Windows 7 machines bluescreen. It seems to install okay after reimaging, though, so maybe it's just some random incompatability with something else.

 

Had forgotten that bit, it's something we have found quite useful as an audit trail, so to speak, of who has used what machine, when etc.

 

We installed the agent via MSI onto 500+ machines and had no bluescreen issues though, will keep an eye out for it though in future :)

  • Thanks 1
Posted
an issue with a whitelisted site being manipulated, tested this through guardian then through squid and admitted that the site was being manipulated by guardian despite the fact it was in a whitelisted category........

 

I've noticed this happen too.

Posted

Interesting posts, I am going to trial Lightspeed too as I have had enough of the support at Smoothwall, its been mentioned lots on but about how bad its got but the simple case is that if the nice lady on the phone says that no one is available at the moment then its a 2 week wait for a response.

 

Didn't realise the MSI thing with lightspeed though, how does that live with BYOD filtering?

Posted
That isn't me trying to talk down Smoothwall by the way, it's a well known issue currently which I'm sure they are trying to address.

 

I think their solution is to increase the cost of support 3 fold.

Posted (edited)
It will default to an SSL login page if the user is not recognised, or you can exclude IP ranges from authentication and filter by IP range, or you can filter by individual IP, PC name or OU. Filtering by an OU is so handy if you want to filter by a room. Edited by RTFM
  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...