Jump to content

Recommended Posts

Posted (edited)
Which auth method is that? Bear in mind that something like NTLM or Kerberos, if you forcibly log the user out they're just going to log straight back in :)

 

It's when your testing as a user, you log the user out of smoothwall, log the user off the machine, change their membership, log back onto the machine and get recognised as the same group as before, not the new one.

 

Its frustrating but maybe its just us....though the other school in the area has the same problem *shrug* :(

Edited by RTFM
Posted
It's when your testing as a user, you log the user out of smoothwall, log the user off the machine, change their membership, log back onto the machine and get recognised as the same group as before, not the new one.

 

Its frustrating but maybe its just us....though the other school in the area has the same problem *shrug* :(

 

When I was testing other users I altered the proxy setting on my machine so that it went to a ssl login page and then logged in using that. Granted, not always possible to test exactly what you want this way but for testing websites and other simple things it's a quick and easy way of doing it.

Posted

Not sure if everyone knows yet but Millgate are now a Lightspeed accredited partner :D

 

If you want to arrange a webinar, demos, pricing or a meeting then Luke and I can help you out with it.

Posted
I have ordered a demo Lightspeed box so will be interested to see how it works. The only thing thats putting me off is the £££ in buying a new firewall to run alongside it. I think my smoothie renewal is for June so have a bit of time to decide. Even with the awful support, rubbish logs and clunkiness of the interface I may be forced to stick with Smoothwall. (it does work though so not all bad)
Posted (edited)
I have ordered a demo Lightspeed box so will be interested to see how it works. The only thing thats putting me off is the £££ in buying a new firewall to run alongside it. I think my smoothie renewal is for June so have a bit of time to decide. Even with the awful support, rubbish logs and clunkiness of the interface I may be forced to stick with Smoothwall. (it does work though so not all bad)

 

That is certainly one thing to take into consideration and its the major down side of a non UTM appliance :)

 

Our new hardware arrived yesterday, exciting!

Edited by RTFM
Posted
We've sent a couple of feature requests back to Lightspeed (combine spam summary emails for accounts with multiple aliases, set time period of spam summary emails)

 

Ooh - just received a spam summary email this morning with all my email aliases combined into the one email, looks like they've sorted that feature.

Posted
Ooh - just received a spam summary email this morning with all my email aliases combined into the one email, looks like they've sorted that feature.

 

Although, actually checking the emails listed as spam, it looks like they are still marking their own marketing / support emails as spam. Very even-handed of them, but probably not actually meant to happen...

Posted

I have used light speed for about 3 years, first TTC8 then the new rocket. The agent on all the PC’s is nice, because I can set different filters for staff students, subnets etc and it is mostly transparent.

I however do not have a say in the matter, our filtering and firewall is all handled by our ITC . They have the light speed box setup with tiered administration so each school can manage their own settings.

I am glad to see light speed support on here now, even on my local listserv light speed seems to me a minority.

I’ll start another thread so I don’t hijack this one with my question.

  • Thanks 1
Posted
I'm fairly sure they tried that, but it's worth double-checking, thanks.

 

Just got around to checking this - yes, both devices are already manually set to 1gb/s, full duplex, no auto-negotiate involved.

Posted

Just had lightspeed in, got to have a little play with their demo box and i really like the look of it and my big campus (we're currently with uniservity which is dire) lots more to consider, just bloxx to look at next week now :)

 

Really looking forward to the day we get whichever option we go for in, the improvments for us a huge.

Posted

Well with the amount of mobile devices around found Lightspeed really offers that educational focus and links to so many resources with My Big Campus. This seems to be a good alternative to the overweighted VLE's out there and opens up to a wider audience.

Great app for iOS

Posted
Well with the amount of mobile devices around found Lightspeed really offers that educational focus and links to so many resources with My Big Campus. This seems to be a good alternative to the overweighted VLE's out there and opens up to a wider audience.

Great app for iOS

 

yep MyBigCampus looks promising for us too. Lightspeed Demo box ordered :)

Posted
Finally I've had a presentation from all 3 big suppliers, had a play with the software from all 3 and given all companies a damn good grilling. I think from my questioning and investigation of all 3 companies I've decided that I'm going to have a bloxx trial first. Bloxx looked like the better filter, i liked their software and while they don't have all the features in place that we want yet they certainly seemed to be on the case. After that I'm going to test lightspeed, they had all the features we wanted and more but potentially weren't as good in the area of blocking out unwanted pages, really liked my big campus though!
  • 2 weeks later...
Posted

In the end, we decided to go for Smoothwall. Lightspeed gave us a trial and my old school let me run a comparison against the Smoothwall there. Lightspeed definitely has the better user interface. The biggest feature I wanted that Lightspeed was missing was HTTPS interception and decryption - it can log the domain off the certificate, but not the full URL.

 

Smoothwall seemed to be somewhat better in blocking my attempts to access dodgy material through the filter. However I have to say the dynamic analysis does not seem to do as much as I feel it should - most of the blocks I hit on Smoothwall seemed to be down to the URL lists. I tried to do Geoff's test "Ask them to filter a big dynamic website like Edugeek." Edugeek did not seem to have enough questionable material on it, so I tried deviantart.com as a tricky case - a lot of innocent images, but also a lot of smut and social features. As far as I could see Smoothwall has the whole site in "non-pornographic nudity" and did not distinguish the pages much between the pages - once I unblocked that, I could sign up to the site and get into everything I tried. Maybe it is just too hard to distinguish "pornographic" from "non-pornographic" nudity - not sure people are much good at saying what art is either.

 

I would be interested to know if Smoothwall can suggest a site that would really show their dynamic page analysis in action.

 

I regret not giving Bloxx more of a chance. I would have liked to see how they compared.

Posted (edited)

Thanks for going with Smoothwall. Difficult to give such examples tbh - if we know of em, they go in the blocklist, that's our first line of defence, and we keep it pretty complete (helps in situations where we have less information on the traffic, eg if someone doesn't want to inspect https).

 

One really useful feature of the content filter is fast moving sites: try proxies, if you get a newish one, or one which has escaped our glance, that will get content filtered, or for example certain google searches, or online games sites are a good contender for being content filtered. Yes, you'll sometimes get parts of a site filtered where others aren't but i tends to be very temporal - particular articles or posts.

 

Worth noting that Bloxx don't content filter anything that's in their list; period. So if edugeek is marked as "forum", then its a forum. (Willing to be corrected if that's old info). Smoothwall's G3 applies all filters to all requests and then decides according to policy (unless you explicitly state otherwise: that, folks is the difference between "allow" and "whitelist").

Edited by tom_newton
  • Thanks 1
Posted
The biggest feature I wanted that Lightspeed was missing was HTTPS interception and decryption - it can log the domain off the certificate, but not the full URL.

 

Not strictly true.

 

There is full blown proxy service on the rocket appliance that you can use for MinM HTTPS interception. We also use it for the MDM global proxy payload on IOS. It will log and block etc HTTPS the same as HTTP traffic.

Most customers do not use it as the SSL decoder does an excellent job, but it is there for those that feel they need it, plus it can be used selectively I.e for curriculum network, but not for BYOD or guest networks where proxy settings might be intrusive, prohibitive, or just an administrative burden.

The transparent bridge will also log and monitor the other 65533 TCP and UDP ports.

 

Simon

  • Thanks 1
Posted
I tried to do Geoff's test "Ask them to filter a big dynamic website like Edugeek." Edugeek did not seem to have enough questionable material on it

 

Did you try the security forum? I'd bet/hope that would set smoothwall off. There's information in the threads in there you absolutely do not want you little darlings reading lest they lay waste to your network.

Posted
There is full blown proxy service on the rocket appliance that you can use for MinM HTTPS interception. We also use it for the MDM global proxy payload on IOS. It will log and block etc HTTPS the same as HTTP traffic.

I am sorry to have missed that then - the demo unit was a bottle rocket, so that is probably where the misunderstanding arose. It probably would not have been enough, but it might have swung our decision.

 

I did feel lacking in information on technical detail for Lightspeed - a lot of the wiki seems to be customer only. It would be helpful if you could put an easily accessible page of technical specifications and features with a comparison of the different models. Maybe one already exists and I missed it as well!

 

 

Did you try the security forum? I'd bet/hope that would set smoothwall off. There's information in the threads in there you absolutely do not want you little darlings reading lest they lay waste to your network.

Did a quick test and it seems not, but I am not quite sure what category the security forum would be blocked under - proxy bypass maybe? I would be surprised about it being blocked under any dynamic filtering though - working out automatically that that content is sensitive seems as if it would be pretty tough. Easy to block the security forum manually of course, but then we have web forums as a category blocked for pupils.

  • Thanks 1
Posted (edited)
I am sorry to have missed that then - the demo unit was a bottle rocket, so that is probably where the misunderstanding arose. It probably would not have been enough, but it might have swung our decision.

 

I did feel lacking in information on technical detail for Lightspeed - a lot of the wiki seems to be customer only. It would be helpful if you could put an easily accessible page of technical specifications and features with a comparison of the different models. Maybe one already exists and I missed it as well!

 

All of the rocket appliances run the same code, from the bottle rocket to the 10GB rocket, so all features are the same on every hardware model, its just a matter of throughput.

Thanks for the feedback however, I will endeavour to see if we can improve the Wiki in this area.

Did you happen to contact support with this question, or attend the free web essentials course, or free training videos ? or was you not informed about them ?

 

Thanks again for the feedback

Simon

Edited by Eappariello
Posted
Did you happen to contact support with this question, or attend the free web essentials course, or free training videos ? or was you not informed about them ?

My information about lack of SSL decryption came from the engineer who came to install the demo unit. I questioned the point specifically, and he did not mention the proxy option. However I only realised the full significance for us in terms of logging later on, so I did not push the point as hard as I might have.

 

I do not recall being pointed to the web essentials course or web videos, but I may have forgotten. However, pre-sale when I am trying to compare different options and get as much of a complete overview as quickly as possible, personally I find video a rather slow way to learn about a product. So had I known about the videos, I would probably have skipped through some but not watched them all.

  • Thanks 1
Posted

Fair points. Thanks for taking the time to give some feedback, we will use it to improve our demo process.

 

My information about lack of SSL decryption came from the engineer who came to install the demo unit. I questioned the point specifically, and he did not mention the proxy option. However I only realised the full significance for us in terms of logging later on, so I did not push the point as hard as I might have.

 

I do not recall being pointed to the web essentials course or web videos, but I may have forgotten. However, pre-sale when I am trying to compare different options and get as much of a complete overview as quickly as possible, personally I find video a rather slow way to learn about a product. So had I known about the videos, I would probably have skipped through some but not watched them all.

  • 2 weeks later...
Posted

It might be of interest to note that we see dynamic content analysis come to the fore in sites like Yahoo Mail where the users news feed might show objectionable content when they log in. On the face of it, yahoo mail is a webmail site in the webmail category, but we do see it blocked based on content - most commonly Gambling and Porn based on the ads and news feeds on the landing page. Of course most of the time you won't see this but periodically we see customers baffled by why the block page appears for something 'normal' like yahoo mail and when you drill into the log you find out it was blocked on content.

 

You'll see it too in sites that randomly generate content when the random generator puts together something that triggers a content block. I can't point you to one though as the nature of it is random.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...