Jump to content

Recommended Posts

Posted
Page 9 (only) of this thread is now being categorised by the Smoothwall content filter under web proxies and blocked. I don't think it likes being criticised.
Posted
Page 9 (only) of this thread is now being categorised by the Smoothwall content filter under web proxies and blocked. I don't think it likes being criticised.

 

I would more expect it to be this

 

Did a quick test and it seems not, but I am not quite sure what category the security forum would be blocked under - proxy bypass maybe? I would be surprised about it being blocked under any dynamic filtering though - working out automatically that that content is sensitive seems as if it would be pretty tough. Easy to block the security forum manually of course, but then we have web forums as a category blocked for pupils.

 

And this

 

My information about lack of SSL decryption

 

Reading this page and taking those key words you could be looking at a forum which is telling you how to bypass filtering.

Posted (edited)
Reading this page and taking those key words you could be looking at a forum which is telling you how to bypass filtering.

That does sound more likely than it being programmed to feel insulted. ;) I was not criticising the filtering of the page - I agree the content makes it suspicious. I just found the coincidence amusing.

Edited by Jollity
Typo
  • Thanks 1
Posted
That does sound more likely than it being programmed to feel insulted. I was not criticising the filtering the page - I just found it amusing.

 

Tempting to put "Proxy bypass" in my sig now, smoothwall should, i assume, block every page i ever post on :p

Posted
Tempting to put "Proxy bypass" in my sig now, smoothwall should, i assume, block every page i ever post on :p

 

Not quite that simple... though I believe there is a test string that's always blocked somewhere in the blocklists.

  • 1 year later...
Posted

Thought I'd dig this thread up a year later.

 

Those who have made the switch from Smoothwall to Lightspeed, what are your experiences ? Are you happy ? regrets ?

  • Thanks 1
Posted
Also interested in this. We've had *countless* demos, webinars, do's, dont's etc of Lightspeed and still it would be apparent that Smoothwall is the preferred product even now. However that's just how it comes across...
Posted
The school has been using smoothwall for a long time now and I've seen it grow, reading back through this thread, a lot of the things smoothwall mentioned haven't materialised in a year since the thread was started (reporting etc.) the layer 7 addition got released without any fanfares and is a paid addon module at 500 quid, I've a demo of it but I can't find any news or information on how to use it (its in outgoing ports and I can't appear to get it to work) I could open a ticket to get info or make a post on the smoothwall forum here - which I did but got totally ignored. The school is gearing up to BYOD and iPads more and more and I'm just feeling out of control with the filtering (students running rampant with private VPN's and other apps) most app traffic is unmonitored as far as I can tell. I need a product more in line with this.
Posted
The school has been using smoothwall for a long time now and I've seen it grow, reading back through this thread, a lot of the things smoothwall mentioned haven't materialised in a year since the thread was started (reporting etc.) the layer 7 addition got released without any fanfares and is a paid addon module at 500 quid, I've a demo of it but I can't find any news or information on how to use it (its in outgoing ports and I can't appear to get it to work) I could open a ticket to get info or make a post on the smoothwall forum here - which I did but got totally ignored. The school is gearing up to BYOD and iPads more and more and I'm just feeling out of control with the filtering (students running rampant with private VPN's and other apps) most app traffic is unmonitored as far as I can tell. I need a product more in line with this.

 

In terms of reporting one of the biggest challenges you would have faced was performance simply because the SQL system that was in the original product couldn't cope with the increase in scale of traffic flow and reporting needs. We've released a massive change to the reporting system that totally changes how it indexes and the result is much much faster reporting. The aim was to make this as seamless and 'invisible' as possible so it is possible you may not even have noticed it happening. Now we have resolved the 'back end' situation with running reports we can address the front end usability and this is work in progress. I have personally been involved in the first phase of the reporting revamp and @ibpalle and I are really excited about what's coming. We expect there will be a number of small revisions as time goes on to better adapt the reporting system for the needs of our customers.

 

As far as the layer 7 module goes, this should fit in seamlessly with your port rules and be configured under the Networking > Outgoing > Ports, find the port rule you want to edit and click 'Edit' on the 'Blocked Services' entry. This will take you to an 'Edit Services' screen where you can use the Layer 7 content to block services.

 

It is not possible to allow services based on these as the problem is identifying them. The way it works is to perform deep packet inspection and often traffic can only be categorised once an initial handshake has been processed. So your client might say hello to a P2P service but can't then send or receive traffic. The inbuilt Manual accessed using the 'Help' or '?' buttons has configuration information for this under the title 'Managing Blocked Services'.

 

App traffic doesn't always behave in a standard way and add into that complications from HTTPS and you have a bit of a minefield. A big part of effectively filtering mobile devices is Authentication. If you're using captive portal then apps aren't ever going to play nice with it because captive portals are browser based and most apps don't interface with the browser at all. The next snag you hit with apps is SNI - they aren't browser based so the applications have to be written to support SNI and lots of them aren't which is a problem when trying to intercept HTTPS. A lot of traffic goes out over HTTPS these days so a lot of this is going to be damage limitation. Private VPNs are a firewall issue more than a filtering one so it might be worth bringing down an iron curtain and blocking all outgoing traffic on all ports then taking each request as it comes.

 

The Smoothwall Support forum on this board is a peer support forum rather than an official support channel - our support engineers cannot prioritise posts on Edugeek over support tickets so if you are experiencing an issue with your Smoothwall product we always recommend that you log a support ticket in line with your Support agreement rather than relying on an engineer seeing your post as many simply are not able to spend time on this board.

Posted (edited)
In terms of reporting one of the biggest challenges you would have faced was performance simply because the SQL system that was in the original product couldn't cope with the increase in scale of traffic flow and reporting needs. We've released a massive change to the reporting system that totally changes how it indexes and the result is much much faster reporting. The aim was to make this as seamless and 'invisible' as possible so it is possible you may not even have noticed it happening. Now we have resolved the 'back end' situation with running reports we can address the front end usability and this is work in progress. I have personally been involved in the first phase of the reporting revamp and @ibpalle and I are really excited about what's coming. We expect there will be a number of small revisions as time goes on to better adapt the reporting system for the needs of our customers.

 

Thats great news! I've found the smoothwall reporting system to be miserably slow and just about useless in real world situations where I've had to present data to our SMT members.

 

Please consider making the reports more "human readable" and in line with what school managers would want to see.

 

The user inteface also needs a lot of work, I completly missed how to change the dates on a report as it was such a small box at the top of the screen and not on the report options toolbar. Imo this should all be in the one place.

 

Also consider offering the option of SSD drives in your future UTM boxes as this would make creating reports so much quicker.

Edited by zag
Posted
Thats great news! I've found the smoothwall reporting system to be miserably slow and just about useless in real world situations where I've had to present data to our SMT members.

 

Please consider making the reports more "human readable" and in line with what school managers would want to see.

 

The user inteface also needs a lot of work, I completly missed how to change the dates on a report as it was such a small box at the top of the screen and not on the report options toolbar. Imo this should all be in the one place.

 

Also consider offering the option of SSD drives in your future UTM boxes as this would make creating reports so much quicker.

 

These are all excellent suggestions - particularly the one about the date/time when running reports. The project @ibpalle and I were working on should be released later this year. It won't address all of these points but it's a stepping stone towards it. Sometimes you have to change the fundamentals before you can make it pretty and we're working hard on getting the functionality there.

 

It would really help if you could take the time to pop your feedback into our UserVoice page as this is used by our product managers to build project scopes and user stories that our UI designer will use to build a user-friendly UI

 

Reporting: Hot (54 ideas)

  • Thanks 1
Posted

I tend to post on the Smoothwall direct support forum with lesser queries without much urgency (It is after all sponsored by Smoothwall..), I am a team of one at the school and rarely have time to spend on the phone with trivial issues and it's easier to post a quick forum post (with maybe input from other users not just Smoothwall), however the times that I have had urgency and logged / called Smoothwall the service has been excellent so that's not really the complaint.

Simple things like the firewall issue, shouldn't really be a problem but it was the interface that caused confusion - I understand what I needed to do and I just get frustrated when it doesn't work, the online documentation didn't give any examples just an explanation of each function.

 

After getting the outgoing ports thing sorted, the layer 7 app kindve works (It's stopping orbot / tor now) but other VPN traffic sails through without a problem - so I guess I'm going to have to be heavy handed and drop all ports except 80 and 443.

 

What are other manufacturers doing about application level filtering ?

Posted
I tend to post on the Smoothwall direct support forum with lesser queries without much urgency (It is after all sponsored by Smoothwall..), I am a team of one at the school and rarely have time to spend on the phone with trivial issues and it's easier to post a quick forum post (with maybe input from other users not just Smoothwall), however the times that I have had urgency and logged / called Smoothwall the service has been excellent so that's not really the complaint.

Simple things like the firewall issue, shouldn't really be a problem but it was the interface that caused confusion - I understand what I needed to do and I just get frustrated when it doesn't work, the online documentation didn't give any examples just an explanation of each function.

 

After getting the outgoing ports thing sorted, the layer 7 app kindve works (It's stopping orbot / tor now) but other VPN traffic sails through without a problem - so I guess I'm going to have to be heavy handed and drop all ports except 80 and 443.

 

What are other manufacturers doing about application level filtering ?

 

Sadly these 'get around your web filtering' applications pupils use are written to use/scan multiple outgoing ports and use whichever one they find unblocked and all too often you have a port unblocked for, say, an application update service or something and these applications jump on it. So it pays to keep outgoing stuff like that on a different subnet to the main LAN then you can set port rules by source.

 

I will pass your feedback re: the manual on to our new Technical Author as I know we are looking at the manual as a long term ongoing project so user feedback in addition to the observations of @ibpalle, me and the support team is always helpful. Don't be afraid to pop it onto uservoice either - anything related to the product is helpful. Personally I'm campaigning for popup helplets like you see on those insurance comparison websites but that's just one suggestion amongst many.

Posted (edited)
So there's really nothing that can be done about private/personal VPNs ? Its running rampant here and it's getting frustrating - I may as well not bother with filtering :( Latest apps are vpnexpress and onavo Edited by caffrey
Posted
Can you not block the applications from running? Do you use Impero or such like classroom management software?
Posted

It's BYOD and iPads, the school owned ones are MDM managed so that's not the problem - It's mainly the BYOD devices, Smoothwall on the main domain works great.

I can't even see the traffic on the realtime firewall logs

Posted
So there's really nothing that can be done about private/personal VPNs ? Its running rampant here and it's getting frustrating - I may as well not bother with filtering :( Latest apps are vpnexpress and onavo

 

Not without locking down every single outgoing port (you shouldnt need to open 80 and 443 because that goes through the proxy). The trouble with applications - Skype and iMessages seem to be the worst at this, is that they ask you to punch big fat holes in your port blocking. So it's a no-win situation. Your school wants Skype so you open all the ports it says it needs, then VPN and proxy bypass software sneak out that window (for example).

 

Software like VPNexpress won't go through the proxy anyway because it uses higher port ranges so blocking VPN applications is literally down to firewall and if you have any ports open for the subnet they're coming from then you start getting issues. I'd suggest your best course of action would be to subnet the LAN the pupils are using and lock down every single outgoing port. If this isn't feasible due to things like 'Skype' being required then I'm not sure what else to suggest. Under the 'Blocked services' in your default and applied port rules is 'VPN/Tunneling' ticked?

Posted
Sounds like I'm basically going to have to rely on the AUP for security for BYOD, everything else is managed and secure (domain network etc.) so I've no concerns, the wifi traffic is on a "guest" IP range and has no authentication (yet) so I could effectively shut down all the ports (1-65535) and see what happens ;p but it seems like it's going to be cat and mouse. It's much more of a safeguarding issue than a security issue (and I don't like hearing from 3rd parties that the students are boasting that they can get by the filter ;p)
  • 2 years later...
Posted

I'm curious, have you had any more luck?

Standard security practice says that blacklists don't work for exactly the reasons you stated: they are a global game of whack-a-mole.

So what have you done to fix the VPN and private browsing issues that you reported two years ago?

 

On my network, we use a lightspeed with strict whitelisting. If it's not on the whitelist, no-one can get at it.... including IT. (super important, we apply the same rules to IT as everyone else. It's the easiest way to find out what does not work). When I instituted this way of doing things, my team got worried about the workload of creating the white list. However, a report on the most common URLs and which computers were accessing them gave us the majority of the white list. This worked for apps as well. Net result, any outgoing connection to anything we did not approve (all those lovely VPN apps, private home VPNs, secure browsers, TOR, etc...) was just dropped.

 

We did a fair amount of tweaking in the first year, but it quickly died down. Once the webzones became stable (they weren't always) teachers stopped worrying altogether.

 

Recently several people I work with at other schools purchased Smoothwall Appliances (one an S8 and the other an S14). They have not yet set them up, but I am very interested in how this will work out. The biggest issue seems to be getting the google authentication working properly...

 

So, your feedback and thoughts after two more years of use would be greatly appreciated.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...