caffrey Posted May 22, 2014 Posted May 22, 2014 (edited) 3g shouldn't be a problem as mobile phone reception is so poor here but you're right I can't stop that. The site is blocked as it should be with the right category, it's the app that still works - I'll play about with it today update, app isn't working now (has something changed recently?) but it still works of course with a personal VPN like onavo Edited May 22, 2014 by caffrey
OB1 Posted May 22, 2014 Posted May 22, 2014 3g shouldn't be a problem as mobile phone reception is so poor here but you're right I can't stop that. The site is blocked as it should be with the right category, it's the app that still works - I'll play about with it today update, app isn't working now (has something changed recently?) but it still works of course with a personal VPN like onavo That's down to firewall policy. Close ports you don't need, that's your best bet.
caffrey Posted May 22, 2014 Posted May 22, 2014 Yes but the vpn apps can port hop I believe, so if I open any they will just use that ?
OB1 Posted May 22, 2014 Posted May 22, 2014 Yes but the vpn apps can port hop I believe, so if I open any they will just use that ? They do, but mainly on high ports. If you've got services that use high ports you can restrict those ports to specific IPs or ranges. PM me some examples of the apps you've seen if you want to. We'll have a look into onavo but generally take a 'broad strokes' approach to specific apps, and improving firewall policy is usually the first port of call.
caffrey Posted May 23, 2014 Posted May 23, 2014 (edited) I don't have a definitive list of apps that are being used as I get no reports from the field except for reports that the students are using VPNs, so instead of enforcing the AUP they come to the fun police (us) to sort it out And of course I'm totally blind to this traffic. We can't use the MDM to list apps as they are BYOD and have no profiles installed, the iPads we do have MDM on and allow users to install apps, you can list those apps but you can only remove apps that were installed by the MDM (not the end user - which is another annoyance...) I'll play around with ports over half term as its a bad time of year to be messing with filtering. Lightspeed isn't a firewall - how is it they can block applications ? Edited May 23, 2014 by caffrey
Howell Posted July 2, 2014 Posted July 2, 2014 We currently using Lightspeed as our MDM, our iPads are 1:1 and supervised devices with the layered ownership model. During school time, the web is filtered using the Lightspeed Rocket, after school we have an out-of-hours policy with that's less restrictive, so it allows Facebook, Twitter etc.. and we have the Global Proxy profile added so they have to authenticate through our Rocket. This also stops them creating a mobile hotspot from their phones at school, attempting to bypass our f. Most websites work fine, but some apps such as Snapchat, Instagram and a few others are still being blocked somewhere, whether it's the Rocket or our Firewall, dunno!We actually want to unblock these apps on their iPads, so they will work whilst the kids are at home.
seawolf Posted July 2, 2014 Posted July 2, 2014 If whatever is going on is blocking the Snapchat App on iOS, please let us all know how it's being done once you figure it out. That is what we are trying to accomplish here.
caffrey Posted July 3, 2014 Posted July 3, 2014 Which firewall ? I blocked all ports going out and stopped a lot of traffic but then skype came along and put a stop to that.
OverWorked Posted January 30, 2015 Posted January 30, 2015 Has anyone got a solution to this yet? Any way of blocking the app without disrupting legitimate Google/Skype services? The snapchat app has just flared up here too. I'm using Smoothwall and Ruckus wireless.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now