Jump to content

Recommended Posts

Posted

Hi Guys,

 

I've had a look through the forums but can't see anything. At the moment in our college we have a large network of Xirrus Wifi points and allow students to connect their phones, tablets, etc up to them.

 

The problem is, they have to manually input the proxy details for our filtering server to get out to the net. I've been trying to think of a way around this I could implement over summer, but WPAD doesn't seem to work well with mobile devices.

 

Can anyone think of any ideas? Or is manual entry the best way?

 

Cheers,

 

Sam.

Posted
We setup a transparent proxy for the BYOD users.

 

Its pretty easy to do on a smoothwall box

 

+1 From past experience transparent proxy is the only way to do this reliably across the multitude of devices that comes with BYOD.

Posted
We use WebMarshal and it's not at all handy for transparent proxy set-up. I agree though, that does look to be the answer. Cheers guys!
  • 2 weeks later...
Posted (edited)

I've just found this thread and thought I'd add to to:

 

We're in the same position as the OP (BYOD, Xirrus wireless). We've separated guest traffic to it's own SSID on a separate VLAN, and have configured SonicWall to act as a transparent proxy. Upstream, we have the local authority proxy, or we can also use their .pac file.

 

However, while this setup works well for http traffic, it does not work for https. (So in the eyes of the users, does not work :-/ )

 

Looking around for solutions, looks like we have 3 options:

1. Get users to enter .pac file details manually (not keen for obvious reasons)

2. Get a Smoothwall/Lightspeed box, and bring the filtering in-house (although having seen the prices, this is not a cheap option)

3. Get on an "Onborder" - Guest GTP100 | onBoarder (this look more reasonable, although I'm not sure how it works/whether it's reliable for https traffic).

 

I'll have a look at WebMarshall, but if anyone has any other idea's, I'm all ears.

Edited by Jimmer3568
Posted

Well, I only started here a month and a half ago and a week before I started we renewed our WebMarshal contract. I would avoid it like the plague in this instance. You can't set them up as transparent proxies, so the only way to use them is by manual input/PAC file and PAC files are unreliable for a lot of tablets and phones.

 

It's definitely clear that you get what you pay for with filtering systems. I think WebMarshal is on the cheap side as it lacks a lot of functionality. When it comes to our next renewal, I'll be heavily pushing for another solution such as Smoothwall!

Posted
We are wanting to implement a guest SSID over the Summer (for BYOD) and currently use Bloxx filtering. I've had a dabble with the instructions I was sent but haven't been able to set a transparent proxy on the guest VLAN :( Anybody got a simple how-to for Bloxx v7?
Posted
We are wanting to implement a guest SSID over the Summer (for BYOD) and currently use Bloxx filtering. I've had a dabble with the instructions I was sent but haven't been able to set a transparent proxy on the guest VLAN :( Anybody got a simple how-to for Bloxx v7?

 

Hi!

 

There are a couple of different ways you can configure the appliance depending on where the appliance sits in your network, the good news is that by deploying the appliance in a transparent/intercepting method of deployment you will still be able to use the appliance as a proxy for your domain machines.

 

Deployment options with a quick blurb below :) ;

 

  • Intercepting - In Line, this is where the appliance essentially acts as a bridge where you have your switch going in to your int/eth0 port and your firewall going in to ext/eth1, it will detect and filter HTTP/HTTPS traffic and push the rest on to your firewall.
  • Intercepting - Gateway, this is where your clients have Bloxx configured as their default gateway - the unit will detect and filter HTTP/HTTPS traffic and everything else will go to the default gateway that is configured for Bloxx.
  • Intercepting - WCCPv2, this is a Cisco protocol and will require Cisco equipment, you configure your Cisco Kit with WCCP that essentially pushes all port HTTP/HTTPS traffic to Bloxx for filtering. If you have multiple appliances WCCP has built-in load balancing and fault tolerance
  • Intercepting - Policy Based Routing, this is kind of similar to WCCPv2 where your layer 3 switch is configured to set the next hop for HTTP/HTTPS traffic to be Bloxx, the switch forwards the traffic to Bloxx where it will filter the requests.

 

You may need to reconfigure your identification methods as NTLM/Kerberos is not supported in a transparent/intercepting method of deployment so it would really depend how the appliance is configured.

 

If you need assistance changing the deployment let me know and I can have a support call raised and schedule in one of the engineers to give you a call to walk through/set up with you.

 

Cheers,

Grant

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...