DCUK6 Posted March 31, 2015 Posted March 31, 2015 Have a proxy that all internet traffic must go though. Looking for a solution that doesnt require a extra certificate as the LEA's proxy already needs one. They have tried using WCCP on their Cisco switches which worked without a extra certificate for HTTPS but overloaded the switch with data from several schools. Is there a Netgear equivalent to WCCP? We have some GS748T's Thanks. Dan
m25man Posted April 2, 2015 Posted April 2, 2015 This is a proprietary Cisco Protocol Web Cache Communications Protocol and is present on several $$$ Cisco Routers and some Cisco switches. Some ISPs provide cacheflow servers which do the same job. This is a Cisco only feature. The closest similar function you are likely to find on some high end non Cisco routers and switches is PBR, Policy Based Routing. This can route between VLANs based on policies such as source - destination IP and protocol. Eg. BYOD IP on port 80/443 Vlan x route to web appliance IP/port on Vlan y To perform such tasks at Layer 3 requires significant processing speed and power and throughput capability not normally seen on budget hardware such as Netgear. The primary task of a switch is switching, once you start to use a switch for routing you can use up resources very quickly. Generally people who buy Netgear have no need for these high end features and those that do would have bought Cisco anyway for that reason. You really can't compare a Fiat Panda with a Veyron. Also consider that implementation of such packet header modification is likely to break many other services that are subsequently NATTED. Web stuff may work but the likelihood of other stuff like sip & H323 etc is dead in the water Eg. They can login to Skype but not make any calls. But this may not be an issue if these are BYOD clients. You may want to consider using a dedicated router to do your BYOD routing instead of trying to do it at switch VLAN level. A cheap Mikrotik sitting in between your BYOD network and your gateway devices might give you the control your looking for. 1
DCUK6 Posted April 2, 2015 Author Posted April 2, 2015 (edited) Thanks M25man, Very helpful. Yeah looking at Cisco switches with WCCP, cost a few £££ Will have to continue with trying out smoothwall/pfsense, possibly putting BYOD traffic through the LEAs non HTTPS proxy. Wont block HTTPS but better than nothing. We have brought up with the LEA that when their contract with Sophos ends next year could they look look one that could have a server on our site with transparent access. Edited April 2, 2015 by DCUK6
Michael Posted April 2, 2015 Posted April 2, 2015 As above, WCCP is a Cisco invention as it were. You may be able to get it on other switches, but again you're talking a lot of money. Many LAs and other Educational providers have decided that packet inspection on secure traffic being necessary, but to be honest (as you've demonstrated), it doesn't take much traffic to cause an overload. I call it trying to win a losing battle, considering more websites everyday are implementing an SSL certificate. It would be interesting to know whether or not you can opt out of such a service - surely you as a school should be able to choose whether you want secure packet inspection, on the likes of Google searches for example? Seems a lot of work/hassle and the situation will only get worse once encryption algorithms become even more complex taking longer to unencrypt.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now