Jump to content

Recommended Posts

Posted
Anyone got a list of plus and minuses for each of these? Experience etc. ?

 

We've had an on-site Lightspeed Rocket device for the poast three years. Filtering performance is good, it seems to block most things you would expect and leave most sites you would want unblocked. You don't have to set the device up as your gateway, it actually filters traffic as it passes through, completly transparently. Forign language sites tend to be poorly catagorised, though, and the process of unblocking a site can be a bit fiddly. Support from Lightspeed has been excellent - they have proper, knowlagable people you can talk to and we've just had an email off them saying that their remote monitor has spotted a potential future issue with our hardware's RAID controller's battery, so they're sending us a new one. That's how support should work - the part turns up before you even know you needed it. It is a bit pricy compared with some other options, although comparable in price to Bloxx and Smoothwall.

  • Thanks 1
Posted

you can do a man in the middle attack on all traffic, proxy all SSL traffic or proxy SSL traffic to certain destinations only.

 

it's very good. We've deployed it in a hosted environment to over 1,000 schools now and can't recommend it enough. PM me if you want a price as hosted is a lot cheaper to onsite with little difference in functionality.

 

Thanks

 

Dave

  • 2 weeks later...
Posted

Lightspeed offers the following SSL methods:

 

1. Block all SSL traffic

2. Block/Allow the traffic based on the SSL cert or TLS SNI data (if available)

3. Decrypt all SSL traffic on the proxy

 

As many sites are starting to enforce SSL (such as Google removing the NOSSL servers last month), this means there is a lot of potential traffic for the proxy server method used for Man in the Middle SSL decryption, negating some of the speed benefits of operating as a Layer 2 network bridge. With LS, if you wish to filter on Google searches (pretty mandatory) it means that you need option 3.

 

Iboss offers all of these methods, but crucially also has a patent around selective SSL decryption, for example filtering based on SSL/TLS (as in 2), but then fully decrypting certain sites (I.e. Google.*). In order to achieve this with LS, they have to employ and additional third party loadbalancer device to selectively route specific SSL traffic to a separate proxy.

 

See Page 17: http://files.lightspeedsystems.com/collateral/white-papers/SSL-Explained.pdf

Posted (edited)

For anybody who is considering iBoss vs Lightspeed I have tested both extensively on a 100Mb/s line with ~1,500 users.

 

Our old appliance was a SonicWALL NSA 3600 but SSL traffic was starting to cause an issue on our line as DPI-SSL can only inspect over 1 CPU core.

 

We had an iBoss running inline for a week but it simply couldn't cope with SSL inspection on all traffic (this is our default preference) - even when selective. iBoss support worked on a number of fixes but the CPU usage was simply through the roof and when any of the cores peaked at 100% we would see all connections dropped.

 

The unit would crash and drop all connections each time it peaked at ~70Mb/s;

 

iboss-70.JPG

 

We ended up going for a Lightspeed Rocket. It seems to run fine although it is configured as a proxy server as it cannot go in-line natively but the ease of use and reporting make up for this and I believe the next major build may support transparent in-line (please?!).

 

Just my experience, feel free to give me a PM. We have had Smoothwall, Lightpseed, iBoss and SonicWALLS run live traffic for us.

Edited by DSP
Posted (edited)

Hi DSP,

 

We are sorry you found these results during your iboss testing. Scaleability and specifically handling of SSL/TLS is something that iboss are noted for. I would suggest that this may have been a configuration issue or even a faulty appliance. A standard iboss appliance can run at 1GB wire speed, and support up to 10,00 devices/ 4 million sessions, and we have several thousand of them in the field.

 

Thinking about your issues, we always try to avoid running in proxy mode and when you were inline it sounds like you experienced a duplex mismatch - To be fair we should have picked up on this.

 

Finally your box was installed by a new partner who had yet to go through our certified training. While they are technically capable, any sort of invasive tech like a web filter has many options and thus potential to cause issues if configured incorrectly. Lessons learned!

 

Thanks for considering us, and wishing you the best.

 

Richard

Edited by rpmoore

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...