Jump to content

Recommended Posts

Posted

I have recently been offered a job to be a network manager at another school so will soon be leaving my current post to go there!

 

The new school currently have an on-site hosted lightspeed box, which is currently being used as a proxy... Meaning that I will need to faff around with proxy servers! (Not fun)

 

At my current school, there lightspeed works with no proxy (Hosted lightspeed and firewall by @SchoolsBroadband . So my question is... Can an on-site lightspeed be setup so that it doesn't need a proxy and just absolutely everything goes through that!? Same way as we have it at my current work place!? Even though the lightspeed is internal?

 

Sorry it's a bit unclear, hopefully you get what I mean, and i know what I mean!

 

Thanks for your help in advance!

 

Matt

Posted

Hi, We have Lightspeed setup where it sits after the firewall and before the main core switch. All internet traffic has to go through this and is all monitored and filtered. It is possible and works very well, we have the agent installed on each computer which automatically captures the users AD Info when logging in to automatically authenticate against Light Speed without any proxy settings etc.

 

Matt (Cool name right)

Posted (edited)
Yes it can but if you want HTTPS inspection it needs to act as a Proxy.

We don't have a proxy, but I think when they installed it there a setting or something where it inspects the HTTPS. Not 100% sure tho, but currently runs perfect and inspects everything.

 

Found: http://files.lightspeedsystems.com/collateral/white-papers/SSL-Explained.pdf on Page 17 and 25 at bottom it says about the Decoding SSL traffic

Edited by MrFrostmaul
Posted

That's correct. Lightspeed can act as a Proxy.

 

The table at the bottom of page 25 is useful. Depending on what level of filtering / reporting you want, will determine how you need to set the Lightspeed up.

 

You can see from that table that without it running as a Proxy, the filter only gets so much information in order to make a decision.

Posted
Hi, We have Lightspeed setup where it sits after the firewall and before the main core switch. All internet traffic has to go through this and is all monitored and filtered. It is possible and works very well, we have the agent installed on each computer which automatically captures the users AD Info when logging in to automatically authenticate against Light Speed without any proxy settings etc.

 

Matt (Cool name right)

 

Awesome name!

Posted

If they have it already working as a Proxy server, why the need to remove it?

 

You don't actually need to turn it off as such. Just stop pointing the clients at the proxy IP and port. They'll then go through the transparent Lightspeed.

Posted
If they have it already working as a Proxy server, why the need to remove it?

 

You don't actually need to turn it off as such. Just stop pointing the clients at the proxy IP and port. They'll then go through the transparent Lightspeed.

 

Ill need to do some more research, but i just hate having to faf around with putting in proxies!

Posted
We run the rocket as a transparent filter using the ip ranges to apply different levels of filtering,also as part of our wifi auth

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...