Koldov Posted February 11, 2016 Posted February 11, 2016 Hi All, I'm going to have to deal with this very soon and wondered if there is anyway I can get around it for shared machines (used by both pupils and staff)? Also that, a WiFi VLAN with a certain range of addresses is used by both staff laptops and student iPads... Kol.
twin--turbo Posted February 11, 2016 Posted February 11, 2016 Hi All, I'm going to have to deal with this very soon and wondered if there is anyway I can get around it for shared machines (used by both pupils and staff)? Also that, a WiFi VLAN with a certain range of addresses is used by both staff laptops and student iPads... Kol. I think we need more information to go on. Filtering of what to where? TT
Koldov Posted February 12, 2016 Author Posted February 12, 2016 Yes, sorry - bit vague! At the moment our internet connection is content filtered (via a proxy server) and different levels of filtering are provided by way of GPO pointing to the relevant proxy server depending who is logging on. We are changing to a new provider and on a basic level, I believe that the filtering is done depending on the IP of the machine... I'm just not sure that's a workable solution. does anybody else use this? Kol.
Blue_Cookeh Posted February 12, 2016 Posted February 12, 2016 Yes, sorry - bit vague! At the moment our internet connection is content filtered (via a proxy server) and different levels of filtering are provided by way of GPO pointing to the relevant proxy server depending who is logging on. We are changing to a new provider and on a basic level, I believe that the filtering is done depending on the IP of the machine... I'm just not sure that's a workable solution. does anybody else use this? Kol. That sounds like a complete PITA. At a minimum I'd expect AD group filtering or how you're currently doing it with GPOs. Most suppliers should be able to do one of these for you...
Koldov Posted February 12, 2016 Author Posted February 12, 2016 Not sure how else to deal with it... It's an LgFL/TRUSTnet/Atomwide thing... WEBSCREEN 2.0... Kol.
twin--turbo Posted February 12, 2016 Posted February 12, 2016 On premesis filtering with AD auth and grouping is the way to go. Even if its a free solution like dansguardian, will give you much greater control. 1
Blue_Cookeh Posted February 15, 2016 Posted February 15, 2016 On premesis filtering with AD auth and grouping is the way to go. Even if its a free solution like dansguardian, will give you much greater control. I like this. You could even just use Squid to forward users to your county's proxies depending on Group if they use different IPs.
twin--turbo Posted February 15, 2016 Posted February 15, 2016 I like this. You could even just use Squid to forward users to your county's proxies depending on Group if they use different IPs. Indeed, I implemented squid ~1999, and supplemented with squidguard later on.
plexer Posted February 15, 2016 Posted February 15, 2016 To provide effective filtering these days you should be employing real time page analysis and include https decryption within your proxy solution. Ben
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now