Jump to content

Recommended Posts

Posted (edited)
Its not brilliant at everything. Its basic web filtering is not great -and probably uses little more than the "free" guardian stuff. I had to add several URLS to get it to handle facebook and instagram correctly (you would have thought they would be all over this kind of stuff)....and I've seen it let through stuff websense blocked. Of course it has no real time web content analysis to speak of. Its user interface is clunky. Its layer 7 visibility really needs a lot more input on their part to get anywhere the visibility you get - say with Meraki's wireless stuff.

 

Hey @AlanD - Are you making use of HTTPS Decrypt and Inspect? If not I would encourage you to set up a HTTPS D&I policy which should greatly improve our filtering.

 

Just to clear up a few points you've raised

 

Its basic web filtering is not great - and probably uses little more than the "free" guardian stuff.

We actually have an inhouse categorisation team of four (of which I'm a member) who are responsible for ensuring our blocklist is up to date with the latest threats - if you ever come across something that's incorrectly categorised then you can let us know through our feedback service (https://uk.smoothwall.com/provide-blocklist-feedback/)

 

I had to add several URLS to get it to handle facebook and instagram correctly

We have a 'Facebook' category which should contain all the domains and URLs used by Facebook - simply allowing or blocking this category as nescessary should have you covered. We don't have one for Instagram at the moment but we are looking to increase the number of services we have categories for in the future.

 

Of course it has no real time web content analysis to speak of

For any requested URL which we do not categorise by domain or URL we will run against our dynamic content analysis rules to try and identify what type of content it is. For best results you should ensure that you have a HTTPS Decrypt & Inspect policy set up - without it we can only scan standard HTTP traffic.

 

If you have any questions then feel free to leave a comment here or PM me directly :)

 

Chris

Edited by CSmith
Formatting improvements
Posted
Despite following the SW guide we still cannot get YouTube filtering to work correctly. We thought we had it when IE would filter, but then found that Chrome would allow anything to play.
Posted
Despite following the SW guide we still cannot get YouTube filtering to work correctly. We thought we had it when IE would filter, but then found that Chrome would allow anything to play.

Hi @ridleyrumpus - Sounds like it might be related to QUIC - Ensure your firewall is blocking UDP port 443 or you have the 'Remove QUIC Header' content modification applied to 'Everything' (You'll need a HTTPD D&I policy set up if you go for this option!).

 

Chris

  • Thanks 1
Posted
Hi @ridleyrumpus - Sounds like it might be related to QUIC - Ensure your firewall is blocking UDP port 443 or you have the 'Remove QUIC Header' content modification applied to 'Everything' (You'll need a HTTPD D&I policy set up if you go for this option!).

 

Chris

 

Been messing with this for days trying to get it to work! Remove QUIC Header was applied, but it was still allowing access to youtube, blocked UDP 443 and it works now :) Thanks.

Posted
Been messing with this for days trying to get it to work! Remove QUIC Header was applied, but it was still allowing access to youtube, blocked UDP 443 and it works now :) Thanks.

 

Haha excellent stuff! QUIC is a bit of a nuisance unfortunately - glad to see you've got it working :)

Posted
I know this is a smooth wall topic but I've been quoted over 6K to renew our sophos UTM 430SG (I think) (hardware) we are using FULL GUARD and I'm just a bit unsure about the price am I being quoted right?

 

Hi Kevin,

 

If you can PM me your contact details, I'd be happy to provide you with a benchmark price,

 

Kind regards

 

Lee

Posted (edited)

Thanks (I think) for the challenges to my statements, Yes we use HTTPS decrypt....although I seem to have add sites daily to bypass it (or at least by pass the authentication requirement - not sure why you need to add them because the rest of browsing works OK - and its authenticated for that to work) in order to work - especially for mobile devices (its not quite so bad for desktops). All the social media stuff needs to work for staff (or I get lynched) and it needs to work on mobile devices. You might think that ticking to allow social media would do the trick - but you soon discover that you need to do some others like allowing unmoderated sites - or creating your own category - and manually entering sites - because things like Twitter don't work otherwise. I confess I wasn't aware of the dynamic real time filtering - which probably explains why some sites for blocked - then later seem to be allowed. It wasn't something I felt was terribly important when comparing solutions (as there is always going to be some stuff let through). Parent Pay was the last thing that I couldn't get to work - worked all the way until you actually got to the point of making a payment. Nothing appears as "blocked" for the user - it just doesn't work.

 

I still think its probably the best product out there at the moment - despite some criticism of it (and overlooking the price - which is not easy). Believe me - I would be more critical of lots of the other stuff out there - most of which don't seem to even know what the prevent strategy is asking us to do. And yes - I'd like clearer view of Layer 7 traffic (Every web filter can filter http/https - the up and coming problem is to monitor and control what other apps are doing using other ports)

Edited by AlanD
Posted
Thanks (I think) for the challenges to my statements, Yes we use HTTPS decrypt....although I seem to have add sites daily to bypass it (or at least by pass the authentication requirement - not sure why you need to add them because the rest of browsing works OK - and its authenticated for that to work) in order to work - especially for mobile devices (its not quite so bad for desktops). All the social media stuff needs to work for staff (or I get lynched) and it needs to work on mobile devices

 

Mobile applications are proving to be quite a pain at the moment - more and more of them are using certificate pinning which means any attempt to decrypt the traffic by the Smoothwall results in the application throwing a bit of a fit. Would you be able to PM me details of any specific apps you've had problems with? We're currently investigating a few different methods of resolving this problem so any input you could provide would be much appreciated.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...