CSmith Posted February 10, 2017 Posted February 10, 2017 (edited) Its not brilliant at everything. Its basic web filtering is not great -and probably uses little more than the "free" guardian stuff. I had to add several URLS to get it to handle facebook and instagram correctly (you would have thought they would be all over this kind of stuff)....and I've seen it let through stuff websense blocked. Of course it has no real time web content analysis to speak of. Its user interface is clunky. Its layer 7 visibility really needs a lot more input on their part to get anywhere the visibility you get - say with Meraki's wireless stuff. Hey @AlanD - Are you making use of HTTPS Decrypt and Inspect? If not I would encourage you to set up a HTTPS D&I policy which should greatly improve our filtering. Just to clear up a few points you've raised Its basic web filtering is not great - and probably uses little more than the "free" guardian stuff. We actually have an inhouse categorisation team of four (of which I'm a member) who are responsible for ensuring our blocklist is up to date with the latest threats - if you ever come across something that's incorrectly categorised then you can let us know through our feedback service (https://uk.smoothwall.com/provide-blocklist-feedback/) I had to add several URLS to get it to handle facebook and instagram correctly We have a 'Facebook' category which should contain all the domains and URLs used by Facebook - simply allowing or blocking this category as nescessary should have you covered. We don't have one for Instagram at the moment but we are looking to increase the number of services we have categories for in the future. Of course it has no real time web content analysis to speak of For any requested URL which we do not categorise by domain or URL we will run against our dynamic content analysis rules to try and identify what type of content it is. For best results you should ensure that you have a HTTPS Decrypt & Inspect policy set up - without it we can only scan standard HTTP traffic. If you have any questions then feel free to leave a comment here or PM me directly Chris Edited February 10, 2017 by CSmith Formatting improvements
ridleyrumpus Posted February 10, 2017 Posted February 10, 2017 Despite following the SW guide we still cannot get YouTube filtering to work correctly. We thought we had it when IE would filter, but then found that Chrome would allow anything to play.
CSmith Posted February 10, 2017 Posted February 10, 2017 Despite following the SW guide we still cannot get YouTube filtering to work correctly. We thought we had it when IE would filter, but then found that Chrome would allow anything to play. Hi @ridleyrumpus - Sounds like it might be related to QUIC - Ensure your firewall is blocking UDP port 443 or you have the 'Remove QUIC Header' content modification applied to 'Everything' (You'll need a HTTPD D&I policy set up if you go for this option!). Chris 1
KibosJ Posted February 10, 2017 Posted February 10, 2017 Hi @ridleyrumpus - Sounds like it might be related to QUIC - Ensure your firewall is blocking UDP port 443 or you have the 'Remove QUIC Header' content modification applied to 'Everything' (You'll need a HTTPD D&I policy set up if you go for this option!). Chris Been messing with this for days trying to get it to work! Remove QUIC Header was applied, but it was still allowing access to youtube, blocked UDP 443 and it works now Thanks.
CSmith Posted February 10, 2017 Posted February 10, 2017 Been messing with this for days trying to get it to work! Remove QUIC Header was applied, but it was still allowing access to youtube, blocked UDP 443 and it works now Thanks. Haha excellent stuff! QUIC is a bit of a nuisance unfortunately - glad to see you've got it working
Wave9_Lee Posted February 10, 2017 Posted February 10, 2017 I know this is a smooth wall topic but I've been quoted over 6K to renew our sophos UTM 430SG (I think) (hardware) we are using FULL GUARD and I'm just a bit unsure about the price am I being quoted right? Hi Kevin, If you can PM me your contact details, I'd be happy to provide you with a benchmark price, Kind regards Lee
kevin_lane Posted February 10, 2017 Posted February 10, 2017 (edited) Thanks Edited February 12, 2017 by elsiegee40
AlanD Posted February 12, 2017 Posted February 12, 2017 (edited) Thanks (I think) for the challenges to my statements, Yes we use HTTPS decrypt....although I seem to have add sites daily to bypass it (or at least by pass the authentication requirement - not sure why you need to add them because the rest of browsing works OK - and its authenticated for that to work) in order to work - especially for mobile devices (its not quite so bad for desktops). All the social media stuff needs to work for staff (or I get lynched) and it needs to work on mobile devices. You might think that ticking to allow social media would do the trick - but you soon discover that you need to do some others like allowing unmoderated sites - or creating your own category - and manually entering sites - because things like Twitter don't work otherwise. I confess I wasn't aware of the dynamic real time filtering - which probably explains why some sites for blocked - then later seem to be allowed. It wasn't something I felt was terribly important when comparing solutions (as there is always going to be some stuff let through). Parent Pay was the last thing that I couldn't get to work - worked all the way until you actually got to the point of making a payment. Nothing appears as "blocked" for the user - it just doesn't work. I still think its probably the best product out there at the moment - despite some criticism of it (and overlooking the price - which is not easy). Believe me - I would be more critical of lots of the other stuff out there - most of which don't seem to even know what the prevent strategy is asking us to do. And yes - I'd like clearer view of Layer 7 traffic (Every web filter can filter http/https - the up and coming problem is to monitor and control what other apps are doing using other ports) Edited February 12, 2017 by AlanD
CSmith Posted February 13, 2017 Posted February 13, 2017 Thanks (I think) for the challenges to my statements, Yes we use HTTPS decrypt....although I seem to have add sites daily to bypass it (or at least by pass the authentication requirement - not sure why you need to add them because the rest of browsing works OK - and its authenticated for that to work) in order to work - especially for mobile devices (its not quite so bad for desktops). All the social media stuff needs to work for staff (or I get lynched) and it needs to work on mobile devices Mobile applications are proving to be quite a pain at the moment - more and more of them are using certificate pinning which means any attempt to decrypt the traffic by the Smoothwall results in the application throwing a bit of a fit. Would you be able to PM me details of any specific apps you've had problems with? We're currently investigating a few different methods of resolving this problem so any input you could provide would be much appreciated.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now