AlanD Posted March 31, 2017 Posted March 31, 2017 "Don't really want to be tied MDM side of things.." Are you saying you don't use an MDM? How do you deliver APPs to these? Why wouldn't you use a MDM? I don't see why Light speed could not filter/monitor - but you might need to enforce a proxy setting or something which would be difficult without an MDM. I don't see why it would have to be LightSpeed's MDM.... a free one would probably be fine. I would be surprised if Lightspeed could not deliver a captive portal page to identify the user....or perhaps if you are primary...can't be with 100Mb leased line....that would be silly. The current problem with iPads is that it is increasingly difficult to monitor anything on them. You can no longer monitor what is typed (into search, or email, or even pages)....so meeting the prevent strategy - which requires us to monitor (rather than filter/block) is almost impossible. And increasingly iPad apps prevent any kind of inspection with certificate pinning and the like which makes man in the middle observations difficult if not impossible even for sophisticated filters with enforced certificate use. This is probably why Link2ICT has its own browser I suspect.
paulhowes Posted March 31, 2017 Posted March 31, 2017 Currently manage these devices using Apple Configurator 2, looking into an MDM but as always comes down to cost!! From what i read there may be better options out there than Lightspeed's Mobile Manager, and as such didn't want to be tied into only being able to use this if we did get funding. Also though i wondered if browsing history on iPads (browsed websites) can still be achieved without the MDM if the school continue to manually mange iPads using Apple Configurator 2 thanks
AlanD Posted March 31, 2017 Posted March 31, 2017 I don't use it - but Google for Education has an inclusive "free" MDM - and I think there are others - including Apple's own "profile Manager" - which again is free (but no, I don't use it). There are lots of benefits of using an MDM - to start with you can just deliver apps and updates over the air without having to plug them back into configurator. You can allow use of a single app only (on the fly). So you definitely need to get an MDM sorted. Browsing history...doesn't give you much of a picture....do you stop them putting it into "private" browsing mode? You get no idea of what they typed into any search engine - or into any website.... and increasingly some web pages won't work with man in the middle monitoring. Difficult to see how you could say you were meeting the prevent strategy.
Jehanzeb Posted March 31, 2017 Posted March 31, 2017 By sounds of it you need a robust filtering service and then pass all traffic through it, you will lose some throughput speed but everything will be filtered (wireless and wired devices). With regards to having it free, profile manager with classroom app from Apple will achieve your goal (depending on iPad gen). If you want to go further step (paid service) then look at Meraki, ZuluDesk, Jamf MDMs. We use inHouse Smoothwall and all our wireless devices filters through it and for students taking devices home get proxies through our filter when offsite. We were also lucky to have free Meraki MDM and iPads are manage via this Mdm. Kindest regards J.
AlanD Posted April 1, 2017 Posted April 1, 2017 I feel that we filter and the prevent strategy are used as another way to raid the funds of schools. To filter the internet...you can do it for £40 a year with a dns filter on a draytek router, or for free with pfsense. It comes included with sophos protection...without buying their UTM. But when you start to want reporting and filtering...and you need it to work withmobile devices...and few products are actaully customised in any useful way to meet the prevent strategy - smoothwall is to some extent. You'd expect whe delivered to a school you tick a school configuration...and you go to an exam board ..and will it download an exam paper. No ..not without creating a rule of it. You tick a box to allow social media for staff..and on the desktop it works..but it doesn't work on any mobile device..unlesss you write more rules...usually ones to bypass inspection..so you can no longer monitor them. Up and down the similar rules are being written every day in every school. You might imagine that filter suppliers to schools would be harvesting these changes and using them to build a better more customised product for schools...but it's seems to me they are just taking the money and running. 1
Jehanzeb Posted April 1, 2017 Posted April 1, 2017 I feel that we filter and the prevent strategy are used as another way to raid the funds of schools. To filter the internet...you can do it for £40 a year with a dns filter on a draytek router, or for free with pfsense. It comes included with sophos protection...without buying their UTM. But when you start to want reporting and filtering...and you need it to work withmobile devices...and few products are actaully customised in any useful way to meet the prevent strategy - smoothwall is to some extent. You'd expect whe delivered to a school you tick a school configuration...and you go to an exam board ..and will it download an exam paper. No ..not without creating a rule of it. You tick a box to allow social media for staff..and on the desktop it works..but it doesn't work on any mobile device..unlesss you write more rules...usually ones to bypass inspection..so you can no longer monitor them. Up and down the similar rules are being written every day in every school. You might imagine that filter suppliers to schools would be harvesting these changes and using them to build a better more customised product for schools...but it's seems to me they are just taking the money and running. I share exact feeling, I had a brief discussion with one of our teacher and the concerns were similar as you described above. Filtering is hindering teacher's work and so teaching staff wants unfiltered access but then how would you monitor/prevent strategy with staff? Constant monitoring and change of rules consume so much of our time, not everyone is dedicated monitoring manager in Schools. More often than less, staff in Schools have multiple job areas, not just one. Regards J.
Saladin Posted April 3, 2017 Posted April 3, 2017 I am in the same positon current favourite seems to be Censornet - any views from anyone? We have used Censornet for over 3 years now and are extremely pleased with the service. We recently asked them about PREVENT and they suggested a different service they offer, which we have now transitioned over to, from "Web Filtering" to "Unified Security Service" Support has always been top drawer and the product has never let us down.
w00dy01 Posted April 5, 2017 Posted April 5, 2017 We use a product called Iceni by Opendium. It is a great product, it has great support and most importantly a great price. Definitely worth a look if you're considering switching! 2
muppet Posted April 5, 2017 Posted April 5, 2017 Another one for i-Boss here. Great product and support is absolutely fantastic.
jonnykewell1 Posted April 7, 2017 Posted April 7, 2017 I'm trying to setup the tunnel to the Iboss cloud but virgin need the Encryption, Authentication and DH group numbers. Does anyone know if there are Iboss defaults for this? I have mine set as aes128, sha256 and Group 5 respectively. These settings are not specified in the Iboss cloud settings and support isn't getting back to me at the minute with an answer.
nicholab Posted April 7, 2017 Posted April 7, 2017 How have people setup their guest networks and the Sophos UTM?
ping Posted April 17, 2017 Posted April 17, 2017 (edited) I'm going through the same exercise. I've been using Lightspeed for about 5 years now and it's worked, and support has been great, but overall the web and content filtering isn't what it was when I started 5 years ago. Here is what I've found so far: Lightspeed's appliance does a fairly good job and now that Longhorn is out, the filter does behave better. I still need to proxy iOS devices because they tell me Apple won't allow them to redirect pages with their mobile filter client for iOS. That's a problem. What's more is that I have to run an open proxy because any type of proxy security, even the most basic breaks a lot of stuff. Lightspeed knows this and hasn't seemed to solve either issue...one has been ongoing for almost a year. Lightspeed's cloud based filter seem really neat, it too can authenticate to a Google domain which is preferred IMHO if you are a Google shop. The downside is that they (Lightspeed) were smart enough to have proxy security, but unfortunately the issues with iOS and secure proxy is still an issue, so then you are left with the mobile filter app for iOS and guess what--- the same limitations are still an issue. Lightspeeed seems to think I'm a good candidate for their "hybrid" setup part local appliance, part cloud. Haven't tested it yet, so can't say much about it. Overall Lightspeed has been fairly responsive and the support has been good. Price is comparable to other offerings out there. Securly. Really neat filter, some pretty interesting features too. However, and I verified this with another school that uses it, the URL categorization is unlike anything you've used before, which means in primary education where we tend to have a bit more restrictions for the younger kids, you'll spend a lot of time adjusting the filter to meet your needs. This is normally the case with any web filter change, but Securly's would be about 5x or more comparatively. I was thinking about Smoothwall or just staying another year with Lightspeed to see if improvements to their current issues get resolved. My needs are: Filter that uses AD or Google authentication Off-site filtering for school owned devices (iOS and MacOS)-- prefer not to proxy Possible future Chromebook deployment You'd think that small of a list would be an easy target to hit, but if you'd shopped for web filters, you know that no one has the magic recipe. Each one does a few great things and a few not so great, which is why I'm thinking I may stay as I am one more year to see what shakes out. Edited April 17, 2017 by ping
AlanD Posted April 18, 2017 Posted April 18, 2017 If you mean "no authentication" - when you say "open proxy" - then that presumably means you have no way to monitor who goes to what web site. That would - in my understanding - not meet the requirements of the prevent strategy - where "monitoring" by user is probably more important than filtering - if we are to track violence/hate/selfharm/radicalisation etc. If you were to run the iPads on a separate (wireless) VLAN - which I assume you are not doing - then you could make he gateway address be lightspeed. It would then not be necessary to use a proxy...and you could use a captive portal to authenticate. It sounds as if lightspeed is as useless as smoothwall when it comes to mobile devices - because inspecting authenticated https traffic breaks lots of standard stuff....and by the time you rewrite all the necessary rules and exceptions you wonder what you were paying for. ...but smoothwall is quite good at reporting for "prevent" - but only quite good - because you don't get the ability to tailor those reports as you can with normal reports. ...I'm pretty certain there would be no way to do off-site filtering without a proxy - unless there is some kind of "app" or bespoke web browser in the device.
ping Posted April 18, 2017 Posted April 18, 2017 (edited) It just means that there are no ways to authenticate the user to the filter itself so that no one could do some sort of DOS as the box would respond to anyone on the assigned port at it's address. These are two separate authentications from what I understand. Outside of open proxy, the best I had with it at one point was only talk to iOS and Chrome devices before that too broke and forced me to have it open. The captive portal still works for filtering and I still have full visibility to sites users visit. I don't think running a separate VLAN for iPads is the answer because the PAC and cert files that are installed on all school owned iOS devices routes the traffic through the filter....moreover, I'm not sure how setting up iPads on a separate VLAN would help when at home since the PAC file and certificate files deal with the routing all traffic to the filter regardless of user location. In the somewhat perfect world, the LS mobile client for iOS would allow page redirects and manual user authentication, but according to LS, Apple does not currently allow it (which if true is just another gripe I have with Apple making it difficult to manage iOS devices). In that somewhat perfect world, we'd not have to proxy traffic back through out internet pipe, but I think you are right that for now proxy is it.....however Securly seems to have gotten around the Apple restriction by doing DNS redirect as there are no iOS clients, so I'm not sure if that's just LS doing the blame game or not since it's pretty clear to me that LS has lost the edge it once had over the competition. IMHO, it seems that they are playing a lot of catch up....and in talking with like of Smoothwall and Securly, it seems that some of the features they have really are making LS up it's game, unfortunately it may just dictate that I should stay in hover mode for another year to see how things shake out. One important note is that my MacOS laptops I don't proxy at all, I have the LS mobile filter agent and though it's a PITA to make sure the MAC addresses are in the Device Registration Portal LS has set up, it does filter the Mac OS users as expected when off-site. When internal the local agent runs and automatically ties into my LDAP box and the solution does seem to play nice switching between the mobile client and local agent as needed. Why that can't work with iOS the same way, I don't fully understand. Thanks for the info on Smoothwall. I thought they too had a client, but again, if what LS is telling me it's an Apple restriction. Edited April 18, 2017 by ping
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now