Jump to content

Recommended Posts

Posted

Hi All

 

We are an FE College using a combination of an SonicWALL NSA5600 firewall and the web filtering module within Sophos AV to provide filtering on our Windows network. As we are seeing an increasing use of SSL, we are now considering the use of SSL-DPI to monitor encrypted communications. Our primary motivation is to improve security and monitoring of web use on managed and unmanaged (guest) devices and ensure we can properly block malicious/undesirable content. Has anyone done something similar, and if you have, what issues did you encounter?

 

I’m also keen to hear what the community are doing with their firewall and monitoring systems in general and how they communicate this out to users (those who complain about privacy violations, etc).

 

hope you can help

 

cheers!

Posted (edited)

We also use a Sonicwall with our VLANS to achieve this. Although we have used our Ruckus wireless to create a segregated Guest SSID which can't communicate with the other VLANs (although you could achieve this through the use of ACLs).

 

The only issue with the SonicWall is the limited reporting functions (as this is what Ofsted like to see) - however I have recently come across FastVue for SonicWall which is a great reporting tool (much better than the Analyzer product).

 

By default we have configured our Guest and BYOD to the strictest levels of content filtering - fortunately we don't have many devices brought in, so the blanket function works well. However if you wanted to give granular access through your Guest or BYOD you'd have to give them credentials to authenticate against the Sonicwall SSO to give the correct access or have several Guest/ BYODs for different departments.

 

As for communicating it - it's all part of the acceptable usage policy which they have to agree to when the hit they guest portal.

 

Hope this helps.

Edited by Techie2000
Posted
We also use a Sonicwall with our VLANS to achieve this. Although we have used our Ruckus wireless to create a segregated Guest SSID which can't communicate with the other VLANs (although you could achieve this through the use of ACLs).

 

The only issue with the SonicWall is the limited reporting functions (as this is what Ofsted like to see) - however I have recently come across FastVue for SonicWall which is a great reporting tool (much better than the Analyzer product).

 

By default we have configured our Guest and BYOD to the strictest levels of content filtering - fortunately we don't have many devices brought in, so the blanket function works well. However if you wanted to give granular access through your Guest or BYOD you'd have to give them credentials to authenticate against the Sonicwall SSO to give the correct access or have several Guest/ BYODs for different departments.

 

As for communicating it - it's all part of the acceptable usage policy which they have to agree to when the hit they guest portal.

 

Hope this helps.

 

this is very similar to the way we've configured our guest network with the Ruckus ZD. Do you have SSL-DPI enabled?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...