Jump to content

Recommended Posts

Posted

Hi,

 

 

 

Can anyone shed any light on whether there is a difference between using an 'Allow' policy for a Category Group versus 'not blocking it'?

 

For example, is there a benefit or otherwise if I 'Allow' Online Banking for 'Staff' explicitly, over not including it in the 'Block' list?

 

Thanks,

Posted (edited)

Not sure I quite understand the question, but if I have grasped it:

 

- Allow will let something through as long as it passes all other checks (bad words etc)

- Block stops it getting through

- Whitelist prevents any processing happening and waves the site through

- Doing nothing will allow the other checks to happen and as long as it isn't in one of the default classifications will be allowed through.

 

So I guess the answer is the only difference between allow and doing nothing is Allow will overrule something else.

Edited by TechMonkey
  • Thanks 1
Posted (edited)

Depends on the order of your policies. You will need to have your policies in the right order. If memory serves Smooth wall applies from bottom of your list up

 

Eg

1. Global allow list - everyone - allow

2. Staff allow list - staffonly - allow

3. Global Blocklist - everyone - block

 

If you tick a category in the Blocklist that category will block no matter what.

 

If you tick a category in the staff allow list that isn't checked in the global allow list then only staff will be allowed to surf sites within that category. Everyone else cannot

 

If you tick a category in global allow then everyone will be able to surf site within that category

 

To summarise smooth wall will check each policy in order until it finds a tick against the category the site is in and action that policy if it does find one.

Eg when I request access to porn hub.com (category porn checked in global block) smooth wall will ask is it a category checked in global Blocklist (it should be😂) and action that policy.

Likewise if i request bbc.co.uk (checked only in global allow) it will review the global Blocklist the staff allow list and then global allow list

 

If it does not match any rule I believe the action is default blocked

Edited by dapaulio
Posted
Depends on the order of your policies. You will need to have your policies in the right order. If memory serves Smooth wall applies from bottom of your list up

 

Eg

1. Global allow list - everyone - allow

2. Staff allow list - staffonly - allow

3. Global Blocklist - everyone - block

 

If you tick a category in the Blocklist that category will block no matter what.

 

If you tick a category in the staff allow list that isn't checked in the global allow list then only staff will be allowed to surf sites within that category. Everyone else cannot

 

If you tick a category in global allow then everyone will be able to surf site within that category

 

To summarise smooth wall will check each policy in order until it finds a tick against the category the site is in and action that policy if it does find one.

Eg when I request access to porn hub.com (category porn checked in global block) smooth wall will ask is it a category checked in global Blocklist (it should be) and action that policy.

Likewise if i request bbc.co.uk (checked only in global allow) it will review the global Blocklist the staff allow list and then global allow list

 

If it does not match any rule I believe the action is default blocked

 

Not sure if Smoothwall has changed but we literally introduced a couple months back and this is incorrect (atleast at it's current update). The web filter applies top down, so in your case, assuming those categories were in the same positions and I allowed porn in the Global Allow List then it would work for everyone. Typically Smoothwall puts a few blocks right at the top (for things like hacking, virus, etc.) as an immutable block but if you were so inclined you could move that policy further down the processing order. As soon as it hits a rule that applies to a particular URL it stops and actions it. I believe there may be an option to 'continue processing' but may have that confused with something else.

  • Thanks 1
Posted (edited)

@Killer_Bot you are correct. just logged on to my Smoothwall and it does actually apply top to bottom (even states at the top of the policy window). I'm not certain whether this has changed with updates either. I'm convinced this must have changed with updates but questioning myself now because my block rule is out of place however my default AUP policy which is used with a block action is in the correct place.

 

Found myself today's job is reorganizing and testing my smoothwall policies :bored:

Edited by dapaulio
Posted

Found myself today's job is reorganizing and testing my smoothwall policies :bored:

 

That sounds like fun! haha

 

It is amazing how quickly they can get a bit unweildy, I'm setting some time aside in the Summer to go through them and make them a bit more logical in their processing. As we have a number of feeder schools use our Internet we have a mix of policies hitting various groups at various points and it can get a little confusing sometimes. Need to plan it all out logically and start again I think.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...