MonkeyNorthern Posted June 27, 2017 Posted June 27, 2017 Hi, Can anyone shed any light on whether there is a difference between using an 'Allow' policy for a Category Group versus 'not blocking it'? For example, is there a benefit or otherwise if I 'Allow' Online Banking for 'Staff' explicitly, over not including it in the 'Block' list? Thanks,
TechMonkey Posted June 27, 2017 Posted June 27, 2017 (edited) Not sure I quite understand the question, but if I have grasped it: - Allow will let something through as long as it passes all other checks (bad words etc) - Block stops it getting through - Whitelist prevents any processing happening and waves the site through - Doing nothing will allow the other checks to happen and as long as it isn't in one of the default classifications will be allowed through. So I guess the answer is the only difference between allow and doing nothing is Allow will overrule something else. Edited June 27, 2017 by TechMonkey 1
dapaulio Posted June 27, 2017 Posted June 27, 2017 (edited) Depends on the order of your policies. You will need to have your policies in the right order. If memory serves Smooth wall applies from bottom of your list up Eg 1. Global allow list - everyone - allow 2. Staff allow list - staffonly - allow 3. Global Blocklist - everyone - block If you tick a category in the Blocklist that category will block no matter what. If you tick a category in the staff allow list that isn't checked in the global allow list then only staff will be allowed to surf sites within that category. Everyone else cannot If you tick a category in global allow then everyone will be able to surf site within that category To summarise smooth wall will check each policy in order until it finds a tick against the category the site is in and action that policy if it does find one. Eg when I request access to porn hub.com (category porn checked in global block) smooth wall will ask is it a category checked in global Blocklist (it should be😂) and action that policy. Likewise if i request bbc.co.uk (checked only in global allow) it will review the global Blocklist the staff allow list and then global allow list If it does not match any rule I believe the action is default blocked Edited June 27, 2017 by dapaulio
Killer_Bot Posted June 28, 2017 Posted June 28, 2017 Depends on the order of your policies. You will need to have your policies in the right order. If memory serves Smooth wall applies from bottom of your list up Eg 1. Global allow list - everyone - allow 2. Staff allow list - staffonly - allow 3. Global Blocklist - everyone - block If you tick a category in the Blocklist that category will block no matter what. If you tick a category in the staff allow list that isn't checked in the global allow list then only staff will be allowed to surf sites within that category. Everyone else cannot If you tick a category in global allow then everyone will be able to surf site within that category To summarise smooth wall will check each policy in order until it finds a tick against the category the site is in and action that policy if it does find one. Eg when I request access to porn hub.com (category porn checked in global block) smooth wall will ask is it a category checked in global Blocklist (it should be) and action that policy. Likewise if i request bbc.co.uk (checked only in global allow) it will review the global Blocklist the staff allow list and then global allow list If it does not match any rule I believe the action is default blocked Not sure if Smoothwall has changed but we literally introduced a couple months back and this is incorrect (atleast at it's current update). The web filter applies top down, so in your case, assuming those categories were in the same positions and I allowed porn in the Global Allow List then it would work for everyone. Typically Smoothwall puts a few blocks right at the top (for things like hacking, virus, etc.) as an immutable block but if you were so inclined you could move that policy further down the processing order. As soon as it hits a rule that applies to a particular URL it stops and actions it. I believe there may be an option to 'continue processing' but may have that confused with something else. 1
dapaulio Posted June 28, 2017 Posted June 28, 2017 (edited) @Killer_Bot you are correct. just logged on to my Smoothwall and it does actually apply top to bottom (even states at the top of the policy window). I'm not certain whether this has changed with updates either. I'm convinced this must have changed with updates but questioning myself now because my block rule is out of place however my default AUP policy which is used with a block action is in the correct place. Found myself today's job is reorganizing and testing my smoothwall policies Edited June 28, 2017 by dapaulio
Killer_Bot Posted June 28, 2017 Posted June 28, 2017 Found myself today's job is reorganizing and testing my smoothwall policies That sounds like fun! haha It is amazing how quickly they can get a bit unweildy, I'm setting some time aside in the Summer to go through them and make them a bit more logical in their processing. As we have a number of feeder schools use our Internet we have a mix of policies hitting various groups at various points and it can get a little confusing sometimes. Need to plan it all out logically and start again I think.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now