Jump to content

Recommended Posts

Posted

Morning All,

 

Not sure if anyone's able to answer these quickly before I waste time on this as RM are doing their very slow responses as always, 3 days for 2 non-helpful emails :p

 

When you setup UBF, it requires a password reset to work etc, but if they don't reset it yet does it just fall back to the standard filtering? or won't it work at all for them? e.g. Everyone has to be force changed? Or can I reset one/two for a test, switch people over, and then it'll just give them new features once they've reset?

 

Also, In the instructions it says about setting the Unify homepage as default but we don't want any of that, just UBF, so is that still required or will the UBF part work once it's setup without requiring any actual access to the Unify pages?

 

Thanks,

Steve

Posted

Hi Steve,

 

Sorry to hear that your UBF query wasn't answered promptly when you contacted RM, however I am able to provide you with some additional information.

 

If you set the UBF proxy address for users that aren’t fully setup yet then they will see login prompts when trying to browse. However you can mix-and-match the proxy addresses that you deploy, so it is common to just deploy the UBF proxy address to a small group of test or initial users, and keep using the default proxy address or transparent filtering for other users.

 

You don’t need to follow the steps to set the RM Unify homepage as default unless you want users to automatically be signed in to the RM Unify launchpad for access to cloud applications.

 

Let me know if you need any more information about this, I'll be happy to help

 

Thanks,

 

The RM Broadband support team

  • Thanks 1
Posted
If you set the UBF proxy address for users that aren’t fully setup yet then they will see login prompts when trying to browse. However you can mix-and-match the proxy addresses that you deploy, so it is common to just deploy the UBF proxy address to a small group of test or initial users, and keep using the default proxy address or transparent filtering for other users.

 

Hi and thanks for that info. Just to confirm though, will that definitely prompt for login? It can't fall back to "standard" filtering? As we use an on-site proxy too and use the RM proxy as an upstream one to ours it'd mean everyone is put onto it, and it'd be no use if all devices for those not setup and all personal devices to suddenly get blocked by it?

 

Also how would that work for servers etc that require access without users being logged in? Or is it expected that they're all pointing to different proxies?

 

I'm struggling to see how we can get two levels of filtering without giving everyone staff proxy (which again in term would mean either bypassing our local proxy, or setting that as the upstream), or without enabling UBF which then would stop everyone accessing the web on any personal device etc without forcing login screens.

 

As an example, our SLT are looking to allow Staff access to Twitter to update the schools Twitter feed, but wouldn't want them to access any website (facebook) etc etc using staff proxies (and thought from previous conversations with SWGfL that UBF might be the way forward, but guessing not by the sounds of it :( )

 

Thanks,

Steve

Posted (edited)

If you have users who haven't or can't reset their password you can point them to a different filter for the short term.

 

When we moved to the RM UBF in summer we did a force reset of all the students passwords so we knew they were in the Safetynet system then made the kids change it again at logon.

It did mean that for some users they had to wait until the next password sync (which is every 15 mins for us) before it stopped nagging them to enter the username and password.

 

Oh and as a further aside, once UBF is enabled your staffproxy does not work along side it. I would suggest setting the Sync tool up and they give users a week to change their passwords before moving them over. Then you can have the different groups so that they can access twitter but not facebook (but good luck with getting all the domains entered as the social media will allow all the staff to have access but at least not the students)

Edited by Boredguy
  • Thanks 1
Posted
As an example, our SLT are looking to allow Staff access to Twitter to update the schools Twitter feed, but wouldn't want them to access any website (facebook) etc etc using staff proxies (and thought from previous conversations with SWGfL that UBF might be the way forward, but guessing not by the sounds of it :( )

 

We do this on the smoothwall on site proxy. Just unfiltered it on RM Safety net and then filter it for student group on the smoothwall side.

  • Thanks 1
Posted
We do this on the smoothwall on site proxy. Just unfiltered it on RM Safety net and then filter it for student group on the smoothwall side.

 

How are you stopping personal devices being directly pointed at the RM proxy and gaining access though? I don't know if it's just the way it was setup legacy here in regards to the video conferencing stuff, but there seems to be nothing that stops someone using any of the RM proxies on any devices unless you disable all passthrough on the smoothie which then stops things like staffproxy/normal proxies on photocopiers etc etc

 

As an example, someone decided to unblock Pinterest that way while I was away, and block it for students on smoothie but this allowed anyone to access it on a personal device by just using the normal RM stuff rather than the pac/wpad auto detect. Needless to say that was reblocked quickly :p

 

Ideally long term, we'd look at pushing everything directly through the smoothie, and disable all upwards filtering (IWF aside), then do it all locally which by the sounds of it will be made a lot easier in Q1 next year with the new RM proxies that are coming out! :)

 

Thanks,

Steve

Posted
If you have users who haven't or can't reset their password you can point them to a different filter for the short term.

 

I'm guessing in that regards though you're not using another onsite proxy? As we're pointing users to smoothwall (and RM upstream) if we put them directly to another RM filter it'd bypass the smoothwall filtering. Or did you manage to find a way to do this via a local proxy?

 

Thanks,

Steve

Posted

Hello Steve

 

It will be useful if I try to clarify a few things ....

 

The user filtering proxy address will always prompt the user to login if the ‘single sign on’ process with their logged in AD user fails due to the user not yet existing in SafetyNet, this unfortunately won’t fall back to default filtering.

 

Neither user based filtering or staff proxy should be used as an upstream proxy to your on-site proxy. Proxy authentication takes place between the final proxy server and the user using the device, and therefore won’t work if there is another proxy in-between.

 

For servers, the service will apply your default filtering policy for any AD service accounts that try to browse through the user based filtering proxy – however we’d generally advise configuring servers to use a non-user based proxy address or to just use transparent filtering instead.

 

As mentioned it is fine to mix-and-match the proxy addresses that are deployed to different users and devices if you would like only a sub-set of users to have user-based filtering policies. Or you could deploy our transparent filtering option for personal/BYOD devices (to apply a default filtering policy), and then staff users that need a different filtering policy could browse through the user filtering proxy address.

 

As a final option – we will shortly be making available an extra four proxy addresses per customer, and you will be able to create your own custom filter policy and apply this to each address from within the SafetyNet administration interface. We’re currently in the process of rolling this out to our filtering platform, and this new functionality will therefore be announced to SWGfL customers shortly.

 

If you have any further questions about this, you can contact our service desk on 0845 307 7870 and speak to a service desk engineer. Also, feel free to PM me with your contact number and I will call you and provide further assistance with your query

 

Thanks

 

The RM Broadband support team

  • Thanks 1
Posted

Ah that's a shame then, the fact it can't be used as upstream makes it pretty useless for our scenario then :s Guess we'll have to wait for the other proxies as a workaround unless smoothwall can do something fancy (or SLT agree to removing smoothwall filtering on all staff which I can't see personally).

 

Thanks for confirming :)

 

Steve

Posted
How are you stopping personal devices being directly pointed at the RM proxy and gaining access though? I don't know if it's just the way it was setup legacy here in regards to the video conferencing stuff, but there seems to be nothing that stops someone using any of the RM proxies on any devices unless you disable all passthrough on the smoothie which then stops things like staffproxy/normal proxies on photocopiers etc etc

 

As an example, someone decided to unblock Pinterest that way while I was away, and block it for students on smoothie but this allowed anyone to access it on a personal device by just using the normal RM stuff rather than the pac/wpad auto detect. Needless to say that was reblocked quickly :p

 

Ideally long term, we'd look at pushing everything directly through the smoothie, and disable all upwards filtering (IWF aside), then do it all locally which by the sounds of it will be made a lot easier in Q1 next year with the new RM proxies that are coming out! :)

 

Thanks,

Steve

 

personal device are all authenticated via 802.1X on WiFi via Smoothwall BYOD authentication and transparent proxy setup. So they are all on the Smoothwall. we do not give out SWGfL proxy information.

Posted

Yep same sort of setup on our test one, 6th Formers login via Radius on Ruckus/Smoothie and have transparent applied from the Smoothie. They can still change the proxy (As an example on my iphone I disable auto proxy, and set manual to staffproxy) and get out without smoothwall filtering though here, Not sure if it's just something odd in this setup or not, but doesn't seem to be blocked by Smoothwall to pass traffic through it when it's not using one of it's proxies, unless you disable all unknown proxies which blocks staffproxy etc etc. The same principle applies for a plugged in device too.

 

The RM proxies are findable by googling swgfl and proxy, so even though they're not given out it seems easy enough to find them. Although they can't login to the staff proxy (or normal one) it still gives them access to the sites as they're unfiltered on RM, and effectively bypassing Smoothie filtering.

 

Or doesn't that seem to happen for you?

 

Steve

Posted

It doesn't get hit by Smoothwall guardian side as it's not using the webproxy to get through, as it's going straight to the RM one. Same way that it won't log anything that's set to use staffproxy etc as it's never hitting guardian.

 

Guess I could try it on the firewall side and do a deny that way. Might have to have a play with that, and give Smoothie a shout in regards to if there's a smart way of doing it.

 

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...