Jump to content

Recommended Posts

Posted

We are considering setting up filtering for pupils using school iPads at home. Can anyone share their experience of how well Smoothwall Global Proxy works in practice? Particularly on iPads.

 

It feels to me as if routing all their Internet traffic via the school is going to cause some additional unreliability.

Posted
I could never get it working. From what I gather the smoothwall box needs to have an external fqdn but couldn't get it to bind to AD when I did this. Very quickly back peddled and restored a previous snapshot.
  • Thanks 1
Posted

Never mind the reliability.... If someone on the internet points their browser proxy settings to your Smoothwall public IP, they can browse any internal web services you have.

 

You can protect it with a certificate, but it wouldn't be hard to extract one from a device.

 

Not very secure in my opinion.

  • Thanks 1
Posted (edited)

For loan laptops I used direct access to route traffic back in and out again however could be slow at times, as for iPad’s that’s even trickier!

 

I personally wouldn’t bother and go down the political route instead. Draft up a letter that both the student and parent must sign agreeing that you cannot control the internet traffic on their home networks and that the responsibility is on the parent and student.

The school will not be liable for any inappropriate internet surfing while the device is off premise.

 

You can however monitor what is surfed via the likes of Meraki (other MDM’s available) and if anything is out of the ordinary then you reserve the right to terminate the loan.

 

Something along those lines...

Edited by Tefters
  • Thanks 1
Posted

Thank you all. I have misgivings but management really like the idea of providing protection off site - they see it as a selling point for one-to-one iPads.

 

From what I have heard, most schools have not gone down this route. The "political approach" seems to be the usual one.

 

Security is a good point, FN-GM. I am also uncomfortable about exposing a proxy externally, even with certificate protection. Maybe the internal website access could be restricted with a rule on the Smoothwall? Though it feels as if there are going to be other loopholes and something more like a VPN would be advisable if we have to do this.

Posted

We had to use the global proxy since we provided some of our PP students with Chromebooks and a 4G connection. We weren't happy giving them free reign on the internet with a school owned device, even if it was at home.

 

We enabled the global proxy, pointed the Chromebooks to it with Google admin console, and it just works as you'd expect. They get the same filtering as if they were in school.

 

I wasn't aware this opened a hole into our network though, so I guess that's something else to add to the list...

  • Thanks 1
Posted

Thank you, Kevin. Good to know it works for someone.

 

It looks as if we will be delaying one-to-one devices for the moment, so the question is now less urgent for us.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...