Jump to content

Recommended Posts

Posted

Hi

 

I work for a school and we have broadband with a local authority. The proxy internet filter settings that go via the local authority are set in group policy on our server, so that all laptops etc pick up the proxy settings automatically via GP to access the Internet.

 

We will be changing over to Smoothwall to use for our filtering.

 

I want to remove the current proxy settings completely in group policy for the filtering, as with Smoothwall it will be transparent, so no need to have proxy settings in GP.

 

Is there a way of doing this with a script to remove the all proxy settings from GP or will it have to be done manually, or use a script on each users login via active directory that removes the filtering ?

 

Is there anything else I need to be aware of when swapping over ? Someone mentioned certificates.

 

Any advice really appreciated. Thanks.

Posted

If you change the GP - the next user that logs on will get that policy - there is no need for any script....

 

I'm not sure that you would want to use transparent filtering....because if you do - how is smoothwall going to identify the user? (...Perhaps you are going to use Smoothwall's Idex tool? But personally I would have left the proxy setting - or at least change the proxy setting to point to smoothwall...because that would mean that I didn't have to push out Idex to all by devices....and proxies will work with devices like tablets too...not sure what smoothwall has done for devices...)

 

...I would use transparent filtering for any BYOD though...and use radius authentication with AD logons to the WiFi...and forward that to smoothwall.

 

And yes....and device that is going be filtered will need a certificate installed. Again this can be pushed out to domain PCs via a GPO (google how to do it...)

 

...but its a pain for BYOD users - because they don't like the hassle of having to install a certificate (and enable it in the case of iOS)…

 

Smoothwall usually include doing most of this as part of their setup/installation as part of the cost....

Posted
If you change the GP - the next user that logs on will get that policy - there is no need for any script....

 

I'm not sure that you would want to use transparent filtering....because if you do - how is smoothwall going to identify the user? (...Perhaps you are going to use Smoothwall's Idex tool? But personally I would have left the proxy setting - or at least change the proxy setting to point to smoothwall...because that would mean that I didn't have to push out Idex to all by devices....and proxies will work with devices like tablets too...not sure what smoothwall has done for devices...)

 

...I would use transparent filtering for any BYOD though...and use radius authentication with AD logons to the WiFi...and forward that to smoothwall.

 

And yes....and device that is going be filtered will need a certificate installed. Again this can be pushed out to domain PCs via a GPO (google how to do it...)

 

...but its a pain for BYOD users - because they don't like the hassle of having to install a certificate (and enable it in the case of iOS)…

 

Smoothwall usually include doing most of this as part of their setup/installation as part of the cost....

 

 

 

 

Many thanks for the info. Yes I did actually wonder about leaving the proxy filtering in, so glad you mentioned that.

Posted
Agree with the rest on this on. Don't forget you can have it both ways. Authenticated users will get the proxy and unauthenticated users will get the transparent policies. This stops them bypassing the standard proxy.
Posted
...and I’d use captive portal with a timeout= length of your lessons for any shared devices ...like tablets. It’s not without problems...because if you don’t open a browser you are not challenged for logon...and apps don’t work...or worse stop working without warning if the session expires. But...it’s probably the only practical solution...
Posted
Agree with the rest on this on. Don't forget you can have it both ways. Authenticated users will get the proxy and unauthenticated users will get the transparent policies. This stops them bypassing the standard proxy.

 

Yep. Agree. And you can granularly adjust your filtering levels with AD authentication. I.e. not one single filtering policy for all.

Posted
Yep. Agree. And you can granularly adjust your filtering levels with AD authentication. I.e. not one single filtering policy for all.

 

Yes, filtering needs to be age appropriate...with a focus on monitoring and reporting ....simply deciding to block everything is not what we are asked to do....nor do I think its our job - or technologies job to act as beating stick for students...if they play computer games in a lesson the teacher should treat it as a discipline issue as if they were kicking a ball around...

 

There will be some debate - about content delivery sites which often contain unmoderated - but loads of potentially useful material - like for example pinterest.... We allow this for older students - but use the "warning" page of facility of smoothwall ...In theory - smoothwall has content recognition capabilities...but you couldn't rely on it 100%....The fact that some material can be shocking/offensive/unacceptable or whaever is to some extent part of a student's education.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...