Jump to content

Recommended Posts

Posted (edited)

Though I'd start a thread on migrations from BGfL to Exa.

 

What kind of ping times do you get to 8.8.8.8? We get 16ms with Exa on fibre 100 MB/s (BT 21CN). We were proviously getting 8ms when we were on BGfL 100Mb/s

 

No problem with bandwidth though speedtest.net gives us near 100meg.

 

I do like the Surfprotect console although on BGfL we had no control over what was blocked or not and no SSO with AD so i'm easily pleased!

 

Also the TLS/SSL inspection is not working for us even though we have rolled out and verified that the Exa Root CA certificate is installed. We have gone to http://certcheck.surfprotect.co.uk and we get the message "IT LOOKS LIKE YOU'RE NOT USING SURFPROTECT YET"

 

Tried with transparent proxy and explicit proxy set in browser.

Edited by Alis_Klar
Posted

Hi @Alis_Klar,

 

Firstly, thanks for moving across to Exa.

 

Can I ask, are you with us directly as a customer or through one of our partners? I am asking from a support perspective. Please, can you give our team a call and we can go through anything with you, especially if you are seeing issues on the Root CA. Just give us a call on 0345 1451234, or PM me with your details and I'll get them to call you.

 

Mark

Posted

What sort of traceroute are you seeing?

 

Our connection goes

 

Client -> Core -> Our internal firewall/filter -> Exa's router in our cab -> r2.lon-the.exa.net.uk -> Google (4 hops with them, google1.lonap.net being the first, so I'm guessing Exa have peering set up directly with Google). 7ms ping on a gigabit link.

Posted

I am going via Link2ICT (BGfL) and know that I should log any issues with them in the first instance. It has been a bit frustrating as this is a new product to them too and I would have liked the oportunity to speak to Exa Directly in the inital setup phase. Once things are bedded in I would be fine with going via Link2ICT for ongoing support.

 

They have said that HTTPS inspection is either ON or OFF for transparent proxy and for explicitly defined proxy e.g. PROXY.QUANTUM... and AD.QUANTUM... and if you have devices which are not proxy aware (we have Amazon fire sticks and some game consoles) Exa can probably make an IP exception as long as the device has a static IP. Therefore the only way to ad-hoc disable inspection (e.g. for troubleshooting) is to use the NOTLS.QUANTIM.. proxy? Is this correct?

 

So I assume the idea is that once we are happy we have rolled out the certificate we can notify you and inspection/decryption will be enabled.

 

Is this why we have no search history viewable in Surfprotect console?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...