Jump to content

what Filtering or Broadband Service do you use? and how?  

91 members have voted

  1. 1. what Filtering or Broadband Service do you use? and how?

    • EXA
      12
    • Schools Broadband
      9
    • Smoothwall
      23
    • Fortigate
      7
    • Other
      16
    • UTM Box (Physical)
      12
    • Cloud Based Filtering
      12


Recommended Posts

Posted

Hi All,

 

Not so impressed with our filtering service since a glaring hole in SSL decrypt and inspect was found so I'm looking at alternatives;

 

I've heard good things about EXA, but their DDOS puts me off, same with Schools Broadband but again, not sure If I should go with cloud filtering or a box.

 

Does anyone have any recommendations or pitfalls? Medium sized secondary here.

Posted
Filtering and broadband could be classed as two different things. We use Schools Broadband with Smoothwall in house at the moment.
Posted

thanks for the replies all,

 

We are on Fortigate, but feel their support is not that great and the configuration is clumsy at best - the error in question just let adult images through a google image search.

 

Ideally we need a solution with a transparent proxy, VPN (Though this is being depreciated) and layered filtering;

 

The biggest problem is SSL on the guest WiFi as fortigate doesn't support that (apparantly)

 

Anyone else with a Fortigate fancy a chat?

  • Thanks 1
Posted
That's a shame, as I was targeting Fortigate once our Smoothwall multi-year payment expires. However, Smoothwall have improved the broken roaming so I'm not inclined to rush into a decision just yet. Disentangling from one to the other would be a non-trivial project.
Posted
thanks for the replies all,We are on Fortigate, but feel their support is not that great and the configuration is clumsy at best - the error in question just let adult images through a google image search.Ideally we need a solution with a transparent proxy, VPN (Though this is being depreciated) and layered filtering;The biggest problem is SSL on the guest WiFi as fortigate doesn't support that (apparantly)Anyone else with a Fortigate fancy a chat?
we have a fortigate at one of our sites and this happened last year...
Posted

We're with BT(1Gbps bearer with 500Mbps port speed) and use a Palo Alto VM300 as both Firewall & URL filtering.

 

Currently do SSL Decryption on all domain computers. Don't currently decrypt BYOD devices. It is technically possible, we'd just need to get everyone to install the certificate on their device. Which we currently don't do.

 

Am very happy with the Palo Alto overall, does everything we need and more. Much better than the Cisco ASA5505 it replaced.

  • Thanks 1
Posted
Currently do SSL Decryption on all domain computers. Don't currently decrypt BYOD devices. It is technically possible, we'd just need to get everyone to install the certificate on their device. Which we currently don't do.
Don't the BYOD device's browser moan about a MITM with no certificate?
Posted
We are on Fortigate, but feel their support is not that great and the configuration is clumsy at best - the error in question just let adult images through a google image search.

 

I'm curious whether that was a bug with the appliance, or a misconfiguration?

For what its worth, SSL decrypt for Google Search can be a problem for certain Google devices - Google have designed certain non-search services to need un-decrypted access to Google. In my opinion, you absolutely should be decrypting Google Search, but you have to accept a minor loss of functionality in Android/ChromeOS devices as a result. (Sorry, I can't remember off the top of my head specifically what breaks - I think there was some rarely used authentication mode in ChromeOS and a few other minor things that break).

 

Don't the BYOD device's browser moan about a MITM with no certificate?

 

Browsers work fine with HTTPS decryption once the user has installed the certificate on their device (present a "you need to install a certificate" splash page when they first log on to the wifi and don't let them any further until its installed. Obviously you need to show them an AUP + privacy policy that explains what the certificate is for and how you're protecting their data).

 

Non-browser apps are more of a problem, especially on Android (thanks Google, again) - we ship a stock "no decryption" list of host names for things that are required for problem apps and which won't significantly impact filtering, and for anything else the school has to make a case-by-case decision on whether to let the app work.

Posted

On SSL decryption for guest wifi:

 

Decryption for long-term BYOD devices is ok, but installing certificates onto short-term guest devices is a hassle you probably don't want, so you probably can't do SSL decryption for guests. What you can do is passive SSL inspection, so you can filter and audit which websites are being accessed, but not specifically what within the website is being accessed. With passive inspection, you can record that someone tried to visit pornhub and block that access, but you can't block accesses to specific porny twitter accounts whilst allowing access to the rest of twitter, for example.

Posted
Don't the BYOD device's browser moan about a MITM with no certificate?

 

Yep, which is why we don't do it. BYOD devices would need the certificate installing, which is honestly a hassle I can't be bothered with. They're still fully filtered, just can't do in depth scanning as we can with domain devices.

Posted
Currently do SSL Decryption on all domain computers. Don't currently decrypt BYOD devices. It is technically possible, we'd just need to get everyone to install the certificate on their device. Which we currently don't do.

 

Yep, which is why we don't do it. BYOD devices would need the certificate installing, which is honestly a hassle I can't be bothered with. They're still fully filtered, just can't do in depth scanning as we can with domain devices.
So you don't do inspection so no need for certificate, but allow BYOD? I cannot get browsers to work without a certificate, inspecting or not. The browsers moan if not certificate regardless
Posted
So you don't do inspection so no need for certificate, but allow BYOD? I cannot get browsers to work without a certificate, inspecting or not. The browsers moan if not certificate regardless

 

the browsers will always moan on a block page since youre intercepting ssl. if youre not inspecting/tampering with the traffic it should work - try checking what certificate the websites are presenting that youre having issues with and that might point you in the right direction

Posted

So another alternative I've been offered is 'ForcePoint' - Has anyone used this program?

 

My only concern with things like Fortigate/Forcepoint etc. is I'm not sure they are really geared towards schools...

Posted
the browsers will always moan on a block page since youre intercepting ssl. if youre not inspecting/tampering with the traffic it should work - try checking what certificate the websites are presenting that youre having issues with and that might point you in the right direction

A captive portal login page will also cause browsers to complain about the certificates for the same reason. (Phones and tablets do have magic "captive portal clients" to try and avoid this problem, but they're a bit hit or miss).

Posted
Hi All,

 

Does anyone have a Sophos UTM Box and they wouldn't mind sharing some info with us? How have you found it and how flexible is it?

 

We have a Sophos UTM and overall, it's been a good, solid product for the last 5 or so years that we've been using it. In terms of hardware, we've had to return it a couple of times in that period, both because of faulty PSUs. The software feature set is pretty comprehensive and covers nearly all what we need, although development has slowed recently, as they push towards XG. We're looking at migrating over to XG in the next few months, so I would look at that to be honest if you're considering Sophos.

Posted

My suggestion would be separate filtering and broadband. Which likely means an onsite filtering device (Smoothwall, Sophos UTM for example) and a un-filtered or at least mainly unfiltered internet connection.

 

We're Exa here for broadband and Smoothwall for filtering. Exa have been very good even with the DDOS, you could have that with anyone. Smoothwall has been very good but support isn't great at the minute. However its level of filtering I feel is very good.

  • Thanks 1
Posted
My suggestion would be separate filtering and broadband. Which likely means an onsite filtering device (Smoothwall, Sophos UTM for example) and a un-filtered or at least mainly unfiltered internet connection.

 

That's been my policy for years. We have an unfiltered Exponential-e leased line and a Smoothwall server. It's a lot easier to fault-find, especially as our leased line service has been outstanding over the last 5 years.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...