Jump to content

Recommended Posts

Posted

I'm sure this must have been answered, and people must be doing it, but how do you set up your users in G Suite so that they can use chrome devices in school (through Smoothwall), then take a school device home and use it.

 

Currently:

 

- Students have a specified proxy in G Suite so when they log into a ChromeOS device, they can use the on premise Smoothwall as their route to the internet.

 

- Students who are isolating are being moved into an OU in G Suite that has 'No Proxy' defined so that they can connect to their own home internet and get online. If they come back into school, I have to move them back into the regular OU.

 

- We are using SW Cloud Filter for users off premise, and this seems to be working well, I am also looking to use this when they are on premise if possible.

 

What's the ideal setup so students can move in and out of school and have a seamless experience, please!?

 

Thanks in advance.

Posted
The cloud filter extension would be the best option but when you mention the cloud filter; is that 'Connect for Chrome' or the new extension? Connect for Chrome is for authentication mainly, proxying still goes via the Smoothwall appliance, whether the client is at school or at home. With the Cloud client, the extension gets installed and the browser itself manages the filtering based on policies retrieved from the Smoothwall appliance.
Posted

I'm using cloud filter (the new extension), which works fine offsite. To use the chromebooks offsite, I have to set them to have 'no proxy' otherwise it gives a proxy error as it can't find it. This is fine if they are only using the device at home.

 

When they come into school, what can I do to get the traffic through the SW? If I leave it to Auto, they get the SSL. If I set it off, they get nothing. If I change it to the manual details, it's fine until they go home again.

 

Would Connect for Chrome identify them properly and pass the traffic through the SSL login page?

Posted

You need the new secret knock feature! Sounds weird but basically it allows the extension to tell an on premise Smoothwall to not transparently intercept traffic from cloud filter clients.

 

You need to do 2 things on the SMoothwal:

 

1: In networking - firewall - smoothwall access find the access rule that applies to the smoothwall internal interface the chromebooks will be using when going to the internet and add the Cloud Filter Client service to the list.

 

2: Navigate to this URL on the SMoothwall UI https://ip.or.hostname.of.your.smoothwall:441/ui/admin/cloud_filter

 

There enter the same internal Smoothwall IP address you added the cloud filter client service for and a refresh of 600. Save the settings.

 

Once this new configuration has been pulled by the clients, they should no longer be double filtered and only use the extension.

Posted

The problem with all of these things is that if you push them out using G Suite's admin console then users who sign into a personal Chrome device or just the Chrome browser will get the extension and be filtered event though it's their own device - unless I have missed something Smoothwall?

 

A lot of our staff and students sign into Chrome so as to get password sync, bookmarks sync etc.

Posted

Very true!

 

If available you could use something like device approval in Gsuite to prevent signing in on personal devices with a school account - not sure if that's included with education GSuite accounts?

 

In our case, to make things easier to manage Securly Chromebook extension will automatically shutdown on just a chrome browser rather than Chromebooks and you can decide whether to filter in-school only or at home.

 

 

 

The problem with all of these things is that if you push them out using G Suite's admin console then users who sign into a personal Chrome device or just the Chrome browser will get the extension and be filtered event though it's their own device - unless I have missed something Smoothwall?

 

A lot of our staff and students sign into Chrome so as to get password sync, bookmarks sync etc.

Posted
Very true!

 

If available you could use something like device approval in Gsuite to prevent signing in on personal devices with a school account - not sure if that's included with education GSuite accounts?

 

In our case, to make things easier to manage Securly Chromebook extension will automatically shutdown on just a chrome browser rather than Chromebooks and you can decide whether to filter in-school only or at home.

 

Yeah I know Securly have a solution :)

 

I want the kids and staff to sign in - I'm trying to encourage them not to use the same password for everything and being signed in and having it suggest and remember passwords is my strategy!

Posted
Chinesewhispers This setup is meant for the chromebooks to not have any proxy settings. The filtering is done by the extension. Remove the proxy settings from a test chromebook and see how that goes.
Posted (edited)
If the chromebooks are going through a SSL Login proxy and are not authenticating before then, then yes, you will get the login page. It sounds like there may be a bit of confusion about the extension and possibly the secret knock feature. Could you raise a ticket with support please and PM me the number. I'll see if I can pick it up. Edited by ibpalle
  • 1 year later...
Posted

You need to be using a transparent proxy for a network location. I would advise if possible a seperate VLAN for the Chromebooks, and set them to go through the filter unauthenticated as your lowest common denominator (e.g. Year 7 pupils). This way you can remove the SSL login and the proxy settings via Google admin console.

 

Hope this helps.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...