Jump to content

Recommended Posts

Posted

Hi, We're purchasing nearly 500 ipads for KS3 use. We have Smoothwall setup and working for filter.

It currently filters on prem and chromebooks through cloud

 

I need to filter internet traffic on the iPads off prem. It can be done with a global proxy however that requires i set the proxy details to be global on the iPad rather than it being on a wifi profile. Otherwise as soon as they go home and connect to their wifi the proxy isn't set and they can use the internet none filtered.

I'm using Intune/endpoint as an MDM for the ipads. Works well for iPads that we use on prem. I can't find anywhere a way to set the proxy globally on the ipad which to me tells me you can't

I have found the Apple filtering stuff thats listed in there but that doesn't seem to filter any traffic

 

Does anyone use Smoothwall and have got around this issue?

 

I'm looking at some alternatives like securly. I need a true cloud filter for ios that will work with Intune as the MDM.

If none of the above is possible i need to find an MDM and filter solution that's ....... free or not over the top at least :)

Posted

I've never used Intune but you can set a global proxy using MDM on iPads.

 

Not to be awkward but before the decision was made to purchase a particular device surely this was all investigated - 500 devices incoming?

Posted

Well that's good to know it can be done with a global proxy. There is a custom option in Intune that uses configurator files so I'll have a look there also.

 

We know the devices can be filtered though off prem. I'm trying to figure out really if it can be done with what we have rather than adding in something else to manage them.

Posted

InTune should have it's global proxy settings configuration via it's Azure Portal settings when using either DEP or AC2 as devices need to be Supervised to take advantage of this. You need to bear in mind that using global proxy may impact on your proxy upload if all devices are being filtered from your network.

 

I would definately look at another filter solution such as Securly as InTune is a PITA as an iOS MDM Solution.

  • Thanks 1
Posted
Well that's good to know it can be done with a global proxy. There is a custom option in Intune that uses configurator files so I'll have a look there also.

 

We know the devices can be filtered though off prem. I'm trying to figure out really if it can be done with what we have rather than adding in something else to manage them.

 

I know what you're saying and how it probably wasn't your decision to do it this way but you might want to flag to the powers that be that fully scoping out a project before commiting to such a huge spend would be better - you'd also know exactly how much you're spending rather than potentially now having to spend more than intended adding additional products etc.

Posted
Well that's good to know it can be done with a global proxy. There is a custom option in Intune that uses configurator files so I'll have a look there also.

 

We know the devices can be filtered though off prem. I'm trying to figure out really if it can be done with what we have rather than adding in something else to manage them.

 

 

LGFL are offering a 6 month trial of their off prem stuff to schools and its nott too expensive post trial either

Posted

Happy to show you how Securly can easily filter those devices for you - including the option to distribute our free parental app.

 

Drop me a message if you'd like to see a quick demo.

 

Thanks,

 

Marc

Posted (edited)
LGFL are offering a 6 month trial of their off prem stuff to schools and its nott too expensive post trial either

 

Yeah with another really poor crippled iOS browser that looks about 8 years out of date, I compare most of these awful 3rd party browser solutions to the "baby software" comment by Jobs at the iPhone launch.

 

Securly lets all students use Safari, a fully featured desktop browser on iOS.

Edited by Brimstone
Posted
Yeah with another really poor crippled iOS browser that looks about 8 years out of date, I compare most of these awful 3rd party browser solutions to the "baby software" comment by Jobs at the iPhone launch.

 

Securly lets all students use Safari, a fully featured desktop browser on iOS.

 

Last i checked doesnt every browser on ios have to use the built in apis? theyre all safari... with a different skin about the edges.

 

So what the sharing tools etc arent upto "desktop browser" standards, can they type in a web address and view it?

 

Some schools may not be able to dump the cash into another filtering solution so haphazardly

Posted

Yeah. Every browser on iOS, even Chrome, is based on Safari and nothing else as Apple require you to use it.

 

As for Smoothwall, its pretty annoying as they have basically got all of this off prem stuff figured out for Chromebooks but Apple is far more restrictive. Global proxy is the best you are going to get with Smoothwall unfortunately.

Posted

Today, global proxy is arguably the best way to filter an iPad - particularly if you want high quality, authenticated filtering.

We are working with apple to do something that doesn't require a proxy. If any of you would like to get in touch, i'd love to hear from you about what would be important in a solution.

Posted
Today, global proxy is arguably the best way to filter an iPad - particularly if you want high quality, authenticated filtering.

We are working with apple to do something that doesn't require a proxy. If any of you would like to get in touch, i'd love to hear from you about what would be important in a solution.

 

Im honestly very happy with the chorme solution, if it mirrors that id be in!

 

Thought the reporting needs some work to be feature comparable with onprem.

  • Thanks 1
Posted
Im honestly very happy with the chorme solution, if it mirrors that id be in!

 

Thought the reporting needs some work to be feature comparable with onprem.

 

Our Chrome solution involves the reporting being done on prem - the data is pushed back to our S14 once per hour - is this different to what you have?

Posted
Our Chrome solution involves the reporting being done on prem - the data is pushed back to our S14 once per hour - is this different to what you have?

 

Instant alerts are still WIP as far as im aware? and either the children are being very well behaved or im getting very few hits!

Posted
Instant alerts are still WIP as far as im aware? and either the children are being very well behaved or im getting very few hits!

 

True instant alerts are missing right now.

 

I'm also a little suspicious about how well behaved the kids are being haha

Posted

Instant alerts are in progress right now. Hope they'll be even better than the on-prem ones! If you want to chat to me about the pros and cons of what you have on-prem, drop me a line. I'd appreciate your comments.

 

I too would love our apple offering to match Chromebook - Apple aren't so keen... yet.

Posted

Hi,

 

As Marc mentioned we at Securly have native cloud filtering and real-time alerts for iPads using Safari, no need to install apps, proxy, or VPN everything back to on-premise kit. We have other customers using Intune MDM for their iPads too so happy to help configure that if needed. :)

 

Drop me or Marc a PM if you'd like to try it out for free.

Posted
Hi,

 

As Marc mentioned we at Securly have native cloud filtering and real-time alerts for iPads using Safari, no need to install apps, proxy, or VPN everything back to on-premise kit. We have other customers using Intune MDM for their iPads too so happy to help configure that if needed. :)

 

Drop me or Marc a PM if you'd like to try it out for free.

thats a lie... a proxy.pac file is a proxy... your offsite es exactly the same as SW except you use a cloud based proxy smoothwall uses on premproxy

Posted
Yeah. Every browser on iOS, even Chrome, is based on Safari and nothing else as Apple require you to use it.

 

Thats incorrect, just because developers are using the same core API, the render engine may be same but the wrapper around this and browser functions are massively different, especially when you have students using iOS, below are just a few Safari only functions that do not appear in other "crippled" browsers.

 

Safari Reader view - converts the web page minus the adverts so make reading lots of text much easier

Accessibility - Safari is the only browser on iOS that fully supports dyslexia readers and voice over, other claim to be able to do this, I've tried a few and they stink

PDF - Safri can convert a whole site into PDF's

Apple Classroom - Teachers use Classroom can easily drag and drop url's to students

Auto Translation - Translates language text,

Cross Site Tracking - This can be blocked via MDM profile configuration restrictions, unlike other browsers

 

The only one I've tried that comes anywhere near would be Firefox but it's slow and clunky when comapred with Safari on iOS.

Posted
thats a lie... a proxy.pac file is a proxy... your offsite es exactly the same as SW except you use a cloud based proxy smoothwall uses on premproxy

 

It's not a standard PAC file...do some reading

 

If you are using an onprem proxy like SW I hope you've got a very fast upload and download speeds, your comparison is not like for like.

  • Thanks 2
Posted
It's not a standard PAC file...do some reading

 

If you are using an onprem proxy like SW I hope you've got a very fast upload and download speeds, your comparison is not like for like.

 

From Securly's own website:

"On-Site and Off-Site Solution: A PAC file that is created by your Sales Engineer is a hard requirement for any off-site iPads. Please reach out to your Sales Engineer by submitting an email to [email protected] to have this created for you."

Posted

yea this is the bit I'm at now. Smoothwall have a global proxy which works quite well actually. My problem is I can't get it to work on Ipads as i need to add the school external address and the Smoothwall name as exceptions. Two things it seems you can't do on ipads.

I'm trying to figure out the pac file but i can't use the smoothwall pac file as its already in use on prem as its what we use to connect devices lol

 

I have requested a demo with Securly to have a look at their solution, they've quoted me and the price isn't too bad for 500 devices so looks promising. If i can get Smoothwall working to my satisfaction then great but its good to have a backup/better option

Posted

Thanks Brimstone,

 

DGardiner - you're correct in that traditionally proxy.pac files were just used to send pretty much everything back to a proxy, maybe a few static exceptions for local servers / networks - used to do this a lot when I worked for Smoothwall. This can be tricky when off-site since you need both good upload / download bandwidth to your appliance since the path is Browser -> On Prem Proxy -> Website -> On-Prem Proxy -> Browser. Few streaming videos can max that out very quickly.

 

Securly is different - we took advantage of PAC files since they're cross-platform, easy to centrally implement and lightweight, especially on iPads where Apple are strict about what you can do with filtering. We provide you with a ready made PAC file URL which you can deploy. Instead of pushing all traffic to a proxy, we are able to utilise our low latency cloud API within the PAC file to work out what needs to be allowed / blocked or scanned in more detail without sending all the traffic via a proxy server It can even do SSO, great for 1:1 iPads. Where we do need to intercept, HTTPS content for example, we do this in our cloud so we ensure there's enough bandwidth and resources available at all times to handle this.

 

If you'd like to learn more one of our founders Vinay wrote an deep-dive tech article on it here; https://blog.securly.com/2020/05/02/remote-filtering-technical-deep-dive-securlys-smartpac-vs-traditional-pac-files-apples-ios-agents/

 

HTH - Chris

  • Thanks 1
Posted
jblackburnHWGA The PAC file you use for internal and external can be different but obviously then has to be hosted elsewhere. However, if you resolve the external hostname to the internal IP of the Smoothwall while users are in the network and to the external address when they are outside the network, you can nuse the same PAC file for both internal and external users with no issues. Then add both IPs and hostname to the exceptions.
Posted

thanks Ibpalle, i'll give it a go. The ipads are on a different proxy port as in this case we're filtering without authentication and just pushing all users on said port through as student filtering. I don't see how I can do this with one Pac file.

I've got some of the best minds at Smoothwall working on it :D

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...