jblackburnHWGA Posted October 20, 2020 Posted October 20, 2020 Hi, We're purchasing nearly 500 ipads for KS3 use. We have Smoothwall setup and working for filter. It currently filters on prem and chromebooks through cloud I need to filter internet traffic on the iPads off prem. It can be done with a global proxy however that requires i set the proxy details to be global on the iPad rather than it being on a wifi profile. Otherwise as soon as they go home and connect to their wifi the proxy isn't set and they can use the internet none filtered. I'm using Intune/endpoint as an MDM for the ipads. Works well for iPads that we use on prem. I can't find anywhere a way to set the proxy globally on the ipad which to me tells me you can't I have found the Apple filtering stuff thats listed in there but that doesn't seem to filter any traffic Does anyone use Smoothwall and have got around this issue? I'm looking at some alternatives like securly. I need a true cloud filter for ios that will work with Intune as the MDM. If none of the above is possible i need to find an MDM and filter solution that's ....... free or not over the top at least
Primus Posted October 20, 2020 Posted October 20, 2020 I've never used Intune but you can set a global proxy using MDM on iPads. Not to be awkward but before the decision was made to purchase a particular device surely this was all investigated - 500 devices incoming?
jblackburnHWGA Posted October 20, 2020 Author Posted October 20, 2020 Well that's good to know it can be done with a global proxy. There is a custom option in Intune that uses configurator files so I'll have a look there also. We know the devices can be filtered though off prem. I'm trying to figure out really if it can be done with what we have rather than adding in something else to manage them.
Brimstone Posted October 20, 2020 Posted October 20, 2020 InTune should have it's global proxy settings configuration via it's Azure Portal settings when using either DEP or AC2 as devices need to be Supervised to take advantage of this. You need to bear in mind that using global proxy may impact on your proxy upload if all devices are being filtered from your network. I would definately look at another filter solution such as Securly as InTune is a PITA as an iOS MDM Solution. 1
Primus Posted October 20, 2020 Posted October 20, 2020 Well that's good to know it can be done with a global proxy. There is a custom option in Intune that uses configurator files so I'll have a look there also. We know the devices can be filtered though off prem. I'm trying to figure out really if it can be done with what we have rather than adding in something else to manage them. I know what you're saying and how it probably wasn't your decision to do it this way but you might want to flag to the powers that be that fully scoping out a project before commiting to such a huge spend would be better - you'd also know exactly how much you're spending rather than potentially now having to spend more than intended adding additional products etc.
DGardiner Posted October 20, 2020 Posted October 20, 2020 Well that's good to know it can be done with a global proxy. There is a custom option in Intune that uses configurator files so I'll have a look there also. We know the devices can be filtered though off prem. I'm trying to figure out really if it can be done with what we have rather than adding in something else to manage them. LGFL are offering a 6 month trial of their off prem stuff to schools and its nott too expensive post trial either
Securly_Marc Posted October 20, 2020 Posted October 20, 2020 Happy to show you how Securly can easily filter those devices for you - including the option to distribute our free parental app. Drop me a message if you'd like to see a quick demo. Thanks, Marc
Brimstone Posted October 20, 2020 Posted October 20, 2020 (edited) LGFL are offering a 6 month trial of their off prem stuff to schools and its nott too expensive post trial either Yeah with another really poor crippled iOS browser that looks about 8 years out of date, I compare most of these awful 3rd party browser solutions to the "baby software" comment by Jobs at the iPhone launch. Securly lets all students use Safari, a fully featured desktop browser on iOS. Edited October 20, 2020 by Brimstone
DGardiner Posted October 20, 2020 Posted October 20, 2020 Yeah with another really poor crippled iOS browser that looks about 8 years out of date, I compare most of these awful 3rd party browser solutions to the "baby software" comment by Jobs at the iPhone launch. Securly lets all students use Safari, a fully featured desktop browser on iOS. Last i checked doesnt every browser on ios have to use the built in apis? theyre all safari... with a different skin about the edges. So what the sharing tools etc arent upto "desktop browser" standards, can they type in a web address and view it? Some schools may not be able to dump the cash into another filtering solution so haphazardly
aicrd Posted October 20, 2020 Posted October 20, 2020 Yeah. Every browser on iOS, even Chrome, is based on Safari and nothing else as Apple require you to use it. As for Smoothwall, its pretty annoying as they have basically got all of this off prem stuff figured out for Chromebooks but Apple is far more restrictive. Global proxy is the best you are going to get with Smoothwall unfortunately.
tom_newton Posted October 21, 2020 Posted October 21, 2020 Today, global proxy is arguably the best way to filter an iPad - particularly if you want high quality, authenticated filtering. We are working with apple to do something that doesn't require a proxy. If any of you would like to get in touch, i'd love to hear from you about what would be important in a solution.
DGardiner Posted October 21, 2020 Posted October 21, 2020 Today, global proxy is arguably the best way to filter an iPad - particularly if you want high quality, authenticated filtering. We are working with apple to do something that doesn't require a proxy. If any of you would like to get in touch, i'd love to hear from you about what would be important in a solution. Im honestly very happy with the chorme solution, if it mirrors that id be in! Thought the reporting needs some work to be feature comparable with onprem. 1
Primus Posted October 21, 2020 Posted October 21, 2020 Im honestly very happy with the chorme solution, if it mirrors that id be in! Thought the reporting needs some work to be feature comparable with onprem. Our Chrome solution involves the reporting being done on prem - the data is pushed back to our S14 once per hour - is this different to what you have?
DGardiner Posted October 21, 2020 Posted October 21, 2020 Our Chrome solution involves the reporting being done on prem - the data is pushed back to our S14 once per hour - is this different to what you have? Instant alerts are still WIP as far as im aware? and either the children are being very well behaved or im getting very few hits!
Primus Posted October 21, 2020 Posted October 21, 2020 Instant alerts are still WIP as far as im aware? and either the children are being very well behaved or im getting very few hits! True instant alerts are missing right now. I'm also a little suspicious about how well behaved the kids are being haha
tom_newton Posted October 22, 2020 Posted October 22, 2020 Instant alerts are in progress right now. Hope they'll be even better than the on-prem ones! If you want to chat to me about the pros and cons of what you have on-prem, drop me a line. I'd appreciate your comments. I too would love our apple offering to match Chromebook - Apple aren't so keen... yet.
Securly_Chris Posted October 22, 2020 Posted October 22, 2020 Hi, As Marc mentioned we at Securly have native cloud filtering and real-time alerts for iPads using Safari, no need to install apps, proxy, or VPN everything back to on-premise kit. We have other customers using Intune MDM for their iPads too so happy to help configure that if needed. Drop me or Marc a PM if you'd like to try it out for free.
DGardiner Posted October 22, 2020 Posted October 22, 2020 Hi, As Marc mentioned we at Securly have native cloud filtering and real-time alerts for iPads using Safari, no need to install apps, proxy, or VPN everything back to on-premise kit. We have other customers using Intune MDM for their iPads too so happy to help configure that if needed. Drop me or Marc a PM if you'd like to try it out for free. thats a lie... a proxy.pac file is a proxy... your offsite es exactly the same as SW except you use a cloud based proxy smoothwall uses on premproxy
Brimstone Posted October 23, 2020 Posted October 23, 2020 Yeah. Every browser on iOS, even Chrome, is based on Safari and nothing else as Apple require you to use it. Thats incorrect, just because developers are using the same core API, the render engine may be same but the wrapper around this and browser functions are massively different, especially when you have students using iOS, below are just a few Safari only functions that do not appear in other "crippled" browsers. Safari Reader view - converts the web page minus the adverts so make reading lots of text much easier Accessibility - Safari is the only browser on iOS that fully supports dyslexia readers and voice over, other claim to be able to do this, I've tried a few and they stink PDF - Safri can convert a whole site into PDF's Apple Classroom - Teachers use Classroom can easily drag and drop url's to students Auto Translation - Translates language text, Cross Site Tracking - This can be blocked via MDM profile configuration restrictions, unlike other browsers The only one I've tried that comes anywhere near would be Firefox but it's slow and clunky when comapred with Safari on iOS.
Brimstone Posted October 23, 2020 Posted October 23, 2020 thats a lie... a proxy.pac file is a proxy... your offsite es exactly the same as SW except you use a cloud based proxy smoothwall uses on premproxy It's not a standard PAC file...do some reading If you are using an onprem proxy like SW I hope you've got a very fast upload and download speeds, your comparison is not like for like. 2
Primus Posted October 23, 2020 Posted October 23, 2020 It's not a standard PAC file...do some reading If you are using an onprem proxy like SW I hope you've got a very fast upload and download speeds, your comparison is not like for like. From Securly's own website: "On-Site and Off-Site Solution: A PAC file that is created by your Sales Engineer is a hard requirement for any off-site iPads. Please reach out to your Sales Engineer by submitting an email to [email protected] to have this created for you."
jblackburnHWGA Posted October 26, 2020 Author Posted October 26, 2020 yea this is the bit I'm at now. Smoothwall have a global proxy which works quite well actually. My problem is I can't get it to work on Ipads as i need to add the school external address and the Smoothwall name as exceptions. Two things it seems you can't do on ipads. I'm trying to figure out the pac file but i can't use the smoothwall pac file as its already in use on prem as its what we use to connect devices lol I have requested a demo with Securly to have a look at their solution, they've quoted me and the price isn't too bad for 500 devices so looks promising. If i can get Smoothwall working to my satisfaction then great but its good to have a backup/better option
Securly_Chris Posted October 26, 2020 Posted October 26, 2020 Thanks Brimstone, DGardiner - you're correct in that traditionally proxy.pac files were just used to send pretty much everything back to a proxy, maybe a few static exceptions for local servers / networks - used to do this a lot when I worked for Smoothwall. This can be tricky when off-site since you need both good upload / download bandwidth to your appliance since the path is Browser -> On Prem Proxy -> Website -> On-Prem Proxy -> Browser. Few streaming videos can max that out very quickly. Securly is different - we took advantage of PAC files since they're cross-platform, easy to centrally implement and lightweight, especially on iPads where Apple are strict about what you can do with filtering. We provide you with a ready made PAC file URL which you can deploy. Instead of pushing all traffic to a proxy, we are able to utilise our low latency cloud API within the PAC file to work out what needs to be allowed / blocked or scanned in more detail without sending all the traffic via a proxy server It can even do SSO, great for 1:1 iPads. Where we do need to intercept, HTTPS content for example, we do this in our cloud so we ensure there's enough bandwidth and resources available at all times to handle this. If you'd like to learn more one of our founders Vinay wrote an deep-dive tech article on it here; https://blog.securly.com/2020/05/02/remote-filtering-technical-deep-dive-securlys-smartpac-vs-traditional-pac-files-apples-ios-agents/ HTH - Chris 1
ibpalle Posted October 26, 2020 Posted October 26, 2020 jblackburnHWGA The PAC file you use for internal and external can be different but obviously then has to be hosted elsewhere. However, if you resolve the external hostname to the internal IP of the Smoothwall while users are in the network and to the external address when they are outside the network, you can nuse the same PAC file for both internal and external users with no issues. Then add both IPs and hostname to the exceptions.
jblackburnHWGA Posted October 26, 2020 Author Posted October 26, 2020 thanks Ibpalle, i'll give it a go. The ipads are on a different proxy port as in this case we're filtering without authentication and just pushing all users on said port through as student filtering. I don't see how I can do this with one Pac file. I've got some of the best minds at Smoothwall working on it
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now