Jump to content

Recommended Posts

Posted

I’m trying to figure this out & getting no where so all advice welcome!

 

An event Is taking place soon in my school which involves live streaming / broadcasting.

 

The current set up in the event location room is a network ports linked to a switch which then further connects to a core switch (with the broadband router connected to it directly) in a far off location.

 

We have a proxy server filtering all traffic between switch and router.

 

Ideally to make things easier and no reliance on inputting proxy settings / bypass settings - how would I best go about giving the company unfiltered internet access for the brief time they are onsite?

 

No pupils & other staff will be onsite at the time using the network so not worried so much about the filtering requirement for that time.

 

Thanks so much for any help

Posted
Using a wpad.dat setup, with the proxy settings in a file on an IIS server that is available to unauthenticated clients should work. As long as they have ‘automatically detect settings’ in Internet Options, they should find the file via DHCP. Set the proxy settings in the file to a passthrough port or policy on your filtering.
Posted
Thanks for the suggestion - it got me thinking actually I can enable our Captive Portal on Censornet which would maybe help here - then possibly ensure they have a relatively lax restrictive credentials.
Posted
Could ask for the MAC addresses in advance, create a reservation and then allow that IP to bypass the proxy/browse without authentication or apply authentication based on IP? I've done that before.
  • Thanks 1
Posted
Could ask for the MAC addresses in advance, create a reservation and then allow that IP to bypass the proxy/browse without authentication or apply authentication based on IP? I've done that before.

 

This one - always easier to keep track of and disable. A little more work to start with perhaps, but not a lot.

Posted
Could ask for the MAC addresses in advance, create a reservation and then allow that IP to bypass the proxy/browse without authentication or apply authentication based on IP? I've done that before.

 

That may be a bit more tricker now that Windows, Android and iOS use MAC address randomisation.

Posted
Create a rule in the firewall to allow access out to internet from specific IP address and bypass that in the proxy or supply a PC and do the same if they don't need anything specific on the laptop other than say PowerPoint etc.
  • 3 weeks later...
Posted

You got VLANS there or no? If so can you let traffic for one VLAN directly out in the firewall?

 

That way when SLT love this event so much that they have them weekly from now on (inevitable?) can always just plug some ports in on the back end to your "just goes in and out" VLAN.

Posted

I purchased a second domestic internet connection (like at home) stuck the router on its own un-routed Vlan and then just pop a port on that vlan if needed, I also have a site wide SSID for it as well.

 

Cheaper than a dedicated BYOD solution but not a replacement.

Posted
I purchased a second domestic internet connection (like at home) stuck the router on its own un-routed Vlan and then just pop a port on that vlan if needed, I also have a site wide SSID for it as well.

 

Cheaper than a dedicated BYOD solution but not a replacement.

It's simple, bit "quick and dirty" but you got just what you need from it - route out directly with no faff. Two thumbs up job done.

Posted

The way I do it here, is have a couple of public IPs and two gateways

 

Gateway 1 is filtered, Gateway 2 is unfiltered (Albiet Pihole DNS) routed on a unifi USG

 

Give a pc a static IP and gateway 2 = bypass filter

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...