SteveB_NI Posted February 4, 2021 Posted February 4, 2021 I’m trying to figure this out & getting no where so all advice welcome! An event Is taking place soon in my school which involves live streaming / broadcasting. The current set up in the event location room is a network ports linked to a switch which then further connects to a core switch (with the broadband router connected to it directly) in a far off location. We have a proxy server filtering all traffic between switch and router. Ideally to make things easier and no reliance on inputting proxy settings / bypass settings - how would I best go about giving the company unfiltered internet access for the brief time they are onsite? No pupils & other staff will be onsite at the time using the network so not worried so much about the filtering requirement for that time. Thanks so much for any help
3s-gtech Posted February 4, 2021 Posted February 4, 2021 Using a wpad.dat setup, with the proxy settings in a file on an IIS server that is available to unauthenticated clients should work. As long as they have ‘automatically detect settings’ in Internet Options, they should find the file via DHCP. Set the proxy settings in the file to a passthrough port or policy on your filtering.
SteveB_NI Posted February 4, 2021 Author Posted February 4, 2021 Thanks for the suggestion - it got me thinking actually I can enable our Captive Portal on Censornet which would maybe help here - then possibly ensure they have a relatively lax restrictive credentials.
Cache Posted February 4, 2021 Posted February 4, 2021 Could ask for the MAC addresses in advance, create a reservation and then allow that IP to bypass the proxy/browse without authentication or apply authentication based on IP? I've done that before. 1
Abaddon Posted February 5, 2021 Posted February 5, 2021 Could ask for the MAC addresses in advance, create a reservation and then allow that IP to bypass the proxy/browse without authentication or apply authentication based on IP? I've done that before. This one - always easier to keep track of and disable. A little more work to start with perhaps, but not a lot.
computer_expert Posted February 5, 2021 Posted February 5, 2021 Could ask for the MAC addresses in advance, create a reservation and then allow that IP to bypass the proxy/browse without authentication or apply authentication based on IP? I've done that before. That may be a bit more tricker now that Windows, Android and iOS use MAC address randomisation.
MatthewL Posted February 5, 2021 Posted February 5, 2021 Create a rule in the firewall to allow access out to internet from specific IP address and bypass that in the proxy or supply a PC and do the same if they don't need anything specific on the laptop other than say PowerPoint etc.
JRA Posted February 27, 2021 Posted February 27, 2021 You got VLANS there or no? If so can you let traffic for one VLAN directly out in the firewall? That way when SLT love this event so much that they have them weekly from now on (inevitable?) can always just plug some ports in on the back end to your "just goes in and out" VLAN.
chazzy2501 Posted March 1, 2021 Posted March 1, 2021 I purchased a second domestic internet connection (like at home) stuck the router on its own un-routed Vlan and then just pop a port on that vlan if needed, I also have a site wide SSID for it as well. Cheaper than a dedicated BYOD solution but not a replacement.
JRA Posted March 1, 2021 Posted March 1, 2021 I purchased a second domestic internet connection (like at home) stuck the router on its own un-routed Vlan and then just pop a port on that vlan if needed, I also have a site wide SSID for it as well. Cheaper than a dedicated BYOD solution but not a replacement. It's simple, bit "quick and dirty" but you got just what you need from it - route out directly with no faff. Two thumbs up job done.
caffrey Posted March 1, 2021 Posted March 1, 2021 The way I do it here, is have a couple of public IPs and two gateways Gateway 1 is filtered, Gateway 2 is unfiltered (Albiet Pihole DNS) routed on a unifi USG Give a pc a static IP and gateway 2 = bypass filter
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now