dev101 Posted May 22, 2021 Posted May 22, 2021 Hello, I have been looking into using smoothwall as a replacement for forcepoint(SWG), I have some questions for anyone that has some experience on the product. With the forepoint we have a filter category called 'Miscellaneous/Uncategorized' and have it set to block by default, this ensures any new inappropriate website is blocked by default. As I understanding it smoothwall does not have this setting? if so how do you work around this?
Steve21 Posted May 22, 2021 Posted May 22, 2021 Pretty much all filters will have an option (named differently) to scan pages before they load which would detect anything unknown like that. So rather than default blocking it, it'll allow it if it's safe etc Steve
stujham Posted May 24, 2021 Posted May 24, 2021 [ATTACH=CONFIG]61885[/ATTACH] Initial setup to include a Core Blocked content system policy as per ours as shown, just tick the core content types to block. Then create policy's as required, as long as your allowed policy's are above the default Blocked Core content then all is good. Process's policy's from top down same as a firewall until it hits the default deny which is this policy.
TechMonkey Posted May 24, 2021 Posted May 24, 2021 Pretty much all filters will have an option (named differently) to scan pages before they load which would detect anything unknown like that. So rather than default blocking it, it'll allow it if it's safe etc Steve I may be misunderstanding but not all filters are content aware, most do not scan the page they only go by URL, so a new website that is not classified will either be allowed by default or with a specific rule blocked. I think there are only two that are fully content aware, Smoothwall and Openendium (spelling is probably wildly off sorry). You do need to be careful as I found a lot of the suppliers use the term 'content filtering' to mean they block the content of a webpage, not they read it and decide. I could never get an answer to what the alternative to this type of filtering was so what the differentiation was. If I understand the original question, you would need a default block rule, so everything is blocked, and then ensure that every category you want allowed is included in an allow rule. This would be pretty harshly locked down, but it is possible. 1
ibpalle Posted May 24, 2021 Posted May 24, 2021 The problem with a default block, rather than a default allow is that there is so much content served up to web pages from different domain names. Content delivery, facebook like, twitter retweet, adverts, cookies .... A default block for anything not specifically allowed could remove bits of web pages due to background blocking of content from other domains. Sometimes that good (ads) sometimes it's not. There may need to be donme a bit of whack-a-mole to get some sites working correctly. For a locked down network I'd suggest ensuring HTTPS inspection is on and blocks in place for inappropriate categories. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now