petben Posted June 16, 2021 Posted June 16, 2021 Hello, I am testing Smoothwall Cloud Filter on a few student laptops (managed by Intune) and the Edge browser extension that Smoothwall installs for filtering works, as do the recommended polices to make it forced, disable Private browsing etc. But I am feeling very uneasy about removing all other filtering for these devices (recommended by Smoothwall to prevent 'double filtering') My first attempt to run Edge from a shortcut with extensions disabled works fine and gives the user complete unfiltered Internet access. I bet there are other ways. "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --disable-extensions can anyone recommend how to stop the above and any other gotchas they found where users can get round the filtering? Thanks
ibpalle Posted June 16, 2021 Posted June 16, 2021 If the device is on-prem then a browser without the extension enabled would get filtered by the on-prem Smoothwall - at least when the secret knock refresh times runs out (default is 600 seconds I believe). Off site it is an issue that only traffic from the browsers with the extension gets filtered, if the user runs a firefox off a USB stick, unfiltered access is available. With the cloud extension on Windows devices, some measure of lockdowns in the OS are needed to prevent for example, running the browser with extensions disabled.
petben Posted June 16, 2021 Author Posted June 16, 2021 OK, it is recommended to use VLANs and have no filtering other than the extension: https://kb.smoothwall.com/hc/en-us/articles/360015978080-Smoothwall-Filter-Firewall-Preparing-for-Cloud-Filter-to-avoid-Double-Filtering Where the Smoothwall Firewall & Filter is deployed with VLAN interfaces created, you can add the new VLAN to the Smoothwall without a Proxy Authentication policy, therefore all traffic from that VLAN (using the Smoothwall as the gateway) will go unfiltered by Guardian and go straight out to the Internet via the Firewall module. anyway, do you know how in the OS to prevent running the browser with extensions disabled? and prevent running browsers off USB? Thanks
ibpalle Posted June 16, 2021 Posted June 16, 2021 That KB is valid but look at option 2 instead of using the VLAN method - we have added a feature called secret knock - this tells the extension on startup to inform the on-prem Smoothwall that web traffic from the browser is already filtered, so don't bother redirecting it. The secret knock should be configured on your system as it's part of both the setup instructions we send out and part of the implementation we perform when setting it up. If your roll-out happened 4-5 months ago that may not have been configured.
petben Posted June 16, 2021 Author Posted June 16, 2021 I don't understand the article then, that is absolutely not what it tells us to do. The 'Secret Knock' should be enabled on the Smoothwall Firewall & Filter to permit Cloud Filter devices to request filtering bypass from the on-prem solution where VLANS are not feasible. Option 2: Secret Knock Where VLANs are not feasible, or are in use but shared with non Cloud Filter Devices (BYOD networks, general WiFi, etc) then the Secret Knock should be configured. VLAN's are feasible on our network. We have a dedicated VLAN for these devices. Thanks
petben Posted June 17, 2021 Author Posted June 17, 2021 ibpalle - Can you please post a link to the latest Smoothwall instructions for installing cloud filter?
ibpalle Posted June 17, 2021 Posted June 17, 2021 We have four deployment types: The Guide for each deployment type is below: https://kb.smoothwall.com/hc/en-us/articles/360008478500-Installing-the-Smoothwall-Cloud-Filter-on-Chromebooks-using-Google-Admin https://kb.smoothwall.com/hc/en-us/articles/360017245300-Install-Cloud-Filter-on-Windows-10-using-Intune-Edge-Only- https://kb.smoothwall.com/hc/en-us/articles/360003615779-Install-Cloud-Filter-on-Windows-10-using-Domain-Group-Policy-Object-GPO- https://kb.smoothwall.com/hc/en-us/articles/360017297219-Install-Cloud-Filter-on-Windows-10-using-Intune-Multiple-Browsers- Additional Notes: With Cloud Filter, Web Filtering is provided as an extension in the browser. The Cloud Filtering License can be linked to a specific on-prem Smoothwall which means Cloud Filter Clients will be subject to the on-prem Web Filtering rules regardless of physical location. When the License for Cloud Filter is complete and linked to the on prem device serial (Smoothwall do this for you), it is the logout button on the UI that syncs changes to the Cloud Filter Clients. Cloud Filter reporting data from the Clients will be available on the on-prem device every hour, and Guardian Web filtering changes take roughly 10min to replicate to the Client devices after Logging out of the on-prem UI. Smoothwall Filter & Firewall: Preparing for Cloud Filter to avoid Double Filtering https://kb.smoothwall.com/hc/en-us/articles/360015978080 Post Deployment Testing Ensure that the Smoothwall Cloud Filter extension has been installed in the relevant browsers (Should be visible at the top right). Navigate to the diagnostics page using the kb below and ensure: “Filter Mode” = Mode 2. Client username and group mappings are correct Finally, make sure a website you know should be blocked by your organisation is blocked by the Cloud Filter Cloud Filter Diagnostics https://kb.smoothwall.com/hc/en-us/articles/360016413920-Running-Cloud-Filter-Diagnostics Cloud Filter Realtime View https://kb.smoothwall.com/hc/en-us/articles/360006892380
petben Posted June 18, 2021 Author Posted June 18, 2021 We spoke to someone at Smoothwall and came to the following conclusion: 1. Use VLANs if you can, if you do then you do not use the secret knock method 2. Apply the 'Multiple Browser' script even if just using a single browser (we are using Edge) 3. Install the Unified client software (there is an Intune ready file supplied) 4. With this setup if students run a shortcut to start the browser with no extensions it logs them off. Everything is supplied by Smoothwall and seems to work fine, but the documentation is incorrect. 1
ibpalle Posted June 18, 2021 Posted June 18, 2021 I'll see what I can do to get the documentaion be more precise.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now