John1981 Posted November 25, 2021 Posted November 25, 2021 (edited) Hi All, Just looking for information on peoples experiences with the Netsweeper client filter. We've recently rolled it out and have found several issues: Clients losing their network connection taking several reboots to get back onto the network Whitelisting anything in the client requires a reinstall with an updated MST file file supplied from Netsweeper themselves? That seems a poor way of managing the software.. General performance issues with delays accessing the web. filtering executables when our config states it should only filter browser traffic I have several calls in with Netsweeper but just wanted to see if anyone here is using the client and has seen the above issues and managed to get them resolved? Cheers John Edited November 25, 2021 by John1981
PaddyNewman Posted November 25, 2021 Posted November 25, 2021 I use/test/PoC it here. Clients losing their network connection taking several reboots to get back onto the network No idea about that one, I certainly haven't seen that Whitelisting anything in the client requires a reinstall with an updated MST file file supplied from Netsweeper themselves? That seems a poor way of managing the software.. I am in the same boat, pushed out to an InTune managed device and could no longer manage as one of the items was being decrypted and didn't like it. You can do whitelisting yourself though within the NSEXCEPTIONS part of the MSI. General performance issues with delays accessing the web. If you run it on low end machines, I felt it was a bit iffy. Put on an older gen2 i5 laptop with 4GB RAM (!) and it felt remarkably doggy, but it is doing the SSL items locally and the laptop is a bit trash, same MSI on an gen6 i7 device with 8GB RAM, no problems. I feel its down to the local physical architecture at that point. filtering executables when our config states it should only filter browser traffic It definitely does EXEs, it shows you that in the list however you can add those exceptions also, they should be able to advise you on how to do this within the MSI, I don't think its documented on their support pages though.
DavidYoung Posted November 25, 2021 Posted November 25, 2021 Hi John, I built a fairly large client filter deployment, my day-to-day experience is more on Chrome and iOS but I assume you're talking Windows. Clients losing their network connection taking several reboots to get back onto the network I don't think we've had any reports of this issue. Whitelisting anything in the client requires a reinstall with an updated MST file file supplied from Netsweeper themselves? That seems a poor way of managing the software. Yes, this is annoying. As Paddy mentioned, you can create the MST yourself with something like ORCA, if you inspect the properties of one they've sent you you can work out the format needed. General performance issues with delays accessing the web. Again, not aware of any reports, however it will depend on the machine resources. filtering executables when our config states it should only filter browser traffic The application runs as a local proxy server so will by default filter all traffic. You can exclude individual applications by adding the as filtering exceptions. I don't know if there's a way to do it the other way around, i.e. only filter some applications and exclude everything else. If you use Chrome or Edge and only want the browser to be filtered you might have a better experience using their Chrome extension but remember there will likely be other ways to get web access in Windows.
John1981 Posted November 25, 2021 Author Posted November 25, 2021 Thanks Paddy and David much appreciated! The network dropouts could be anything really so I'll discount those until we can work out whats going on there.. As "phase one" we asked for only browser traffic to be filtered so we have the a list of browser executables with the action of "normal filtering" and have an entry of exe:// "allow always" but I'm sure https inspection is still happening as our vpn executable is having issues talking to a secure url for connection due to what looks like https inspection. Would i need another entry to block decryption for executables in general? But the Chrome extensions seems like a more manageable way to filter browser traffic until we've ironed out the various issues we're having. I've downloaded Orca and can open the MSI settings though I can't see anything obvious when looking for NSEXCEPTIONS We'll have to do some troubleshooting on the slow internet and intermediate internet issues as I'm experiencing it on my laptop (8th gen i5 and 16gb of ram) Both at home and in our office. But if thats sufficient then maybe something else is causing the issues. Again, appreciate your comments.
PaddyNewman Posted November 26, 2021 Posted November 26, 2021 Hi John, Buried in something right now so can't go on the hunt, but within the MSI > Property area there is an NSEXCEPTIONS area. Mine currently has a 0 in there, but it can be amended. You should be able to extract your current exceptions and paste into that field directly from text. I can't recall right now as its in one of my hundreds of text files, but that lets you add to the bypassing list.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now