Jump to content

Recommended Posts

Posted

My first impressions of Securly has been quite poor. We are a new customer, purchased a couple of weeks ago. Got an onboarding form quite quickly, filled it out with as much technical information that I could. An email from Craig with my logon details and some onboarding information. Then, nothing. No calls, follow up emails, just a list of "this is what we might suggest as a way to setting things up". There is a widget in the bottom corner of the Securly screen with how to set the basics but it isnt intuitive - i.e. it tells me to do something but not why, the 40 minute youtube video shows a lot of information on a fully working system but nothing on how to get there - I would prefer to plan what I am going to do and why rather than just blindly follow a "click this, do that". Especially as it becomes harder to change things once you get started.

 

However, im a network manager so I can dig through the screens and i'm a dab hand at google and reddit forums. First, I needed to find how securly actually works - that gives me an idea of how im going to lay things out. I managed to find this: https://www.securly.com/assets/images/DNSwhitepaper_final.pdf

 

So at heart Securly has two DNS streams and a proxy that can be authenticated should you require. One DNS goes through the proxy, the other DNS blackholes unwanted sites. You need an SSL certificate installing for functionality (pure guests can get away without if they are happy to get an unsafe webpage error for redirected HTTPS bad sites - this is to be expected of course). There is a Securly chrome and edge extension available, I have no idea why I need this or what it does.

 

Now I can get down to it.

  • Set my firewall to allow client egress to securly IPs for DNS and proxy (we currently have an inline proxy with PAC so there is no direct egress for our clients).
  • Import from azure AD went without a hitch, created a couple of test profiles (you cannot rename the profiles, make sure you choose a sensible name), map the profile to an azure group and all is good.
  • My first test PC setup with smartPAC seemed to work but would only filter with the default group, it would not pick up on my "proper mapped group for my azure AD group membership". Teasingly there is a "you might be seeing this if you havent logged in" button in the corner of the block screen. I click this, it now seems to recognise me as a 365 logged in user now. At least this gives me something to google.
  • Searched the get started https://support.securly.com/hc/en-us/sections/4405534891031-Get-Started for answers and found references to installing an extension (I wanted a fairly seamless approach, adding an extension was not mentioned by sales - in fact one of the selling points was that nothing needed to be added as the smartpac took care of things). No mention in the docs of why I need to add an extension or what it does. I decide not to install this.
  • Then found another article that says I need to run an IIS server (not an existing one) to get 365 SSO (?) Sales DEFINITELY said nothing about that https://support.securly.com/hc/en-us/articles/115004747727-How-to-set-up-Office-365-Azure-AD-SSO-IIS-server- Im not going to run a random PS1 script with no breakdown or manual instructions on what it does on my IIS. The article also says I need to do this to get the groups setup from my AzureAD. Thats odd because I already did that by clicking on groups and accepting my azure AD permission. I decide not to do this.
  • In the end I appeared to sort it by switching a global setting named "Force logins" but I suspect this will cause me issues later.

 

so now my domain logged in client that uses chrome with 365 SSO for all our other 365 browser authenticated apps will now correctly filter according to the mapped azure group -> securly profile. Time to set up guests:

  • Guest access is via guest DNS, not a problem as that is what I do for our current guest networks; we have two - one for staff BYOD and one for pupil/IOT BYOD. Staff use unifi vouchers to get on their network, pupils use a "known" SSID password. we are in the process of moving to packetfence for both. Separate VLANS, separate egress (pupil BYOD uses the backup internet line), separate filtered profiles.
  • Now for the biggie, you cannot have more than one guest profile on Securly - I emailed support asking how to add a second "guest" profile as I did not seem to have the ability to do so on the Securly screen. Securly can identify ingress IP and can determine if a "guest" has used one of your particular public IP (so could in theory have multiple guest profiles for each of your public IPs) but will not let you create additional guest profiles to do so.
  • Securly WILL let you create a custom IP profile that will trigger on ingress from a certain IP *but* requires that profile to be authenticated (as I have just clicked force logons to get round the issue above). There does not appear to be a way to ask for logons on certain profiles. sure I could ask staff that BYOD to use their school password but this will be useless for the visiting saleman doing a presentation or guests in assembly having a presentation - they will not have a school logon (and I am loathe to create "known password" logons, no matter how locked down they are!). The pupil BYOD is also used for IOT devices (photocopiers wanting to phone home, DAVIS weather stations, That drama projector that insists is needs internet access) that require the internet - those can live on the pupil heavily filtered vlan and be kept well away from anything else. That also means unauthenticated. Staff BYOD will allow more unrestricted youtube, social media etc. Pupils will have these tightened.
  • I emailed support regarding the above and simply got a "no, you cannot do that, we support one guest profile". No work around, no pointers.
  • I listed my thoughts on a potential solution as a reply to the support email and have just had a reply from Chris to say that my solution should work and is "pretty much how Securly works". Well why didnt you say that in the first place? Are we the only school to ever require a two tier guest filtered network?
  • I have no idea on ways to whitelist the Securly certificate self help page from monitoring, which is available in SSL only ( securly.com/ssl ). In my old system the guest network would whitelist the certificate page from both authentication requirement and https bumping.

 

Shortcomings in using:

  • There is no way of re-categorising a certain site internally. There is a way of adding a site for "consideration" of re-categorising. So if you have 5 profiles and http://www.this_is_a_site_im_happy_to_allow.com happens to be a "real gambling site" but you are allowing it for a reason then you have to add this to all 5 profiles, you cannot do an internal re-categorisation. Obviously this IS a gambling site but might be allowed for "you" as an "educational gambling" site. We have had quite a few sites in the past that have been allowed (old flash gaming websites that ARE technically gaming websites but are allowed for various reasons) to be re-categorised "internally" as allowed.

 

Im not saying the above is impossible but I have had to sort all of it out myself. In short, Securly seems to be capable as a product. Support have gotten back to me initially with no help but on pressing with a little more (due to my own googling and research not through any help of Securly) they have responded a little better. Onboarding though has been very bad, and since this is the "first contact" im already off to a negative.

Posted

Hi KK20,

 

Thanks for the detailed overview.

 

Apologies if you haven't had the contact from Securly you would have liked - we typically provide meeting links to schedule time with our engineers on your onboarding form, so that we are not pressuring customers but instead letting them use our resources whenever they need to - all support and professional services are free and you have unlimited access - I appreciate this doesn't work for everybody though and that reaching out to you directly to check in is helpful so i'd be more than happy to set up a call with myself and one of our senior engineers to address your points above.

 

You can reach me directly at [email protected] or on 07889670691 - or if you'd like to DM me your details, i'll send over some updated onboarding documentation and our live booking systems so that you are able to schedule time with our engineers directly to assist.

 

Thanks,

 

Marc

Posted
Sounds good. I will get a wishlist of "this is what I have done, how do I now do this" to you later week. Ive pretty much gotten it working now with my test machine, it is just the guests I need to test when I get a chance. I have shelved this rollout for the time being (I have another month remaining on my current filter license) as other things have come up today.
Posted

I'm quite surprised regarding onboarding - when we signed up they were very insistent we had an onboarding session with an engineer to get everything running.

 

That said, I do agree about flexibility - it is not a flexible system. Lots of features it could do with adding, and a total lack of any process to push for changes - things just disappear into a black hole and nothing changes.

Posted
the exact opposite for me. short of raising another ticket to ask for help the most information ive had was from Marc up above.
Posted

Perfect, thank you.

 

If anything at all crops up which you'd like to discuss or run through in more detail, please reach out to me.

 

Our Snr Pre-Sales engineer Craig, who sent your onboarding doc is available on here too - @CJF

and our Head of UK Support Chris is also available on here too - Securly_Chris.

 

Thanks,

 

Marc

Posted (edited)

With the help from Chris I have managed to get a working solution. Tweaks needed to be made behind the scenes (the setting was not available in the GUI)

 

1) We now have Staff BYOD using the regular Securly guest DNS - this worked originally and we can set the "guest policy" in securly to be lightly filtered.

2) Pupil BYOD needed a little tweaking. I was mostly there with a separate "IP policy" and our Pupil BYOD egressing on a specific public IP. What Chris needed to do is manually disable authentication on this public IP. Now I can set a more stringent filtering on this custom IP policy. This uses the "regular" securly DNS but will also need the certificate installing (unfortunate but cannot be helped). At least the securly.com/ssl page doesnt put a https cert error. I am offering that to our pupils from the wifi landing page.

 

Notes so far.

 

As earlier, you cannot recategorise domains internally. this is now a pain. I am up to 8 policies and we are a small school (on account of needing the separate guest policies, "games" policy allowed at lunch, staff, young pupils, older pupils). If I wish to "allow" a website, that is 8 policies I need to go into rather than a simple "recategorise internally". NOTE! I am not talking false positives, this is a genuinely categorised website that we allow (these are usually gaming websites that we allow, some for ICT etc)

 

You can only assign a single IP to an IP policy. We have internet failover and our smartDNS will failover at the same time. this gives two potential egress IPs for our pupil BYOD policy. I need to clone (and independently update) the pupil BYOD policy. It would have been nice to allow custom IP policies to have more than one IP.

 

You have to go to support to selectively disable authentication on policies. Not sure why this cannot be in the GUI - especially for custom IP policies. This is also not mentioned in the documentation and would have saved a lot of time - as I said earlier, I cannot be the only person to have used 2 guest WIFI "tiers"?

 

No user lookup when adding usernames etc. A small but annoying mention. Typing a full name rather than having a user lookup (similar to how 365 works) is annoying, especially when typing a list of email addresses or when searching for our Czech and Polish staff- my spelling is not the best and the 365 autopopup is a godsend (I am actually using outlook address book to copy and paste into securly!)

 

You cannot rename a policy. You need to clone, remap to all the groups.

 

It is hard to locate which policies are mapped to which groups (for example if you need to clone and rename). The policy page does not give a list of what it is mapped to and the mapping page will not let you filter by policy. Since our Azure AD has teams with all our sets, we have rather a few security groups to wade through. Obviously we only use the core pupil year groups but it would be nice to have at least a filter.

 

Safeguarding groups cannot be assigned to policies. I.e. we have younger pupils and older pupils. Separate staff cover younger and older pupils, it would be nice to have triggers sent to appropriate groups depending on the policy that triggered it. Likewise guest "triggers" sent to a separate group. I understand that auditor is a separate package but this would seem a logical decision for safeguarding.

 

Support got back to me quite quickly and was efficient (thank you Chris). I had forgotten about my failover IPs, they were added very quickly to our account.

Edited by KK20
Posted

This is a little disheartening. Was looking at Securly as a possible replacement for our Smoothwall but it's more expensive and lacks the firewall element of Smoothies UTM.

Wondering if it's "better the devil you know" for another couple of years....

Posted

dont get me wrong, it is working and since I have gotten in touch with Chris directly things progressed quickly, support did get back to me. I was very disappointed in the start though - I am technical and (given the time) like to get under the bonnet but others may just want a "just make it work for me" approach. I am surprised securly was more expensive than smoothwall for you though, smoothwall was literally twice the price of securly for us (even their "small school" option) and works "cloud based" so offsite.

 

However, dont just trust the demonstration, one mistake I made was to not run a thorough trial, that one is on me as I would have been better prepared.

 

Your mileage may vary as they say - there are a number of people who it went very smoothly for on here.

  • Thanks 1
Posted

Thanks KK20. Luckily I have a little bit of time before I need to take the plunge so I do have a trial in the works.

The quote is not hugely more expensive than Smoothwall so if the trial goes well I'd have no issue with making the switch.

Posted (edited)
we use a pfsense firewall with snort and pfblockerNG. This works will with Securly as our guest networks have a captive portal. The gotcha being our domain DNS server has a forward to Securly DNS but the guest network cannot simply DHCP the Securly DNS (or the captive portal wouldnt work, nor local web server etc). PFSense has a DNS forwarder (dnsmasq) capability which can be bound to the guest vlan - so now there are static hosts in the DNS forwarder with a DNS forward to Securly Guest DNS. Edited by KK20
  • 3 months later...
Posted

Our experience with deploying Securly to several schools as an MSP has been similar.

 

The sales people are decent, but the onboarding session promised is non-existent and there's a bunch of settings that you have to go through support to change which is not helpful when doing a migration over a weekend.

 

Expected more for the cost really...

Posted (edited)

5 months on and we are doing "ok". There are a number of small nuances such as no ability to add a comment to the block or allow. For example "why was myairbridge.com allowed?" there is simply a mass of URLs that have been allowed.

 

There are overall categories but not many. Our previous filter had a good 40 categories that you could allow/block before needing to resort to manual block/allow, securly has 14. The allow list is growing exponentially. You cannot filter BBC iplayer at all as the proxy is not located in the UK it seems, you need to add a blanket exception to iplayer. Im not sure how other streaming platforms fare as we dont use others. Performance can be hit and miss at peak times, we do get a slowdown from the securly proxy which is noticeable if you are allowed to remove the smartpac option. Not enough to cause an issue overall but certainly noticeable. Ability to use the smartpac on devices that are off premises is good and works, pupil (and staff) devices do work offsite nicely.

 

Overall our first few months have been "ok" but there are improvements that could be made. Still, it was cheaper than the others and budget was a concern for us.

Edited by KK20
Posted

You not on the UK cluster then? iPlayer works fine for us. They do have an EU one based in Ireland but you should be on the UK one to avoid issues with the likes of iPlayer.

Anyways all seems to work great across our 28 schools.

  • Thanks 1
Posted (edited)

Here is a direct copy of the support reply when I queried it:

 

Unfortunately, while our AWS datacentre is in the UK, BBC has marked some of our IP as outside the region.

 

To avoid this you would need to add bbc.co.uk and bbc.com to your global allow list. How do I allow or block websites and custom keywords with the Nucleus UI?

 

All our BBC iplayer requests state that we arent in the UK so I needed to add BBC to the allow list.

Edited by KK20
Posted

Our single test roll out so far has been a success. Once we got the correct smartPAC in (both support and us missed a crucial mis-type) its been great.

 

Of course the proof will be when we roll out to all our schools.

 

The multi school portal needs work - lots of info we can’t see in there and things.

  • 3 weeks later...
Posted

Really interesting reading this, we currently have Smoothwall at two sites, it has its quirks, most annoyingly the idex agent not detecting a login and the need to log off and on again, or restart the service on the domain controllers. Reporting is rubbish, even with the cloud enhancements. Support has been a bit better of late, last year it took days to get a response. But for the most part it works. Plus it's nice and easy to setup different filtering levels based on IP ranges within the schools for guest etc.

 

We've had the renewal through for next year and it's very competitivly priced. Securly is almost the same price over three years. This also includes adding a third site, so three UTM's. Lightspeed is slightly more expensive, but I have again heard story's of client issues etc.

 

To add to the the cost with the Securly/lightspeed option we are going to have to source separate firewalls for each location. We have had pricing for WatchGuard that's somewhere between 4K and 8k each site depending on size. So the costs really start to stack up.

 

The cheapest firewall solution looks to be pfSense, that's looking like 13k over 3 years with 3 X Netgate boxes, installation and some support from the 3rd party. I know we could run this on some of our own hardware, but I am not a firewall expert and would like someone who does it for a living to set them up.

 

I am wondering like others if it's better the devil you know!

Posted

We use Securly across our Trust - 28 Schools from 2000+ Secondaries to little 100 pupil primaries. One filtering console - policies for each school. Dead easy to use and setup.

 

Firewalls at Primaries are Unifi UDM Pros - managed on one console - easy to configure and just work. Secondaries - couple of old Smoothwall boxes as just firewalls now, one WatchGuard (new build) and the rest Untangle - free version on an inexpensive bit of tin. Certainly nothing in the many k's price bracket for us.

  • 6 months later...
Posted

Sorry to tag onto an old thread, but...

 

From what I can see any devices that don't have the browser extension installed all fall to guest policy is that correct?

 

For example a group of devices (eg android box's built into ITV's) on their own vlan, it would not be possible to aim a policy as these specifically based on their internal IP address the way you can on a hardware appliance?

Posted

Browser extension is for ChromeOS only. Other devices you would use either DNS filtering or SMARTPac or both.

 

You could also point things to your guest filtering policy which is what we sometimes to things that just need internet access (e.g so tills at primaries).

 

If something does not authenticate - it will be dumped onto the default policy which sounds like what's going on here.

  • Thanks 1
Posted

Ah I see, we're not using it at the moment I'm investigating how it would work with our setup so this is all usefull info.

 

So for Chromebooks you use the browser extension, Windows devices use the SMARTPac agent.

 

Any other devices where these options are not available DNS filtering is used but all of these would fall under the default policy, its not possible to seperate based on internal IP address.

 

But you can have a seperate guest policy.

 

Have I got all that correct?

 

 

 

Posted

More or less.

 

Smartpac proxy you push to any devices that support this - which is most - ipads, Windows and so on. DNS works on anything and will prompt for user login. You can have a separate guest network either on a different external IP that you tell Securly or you use the Guest DNS servers. The guest does not require signin.

  • Thanks 1
Posted

So I guess you would need to put the Smartpac on servers too in order to whitelist these from filtering?

 

Okay so anything without the extension or proxy you would be prompted for account log in and then you'll get the relevant user policy.

 

The guest policy requires no log in, if you don't have another external IP you would set the guest vlan DNS address' in DHCP to theirs?

 

Thanks again

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...