Jump to content

Recommended Posts

Posted

I just pop on the SSL cert on servers and nothing else. Securly won't block updates and the like and of course you never browser on server.

 

Yes - all filtering methods other than the guest prompt the user to auth (well not ChromeOS with the extension as it just knows who you are).

 

Use the guest DNS settings if you don't have more than one external IP.

  • Thanks 1
Posted
The way have it setup is our DNS forwarders on our DC point to Securly, meaning if a device doesn't have the SSL/SmartPAC/Extension they get basic DNS based filtering. This works for headless devices like tills etc. Plus also our guest network. We then install the PAC or extension on managed devices to get a more granular level of filtering. Like others have said you can't filter by specific internal addresses, the only way to achieve that is to have that VLAN leave the network on a different external IP, you can then apply a set level of filtering to that in the Securly UI. We have had this running for 3 months now and I can say hand on heart it's far better than the smoothwalls we were using before.
  • Thanks 1
Posted (edited)

Thanks everyone for your input.

 

I'm thinking out loud here, what do you do about those few nuisance devices that you are asked to connect to the internet such as xbox's, firesticks ect... From the looks of it these would fall to the default policy (can a firestick display a splash page!?) or guest policy and as such these policies would have to allow the streaming websites category (or equivalent) on the whole policy. I currently create a custom policy for things like this and apply it just to the IP of that device.

 

I'm know I'm being very nitty gritty but I'm thinking of scenarios have come up and its more valuable to have a real word answer than a sales answer.

Edited by speakercon
Posted
Correct they would get the default filtering which is technically the guest policy, this does not force login as it's just basic DNS filtering. It's also the most relaxed filtering. Not had any issues with things being blocked as yet. You could always set a static DNS server on the device which bypasses the filtering entirely. Unless you will be blocking all other DNS on your firewall apart from Securly. Which is a good idea.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...