Jump to content

Recommended Posts

Posted

Hi our school has recently signed up for rm filtering only (we get broadband via virgin) but im having issues with the staff laptops. Filtering is great at site (proxy added) but when they go hone they cant access anything without having to remove the proxy (obviouly) RM tell me i need a pac file but thats were they leave it I have no knowledge of such things, anyone else come across this and know a fix

 

thanks

Posted

I have a shortcut placed on desktop that takes the user to the proxy settings box and allows you to turn off and on proxy - not ideal but works.

 

There is another way around depedning on your router, you could have a seperate vlan setup by RM for certain ip addresses where the proxy is store on the router so the laptop does not need the proxy set up. We have this for our guest wifi.

Posted

We use RM filtering within our school - currently have to guide staff to turn the proxy on/off manually.

 

I'd be interested in the PAC files if this is a better solution - following to see any thoughts.

  • 2 months later...
Posted
Am i missing something as their website states...

 

Transparent filtering – all connected devices are automatically filtered, no need to set a proxy

 

You can switch the transparent filtering on per subnet/ip range. And also set the level of transparent interception.

 

Alternatively you can have transparent filtering switched off and just use the proxy. It’s up to you how you configure your network. They just have the different options available these days so you don’t have to use the traditional proxy.

 

I think RM broadband have had transparent filtering option available for the past 10 years. Although it’s only been a user configurable option (Without a change request to support) in RM SafetyNet web interface for probably 5 years.

Posted
Am i missing something as their website states...

 

Transparent filtering – all connected devices are automatically filtered, no need to set a proxy

 

They probably are offering it as an add on if you don't want to go via their own connection. At that point, without magic routing, there is no way for it to be transparent, so you must explicitly state the endpoint.

 

We do something similar, but we bring the traffic to us via VPN, which is then transparent rather than explicit proxy. RM probably don't want to have VPNs all over the place.

Posted
In the past when I have worked in schools without transparent filtering I have put two shortcuts on the users desktops. They both reference a reg file turn the proxy on or off. Being able to just double click something seemed to be okay for the staff I have worked with.
Posted

Downside to the Transparent Proxy is that unless you play with assigning different IP ranges in RM Safetynet to different security policies, is you don't get any User Based logs, or group based filtering.

 

For our few staff loan laptops they are set as Transparent so they can function at home, and in school it just means they get the "Student" level filter which is the default with the most restrictions, compared to when they are on a normal device which can then put them through the Staff filter which is slightly less restricted (but does need a proxy address added)

 

If your wanting to keep User Based Filtering logs for when the students use the device in school, then you will need to go the pac route... if not just clear the proxy value so it's transparent and away it goes.

Posted
Downside to the Transparent Proxy is that unless you play with assigning different IP ranges in RM Safetynet to different security policies, is you don't get any User Based logs, or group based filtering.

 

Does it not support user authentication!?

Posted
Does it not support user authentication!?

 

I believe if you use the RADIUS authentication with your Wi-Fi system and pass credentials onto RM Safety you can still collect user logs whilst using transparent mode.

Posted
Does it not support user authentication!?

If you can send the Framed-ip-address on to the RM Radius accounting yes, as long as you also setup the RM unify Captive Portal as well as a fall back (and your not running it via any NAT which might cause issues!)

 

In the Safetynet Admin site, go to Network Configuration -> Radius and they have a guide on how to set it up with Windows NPS.

Ideally you would want to make sure your devices are on a different subset of IP addresses so you can set the different policy to it, otherwise if you have any guest WiFi setup with Transparent it will send those users to the captive portal to login with their RM unify details.

Posted

Normal User Based Filtering one domain devices is via network credentials so it's seemless.

You only need to use Radius if you want user based filtering and Transparent proxy on non-domain devices, such as BYoD

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...