Jump to content

Recommended Posts

Posted
Sounds pretty much like proxy based web filtering solutions are unstable and don't offer the same experiance as on premise and don't really work . You probably need to look into SASE. Cloud native security tools that deliver the same security as an on premise solutions. These solutions are hosted in the cloud and offer the same security and filtering anytime anywhere . Look up the Gartner SASE magic quadrant 2023, there's only one vendor ranked as as leader currently.
Posted

So case study. We have deployed windows 11 via intune to laptops and desktops. The site also has a suite of managed Chromebooks that has the cloud filter extension. There is an onprem smoothwall and cloud filter. Azure authentication and google authentication with secret knock configured

 

What is the best practice.

Should devices on prem be filtered by the on prem smoothwall or should they be cloud filter?

 

We are finding that they are being filtered by both it seems. Witnessed an on prem block page followed shortly by cloud filter block. Some users claim to that students are accessing sites that should be filtered on our Chromebooks. I have had to recall all Chromebooks to check and test the they all registered upto date and the extension is present and working

 

Is this right as I read double filtering can cause confusion result in potential mis blocks or non blocks of sites.

 

All testing I have carried out have resulted in some kind of block as expected but curious to know how a student managed to access something he shouldn’t have. Is there a misconfiguration of our secret knock or are these the unavoidable issues with cloud filter

Thanks

Posted

Configure the 'secret knock' setting in Guardian » Client interfaces » Cloud Filter. Then add the service 'Cloud filter bypass' in Network » Firewall » Smoothwall access.

 

This will tell the cloud filter extension clients to contact the onprem so onprem won't filter them.

  • Thanks 1
Posted
Configure the 'secret knock' setting in Guardian » Client interfaces » Cloud Filter. Then add the service 'Cloud filter bypass' in Network » Firewall » Smoothwall access.

 

This will tell the cloud filter extension clients to contact the onprem so onprem won't filter them.

 

Thanks, so I check this and I have both of these

 

What is the recommended knock refresh for a school. Currently set to 600 seconds

Posted
Thanks, so I check this and I have both of these

 

What is the recommended knock refresh for a school. Currently set to 600 seconds

 

600 is the recommended value. Are you seeing entries in the list below? If you see a system being double filtered, check this list to see if the IP is there and also check that the client is receiving the configuration correctly.

 

https://kb.smoothwall.com/hc/en-us/articles/360016413920

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...