Jump to content

Recommended Posts

Posted

Morning,

 

This summer or current 3 year deal is up, so looking to start early and get some foundations in place.

 

To be fair, have been really impressed with our current connection, apart from a whole days outage last year its been faultless for the last 3 years, delivering on its 1000/1000 speeds via a baracuda on site managed firewall. We are very rural in a tiny village so lucky to get away with it really. I suppose all suppliers out here would be stuck with using Openreach anyway, so on the connectivity side it will be who can offer the best solution in regards to pricing, sla and managed firewall.

 

Over to the filtering side, we are using securly. Ill stick my head up here and say it has been nothing but fantastic compared to solutions I have seen and used before. I see on this forum (always take with a pinch of salt, we all come here for a moan usually) issues with smoothwalls support, and netsweeper doing what it wants at times. I cannot remember the last time anyone has spoken to me regarding issues with our filtering, websites being blocked or when I have had a new system installed that just point blank will not connect or the filtering blocks. Students and staff always get fast connections and can have a 90 kids watching a live stream like last week and no issues at all on their individual devices. The only "let down" I have with it, due to its design is it not logging so called "bypassed" traffic. If traffic or a site is whitelisted (all of O365 for instance) it will not log the connection, as naturally this traffic is passing direct and so not via thier cloud filters. All google searches, and youtube for instance are logged so we are covered, but maybe one day a bit may slip through. I also use SENSO across the site and log all traffic that was too, so we do have a fall back.

 

Being as this is my only gripe with securly I am debating if its even worth looking else where, it works, it works well, causes me no issues and recently passed quite an intense pentest I had done on site.

 

Anyview, or recommendations to any filtering which may take me up to the next level :)

Posted
Interesting to see if 1gb's have changed pricing much in last 3 years.

 

residential has dramatically dropped in price. I appreciate it's contended but I'm getting 900Mb/s down and 300 up for £30 month. I suspect business have a similar drop, not sure if leased lines would follow.

Posted

Same position as you and currently getting quotes. 1Gbps lines have definitely come down in price (in our case anyway but we are an urban school).

Likewise I have found Securly to be really good. It has the occasional issue with embedded content like Youtube clips but their support is quite good at dealing with it.

Posted
Only had 1 issues with the embeddded problems, was a vimeo link as well. I suppose as they start whitelisting sites shouldnt get any more issues. 1gig is more than enought for us, doesnt warrant going to 10gig so hopefully an annual reduction to go with it as well.
Posted

We have recently started using Securly, and for BYOD I it took me 2 days to find a massive hole. Securly uses DNS filtering so for BYOD if the device owner choses there own DNS server, Securly is bypassed.

For Windows computers, install Firefox, and use the DNS over HTTPS feature to Cloudflare,.

For Android phones, in the settings under network, select a private DNS, and the use a "inconeto tab" in the browser.

Note for both of the above, this is not a hack, it is just enabling some settings.

I am disapointed it was so easy to bypass Securly.

Posted
We have recently started using Securly, and for BYOD I it took me 2 days to find a massive hole. Securly uses DNS filtering so for BYOD if the device owner choses there own DNS server, Securly is bypassed.

For Windows computers, install Firefox, and use the DNS over HTTPS feature to Cloudflare,.

For Android phones, in the settings under network, select a private DNS, and the use a "inconeto tab" in the browser.

Note for both of the above, this is not a hack, it is just enabling some settings.

I am disapointed it was so easy to bypass Securly.

 

Could you block DNS requests going externally/anywhere other than securly at your firewall?

Posted

Its not a massive hole, its designed to be a DNS filter so you would treat it as such.

 

I am in an environment without BYOD. Who allows students to install firefox and change network settings on protected non BYOD devices anyway?

Posted
Could you block DNS requests going externally/anywhere other than securly at your firewall?

 

DNS over HTTPS, No we can not block port 443 (without blocking all the sites that use https!).

Posted

It kinda is a massive hole. It is how ransomware and malware coordinate attacks, by using their own DNS servers to connect to the command structure. Generally, nothing should need external DNS access except your own DNS servers. Exceptions should be allowed specifically.

 

Also, unless you have your network fully locked down, so no one can just plug into a network port, anyone can attach a device and bypass your filtering. New KCSIE is dead against that.

 

I'd always try and lock down your network with the worst case scenario (within reason) as someone will try something you don't expect and if you are only counting on how you allow people to connect, you will be wide open.

Posted
Morning,

 

This summer or current 3 year deal is up, so looking to start early and get some foundations in place.

 

To be fair, have been really impressed with our current connection, apart from a whole days outage last year its been faultless for the last 3 years, delivering on its 1000/1000 speeds via a baracuda on site managed firewall. We are very rural in a tiny village so lucky to get away with it really. I suppose all suppliers out here would be stuck with using Openreach anyway, so on the connectivity side it will be who can offer the best solution in regards to pricing, sla and managed firewall.

 

Over to the filtering side, we are using securly. Ill stick my head up here and say it has been nothing but fantastic compared to solutions I have seen and used before. I see on this forum (always take with a pinch of salt, we all come here for a moan usually) issues with smoothwalls support, and netsweeper doing what it wants at times. I cannot remember the last time anyone has spoken to me regarding issues with our filtering, websites being blocked or when I have had a new system installed that just point blank will not connect or the filtering blocks. Students and staff always get fast connections and can have a 90 kids watching a live stream like last week and no issues at all on their individual devices. The only "let down" I have with it, due to its design is it not logging so called "bypassed" traffic. If traffic or a site is whitelisted (all of O365 for instance) it will not log the connection, as naturally this traffic is passing direct and so not via thier cloud filters. All google searches, and youtube for instance are logged so we are covered, but maybe one day a bit may slip through. I also use SENSO across the site and log all traffic that was too, so we do have a fall back.

 

Being as this is my only gripe with securly I am debating if its even worth looking else where, it works, it works well, causes me no issues and recently passed quite an intense pentest I had done on site.

 

Anyview, or recommendations to any filtering which may take me up to the next level :)

 

We run Securly in one of our school's and compared to a Smoothwall box I've not been that impressed.

 

We've had an open ticket with them for over 12 months.

 

We are experiencing an issue where we are unable to embed YouTube videos in to a PowerPoint, this is a site-wide issue affecting all levels of Securly policy for all staff. To clarify, the video is accessible and can be watched on YouTube but when embedding in to a presentation the clip does not load. Any ideas on what could be blocking this?

 

Their latest response was: Our developers are still working to resolve the problem. I do not have an ETA on when a fix will be released at this time.

 

That was in November.

Posted
We run Securly in one of our school's and compared to a Smoothwall box I've not been that impressed.

 

We've had an open ticket with them for over 12 months.

 

We are experiencing an issue where we are unable to embed YouTube videos in to a PowerPoint, this is a site-wide issue affecting all levels of Securly policy for all staff. To clarify, the video is accessible and can be watched on YouTube but when embedding in to a presentation the clip does not load. Any ideas on what could be blocking this?

 

Their latest response was: Our developers are still working to resolve the problem. I do not have an ETA on when a fix will be released at this time.

 

That was in November.

 

There is a massive problem with Securly and YouTube filtering. I was told that their dev team works on a new addon that will solve this issue, but this was an update from a few months ago.

I agree that their support sucks and all our complaints about YouTube being slow were just passed to dev team and then ignored.

 

DNS filter works, but you need to follow their best practice guide - page 9 - 11

I personally prefer Securly vs Smoothwall as there is no box to worry about, all cloud.

Reports are easy to generate and to be honest we don't really deal with web filter anymore as this is all Safeguarding team job now.

Posted

I think the DoH and DoT issue is a firewall one rather than a web filter one right?

Presumably Smoothwall have to block traffic from IPs that provide this. Last time we had Smoothwall (few years ago now) pupils on our BYOD could use VPNs that used DoH and they just sailed through and any changes support made didn't make any difference. As I say my experience isn't current.

Posted
Thank you for the link, I assume that you are refering to firewall rule 4, block UDP, on ports 80, 443, and 5353. I wonder what else will get blocked if UDP is disabled?
Posted
Thank you for the link, I assume that you are refering to firewall rule 4, block UDP, on ports 80, 443, and 5353. I wonder what else will get blocked if UDP is disabled?

 

Rule 4 blocks Quic protocol on UDP. It doesn't disable the whole UDP. That would be silly.

 

Screenshot 2024-01-24 14.27.57.png

 

You need this otherwise all Apple users don't even need VPN to access any website. They can enable private relay on WiFi and browse whatever they want.

Try it: Just pick up any iPhone connect to your BYOD and enable Private Relay and panic!

 

More info about this here: https://support.apple.com/en-gb/guide/iphone/iph499d287c2/ios

  • Thanks 1
  • 2 weeks later...
Posted
Ours is up mid year, wanting to look at iBoss.. anyone here used them before?

 

A school I was a tech at junked them in favour of lightspeed. They didn't rate it and they appear to focus on US customers, can't hurt to trial it though. If they are US targeted, do they receive the UK lists from IWF, PIPCU and CTIRU, those would be my initial concerns.

The ISP under the hood might, but belts and braces, my ISP doesn't.

  • Thanks 1
Posted
Doesnt have to be :)

 

I mean, it would be a hard sell to convince me to move away from Securly, but never say never.

 

 

If you'd like a quote for connectivity/firewall and/or filtering/monitoring, happy to oblige anytime. drop me a PM or email me direct if it's of interest,

 

cheers

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...