Jump to content

Recommended Posts

Posted

Hi all,

 

For years now, we've had our Smoothwall on-premises box and Cloud Filter linked up and we had a custom category which allowed us to allow specific YouTube videos while blocking access to the rest of YouTube for students. We are a Google school and have strict Restricted Mode in place on Google Admin for students. It used to work well - We'd approve the video on YouTube and then add the full URL to our custom category. This would then allow that video for Windows AD users through the on-premises box and for Chromebook users through the Cloud Filter.

 

We recently discovered a hole in this setup, where students were using the YouTube embed tool in Google Classroom to search for YouTube content. We decided to redo our YouTube policies and followed this KB article: https://kb.smoothwall.com/hc/en-us/articles/360002030930

In hindsight, it does mention that it's most appropriate for non-GSuite for Education users.

 

Since we've done this, YouTube has been basically a no-go for students. After a support call, we've been able to get the on-premises filtering working correctly for Windows AD users. However, Cloud Filter refuses to play ball and outright blocks YouTube for students.

 

I've just got off a second support call trying to get Cloud Filter to work, and it lasted 5 minutes. The support engineer said that basically, our method of blocking YouTube while allowing specific YouTube videos would not work on Cloud Filter, and the only way to be selective is to unblock YouTube entirely through Cloud Filter and use Restricted Mode to restrict content. However, this would surely allow students access to YouTube and whatever unrestricted YouTube videos there are, which could cause disruption and timewasting in lessons.

 

I was also told that the old method we were employing that has worked for years until we changed anything will definitely not work.

 

Does this sound correct? Has anyone else had/got a similar setup and how do you get it to work?

 

Thanks in advance!

Posted

We did introduce a new field in the custom categories for video IDs - this was to be used in situations where youtube or vimeo needed to be blocked but access to certain videos and playlists was needed.

 

Adding video and playlist IDs to this field in a category and then allowing them before blocking video otherwise should work on the cloud filter and on-prem if https inspection is enabled for youtube.

 

The original method was using a youtube for education feature which is no longer available I believe.

  • Thanks 1
Posted

While emailing back and forth with the Smoothwall engineer, he asked me to check the built-in "YouTube Allowed Videos and Playlists" standard category that we had started using after the redo, while logged into Cloud Filter. I couldn't, because it's not a custom category and it would appear you can't view standard categories through Cloud Filter. I doubt this is the reason, but it made me think that perhaps Cloud Filter doesn't see custom content added to standard categories.

 

Well, as a last-ditch effort after posting this thread on Friday, I decided to move everything from that standard category into a brand new custom category on the on-premises box. I added the full YouTube URLs into the Domain/URL Filtering box like we used to when we had everything working, rather than using the Video ID box. I updated the web filter policy to allow the new custom category for students. I left the YouTube block policy where it is, enabled to stop students from accessing anything else on YouTube other than the approved videos. Then, I logged out to publish the changes to Cloud Filter.

 

Sure enough, the approved YouTube videos started working across Windows and Chrome devices again. YouTube remained blocked if we tried navigating to youtube.com or any unapproved videos as a student. If we clicked on an approved YouTube video link, we couldn't then search at the top (this was another workaround some students were using). I left it there for Friday. The only thing I had to figure out was why students couldn't view videos that were previously approved and then embedded into a post on Google Classroom.

 

This morning, using the Realtime web filter log, I discovered that "youtube.com/embed" was blocked. I also found "https://www.youtube.com/youtubei/v1/player?prettyPrint=false" was required to load the videos in Classroom. Once I added those to the new custom category, embedded videos in Google Classroom posts started to work. Then, while I was in the realtime web filter log, I wanted to see if I could work out a way to fix the Google Classroom workaround that the students were using. Through pure guesswork, I found the URL "https://classroom.google.com/u/0/n/picker?hl=en-GB" which I blocked for students, and this has blocked the search box that would pop up when trying to embed a YouTube video to a Google Classroom post. Oddly, this doesn't block the search box 100% of the time on Windows devices using the on-premises box but it's rock-solid on Chromebooks using the Cloud Filter.

 

So, this might be considered a bit of a bodge job, but we have everything hopefully working in the way we want it to. YouTube is blocked for students overall, and they can only access pre-approved videos that are explicitly allowed through Smoothwall across both Windows devices and Chromebooks. Plus, we managed to fix the holes (that we're aware of) in the policy!

  • Thanks 2
  • 3 months later...
Posted

Thank you! These bits aren't documented very well and support can be less than supportive.

 

 

While emailing back and forth with the Smoothwall engineer, he asked me to check the built-in "YouTube Allowed Videos and Playlists" standard category that we had started using after the redo, while logged into Cloud Filter. I couldn't, because it's not a custom category and it would appear you can't view standard categories through Cloud Filter. I doubt this is the reason, but it made me think that perhaps Cloud Filter doesn't see custom content added to standard categories.

 

Well, as a last-ditch effort after posting this thread on Friday, I decided to move everything from that standard category into a brand new custom category on the on-premises box. I added the full YouTube URLs into the Domain/URL Filtering box like we used to when we had everything working, rather than using the Video ID box. I updated the web filter policy to allow the new custom category for students. I left the YouTube block policy where it is, enabled to stop students from accessing anything else on YouTube other than the approved videos. Then, I logged out to publish the changes to Cloud Filter.

 

Sure enough, the approved YouTube videos started working across Windows and Chrome devices again. YouTube remained blocked if we tried navigating to youtube.com or any unapproved videos as a student. If we clicked on an approved YouTube video link, we couldn't then search at the top (this was another workaround some students were using). I left it there for Friday. The only thing I had to figure out was why students couldn't view videos that were previously approved and then embedded into a post on Google Classroom.

 

This morning, using the Realtime web filter log, I discovered that "youtube.com/embed" was blocked. I also found "https://www.youtube.com/youtubei/v1/player?prettyPrint=false" was required to load the videos in Classroom. Once I added those to the new custom category, embedded videos in Google Classroom posts started to work. Then, while I was in the realtime web filter log, I wanted to see if I could work out a way to fix the Google Classroom workaround that the students were using. Through pure guesswork, I found the URL "https://classroom.google.com/u/0/n/picker?hl=en-GB" which I blocked for students, and this has blocked the search box that would pop up when trying to embed a YouTube video to a Google Classroom post. Oddly, this doesn't block the search box 100% of the time on Windows devices using the on-premises box but it's rock-solid on Chromebooks using the Cloud Filter.

 

So, this might be considered a bit of a bodge job, but we have everything hopefully working in the way we want it to. YouTube is blocked for students overall, and they can only access pre-approved videos that are explicitly allowed through Smoothwall across both Windows devices and Chromebooks. Plus, we managed to fix the holes (that we're aware of) in the policy!

Posted

As Tom has mentioned, we are currently making some improvements to how we manage YouTube. We will soon be releasing a new tab for our custom categories so you can manage Video IDs from the cloud portal. We have also been doing work on our Cloud Filter extension so it handles YouTube more effectively.

 

If anyone is interested in a beta release of this, please reach out to me.

  • 5 months later...
Posted
Have the YouTube improvements been released yet? We're on Maiden 22.

 

Yes the improvements have now been released to the cloud filter portal. If you would like me to run through them with you at some point, please let me know.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...