Jump to content

Recommended Posts

Posted

Hi ,

 

ANyone using the Edge addon for the cloud filter ? I know it is filtering correctly . But i cant see any logs in my on-premise smoothwall.

 

Is there a seperate report i need to run for cloud filter logs ? or should they all be mixed in .

 

Thanks !

 

2097

Posted
Depends - in some cases we pull the logs back down to on-premise hourly. The newer method is to push everything into the cloud and report on it there. We can do either for you, but I am not sure how you are set up right now.
Posted

@Tom

 

Thanks Tom , Im logged into the Cloud portal but it says "Reports" is an option to purchase ? Am i looking in the correct place ?

 

I think they possibly might be onsite , as looking through previous smoothwall daily reports i can see Email address's for usernames , which i think means for our setup they are using Intune joined devices.

 

What is the reporting like on the cloud addon , does it only upload logs of blocked content aposed to the onsite smoothwall that logs everything ?

 

Thanks

Posted
You can look at the logs from the cloud filter clients in the filter section too - there is a log viewer there. The logs will likely be transferred to the local Smoothwall just not in real time. You can see real time logs on the device itself as well:

 

https://kb.smoothwall.com/hc/en-us/articles/360006892380-Checking-that-Cloud-Filter-Policies-Work-Real-time-log-viewer

 

Thanks ,

 

Does it update smoothwall with all internet traffic ? Or just logs of websites that have hit the blocklist ?

Posted
All web traffic that is going through the cloud filter extension.

 

 

Its strange as i can see a search result of a teacher using an email address ( which i assume is on an Intune Cloud laptop) . I can only see this in the smoothwall Safeguarding report email .

 

If i run a user report on said user , it doesnt bring up anything ?

 

Am i missing something .. Or do i require support.

Posted

Depends - is this an alert from the cloud portal or a daily summary from the safeguarding notifications on the Smoothwall?

 

If you run a report, usernames will be case sensitive as well I believe. Also, take a look at the reports - logs - web filter and select the date and approximate time, then add other filters to see if you can find the log entry there.

Posted

Found the mistake ,

 

When searching logs you use their 365 email instead of local AD username .

 

What a numpty i am :D

 

Thank you guys

  • Thanks 2
  • 2 months later...
Posted

sorry to ressurect this thread.

cloud filter synced with on prem smoothwall. how long does it take to sync a policy change made on smoothwall.

and is there a way if shortening the sync time for the logs. i understand i can get the logs directly off the client but this has proven to be difficult at times with gaining access. and with logs 30-60 mins behind live events its difficult to put in a solution then to wait for the next sync.

Someone mentioned smoothwall.cloud logs are better. i dont seem to be registered for it on the site in question.

advice welcome

Posted (edited)

Hi dapaulio

It is always On Premise that is the master, this means that when someone is logged in, the various rules are locked in Cloud Filter.

The rules in Cloud Filter are then greyed out and a red banner is visible with the text "Your policy has been locked due to an active login on your Smoothwall device."

 

As soon as you log out of On Premise, the rules are synchronized and changes can be made to the Cloud Filter.

 

The good thing about Cloud Filter is that you can let non-technical personnel have access to only the Filter (which you decide yourself in the filter), then they can e.g. get to turn off or turn on already existing rules.

Everything is logged, so you can see who did what in a simple way..

Just don't forget to tell them that they need to publish the changes when they're done, in order for them to be sent out to clients and synced to On Premise

 

Contact your Smoothwall contact in the first instance or secondly ask Tom Newton to enable Cloud Reporting.

Edited by Joeloman
  • Thanks 1
Posted
Hi dapaulio

It is always On Premise that is the master, this means that when someone is logged in, the various rules are locked in Cloud Filter.

The rules in Cloud Filter are then greyed out and a red banner is visible with the text "Your policy has been locked due to an active login on your Smoothwall device."

 

As soon as you log out of On Premise, the rules are synchronized and changes can be made to the Cloud Filter.

 

The good thing about Cloud Filter is that you can let non-technical personnel have access to only the Filter (which you decide yourself in the filter), then they can e.g. get to turn off or turn on already existing rules.

Everything is logged, so you can see who did what in a simple way..

Just don't forget to tell them that they need to publish the changes when they're done, in order for them to be sent out to clients and synced to On Premise

 

Contact your Smoothwall contact in the first instance or secondly ask Tom Newton to enable Cloud Reporting.

 

Top man thank you. There was me sat in smoothwall waiting for a change to propagate on the client and all I needed was to log off. Whole hour I waited in anticipation 🤦 which make sense now as I had to log back in cos of the idle timeout. Only reason I knew it was delayed was because the block screen showed a category still I know I removed.

 

Follow-up question is this the same for the web filter logs. Do they upload more often when I’m logged out of onprem smoothwall.

Posted
The logs upload every 5 minutes from on prem, and from the cloud agent, regardless.

 

Interesting as there was a defo time delay of nearly an hour before it synced back to on prem but it only sync about 30mins worth of logs. Leaving still 30 mins gap in the logs

 

Is there a misconfiguration somewhere. I have have pushed thru tonight an update to the latest Leeds release being 5 releases behind

Posted

I recommend you to use Cloud Reporting. Then 5 minutes is correct.

 

Then the Safeguarding alarms will also come much faster from the cloud service.

What happens for you today is that first the Cloud clients must report to the Cloud Filter, which then packages up the logs and sends them to On Premise. I think the setting was 30 minutes.

  • Thanks 1
Posted
Yeah, the "download back to on-prem" method is much slower. Also there's a version which still takes 30 mins to upload, but that's been replaced and only a handful of folks are on it
Posted
Yeah, the "download back to on-prem" method is much slower. Also there's a version which still takes 30 mins to upload, but that's been replaced and only a handful of folks are on it

 

Hi tom I support a number of school all practically with smoothwall. Can I get access cloud filter to all of them in one central logon

If so how is the best way I can enrol my company 365 address to all the sites.

 

If not I have individual office 365 accounts for all sites

Thanks

Posted
Hi tom I support a number of school all practically with smoothwall. Can I get access cloud filter to all of them in one central logon

If so how is the best way I can enrol my company 365 address to all the sites.

 

If not I have individual office 365 accounts for all sites

Thanks

 

Yes*

 

* the functionality for this is currently hidden - we have only recently added in "MSP" support for 1 person with many customers. Fire me an email - [email protected] - and I will get it turned on for you. It is going GA in the next weeks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...