Jump to content

Recommended Posts

Posted

Hi All

 

We have one pupil that we need to lock right down, we would block internet use entirely but its not practical as many of his classes use web based revision websites.

 

We have both Smoothwall and IMPERO but was wondering if the great and good out there might share an outline of how you might achieve this?

 

It cant rely on teaching staff to switch on / off internet in IMPERO as it needs to be permanent wit the ability to add websites to a whitelist?

 

any ideas?

 

Cheers

 

Steve

Posted

I would most likely:

 

Add the student to a group (either in AD or Google) that Smoothwall recognises.

 

Create a policy that blocks everything for that group.

 

Create a policy with the whitelisted websites/categories the student needs (Google services, Microsoft services etc) and place that one place above the block policy. You can then add to this policy anything the student needs to access that might not be immediately obvious. You could neaten it with a category group if so desired.

 

Might be a better way of doing it, but that's how I would approach it.

  • Thanks 3
Posted
Yeah we just have an allowlist group on impero, anyone added to this group can only access the allowed set of websites. Usually the Isolation kids.
  • Thanks 1
Posted

To play devil's advocate - this isn't a technical issue. It is a behavioural issue and the school should have policies in place to deal with these things. They should be dealt with using suitable sanctions as they would be for any other offence.

However in the real world I know this doesn't happen and you will have to solve it using one of the methods already posted :rolleyes:

Posted
I would most likely:

Add the student to a group (either in AD or Google) that Smoothwall recognises.

Create a policy that blocks everything for that group.

Create a policy with the whitelisted websites/categories the student needs (Google services, Microsoft services etc) and place that one place above the block policy. You can then add to this policy anything the student needs to access that might not be immediately obvious. You could neaten it with a category group if so desired.

Might be a better way of doing it, but that's how I would approach it.

 

An "Allow" policy would be better than a "whitelist" (now called "Do not filter" on the newer UIs), as you'll still have your content aware filtering and monitoring.

To play devil's advocate - this isn't a technical issue. It is a behavioural issue and the school should have policies in place to deal with these things. They should be dealt with using suitable sanctions as they would be for any other offence.

However in the real world I know this doesn't happen and you will have to solve it using one of the methods already posted :rolleyes:

On the other hand, "no internet access" might be the chosen sanction (but they need to get to Google/Office 365 to be able to do work).

  • Thanks 1
Posted
An "Allow" policy would be better than a "whitelist" (now called "Do not filter" on the newer UIs), as you'll still have your content aware filtering and monitoring.

 

On the other hand, "no internet access" might be the chosen sanction (but they need to get to Google/Office 365 to be able to do work).

 

Yes, sorry a mix up of terminology! I meant a whitelist of sites, but in Smoothwall terms, Allow is the right action to take!

  • Thanks 1
Posted

Not using Smoothwall, but we have a similar measure in place. We have a profile set up on our filtering that we've named "Walled Garden", which is an allowlist of the bare minimum of sites required for core teaching and learning: Google Workspace URLs for Docs, Drive, Classroom, etc. and a couple of other revision sites, with no access to web searches. That profile gets applied to Windows users via Group Policy proxy settings, depending on membership of the relevant security group.

 

We also have Chromebooks dedicated for isolation use, which are also configured to use that "Walled Garden" proxy., regardless of the user.

 

It's used fairly sparingly, but I know that there have been cases where it's a safeguarding thing, so a little too serious for the "it's not a technical issue" thing.

  • Thanks 2
Posted
As others have done we have a group the student gets put into that is linked to a smoothwall group that has additional restrictions (an allowed rule preceding a total block rule). We also have a small suite of pcs for students that 'internally excluded' that have static IPs and those IPs are in a location group that has the same restrictions as the user group. There is a relatively high turn over over of students using the IE pcs so having a location frees up some admin time of assigning students to the group.
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...