Stevecee Posted April 18, 2024 Posted April 18, 2024 Hi All We have one pupil that we need to lock right down, we would block internet use entirely but its not practical as many of his classes use web based revision websites. We have both Smoothwall and IMPERO but was wondering if the great and good out there might share an outline of how you might achieve this? It cant rely on teaching staff to switch on / off internet in IMPERO as it needs to be permanent wit the ability to add websites to a whitelist? any ideas? Cheers Steve
simpsonj Posted April 18, 2024 Posted April 18, 2024 I would most likely: Add the student to a group (either in AD or Google) that Smoothwall recognises. Create a policy that blocks everything for that group. Create a policy with the whitelisted websites/categories the student needs (Google services, Microsoft services etc) and place that one place above the block policy. You can then add to this policy anything the student needs to access that might not be immediately obvious. You could neaten it with a category group if so desired. Might be a better way of doing it, but that's how I would approach it. 3
ITGuyNW Posted April 18, 2024 Posted April 18, 2024 Yeah we just have an allowlist group on impero, anyone added to this group can only access the allowed set of websites. Usually the Isolation kids. 1
Anonymous2000 Posted April 18, 2024 Posted April 18, 2024 To play devil's advocate - this isn't a technical issue. It is a behavioural issue and the school should have policies in place to deal with these things. They should be dealt with using suitable sanctions as they would be for any other offence. However in the real world I know this doesn't happen and you will have to solve it using one of the methods already posted
Rob_D Posted April 18, 2024 Posted April 18, 2024 I would most likely: Add the student to a group (either in AD or Google) that Smoothwall recognises. Create a policy that blocks everything for that group. Create a policy with the whitelisted websites/categories the student needs (Google services, Microsoft services etc) and place that one place above the block policy. You can then add to this policy anything the student needs to access that might not be immediately obvious. You could neaten it with a category group if so desired. Might be a better way of doing it, but that's how I would approach it. An "Allow" policy would be better than a "whitelist" (now called "Do not filter" on the newer UIs), as you'll still have your content aware filtering and monitoring. To play devil's advocate - this isn't a technical issue. It is a behavioural issue and the school should have policies in place to deal with these things. They should be dealt with using suitable sanctions as they would be for any other offence. However in the real world I know this doesn't happen and you will have to solve it using one of the methods already posted On the other hand, "no internet access" might be the chosen sanction (but they need to get to Google/Office 365 to be able to do work). 1
simpsonj Posted April 18, 2024 Posted April 18, 2024 An "Allow" policy would be better than a "whitelist" (now called "Do not filter" on the newer UIs), as you'll still have your content aware filtering and monitoring. On the other hand, "no internet access" might be the chosen sanction (but they need to get to Google/Office 365 to be able to do work). Yes, sorry a mix up of terminology! I meant a whitelist of sites, but in Smoothwall terms, Allow is the right action to take! 1
jthompson Posted April 18, 2024 Posted April 18, 2024 Not using Smoothwall, but we have a similar measure in place. We have a profile set up on our filtering that we've named "Walled Garden", which is an allowlist of the bare minimum of sites required for core teaching and learning: Google Workspace URLs for Docs, Drive, Classroom, etc. and a couple of other revision sites, with no access to web searches. That profile gets applied to Windows users via Group Policy proxy settings, depending on membership of the relevant security group. We also have Chromebooks dedicated for isolation use, which are also configured to use that "Walled Garden" proxy., regardless of the user. It's used fairly sparingly, but I know that there have been cases where it's a safeguarding thing, so a little too serious for the "it's not a technical issue" thing. 2
NegativeKillDeath Posted April 18, 2024 Posted April 18, 2024 As others have done we have a group the student gets put into that is linked to a smoothwall group that has additional restrictions (an allowed rule preceding a total block rule). We also have a small suite of pcs for students that 'internally excluded' that have static IPs and those IPs are in a location group that has the same restrictions as the user group. There is a relatively high turn over over of students using the IE pcs so having a location frees up some admin time of assigning students to the group. 2
tom_newton Posted April 18, 2024 Posted April 18, 2024 Some excellent advice from other Smoothwall users on here. Nothing to add really.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now