mrstrong Posted July 9, 2025 Posted July 9, 2025 I'm trying to tidy/simplify these (ours are a bit of a mess / confusing) starting with Web filter policies. Could anyone share their basic setup ? Had a look online and found this article https://kb.smoothwall.com/hc/en-us/articles/360002031710-Default-Web-Filter-Policies-Overview It shows two interesting examples that I was thinking of using as a starting point, they do differ somewhat as first one uses policy folders based on "Who" which seems an interesting approach but not sure about having core blocked content so high up (rule 2.5) ? and
NegativeKillDeath Posted July 9, 2025 Posted July 9, 2025 I like the first layout, I guess you'd modify core block content to only include categories you wan't no one accessing.
mrstrong Posted July 9, 2025 Author Posted July 9, 2025 (edited) but IT staff would need access to some "core blocked content" so you'd have to move "IT Staff" folder above the "Everyone" policy folder ? edit: so not sure why the Smoothwall docs have Everyone above IT Staff by default Edited July 9, 2025 by mrstrong
sigma Posted July 9, 2025 Posted July 9, 2025 Probably because even IT staff are subject to the IWF and other mandatory blocks?
ibpalle Posted July 9, 2025 Posted July 9, 2025 Reason all group specific policies are below the everyone is that everyone is for blocking content that no-one should have access to as well as allowing categories like software updates. If IT staff need access to anything that is blocked for everyone, remove it from the everyone policy and make sure it's added to the group specific policies for the other groups. That way you keep the staggered approach and avoid having any confusing sequencing in the policy list - remember, it's always recommended to not block, rather than allowing. 1
mrstrong Posted July 10, 2025 Author Posted July 10, 2025 (edited) @ibpalle so you recommend I use the first example as best practice / starting point and tweak as appropriate ? Edited July 10, 2025 by mrstrong
ibpalle Posted July 11, 2025 Posted July 11, 2025 @mrstrong Yes - there are many ways to arrange policies and this is our recommended starting point. It makes it easier to follow the mantra of better to not block than to allow. Simple basic everyone policies just blocking the real nasties that no one should have access to and then use the group policies to flesh the categories out. You can also make the students folder apply to unauthenticated and default users too, getting rid of policy 6.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now