Jump to content

Recommended Posts

Posted (edited)

Hi,

We've got a public IP on our router but stopped using it when the kids discovered they could plug in a network cable, not use a proxy and get straight out to internet.

Is there a way to force use of a proxy server (at isp). We don't have ISA. Need to enable public IP for remote access.

Thanks

Edited by karldenton
Posted
I assume that the kids are using there own equipment. If not and it is a windows domain use GPO in AD to enforce your security policies. I would stop their equipment by using reserved IP address on the equipment you know about so they can't get an ip from DHCP.
Posted (edited)
The best solution short of NAC would be a firewall that has has a rule that redirects all port 80/443 traffic to a transparent proxy. This is set to allow things like Java/Quicktime/Windows Updates through without authentication but stomp on anything else. On the block page you could put info on how to setup personal machines for the school proxy. Edited by Geoff
Posted
Buy ISA and install it. It's relatively cheap for schools and, if you're letting users use their own laptops, it will also save your internal network from endless harm by restricting access to whichever parts you choose.
Posted
You need some form of firewall device to act as your router. Something like Smoothwall Express or IPCop will do this job, and allow you to enable transparent proxying also.
  • 2 months later...
Posted

Anymore ideas on this ??

Got vpn working fine over the holidays. Just need to stop pupils connecting their own equipment and connecting without a proxy.

Tried setting a rule on the firewall to block all traffic except those going to Redstone IP addresses - works fine for a while then something must change at Redstone and you've got to turn the setting off

Posted
You could put 2 network cards in a box with smoothwall express on it one card will have the external(public) address and create a new internal ip range. smoothwal can sort the routes out for you. or you can do the same with isa etc... depends on how much you want to spend!
Posted

I'd rather not spend anything if possible !. Our ISP do the filtering, router does the firewall rules and VPN. Just need to stop the students connecting outwards.

Changes in DHCP?

Posted
the way i explained doesn't allow acces without going through an internal proxy first. like chrish said smoothwall express is the free version. but there are paid for alternative like isa which in essence would do the same job. you'd change your internal dhcp addressing to a different range so the kids have no chance of getting out on the internet with out the proxy settings inserted.
Posted

Yeah we've got the smoothwall school guardian on trial at the moment.

Sorry for sounding dumb but:

Our internal network at the moment is 192.168.42.*

So install Express.

Keep internal network the same but change router to a different range eg 192.168.1.1

Get smoothwall to do the routes. Can you set an upstream proxy in smoothwall so its filtered by our isp too?

Posted
in lancs we have public (cleo) addresses assigned to each school which are 10.*.*.* for example. now in school i have a school guardian box which has 2 net cards inside of it one of the cards has a 10.*.*.* addres and routes through to the lancs proxy for further filtering and the other card has our internal ip range on it which is 192.168.*.* in the gaurdian settings you can set one as the internet connection and one as local network and as far as ican remember it sets up the route for you between the with transparent proxying (not done it for a while and the builders are in this week so no servers are up) tom will probably clarify everything. so you'd take the router out of dhcp and put in a gpo of somesort for proxy settings in ie and a software restriction policy to stop firefox portable if need be.
Posted
if your going for school gaurdian there's no need for the express product. but i believe express will do everything you need it to do. but ask tom for clarification on this again i could be wrong!
Posted
Yes you can set an upstream proxy in Smoothwall. You need to tell your router to redirect all web traffic to the proxy else it could be bypassed.
Posted

OK.

 

What I will have to do is:

 

Router External IP: 55.*.*.*

Internal: 192.168.1.1

 

Smoothwall External: 192.168.1.2

Smoothwall Internal: 192.168.42.*

 

Is the correct?

 

For VPN we are thinking of using mapped network drives. How does the router or smoothwall know when you map a drive to change the IP to the correct range?

Posted

karl... not sure what you mean there... for VPN, you should be using something... VPNish, like PPTP, L2TP or IPSEC. You might then map a network drive over that.

 

If you can, get your router to present a public IP to the smoothwall - this will prevent double-NAT and make life easier.

 

Tom

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...