Jump to content

Recommended Posts

Posted

Ive just installed the trial, have set my machine to use it as the default gateway. Ive not done any configuring on it yet just using it straight out the box.

 

Tried to go to facebook, and its banned, but when I log in to bypass it it doesnt load properly, just the text no images etc.

 

Also, does smoothwall make you log in to bypass every single banned site, or is there a way of once logging in and authenticated, being able to browse freely.

Posted

Firstly, bypass is a tricky one for some sites - at the moment it simply bypasses for "facebook.com" and much of facebook comes from other domains (particularly fbcdn).

If you wan't to unblock social networking sites, it is probably easier to allow it in the policy...

 

Secondly - you should set up some sort of authentication - this will let your more senior users :) have less filtering. Remember the default policy is pretty hardcore.

  • Thanks 1
Posted
We have ours running through an upstream proxy. We point the students at smoothwall and the staff at the upstream proxy. So our staff dont have the smoothwall filtering.
Posted
We have ours running through an upstream proxy. We point the students at smoothwall and the staff at the upstream proxy. So our staff dont have the smoothwall filtering.

 

Surely it would be better for all your users to go through your smoothwall box? Authentication will allow for different policies and all your logging will be done in one place. If you have no control of the upstream proxy, what do you do if the boss-man asks, "was Mr X running his Ebay store during lesson times?"

  • Thanks 2
Posted (edited)

What we have now, is everyone goes through the firewall (set as the gateway) as a transparent proxy, but staff have the ability to 'log in' to bypass the proxy (not complete bypass but a lot less restricted)

 

Ive managed to get smoothwall talking to AD via LDAP, ive imported the OU/groups I want it to use, but Im not sure how to set up the policies based on the groups from OU.

 

I only really want 2 policies - staff and studentd..

 

Again, I apologise for not reading the manaul Im just struggling for time

Edited by redhelpdesk
Posted

First, go onto the guardian > filtering > filters page. Then cut down your filter called "default AUP" until it is suitable for everyone.

 

Now create an "add on" policy for students.

 

Now go to the "policies" tab and add a "block" for your new policy to group "students". If you have not already sorted out the group, you will need to map it to the right place on your AD in "services/authentication" where you might also give it a better name than "Group 5" :)

  • Thanks 1
Posted

Thanks for the repy tom.

 

Ive imported all the student groups from AD, assigned them to group 5 (renamed to students).

 

Ive assigned the allstaff group from AD to the Default Users group, and ive assigned the Domain Admins group from AD to the Network Administrators group.

 

The diagnistics for the settings in Services - Authentication - Control all go green.

 

What do I want in Guardian - Authentication settings ?

 

I want to be able to reportusage on a per user basis, I only want staff to be able to log in and bypass.

 

Whatever Ive done now, Im getting this:

URL: http://www.google.com 
Reason: Banned site: A blanket block is in place and this site has not been explicitly allowed 
Category: N/A 
Group: Default Users 

 

So ive obvisouly set something wrong somewhere.. however even trying to bypass using my username and password from AD isnt working.

Posted

I'm not sure you can use the Domain Admins group. Create another group in AD and add yourself to that. Then map that to the network admins group on the smoothwall.

 

My setup is nearly the same as yours apart from staff are not allowed to override the blocks.

Posted

Login/bypass requires a username local on the smoothwall (like your "admin").

 

I don't know why domain admins shouldn't work - it looks like it hasn't found a group for you. Might try a second group, see if it is that though.

  • Thanks 1
Posted

I have created an all staff group and assigned staff from AD to that. But I dont seem to be getting any filtering now. The student group seems to work OK.

 

I really cant understand though how the filtering groups / levels pages work.

 

I want to have staff to have pornography/bombs etc banned (pretty much just anything illegal) but still give them access to facebook and everything else.

 

Also another point - we give access to students on their personal laptops. We register their MAC addr with our wireless radius, and the mac address of each laptop has an account in AD. Would it work to use that account/group from AD to apply the filtering to ?

 

Thanks in advance for your help.

Posted

Pardon my ignorance but is the commercial version? [you did say 'trial']. You know you'll get paid for support? try the smoothwall community forums also.

 

I've been running smoothwall express since version 2 at home and have added smooth mods called 'urlfilter' with success.

 

you will need to run the advanced proxy in transparent mode for urlfiltering to work.

 

check here for urlfilter and here for advanced proxy.

 

i'd block the same categories for staff and students.

 

 

alternatively, you could send all student traffic through your smoothwall box, and staff straight through to your designated ISP's proxy [who really should have filtering in place for school situations].

Posted
Pardon my ignorance but is the commercial version? [you did say 'trial']. You know you'll get paid for support? try the smoothwall community forums also.

 

I've been running smoothwall express since version 2 at home and have added smooth mods called 'urlfilter' with success.

 

you will need to run the advanced proxy in transparent mode for urlfiltering to work.

 

check here for urlfilter and here for advanced proxy.

 

i'd block the same categories for staff and students.

 

 

alternatively, you could send all student traffic through your smoothwall box, and staff straight through to your designated ISP's proxy [who really should have filtering in place for school situations].

 

Trial as in the sense demo.. Theyve given us the full commercial school guardian for 30 days to test run it. Our ISP is a commercial ISP not an educational one, so no filtering provided by them. I need 2 seperate policies for the aforementioned reasons - facebook / google images / etc for staff but not students, which is possible with smoothwall I just cant figure out how to change the levels / sections for each group. (Im in the middle of another massive project at work as well so cant really spend the hours on this I'd like, as it seems to do everything we want at a very competetive price.. )

Posted
I have created an all staff group and assigned staff from AD to that. But I dont seem to be getting any filtering now. The student group seems to work OK.

 

I really cant understand though how the filtering groups / levels pages work.

 

I want to have staff to have pornography/bombs etc banned (pretty much just anything illegal) but still give them access to facebook and everything else.

 

Also another point - we give access to students on their personal laptops. We register their MAC addr with our wireless radius, and the mac address of each laptop has an account in AD. Would it work to use that account/group from AD to apply the filtering to ?

 

Thanks in advance for your help.

 

Go to Settings -> Authentication and at the bottom of the page you set whether or not a group has web access and whether that web access is filtered or not... I suspect it says 'Yes (unfiltered' next to your staff group

 

For the personal laptops you might be better off forcing them to authenticate with their usernames. AFAIK you cannot auth against computer accounts. You are better authenticating with usernames anyway for accountability - you probably haven't had chance to check out the reports yet but they are pretty awesome!

Posted
Go to Settings -> Authentication and at the bottom of the page you set whether or not a group has web access and whether that web access is filtered or not... I suspect it says 'Yes (unfiltered' next to your staff group

 

For the personal laptops you might be better off forcing them to authenticate with their usernames. AFAIK you cannot auth against computer accounts. You are better authenticating with usernames anyway for accountability - you probably haven't had chance to check out the reports yet but they are pretty awesome!

 

The way the laptops work is they have a user accuont, not a computer acocunt, with the account name the mac address, and the display name the student, and this account is what talks to the radius. Would that work?

 

I think you could be right about not adding the staff group to the filtered bit, i remember seeing that last night. How do I enable facebook etc for staff? I cant figure out the filtering tab where you can tick and untick sections - how do you know which group you are appling it to?

Posted
I cant figure out the filtering tab where you can tick and untick sections - how do you know which group you are appling it to?

 

To run through making a new policy denying staff access to stuff:

1. Go to Filters tab

2. Type a name at the top (e.g. Staff Deny Policy)

3. Tick all the stuff you don't want them to access

4. Click 'Add'

5. Go to Policy tab

6. At top select your staff group, the Staff Deny Policy filter, Always and Block

7. Make sure 'Enabled' is ticked and click 'Add'

8. Go to Gaurdian -> Authentication -> Settings

9. Make sure Staff are set to 'Yes (filtered)'

 

You will be prompted to apply changes and restart the proxy at relevant points. After all this is done, your staff will no longer be able to surf for pr0n.

  • Thanks 3
Posted
To run through making a new policy denying staff access to stuff:

1. Go to Filters tab

2. Type a name at the top (e.g. Staff Deny Policy)

3. Tick all the stuff you don't want them to access

4. Click 'Add'

5. Go to Policy tab

6. At top select your staff group, the Staff Deny Policy filter, Always and Block

7. Make sure 'Enabled' is ticked and click 'Add'

8. Go to Gaurdian -> Authentication -> Settings

9. Make sure Staff are set to 'Yes (filtered)'

 

You will be prompted to apply changes and restart the proxy at relevant points. After all this is done, your staff will no longer be able to surf for pr0n.

 

Thanks for that. I have done that, but the staff group is still getting banned going to facebook?

 

The default policy is still set to block social networking - I cannot figure out how to take it out the default policy?

Posted
You probably need to edit the "default AUP" filter - clicking it form the "policy" page will take you straight there. Uncheck "Social networking", press "add", "apply" and you should be good to go. You can later ban it for select groups if you need to.
  • Thanks 1
Posted

Thanks Tom, thats probably it. I wasnt clicking the Add button, I thought that was about adding a new policy rather than adding the new rules to that policy. Makes sense now.

 

Could you possibly answer about how we could go about filtering guest (students personal) laptops. Would it just be by assigning them the default gateway of the smoothwall box via dhcp, and forcing all traffic through that? Could we then also force that group to require them to enter their username and password?

 

How does smoothwall work for our School assigned blackberrys, and staff personal wifi devices which we allow to connect to through our wifi and internet, would it just work the same way and filtering done through default gateway?

 

Also, is there any way to get firefox to authenticate seamlessly like IE does (without the popup credentials box?)

 

My last question (for now at least!) is about pptp vpn access. We currently use this for staff, does schoolguardian allow the passthrough of pptp connections to the Windows server? (and will staff be able to browse the web over the vpn and out through the smoothwall and to the internet?)

 

Thanks for the help with this.

Posted

OK... working vaguely back'ards:

 

PPTP: Passthrough - yes - You will need to forward the relevant ports though (TCP port 1723 forwarded to the VPN server, as well as the GRE protocol (protocol 47))

 

Firefox: Should be ok with NTLM - what platform is it running on, and are the machines part of your domain?

 

Dingleberries: Don't think these can authenticate. You will probably have to tweak the unauthenticated users rules. Will have a play with some of ours here at some point.

 

Personal laptops: It is best if you can get them to assign a proxy properly (eg. via DHCP/DNS with WPAD). You can also turn on transparent proxying on the smoothwall, though this will only handle HTTP traffic, not HTTPS, and would be a fallback for student devices which did not pick up the web proxy.

  • Thanks 1
Posted
OK... working vaguely back'ards:

 

PPTP: Passthrough - yes - You will need to forward the relevant ports though (TCP port 1723 forwarded to the VPN server, as well as the GRE protocol (protocol 47))

 

Firefox: Should be ok with NTLM - what platform is it running on, and are the machines part of your domain?

 

Dingleberries: Don't think these can authenticate. You will probably have to tweak the unauthenticated users rules. Will have a play with some of ours here at some point.

 

Personal laptops: It is best if you can get them to assign a proxy properly (eg. via DHCP/DNS with WPAD). You can also turn on transparent proxying on the smoothwall, though this will only handle HTTP traffic, not HTTPS, and would be a fallback for student devices which did not pick up the web proxy.

 

Thanks for the quick reply. I think I might have it set in transparent proxy mode just now, as all I am doing on my test machines is setting the default gateway as the smoothwall box and its filtering that way ?

 

Firefox I noticed the popup on Windows 7. Cant remember if it happened on XP or not will check in the morning.

 

The blackberries was just an example, we have iphones, nokias, htc touch etc all on the wireless too.

 

So with the student personal laptops, the proxy settings are applied via dhcp? Will this work for mac/safari laptops as well?

Posted
I would suggest that you push proxy settings via DHCP. You will find some work, some don't. Those that don't can get reduced (no HTTPS) service via transparent proxy. Those that do.. well, we won't worry about them :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...