tom_newton Posted January 25, 2011 Posted January 25, 2011 Detjo I saw your post about the proxy you use and I am currently using the same config. I.E. SQUID with K9 Web filter. Proxy works fine and users only gain access to sites allowed through K9, however they do not get the K9 splash screen if a page is blocked. They just get page cannot be displayed... Is this something you have managed to get working ? Is that for all sites? It's kind of expected behaviour with HTTPS, but can't think why it would break under HTTP.
supernova Posted January 25, 2011 Posted January 25, 2011 It is for all sites - K9 redirects the user to it's own splash screen on the localhost port 2372, but I'm assuming as nothing is hosted locally on the user PC, this is why it gets page cannot be displayed. It's no big deal, but would be a nice to have..
soapyfish Posted January 28, 2011 Posted January 28, 2011 I use Squid on Debian in school, which uses the LEA proxies as a parent. The Filtering is also all done by the LEA. According to Calamaris squid monitoring tool. Average speed increase: 46.98% Bandwidth savings in Percent: 34.45% I guess thats good ?
tom_newton Posted January 28, 2011 Posted January 28, 2011 I use Squid on Debian in school, which uses the LEA proxies as a parent. The Filtering is also all done by the LEA. According to Calamaris squid monitoring tool. Average speed increase: 46.98% Bandwidth savings in Percent: 34.45% I guess thats good ? Relatively. I "rule of thumb" 25% cacheability in a school environment.
soapyfish Posted January 28, 2011 Posted January 28, 2011 Now I just need to get the transparent Proxy working on OpenBSD PF and the redirection rules sorted out !
dave.81 Posted February 4, 2011 Posted February 4, 2011 We have been using Smoothwall SG for the past 3 years, before that censornet and before that Squid. Although we are carrying out a review of internet service provided here so this thread is interesting seeing how many are using Forefront TMG and SW but very few others. 1
sven Posted March 10, 2011 Posted March 10, 2011 We run a nested proxy here. Our internet connection is provided by our local council, who run a proxy with caching. We connect into that via A 10mb Telewest Fibre. We run a Forefront TMG server which acts as a local proxy which does all of our site side web caching. That way, sites can be served across LAN if already in the cache. TMG web chains onto the external proxy that handles the majority of the web filtering. Eventually, I'll get round to adding some filter policies of our own via TMG
tom_newton Posted March 10, 2011 Posted March 10, 2011 We have been using Smoothwall SG for the past 3 years, before that censornet and before that Squid. Although we are carrying out a review of internet service provided here so this thread is interesting seeing how many are using Forefront TMG and SW but very few others. I like to think Forefront's popular because its cheap, and many people already have ISA, and we're popular because we're GOOD
spc-rocket Posted March 10, 2011 Posted March 10, 2011 Hi, We use ISA 2004 with SurfControl/Websense, soon will be moving over to the Forefront TMG for firewall and web filtering. I personally think the URL subscription license on the enterprise pack for EES is really good and makes it cheaper to run. I.e. ISA was cheap - £150 or so per processor (on select) and there was no requirement of CAL. The same is true of Forefront TMG if not used with URL filtering subscription, however if you subscribe to the URL filtering it does cost but on EES's Enterprise pack this is included so no need to buy expensive and sorry all those filtering companies are bloody expensive in my opinion. Even education discount don't cut it and the per user licensing or per appliance licensing is also expensive for a lot of education customers. Will be trialling the URL filtering capability on a Forefront TMG test box (free to trial for 60 days i think). Many people still have reservation of ISA or TMG not being a good firewall, well its really good at firewall and also a cache server. I really don't believe in the hardware firewall vs software firewall, its all about deep packet inspection, and protocol inspection, IDS etc not just blocking ports. Ash.
januttall Posted July 3, 2011 Posted July 3, 2011 We currently and have been doing for some time been filtering with dansgurdian and squid throu ubuntu works verry well i must admit and it also scans files and pages for viruses using clamav, and sets difrent filter groups for each set of users and grabs them from AD once a day. its also set transparently so no settings have to be enterd into any clients. and they dont see it unless they hit a blocked site when its splash screen is displayed with user name and reason why. i also like the abilaty to be able to search through the pages users have been on by date time username computer name ip etc. verry usefull and help full.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now