Jump to content

Recommended Posts

Posted

We've been fortunate enough to convince our NGFL that Symantec Web Security is as much use to us as a cup of coffee in the back of a CRT. As a result, we've "retired" the box, and moved onto Bloxx.

 

Now, Bloxx has been a 'mare. It blocks at will(and will not allow you to countermand the block), crashes if you ask it to report, and is generally no use at all. So, we've had enough (as have NGFL by all accounts).

 

NGFL are trying to hammer out a pricing deal on some other solution whose name escapes me right now, but in the meantime we're having to use Portable Firefox (with restrictions) pointing at the retired SWS box for some things that Bloxx..well..blocks.

 

As I say..'mare.

 

I've been playing with Dansguardian/Smoothwall/IPCop on VMware on the SWS box to try and get that running instead. It's a headache.

 

 

Here's the setup:

 

SWS box and print server - Compaq Evo. SWS runs on port 8005 (had to change it as kids were using 8002 with "unauthorised programs). SWS then filters the request, and passes it onto another machine on port 80 for the data.

Parent machine has ACL set up so that ONLY a machine with the print/SWS server name, fixed IP, and NIC MAC address can send/recieve data to it.

 

SO:

 

I set SWS (content license expired) to "guest mode", so no login is needed. I set the filtering to "Audit" so it's just effectively a "pass through" from the parent machine to port 8005 on the box.

 

This works for me on Firefox and IE...pointing to the Evo on port 8005 gives me 'net access without authentication.

 

Then I installed VMWare player and the various prebuilt VMs I mentioned above, and this is where I came unstuck. None of them seem to cater for our setup!

 

Is there any solution out there, free, that can be used in a VM on the Evo or another seperate box and accept data from the machines on the network, filter it through dansguardian or similar, and then output it to port 8005 on the Evo for SWS to then in turn give it to the main proxy on the network?

 

Everything I looked at seems to be "one green trusted nic, one red "bad"nic"..which makes sense...except that the untrusted NIC wouldn't in our case be connected to a physical router...but would need to send data to port 8005 on the SWS box instead.

 

Is this possible?

 

Sorry if it doesn't make much sense..it's been frying my head after a long week!

Posted
You just need a squid and dansguardian install with your SWS box as the parent proxy. It wouldnt take you long to get your head round a basic setup.
Posted

hmm. I have 3 options...VM it on the existing box, put it on a new box, or try and set my SME Server box up with Squid and DG then...

 

Any good guides on configuring this sort of setup?

Posted
It may only be a temporary solution...Bloxx uses AD integration to do the authentication automatically...I think we could manage without it. Staff and students needs vary, but using the bigblacklist lists would make a good start to both, and we can always finetune site access using Netsupport School.
Posted

In that case you could just install debian or Ubuntu. apt-get install squid dansguardian. You then then set Dansguardian to use squid as it parent and squid to use sws as its parent. You could probably get away without using squid and just put dansguardian on and use SWS as its parent.

If you look through the config file for each you will glean enough info to get a basic install working.

Posted
I'll give that a shot tomorrow then..:) I'll try the squid/DG bolt-in for CentOS (SME server base), and then if that doesn't work I'll grab one of the scrap P2 boxes from storage and Ubuntu it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...