Jump to content

Recommended Posts

Posted

Hi,

 

We currently use a Cisco 4402 WLC which is at its capacity of 50 AP's, A Bloxx Webfilter due for renewal and a Global Technologies Firewall which is backwards.

 

The Bloxx unit is currently acting as a transparent proxy (cabled physically between core switch and firewall), clients use our Cisco core switch as the default gateway and this routes traffic to the firewall on a different VLAN (passing through the bloxx unit). The proxy isnt configured on clients, we use the bloxx sendlogon app which runs as logon and logoff scripts so the bloxx unit know who is on a particular machine, thus giving them the appropriate web filtering policy. The bloxx unit has to be configured this way due to our guest wireless network works, a proxy cant be configured. Also this allows us to webfilter smartphones and tablets etc which do login to our normal wireless network (authenticates against AD) but these get a general webfiltering policy as the bloxx unit doesnt know who is using the device.

 

We recently had a representative from Sonicwall discuss there range of NSA devices which will combine the firewall, web content filter and WLC.

This looks like an appealing solution as we can set this device as the clients default gateway, filtering will be transparent for any AD machines and any other wireless device. If we use the Sonicwall appliance for wireless authentication it'll know who is on what wireless device and be able to apply the correct web filtering policy unlike our existing solution.

 

Does anyone use the Sonicwall devices for these purposes or does anyone have any other products that'll perform these actions?

 

Thanks

 

John

Posted

I'm slightly biased, but I would say come and talk to Smoothwall - many schools use our UTM. We're probably more education focused than Sonicwall (a bit more filter-oriented IYSWIM), although there's not a lot wrong with their kit. The advantage you will have there is integrated wireless, although similar levels of integration can be achieved separately.

 

Certainly replacing firewall and inline content filter with a UTM is a common idea - it reduces from 2 points of failure to one.

Posted
Plus 1 for smoothie, just going through the process of hopefully getting one myself - plus you get nice shiny mugs :)

 

Another very happy smoothie user here cannot recommend them highly enough :) great people, great product, great support (when its needed) so yup 10/10 for them :)

Posted

Used smoothwall before, blows bloxx right out of the water in every aspect - filtering, smoothy is far superior and allows whatever you deem fit through, bloxx has massive gaping holes!

 

Firewall - Sonicwall is fantastic for business environments but education not so much, again I would switch to Smoothwall UTM for this, reason why not so good for education - needs to be lenient and there are just far too many options and variables that it can literally take months to get right (though when you do, just make a backup and you can reload it on if you ever have issues).

Posted

Many thanks for the replies.

Has anyone used a Smoothwall UTM in conjuction with a wireless guest network? I wonder if it'll be possible to use NTLM for all the desktops etc and webpage auth for the wireless guest network?

Posted
Many thanks for the replies.

Has anyone used a Smoothwall UTM in conjuction with a wireless guest network? I wonder if it'll be possible to use NTLM for all the desktops etc and webpage auth for the wireless guest network?

 

Yes you can.

Posted
Plus 1 for smoothie, just going through the process of hopefully getting one myself - plus you get nice shiny mugs :)

 

Shiney new mugs eh! we didn't get them..but i suppose the fantastic pre/after sales and technical support more than makes up for that!

 

Many thanks for the replies.

Has anyone used a Smoothwall UTM in conjuction with a wireless guest network? I wonder if it'll be possible to use NTLM for all the desktops etc and webpage auth for the wireless guest network?

 

We use (2x) UTM-1000 appliances with Ruckus Wireless, combined with VLAN'ing etc to offer a totally segregated guest/wireless provision.

With the latest Guardian 3 filtering it offers you an abundance of non/transparent proxy and authentication options.

You could use NTLM, whereas SSL Authentication is very flexible (especially for some mobile devices etc) and you can always filter based on location (ie. IP range.)

The UTM-1000 can also handle all your DHCP,DNS & routing etc for either for your whole LAN or as we have done soley for the guest/wireless WLAN.

Posted
Used smoothwall before, blows bloxx right out of the water in every aspect - filtering, smoothy is far superior and allows whatever you deem fit through, bloxx has massive gaping holes!

 

Firewall - Sonicwall is fantastic for business environments but education not so much, again I would switch to Smoothwall UTM for this, reason why not so good for education - needs to be lenient and there are just far too many options and variables that it can literally take months to get right (though when you do, just make a backup and you can reload it on if you ever have issues).

 

I agree with this, we have Sonicwall and it awesome for enterprise but if I could choose again for education I d go for smoothwall

Posted

We use (2x) UTM-1000 appliances with Ruckus Wireless, combined with VLAN'ing etc to offer a totally segregated guest/wireless provision.

With the latest Guardian 3 filtering it offers you an abundance of non/transparent proxy and authentication options.

You could use NTLM, whereas SSL Authentication is very flexible (especially for some mobile devices etc) and you can always filter based on location (ie. IP range.)

The UTM-1000 can also handle all your DHCP,DNS & routing etc for either for your whole LAN or as we have done soley for the guest/wireless WLAN.

 

That be exactly what we have again with Ruckus at my school, we use the SSL Login feature for students bring your own devices they use the AD credentials and it lets them through on there iPads, Android Phones etc and they are very happy with it :)

  • Thanks 1
Posted
Yep, the actual solution was good but to points.

 

1. The access points where junk anyways breaking and needing to be power cycled.

2. The filtering on the Sonicwall is useless never seems to get anything. Sonicwall doesnt seem to believe in blocking proxy sites.

 

Because of these 2 points i wouldnt be using that solution.

 

Ignore that last comment, i thought you said Sonicwall. It was late when i posted that.

 

To confirm Smoothwall is an excellent product.

 

Sorry :)

Posted

Thanks for the replies, i'll look into the Smoothwall solutions.

We'd be setting this device up as the clients default gateway, no proxy settings at all. Is this how most people have it configured and is it able to filter HTTPS traffic this way?

Posted

Sorry, 1 last question i promise :)

Is anyone using the Anti-Spam features? we host our own exchange 2010 servers and have a websense email filter and ideally we'll like to remove it.

Posted
Sorry, 1 last question i promise :)

Is anyone using the Anti-Spam features? we host our own exchange 2010 servers and have a websense email filter and ideally we'll like to remove it.

 

Yup I use it and its great, the quarantine feature with the users self-releasing email is great as well really like that feature :) Not finding too many false positives either which is good news and keeps the complaints about missing email down :)

Posted
Thanks for the replies, i'll look into the Smoothwall solutions.

We'd be setting this device up as the clients default gateway, no proxy settings at all. Is this how most people have it configured and is it able to filter HTTPS traffic this way?

 

We still put all the proxy settings in for our main workstations as they are not allowed to go transparent on the main network they are required to authenticate and yes we filter HTTPS traffic on the main LAN as well.

 

The Guest devices are on a transparent proxy thus no proxysettings and it works fine, it can do HTTPS filtering as well on that side but only on modern clients and browsers, cannot remember the ins and outs of that one but it does tell you when setting it up on the smoothie :)

Posted

We have a "development" guest wireless with smoothwall as a non-transparent proxy server, using SSL logins against AD, clients need to be configured to use a proxy.pac file. Works best with a device that supports tabbed browsing.

 

To make YouTube work on an iPhone/iPad we needed to add some domain names to a whitelist.

 

Was asked to join an Android mobile phone to it today though which does not work with a proxy.pac file, and having some trouble making it work with manual proxy settings.

 

Not sure if this means that we will have to look at a transparent proxy server with one filtering policy suits all approach to provide a system that works with any device :confused:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...