sturgeo Posted November 21, 2011 Posted November 21, 2011 Hi, We currently use a Cisco 4402 WLC which is at its capacity of 50 AP's, A Bloxx Webfilter due for renewal and a Global Technologies Firewall which is backwards. The Bloxx unit is currently acting as a transparent proxy (cabled physically between core switch and firewall), clients use our Cisco core switch as the default gateway and this routes traffic to the firewall on a different VLAN (passing through the bloxx unit). The proxy isnt configured on clients, we use the bloxx sendlogon app which runs as logon and logoff scripts so the bloxx unit know who is on a particular machine, thus giving them the appropriate web filtering policy. The bloxx unit has to be configured this way due to our guest wireless network works, a proxy cant be configured. Also this allows us to webfilter smartphones and tablets etc which do login to our normal wireless network (authenticates against AD) but these get a general webfiltering policy as the bloxx unit doesnt know who is using the device. We recently had a representative from Sonicwall discuss there range of NSA devices which will combine the firewall, web content filter and WLC. This looks like an appealing solution as we can set this device as the clients default gateway, filtering will be transparent for any AD machines and any other wireless device. If we use the Sonicwall appliance for wireless authentication it'll know who is on what wireless device and be able to apply the correct web filtering policy unlike our existing solution. Does anyone use the Sonicwall devices for these purposes or does anyone have any other products that'll perform these actions? Thanks John
tom_newton Posted November 21, 2011 Posted November 21, 2011 I'm slightly biased, but I would say come and talk to Smoothwall - many schools use our UTM. We're probably more education focused than Sonicwall (a bit more filter-oriented IYSWIM), although there's not a lot wrong with their kit. The advantage you will have there is integrated wireless, although similar levels of integration can be achieved separately. Certainly replacing firewall and inline content filter with a UTM is a common idea - it reduces from 2 points of failure to one.
glennda Posted November 21, 2011 Posted November 21, 2011 Plus 1 for smoothie, just going through the process of hopefully getting one myself - plus you get nice shiny mugs 1
john Posted November 21, 2011 Posted November 21, 2011 Plus 1 for smoothie, just going through the process of hopefully getting one myself - plus you get nice shiny mugs Another very happy smoothie user here cannot recommend them highly enough great people, great product, great support (when its needed) so yup 10/10 for them
featured_spectre Posted November 21, 2011 Posted November 21, 2011 Used smoothwall before, blows bloxx right out of the water in every aspect - filtering, smoothy is far superior and allows whatever you deem fit through, bloxx has massive gaping holes! Firewall - Sonicwall is fantastic for business environments but education not so much, again I would switch to Smoothwall UTM for this, reason why not so good for education - needs to be lenient and there are just far too many options and variables that it can literally take months to get right (though when you do, just make a backup and you can reload it on if you ever have issues).
sturgeo Posted November 22, 2011 Author Posted November 22, 2011 Many thanks for the replies. Has anyone used a Smoothwall UTM in conjuction with a wireless guest network? I wonder if it'll be possible to use NTLM for all the desktops etc and webpage auth for the wireless guest network?
andyrite Posted November 22, 2011 Posted November 22, 2011 Many thanks for the replies. Has anyone used a Smoothwall UTM in conjuction with a wireless guest network? I wonder if it'll be possible to use NTLM for all the desktops etc and webpage auth for the wireless guest network? Yes you can.
MYK-IT Posted November 22, 2011 Posted November 22, 2011 Plus 1 for smoothie, just going through the process of hopefully getting one myself - plus you get nice shiny mugs Shiney new mugs eh! we didn't get them..but i suppose the fantastic pre/after sales and technical support more than makes up for that! Many thanks for the replies. Has anyone used a Smoothwall UTM in conjuction with a wireless guest network? I wonder if it'll be possible to use NTLM for all the desktops etc and webpage auth for the wireless guest network? We use (2x) UTM-1000 appliances with Ruckus Wireless, combined with VLAN'ing etc to offer a totally segregated guest/wireless provision. With the latest Guardian 3 filtering it offers you an abundance of non/transparent proxy and authentication options. You could use NTLM, whereas SSL Authentication is very flexible (especially for some mobile devices etc) and you can always filter based on location (ie. IP range.) The UTM-1000 can also handle all your DHCP,DNS & routing etc for either for your whole LAN or as we have done soley for the guest/wireless WLAN.
mwbutler Posted November 22, 2011 Posted November 22, 2011 +1 for Smoothwall and their support is excellent.
irsprint84 Posted November 22, 2011 Posted November 22, 2011 Used smoothwall before, blows bloxx right out of the water in every aspect - filtering, smoothy is far superior and allows whatever you deem fit through, bloxx has massive gaping holes! Firewall - Sonicwall is fantastic for business environments but education not so much, again I would switch to Smoothwall UTM for this, reason why not so good for education - needs to be lenient and there are just far too many options and variables that it can literally take months to get right (though when you do, just make a backup and you can reload it on if you ever have issues). I agree with this, we have Sonicwall and it awesome for enterprise but if I could choose again for education I d go for smoothwall
john Posted November 22, 2011 Posted November 22, 2011 We use (2x) UTM-1000 appliances with Ruckus Wireless, combined with VLAN'ing etc to offer a totally segregated guest/wireless provision. With the latest Guardian 3 filtering it offers you an abundance of non/transparent proxy and authentication options. You could use NTLM, whereas SSL Authentication is very flexible (especially for some mobile devices etc) and you can always filter based on location (ie. IP range.) The UTM-1000 can also handle all your DHCP,DNS & routing etc for either for your whole LAN or as we have done soley for the guest/wireless WLAN. That be exactly what we have again with Ruckus at my school, we use the SSL Login feature for students bring your own devices they use the AD credentials and it lets them through on there iPads, Android Phones etc and they are very happy with it 1
FN-GM Posted November 22, 2011 Posted November 22, 2011 Yep, the actual solution was good but to points. 1. The access points where junk anyways breaking and needing to be power cycled. 2. The filtering on the Sonicwall is useless never seems to get anything. Sonicwall doesnt seem to believe in blocking proxy sites. Because of these 2 points i wouldnt be using that solution. Ignore that last comment, i thought you said Sonicwall. It was late when i posted that. To confirm Smoothwall is an excellent product. Sorry
sturgeo Posted November 23, 2011 Author Posted November 23, 2011 Thanks for the replies, i'll look into the Smoothwall solutions. We'd be setting this device up as the clients default gateway, no proxy settings at all. Is this how most people have it configured and is it able to filter HTTPS traffic this way?
sturgeo Posted November 23, 2011 Author Posted November 23, 2011 Sorry, 1 last question i promise Is anyone using the Anti-Spam features? we host our own exchange 2010 servers and have a websense email filter and ideally we'll like to remove it.
glennda Posted November 23, 2011 Posted November 23, 2011 I'm going to be when i move over to it if i'm allowed to do it!
john Posted November 23, 2011 Posted November 23, 2011 Sorry, 1 last question i promise Is anyone using the Anti-Spam features? we host our own exchange 2010 servers and have a websense email filter and ideally we'll like to remove it. Yup I use it and its great, the quarantine feature with the users self-releasing email is great as well really like that feature Not finding too many false positives either which is good news and keeps the complaints about missing email down
john Posted November 23, 2011 Posted November 23, 2011 Thanks for the replies, i'll look into the Smoothwall solutions. We'd be setting this device up as the clients default gateway, no proxy settings at all. Is this how most people have it configured and is it able to filter HTTPS traffic this way? We still put all the proxy settings in for our main workstations as they are not allowed to go transparent on the main network they are required to authenticate and yes we filter HTTPS traffic on the main LAN as well. The Guest devices are on a transparent proxy thus no proxysettings and it works fine, it can do HTTPS filtering as well on that side but only on modern clients and browsers, cannot remember the ins and outs of that one but it does tell you when setting it up on the smoothie
drewp Posted November 23, 2011 Posted November 23, 2011 We have a "development" guest wireless with smoothwall as a non-transparent proxy server, using SSL logins against AD, clients need to be configured to use a proxy.pac file. Works best with a device that supports tabbed browsing. To make YouTube work on an iPhone/iPad we needed to add some domain names to a whitelist. Was asked to join an Android mobile phone to it today though which does not work with a proxy.pac file, and having some trouble making it work with manual proxy settings. Not sure if this means that we will have to look at a transparent proxy server with one filtering policy suits all approach to provide a system that works with any device
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now