KDW1987
Members-
Posts
28 -
Joined
-
Last visited
-
Cisco umbrella isn't listed as an approved we filtering solution on the UK safer Internet centres website btw
-
Isn't there a way to use pi-hole with a raspberry pi to block this?
- 35 replies
-
- youtube ads
- youtube
-
(and 1 more)
Tagged with:
-
Fortinet Everything (firewall/switching/wireless)
KDW1987 replied to titch's topic in Wired Networks
It depends on what you are moving from. Their solution is not on par with enterprise wireless solutions like Aruba, Cisco, and Extreme Networks. Before you go ahead after a slick demo, ask them about the Level 9 CVEs they have had in the last few months and how that could give someone access to your firewall, switches, and wireless by brute force. CVE-2026-24858, the FortiCloud SSO flaw, enables attackers who have a FortiCloud account and a registered device. Fully patched FortiGate firewalls were compromised via CVE-2025-59718 in January, and Arctic Wolf had an article on CVE-2025-25249, which allowed a Remote Code Execution Vulnerability in FortiOS and FortiSwitchManager. The flaw was in the CAPWAP Wireless Aggregate Controller Daemon and could allow an unauthenticated, remote threat actor to execute arbitrary code or commands. -
Applications are becoming suspended for one member of staff
KDW1987 replied to cheaptonersucks's topic in Windows 10
Are you still working in education? If you are looking to use scaler for education I had noticed they are not listed as an approved web filtering vendor with the UK safer Internet centre for offsite filtering -
Unable to play Youtube videos on managed ipads (meraki)
KDW1987 replied to iMangles's topic in Mobile Devices & Tablets
Zscaler are not curently listed on the UK safer Internet centre as an approved filtering vendor. When I questioned about why a member of their team that has since left they do not have the iwf or ctru block lists included within their solutions web filtering. Which I believe is a DFE mandatory requirement. -
Smoothwall: Filtering For Pupils At Home
KDW1987 replied to dhicks's topic in Internet Related/Filtering/Firewall
I have been using the palo alto's new prisma browser solution now for a year and it would fix this issue . You have to get the kids to install a third party browser on their personal device. But once they have the browser installed and have logged in once, it cashes the user details when a user first logs in against that local user account and after a reboot it will sso them back into that account, making the whole user experience simple. It works on both byod and managed devices, but the parent has to install that browser on the kids profile and remove all other browsers and admin rights to stop them installing exe.'s / other browsers etc. The Prisma browser also has all the dlp, casb and data controls and AI filtering capabilities to meet the DFEs new AI standards for kcsie and is cloud based SASE solution meaning it applies anytime, anywhere. -
Website not blocking on Meraki Firewall
KDW1987 replied to Slarty66's topic in Internet Related/Filtering/Firewall
This is because the firewall is not doing decryption. If you are not decrypting the traffic you wont be able to fully block web applications. To meet kcsie you really need a holistic solution which includes URL, DNS and layer 7 application control as without decryption enabled across all 3 features as a minimum now. Plus the new DFEs AI filtering standards now mean we need tools that can provide dlp and casb tools to meet those standards too. -
Sorry what I should have said is it is not technically impossible to deploy multiple certificates, what I am saying is that is not recommended and this can makes things very challenging and fragile and often breaks things, often 1 of the SSL certificate stops working and goes unnoticed and without regular monitoring and maintenance this set up does not really work. From experience I have never seen this be the recommendation as the set up in nearly all of situations with a dual web filter and firewall I have only ever see the schools do SSL on 1 of the 2 solutions that are deployed, which is always the web filter for safeguarding reasons understandably . From what I know the reason behind this is that this can cause conflict on traffic and have a huge performance impact on the speed of the network, as doing ssl is heavy work for a single filter / firewall as it is, so doing dual inspection on all traffic on the network will start to have very heavy performance impact on throughput capabilities of the appliances. I have also seen that this can have issues with TLS 1.2 and if web traffic gets blocked it becomes challenging to trouble shoot where the problem lays. In most dual set ups the the education web filter will normally be set up as a web proxy and often the rule at the firewall is set to not decrypt any traffic coming from the web proxy and therefore the all of the advanced security features such as sand-boxing, as I mentioned wont be scanning this traffic. This is why it's recommended to use a single appliance to reduce this complexity not have to face this challenge. Sorry for any confusion.
-
Hi , represent only myself and am just sharing my experiance of helping deploy next generation firewalls and filtering systems within education settings. Most URL and DNS filtering tool are built around traditional web crawlers to help detect and profile domains and urls for their categories . Most next generation vendors are now using machine and deep learning and AI to go further. These tools offer live profiling capabilities which help to detect newly registered and uncategorised urls and Domains that are using techniques to avoid security scanning tools and web crawlers. This is mostly being done by malicious attackers, but we also see this being used for filtering avoidance by students too.
-
Hi Rob, It's not that you can't deploy it this way, it is more that you are doing dual man in the middle inspection and that is very heavy on performance. Also the firewall and filter will need a trusted CA to do DPI and the web filter for the same without that it does not work. I have seen schools use the same certificate on both solutions many times and evently it either stops working on one, or the other appliance without you knowing, or it was never really working in the first place, or it grinds everything to hault. You are right about if you are doing this with an agent on the device. However most agent based solutions are swig solutions, or web proxies which means they are not doing the filtering locally on the device. Traffic is being routed via a cloud hosted solution, working as a web proxy. The key is to know if the filtering is happening locally or not. The only draw back to a local agent based solutions is the performance impact on the device and you can't deploy this on byod as the end user retains the right to remove any software and will mean you can not enforce that filtering because of this.
-
Sorry but that is not really possible.... this is because the certificate is installed on the device, you can't really install multiple ssl certificates, or it's will just eventually break, or bring the network speed right down. It might seem to work for a short period of time but eventually it just breaks. Can you explain how you do this with 'seperation'. Most market leading vendors have a firewall and filter as one solution in a UTM style offering or often referred to as a next generation firewall. The main benefit this offers is because most traffic is now application based and app controls is a firewalls responsibility not the dns or url filter. By having a combined solution you get a more comprehensive holistic solution with a single reporting tool. A dual offering will require dual reporting to meet safeguarding requirements.
-
Sounds pretty much like proxy based web filtering solutions are unstable and don't offer the same experiance as on premise and don't really work . You probably need to look into SASE. Cloud native security tools that deliver the same security as an on premise solutions. These solutions are hosted in the cloud and offer the same security and filtering anytime anywhere . Look up the Gartner SASE magic quadrant 2023, there's only one vendor ranked as as leader currently.
-
Just an FYI you have to enable HTTP inspection to be compliant with safeguarding and KCSIE . Just because an appliance has a 10gbps port doesn't mean it can deliver 10gbps throughput. It's a Barn door on a bike shed analogy. From what I am aware Smoothwall do not have a firewall with a 10gbps throughput capability I believe, secondly if you are an average sized school I don't believe you are going to get close to a traffic throughput of 10gbs anytime in the next 8-10years. Working with sizing firewalls for the average 1/ 1.5k user school I have seen a peak throughput in a day at any given time of around 0.8-1.2gbps. An S15 from testing with SSL enabled can not handle 10gbps nor can an s14. Data sheets can be misleading and none provide number with SSL enabled because this is a how longs a piece of string question and most have dropped the URL filtering from their threat mix of data as this has a heavy impact on the performance numbers these are the things to look out for when checking those numbers on a datasheet.
-
Smoothwall - Blocking Google searches
KDW1987 replied to lparry's topic in Internet Related/Filtering/Firewall
Block QUIC?

