Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. If you are a Smoothwall user you can already expand your coverage by installing our agent on the laptops
  2. I'd definitely look at kerberos or idex - microsoft is killing NTLM, altho negotiate should pick one of the two. Are the clocks on the machines and the smoothwall set well?
  3. I would suggest to put in a support ticket (feel free to put the number here so I can track it).
  4. Idex is a good idea - it's likely very similar to how the forti used to work
  5. I#ll have someone take a look
  6. If monitoring is what you are looking for, Smoothwall offer a pure monitoring product, with very low false positive rates. I can happily show you around.
  7. Awesome - 1-0 to me. In future this sort of thing is an easy fix with a support ticket (in case I am not about to sniff it out) - but I am always happy to get involved
  8. Whew. That's a large block of bad words in javascript. I have excluded it from a LOT of categories. Try tomorrow and let me know how you go on
  9. Hmm - I havent been able to reproduce it - can you give me the exact url of the javascript?
  10. We can sort that in the rules - I'll get it done.
  11. I've started a UK Edtech starter pack... https://blueskydirectory.com/starter-packs/all?q=edtech It's annoyingly hard to add folk to starter packs, but if you see something missing, let me know
  12. Yeah I think Bluesky is where I am at - @tdnewton.bsky.social anyone done an Edugeekers starter pack?
  13. Im not sure if theres a way to fix that for all sites - nuking the browser profile directory might do it, though it's likely to recur (student visits stie off-net, gets pinned, comes back) so teaching them to fix it themselves is probs plan A. As a linux user they are probably savvy - if they want to do work experience tell them to hit me up
  14. Personally, I think the DfE guidelines are broadly incompatible with BYOD. Without MiTM, there's relatively little discrimination available to filters. We will be releasing an update next week which allows you to strip ECH from DNS requests. This will plug a gap and stop sites using ECH - but we have to then block DoH, which we can do, but is a bit of a whackamole.
  15. HSTS probably means the cerificate was remembered by the browser. Try clearing the HSTS cache for that site, see if that works: https://www.thesslstore.com/blog/clear-hsts-settings-chrome-firefox/
  16. I concur Sigma - most folks saying they do actual content filtering aren't. This is a shame. You do need either an agent in the browser, or SSL inspection turned on for this as well.
  17. Nice to hear some stories of improved performance. You'll be pleased to know we havent run out of castles - Newport is actually my daily driver for mucking about with on-prem stuff on my hyper-v VM now.
  18. Early on in the lifecycle of search, we absolutely did used to block all search, and then just allow the ones we "trust" to have decent safesearch! The only thing thats rendered that moot is that running a search engine is nigh on impossible these days, so everything comes back to one of the big 2, and applies their safesearch (Which has its limitations, sure, but it's what we got). I suspect we will see a similar trajectory in AI, as the same market forces apply. For now, only allowing the tools you've consciously invited into your school seems prudent to me.
  19. Really you would need monitoring for that - the filter will pick up some bits on openai (which I would think carefully about allowing student access to), but almost impossible to get context.
  20. I dont think anyone is intending that you use your firewall as a filter - you'd want to add one of the accredited filters on top https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering/filtering-accreditation-scheme-for-uk-schools [or of course combine it with those guys who do both]
  21. Some good recommendations - the Sophos is definitely a solid firewall. You might want to keep that for fw? Hopefully you don't need anything too clever though - no internal servers etc, so you can probably use something less full featured. We can happily offer you a cloud filter plus a firewall if you'd like to have a look, get in touch (or if you just want to talk to a firewall nerd) [email protected]
  22. We are asking google how schools are *supposed* to do this - it doesnt appear YT premium is available as a school subscription. We believe it should be, we can't be antagonist with folks like Google, we won't win.
  23. We do have an android agent which you can use as well if the cert method gives you any bother.
  24. Think about it on a search engine basis rather than a browser basis. You can choose a search engine, and then lock the search engine down. You can lock a search engine down with a web filter - which I am sure you already have, or in some cases other ways, eg if the accounts are logged in to google or microsoft, or by using DNS https://support.google.com/websearch/answer/186669
×
×
  • Create New...