Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,876
  • Joined

Everything posted by tom_newton

  1. We do have an android agent which you can use as well if the cert method gives you any bother.
  2. Think about it on a search engine basis rather than a browser basis. You can choose a search engine, and then lock the search engine down. You can lock a search engine down with a web filter - which I am sure you already have, or in some cases other ways, eg if the accounts are logged in to google or microsoft, or by using DNS https://support.google.com/websearch/answer/186669
  3. Happy to help out - sounds like we are well placed as we can do firewall and filtering all in the one spot. Drop me a line - [email protected] - and I will put you in touch with the relevant people Tom
  4. Not sure I fully understand the problem - drop me an email and let me get to the bottom of it. [email protected]
  5. Which is why it picks up on much less - eg this post would be picked up by Smoothwall... it's a choice.
  6. You should probably also suggest that BYO devices will be increasingly difficult to manage from a filtering perspective, too.
  7. Yes, you would still need a cert on the client. And then you'd find you'd grep for a term and not find it because the post was trivially, but irreversibly-for-a-fragment encoded
  8. All those criteria, yes - although no proxies in the cloud. While these exist, we aren't fans - they have all the issues of regular proxies (mitm, failing sites, horrible failure modes) plus a few others (cost, sharing IPs with who knows who in who knows where). As such all of our cloud solutions work by making filter decisions on the device - so on the ipad, we build a filter into the firefox browser (or on chromebook we put it in an extension). This way, the device can always make an extremely rapid decision on block/no block, and has as much data as possible to go into that process. We then reach out to our cloud for things like "hey I need to send an alert to the DSL". Feel free to drop me an email - [email protected] - and I can put you in touch with the right folks to show you this in action. Tom
  9. These sorts of issues are why we reluctantly built a custom browser (on top of firefox). At least this way we can capture full URLs, and also anything typed in the browser.
  10. Do you have a support ticket in with us? It's not something I've seen commonly tbh
  11. In the areas of safety and moderation I'd suggest we are hard to beat. Would love to chat about what you think we can do better, big things coming in monitor land...
  12. I'd be happy to show you the basics on a video call. Drop me an email. [email protected]
  13. Sad to hear - but also crazy to see what happened post maiden... spells in jail and all sorts.
  14. Sorry - for the filter there's a browser extension, Monitor is agent only.
  15. Even doing full content filtering (which, as some have pointed out, requires as a minimum, a certificate on the device, and some sort of authentication... ) isnt necessarily going to catch typed content. As someone above pointed out, that content probably *is* in post data somewhere, and if you effectively grepped the network traffic, you might find it. Having said that, we did that on outbound data for a while and it was a PAIN. Because you can't take a screenshot like you can with monitoring solutions, there's zero context, and because there isn't much textual context either you end up with overmatching. You can't block it, as you can't display a blockpage, so when something randomly overmatches some GUID that a site is using and blocks it, pop, the site is partially broken, but nobody knows why. Add to that the increasing difficulty (ECH etc) of proxying unmanaged devices, and the increasing prevalence of alternate internet connections, and you have a lot of hard work for little return. The only real option here is managed devices. From a budgetary standpoint there are some schools asking kids to BYO a from a set list of devices which then get managed by the school while that student is on roll. Also not perfect. Apologies - no silver bullet, and a plethora of werewolves. Happy to talk through with you and your DSL at any point.
  16. You'll always want an agent AND extension, as agents find it hard to see what's going on inside the browser, but management of same is getting easier, and we are slowly building a toolset to manage both.
  17. It is the 2.0 evolution of that - waiting for the monitor client team to support it is why it's not ready for public consumption yet
  18. There's an "endpoint management" tool coming to Smoothwall monitor soon - it's in beta for filter if anyone would like to play with it. This allows you to see which clients are installed and reporting home.
  19. Not to go off on a tangent - but this is probably because google have removed that metadata fairly recently, making it difficult to augment safesearch. There's something in the works chez Smoothwall, but these guys at Google do make our lives harder for funsies.
  20. Generally speaking, filtering that's a "bolt on" to an ISP [note, some ISPs provide a good level of filtering, but will not just "throw this in" for a small fee] is less capable than filtering that you choose yourself. For example there are ISPs which will provide Smoothwall filtering (and indeed Netsweeper). These will tend to come with reporting, authentication, and all the things you need to keep young people safe. I hope the guys at SchoolsBroadband won't object to my saying that the shifting of bytes from A to B is the easy bit, and filtering is much harder - the balance of costs will likely reflect that in more capable systems. I would also point out that Filtering is NOT Monitoring. You will almost certainly need a separate monitoring product if you want to do a good job at this (there are situations in which manual supervision is an option). Trying to do real monitoring from filter logs just isnt possible any more with the complexity of the modern web. If you do want to buy this all from one source, again, those ISPs with a more full service attitude can include monitoring. I promise you that a decent monitoring product is night and day different to what you are used to. I am happy to talk to you on a non-commercial basis (I am not a salesperson ) about any of these things!
  21. A lot of port 80 traffic will be "can I get to the internet" checks, which run on 80 so they can be redirected to login pages.
  22. Do you have a support ticket? I will raise it - but both browsers updates are released close to one another
  23. Connection reset smells like packet filtering to me
  24. Possibly something in a network filter blocking an ad domain? I suspect ol Melon Husk is trying to wring the last vestiges of ad revenue out of X. I'd also look to see if you are using different DNS servers (yes, it could be DNS). Sometimes different servers get you different GeoIP results which might confuse some dreadful security measure into thinking you are a wrong un.
  25. That's right. The smoothwall extension conforms to manifest v3 (which was a painful process)
×
×
  • Create New...