Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. Smoothwall ipad filter should definitely catch those - as there's a second request made to the real site!
  2. Yes, for the same reason (no auth = dont know who you are) destination auth exceptions still apply to all users - so by definition all users can then access insta. You could... fix IP range of ipads. Dest auth except insta Block insta for all Unblock insta for ipad IPs as a higher priority policy
  3. Stuart is a good egg. I was pretty sure that that you had done nothing wrong, and that it's a hardware fault from what you described!
  4. No, you cant do an auth exception by group, because you don't know who it is until you auth! Catch 22! Auth exception by destination address?
  5. Always get the blame - thanks for keeping your system up to date tho!
  6. Instead, use that limited linux knowledge to see if linux still sees all the hardware: lshw -C network If we dont see all the NICs, it's a hardware issue, get it RMA'd If you do see all the NICs it's a software issue, which I'd _expect_ the reinstall to fix, so I am thinking it's h/w. I've not seen something like this, but it's a minute since I have been persistently "on the tools". Whichever way the cat jumps, get a support ticket in.
  7. Quite possibly allowing the traffic to hit the proxy (rather than just be bridged) means its source IP is probably more palatable to something upstream Edit: I am going to claim a win on "firewall problem" BTW
  8. Not something I have seen - usually problems are with long running connections for this sort of thing, but I cant imagine that's the case. FW rather than filter, perhaps?
  9. You might be better looking at a system that supports agent based filtering. I am pretty sure TS can help you there.
  10. Hey folks - anyone else want to test this out? We are just pre-release
  11. Not one i'm familiar with - have you got a support ticket you could DM me and i will make sure it routes to the right places
  12. I would still recomment someone like mailgun or sendgrid for this - the mail providers are cheap-bordering-on-free and have reasonably generous quotas, proper logging, etc
  13. With the ipad client, that's not really intended for use with "class trolley" style ipads unless they are in apple's shared ipad mode: really this is needed to get good auth. You have to have kids logging in to their ipads. If you don't - filtering via on-prem with a login page is probably your best bet.
  14. It's a bit clunky, but you can see the policy id if you mouseover the "edit" button on each policy
  15. In Australia we've seen kids not being able to have youtube accounts, but being able to access "un-logged-in" youtube, which has had... unintended consequences. Some of the other filter vbendors and I are working with UKSIC to try and get Google to make youtube a bit more school friendly
  16. As Joel said - we do have our parental control functionality through the Qustodio brand. Happy to chat about it - send a DM!
  17. It won't be able to do as good a job, no
  18. We have this functionality in our US filter stack - it will be coming to the UK in due course
  19. Any antivirus or anything running that might have decided this looks like malware?
  20. Sometimes the extension can take a few seconds to start - particularly if it's been a while, or the user has cleared their profile, as you will need to download a new rules list (~35Mb) rather than an update. Certainly if the agent couldnt communicate with the agent, it would also cause issues - that's an interesting bit of troubleshooting. DM me your ticket and I will make sure it's looked into
  21. Whatsapp doesn't do DNS lookups - I'm doing some work with one of the best DNS firewalls out there, they have to have a static IP sig for whatsapp too
  22. I'd go for allowing the IPs, and exempting them from filtering. As it's staff, the risk is low. Whatsapp is a pain.
  23. Nice to see we've gone 3 for 3 on "It wasn't the smoothwall" that's a relief, but we are used to it - the filter is often a place people find stuff being blocked, so its natural to come there first (and it deffo sometimes IS us)
×
×
  • Create New...