Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. I'd be inclined to separate out the guest traffic and just point that at the Smoothie - you might be there for a while untangling fire alarms, and if it aint broke..
  2. It will, yes. That is kind of odd, I dont know why it would not be installed!
  3. It's still there. I would take a look at System/modules - SNMP is actually a modular add-on (back in the day SW was very modular, we sold different bits at different prices, very a-la-carte. Frankly it is one of the reasons why the Smoothwall UI could be more joined up, but isn't.. everything has to work even if something else is randomly missing) Anyway, these days, modules are a relic, largely. But it is very possible that somehow that module aint installed. You should just be able to add it in. It would suggest to me evidence of something slightly fruit and nut if that were the case, but anyway, let's check that first. Tom
  4. Looks like a tough one - I will raise it with our team.
  5. Concur with 80 and 443 and wait for someone to complain about anything else. 99% of software can fall back to -over-https-connect style anyway
  6. We used to resell https://mailroute.net/ - it is very good but it just doesnt fit with our strategy, and proved hard to bill, so we are winding down the customerbase. Talk to RA Plecas there, she's a good egg. Having said that the built in stuff from Microsoft is pretty solid.
  7. Apparently google are separating chrome from chromeos in order to make this less bad in the future.
  8. If you can update to our latest software version (Maiden) we have had customers experience much higher throughput. Firewall performance testing is a dark art - particularly at higher speeds!
  9. The new extension rules (manifest V3) are only supported post 88 - https://developer.chrome.com/docs/extensions/develop/migrate#:~:text=displaying%20a%20warning.-,Manifest%20V3%20is%20supported%20generally%20in%20Chrome%2088%20or%20later,information%20for%20individual%20API%20members. The transition away from MV2 starts in June https://developer.chrome.com/blog/resuming-the-transition-to-mv3 So not a hard "no support" but it is going to be tricky to get extensions that work, and I suspect other things will follow shortly after
  10. Chrome 88 will be a bare minimum for Chrome soon with the MV3 changes. Sadly I suspect you may be fighting a losing battle with these devices.
  11. One option might be a VM with full admin rights, and that bypasses the majority of fiewall and filter? Use Faronics Deep Freeze or similar to "revert to factory" every day so it doesnt become malware hell, and only allow RDP access to it? Noel, I think you are on the right track with fiddler. Maybe break out wireshark as well, see if there's any non-http traffic. Systinternals processmonitor is another good tool for trying to find where some opaque horror is failing to load.
  12. To answer a couple of questions that have been floating around here.... You should look for an accredited filter. If you want an on-site appliance, Smoothwall is currently the choice in accredited filter suppliers. https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering/filtering-accreditation-scheme-for-uk-schools As for "You cant do 2 mitms" - you can. I think my record is 3 (one LA Firewall, 1 Smoothie at the school edge, and one Sophos AV client), but 2 including a client like Senso or Sophos is super super common. Wether you should is another ball game. Consider what you are getting out of MiTM at the firewall. Assuming most of your infrastructure is in the cloud, and devices go on and off network, you are probably not adding a ton of value. Finally - why MiTM in a web filter when it's just domains and URLs? Well, it aint just domains and URLs - a good web filter will also do realtime dynamic content filtering (that's not just marketing BS, I would be happy to show you it working!), plus if you want the URL part, or any search term filtering/alerting you will need that MiTM.
  13. Drop me an email with a ticket number. The fix is in Leeds-75 (but it is already hotfixable). L75 is currently in internal staff testing, first customer release next week.
  14. Login page with a "login by microsoft" button I think is the only option I think. You can do RADIUS wired but I have never seen it done.
  15. You should only push one. You wouldnt want 2 to install at once, and that would happen if you had 2 pushed to a 110+ device, as we are still allowed to do MV3 on self-hosted extensions for now, so you'd have both running and it would be no fun at all. If you *didn't* get an email from us, then we have only seen chrome 110+ from you in our telemetry, so you can go back to your day and not worry.
  16. You can't - as extensions are per-user, and that user could log in anywhere. So use the MV2 one while you still have any pre-110s about. If our comms is a bit long winded and hard to decipher, would appreciate some feedback for the product marketing folks!
  17. Targetted you for 74 - should solve it. Tom
  18. This looks like an old ticket pertaining to CA issues - something different entirely? And it's closed... I don't want to try and guess at tickets because obviously I don't know who you are. If there's a different ID let me know Meanwhile I have asked the dev team if the other ticket in this thread is a known issue
  19. Looks like... fun. Have you got a support ticket and I will get a developer to take a look It miiight be an issue we had with the auth page recently (a;though if it is it is presenting in a different way) so do make sure you are up to date with the latest software
  20. Possible QUIC/HTTP2 allowed at firewall level?
  21. Added a specific article to our kb request list - thanks for the heads up
  22. It should be doable without different subdomains or a reverse proxy (which your smoothwall does have if you need it). If it's a browser timeout error that does sound like a misconfiguration somewhere. I would first check with your ISP - it is possible their firewall isnt allowing "non standard" ports in
  23. Have you got a support ticket in with us?
  24. The fix is in how we generate the individual mitm certs per-site but not a change to the CA, so it should be super easy to roll out a fix
×
×
  • Create New...