Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. So if you are using 802.1x/Radius on the wifi, you dont need the smoothwall login page. You need to send your radius accounting packets to the Smoothwall and you're good to go.
  2. tom_newton

    Home printer

    Agree with those who've pointed out there's a few bits of requirement gathering to do! For me... I'd go with a black and white laser (I have a ricoh Sp311, but it's a little long in the tooth now). I would never trust an inkjet to be ready to print when I want it. Any photo quality printing, I outsource to photobox. Almost certainly your printer will be networked, so that's a given these days. I prefer an ethernet port because I am a curmudgeon. Also it's usually a sign of a printer that's less reliant on nonky drivers. I'd always like a duplexer - printing double sided is really useful to me at least. If I replaced my printer today? I'd have exactly the same, but ideally something that supported printing from Android. Edit: Cheap flatbed scanner. Fits in a drawer. No worries about one thing breaking and obsoleting the other, and the printer is smaller and neater.
  3. Yup - you want to except it completely, some of these IoT-y things hate being proxied. Particularly doorbells. It's the video.
  4. Android agent will be the answer for school owned. You want a beta next week-ish? Tom
  5. Are these BYO google devices or school owned?
  6. Some folks have reported issues with google meet - these should also be fixed now
  7. Blocklist changes are out
  8. OK, it has been narrowed down to a blocklist issue - a new blocklist is coming shortly. Whoever guessed "it was the blocklist changes" is at least 70% correct (another bugfix combined with these).
  9. Is this the extension or are we seeing it on on-premise too?
  10. Talk to the folks at Linewize.com - our sister company in the US
  11. That single core working hard is likely to be the one doing reporting - that can be multi-processed but I think the default is one
  12. Can you show me what it looks like? It's threads not processes - so as long as you're seeing 1 entry in top using more than 100% CPU things are good
  13. There's a degree to which TF is there to say "have you got filtering, and is it configured in a way you'd expect" not "is the filtering any cop". That's an interesting and subtle difference. The latter is bloody hard to test - BECTA used to certify, but that's long gone, sadly. I was speaking to the TF folks the other day, and wondering about wether the filter vendors could use a "canary URL" (eg we all agree to put prn.testfiltering.com into our porn lists, ang gmb.test... into gambling). Would need the major vendors to agree... not impossible
  14. So, it *is* possible to cache stuff still as Joel says, but it's increasingly hard. We use squid cache in Smoothwall and it's pretty single threaded (unlike the webfilter which is aggressively multithreaded) - and the reason the cache is pretty single threaded is cache consistency. This is why it's a hard balancing act to get the right proportion of cache and performance. We will be improving the mt performance of auth in maiden (probably GA in a few weeks), and then the subsequent castle will have a lot of updates (we're doing a big kernel and OS update).
  15. Some good points from my Swedish friend Joel, and our colleague ibpalle I would also throw into the mix that caching is surprisingly CPU intensive, so be sure to balance that out
  16. Edgecdn domain was only in audio/video - not spotify. Category fixed too.
  17. Article updated - thanks
  18. Do we have the recording up somewhere yet? Some of my colleagues are keen to see what I was up to
  19. Filtering different in 2 browsers usually means one is using QUIC or HTTP3 and getting past the filter that way
  20. It's done Tim - it just needs enabling in the cloud portal for instant alerts, as it works differently (doesnt pass through on prem at all). - - - Updated - - - We do have a (very) experimental firefox build if anyone wants to try it
  21. For cloud: smoothwall:// diag in the URL bar gets you the diag page with the blocklist version The version is a unix timestamp - whack it in here - https://www.unixtimestamp.com/ - to convert it to Mon Oct 16 2023 11:56:01 GMT+0100 (British Summer Time)
  22. Q1 24 or thereabouts
  23. If you have reverse DNS you can use that as a location by "list of hostnames" - you may have to turn on reverse dns lookup in the filter (web proxy, settings... may be advanced, cannae remember) - it does put a little extra load on your dns servers, which is why it is off by default (1 extra lookup/request)
  24. Pretty much - that means that something failed that wasnt able to give us a http failure code. It's almost always something cert-y. For IOS consider using our iPad secure browser - that will help you avoid such issues in future
  25. No - if there's no policy, default is "allow" - we've got categories, but no policy. That's perfectly normal. Unauthenticated stuff may be something that's in the "Do-not-auth-for" list - on long-lived systems this list can grow and grow, and sometimes needs a prune, or it could be something on the PC that's not authenticating (maybe some stuff is traditional proxy, some is inline, and inline isn't authing?) Suggest a health check (contact your Smoothwall CSM) would be useful
×
×
  • Create New...