Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. If you have any questions you'd like to ask at Smoothwall feel free to have a chat with me. Always open to hearing folks' experience with filtering - email in the signature
  2. SIP proxy? And have you submitted a ticket? I'd be surprised if there was a big delay - our ticket numbers have been a LOT better this year than last (not that there isn't still progress to be made)
  3. Would like to hear about how we didn't live up to our standards - and don't worry, if you do get in touch you won't get a hard sell from me. Just genuinely interested in where we can improve - [email protected] if you would be so kind as to let me know (or air it in public here - I am also cool with that)
  4. It'll do for blocking - but routing, you can't miss a packet.
  5. Definitely don't feel stupid. That's a most non-obvious cause. I've been doing this YEARS and I wouldn't have got there much quicker if at all
  6. You will not find such a thing, I'm afraid. All layer 7 stuff is fuzzy. Even those that claim "first packet match" are BS (I know, I have evaluated most all of the 3rd party components that exist) and getting worse - so much traffic is encrypted these days it's increasingly hard to match. There's a couple of options as I see it. Most bulk traffic is HTTP/S so you could run a web proxy on/pointing to the Sat gateway, and that way shift the majority of slowish-but-big traffic in that direction, leaving your DSL to take the unproxied UDP traffic from zoom/teams? You might also do some layer3 routing on anything that's unproxied, but bulk: backups, perhaps? I think my advice here is don't let perfect be the enemy of working. Hopefully your DSL comes towards the top end of 3Mb as much less and you might struggle with video - particularly as the upstream is likely to be pretty rancid. I spent a lot of time tuning when I moved here (surrounded by FTTC and Virgin, our new build was off a child cabinet which had a bit of long, thin, worn wet string to the exchange). It is certainly worth fiddling with the DSL modem (swapping the ISP supplied junk out) and trying stuff like going for ADSL2 rather than 2+ as that can even out your upload.
  7. The annoying non-feature which is causing this should be removed in Leeds-54.
  8. For mode 1 you need 3 things - username, config and a blocklist - does the daig page show all these 3 available?
  9. As my colleague says, I'm sure we can help, sounds like what you're after has been languishing with the wrong person. If you let me know your deets - feel free to email [email protected] - I will put you in touch with your Customer Success Manager who will make sure things happen!
  10. What's being blocked? Sounds like a place where we can improve categorization
  11. Make sure Smoothwall is seeing the same IP address ranges as your AD as well - eg. if idex reports tom is logged in as 192.168.12.13 and then 192.168.10.12 hits the smoothie, there'll be no correlation.
  12. There's definitely a radius wrinkle in L49 (fixed in 50). You 100% sure it's not a unidirectional routing issue if there's a packet going one way but not tother?
  13. Can you create a support ticket with your serial in it, and DM me the number. I'll then see if I can remote on and get the requisite logs
  14. Hey, it'll actually be 49 when this is fixed - but the blank ones can be ignored, they are false positives.
  15. This looks fine as-is to me. I'd sayyour DCs could, probably should go direct. There's no advantage in them using the smoothie. The only "interesting" bit is making sure the smoothie looks up your local stuff in your local AD, so we can rdns stuff, do AD binds, etc. but that's fine here. Smoothie will do a bit of DNS caching for you, but that's probably not super relevant.
  16. Smoothie only needs conditional forwarders to your dc for local Lookup, you can and should probably point at all the 8s or whatever for general resolving
  17. @Primus if you can PM me your details i'll make sure your schools all get the updates simultaneously. We have a phased rollout and sometimes folk get straddled between 2 phases. @Benjaminbl12 It seems unlikely that 42 has caused this - but i'd like to look more deeply - if you can let me know a support ticket or school name?
  18. Instant alerts are in progress right now. Hope they'll be even better than the on-prem ones! If you want to chat to me about the pros and cons of what you have on-prem, drop me a line. I'd appreciate your comments. I too would love our apple offering to match Chromebook - Apple aren't so keen... yet.
  19. Today, global proxy is arguably the best way to filter an iPad - particularly if you want high quality, authenticated filtering. We are working with apple to do something that doesn't require a proxy. If any of you would like to get in touch, i'd love to hear from you about what would be important in a solution.
  20. Smoothwall's reporting is moving to the cloud - would love to chat to you about this so you don't need to consider moving - happy to hear what we can do to make your lives easier.
  21. I'll double check where we are with hotspot shield, but TBH, an IPS is going to be little use against it, as the traffic is encrypted, so stream based IPS rules are next to worthless. Usually it's a case of enhancing web filter rules and being sure all your traffic goes via the proxy.
  22. Sensible as usual from Steve
  23. It is - you will need to raise a support ticket for it. Can I ask why you want to do this? If it might be a common thing, we can potentially release a "proper" version. There's also the slightly odd version where you block the site you want to redirect, and use blockpage redirection, but i'd say that's dangerous with a domain like this.
  24. One to add to your list if you want something comparative to eSafe (particularly with regard to human moderation) would be Smoothwall monitor. Obviously, I will tell you it's fantastic, as I am horrifically biased, but if you want to know more i'd be happy to chat.
×
×
  • Create New...