Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,875
  • Joined

Everything posted by tom_newton

  1. Glad to be of help. I do miss being in Ed-Tech...
  2. I've used both in a commercial environment, and I have to say, using office365 is a massive chore compared with google docs. Being tied to crappy desktop software is just so limiting compared to the in-browser editing for collaboration. Sharepoint is just horrifying.
  3. IIRC - and i've been out of the loop 8 months - lightspeed does selective SSL inspection for some pretty rudimentary content-aware filtering
  4. Some of the billion devices offer basic QoS too, along with mac address reservation for an IP, that should do it - I have a 7800DXL which has these features, but I have not had cause to use them.
  5. Emphatically yes - although I don't get worked up about non-technical people misusing the terms. This used to be one of my go-to questions for interviewing prospective tech hires. Interesting as services that used to be "Internet based" - eg POP3, FTP, VoIP, video streaming, etc are now often tunneled over HTTP(S) either directly, or, in the case of mail protocols, by going to a web service. This does make for some marginal grey areas (which I would expect a good interview candidate to be able to explore!) I'm also particular about the Internet getting a capital I
  6. If you're already using 802.1x for byod wifi auth, my advice would be to pass that straight on to a filter that can handle it (eg. my vote - the Smoothwall... I may have gone, but not forgotten!)
  7. Give yourself 6 months. The last thing you want is to force your own hand by coming up against a renewal with not enough time. Talk to your smoothwall rep as well - let them know what you like about anything else you are looking at.
  8. First up, block every machine but your mailserver from tcp/25 outbound. If your firewall allows, monitor that rule: you then have solved the problem AND found the culprit in one move. OTOH, Wireshark is fun and useful, so I will answer your question as posed, as well. In the absence of a mirror/span port on your switch, put a hub where you want to sniff (in this case, between your switch and your firewall, you are looking to find malicious traffic leaving your network). Plug your Wiresharking box into the hub as well (so there are 3 cables in there, 1 to switch, one to fw/router, one to your wireshark PC). Run wireshark as root/administrator (delete as applicable for OS) as you need admin privs to put a network card into promiscuous mode. Be sure you're sniffing the ethernet port not the wifi if its a laptop. Happy huntin'
  9. Shared IPads or 1:1? Ideally, for 1:1 you want to use Radius accounting with your Wifi APs. NTLM should work for 1:1, but can be hard to "clear off", and does need global proxy setting. For shared, SSL login is probably the best (only?) method.
  10. Some quality suggestions on here - I tellst thee it could be done if you looked hard enough Hope Smoothwall take this on and improve the shipped version.
  11. Nb: not a Smoothwall opinion (any more ) You will need to be pretty competent technically if you want to add value - Smoothwall already have some large partners who are strong in sales, the little guys only do really well if they are strong technically. With you coming from IT sales, I don't know your background! I would STRONGLY suggest looking at a range of complementary products - with your sales background, I am sure you know how hard it is to get to speak to the right people. If you get there and they've renewed iBoss 3 months ago, you're going to want to be able to talk wireless.. or something else that might actually be useful.
  12. The kerberos script is like ident, but unspoofable, but does need to be on a domain (or otherwise trusted) machine. It causes the smoothwall to link an IP and username for a short period (5 mins). Unfortunately the script continues to run on the "switched out" user. Sure it could be solved if someone looked hard enough.
  13. Great - barely watch anything on prime because it means using the ps3.
  14. If its hitting an allow policy, auth is probably a red herring. Transparent proxy by any chance?
  15. Big fan of backblaze myself.
  16. Had 2 condensers - one of which connected to mains draining, so didn't need emptying. Never been able to find a similar one since it died. Current one I have no complaints about, and it lived in an unheated cellar for a year or 3. I'd definitely have a vented if I had a vent-able place to put it. Simpler, cheaper, and no need to muck about with emptying the water.
  17. What's the nature of the failure? Is the smoothwall your default gw?
  18. Your times can be a specific day - but no 2 weekly or anything like that. I did have a bad hack that linked to a public ical and made timeperiods, but it never got above "hack" status.
  19. Used to have a Humax, it was pretty good. Now have an echostar slimline thing (I gave the Humax away when we got sky, now we have Roku + NowTV) - the echostar is a total dog. A friend has a humax freesat box, and he swears by it.
  20. All 3 systems have the same answer for SSL traffic: MITM it with a proxy. All 3 need certs pushing to the client for this. All 3 can optionally not MITM some traffic. Iboss can optionally not even proxy some traffic.
  21. Suspect 100% SSL is not far away. Then you end up relying on a domain list(!) to do your dirty work. If facebook, google, and microsoft are on the decrypt list, you may end up proxying 60-70% of your traffic. See also: square one, back to. I hate the internet
  22. Bear in mind that whilst proxying might be older tech, with encrypted traffic you are always going to need to proxy to get any sort of granular filtering. Even those who claim to be non-proxy based (eg lightspeed) have this caveat.
  23. Have you changed the authentication method on the smoothie to "core auth" (meaning "someone else will tell me") for the wireless IP range?
  24. Yes: you want 802.1x - this uses a username and password from AD instead of a passphrase, and is a one-shot deal per device (or until pw change). This can be used to seamlessly log into Smoothwall - and you can then have one SSID for everyone.
  25. Great news - said nipper is lucky to be going to a brilliant family (admittedly, I have only one datapoint for my sample here, but I feel that's sufficient in this case)
×
×
  • Create New...