-
Posts
5,875 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by tom_newton
-
Glad to be of help. I do miss being in Ed-Tech...
-
I've used both in a commercial environment, and I have to say, using office365 is a massive chore compared with google docs. Being tied to crappy desktop software is just so limiting compared to the in-browser editing for collaboration. Sharepoint is just horrifying.
-
Anyway to cap bandwidth speeds at home?
tom_newton replied to abillybob's topic in Internet Related/Filtering/Firewall
Some of the billion devices offer basic QoS too, along with mac address reservation for an IP, that should do it - I have a 7800DXL which has these features, but I have not had cause to use them. -
Do you consider "WWW" and "The internet" two separate things?
tom_newton replied to Duranis's topic in General Chat
Emphatically yes - although I don't get worked up about non-technical people misusing the terms. This used to be one of my go-to questions for interviewing prospective tech hires. Interesting as services that used to be "Internet based" - eg POP3, FTP, VoIP, video streaming, etc are now often tunneled over HTTP(S) either directly, or, in the case of mail protocols, by going to a web service. This does make for some marginal grey areas (which I would expect a good interview candidate to be able to explore!) I'm also particular about the Internet getting a capital I -
If you're already using 802.1x for byod wifi auth, my advice would be to pass that straight on to a filter that can handle it (eg. my vote - the Smoothwall... I may have gone, but not forgotten!)
-
First up, block every machine but your mailserver from tcp/25 outbound. If your firewall allows, monitor that rule: you then have solved the problem AND found the culprit in one move. OTOH, Wireshark is fun and useful, so I will answer your question as posed, as well. In the absence of a mirror/span port on your switch, put a hub where you want to sniff (in this case, between your switch and your firewall, you are looking to find malicious traffic leaving your network). Plug your Wiresharking box into the hub as well (so there are 3 cables in there, 1 to switch, one to fw/router, one to your wireshark PC). Run wireshark as root/administrator (delete as applicable for OS) as you need admin privs to put a network card into promiscuous mode. Be sure you're sniffing the ethernet port not the wifi if its a laptop. Happy huntin'
-
iPads through Smoothwall
tom_newton replied to alfatec's topic in Internet Related/Filtering/Firewall
Shared IPads or 1:1? Ideally, for 1:1 you want to use Radius accounting with your Wifi APs. NTLM should work for 1:1, but can be hard to "clear off", and does need global proxy setting. For shared, SSL login is probably the best (only?) method. -
How hard is it to start a Smoothwall reseller?
tom_newton replied to cyberguy's topic in Internet Related/Filtering/Firewall
Nb: not a Smoothwall opinion (any more ) You will need to be pretty competent technically if you want to add value - Smoothwall already have some large partners who are strong in sales, the little guys only do really well if they are strong technically. With you coming from IT sales, I don't know your background! I would STRONGLY suggest looking at a range of complementary products - with your sales background, I am sure you know how hard it is to get to speak to the right people. If you get there and they've renewed iBoss 3 months ago, you're going to want to be able to talk wireless.. or something else that might actually be useful. -
The kerberos script is like ident, but unspoofable, but does need to be on a domain (or otherwise trusted) machine. It causes the smoothwall to link an IP and username for a short period (5 mins). Unfortunately the script continues to run on the "switched out" user. Sure it could be solved if someone looked hard enough.
-
[news] Amazon Prime Video released for Roku UK
tom_newton replied to abillybob's topic in Jokes/Interweb Things
Great - barely watch anything on prime because it means using the ps3. -
Smoothwall Unauthenticated IP
tom_newton replied to Techdw's topic in Internet Related/Filtering/Firewall
If its hitting an allow policy, auth is probably a red herring. Transparent proxy by any chance? -
Big fan of backblaze myself.
-
Had 2 condensers - one of which connected to mains draining, so didn't need emptying. Never been able to find a similar one since it died. Current one I have no complaints about, and it lived in an unheated cellar for a year or 3. I'd definitely have a vented if I had a vent-able place to put it. Simpler, cheaper, and no need to muck about with emptying the water.
-
transparent proxy Smoothwall
tom_newton replied to zoioroxo's topic in Internet Related/Filtering/Firewall
What's the nature of the failure? Is the smoothwall your default gw? -
Your times can be a specific day - but no 2 weekly or anything like that. I did have a bad hack that linked to a public ical and made timeperiods, but it never got above "hack" status.
-
Used to have a Humax, it was pretty good. Now have an echostar slimline thing (I gave the Humax away when we got sky, now we have Roku + NowTV) - the echostar is a total dog. A friend has a humax freesat box, and he swears by it.
-
Has anyone heard of iBoss
tom_newton replied to frank_7's topic in Internet Related/Filtering/Firewall
All 3 systems have the same answer for SSL traffic: MITM it with a proxy. All 3 need certs pushing to the client for this. All 3 can optionally not MITM some traffic. Iboss can optionally not even proxy some traffic. -
Has anyone heard of iBoss
tom_newton replied to frank_7's topic in Internet Related/Filtering/Firewall
Suspect 100% SSL is not far away. Then you end up relying on a domain list(!) to do your dirty work. If facebook, google, and microsoft are on the decrypt list, you may end up proxying 60-70% of your traffic. See also: square one, back to. I hate the internet -
Has anyone heard of iBoss
tom_newton replied to frank_7's topic in Internet Related/Filtering/Firewall
Bear in mind that whilst proxying might be older tech, with encrypted traffic you are always going to need to proxy to get any sort of granular filtering. Even those who claim to be non-proxy based (eg lightspeed) have this caveat. -
Have you changed the authentication method on the smoothie to "core auth" (meaning "someone else will tell me") for the wireless IP range?
-
Yes: you want 802.1x - this uses a username and password from AD instead of a passphrase, and is a one-shot deal per device (or until pw change). This can be used to seamlessly log into Smoothwall - and you can then have one SSID for everyone.
-
Great news - said nipper is lucky to be going to a brilliant family (admittedly, I have only one datapoint for my sample here, but I feel that's sufficient in this case)
