Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. YEs - there's the user manuals, but better than that, when you move to Smoothwall, do a planning call with one of our techs (this is SOP, so no need to even ask!), and they will make sure you are on the same page with regard to certificates, proxies, transparent filtering etc.
  2. Not seen the change myself yet: annoyingly these do tend to roll out piece-meal. FWIW, it is not possible to redirect users to another site - you need to MitM to do that as well, which is why the Smoothwall blockpage MITMs on HTTPS regardless of what you have set up. The only way to keep functionality is to MitM, and you will really need to push a cert for that. You can do this with a transparent proxy too, so no need for wpad/proxy.pac, contrary to popular opinion
  3. Many Smoothwall Edu customers also use our firewall functionality - happy to answer any of your questions!
  4. The time sync is one to watch - got to be right on server, Smoothie, and PC. Email me your ticket # and I will have a nose about.
  5. We are supposed to be releasing a category... @OB1 has it gone out yet? (Am hiding in the wilds of eastern europe, so can't go poking around the blocklist lair and find out!)
  6. I know the guys at threattrack well. They are a good bunch. Their detections are generally in the right sort of area too, though perhaps not quite as consistent as some of the big boys, they are very effective.
  7. If you are lucky enough to have a small gym nearby, ffs use it. Small ones are the est, IME, as they are most often staffed (And patronised by) knowledgeable, helpful, friendly people. I stopped training a few years back due to the usual lazy excuses, but the real reason was, the gym I used to go to motivated me. I knew the guys, I knew if i missed a day i'd get some light-hearted sh1t for it the next time, I took advice from a 16 year old kid, and a 90 year old, and all points in between. Still good friends with some people I met there. If you're new, you will get so much more out of the help and advice more experienced people can give you. Also ignore [most of] what you read on the internet - here's probably a good place for advice because it is largely not full of "I ams" and "keyboard warriors", but many dedicated fitness forums are. Nowt like talking it through with an expert who you know is an expert, IYSWIM
  8. That should be normal; a JPEG is lossy compressed, the printer needs an uncompressed (some drivers may do lossless compression, but that's less effective than the original jpeg) raster, so you will find that the data is much larger.
  9. Myth: All office equipment must be tested annually <- a visual inspection will do nicely
  10. This is perfectly possible - you can easily transparently proxy HTTPS, and unless you want MITM, you won't need certs - but all you will get is domain names for blocking. I suspect Squid will do this out of the box - but you would need to be using version3, and I am not sure how common that is yet as standard on most distros. It's even possible to use google's NOSSLsearch selectively without resorting to DNS...
  11. Chromebooks will let you do 802.1x authentication on a per-user basis... that may be an option with the ruckus gear. Be aware that putting stuff in auth exception does *not* mean it is automatically allowed: quite the opposite, you can find that depending on your rules these sites now get blocked because the user browsing is in "unauthenticated users". The policy test tool can prove this if needed.
  12. OB's right - what you're seeing is actually an artefact of a change to our logging: we used to just not display 407s, because NTLM naturally generates a lot of them. now we do, because the logging system can handle the extra workload, and *because* of our commitment to safeguarding we want to be able to say "we log everything we can".
  13. In the file settings/main/settings USE_HOSTNAME_IN_REDIRECTS=on is the thing to twiddle. Gets gui exposure ~main75
  14. Our website is suffering a spot of downtime. Your issue is definitely dns related. The first thing i'd try is get this domain resolving on that network: that's the easiest. There is an option to go via ip, but it is hidden (backend config tweak). I will dig that out for you, but that would be a less preferred option.
  15. [Warning, overkill] Could route the call over IP and use something like this: http://www.voipon.co.uk/grandstream-gxw-4104-p-336.html?gclid=COK6m9yXnL0CFSQXwwodFHwAbQ to dump it back on the PSTN at the near end. Even use an ATA at the far end if they have a specific bit of phone kit.
  16. Someone finding one of those PCs, yesterday: click here
  17. It is a bit disturbing that these kids are only a few short years from being able to go out and work, get a mortgage, their own credit card, etc., and seem to have no idea of the value of money. Surely every purchase must have a price tag attached?
  18. Google make it increasing difficult to use their service without https - also it is quite difficult to teach users that "if it doesn't work, try http". If you want to do this well, you'll need a filter capable of SSL interception and header insertion.
  19. Generally we don't care if it even has a keyboard or mouse... but then we are odd.
  20. BYOD device isn't windows XP or aged android is it?
  21. be there wed/thu/fri - @zag if you fancy joining us for that beer, i'm sure we'll see you on stand at some point.
  22. You might find it needs adding to the "SNI allow list" as it does a bit of unpleasant tunnelling. My advice: avoid puffin, as it is unfilterable, and their developers have been very unhelpful when contacting them about making it easier to allow their product.
  23. I think people from our soton office will be on the train - I'll ask though
  24. Spend ~£100pcm. Roughly 50/50 gas and leccy - 2 bed back to back terrace. Suspect main offenders are aged server, aging TV, and aged combi-boiler. Oh, and lack of "pegging out" location leading to excessive reliance on tumble drier. Cats: 1. Probably something of an energy sink, as it causes things to be washed more frequently.
  25. @Dos_Box - you will find that shooting birdlife is pretty expensive. I find myself wishing for more length (quiet at the back!) with a variety of birds (ok, this really should have been rephrased) even with a 400mm lens (Canon's 100-400) which is about £1k's worth. Not to say you can't get good results with small birds, it's just trickier, i've crept up on tiny bee-eaters in africa with my previous long 'un, a cheapie 75-300, and I have a few decent pics of little sunbirds with the 400. Just don't expect miracles, and expect to pay a fair whack. You can get up to 500mm with a sigma for under £1k tho. I also find carrying the 1-4 a bind: sometimes I will do without a camera at all to save toting the thing, which is not a good plan. If you go for an older DSLR mind, you can always rent lenses fairly inexpensively, or borrow one from a friend (most decent camera insurance covers lending of lenses - I loaned mine to @rob_f when he went sailing off the south coast!)
×
×
  • Create New...