Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. Good luck Ben, I shall miss you as a breaker of all things Smoothwall, but hopefully see you at trade shows and EG events?
  2. Did you know that google have begun effectively MITMing images sent to a gmail account? The Smoothwall Blog: Gmail Users: Google Makes Your Data More Secure, Owns a Bit More of Your Life
  3. Same issues - just moved further away and harder to resolve. You either filter SSL or you don't. You can do it DNS based, but that gets old fast.
  4. At ISP level, most filtering is DNS based, and not very good. Here's today's example: BBC News - Porn filters block sex education websites Yesterday's was about proxy anonymizers. Yes, this *will* get better. As it gets better, it will get more expensive. Good, Fast, Cheap. Pick any 2. I suspect in time a lot of this sort of thing will be done in private clouds, by ISPs, with products like Smoothwall and Lightspeed.
  5. Why Our Brains Make Us Click on Lists : The New Yorker <- this might interest you
  6. Is the clock drifting on those boxes?
  7. I'll talk to the marketing guys tomorrow (and read this thread properly)
  8. Is lightspeed blocking access to the CRLs you need? That could slow things down as IE will look to see if the cert has been revoked and have to wait $timeout seconds to find out that it can't...would hope lightspeed have a CRL category you can allow?
  9. How do the different versions of IE pan out? Interesting to see if, as predicted, IE users have become more update-prone Wonder how these compare to netcraft's figures - are we different from the population at large? Does anything change radically between, say the UK school day and evening times?
  10. 95% - its just thechips and gravy that keeps me from 100%, it's a vile concept.
  11. Anything you think would be useful in terms of UI improvements, my DDI is in my 'sig - please drop me a line by email or phone and we will do what we can to improve - there is a programme of improvements on the go at the moment, but the more feedback we get the better that will be
  12. That may be because you aren't authenticating in ISA - this is almost certainly doable. If you already have an ISA proxy, plus whatever EXA are up to I would seriously caution against adding another (eg. squid) box into the mix, it will make troubleshooting an order of magnitude harder.
  13. if it is just logging you don't need dansguardian - squid can do authentication and logging - all dg will add in that case is blocking (and a bunch of complication you won't want), which you seem to have covered. Who is your ISP?
  14. Oh, and if you wouldn't mind emailing me a copy of your config I may be able to get around to testing its performance...
  15. That looks like a busy, but ultimately fairly healthy box, however the load averages tell a slightly different story - a load average of 10 with 2 quad cores is a mite high. What content modification rules have you got in place - they're the first place to look for reducing CPU load.
  16. An upgrade. Yes. Clicky clicky, waity waity, ooh, done. Should be fun
  17. Try turning off the "sophos web protection" feature on your desktop AV - it looks like it is responsible for a *lot* of requests. Can you do 2 things for me - confirm the processor you are running on, and run "top" on the commandline at peak time, and tell me how much CPU time squid is using. I suspect the difference between now and a couple of years ago is the number of web requests needed to complete the same "job" - google has doubled in "weight" over just a few years, and the likes of BBC are considerably request-heavier too, with a lot of in page updates.
  18. @buzzard - it isn't, generally - it must be that the OP is shifting a serious amount of traffic. In actual fact Guardian has become slightly more efficient over the last 18 months.
  19. To be fair it seems that support may have got this one right - the box is often seeing 600% CPU usage in Guardian alone, and load averages of 10+ on an 8 core box. Load average is "number of tasks waiting for CPU" - you have effectively 8 CPUs with 10/11 tasks waiting at busy times, so 2-3 are going to end up not served in a timely manner. You may just have a great deal of traffic - is there perhaps, as a previous poster speculated, one or two users applying dubious workloads? We do have the 64bit release coming in a week or so, but I am not sure it will do a lot for you, given that your machine is already pretty effective in using its CPU cores to the max.
  20. Thanks or that - it may be there's just not enough cores to handle the load after all - but I will check out the ticket.
  21. Chris, There could be a couple of issues in play here. First, we have seen connection tracking overloads on some sites - if you haven't already, go adjust the conntrack table (networking/advanced IIRC) - if it's set to 65000 or so (auto) double it. If it's not that, there could be a few other things pegging out the box's processor. It does sound like you have an unusually busy system there. Would certainly be worth working out what's the bottleneck before laying out any cash either on our tin, or a 3rd party's (which may well be cheaper in some cases!)
  22. You'll need both Suspect the second should read: "(^http://[a-z]*\.google\.[a-z]*/[a-z]*\?)"->"\1&safe=vss" though ive not tested it
  23. Interesting thread. @zag - blocking tor is a one click op - assuming you have a firewall block rule set up somewhere, adding the layer7 tor inspection is one ticky. Admittedly it is a reasonably well hidden ticky... but we are slowly improving findability on our GUi - yeah, its a big old beast as we've the most full featured product! Also worth pointing our that you won't block tor etc on a web filter per se - you need to be using some firewall functionality for that, as tor simply ain't going to go through your proxy. In a Smoothwall sense this would be either a UTm or bridge deployment (Lightspeed I think is generally bridge type or bypass, either will work, sophos, AFAIK will do neither, do correct me if Im wrong)
  24. Saved me a lot of hassle on more than one occasion.
  25. I'll restate my question - given that Smoothwall knows a pupil by their AD creds, how would a MIS and Smoothwall best communicate about a student? My theory was "MIS knows UPN, if Smoothie knows UPN, then we know who we are talking about with no ambiguity".
×
×
  • Create New...