-
Posts
5,873 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by tom_newton
-
Good luck Ben, I shall miss you as a breaker of all things Smoothwall, but hopefully see you at trade shows and EG events?
-
The Death of School Proxies?
tom_newton replied to zag's topic in Internet Related/Filtering/Firewall
Did you know that google have begun effectively MITMing images sent to a gmail account? The Smoothwall Blog: Gmail Users: Google Makes Your Data More Secure, Owns a Bit More of Your Life -
The Death of School Proxies?
tom_newton replied to zag's topic in Internet Related/Filtering/Firewall
Same issues - just moved further away and harder to resolve. You either filter SSL or you don't. You can do it DNS based, but that gets old fast. -
The Death of School Proxies?
tom_newton replied to zag's topic in Internet Related/Filtering/Firewall
At ISP level, most filtering is DNS based, and not very good. Here's today's example: BBC News - Porn filters block sex education websites Yesterday's was about proxy anonymizers. Yes, this *will* get better. As it gets better, it will get more expensive. Good, Fast, Cheap. Pick any 2. I suspect in time a lot of this sort of thing will be done in private clouds, by ISPs, with products like Smoothwall and Lightspeed. -
Why Our Brains Make Us Click on Lists : The New Yorker <- this might interest you
-
Authentication Box
tom_newton replied to Wubbalubbadub's topic in Internet Related/Filtering/Firewall
Is the clock drifting on those boxes? -
I'll talk to the marketing guys tomorrow (and read this thread properly)
-
O365 Exchabge via Lightspeed box is slow
tom_newton replied to bodminman's topic in Internet Related/Filtering/Firewall
Is lightspeed blocking access to the CRLs you need? That could slow things down as IE will look to see if the cert has been revoked and have to wait $timeout seconds to find out that it can't...would hope lightspeed have a CRL category you can allow? -
Some more 1 Million posts stats
tom_newton replied to Dos_Box's topic in General EduGeek News/Announcements
How do the different versions of IE pan out? Interesting to see if, as predicted, IE users have become more update-prone Wonder how these compare to netcraft's figures - are we different from the population at large? Does anything change radically between, say the UK school day and evening times? -
North-o-meter: Where in the country do you belong?
tom_newton replied to elsiegee40's topic in General Chat
95% - its just thechips and gravy that keeps me from 100%, it's a vile concept. -
Our experiences with Sophos Web Filter
tom_newton replied to cyr0n_k0r's topic in Internet Related/Filtering/Firewall
Anything you think would be useful in terms of UI improvements, my DDI is in my 'sig - please drop me a line by email or phone and we will do what we can to improve - there is a programme of improvements on the go at the moment, but the more feedback we get the better that will be -
Internet Logging Software Recommendations
tom_newton replied to crc-ict's topic in Internet Related/Filtering/Firewall
That may be because you aren't authenticating in ISA - this is almost certainly doable. If you already have an ISA proxy, plus whatever EXA are up to I would seriously caution against adding another (eg. squid) box into the mix, it will make troubleshooting an order of magnitude harder. -
Internet Logging Software Recommendations
tom_newton replied to crc-ict's topic in Internet Related/Filtering/Firewall
if it is just logging you don't need dansguardian - squid can do authentication and logging - all dg will add in that case is blocking (and a bunch of complication you won't want), which you seem to have covered. Who is your ISP? -
How slow is your Smoothwall? UTM or own hardware?
tom_newton replied to lmgtfy's topic in Internet Related/Filtering/Firewall
Oh, and if you wouldn't mind emailing me a copy of your config I may be able to get around to testing its performance... -
How slow is your Smoothwall? UTM or own hardware?
tom_newton replied to lmgtfy's topic in Internet Related/Filtering/Firewall
That looks like a busy, but ultimately fairly healthy box, however the load averages tell a slightly different story - a load average of 10 with 2 quad cores is a mite high. What content modification rules have you got in place - they're the first place to look for reducing CPU load. -
How slow is your Smoothwall? UTM or own hardware?
tom_newton replied to lmgtfy's topic in Internet Related/Filtering/Firewall
An upgrade. Yes. Clicky clicky, waity waity, ooh, done. Should be fun -
How slow is your Smoothwall? UTM or own hardware?
tom_newton replied to lmgtfy's topic in Internet Related/Filtering/Firewall
Try turning off the "sophos web protection" feature on your desktop AV - it looks like it is responsible for a *lot* of requests. Can you do 2 things for me - confirm the processor you are running on, and run "top" on the commandline at peak time, and tell me how much CPU time squid is using. I suspect the difference between now and a couple of years ago is the number of web requests needed to complete the same "job" - google has doubled in "weight" over just a few years, and the likes of BBC are considerably request-heavier too, with a lot of in page updates. -
How slow is your Smoothwall? UTM or own hardware?
tom_newton replied to lmgtfy's topic in Internet Related/Filtering/Firewall
@buzzard - it isn't, generally - it must be that the OP is shifting a serious amount of traffic. In actual fact Guardian has become slightly more efficient over the last 18 months. -
How slow is your Smoothwall? UTM or own hardware?
tom_newton replied to lmgtfy's topic in Internet Related/Filtering/Firewall
To be fair it seems that support may have got this one right - the box is often seeing 600% CPU usage in Guardian alone, and load averages of 10+ on an 8 core box. Load average is "number of tasks waiting for CPU" - you have effectively 8 CPUs with 10/11 tasks waiting at busy times, so 2-3 are going to end up not served in a timely manner. You may just have a great deal of traffic - is there perhaps, as a previous poster speculated, one or two users applying dubious workloads? We do have the 64bit release coming in a week or so, but I am not sure it will do a lot for you, given that your machine is already pretty effective in using its CPU cores to the max. -
How slow is your Smoothwall? UTM or own hardware?
tom_newton replied to lmgtfy's topic in Internet Related/Filtering/Firewall
Thanks or that - it may be there's just not enough cores to handle the load after all - but I will check out the ticket. -
How slow is your Smoothwall? UTM or own hardware?
tom_newton replied to lmgtfy's topic in Internet Related/Filtering/Firewall
Chris, There could be a couple of issues in play here. First, we have seen connection tracking overloads on some sites - if you haven't already, go adjust the conntrack table (networking/advanced IIRC) - if it's set to 65000 or so (auto) double it. If it's not that, there could be a few other things pegging out the box's processor. It does sound like you have an unusually busy system there. Would certainly be worth working out what's the bottleneck before laying out any cash either on our tin, or a 3rd party's (which may well be cheaper in some cases!) -
Dansguardian and google images
tom_newton replied to JustusCook's topic in Internet Related/Filtering/Firewall
You'll need both Suspect the second should read: "(^http://[a-z]*\.google\.[a-z]*/[a-z]*\?)"->"\1&safe=vss" though ive not tested it -
Interesting thread. @zag - blocking tor is a one click op - assuming you have a firewall block rule set up somewhere, adding the layer7 tor inspection is one ticky. Admittedly it is a reasonably well hidden ticky... but we are slowly improving findability on our GUi - yeah, its a big old beast as we've the most full featured product! Also worth pointing our that you won't block tor etc on a web filter per se - you need to be using some firewall functionality for that, as tor simply ain't going to go through your proxy. In a Smoothwall sense this would be either a UTm or bridge deployment (Lightspeed I think is generally bridge type or bypass, either will work, sophos, AFAIK will do neither, do correct me if Im wrong)
- 79 replies
-
- firewall
- recommendations
-
(and 1 more)
Tagged with:
-
Saved me a lot of hassle on more than one occasion.
-
I'll restate my question - given that Smoothwall knows a pupil by their AD creds, how would a MIS and Smoothwall best communicate about a student? My theory was "MIS knows UPN, if Smoothie knows UPN, then we know who we are talking about with no ambiguity".
