Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,876
  • Joined

Everything posted by tom_newton

  1. Saved me a lot of hassle on more than one occasion.
  2. I'll restate my question - given that Smoothwall knows a pupil by their AD creds, how would a MIS and Smoothwall best communicate about a student? My theory was "MIS knows UPN, if Smoothie knows UPN, then we know who we are talking about with no ambiguity".
  3. Chaps et Chapesses, Quick question. If I wanted to determine a student's UPN [yes, I mean unique pupil #, or the equivalent in your locale - thanks!] from AD, how would I do that? Do you folks generally maintain some link for MISy purposes? If so how is this managed? Cheers, Tom
  4. As a subdomain you can differentiate sites, and just mitm that?
  5. It certainly does work - but there are two reasons it wouldn't apply: 1. The site is using SSL encryption, and you aren't MITMing it - we then have no access to the URL. 2. There's another rule above the one you're writing which applies an allow or whitelist action to the site in question.
  6. @john you've got my mobile I am sure - you're always welcome to come out with us Smoothwall folks, even if you're an ex-customer you are not an ex-favourite
  7. I'll be there weds afternoon/thurs morning, mostly lurking around the Smoothwall booth
  8. Auth bypass is probably not the place - it looks like it is managing auth but that the site isn't playing nicely with SSL. While i look into it, try making another ctegory with just this site in it, and applying a whitelist rule. That's the most powerful "let this stuff through" rule there is
  9. I presume you are using a transparent proxy? There's 2 possible issues: 1. Authentication. In general, apps hate authentication, but browsers are OK. A good solution to this is to use the 802.1x authentication tie-in with smoothwall. This authenticates the device prior to any traffic being sent, so is much more useful for apps. 2. Transparent proxying Smoothwall is an HTTP proxy. Some apps use non-HTTP protocols over the HTTP ports, or don't stick to the standards in some ways. Facebook moile's definitely not one of these, but I guess whatsapp may be. Would suggest making sure it's not auth that's the problem, and then we can look at individual apps. It's also worth turning on SNI exceptions in your transparent proxy authentication policy - this works around some badly behaved apps.
  10. Thanks - good to hear about the old place - must have changed a heck of a lot since I was a pupil in the early 90s. If you ever get a Smoothwall onsite I will have to come and do the install
  11. Remember when my dad used to teach, he went through a similar thing in '95 when Crofton high was pretty much destroyed (History of the School) - not much IT to recover but we went to the other local schools begging old Geography books! Horrible thing to happen, and so difficult to recover from. The school I went to (outwood grange) also had a major fire - the remnant of which was a plexiglass "bubble" through which you walked to get between buildings. The idea being, if one building caught, the bubble would melt, and the fire couldn't spread. I presume it's still there...
  12. Got it Sky+'d... should be pretty good.
  13. Should be a matter of using the port forward page on the networking tab to add a rule - TBH I can't remember the fields off hand, I think there's a dropdown to pick your external interface, then a "from" IP (that's *their* IP, leave it blank to begin with then tighten down later), the from port (this is the port they'll connect to), then internal ip/port combo (this is whats open on the phone system).
  14. ICT direct. Failing that, probably best go to ICT Direct. They've done us a good job on a server rack after we bought one from ebay and it sucked. Ebay bad; John, Dave, Vicki & crew good.
  15. SCP is the only way I think. You can do it either way: scp from the windows server is usually easiest.
  16. Have you got any IDS/IPS setup on the firewall
  17. Without MITM you can't redirect HTTPS requests to HTTP - unless the origin website does it for you, in this case, Google are willing to do so with "nosslsearch". The DNS based trickery to achieve this, in my view is overkill. I prefer a connect-header rewrite, but this relies on your proxy to support it. Short answer: you need a DNS server that supports their kludge, or a proxy server that supports mine
  18. I'm duty bound to suggest you try Smoothwall we have a lot of happy corporates as well as schools on our books! PM me your details if you want to take a looksee.
  19. I live on a road with "crescent" in the name that's perfectly straight, so I make a habit of spotting such oxymoron roads
  20. Drop me an email with your Cv and tell me what you're good at and I will have a poke around @ Smoothwall Leeds. We're often short of bodies...
  21. They didn't develop it, though AFAIK they paid for it to be developed... (not by us before you ask!!!)
  22. Took it for a dodgy knee - never worked worth a curse. Does seem to work for dogs, but maybe that's a proxy-placebo?
  23. Forcing safesearch has got a spot harder over the last year or two thanks to the prevalence of https - but with the right filter it is eminently possible.
  24. You should be able to at least remove comments & related vids in your content filter: Smoothwall supports both. We also support youtube edu mode, and can block the ads too - description might be trickier, but one of the blocklist team could have a go I am sure.
  25. Hmm, interesting. Since my favourite ISP (UKOnline) was devoured by garbage, I have been looking for the one true ISP. Colleagues suggest Andrews and Arnold.. Related question: best home router (screw wireless, can do separate AP) - but is there one with decent diags and a good modem? All reviews concentrate on "fluff" IME.
×
×
  • Create New...