Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. SNI is the trick we use - basically the browser gives away where it is going, so you can domain filter (and MITM if you feel that way out), sadly its a fairly new extension, but support is there in all major tablets and laptops afaik
  2. It is possible to transparently filter https with the right filter. Sadly this relies on client side extensions not present in winXP, early IOS or pre-gingerbread android.
  3. Good news IMO.
  4. Nothing's perfect - a combinmation of force strict safesearch, deep url filtering and blocked search terms will get you a fair old distance though
  5. Technical Consultant is the job ad...
  6. MAC_Find: Vendor/Ethernet/Bluetooth MAC Address Lookup and Search <-- find out the manufacturer from the MAC - might help narrow it down. Also, try pointing nmap at it for an OS fingerprint?
  7. Looks like half a "duo" - logitech did a squeezebox for a while where all the display etc. was on the remote, and the bit that made the noise was "headless". Still perfectly useable I would have thought (never had a duo) - if you are willing to control what you listen to from the server, either via web interface, or droid/iphone app.
  8. I'm slightly biased, but I would say come and talk to Smoothwall - many schools use our UTM. We're probably more education focused than Sonicwall (a bit more filter-oriented IYSWIM), although there's not a lot wrong with their kit. The advantage you will have there is integrated wireless, although similar levels of integration can be achieved separately. Certainly replacing firewall and inline content filter with a UTM is a common idea - it reduces from 2 points of failure to one.
  9. When the bad address isn't given to your client PC, can you ping it, or does it appear in any arp-tables anywhere? TBH if it were a second DHCP server you would probably see the issue more often (it sounds like it is limited to a handful of addresses?), I would start by looking for hosts that might be squatting on those addresses with a static IP.
  10. Something else has stolen the address? Is there a rogue DHCP server on your network someplace?
  11. Not really "less secure" per se, but it is harder to do authentication on a tproxy, you tend to have to rely on getting an ip:username pair from some login thang (could be from your wireless setup?) and holding it - of course you either need a way to refresh it, or guarantee of binning it when a new user logs in. Managing SSL is also harder with transparent proxies, but if you have a modern browser AND a decent proxy, you'll be ok. Transparent proxying in general is a pain in the butt, but one we are stuck with.
  12. There's really two choices here: Squeezebox, or wrong. I've 2, including a pre-logitech v1 from ~10 years ago which is still getting use. Few smoothie people have em, all seem happy. Rich the local audiophile has a couple, Lawrence has patched his to have a larger clock to cope with duff eyesight, Pete is running the server off a NAS...
  13. AAISP - Home might be an option? Our development team use them for testing, seem tech compatible iyswim. Unfortunately despite being just round the corner from you we can't get fttc at all, so we're on wireless from metronet which is awesome but no cheap.
  14. PM sent.
  15. Once again we are looking to expand the pre-sales team in Leeds, so I can spend more time posting on edugeek (not true). Looking for someone who can work with sales folk, who doesn't mind spending time on the road, and who can do things like: * presenting technical solutions to customers * designing firewall and filtering deployments * setting up and installing firewall and filter systems from Schools, full LEA to corporate * answering questions on edugeek * helping the sales team understand the products * assisting the product manager (me) in shaping future products knowledge wise * solid knowledge of IP/networking * windows networking & AD * any web filter, the more the merrier * linux/firewall/vpn helpful but not essential Quals... we hire people, not paper, but CCNA type stuff shows you might be in the right ballpark! PM me if you want any further detail, we'll probably have a job ad on the website before too long.
  16. Coffee's in the post... guaranteed no mustelid dump, either.
  17. It is possible, it just opens up a lot of other holes for stuff to tunnel through. We are working on ways to recognise skype and allow it, but the protocol is very unfriendly to this.
  18. If you come in on the train, and dont mind a little walkies, hammersmith tube is not too far, the olympia station is limited service, and a "guaranteed extra change" IYSWIM.
  19. Novotel Hammersmith is best for walkably close, but not cheap Ibis Earls court is cheaper, bit of a longer walk but if you are "just" visiting, that's OK - bit of a trek if you're exhibiting but still doable. Other than that there's loads of el-cheapo on cromwell road IIRC, stuff like "easy hotel", again, walkable - i've walked as an exhibitor from some fleapit on cromwell, back when our show budget was 2 quid and a big orange.
  20. Indeed - that's the "other" way to do it. Still need an HTTPS intercepting filter though, and they are still not that common. We plan to support this way RSN.
  21. Not sure - I will try and get hold of the support team leader. Still, if you think you have what it takes, there is no harm in firing in your CV
  22. You *may* be out of luck with netsweeper - afaik they support neither known method of limiting google accounts are you running your own proxy prior to netsweeper?
  23. Of course it's not one of ours, we only sell to the more discerning dictator
  24. Still got a bags of sweets left - only 3 this year, but we don't do decorations. Ah well, Smoothwall pre-sales tech team will be fat. BTW, I thought it was the knocker that played the trick in the absence of treat - it was in my day. I vaguely lament the dearth of harmless tricks
×
×
  • Create New...