Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. Quick heads-up for you folks.. we are still recruiting for at least 2 positions in southampton... there's a sysadmin role and also a support team member afaik. Careers at Smoothwall <-- sysadmin ad is here TBH I am not closely involved in these recruitments as they are both in our fareham office, but if you want to email me CVs I will forward them.
  2. It should be possible in either version i think.. yeah, definitely. DT - remind me tomorrow and we'll work it out
  3. Actually, dansguardian is not a good proxy - as it relies on another proxy to do the heavy lifting - squid. If you don't need the filtering aspects (which in this case we don't) squid3 is a very capable, and reasonably well documented open source proxy, capable of acting as a transparent proxy. It is also packaged with all good linux distros, and some bad ones.
  4. Suggest that will only work if your proxy is willing to act transparently. Which it may or may not. There are other possible hacks, such as running a tproxy which upstreams to your regular proxy, but these are not for the faint hearted
  5. Stay at the novotel, it has good price:closeness. Make sure set-up and tear-down is known in advance, and if you need to cart stuff to a car, get someone to bring it to the olympia multi-storey REALLY early. Traffic is always bad. Use the exhibitor lounge, it is crap, but slightly less crap than everything else. Pay attention to those walking past - you don't have to be pushy but people who are interested WILL walk by if you don't say hello Feel free to call at Smoothwall if you need to borrow something, i'm not doing set-up this year, but my colleagues are a kindly lot Comfortable not-too-new shoes essential If you have any specific questions, i'll try and answer - this will be my 7th or 8th BETT as an exhibitor, started with me, the MD and the head of tech support on a tiny stand, now marketing dept. look after everything. How times change
  6. Yes it is - two new support engineers have accepted positions at Smoothwall this month, so things should improve soon.
  7. application control is more a firewall feature - need to be on the gateway really. Might I ask which applications you're looking to control, and if you are wanting to block or monitor?
  8. what auth you using on censornet? How do clients get proxy? Tried a packet dump? Should help narrow it down. Smells like proxy issue to me.
  9. unfortunately a URL filter is always going to suffer against proxies. You need a content filter... Meantime, block info and cc and use an ssl whitelist?
  10. there are fixes in the works later this month for itunes and the Youtube application. Both are workarounds for ipad idiosyncrasies. Am on holiday right now but my colleagues in presales or support will supply further info if asked!
  11. What issues with smoothie? Much as i'd obviously suggest certain commercial solutions that do just as you want, i'd still rather you use smoothie express than any other thing
  12. We pay ~850/mo for microwave 100/100. Provider only covers a few cities though, nowt south of brum yet, installed within 14 days
  13. Interesting. We've classified the sun under "adult" as so much there is a bit dubious (particularly page3, but other images too)- totally understand that kids can legally get the same content at the newsagent, but there isn't a newsagent on every desk IYSWIM
  14. A while ago Bing was doing a better job than google IMO, now the balance is a bit the other way. Both have caused problems for filtering folk in the past by changing things without warning, or worse only changing for some users! We can do "deep url" scanning (usually, when the search engines are behaving) to block images from known dodgy sites, though that usually entails blocking a few odd ones like blogger.com to make it really work.
  15. Safesearch "strict" is much better than moderate in this case. Any forcing of safesearch should be to "strict", as the moderate ones are often just for text etc. A hard one to block as a search term - the presence of tokyo seems relatively irrelevant, other cities work too, though not quite as well.
  16. You could lock the PC down fairly hard, and use one of the many "netnanny" type client-side filters. Most of these log. Or get a router which supports some rudimentary web logging. Also turn off wireless, and if you are feeling like a real b--tard hot-glue the cable into the PC and the modem/router (this could leave you down a NIC (or a motherboard if it's onboard) and a DSL router.. )
  17. Thanks Daz. We actually had to fork over some wedge to our friends at GFI (nee Sunbelt) in order to allow all our customers who currently had clam to have their AV honoured up until the end of their contract with Smoothwall. That did mean that those who bought 1 year renewals effectively got penalised slightly, but it was about as fair as we could be.
  18. Have you got "advanced mode" on in your selection tree? You rascal
  19. Blocking https entirely is using a sledgehammer to crack a nut. I don't remember what exa use to filter, but it should be able to do this ok, I might forgive if it is transparent filtering and you use xp, but otherwise... Grr. A word of caution on host file jiggery poker. If you use a proxy the dns lookup is done there so host won't work. Also, if students can hit facebook over https, then it is woefully easy to access other secure sites that might cause problems, from secure Google images to secure proxy anonymizers. The easiest way to control https by domain is to use a traditional proxy. You could perhaps run up squid with an https whitelist as a cheap and not very cheerful alternative. Happy to discuss further options if you want to explain how exa are filtering, either here or by phone /email, tho I am out of the office for a day or so now, I'm still vaguely in touch!
  20. The youtube app will not work well with many proxies, as it needs support for certain http features. Most clients will gracefully fall back to earlier modes of http, but oh no, that would be too easy. For Smoothwall customers, we're working on a workaround so that the proxy allows these features for whitelisted domains (thers only a few googlevideo domains we need, shouldnt impact other filtering...) - I dont know if it has been proven to work yet though. I think you may be stuck between asking Microsoft for a feature, and apple/youtube to fix a bug....
  21. Time to find out if they've fixed any auth bugs...
  22. It's a bit of an overhaul of Guardian, lots of cool new stuff, but migrating will take a bit of thinking. Have a look at Kanal von SmoothWallTV - YouTube there are some intro videos on there.
  23. Probably depends on your authentication type - can the latest bloxx offer a different auth type (eg. captive portal) on a separate proxy port, for example? Thats how we'd approach it usually.
  24. 2 it seems - hard to tell from the version, as that's the base software version. If rules are being "ordered" automatically though, thats G2.
  25. Default route is the smoothie only for the clients, and they can still happily have a route that lets them get to the DNS server (which has a route to the "real" gw). WCCP is the shiz tho, as you can let the cisco do the heavy lifting, you just need the wccp device to be on the path that the clients you need to proxy are taking to the internets, then redirect 80/433 based on src ip, and bob's your mother's brother. Unfortunately it carries the usual cisco learning curve (more of a learning cliff)
×
×
  • Create New...