Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. If anyone has cisco kit knocking about WCCP is a great way to do transparent stuff
  2. DNS requests should go to your internal dns server in any case. For other stuf, the smoothie will send an ICMP reply that says "actually, the gateway's over there, but dont tell the web browser"
  3. Sorry, I am being unclear - perhaps due to sometimes writing posts while on the phone It *always* works for "regular http", sometimes it just doesn't play ball with https, in the case of smoothwall, it means that clients that DONT support SNI get blocked from accessing HTTPS, but everyone gets HTTP regardless.
  4. Tricky one. One option is to do it for all clients - those with a proxy set won't send ANY http(s) traffic, and as such won't see a difference. Other options are have your Access Points on a separate VLAN? Anyone think of any more cunning plans? There is another method, which requires a bridging device between your AP/the switch your APs are attached and the internet...
  5. I guess you can work out which product I can name. So.. lets say you have your wireless clients on a particular IP range, 192.168.7.0/24 Their gateway is a firewall on 192.168.7.254 They get to know of this gateway via the eternal miracle of DHCP 1. You get a "Product X" filter (see how amazingly unbiased he is, marvel at his bias free words... ) 2. You put it on 192.168.7.253, and say "please be a transparent proxy, thanks, your gateway is 192.168.7.254" 3. You change DHCP so the wireless devices get 192.168.7.253 as their gateway 4. (optional, more secure) you configure your gateway firewall to only allow http(s)connections from 253 5. Cackle slightly evilly as folk get their internets filtered Note: this only works for HTTPS traffic for clients which support SNI. See Wiki for list. Notable baddies: IE on XP, Older Android, iphone3 and below.
  6. Iptables (or WCCP in a pinch) is used to hijack the HTTP/S traffic and then something like TPROXY to help it on its way through squid. This is the sort of naff implementation detail you dont need to worry about if you have a filtering vendor to help out tho
  7. @Sheridan, which Guardian version you on? Also I think OB may have mangled his regex and not updated it on here
  8. Make a proxy your default gateway for wireless devices. You can happily make the proxy's default gateway your "real" default gateway, and a well configured proxy should ignore all non-http(s) traffic and pass it to the real deal.
  9. You need to tell squid not to authenticate those domains. I guess you are doing NTLM auth - we have years of experience in finding domains which don't play ball when you have an authenticating proxy, but we still get caught by one or two. Watch out for itunes as well, it plays VERY badly with inspecting proxies.
  10. Google's Outlook plugin for Appsync is also crap with proxies (it doesn't like authenticating much). I am not the biggest fan of mr Google. OTOH, the newer builds of Android support SNI, so are much more suitable for transparent proxying than their predecessors.
  11. Never used either, but I use Mozy which is similar to backblaze. These sort of services are EXACTLY what's needed, as there are some failure modes of other types of backup that could really screw you over
  12. Nice one ZH, another little 'un eh? Just can't give up the sleepless nights?
  13. Would avoid bothering with setting the trip limit, it causes only pain (for every useful symptom of changing it there are 10 irritations), to the extent it is going away in later versions of guardian. Would welcome a call/email if you want to chat trip limits, blocking etc
  14. Happy birthday ye scottish ruffian
  15. I believe it is doable - but you need the whole URL and as such will need some form of HTTPS interception type malarkey.
  16. Comes among a lot of hard games for the red wronguns, maybe... just maybe.. can we really do it 2 seasons on the run?
  17. And now we've got this new finnish lad... seems to be a CM... but ACM? DCM? Clayton's doing well... dont want to drop him, cant see Howson being dropped... back to playing a CM on the left? A good CentreHalf whose legs will last the season now please Simon...
  18. The return of Becchio, the signing of Forsell, the form of McCormack.. begs the questions: Two or one? Who? For me: Becchio & McCormack to start as a traditional front 2, with Forsell on the bench.
  19. Didn't realise it was so good, TBH - worth knowing, as I always get asked about home use, and it is difficult to know what to recommend.
  20. Content-Type: application/x-ns-proxy-autoconfig is what it should return. On your apache server (presume it is linux), run: curl -I /proxy.pac to check the headers
  21. Drop me a PM with your details, and i'll get it sorted. FWIW, Guardian3 (still in slow rollout) doesn't count IPs at all, it uses a much less intrusive technique.
  22. Our southampton office have a Smoothwall + Zen FTTC set up in this way, and our sales director Richard has the same but with BT.
  23. They all have to resell BT, as BT own the cabinets, so any LLU is "virtual LLU". IIRC the EU or whoever it is tells them not to be anticompetitive has set a date for when they need to provide true unbundling. Personally I would not hold my breath. My advice: if what you have now is on the good side of acceptable, don't move - it is inviting trouble
  24. Think the first 2 games we were better than the scoreline. Southampton are flying though, irritating since a large number of my colleagues are based there. Having said that, the first person to give me gyp about the result was support manager Tim, and he's Danish! *shrug*
×
×
  • Create New...