-
Posts
5,873 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by tom_newton
-
@Ranj - you may need to upgrade the auth component to the version which supports multiple AD controllers, then use NTLM on one port, and SSL login (or ident) on another. If you havent been granted Auth3 yet, either PM me your details and i'll add it, or wait until ~tomorrow when it goes on general release.
-
Blocking Skype with Smoothwall
tom_newton replied to MartinT's topic in Internet Related/Filtering/Firewall
Heh, sometimes I amaze even myself Martin... i'm thinking we communicated by email in less enlightened days.. are you the Martin from Ascot who's been with Smoothwall for.. next to forever.. and who works at a school with a saint's name? -
Smoothwall Database Errors
tom_newton replied to MartinT's topic in Internet Related/Filtering/Firewall
Looks like you may need a database rebuild... worth getting in touch with support. -
Well - rep for jon - curry is up there with whisky for its restorative power - to quote a friend of mine it's "good for what ails ye", as is anything with garlic and chilli (which in our house includes spag bol, and a number of other dishes you would normally not associate with large amounts of chilli) Also tho.. rep for Dan - Lemsip is horrible stuff.
-
Smoothwall user cannot login, limit reached
tom_newton replied to ianniow's topic in Internet Related/Filtering/Firewall
ian, could you pm me over your details, I just want to double check something as there's been a few auth changes recently, want to know which version you run -
Blocking Skype with Smoothwall
tom_newton replied to MartinT's topic in Internet Related/Filtering/Firewall
Try blocking https connects to a bare IP in guardian (its a "special" class in policy table) - that, along with sufficiently tight port rules should do it ok. -
Smoothwall user cannot login, limit reached
tom_newton replied to ianniow's topic in Internet Related/Filtering/Firewall
I think ian is having concurrent (single) user issues rather than licence issues - certainly sounds that way -
Smoothwall user cannot login, limit reached
tom_newton replied to ianniow's topic in Internet Related/Filtering/Firewall
An auth restart shouldnt bother other users in an NTLM environment. Sounds like a strange one this - is her PC misbehaving? Which is the latest auth update you have installed, out of interest? -
Smoothwall user cannot login, limit reached
tom_newton replied to ianniow's topic in Internet Related/Filtering/Firewall
Does the user appear under services/auth/logged-in users? You should be able to force a logout there. Also you could restart the auth subsystem (services/auth/control) as a last resort - this is faster than restarting virtually anything else, and if you are using NTLM, shouldnt really impact users too heavily. -
Google's new secure search
tom_newton replied to Teapot's topic in Internet Related/Filtering/Firewall
Interestingly, separating live@edu from hotmail without interception seems possible, whereas separating google(mail|dox|etc) from secure search looks to require HTTPS interception. -
@36 - what you want to do sounds fine. If you are having any issues configuring, its OK to ring support and just ask "how do I..."! @markyboy - you are a suspicious chap - 3 posts and all pimping Lightspeed. I'm not entirely convinced you don't work for them if you do, its worth mentioning - gives you more credibility not less, IME. If you don't - please accept my apologies for being suspicious!
-
It's ok to mention Bloxx - just don't say it 3 times whilst looking in a mirror They don't have a bad old system either (I have one!) - it is certainly simpler in look, but I feel ultimately at cost of expressive filtering rules Again - if there's UI paradigms that you guys would particularly like to see - wether you are thinking "just tweak this here" or "change that radically" let me know. We really can get things done!
-
7years: 2 sick days. Nothing for ~5 years - score 1 for whisky on toast.
-
Replace dairy with whisky. Works a treat.
-
Generally just the bad bits. Depends on how the site is infected and which problems are encountered. you can also turn on AntiVirus, which has a significant performance cost, but will further reduce the level of any infection.
-
@HCC - No worries about being negative - if we don't get negative feedback it is hard to improve. Would welcome any detailed criticisms by email as well - particularly "stuff you do every day" which is hard. If you could also let me know what server platform you're running on, and how many users you have, we can assess wether it should be sufficient. FWIW, we are releasing 3 sets of updates (Reporting, auth, Guardian) of which only reporting is out fully (make sure you are up to date), each of which will cause that component to use *less* resource than its predecessor, so you may find that in the coming months you get some "free" performance. I would personally suggest that Securus + RM will eave you open to abuse in the anonymizer area..
-
@Rabbie - drop me a mail with any concerns you have and i'll put you in touch with the right folk. @Salan - We hope to re-vamp our training to be more "bite size" and easy to deliver soon. I'll let Edugeekers know as soon as we manage that! If reports are taking overnight - we have issues there. Worth talking to support direct. I understand Stone's training wasn't ideal - it was their first go at it IIRC. @36degrees - not a stupid question - the answer is "maybe" - how do you want it to work? You don't *have* to authenticate users, but if you want names in the reporting and different levels for different users, then you will need to. NTLM is the most common method of authentication. It generally works OK, but the more you deviate from Windows+IE, the less friendly it is! NTLM lets you authenticate without ever retyping a logon. There are a number of other authentication methods, but all ultimately involve entering a second logon (which in many many cases is the same as your first logon.. this is only limited by your network setup) - and some of these modes can save passwords etc.
-
Hi Folks. First of, I hope you've raised these issues with someone in Tech here HCC. If not, we should have a look at them. Often, slow interfaces are due to large volumes of reporting data. Sometimes a database rebuild can help this without bumping server hardware. We are aware that our interface isn't great. There are changes afoot - notably Guardian will have a revamped interface in October, but the menu system which you find so irritating is slightly more ingrained (I won't go into the gory details of why its set up like that.. suffice to say we arent its biggest fans either) and won't be getting a full new look til early next year, but we are going more task based at the behest of customers like yourself. Licencing wise - again, we know "counting IPs" isn't great, though there aren't many alternatives, we think we have found one. Watch this space. Though as you have found out, if you run into licencing issues, we are happy to resolve them in your favour Finally... everyone's favourite. Authentication. Yuck. It is a pain in the backside, but it isn't a Smoothie-specific pain. NTLM will only work with wininet based browsing - that's microsoft for you. And there's not much else in the way of auth methods that are "seamless". However - we can now offer multiple auth methods on the same box, which might solve some of your issues. Additionally, we should (depends on your setup) be able to remove the need to type in the domain\ portion of the username. @RabbieBurns - drop me a mail. Short answer is: you should be ok on all those fronts. Support should not be a problem, as our Sydney distributor is pretty spot on, and between our UK and US based internal support offices, we can usually get support to them pretty rapidly if they need it.
-
I notice comment from Mr "Bob Im a Doylem And Didn't Read The SmallPrint Jones" is conspicuous by its absence.
-
Starting at the bottom and working up... Your cisco is likely to be able to provide excellent firewall capability if you are happy managing it. Otherwise, we SmoothWall types also do firewall bits, which are extremely cost effective when bought with the filter. Internet connections - generally you have leased line, very expensive way to get bandwidth, or aggregated ADSL. 20-40 meg is perfectly achievable. These folk: Smart Connect are reputed to be OK, If you call Andrew Bamford there, he may well be able to help you. Also worth checking if you are getting FTTC in your area any time soon. Here in West Leeds (Armley exchange) we are apparently due in August, and will be able to get VDSL at 40x10 (yum). Worth noting that many LEA-provided connections are simply bonded DSL. Finally... IPs, subdomains, etc. How many IPs you need depends entirely on how many internal services you need to run. Depending on your setup and the connectivity you end up with, it may prove more effective to move shool websites outside your own network. Subdomains are effectively free, however - once you control your own DNS you should have no issue there. HTH,
-
I think you may well be too late - I only spotted the error long after it had been sent to print - but it's subtle enough to be our in-joke
-
I see minor apostrophe error on the artwork for the US banner too - but I told Sue not to worry, it is tradition
-
And I thought I was bad... i'll have to check it out now
-
Thanks for organising Chris & the gang. Aforementioned colleague was suitably contrite when he *finally* turned up at my door - and in fairness to Gav we have been working together 6 years, and in that time he has never once been late Looking forward to the next edugeek do (ISTE Conference 2010) and hopefullhy more after. Chris, maybe we SmoothWall folk could help organise a conf outside chorley (somewhere for the southern devils, perhaps?).
-
Nor did I.. Flemming's kept that one firmly under his hat
