-
Posts
24 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Danielbarron
-
InternetKit ceasing trading
Danielbarron replied to uu2's topic in Internet Related/Filtering/Firewall
https://sites.google.com/site/appsforeducationresources/teacher-school-google-sites -
InternetKit ceasing trading
Danielbarron replied to uu2's topic in Internet Related/Filtering/Firewall
I am missing a point here - why would a school pay for a website? They all get Google Apps for free and that includes Google Sites. OK sites is not the best but it's easy enough, can be data driven by spreadsheets, permissioned, backed up, resilient. And Free. I think they don't even need to pay for their domain as .sch.uk are free to the schools? I assume Office 365 has a similar feature but I've not looked into it. -
Smoothwall Updates
Danielbarron replied to cookie_monster's topic in Internet Related/Filtering/Firewall
SmoothWall | Products » Feature Pack Updates will give you some more info but not much. Nowadays we do a continuous rolling set of improvements rather than lump them up on the existing products. FP4 was released in parts over the last few months and the authentication stuff you mention is very recent. http://download.smoothwall.net/pdf/manualsfp4/networkguardian2008-fp4-admin.pdf page 152 and page 66 has some useful info also. -
Yes. You could do the same with a cluster of hosted NG on VMs or real boxes too. I have a test set up if you want to try it PM me. Amazon provide VPN from the cloud to your LAN. Although I've not yet tried it. The AD could be on your LAN or in the cloud. The one I set up was in the cloud. Actually you could have one on the LAN and a VPN to one in the cloud in the same domain. Once filtering is hosted/cloud you will need some way of authenticating the user so it knows that you, first of all, have permission to use the proxy and which policy to apply and who you are for reporting and logging purposes. On a LAN you can use NTLM and thus have single sign-on and nothing to do when you start web browsing. To solve this for hosted you have to use auth methods that can go through the internet and it may require client software to do this depending on what you want to do. Plus a roaming laptop may be more tricky to lock down compared to a static PC on a LAN. So there's a number of interesting and different challenges.
-
It does not feel like it's slow although I've done no specific tests. Yes Imran was going to do that at some point. However I beat him to it with AC which is one way. Another is to add the xen patches to the kernel. When there is anything to test I will let you know but it will be some time away. AC provides a load balancer. Info here: Elastic Load Balancing Works great.
-
I've been looking at SmoothWall (primarily Guardian filtering) on Amazon Cloud. I got it working but it's a lot of effort. Once working it's great and can provide a nice cluster (resizeable easily) of load balanced Guardians authing against, for example, an Active Directory. But initial set up is very hard. Making it not hard is high on our priority list. The reason it's hard includes issues like AC does not have a console so it's not possible to interactively solve networking issues if you can't ssh to it. They also don't allow you to run your own Kernel. Imran has Network Guardian working on a standard Debian with standard apt-get-able xen. The NG requires no modifications and works happily and can have updates including new kernels and reboot and is great. This is in un-modified guest mode. He had to do things like robf listed like give it a static mac address and some networking stuff I don't understand. But these were just config options and the NG is unmodified and fully standard production.
-
SmoothWall Feature Pack 3
Danielbarron replied to Netwacky87's topic in Internet Related/Filtering/Firewall
You could block .jar files. The flash filter is for flash and .jar is java. Is there much educational content using java instead of flash? -
SmoothWall Feature Pack 3
Danielbarron replied to Netwacky87's topic in Internet Related/Filtering/Firewall
If anyone wants to try out the latest Guardian FP3 filtering, let me know and I can give you a free account on my hosted Network Guardian. Yes it's the same thing I posted a week ago in another thread but no one took me up on the offer yet. -
Imran (SmoothWall external infrastructure sysadmin) and I are doing an experiment with a hosted Network Guardian to provide hosted web filtering which requires no client installation. Currently we are looking for a few volunteers to try it out for free. It requires a small config change to the proxy settings on the laptop and a username and password whenever the user wants to web browse (the browser will normally cache this so one only needs to remember it once). It comes with no warranty or guarantee or even support and may be stopped at any moment. However you can contact me or Imran for support and suggestions and we'll do our best to help you or pass it on to an official SmoothWall support agent. We're looking for a couple of users with a small number of computers or laptops. It can even be used for home filtering for teachers not just laptops for kids. My mother is a head teacher and she uses it at home. It is a black-box solution as in you can ask for filter settings to be changed but there is no front end to allow you to change settings yourself. But if something is blocked that should not be then simply don't use the filter and let us know. Of course you will need to lock down settings by the kids running as non-admin on the laptops. Send me a PM or email me for more info. Email is daniel.barron at smoothwall.
-
Smoothwall Password Length
Danielbarron replied to cookie_monster's topic in Network and Classroom Management
Scoped for FP3 which is still currently end Oct early Nov. -
Blocking Flash Games Software restriction Policies... Hash
Danielbarron replied to MyDejaVu's topic in Windows
GameKiller3 If you switch names now you will lose the known brand name. -
Blocking Flash Games Software restriction Policies... Hash
Danielbarron replied to MyDejaVu's topic in Windows
Have you a URL to the software? I know of Securus the company who do E-Safety software but this monitors and does not actually block. -
It's a very interesting and complicated topic. More than you might think. Just look at the comments on that article. Many people not knowing what they are talking about and just about the only one who knows anything is the long post by AC. (No it was not me!!). But to answer your question - yes it is fixed. On the proxy page there is a tick to allow you to turn on checking that the destination IP and the host header match. "Check request headers against original destination IP:" Or use many of the workarounds. However the problem is that most big companies like Google, Microsoft, Yahoo, iTunes etc use stealth DNS round robin. This means one can never be sure that the client PC and the proxy will agree on which IP(s) a hostname resolves to. The vulnerability exists when they differ. Those companies make checking very very difficult. There is more info here: https://support.smoothwall.net/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=337&nav=0
-
Smooth-Guardian Licensing issue
Danielbarron replied to parasol's topic in Internet Related/Filtering/Firewall
The 7 day thing imo confuses matters. The point is the licensing is "per computer using the proxy". So a school with 1000 pupils but 200 computers only pays for 200 computers and adding more pupils will cost nothing. The licensing is not per user or per current user or current connection. If you have 11 computers but only a 10 computer licence then it will trip up. But, as Blizzard like saying, that is working as intended. The way it works is simply by counting IPs. This has problems but in all the years it has worked like that (it is so old I actually wrote that bit of code) it is only very recently come up with a problem (to my knowledge). A good example is wired and wireless laptops might take up to 2 IPs each. In cases like this where licensing enforcement causes problems for customers, contacting the account manager is definitely the best thing to do. The last thing we want is paying customers to be inconvenienced by a licensing enforcement system getting it wrong. As a side note - DHCP should not cause any problems as you will find PCs get the same IP each and every time - especially Windows PCs - as they will ask for it when renewing. So the same batch of 100 PCs will get the same 100 IPs in the standard case. -
I am not an expect on this but, yes it is off by default. In addition you will need to install a CA on the clients you want to intercept. The CA is exported from the SmoothWall. Do check out this info before using that feature: https://support.smoothwall.net/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=340 The online help system now includes the entire manual, searchable and indexed and so on. So you can navigate to the "guardian » filtering » per group settings" page and click help. It explains about exporting the certificate.
-
I will have to ask some obvious questions here for diagnosis. You have Guardian enabled for filtering? Is your blocklist up to date? Do you have filter logging disabled (it should be enabled)? Have you rebooted since installing FP2 (you must have as in the screen shot there is no reboot needed request)? Is the date set right on the SmoothWall? If that does not solve it the support team will be happy to help.
-
For that particular report do as follows: Go to the reporting page. Click on Web Content. Click on Top Domains. Click on Top blocked domains excluding adverts. Do not change the group pull down (unless you want to) That will display top blocked domains. You can then click on the domain you might be interested in and you will see a drill down menu which includes "Top groups who have requested this domain". Hopefully that will get you the information you want. But if not let us know. And, indeed, any other reports you think we should include by default. The layout of the included reports has been tried to match how one might approach a requirement. So if the main thing is users then start at users. If you want to know about content (or blocked content) start at Web Content. Feedback is welcome.
-
Very likely it's been a while since you rebooted and it took the opportunity for a disk check. Same thing happened to one of the developers' home smoothies today. He thought it dead but no - was just running a disk check. We are looking at reducing or removing disk checks such as moving to a different file system in the next major version. For example: ext4 - Wikipedia, the free encyclopedia
-
It's the other way round. The support site uses a commercial 3rd party program called Kayako. Its in-built licensing thinks there is a mismatch between which domains have been paid for and which you are visiting. Strangely it does this on the client end. So it's not SSLI that does not like the support site but the support site that does not like SSLI. Unfortunately that part of the Kayako software is closed source so we can't fix it so we have to add a work-around to SSLI. The irony is not lost on me though
-
It won't be 8am. Late morning at the earliest. And even still it is possible a last minute huge bug might be found thus delaying. Also you should read this: https://support.smoothwall.net/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=340 before rushing to upgrade in case some of the issues affect you. We already have fixes but it takes time to test so those it will be at some point during April they will be released That article will be updated as more information becomes available.
-
We've recently taken on (yes SmoothWall continue to grow) a dedicated Development Manager and he, along with Tom and our support staff will be organising a more formal beta testing programme. This means some people will have access to stuff sooner and can bend our ear more. If interested, for now, contact Tom. Monday is still the plan unless anything pretty major crops up in our testing at the very last minute. There are some minor blemishes we already know about and these will be addressed within a couple of weeks of release most likely.
-
Smoothwall Network Guardian Negatives?
Danielbarron replied to mb2k01's topic in Internet Related/Filtering/Firewall
Sorry you've had so many troubles. That machine sounds like a desktop PC? Generally one might have more success with servers with SmoothWall. Desktops tend to use the latest cheapest nic, controllers and so on. The amount of change in these type of devices makes it hard to keep up with drivers. We try to keep up with server hardware and main brands like Intel and generally do a good job but there is always a latest version that someone might find. SmoothWall uses Linux at its core and if no Linux drivers exist it makes it impossible to support. The other replies are good - using a UTM or VM removes hardware issues. Alternatively we could pick up your hardware, if you can lend it to us for a couple of weeks, and see if we can make a driver disk? (We means SmoothWall - I work for them.) I've not looked at your ticket but judging by the time of the post I assume all possible remote ideas have been attempted. -
Smoothwall Network Guardian Negatives?
Danielbarron replied to mb2k01's topic in Internet Related/Filtering/Firewall
There must be reasons why other products are bought. Could be features, support, price, sales guy, being unknown, not trusting something new, too much of a learning curve, hard to use or configure, backhanders, school/county policy, better the devil you know, or anything. Negative feedback is great so one knows what to fix.
