ibpalle
Smoothwall Staff-
Posts
1,661 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ibpalle
-
Smoothwall Hybrid Cloud Filtering
ibpalle replied to jaminben's topic in Internet Related/Filtering/Firewall
The safeguard notifications (The daily, weekly, monthly ones) will show safeguarding incidents, the instant alerts won't work for cloud filter logs currently. That is underway as I understand it and it won't be dependant on cloud reporting. -
Smoothwall Hybrid Cloud Filtering
ibpalle replied to jaminben's topic in Internet Related/Filtering/Firewall
You are not loosing reporting but since the clients filter on the actual device, logs are collected there and sent to the on-prem device every 5 minutes. The realtime log viewer in the cloud portal that you also have access to, will allow you to see the logs for a specific active device. The safeguarding alerting won't be instant, obviously due to the delay in the transfer of logs and currently they are not triggered on cloud log ingestion but that will change. The daily/weekly/monthly notification safeguard reports will contain data from the cloud filter logs. -
We have four deployment types: The Guide for each deployment type is below: https://kb.smoothwall.com/hc/en-us/articles/360008478500-Installing-the-Smoothwall-Cloud-Filter-on-Chromebooks-using-Google-Admin https://kb.smoothwall.com/hc/en-us/articles/360017245300-Install-Cloud-Filter-on-Windows-10-using-Intune-Edge-Only- https://kb.smoothwall.com/hc/en-us/articles/360003615779-Install-Cloud-Filter-on-Windows-10-using-Domain-Group-Policy-Object-GPO- https://kb.smoothwall.com/hc/en-us/articles/360017297219-Install-Cloud-Filter-on-Windows-10-using-Intune-Multiple-Browsers- Additional Notes: With Cloud Filter, Web Filtering is provided as an extension in the browser. The Cloud Filtering License can be linked to a specific on-prem Smoothwall which means Cloud Filter Clients will be subject to the on-prem Web Filtering rules regardless of physical location. When the License for Cloud Filter is complete and linked to the on prem device serial (Smoothwall do this for you), it is the logout button on the UI that syncs changes to the Cloud Filter Clients. Cloud Filter reporting data from the Clients will be available on the on-prem device every hour, and Guardian Web filtering changes take roughly 10min to replicate to the Client devices after Logging out of the on-prem UI. Smoothwall Filter & Firewall: Preparing for Cloud Filter to avoid Double Filtering https://kb.smoothwall.com/hc/en-us/articles/360015978080 Post Deployment Testing Ensure that the Smoothwall Cloud Filter extension has been installed in the relevant browsers (Should be visible at the top right). Navigate to the diagnostics page using the kb below and ensure: “Filter Mode” = Mode 2. Client username and group mappings are correct Finally, make sure a website you know should be blocked by your organisation is blocked by the Cloud Filter Cloud Filter Diagnostics https://kb.smoothwall.com/hc/en-us/articles/360016413920-Running-Cloud-Filter-Diagnostics Cloud Filter Realtime View https://kb.smoothwall.com/hc/en-us/articles/360006892380
-
That KB is valid but look at option 2 instead of using the VLAN method - we have added a feature called secret knock - this tells the extension on startup to inform the on-prem Smoothwall that web traffic from the browser is already filtered, so don't bother redirecting it. The secret knock should be configured on your system as it's part of both the setup instructions we send out and part of the implementation we perform when setting it up. If your roll-out happened 4-5 months ago that may not have been configured.
-
If the device is on-prem then a browser without the extension enabled would get filtered by the on-prem Smoothwall - at least when the secret knock refresh times runs out (default is 600 seconds I believe). Off site it is an issue that only traffic from the browsers with the extension gets filtered, if the user runs a firefox off a USB stick, unfiltered access is available. With the cloud extension on Windows devices, some measure of lockdowns in the OS are needed to prevent for example, running the browser with extensions disabled.
-
The only permission the Smoothwall AD bind user needs is the ability to add computers to the domain - this is standard for user accounts so unless it has been revoked in the user rights, a normal user account should work fine.
-
Smoothwall NTP - Am I reading this right?
ibpalle replied to Norphy's topic in Internet Related/Filtering/Firewall
Yes - you are both right. Techmonkey just clarified the 'path' as such. Smoothwall provides the time service internal and retrieves the time externally - which is the case when Smoothwall is the time server. If no interfaces have been selected, then Smoothwall just acts as a client, using whatever time server setting enabled in that section. -
On a Smoothwall system we would suggest using RADIUS accounting - an SSID can be setup to use 802.1x which takes a username and password in the wifi profile to connect. The Fortigate should have the capability to receive RADIUS accounting (and possibly auth as well). Wether this is possible for Azure accounts, I'm not certain, but will be for AD accounts. Users connect and use the user/pass in the wifi profile for the SSID instead of shared key and/or manual signin.
-
Smoothwall NTP - Am I reading this right?
ibpalle replied to Norphy's topic in Internet Related/Filtering/Firewall
Yes, you are correct. The Smoothwall is either a time server or a time client. If you enable any of the interfaces for time service, the Smoothwall becomes a server retrieving time from stratum servers afaik. Select the multiple random servers option for time retrieval - and try the get time now button and see if that corrects the time. -
Smoothwall Hybrid Cloud Filtering
ibpalle replied to jaminben's topic in Internet Related/Filtering/Firewall
Some points to take in regarding hybrid deployment. On-prem Transparent will intercept all outgoing web traffic. Cloud clients will bypass the on-prem filter to avoid being double filtered. Various auth methods exists for users including RADIUS and our iDex system for AD accounts which will give you the option of having BYOD Wifi connection profiles with AD usernames/password so even users own devices can be filtered and logged by their right username. Cloud filter extension Extension installs on a browser (Chrome, Microsoft Edge, ChromeOS) or gets installed as a browser with the extension built in (iPads, not released yet) and will filter web access done from those browsers at all times, regardless of location. Traffic already being filtered by the extension won't be intercepted by the on-prem Smoothwall, this is done to prevent double filtering. Traffic coming from on-prem clients with the extension installed but NOT coming from the browser with the extension, will be filtered by the on-prem device. That obviously won't be the case if the user is not on-prem. All logs gets collected on the on-prem device and the cloud clients themselves have a realtime log viewer for easy troubleshooting. Also, once the cloud filtering is deployed, you will also get access to our cloud portal that allows you to edit and maintain filtering settings remotely without logging into the on-prem Smoothwall. The portal will have other features as well like cloud reporting soon (Cloud reporting will be an add-on and have an additional cost) -
We have been setting up cloud filter as a free addition - it just needs a serial and a setup process, and was released publicly recently, which is why it's not part of previous setups.
-
The option to not validate is still there on Android 11. Used this myself after updating to 11 last year. The CA that created the certificate the Smoothwall RADIUS service is using can be downloaded from the services - authentication - BYOD page. You could try to import that on an android, use it for Wifi and see if that changes behavior. I'd recommend turning the dynamic MAC address feature off for the School Wifi connection first as a test.
-
Since you already have Smoothwall, why not try out our cloud filter - it's not a extra cost to what you have already. Have a chat with your account manager to get a test or a demo.
-
I think that one is on me - I was looking through my mails and messages and can't see if I asked her to reach out. Could you PM me with the school name please?
-
The majority of the onboardings for the new cloud products were actually done by a couple of contractors - easier to train up when it's just onboarding that needs to be done. We ended up having one stay with us permanently too.
-
Obligatory +1 for staying with Smoothwall. Take a look at some of the new cloud filter and safeguard management and monitor software - the full package of options may sway you to stay with us for a bit longer.
-
Smoothwall bandwidth module setup
ibpalle replied to mrstrong's topic in Internet Related/Filtering/Firewall
Yes that looks right - obviously the #kB needs filling in -
Smoothwall safeguarding notifications blank
ibpalle replied to jslate1980's topic in Internet Related/Filtering/Firewall
It was found too late to be in 47 - 48 will have the official fix. -
Is there a proxy in front using HTTPS inspection? If so, have you installed the CA used to implement this?
-
Google Safesearch - Explicit results
ibpalle replied to Timetable's topic in Internet Related/Filtering/Firewall
I think the safesearch will prevent any inappropriate explicit results but your example doesn't make that clear. The dropdown just shows the option?
