ibpalle
Smoothwall Staff-
Posts
1,661 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ibpalle
-
There is an Adobe category in the blocklist. Try to add that to a do not filter policy.
-
Jamf Shared iPads Smoothwall Authentication
ibpalle replied to jakepq's topic in Internet Related/Filtering/Firewall
You should be able to tell by the proxy auth policy they used. Also, if you are using the background tab method, go to the login page manually and it will tell you you need to keep the tab open to stay logged in. -
Jamf Shared iPads Smoothwall Authentication
ibpalle replied to jakepq's topic in Internet Related/Filtering/Firewall
Using the SSL login with background tab may be a better option - session cookie keeps the user logged in as long as the browser hasn't been closed. The background tab option allows you to logout more reliably. -
Smoothwall - NIC bonding
ibpalle replied to synaesthesia's topic in Internet Related/Filtering/Firewall
I do not know but I would think the simpler bond options, Active-backup, Round-robin and Balance Xor would just work. -
Smoothwall On-Prem, Cloud Filter and YouTube Issue
ibpalle replied to DeGrimmy's topic in Internet Related/Filtering/Firewall
We did introduce a new field in the custom categories for video IDs - this was to be used in situations where youtube or vimeo needed to be blocked but access to certain videos and playlists was needed. Adding video and playlist IDs to this field in a category and then allowing them before blocking video otherwise should work on the cloud filter and on-prem if https inspection is enabled for youtube. The original method was using a youtube for education feature which is no longer available I believe. -
I don't think it's on the roadmap in any serious way.
-
Yes, without a login, Youtube assumes you are a minor and strict filter is in use by default I think.
-
Those are normally caused either by Youtube strict or moderate filtering which can be imposed by Youtube using the Google admin console or by content modification policies in Smoothwall. Try to remove the content modifications for strict and/or moderate mode if they are being applied.
-
If the Ubiquiti Dream machine is also the wifi access point and the point of wifi traffic exit, then wifi traffic won't pass through Smoothwall and be unfiltered. You can try giving the Smoothwall IP as gateway for Wifi DHCP clients.
-
Smoothwall Youtube Comment removal not working.
ibpalle replied to Rob_D's topic in Internet Related/Filtering/Firewall
QUIC enabled apps and browsers should all revert to tcp if QUIC isn't available. -
Smoothwall Youtube Comment removal not working.
ibpalle replied to Rob_D's topic in Internet Related/Filtering/Firewall
I assume this is not a cloud filter extension client? Normally this is caused by the browser using the QUIC protocol - Youtube and Google searches can switch to QUIC if that isn't blocked. Try blocking outgoing requests for UDP ports 80 and 443 in the firewall. https://en.wikipedia.org/wiki/QUIC -
Smoothwall Youtube Comment removal not working.
ibpalle replied to Rob_D's topic in Internet Related/Filtering/Firewall
Are the other content mods for youtube working? When you go to youtube and look at the certificate, is it a Smoothwall generated one? -
Smoothwall not filtering gamepluto.com
ibpalle replied to 5tu's topic in Internet Related/Filtering/Firewall
UDP 80 and 443 Yeah, that should be enough. Try to enable forwarded traffic auditing option in network - settings - advanced. Then go to the reports - realtime - firewall and enter a filter of destination ports 80 and 443 and your source IP. Enable QUIC again, restart browser and try to browser while checking the traffic in the firewall logs. It should show the QUIC traffic - you may be able to see if there are issues with the firewall policies. -
Smoothwall not filtering gamepluto.com
ibpalle replied to 5tu's topic in Internet Related/Filtering/Firewall
Interesting. Is there a difference between: If a search is being done after opening Chrome, going to Google.co.uk and searching and If a search is being performed right after opening chrome, no opening of google.co.uk and then use the address field for the search? In the 2nd case, the browser may default to google.com instead of google.co.uk, which may be excluded. Just a thought as I've seen something similar. -
Works fine here but could be due to logs actually being present.
-
No - the traffic is going to the external IP - there will be no internal system IP in any packet that can be seen. What you could do is enable IDS on your LAN/BYOD interfaces and enable the Current Events, Known Malicious Sources, Malware, Virus policies. That will show in the IDS logs if any outgoing traffic matches these policies.
-
There is an alert you can enable in the reports - alerts - alert settings. The system services section - enable the web proxy and web filter as alerts and include them in the alerts you are already sending out to your team.
-
For a BYOD not using HTTPS inspection and not blocking QUIC - yes.
-
Smoothwall - Idex database internal error
ibpalle replied to timbo343's topic in Internet Related/Filtering/Firewall
Support needs to take a look - you can try deleting the iDex database on the settings page and then run the sendaddatanow.exe in the iDex agent install directory on a DC. Also check that the AD directories is still in the directory list and you can edit and save it. -
Yes, that is correct.
-
Just a few replies • Web proxy randomly crashes and needs restarting – with no alert telling us it needs to That should be possible to address. It's not something we get complaints. • http/https-QUIC needs adding to firewall reject rules Yes they do. Nothing to do with the cloud filter extension though as that doesn't matter for the cloud filter extension but for normal filtering it does. There is a content mod to remove the QUIC header but that will only work with https inspection and if the browser is not in QUIC to begin with. • Devices which secret knock via cloudfilter will not filter traffic when a browser is used that hasn’t got the cloud filter extension, for example renamed portable browsers that are difficult to police in an intune enviroment Cloud filter extension is meant for managed devices and works in the browser itself. That should have been explained as it's one of the cons of using the cloud filter.
