ibpalle
Smoothwall Staff-
Posts
1,661 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ibpalle
-
Correct - so look at the block reason - the category that caused the block will show there. The block reason will also show if the block is caused by a domain block or content filter block. The reason line will look like this: Content of type CATEGORY (method) blocked Method will be one of 4 reasons: Domain/URL filtering - the domain or URL triggered the block. Content filtering - The content on the page triggered the block. URL Patterns - the content of the URL triggered the block. Search term filtering - The search phrase triggered the block.
-
Smoothwall HTTPS Interception Weekly Warning.
ibpalle replied to kennysarmy's topic in Internet Related/Filtering/Firewall
Just a bit of background. The warning was included as we were not quite certain about the legality of performing HTTPS inspection on user traffic. There were no precedent at the time and obviously Smoothwall is used in many different countries with different laws. It was fine initially when HTTPS was something that wasn't used widely but as everyone and their grandmother now use HTTPS for apps, sites and software the method of showing a warning in this manner isn't really fit for purpose. -
Filtering non-english Language websites and content
ibpalle replied to woodham's topic in Internet Related/Filtering/Firewall
Smoothwall has a lot of content filtering enabled for non-english - https inspection or the cloud filter extension is required for the Smoothwall to be able to see the content of websites so maybe that is why you aren't seeing the results you expect? -
Smoothwall HTTPS Interception Weekly Warning.
ibpalle replied to kennysarmy's topic in Internet Related/Filtering/Firewall
Hi kennysarmy I would recommend disabling the warning - too many system apps, background apps etc are using https so the risk of not actually seeing the warning is fairly high and can then cause access issues in general. The best option for finding out what needs to be added is to test access to the Bromcom system from a known IP and then use the realtime web filter logs to monitor traffic from that IP and see what domains are accessed - any that are recognised by the category will list the category in the category field, any that are not in there will not, so add those o the Bromcom category. -
Core blocked content is a category group - one category included is causing the block, likely due to content filtering. The blockpage will show what category is causing the block among the ones included in core blocked content. The category groups are yours to configure as you need - there is a handy reference here: https://kb.smoothwall.com/hc/en-us/articles/360004511520 - here you can download a list of our categories along with a short description of what type of content they cover.
-
You can create a new certificate with all the variations of the hostname users may try. IP, hostname, host and domain name. Take a look at this KB: https://kb.smoothwall.com/hc/en-us/articles/360002833340
-
Netsweeper List Entry replace url question.
ibpalle replied to filteringtech's topic in Internet Related/Filtering/Firewall
Is the request part not wrong? It says URL - is there an option for domain (Soz, not a Netsweeper expert) -
Web Filtering and Monitoring
ibpalle replied to jnfarmer's topic in Internet Related/Filtering/Firewall
No metal is a nice dream but if you have BYOD networks, it may not be feasible. In any case, Smoothwall has a cloud filter extension which can be applied with no metal on-premise. Smoothwall monitor is not a filter as such, it's a monitor (Duh ) that generates alerts and reports for safeguarding breaches but doesn't do any filtering. It can be combined with the cloud filter extension but again, these are extensions that need to be installed on a managed device, so not much use for BYOD networks. Hope this helps a bit -
Smoothwall content modification
ibpalle replied to TechMonkey's topic in Internet Related/Filtering/Firewall
No reports of it not working as far as I can tell - 2 things to make sure of is 1: https inspection needs to be enabled for Youtube - I assume this is the case otherwise those mods would have never worked. 2: Block QUIC outgoing. If the Smoothwall is the firewall as well as the web filter, make sure to put a firewall policy in place to block outgoing requests to UDP ports 80 and 443 - those are used by the QUIC protocol, which Youtube will use if it can, bypassing filtering. There is a content mod to remove the QUIC header but if a browser is already in QUIC mode, then the content mod wont help. -
Smoothwall monitor needs to be installed on the device so for BYOD it probably is not a good idea generally. The safeguard reports from a Smoothwall could help but currently it's not possible to turn it off for specific times a day.
-
Smoothwall VPN set up - hand holding required!!
ibpalle replied to mdrabble's topic in Internet Related/Filtering/Firewall
So an ipsec VPN to what VM OS type? What software is the VM client using if any? -
Smoothwall VPN set up - hand holding required!!
ibpalle replied to mdrabble's topic in Internet Related/Filtering/Firewall
Should be simple enough but vpns are always tricky - so many parameters that have to fit. Are you trying to create a VPN between 2 smoothwalls so you can access a VM or are you wanting to create a tunnel between a Smoothwall and a VM. -
Smoothwall Guardian CA expiry warning
ibpalle replied to mdrabble's topic in Internet Related/Filtering/Firewall
Hi all A KB on how to create a new CA is located here: https://kb.smoothwall.com/hc/en-us/articles/360002833340 Once the new CA is created, it won't be referenced on the smoothwall/getcert(getmitm) page until the new CA is set as the default. -
Smoothwall Guardian CA expiry warning
ibpalle replied to mdrabble's topic in Internet Related/Filtering/Firewall
Yes, the new CA and the old wont clash so both can be installed at the same time. You can push out the new one and once ready, swap on the Smoothwall. The only issue is that the http://ip.or.hostname/getcert will present the old one until the CA is swapped in the UI. -
Smoothwall Guardian CA expiry warning
ibpalle replied to mdrabble's topic in Internet Related/Filtering/Firewall
The button below the notification takes you to this KB which shows you step by step what to do: https://kb.smoothwall.com/hc/en-us/articles/360002833340 -
Do I need an SSL Certificate anymore?
ibpalle replied to CHiLL's topic in Internet Related/Filtering/Firewall
Hi CHill You can use an internal self-signed/created CA to create certificates for internal infrastructure - external too if the only users accessing the resource are likely to have a trust for your Self-signed CA. Since I use the Smoothwall HTTPS inspection, all my devices have the Smoothwall CA installed so I can create certificates for media server and other internal systems. -
Running reports in Smoothwall
ibpalle replied to localzuk's topic in Internet Related/Filtering/Firewall
Currently not aware of any issues with the user audit report - just ran one here myself and it gave me the right timeframe. Audit logs can generate rather large reports - try to go to recent and saved and find it there, then download it as CSV - your browser may object at having to display a huge table. -
List of domains for WeChat are listed here: https://www.netify.ai/resources/applications/wechat Try to allow those.
-
New version of Smoothwall iDex agent released
ibpalle replied to ibpalle's topic in Internet Related/Filtering/Firewall
I was not aware that would happen. Thanks. -
Hi all A new version of the iDex agent - version 2.3.3 is now available for download from https://software.smoothwall.com Install over the top of the existing agent. A reboot should not be required. Also, FYI - it's possible to add a a list of usernames the iDex agent should not report on. This can be useful if service accounts show up as logged in users. From: https://kb.smoothwall.com/hc/en-us/articles/360007256160 Service accounts on the domain may be picked up by IDex when called and may cause authentication and group-mapping conflicts for users. When using iDex agent 2.2.4 and above, a parameter can be added in the 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IDexAgent\Parameters' folder. Create a string value called 'LogonExclusions' and add any usernames in a comma separated list. Once done, restart the iDex agent service. This will need to be done on all iDex installs.
-
Smoothwall IDex being very flakey
ibpalle replied to mdrabble's topic in Internet Related/Filtering/Firewall
iDex does have an issue with nested groups - should be partly resolved by this new updated version - in those cases, we often do what you did. Have an AD connection to manage the group mappings which works fine for iDex as well. Announcing new versions of iDex and other types of supplementary software hasn't been our strong suit for sure. I always felt it could be taken as an occasion for a marketing push in some way or form. We did try mailing lists at some point, announcing new updates and blocklist changes but those mails rarely ended up in the right hands. Changes in tech crew, email was for the ones who signed the POs, not the ones that used the product and so on. -
I have advised the block team. With HTTPS inspection on, it would have been You can also add the domain to the Smoothwall categories until we add it in the official one. Go to the policy objects, categories and expand the standard category list. There you can add to the blocklist categories. Also a good resource is this: https://kb.smoothwall.com/hc/en-us/articles/360004511520 A list of the Smoothwall blocklist categories - good for reference.
-
There are MDMs for iPad that can be used to push out the certificate as well. The builtin page is good for BYOD devices in general.
-
Help with WPAD related issue
ibpalle replied to CyBeRkId2002's topic in Internet Related/Filtering/Firewall
The site https://findproxyforurl.com/ has a lot of good info on pac files. And as some have mentioned, clients need to be able to resolve the hostname only of wpad and resolve that to the system hosting the proxy.pac/wpad.dat file. In MS DNS services, the WPAD hostname is blocked by default - it has to be removed from that and then an alias or hostname of wpad needs to be added to your DNS. It's important that clients can resolve the hostname only of wpad, not just the full host and domain name like wpad.mydomain.local. You may need to add search domains to DHCP as well.
