Jump to content

Eappariello

Members
  • Posts

    77
  • Joined

  • Last visited

Reputation

90 Excellent

About Eappariello

Personal Information

  • Biography
    I have been working in the IT, Networking and security industry for over 30 years and 10+ in education.......Yes, I am old :)
  • Occupation
    Cyber Security
  • Location
    London
  • Homepage
    http://www.iboss.com

Employer (optional)

  • Company Represented
    iboss Cybersecurity

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. That link is under the business website section as DNS based filtering works for corporates for a light touch approach on Guest and BYOD networks. And your quite correct needs to have ACL's so that only the cloud gateways can be used as DNS servers. For Edu we recommend using GRE or IPSEC tunnels for unmanaged devices, and for managed devices the 'cloud connector' which also takes care of decryption, authentication, TLS 1.3, and the data redirection to the cloud. Hope that helps.
  2. @TimStannard - As a iboss customer you can register at https://support.iboss.com/index.php?/Enterprise/Base/UserRegistration/Register Once your in, search for "manuals" where you will find PDF's for the SWG, FireSphere, CISO dashbaord, IPS, and other threat defense features. Let me know if you have any problems getting what you need..
  3. @CyberNerd I can only apologise that you have received that information, it's not correct. If you pm me your school I can look into why this happened. Browser updates have no bearing on our filtering ability, and the solution is browser agnostic. The last iOS7 update meant that safari checks in before loading with a cloud service, and this fix was available immediately upon release of iOS7 Lightspeed also fully supports Chromebooks, and we have several Chromebooks only customer sites. Again, my apologies you received this incorrect information. Happy to answer any other questions anyone has around this here or via PM Simon
  4. Authentication with the Lightspeed Rocket has been discussed in other threads...but incase anyone reads this I thought it best to clear up a couple of things. The Agent in question above is not mandatory but optional, there are OSX, Windows, and Linux versions, and is generally recommended for managed wired devices and gives a very detailed view of client authentication events plus other useful information. A centralised DC agent can also be used, authentication on block messages, 802.1x for integration with wireless systems authentication such as Radius, and various captive portal options for BYOD or guest devices (unmanaged). Also, incase it helps: WCCP has been around a long time. Check out its abilities to filter HTTPS traffic before jumping. If thinking of authenticating every session with a challenge like NTLM and you should check scalability...web 2 .0 creates lots of sessions. Authentication is always a great topic of discussion but not that's straightforward when dealing with mixed environments and operating systems. Look forward to more discussion Simon
  5. Good question Its really needed for devices that are used by different students each lesson or at different times a day (A device cart for example). You would not want a student logged into a device another student will use next lesson as it will make the reporting inaccurate. So Authentication lifetimes are important from that perspective. If its a one2one environment the lifetimes can be much longer as devices do not pass from one student to another.
  6. Not really, it depends on what the school feel is acceptable for students etc to re Auth. Of course deployment can also make a difference in that a 121 deployment would just need to Auth once a day, perhaps BYOD the same. Also, don't forget the default Auth time is just that, you can specify different Auth times based on Users, User Groups, and User OU's, so for example Staff could be 12 hours and students 1 hour.
  7. This is resolved in 2.6.RC2 available now.
  8. I can not comment on what will happen on the Ruckus, sorry. Yes the users would only Auth against the Ruckus Auth page / captive portal page. Not sure if you can restrict the Ruckus to only Auth against certain groups. For the lightspeed rocket you can restrict to a certain OU if that helps. The 55min Auth timeout is just for the lightspeed captive portal web authentication. If you use radius that will inform the rocket of new login and logout events so the timeout does not apply.
  9. If you are on version 2.4> you can use radius Auth information from your Ruckus to transparently Auth to the rocket (802.1x). You basically setup the Wireless controller to point to the rocket as a secondary radius accounting server, the rocket will do the rest. In the meantime you could increase the authentication timeout and ask the students to manually logout using lsaccess.me/logout
  10. Yes every tier has its own authentication sources - but the radius shared secret has to be the same across every tier.
  11. Did you know... Any user can goto lsaccess.me/logout to end their web authentication session before it expires. Very useful for iPad carts. You can push out a webclip with configurator or your MDM with this link to provide a LogOut button for iOS devices. Also: For those of you with wireless setups that make use of EAP and a radius server you can now add the Lightspeed rocket filter as Radius accounting server, providing transparent authentication when a user authenticates to the wireless controller. Hope this helps Simon
  12. Lightspeed MDM will still operate with iOS7 devices, it just does not have the new iOS7 profile features. The new Lightspeed MDM version will be released this week with the new features for iOS7. Contact your in country support guys or RSM for more info, and to get upgraded to the new site. Hope this helps Simon
  13. Hi Kathy, Sounds like the Apple Push Notification Ports are not open or reachable. As a test see if you can telnet to the below ports gateway.push.apple.com : port 2195 1-courier.push.apple.com : port 5223 Yu should get a response like the one below. Connecting to 1-courier.push.apple.com:5223 Connected.
  14. If you have the IP of the device add this IP to the inspectors area. Then go into the web activity report and choose show inspector data only and you should see anything that of the policies or DPI checks are blocking. You can also use the internal and external IP plus protocol report to see where the App is trying to talk to. The support chaps are always there to help if needed also. Simon
  15. @BKGarry Sounds like @marekbrad can help out. Also, you will find communities on MBC itself to ask this questions and it might also be worth posting up on EduTalk on MBC also. We also have MBC Coaches/Experts that have launched and supported MBC in large environments that you can utilize if needed.
×
×
  • Create New...