Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. I guess 900 users puts you into the cheaper category, I bet its a lot more for 10-15!
  2. Hmm I'm just used Adobes Education pricing and its £29.49 per user for all apps, or £12.64 per app per user (all per month!) and £278 per annum for each device for all apps. Does going through a reseller drop it that much, £4 a year per user seems massively cheaper!
  3. We've been asked to setup Adobe CC (mainly Premiere/After Effects) for a small group of students - the pricing seems ridiculous to me, for 10 students its £3400 using the per user per year option, or £2800 per device per year. Is there another way to do this or is it just that expensive?
  4. It was a deployment from SCCM (upgrade from 1809-20H2) but its also happened on the odd few that were upgraded in place using the 20H2 iso Its odd as the accounts work OK - they're just invisible in the console! If I create a new account, it appears in the Groups (i.e in the Users group) but not in the Users panel!
  5. On most (all I've tried so far anyway!) of our updated 20H2 desktops, the local user manager console (lusrmgr) opens up and shows the groups ok, but no users (even when logged in as the local admin account) I've never seen this before, its only on the 20H2 machines and I haven't found a fix anywhere - has anyone else seen this or is it an oddity from our upgrade process (from 1809)?
  6. Smoothwall cloud filter isn't included, and getting any kind of support takes weeks so I think we need to look elsewhere
  7. We’re about to roll out a small (up to 150) device web filtering system for laptops issued to students. This is on the back of the dfe laptops that have Cisco Umbrella expiring soon, but we want to do this long term anyway as we intend to keep supplying laptops to students who need them We have smoothwall at the moment but that’s not something we will use in the future, so has anyone got any positive experiences with a wholly web based web filter for education? I’d rather keep the in house filter and firewall separate for renewal purposes and also to keep it simple,as the mobile solution will be a lot less restrictive What we’d like is a simple reliable cloud filter that can be installed and configured (and not removed!) for student devices that will always remain at home- with cloud based management and reporting for us. There’s quite a few options out there so I’m interested in peoples experiences and the cost differences?
  8. Great, thanks I think Sophos XG is our preference at the moment. We'll be migrating the primaries off smoothwall as well but they'll only need smaller devices.
  9. Is anyone using Sophos XG for web filtering and firewall? We've used smoothwall for years because the filtering was great but without support its not worth it anymore, we evaluated an old sophos UTM years ago and I seem to remember it was poor at picking up proxy avoidance sites at the time
  10. I think I've fixed it, tests are working so far anyway! I noticed that a on the PCs I was testing a lot of random traffic was hitting the firewall, rather than the proxy. On these winhttp was set to direct (no proxy), and the users GPO specified the proxy in their policy. I put a policy on the PC to set the winhttp proxy to import from IE and now I can connect reliably to PS each time - the machine proxy is effectively the same as the user proxy as it uses authentication on the network
  11. I'd have to a few changes to switch to a transparent proxy, but its only the Meet app that has a problem with it - it seems to just ignore the proxy
  12. Its definitely something in the smoothwall firewall, as if I switch off the Default catch all rule to Allow traffic -and it works first time every time. Switch that rule back on and it works intermittently. Problem is nothing that showing as 'Dropped' seems to relate to this as when I allow them it still fails!
  13. When I was using an old firewall last year I allowed all https traffic and rdp from specified clients and it worked ok, but I haven't tried that with smoothwall yet - the fact it connects after a few attempts suggests an initial connection is failing somewhere but once established it stays connected all day!
  14. Even if I wanted to stay with smoothwall it’s hard work getting a reply from them these days. Such a shame but the customer service seems to have gone off a cliff.
  15. I think that's the next thing to try. I've reinstalled the Meet app and it now doesn't offer the option to start a new meeting, only join an existing one, which suggests the newer version of the app disables this when it can't 'see' the route it needs.
  16. These are the iOS apps so once logged in to any you're logged in to all. The Meet app opens fine, but always times out when trying to start a new instant meeting - which is the Drop entries in the log. The proxy is unauth and the other google apps (mail,drive etc) all work fine. Also, if you open Meet in the safari browser it works fine!
  17. Hmm, what I have setup is a rule to bypass https inspection for the google urls - including the ones you mention as well as the accounts. I also have a firewall rule to allow the https/19302-19309 ports out to the two google IP ranges as well So the ipad has a smoothwall proxy/port set and therefore should use that - but it seems to hit the firewall on the a lot of the ranges I listed above, suggesting its ignoring the proxy setting altogether. A snippet from the firewall log shows that its trying to access https for ranges out of the 2 google specify - and its blocked by the default rule (correctly!)
  18. Yeah I only had the original two IP ranges allowed, which didn't work, so I traced what was being blocked and it was the ranges above (usually https) Unblocking those is not an option, as it gives access to unfiltered google search - and it allows access to very unsuitable content through the google images search! The google document doesn't seem to differentiate between normal meet browser access and ios app access - I haven't tried it on android. Our ipads use a proxy which works for everything except Meet - which seems to ignore it and therefore wants a ton of addresses open on the firewall.
  19. It hits quite a range of IPs: 108.177.0.0/1617.173.255.0/24172.173.255.0/24172.217.0.0/16216.58.0.0/1674.125.250.0/24172.217.169.0/2474.125.250.0/24172.217.16.0/24142.250.0.0/16 Problem is, whitelisting them is whitelisting *.google.com which means if your smoothwall is the default gateway and the proxy is switch off on the device, then they have unfiltered access to google search!
  20. Has anyone managed to get the iOS Google Meet app to work reliably, specifically through a smoothwall? I've followed their setup and tcp/udp 19302-19309 is allowed, as well as https to the 74.125.250.0/24 and 142.250.82.0/24 ranges but it usually times out. Normal browser based meet opens fine, but just the iOS app fails to connect. The smoothwall logs show nothing although I find that's the case a lot of times as it too slow to update
  21. Thread revival here, but I'm still having real problems with this. We're going through a smoothwall and the whole psfcloud.com domain is whitelisted, and bypasses https inspection. The firewall allows http/https/rdp to the same domain, yet it still takes up to 4 times to connect - and then it connects fine and works until logged out Its bizarre as it implies its not being blocked as it does eventually connect, but the random nature of when it will work is annoying the hell out of me, let alone the people who are using it! Has anyone got a smoothwall they could share their settings with for this?
  22. I'm also thinking about splitting the UTM into seperate firewall and filters as well, as it gives me more options - and I'd expect the firewall to have a slightly longer lifespan - plus it means we're splitting the support
  23. Do you mind me asking how much this cost you? Sophos XG was impressive the last time I demo'd it but the smoothwall beat it on price (not massively it has to be said)
  24. Fortigate looked good the time we last renewed our smoothwall, but it was quite a bit more expensive, but that was nearly 3 years ago so maybe close these days
  25. I think Sophos is the next best UTM from what I've heard. I used to love Smoothwall but the support is pretty much useless now, and they seems to be downgrading the specs of their UTMs compared to previous models We still want onsite as we need a firewall as well, and have several 'guest' LANs in use as well.
×
×
  • Create New...