-
Posts
755 -
Joined
-
Last visited
Reputation
386 ExcellentAbout mrstrong

Personal Information
-
Location
England
Recent Profile Visitors
The recent visitors block is disabled and is not being shown to other users.
-
Allowing WhatsApp through smoothwall
mrstrong replied to mrstrong's topic in Internet Related/Filtering/Firewall
just fyi, our whatsapp now looking healthy again on guests network (no https inspection) All that was needed was a "Do Not Filter" action on the "WhatsApp Messenger" category (plus firewall allow XMPP etc) easy when you know how, thanks @timbo343 No need for a new category as e.g. https://57.144.223.33/ matches the built-in "WhatsApp Messenger" category via "URL patterns" So I think smoothwall must be mantaining this 🤞 -
similar here, old hardware, no money, not enough time in the day @mikes sounds like you are using the old autopilot v1 there is a new autopilot V2 but @DWilson1997 is not using autopilot at all, just using the "Microsoft Entra Joined Device Local Administrator" role to join them to intune, e.g. intune thinks they are "personal devices". I had to allow enroll personal for group with user with this role. Be interested to know if it's still working well for him / any downside to skipping autopilot. I guess if it's in autopilot and lost / stolen it's tied to your org, bit like ipads in apple school manager. The naming thing is not a biggie obvs. just curious, maybe if you use a home / pro sku it prompts for computer name and then steps up to Education / Enterprise when you join it ? This is more of a proof of concept thing for me to see how we could move away from very old on-prem server. Unfortunately I rarely have any spare time to really get stuck into it.
-
Allowing WhatsApp through smoothwall
mrstrong replied to mrstrong's topic in Internet Related/Filtering/Firewall
just had a thought, perhaps as there is another VLAN on Port 2 it won't let me change the "Block HTTPS traffic with no SNI header" on the interface to "Allow Transparent HTTPS incompatible sites and filter others using name from certificate". I'd have to delete both and re-create ? Or perhaps I could just create category with whatsapp IPs and "allow" them just for staff on this VLAN ? -
Allowing WhatsApp through smoothwall
mrstrong replied to mrstrong's topic in Internet Related/Filtering/Firewall
yes i got those firewall rules set up but its the web filter / proxy dropping it I think e.g.: I think because interface has "Block HTTPS traffic with no SNI header" even though I deleted that interface and created a new policy (with "Allow Transparent HTTPS incompatible sites and filter others using name from certificate" But interface is still showing as "Block HTTPS traffic with no SNI header". Interface: Policy: This is also a BYOD network for guests so not doing HTTPS inspection -
finally got round to trying this yesterday! Used a usb prepared with rufus Windows 11 Education 24H2 iso I had. went through the standard windows setup screens (guess i could skip some with a autounattend.xml ? ). I didn't get asked for machine name though during the OOBE, any ideas why?
-
Allowing WhatsApp through smoothwall
mrstrong replied to mrstrong's topic in Internet Related/Filtering/Firewall
bump. nobody allowing whatsapp through smoothwall ? just having another look and it seems to be just a few IPs getting denied e.g. 31.13.73.53 57.144.253.33 57.144.223.33 I deleted the interface and created a new policy as No Authentication (Staff for unauthenticated requests) with "Allow Transparent HTTPS incompatible sites and filter others using name from certificate" but interface is still showing as "Block HTTPS traffic with no SNI header" 😕 -
Subject Access Request Emails
mrstrong replied to Bankesy's topic in Data Protection & Information Handling
Thanks I might go back and re-try copilot then, esp. as like you say its "held within the 365 tenant enclosure". I have A3 license so hopefully that is enough to get started. -
Subject Access Request Emails
mrstrong replied to Bankesy's topic in Data Protection & Information Handling
is that just using copilot in the Edge browser for your prompts, i.e. https://m365.cloud.microsoft/chat ? Then you paste the code into your editor (local VS code?) to test ? I tend to use gemini, I tried https://m365.cloud.microsoft/chat but confused me a bit, e.g. on the LHS mine has Agents like "Microsoft 365 Admin" I tried this for an MS 365 question I had, but it seemed to do worse than using just the standard "chat" so went back to gemini. I think claude costs and can't see school funding that. -
Subject Access Request Emails
mrstrong replied to Bankesy's topic in Data Protection & Information Handling
interesting, tempted to have a "play". How did you "vibe code" it, e.g. just type prompt into copilot ? Did you have to test / tweak code in an editor ? -
how do you have set this up? 3 cables output from PC e.g. HDMI to board, VGA and DP to monitors? I guess it depends on motherboard / graphics capability ?
-
well not having had time to evaluate/investigate it (pixlr) I assumed there could be potential risks, eg letting pupils use AI Image generation. Do you disagree ?
-
re newline C-series, £595 for a 65" seems pretty good, shame no freeze on remote, I've seen ones where blue button does freeze. Who is supplier offering them at £595 with 5 year warranty ? Maybe "grey market" ?
-
Allowing WhatsApp through smoothwall
mrstrong replied to mrstrong's topic in Internet Related/Filtering/Firewall
Mmm, I tried to change interface Behaviour from "Block HTTPS traffic with no SNI header" to "Allow Transparent HTTPS incompatible sites and filter others using name from certificate". but drop down arrow is disabled. Also the interface Method is set to Core Authentication and I can't change it. Not sure why it is "Core Authentication" as there is only one policy with No Authentication (Staff for unauthenticated requests). Google is suggesting I bypass the proxy via Services > Web Proxy > Authentication > Exceptions "This forces Smoothwall to step completely out of the handshake path when staff devices reach for any Meta infrastructure, removing the SNI validation check entirely" Does that sound correct ? Or is it worth just trying to delete this interface and re-create as No Authentication (Staff for unauthenticated requests) with "Allow Transparent HTTPS incompatible sites and filter others using name from certificate" ? -
it's getting harder to "opt-out" of AI, e.g. I've been looking for a basic image editor for pupils to use on our chromebooks We used to use Pixlr online but that's now got a lot of AI features so I've had to block it. Same for BeFunky and Sumo Paint. Photopea probably best I've found so far but still has some AI and quite complicated for primary.
