randomguy
Members-
Posts
2 -
Joined
-
Last visited
Reputation
5 NeutralAbout randomguy

-
Our experiences with Sophos Web Filter
randomguy replied to cyr0n_k0r's topic in Internet Related/Filtering/Firewall
Though forums can get pickly, I welcome any discussion. I would rather steer this conversation towards a solution that makes you (and anyone else who reads) happy rather than have this disentigrate into a flame war. Raw logging is realtime, there is a cron job that runs every few minutes and takes the raw log and converts them to another format for reporting and dashboard. Depending on what data you are trying to find it might be easier for Support to look at the reports rather than the raw logs. Note that if you are using Endpoint or a cluster then logging may indeed not be realtime as they need to sychronize. It may be that for your problem, when talking to your support person, report logging was better to look at than raw logs. I know for me, raw realtimes logs have been possible. Regardless, this would only be an issue for support. Do you find that this impacts your normal operation? Your experience with Support is not the same as mine. Do you know if you are using actual Sophos support (eg talking to a Sophos employee) or are you going through a partner or reseller? I thought you were asking to turn off all filtering and antivirus everywhere. To turn it off for a particular site, create a Local Site List entry, tag it will Globally Allow, and set it to Trusted. Trusted sites do not get virus scanned, do not have file type blocking, and the download appears to start immediately. You effectively now allow ALL traffic through the filter for that site. The SWA should by default scan everything except for what you tell it not to. It cannot predict which sites you will have trouble with 3rd party devices - you need to tell it which sites to turn off scanning for. Default scan, except when told ahead of time not to. This would be (IMO) sound practice. Tom_Newton - how does Smoothwall do this? Can you turn off all scanning for a site? For a client (eg a specific computer)? Across the board? You say that you hate the "awful" download page so you turn it off. Then you say the appliance is downloading it without telling the user what it is doing. It kinda feels like you are asking for it both ways. The SWA must download the file and scan it before giving it to the client computer. You cannot properly scan a file until you have all of it. I don't really know any of the competitors products, but is there anyone else who does antivirus scanning on the gateway and also starts the download to the client immediately? Tom can you answer for Smoothwall - do you have "immediate" downloads? One thing - if you are using Sophos Endpoints then all filtering and AV is done on the windows computer itself, and downloads will appear to start immediately. If there is someone out there with a self signed cert, can't you add it on the "Certificate Validation". AFAIK this would the allow the cert even though it is improperly signed. I admit this is not my area of expertise or maybe I don't understand what you need. I admit that I mistyped MB as GB. Give me a break - do you think I don't actually know the difference? If you fix my typo then the reply stands - 120GB is small. It sounds like you've bumped it up and your problems have been resolved. Maybe I don't understand what you are asking for. In help under "Block Page Template" %%user_name%%: This page element key provides the name of the user who has made the request for the blocked page, as provided by Active Directory. If Active Directory is not available, the IP address from which the request was made will be displayed instead. %%user_ip%%: This page element key provides the IP address from which the request for the blocked page has been made. %%sophos_block_text%%: This page element key provides the reason that a requested page has been blocked. Are those not the variables you were asking for? They've been there for 2+ years. If those are not what you are asking for - can you explain? As I started off by saying I would rather genuinely help you rather than argue with you. This is a debate throughout the security community and we'll have to agree to disagree on this one. 1) You can disable the appliance from scanning downloaded files from domains that you specify. I agree that you cannot disable A/V based on the source (eg don't do scanning for this laptop) or disable A/V across the board. For example it is common to set your own internal servers as Trusted. Theoretically you could set the entire .com TLD as trusted to turn of A/V and all protection - although at the point you are just getting a proxy without any security. 2) If you want, I'm willing to try to help you on this. 3) I can't comment on this. If true, then I agree it sucks although I don't know if anyone else is better. Again, are you talking to Sophos itself or a partner/reseller? -
Our experiences with Sophos Web Filter
randomguy replied to cyr0n_k0r's topic in Internet Related/Filtering/Firewall
- Logging is not real time. Reporting is not realtime and the dashboard can take few minutes. Support with SSH should be able to see real time logging. - There is no way to bypass traffic being scanned by this appliance. You can allow any/all categories, but there are several that Sophos does not allow you to "allow" thus you are never actually allowing ALL traffic through the filter. There are some security categories that should never be allowed. If there are specific sites that you want to allow that are one of these categories, use the LSL. Why would you buy a security product if you want to allow all traffic with no antivirus or security filter? - There is no way to turn off scanning on files that are downloaded. For files that are larger than about 10MB sophos displays this awful "download" page then makes you sit there while it "scans" the file. Then once its finished you have to download the file AGAIN from the appliance. You are effectively clicking download for the file twice every single time. Configure | Accounts | Notification Options | Display patience page when scanning large files This will turn off the download webpage. It will still do an antivirus scan (why would you want to turn it off). The appliance needs to download the entire file from the webserver onto the appliance before it does a virus scan so the two stage download still occurs but is invisible to the user. If you absolutely trust a specific site and don't want to virus scan that site then put it in the LSL as trusted. - The filter cannot unblock self signed certificates. Sophos' default behavior is to block self signed certs and there is no way to change this. We have had to completely disable HTTPS scanning on the filter. Global Policy | Certificate Validation Add yourself as a root signing authority. - Loading configuration pages takes 10+ seconds for every page. Nothing is snappy in this GUI. Should be snappy. You are probably not running on appropriate hardware/VM configuration. VM configuration is complex and small misconfigurations can cause performance issues. I don't know if you've got a good configuration or not, once you decide to run it in a VM you take responsibility for configuring it. Make sure that you've gone through the "Virtual Web Appliance Startup Guide". Saying that hardware and concurrent connections makes no difference to performance means you don't understand the system. - Running reports takes between 30-45 seconds every single time you run a report. Doesn't matter if it's big or small. We have had to reduce our reporting down to only keeping the most recent 3 months because the filter fills up it's hard drive. *Sophos' tech supports solution to this is to just keep increasing the hard drive space for the appliance. I have no idea how many users you have. For a VM with 1200 users the recommended Hard drive is 250MB. The WS1100 comes with a 1000 MB drive. You have 120MB and are complaining that it fills up. Hard drives are cheap, the smallest you can normally buy is 500MB so don't complain if you are running a server on a hard drive smaller than an iPad. - The block pages cannot be customized to remove the Sophos logo and branding. You can use a custom HTML page but if you do you lose the ability to use variables like username, ip of the machine, category being blocked, etc. If you use the sophos block page the XML cannot be modified to remove the sophos logo and copyright branding. Sophos does not consider security through obscurity a sound best practice. Custom HTML can remove branding and you can can use variables to put in everything (such as category being blocked) in. You can do whatever you want (granted you need to know HTML and basic programming concepts). Security through obscurity is a horrible practice. - Customer support is terrible. We had the filter stop passing traffic 3 days ago which caused our entire district internet to be unavailable. After 3 calls sitting on hold a combined 52 minutes we were finally able to get through to a technician. The technician blamed the fact the appliances hard drive had filled up with reports on it no longer passing traffic. Sophos apparently has no way to prune old logs if the HD becomes full so as to not completely break the appliance. I cannot comment, although I believe you get a Yellow and Red alert with emails before the hard drive is full. Get a bigger drive and don't ignore alerts. - When calling support (7 times in the past 2 months) for various issues with the filter I have not once every had them say the problem was actually with the filter. They will blame everything else other than their product. They have blamed our network, our firewall, our internet connection, our Hard Drive space, etc. Everything except their product. I don't know your situation so I cannot comment too much. I will say you are running on a very small hard drive, and you have 5 schools which I presume are at 5 different locations going through a single appliance then network configuration and bottlenecks can be a problem.
