-
Posts
240 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rob_f
-
Smoothwall with Citrix/Terminal Server
rob_f replied to cookie_monster's topic in Internet Related/Filtering/Firewall
Now here's a question, if you're assigning your sessions unique IPs how do you know which session IP is in which room? Do you have a server-per-room? I'm intrigued as to how it worked before... didn't you say on another thread (or it might have been to nile) that it stopped working when you turned on HTTPS interception? Does it start working again if you turn that off? Thanks! Rob. -
Smoothwall with Citrix/Terminal Server
rob_f replied to cookie_monster's topic in Internet Related/Filtering/Firewall
That looks like the one, or -> Virtual IP addressing in Citrix Presentation Server 4.0 I'd suggest it's a good idea in general, but obviously doubles up your IP address space (i.e. 1 IP per thin client + 1 IP client session) - not really read into any other potential implications. Did you ask this on tek-tips too ? (Citrix solutions - Unique IP address for each client) Set up a VPN for them!? That'll learn you to stray from the 'geek -
Apologies guys, rushed entirely off my feet today. I don't have any experience using simple bind, but it looks like your realm may be wrong for Kerberos (or you've got discover kerberos realms by DNS ticked, and it can't find them. Or you're not using your AD server as DNS server). Will try to have a look later, but in the meantime does: https://support.smoothwall.net/index.php?_m=troubleshooter&_a=steps&troubleshootercatid=4&parentid=0 help ?
-
Few more hops but actually quicker than UT from our US office in Charlotte, NC traceroute to www.edugeek.net (78.46.90.194), 30 hops max, 38 byte packets 1 --snip-- (--snip--.161) 0.889 ms 0.932 ms 0.989 ms 2 --snip-- (--snip--.81) 0.992 ms 0.943 ms 0.988 ms 3 10.231.0.161 (10.231.0.161) 6.994 ms 6.943 ms 6.987 ms 4 10.231.39.253 (10.231.39.253) 19.980 ms 19.928 ms 19.970 ms 5 10.231.39.254 (10.231.39.254) 19.983 ms 19.934 ms 19.976 ms 6 5-block.connectregus.com (75.103.5.254) 19.981 ms 19.933 ms 19.977 ms 7 ge-6-12.car1.Cincinnati1.Level3.net (4.53.64.33) 19.984 ms 19.931 ms 19.977 ms 8 ae-2-5.bar1.Cincinnati1.Level3.net (4.69.132.206) 19.980 ms 19.933 ms 19.979 ms 9 ae-10-10.ebr2.Chicago1.Level3.net (4.69.136.214) 28.976 ms 26.929 ms 35.969 ms 10 ae-5.ebr2.Chicago2.Level3.net (4.69.140.194) 26.976 ms 26.930 ms 26.976 ms 11 ae-2-2.ebr2.Washington1.Level3.net (4.69.132.70) 43.966 ms 43.920 ms 43.967 ms 12 ae-44-44.ebr2.Frankfurt1.Level3.net (4.69.137.61) 134.913 ms 134.890 ms 132.883 ms 13 ae-72-72.csw2.Frankfurt1.Level3.net (4.69.140.22) 142.913 ms 134.862 ms ae-82-82.csw3.Frankfurt1.Level3.net (4.69.140.26) 134.916 ms 14 ae-1-69.edge6.Frankfurt1.Level3.net (4.68.23.14) 135.869 ms 134.867 ms ae-3-89.edge6.Frankfurt1.Level3.net (4.68.23.142) 132.918 ms 15 LAMBDANET.edge6.Frankfurt1.Level3.net (195.16.161.6) 135.870 ms 134.805 ms 134.909 ms 16 FRA-3-eth100.de.lambdanet.net (217.71.96.70) 134.921 ms 134.861 ms 134.911 ms 17 NUE-2-eth210.de.lambdanet.net (217.71.96.162) 137.911 ms 136.920 ms 138.844 ms 18 lambdanet-gw.hetzner.de (213.239.242.214) 137.915 ms 138.857 ms 137.937 ms 19 hos-bb2.juniper3.rz4.hetzner.de (213.239.240.142) 134.891 ms 136.856 ms 137.935 ms 20 hos-tr4.ex3k16.rz9.hetzner.de (213.239.244.253) 135.888 ms 136.855 ms 136.968 ms 21 eg4.edugeek.net (78.46.90.194) 138.856 ms !<10> 138.859 ms !<10> 137.941 ms !<10>
-
From my personal webhost in Utah: 1 --snip-- (--snip--) 0.391 ms 0.466 ms 0.504 ms 2 te11-3-0d0.mcr1.saltlake2-ut.us.xo.net (65.46.63.9) 1.396 ms 1.403 ms 1.397 ms 3 216.156.0.5.ptr.us.xo.net (216.156.0.5) 18.491 ms 18.488 ms 18.481 ms 4 207.88.12.186.ptr.us.xo.net (207.88.12.186) 17.802 ms 17.844 ms 17.837 ms 5 sjo-bb1-link.telia.net (213.248.86.93) 20.617 ms 20.618 ms 20.826 ms 6 nyk-bb2-link.telia.net (80.91.254.176) 70.954 ms 71.323 ms 71.176 ms 7 prs-bb2-link.telia.net (80.91.253.125) 148.308 ms 148.026 ms 148.804 ms 8 ffm-bb2-link.telia.net (80.91.252.234) 163.709 ms 163.703 ms 163.693 ms 9 ffm-b2-link.telia.net (80.91.249.103) 157.637 ms 158.035 ms ffm-b2-link.telia.net (80.91.252.254) 164.112 ms 10 hetzner-ic-134650-ffm-b2.c.telia.net (213.248.92.82) 160.960 ms 160.968 ms 161.269 ms 11 hos-bb1.juniper3.rz4.hetzner.de (213.239.240.234) 159.003 ms 159.011 ms 159.001 ms 12 hos-tr4.ex3k16.rz9.hetzner.de (213.239.244.253) 162.355 ms 162.539 ms 162.292 ms 13 eg4.edugeek.net (78.46.90.194) 159.958 ms !X 160.177 ms !X 160.152 ms !X
-
Smoothwall temporary bans
rob_f replied to SpuffMonkey's topic in Internet Related/Filtering/Firewall
Sure does ! Them being set as "no" on that authentication page is the only bit that actually makes them banned as such, you can just fiddle it round so that they get a specific policy. Really temporary bans is just temporarily making a user a member of a specific group. -
Smoothwall temporary bans
rob_f replied to SpuffMonkey's topic in Internet Related/Filtering/Firewall
Guardian > Authentication > Settings, set the "Banned Users" group to "Yes (filtered)" rather than "no". They'll then be able to browse the web. Now create a policy that says "Banned Users - Everything - Always - Block" then a new custom filter with a custom category for the list of sites they need to get to, then apply it to them with an "Allow". ...if aforementioned solutions don't work out for you that is -
Smoothwall end to end througput testing
rob_f replied to plexer's topic in Internet Related/Filtering/Firewall
Have sent you a PM with some instructions... -
SmoothWall Constant Outgoing problem
rob_f replied to Netwacky87's topic in Internet Related/Filtering/Firewall
"-" can also be traffic to a site that you have not required to use authentication (Guardian > Authentication > Settings) as it doesn't ask/check who the request is from, hence the username for the request is "-". EDIT: The various IP based reports (Information > Reports > Reports then Users > IP Sections) should give you top bandwidth by IP address IIRC. -
Block youtube but allow specific channels?
rob_f replied to pete's topic in Internet Related/Filtering/Firewall
SmoothWall does that out of the box - if you're not blocking facebook/social networking it will still analyse every page for porn/weapons/violence/etc and block them if they breach based on phrase content. You could then also put your own phrases in to block in addition to the predefined phrase analyses. In addition, the new post (outgoing) monitoring allows you to block when people post inappropriate things on to facebook, etc. - so you could for example put staff members names into a message censoring list to stop anyone talking about them in statuses, messages, wall posts etc. -
Been distracted since I first saw this thread this morning, so apologies for the delay. I've always had great difficultly determining what people are talking about with the difference between (using aforementioned terminology) "hardcore" Xen and citrix Xen. I've only used the Citrix one which was effortless to install SW software. Now I haven't had the pleasure of getting my hands dirty with the hardcore stuff, but I gather from one of my colleagues that causes problems as Xen likes to give it a new MAC address every time it reboots. Smoothie currently evaluates this as a new network card and hence causes all sorts of problems. I am lead to believe that doing something like vif = [ 'type=ioemu, bridge=eth0, mac=00:16:3E:23:8D:36' ] to hard-code a MAC address in there will stop this. That's the way VMware and the like configure their VMs. As I said though, i've yet to try this myself - I'll have a chat with the main guy here who deals with the hardcore xen stuff when he returns from a brief hol on Monday if there's anything else. And to reiterate, Citrix Xenserver seems trouble free. If only the naming wasn't as confusing.
-
Smoothwall - ESX 4 VMTools?
rob_f replied to Macinator's topic in Internet Related/Filtering/Firewall
We'll have a look and see what's different in the Linux versions of these drivers. Mostly I think the v4 tools are to support the new hardware spec, mainly with regards to graphics, sound, mouse etc. - which are irrelevant on the Smoothie. But certainly the disk and network drivers are worth a look, so we'll keep you posted. Thanks! ~ -
I take it that the issue is that you need to allow gumtree.com (as it's blocked on a list) then block a part of it? I *think* you need to do this with a URL regular expression. nile_c will be able to back my guess up with solid actual knowledge, but... Add in your custom allow the following under the URL Regular Expressions box: (?:[^/]*\.)thissite.com(?!(/adultsonly))(/?)(.*) Replacing thissite.com and adultsonly appropriately. This will then allow any URL that matches thissite.com but not thissite.com/adultsonly. I think. You may want to put this in a new filter with a new custom category then set the action to "skip url blocking" so that it still analyses the phrase content on the pages that you are allowing access to. Best wait for Nile to confirm if you can wait 'til the morning. Thanks! Rob.
-
I believe this error occurs when clients start sending data but for some reason it isn't getting returned to them, for example if they disconnect or there are network issues inbetween. I may be wrong however It isn't necessarily indicative of a problem with the SmoothWall system itself, do you have any pattern or frequency of occurrence of the error? Thx
-
Smoothwall - Realtime Web Filter
rob_f replied to Gatt's topic in Internet Related/Filtering/Firewall
Unusually the filter box on the realtime web filter doesn't appear to be a regex, but will check - either way I will pass on as a feature request though. Only thing I can think of is not to log explicitly allowed sites (Guardian > Web Proxy > Advanced) and then put in an allow for these domains. However you'll then lose logging of anything set to Allow. --update-- Just had a peek at the code and this doesn't look to be currently possible. Will pass on to a certain product manager... -
It'll probably break a few websites, but... Guardian > Policy Add a new policy, you'll see under the filter dropdown some "special" filters at the top: Either that or you might want to look at the setting in Guardian > Web Proxy > Advanced to do a DNS reverse lookup in domain blocking. Will do a reverse lookup for any IP URL and then compare that to the domain lists. Is there something particular that you're looking to block that perhaps we can do better in the blocklists? Thanks, Rob.
-
SmoothWall Feature Pack 3
rob_f replied to Netwacky87's topic in Internet Related/Filtering/Firewall
Some people do this, others take a more "minimal" filtering policy (i.e. just blocking the absolute extreme stuff you would never want to allow) from the LA and supplement it with the local controls that the smoothie gives them. Some people use it to have an additional internet connection (ADSL etc) in combination with the LA connection... lots of different ways! Rob. -
SmoothWall Feature Pack 3
rob_f replied to Netwacky87's topic in Internet Related/Filtering/Firewall
Yeah that was the problem I had too The existing "Online Gaming" category now includes the flash analysis signatures relevant to online gaming, so unblocking online games disables the flash filter's detection of games. Good to see it out there any hopefully doing some good, remember edugeek folks that this feature was exclusively announced at your very own educonf09 ! -
Hey - is this SmoothWall Express or Corporate? Either way you might want to log onto the console locally as "root" and the password you chose during install - from there type "top" which will basically give you a task manager type thing (I'm assuming unfamiliarity with linux at this point - apologies if untrue!). You'll see something like: http://www.cyberciti.biz/nixcraft/vivek/blogger/uploaded_images/linux-cpu-utilization-780043.png The "CPU(s)" line tells you the percentages of different states the processor(s) are in, and the Mem and Swap lines show you your memory utilisation. Pressing "P" (i.e. shift-p) will sort the processes by processor utilisation. Does this give you any clues as to what might be eating away at the system? A very busy disk, especially for a fresh install would indicate hardware problems, either in the driver support or the actual underlying physical layer. Having said all that, if it's SmoothWall Corporate, give support a call. They'll work all that out for you Let me know what you find out anyway, or if you need more help Rob.
-
Rack ears went out in the post today Chris - Royal Mail so expect them in 6-8 weeks You'll have to update the photo when they arrive!
-
Just picked up a few switches from this offer - the APs are nice and sturdy; good to see one made out of metal for a change! Now to make them do something....
-
Smoothwall safe image search
rob_f replied to cookie_monster's topic in Network and Classroom Management
Under SmoothWall Guardian you'll want to tick the "force safe search" toward the bottom of your (by default) recommended security rules policy. Or alternatively : https://support.smoothwall.net/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=323 On new installs it's the default as of the SP4 iso. HTH! Rob. -
Smoothwall Problem - Blocking Https sites
rob_f replied to adhutton's topic in Internet Related/Filtering/Firewall
Is there anything interesting in the logs when they get refused access? If it is the SSL certs being invalid then you should see that. If not might be worth a quick call to support. Ta, Rob. -
Hey Jose - all ports should be the same, so 800 by default - so it looks like using 442 there is the problem. Strange that it would work for some sites though... I'd give that a try first, and if still fails let me or support know. Thanks! Rob.
