rpmoore
Members-
Posts
41 -
Joined
-
Last visited
Reputation
85 ExcellentAbout rpmoore

Personal Information
-
Occupation
Tech Expert
-
Location
Manchester
- X
-
Homepage
http://www.westhullfm.org.uk
Employer (optional)
-
Company Represented
West Hull FM
-
A big problem selling into education is that customers are no longer loyal to a supplier or vendor, and everything largely comes down to price. Of course we all understand the pressures on budgets, but sellers need to get enough out of a deal to ensure that as a business they are still around to support customers over the life of a multi-year contract. Smoothwall, Bloxx and Lightspeed have been fighting to the bottom of the barrel for years, and if that vendor only operates in the edu space then something has to give way at some point. I can only guess Akamai's plans for Bloxx
-
iBoss - Apple Push Certificate Error
rpmoore replied to DanHamilton's topic in Mobile Devices & Tablets
Hi Dan, Can you give our support team a call on 020 3713 0472 and they will be able to help? Alternatively PM me your contact details and I'll put them in touch. Thanks Richard -
New Web Filter and Firewall for School
rpmoore replied to Techdw's topic in Internet Related/Filtering/Firewall
Hi Plexer, I was tongue-in-cheek heckling Dave who provides filtering via Lightspeed, which is an SWG product. [/url] Richard -
Hi ITGURU - what I meant is that normally you would have to authenticate against the wireless, and then against the web filter to get access to the network with the appropriate filter settings. With at least Radius authentication the wireless controller talks to the filter and authenticates the client and sets the appropriate filtering policy with just one sign on. You can take it further, for example with Ruckus, iboss have RIOT integration which also feeds back location data from Ruckus to iboss, allowing location based filtering on the fly. Richard
-
@Edu-IT I know that. However BYOD is BYOD and the requirements and challenges are the same whether edu or corporate. R
-
@john, you are never going to be able to enforce MDM on student devices; MDM is only ever going to work on school owned devices... I have seen some of the better web security vendors doing stuff like behavioural based tech to detect threats from BYOD student devices Rich.
-
Hi DSP, We are sorry you found these results during your iboss testing. Scaleability and specifically handling of SSL/TLS is something that iboss are noted for. I would suggest that this may have been a configuration issue or even a faulty appliance. A standard iboss appliance can run at 1GB wire speed, and support up to 10,00 devices/ 4 million sessions, and we have several thousand of them in the field. Thinking about your issues, we always try to avoid running in proxy mode and when you were inline it sounds like you experienced a duplex mismatch - To be fair we should have picked up on this. Finally your box was installed by a new partner who had yet to go through our certified training. While they are technically capable, any sort of invasive tech like a web filter has many options and thus potential to cause issues if configured incorrectly. Lessons learned! Thanks for considering us, and wishing you the best. Richard
-
Thanks @tom_newton you took the words from my mouth, and yes we don't proxy traffic by default @caffrey back to your question, to do SSL MITM decryption generally requires the session to be proxied with the inherent certificate issues; however iboss have another cunning feature for windows PC's. Our EdgeScan client performs the SSL decrption within the Windows TCP/IP stack, both removing the certificate problem as well as offloading the SSL decryption onto the endpoint workstations Cheers, Richard
-
As far as I am aware, LS does not offer selective SSL decryption, and you have to either decrypt ALL SSL or none. To avoid a massive bottleneck, particularly on larger installations LS tend to specify an external load balancer to divert specific SSL traffic to a separate proxy appliance. iboss automatically diverts SSL traffic from the L2 bridge onto internal proxy for decryption based on the selective policy. cheers, Richard
-
@tom_newton is of course correct. In order to do man in the middle SSL decryption, a proxy is required to handle the mechanics of certificate exchange - you can't bend the laws of physics. iboss natively uses a Layer-2 bridge for filtering TCP and UDP traffic which runs at wire speed. We then do selective decryption based on the domain category, and only traffic that needs to be decrypted is then diverted onto the proxy. We have a couple of patents around our proxy to overcome the speed limitations of the standard squid offering. It is reckoned that SSL traffic will grow from the current 40% level to as much as 70% (according to Gartner), so selective decrypt provides all the benefits without the performance and speed overheads. @RichCowell - looking forward to the ANME meeting, i'll get the papers over to you later today. I'll bring my demo kit with me if anyone wants a look through the product over a cuppa. Cheers, Richard
-
@techie08, sorry about your experience. As we continue to build market share here in the UK, we are getting more reseller partners through our certified technical training so there are now lots of really good options for installation assistance. Add to that we are happy to provide unmetered support to our EDU customers as part of the product then you should now be covered moving forward. I think one of my colleagues is going to check in with you to see if there is anything else we can help with. Cheers, Richard
-
Caching is very much a technology of yesteryear as more content is now dynamic, streamed, or encrypted etc (remember the mighty CachePilot that was once everywhere, now collecting dust in a closet near you). In terms of using a proxy server there are a number of issues, for example products that are based on squid struggle with throughput in excess of 2-300Mbps due to the nature of this piece of software. If you start to add on other services on the same box such as dynamic categorisation, reporting etc and then ask it to do this for 2-3000 devices on a typical large secondary network you can see where the bottlenecks start to come into play. The other major issue with using a proxy is that they can only control traffic that plays nicely with them, meaning that things like malware/ or proxy avoidance tools (ultrasurf, TOR etc) that often use obscure UDP ports have to be controlled at the firewall. HTH, Richard @ iboss UK
-
Hi Christine, Just to point out that Android is now fully supported by iboss, and if you have the SWG it also integrates the reporting and web filtering into one solution. Richard
