rpmoore
Members-
Posts
41 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rpmoore
-
A big problem selling into education is that customers are no longer loyal to a supplier or vendor, and everything largely comes down to price. Of course we all understand the pressures on budgets, but sellers need to get enough out of a deal to ensure that as a business they are still around to support customers over the life of a multi-year contract. Smoothwall, Bloxx and Lightspeed have been fighting to the bottom of the barrel for years, and if that vendor only operates in the edu space then something has to give way at some point. I can only guess Akamai's plans for Bloxx
-
iBoss - Apple Push Certificate Error
rpmoore replied to DanHamilton's topic in Mobile Devices & Tablets
Hi Dan, Can you give our support team a call on 020 3713 0472 and they will be able to help? Alternatively PM me your contact details and I'll put them in touch. Thanks Richard -
New Web Filter and Firewall for School
rpmoore replied to Techdw's topic in Internet Related/Filtering/Firewall
Hi Plexer, I was tongue-in-cheek heckling Dave who provides filtering via Lightspeed, which is an SWG product. [/url] Richard -
Hi ITGURU - what I meant is that normally you would have to authenticate against the wireless, and then against the web filter to get access to the network with the appropriate filter settings. With at least Radius authentication the wireless controller talks to the filter and authenticates the client and sets the appropriate filtering policy with just one sign on. You can take it further, for example with Ruckus, iboss have RIOT integration which also feeds back location data from Ruckus to iboss, allowing location based filtering on the fly. Richard
-
@Edu-IT I know that. However BYOD is BYOD and the requirements and challenges are the same whether edu or corporate. R
-
@john, you are never going to be able to enforce MDM on student devices; MDM is only ever going to work on school owned devices... I have seen some of the better web security vendors doing stuff like behavioural based tech to detect threats from BYOD student devices Rich.
-
Hi DSP, We are sorry you found these results during your iboss testing. Scaleability and specifically handling of SSL/TLS is something that iboss are noted for. I would suggest that this may have been a configuration issue or even a faulty appliance. A standard iboss appliance can run at 1GB wire speed, and support up to 10,00 devices/ 4 million sessions, and we have several thousand of them in the field. Thinking about your issues, we always try to avoid running in proxy mode and when you were inline it sounds like you experienced a duplex mismatch - To be fair we should have picked up on this. Finally your box was installed by a new partner who had yet to go through our certified training. While they are technically capable, any sort of invasive tech like a web filter has many options and thus potential to cause issues if configured incorrectly. Lessons learned! Thanks for considering us, and wishing you the best. Richard
-
Thanks @tom_newton you took the words from my mouth, and yes we don't proxy traffic by default @caffrey back to your question, to do SSL MITM decryption generally requires the session to be proxied with the inherent certificate issues; however iboss have another cunning feature for windows PC's. Our EdgeScan client performs the SSL decrption within the Windows TCP/IP stack, both removing the certificate problem as well as offloading the SSL decryption onto the endpoint workstations Cheers, Richard
-
As far as I am aware, LS does not offer selective SSL decryption, and you have to either decrypt ALL SSL or none. To avoid a massive bottleneck, particularly on larger installations LS tend to specify an external load balancer to divert specific SSL traffic to a separate proxy appliance. iboss automatically diverts SSL traffic from the L2 bridge onto internal proxy for decryption based on the selective policy. cheers, Richard
-
@tom_newton is of course correct. In order to do man in the middle SSL decryption, a proxy is required to handle the mechanics of certificate exchange - you can't bend the laws of physics. iboss natively uses a Layer-2 bridge for filtering TCP and UDP traffic which runs at wire speed. We then do selective decryption based on the domain category, and only traffic that needs to be decrypted is then diverted onto the proxy. We have a couple of patents around our proxy to overcome the speed limitations of the standard squid offering. It is reckoned that SSL traffic will grow from the current 40% level to as much as 70% (according to Gartner), so selective decrypt provides all the benefits without the performance and speed overheads. @RichCowell - looking forward to the ANME meeting, i'll get the papers over to you later today. I'll bring my demo kit with me if anyone wants a look through the product over a cuppa. Cheers, Richard
-
@techie08, sorry about your experience. As we continue to build market share here in the UK, we are getting more reseller partners through our certified technical training so there are now lots of really good options for installation assistance. Add to that we are happy to provide unmetered support to our EDU customers as part of the product then you should now be covered moving forward. I think one of my colleagues is going to check in with you to see if there is anything else we can help with. Cheers, Richard
-
Caching is very much a technology of yesteryear as more content is now dynamic, streamed, or encrypted etc (remember the mighty CachePilot that was once everywhere, now collecting dust in a closet near you). In terms of using a proxy server there are a number of issues, for example products that are based on squid struggle with throughput in excess of 2-300Mbps due to the nature of this piece of software. If you start to add on other services on the same box such as dynamic categorisation, reporting etc and then ask it to do this for 2-3000 devices on a typical large secondary network you can see where the bottlenecks start to come into play. The other major issue with using a proxy is that they can only control traffic that plays nicely with them, meaning that things like malware/ or proxy avoidance tools (ultrasurf, TOR etc) that often use obscure UDP ports have to be controlled at the firewall. HTH, Richard @ iboss UK
-
Hi Christine, Just to point out that Android is now fully supported by iboss, and if you have the SWG it also integrates the reporting and web filtering into one solution. Richard
-
Mikeyd101 - I just tested this against the iboss here on my home lab. Straight away access to the Hotspot Shield website was blocked under the 'proxies' filtering category. After installing Hotspot Shield on a test machine it was totally blocked by iboss - See the screen shot attached where it is attempting to connect to various hosts. Make sure that in Controls > Applications > High-Risk Activity lock you have selected to block appropriate applications. Optionally you should also ensure that your firewall is setup to only allow appropriate users to access appropriate outbound ports or services. All the best, Richard. iboss UK.
-
Filtering and firewall
rpmoore replied to Marshall_IT's topic in Internet Related/Filtering/Firewall
Huxlow - we look forward to welcoming you back. We have just completed a major upgrade to our UK service center (people, processes and systems) and can now offer better services and SLAs to our customers than ever. Richard- 74 replies
-
Congratulations. I'm just 7 days into the adventure myself. All very time consuming, but we'll rewarding.
-
Filtering and firewall
rpmoore replied to Marshall_IT's topic in Internet Related/Filtering/Firewall
We are also replacing our dated QoS module this year and will also offer bandwidth by category and group, and hopefully by application.- 74 replies
-
Filtering and firewall
rpmoore replied to Marshall_IT's topic in Internet Related/Filtering/Firewall
I dont think that is entirely true. We have been up against Lightspeed quite a bit recently and in most occasions have won in a shootout. Depends whether you want the most effective web filtering, or a cheap 'swiss army knife jack of all trades' product I am of course biased!- 74 replies
-
Instead of using Spam Assassin, of indeed trying to build our own engine from scratch we decided that there were people far more qualified on antispam than us. We use the Mailshell engine, which regularly ranks as the most effective OEM solution available - see recent review. . Similarly the antivirus/malware component of our product is VIPRE.
-
At the moment, I would agree. SonicWALL is a polished firewall and I have a lot of respect for them. Smoothwall has focussed on delivering the best web content filter for education, and I have to admit have taken our eye off the firewall side in recent years. This is why we are now addressing those issues with the introduction of L7 and also things like a new QoS module within the firewall. We have also recently employed a full time UI designer and will soon be overhauling the interface to make the product easier and more accessible.
-
I'd probably be a bit biased to comment Seeing you are a Leeds fan however is interesting, as our offices are in the shadow of the great Elland Road and we are all regulars - compared to those other vendors from different countries, one of which isn't even sure what football is....!
-
Hi RTFM - I personally think that it currently compares well to mid market solutions such as SonicWALL, and we sell a lot of our UTM product, combining firewall with Guardian. However, we are currently redeveloping the firewall to include full Layer 7 analysis. Ultimately we will be able to identify and manage 000's of applications in a very granular manner - making us more comparable to the like of Palo Alto. This will launch in a couple of months. While some other vendors are adding complimentary products (i.e. MDM, Desktop AV) to their core offerings, we believe in sticking to providing a great firewall with the best filtering on the market. (If anyone wants further info on the new functionality please IM me) Richard
-
This is an interesting thread, and as the established web filtering market leader in UK education and LA markets it is my job to make sure Smoothwall exceeds our customer expectation from a product and service perspective. I have discussed the points raised in this threat regarding support reactiveness with our COO, who replies below. Both of us are contactable personally should you need to get in touch - we always welcome constructive feedback good or bad. I'm always seeking to improve the quality and responsiveness of our Support to Customers and provide value for money to them, so it's a direct concern to me that some forum members are posting issues here about Smoothwall's support whilst others have enjoyed the level of service that they, and I, expect. It's well known that we have grown very significantly but that cannot become a reason why we falter in providing services to some customers. Empirically and anecdotally from your posts, support turnaround times are, on occasion, erratic so we are working continually to improve:- • we are investing in additional Support staff and training, more will be in post by the end of March, • some of you will be aware that our knowledge base has been completely re-written over recent months and is available via Smoothwall's Support portal to enable fast responses on known issues and FAQs, • in response to customer input, new advisory services and enhanced training services are now launched • all of our service agreements have been re-written and enhanced to provide more flexibility, choice and value for money for our Customers for the full life of your Smoothwall solution. There's more to come but, in the immediate short term, my focus is to ensure that we deliver excellent service to all of our Customers. Gary Pearson - Chief Operating Officer, Smoothwall.
