Jump to content

ping

Members
  • Posts

    2
  • Joined

  • Last visited

Everything posted by ping

  1. It just means that there are no ways to authenticate the user to the filter itself so that no one could do some sort of DOS as the box would respond to anyone on the assigned port at it's address. These are two separate authentications from what I understand. Outside of open proxy, the best I had with it at one point was only talk to iOS and Chrome devices before that too broke and forced me to have it open. The captive portal still works for filtering and I still have full visibility to sites users visit. I don't think running a separate VLAN for iPads is the answer because the PAC and cert files that are installed on all school owned iOS devices routes the traffic through the filter....moreover, I'm not sure how setting up iPads on a separate VLAN would help when at home since the PAC file and certificate files deal with the routing all traffic to the filter regardless of user location. In the somewhat perfect world, the LS mobile client for iOS would allow page redirects and manual user authentication, but according to LS, Apple does not currently allow it (which if true is just another gripe I have with Apple making it difficult to manage iOS devices). In that somewhat perfect world, we'd not have to proxy traffic back through out internet pipe, but I think you are right that for now proxy is it.....however Securly seems to have gotten around the Apple restriction by doing DNS redirect as there are no iOS clients, so I'm not sure if that's just LS doing the blame game or not since it's pretty clear to me that LS has lost the edge it once had over the competition. IMHO, it seems that they are playing a lot of catch up....and in talking with like of Smoothwall and Securly, it seems that some of the features they have really are making LS up it's game, unfortunately it may just dictate that I should stay in hover mode for another year to see how things shake out. One important note is that my MacOS laptops I don't proxy at all, I have the LS mobile filter agent and though it's a PITA to make sure the MAC addresses are in the Device Registration Portal LS has set up, it does filter the Mac OS users as expected when off-site. When internal the local agent runs and automatically ties into my LDAP box and the solution does seem to play nice switching between the mobile client and local agent as needed. Why that can't work with iOS the same way, I don't fully understand. Thanks for the info on Smoothwall. I thought they too had a client, but again, if what LS is telling me it's an Apple restriction.
  2. I'm going through the same exercise. I've been using Lightspeed for about 5 years now and it's worked, and support has been great, but overall the web and content filtering isn't what it was when I started 5 years ago. Here is what I've found so far: Lightspeed's appliance does a fairly good job and now that Longhorn is out, the filter does behave better. I still need to proxy iOS devices because they tell me Apple won't allow them to redirect pages with their mobile filter client for iOS. That's a problem. What's more is that I have to run an open proxy because any type of proxy security, even the most basic breaks a lot of stuff. Lightspeed knows this and hasn't seemed to solve either issue...one has been ongoing for almost a year. Lightspeed's cloud based filter seem really neat, it too can authenticate to a Google domain which is preferred IMHO if you are a Google shop. The downside is that they (Lightspeed) were smart enough to have proxy security, but unfortunately the issues with iOS and secure proxy is still an issue, so then you are left with the mobile filter app for iOS and guess what--- the same limitations are still an issue. Lightspeeed seems to think I'm a good candidate for their "hybrid" setup part local appliance, part cloud. Haven't tested it yet, so can't say much about it. Overall Lightspeed has been fairly responsive and the support has been good. Price is comparable to other offerings out there. Securly. Really neat filter, some pretty interesting features too. However, and I verified this with another school that uses it, the URL categorization is unlike anything you've used before, which means in primary education where we tend to have a bit more restrictions for the younger kids, you'll spend a lot of time adjusting the filter to meet your needs. This is normally the case with any web filter change, but Securly's would be about 5x or more comparatively. I was thinking about Smoothwall or just staying another year with Lightspeed to see if improvements to their current issues get resolved. My needs are: Filter that uses AD or Google authentication Off-site filtering for school owned devices (iOS and MacOS)-- prefer not to proxy Possible future Chromebook deployment You'd think that small of a list would be an easy target to hit, but if you'd shopped for web filters, you know that no one has the magic recipe. Each one does a few great things and a few not so great, which is why I'm thinking I may stay as I am one more year to see what shakes out.
×
×
  • Create New...