Koozali.org: home of the SME Server

Webfilter contrib

Offline jameswilson

  • ****
  • 739
  • +0/-0
    • Security Warehouse, trade security equipment
Webfilter contrib
« on: June 25, 2018, 12:56:18 PM »
Following on from a post about this contrib i installed it. However it isnt blocking anything. I have checked it is installed and even done a full reconfigure etc.
I did previously run dansguardian on this server and wonder if there is a config file somewhere, but i have no idea where to look?

James

Offline Jean-Philippe Pialasse

  • *
  • 2,763
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: Webfilter contrib
« Reply #1 on: June 29, 2018, 09:37:22 PM »
usually both for webfilter (based on squidguard) and dansguardian, the issue reside in using the transparent proxy and being able to force it on client.

Dansguardian could add one level of difficulty with handling the group configurations


Offline jameswilson

  • ****
  • 739
  • +0/-0
    • Security Warehouse, trade security equipment
Re: Webfilter contrib
« Reply #2 on: July 02, 2018, 11:34:58 AM »
Thanks
I have checked and the http proxy is showing as enabled?

James

Offline Daniel B.

  • *
  • 1,699
  • +0/-0
    • Firewall Services, la sécurité des réseaux
Re: Webfilter contrib
« Reply #3 on: July 02, 2018, 06:17:54 PM »
You need to have your web trafic handled by SME Server's proxy (squid) for the filtering to take effect. When SME is running in server&gateway mode, this can be done automatically for clear text (http) using transparent proxying. No settings needed on the clients. But, if SME is running in serveronly mode, and more generally, for https filtering, this can't be done automatically. You need to configure your clients to explicitely use SME as an http proxy (http://<local sme ip>:3128)

Note that in any case, https is much more limited:
  • Filtering is only done on domain name (vs full URL for clear text)
  • No nice error message displayed, the page just won't load and the browser will display it's own "Connection refused" error message
C'est la fin du monde !!! :lol: