Cool to see that you feel the same way as I just explained to my colleagues that filtering should be handled on the endpoint and not in the firewall. This a couple of months ago.
@theundertaker59632 жыл бұрын
I already have a good 8 places to post this to off the top of my head, and I assure you I will send many more people over to this video as the time goes by. Thanks!
@PowerUsr12 жыл бұрын
Excellent content here Tom. I think this should answer a lot of the questions you get on the forums and on the vlog. Thanks again
@mind12962 жыл бұрын
Absolutely agree. Tom's every content is straightforward, sticks to the point and helps the community. Keep it coming!
@inferKNOX22 жыл бұрын
I have been having a nightmare with filtering in an environment where management wants everything blocked and select sites accessible. In my case, it involves a Fortigate, which, once you install its CA to the endpoints, is quite good about it. Issues remain surrounding certificates that span wanted and unwanted services though, with Google's one for itself and KZbin being a prime example. Besides that, opening a site up leaves the issue of inaccessible dependencies like scripts, etc, that need to load from other sites, including CDNs. So the end user may have access to the site, but everything is broken until one inspects and discovers all the other sites the browser needs to load from for it to work (there may be a better way, but I'm yet to find it). This gets especially bad when different pages have different dependencies. To top it all off, opening access to CDNs for some dependencies gives the headache of unwanted sites, etc, on the CDNs, also becoming accessible when they shouldn't be... it's nuts and I hate it.
@RobbyPedrica2 жыл бұрын
HTTP/3 that is based on QUIC, is supported for DPI inspection in v7.2 of FortiOS.
@LAWRENCESYSTEMS2 жыл бұрын
Thanks
@Alexnz9352 жыл бұрын
thank you tom for this vidoe, I just wanna say thank you for all your great content over the years, It has taught me alot over the last 3 years I just wanna say thank you going for my JNCIP-SP this week, I just wanna say thank you for all your great content, not the smartest dude but your vidoes are fun to watch and easy to work along side with you and build out from there, I build my first every truenas system because of your vidoes on True Nas just though I would say thank you for the years of great content and can't wait for many more years of content from you.
@JasonsLabVideos2 жыл бұрын
So far Arista does the best CF I have used yet!
@joshsmith49982 жыл бұрын
This aligns with what I've been thinking as well when it comes to content filtering. We have been hesitant to implement decryption on our Palo Alto fw because of the challenge to maintain the certificate and deploy it and then needing to Manage and monitor the filtering from PAN-OS. I'm sure it's manageable with larger teams of people but we're a small team at my org so something like an endpoint solution seems like a better fit if that's a road we ever intend to travel.
@RobbyPedrica2 жыл бұрын
You can use a single host cert across multiple firewalls in a wildcard fashion with either manual push or auto through AD Cert services. Not that difficult to maintain. Vendors APIs make this even easier if you're into config automation.
@joshsmith49982 жыл бұрын
@@RobbyPedrica Thanks for the context, definitely not outside the realm of what I can personally do but sadly I only have a team of 3 including myself, a new-to-IT helpdesk guy, and my boss (our director). Even if I were to set something like this up nobody else on my team would really be inclined to maintain or replace the cert when it expires as they're not particularly keen to certificates or managing our Palo Alto HA FWs. Definitely a strong consideration for the future when we have more sysadmins at our disposal though. Just kinda trying to keep the environment manageable should I ever choose to move along for the time being which is something we all deal with I 'spose.
@RobbyPedrica2 жыл бұрын
@@joshsmith4998 I personally look after around 1200 firewalls. With the right tools, volume is irrelevant and difficult becomes easy.
@joshsmith49982 жыл бұрын
@@RobbyPedrica that’s no small feat! I’m In a role currently wearing all the hats for a convenience store chain with almost 100 locations and trying to keep the machine oiled has been a lot. Automating manual processes has been a must and I’ve honestly just been learning every day.
@djstraussp2 жыл бұрын
Great information with a touch of granularity. I'll be checking out you're recommendations about those software solutions.
@robomac882 жыл бұрын
What would you suggest for schools and churches that want to offer an open guest network, but also want to block torrents and adult content on it? Putting certificates on devices is not an option so would the best approach be something like OpenDNS or Untangle?
@LAWRENCESYSTEMS2 жыл бұрын
Untangle is a popular solution for that.
@rajismiley89372 жыл бұрын
So in my experience for small business and or the family home in my case, I have combining the speed of suricata/snort and Adam:One Dns pfsense plugin. It has been really effective in applying certain devices in the home or office with different policies that can be applied in terms of what websites could be visited. I havent seen it fail, but I most certainly havent implemented it in a commercial sense for any my clients. Imo the next step I am considering seeing I feel i have outgrown my pfsense was to shift to a palo vm, which I have managed to build on great compute specs and only forced to pay 4k for 3 years. I havent done it yet because, as I mentioned, its 4k, sigh. The certificate thing can be automated across most NG firewalls today in terms of renewal and even for deployment to endpoints. But not something I'd recommend, cus down time even at home, is NOT A HAPPY HOME. My home is my lab, don't do that, I warn most. What I am really looking out for in terms tech, is the emerging DDI and IPAM Saas products becoming more and more accessible in price to the midmarket and special interests groups such a hybrid dev houses and automated containerised services that are infra and cloud agnostic.
@GrishTech2 жыл бұрын
zscaler is an okay product that lives on the client device. I agree that client-based solutions are far more superior than something on the edge.
@michaelsworkshop90312 жыл бұрын
What are your thoughts about DNS security services like Cisco Umbrella? Managing some of these issues by controlling/filtering DNS inside the firewall is the only way we were able to cover these types of needs across Chromebooks, PC, Mac, iPads, iPhones, Android, etc., by controlling what the endpoint devices were able to lookup and connect to. pfSense restricts users to use our filtering DNS servers. No WFH users on these particular deployments, making it simpler to enforce.
@LAWRENCESYSTEMS2 жыл бұрын
We prefer endpoint management over DNS filtering.
@netwolfstar Жыл бұрын
Would be good if you would review Firewalla gold.
@LAWRENCESYSTEMS Жыл бұрын
It's a consumer device that I currently don't have time to look at.
@qcnsllcqcnsupport76162 жыл бұрын
Hey Tom, thanks for all the great videos...i know how you feel about firewalls that's not open source but I think sophos xg does a very good job at this. And there's a free version...
@JasonsLabVideos2 жыл бұрын
That fw needs HUGE resources to run ! EWW
@HisLoveArmy2 жыл бұрын
The new XGS model is a lot faster also. For the price it’s a really great firewall.
@sven9572 жыл бұрын
Have you tried out cloudflares zero trust solution? Seems interesting to me because it has pretty granular control and its free for smaller customers
@LAWRENCESYSTEMS2 жыл бұрын
I don't like the idea of being locked to a particular vendor solution. Changing out the software via software loaded on each endpoint is easier to manage.
@rajismiley89372 жыл бұрын
I tried it, and the problem with cloudflare is that location data is selectively given up, its not zero trust if you cant even do the damn basics.
@mithubopensourcelab4822 жыл бұрын
Neither Saaslio nor Zorus provides transparent pricing on their website.
@FabioVascoGomes2 жыл бұрын
I think it's $3/month/device. At least is what a Google search shows.
@mithubopensourcelab4822 жыл бұрын
Excellent video.
@derrysan2 жыл бұрын
Just realized that untangle is part of Arista now.
@mithubopensourcelab4822 жыл бұрын
Web filtering is most difficult to manage.
@kchiem2 жыл бұрын
4:46 "but before we get into how we solve that solution.." hmm....
@sebastienloyer94712 жыл бұрын
Filterd ,, stay safe
@melltelae35572 жыл бұрын
untangle has decent filtering for schools and such. looks like Arista owns Untangle.. wonder when that happened!@
@LAWRENCESYSTEMS2 жыл бұрын
They bought them earlier this year
@clarkmakoni9052 жыл бұрын
Yeah, 2nd comment 😁. Hi Tom.
@TechySpeaking2 жыл бұрын
First
@hycron12342 жыл бұрын
So .... no real solution that is free and open source?
@LAWRENCESYSTEMS2 жыл бұрын
Not aware of anything
@hycron12342 жыл бұрын
I might trial Saaslio, Zorus seems like overkill for home use.