PDA

View Full Version : Untangle use in small company?


Vallan
07-06-2007, 09:35 AM
First I’d like to say WOW! What an amazing looking product. I was stunned that there was something this cool available open source.

I’m hoping someone can clarify how untangle can work for me.

I work for a small company with 15 computer users that periodically like to infect their computers with spyware or viruses out of ignorance or stupidity. (Should you really have to tell the 40+ yr old guy not to open the attachment offering you a peek at Britney Spear’s hoohoo?)

Right now we have users checking work email via our ISP and downloading emails to their own copies of outlook. Some also get email via webmail interface. I am guessing my next steps should be

Implement Untangle for the spyware and web content filtering - seems obvious

Anti-virus - ??? Will untangle strip the viruses from web emails and/or from downloads from our ISP (the emails reside on their servers, we don’t have an email server) OR should I be trying to setup an email server (saw a reference to Zimbra from the Untangle company founders story). I’d assume that would mean I need a way to get all of the emails from our ISP to an internal server or less desirable to actually host an email server.

Then you need to figure out how to block users from downloading their viruses from home accounts?

Can anyone give me some advice? The simpler and cheaper the solution the better until we get big enough to hire some IT guys. Again, amazing product!

richie
07-06-2007, 10:31 AM
Hi.

If virus blocker is installed, it can scan web, mail ( smtp, pop, imap) and ftp. You can also select extensions ( i.e. exe, com,bat, doc, etc. ) under web traffic.

Vallan
07-06-2007, 11:30 AM
That would be fantastic if I didn't have to install anything else! Zimbra looks very nice, but I'm really just want to keep everything up and running so we can focus on the work that pays our salaries. When I read the founders story about the need for a product like Untangle for small companies I thought, "hey! They're describing us!"

Love the user interface (I know a good GUI interface can take as long to design as the product itself).

:)

ahang
07-06-2007, 12:54 PM
Hi, I have similar needs at my company (an insurance company with about 200 users). Unfortunately during testing I have had mixed results. I have attempted configuring a test system or two on older machines. The first one is a Dell Poweredge 1650 and the second is a Dell GX240. Both are machines I just have lying around. The poweredge has 3 NIC's and the GX240 has just one. The GX240 loaded easily and seems to work okay, although it is a little slow. The Poweredge just reboots constantly and I have tried both the stable release and the beta version that was just released. Vallan, what kind of hardware are you using for your tests? Have you had any problems with configuring the software?


Thanks,

Vallan
07-06-2007, 02:39 PM
ahang,

you're further along than I am. I just burned my ISO this afternoon. I really only have 2 existing file servers in my company. Everything else is desktops. I'll probably order a barebones kit to get a test box to try out Untangle. I like the idea of running the box in an "observation" mode for a few weeks and let it log the traffic so I can get an idea of what's going on in our network before I get creative and implement.

Then I imagine I'll go live on a Friday after lunch and see if there is any screaming or yelling.

ahang
07-09-2007, 10:22 AM
Vallan, as of right now I'm pretty much leaning against any deployment of this product for my company. I really wanted this product to work though, it just doesn't seem there yet.

The main reason I wanted this system was that we are primarily a Windows shop and I come from a Linux/Unix background. This product with a polished and easy to use GUI seemed like a good tool that could be easily integrated by our staff(mostly MCSE's) Unfortunately the polish doesn't seem quite there yet.

My gripes:
- surprisingly slow for a barebones debian install.
- i cannot get apps to install, get an unknown error(maybe the store was down).
- the install reboots one of my test machines repeatedly.
- i cannot believe this is version 4.2 and 5.0 of a software package, it doesn't seem that evolved yet.


I would like to revisit this software in a few months, I still have high hopes and really like the concept. Good luck in your evaluation.

dmorris
07-09-2007, 04:03 PM
Vallan, as of right now I'm pretty much leaning against any deployment of this product for my company. I really wanted this product to work though, it just doesn't seem there yet.

The main reason I wanted this system was that we are primarily a Windows shop and I come from a Linux/Unix background. This product with a polished and easy to use GUI seemed like a good tool that could be easily integrated by our staff(mostly MCSE's) Unfortunately the polish doesn't seem quite there yet.

My gripes:
- surprisingly slow for a barebones debian install.
- i cannot get apps to install, get an unknown error(maybe the store was down).
- the install reboots one of my test machines repeatedly.
- i cannot believe this is version 4.2 and 5.0 of a software package, it doesn't seem that evolved yet.


I would like to revisit this software in a few months, I still have high hopes and really like the concept. Good luck in your evaluation.

sorry, to hear about your experiences...

out of curiousity - did you ever get the apps to install?
were you using 4.2 or the 5.0 beta?
what happened when you clicked on the app on the left?

ahang
07-10-2007, 02:36 PM
sorry, to hear about your experiences...

out of curiousity - did you ever get the apps to install?
were you using 4.2 or the 5.0 beta?
what happened when you clicked on the app on the left?

I finally got apps to install yesterday, what ports do you guys use for the install?
- it was some unknown error, generic contact system admin message. maybe a message stating ports xxx cannot be reached would be helpful.

Versions were both 4.2 and 5.0beta, the main problem i have now is my dell 1650 which still reboots constantly. maybe something to do with the scsi drivers.

i will install it on a few other dell test machines and see if it works, had you guys had problems with certain types of hardware before?

anyway, i will be surprised to see how the product looks in a few months after beta version 5 has been out for a while.

dmorris
07-10-2007, 03:19 PM
It uses port 80 and port 443 to talk to the library.
(It gets proxied through the untagle server first)

Not sure what happened...

The installer is based on knoppix with a 2.6.18 kernel.
So some of the newer hardware doesn't work yet, either with the version of knoppix we use or the kernel we are using.

hescominsoon
09-01-2007, 09:35 AM
It uses port 80 and port 443 to talk to the library.
(It gets proxied through the untagle server first)

Not sure what happened...

The installer is based on knoppix with a 2.6.18 kernel.
So some of the newer hardware doesn't work yet, either with the version of knoppix we use or the kernel we are using.

What is your kernel configuration? You mention 2.6.18. Do you backport security patches back into your kernel tree or do you stay with the knoppix kernel or is your kernel customized for your application?

hescominsoon
09-01-2007, 09:39 AM
Vallan, as of right now I'm pretty much leaning against any deployment of this product for my company. I really wanted this product to work though, it just doesn't seem there yet.

The main reason I wanted this system was that we are primarily a Windows shop and I come from a Linux/Unix background. This product with a polished and easy to use GUI seemed like a good tool that could be easily integrated by our staff(mostly MCSE's) Unfortunately the polish doesn't seem quite there yet.

My gripes:
- surprisingly slow for a barebones debian install.
- i cannot get apps to install, get an unknown error(maybe the store was down).
- the install reboots one of my test machines repeatedly.
- i cannot believe this is version 4.2 and 5.0 of a software package, it doesn't seem that evolved yet.


I would like to revisit this software in a few months, I still have high hopes and really like the concept. Good luck in your evaluation.

do you get any messages on the console or is there anything in the logs? The 1650 is plenty "old" enough so it should work. Have you tried passing noapic and no acpi to the kernel at startup?

dlasher
12-14-2007, 03:31 PM
RE: Dell 1650 -- having the same issue

If you turn on all the logging, you'll see if fails to mount root at /dev/sda1

"cannot open root device "sda1"

I'm not sure what modules need to be loaded, that load during the install, but not at this point in the boot.

I can boot off a centos "rescue" CD, mount the file system, move around, it all looks fine. aacraid and aic7xxx are in the modules.conf

not sure what the issue is.. :(

dlasher
12-14-2007, 05:29 PM
Found this in a thread, about the same issue: (Found here: http://forums.untangle.com/showthread.php?t=167)


by default (in untangle) the 3ware card is compiled in as a module.. so the only way you can boot to it is if the module is in initrd, which in untangle's case, isnt.
So you'll have to recompile the kernel on another machine, and make sure the 3ware drivers arnt modules.

The kernel untangle installer uses is completely different from what actually gets installed, which is why you can see that drive (or the array) from the installer CD..


How do you force the modules to load on boot? Can you add it to the grub options? Maybe copy over the kernel from the install CD?

Seattle_mgr
12-15-2007, 12:30 AM
I've done about six installations, most for testing on a variety of different platforms, including a latitude 500 laptop that I have in my home lab. I have not had any hardware problems to date, nor any of our other full deployments (9 to date.)


----------
- surprisingly slow for a barebones debian install.
- i cannot get apps to install, get an unknown error(maybe the store was down).
- the install reboots one of my test machines repeatedly.
---------------
I have not experienced any of the above: quite the opposite