Old 10-24-2011, 09:51 AM   #1 (permalink)
Newbie
 
Join Date: Oct 2011
Location: Las Vegas, Nevada USA
Posts: 14
BRR_IT is on a distinguished road
Question Policy Design

Hello Everyone,

I need a little help with our policy design. Here's what I am trying to achieve.

I want a "Default" rack that hosts
  • Spam Blocker
  • Phish Blocker
  • Spyware Blocker
  • Web Filter Lite (block social media, gambling, etc)
  • Virus Blocker
  • Attack Blocker
  • Intrusion Prevention
  • Ad Blocker
  • Firewall
  • Protocol Control

I have a series of other racks that are linked to specific sets of users. So for example we have our CEO's on a "presidents rack". They will get more access to the internet and should have social media unblocked.

Right now I have the "presidents rack" using the Default rack as a parent. When I install Web Filter Lite, and put *.* in the pass list, the "presidents" are still blocked from Facebook, etc. I think the parent rack is the issue.

Basically I have a set of rules that should apply to everyone, unless we have special rules for that employee/group.
BRR_IT is offline  
Old 10-24-2011, 09:53 AM   #2 (permalink)
Untangle Ninja
 
hlarsen's Avatar
 
Join Date: Jul 2010
Location: sfba
URLs submitted: 1
Posts: 1,139
hlarsen is on a distinguished road
Default

you're doing it right.

have you verified they are actually going to that rack? you can use the Session Viewer (from the rack selection dropdown) to check, or just find what Event Log their traffic is showing up in.
__________________
Attention: Support on the Untangle Forums is provided by volunteers and community members.
If you need official Untangle support please call or email support@untangle.com.
hlarsen is offline  
Old 10-24-2011, 10:13 AM   #3 (permalink)
Master Untangler
 
jcoehoorn's Avatar
 
Join Date: Mar 2010
Location: York, NE
Posts: 475
jcoehoorn is on a distinguished road
Default

I'd pull intrusion prevention out of the default rack, and only use that particular item on a rack reserved for your servers.
__________________
Three time Microsoft ASP.Net MVP managing an IBM System x3250 / X3440 / 8GB with Untangle 9.2 to protect 40Mbits for 450+ residential college students and associated staff and faculty
jcoehoorn is offline  
Old 10-24-2011, 10:20 AM   #4 (permalink)
Newbie
 
Join Date: Oct 2011
Location: Las Vegas, Nevada USA
Posts: 14
BRR_IT is on a distinguished road
Default

Quote:
Originally Posted by hlarsen View Post
you're doing it right.

have you verified they are actually going to that rack? you can use the Session Viewer (from the rack selection dropdown) to check, or just find what Event Log their traffic is showing up in.
Ok, I am going to try the setup again and see what happens. Thanks for the help!
BRR_IT is offline  
Old 10-24-2011, 10:24 AM   #5 (permalink)
Newbie
 
Join Date: Oct 2011
Location: Las Vegas, Nevada USA
Posts: 14
BRR_IT is on a distinguished road
Default

Quote:
Originally Posted by jcoehoorn View Post
I'd pull intrusion prevention out of the default rack, and only use that particular item on a rack reserved for your servers.
Are there any specific benefits to this? I have noticed it has "blocked" a few things, but from what I can tell it usually websites that people are visiting, or from IMAP connections to our mail server. All of the "blocks" originate from our users and not our servers. Just wondering.
BRR_IT is offline  
Old 10-24-2011, 10:49 AM   #6 (permalink)
Newbie
 
Join Date: Oct 2011
Location: Las Vegas, Nevada USA
Posts: 14
BRR_IT is on a distinguished road
Default

Inside Policy manager, I am able to reorder the policies. Does the order of the policies matter? Right now I have the default rack at the bottom, but it doesn't seem to be blocking anything. When I move it to the top, it blocks everything, but doesn't unblock for the specific users we want it to unblock for.
BRR_IT is offline  
Old 10-24-2011, 10:56 AM   #7 (permalink)
Untangle Ninja
 
hlarsen's Avatar
 
Join Date: Jul 2010
Location: sfba
URLs submitted: 1
Posts: 1,139
hlarsen is on a distinguished road
Default

yes, they match from the top down - if a rule matches, it will send the match to the rack specified. you don't need a rule for the default rack, anything that doesn't match a policy will go to the default rack.

all the policies do is send traffic to a rack, it's the apps in the racks themselves that do the filtering. we have a good example of multiple policies on our wiki here, or you can call support.
__________________
Attention: Support on the Untangle Forums is provided by volunteers and community members.
If you need official Untangle support please call or email support@untangle.com.
hlarsen is offline  
Old 10-24-2011, 11:14 AM   #8 (permalink)
Newbie
 
Join Date: Oct 2011
Location: Las Vegas, Nevada USA
Posts: 14
BRR_IT is on a distinguished road
Default

Quote:
Originally Posted by hlarsen View Post
we have a good example of multiple policies on our wiki
Ahhh.. I see in the Wiki, that both policies have the "proxy" filter selected. I was trying to have a set of categories on the default rack apply to all child racks, but reading into it seems like that won't work. On the child rack, I'll need all the same settings I have on my default. Is that correct?

That's kind of a bummer because I have 11 different child racks and there is only minor web filter differences between them. And if I want to make a change globally (let say to accept a domain for every employee) I'd have to open the 11 child racks and add the domain.
BRR_IT is offline  
Old 10-24-2011, 11:16 AM   #9 (permalink)
Untangle Ninja
 
hlarsen's Avatar
 
Join Date: Jul 2010
Location: sfba
URLs submitted: 1
Posts: 1,139
hlarsen is on a distinguished road
Default

when you add a new Web Filter to a child rack, that's the only Web Filter that matters for that rack - all settings are copied from the greyed out apps only. you can import/export pass/block lists between the filters, but you'll need to change them each individually (as well as set categories individually).
__________________
Attention: Support on the Untangle Forums is provided by volunteers and community members.
If you need official Untangle support please call or email support@untangle.com.
hlarsen is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:47 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2