ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Web filtering for SMB

    IT Discussion
    9
    17
    899
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AdamFA
      AdamF
      last edited by

      Does anyone use Web filtering in the SMB space ? If so, what is recommended for a small (less than 10 person) office? A Ubiquiti Edge router is on the edge, but if you would want to then filter web traffic through a box that filters and also monitors, what are people using? I previously used untangle back in the day, but have not worked with any web filters since then. 100% not interested in a UTM.

      1 Reply Last reply Reply Quote 1
      • DustinB3403D
        DustinB3403
        last edited by

        Are you looking to block content, like online gambling, porn etc? PiHole does an amazing job out of the gate and makes it pretty easy to do this if you want something quick and simple to setup and maintain.

        AdamFA 1 Reply Last reply Reply Quote 0
        • travisdh1T
          travisdh1
          last edited by

          Easiest, fastest, use Cloudflare DNS
          1.1.1.2 and 1.0.0.2 blocks known malware sites
          1.1.1.3 and 1.0.0.3 blocks malware and porn sites

          PiHole is good if you want an easy local solution.

          AdamFA 1 Reply Last reply Reply Quote 3
          • AdamFA
            AdamF @DustinB3403
            last edited by

            @DustinB3403 said in Web filtering for SMB:

            Are you looking to block content, like online gambling, porn etc? PiHole does an amazing job out of the gate and makes it pretty easy to do this if you want something quick and simple to setup and maintain.

            I use Pi-Hole at my house. Good idea. I'm looking to block accidental stuff. Want to do what I can to keep malware, etc out as much as possible.

            scottalanmillerS 1 Reply Last reply Reply Quote 1
            • AdamFA
              AdamF @travisdh1
              last edited by

              @travisdh1 said in Web filtering for SMB:

              Easiest, fastest, use Cloudflare DNS
              1.1.1.2 and 1.0.0.2 blocks known malware sites
              1.1.1.3 and 1.0.0.3 blocks malware and porn sites

              PiHole is good if you want an easy local solution.

              That's great. I didn't know they came out with 1.1.1.3. That's awesome!

              1 Reply Last reply Reply Quote 1
              • dbeatoD
                dbeato
                last edited by

                I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                black3dynamiteB scottalanmillerS 2 Replies Last reply Reply Quote 0
                • T
                  thecreaitvone91
                  last edited by thecreaitvone91

                  Back in My SMB days I used NxFilter. You point your clients DNS to it (I did it using DHCP) and you can still use it if you have a domain, I just setup Zone Transfers from the AD DNS to Nxfilter, I had them setup in a failover pair. Does AD authentication for Group Lists of allowed/block sites, reporting etc. You'd normally block client devices from using Port 53 so they couldn't do their own lookups on your firewall.

                  https://nxfilter.org/p3/

                  DashrenderD 1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @thecreaitvone91
                    last edited by

                    @thecreaitvone91 said in Web filtering for SMB:

                    Back in My SMB days I used NxFilter. You point your clients DNS to it (I did it using DHCP) and you can still use it if you have a domain, I just setup Zone Transfers from the AD DNS to Nxfilter, I had them setup in a failover pair. Does AD authentication for Group Lists of allowed/block sites, reporting etc. You'd normally block client devices from using Port 53 so they couldn't do their own lookups on your firewall.

                    https://nxfilter.org/p3/

                    A zone transfer instead of just making the NXfilter the upstream DNS for AD's DNS?

                    T 1 Reply Last reply Reply Quote 0
                    • T
                      thecreaitvone91 @Dashrender
                      last edited by

                      @Dashrender said in Web filtering for SMB:

                      @thecreaitvone91 said in Web filtering for SMB:

                      Back in My SMB days I used NxFilter. You point your clients DNS to it (I did it using DHCP) and you can still use it if you have a domain, I just setup Zone Transfers from the AD DNS to Nxfilter, I had them setup in a failover pair. Does AD authentication for Group Lists of allowed/block sites, reporting etc. You'd normally block client devices from using Port 53 so they couldn't do their own lookups on your firewall.

                      https://nxfilter.org/p3/

                      A zone transfer instead of just making the NXfilter the upstream DNS for AD's DNS?

                      You couldn't do Groups or custom filters or reporting if you did it that way as all requests would be coming from the DC itself.

                      1 Reply Last reply Reply Quote 0
                      • black3dynamiteB
                        black3dynamite @dbeato
                        last edited by

                        @dbeato said in Web filtering for SMB:

                        I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                        Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                        DustinB3403D JaredBuschJ 2 Replies Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403 @black3dynamite
                          last edited by

                          @black3dynamite said in Web filtering for SMB:

                          @dbeato said in Web filtering for SMB:

                          I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                          Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                          That's what I'd do.

                          1 Reply Last reply Reply Quote 0
                          • JaredBuschJ
                            JaredBusch @black3dynamite
                            last edited by

                            @black3dynamite said in Web filtering for SMB:

                            @dbeato said in Web filtering for SMB:

                            I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                            Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                            This will only work for another year or so. Most browsers are going to default to DNS over HTTPS soon.

                            black3dynamiteB DashrenderD 2 Replies Last reply Reply Quote 0
                            • black3dynamiteB
                              black3dynamite @JaredBusch
                              last edited by

                              @JaredBusch said in Web filtering for SMB:

                              @black3dynamite said in Web filtering for SMB:

                              @dbeato said in Web filtering for SMB:

                              I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                              Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                              This will only work for another year or so. Most browsers are going to default to DNS over HTTPS soon.

                              Yeah, I forgot about that.

                              1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @JaredBusch
                                last edited by Dashrender

                                @JaredBusch said in Web filtering for SMB:

                                @black3dynamite said in Web filtering for SMB:

                                @dbeato said in Web filtering for SMB:

                                I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                                Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                                This will only work for another year or so. Most browsers are going to default to DNS over HTTPS soon.

                                This is overridable. So for business it something you can overcome.
                                And MS is also working to update their DNS to be DNS over HTTPS... just need PI Hope to follow suit... then the browser will stick with the DHCP provided DNS.

                                JaredBuschJ 1 Reply Last reply Reply Quote 0
                                • JaredBuschJ
                                  JaredBusch @Dashrender
                                  last edited by

                                  @Dashrender said in Web filtering for SMB:

                                  @JaredBusch said in Web filtering for SMB:

                                  @black3dynamite said in Web filtering for SMB:

                                  @dbeato said in Web filtering for SMB:

                                  I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                                  Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                                  This will only work for another year or so. Most browsers are going to default to DNS over HTTPS soon.

                                  This is over rideable. So for business it something you can’t overcome.
                                  And MS is also working to update their DNS to be DNS over HTTPS... just need PI Hope to follow suit... then the browser will stick with the DHCP provided DNS.

                                  Can you edit that to English?

                                  1 Reply Last reply Reply Quote 1
                                  • scottalanmillerS
                                    scottalanmiller @AdamF
                                    last edited by

                                    @fuznutz04 said in Web filtering for SMB:

                                    @DustinB3403 said in Web filtering for SMB:

                                    Are you looking to block content, like online gambling, porn etc? PiHole does an amazing job out of the gate and makes it pretty easy to do this if you want something quick and simple to setup and maintain.

                                    I use Pi-Hole at my house. Good idea. I'm looking to block accidental stuff. Want to do what I can to keep malware, etc out as much as possible.

                                    Pi-Hole + CloudFlare DNS goes a long way. And free.

                                    1 Reply Last reply Reply Quote 2
                                    • scottalanmillerS
                                      scottalanmiller @dbeato
                                      last edited by

                                      @dbeato said in Web filtering for SMB:

                                      I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                                      He said his goal was accidents. DNS filtering is perfect for accidents.

                                      1 Reply Last reply Reply Quote 3
                                      • 1 / 1
                                      • First post
                                        Last post