Remix.run Logo
kccqzy 4 hours ago

That’s usually done not on the network side but through the device itself. Think MDM and endpoint management.

ocdtrekkie 4 hours ago | parent [-]

A good solution is tackling it on both. At work we have network level firewalls with separate policies for internal and guest networks, and our managed PCs sync a filter policy as well (through primarily for when those devices are not on our network). The network level is more efficient, easier to manage and troubleshoot, and works on appliances, rogue hardware, and other things that happen not to have client management.

ekr____ 3 hours ago | parent [-]

Well, if you have MDM you should be able to just disable ECH.

ocdtrekkie 3 hours ago | parent [-]

This is also indeed done on both. Browser policies.