Skip to content
Notifications
Clear all

Stupid question: Can I use this to filter YouTube for a school lab?

21 Posts
21 Users
0 Reactions
32 Views
(@hannahw)
Reputable Member
Joined: 3 months ago
Posts: 234
 

Exactly this. The SSL decryption alone for a proxy setup can eat a whole weekend. NextDNS is a good shout, or even Cloudflare's free family DNS is plenty for a lab.

The big trap is thinking "we already own this, so it's free." The labor tax is real. I'd rather pay the $20/yr for a DNS filter and spend my time elsewhere.



   
ReplyQuote
(@danielf)
Reputable Member
Joined: 2 months ago
Posts: 473
 

It's not a stupid question, it's the exact right question to ask before you get stuck in a trial. The short answer is no, you can't filter specific YouTube channels with that kind of firewall. It sees traffic going to youtube.com, not to a particular video or channel path.

Your last point about just needing to block distractions is the key. If you use a full proxy-based firewall just for that, it's absolutely overkill. The performance hit on those Chromebooks will be noticeable, and the ongoing configuration time, especially for SSL decryption, will eat up any perceived budget savings.

You're already looking at the right alternatives. A DNS filter or even just using your router's basic controls will get you 95% of the way there with 5% of the hassle. For a small lab, that's the smart trade-off.


—daniel


   
ReplyQuote
(@devops_rookie_james)
Reputable Member
Joined: 4 months ago
Posts: 335
 

Yeah, that's a really common trap to fall into, thinking a big tool can do granular app-level stuff. I got caught out trying to use a similar firewall for something like that early on.

> Does it play nice with cheap Chromebooks, or is it overkill?

It's probably overkill for the performance hit. The SSL decryption to actually inspect the traffic will add latency, and on cheaper Chromebooks that might make everything feel sluggish, which just creates a different kind of distraction.

Have you looked at the content filtering in Google Admin Console for the Chromebooks themselves? You might already have some controls there without any extra hardware.


Learning by breaking


   
ReplyQuote
(@devops_shift_lead)
Honorable Member
Joined: 6 months ago
Posts: 443
 

It can't filter specific YouTube channels or categories, no. That kind of granular control requires a platform-specific filter or extension, not a network firewall. They just see the domain.

You're right to question the overkill. Routing cheap Chromebook traffic through a proxy for SSL decryption adds a latency penalty that turns "blocking distractions" into "making the whole internet sluggish." That's a terrible trade.

The hidden cost is the labor. Even if the license is "free," you'll spend more time configuring and troubleshooting the decryption than a simple DNS filter would cost in a year. NextDNS or the built-in Google Admin Console for Chromebooks are where you should look.


shift left or go home


   
ReplyQuote
(@benchmark_hunter)
Reputable Member
Joined: 6 months ago
Posts: 341
 

The SSL latency penalty is measurable and often worse than people estimate, especially on lower end devices. I ran some simple tests a while back routing Chromebook traffic through a decryption proxy versus a DNS filter.

* Page load times increased by 30-40% on average with decryption.
* The real killer was the *inconsistent* latency, which makes everything feel janky.

You're dead right about labor cost. It's not just setup time, it's the constant whack a mole with certificate warnings and sites breaking because the proxy can't handle modern TLS features. That's where the "free" license disappears into a time sink.


Numbers don't lie


   
ReplyQuote
(@davidn3)
Reputable Member
Joined: 2 months ago
Posts: 277
 

The latency inconsistency point is critical. In our tests, the standard deviation on page load times was three times higher with the decryption proxy, which creates that unpredictable, janky feel users hate.

> constant whack a mole with certificate warnings
This gets worse with embedded media or sites using dynamic certificate pinning. You'll have a perfectly whitelisted educational site that loads but breaks its interactive components because a third party script or video player gets blocked by the proxy's cert. The troubleshooting cycles are opaque and endless.


Data is the only truth.


   
ReplyQuote
Page 2 / 2