Jump to content

Recommended Posts

Posted

This is posted here as swgfl are slow to get this resolved. I've noticed that using the staffproxy on the swgfl I can view intranet webpages from other schools!

 

Well 2 anyway... they're both on the 10.X range so should be non routable.. but there they are.

 

Does anyone dare give me an ip address to try?

 

I made a hideous mistype of an ip address 3 weeks ago and it lead me to a printer... but it wasn't mine? Curious the printer had a direct print option so I uploaded a pdf with my details... 5 minutes later a worried admin gave me a call! At we thought that some horrible error was made at his end but he asked me to try another schools range and bam another printer I don't own...

 

I'd actually landed on someone else's ruckus AP but don't know who's ...

 

anyhow give me an ip and ill let you know if I can see you.

 

 

if you want to test me the try 10.44.8.7 (you'll get a denied isa if it works) (he couldn't but maybe someone else can)

Posted
This is posted here as swgfl are slow to get this resolved. I've noticed that using the staffproxy on the swgfl I can view intranet webpages from other schools!

 

Well 2 anyway... they're both on the 10.X range so should be non routable.. but there they are.

 

Does anyone dare give me an ip address to try?

 

I made a hideous mistype of an ip address 3 weeks ago and it lead me to a printer... but it wasn't mine? Curious the printer had a direct print option so I uploaded a pdf with my details... 5 minutes later a worried admin gave me a call! At we thought that some horrible error was made at his end but he asked me to try another schools range and bam another printer I don't own...

 

I'd actually landed on someone else's ruckus AP but don't know who's ...

 

anyhow give me an ip and ill let you know if I can see you.

 

 

if you want to test me the try 10.44.8.7 (you'll get a denied isa if it works) (he couldn't but maybe someone else can)

 

Its been like that for years! We moved our internal range away from 10.x to our own range. (if this makes sense)

Posted
A school that I worked at in Milton Keynes was like that. It was useful once when one of the techs who did support at primary schools asked me for some help and I could RDP to her machine but I considered it dangerous otherwise and said so. All it takes is one badly secured school to expose the entire school's network!
Posted

Sigh, I haven't got time for that... It does seem one way and only with http and https. RDP and ping do not work as far as I can tell..

 

Putting myself behind a NAT would do it but I may loose access to other services..

 

Anyone get to my ISA box yet?

Posted
Hmm why haven't they VLAN'ed you all separately I wonder? An Intranet between schools should only be in place if you're either part of a trust, or agree to work closely together etc...
Posted
Sigh, I haven't got time for that...

 

Data security is one of the most important things in IT......

 

Putting myself behind a NAT would do it but I may loose access to other services..

 

No you wouldn't setup properly you wouldn't loose a thing.

Posted

Well I can't get to your server from my end so I'm going to cry :p

 

We used to be able to access our local primary school which was also on the SWGfL which was very handy since we support them as well, but when they updated the firewalls 3 years ago we lost that functionality so had to resort to Logmein, and now via VPN connection.

Posted

There was a time that you could see everything from any school that was connected to any of their networks. We would sometimes be able to connect to printers in a completely different school and print out test pages (if we were so inclined) :) . Not sure if it's still that bad now though as we ditched them a few years back. Shocking setup. That's why we all had to have the IP addresses they assigned to us - you couldn't expand the range without causing a conflict with another school.

 

HBJB

Posted
Back in 2000 when we SWGfL first launched, we were provided documentation with what each schools IP range would be. Not something that would ever be circulated in this day and age, but was quite handy at the time.
  • 3 weeks later...
Posted

If you think that's bad, stick a trial of Procurve manager plus outside your firewall (if you have one, pretty bad if you don't!) and scan the whole 10.x range. We could pickup any device that would respond with an IP using that on the entire SWGfL network back in 2006. Needless to say we put a stop to that pretty quickly!

 

No longer with SWGfL (thank ****), and bored / looking for something to do, hence the rather odd bump :p

  • 3 years later...
Posted

Hi,

 

Resurrecting this old thread as I’ve found the same experience at my school (not swgfl). When testing IP scanning I can see devices on other networks, and without intending to do any harm, have been able to connect to certain devices (even appeared to have found a network printer with no password).

 

My understanding of networking is limited, and I don’t see why this is happening, but it's obviously a concern. Is this something the LA broadband provider should address, or do I need to do something to protect my school, and if so what do you recommend?

Posted
Hi,

 

Resurrecting this old thread as I’ve found the same experience at my school (not swgfl). When testing IP scanning I can see devices on other networks, and without intending to do any harm, have been able to connect to certain devices (even appeared to have found a network printer with no password).

 

My understanding of networking is limited, and I don’t see why this is happening, but it's obviously a concern. Is this something the LA broadband provider should address, or do I need to do something to protect my school, and if so what do you recommend?

 

Back in 2007 when we first noticed the issue on SWGfL the first thing we did was put an ISA firewall between us and the ISP, stopped using the 10.x network provided by SWGfL and made our internal network a 172.x. You would think the ISP would have something between you and their other customers to protect you all but if it's still going on today i imagine they're leaving it down to the individual schools to protect themselves.

  • Thanks 1
Posted
We've not looked for a while, but we used to be able to see the various switches used by our LA as well as the web interfaces of various security cameras across the county.
  • Thanks 1
  • 3 months later...
Posted

We asked them about this issue a couple of days ago and they said that if it was happening it must have been a change that we had requested! Of course we did not request the ability to see other schools or for them to see us.

 

They then generated a firewall audit for us and we have removed any rules that are no longer in use but the issue continues. They don't seem to know what to do about it.

Posted
How did you resolve the issue? It's odd because SWGfL initial reaction was that we were wrong and it wasn't possible unless we requested it. We have not requested it and after a firewall audit we can't really see why it is happening.
Posted
How did you resolve the issue? It's odd because SWGfL initial reaction was that we were wrong and it wasn't possible unless we requested it. We have not requested it and after a firewall audit we can't really see why it is happening.

 

Could it have been requested a long time ago?

 

Thy should have proof that they can show you to back up their comments that it was requested

Posted

I'm gonna guess you're logged into staff proxy? (Or at least using that proxy)

 

Unless they changed something it's an issue with staff proxy as once you're on it you all effectively get merged into the one network. It didn't used to happen if you were on normal proxy.

 

Might have changed but this was certainly the issue a few years back

 

Steve

  • Thanks 1
Posted (edited)

I've been the IT manager at this school for almost 12 years, I've not requested it. It is possible that it was requested before my time but we have had a new range of IP's from SWGfL in that time.

 

As I mentioned we have had a firewall audit and they sent us all of the ACL's for our router, I can't understand why it is allowing this access because it looks ok to me.

 

To be clear, we are able to connect to other schools equipment such as printers, wifi controllers etc. I then asked my other half who is a teacher in a different school (in a different county!) to see if she could access my wifi controller by typing in it's IP. She could :(

 

I think it may be an idea to introduce a firewall between the router and our network as clearly the SWGfL are not setting up the routers correctly.

 

I guess it's my bad really, I should have checked this earlier but you kind of assume that people you are paying large amounts of money for the connection are doing it correctly. It would be better if we could configure our own Cisco router.

Edited by MatZeRO
Posted (edited)
I've been the IT manager at this school for almost 12 years, I've not requested it. It is possible that it was requested before my time but we have had a new range of IP's from SWGfL in that time.

 

As I mentioned we have had a firewall audit and they sent us all of the ACL's for our router, I can't understand why it is allowing this access because it looks ok to me.

 

To be clear, we are able to connect to other schools equipment such as printers, wifi controllers etc. I then asked my other half who is a teacher in a different school (in a different county!) to see if she could access my wifi controller by typing in it's IP. She could :(

 

I think it may be an idea to introduce a firewall between the router and our network as clearly the SWGfL are not setting up the routers correctly.

 

I guess it's my bad really, I should have checked this earlier but you kind of assume that people you are paying large amounts of money for the connection are doing it correctly. It would be better if we could configure our own Cisco router.

 

Sounds like they haven't set any acl for their networks gateway which then is allowing routing between subsets on the wan. Definitely recommend introducing your own firewall or even better move away from their network. This would, in my opinion, be a breach of data protection, it enables any body who has infiltrated another schools system to internally attack other schools networks. Very serious and poor response by your gfl provider.

Edited by forkies
Posted

If it was a swglf wide issue everyone would be able to access everything. Speak directly to RM and see what they say. If not make sure it isn't something your LEA has put in place.

 

I had the access removed straight away. I spoke to the help desk based in my local authority and they told me it was my predecessor!

 

My current school is with EXA but my previous was with the grid and I couldn't access any of the other schools I supported who were also on the grid.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...