Jump to content

Recommended Posts

Posted
We usually find out about these by hook or by crook; rarely get the time to go along though! Thankfully we've had a lot of dealings with them so have been able to get the information we need beforehand. (also in Northants)
Posted

Well got an official response. Apparently No HTTPS sites can have the block page anymore!....

 

Now to look at going to smoothwall! Such faff!

 

On the plus side... They have finally fixed all the existing issues.

 

Seems weird how they can now still be viable... If a page is blocked I want a block page... How can an filtering solution still be viable if there is no block page anymore!

 

Anyway thanks for the replies all.

 

Matt

Posted

Morning @Edu-IT, @synaesthesia and @mtayloronline

 

Just to confirm this isn't all HTTPS sites at all. The vast majority still get the blocked page.

 

Its a rather complex issue that involves the SSL protocol, wildcard certificates and new interpretations of how these are implemented on certain sites when using filters in a layer 2 bridge mode (as we do by default as using layer 2 bridge has lots of advantages over a filter in proxy mode). My current understanding is that this isn't just a Lightspeed issue and is effecting multiple vendors.

 

I've one of my senior NOC engineers writing a technical white paper on the issue which I should have by the end of the day and will post once completed.

 

Thanks

 

Dave

Posted (edited)
Thanks @SchoolsBroadband; always good to get all sides of a story hence asking for input rather than jumping down anyone's throat :) I imagine from what you say it may well be something we experience from time to time with the Fortinet filter; but it's rare. Looking forward to that whitepaper, as I wonder if it's related to how rare it is to get proper wildcard SSL certificates done these days (which I have little doubt is for the best now, with all the SSL hacks/issues/vulnerabilities that are getting publicised a lot recently) Edited by synaesthesia
  • 2 weeks later...
Posted

Is he still making this white paper?

 

Morning @Edu-IT, @synaesthesia and @mtayloronline

 

Just to confirm this isn't all HTTPS sites at all. The vast majority still get the blocked page.

 

Its a rather complex issue that involves the SSL protocol, wildcard certificates and new interpretations of how these are implemented on certain sites when using filters in a layer 2 bridge mode (as we do by default as using layer 2 bridge has lots of advantages over a filter in proxy mode). My current understanding is that this isn't just a Lightspeed issue and is effecting multiple vendors.

 

I've one of my senior NOC engineers writing a technical white paper on the issue which I should have by the end of the day and will post once completed.

 

Thanks

 

Dave

Posted
Are @SchoolsBroadband able to offer Lightspeed filtering to 'off network' schools - schools who don't have broadband with you - or is this not possible?

 

Further to this question, i'd also like to ask @SchoolsBroadband if current customers can ditch the filtering and just stay as a firewall + leased line option (or even just leased line?)? ....obviously i mean when the contract term ends and depending on whether the customer renews. Basically is it easily adapted to what particular parts a school wants similar to what edu-it asks?

Posted (edited)

Well today an email has gone around saying that Google safe search is not going to be working from december and might bring back unsafe results... Can't wait for the kids to click onto that one!....

 

Seriously what the F is going on with Google!!!

Edited by witch
Posted
That's a Google caused problem @mtayloronline - Google are scrapping "non-ssl" search, which means the only way to ensure safe search is for filtering solutions to engage in a man in the middle attack, but that requires all the endpoints to have a custom certificate installed so that the browsers don't scream about it being unsafe.
Posted
That's a Google caused problem @mtayloronline - Google are scrapping "non-ssl" search, which means the only way to ensure safe search is for filtering solutions to engage in a man in the middle attack, but that requires all the endpoints to have a custom certificate installed so that the browsers don't scream about it being unsafe.

 

After posting i figured it probably was.. Just all bad timing for schools broadband i guess.

  • 2 weeks later...
Posted

Hi Matt,

 

we're still in discussions with Lightspeed as we have multiple ways of doing this all which impact customers in a different way and with over 1,000 schools we have to get it right first time and give a clear and consistent message. Please have patience and we'll send through the official channels.

 

Thanks

 

Dave

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...