Opendium_Steve Posted November 12, 2015 Posted November 12, 2015 Why was there an issue with Google SSL ? Our LA use netsweeper and saw no issues with google SSL. I'm not sure whether this is specifically what @JGoswell is talking about, but originally Google used to have a mechanism to force searches to be unencrypted so that filtering systems could filter them. Unfortunately, some wifi hotspot providers took to abusing that mechanism to inject advertising into Google pages so Google pulled the feature and replaced it. The replacement system allowed schools to force safesearch on whilst keeping the searches encrypted. Safe search is only part of what many schools want though - schools often want additional protection from their own filters, audit logs, etc. and all of this requires intercepting the encryption. Whilst many filter systems have supported HTTPS interception for years, it seems that the systems used by the regional broadband consortia often didn't, or at least required major changes to support it. To be completely fair, HTTPS interception does require significantly more resources than filtering HTTP traffic so its not unreasonable to need to upgrade hardware, etc. to support it. However, I'm aware that some LEAs sent memos around to schools saying that they would no longer be able to offer any filtering for Google searches (I sincerely hope that they've upgraded by now though!). The SWGFL introduced SSL interception for Google just before the summer I think. Also, I was advised by one company that the issue of Google Translate being an open proxy and that is was a known issue with ALL filtering solutions. I think that's a simplification anyway. Some filtering systems rely on nothing bug a big URL database and they have big problems with Google Translate, others also do content analysis to categorise sites. Whilst not perfect, the latter type of filter will offer more protection to Google Translate abuse.
JGoswell Posted November 12, 2015 Posted November 12, 2015 Hi @ITGURU, Regarding Google SSL, essentially, yes, what @SteveHill just said - we've an explanation here: Changes to Google SSL and RM SafetyNet | RM Education - What we do And with that, I've got to go. Jamie @ RM
SchoolsBroadband Posted November 12, 2015 Posted November 12, 2015 Well people walk with their feet. We've had a lot of annoyed SWGFL customers join us this year. If a service keeps on breaking that you rely on and pay a small fortune for then leave. Whether that be to us or another provider. We've had 100% uptime i the last 18 months whether that be proxy, firewall or core network. Also why are changes made in the day time?! We ban anything but the highest level of emergency maintenance for anything happening in the day time. All upgrades are done in the early hours of the morning which makes sense so if it goes wrong people are not affected....
pirran Posted November 20, 2015 Posted November 20, 2015 Our feet are moving, not fast enough for my liking due to contracts. Yet again today, transparent proxy will not allow Outlook to connect to 365 and users can't even access the 365 website. Tested externally, tested on non-transparent proxy = fine. Connection issues are sporadic with some machines working others whilst others don't. No notification of issues from RM and this is the 'new higher capacity service' (I've lost track of the number of times I've been told it's been improved). It looks like we're going to manage to get a smoothwall UTM in place before the end of our SWGFL contract and then request a bypass for the proxy farm. RM or @AJWhite1970 how about refunds for a service not being provided?
witch Posted November 20, 2015 Posted November 20, 2015 Sorry to swim against the tide, but I have had very few problems with the SWGfL filtering or proxy and we are pretty happy really 1
Boredguy Posted November 20, 2015 Posted November 20, 2015 Can't say we've had any major issues recently. I'll be shopping around in the next month ready for the renewal that is due in August but on the whole there is nothing that is making us say "We must move"
JGoswell Posted November 20, 2015 Posted November 20, 2015 Hi @pirran I'm sorry you've experienced an issue this morning. I understand Chris in our support team spoke with a colleague of yours this morning. As you might now know, we were unable to find a solution-wide problem and we’ve had no similar reports from other schools – given your issue was with O365, we’d expect to have heard about it pretty quickly if others were experiencing the same thing. We’re going to send over some suggestions about how to find the root of the issue – there’s a tool you could put on a machine on your network to capture info and track it down. If the problem reoccurs, please do give us a call, as we’d of course like to help if we can. Jamie @ RM
localzuk Posted November 20, 2015 Author Posted November 20, 2015 I've had a call open for 2 weeks, and only today did someone actually pay attention to the problem we're having. My earlier date/time/proxy server details were ignored and now I have to go hunting for another user experiencing the same problem so I can report it again! Its a bit of a major issue as well, as some users are currently getting unfiltered YouTube!
JGoswell Posted November 20, 2015 Posted November 20, 2015 (edited) Hi @localzuk It’s can be hard to identify customers on the forum because of usernames but I think we’ve identified your support number and I’ll pick this up directly with our engineer – apologies for the delay. It seems the issue is at least partly related to Google’s recent withdrawal of its schools YouTube service. We informed all schools that use the service about this by email. We’ll be following that up with another email shortly linking to an FAQ explaining what’s happened. You can see the information we’ve already provided here: RM Education Jamie @ RM Edited November 20, 2015 by JGoswell
Steve21 Posted November 27, 2015 Posted November 27, 2015 Pew pew goes the DDOS ARGGGH death.... Goes the SWGFL! Steve 2
Boredguy Posted November 27, 2015 Posted November 27, 2015 And there I was thinking it was just cause I was sending ya a PM
Steve21 Posted November 27, 2015 Posted November 27, 2015 And there I was thinking it was just cause I was sending ya a PM Haha slacking at work detected! NUKE Steve
JGoswell Posted November 27, 2015 Posted November 27, 2015 (edited) Hi all, Yes, that was an unusually large DDOS attack. A couple of customers did notice the affects for a few minutes but our new DDOS mitigation system had by then kicked in and neutralised the attack in short order. Jamie @ RM Edited November 27, 2015 by JGoswell
Gibson335 Posted December 9, 2015 Posted December 9, 2015 Zen Internet. Best thing we ever did. However I have heard good reports about @SchoolsBroadband We're moving to Zen Internet next year I think. Glad to see them mentioned on here so positively.
localzuk Posted January 7, 2016 Author Posted January 7, 2016 Yup. Experiencing some very odd behaviour @Steve21. 1
Steve21 Posted January 7, 2016 Posted January 7, 2016 *stab stab* Ah well, at least it's nothing broke on my end haha Steve
AJWhite1970 Posted January 7, 2016 Posted January 7, 2016 Investigating - We are aware a small number of customers are experiencing degraded browsing performance in SWGfL. Our engineers are working on resolving this as a priority Good job it's only a small number!!!!
Boredguy Posted January 7, 2016 Posted January 7, 2016 Shame the status page only shows them investigating from 10:25 though (and it only just refreshed on my rss feed)
Oaktech Posted January 7, 2016 Posted January 7, 2016 Still high latency here... But it's OK, my FTTC was installed over Christmas, I'll be on a new 80/10mbps FTTC connection by monday morning and I'll be able to remove my sub to this page! My 100mbps symetric leased line is still dragging on because of civil engineering difficulties.
localzuk Posted January 7, 2016 Author Posted January 7, 2016 Update from SWGfL. The degraded performance being experienced by a number of customers is due to a DDoS attack against a specific school within our network. Steps are being taken to block the attack.
newpersn Posted January 7, 2016 Posted January 7, 2016 The degraded performance being experienced by a number of customers is due to a DDoS attack against a specific school within our network. Steps are being taken to block the attack A specfic school?!?!
Opendium_Steve Posted January 7, 2016 Posted January 7, 2016 Yes, We've got several schools currently with ~90% packet loss on their SWGFL connections (doesn't appear to be a proxy issue, just a connectivity issue). Helpfully RM said "No one else has reported a problem" when they phoned them...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now