Jump to content

Recommended Posts

Posted
This is coming in a couple of months to smoothwall, i saw a preview of their safeguarding stuff (@dan_at_smoothwall & @CJF correct me if im wrong) and it looked good. It can also be set up to schedule emails to specific users on who, when and what was searched.
Posted

I have 4 reports (Weapons, Terrorism, Violence and Pronography) a week sent, with Users with "Top Hits" for certain categories. They are emailed me on a Friday afternoon and I deal with issues from there.

 

So far the only category that gets hits is Pornography which is in 99% of ases so far false positives, from innocent images being blocked in image searches. Haven't had anyone getting hits on the other categories yet...

 

I do like the idea of a seperate block page for PREVENT categories though, I might look into that!

Posted

How do you get it to link category to students? Found the way to do students hits, and categorys on their own but not linked :s So like 10 hits from Jim in Terrorism, and 6 to Jill etc or isn't doable? (or am I being blind this morning)

 

Steve

Posted

Go to reporting, then Custom. Fill int eh anme and all that a stuff.

 

Under sections choose User Activity, then on the "User Activity" section, on the Options, I have Display top "20", Unit "Hits", Category (whichever you want). For group I use everybody (I don't limit to students).

 

Then on Advanced choose DENIED and DENIED POST

  • 11 months later...
Posted

Out of interest how are people dealing with TLS/SSL traffic monitoring / filtering in the dawn of secure web searches?

Are you concerned about the black hole of data ? Given the `prevent` guidelines

 

Where students are logging into the educational network if monitoring SSL are you enforcing certificates on to their personal devices ?

 

I believe we are expecting an inspection this year and trying to capture as much as possible to ensure that our technological solution is going to be compliant, or if we exceed requirements?

 

Our web filtering solution is due to expire mid year so would also be really useful to get feedback as to working solutions that have been through an inspection and were proven to be excellent.

Posted

Secure web searches stop you seeing what they type in the full URL they go on is usally visible.

 

That said, we have HTTPS decrypt and inspect on all our students, we don't have issues with personal devices as students don't have them on the WiFi and if they did then yes I would force decrypt and inspect on them as well, even if it required me to make them install a certificate.

 

We are moving to have out current Smoothwall setup moved to be inline, so there is no avoiding all the traffic in future as well, and I am going to tighten the https decrypt and inspect up as well to include staff in certain areas (such as searches), but only small areas.

 

I am sure I have read somehwere that you can infact get a 3rd party certificate for the decrypt and inspect part of smoothwall although it isn't a simple process and might take some intevention from the support team. Which would remove the need to install the schools our certificate, they would merely get the message saying they are being intercepted. Being as though my smoothwall renewal starts in March maybe I should burn my support credits and find if anyone really wants to know?

Posted

We use Sophos UTMs in all our schools now. They have an extremism category which is blocked. A log is emailed out to me each night with any hits in it - usernames, and the sites they visited etc... We had a bunch of hits a couple of days ago, as pupils were searching for Anglo Saxon related stuff, and kept finding an Anglo Saxon "white power" organisation in England.

 

We've got SSL interception enabled (with exceptions for certain types of sites, such as banking, shopping, and individual sites/services that have clients that check the validity of the certificate so fail to work with it enabled on them).

Posted (edited)
Out of interest how are people dealing with TLS/SSL traffic monitoring / filtering in the dawn of secure web searches?

We've been decrypting and inspecting HTTPS ever since Google made secure web search the default by switching from https://encrypted.google.com to https://www.google.com in 2014.

 

www.edugeek.net/forums/internet-related-filtering-firewall/145867-google-moving-ssl-searches.html

 

All of our domain and non-domain devices (inc. BYOD) have the MITM certificate installed.

Edited by Arthur
Posted

We have smoothwall doing https inspection (since Google removed the no ssl option), all devices accessing the internet have to have the MITM cert installed.

Prevent report is emailed to me every night.

 

Moving to Sophos UTM soon which seems (from the demo) to do the same thing.

Posted

Are they Prevent specific inspection something that they are doing purely for colleges?

 

Or has anyone heard of a school having one??

 

also - if anyone has had specific questions at a normal OFSTED it would be useful to know what was asked and what they seemed to be looking for

 

in my case - for Primary - but generally I suspect everyone needs to know

 

Mike

Posted

As we are due an OFSTED soon we have Lan School 8 set up with the Report server. This monitors all activity plus we can monitor the students with our Palo Alto.

Trouble is for us that in a few months we will have to set up another report server as we are moving to Impereo, we are part of an academy and have to comply with the other schools within it.

  • Thanks 1
Posted
We a trial dummy run ofsted and i got asked a few questions. For the life of me i cannot remember what i got asked but i have the notes somewhere as the guy who conducted it send them to me so will have a look what i got asked. It also tied in with encryption. I'll mention when i find the notes and if anyone wants them, i dont mind sharing.
  • Thanks 4
Posted (edited)
Just putting this out there for information...

We had a HMI Inspector in College a fortnight ago specifically to look into how we are dealing with the PREVENT agenda. Our Vice Principal set up a schedule for the day and I was due to meet with the inspector alongside other Support staff with a pastoral role during the morning. However on arrival the inspector asked if he could meet the network manager individually. Thankfully I had prepared for this visit so it wasn't a problem but in my sixteen years experience of working in Ed and I think five OFSTED inspections, I have never known the network manager to be asked for a 1:1 meeting.

I had put some PREVENT specific scheduled reports in place looking at Smoothwall categories of Terrorism, Intolerance and Violence and created a PREVENT specific block page providing advice of who to contact etc. We also have a desktop link for all staff to online Prevent training, in case anyone wants to refresh on the training they have all had.

To be honest the Inspectors questions were quite basic. Do you filter internet access? What sorts of things are filtered? How do you know things are being blocked? What systems do you have in place? I got the impression that they are still learning what to ask about but hopefully this info will be of use to some of you out there.

Andy

Cheers for this Andy. I know the HMI's are being trained (or have been over the last few months) in safeguarding technology and prevent. I know a few of the people who have been training them.

Funnily enough when I worked there I was called into a meeting with the HMI in my first few weeks in IT. Again - the only time I've been directly involved with an inspection.

 

[edit] Doh - its 2017 now!

Edited by IrritableTech
Posted
We've been decrypting and inspecting HTTPS ever since Google made secure web search the default by switching from https://encrypted.google.com to https://www.google.com in 2014.

 

www.edugeek.net/forums/internet-related-filtering-firewall/145867-google-moving-ssl-searches.html

 

All of our domain and non-domain devices (inc. BYOD) have the MITM certificate installed.

 

I hear where your coming from with this but as HPKP & HSTS becomes more prevalent MITM decrypt will be impossible.

 

What are web security vendors doing to enable the industry and the like the ability to intelligently safeguard those who we are responsible for ?

 

Personally I can't see how, without being hooked into GCHQ/NSA etc will we ever be truly able to inspect web traffic for any meaningful monitoring / reporting. Assuming that HPKP/HSTS in the not too distant future maybe we are destined to a hiding. This is making the move away from our current vendor ( not through choice ) extremely diffiucult as no one appears to actually fully able to converse what we are obliged to do. Ofsted themselves appear clueless, as long as you can prove that users are unable to get to obvious type web sites and you can report seems to suffice, but we know that isn't really the case these days.

 

Be interested in others viewpoint.

Posted
I hear where your coming from with this but as HPKP & HSTS becomes more prevalent MITM decrypt will be impossible.

What are web security vendors doing to enable the industry and the like the ability to intelligently safeguard those who we are responsible for ?

Personally I can't see how, without being hooked into GCHQ/NSA etc will we ever be truly able to inspect web traffic for any meaningful monitoring / reporting. Assuming that HPKP/HSTS in the not too distant future maybe we are destined to a hiding. This is making the move away from our current vendor ( not through choice ) extremely diffiucult as no one appears to actually fully able to converse what we are obliged to do. Ofsted themselves appear clueless, as long as you can prove that users are unable to get to obvious type web sites and you can report seems to suffice, but we know that isn't really the case these days.

Be interested in others viewpoint.

 

RFC 7469 covers that, advising that browsers disable violation reporting for user defined root certificates (ie. like those we use for our MITM interception). So, realistically, browsers should continue to allow us to do what we do, if they follow the RFC correctly.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...