Jump to content

Recommended Posts

Posted

I am struggling to get this GAFE YouTube settings for restricted access thing working. I've followed the general instructions about adding CNAMEs for the various YouTube URLs and I've changed the settings in the GAFE Admin Console. It is working mostly, in the fact that we do get served the restricted version of YouTube, but when a teacher tries to sign into YouTube in order to access the unrestricted version I get "This webpage is not available ERR_QUIC_PROTOCOL_ERROR

 

It did work for the first week or so, I swear! Anyone had this?

Posted (edited)
I am struggling to get this GAFE YouTube settings for restricted access thing working. I've followed the general instructions about adding CNAMEs for the various YouTube URLs and I've changed the settings in the GAFE Admin Console. It is working mostly, in the fact that we do get served the restricted version of YouTube, but when a teacher tries to sign into YouTube in order to access the unrestricted version I get "This webpage is not available ERR_QUIC_PROTOCOL_ERROR

 

It did work for the first week or so, I swear! Anyone had this?

 

Hi Tammie,

 

Please provide a detailed description of the steps you have taken to try to get this to work, ideally include links to pages from where you got the information you used to perform the configuration.

 

 

:edit: - also could you also confirm your browser(s) and what proxy/filtering system you are using. Finally, that error might actually be a transient issue with something inside the youtube/google datacentre, try it again today.

Edited by psydii
  • Thanks 1
Posted (edited)

Hi psydii, thanks for your reply. I hope you can make sense of my instructions, I appreciate you even having a look as it's complicated!!

 

It was based on GAFE outline for restricting YouTube across the network so students who were not signed in to Google would get a restricted version of YouTube.

 

The basic instructions for what I did are here at post #19

 

My actual steps are these:

Step 1 - in Google Admin Console

Follow this https://support.google.com/a/topic/6206681?hl=en&ref_topic=6259349

The step “Restrict YouTube content on your network” refers to the following.

Step 2 - in DNS Manager

 


    [*=1]Server Manager, DNS, r click DNS Manager
    [*=1]While in your DNS manager, select “Forward Lookup Zones” on the left pane
    [*=1]Right click in the white space and select “New Zone”
    [*=1]Select Next to progress through the New Zone Wizard.
    [*=1]On the second screen, select Primary Zone.
    [*=1]Replicate to all DNS servers running on domain controllers in this domain
    [*=1]Enter the name of the zone. You will have to follow these steps three times iterating through the following list:

youtube.com

googleapis.com

youtube-nocookie.com

It is imperative that you type these exactly as shown!

8. Allow only secure dynamic updates

9. Finish!

10. Repeat for the other two URL’s outlined in step 6

Now to configure each zone:

youtube.com

 


    [*=1]Left click
    [*=1]Right click in the white space on the right pane and select New Host (A or AAAA)...
    [*=1]Host - * FQDN - youtube.com IP - 206.111.13.155
    [*=1]Step 2
    [*=1]Host - accounts FQDN - accounts.youtube.com (may be just youtube.com) IP - 206.111.13.154
    [*=1]Step 2
    [*=1]Host - restrict FQDN - youtube.com IP - 216.239.38.120
    [*=1]Right click in the white space on the right pane and select New Alias (CNAME)...
    [*=1]Alias - m FQDN - youtube.com FQDN for target host - restrict.youtube.com
    [*=1]Step 8
    [*=1]As step 9, with Alias - www

googleapis.com

 


    [*=1]Right click in the white space on the right pane and select New Alias (CNAME)...
    [*=1]Alias - youtube FQDN - googleapis.com FQDN for target host - restrict.youtube.com
    [*=1]Step 8
    [*=1]As step 12, with Alias - youtubei

youtube-nocookie.com

 


    [*=1]Right click in the white space on the right pane and select New Alias (CNAME)...
    [*=1]Alias - www FQDN - youtube-nocookie.com FQDN for target host - restrict.youtube.com

We are with SWGfL for our broadband and have RM Safetynet with a proxy filter. In the SafetyNet rules I have allowed *.youtube.com and accounts.youtube.com to be on the safe side.

 

It was working - when staff went to YouTube initially they got the restricted version and then could sign in to YouTube with their GAFE account to get the unrestricted one. Now after the half term break no-one can sign in. I have also tried removing the accounts.youtube.com part of the youtube.com forward lookup zone in the DNS, no difference.

 

For info, I signed into Chrome with incognito, signed into a non-GAFE account and tried to sign into YouTube and got this error:

 

image?w=629&h=120&rev=8&ac=1

 

Tammie

 

 

 

 

 

Edited by Tammie
  • Thanks 1
Posted
Hold on, it's suddenly working! I did make some of those allow rules this morning so I guess one of those has made the difference. It's good that @psydii asked me to retrace my steps ... :-)
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...