mats Posted April 25, 2016 Posted April 25, 2016 Supplementary question - the Sept 2016(?) draft of "Keeping children safe in education / Statutory guidance for schools and colleges"* from the DfE includes the line "Governing bodies and proprietors should be confident that systems are in place that will identify children accessing or trying to access harmful and inappropriate content online.". This smells like automated reporting of attempts to get to the bad bits of teh intarnet. So - does your solution feature reporting or do you have to go through the logs to find the misbehaving children? Ta, Mat * https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/487799/Keeping_children_safe_in_education_draft_statutory_guidance.pdf
clockend25 Posted April 25, 2016 Posted April 25, 2016 Lightspeed through our ISP. Would prefer Smoothwall, but it's a million times better than the fortigate appliance we were on before.
MikeGreen Posted April 26, 2016 Author Posted April 26, 2016 Thanks Everyone, I think this had pretty much answered my questions. Thanks again to all.
enjay Posted April 26, 2016 Posted April 26, 2016 Supplementary question - the Sept 2016(?) draft of "Keeping children safe in education / Statutory guidance for schools and colleges"* from the DfE includes the line "Governing bodies and proprietors should be confident that systems are in place that will identify children accessing or trying to access harmful and inappropriate content online.". That's the amusing added challenge with BYOD - simply telling students the WPA key isn't sufficient, as my understanding of the bit you've quoted is that you need to be able to uniquelyidentify students who are accessing/attempting to access stuff they shouldn't. There's a thought. Obviously, we're blocking stuff and we can report on who has accessed what, which we review periodically, but that paragraph says "trying to access". Does that mean I should also be reporting on who has hit the "this site has been blocked" page when trying to go somewhere? That could be really difficult, if not impossible, as our blocked content report includes ad sites, etc. not just sites which someone has deliberately attempted to access...
Wave9_Lee Posted April 26, 2016 Posted April 26, 2016 Hi Mike, one last shout for SOPHOS, happy to provide a price/demo which I think you would be pleased with, cheers Lee
Opendium_Steve Posted April 26, 2016 Posted April 26, 2016 Supplementary question - the Sept 2016(?) draft of "Keeping children safe in education / Statutory guidance for schools and colleges"* from the DfE includes the line "Governing bodies and proprietors should be confident that systems are in place that will identify children accessing or trying to access harmful and inappropriate content online.". This smells like automated reporting of attempts to get to the bad bits of teh intarnet. So - does your solution feature reporting or do you have to go through the logs to find the misbehaving children? Sounds to me like they expect: 1. Children to be authenticated (and their web traffic be logged against their identity) 2. Staff to be alerted to children who's web traffic is being blocked by the filters. 3. Probably also staff to be alerted to attempts to access inappropriate content even if it doesn't trigger the filters. I guess you could achieve this be trawling through the logs manually, but sensibly you'd want your filter to be able to produce summary reports on a regular basis for staff to review and follow up on. Pretty much all of the mainstream commercial on-premises filters (Iceni, Smoothwall, Lightspeed, etc.) will do these kinds of reports. The third part of this probably requires monitoring web searches. I can think of a few LEA systems that would fall short though - they often don't authenticate the users, so even if you get a report it can be hard to identify the user responsible. I also note paragraph 76 - "As part of their safeguarding and or child protection policy governing bodies and proprietors should have in place a clear policy on the use of mobile technology in the school." You could just ban mobile devices entirely, but my feeling is that this is going to be widely ignored and therefore much less effective than properly supporting BYOD through your filters.
caffrey Posted April 26, 2016 Posted April 26, 2016 Main problem with BYOD here is the use of VPNs - we've yet to effectively block those
Boredguy Posted April 26, 2016 Posted April 26, 2016 Sounds to me like they expect: 1. Children to be authenticated (and their web traffic be logged against their identity) Shame that's not a feature of our current filter provider unless we upgrade and change everyone password as it does not have proper AD integration 2. Staff to be alerted to children who's web traffic is being blocked by the filters. Check 3. Probably also staff to be alerted to attempts to access inappropriate content even if it doesn't trigger the filters. Shucks, another thing that we wouldn't be able to do. If only I'd been allowed to change our provider *sigh*
Opendium_Steve Posted April 26, 2016 Posted April 26, 2016 Shame that's not a feature of our current filter provider unless we upgrade and change everyone password as it does not have proper AD integration Dare I ask what you're using? If only I'd been allowed to change our provider *sigh* Maybe you can use this as leverage
jmak Posted April 26, 2016 Posted April 26, 2016 I think we get a lot of false positives with our Lightspeed setup. Examples from today from my use with student level privileges: lifehacker classified as adult (I was trying to follow the link from here about Open365); anything redirected from here via "redirecting at" classified as advertising. Ours is configured by our LA - I'd be interested in whether other Lightspeed users see this, ie is it inherent in the product or is it configuration.
minimoo Posted April 26, 2016 Posted April 26, 2016 we've been using watchguard products here - they seem to come in at under 10k for 3 years - so 6k pa seems a lot for the original poster
Opendium_Steve Posted April 26, 2016 Posted April 26, 2016 we've been using watchguard products here - they seem to come in at under 10k for 3 years - so 6k pa seems a lot for the original poster Depends on how big a school it is, but I'd agree that 6k sounds fairly astronomical for most schools...
minimoo Posted April 26, 2016 Posted April 26, 2016 watchguards M4600 is on google for 21k (with a 3 year subscription) - without any educational discount - they advertise that as being able to support upt to 11Gbps of UTM traffic - if you know a school with a 10gbps internet connection, please pm me the name as i want a job there ;)
rpmoore Posted May 1, 2016 Posted May 1, 2016 Main problem with BYOD here is the use of VPNs - we've yet to effectively block those This is a job for a decent firewall with Layer 7 application aware abilities.
manc_techie Posted May 2, 2016 Posted May 2, 2016 I'm using an iBoss here, my predecessor installed it and got a great price and been more than happy with. Works seamlessly with AD on both client PC's and BYOD as a transparent proxy and provides us with immediate notifications if students search for specific keywords or try to access specific apps e.g. VPN clients. As we have a very limited WAN link due to location the bandwidth streaming based on sites/clients this has been great for controlling access to online videos for teaching. I believe they offer a 30 day trial but happy to answer any questions folk might have, used Smoothwall and Websense before and I prefer this platform (even though both of those are great products)
Duke5A Posted May 2, 2016 Posted May 2, 2016 I just setup a Barracuda filter for our guest wireless access and I've been very impressed with it so far. I haven't even scratched the surface yet with everything it is capable off.
Jambon360 Posted May 3, 2016 Posted May 3, 2016 Hi Duke5A I just setup a Barracuda filter for our guest wireless access and I've been very impressed with it so far. I haven't even scratched the surface yet with everything it is capable off. Can I ask what appliance you purchased and how did you find Barrauda's pricing for your Appliance? I currently have a Barracuda NG F400 firewall installed doing NAT translation and some level of filtering but looking for more indepth reports. Im currently looking at the Web Security Gateway Model 810 Appliance but find the priceing a bit hard to swallow. Thanks.
nelliott Posted May 3, 2016 Posted May 3, 2016 Main problem with BYOD here is the use of VPNs - we've yet to effectively block those what firewall are you using? i've got a smoothwall box with a layer 7 license on it which blocks applications which has a category for vpns.
caffrey Posted May 3, 2016 Posted May 3, 2016 We use Smoothwall too, tried that layer 7 module on trial and found it never worked for us. It might have improved since then but it was extra cost. Slightly O/T How well does Sophos block apps ?
Duke5A Posted May 3, 2016 Posted May 3, 2016 Hi Duke5A Can I ask what appliance you purchased and how did you find Barrauda's pricing for your Appliance? I currently have a Barracuda NG F400 firewall installed doing NAT translation and some level of filtering but looking for more indepth reports. Im currently looking at the Web Security Gateway Model 810 Appliance but find the priceing a bit hard to swallow. Thanks. We opted to go with their 410Vx virtual machine since we already have a virtual cluster and the pricing for the VM was a LOT cheaper than the appliance. It's advertised as handling up to 800 concurrent users or 80Mbps of traffic. I set it up using WCCP to handle the redirecting of traffic at our core switch. We priced out a couple of other vendors and all of them were very pricey when looking at physical appliances - I had no idea it would cost that much. The virtual machine was significantly cheaper, but I don't have the cost on hand. What steered us their way was the fact we already have one of their messaging archival appliances and it has been rock solid in five years of service. At the end of the fourth year our service contract entitled us to a new box and their tech support team pretty much handled the entire migration remotely.
Electra Posted May 4, 2016 Posted May 4, 2016 Just spotted this on my Twitter feed - looks interesting. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now