Dom_ Posted February 21, 2018 Posted February 21, 2018 I've just had the issue on one machine here, and it was IE caching the old wpad that was the issue.... Try this: Reset IE (including personal files), then close all instances of IE Open cmd as admin, and run these commands: del \wpad*.dat /s ipconfig /flushdns nbtstat -R (case sensitive) That fixed it for me. 1
sister_annex Posted February 21, 2018 Posted February 21, 2018 Just logged into Netsweeper for the first time and appear to have almost no access whatsoever. FFS. At least you've been given access... I'm still waiting for details, none of our staff or students can access anything (they're just hitting the default filter block page), O365 admin isn't working either, neither is AAD sync :/ Oh yeah, I'm supposed to be on annual leave today (and the rest of the week) tbh I'm a little bit unhappy with the whole experience atm...
clockend25 Posted February 21, 2018 Posted February 21, 2018 I've just had the issue on one machine here, and it was IE caching the old wpad that was the issue.... Try this: Reset IE (including personal files), then close all instances of IE Open cmd as admin, and run these commands: del \wpad*.dat /s ipconfig /flushdns nbtstat -R (case sensitive) That fixed it for me. Sorted in the end by a couple of their techs, but thanks. The disappointing thing for me is how little of our configuration has been transferred over from our Lightspeed setup. From what I can see, all @SchoolsBroadband have done is recreate policies and ensure accounts are receiving the same level as they were before. Everything else appears to have been left for us to do, which has resulted in a huge workload over the past couple of days, and some severe disruption in the process. Your support guys and girls do a great job, but it feels like a lot of this work could have been avoided if the migration itself had been more thorough. Is there any update on when the issue with BYOD authenticating against Netsweeper will be sorted? I was told later this week... 1
SchoolsBroadband Posted February 21, 2018 Posted February 21, 2018 Thanks for the praise to our tech team I'll make sure I feed it back. I wish we could automate moving config from Lightspeed to Netsweeper. If we could then we would but Lightspeed is a closed system and we've no access to databases and config files on the Rockets unfortunately. I'll get back to you on the BYOD authentication as I know its very close depending on which iteration you are using of course. Dave
clockend25 Posted February 21, 2018 Posted February 21, 2018 I'm talking more about policies and URL lists we had set up previously. As I still have access I've gone back on and retrieved this information and either configured it myself or passed it on to your support team, but this surely should have been done during the migration.
clockend25 Posted March 5, 2018 Posted March 5, 2018 Migrated on Feb 16th. Still no functioning BYOD network.
snagrat Posted March 8, 2018 Posted March 8, 2018 We have problems with iPads. Redirfects to authportal but then do not accept any credentials. Anyone had this?
fiza Posted March 8, 2018 Posted March 8, 2018 We have problems with iPads. Redirfects to authportal but then do not accept any credentials. Anyone had this? We don't have many iPads but we asked for a secondary proxy port that doesn't require authentication and defaults to pupil level filtering. Makes life easier for us.
snagrat Posted March 8, 2018 Posted March 8, 2018 We don't have many iPads but we asked for a secondary proxy port that doesn't require authentication and defaults to pupil level filtering. Makes life easier for us. Planning on doing this, but can't be done straight away apparently. May just get it setup and get the proxy on the iPads set for tomorrow
snagrat Posted March 8, 2018 Posted March 8, 2018 Not great first experience of migration today. Although most of the little issues got resolved we still have no iPads. They will not authenticate correctly so asked for the additional proxy/port to be created. Heard nothing back so unsure if this will be created tonight ready for tomorrow. If not, 60 iPads will be sat doing nothing. The MDM is also not working, but may be an authentication issue as above so will wait for that to be solved first. Also had issues with Skype and OneDrive not logging in on BYOD machines. Had to put the URLs in to the default filter list. Being ask SB as what services we used, I would have expected them to be added before hand - seems the initial questionnaire wasn’t consulted by the engineer who migrated us. Still, can only get better from here on
whartomt01 Posted March 8, 2018 Posted March 8, 2018 You still getting the authportal pop up and doesnt seem to recognise credentials? You using a pac file for proxy for ipads and anything mentioned about your DNS. We got around it with the proxy ports setup pointing to pupil or staff . But interesting to hear others with the same issue (sorry not helpful i know) Got a few migrations of the next few weeks. will see if they have the same issues (Although we are having the ports setup before install fingers crossed)
snagrat Posted March 8, 2018 Posted March 8, 2018 You still getting the authportal pop up and doesnt seem to recognise credentials? You using a pac file for proxy for ipads and anything mentioned about your DNS. We got around it with the proxy ports setup pointing to pupil or staff . But interesting to hear others with the same issue (sorry not helpful i know) Got a few migrations of the next few weeks. will see if they have the same issues (Although we are having the ports setup before install fingers crossed) Yes exactly that! Nothing mentioned about DNS. Although the engineer said this has happened before and Netsweeper are working on it. We are using a PAC file. The PAC side is working so as soon as they give me the new proxy I can just change in PAC file and hopefully they will work.
whartomt01 Posted March 8, 2018 Posted March 8, 2018 We were kind of told it looked like an internal DNS issue. But i don't really see it. Pac files were working for everything else. Can i ask where you host you pac file too? And What MDM your using Strange that they didnt automatically set the ports up for you before the install. After issues we had, i was told it would be part of the process for new schools. Yeah will be fine then with the new ports. Just means you dont know which pupil is using an ipad for reporting (but if like me, thats how we had it in lightspeed anyway)
snagrat Posted March 8, 2018 Posted March 8, 2018 We use ZuluDesk. iPads can’t check in. PAC is hosted on the DC (only server in school).
whartomt01 Posted March 8, 2018 Posted March 8, 2018 same kind of issue for us. we had mosyle. Needed urls or ports unblocking once they had the pupil and staff proxy port set up. And we seemed to have an issue of having the pac hosted on the same server as authportal. We had an intranet page hosted on the same server. Couldnt browse to it without getting the authportal login popup. If you can. Stick IIS on a random PC and host it there to test an ipad. Seem to think it helped something. It's like the ipads would access the pac file then so it would use the exception for 'authportal'
snagrat Posted March 8, 2018 Posted March 8, 2018 I can live with the MDM not working straight away, but I need these iPads to at least be able to get on the internet. Will be a phone call to support first thing to see if the ports were configured for me. If not, a call to the school with an apology.
sister_annex Posted March 8, 2018 Posted March 8, 2018 We've not been happy with the entire process... we've been migrated nearly 2.5 weeks and we're still picking apart issues. The biggest one we found yesterday was that under the default policy the 'General' category was allowed out, meaning that a good chunk of the school's internet usage was being allowed out, effectively, anonymously; with no way of auditing who had been to the sites that fell into that category. IMO that alone is a biggy. Our Authportal wasn't set up correctly (I followed the instructions provided but the follow-up settings were missed) meaning that users were getting sporadic failures in authentication with NS, stopping sites from working correctly. And trying to get YouTube working has been a right nightmare! We don't allow our students to Youtube, but our staff are and for some strange reason (one that we have yet to figure why) if we allow the streaming media category it still will not work with only half the page loading. We can get around it by adding i.ytimg.com and s.ytimg.com to the default policy, however, adding it to the staff policy it gets ignored, checking the log files it seems that no matter what those two urls go via the default policy regardless. Also, if you move your users around groups, be prepared to email support and ask them to do an AD Sync as that isn't automatic either... Oh and don't get me started on BYOD... All this, on top of no manuals and training, and from what I can gather a distinct lack of knowledge at the end of TS (although they do try to be as helpful as possible), has left us with a bitter taste in our mouths. We are hoping that over the coming week we will iron out our remaining issues. Thankfully we have a good team that keeps everything else ticking over whilst my NM and I spend what seem to be endless days looking at this. God help those of you that are PT or on your own.
Blue_Cookeh Posted March 8, 2018 Posted March 8, 2018 (edited) We've got our migration tomorrow and will post back with how it goes - we've not really had any issues with getting the migration process it self sorted, Asmara at SB has been more than helpful. I am worried about losing access to features or having less control, and having to go back to managing proxy settings again (I thought those days were long over ) but will hold judgement! If worse comes to worse I can shift our school onto our secondary FTTC line and filter on our Sophos box - although not ideal with the connection speed. Realistically, I'm expecting some teething issues. SB are moving us from one platform to an entirely different one, it was never going to be 100% smooth sailing. I really hope there is an automatic or scheduled AD sync, though. We change things around a lot in our AD... Edited March 8, 2018 by Blue_Cookeh 1
snagrat Posted March 9, 2018 Posted March 9, 2018 Anyone know how to create a Shared List? I’m only adding local lists at the moment
BrotherSidious Posted March 9, 2018 Posted March 9, 2018 You can convert an entire local list to a shared list by clicking the button at the top "Convert Local List to Shared List" whilst viewing a local list if you want to move all of the entries into a shared list. Please be aware that entries in a local list take precedence over those in a shared list. The second option (the one we use more frequently now) is to navigate through URL Tools on the left hand menu then into URL List Manager. Once this opens, click on the create TAB and then you can create a new list. You may need to contact SBB as when they set us up, they did not enable this so we could not create shared lists this way not could we add or edit anything within our shared lists until they made a change. Once it has been enabled it works fine. 2
Popular Post BrotherSidious Posted March 9, 2018 Popular Post Posted March 9, 2018 (edited) Things we wish we knew before our NetSweeper migration: The whole filtering premise is based on the fact that the end user is identified and then associated with a SINGLE group. Although each group can have multiple policies that apply to it at different times, only one policy can be in effect at a time. In a nutshell, a user is only subject to a single policy at any one time. This is absolutely fundemantal to getting your filtering to work correctly. Policies can be made up of a single local list, multiple shared lists and categories. Any of these can be set to allow or deny and they are processed in a specific order of precedence as follows: Local list, shared list, categories. There is also a Default Policy which is critical (and this can’t be stressed enough) to getting things working correctly. Any allow rules in this list will allow any user to connect to that site anonymously leaving you with no audit trail! Due to this, we were advised that nothing should be allowed within the default list EXCEPT entries that are required by specific applications that can only connect anonymously. This should not apply to users browsing the internet, so this is not the place to add rules which allow your users to access the internet (you have been warned) ! Denying users access to the internet using the Default Policy is key in getting your filtering to work correctly, which initially may seem counter intuitive. When a user initially requests a page they will do so anonymously and if your default filter is set up correctly they will be denied. As soon as the request is denied, it will be passed on to your Auth Portal which also has a key role in your filtering process. Once the request is received by Auth Portal, it will check who the user is in AD and convert your AD credentials to NetSweeper compatible credentials. This conversion process is configured as part of the migration. Once the system has the users NetSweeper credentials, these will be matched to a group which will in turn link to a policy which will then determine whether or not the user is allowed or denied access to a specific site. From this it can be seen that the conversion of your AD credentials e.g. DomainName/Username to NetSweeper credentials e.g. Username@NSW-00XXX (where XXX is your unique number) is vital to the process. It is, therefore, essential that your Auth Portal is configured correctly otherwise your filtering will not work as the system will be unable to determine who the user is and all requests will be processed solely by the Default Policy. IMPORTANT : If when you look in your logs, you start to see entries against the Default Policy with credentials in the AD format e.g. DomainName/UserName rather than the NetSweeper format (Username@NSW-00XX) then it is highly likely that there is something amiss with your Auth Portal configuration and this needs addressing as a matter of urgency. Your users are assigned to AD groups and these are imported into the equivalent NetSweeper groups. However, if you move a user between your AD groups, this will not cause the NetSweeper groups to update! It will automatically add new users but it will not move them. This is worth knowing if you move users between groups (such as to temporarily limiting internet access as a consequence). The only way to have moves updated is to contact SBB and ask them to manually run an import for you. This is a nightmare if you have AD Group memberships changing regularly. NetSweeper uses wildcards in a different manner to LightSpeed so care needs to be taken when you import any rules from LightSpeed that include the * wild card. We found that simply stripping out all the “*.” from the beginning of URLs and the * from the end gave us what we wanted. Shared lists are incredibly useful but in our case we could not initially create them properly or add or edit entries within them. If this is the case, then contact SBB as you should have this level of access and they can enable it. Edited March 9, 2018 by BrotherSidious 7
IrritableTech Posted March 9, 2018 Posted March 9, 2018 Thank you @BrotherSidious that is extremely useful to know pre-migration. Does anyone have answers and experience of the following? Can we use our radius server to authenticate our BYOD users against the filter? Or from reading the post above does the auth portal have to get involved to convert the username? I know there is an issue at the moment with the auth portal and BYOD and that the current work around is to setup an additional un-authed proxy port and set traffic to be filtered at a particular level. Can one proxy be used to filter two IP subnets at two distinct filtering levels (I'm thinking Staff BYOD and 6th form) or will I need two additional proxy ports? Is it possible to bypass the proxy (assuming fortinet isn't blocking 80&443) if we find a piece of legacy software or a device that doesn't like proxies?
Nightshade2k Posted March 9, 2018 Posted March 9, 2018 (edited) Rather than go into a long painful story, ill just say this in the end because we run as a conference site at our school and we have times when BYOD users were using our guest internet services and technicians were not on site we specifically got to the point where we asked SB to allow us to use the Fortigate Filtering for our BYOD SSID's because while they could set NS to work with specific filtering for the SSID , there are some devices that require "additional" configuration to work with netsweeper aka editing settings on certain devices to point at the proxy manually. i have said to SB that imo at the moment its best to offer customers access to the Fortigate filters for BYOD if they have similar issues to ours, the bone of contention is that this adds load direct to the centralised Fortigates they use, so too many people using these instead of NS could cause them issues. I have remained quite silent on this point, but i have decided moving forward that while NS im sure will work out in the end, that im likely going to go full onsite fortigate filtering in the near future, ive been chatting to a couple of guys in the US and UK who are using full onsite fortigate and while there are risks as with everything we do this seems like a good option, i know that local lightspeed and smoothwalls are options to but i quite like the forticloud suite. i forgot to say that despite what people may think of SB, at the end of the day they do try very hard to get things working but the support team are often i feel overwhelmed especially due to all these migrations, im sure again in time this will calm down, cant reccomend Jamie in second line enough hes super helpful as is Nathan. Despite all these issues the SB prices for broadband are still very competitive. so im not saying jump ship at all! Edited March 9, 2018 by Nightshade2k 2
BrotherSidious Posted March 9, 2018 Posted March 9, 2018 Has anyone who has moved over to NetSweeper typed in Lightspeed on its own and then been informed that the page is blocked "The site you have chosen has been categorized as: Search Keywords". Why would the word Lightspeed be blocked/filtered?
SchoolsBroadband Posted March 9, 2018 Posted March 9, 2018 Full Fortigate is an excellent solution when also used with Fortianalyzer. Alas for most schools it's outside of their budgets which is why we don't go to the mass market with that solution. Dave Rather than go into a long painful story, ill just say this in the end because we run as a conference site at our school and we have times when BYOD users were using our guest internet services and technicians were not on site we specifically got to the point where we asked SB to allow us to use the Fortigate Filtering for our BYOD SSID's because while they could set NS to work with specific filtering for the SSID , there are some devices that require "additional" configuration to work with netsweeper aka editing settings on certain devices to point at the proxy manually. i have said to SB that imo at the moment its best to offer customers access to the Fortigate filters for BYOD if they have similar issues to ours, the bone of contention is that this adds load direct to the centralised Fortigates they use, so too many people using these instead of NS could cause them issues. I have remained quite silent on this point, but i have decided moving forward that while NS im sure will work out in the end, that im likely going to go full onsite fortigate filtering in the near future, ive been chatting to a couple of guys in the US and UK who are using full onsite fortigate and while there are risks as with everything we do this seems like a good option, i know that local lightspeed and smoothwalls are options to but i quite like the forticloud suite. i forgot to say that despite what people may think of SB, at the end of the day they do try very hard to get things working but the support team are often i feel overwhelmed especially due to all these migrations, im sure again in time this will calm down, cant reccomend Jamie in second line enough hes super helpful as is Nathan. Despite all these issues the SB prices for broadband are still very competitive. so im not saying jump ship at all!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now