Jump to content

Recommended Posts

Posted

Can I check I have this right. For unmanaged devices (ie BYOD), the user must:

 

- Install the certificate

- For Windows, ensure auto detect settings is ticked

- For iOS change the proxy to Auto (but add no URL).

 

Is there no way to have filtering with no proxy set at all?

 

Our WPAD and PAC are working OK but getting users to set a proxy on their phone is a pain, the certificate is less complicated

Posted
We've got our migration tomorrow and will post back with how it goes - we've not really had any issues with getting the migration process it self sorted, Asmara at SB has been more than helpful. I am worried about losing access to features or having less control, and having to go back to managing proxy settings again (I thought those days were long over :() but will hold judgement!

 

If worse comes to worse I can shift our school onto our secondary FTTC line and filter on our Sophos box - although not ideal with the connection speed.

 

Realistically, I'm expecting some teething issues. SB are moving us from one platform to an entirely different one, it was never going to be 100% smooth sailing.

 

I really hope there is an automatic or scheduled AD sync, though. We change things around a lot in our AD...

 

Hi there,

 

AD is currently sync'd. We will be upgrading to v6 at the start of the summer holidays and it does LDAP lookup's rather than sync which will be an improvement too.

 

Thanks

 

Dave

Posted
Hi there,

 

AD is currently sync'd. We will be upgrading to v6 at the start of the summer holidays and it does LDAP lookup's rather than sync which will be an improvement too.

 

Thanks

 

Dave

 

Hi Dave. Could I just ask you to clarify the above statement with regards to "AD is currently synch'd" as 48 hours ago we were told that there is no dynamic synching. If we move our users between groups in AD we were told we would have to request a complete manual synch (which basically erases all users and then re-imports all your users into their current groups) as the system cannot do this automatically.

Posted
We've not been happy with the entire process... we've been migrated nearly 2.5 weeks and we're still picking apart issues. The biggest one we found yesterday was that under the default policy the 'General' category was allowed out, meaning that a good chunk of the school's internet usage was being allowed out, effectively, anonymously; with no way of auditing who had been to the sites that fell into that category. IMO that alone is a biggy.

 

Our Authportal wasn't set up correctly (I followed the instructions provided but the follow-up settings were missed) meaning that users were getting sporadic failures in authentication with NS, stopping sites from working correctly.

 

And trying to get YouTube working has been a right nightmare! We don't allow our students to Youtube, but our staff are and for some strange reason (one that we have yet to figure why) if we allow the streaming media category it still will not work with only half the page loading. We can get around it by adding i.ytimg.com and s.ytimg.com to the default policy, however, adding it to the staff policy it gets ignored, checking the log files it seems that no matter what those two urls go via the default policy regardless.

 

Also, if you move your users around groups, be prepared to email support and ask them to do an AD Sync as that isn't automatic either...

 

Oh and don't get me started on BYOD...

 

All this, on top of no manuals and training, and from what I can gather a distinct lack of knowledge at the end of TS (although they do try to be as helpful as possible), has left us with a bitter taste in our mouths.

 

We are hoping that over the coming week we will iron out our remaining issues. Thankfully we have a good team that keeps everything else ticking over whilst my NM and I spend what seem to be endless days looking at this. God help those of you that are PT or on your own.

 

Pretty much our experience as well. I'd be interested to know who did your migration as it sounds like an identical cock-up.

Posted
Pretty much our experience as well. I'd be interested to know who did your migration as it sounds like an identical cock-up.

I don't think it would be fair to name the person here, we have been in close contact with our reseller and SchoolsBroadband over the last few working days and managed to get most all the issues sorted. If you've bought through a reseller/partner I would speak to them - otherwise contact your account manager - it will get sorted (even if there have been headaches along the way)

 

We still have a few questions that need answering (mainly procedural) but hopefully, they will be answered in the coming days.

  • Thanks 1
Posted (edited)

Wasn't suggesting making it public. Just wondered if this is a case of complete incompetence on SB's part or whether a select few people have not followed procedures.

 

Like you I've been working with their support team to resolve individual issues. Larger issues with the platform remain though and some look insurmountable.

Edited by clockend25
Posted

We do have one engineer in particular that has now left the company that was doing Netsweeper installs but I don't want to / can't comment on that further for obvious reasons.

 

If you've got any specific cases still outstanding please send me them via PM and I will take it up with the TBT manager.

 

Thanks

 

Dave

  • Thanks 1
Posted

All of our issues stemmed from an incomplete Auth Portal configuration. Unfortunately, two weeks post migration we discovered this and tried to fix this ourselves and made an error as the configuration is case sensitive. Moral of the story : if you think you have an issue with your Auth Portal configuration ask SBB to check it and don't mess with it yourself.

 

Unfortunately, when we started submitting multiple tickets as websites weren't working, it wasn't really picked up that Auth Portal was the underlying issue. We were simply getting tickets closed as individual websites became accessible.

 

After 2.5 weeks of various issues I copied David Tindall into one of our HelpDesk submissions and in fairness I got an email reply from him within the hour and had a follow up conference phone call within 2 hours. We also had an engineer remote in and take a look at our configuration and they discovered the underlying issue whilst I was on the conference call with David. Since the engineer resolved our Auth Portal issue the system has started to behave as we expected it to and we are getting to grips with our filtering arrangements. The only real issues now are identifying those applications that need access to the internet and don't authenticate (some update and registration services) as these need entries in the Default Filter in order to allow them to work. Over time we should identify these and get back to where we were with LightSpeed.

 

If it wasn't for the Auth Portal issue, the process would have been much more straightforward and I suspect we would be fully up and running as per LightSpeed by now.

 

However, our WiFi solution for BYOD is having to be completely rethought as we cannot replicate our current approach with NetSweeper which is hugely disappointing as with LightSpeed it simply "just worked". This is now with SLT as they will have to decide on which "compromised" solution we implement.

Posted

Evening All,

 

@mavhc

 

To answer your questions,

1) NTLM is the mechanism used to allow transparent authentication, this assumes you are using an NTLM supported browser. Any unsupported browser should result in a generic authentication pop up. If for any reason this is not working for you drop me a PM with more details and I can get one of the guys to take a look. The client will still need the proxy specifying one way or another.

2)A transparent proxy is currently not possible due to them not scaling large enough to cope with the ever increasing speeds without removing load balanced HA.

3)Explicit proxies will not be affected by TLS 1.3, only transparent solutions will struggle to decrypt SSL and may need modification. That being said with any major change we (and our suppliers) test our products to reduce any impact on you guys.

 

Hope that helps,

 

Thanks,

Posted
Evening All,

 

@mavhc

 

To answer your questions,

1) NTLM is the mechanism used to allow transparent authentication, this assumes you are using an NTLM supported browser. Any unsupported browser should result in a generic authentication pop up. If for any reason this is not working for you drop me a PM with more details and I can get one of the guys to take a look. The client will still need the proxy specifying one way or another.

2)A transparent proxy is currently not possible due to them not scaling large enough to cope with the ever increasing speeds without removing load balanced HA.

3)Explicit proxies will not be affected by TLS 1.3, only transparent solutions will struggle to decrypt SSL and may need modification. That being said with any major change we (and our suppliers) test our products to reduce any impact on you guys.

 

Hope that helps,

 

Thanks,

 

Thanks, I'm not (yet) using your service, keeping a close watch though.

  • Thanks 1
Posted

Since our Auth Portal issue was resolved, staff and students are generally reporting that the internet is more in keeping with how it was in Lightspeed. We are having to tweak filters as you would expect as the two systems (Lightspeed and NetSweeper) work slightly differently but that's not been too onerous as imported out Lightspeed settings into NetSweeper to start with. Identifying where some applications/services go and what needs unblocking has been time consuming but my colleague has manged to resolve most of those using a combination of fiddler (https://www.telerik.com/fiddler) and watching live traffic passing through NetSweeper. We have had a couple of HelpDesk tickets and queries resolved by Jamie at SBB who sorted things out very quickly and was very helpful which was greatly appreciated and does show that with the right staff, SBB can deliver the level of service I expected from them.

 

BYOD remains a separate manner and when we finally finish that I will update accordingly but at the moment this is in our hands as we decide our way forward so any delay as this stage is not due to SBB.

  • Thanks 1
Posted
I'm glad someone's having a good time. We're continuing to fight our way through issue after issue with their helpdesk. I'm hoping at some point I'll be able to do my job again.
Posted
I'm glad someone's having a good time. We're continuing to fight our way through issue after issue with their helpdesk. I'm hoping at some point I'll be able to do my job again.

 

Sorry your having a tough time of it. If you have multiple tickets open and numerous issues I would recommend dropping Dave Tindall a message mate with details and ticket numbers. If you want to post what your issues are, we can see if they are the same as any we have encountered and suggest what we tried. If its wireless/BYOD related than unfortunately we cant help/advise at this time as we haven't sorted ours yet.

  • Thanks 1
Posted
Has anyone been given training on how to use the NetSweeper Admin Console or been given written instructions? What do we do/can we do with Group Manager/ Policy Manager/Category management. i would like to customise our setup but at the moment I am a bit lost in the Console.
Posted
I want to setup a web page with instructions for our BYOD users when they connect so it tells them how to set up Proxy settings on their iOS or Android device. Has anyone already got some good instructions that I could pinch please?
Posted
Sorry your having a tough time of it. If you have multiple tickets open and numerous issues I would recommend dropping Dave Tindall a message mate with details and ticket numbers. If you want to post what your issues are, we can see if they are the same as any we have encountered and suggest what we tried. If its wireless/BYOD related than unfortunately we cant help/advise at this time as we haven't sorted ours yet.

 

Dave's already aware of our issues. We're still working through the plethora of sites and services that no longer function and having consumed three weeks of my time thus far it shows no sign of letting up. It's telling that the biggest breakthrough we've had in terms of understanding the new setup came from a post from a fellow user on here.

 

Our BYOD is now 'working' although I've got a big wedge of documentation to put together before we can realistically roll it out again to users.

Posted
Has anyone been given training on how to use the NetSweeper Admin Console or been given written instructions? What do we do/can we do with Group Manager/ Policy Manager/Category management. i would like to customise our setup but at the moment I am a bit lost in the Console.

 

We read this : https://helpdesk.netsweeper.com/docs/5.3/#t=User_Guides%2FManaging_Filtering_User_Acct%2FManaging_Filtering_with_a_User_Account.htm

 

Slightly simplified but : We have groups in AD for lower school, sixth form and staff. Each of these gets imported into NetSweeper as a Group with their own Policy. Within these policies you can tweak the allowed or denied categories for each individual group (we have one policy group).

 

We then have 5 shared lists:

 

Allowed for staff - linked only to the Staff policy

Allowed for Staff and sixth form - linked to the staff and sixth form policy

Allowed for Staff, sixth form and lower school (effectively everyone) - inked to all three policies

Denied for Students - Linked to sixth form and Lower school groups policies

Denied for Everyone - Linked to all three policies

 

Now this could be simplified and the allow and denies could be incorporated into the same shared list BUT you can set a shared list to accept only allow or deny rules. By separating the allow and deny lists we can hopefully eliminate someone going into a dual role list and accidentally selecting allow versus deny (or vice versa) as our lists wont allows you to enter the incorrect setting.

  • Thanks 1
Posted
We read this : https://helpdesk.netsweeper.com/docs/5.3/#t=User_Guides%2FManaging_Filtering_User_Acct%2FManaging_Filtering_with_a_User_Account.htm

 

Slightly simplified but : We have groups in AD for lower school, sixth form and staff. Each of these gets imported into NetSweeper as a Group with their own Policy. Within these policies you can tweak the allowed or denied categories for each individual group (we have one policy group).

 

We then have 5 shared lists:

 

Allowed for staff - linked only to the Staff policy

Allowed for Staff and sixth form - linked to the staff and sixth form policy

Allowed for Staff, sixth form and lower school (effectively everyone) - inked to all three policies

Denied for Students - Linked to sixth form and Lower school groups policies

Denied for Everyone - Linked to all three policies

 

Now this could be simplified and the allow and denies could be incorporated into the same shared list BUT you can set a shared list to accept only allow or deny rules. By separating the allow and deny lists we can hopefully eliminate someone going into a dual role list and accidentally selecting allow versus deny (or vice versa) as our lists wont allows you to enter the incorrect setting.

 

This is not how ours was setup. From the off we seem to have ;

 

admin_web_filtering

default_web_filtering

pupil_web_filtering

staff_web_filtering

 

We also have 2 new ones;

 

transparentpupil (no idea why this is there)

byod (which I asked for)

 

 

We did ask for the Lightspeed policies we already had to be transferred so I don't know if those policy groups are related to that.

Posted
This is not how ours was setup. From the off we seem to have ;

 

admin_web_filtering

default_web_filtering

pupil_web_filtering

staff_web_filtering

 

We also have 2 new ones;

 

transparentpupil (no idea why this is there)

byod (which I asked for)

 

 

We did ask for the Lightspeed policies we already had to be transferred so I don't know if those policy groups are related to that.

 

They will be your AD groups - the same way sidious has them, the shared lists can then be applied to these groups (so if you wanted to unblock phonicsplay.co.uk for staff & students, you could have a shared list linked to both of these policy groups to save you adding to each group individually.

  • Thanks 1
Posted (edited)
I think they are the default groups. We created our own groups and assigned our users accordingly in AD and then had our data re-imported so we could have the structure we wanted. You can add a new group in AD in the same OU as these default ones and it will create a corresponding group in NetSweeper BUT we were told that the group name must have "web filtering" on the end of its name in order for it to be created and for it to import users correctly. Edited by BrotherSidious
  • Thanks 1
Posted
Thank you for the link to the user guide.

 

Should we be changing the password for the Console given to us by SB?

 

We changed ours without any issues

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...