SchoolsBroadband Posted August 26, 2018 Posted August 26, 2018 as soon as I'm back on holiday week after next All has been rather successful over the summer to say the least! Dave
BrotherSidious Posted September 14, 2018 Posted September 14, 2018 Prior to the six weeks break we had access to a number of websites via our NetSweeper filtering and thought (as all these sites were working) we were finally there with regards to getting things sorted. Since our return we are getting calls on a daily basis from staff who can no longer access websites they and students could happily access prior to the break. We changed absolutely nothing on our filtering over this period but somebody somewhere most definitely has! Finance were unable to log in to previously accessible bank sites, staff couldn't access online sites to place orders, pinterest would not allow access, goggle maps broke and this morning I walk into a HelpDesk ticket that bingmaps.com is no longer working. We are slowly resolving these on a site by site basis but this is extremely frustrating as all these sites worked perfectly before. Is anyone aware of an underlying change that could have affected multiple websites? It truly sucks to believe that your filtering was all correctly configured ready for the start of the academic years only to find out on day 1 that your department would be spending half its time trying to make previously accessible websites accessible again. Not a happy bunny ! 1
TMBS Posted September 14, 2018 Author Posted September 14, 2018 We've had the same issue too. Lots of previously accessible sites, and sites we'd unblocked ourselves in Netsweeper no longer work, which is extremely frustrating for staff and students. I picked up an extremely rude word in our filtering that a student had typed in about me 'Miss B******* is a c***', simply because he got that frustrated about 'me' blocking everything and he couldn't complete his courseswork! After a conversation he now understands I don't sit there pressing the block button! I tried to run a report to see what was being blocked in a URL but the Reports section has completely changed and we're never issued with any user guides. When I asked support for help and/or a guide they couldn't help me either and said there weren't any guides available. I see in their latest email they are working on a user guide and we can email if we need to know how to do something. A little late in the day when you've been trying to use it for over a year! Support have also been extremely slow in dealing with calls logged, I'm waiting at least two days for a response and that is after responding the the 'Your case has been logged' email with I'm still waiting for a response to this. Okay Friday morning rant over! 1
clockend25 Posted September 14, 2018 Posted September 14, 2018 Prior to the six weeks break we had access to a number of websites via our NetSweeper filtering and thought (as all these sites were working) we were finally there with regards to getting things sorted. Since our return we are getting calls on a daily basis from staff who can no longer access websites they and students could happily access prior to the break. We changed absolutely nothing on our filtering over this period but somebody somewhere most definitely has! Finance were unable to log in to previously accessible bank sites, staff couldn't access online sites to place orders, pinterest would not allow access, goggle maps broke and this morning I walk into a HelpDesk ticket that bingmaps.com is no longer working. We are slowly resolving these on a site by site basis but this is extremely frustrating as all these sites worked perfectly before. Is anyone aware of an underlying change that could have affected multiple websites? It truly sucks to believe that your filtering was all correctly configured ready for the start of the academic years only to find out on day 1 that your department would be spending half its time trying to make previously accessible websites accessible again. Not a happy bunny ! I've logged on here this morning to post exactly the same. Lots and lots of issues with content being blocked via the default policy. Our finance department are still unable to order online with a credit card as something is blocking the verification process, and our media students cannot access Wix.
sister_annex Posted September 14, 2018 Posted September 14, 2018 We're seeing a lot of these type of errors in the console when trying to figure out what's going on. Redirect from 'https://s.pinimg.com/webapp/js/pjs-locale-en_US-lite-3dcf38fa608036c641ca.js' to 'https://authportal/authportal/auth.asp?cat=1,33,45&ttl=-200&groupname=default%5fweb%5ffiltering%40NSW%2d00AAA&policyname=default_web_filtering@NSW-00AAA&username=NSW%2d00AAA&userip=188.*.*.*&connectionip=127.0.0.1&nsphostname=proxy4.schoolsbroadband.net&protocol=icap&dplanguage=-&error=0&url=https%3a%2f%2fs%2epinimg%2ecom%2fwebapp%2fjs%2fpjs%2dlocale%2den%5fUS%2dlite%2d3dcf38fa608036c641ca%2ejs' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin 'https://www.pinterest.co.uk' is therefore not allowed access. Basically, it appears that sites don't like that the that the request is blocked as it appears that the request is coming from an unknown location for that site - and this has been the case for a large number of sites over the last 2 weeks The only way I have been able to sort this is by adding the offending sites into the Default Web Filter Rule thus avoiding the authportal redirect. Hopefully, once the new inline stuff gets out of Beta issues like this will become moot
sister_annex Posted September 14, 2018 Posted September 14, 2018 I've logged on here this morning to post exactly the same. Lots and lots of issues with content being blocked via the default policy. Our finance department are still unable to order online with a credit card as something is blocking the verification process, and our media students cannot access Wix. I had to add this site into the default rule to get Wix to work: static.parastorage.com The CC thing is a nightmare as they all use so many different portals for verification 1
clockend25 Posted September 14, 2018 Posted September 14, 2018 Thanks I'll give that a try. Could only see 'wixstatic.com' being blocked previously so fingers crossed...
Wubbalubbadub Posted September 14, 2018 Posted September 14, 2018 http://www.edugeek.net/forums/internet-related-filtering-firewall/199456-schools-broadband-netsweeper-transparent-line-beta.html#post1703059 If this helps anyone.. 1
TMBS Posted September 14, 2018 Author Posted September 14, 2018 The only way I have been able to sort this is by adding the offending sites into the Default Web Filter Rule thus avoiding the authportal redirect. How are you doing this? By adding the URL to Policy Manager for the default web filtering policy? Is anyone able to run logs? The platform has changed but when I add a filter for my policy, the default policy and my username it picks up no traffic. So I'm not even able to monitor where the traffic is going and being blocked.
Dom_ Posted September 14, 2018 Posted September 14, 2018 It doesn't flag usernames in the logs (at least, none of mine do), so you just have to sift through all the live default + applied policy data. Has anyone got the app store working? It works fine at some of my sites but not at all at some - all using the same shared policies!
clockend25 Posted September 14, 2018 Posted September 14, 2018 Yeah, requests hit the default policy unauthenticated so if something's being blocked there then you need to know the precise time and then go digging for the URL. Also note that anything unblocked on the default policy will be accessible for all users irrespective of settings on other policies.
sister_annex Posted September 14, 2018 Posted September 14, 2018 How are you doing this? By adding the URL to Policy Manager for the default web filtering policy? Yes, add it to the local list on the Default Policy - we've had to do this a number of times. As mentioned before; any sites added to this are available to everyone regardless of settings in other policies. The traffic to these sites is effectively anonymous.
TMBS Posted September 14, 2018 Author Posted September 14, 2018 It doesn't flag usernames in the logs (at least, none of mine do), so you just have to sift through all the live default + applied policy data. Has anyone got the app store working? It works fine at some of my sites but not at all at some - all using the same shared policies! We can filter by username in the Logs section. Is this what you mean? No the app store is still not working.
snagrat Posted September 29, 2018 Posted September 29, 2018 Can anyone explain what the Default Policy is used for? Surely if everyone is filtered by their AD group, or via the unauthenticated proxy ports then the default web filter rule shouldn’t be needed? I get a lot of sites that get filtered at the default level even though the site is allowed at the user level
azureusnation Posted September 29, 2018 Posted September 29, 2018 Because of how proxies work not all traffic is made in the users context. The machine also makes requests in its own unauthenticated context that is then picked up by the default policy. This is why I will be moving to Smoothwall and another provider when our contract is up in April as Proxy technology is old and out dated.
mavhc Posted September 29, 2018 Posted September 29, 2018 Is smoothwall not a proxy then (wrt filtering)? What is it?
ITGuyWestMidlands Posted September 30, 2018 Posted September 30, 2018 I think he is referring to it also being a transparent web filter
SchoolsBroadband Posted September 30, 2018 Posted September 30, 2018 Hi all, We've a few places left on the final beta of our new transparent filtering service and this gets rid of the issue mentioned. So no more proxy settings ever again. Feedback has been excellent so far. Do send me a PM if you'd like to go on it or be top of the list to migrate once final beta finishes in a month. Dave
AlanD Posted September 30, 2018 Posted September 30, 2018 We've a few places left on the final beta of our new transparent filtering service and this gets rid of the issue mentioned. So no more proxy settings ever again. If you don't use a proxy - there will be no automatic means for a PC to identify the user to the filter. So you would need a captive login page or something in addition to the the user logging onto the domain. ..or you need a identity client software app on the device.... So you probably would still choose to use a proxy for domain devices....
SchoolsBroadband Posted September 30, 2018 Posted September 30, 2018 Yes @AlanD that's correct. On our transparent solution we use either an agent on each PC or captive portal which syncs back to Windows AD, Azure AD or Googleauth. There's also a chrome plugin which works a treat too. We can also do IP based filtering but that of course only identifies the device and not the user. Dave
IrritableTech Posted September 30, 2018 Posted September 30, 2018 Yes @AlanD that's correct. On our transparent solution we use either an agent on each PC or captive portal which syncs back to Windows AD, Azure AD or Googleauth. There's also a chrome plugin which works a treat too. We can also do IP based filtering but that of course only identifies the device and not the user. Dave Can you not use Radius to filter based on user and do away with captive portal?
SchoolsBroadband Posted September 30, 2018 Posted September 30, 2018 yes I think you can. Thanks for pointing that out @IrritableTech as Netsweeper does support Radius. Dave
Blue_Cookeh Posted October 1, 2018 Posted October 1, 2018 (edited) We did our migration this morning and so far the lack of authportal redirection has meant web browsing feels a lot more snappy now. Oh... and no more proxy settings! Agent is super light and easy, logs are all top notch. If SB can keep their recent Netsweeper stability up it's all happy days Edited October 1, 2018 by Blue_Cookeh 2
ITGuyWestMidlands Posted October 1, 2018 Posted October 1, 2018 How does it deal with RDS (multiple sessions)?
Blue_Cookeh Posted October 2, 2018 Posted October 2, 2018 FWIW if you're on the new system with the Auth agent I've seen an issue where users' sessions expire in Netsweeper overnight and then in the morning they're considered "noauth" and forced back down to a Pupil profile. I assume this is because the auth agent is only run via a Logon script if you followed SB's instructions. Most of our staff (we're 100% Windows 10) don't actually log off their devices regularly, they just put them to sleep which obviously just locks their session rather than logs them out. I'll have a play around with task scheduler or something today to force a reauth every X minutes or something, unless @SchoolsBroadband has already caught this? 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now