Jump to content

Recommended Posts

  • 3 weeks later...
Posted
Prior to the six weeks break we had access to a number of websites via our NetSweeper filtering and thought (as all these sites were working) we were finally there with regards to getting things sorted. Since our return we are getting calls on a daily basis from staff who can no longer access websites they and students could happily access prior to the break. We changed absolutely nothing on our filtering over this period but somebody somewhere most definitely has! Finance were unable to log in to previously accessible bank sites, staff couldn't access online sites to place orders, pinterest would not allow access, goggle maps broke and this morning I walk into a HelpDesk ticket that bingmaps.com is no longer working. We are slowly resolving these on a site by site basis but this is extremely frustrating as all these sites worked perfectly before. Is anyone aware of an underlying change that could have affected multiple websites? It truly sucks to believe that your filtering was all correctly configured ready for the start of the academic years only to find out on day 1 that your department would be spending half its time trying to make previously accessible websites accessible again. Not a happy bunny !
  • Thanks 1
Posted

We've had the same issue too. Lots of previously accessible sites, and sites we'd unblocked ourselves in Netsweeper no longer work, which is extremely frustrating for staff and students. I picked up an extremely rude word in our filtering that a student had typed in about me 'Miss B******* is a c***', simply because he got that frustrated about 'me' blocking everything and he couldn't complete his courseswork! After a conversation he now understands I don't sit there pressing the block button!

 

I tried to run a report to see what was being blocked in a URL but the Reports section has completely changed and we're never issued with any user guides. When I asked support for help and/or a guide they couldn't help me either and said there weren't any guides available. I see in their latest email they are working on a user guide and we can email if we need to know how to do something. A little late in the day when you've been trying to use it for over a year!

 

Support have also been extremely slow in dealing with calls logged, I'm waiting at least two days for a response and that is after responding the the 'Your case has been logged' email with I'm still waiting for a response to this.

 

Okay Friday morning rant over!

  • Thanks 1
Posted
Prior to the six weeks break we had access to a number of websites via our NetSweeper filtering and thought (as all these sites were working) we were finally there with regards to getting things sorted. Since our return we are getting calls on a daily basis from staff who can no longer access websites they and students could happily access prior to the break. We changed absolutely nothing on our filtering over this period but somebody somewhere most definitely has! Finance were unable to log in to previously accessible bank sites, staff couldn't access online sites to place orders, pinterest would not allow access, goggle maps broke and this morning I walk into a HelpDesk ticket that bingmaps.com is no longer working. We are slowly resolving these on a site by site basis but this is extremely frustrating as all these sites worked perfectly before. Is anyone aware of an underlying change that could have affected multiple websites? It truly sucks to believe that your filtering was all correctly configured ready for the start of the academic years only to find out on day 1 that your department would be spending half its time trying to make previously accessible websites accessible again. Not a happy bunny !

I've logged on here this morning to post exactly the same. Lots and lots of issues with content being blocked via the default policy. Our finance department are still unable to order online with a credit card as something is blocking the verification process, and our media students cannot access Wix.

Posted

We're seeing a lot of these type of errors in the console when trying to figure out what's going on.

 

Redirect from 'https://s.pinimg.com/webapp/js/pjs-locale-en_US-lite-3dcf38fa608036c641ca.js' to 'https://authportal/authportal/auth.asp?cat=1,33,45&ttl=-200&groupname=default%5fweb%5ffiltering%40NSW%2d00AAA&policyname=default_web_filtering@NSW-00AAA&username=NSW%2d00AAA&userip=188.*.*.*&connectionip=127.0.0.1&nsphostname=proxy4.schoolsbroadband.net&protocol=icap&dplanguage=-&error=0&url=https%3a%2f%2fs%2epinimg%2ecom%2fwebapp%2fjs%2fpjs%2dlocale%2den%5fUS%2dlite%2d3dcf38fa608036c641ca%2ejs' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin 'https://www.pinterest.co.uk' is therefore not allowed access.

Basically, it appears that sites don't like that the that the request is blocked as it appears that the request is coming from an unknown location for that site - and this has been the case for a large number of sites over the last 2 weeks

 

The only way I have been able to sort this is by adding the offending sites into the Default Web Filter Rule thus avoiding the authportal redirect.

 

Hopefully, once the new inline stuff gets out of Beta issues like this will become moot

Posted
I've logged on here this morning to post exactly the same. Lots and lots of issues with content being blocked via the default policy. Our finance department are still unable to order online with a credit card as something is blocking the verification process, and our media students cannot access Wix.

 

 

I had to add this site into the default rule to get Wix to work: static.parastorage.com

 

The CC thing is a nightmare as they all use so many different portals for verification

  • Thanks 1
Posted
The only way I have been able to sort this is by adding the offending sites into the Default Web Filter Rule thus avoiding the authportal redirect.

 

How are you doing this? By adding the URL to Policy Manager for the default web filtering policy?

 

Is anyone able to run logs? The platform has changed but when I add a filter for my policy, the default policy and my username it picks up no traffic. So I'm not even able to monitor where the traffic is going and being blocked.

Posted

It doesn't flag usernames in the logs (at least, none of mine do), so you just have to sift through all the live default + applied policy data.

 

Has anyone got the app store working? It works fine at some of my sites but not at all at some - all using the same shared policies!

Posted
Yeah, requests hit the default policy unauthenticated so if something's being blocked there then you need to know the precise time and then go digging for the URL. Also note that anything unblocked on the default policy will be accessible for all users irrespective of settings on other policies.
Posted
How are you doing this? By adding the URL to Policy Manager for the default web filtering policy?

 

Yes, add it to the local list on the Default Policy - we've had to do this a number of times.

 

As mentioned before; any sites added to this are available to everyone regardless of settings in other policies. The traffic to these sites is effectively anonymous.

Posted
It doesn't flag usernames in the logs (at least, none of mine do), so you just have to sift through all the live default + applied policy data.

 

Has anyone got the app store working? It works fine at some of my sites but not at all at some - all using the same shared policies!

 

We can filter by username in the Logs section. Is this what you mean?

 

No the app store is still not working.

  • 3 weeks later...
Posted

Can anyone explain what the Default Policy is used for?

 

Surely if everyone is filtered by their AD group, or via the unauthenticated proxy ports then the default web filter rule shouldn’t be needed?

 

I get a lot of sites that get filtered at the default level even though the site is allowed at the user level

Posted
Because of how proxies work not all traffic is made in the users context. The machine also makes requests in its own unauthenticated context that is then picked up by the default policy. This is why I will be moving to Smoothwall and another provider when our contract is up in April as Proxy technology is old and out dated.
Posted

Hi all,

 

We've a few places left on the final beta of our new transparent filtering service and this gets rid of the issue mentioned. So no more proxy settings ever again.

 

Feedback has been excellent so far. Do send me a PM if you'd like to go on it or be top of the list to migrate once final beta finishes in a month.

 

Dave

Posted

We've a few places left on the final beta of our new transparent filtering service and this gets rid of the issue mentioned. So no more proxy settings ever again.

 

 

If you don't use a proxy - there will be no automatic means for a PC to identify the user to the filter. So you would need a captive login page or something in addition to the the user logging onto the domain.

 

..or you need a identity client software app on the device....

 

So you probably would still choose to use a proxy for domain devices....

Posted

Yes @AlanD that's correct.

 

On our transparent solution we use either an agent on each PC or captive portal which syncs back to Windows AD, Azure AD or Googleauth. There's also a chrome plugin which works a treat too.

 

We can also do IP based filtering but that of course only identifies the device and not the user.

 

Dave

Posted
Yes @AlanD that's correct.

 

On our transparent solution we use either an agent on each PC or captive portal which syncs back to Windows AD, Azure AD or Googleauth. There's also a chrome plugin which works a treat too.

 

We can also do IP based filtering but that of course only identifies the device and not the user.

 

Dave

 

Can you not use Radius to filter based on user and do away with captive portal?

Posted (edited)

We did our migration this morning and so far the lack of authportal redirection has meant web browsing feels a lot more snappy now. Oh... and no more proxy settings! :cool:

 

Agent is super light and easy, logs are all top notch. If SB can keep their recent Netsweeper stability up it's all happy days :)

Edited by Blue_Cookeh
  • Thanks 2
Posted

FWIW if you're on the new system with the Auth agent I've seen an issue where users' sessions expire in Netsweeper overnight and then in the morning they're considered "noauth" and forced back down to a Pupil profile.

 

I assume this is because the auth agent is only run via a Logon script if you followed SB's instructions. Most of our staff (we're 100% Windows 10) don't actually log off their devices regularly, they just put them to sleep which obviously just locks their session rather than logs them out. I'll have a play around with task scheduler or something today to force a reauth every X minutes or something, unless @SchoolsBroadband has already caught this? :)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...