Jump to content

Recommended Posts

Posted
I think they are the default groups. We created our own groups and assigned our users accordingly in AD and then had our data re-imported so we could have the structure we wanted. You can add a new group in AD in the same OU as these default ones and it will create a corresponding group in NetSweeper BUT we were told that the group name must have "web filtering" on the end of its name in order for it to be created and for it to import users correctly.

 

Ok that's making sense now. So the pupil_web_filtering group has all pupils in it so could I create separate groups for Years 5 & 6 and have different polices for them? Would I have to take them out of the pupil_web_filtering group?

Posted
Just reading through the Netsweeper guide and I can already see that we are missing "Filtering Options" where incorrectly categorised URLs can be reported. Should we have this?
Posted
Ok that's making sense now. So the pupil_web_filtering group has all pupils in it so could I create separate groups for Years 5 & 6 and have different polices for them? Would I have to take them out of the pupil_web_filtering group?

 

Yeah - you'd need to get in touch with SBB to force synchronise the users once you've moved the groups (and possibly to add the new groups you've created)

  • Thanks 1
Posted
Yeah - you'd need to get in touch with SBB to force synchronise the users once you've moved the groups (and possibly to add the new groups you've created)

 

Is the sync not dynamic? What about when new students start, would they get added automatically because they will be in the correct group in AD or does that need a forced sync?

Posted
Is the sync not dynamic? What about when new students start, would they get added automatically because they will be in the correct group in AD or does that need a forced sync?

 

I think it does a daily update, but might be wrong, it's definitely not dynamic (yet - I believe Dave said it's something they're developing)

  • Thanks 1
Posted
I've been told changes are automatically synced once a day around 5pm. Beyond that you'll need to request a sync from SBB. I believe when they upgrade to the next version of Netsweeper it will reference AD directly and not require syncing.
  • Thanks 1
Posted

In the OU called Web Filter Groups, which contains the AD Groups that will be converted into NetSweeper Groups, you need to ensure your AD users are only a member of ONE AD group. If an AD User is in more than one AD Group, the import puts them in to a corresponding NetSweeper group based on alphabetical order which may give you unexpected results. In your case you would need to create a Year 5 and Year 6 AD group in the Web Filters Group OU (with "web filter" on the end of the AD Group name) and ensure that the correct AD users are in the correct AD group. This gets you to the point where the AD side of things are complete.

 

These NEW AD groups will be automatically imported into NetSweeper and become NetSweeper Groups and will have a single policy linked to them. However, as your AD User Accounts were previously members of in an existing AD group (pupil_Web_Filtering) they will not automatically move in NetSweeper to your new Year 5 and Year 6 NetSweeper Groups (NetSweeper Limitation). NetSweeper does add in completely new AD Users to the correct NetSweeper group BUT it does not automatically move existing AD Users to new NetSweeper groups if you move existing AD Users between AD Groups!

 

Due to this limitation, you will need to ask SBB to run a manual import for you which will effectively clear the memberships of the NetSweeper groups and repopulate them for you based on your current AD Structure of AD users and AD groups. You will need to repeat this request every time you move existing AD Users between AD Groups in this OU (doesn't apply to any AD Groups outside of this OU).

 

Once this is complete you should have the users where you want in NetSweeper and be able to configure your policies accordingly.

  • Thanks 2
Posted
I've been told changes are automatically synced once a day around 5pm. Beyond that you'll need to request a sync from SBB. I believe when they upgrade to the next version of Netsweeper it will reference AD directly and not require syncing.

 

We have had to ask every time. Although new groups may get created at 5pm the users definitely do not move between groups without you requesting a full import. We know this as without making this specific request we moved users and after three days they still hadn't moved. Requested a manual import and when that was done the users had moved.

 

Easy for you to check for yourself. Create a test account in one AD group, wait for it to import into NetSweeper then move it in AD and see it is moves in NetSweeper :)

  • Thanks 2
Posted
I've been told changes are automatically synced once a day around 5pm. Beyond that you'll need to request a sync from SBB. I believe when they upgrade to the next version of Netsweeper it will reference AD directly and not require syncing.

 

Correct. This is in v6 which we'll be rolling out in the summer and does LDAP lookups

 

Dave

Posted

You then have to import any Google Edu accounts to get Chromebook filtering to work...

 

I'm also getting students being blocked from accessing GDrive, despite asking on numerous occasions that it is allowed at all times. Not sure why it is proving to be such an issue? My latest request to unblock it has just been replied to with:

 

This would require that we unblock all ports other than 80 and 443 in order to allow this to work.

 

I'm no expert but that is ringing big warning bells!!!

Posted
You then have to import any Google Edu accounts to get Chromebook filtering to work...

 

I'm also getting students being blocked from accessing GDrive, despite asking on numerous occasions that it is allowed at all times. Not sure why it is proving to be such an issue? My latest request to unblock it has just been replied to with:

 

This would require that we unblock all ports other than 80 and 443 in order to allow this to work.

 

I'm no expert but that is ringing big warning bells!!!

Our users are getting into Drive but cannot share documents. It doesn't bring up the sharing dialogue box and eventually times out. I have raised this with SBB but not heard back yet.

Posted
Our users are getting into Drive but cannot share documents. It doesn't bring up the sharing dialogue box and eventually times out. I have raised this with SBB but not heard back yet.

 

We had this happen yesterday and ran chrome://restart to resolve the issue.

 

Scott at SBB managed to get our Chromebooks up and working. Might be worth asking for him to call you back :)

Posted
We had this happen yesterday and ran chrome://restart to resolve the issue.

 

Scott at SBB managed to get our Chromebooks up and working. Might be worth asking for him to call you back :)

 

We don't have Chromebooks at the School. This is using Drive on PCs.

Posted
We read this : https://helpdesk.netsweeper.com/docs/5.3/#t=User_Guides%2FManaging_Filtering_User_Acct%2FManaging_Filtering_with_a_User_Account.htm

 

Slightly simplified but : We have groups in AD for lower school, sixth form and staff. Each of these gets imported into NetSweeper as a Group with their own Policy. Within these policies you can tweak the allowed or denied categories for each individual group (we have one policy group).

 

We then have 5 shared lists:

 

Allowed for staff - linked only to the Staff policy

Allowed for Staff and sixth form - linked to the staff and sixth form policy

Allowed for Staff, sixth form and lower school (effectively everyone) - inked to all three policies

Denied for Students - Linked to sixth form and Lower school groups policies

Denied for Everyone - Linked to all three policies

 

Now this could be simplified and the allow and denies could be incorporated into the same shared list BUT you can set a shared list to accept only allow or deny rules. By separating the allow and deny lists we can hopefully eliminate someone going into a dual role list and accidentally selecting allow versus deny (or vice versa) as our lists wont allows you to enter the incorrect setting.

 

We used this :)

  • Thanks 1
Posted
Thanks. Do you have an alllow and deny list under Category Management on the left? I don't appear to have access to them.

 

Cheers

 

No, we don't...

Suppose it's worth asking what you are trying to achieve?

Posted

I have a problem with the proxy settings in IE (we run windows 7). The proxy is correctly set and I have exceptions in for local addresses but if I try to browse to the web ui of one of my switches I get the "ERROR: Failed to connect to host" screen which is the response sent by the proxy.

 

My exceptions are set like this : authportal;.local;172.*.*.*

 

 

Should that not bypass proxy for any local addresses?

Posted
hmmm we use a Pac/WPAD - I assume your switches are on the 172 range?

 

(when we excluded IP Addresses previously we just used 192.168.* - or in your case 172.*)

 

 

Yes they are. I set proxy details via registry GPP

I will try it with just 172.* and see what happens.

 

Thanks

Posted
You're welcome to have a copy of our PAC file if that helps?

 

Thanks. It would be good to see a working pac file and see where I went wrong.

Posted

This is ours (with identifiers removed and will need renaming to a .pac file) - they can be more complex, but this works great for us - we host it on the same IIS server as the Authportal but using a different host header i.e. http://pac/proxy.pac & http://wpad.domain.local/wpad.dat

 

there are extra steps needed to get wpad working (registry settings in DNS etc) however, if you're pushing your settings via GPP a pac file will be fine and Both Chrome and IE will use the same settings

 

We have had no issues with this at all

 

School.txt

Posted

Having a great day with this here. For schools that have switched with Chromebooks. We are being told we have got to put them all on an IP reservation and have that range applied to a single filter policy. Is this what other schools have had to do?

 

Previously staff and students have logged in and been able to get the same filter policy as the computers which worked so well. It is going to be so restrictive having them all on one policy.

 

Thanks

Posted
Having a great day with this here. For schools that have switched with Chromebooks. We are being told we have got to put them all on an IP reservation and have that range applied to a single filter policy. Is this what other schools have had to do?

 

Previously staff and students have logged in and been able to get the same filter policy as the computers which worked so well. It is going to be so restrictive having them all on one policy.

 

Thanks

 

I'm also guessing with this there is no auditing of what user has accessed certain sites whilst using them. Thankfully we don't use Chromebooks, however, our BYOD is currently non-existent because of this reason, that is until we can find a viable solution to user internet tracking on these devices.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...