Jump to content

Recommended Posts

Posted

A nice prevent compliant solution being provided by SchoolsBroadband then - good job!

 

You couldn't make it up - their name is Schools Broadband yet their solution doesn't meet the requirements that schools have to meet under their statutory duties - they literally market themselves solely to schools with a solution that is clearly unfit for schools.

Posted
A nice prevent compliant solution being provided by SchoolsBroadband then - good job!

 

You couldn't make it up - their name is Schools Broadband yet their solution doesn't meet the requirements that schools have to meet under their statutory duties - they literally market themselves solely to schools with a solution that is clearly unfit for schools.

I have found most products marketed as suitable for schools are intact not. Look at all the rubbish educational software that has been produced.
Posted
I have found most products marketed as suitable for schools are intact not. Look at all the rubbish educational software that has been produced.

 

Sorry, you are of course correct!

Posted (edited)
Sorry, you are of course correct!

 

Do you just moan? It is like a broken record! SchoolsBroadband have problems we get it, we are the customers but your comments don't help! If i read between the lines you are not even a customer!

Edited by Shadow_Walker
Posted (edited)
Do you just moan? It is like a broken record! SchoolsBroadband have problems we get it we are the customers but your comments don't help! If i read between the lines you are not even a customer!

 

Sorry I didn't realise I needed your permission to comment or that all my comments had to be positive even in the face of yet another howler from SB.

 

Whether I am a customer or I am not a customer of SB is really neither here nor there - we have a forum sponsor who lurches from problem to problem making huge sums of money out of the public purse.

 

If there weren't any problems then I'd have nothing to say about them would I?

 

The fact that they couldn't run a knees up in a brewery is not my fault.

 

I was also pointing out that a school using this product may be failing in the execution of their statutory duties - something incredibly serious.

Edited by Primus
Posted
Sorry I didn't realise I needed your permission to comment or that all my comments had to be positive even in the face of yet another howler from SB.

 

Whether I am a customer or I am not a customer of SB is really neither here nor there - we have a forum sponsor who lurches from problem to problem making huge sums of money out of the public purse.

 

If there weren't any problems then I'd have nothing to say about them would I?

 

The fact that they couldn't run a knees up in a brewery is not my fault.

 

I was also pointing out that a school using this product may be failing in the execution of their statutory duties - something incredibly serious.

 

It is constant though! How do you know the ins and outs of the problems, have you spoken to one of their account managers or do you just get your information from here? It's easy to criticise a company you don't use, just trying to stick the knife in a bit further!

 

In my last job we had RM Broadband and in 3 years i may have had 3 hours of downtime with them. I never criticised SB then when this was happening and now 2 of the academies in our MAT are with them and have had problems I tend to stick to talking the problems out with support and our account manager.

 

Your helping no one with this constant moaning!

Posted
It is constant though! How do you know the ins and outs of the problems, have you spoken to one of their account managers or do you just get your information from here? It's easy to criticise a company you don't use, just trying to stick the knife in a bit further!

 

In my last job we had RM Broadband and in 3 years i may have had 3 hours of downtime with them. I never criticised SB then when this was happening and now 2 of the academies in our MAT are with them and have had problems I tend to stick to talking the problems out with support and our account manager.

 

Your helping no one with this constant moaning!

 

Constant moaning? Before today the last time I commented on a SB related thread was February 11th?!

Posted
Constant moaning? Before today the last time I commented on a SB related thread was February 11th?!

 

Yes and how many times before then? Your not a customer so why do you see so interested in sticking the knife into them?

Posted

I haven't actually said whether I am or I'm not a customer.

 

I have however pointed out that in this thread I was pointing out that schools who follow SB's advice will not be Prevent compliant which is a big problem.

 

I have also pointed out this company make vast sums of money from the public purse by offering a poor service and they are a forum sponsor yet they frequently have major issues.

Posted
If they're leaving a bad impression here, that's a marketing problem for them. They're way more open than everyone else though, so pros and cons.
Posted
We've just tackled a similar issue with a Smoothwall school with devices that are otherwise untrackable; the world's worst ever Android that didn't come from a random Chinese knockoff factory, the Tesco Hudl. It took a lot of work but the easiest solution in the end was using RADIUS auth accounting via the wireless provider (Ruckus) to force logins and therefore track who was doing what with the internet. I'm sure Netsweeper is capable of handling RADIUS requests, perhaps that's something that'll be worth investigating?
  • Thanks 1
Posted (edited)

I was told by @SchoolsBroadband that Netsweeper didn't work with RADIUS. No idea if that's true or not, or if so whether the imminent upgrade will improve things.

 

Anyway, I'm still having daily struggles trying to get this solution working. Biggest issues remains the BYOD network which still isn't fit for mass-use. Otherwise it's constantly battling issues emanating from a botched migration. I discovered today that my PC was able to access the internet unfiltered if I removed the proxy. Apparently an engineer looking at an issue a few weeks ago had forgotten to remove a firewall policy he set up in the process.

Edited by clockend25
Posted
I haven't actually said whether I am or I'm not a customer.

 

I have however pointed out that in this thread I was pointing out that schools who follow SB's advice will not be Prevent compliant which is a big problem.

 

I have also pointed out this company make vast sums of money from the public purse by offering a poor service and they are a forum sponsor yet they frequently have major issues.

Well they’ve got to spend their ‘vast sums of money from the public purse’ somehow so why not spend it here to help keep the site running and give people, such as yourself, the opportunity to provide feedback.

  • Thanks 1
Posted

@clockend25 that's correct ref Radius for the moment. Netsweeper does work with Radius but our design implementation to scale and be resilient means that the proxy servers have to sit outside of the NAT which I'm told means that Radius won't yet work. We are working with Netsweeper on a software upgrade to allow Radius to work in full.

@Primus we do not make vast sums of money. We have just invested about £500,000 into our new Netsweeper platform. This has been a very strategic investment which will allow us to be able to filter and protect a much higher amount of bandwidth (we anticipate a huge increase over the next 2 years) which we couldn't do on our existing platform. We are a very important customer for Netsweeper and we're both working on a lot of additional features which you will see on our Netsweeper deployment before others.

 

I should also point out (and I don't mean this to brag as that's not my style) but last year we won Best Security at the Internet Service Provider Awards for our hosted Fortigate and filtering platform as well as Best Use of Business Cloud a couple of years ago for the same thing due to the level of security and protection of staff and children.

 

Finally we have been doing AD and other auth integration with advanced reporting for years as standard. Far longer than our biggest competitors in the market and most Local Authorities. You'd be surprised how many schools (primary in particular) still don't have any easy / decent way of telling who the end user actually is.

 

Our new Netsweeper platform is coming on leaps and bounds and thus far in 6 months has 100% uptime which is what we were trying to address and aim for due to historic issues affecting our previous vendors. Yes it takes a while for our customers, partners and our own engineers to fully learn the intricacies of the product but we're certainly getting there and are now having a lot of positive comments on increased speed, better reporting, no downtime. There's still some way to go of course and we've a lot coming up in the development roadmap which we'll keep you all up to date with as and when it's here.

 

Thanks to all of our loyal supporters in particular :)

 

Dave

  • Thanks 2
Posted

Morning All,

 

Firstly apologies to anyone waiting for a PM reply, spent the last 2 weeks upgrading LS filters and haven't had chance to get on here. Expect a reply today.

 

RE Chromebooks, the best solution currently (assuming you use Google auth) is to install the Netsweeper Chrome plugin, this will fully report the user logged in to the Chromebook to the Netsweeper Webadmin. The next problem is making sure those users exist on the Webadmin. At the moment we have to upload those users via CSV file so will need you to export from GSUITE (or similar) and provide us with a list. Google auth integration is one of the items on the roadmap Dave mentioned earlier and we are working with Netsweeper to achieve this as fast as possible.

 

As all your main LAN traffic uses specific proxy ports (generally 31280,) as an additional security measure we block 80/443 using the Fortigate. The Chrome plugin means that traffic actually uses 80/443 meaning our advice is to have the Chromebooks on one range so we can whitelist them on the Fortigate. This doesn't have to be the case, but in the event a pupil machine ends up without proxy settings we would rather they can't get to the internet unfiltered.

 

For those that don't use Google auth and also don't want unauthenticated filtering so long as the Chromebooks can communicate with the IIS server you can use NTLM to authenticate with your AD, in this case we would just use the standard proxy port instead of the plugin.

 

Just a final note on BYOD, the above also applies. If unauthenticated filtering is not sufficient you can just use NTLM to authenticate via AD.

 

Hope that helps,

 

Rob

  • Thanks 3
Posted

I should also point out (and I don't mean this to brag as that's not my style) but last year we won Best Security at the Internet Service Provider Awards for our hosted Fortigate and filtering platform

 

You have the best security in the world when your routers are offline.. no one can get in! [emoji6]

 

#onepeedoffcustomerofschoolsbroadband

#idontevenlikethehashtagthingsbutimthatannoyed

Posted

Overall we are now getting to grips with NetSweeper with regards to our internal network. However, from our WiFi network perspective we are unable to have the same solution we had in place as we had with Lightspeed, which at the moment means we have suspended all WiFi access until SLT agree with which approach we will now take, as none of the options open to us at the moment are ideal and each have their own pro's and cons.

 

In honesty, if I had been aware of this I would not have gone ahead with the "early" adoption of NetSweeper and would have delayed for a bit but as we thought we would have to go to NetSweeper eventually we took the opportunity to migrate over Feb Half Term.

 

Previously we could distinguish between staff and students on the same SSID (because of user authentication) and could give them the same level of internet access as they would have had on our internal network, all managed by central Lightspeed rules. Using AD Groups we also restricted access to just members of our sixth form and not the entire student cohort. Our WiFi network for this (BYOD) was largely isolated from our internal network in order to provide a level of insulation and was only used to provide access to the internet (not internal resources). We achieved this isolation by having the traffic for this SSID pass through a different port on the Mikrotik router but regardless of the Mikrotik port used, all traffic was managed by a single central set of rules in Lightspeed. We also had to do zero work on the client end other than to simply provide users with the SSID and password. As users still had to authenticate, we were still able to monitor internet usage and could also block an individuals access with a simple AD group change. With NetSweeper we have been advised that this approach cannot be used so we are having to consider which of our remaining options will be acceptable. This is a great shame as if the WiFi could be used in the same manner as before the transition from Lightspeed to Netsweeper would be largely complete by now.

 

Fortunately we have no Chromebooks internally so we haven't experienced the same issues that others are encountering on the internal side of their network. This is a shame as overall NetSweeper has some positive points and I'm sure from Schools Broadband's perspective its reliability and performance improvements are worth it. However, I feel it would have been better to have trialed this migration on only a few schools to help identify some of these client issues in advance so that they could be addressed before so many other schools migrated. Radius is a perfect example of this, although SBB and NetSweeper are working on this, it would have been better if this had been identified earlier and then some schools could have held off on their migration until this was resolved as this may help address some of the issues users are experiencing.

 

Unfortunately some schools have migrated their filtering only to discover that post migration their clients are not working, the system is more difficult to manage (from their perspective) and WiFi seems to have been considered as an after thought even though for most schools it is now an essential feature. This not only leads to frustrated support staff but this also frustrates staff and students who are already under pressure with exams rapidly approaching and resources that were previously and easily available being difficult to access.

 

I appreciate the effort that SBB are now putting into resolving this issue but the whole process feels rushed with insufficient testing carried out from the clients perspective, poor guidance and training resources for those that now need to manage NetSweeper onsite at schools and on occasion, conflicting information from SBB support staff as if they themselves are not fully sure of the correct way to implement the solution. I feel that SBB have some serious work to do in order to regain the confidence of its users and suspect that those coming up for renewal may well be looking elsewhere until these issues are fully resolved. Only time will tell if SBB are able to regain that confidence and deliver a solution which meets the various needs of a school environment.

  • Thanks 2
Posted
In the meantime could you perhaps run a RADIUS account server on a DC for instance, point your WiFi to that so it prompts for login credentials and push traffic through a local proxy such as squid for the time being to achieve what you need? It's far from ideal, as radius via the firewall/filter and wireless systems is almost a turnkey solution but you should be able to achieve something workable with no cost and relatively little effort. Have unauthenticated wifi clients go to a separate DHCP range maybe so they pick up the squid proxy as gateway. (thinking out loud, so could be rubbish!)
  • Thanks 1
Posted
Our new Netsweeper platform is coming on leaps and bounds and thus far in 6 months has 100% uptime which is what we were trying to address and aim for due to historic issues affecting our previous vendors. Yes it takes a while for our customers, partners and our own engineers to fully learn the intricacies of the product but we're certainly getting there and are now having a lot of positive comments on increased speed, better reporting, no downtime. There's still some way to go of course and we've a lot coming up in the development roadmap which we'll keep you all up to date with as and when it's here.

Well I'm glad you're happy with it!

Posted
Has anyone who has migrated over had problems with the fortinet vpn? When we try connect to it, it connects fine but then won't let us remote onto another computer or server via IP address or name.
Posted
Has anyone who has migrated over had problems with the fortinet vpn? When we try connect to it, it connects fine but then won't let us remote onto another computer or server via IP address or name.

 

Evening,

 

this sounds like a routing issue if you are connecting ok.

 

Suggest you take a tracert and send it to support who will look into it for you.

 

Thanks

 

Dave

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...