Jump to content

Recommended Posts

Posted

Guys, the best thing you can do is buy your own leased internet line and bring filtering under the control of the school, managed and secured exactly to your requirements. Spend a little more, it’s certainly worth the investment in your network, business and pupils.

If you want free advice just ask?

  • Thanks 2
Posted (edited)
Guys, the best thing you can do is buy your own leased internet line and bring filtering under the control of the school, managed and secured exactly to your requirements. Spend a little more, it’s certainly worth the investment in your network, business and pupils.

If you want free advice just ask?

 

I think i will in future - i signed up to a 5 year contract with Schools Broadband, 2 years ago.. So i'm stuck for now. I'm looking for any excuse to escape! I think the primary schools we support are up much sooner. So i will move as they come!

Edited by Wubbalubbadub
Posted
The biggest benefit was that with something hosted, a tiny bit of responsibility was lifted and more importantly there were more than just the people on site available to remedy issues. For what it's worth, Lightspeed did that perfectly fine and if there were issues Schools Broadband could resolve them without any delay. It had it's issues, but swings and roundabouts.
Posted
Guys, the best thing you can do is buy your own leased internet line and bring filtering under the control of the school, managed and secured exactly to your requirements. Spend a little more, it’s certainly worth the investment in your network, business and pupils.

If you want free advice just ask?

 

To be clear, this is the case with SB. We still have control over our filtering and firewall setups, albeit they're not hosted on site. It's a far cry from the days of EMBC and centrally-enforced policies. Shudder.

 

Incidentally, I have a Bottle Rocket for sale if anyone's interested.

Posted

SB are not the only people to be backing away from Lightspeed. Others have had issues with Smoothwall (though I don't think they ever had an ISP scale offer). Fortinet waxes and wanes when it comes to HTTPS at ISP scale.

 

As a customer who asks questions and occasionally gets frank answers. I'm not sure anyone can solve today the technical challenges of providing filtering that genuinely covers school safeguarding / prevent requirements at 'national' ISP scale. It can be done with on prem boxes, but that costs a lot more because in 2018 you need failover and gigabit and https and behavioural/ML analysis.

 

I would be interested to know if the traffic / architecture of the US K12 internet filtering is comparable to the RBCs of old in the UK.

  • Thanks 1
Posted

I don’t know what the RBCs of old were, but I’ll try to give my perspective.

I am a small – medium sized districted compared to most.

We have ITC’s that I equate with your LEA. They provide central hosted systems including firewall, filtering, SIS/MIS, library, and fiscal. They are also the ISP.

Larger district host some if not all of that in house.

My ITC had / has a LS cluster for filtering, they struggled with bandwidth for a time. The LS system was rated to handle 10G of traffic, but only filter 2-3G of it. They floated the idea of moving some of the filtering to the edge to take the load off the cluster. This was all back on version 2.x

They also merged with company supplying another filtering platform. They offer both now.

Due to other issues I had with LS at the time, I switched to the other and have it on site, so I have full control.

I’ve learned the both platforms have their pros and cons.

The biggest issue with a central filtering solution is some settings are global and must be one way for all schools. Other settings such as allow lists and blocked / allowed categories can be managed by each school through the tiered admin setup.

The ITC would keep us updated with the software and occasionally needed to roll back when an issue was found. I have no doubt they are on 3.x now.

 

I will not speculate on why SB didn’t update, but just say an onsite device that you have full control over will always be better than a hosted system shared with other customers.

  • Thanks 1
Posted

RBCs are/were the Regional Broadband Consortia and they provide/d internet services to schools (and sometimes other local government services). They were formed by consortia of LEAs as it was considered that regional aggregation would provide the required economies of scale as it was envisaged that the programme required the building of physical infrastructure to meet the national specifications. An 'average' RBC would serve 2000 schools and 600,000 students.

 

psydii's 2018 UK School internet traffic (gu)estimates:

0.05 - 0.1 Mbit/sec/person (that is to say a school with 2000 people in it would saturate a 100Mb/sec line, not that each student uses 0.0.5Mbit/sec all day)

75% of this traffic is encrypted and therefore requires DPI, and MITM attacks.

Yet 5 years ago it was more like 20% of traffic was encrypted.

 

Each UK educational ISP / RBC might be seeing 20-100Gbit/sec traffic. As services move to the cloud these numbers are only going to rise... for example if every school in an "RBC" moved to hosted sims that could see RBC traffic rise by 10Gb/sec. This sort of increase often causes problems, for example when a system is built for 10 or 40Gb/sec and is running at close to capacity, the next step up might require a complete re-architecture of the DPI; vendors and products that can handle 10Gb/sec might not be capable of the same reliability of capabilities at 40Gb/sec.

 

For reference Fortinet's top of the line service provider kit has only started to hit these speeds for (DPI / HTTPS) on paper in the last year or two.

Posted
we heavily tested Fortinets filtering on our current hosted firewalls and some much larger ones in Fortinets labs in France for 3 days solid blitzing them with all kinds of configs and unfortunately we deduced the same that to do HTTPS filtering properly you'd need some ridiculously huge Fortigates which just weren't economically viable. Shame really as the Fortinet filtering when used in conjunction with FortiAnalyzer or Forticloud for reporting is miles better than it used to be.
Posted

Everyone could be right, from their own perspective, Lightspeed could have implemented fixes that required SB to completely rearchitect their network, SB could have asked LS to fix things in a way that would mean LS had to rearchitect their software/hardware.

 

With everything moving so fast, scaling so quickly, at some point something's going to break down, and someone's got to spend a lot of money changing things.

 

You can pay more to do it yourself, at more common scales, Gb rather than 100Gb, one config rather than 100 at the same time. Advantage is that's tested more.

 

As a school, what would you need when the main filtering is failing, an identical config on another system? A fallback system where almost everything/almost nothing is blocked, simpler? Would you want to configure, say, Gsuite and Office365 to have direct access?

Posted
To be clear, this is the case with SB. We still have control over our filtering and firewall setups, albeit they're not hosted on site. It's a far cry from the days of EMBC and centrally-enforced policies. Shudder.

 

Incidentally, I have a Bottle Rocket for sale if anyone's interested.

 

The only time we stopped schools doing completely their own thing was when they wanted to do something seriously stupid ... other LAs on EMBC operated differently, but Northants worked damn hard to be flexible.

Posted
Tellings lies Lightspeed are..... as SB suffers another critical outage...

Aggregation routers and web filtering are two different things. SB have already confirmed that this was a hardware problem not filtering.

Posted

Going from my experience of Lightspeed as a non-SB customer, our LA provides our broadband and uses Lightspeed filtering, and to be honest, its pretty much fine, rarely get any issue other than a new blocked site we need access to.

 

If it works for our LA, then logic surely states it should work for SB customers. Same in reverse, if SB customer have LS issues, then sure non-SB Lightspeed customers would have problems too?

Posted
Going from my experience of Lightspeed as a non-SB customer, our LA provides our broadband and uses Lightspeed filtering, and to be honest, its pretty much fine, rarely get any issue other than a new blocked site we need access to.

 

If it works for our LA, then logic surely states it should work for SB customers. Same in reverse, if SB customer have LS issues, then sure non-SB Lightspeed customers would have problems too?

 

LA setups are very different to ours. One very big and important difference is that an LA normally dictates what internal IP addresses ranges their schools use so there are no conflicts. Where as we have schools that use the same internal IP addresses. We can't just tell all of our customers to change IP address to make them work as Lightspeed is not VLAN aware.

 

Dave

  • 1 month later...
Posted
LA setups are very different to ours. One very big and important difference is that an LA normally dictates what internal IP addresses ranges their schools use so there are no conflicts. Where as we have schools that use the same internal IP addresses. We can't just tell all of our customers to change IP address to make them work as Lightspeed is not VLAN aware.

 

Dave

 

When we joined SB 2 years ago we had 2 VLANs but we were told that we had to change the IP range of 1 as it was already used within SB. So why was that?

Posted

Hi @fiza

 

We have multiple clusters of Rockets. Each cluster can use the same IP address as another cluster but you can't have say 192.168.0.0/24 more than once on the same cluster. At the time you came over it would guess that all of our clusters had that IP range taken already, hence why we needed you to change it. We kept this to an absolute minimum in the past where possible.

 

With Netsweeper it doesn't matter. All customers can use whatever internally IP addresses they like, so no need to reconfigure a new customers network to work with our service from an IP address point of view.

 

Dave

Posted

 

As a customer who asks questions and occasionally gets frank answers. I'm not sure anyone can solve today the technical challenges of providing filtering that genuinely covers school safeguarding / prevent requirements at 'national' ISP scale. .

 

..I'm not even sure it can be done on an individual school scale. Modern VPNs are so good (..or should that be bad..) that any BYOD device with one can drill straight though smoothwall and as far as I can tell most other filtering solutions....completely invisible...in fact ...it is that invisibility which allows me to know they are running a VPN!

 

And even for those without a VPN you have to add so many exceptions (its almost become a full time job) to allow mobile apps to run - by making them exceptions to https inspection....

 

And eat as much as you like data packages on devices of course mean that most students can get faster speeds staying on their 4G connection rather than using school wireless...In fact I think they should allow us to use 3G/4G blockers....

  • Thanks 3
Posted (edited)
..I'm not even sure it can be done on an individual school scale. Modern VPNs are so good (..or should that be bad..) that any BYOD device with one can drill straight though smoothwall and as far as I can tell most other filtering solutions....completely invisible...in fact ...it is that invisibility which allows me to know they are running a VPN!

 

And even for those without a VPN you have to add so many exceptions (its almost become a full time job) to allow mobile apps to run - by making them exceptions to https inspection....

 

And eat as much as you like data packages on devices of course mean that most students can get faster speeds staying on their 4G connection rather than using school wireless...In fact I think they should allow us to use 3G/4G blockers....

 

You're bang on with all that IMO - with the likes of certificate pinning coming in I don't see filtering as we have it today existing in 4-5 years time.

 

Cell blockers wouldn't be any good either, we have alarms, machines etc that rely on the cellular network, plus they're a good emergency alternative.

Edited by Blue_Cookeh
Posted
I'm still not sure what the point of filtering is, they have unfiltered phones and home internet, what are we protecting who from? It's an out of date system

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...