Jump to content

Recommended Posts

Posted

Hi guys

 

I have been having a bit of a nightmare...

We've had internet speed and connectivity drops for some time.

My initial thought was an issue with the web filter (Lightspeed), as since we upgraded to 3.0 in about September 17 we had difficulties sometimes logging in etc.

 

Anyway several updates later etc, I was assured that it wasn't an issue with our rocket.

We then started looking at all kinds of other things. Our DNS servers (which were only virtualised last summer) I thought could have been an issue, then we were looking at our ISP as our bandwidth was maxxing out sometimes, then back to the filter as they'd released a new user agent (the LMA) which I wasn't aware of, a dodgy internal server was also looked at.

 

So at 3:30 Friday afternoon, which was an INSET Day so most staff left by that point, our internet fully goes down. Up until that it'd only been drops.

We unplug the entire network and patch things back in looking for a loop or something.

 

Turns out that when we remove the web filter all is absolutely perfect, speeds faster than ages, non drops or anything.

By this point I'd accepted that our out of warranty six year old filter had had it. I speak to their support guys in America, and run a workaround plan by them.

 

Workaround is to create a Virtual Rocket, backup the database and config from the physical and restore that to the virtual and then change the IP of the virtual to that of the physical, unplug the physical and hope that the clients user agent talks to the virtual as if it were physical. Their support guys said that's a great idea and I should go for it.

 

So I have spent the weekend creating a virtual rocket, and doing all that (given that the physical was faulting that took longer than I'd hoped).

But it seems that using a virtual as a filter on its own without a physical does not work. Their support guy who's oncall today on his own isn't sure why.

My staff and students return on Tuesday, with tomorrow being bank holiday and me actually being off until Thursday.

 

My workaround this evening is remove our current DNS forwarders and use OpenDNS.

This seems to be working fine, but I just read on another post that the free version is limited to 50 users.

 

Without really having the opportunity to test 50 users prior to Tuesday morning I wondered if anyone has any info on this limitation? Can't see anything about it on their website.

 

Any suggestions would be welcome at this time.

No V-Lans here and staff IPs are mixed in with students....

 

Cheers for any suggestions in advance...

Posted (edited)

Would it be possible to fire up a server with Untangle installed on a 30 day trial. I'm in the process of switching to Untangle (paid) and they offer a 30 day trial, which would help you in the short term. You don't need a super-powerful server, just multiple NICs and a half-decent PC.

 

Another option could be to grab yourself a Draytek router, on next day delivery, and purchase a WCF (Web Content Filtering) add-on - something in the region of £ 50 per year.

Comparison

 

All the best

 

EDIT: Draytek Vigor 2762n (Amazon Prime - delivered Tuesday 8th)

You can also have a 30-day trial for the Draytek Content filtering product - accessible from the webui of the router...

 

EDIT 2: Just remembered that OpenDNS operate a free (no signup required) blocking service called Family Shield which will always block domains that are categorised in their system as: Tasteless, Proxy/Anonymizer, Sexuality and Pornography.

 

To use this, simply set your DNS forwarders to:

208.67.222.123

208.67.220.123

Note, this is different to their sign-up (also free) service - they use 208.67.222.222, and 208.67.220.220

Reference: https://www.opendns.com/setupguide/?url=familyshield

Edited by mrwoberts
Posted

A free trial of flash start cloud filtering would get you out of a short term hole. They were at BETT this year and I'm helping them with their release of their Cloud Box product to the UK market later this year ( I'm just a school on the alpha release, not associated with them in any way)

 

http://www.flashstart.com

Posted
Would it be possible to fire up a server with Untangle installed on a 30 day trial. I'm in the process of switching to Untangle (paid) and they offer a 30 day trial, which would help you in the short term. You don't need a super-powerful server, just multiple NICs and a half-decent PC.

 

Another option could be to grab yourself a Draytek router, on next day delivery, and purchase a WCF (Web Content Filtering) add-on - something in the region of £ 50 per year.

Comparison

 

All the best

 

EDIT: Draytek Vigor 2762n (Amazon Prime - delivered Tuesday 8th)

You can also have a 30-day trial for the Draytek Content filtering product - accessible from the webui of the router...

 

EDIT 2: Just remembered that OpenDNS operate a free (no signup required) blocking service called Family Shield which will always block domains that are categorised in their system as: Tasteless, Proxy/Anonymizer, Sexuality and Pornography.

 

To use this, simply set your DNS forwarders to:

208.67.222.123

208.67.220.123

Note, this is different to their sign-up (also free) service - they use 208.67.222.222, and 208.67.220.220

Reference: https://www.opendns.com/setupguide/?url=familyshield

 

Thanks @mrwoberts

 

I had configured the OpenDNS signup free service with DNS servers 208.67.222.222, and 208.67.220.220.

That is working, but I am unsure whether they will run into any issues tomorrow when there are several hundred people using the network. I read on another Edugeek post that OpenDNS free is limited to 50 users. Does this mean that when we have lots of activity tomorrow that it would be stop filtering??

 

If so does the Family Shield have a similar limitation? I think I prefer the one I have already setup as it sounds like it's more geared towards enterprise than "family". Just where I am not actually in the next couple of days I want to be fairly confident that they're not going to run into all sorts of issues with me not there...

Posted
A free trial of flash start cloud filtering would get you out of a short term hole. They were at BETT this year and I'm helping them with their release of their Cloud Box product to the UK market later this year ( I'm just a school on the alpha release, not associated with them in any way)

 

FlashStart, the Internet protection - FlashStart

 

Thanks I am just going to have a look at this one, as a backup in the event that OpenDNS is not going to continue filtering beyond 50 users.

Posted

I’m not impressed by the lightspeed do this, oh does that not work response but...

 

Presumably your dns server are set up to use opendns as forwarders? In which case that may not get hammered that much and technically you’ve only got two or three ‘users’ querying them.

 

I hope lightspeed are more helpful tomorrow.

Posted

Another option could be to grab yourself a Draytek router, on next day delivery, and purchase a WCF (Web Content Filtering) add-on - something in the region of £ 50 per year.

Comparison

 

 

We use the DrayTek filter behind smoothwall....so that if smoothwall (and its aassociated cable connection fails, our FTTC connection (normally load balanced into smoothwall) can still supply internet which is at least filtered....if not monitored.

 

So its a bit of a belt and braces approach...in fact its pretty rare for anything to get through smoothwall and be blocked by the Draytek solution....but for £50 a year it provides us with peace of mind that we can at least continue to filter even if smoothwall failed.

 

...I've not tried openDNS..which seems a simple make do for now step....its not going to be robust of course...because users could just use IP addresses (unless you disallow this - but guessing even if you do - its done in the lightspeed rocket...)

Posted
I’m not impressed by the lightspeed do this, oh does that not work response but...

 

Presumably your dns server are set up to use opendns as forwarders? In which case that may not get hammered that much and technically you’ve only got two or three ‘users’ querying them.

 

I hope lightspeed are more helpful tomorrow.

 

They’ve been helpful overall and it was me who suggested the moving to virtual but there guy agreed that it was a perfect solution when perhaps it’s seemingly not.

 

Are you saying that each DNS server is a user? Yes we have 2 dns servers set up as forwarders so if the 50 user limit does exist then we should be fine. I was thinking this is applied to client users in which case we have 600 ish.

Posted
I’m guessing, but thinking about it how does opendns know how many ‘users’ are connecting. I think in all honesty it’s likely to be a rate limit on requests per hour by ip or something. Your internal dns will help limit the external requests, so you may well be fine.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...