Jump to content

Recommended Posts

Posted (edited)
@mrwoberts

 

Does it do per user filtering and reporting to the new KCSIE requirements ?

 

Yes. It has a Policy Manager (linked to AD) where you specify what policy is applied to a group of users. You can also create rules based on IP address, hostname, pretty much anything. I love the granularity.

 

I get reports (daily/monthly..) and instant alerts (triggered events).

 

I'm in the process of looking at the AD-connector script because I think it associated a device with an incorrect IP address. Other than that we get the kind of protection we've been looking for.

 

-- EDIT

 

Forgot to mention, you can block websites, allow but flag them, or block and flag. This is useful when trying to keep a balance between 'blanket blocking' and effective monitoring.

Edited by mrwoberts
  • Thanks 1
Posted
@mrwoberts

 

What made you go with Untangle?

 

I had a trial run of it and was impressed. It provides the protection we need - firewall, filter, reporting, cloud management

Aside from that, it actually turned out lower cost than other providers we approached. It certainly helped that we had some kit to reuse, otherwise we would have had an additional £ 500+ for hardware to factor in.

  • Thanks 1
Posted
It sure does, in a most excellent way (said in my best Bill and Ted voice)

Take a look at the live demo...

Untangle

Not to hijack, but do they state they implement the IWF blocklist anywhere?

Posted
It sure does, in a most excellent way (said in my best Bill and Ted voice)

 

Take a look at the live demo...

Untangle

 

That Untangled looks EPIC! to quote another popular phrase. Thanks for the heads up.

 

I find our current Smoothwall to be rather lacking.

Posted (edited)
Not to hijack, but do they state they implement the IWF blocklist anywhere?

 

Good question. In short, yes they do. Here's a link to the Filtering Provider Response on the SaferInternet site.

https://d1afx9quaogywf.cloudfront.net/sites/default/files/Filtering/Monitoring/2017%20Untangled%20-%20Filtering%20Provider%20response.pdf

 

It's worth noting that you will see an amber box in one of their responses, but when I delved deeper it I found a few items that satisfied the requirements...

 

  • Untangle.com are the manufacturer of our firewall/web filter. The filter automatically receives updates from a company called Zvelo who are members of the IWF.
  • The UK government CTIRU filtering list, not a public list, is provided to Zvelo, who use this in their database, which Untangle uses.
  • Categories Terrorism/Extremism are included in Hate Speech Untangle category.

 

Helpful forum posts

https://forums.untangle.com/feedback/38032-feature-request-web-filter-iwf-uk-government-ctiru.html

https://forums.untangle.com/web-filter/38129-web-filter-categorisation-anomalies.html

 

-- EDIT

Added bullet point

Edited by mrwoberts
Posted

We use a load balanced combination of a business fttc 80mb/s and a business 300 mb/s costing £50 and £80 a month. Contention is barely noticeable during the day...but perhaps a drop of 25% in evenings...so much faster than a leased 100mb line.... And a lot cheaper.

 

While filtering and blocking unsuitable material would be be necessary... Its monitoring that schools need to do... And producing reports of which user searched for what... Can be a challenge because in a primary school you may not be accustomed to have students login. Perhaps it's enough for reports to say which device... And teachers log which child used which device...

 

I think I'd be talking to Lea first... Because fees might include MIS use or other lea services.... And they will almost certainly require you to reconnect your MIS to their systems...

 

Sounds as if you could save money and get a faster connection... But it wouldn't be a cost free change... Nor effort free...

Posted

Moving from your LEA provider is perfectly possible and can save you money, but I'll list a few thoughts some of which haven't been covered in the thread from my experience...

 

It sounds like you don't have a great relationship with your IT support - if you can't get them on board, does the school have the knowledge in house of your existing network, vlans, IP ranges etc. to communicate this with a possible new provider - does that person have access to be able to achieve a move?

Have you the expertise in house to effectively maintain and monitor a filtering product? You'll need to ensure it is robust, effective, updated and otherwise fit for purpose. Or do you need a supplier who will fully take on this responsibility? Same goes for a firewall.

Are the LEA offering additional services which you may struggle, or have to outlay further public funds to replicate? Secure access to their hosted systems is a typical one, finance, trip management, enrollments, email, web hosting. They may charge you for accounts, tokens, support etc. all which you'll need to factor in.

Speed - are the services available in your area to boost your speed? In practice will they deliver? Some small village schools who think they are being charged a lot for very little find they are being heavily subsidized by the LEA to get a half decent connection to the premises.

What other services are provided over your LEA link? Telephones, the library attached next door, community wifi?

Posted
We use a load balanced combination of a business fttc 80mb/s and a business 300 mb/s costing £50 and £80 a month. Contention is barely noticeable during the day...but perhaps a drop of 25% in evenings...so much faster than a leased 100mb line.... And a lot cheaper.

 

@AlanD Care to give us a bit more as in providers and what you use to load balance and filter please.

 

Ta

Posted
Moving from your LEA provider is perfectly possible and can save you money, but I'll list a few thoughts some of which haven't been covered in the thread from my experience...

 

It sounds like you don't have a great relationship with your IT support - if you can't get them on board, does the school have the knowledge in house of your existing network, vlans, IP ranges etc. to communicate this with a possible new provider - does that person have access to be able to achieve a move?

 

 

The move would have to be carried out and set up by our IT support company. They should be capable of this but from experience they seem to not be too familiar with school systems.

 

Have you the expertise in house to effectively maintain and monitor a filtering product? You'll need to ensure it is robust, effective, updated and otherwise fit for purpose. Or do you need a supplier who will fully take on this responsibility? Same goes for a firewall.

 

I should be able to maintain and monitor the filtering. That is currently our situation anyway. I could probably do the firewall as well if given the correct access to our systems, but we could easily get the IT support to set that up.

 

 

Are the LEA offering additional services which you may struggle, or have to outlay further public funds to replicate? Secure access to their hosted systems is a typical one, finance, trip management, enrollments, email, web hosting. They may charge you for accounts, tokens, support etc. all which you'll need to factor in.

 

The only thing still provided through the LEA is the phone lines and proxy. All our emails are done through Office 365 which I / IT support manage.

 

We are still in a transitional phase so we're not 100% certain what things we'll have to keep or replace that are linked with the LEA. This is part of the problem at the moment- 'the powers that be' decided to drop county IT support without really thinking it through and took on a IT company which I told them wouldn't meet our needs. We are now in the early stages of being in a MAT and nobody seems to have a clue what they're doing.

Meanwhile, I'm trying to keep our ICT infrastructure up and running while trying to scavenge details from people who don't really know anything and don't seem to care :ohwell:

 

Speed - are the services available in your area to boost your speed? In practice will they deliver? Some small village schools who think they are being charged a lot for very little find they are being heavily subsidized by the LEA to get a half decent connection to the premises.

What other services are provided over your LEA link? Telephones, the library attached next door, community wifi?

 

We're in a urban area surrounded by modern residential estates. I'm not sure how far away the nearest cabinet we are but I'm fairly sure we could atleast get 40Mbs FTTC, if not a cable connection. Nearest high-school is a fair way away, but there is another primary school about 1km away.

Posted
@AlanD Care to give us a bit more as in providers and what you use to load balance and filter please.

 

Ta

 

Ah sorry - yes...FTTC is with plusnet....and we pay extra for 4 hour guarantee of service (Beware....guarantee of service...does not mean guarantee of internet provision - it means someone will be on site....or contact within 4 hours...as anyone with a leased line that fails will tell you....you can still be without internet for a fortnight should your leased line go down...longer if it means fixing underground connections....but they will have met their 4 hour response time by sending someone to you to shake their head and agree with you that there is a problem that needs to be solved.)

 

And the 300Mb/s is with Virgin...who seem to have some kind of contempt for public sectors - denying them the services and advantages that are available to "business". I never quite understood why they should be treated differently - especially when paying the same fee, but apparently its something to do with business services being "managed" outside the UK...but they are not allowed to do that for public services...

 

And we use smoothwall to monitor (and less importantly filter)....which costs a fortune...but does have good prevent strategy reporting "out of the box". There is a bit of me wanting to say its the only thing that is good about it. Note again, that it is "monitoring" which is key. Any number of free solutions will filter - or you could get yourself a draytek router and pay £40 for their DNS filtering....PFsense is another widely used free product - unless you pay for support.... or use Open DNS ....but not all of these filters use the non published filter/want lists that government make available for the prevent strategy. Many opensource...or American based filters don't even know about the prevent strategy....and while you could complete a list of your own keywords to flag up in searches for radicalisation, self harm, grooming or whatever.....frankly you have not got time to do this....and probably not the expertise either. We needed a solution that would be a firewall as well and one which provided reverse proxy (because we have internal web sites that need to be accessed)...and quite liked the way smoothwall incorporates a radius server so it knows about BYOD users...I think the Sophos UTM does all this too - but not so good at the prevent monitoring....but does do SSO for reverse proxy....

  • Thanks 1
Posted (edited)

At our main site we currently use 300mb Virgin cable and 80mb plus net as failover. However we’ve just moved to a 100mb leased line.

We have another school joining our MAT and we are putting them on an 80/20 EoFTTC line. Have you considered a provider that provides that service?

 

As above, just check things like sims, anycomms etc don’t rely on you been on an LA connection. The school we are taking has one big AD connected to rest of LA sites

Edited by karldenton
Posted
We needed a solution that would be a firewall as well and one which provided reverse proxy (because we have internal web sites that need to be accessed)...and quite liked the way smoothwall incorporates a radius server so it knows about BYOD users...I think the Sophos UTM does all this too - but not so good at the prevent monitoring....but does do SSO for reverse proxy....

Did you happen to look into the Azure application proxy https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/application-proxy when looking for a solution to exposing internal services externally?

We've used it extensively and found it to be brilliant at what it does, as well as incredibly simple deployment of 2FA to applications that wouldn't have supported it otherwise.

Posted
The move would have to be carried out and set up by our IT support company. They should be capable of this but from experience they seem to not be too familiar with school systems.

 

 

 

I should be able to maintain and monitor the filtering. That is currently our situation anyway. I could probably do the firewall as well if given the correct access to our systems, but we could easily get the IT support to set that up.

 

 

 

 

The only thing still provided through the LEA is the phone lines and proxy. All our emails are done through Office 365 which I / IT support manage.

 

We are still in a transitional phase so we're not 100% certain what things we'll have to keep or replace that are linked with the LEA. This is part of the problem at the moment- 'the powers that be' decided to drop county IT support without really thinking it through and took on a IT company which I told them wouldn't meet our needs. We are now in the early stages of being in a MAT and nobody seems to have a clue what they're doing.

Meanwhile, I'm trying to keep our ICT infrastructure up and running while trying to scavenge details from people who don't really know anything and don't seem to care :ohwell:

 

 

 

We're in a urban area surrounded by modern residential estates. I'm not sure how far away the nearest cabinet we are but I'm fairly sure we could atleast get 40Mbs FTTC, if not a cable connection. Nearest high-school is a fair way away, but there is another primary school about 1km away.

 

Hi Tooplanx,

 

I'd be happy to provide you with some options and pricing for solutions to meet your needs. Please drop me a PM or contact me using my details below if that's of interest.

 

cheers

  • 2 weeks later...
Posted (edited)

Hi

I've been doing what you're suggesting at a similar sized primary for around 3 years now.

 

I'm using business FTTC (80/20) from Spitfire Internet (around £60/month inc. line rental). Would probably use Zen now.

Router is a used Draytek 2830 (eBay £30) which has been rock solid and has enough performance for an 80mbps connection.

 

I have a Gen7 HP Microserver upgraded to 8GB RAM, additional dual NIC, 40GB SSD for OS and 250GB cache disk for Squid. Running Ubuntu server (no GUI).

Software includes:

Shorewall Firewall

Squid Proxy

E2Guardian Webfilter

Shalla Blacklists

 

Filter updates automatically from Shalla weekly and confirms this to me via email. MITM SSL interception configured for pupils. I hold pre-configured spares for the router and Microserver. I use this as a test rig at home to evaluate changes and test any tricky filtering scenarios.

 

Performance is good and it saves around £2K annually compared to a commercial provider. If you wanted to do something similar happy to help (can send you a disk which you plug into a Microserver and have a test system up and running in a few hours).

Edited by ReBoot
Posted
@ReBoot perhaps I've missed it but I can't see where you are implementing the IWF blocklist?

 

I would like to implement the blocklist but the IWF choose to operate in secrecy. The relative risk of not blocking this list locally is small as it is already blocked by 95% of UK ISPs and major search providers such as Microsoft and Google. The IWF list is around 500-800 URLs (not domains) - I currently block 800K adult domains and 50K adult URLs.

 

The simple answer if deploying a solution such as I proposed is to go with an ISP who already block the IWF list. From a procurement perspective it does feel like there is a filtering cartel in operation who inflate prices and pass this on to schools who are already stretched financially.

 

This looks like a move in the right direction. http://icalert.com/about/

Posted
I would like to implement the blocklist but the IWF choose to operate in secrecy...[/url]

 

The IWF is an essential resource for any reputable filtering solution (my opinion). I couldn't see it stipulated in the KCSIE or PREVENT guidance (someone please correct me), and I can't imagine you would have your hands slapped by an Ofsted inspector for not including it, but I personally would just want the peace of mind of having a package that ticks these boxes. Have you taken a look at the Filtering provider responses ?

LINK

 

A lot of those filtering solutions will implement a database of millions of domains/URLs. Hard to beat a paid solution when you think of the resources needed to keep ahead of the game in the realm of filtering.

 

Thanks for sharing your solution though, especially the icalert link.

Posted

Don't confuse the IWF blocklist with the more general blacklists used in most filtering appliances. The IWF list is tiny and already blocked by the majority of ISPs and search providers. I wouldn't therefore see it as an essential resource but good if you can include it.

 

The lists I use block around 1.8 million domains and URLs. The IWF list blocks 500-800.

 

The IWF does come in for some criticism I suggest you read its Wikipedia entry.

 

"In February 2009 a Yorkshire-based software developer lodged a formal complaint regarding the IWF status as a charity with the Charity Commission, in which he pointed out that "regulating the worst of the internet" was "not really a charitable purpose", and that the IWF existed mainly to serve the interests of ISPs subscribing to it rather than the public. An IWF spokesperson said that the IWF had attained charitable status in 2004 "in order to subject itself to more robust governance requirements and the higher levels of scrutiny and accountability which charity law, alongside company law, brings with it".[59] The IWF is listed by fakecharities.org, "a directory of those so-called charities that receive substantial funding from either the UK or EU governments".[60] It has also been termed a quango by critics, implying poor management and lack of accountability."

Posted

It's entirely possible I don't fully understand the scope of IWF, but just a brief look on their website suggests something a but more substantial that you are giving them credit for,

 

"More than 1,000 webpages are assessed and removed each week by our analysis." I'm confused how they could do all that simply by blocking 500-800 urls. Do you have some info regarding those states, I'm genuinely interested.

 

re: wiki article - I support just about every company engaged in this kind of activity will come under criticism, after all, they are essentially 'policing' content on the internet, which I'm happy about.

Posted (edited)

https://www.iwf.org.uk/become-a-member/services-for-members/url-list/url-blocking-faqs

 

Look under what is the IWF URL List

 

The IWF list contains specific web pages, or URLs. Every URL on the list depicts indecent images of children, advertisements for or links to such content, on a publically available website. The list typically contains 500 - 800 URLs at any one time and is updated twice a day to ensure all entries are still live.

 

Any child sexual abuse content on a UK website is removed within hours so this content is not added to the list. Details of any child sexual abuse content hosted outside the UK are passed to Hotline in that country so they can investigate it within their own legislation and with their national law enforcement agencies. Whilst processes to have the content removed are instigated, the specific URLs are added to a list which we make available to service providers, under licence, so they can develop technical solutions to prevent their users being accidentally exposed to it.

 

We have no plans to extend the type of content included on the list.

Edited by ReBoot
  • Thanks 1
Posted (edited)

For info, as it seems topical, Safer Internet Centre have updated their guidance for Appropriate Filtering for Education downloadable .pdf here:

 

https://www.saferinternet.org.uk/advice-centre/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering

 

not wanting to re-state what many already know, more info at NEN.gov.uk

 

both of which are advocated within the statutory guidance for Keeping children safe in education from the DFE; KCSIE 2016

 

I'm all for finding a cheaper/better way of doing things within schools, especially considering how constrained budgets are, but some areas have a higher consideration than simple cost.

 

cheers

 

Lee

 

edit:

Annex C of the KCSIE doc is where it refers to UK Safer Internet Centre guidance

Edited by Wave9_Lee
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...