Jump to content

Recommended Posts

Posted

Hi I am not sure how many of you will be familiar with PBSA, it is a public sector broadband aggregate - I am not sure if this is a Wales only thing so apologies.

Basically we were forced to move from our existing Radio link, to a new PBSA organised fibre link to our LEA. Instead of running our own web filter we are now using Smoothwall.

 

We were assured that we would keep our existing IP addresses as I warned in no uncertain terms, if this changed then our services would break. (stupid me for not getting this in writing...)

Well the switchover happened on Monday, it all went fine but we had different IP addresses so our Exchange Server and DirectAccess did not work.

 

They have now changed the routing so that external --> internally, our IP addresses are back to normal (i.e. sending an e-mail to our domain works again).

 

However, when we send an e-mail from our mailserver, it is sent outbound on a PBSA IP address beginning with 159 instead of our usual 194.

I've changed our SPF records etc - but the problem is this IP address seems to be shared and it is on multiple blacklists! So over half of our e-mails are now being rejected, which is making Senior Management sad :-(

 

The LEA have basically said it is our problem now, first they said it was because our server supported out of date SSL (so scored an F on SSLlabs - now fixed, but not sure how that would relate...) - now they are saying we will have to ring every single host that our mail is being rejected by and request delisting! The problem is that this IP address appears to be a shared one so as soon as it is delisted, it will end up relisted just as quickly!

 

Does anyone have any experience with this? We were debating moving to the Cloud for our school e-mails this summer, I was against the idea but now I am thinking we should just do it. Ditch this exchange and just be done with it. None of the other schools in our LEA area have had this problem as they are all cloud hosted.

Posted
If clients are sending directly out you could source map the traffic to the IP you want using rules in the networking - configuration - source mat and LLB rules
Posted

PBSA is Wales only, as far as I know.

 

MX Toolbox is a good place to check the common blacklists: https://mxtoolbox.com/blacklists.aspx

Most email servers use these blacklists, so you shouldn't have to contact every recipient, just get yourselves delisted from those blacklists. But you're right that if you're on a shared IP, you're going to have problems with compromised hosts at other schools getting you relisted, and there isn't anything you can do about that - PBSA need to be proactively blocking compromised hosts for the good of everyone on the network.

 

Obviously make sure the spammers aren't on _your_ network before complaining too loudly :) but if PBSA won't take responsibility and clean up the hosts sharing that IP I don't think you have much alternative but to send your email via another host - either by using a cloud email system, or setting up your own SMTP relay somewhere out on the internet. Note that cloud systems are also shared, so do sometimes end up blacklisted, but the likes of Microsoft / Google / etc tend to give more of a damn about fixing the problem.

Posted (edited)
PBSA is Wales only, as far as I know.

 

MX Toolbox is a good place to check the common blacklists: https://mxtoolbox.com/blacklists.aspx

Most email servers use these blacklists, so you shouldn't have to contact every recipient, just get yourselves delisted from those blacklists. But you're right that if you're on a shared IP, you're going to have problems with compromised hosts at other schools getting you relisted, and there isn't anything you can do about that - PBSA need to be proactively blocking compromised hosts for the good of everyone on the network.

 

Obviously make sure the spammers aren't on _your_ network before complaining too loudly :) but if PBSA won't take responsibility and clean up the hosts sharing that IP I don't think you have much alternative but to send your email via another host - either by using a cloud email system, or setting up your own SMTP relay somewhere out on the internet. Note that cloud systems are also shared, so do sometimes end up blacklisted, but the likes of Microsoft / Google / etc tend to give more of a damn about fixing the problem.

 

Yeah, we are on some rotating outgoing e-mail, so our outgoing e-mails can be from about 4 different IP addresses. Every single one of them is on a blacklist. I did check our queues and our server is secure; plus we ran our mailserver on our old IP address for years with no problem at all.

 

I ended up doing as you suggested and using Microsoft's Office 365 mail protection; all our outgoing mail is routed through them via a send connector and it all works 100% now. It proves it wasn't our mailserver the whole time... I had spent probably 25 hours in total wasting my time rewriting SPF records, sending e-mails, explaining to staff what the delivery failure notification meant... plus all the problems to the school having important e-mails about upcoming events not getting out

 

These new IP addresses were having mail rejected from Day 1. The Police, Fire Service and NHS (infact anything public sector) all apparently use this PBSA as their ISP now, so it does make me wonder just how many of these Public Sector bodies are having e-mails denied so that members of the public think they are being ignored!

 

We were sold this thing as "it'll be a lot easier for you to manage, any problems we will fix them straight away, you will keep your old IP addresses and configuration" - if it was free I wouldn't be so bitter but we had to pay even more than we currently paid for our link and filtering solution (plus our filtering solution had A/V and antispam bundled in). We had no communication from PBSA, it has to go through our LEA so it becomes a nightmare.

The link itself and smoothwall etc - got no problems with it in and of itself, it works well. Just wish the communication was a lot better. they did nothing to find out what our requirements were.

 

Infact I remember our LEA basically told us we had to get this new link - we were threatened "unless you get this new filter and pay for it £6 per user per 3 years, you will breach GDPR, human rights act, and your school will be liable for £100,000 fines plus you personally will be liable for penalties" - so of course there is no way our SMT will decline that.

Anyone noticed that? firms threatening schools with scary fines to get cash? Kyocera threatened us with massive GDPR fines when we returned their leased printers - they said unless we pay £1000 per unit for a "memory wipe", they would not clear the RAM/HDDs of the units so when they are issued to other sites, there is a chance our school data would be on them so we'd breach GDPR - and even if I manually factory reset the units the data would still be there - I told them I'd never buy another Kyocera unit ever again... (but that is a rant for another section)

Edited by mikes
Posted
Infact I remember our LEA basically told us we had to get this new link - we were threatened "unless you get this new filter and pay for it £6 per user per 3 years, you will breach GDPR, human rights act, and your school will be liable for £100,000 fines plus you personally will be liable for penalties" - so of course there is no way our SMT will decline that.

 

Pretty shocking behaviour, but I'm sorry to say not completely unusual. I've seen similar behaviour from another LEA in the South of England (who shall remain nameless) who started threatening schools in a similar way when the schools made noises about leaving the LEA's broadband consortium. We picked up a few schools at that point, but many more enquiries that ultimately went nowhere as soon as the LEA put the frighteners on them.

 

For the sake of clarity: using your own filter and internet connection does *NOT* mean you are going to breach GDPR, Prevent, KCSIE, etc.. It means that you have to take responsibility for these things yourself, but you might do a better job of it than the LEA does. I'm also unconvinced that, were a GDPR breach to happen while you're using the LEA network, you would be able to absolve yourself of the liability by just pointing at the LEA and claiming it was their responsibility!

Anyone noticed that? firms threatening schools with scary fines to get cash? Kyocera threatened us with massive GDPR fines when we returned their leased printers - they said unless we pay £1000 per unit for a "memory wipe", they would not clear the RAM/HDDs of the units so when they are issued to other sites, there is a chance our school data would be on them so we'd breach GDPR - and even if I manually factory reset the units the data would still be there - I told them I'd never buy another Kyocera unit ever again... (but that is a rant for another section)

Wow, not come across that one before.

 

From a legal perspective, I would say that its the schools' responsibility to ensure that hardware is wiped before divesting themselves of it. Strictly speaking, sending the data to Kyocera for destruction would probably require there to be a written data processing agreement between the school and Kyocera.

 

Obviously this is a big problem if Kyocera provide no way for the customer to wipe the hardware (ok, so Kyocera will wipe returned hardware for a fee... What happens if the school wants to sell their old kit on ebay? You definitely have to wipe it yourself then!). I have no idea what happens if the hardware is dead (making any wiping functions unusable) and being returned under warranty. Same applies to things like dead unencrypted hard drives that are being returned under warranty...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...