browolf Posted July 11, 2019 Posted July 11, 2019 just make sure you set the certificate and agent to install NOW before it happens.... then it will just work Should I install the user settings GPO beforehand also?
Joanne Posted July 11, 2019 Author Posted July 11, 2019 Yeah, that installs the certificate. The only thing I left was the PAC file for the iPads. But you can do it all before the change. Keep an eye out for that MDM setting.... you gotta remember to add your wifi security key in... a few of us didn't and had to re-attached all of our ipads to the wifi! 1
1TF0rward Posted July 11, 2019 Posted July 11, 2019 Yeah, that installs the certificate. The only thing I left was the PAC file for the iPads. But you can do it all before the change. Keep an eye out for that MDM setting.... you gotta remember to add your wifi security key in... a few of us didn't and had to re-attached all of our ipads to the wifi! I have just sent the pac though Lightspeed MDM. WiFi settings are already there is that okay?
browolf Posted July 11, 2019 Posted July 11, 2019 Should I be able to log on to the netsweeper portal prior to our switch over? (which is monday incidentally)
Mark182 Posted July 11, 2019 Posted July 11, 2019 Should I be able to log on to the netsweeper portal prior to our switch over? (which is monday incidentally) We move over Monday at 4pm!
ticktock Posted July 11, 2019 Posted July 11, 2019 Yes, you will need to setup your policies. Download the documentation from BTLS. Quite a bit of work involved.
Mark182 Posted July 11, 2019 Posted July 11, 2019 Yes, you will need to setup your policies. Download the documentation from BTLS. Quite a bit of work involved. We are as 'ready' as can be
browolf Posted July 11, 2019 Posted July 11, 2019 BTLS says "accounts will be created on the day of migration and emailed out to the head, bursar and IT coordinator."
ticktock Posted July 11, 2019 Posted July 11, 2019 You can login using this via office 365: https://filter.education.btlancashire.co.uk/webadmin/start/
Joanne Posted July 12, 2019 Author Posted July 12, 2019 ^^ Yeah you can log in beforehand using O365 credentials. I've been perusing my NetSupport today and found that kids have been getting onto YouTube.... no idea how though... also can't seem to find a report on Netsweeper that I can search with computer name....
Paul_L Posted July 12, 2019 Posted July 12, 2019 ^^ Yeah you can log in beforehand using O365 credentials. I've been perusing my NetSupport today and found that kids have been getting onto YouTube.... no idea how though... also can't seem to find a report on Netsweeper that I can search with computer name.... Is this from an iPad? or a device not on your domain (ie a device that does not have the agent on)?
Joanne Posted July 12, 2019 Author Posted July 12, 2019 (edited) it's from a laptop. Got 2 different kids on 2 different laptops which NetSupport picked up on. I have the machine names and the kids usernames... my IP lease time is 8 hours, so each machine gets a different IP each day. NetSweeper doesn't seem to like that, even though it's totally normal thing to have set up. I've opened a call with BTLS. I want to know how it's happened. I want to know what report to run on Netsweeper, because all the reports I run give me pie charts.... I just want a web activity report based on computer name within the space of a couple of hours. Was EZPZ on Lightspeed.... EDIT: assuming this means he got onto youtube.... or could it be that there was an embedded video in the website? This is on NetSupport.... Edited July 12, 2019 by Joanne
browolf Posted July 16, 2019 Posted July 16, 2019 (edited) ^^ Yeah you can log in beforehand using O365 credentials. You have to be "set up" for that to work. Our migration was a disaster because they didn't set up any accounts to login to the configuration and they didn't email anyone. I had deployed the client and the certificate. After I called this morning, they rolled it back it to lightspeed and set me up on the system with my o365 account. 2 hours later I've just found out that the roll back has also failed and now we have no filtering. at all. everything works. Waiting for them to figure that out. Edited July 16, 2019 by browolf
Mark182 Posted July 16, 2019 Posted July 16, 2019 Our move last night went really well. Just sorting out the captive port out for the ipads ect.
1TF0rward Posted July 16, 2019 Posted July 16, 2019 Our move is 4pm today. Hope it goes smoothly! Guess I can only blame myself if it doesn't.
caffrey Posted July 16, 2019 Posted July 16, 2019 Is anyone using Radius instead of the captive portal ?
ticktock Posted July 16, 2019 Posted July 16, 2019 Hopefully, due to go live next week. You don't have access to the Radius config on the web interface so you will need to contact BTLS to ask if they will set it up for you at their end. I'll let you know how it goes. 1
SimpleSi Posted July 17, 2019 Posted July 17, 2019 JFI At my wife's school, a number of teachers were reporting that their class computer was blocking access to youtube (even though setup on staff filtering) Logging out and logging in again gets it back working BTLS told her that this is expected behaviour if computer kept logged in for more than 10 hours - it reverts to student level filtering
SchoolsBroadband Posted July 17, 2019 Posted July 17, 2019 JFI At my wife's school, a number of teachers were reporting that their class computer was blocking access to youtube (even though setup on staff filtering) Logging out and logging in again gets it back working BTLS told her that this is expected behaviour if computer kept logged in for more than 10 hours - it reverts to student level filtering This can actually be changed on Netsweeper as we have done this for our customers. 2
Strawdog Posted July 17, 2019 Posted July 17, 2019 Anyone worked out how to force YouTube restricted mode? I've tried adding "YouTube-Restrict: Strict" to the various URLs as recommended here but that just blocked it completely :\ We don't use GSuite. Been a fun week since migrating over Friday night - between our mixture of OS:X, Windows, iOS and Android clients along with our guest network devices being NAT'd in an isolated 10.0.0.0/8 network it's been just how I wanted to spend the last week before Summer.
Strawdog Posted July 17, 2019 Posted July 17, 2019 Oh and you all might want to block Reddit as that was accessible to everyone after we migrated.
Strawdog Posted July 17, 2019 Posted July 17, 2019 ....and OS:X clients have no internet access when off campus if configured to use the BTLS .pac file.... Guess we're back to using Locations again to define connection states for different places
ticktock Posted July 17, 2019 Posted July 17, 2019 That is shocking and a massive leap backwards. I was advised it wouldn't be an issue when I queried it with BTLS. Is it the same for windows?
Strawdog Posted July 17, 2019 Posted July 17, 2019 (edited) Not tested a Windows client but they don't use a .pac file so they should be fine. Another option is to turn off SSL decryption altogether (Policy Management -> Policy Manager -> select relevant policy -> URL/Keyword Shared Lists -> Manage Shared Lists -> Remove 'Selective Decryption and add 'No Decryption' lists) but given how many sites use HTTPS now this blows a major hole in your monitoring ability. The .pac file location (http://pac.education.btlancashire.co.uk/btls.pac) doesn't appear to be accessible from non-CLEO IPs. Apple Profile Manager has an option when defining a .pac file location to bypass it if it is unreachable but we don't manage most of our staff MacBooks with it (sods law we mainly use it to manage devices that remain in school) and I've not tested it yet. Edited July 17, 2019 by Strawdog 1
Joanne Posted July 18, 2019 Author Posted July 18, 2019 my other school has governors bringing their own devices in and they can't access internet. I've printed out the insane instructions for OSX and iOS, but I'm not sure how many people will go for a profile being installed on their phone / tablet / machine. I honestly don't understand why they didn't pick a solution that was full transparent proxy. The money saved is probably going to have to be spent on providing extra support for the mess they have made.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now