Jump to content

Recommended Posts

Posted (edited)

Hi,

 

Our users are unable to get mail (send, receive, update inbox etc.) via the iOS Mail client when connected to our network (I have tried this on multiple iPads with different email providers including lgflmail (StaffMail). WebScreen doesn't show any blocked URLs, so I assume a firewall rule is blocking this somewhere. As this is managed by LGfL, we can't see exactly what is being blocked and work from there.

 

Could someone post/PM me their LGfL MIP request spreadsheet (or post the rules they have enabled in their firewall configuration) that allowed this to work for their users?

 

Thanks :)

Edited by interslice
Posted (edited)

Sorry, to clarify, this is when users have connected to our internal network with an iPad or iPhone and are trying to use the Mail app to retrieve their email from (for instance) iCloud (or LGfL StaffMail (lgflmail)).

 

Connection and usage of the Mail app with the accounts in question is fine when connected to the internet via my phone as a mobile hotspot...

Edited by interslice
Posted

Strange! I will raise a case with LGfL and ask them what is going on/whether they have predefined rules for this (or whether they can tell me what other schools have used!).

 

Thanks!

Posted
I don't know LGFL, but they might be blocking POP/IMAP/SMTP - used to be common among education IT suppliers.

 

Quite possibly - I have just hooked up an old Android tablet and tried to pull from mail via the built in email application - same issue, so looks like IMAP and SMTP access are definitely being blocked.

Posted

Try logging a call with Atomwide and asking them to unblock all known ports to Apple for your iOS mail app to work on your wireless range (or your whole network). They should have the details from previous cases and you may not need to supply any details in the MIP request, if at all.

 

I had a similar issue in the past where the mail app wouldn't connect internally, I logged a call asking them to do just that and they fixed it themselves. Atomwide seem to have some new staff on the help desk, so you may need to be a bit "assertive" but you should be able to get it resolved.

Posted

As others have said, just raise a case with the LGfL Service Desk and let them know what mail services you want access to. They do have standard rules they can apply and you won't need to complete a spreadsheet.

 

WebScreen just deals with ports 80 & 443, so that's why the reports will be blank as the mail client will make requests on 465/587, 993, 995 etc which will need the firewall changes.

  • Thanks 1
  • 2 years later...
Posted

Holy Thread Necro Batman!!!

 

Sorry to ask this again but Atomwide are being a bit slow with their support...

 

I've been battling with trying to get a staff members phone onto our guest wireless so they can get their emails (long story).

 

When I try my phone (iPhone if it matters) it is OK apart from one account (NTL World/Virgin) all the other accounts work fine (Outlook) but they were set up with some sort of auto-discovery magic.

 

I am trying to be a bit hands-off as it is a personal device, but their phone (Android) isn't getting any mail (Internet is OK) so I don't really want to delve into her device settings.

 

I can see from my phone that the NTL World/Virgin account (which I needed to set-up manually is using IMAP and SMTP, ports 993 and 465.

 

Nothing appears to be blocked in Webscreen which I can see from this thread is about right and that LGfL must block these ports on their firewall for some reason.

 

Question is why...?

 

But also I don't know why their email accounts (one of them is Outlook, the others GMail) aren't getting mail either on their Android phone. Could they be set-up to use these ports somehow?

Posted (edited)

@Koldov you can always drop me a ping on here or call me if you are having issue.

 

We block all ports outbound aside from a handful, otherwise nothing would stop me opening my Pi at home on TCP 993 and tunnel my school machine through it, bypassed the firewall with ease. We open them to known hosts, if you have the server addresses you can send us those and we'll open them.

 

We know the ports needed, that isn't a problem.. pm me the case ref and I'll knock it out for you ASAP.

 

EDIT : Scrap that, found it, lets arrange a time I can reboot it :)

Edited by PaddyNewman
Posted
We block all ports outbound aside from a handful, otherwise nothing would stop me opening my Pi at home on TCP 993 and tunnel my school machine through it, bypassed the firewall with ease. We open them to known hosts, if you have the server addresses you can send us those and we'll open them.

There’s nothing stopping me now - I use port 443 on my vpn server to bypass the LGfL firewall and tunnel all my traffic. Works great to get round the filtering and port blocking issues that LGfL has.

 

So by blocking all outbound ports on the LGfL network isn’t blocking the stuff you guys was trying to block in the first place... however I do understand why it's done but I think it is too aggressive. For example, LGfL blocks all Cisco Meraki ports even though it's one of LGfL's offerings... as well as educational software - SQUID, B Squared, Third Space Learning to name a few.

Just wished that LGfL would keep up with these new technologies and not be a ISP that is restrictive to the point where we have to raise a ticket each time we want to use something new or allow software to work. Even if there was a button in the support site to allow the most common ports open, I would be happy.

 

Apologies for the rant,

Posted

A rant is all good! Happy to have a chat about it and see if there's something we can do, or even if you can give us some ideas, always game to throw some feedback to the relevant folk!

 

Agreed on Meraki, it's on my list! Any other key items that you haven't mentioned?

 

If you are happy to chat, feel free to buzz me/pm and I'll get my DDI to you, and no, I'm not going to attempt to stop your tunnel, you do you, I would too!

Posted

As a 20 year veteran, I appreciate LGFL blocking most outbound traffic. 1) it does exactly what I'd have done if the firewall rules were all down to me and 2) makes it not-my-fault when something doesn't work because of it!

 

Though everything apart from legitimate non http/s traffic tunnelling out via 443 makes this less effective these days. :(

 

Just wished that LGfL would keep up with these new technologies and not be a ISP that is restrictive to the point where we have to raise a ticket each time we want to use something new or allow software to work. Even if there was a button in the support site to allow the most common ports open, I would be happy.

 

Also for what it is worth, any new app that used MS365 authentication has to be reviewed and authorised by me *BECAUSE* those apps *get access to data* and therefore need a DPIA. GDPR makes the fact that things are generally blocked by default a necessity. This feels like a regression for the teachers, and is in direct conflict with my philosophy of making IT adoption friction-free, but like the port blocking before it, the balance has shifted on this one.

Posted
We're a Google school here, and block everything except the Gmail apps for security purposes. Perhaps they're enacting something similar regarding the iOS Mail app and what protocols it uses to access LGFL Mail?
Posted

Wow! Ok... didn't mean it to be an LGfL bashing thread!

 

However, much I hate to admit it, there is a LOT I don't know about I.T. and I for one am quite glad that for the most part the buck stops with LGfL as our main firewall/filtering provider. A company of their size looking after that many schools should err on the side of caution, as not every school has a massive team (or even 'that one tech') who has a complete mastery of all the dangers lurking on the internet... I know that LGfL have to deal with a lot of schools (some without technicians) who ask for things and yet don't really quite understand the consequences and I'm sure it must be tedious to be asked the same things over and over again (I'm guess I should mention one of my frantic 'internet down' calls to the helpdesk, then after a while of checking the cab I had worked on earlier realising I had obviously nudged a Fibre connecter 1mm out of its socket)...

 

They do offer lots of options as far as I can tell for 'I'm an I.T. genius and can you please stop blocking everything', but I won't be taking up that offer anytime soon. I can't say I'm not confused by the array of options in Webscreen to allow or deny by 'bundles, categories, or local lists' and how sometimes when I think I've blocked or allowed something it doesn't quite have the effect I thought it would, but in general it's OK on a basic level which as a front end is what 'most' schools need..

 

As far as the ports go, I had to say I was just confused as they appear to be what secure mail (but I guess 'traffic') has to pass through and I guess I just found it strange that it was blocked (because that's the ports secure mail need) and then it confused me as to why all email doesn't need these ports open..... and thought I'd ask the question and expose my own ignorance... If it is open to abuse then I can see the benefit of trying to block it and as a managed service can't see the issue with needing to request a change.

 

I did think of giving you a shout on here @PaddyNewman, but I'm not sure in what capacity you lurk... I'm sure you are busy enough and it feels a bit like 'catching you in the corridor' and we all know that is pet hate of a lot of us I.T. techs....

 

Cisco Meraki is a strange one... none of the teacher laptops with it on actually report whilst 'in school' but are OK when off the network and yet I can do everything I need to with the Apple iPads as they seem to bypass whatever is being blocked (it actually made me think it was something I'd done on the laptops as they're fairly well locked down)... It never bothered me too much though, as iPads are the only thing I really to need to do anything with in school and when the teacher laptops are in school I can do what I need manually (not that I actually do anything with them in Meraki, it's only on so I can keep statistics on use etc.)... The same is true I believe of the Google/YouTube issue that seems to be able to bypass as well.

Posted

I wouldn't say its bashing, everyone has different ways of working.

I will state though, my biggest worry is not the adults on the network, its the kids, I was one and I was a sod in school when it came to IT and they have only got smarter! Adults tend to stay on the right path, kids less so and devote their time to digging round anything that gets in their way!

But to answer your queries...

 

Wow! Ok... didn't mean it to be an LGfL bashing thread!

They do offer lots of options as far as I can tell for 'I'm an I.T. genius and can you please stop blocking everything', but I won't be taking up that offer anytime soon. I can't say I'm not confused by the array of options in Webscreen to allow or deny by 'bundles, categories, or local lists' and how sometimes when I think I've blocked or allowed something it doesn't quite have the effect I thought it would, but in general it's OK on a basic level which as a front end is what 'most' schools need..

 

Happy to hear about what could make things clearer? We try to make it clear but if there are UI changes that could make things clearer, we can always take a look and see what can be done.

 

As far as the ports go, I had to say I was just confused as they appear to be what secure mail (but I guess 'traffic') has to pass through and I guess I just found it strange that it was blocked (because that's the ports secure mail need) and then it confused me as to why all email doesn't need these ports open..... and thought I'd ask the question and expose my own ignorance... If it is open to abuse then I can see the benefit of trying to block it and as a managed service can't see the issue with needing to request a change.

 

So, I've queued up the change to your firewall for the VirginMedia/NTLWorld FQDNs and their associated ports, the word 'secure' means nothing to me personally, you are only as secure as you think you are ;) All email does need those ports open, however some like Office365 and Exchange can be connected via the ActiveSync or Exchange connection over TCP 443, which is open by default, otherwise you'd have no internet at all. Anything is open to abuse, as stated you can tunnel over any of the open ports, but we obviously can't restrict endpoints for 80/443 as thats simple HTTP(S) and we would be stopping your internet access, I don't think schools would like to work on a whitelist only method!

 

I did think of giving you a shout on here @PaddyNewman, but I'm not sure in what capacity you lurk... I'm sure you are busy enough and it feels a bit like 'catching you in the corridor' and we all know that is pet hate of a lot of us I.T. techs....

 

My email is always monitored, and I am happy to help if anyone is stuck anywhere relating to any of our services. Support isn't my direct job, but if you are truly stuck and feel something has stalled, always feel free to ping me. Actual direct changes or things that need me to do anything that would affect your school however, I would need a case for audit purposes, but info and basic pointers, I am happy to provide.

 

 

Cisco Meraki is a strange one... none of the teacher laptops with it on actually report whilst 'in school' but are OK when off the network and yet I can do everything I need to with the Apple iPads as they seem to bypass whatever is being blocked (it actually made me think it was something I'd done on the laptops as they're fairly well locked down)... It never bothered me too much though, as iPads are the only thing I really to need to do anything with in school and when the teacher laptops are in school I can do what I need manually (not that I actually do anything with them in Meraki, it's only on so I can keep statistics on use etc.)... The same is true I believe of the Google/YouTube issue that seems to be able to bypass as well.

 

Meraki rules are needed, we have a default rule for these, I can make note in your support case and we can open the required ports for you to allow the devices to call home when on site if you want.

Posted
Just to be clear, I'm not bashing LGfL. They do what is necessary to keep schools secure on the internet. As I understand it the level of security they have was (I believe) somewhat forced upon they through the procurement framework used (the PCN?) and this did hit some schools quite hard (a decade ago). But these days its its looking less and less over the top and more and more like the baseline as campaigns from NCSC raise awareness and standards. I actually quite like the spreadsheet for making firewall change requests. I have a folder which contains all of the changes we have requested, which is great for auditing and also for finding out wondering *why* something is the way it is. The ACLs on the core switch (under my our control)... less so.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...