Jump to content

Recommended Posts

Posted
How do you stop pupils using VPNs to by-pass filtering. I'm particularly interested in those with G Suite for Education and Chromebook environments, but keen to understand other setups too.
Posted
We never managed to do this. You need layer 7 filtering, which is apparently something that our Smoothie can do, though it requires an extra license. Our Ruckus ZoneDirector also has an option to do Layer 7 filtering, however it's apparently not recommended to do it at that level (and should be done at the filtering/firewall level) and also can have a big hit on that device's performance.
Posted

We tried for a while using Smoothwall, to some effect, but then every outside agency that comes in needs their VPN to work (NHS, Careers, Religious groups, HR, auditors etc etc...) so it was more trouble than it was worth.

 

We audit the apps on our ipads (BYOD) and give a list of users with VPNs installed to Year managers and they chase up.

Posted

If they're school issued Chromebooks then surely you control the extensions and apps they can install?

 

If you speak to Smoothwall you might find they add L7 free of charge.

 

For BYoD we massively locked down ports that could get out on that vLAN.

  • Thanks 1
Posted

With Chromebooks, just block all extensions except the ones you allow. Whitelist API access to the services you allow. Use extension based filtering service like Securly that works on any network. Deploy the network to the Chromebooks - which prevents them editing the settings and if the devices never go home - use the policy that restricts them to deployed networks only.

 

On other devices you need an egress firewall that blocks outgoing ports that you don't want open and have some form of deep packet inspection/L7 firewall. On our BYOD gateway (ClearOS) we use the Gateway Management App and turn on the "don't talk to strangers" feature will kills all vpns.

  • Thanks 1
Posted
On the Chromebooks students and staff can only install approved apps, so they can't install any VPN software. We use Securly for the web filter on the Chromebooks, as this is a cloud filter if they connect to a hotspot they will still get the filtering system. On top of this at School we have a Fortigate firewall which we also block VPN ports and apps with.
Posted

Its a whack-a-mole I'm afraid and anyone who tells you that their particular brand of filter/firewall can block *all* VPNs is lying. We recently surveyed a load of schools about VPNs and about 70% of the respondents said that they aren't worried at all by them because their filter blocks them all... That tells me that 70% of schools are a bit deluded. :)

 

The best you can do is have a filter/firewall that blocks the most popular ones, keep your ear to the ground and whenever you find a new one becoming a problem let your filtering supplier know and give them as much information as you can. You're reliant on having a supplier who can put their development team on the problem and react quickly to figure out how to block the new VPN.

 

I'm actually working on some traffic analysis code to block a new problem VPN at the moment. Some are trivial to block, but some use really sneaky and devious techniques to avoid detection...

 

Also, make sure VPN use is banned in your acceptable use policy, that suitable punishments are handed out, and that VPN use features in your online safety curriculum. Key points:

* VPNs have legitimate uses (e.g. when you're using untrusted networks);

* But you might be breaking an AUP by using one;

* And you might be putting yourself in danger by bypassing malware filters, online safety systems, etc.

* And that you have to trust the VPN provider - if its a free VPN, where are they getting their money? Are they snooping on/meddling with your data in order to monetise you?

 

Also, being very strict with your filters encourages VPN use (and 4G use), so have a think about whether you can relax your filtering a bit - monitoring instead of prohibition. Balance up the benefits of filtering vs. the safeguarding opportunities you miss if overzealous filtering pushes people onto VPNs/4G.

  • Thanks 2
Posted

Dont use chrome book or GSuite - but when I enquired with my account manager at smoothwall about Layer 7 filtering I was told Layer 7 used to be a paid upgrade to the system but is now standard.

 

They added it to my licence and was able to deploy as per their KB article.

Posted

I am sad to say I am almost at the point where we are about to kill BYOD off completely.

 

The Cons for us in terms of providing an internet connection which they can circumvent with any new VPN that our filtering doesn't know about yet, most definitely outweighs the Pros.

 

The safeguarding loophole this creates is not worth it. Especially with the new Ofsted framework. They are now obviously very hot on safeguarding and monitoring.

 

The irony being that 90% of kids have enough data now to get round our filtering should they wish so why bother expose yourself to the risk.

Posted
The safeguarding loophole this creates is not worth it. Especially with the new Ofsted framework. They are now obviously very hot on safeguarding and monitoring.

 

Per KCSIE, online safety policy is expected to be driven by a risk assessment, and Ofsted *should* take account of that risk assessment. So you need to weigh up the risk of:

 

Providing BYOD:

  • Some kids will use VPNs to bypass filtering.
  • Some traffic won't be filtered / monitored, but you've made a decision to allow it in order to promote the use of your wifi.
  • But some traffic will still be filterable / monitorable, and that's where you get your safeguarding opportunities from.

 

verses not providing BYOD

  • Everyone uses 4G.
  • You get no filtering/monitoring capabilities at all.

 

I think we can all agree that if a kid wants to get to bad stuff, they'll find a way. The point of BYOD is to provide a safer space for kids to use the internet, not to provide a completely risk-free space irrespective of what kids do to get around those safeguards. Providing BYOD gives the school some scope for safeguarding but opens you up to potential liabilities; not providing BYOD means you miss safeguarding opportunities.

 

why bother expose yourself to the risk.

The decision not to provide BYOD should also be considered a risk. Its not a straightforward decision, but its wrong to consider one option to be a risk and the other to have no risk at all. Ofsted should be listening to the school's reasoning, whichever way you decide to go.

  • Thanks 1
Posted
I am sad to say I am almost at the point where we are about to kill BYOD off completely.

 

The Cons for us in terms of providing an internet connection which they can circumvent with any new VPN that our filtering doesn't know about yet, most definitely outweighs the Pros.

 

The safeguarding loophole this creates is not worth it. Especially with the new Ofsted framework. They are now obviously very hot on safeguarding and monitoring.

 

The irony being that 90% of kids have enough data now to get round our filtering should they wish so why bother expose yourself to the risk.

 

To be fair if you massively lock down what is available on the BYOD network - eg. close all ports and only open www and dns and then lock DNS down to only certain providers etc. you can effectively block the vast vast majority.

  • Thanks 1
Posted

Fair points.

 

I suppose I am looking at it more from a service provision point of view rather than a safeguarding viewpoint.

 

It would be interesting to know what view an Ofsted inspector would take on non provision of BYOD. Could be Damned if you do, Damned if you don't

Posted
To be fair if you massively lock down what is available on the BYOD network - eg. close all ports and only open www and dns and then lock DNS down to only certain providers etc. you can effectively block the vast vast majority.

I can name a few that will work fine with no access to DNS, everything closed except HTTPS and HTTPS directed to a transparent filtering proxy. I've done a lot of work dissecting how some of the more sneaky VPNs work - its basically down to a combination of some really clever tricks played by the VPN, combined with the DNS tricks that some of the really big services such as Cloudflair and Facebook use, which makes it difficult to detect and block the VPN without also breaking some services that use DNS tricks for legitimate reasons.

 

As far as I know, Smoothwall, Sophos and Lightspeed still can't successfully block Hotspot Shield, for example (someone correct me on this if I'm wrong though - I know SW have a KB article on blocking hotspot shield, but its years out of date and current versions don't work like that any more). Part of the trouble with mobile devices is that the VPNs often download a list of servers while on 3G and then use that list to find a server to connect to when they go onto the wifi network, so they don't rely on having working DNS, etc. on the wifi network.

Posted
I suppose I am looking at it more from a service provision point of view rather than a safeguarding viewpoint.

 

Absolutely - if you choose to provide BYOD and something bad happens, you can find yourself fighting against accusations that you provided a service that allowed them to do something bad. With VPNs you can make a pretty good argument that the student intentionally bypassed the filters so its not your fault, but sometimes you make a concious decision to allow an app that you know could be a risk, and that can be harder to defend.

 

Example: boarding schools often allow WhatsApp because the parents insist on using it to talk to their kids, but WhatsApp is end-to-end encrypted so there's no telling what the kids are using it for. So in that case, the school has made a concious decision to allow an app, even though it presents a risk. If something bad happened involving a child using WhatsApp, they would have to defend their decision to allow it. And indeed, I've seen ofsted criticise a boarding school for not allowing enough social media access, because it hampered the kids' communications with their parents.

 

On the other hand, not offering BYOD takes that liability of allowing kids to do bad things away from the school, and places it firmly on the parents who supplied the 4G connections/devices. But if something bad happens, questions should be asked about whether the lack of BYOD caused safeguarding opportunities to be missed. No easy answers on any of this I'm afraid, but recognising that you are balancing the risk rather than eliminating it is important.

It would be interesting to know what view an Ofsted inspector would take on non provision of BYOD. Could be Damned if you do, Damned if you don't

Someone may correct me on this, but unfortunately I don't think Ofsted have any particularly firm guidance on the technical aspects of online safety, and it ends up being down to the individual inspectors. I've seen some inspectors do some really crazy stuff on occasion, so would like to see them get better guidance. :)

  • Thanks 1
Posted
I can name a few that will work fine with no access to DNS, everything closed except HTTPS and HTTPS directed to a transparent filtering proxy. I've done a lot of work dissecting how some of the more sneaky VPNs work - its basically down to a combination of some really clever tricks played by the VPN, combined with the DNS tricks that some of the really big services such as Cloudflair and Facebook use, which makes it difficult to detect and block the VPN without also breaking some services that use DNS tricks for legitimate reasons.

 

As far as I know, Smoothwall, Sophos and Lightspeed still can't successfully block Hotspot Shield, for example (someone correct me on this if I'm wrong though - I know SW have a KB article on blocking hotspot shield, but its years out of date and current versions don't work like that any more). Part of the trouble with mobile devices is that the VPNs often download a list of servers while on 3G and then use that list to find a server to connect to when they go onto the wifi network, so they don't rely on having working DNS, etc. on the wifi network.

 

Well in my testing I cannot get a VPN to connect in our environment and I’ve tried all the major ones.

  • Thanks 1
Posted
...Someone may correct me on this, but unfortunately I don't think Ofsted have any particularly firm guidance on the technical aspects of online safety, and it ends up being down to the individual inspectors. I've seen some inspectors do some really crazy stuff on occasion, so would like to see them get better guidance. :)

 

 

Seems to further add to the general opinion that Ofsted doesn't have a bloody clue when it comes to anything technology or IT related in schools. I don't know which one I'm more concerned about. Their lack of interest or lack of concern about it.

  • Thanks 1
Posted
It would be interesting to know what view an Ofsted inspector would take on non provision of BYOD. Could be Damned if you do, Damned if you don't

 

No schools down here allow children to have their own, non-school issued, devices. Phones are all handed in etc... So, no need for BYOD.

Posted

You don't allow a connection to the internet, only via your proxy. So you only allow dns to your dns server, which can log everything, and http(s) to your proxy, which can log everything.

 

At that point the VPN software must disguise everything as an https request, so you sort by bytes and see that asd8a9da9sg8.asdfasf9as8dfsh9s.com is getting loads of traffic. Also you require auth on the proxy, so you know who's using what.

Posted
You don't allow a connection to the internet, only via your proxy. So you only allow dns to your dns server, which can log everything, and http(s) to your proxy, which can log everything.

 

At that point the VPN software must disguise everything as an https request, so you sort by bytes and see that asd8a9da9sg8.asdfasf9as8dfsh9s.com is getting loads of traffic. Also you require auth on the proxy, so you know who's using what.

 

How do you know whether an HTTPS connection to get.adobe.com is a legitimate request, or a VPN?

Posted
Seems to further add to the general opinion that Ofsted doesn't have a bloody clue when it comes to anything technology or IT related in schools. I don't know which one I'm more concerned about. Their lack of interest or lack of concern about it.

 

If an inspector raises something during an inspection which is based on their own ideas rather than any guidance, it is open for challenge and should be challenged. They refuse to officially look at anything related to data protection or privacy, but will look at Safeguarding (IT IS ALL LINKED TOGETHER!!!!!)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...