rjf2019 Posted January 30, 2020 Posted January 30, 2020 We are looking at implementing the HTTPS filtering offered by LGfL. As well as the advantage of improving the filtering, it is extremely helpful for staff to see the blocked page message on HTTPS pages, rather than quering whether the site / internet is simply down. In preparation for this, we have deployed the HTTPS certificate to all iOS devices via our MDM, and also to Windows devices using a GPO. I understand that Chromebooks are not supported, and we just need to advise LGfL of an IP range that they will be in so that they are excluded. In terms of personal devices, this is what I'm thinking. For staff personal devices on the staff wifi, we will place a link to the certificate on the school website, and it will be up to them to install it / choose not to use the wifi. In terms of guests, it seems a bit infeasiable as we might have parents trying to forward an email to the admin staff etc that just need it for a minute. I'm wondering whether we also point our guest wifi to a subnet that doesn't have the HTTPS filtering enabled. Finally, as a starting point, I am considering having the HTTPS filtering targetted at a narrow IP range (outside of DHCP scope) and statically adding a few devices to the subnet to test. Just in case we find any issues, we haven't prevented the whole school from using the internet. I'd welcome any thoughts from anyone that has implemented this on LGfL, or the equivalents from other providers.
Cat_Jam148 Posted January 30, 2020 Posted January 30, 2020 We switched on the HTTPS filtering a few years ago and haven't really had any issues with it. Looks like you've got the majority of things sorted out. For our guest network, we have a slice of our IP range that doesn't have the filtering enabled as it was decided it would be difficult and time consuming getting guests to install certificates on their personal devices. When a device joins the guest network, it gets put onto that IP range. Just a heads up that the HTTPS filtering only affects Google services, all other internet access is unchanged. If staff are on your WiFi, they'll still receive e-mails and use the internet if they know the web address or use Bing (Shudders) etc... It's only Google/Youtube that throws up a cert warning. 1
ibpalle Posted February 3, 2020 Posted February 3, 2020 Always a good idea to test with a limited but representative set of users - HTTPS inspection can interfere with a lot of applications. Browser generally are fine but third party apps using HTTPS often use certificate pinning or simply embed public keys into apps, as they only need to talk to their own server. Generally applications is the main thing to test when moving to HTTPS inspection. 1
rjf2019 Posted February 11, 2020 Author Posted February 11, 2020 Thanks both. Really helpful to hear about your experiences.
mountaingoat20 Posted February 12, 2020 Posted February 12, 2020 Does the LGFL use the same RM filtering services that SWGFL use?
Cat_Jam148 Posted February 12, 2020 Posted February 12, 2020 It's a system called Webscreen, which I believe is a version of netsweeper.
SchoolsBroadband Posted February 12, 2020 Posted February 12, 2020 Does the LGFL use the same RM filtering services that SWGFL use? No, LGFL use Netsweeper (same as us (Schools Broadband) RM use their own in house solution which is Safetynet or sometimes Smoothwall I think. Dave
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now