Jump to content

Recommended Posts

Posted

Hi all,

 

We need some advice on what content filtering to use.

 

We have something, but in all honesty it is useless. The teacher that set it up has now gone and no one knows how it works. We need a new start!

 

We are primary school, so all the given stuff needs to be filtered. We also need different access for teachers. We would also need to be able to change access e.g. block and allow certain sites.

 

The people who provide our computers and switches are looking into 'Watchguard'. But in all honesty, it is not their forte, so out of good practice, I just want to search myself as well.

 

How do they work? Does it sit on your Router? Or do you change the DNS and it filters it like that? Just curious as how it works on a large scale. Obviously, it is not a programme installed on each laptop!!

 

Thank you very much

Posted (edited)
Hi all,

 

We need some advice on what content filtering to use.

 

We have something, but in all honesty it is useless. The teacher that set it up has now gone and no one knows how it works. We need a new start!

 

We are primary school, so all the given stuff needs to be filtered. We also need different access for teachers. We would also need to be able to change access e.g. block and allow certain sites.

 

The people who provide our computers and switches are looking into 'Watchguard'. But in all honesty, it is not their forte, so out of good practice, I just want to search myself as well.

 

How do they work? Does it sit on your Router? Or do you change the DNS and it filters it like that? Just curious as how it works on a large scale. Obviously, it is not a programme installed on each laptop!!

 

Thank you very much

 

Is your current solution really useless or is it just that it’s not at its best now that the person who knows how to control it has left? This is a process issue: software should be centralised and documented, not held in one person’s memory.

 

Other than that, you will need to produce a proper list of requirements. I did one for my previous employer that we then just updated each time we needed to renew or re-tender for a filtering solution and that served us well, but that was for a 6th form college, so wouldn’t be helpful even if I still had a copy (but if you or anyone else wants a bash, think starting with regulatory/non-functional requirements, then technical requirements). A laundry list of products is no help if you don’t have a proper set of requirements to evaluate them against.

 

I’d second the call to see what your LEA have and hop onto that if it’s suitable. Presumably if you are part of a MAT they’d already have a central solution you could use too?

Edited by Roberto
  • Thanks 1
Posted
I’d second the call to see what your LEA have and hop onto that if it’s suitable. Presumably if you are part of a MAT they’d already have a central solution you could use too?

 

 

We are part of MAT, but the have not got their act together yet. Their procurement is not something that I have all that much trust in. Afraid we are on our own when it comes down to this.

 

 

 

 

I have contacted the High school to see if they can recommend anything.

 

- - - Updated - - -

 

Is there not something that your LEA provides?

 

Afraid nothing that would suit us.

Guest Guest
Posted
We've used SurfProtect from Exa since January its been pretty good so far, for Primaries its £750 for non Exa connectivity and allows different access profiles for different users
Posted

Consider contacting LGfL, they have a fantastic combined offer that solves a lot of common issues, and the reliability of the internet connection and filtering is second to none.

 

*they also have taken over the National Grid for Learning brand, as they work outside of London now.

Posted
Hi all,

 

We need some advice on what content filtering to use.

 

We have something, but in all honesty it is useless. The teacher that set it up has now gone and no one knows how it works. We need a new start!

 

We are primary school, so all the given stuff needs to be filtered. We also need different access for teachers. We would also need to be able to change access e.g. block and allow certain sites.

 

The people who provide our computers and switches are looking into 'Watchguard'. But in all honesty, it is not their forte, so out of good practice, I just want to search myself as well.

 

How do they work? Does it sit on your Router? Or do you change the DNS and it filters it like that? Just curious as how it works on a large scale. Obviously, it is not a programme installed on each laptop!!

 

Thank you very much

 

Sophos XG will do that for you, an appliance on site that you can manage. Wave 9 can install and manage/support and provide training if required. If you like a quote and more info, drop me a note or pm, I’d be happy to help you out.

 

cheers

 

Lee

Posted
How big is your primary school? Something like an Smoothwall S2 appliance may well be suitable.

 

200 students 10 ish teachers

 

Thank you!

Posted

Is there someone (you?) who will manage it day to day? I only ask as most filter systems are URL aware only so you have to know the address to filter it. There are a couple of proper content filters, that read the text, that keep you ahead of the game but you have to be explicit with the suppliers as they will all call them content filters, because they filter web page content. Personally I think this is weaselly words but hey ho. I would recommend a proper content filter if there is a light management touch needed (this is normally the case in a primary) as this will catch more issues and doesn't need someone to add naughties as they pop up.

 

Before someone pulls me up, yes nearly all the filter systems offer updated URL lists, but they can be days if not weeks behind the kids. Just look at the "URL to block" threads.

 

The only proper content filters I know of off the top of my head are Smoothwall and Openendium.

  • Thanks 2
Posted

Securly has a primary school solution - pure cloud based so very easy to get up and running - We can get you a list of references close to you so you can see how other schools are using our solutions and give you an overview at a time which suits you.

 

Give me a shout if you want to have a look!

  • Thanks 1
Posted
How do they work? Does it sit on your Router? Or do you change the DNS and it filters it like that? Just curious as how it works on a large scale. Obviously, it is not a programme installed on each laptop!!

 

Some systems (often cloud based) are indeed entirely based on a client running on each machine, some systems use a combination of an on-machine agent and a gateway device, and some don't need any client software at all, some use DNS filtering exclusively. So there are a few different ways things work, and it does depend on the individual vendors. There are obviously pros and cons with each.

 

Firstly, I would avoid anything that relies entirely on a client on each machine. The Safer Internet Centre's Appropriate Filtering guidelines say that filters should be "network level", so relying on a client doesn't meet their guidelines. Its worth looking at their guidelines, which are here:

https://www.saferinternet.org.uk/advice-centre/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering

 

Also most vendors have a checklist against that advice - again, worth having a look:

https://www.saferinternet.org.uk/advice-centre/teachers-and-school-staff/appropriate-filtering-and-monitoring/provider-responses-0

 

To get an appropriate level of filtering/monitoring, you need a system that will do HTTPS decryption. This means that you do need to install _something_ on each device - either a certificate, or an agent which takes care of the certificate installation. For Windows machines this is easy to do through group policy, and similarly for MDM managed devices the MDM will do it for you. For stand-alone devices it can be a bit of a pain, whatever system you use.

 

So, things vary from system to system, but I can explain from the perspective of running an Opendium Web Gateway or UTM system:

 

The device goes between your network and your internet connection - either as well as your existing router, or completely replacing it. It does both firewalling of non-web traffic, and filtering of web traffic, and this is the safest configuration since it means that all traffic to/from the internet has to pass through the device, so can be controlled. We don't use any on-device agents, so nothing to install on the machines other than a certificate.

 

If you have multiple VLANs, you can use the UTM to control traffic between them (e.g. segregating BYOD from the rest of your LAN, etc.)

 

Being able to identify the users is also part of the safer internet centre's guidelines - it allows you to set different filtering levels for different user groups (e.g. staff / students) and means that you can easily identify vulnerable users in safeguarding reports. For machines on your Active Directory domain this is done through Kerberos single signon, so is completely transparent to the user; for other machines there are a variety of options and exactly which you choose is dependent on your network infrastructure and your requirements - most schools use WPA2-Enterprise wifi networks, which works very well.

 

Most of of the filters on the market are simple URL block lists, a few of them (Opendium included) do real-time content inspection. Simple URL block lists don't really cut it on sites that tailor content to the individual users, so I'd definitely say go for a filter that does content inspection (yes, I'm biassed, but we're not the only supplier that does it so you have some options).

 

You said that this isn't your IT supplier's forte, so I very much recommend that you look at how much support you'll get from the filtering vendor themselves. It isn't reasonable to expect your IT supplier to be able to do a good job of supporting the system themselves since they have very little experience with it - make sure you can go directly to the filtering vendor and get any help / advice you need. A filtering system is not a "fit and forget" device like a simple router - it does need ongoing work to make sure the apps you want to work do work, and the things you want to block are blocked.

 

If you need any help and advice, please give us a call. We don't do "hard sell" and are happy to answer your questions even if you go elsewhere in the end.

  • Thanks 1
Posted
Firstly, I would avoid anything that relies entirely on a client on each machine.

 

There aren't any cloud solutions out there that rely entirely on a client on each machine. All of them have the ability to fall back to DNS level filtering if needs be, just to point that out. :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...