Jump to content

Recommended Posts

Posted

Hi All,

 

Would anyone know how to block uploads on facebook, as of last-night, we've had enough, we're averaging around 4.5GB into facebook a night, due to being a very large independent boarding school.

 

We have a deny access between 8am-4pm, however after its open. I cant seem to get my head around it.

 

RM Safteynet ignores my ban on http://facebook.com/editalbum.php (where photos go in)

 

Any one have any luck doing this on an ISA server?

Posted

With SmoothWall you'd be able to block a specific URL at set times, or limit bandwidth per URL(!). However, our next feature pack (not the one currently in test... the next one) is "about" outgoing filtering.

 

Certainly HTTP get/post will come under scrutiny - quite how much is TBC - if you have any ideas i would like to hear them... certainly a "top uploaders" report would be cool to nobble the worst offending users, no?

Posted

RM 2MB non-lease lined 20/1 contention, our incoming/outgoing email line, after 5p.m. you cannot access mail externally due to the lack of speed on the line.

 

Our Fundraising database also accesses various things out of school on the same line (We are Independent), which in turn slows this down.

Posted
With SmoothWall you'd be able to block a specific URL at set times, or limit bandwidth per URL(!). However, our next feature pack (not the one currently in test... the next one) is "about" outgoing filtering.

 

Certainly HTTP get/post will come under scrutiny - quite how much is TBC - if you have any ideas i would like to hear them... certainly a "top uploaders" report would be cool to nobble the worst offending users, no?

 

You mean my daily ban list? Sure, at present with ISA reporting there are some variables that go a-miss. I.e. "requires authentication" however most of the time through some genius method only an IP address is shown, rather than student.

 

Any chance of usage per NETBIOS name? or associated an account with NB name?

Posted
Hmm, interesting - so these being boarders you haven't got them auth'd against AD, so the name of the PC might be useful... afraid we only log the (reverse-dns looked-up) hostname at present.
Posted (edited)
Hmm, interesting - so these being boarders you haven't got them auth'd against AD, so the name of the PC might be useful... afraid we only log the (reverse-dns looked-up) hostname at present.

 

Oh, they are auth'd against AD, ISA ties all its groups and authentication through the DC's. However, "quirck, bug, general annoyance" it doesn't always authenticate properly.

 

I remember an instance a while ago where specific boarders were using "Your Freedom" a paid SSL tunnel to get through ISA, and I still cant figure out why, the only reason they were caught, was the IP address showing massive traffic in logs, upon tracerting, and resolving the IP's we found them to be proxies.

 

How a java based applet running on machine could instantly bypass ISA authentication (required) via SSL is beyond me.

 

And now as per post... another major point is trying to limit traffic through facebook uploads, another point to add, with upcoming VLE implementation, traffic limitation is now a key priorty to providing a quality QOS inside and outside school

 

(If our lease line bid goes through, everythings going to go through a debian squid box, tied into AD, and specific delay_pools setup to limit facebook traffic to around 100kb/s down, 15kb/s up at most. Which would resolve all these issues, but can't guarntee its going to be approved)

Edited by ahuxham

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...