Jump to content

Recommended Posts

Posted

Why can't schools set their own subnets rather than the ones defined by LGfL?

 

Currently operating a flat network and I have been told we are secure by utilising LGfL services. WTF?!

 

Clearly they won't understand segregating admin, curriculum, BYOD etc. I've been instructed to create a seperate SSID and utilise the DHCP/NAT to isolate devices that aren't school property.

 

But what about seperating printers, VoIP, CCTV, alarm systems etc? Obviously no clue whatsoever.

Posted

Devils advocate, do they need to know. Just need a decent enough router/switch to run 1:1 SNAT on the interface that they see, structure it how you like and as long as you don't go over the allocated number of IPs it can be properly segmented if overly complicated.

 

Unfortunately most providers are awful when it comes to stuff like this, ideally they should give you an ip pool you can divide up as you see fit and just define a summary route from the school with division and routing handled in house.

  • Thanks 1
Posted

I've been doing as @SYNACK for over a decade. No big deal. One thing doing it that way gives you is the total cover that the LGFL firewall gives you (anything goes wrong it very much not your problem or fault), and the flexibility of running your own as the gateway between your private subnets and the LGfL subnet.

 

If you really don't like that you can always move to be an option 2 site, but I have long felt it doesn't offer anything that outwieght the peace of mind that your connection to the internet and the filtering and firewall are entirely somebody else's *responsibility*.

Posted

This is one of the main reasons I moved away from the LEA. Not having control of our router and by extension subnets and access control rules made the connection "unfit for a modern school". We had all our computers, servers, printers, switches, access points, CCTV cameras all running on the curriculum network. The only separate scope was the VOIP which had its own internet connection as the LEA don't support VOIP on their connections.

 

As @SYNACK said you can run a second router and SNAT the packets but when I've done this in the past it's been a case of treating the symptom not the disease.

 

Certainly here in Lancashire the motivation for setting the subnet on each school was so that each school could talk through the county network. 10+ years ago you could just type in the IP of a server in another school and go for it. I know the council still have that power and can remote directly into servers from their office (unless of course you setup Windows Firewall to drop RDP packets from outside your subnet). I shouldn't have to setup defenses against attack from other schools on the councils "internal network".

Posted

How do you separate those things now on a 'flat' network?

 

Networking isn't a strong suite of mine so forgive me if I'm being a bit naive and not understanding the problem...

 

When we joined LGfL we were told we would have to change our I.P. addressing scheme, this was a pain and cost us due to having a network support contract which is break/fix only and not config and it was way over my head at the time (we were also later told that it might have been possible to keep our I.P. range)... :doh:

 

However we told the network support engineer to set up our switches exactly as it had been (with a few tweaks), just within the range of the new I.P. addresses so everything Curriculum, Admin, Printers, Servers, VoIP, CCTV have their own VLAN. Wireless networks are also split into Admin/Curriculum SSIDs and also a separate Guest/BYOD with an ACL (this was created by our network support engineer at additional cost though). Our broadband connection is with Virgin, but our alarms are separate on BT lines so not a problem.

Posted

Certainly here in Lancashire the motivation for setting the subnet on each school was so that each school could talk through the county network. 10+ years ago you could just type in the IP of a server in another school and go for it. I know the council still have that power and can remote directly into servers from their office (unless of course you setup Windows Firewall to drop RDP packets from outside your subnet). I shouldn't have to setup defenses against attack from other schools on the councils "internal network".

 

LGfL has always been quite different from the other RBC's and their successors. I heard rumors of such open ports back in the earliest days, but by 2005 each school was isolated. In my experience the schools have always had some degree of control and since 2011 almost total control of whether they want the full "option 1" service or the more-or-less-bare-wires "option 2".

 

They have also always been very hot on security. Their stance today seems sensible, and perhaps just a little behind the curve, but many frustrations people have with their restriction are derived from their knowledge that most schools (and organizations in general) have *no idea* how hostile and dangerous the internet is, so they took steps to protect everyone which frustrated some (for example they put an outright ban on open RDP back in 2011 and Remote Access tools in general). They have relaxed that position over the years, but somethings they still insist that the Head Teacher reads and signs off on risks before they will action. This, in my view is prudent.

 

I run a large option 1 site with multiple subnets and have no problems.

Posted

I think the main reason for keeping your IP Addressing within their subnet is if you utilise majority of their services.

We use their scopes but have several 192 ip address ranges which are Natted to a single IP if they need internet access.

 

as @fiza said, @PaddyNewman is your go to guy.

  • Thanks 2
Posted
How big is your range? If for example they give you a /19 you could subnet that down?

 

This is pretty much what we do at the 3 primary schools we look after. We still utilise option 1, with the LGfL router and firewall but the /21 for each school is subnetted to our Meraki core switch. We then control all of our different VLANs internally.

 

Of course, if this doesn't work for you and you really want full control, you can go for option 2. But I would much rather the extra layer of security with option 1 with the internal controls, as I've done at our schools.

Posted
Clearly they won't understand segregating admin, curriculum, BYOD etc.

 

Every LGfL implementation I've seen has had a separate IP scope for admin and curric, direct on the LGfL firewall, as two separate ports. It's just that most customers generally have (or historically had) a flat network and only used one or the other.

 

We discussed a VLANing project with LGfL just recently, and they told us we had up to 2k addresses available on a /21 network. That would allow us 8 x Class C networks, which would have been enough to VLAN anything we needed. We were warned against NATing also, but mainly just to avoid unnecessary complication. There probably are technical arguments why, but complication was enough explanation for us tbh.

 

A big reason you're restricted to their IP range is because they're not a regular ISP. When you join LGfL, you join their WAN, and share their Internet connection, so it's a bit different.

 

Historically they have been quite restrictive, but I've found these days, within sensible limits they've been a lot more accommodating. But I guess it depends what you're trying to achieve, and why.

  • Thanks 2
Posted

Hi @Chuckster

 

I am an LGfL customer but am also working as a consultant for them with a focus on web filtering, so can see from both sides of this.

 

It is annoying that you have to fit in with the IP addressing scheme and appreciate for new customers this can be a lot of work to change over.

 

There are, however advantages of doing this. The main one is my area of expertise, Webscreen which need to be able to identify the traffic from the individual IP address to deliver per-user/per-device filtering and detailed logging.

 

You absolutely can run VLANs on the LGfL network, 2 of my larger schools do. You just need to work with the support desk to let them know what the address of your internal router/L3 switch for the 'next hop'.

 

Hopefully this makes sense.

 

David

  • Thanks 1
Posted (edited)

Feel free to call in and ask for me if you need something - just pop through the normal support number and ask for me and I'll try to assist - if you want a full reason posted in here, let me know and I'll do that instead. I'll have to watch what I say but I certainly will try to detail as much as to why we do what we do :)

Apologies for the delayed response also, I was travelling/working!

Edited by PaddyNewman
  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...