Jump to content

Recommended Posts

Posted
This is the first time we have had the issue, google support recommended re-adding the whitelist to our web filtering, waiting to hear back from them as its supposedly been escalated
Posted
Just throwing my hat into the ring on this one, we have this for some of our sites too and we are on SBB.

 

Has anyone completely confirmed this is a filtering/firewall issue?

 

We're on SBB too. we've opened up a support ticket, but not had anyone come back to us about it yet.

Posted

Okay, stupid question - what is SBB?

I don't know how it could be a firewall issue if the setting I changed makes the issue completely stop. Like no reports whatsoever if I make that one change.

change: applied setting "always show usernames & photos" on log on screen. it was previously set to never show usernames & photos. Makes no sense to me!

Posted
Okay, stupid question - what is SBB?

I don't know how it could be a firewall issue if the setting I changed makes the issue completely stop. Like no reports whatsoever if I make that one change.

change: applied setting "always show usernames & photos" on log on screen. it was previously set to never show usernames & photos. Makes no sense to me!

 

It's definitely not a stupid question. SBB is SchoolsBroadband, our ISP.

Posted

:) thx for SBB clarification.

I have an escalated ticket with Google open. I actually missed a call from them earlier...waiting on them to call back. I'll keep you posted.

Posted

This is now affecting our site as well. Two days ago we'd never had this error.

 

Silly question - where would I edit our allowlist? I have taken a look through my workspace admin but can't seem to find the setting.

 

Thanks

Posted

Screenshot 2024-03-22 105344.png

Ticket open with SBB-Talkstraight for 3 months...

 

Guess for schools, the "It's affecting our Teaching and Learning" card isn't enough to get it working sooner.

Screenshot 2024-03-22 105344.png

Posted (edited)

One of my team has just found that adding gstatic.com to the pupils filtering (Url allow) has fixed it for them in another school, so about to add that to a few schools manually to see if that fixes it. (*just tried and its sorted it for us!)

 

If you are on SBB and have the logon details its here https://netsweeper0.schoolsbroadband.net/webadmin/common/ (well, it is for us anyway)

Edited by uke
  • 6 months later...
  • 3 weeks later...
Posted
We have had this issue for about a year now, already tried everything suggested on here. Have not contacted our ISP (talkstraight) as I have always assumed it is firewall related (lightspeed rocket) as there are frequent issues with the chromebooks connecting to the captive portal (QUIC error), generally have to turn the wifi off and on again a few times to get the captive portal, then get the 400 error. Powerwash tends to work most times, just an annoying daily thing to deal with
  • 3 weeks later...
Posted
We are now getting this error with a FortiGate firewall. Does anyone have any further information or help? Have tried all above but getting this error intermittently on the Chromebooks
  • 2 months later...
Posted

We had this issue some months back, and now it's back with a vengeance. Google had no answer the first time around. I put it down to 'life extension' updates, however this is proven wrong by devices that have not had a life extension. We use Smoothwall and already have the gstatic.com filtered, but also the problem is happening on Chromebooks that have been taken home, so that surely proves the firewall wall theory to be wrong and points back at Google?

 

There are only so many times one can Powerwash/factory reset these devices!

 

Are there any other theories?

Posted

We only have this issue at shcool, pupils/parents report the chromebooks work fine at their home. for us the main issue is getting the captive portal to display BEFORE anyone can log in, the work around for us has been to add our test student account to evey chromebook then login as that, sign into the captive portal with test student, sign out, then let pupil sign in. once a pupil has signed in (and if they regularly need to borrow a chromebook then we keep a google sheet of whose logged into which chromebook and try to ensure they get the same one that already has their account on) they can login next time without needing the captive portal - that will trigger when they are logged in and try to load a web page..

The chromebooks that seem to trigger the captive portal best are running chromos 118-122, anything newer seems to struggle and we just get a gstatic white error page instead of the captive portal.

  • 2 weeks later...
Posted

Smoothwall came through with the below. Worked for me. Not pupils and staff just authenticate once they've logged in.

 

There are a couple of things we can try. In Web Proxy > Authentication > Exceptions could you add the Connect for Chromebooks category to the exceptions.

 

https://kb.smoothwall.com/hc/en-us/articles/15301667846684-Creating-authentication-exceptions

 

Next, create a web filter policy (Guardian > Web filter > Manage polices) for the same category, with an action to Allow for all users. Place it at the top of the list.

 

https://kb.smoothwall.com/hc/en-us/articles/360015987639-Create-Web-Filter-Policies

Posted (edited)

Finally had some success with this today. Now this has worked perfectly on our Lightspeed Rocket set up and triggers the captive portal every time without fail. These are the terms/headers/categories for the areas that i have used below. Hopefully this will help anyone still struggling!

 

Web Filter -> Settings -> Proxy Server

SSL Decryption Exemptions:

connectivitycheck.gstatic.com

gstatic.com

tools.google.com

clients3.google.com

pki.google.com

apis.google.com

safebrowsing.google.com

clients4.google.com

googleusercontent.com

play.google.com

clients5.google.com

ajax.googleapis.com

accounts.google.com

client-channel.google.com

ssl.gstatic.com

googleapis.com

pack.google.com

dl-ssl.google.com

storage.googleapis.com

dl.google.com

accounts.youtube.com

commondatastorage.googleapis.com

omahaproxy.appspot.com

clients6.google.com

ytimg.com

accounts.google.co.uk

clients2.google.com

clients1.google.com

m.google.com

cros-omahaproxy.appspot.com

apps-apis.google.com

oauth.googleusercontent.com

verisign.net

 

-----------------

Web Filter -> Settings->Authentication

Web Destination Exemptions

connectivitycheck.gstatic.com

pki.google.com

ssl.gstatic.com

accounts.google.com

apis.google.com

 

-----------------

Web Filter -> Settings->Authentication

Proxy Destination Exemptions

connectivitycheck.gstatic.com

accounts.google.com

clients*.google.com (if wildcards or accepted, in my case they aren't so the below clients2-6)

clients2.google.com

clients3.google.com

clients4.google.com

clients5.google.com

clients6.google.com

play.google.com

googleusercontent.com

storage.googleapis.com

 

-----------------

Web Filter->Database->Categorized Sites

Mark as 'Local-Allow'

connectivitycheck.gstatic.com

accounts.google.com

pki.google.com

ssl.gstatic.com

clients3.google.com, clients4.google.com, etc.

apis.google.com

play.google.com

storage.googleapis.com

Edited by athomashayter

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...