jtcoops Posted June 13, 2025 Posted June 13, 2025 One of our schools are with LGFL and use their School Protect filter. They have an issue which doesn't affect our other schools under LGFL, and having raised this issue with LGFL there hasn't been any real progress in resolving. Since March and the latest update of Chrome / Edge certain websites simply will not load properly. They either time out completely, or load a very basic text only version. At the moment if we use Firefox the sites load up as normal. If we run an old version of Chrome the sites load fine. New version and the issue returns. It started with just one website but we are finding more sites are getting affected. The attached gives a screen shot. The top is how the site renders on new devices running Chrome released since March. The bottom is how it displays on old installs of Chrome (test environment). However if we join one of the PCs to a wifi hotspot the sites load fine, so its not a Chrome issue as such, its a rendering / block by an element of the site via the web filter. Has anyone encountered this and can give a steer on how we fix it? Affects Wifi and LAN connected devices. Chrome issue.docx
PaddyNewman Posted June 14, 2025 Posted June 14, 2025 Developer tools > Network. What's failing to load? Got a case, I'll look at it for you.
jtcoops Posted June 16, 2025 Author Posted June 16, 2025 Hi thanks for this. So the components failing to load are in the snip below, this covers the initial page, login page for email, then after the login is processed
PaddyNewman Posted June 16, 2025 Posted June 16, 2025 The failure to load "https://auth.every.education/images/every-logo_sm.png" is weird. Can you DM me the case ref so I know the school and will check some logs.
PaddyNewman Posted June 16, 2025 Posted June 16, 2025 Thanks, I've got that. Can you double click the failed loading files (the every-logo_sm.png) would be a good one to try and load.
PaddyNewman Posted June 16, 2025 Posted June 16, 2025 (edited) Thanks, can see the problem, will update the support case then you are welcome to feed it back here if you wish Edited June 16, 2025 by PaddyNewman
jtcoops Posted June 16, 2025 Author Posted June 16, 2025 Thank you so much for your help. We keep finding little gems left behind by the previous IT Manager and this is firmly in that category. Ive updated and closed the ticket.
DavidYoung Posted June 16, 2025 Posted June 16, 2025 I work with @PaddyNewman at LGfL and wanted to update this thread with the fix in case there's any other LGfL (or other provider) customers experiencing a similar issue. Last year, a new technology called TLS-ECH (https://developers.cloudflare.com/ssl/edge-certificates/ech/) was rolled out by CloudFlare which hides the domain name from filters (all inline network-level filtering, not just ours). We quickly updated our DNS servers to counter this by removing the required HTTPS records delivered by clients and, more recently, blocking the underlying ECH domain (cloudflare-ech.com). This means that all LGfL customers using our DNS resolvers are fully protected from this bypass. Those not using our DNS servers (e.g. Google DNS, OpenDNS, etc.) will find sites that implement ECH aren't accessible as the protocol does not have a fallback. The solution here is for LGfL schools to make sure you're using our DNS forwarders (there are several depending on what YouTube mode you want). We also implement PDNS, safe search and other protections through our DNS servers. Making sure you are using HTTPS decryption is also important for proper filtering. Those using other network filtering platforms should check with your provider that they can properly filter ECH sites both when using decryption and when not. Hope this helps if anyone else has a similar issue. David 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now