Jump to content

Recommended Posts

Posted (edited)

Hello,

 

Where I am currently, only myself (Network Manager) has access to block/unblock websites. This, partly is down to me being accountable to my DSL for what changes we make.

 

I've been looking at giving my staff a bit more freedom, as requests come in that they could action.

However, Smoothwall doesn't currently have any auditing in place (eg who makes changes), so I wouldn't be able to keep track of any changes are made.

Not that I don't trust my staff, but it's something I would want for KSCIE.

 

Smoothwall say it's one of their most popular requests, but have no timescale on it (Annoyingly...)

 

 

Just wondering what others' views are on this & what the practices are elsewhere around this.

 

 

Edited by DrCheese
Posted

Team of 3 IT (NM and 2 senior techs) We will use our own judgement to block sites that need it when reported to us (or if we see it in the wild). Unblock requests go via form to Deputy head which needs to have a justification on it and that then gets passed to us. 

Posted (edited)

Just me and my deputy. Overseen by the DSL (who also happens to line manage the IT Service). Very rarely actually get a legitimate request to have something unblocked, usually it was transient error,  a pause by the web-filter as it decides what category to put the site as its new that day, or that the teacher hasn't signed into YouTube so gets the most restricted set of results.

 

All requests logged on the help desk, and form part of a termly report from IT to the dsl.  (the report is more to demonstrate KCSIE compliance to governors than serve any practical purpose - since the anything that needs to be reviewed happen pretty much instantly it hits the helpdesk, or escalated within the line-management framework which operated at a much faster cadence than the formal reports).

 

(Technically the DSL has access to the filtering platform as does the Head Teacher, but they never logon)

 

Edited by psydii
Posted

If it's miscategorised or uncategorised, then I just update it with Fortinet directly (or staff can) with their online form and a human their end checks it and updates everyone's firewall within a few minutes. This covers 90% of all unblock requests cos it'll be a new edu-specific website or newly registered and not seen before.

 

If it's a real need to bypass an otherwise blocked category, then I bounce it to the head first.

Only myself or my tech will actually do the unblock in this case.

Posted

Just me onsite, Trust core team can as well if it needs adding to HTTPS bypass etc

 

All requests are submitted via automated form and goes to the Principal or there delegate before i add to allow lists.

 

Game blocks i use my judgement on to escalate or just block 

Posted

Thanks folks, this helps a lot

 

@tom_newton But can changes to the on prem box be made from smoothwall cloud?

We use smoothwall cloud for our off site devices of course, but all our policies and so on are done on the on prem device.

 

 

Posted

Interesting question there.  I wonder what everyone's views are on the latest SIC guidance (May 2025) regarding internet filtering

 

https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring

 

Specifically

https://d1xsi6mgo67kia.cloudfront.net/uploads/2025/05/Appropriate-Filtering-for-Education-settings-2025-final-clean-2.pdf

 

Page 2 at the bottom

 

image.thumb.png.f93d22968752921b1def1930d5471145.png

 

To me this reads that system admins should not be able to amend\change blocklists.  This sounds like a mistake.  Normally I'd say we can just ignore this guidance, but the definitions here are apparently cited by the DfE and in the latest KCSIE documents, making ignoring it a lot more troublesome.

 

Thoughts?

Posted
5 minutes ago, mbedford said:

Page 2 at the bottom

 

image.thumb.png.f93d22968752921b1def1930d5471145.png

 

To me this reads that system admins should not be able to amend\change blocklists.  This sounds like a mistake.  Normally I'd say we can just ignore this guidance, but the definitions here are apparently cited by the DfE and in the latest KCSIE documents, making ignoring it a lot more troublesome.

 

Thoughts?

IWF Is the Internet Watch Foundation, and apparently CTIRU Is counter terrorism.

 

These lists will have adult content, harmful and otherwise illegal content in them.

The way that's worded is that staff can't remove stuff from those specific lists.

 

I would be concerned about any staff member wanting anything (correctly) in those lists to be unblocked.

 

Also "should" not "must" 

 

Posted
2 minutes ago, machy said:

IWF Is the Internet Watch Foundation, and apparently CTIRU Is counter terrorism.

 

These lists will have adult content, harmful and otherwise illegal content in them.

The way that's worded is that staff can't remove stuff from those specific lists.

 

I would be concerned about any staff member wanting anything (correctly) in those lists to be unblocked.

 

Also "should" not "must" 

 

I agree with your interpretation, but in practice.  How do you prevent a system admin from changing the block list? 

 

I administer our web filter and of course, I am not going to do anything untoward, but, I am not prevented from doing so.  Any web filter which did prevent the system admin from disabling or enabling features is not going to get much more than a cursory glance from an evaluation at purchase time.  What if the IWF or CTIRU accidentally blacklist a legit site, i know, unlikely, but over the last few years, life has taught me the things that were once very unlikely, actually aren't.

 

https://duckduckgo.com/?q=Cloud+outages&t=ffab&ia=news&iar=news

Posted (edited)
4 minutes ago, mbedford said:

 How do you prevent a system admin from changing the block list? 

 

Those lists are carefully guarded, they are not accessible on any filtering platform, they just exist. From an admin's point of view they may as well be compiled into the executable.

 

If you are rolling your own filtering system, IWF and the ?Home Office? are not going to give those lists to you, so you cannot build a compliant filtering platform in house.

Edited by psydii
Posted (edited)
5 minutes ago, psydii said:

Those lists are carefully guarded, they are not accessible on any filtering platform, they just exist. From an admin's point of view they may as well be compiled into the executable.

 

If you are rolling your own filtering system, IWF and the ?Home Office? are not going to give those lists to you, so you cannot build a compliant filtering platform in house.

We use Sophos UTM for our webfiltering and I am very much able unblock any URL I want, regardless of which list it was identified in.  I agree, the list itself should not be changed, but preventing admins from administering a system is like using a sledgehammer to push in a thumb tack, its the wrong solution to the problem.

Edited by mbedford
Posted
39 minutes ago, tom_newton said:

Yes, all policy changes sync 

Hi Tom,

 

I have smoothwall cloud but it's just all the reporting features, how do I enable management from the cloud, or is this a paid extra?

Posted (edited)

Meeting digital and technology standards in schools and colleges - Filtering and monitoring standards for schools and colleges - Guidance - GOV.UK

 

States:

 

Quote

How to meet the standard


Governing bodies and proprietors have overall strategic responsibility for filtering and monitoring and need assurance that the standards are being met. 

 

To do this, they should identify and assign: 

 

  • a member of the SLT and a governor, to be responsible for ensuring these standards are met
  • the roles and responsibilities of staff and third parties, for example, in-house or third-party IT support

 

There may not be full-time staff for each of these roles. Some responsibilities may lie as part of a wider role within the school, college, or trust. However, it must be clear who is responsible and it must be possible to make prompt changes to your provision.

 

Technical requirements to meet the standard  


The SLT is responsible for:

 

  • buying filtering and monitoring systems
  • documenting decisions on what is blocked or allowed and why
  • reviewing the effectiveness of your provision
  • overseeing reports

 

They are also responsible for making sure that all staff: 

 

  • understand their role
  • are appropriately trained
  • follow policies, processes and procedures
  • act on reports and concerns

 

Senior leaders should work closely with governors or proprietors, the DSL and IT support in all aspects of filtering and monitoring. Your IT support may be in-house or a third-party service provider.

 

Day-to-day management of filtering and monitoring systems requires the specialist knowledge of both safeguarding and IT support to be effective.

 

 

Edited by MYK-IT
  • Thanks 1
Posted

1. IT manager has access

2. Safegarding officer could have access however any unblocks should be vetted through the right channels.

IF you have a company that manages smoothwall, requests from IT manager, safeguarding officer and head.

 

The fewer the better.

 

5nowman

Posted

Some central blocking was by our provider (HGfL) and some blocks were added locally by the Network Manager, usually at the request of teachers who saw off-task/disruptive behaviour by students.

 

It was possible to delegate control of local filters to teachers/other staff, but this was seldom done as they "wanted it done", but they tended to be not interested in doing the work. Also, we had a history of password leakage to students by staff who did not take the issue seriously.

 

Summary: Filtering was by the LEA and the Network Manager (using IronPort, I think?)

Posted
1 hour ago, gszech said:

The web filter is managed by our safeguarding team as per DFE Meeting digital and technology standards in schools and colleges requirements. 

Our role is to make sure that the safeguarding filter works and test it at least once a year. 

 

Thanks

Greg

Been thinking for a while of adding "Associate Deputy Safeguarding Lead (Digital Safety)" to my job title.  (that title looks made up, but its not far of several others that exist in the wider safeguarding team!)

Posted

I mainly, but not exclusively themake changes for Netsweeper and Impero.  Both have an audit trail.

 

It depends on why the change is needed.  Is it a real change, or a fix to repair something that no longer works or shouldn't work but now does? If it's one of those or within our policy, I just get on with it.  

 

I will block if I see something that needs blocking, and it's a Safeguarding issue, as a do first, report later. 

 

I'm generally having to make a few recategorization requests on a daily basis sadly.

 

More concerning is having to keep an eye on the ISP, who make stupid changes without telling anyone, such as turning off decryption and replacing it with a bypass for google.com and google.co.uk last Monday.  It's wasn't off for long, but it shouldn't have happened at all.  So, I monitor them like a hawk, as usually when they make changes it has unwanted side effects for us that need mitigating.  

  • 3 months later...
Posted
On 18/06/2025 at 14:11, DrCheese said:

Hello,

 

Where I am currently, only myself (Network Manager) has access to block/unblock websites. This, partly is down to me being accountable to my DSL for what changes we make.

 

I've been looking at giving my staff a bit more freedom, as requests come in that they could action.

However, Smoothwall doesn't currently have any auditing in place (eg who makes changes), so I wouldn't be able to keep track of any changes are made.

Not that I don't trust my staff, but it's something I would want for KSCIE.

 

Smoothwall say it's one of their most popular requests, but have no timescale on it (Annoyingly...)

 

 

Just wondering what others' views are on this & what the practices are elsewhere around this.

 

 

Giving staff more freedom without auditing is risky, especially for compliance like KSCIE. Without logs, accountability is lost. Until Smoothwall adds auditing, you might consider creating a change‑request workflow where staff submit requests to you for action, ensuring control. Alternatively, explore third‑party tools or firewall solutions that include detailed change logs and role-based access.

Posted

Me and both tech are able to block/unblock sites.

 

MS Form for staff to complete which is then approved/denied by DSL, which then creates a helpdesk ticket

 

We add request to fortigate with with staff initials of tech, date and approval date and ticket number in the comment box.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...