Jump to content

Recommended Posts

Posted

I havent used the SWGLF admin filtering system for well over a year now, but i have just faxed off some headed paper so that i can get on and take a look.

 

Are you saying that you can disable all filtering for all users from that cpanel?

Posted (edited)

There is a new proxy server which can be used. It's the same as unfiltered but purely for wsus, sophos etc... but again still works as a unfiltered.

 

If you give swgfl a call i'm sure they'll give you it. ;)

Feel free to PM me and ill pass it on.

Edited by flexyjerkov
Posted
I havent used the SWGLF admin filtering system for well over a year now, but i have just faxed off some headed paper so that i can get on and take a look.

 

Are you saying that you can disable all filtering for all users from that cpanel?

 

Yes. You have complete control. But whatever you turn off is turned off for everyone. If you'd want to have your own filtering solution in school.

 

You can disable or enable whatever you want BUT you do so for all users (we like a 'them and us situation' here :)

 

Yep, but if you have your own solution in school then this shouldn't be a problem as you can maintain 2 filtering systems onsite instead.

Posted

I can’t believe we where not given any prior warning apart from one document dated 2006 which I had never seen until it was dug up by the SWGFL

 

The extra work involved with creating Staffproxy accounts that this has caused is such a pain. We have put time into making shore sufficient security in place on our network to stop any unwanted people using unfiltered.proxy.

 

So why can't it be an option for individual schools to have it enabled?

Posted

Think it maybe because its unfair to have one rule for one school and another for another school. For us we've not had a problem with the removal of unfiltered as we had an idea it was coming once we found out about staffproxy.

 

MicrodigitUK... I was probably one of them who kept getting through your security, Well thats if you were there 6 years ago.

Posted

Hi All,

I noticed this thread and thought that it might help if I gave a brief overview of the SWGfL filtering solutions/proxy servers.

 

Standard SWGfL Filtering

 

Using the standard SWGfL Filtering, which is accessed via cache.swgfl.org.uk or cache. (where is the school's domain name) you have the option to manage the level of filtering that is applied to the school, via the SWGfL Filtering website https://admin.filtering.swgfl.org.uk

 

The SWGfL filter lists, that can be enabled/disabled by ticking or unticking the box next to the filter list are:

 

Content

SWGfL Drugs and Substance Abuse List

SWGfL Intolerance List

SWGfL Violence List

SWGfL Pornography and Illegal or Age-Restricted Activity List

SWGfL Proxy Bypass List

 

 

Services

SWGfL Web-Based Chat List

SWGfL Web-Based Mail Services List

SWGfL Mobile Phones/SMS/Ring Tones List

SWGfL Web-Based Social Networking List

SWGfL Non-Educational Games List

 

 

Download

SWGfL Banned .exe Download List

SWGfL Banned .mp3 Download List

 

 

In addition to this, you have the option to create additional permit or deny rules for both URLs and search terms, which override the above filter lits.

 

From within https://admin.filtering.swgfl.org.uk, the other available options are to enable or disable the school's filter lists and to enable or disable access to Staff Proxy. These options can be found under 'Local admin details':

 

Your Filter List Enabled

 

Allow Use of staff Proxy until

 

 

Under 'User Management' you can create and manage Staff Proxy users.

 

 

As has been mentioned in an earlier post, it is possible to disable all filter lists within the SWGfL Filtering Administration website, which would give you an almost entirely unfiltered internet connection but this is not advisable as this is a global change (per establishment) which would mean that all users in the establishment would have an unfiltered internet connection.

 

 

SWGfL Unfiltered Access

 

Users browsing via unfiltered.cache.swgfl.org.uk or staffproxy.swgfl.org.uk will be routed via the SWGfl Staff Proxy servers. This is a filtered proxy service with the additional option of logging in to Staff Proxy to gain unfiltered access. This is done by entering login.staffproxy in the address bar of your web browser and then entering valid username and password for a user who has been granted access to login to Staff Proxy.

 

Note that unfiltered access does not mean unmonitored access and all unfiltered access via Staff Proxy is logged in the same way as access by the SWGfL filtered proxies.

 

 

In addition to Staff Proxy, the SWGfL has proxy server (smartcache.proxy.swgfl.org.uk) which has historically been used to provide an unfiltered upstream connection to SWGfL content delivery and caching servers (SmartCache 2) with SafetyNet Universal installed. This is to ensure that only one level of SafetyNet Filtering is applied, to ensure that schools have full control over their filtering solution without the risk of upstream filtering overriding rules applied to the local filtering solution.

 

Access to smartcache.proxy.swgfl.org.uk is using an IP access list, which is designed to permit access from only 1 IP address within a SWGfL establishment.

 

Due to the recent removal of the SWGfL unfiltered proxies, a decision has been made to allow other local filtering solutions access to smartcache.proxy.swgfl.org.uk, for the same reasons as access is granted to SWGfL content delivery and caching servers. As a responsible educational ISP the SWGfL are doing as much as possible to ensure that the smartcache.proxy service is not abused, as such, access will only be granted to a single IP address and only following confirmation that the IP address has been assigned to a local filtering solution such as SmartCache 2, WebSense, Equiinet, Blox etc.

 

If you are in a position whereby you have a local filtering solution that requires an unfiltered upstream connection, you can request access to smartcache.proxy.swgfl.org.uk by logging a call with the SWGfL help desk and then arranging for the school head to send a signed fax, on school headed paper, stating that you agree to abide by the terms applied to usage of the service.

 

 

I hope this helps to clarify the options available - Please feel free to drop me a PM if you have any questions.

 

Chris

Posted (edited)
Hi All,

In addition to Staff Proxy, the SWGfL has proxy server (smartcache.proxy.swgfl.org.uk) which has historically been used to provide an unfiltered upstream connection to SWGfL content delivery and caching servers (SmartCache 2) with SafetyNet Universal installed. This is to ensure that only one level of SafetyNet Filtering is applied, to ensure that schools have full control over their filtering solution without the risk of upstream filtering overriding rules applied to the local filtering solution.

 

Access to smartcache.proxy.swgfl.org.uk is using an IP access list, which is designed to permit access from only 1 IP address within a SWGfL establishment.

 

Due to the recent removal of the SWGfL unfiltered proxies, a decision has been made to allow other local filtering solutions access to smartcache.proxy.swgfl.org.uk, for the same reasons as access is granted to SWGfL content delivery and caching servers. As a responsible educational ISP the SWGfL are doing as much as possible to ensure that the smartcache.proxy service is not abused, as such, access will only be granted to a single IP address and only following confirmation that the IP address has been assigned to a local filtering solution such as SmartCache 2, WebSense, Equiinet, Blox etc.

 

If you are in a position whereby you have a local filtering solution that requires an unfiltered upstream connection, you can request access to smartcache.proxy.swgfl.org.uk by logging a call with the SWGfL help desk and then arranging for the school head to send a signed fax, on school headed paper, stating that you agree to abide by the terms applied to usage of the service.

 

Hi Chris, many thanks for the heads up. :-) I’m not sure of your involvement with SWGfL if any so please forgive me if I’m asking the obvious (information from SWGfL is generally not forthcoming and is akin to getting blood from a stone!)!

 

I have been informed by someone that shall remain nameless that your post was just “forum gossip” however today I noticed this on the SWGfL website: South West Grid for Learning Trust - SWGfL News

 

Currently on our site we have an RM SmartCache as our local proxy. This is used by all users on site (Staff and students); this in turn uses the “proxy.swgfl.org.uk” proxy.

 

We had also been using the “unfiltered.proxy.swgfl.org.uk” proxy purely for unfiltered tech support ‘net access and server ‘net access.

 

I am finding the staff proxy/update proxy is next to useless and have to keep changing proxies to get at things. In some cases, regardless of the proxy used I just can’t get at / do things that I ought to be able to!

 

If our school selected to use the “smartcache.proxy.swgfl.org.uk” as suggested in your post could we proxy this (with ISA Server for example) internally for technical support/update purposes (essentially giving us a secure unfiltered feed) and continue to use our RM SmartCache 2 to proxy the feed from the “proxy.swgfl.org.uk” proxy? If so that’s what I’ll suggest to our senior team as this would put us back in the exact same position as we were prior to 06th Nov 2008 which is essentially what I want from SWGfL! :-)

 

Cheers

 

 

Ben

Edited by bgarston
Posted
Hi Chris, many thanks for the heads up. :-) I’m not sure of your involvement with SWGfL if any so please forgive me if I’m asking the obvious (information from SWGfL is generally not forthcoming and is akin to getting blood from a stone!)!

 

I have been informed by someone that shall remain nameless that your post was just “forum gossip” however today I noticed this on the SWGfL website: South West Grid for Learning Trust - SWGfL News

 

Currently on our site we have an RM SmartCache as our local proxy. This is used by all users on site (Staff and students); this in turn uses the “proxy.swgfl.org.uk” proxy.

 

We had also been using the “unfiltered.proxy.swgfl.org.uk” proxy purely for unfiltered tech support ‘net access and server ‘net access.

 

I am finding the staff proxy/update proxy is next to useless and have to keep changing proxies to get at things. In some cases, regardless of the proxy used I just can’t get at / do things that I ought to be able to!

 

If our school selected to use the “smartcache.proxy.swgfl.org.uk” as suggested in your post could we proxy this (with ISA Server for example) internally for technical support/update purposes (essentially giving us a secure unfiltered feed) and continue to use our RM SmartCache 2 to proxy the feed from the “proxy.swgfl.org.uk” proxy? If so that’s what I’ll suggest to our senior team as this would put us back in the exact same position as we were prior to 06th Nov 2008 which is essentially what I want from SWGfL! :-)

 

Cheers

 

 

Ben

 

Hi Ben,

That post took me ages to write - Fancy someone ruining all my hard work by suggesting that it was forum gossip :rolleyes:

 

Seriously though, the information in my post was definitely accurate, as you have seen from the SWGfL website.

 

I will drop you a PM with some more information about smartcache.proxy.swgfl.org.uk.

 

Many thanks,

 

Chris

Posted
As far as I know, contracts that schools and LEAs sign with SWGfL specify that you aren't allowed to install a second, non SWGfL line...

 

Eh? What's that? (pricks ears up).

 

I don't ever remember seeing anything about that - but then again I didn't do the signing up to the SWGfL.

 

We're activly looking into a backup ADSL link - any links to verify this restrictive piece of RM bo!$%ks?

 

HBJB

Posted

all,

 

was at the 2nd network managers confernece today for Somerset Network Managers, unfiltered access will not be coming back, ELiM have stated today that staff proxy will now need to be used, got gven the whole spiel about pornography access by staff etc etc.

Posted
Eh? What's that? (pricks ears up).

 

I don't ever remember seeing anything about that - but then again I didn't do the signing up to the SWGfL.

 

We're activly looking into a backup ADSL link - any links to verify this restrictive piece of RM bo!$%ks?

 

HBJB

 

Not RM ... this pretty standard across all RBCs as it puts risk on JANET. Remember that the SLA you have with the LA is cascaded down from the RBC which is cascaded down from their providers, one of which will be JANET ... and they are seriously against you having another connection on the network unless you play by some very serious rules.

 

The same goes for the filters ... I don't know of any LA / RBC that would now be happy to give staff unfiltered access.

Posted

If we have our own filtering system and restrict who has access to to the resources surely that's enough to satisfy the RBC.

 

I can't track any documents down about what hoops we need to jump through to have a failsafe route to the internet. I find it a bit ironic that they seem to want your backup connection to be from the same provider that would most likely be down at the same time. Surely a backup connection must be from someone else.

 

HBJB

Posted

Staff proxy, dont get me started, up my life this week.

 

Unfiltered access is now a joke, logmein is broken and for a while none of the updates for nod or WUS worked. Teachers were complaining at why I couldn't download youtube videos and such.

 

The current login procedure is terrible, talk about kicking the out of it. Do I need to be told every time I use the "service" that I will be in trouble if I look at pictures of naked women / men / donkeys? Do I have the attention span of a year 5 pupil?

 

you SWGFL!

 

Posted
We've been on this proxy for quite a few months, it's a royal pain in the ass but hey-ho, life must continue. Seems we were thrown on early because we needed to change IP ranges (they changed our proxies while they were at it).
Posted
We've been on this proxy for quite a few months, it's a royal pain in the ass but hey-ho, life must continue. Seems we were thrown on early because we needed to change IP ranges (they changed our proxies while they were at it).

 

Progress makes things better! Oh wait....

Posted
Not RM ... this pretty standard across all RBCs as it puts risk on JANET. Remember that the SLA you have with the LA is cascaded down from the RBC which is cascaded down from their providers, one of which will be JANET ... and they are seriously against you having another connection on the network unless you play by some very serious rules.

 

The same goes for the filters ... I don't know of any LA / RBC that would now be happy to give staff unfiltered access.

 

Surely schools will need some kind of backup connections if the main one goes down and in my opinion they should be from another supplier and not part of the same line. When school are told to use VLEs etc that may be hosted elsewhere it is imperative to have backup lines for internet access for things like UCAS, VLEs and emails etc.

 

The notion of the second line infiltrating the main RBC/JANET connection is valid but they should offer so guidance on how a school can a have safe second connection as well as the main connection provided by RBC. Saying that the second backup connection is against the rules and is strickly not allows seems plain silly.

 

It is restrictive things like the above that puts people off the whole RBC thing in the first place. My biggest grip about RBCs in general is that they are looking at bolt on bits i.e. add-on to the services rather than looking at improving the the reliability of the core services i.e. reliable internet access, reliable web filtering and reliable email access and filtering. Providing some flexibility of IP address assignment or network design would also help as well rather than dictating what the school should use. If this break the grand SSO and Federated services (i will be suprised if RBCs get this done until 2012 if that) then be it and let the school become one of the identity provider in the whole SSO framework.

 

Gone of the topic here slighly but the above points do need consideration.

 

 

Ash.

Posted

Ref: additional backup ASDL links

 

First we have heard about not being allowed. When we approached the LA about our requirements, they even suggested we should get an ADSL line and run our applications over it.

 

I know of several other schools that also do this. We use the connection for email, and terminal server access.

Posted

I have now switched to the “smartcache.proxy.swgfl.org.uk” and with a local linux proxy server (I have setup to get around the 1 IP address problem), where back on unfiltered via my new linux proxy. (Better than that silly staffproxy login thing for us techs)

 

P.S Our school received an email today with the following letter from The SWGFL.

S088-08 SP056-08[1].doc

Posted
I have now switched to the “smartcache.proxy.swgfl.org.uk” and with a local linux proxy server (I have setup to get around the 1 IP address problem), where back on unfiltered via my new linux proxy. (Better than that silly staffproxy login thing for us techs)

 

P.S Our school received an email today with the following letter from The SWGFL.

 

We did the same; we have ISA proxying the feed (so we can secure the feed down to specific domain users and servers, etc) and our RM SmartCache 2 can still look at the normal filtered SWGfL proxy for all students and the remainder of staff on site. This solution essentially puts us the same position as before which is a result! :-)

 

Cheers

 

 

Ben

  • 2 weeks later...
Posted

 

4. I explained that although I had no problem with them tracking usage, the implementation of the system was severely lacking. I was now facing entering 200 user names 1 by 1 into their web interface and telling my staff of the annoying go to login.staffproxy etc. way to get unfiltered access. She was sympathetic and would take my concerns into consideration but there was nothing she could do now.

!

Then you have issues like ensuring that none of these staff let kids know this information. But cover teachers can get hold of it. As well as it being an "all or nothing" approach.

 

I'd also be reluctant to call something which only works in a few specific web browsers a "web interface" too.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...