NetworkGeezer Posted November 27, 2006 Posted November 27, 2006 What do you do at your school? Do you prefer the control (and added headaches) of having public IP addresses or do you let the ISP have the bother of looking after the firewall?
Guest Guest Posted November 27, 2006 Posted November 27, 2006 Unfortunatly we have RBC which comes with the headaches of service down, email and cache/filtering proxy are crap, etc Would love the "headache" of a public IP.
alonebfg Posted November 27, 2006 Posted November 27, 2006 we have a rm service called swgfl they deal with ll of that for us so i cant be any help our ip address is not a puplic one.
NetworkGeezer Posted November 27, 2006 Author Posted November 27, 2006 we have a rm service called swgfl they deal with ll of that for us so i cant be any help our ip address is not a puplic one. That's fine all I was trying to see was what people had in place and the pros and cons. It'll be god to have the opinions of opel who implement Websense or DansGuardian on site to see what they do.
Slartibartfast Posted November 27, 2006 Posted November 27, 2006 We pay an obscene amount of money (over 26000) for a crippled RBC broadband connection. No public IPs, and a variety of restrictive practices by the LEA make even simple tasks difficult.
NetworkGeezer Posted November 27, 2006 Author Posted November 27, 2006 RBC= Regional Broadband Consortium Each consortium is made of a group of local education authorities who banned together to buy broadband services from an ISP for their schools. You can recognise them by the fact their names tend to be of the form xGfL where x = region name. I supposed I used RBC generically to refer to indirectly purchased broadband.
PiqueABoo Posted November 27, 2006 Posted November 27, 2006 added headaches You get headaches either way.. the respective magnitudes depend on your competence versus theirs.. s'no generic answer for that. I imagine genuinely competent people will suffer in consortiums. It's difficult for large organisation to deal with exceptions and they often end up taking away choices that their average "customer" can't handle.
indie Posted November 27, 2006 Posted November 27, 2006 Unfortunatly we have RBC which comes with the headaches of service down, email and cache/filtering proxy are crap, etc Would love the "headache" of a public IP. Northern Grid by any chance?
CyberNerd Posted November 27, 2006 Posted November 27, 2006 we have best and worst of both worlds. RBC dishes out RFC1918's, then we firewall and NAT again onto another network. So basically we pay for the rubbish RBC connection/ useless proxy and a load of other services we don't use (SMT won't change this). but we also get the 'headaches' of being in control of the network - which does have some advantages
Ric_ Posted November 27, 2006 Posted November 27, 2006 A quick search should throw up more through discussions of this topic. Personally, I use a RBC connection (CLEO in Lancashire) - one which I believe is one of the better ones. With RBC connections, you often get added goodies thrown in, like DNS and web hosting, VLE, mail, content filtering and access to NEN (National Education Network) to name but a few. You really need to weigh up the pros and cons of each before choosing one way or the other... price or external IPs isn't really a good guage. You need to be able to show good value, reliability, security and protection for the little darlings. As I said above... search for the site for further details.
DMcCoy Posted November 28, 2006 Posted November 28, 2006 We use the Segfl. Its rubbish. I have had a number of 24+ hour down times this year. Email delayed in a queue for OVER 30 days! Email is always delayed and I no longer trust it. I am not allowed smtp, bit torrent (linux iso), ICMP or any other interesting services. Recently all my external requests were given the ip of one of their routers, and were therefore blocked by the firewall rules. After that some dns requests to my isp (and other) dns servers started returning the internal RM ip addreses (10.20 etc). Content filtering is from the stone age and has not changed in 5 years. I have no control, and would love to have a public iip address and my own firewall sat in front of it.
Nij.UK Posted November 29, 2006 Posted November 29, 2006 I use EMBC (East Midlands - Leicester) and we get all the things that Ric said... The only problem is that the quality of the serivce is quite poor, but i think we pay around 9000pa... so its not as expensive as what some are paying!
NetworkGeezer Posted November 29, 2006 Author Posted November 29, 2006 A quick search should throw up more through discussions of this topic. Yes I have read the previous thread on people thinking of leaving their RBC/LA provision altogether and going it alone e.g. via ADSL. My question was more about people in CyberNerd's situation where they are incharge of firewall and other services but still have the RBC as their ISP or do most people just except the NAT provided by the RBC. Interesting reponses none the less.
GrumbleDook Posted November 29, 2006 Posted November 29, 2006 We have been sorting out a good arangement with our RBC. We have our own firewall and NAT internally ... we still have htem NAT some public address to EMBC NATted addresses ... and we redirect those when they reach our firewall. We have control of our filters (non-authenticating in pass through mode at level 1 for any traffic that goes through our filewall) and we host our own internal mail and web filters, along with our own webservers and email. Just gotta do some changes on DNS this weekend and we will be good to go.
SpuffMonkey Posted November 29, 2006 Posted November 29, 2006 We have been sorting out a good arangement with our RBC. We have our own firewall and NAT internally ... we still have htem NAT some public address to EMBC NATted addresses ... and we redirect those when they reach our firewall. We have control of our filters (non-authenticating in pass through mode at level 1 for any traffic that goes through our filewall) and we host our own internal mail and web filters, along with our own webservers and email. Just gotta do some changes on DNS this weekend and we will be good to go. What firewall/web filtering products do you use GD??
alonebfg Posted November 29, 2006 Posted November 29, 2006 i find swgfl good in the way it works the only problem i have had is the responce time to a router issue which took nearly 1 wk but filterd email is really good and music downloads also a site called infomapper.com which is free to swgfl is gogle earth plus it has os maps historic maps world maps and you can overlay the lot so i cant moan. Its the extra services that make it worth it.
GrumbleDook Posted November 29, 2006 Posted November 29, 2006 Firewall is now a Firebox X700 and we use Smoothwall for web filtering and MailMarshall for email filtering ... depending on how good we find the email filtering over the spring term we may drop MailMarshal. I have used EMF before (Whilst at Brooke Weston) and I really like it ... it takes a bit of tweaking but generally it is spot on. Smoothwall has a few interesting issues but Stephen is in conversation with the Smoothwall guys and we hope to iron these out shortly ... it looks like one issue (embedding of movie files in web pages not loading the link properly) is down to a combination of the firewall and Smoothwall ...
SpuffMonkey Posted November 30, 2006 Posted November 30, 2006 Did you "roll yer own" Smoothwall - or have it installed for you? I'm thinking of having a look at it.
GrumbleDook Posted November 30, 2006 Posted November 30, 2006 We bought in Corporate Guardian because we wanted the support and updates for at least the first year ... and it worked out cheaper than Symantec Web Security too. Tom and folks were really helpful sorting out exactly what we needed and Stephen (a confirmed non-*nix person) was happy. Basically an ISO that we loaded onto one of our Poweredge boxes ... went on very smoothly (pardon the pun) ... and had a relatively easy guide to set it up. When we have more time I would like to get to grip with building our own DansGuardian box ... if nothing else to give the rest of the team the experience of doing it.
Geoff Posted December 1, 2006 Posted December 1, 2006 If you need a hand with Dansguardian/Squid/etc please direct things at me. I can most likely help.
webman Posted December 1, 2006 Posted December 1, 2006 Have you finished the squid+dg howto yet Geoff?
contink Posted December 1, 2006 Posted December 1, 2006 If you need a hand with Dansguardian/Squid/etc please direct things at me. I can most likely help. Hi Geoff, I'm seriously thinking about the Extended Defence+ homebrew version of Smoothie but having loaded it on a spare PC I'm well aware that I'm in over my head with it all.. Any pointers on where to start and what to read first so I can get to grips with it all... Bearing in mind my primary concerns are: - Firewall - Guardian Reactive firewall - Content filtering (for a primary school) I suspect I may go with School Guardian if the school decide to drop the LEA link as the cost/risk element is in favour of an "out of the box" solution with support but I'd still like to learn this stuff for my own benefit.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now