Jump to content

Recommended Posts

Posted

Our LA have decided to revoke our wayleave, so who knows what happens in a few weeks when the Synetrix contracts end........

 

We have not even agreed the cable route in our case and are unlikely to agree as they have failed to make contact to discuss the route despite several attempts from our side.

 

Depending on how they handle the situaton, they could end up having more and more schools pull out of it. The wise thing would be to allow those who have worked out for themselves that the proposed service is not fit for purpose to leave, but if the court has to force them to let certain schools leave, thenany school they had previously denied this could actually have a case for compensation and more.

These are my thought, but I don't know for sure.

Posted

I have looked at the contract in details and all the promotion material that they sent out when asking schools to sign up. All I can see is mention of how the infrastructure will be put in place. No details of services apart from a listing and what schools would have had to typically pay if bought separately. And this list is actulally a listing of services that was available on LGfL 1.0.

 

So was it not safe to assume that that Broadband will be a direct replacement of LGfL 1.0? It appears to me all schools signed for was for Broadnabd to their school and LGfL 2.0 is now making up how they would like to administer the rest of the services as they go along. This is really not good for my school. I will keep you posted, when I hear from them.

Posted
So was it not safe to assume that that Broadband will be a direct replacement of LGfL 1.0?

 

This was pointed out to them. They basically stonewalled.

 

LGfL 2.0 is now making up how they would like to administer the rest of the services as they go along. This is really not good for my school. I will keep you posted, when I hear from them.

 

This too was pointed out. Atomwide (a name I class almost as low as TFL in my list of all time worst people to deal with) said they just do what they're told by LGFL. LGFL said nothing useful that ammounted to "we're not going to budge".

  • 2 weeks later...
Posted

Just found this thread. I am currently assisting a few dozen schools in London with the switchover and so far it has been nothing but trouble.

We have a few schools that run their own filtering and firewalling (option 2 with Synetrix) and they are basically up #### creak. Nowhere in the technical documentation that the schools received does it state that they will not be able to continue this type of service on the new network. It was only after an extensive phone conversation with someone at LGfL headquarters that it came to light that there is no 'connection only' option nor is there the ability to have a clean feed even to one IP address or username. ALL traffic will go through the Internet Watch Foundation's filters, which on the face of it seems like a good idea but we all know that no filtering is 100% effective. Atomwide will then apply their own four categories on top of this filtering to limit access even further.

 

It is an absolute joke that out of the box the standard LGfL 'Internet connection' (can it really be called this if all it allows access to is filtered web?) doesn't even allow email access. Last time I checked that was a pretty crucial part of the Internet.

 

Also seems a bit fishy that the remote support system that is used by the SIMS helpdesk (A Capita company) is banned for 'security reasons'. Who owns Synetrix? Oh yes, that'll be Capita as well.

 

I was annoyed when Capita/Synetrix implemented a blanket port 25 block across the whole of the LGfL but Atomwide's policies are on another level entirely.

 

If you are not happy please make your feelings known. One of my schools simply phoned up Synetrix and asked if they could continue the service with them and they were only too happy to oblige. They halved their bill from 27k to 12k for a three year 100Mbit connection.

 

If the Atomwide network was actually secure that would be one thing but I've demonstrated to others that I can access absolutely anything I want (pornography, AIM, FaceBook etc) through their connection using one freely available tool. Once kids know this it will be an endless game of cat and mouse as LGfL play catch up and blocks even more of the 'Internet'.

 

My last point in this rant (I'll stop soon, I promise) is that some of the Virgin engineers that are installing the kit are clearly totally incompetent. I have pictures of installs that would make you cringe. Routers hanging out of the front of cabinets, doors that if shut would crush the MTRJ fibre connector to pieces etc etc. This is kit that's been installed into cabinets that were on LGfL's 'approved list'. Don't even get me started on why a primary school of 200 users needs a 2U £7k+ cisco firewall.... All of this enterprise grade equipment is not free, you and I are paying for it somewhere down the line...

  • Thanks 1
Posted
I had to remove the Virgin kit from my racks and put it all back in the right way round. The clown who 'installed' it put the Cisco firewall in backwards so that half of it was sticking out the front & I couldn't shut the door. He couldn't manage the router at all so just plopped it on top of the rack. Useless.
Posted (edited)

I'm at a school today that's recently switched over (tunnelling through their connection in order to access stuff that I need to!!). The IT office has been inundated with staff and students coming in to complain that they can't access websites or their email or other online services.

 

Sorry, edited for clarity, the following, unlike the above, is nothing to do with lgfl2, just a general rant about poorly managed IT :-)

I've been dealing with muppets all day and am fed up with it. I spoke to one central IT department that looks after IT for a group of 50 schools and they are refusing to open a port OUTBOUND on one school's firewall because they insist everything has to go through their ntlm-only poxy proxy server. They don't even have a route to the Internet, DNS requests from clients are blocked and the only service their users (inc staff) can access is filtered http and https. It's the BOFH's dream.

Edited by sramdeen
Posted

These all sounds very frightening. Not that I was not already alarmed by the other restrictions I knew they intend to impose.

 

We are in a more difficult situation as the cable route has not even been agreed. The proposed route is a No no as this would cause damage to a £35k structure and Virgin has refused to look into alternative routes. So this looks like we could end up paying for a service which cannot be delivered as there is no wires to convey it.

It does appear as one big con. I can imagine what my users would do to me if their daily routine was disrupted as above at switch over.

Scary stuff.

Posted
they are refusing to open a port OUTBOUND on one school's firewall because they insist everything has to go through their ntlm-only poxy proxy server. They don't even have a route to the Internet, DNS requests from clients are blocked and the only service their users (inc staff) can access is filtered http and https.

 

::shrug:: This is **education** and it's almost like that here (not LGfL) and presumably other places: There are DNS servers you use that work, a bunch of proxies where schools can pick a predefined filtering level or implement their own, if you must you can get IMAP & SMTP-AUTH 587 out to some places and possibly a couple of others. maybe videoconferencing type stuff etc. for which I presume there was a credible business case.

 

The folk providing RBC etc. connections have a 'duty of care' that you don't appear to appreciate (comments on "filtered web"). They're possibly overdoing it here, but you haven't said anything/enough to convince me that's the case e.g. what port and why etc?

Posted

Sorry, this was me having a rant but is nothing to do with the lgfl2 content of this thread so I shouldn't have posted it. It's been one of those days!

FYI from this particular site (nothing to do with lgfl), all recursive dns requests from clients are blocked, submission/587 - No chance, IMAP won't work due to DNS being blocked and IMAP closed off at the firewall in any case. The requested port was for some offsite backup software to obtain a license from a central server.

 

Anyway, apologies for the slight thread hijack. Back on track!

Posted

Reading this thread makes me feel uncomfortable on my chair. We are migrating to LFfL2.0 over the summer, or at least this is what I hope (the provisional deadline keeps on moving) and though I knew about the ports blocking didn’t know they were that strict.

I assume that the link for SLG will be operational under LGfL2.0, and that parents will be able to access our data, right???

Posted

Well I've uploaded my mips request, first one was refused, after some backwards and forward support conversations, via the LGFL support site. I uploaded a new MIPS request.

 

I have it in writing here now, that I can have inbound traffic to port 80 and 443 to multiple servers, i.e. email, vle, library etc.

 

I can have IMAP/s and POP3/s ports open for my email server, and they will relay email to my mailserver.

 

As usual it seems to be a case of getting the first line monkeys to actually talk to the people that know how the network is going to work rather than deailing with canned responses.

 

Outbound traffic who knows what they will block, but I gotta assume most outbound traffic will be fine.

  • 4 weeks later...
Posted

Thought I'd update the thread and let you all know that we're terminating our LGfL2.0 connection as of this summer. We want to be able to do things that are currently against some of LGfL's security policies, and unfortunately due to some communication issues with LGfL just don't feel it's the service for us.

 

To be fair the service hasn't been bad, and Atomwide are fine once you know how things work but we needed greater flexibility without the level of filtering that is currently applied.

Posted
How did you manage this without having to pay £xx000? We don't have the service installed and are still been unable to cancel our contract?
  • Thanks 1
Posted
How did you manage this without having to pay £xx000? We don't have the service installed and are still been unable to cancel our contract?

 

I've dropped you a PM explaining. Unfortunately I doubt any other schools will be able to use the route we took :(

Posted

A quick update:

 

School A: Waited three weeks after the system was supposedly 'live' to get a functional connection. I'm not talking about filtering or firewalling, I'm talking about any form of connection to the Internet. I lost count of the number of times I called Atomwide, and the number of promised call-backs that never materialised. I was completely ignored by the contact at Virgin Media.

Two changes were required to the configuration of the Virgin router. I raised the ticket requesting the first of these on 29th March. It took over 3 weeks to carry out. I have no idea why it should have taken so long. School 'A' now has a working connection but are now starting the fun process of getting their email and other services unblocked.

 

School B: Connection was installed 11 April. Onsite head of IT logged a call a few days later over the Easter break regarding services that no longer worked. The school rely on: Filemaker, email (IMAP & SMTP) and an offsite backup service (CrashPlan). The helpdesk keep coming back saying that the changes have been made but they haven't. The ports are still well and truly blocked. This is all outbound not inbound. The school's nominated contact asked the person on the support desk if she could pass the phone over to me and that she was giving me authorisation to talk to them about the problems. They refused so instead we put the phone on speakerphone, I told the head of IT what to ask them and she relayed it to the helpdesk. They could obviously hear what I was originally saying. It's absolutely insane.

  • Thanks 1
Posted

And now for something positive :)

I thought it might be useful to list a few common OUTBOUND ports that most schools rely on. Perhaps others could contribute to this list?

The format is source, destination, protocol, description:

 

[table=width: 500, class: grid]

[tr]

[td]Source IP(s)[/td]

[td]Destination IP(s)[/td]

[td]Port(s)[/td]

[td]Protocol (TCP/UDP/Both)[/td]

[td]Description[/td]

[/tr]

[tr]

[td]Any[/td]

[td]Any[/td]

[td] 2195, 2196, 5223[/td]

[td]TCP[/td]

[td]Apple Push Notification (iMessage, app updates, app notifications, etc)[/td]

[/tr]

[tr]

[td]Any[/td]

[td]Any[/td]

[td]25, 110, 143, 587, 993[/td]

[td]TCP[/td]

[td]Email access via email client e.g Outlook, Apple Mail, Android, iPhone etc[/td]

[/tr]

[tr]

[td][/td]

[td][/td]

[td][/td]

[td][/td]

[td][/td]

[/tr]

[/table]

 

 

Other things to think about: Offsite backup, other apps that don't use ports 80 or 443 such as video conferencing, databases etc.

  • Thanks 1
Posted
Let me get this straight.... they're blocking OUTBOUND connections??!?

 

Yes, but will unblock if requested and if it doesn't conflict with their security guidance.

Posted
Yes, but will unblock if requested and if it doesn't conflict with their security guidance.

 

What annoys me is that this policy wasn't mentioned to schools in the technical literature that went out before the schools signed the contract. I'm sure most people would have presumed the firewalling policies would have been the same or very similar to Synetrix's.

They do seem to be unblocking ports as requested but are reluctant to do so when the destination is listed as 'any' rather than to a specific IP address. In most cases limiting access to a range of addresses just isn't viable. Most large scale stuff is delivered via content delivery networks that are forever adding servers in different geographic locations as and when the load changes. For example, It's all well and good to unblock all of 17.0.0.0/8 (Apple) but when Apple use Akamai's CDN then what do you do?

Same goes for many offsite backup providers. Host names are often round robin'd and are subject to change. I hope they relax this policy as it's causing some pain at the mo.

 

Soulfish, do you happen to know or have in writing what their 'security guidance' is? Otherwise it's fairly ambiguous.

  • Thanks 1
Posted
What annoys me is that this policy wasn't mentioned to schools in the technical literature that went out before the schools signed the contract. I'm sure most people would have presumed the firewalling policies would have been the same or very similar to Synetrix's.

 

EXACTLY!! They hoodwinked us into a long contract we cant get out of and that irks me even more than their rediculously impractical policies.

Posted
EXACTLY!! They hoodwinked us into a long contract we cant get out of and that irks me even more than their rediculously impractical policies.

 

Claim false advertising... or misleading advertising.

 

That should help you get out of a contract... Or get them to change it to what it was supposed to be.

Posted
What annoys me is that this policy wasn't mentioned to schools in the technical literature that went out before the schools signed the contract. I'm sure most people would have presumed the firewalling policies would have been the same or very similar to Synetrix's.

 

Too true, and something I feel very strongly about. If this was me personally (say taking out a mobile phone contract), I would have no hesitation in pulling out immediately. I feel tricked, because as you say; these restrictions were never mentioned in the sign up documents. It was only after signing up to a lengthy contract, that we were told.

 

Both the head and myself at my school are of the view point that if we experience any negative issues with the new connection other than minor teething issues as to be expected, that have any impact on the current levels of support that the school receives, we will be passing the cost on to LGFL. If they are unprepared to reimburse, we will be only to happy to deduct it from our yearly payments for the service.

 

I have read some quite worrying horror stories on this forum so I am not looking forward to the day when we are switched across in any way.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...