Jump to content

Recommended Posts

Posted

We have been using Teamviewer as our remote support tool on LGFL 2.0 since April, but suddently last Thursday it all stopped working and comes up with " Not ready. Please check your connection."

Nothing has changed on our Network so I am wondering if Atomwide has finally decided to block this..

 

Is any other LGFL school experiencing this?

Posted
We have been using Teamviewer as our remote support tool on LGFL 2.0 since April, but suddently last Thursday it all stopped working and comes up with " Not ready. Please check your connection."

Nothing has changed on our Network so I am wondering if Atomwide has finally decided to block this..

 

Is any other LGFL school experiencing this?

 

Yep, im surprised it let you go this long! details are here: http://files.lgfl.net/LGfL/Policies/LGfL%20Security%20Guidance%20-%20March%202012.pdf

 

If it's not RAV3 or CentraStage then tough appears to be the LGfL stance.

Posted

I would not be surprised as LGFL/Atomwide's official stance is - all remote tools except RAV3 and CentraStage are blocked and unavailable.

 

Apparently they are working with LogMeIn to try and get it using the USO system but that is the only 3rd party discussions I know of.

Posted

Not sure that that is actually the case …. Looks like what’s actually happened here is that a number of security holes have been closed down one side effect being that TeamViewer has stopped working.

 

However section 8 in

 

http://files.lgfl.net/LGfL/Policies/LGfL%20Security%20Guidance%20-%20March%202012.pdf

 

talks about getting category 2 web filtering enabled which lets an un-specified selection of remote access products work including TeamViewer or so I’m told

 

So getting this going again appears to be get your head to sign the school up to Cat 2 and get hold of a couple or three OTP tags – once your head has agreed then the extra category appears in the web filter system on the support site and your away.

 

I imagine they (LGfL/Atomwide) will be having a hard time keeping track of changing technology and the work that’s ment to be happening with LogMeIn may well have uncovered the ‘features’ that have been resolved - so if you’re using some form of remote access that looks like they might object to it for some reason then being signed up to the cat 2 filter sounds like a plan.

Posted

Hi All

 

A quick update on where we are.

 

We've been running LGfL2 Option 2 since the beginning of September with no issues. Remote support and mail hosting are working fine, and our new Palo Alto firewall is the dog's doodahs!

 

Attached should be the latest powerpoint from LGfL giving a very rough overview of the service.

 

Happy to answer any questions.

 

Shaun

Option2LGfL20121011.pdf

  • Thanks 1
Posted

Hi David

 

I understand their stance. They don't want everyone signing up for option 2 without understanding the risks. Not all schools have the technical capability to implement this in-house, and there's a huge risk to outsourcing your edge security.

 

Option 2 works brilliantly. But I would never have seriously considered it an option without a enterprise class next-gen firewall or the ability to manage it myself.

 

Shaun

Posted
One thing to consider when you take up Option 2: there are ten internet trunks into Option 2 and your connection will be on one of them. This essentially means that you have a 10% chance of being taken out by a dDOS of an Option 2 site. dDOS used to be a significant problem for LGfL 1 - have you considered this risk for your site?
Posted
One thing to consider when you take up Option 2: there are ten internet trunks into Option 2 and your connection will be on one of them. This essentially means that you have a 10% chance of being taken out by a dDOS of an Option 2 site. dDOS used to be a significant problem for LGfL 1 - have you considered this risk for your site?

 

If they bothered to implement a BGP AS that the schools could peer to then this should be mitigated.

Posted
Hi All

 

A quick update on where we are.

 

We've been running LGfL2 Option 2 since the beginning of September with no issues. Remote support and mail hosting are working fine, and our new Palo Alto firewall is the dog's doodahs!

 

Attached should be the latest powerpoint from LGfL giving a very rough overview of the service.

 

Happy to answer any questions.

 

Shaun

 

Got to agree about the PA firewalls. We got a PA-4020 in the summer for our new 1gb connection (we moved away from LGfL) and it's absolutely brilliant :).

 

SSL VPN could be a bit better, but the firewall side is absolutely amazing :D

Posted

Hi Eric

 

Yes - We understand the risks, which again is why decent next-gen firewalling is essential for all sites considering Option 2.

 

Have you considered that LGfL 2 Option 1 is a far more attractive target for a DDoS attack, and that Atomwide's plan to just turn off connections and wait for the attack to stop isn't really ideal in the event of a large, coordinated attack?

 

Only time will tell. I know we shouldn't really compare LGfL2 with LGfL1, but how much of the LGfL1 Option 1 downtime was due to internal/external attacks, and how much was due to reactive last-minute global policy changes which were not published until after implementation and broke something important?

 

Shaun

Posted
Got to agree about the PA firewalls. We got a PA-4020 in the summer for our new 1gb connection (we moved away from LGfL) and it's absolutely brilliant :).

 

SSL VPN could be a bit better, but the firewall side is absolutely amazing :D

 

You pretty much sold me on Palo before I'd even tried the kit. Everything else we demoed either had Palo's features "coming soon" or were cloud based because the box couldn't handle it.

 

I'm also loving SSL decrypt - That more than doubled the amount of dropped traffic from our student's BYOD vlan :)

Posted

Shaun,

 

Another couple of questions....

 

1) Other than the cost of the firewall, is there any other costs associated with moving to Option 2?

 

2) Do you (and can you) still use the LGfL assigned IP range?

 

Cheers

 

Adam.

Posted
Shaun,

 

Another couple of questions....

 

1) Other than the cost of the firewall, is there any other costs associated with moving to Option 2?

 

2) Do you (and can you) still use the LGfL assigned IP range?

 

Cheers

 

Adam.

 

Hi Adam

 

The main cost is time - The next gen firewalls do so much more that you will be looking at a few weeks to get everything up and running. With the Palo, there's also annual support and software subscriptions which cost a fair bit.

 

Do you mean the internal or external IP ranges? Internally, you can use whatever you want. Externally, you'll get a new range of IP's, and and MIPs you have setup will be removed, so you will need to make DNS changes for anything you're hosting. Atomwide reduced our TTL, so we had all of 5 minutes downtime for the DNS changeover.

 

Shaun

Posted

Yes - We understand the risks, which again is why decent next-gen firewalling is essential for all sites considering Option 2.

 

Doesn't protect you against dDOS, though.

 

Have you considered that LGfL 2 Option 1 is a far more attractive target for a DDoS attack, and that Atomwide's plan to just turn off connections and wait for the attack to stop isn't really ideal in the event of a large, coordinated attack?

 

Only time will tell. I know we shouldn't really compare LGfL2 with LGfL1, but how much of the LGfL1 Option 1 downtime was due to internal/external attacks, and how much was due to reactive last-minute global policy changes which were not published until after implementation and broke something important?

Shaun

I agree, we don't really know what caused LGfL1's downtime. It didn't need to be coordinated dDOS, though: it could easily happen as a result of an attack on a particular IP in a school. The continuing risk with Option 2 is that an attack like that will still take you down.

 

As you say, time will tell.

Posted

Wow this is the first time I'd heard of option 2 on LGFL 2.0 were they hiding it ?

 

Just gone over to LGFL2.0 and it's been a complete nightmare since last wednesday.

 

And not being allowed to request a MIPS for ANY/ANY over port 22/ssh but allowing ANY/ANY over port 21/FTP, is a complete joke and a shambles.

 

They also seem to expect every computer in the organisation to have a staticly assigned IP address, I mean haven't they heard of DHCP.

Posted
Wow this is the first time I'd heard of option 2 on LGFL 2.0 were they hiding it ?

 

Just gone over to LGFL2.0 and it's been a complete nightmare since last wednesday.

 

And not being allowed to request a MIPS for ANY/ANY over port 22/ssh but allowing ANY/ANY over port 21/FTP, is a complete joke and a shambles.

 

They also seem to expect every computer in the organisation to have a staticly assigned IP address, I mean haven't they heard of DHCP.

 

I can see why they would not allow an any/any for SSH - The majority of naughty traffic now runs over SSH to avoid detection and processing by last-gen firewalls and content filters. It's the kind of traffic that has to be controlled.

 

I assume that you're running your own firewalls inside the LGfL2 firewall to handle the SSH traffic, and the any/any rule was just to allow you to add additional firewall interfaces in the future? If so, just add some unused addresses to the MIP, and they'll be ready when you need them.

 

Not sure about the static IP issue - What were you trying to setup?

Posted
Wow this is the first time I'd heard of option 2 on LGFL 2.0 were they hiding it ?

 

Just gone over to LGFL2.0 and it's been a complete nightmare since last wednesday.

 

And not being allowed to request a MIPS for ANY/ANY over port 22/ssh but allowing ANY/ANY over port 21/FTP, is a complete joke and a shambles.

 

They also seem to expect every computer in the organisation to have a staticly assigned IP address, I mean haven't they heard of DHCP.

 

I agree letting 21/ftp in but not 22/ssh is a bit of an odd one – personally I’d not do either but run them both down RAV3 so it’s ALL authenticated.

 

I don’t see how DHCP fit’s into this as you can have an ‘any’ inside the network – it’s the any side on the Internet that they will not let you do.

 

Just run up RAV3 and run the whole lot down that – what’s wrong with that ?

 

Or failing that just do the OPT2 bit with LGfL and look after your own security.

Posted
By the time the dDOS traffic reaches your firewall it has filled up the pipe (your "last mile" if you like.) It doesn't matter how much bad inbound traffic Palo Alto drops for you: your usable downlink bandwidth is hosed. This is why your referenced page says:

 

... its [sic] very important to acknowledge that DDoS protection must begin before traffic ever reaches your network. ISPs are increasingly important partners in the fight against dDoS, and they have the ability to keep some DDoS traffic from reaching the intended target.
and this is why I said, "Doesn't protect you against dDOS ..."

 

Effective dDOS mitigation has to be done at the edges of an ISP with an inbound capacity which dwarfs the traffic which the DOS perpetrators can achieve. This means that your ISPs inbound capacity is still sufficient to supply you, and all the rest of its customers, after dDOS traffic has been removed. I believe that some dDOS attacks are now generating such large amounts of traffic that finding an ISP that can cope (and is willing to try) must be getting harder.

Posted
I agree letting 21/ftp in but not 22/ssh is a bit of an odd one – personally I’d not do either but run them both down RAV3 so it’s ALL authenticated.

 

It's not IN, it's OUT traffic.

 

I can't ssh OUTbound on my network unless I set up the ip address it's going to.

 

But apparently I am allowed to ftp out, from ANY/ANY.

 

Lets assume my workstations addresses are all DHCP configured, and that I could be logging into any PC on my network, or hell I could be a student.

 

So lets say I want to deploy some software to my webserver, or teach the kids good practice by using SCP or SSH to get to a remote server, or I want to update a git branch.

 

I have to complete a MIPS request, for every site I connect to.

 

I don’t see how DHCP fit’s into this as you can have an ‘any’ inside the network – it’s the any side on the Internet that they will not let you do.

 

So you can have

ANY<>1

1<>1

1 <> ANY ?

ANY<>ANY ?

 

Just run up RAV3 and run the whole lot down that – what’s wrong with that ?

 

RAV3 being incoming, that I understand

 

Or failing that just do the OPT2 bit with LGfL and look after your own security.

 

How about if they just got a clue.

 

We came from an option 2 on LGFL 1.0 but was told there was no option 2 on LGFL 2.0, I only just found out about option 2 a couple of days ago.

 

So not really any time to get a firewall ordered and installed(although I could have just used my IPCOP install that has been running fine) , let alone find a budget for it.

Posted
It's not IN, it's OUT traffic.

 

I can't ssh OUTbound on my network unless I set up the ip address it's going to.

 

But apparently I am allowed to ftp out, from ANY/ANY.

I'm having the same problem, we have some software we wrote sitting on all of our schools SIMS servers that send via SFTP back to us some reports twice a day to feed into our parent portal. Schools that have gone over to LGFL2 no longer can connect to us even though the rest of the world can. We have two more schools to migrate and then apparently we can have static routes set up to our receiving server, until then we have to run up RAV3 to each of the schools that has migrated and pull the data!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...