Jump to content

Recommended Posts

Posted

And lets not get me started on so called SSO.

 

Single sign on to what ? Yes that right it sign on to there resources on the LGFL.

Does it allow sign on to fronter ? No

Does it allow sign on to my network ? No

Does it allow sign on to SIMS ? No

Does it allow sign on to my RDP sessions ? No

 

Or any of my other online resources... No.

 

Why not just call it, ASO. (Another Sign on).

  • Thanks 1
Posted
And lets not get me started on so called SSO.

 

Single sign on to what ? Yes that right it sign on to there resources on the LGFL.

Does it allow sign on to fronter ? No

Does it allow sign on to my network ? No

Does it allow sign on to SIMS ? No

Does it allow sign on to my RDP sessions ? No

 

Or any of my other online resources... No.

 

Why not just call it, ASO. (Another Sign on).

 

Hi - I'm afraid you have this lot completely wrong.

 

Making the assumption your actually talking about USO in LGfL then you can feed USO from your sims system using AutoUpdate, Fronter can sync to USO, USO can sync into an AD locally in the school using Adsync your RDP server can use the local AD to do authentication as can your edge server that presents RDP over https - if you don’t want to run a local https gateway then there is one in the core of LGfL you can use and that’s glued into USO so I'm afraid it's most certainly NOT ASO but really does glue all these things together and makes them work on a single username and password that you can disable in one place and kill everything off.

Posted

to further Nodrog's post: It also isn't billed as 'single sign on' as that implies that you sign in once and it works everywhere. The branding is Unified Sign On. One username and password sync'd to all your systems.

 

And in that context it can do every thing you say it can't. The key to success though is ADSync - since most systems have an LDAP connector, and people always know their Windows username and password. I will say though, it can feel like quite a big step giving up control over the creation of usernames and passwords, and their location in AD. I've managed five AD's in the last 12 years, and ADSync would have fitted neatly into everything except CC4. Certainly though the business case for its adoption was (for us) quite clear.

Posted (edited)

I was about to raise an eyebrow about the ban on SSH... however.... looking at my rules I can see why I can SSH OUT from where ever I want to...

 

Only a very limited number of users (or computers) are likely to have need to SSH to remote sites. These can be specifically enabled via the Firewall Change request form. For us, the set of computers that perform roles that require SSH ->External access is within the set of computers that have static IP (or in the case of my own laptop - a DHCP reservation).

 

Unrestricted SSH is one of those mechanisms that can leak data etc, and provide a back door into your network. By creating a specific rule per requirement, it provides an audit trail, and also an easy way of locking down in the event of a breach etc.

 

Of course this approach is undermind somewhat if FTP->Any is allowed.

Edited by psydii
grammar
Posted
By the time the dDOS traffic reaches your firewall it has filled up the pipe (your "last mile" if you like.) It doesn't matter how much bad inbound traffic Palo Alto drops for you: your usable downlink bandwidth is hosed. This is why your referenced page says:

 

and this is why I said, "Doesn't protect you against dDOS ..."

 

Effective dDOS mitigation has to be done at the edges of an ISP with an inbound capacity which dwarfs the traffic which the DOS perpetrators can achieve. This means that your ISPs inbound capacity is still sufficient to supply you, and all the rest of its customers, after dDOS traffic has been removed. I believe that some dDOS attacks are now generating such large amounts of traffic that finding an ISP that can cope (and is willing to try) must be getting harder.

 

Hi Eric

 

I completely agree. Virgin Business do indeed do DDoS mitigation at their end. Why Atomwide are convinced that they don't is beyond me.

Posted

Of course this approach is undermind somewhat if FTP->Any is allowed.

 

Yep - it's a base policy I believe because people don't really understand it and if they banned it they would have even more people complaining ..... I've had outbound ftp blocked on my schools but it's a bit brutal

  • 4 weeks later...
Posted

The latest and greatest is that this week some of their switches blew and 32 schools across London were left without internet. Nice Infrastructure.

 

I seem to be having an issue with their Outlook Profiles for user downloaded via the staffmail support. Seems to be struggling to authenticate and once they're all set up some users are only getting partial downloads, some are getting it all but everytime they close outlook it loses the password settings. Some sites on 2010 just refuse to authenticate altogether when trying to find the exchange servers, Anyone else getting this? Worked find before the changeover and recent issues...

Posted
I seem to be having an issue with their Outlook Profiles for user downloaded via the staffmail support. Seems to be struggling to authenticate and once they're all set up some users are only getting partial downloads, some are getting it all but everytime they close outlook it loses the password settings. Some sites on 2010 just refuse to authenticate altogether when trying to find the exchange servers...
I have always had problems with users losing part of their Staffmail logon credentials and this is continuing now we are using Office 2010. Specifically some users constantly have to re-insert LGFLMAIL\ in front of their username.

 

It is fairly extraordinary that LGfL support documentation explains how to set up a Staffmail user "by hand," when we are working at the enterprise level. Getting better automation of email account setup is one possible attraction of moving to our own Exchange server, which would significantly diminish the utility of Staffmail.

  • 2 weeks later...
Posted

We are in the same boat and I know a number of schools in Hillingdon are fed up with the restrictions imposed by Atomwide. I was given some info by LGFL that there may be a solution which will only work if you have your own firewall. Luckily we are in that boat but if you only have their firewall.. youre stuffed.

Other than that I was / may look at alternative providers.. BETT is just around the corner so I'll be knocking on a few doors with other ISP's.

  • 10 months later...
Posted
The distribution of illegal images also come under different laws to those dealing with copyright as well. I have asked for specific case law references and when (if) I get them I'll stick them up.

 

Grumbledook,

 

I have stumbled upon this thread again. Do you now have case law references in this area, please? I would be very interested in them.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...