filteringtech
Members-
Posts
93 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by filteringtech
-
tlu.dl.delivery.mp.microsoft.com
filteringtech replied to Sonic007's topic in Internet Related/Filtering/Firewall
Doh! It's the *.microsoft.com that does it. Honestly, I cant see why it would be blocked in the standard setup. -
tlu.dl.delivery.mp.microsoft.com
filteringtech replied to Sonic007's topic in Internet Related/Filtering/Firewall
What seemed odd to me was that when I did a Trace Request, for us the Policy Server showed it was allowed by an "allow" in the Global Shared list, that when I looked in the Global Shared list doesn't exist! Will be interesting to see if that still exists after tonight's maintenance. -
tlu.dl.delivery.mp.microsoft.com
filteringtech replied to Sonic007's topic in Internet Related/Filtering/Firewall
You are Schools Broadband? You have the "standard lists" applied? Decryption? Should go stright throught. Try a Trace Request and a Category lookup. I wonder if you notice the same as me? -
I'm old school too. We're not paid to be Microsoft's beta testers. Once the updates are proven stable, they they go in.
-
Found some odd entries in our Netsweeper logs going through an "admin" proxy from an external IP. Nothing unexplained should be going through through that proxy from an external IP, never mind an attempt to access porn. Reported it to my line manager. The following day realised these changes had been made in Netsweeper around the same time. No phone call, no ticket update, no email and currently still no explanation to provide to our DSL as would be the case for a "genuine" attempt to access a safeguarding category. This was a direct hit, not an accident from a poorly crafted search request. One of the IP addys in the above matched the IP addy in the playboy.com log entries. Still wondering why. If it were a testing activity, we would have expected to be advised prior to the activity, and why try to access porn? Curiously, this doesn't appear in the standard "Safeguarding Report" that SB generate. That's another support ticket I suppose. Would Schools Broadband care to comment?
-
My testing today is showing that if I make a change to a Shared List, eventually it goes through, though this is taking over 30mins which is still rubbish. If I make a change to a Local List, it never updates Policy Server: Policy3, so doesn't take effect. I presume there is more chance of Schools Broadband reading this here than on a ticket.
-
For a problem that we reported in a support ticket on 4th October (that other schools may have reported earlier), and one of your support staff confirmed in the same ticket on 12th October, an event report on the Status Portal was raised on 19th October (stating that the problem started on 18th October). There are no further details provided other than confirming you have involved Netsweeper and no problem owner and that your Netsweeper service has a status of "degraded". For those of us who are on our knees because any Netsweeper changes that we make one day, do not seem to take effect until the next day - disrupting teaching and learning and our legal safeguarding obligations (KCSIE), can we have an update on this "Top Priority" issue please?
-
Twitter under fire over CSAM
filteringtech replied to sigma's topic in Internet Related/Filtering/Firewall
That's horiffic. Must have been difficult to deal with and really upsetting for everyone in school involved. Thanks for sharing. -
There is the Web Proxy category that catches most of them for us. (Web Content/Security/Web Proxy) There are some Google Docs and Google Sites that list hundreds of them. SBB whitelist these domains and I've had to block them individually - even though Netsweeper categroizes correctly them as Web Proxy.
-
Nor do they. We had an issue with a blocked port while trying to upload something to an AWS domain. In order to remedy it, they whitelisted amazon-adsystem.com and primevideo.com
-
Yes, I am very fed up with them telling me its just us! The trouble with Schools Broadband is that they whitelist and bypass decyption in the Global, Master and other shared lists, so the things that would be normally (and properly) blocked by Netsweeper, go sailing straight through. You can see this in the Category Lookup Tool and Trace Request Tool. My support tickets just sit there even though they have been open for months because you can't force category processing from a local list if it's been whitelisted in a shared list, and I am fed up with having to block individual items that Netsweeper categorises correctly. It's not Netsweeper at fault, but a truely crappy and incompetent configuration from Schools Broadband. (Oops I finally said it!) It is a shame, because their Broadband Service we find to be good and reliable. Most over my recent allows and blocks are to try mitigate against it. Happy to share our experience either here or via PM. Wondering if we need an informal user group so that we are not re-inventing the same wheel?
-
Twitter under fire over CSAM
filteringtech replied to sigma's topic in Internet Related/Filtering/Firewall
I got "We take take your requests seriously blah blah....." appended to my Support Ticket on 18th August. Despite it being "prodded" there has been no update to the ticket from Schools Broadband for exactly 2 months, and Twitter images are still whitelisted/unfiltered for all their customers including pupils - unless schools have added a block to twimg.com for pupils. If the whitelisting was removed, Twitter images would be category processed, and if decrypted, the porn and extreme content would have a chance to be blocked. I cannot think that any school would want any of this bypassing filtering in any circumstance. -
Is that their new "in house" front end or raw Nesweeper logs? I've been adding spurious changes just to time them and its getting progressively slower. I had been making changes to enforce safe seach on search engines where there is an enforceable parameter that can't be set in Group Policies, or where there is no enforceable safe search to redirect back to Google since that seems more useful than a block request. Initially, I coudn't figure out why it wasn't working until I made the change one day, and tested it the next once the updates had finally been applied. I think that SBB's lists that they apply to us have so much redundancy and duplication (in some cased, they have 5000+ lines where one will do, if they understood the "referrer header" parameter), that there must be some self-inflicted performance degradation.
