Jump to content

ChetterHummin

Members
  • Posts

    13
  • Joined

  • Last visited

Everything posted by ChetterHummin

  1. I'm thinking it may be power-related. The fact there isn't anything in the logs indicates the AP didn't completely lose power, but the loss of signal at certain times indicates it was enough of a power restriction that the AP radio was temporarily powered down. I doubt the PoE switch itself is being overloaded as you would see something in the log for that- possibly the power delivery port on it is faulty instead? Otherwise you could try using a PoE injector brick with the problem APs and see if the problem goes away. Another question- is it always the same APs having the problem, or does it seem to be all of them? If its just a few and you can narrow it down to a single PoE switch they all share, that would be a suspect.
  2. This is quite a common issue, if you have another public IP you can use as the egress for the school, you will likely find it goes away. There doesn't seem to be any rhyme or reason to why the recaptchas get triggered, just that it happens more often when there are lots of search requests coming from a single public IP (which schools can't do much about). Edit: I see you've tried load balancing. It might be worth just assigning a single alternative public IP instead to see if that makes any difference.
  3. At that point, the next step is completely exempt the source IP of the client (temporarily) so you know no filtering is being applied at all for the test. If you still get the issue even then, it could be something doesn't like the public IP of that particular internet line.
  4. I also have a GL.Inet portable router, they do one called the 'Mango' which is super cheap (around a third the price of that Unifi one). It only does 2.4GHz WiFi and of course no UniFi Teleport, but it supports the standard VPN types (Wireguard, OpenVPN). Its helped me out in some pinches and is so low power you can run it off a standard USB port.
  5. FortiGates are stronger performers for pure firewall features, such as timed policies. Smoothwalls can have timed web filter policies, but not actual firewall policies. Unless you have specific circumstances though, the Smoothwall firewall features should do all that you need. What you want to consider is are you happy with the reporting, ease of navigating/amending the filtering, how well the system performs under typical load...
  6. My own take on this: - Whether the S6 (edit: I don't think the S6 exists so guessing that is a typo? Possibly you mean the S5) is good enough depends on how many users are at the school. Different models are built for different capacity. They will all provide the necessary filtering though. - RE managed service infrastructure single point of failure: this is only an issue if the datacentre itself isn't built with redundancy in mind. They can have multiple network links to the datacentre and multiple physical hosts for example. - Cloud based filter effectiveness depends on whether you own the devices it is deployed on. If you own the devices, you can go to town with InTune/group policy to make up for any shortcomings of the cloud filter software. If you don't own the devices, ultimately you can only do so much. - From my own experience, moving from JANET to a direct access line many years ago didn't make any difference with cyber attacks. It did expose some bad server configuration that had been masked by the old setup though... JANET would definitely help protect against DDoS. I can't see many schools being targeted by any serious DDoS attack though, since it is costly to run them and most of those bad actors are motivated by money. There are more tempting targets for them...
  7. Something that might be related:
  8. To give more context: If inbound calls are fine, we know its not just an issue with the line. Otherwise any call going over it would have the same issue, whether inbound or out. Outbound calls will follow the codec priority list of your own VoIP system, whereas inbound calls will have the remote side's codec priorities. Internal calls would be fine since they wouldn't go over the Internet line. In other words, a particular codec likely isn't performing well over that Sky line for some reason.
  9. I've done some VoIP in my time and my hunch here is the codec the outbound calls are being negotiated in is causing the issue. There are different codecs a VoIP system can negotiate to use- they are usually set at the config level. See if your VoIP provider can set a different codec to be preferred/higher up the priority list. See below an example:
  10. When you say unusable on the Sky line, is it a case of very poor call quality or are the phones failing to connect at all over it?
  11. Have some more information. The schools are going through Netsweeper for filtering- have spoken to our provider and sounds like Cloudflare isn't playing nice with the deep inspection. They've managed to get a workaround in place for this and escalated their end.
  12. Wondering if anyone else is seeing issues with websites such as asda.com and currys.co.uk this week? Having reports of these websites blocking staff and it seems related to Cloudflare. I am assuming it is due to the fact the schools all share a public IP address. Have tried reaching out to the website owners individually but as you can imagine, Asda support isn't geared towards website administration...
  13. I'm really curious how this is going to play out in the long run. I have seen a few other threads on here of this issue: It seems like Google will only listen/respond if the affected company is a big player (like Securly, which is big in the US). If its an individual school or smaller provider they have to wait for the blacklist entry to expire (around a week or two from what I've seen so far). I've noticed that even when someone does sign in with a Google account to get around this issue, Youtube videos embedded in other sites (Google slides for example) are still broken.
×
×
  • Create New...