Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. Where are they all going to sit the exam? In the hall/gym like existing? Good luck getting good enough power and WiFi for that! Or in the existing IT suites (assuming you have enough)? Then do you need a lot more exam invigilators and other necessary exam resources per room?
  2. How are your AD accounts provisioned?
  3. Or is there an ACL configured that's only allowing the specific IP addresses to connect to it?
  4. One issue I encountered with a VM based filtering solution in the past, was with regards to non-proxy aware applications and similar, as in things that will follow the network default route, instead of redirecting to the filtering VM. For us, this traffic just went straight out to the Internet unfiltered (which can be an issue if say a browser doesn't get the proxy setting for whatever reason). We switched to an on-site in-line solution, where the traffic had to flow through it regardless to get to the Internet. A cloud solution, as long as you configure it in your network as your next hop would also be an in-line solution.
  5. If you have Microsoft licensing and cost is your biggest factor, Intune will likely come out the cheapest. It's probably not the best, but it does the job for us (though we only have ~200 iPads and we don't make that many changes).
  6. There are last "lastLogon" and "whenChanged" extended attributes that could be queried. Looking at one machine, I can see that "lastLogon" was modified today at 11:36:58, about just over 20 minutes before posting this. However, I don't know how I'd actually query this in PowerShell and get a useful result.
  7. I don't understand why this is such a sticking point. Exam boards are within their rights to say that generative AI sites are blocked during exams, which would also apply to online exams where the Internet cannot be disabled but definately restricted. They can also suggest that students should not have access to generative AI sites whilst in school or on school devices and I fully expect that to come down as DfE guidance in the future. We can block Internet access entirely, but unless you're operating a specific allow list only filtering system, there will always be sites that fall through the cracks. You can't tell me that students in your environment haven't accessed material that they shouldn't whilst in school because the filter didn't block it. We have to operate within the guidance as best we can and with the resources/services we have access to.
  8. Or a filtering solution that categorises websites/URLs and blocks those categories.
  9. We've bought our wildcard SSL certificate from GoDaddy for many years now and they've auto-renewed two months early, at well over double the rate and charged the school credit card that was stored on the account (and actually overdrawn it causing other issues). This has got us thinking; do we actually need an SSL certificate anymore? We used the *.school.bham.sch.uk certificate for the following services according to our documentation and internal knowledge: RDS - Now retired Microsoft Always-On VPN - Now Retired Home Access Plus - Now retired from external access - access is only internal only for the booking system Our remote access method now is Sophos IPSec VPN, which doesn't use our school wildcard SSL certificate (as far as I am aware). I don't think we use the SSL certificate for anything else. As I wrote the above, I realised that our internal Home Access access would start showing no/invalid certificate warnings when a user attempts to access either https://hap.school.bham.sch.uk or https://hap.school.local. Can I use our internal CA to generate trusted SSL certificates for internal websites?
  10. If there's one thing we've all learned working in education, you cannot rely on an exam board staying ontop of technology and/or it's terminology. Not only are exams the last time in your life you won't have internet access, they're also the last time in your life you won't have AI. At an absolute basic level, yes. However you're requiring the student to study, retain and recall the information. Using AI or essay writers means they aren't doing that and therefore not actually learning. They must it must be blocked during an actual assessment and I wouldn't rule out it becoming a block dictated by the DfE, unless there are specific courses designed around it.
  11. I also wouldn't accept it, it's not what you ordered. There is a value difference between brand new and recertified and I presume they didn't send you the price difference back along with the recertified drive.
  12. Oh ok, so aside from devices used to sit exams (for access arrangements, Peason POP, etc), it's more of a recommendation to block. But as an insitution, we have to be vigilant about malpractice in work that is submitted, like old essay writing services, etc. If you're allowing students to install and use offline tools on school systems, I suspect there might also be other things you'd need to worry about.
  13. Nothing, we have no remit over their personal devices. However, we have to ensure we have systems in place to prevent them (as much as possible) from accessing things they shouldn't when they are under our supervision or using devices that we provide, and this is something that the exam boards deem as an area to block.
  14. I'm not sure that's necessarily relevant, the exam boards want these sites blocked to prevent cheating and it's our job to implement that. We all know that regardless of which filtering service is used, it's always possible to find harmful content. Does that mean we shouldn't bother at all? No, that's why we have other behaviour procedures in place.
  15. Thanks for your reply. We are running firmware 19.0.2. The XG displays 19.5 as available and set to automatically upgrade, though it hasn't, so I wonder if updates are being witheld by our supplier via Sophos Central. We're not seeing any other high usage on the device, including Internet activity, so it doesn't appear to be network/Internet related from that respect. The only correlation we are seeing is that when it happens, we have the most amount of users connected at about 250...which should be well within the XG's capability as far as I can tell. I'm not willing to test that yet with user's on-site and especially with OFSTED in!
  16. We are experiencing spikes of 100% CPU usage on our Sophos XG 330 at certain points of the day. It usually happens around 2pm, but not limited to that. We cannot see what is causing the high CPU, as none of the other diagnosit charts are spiking (like throughput charts would if it was an ICMP DDoS attack or something, like we've had/seen in the past). Our supplier is investigating the issue, but it's been ongoing for a while and we have OFSTED in today and tomorrow, which has prompted me to post the issue on here! I've had a DM from a user on here relating to a post I made in another thread, suffered a similar issue and understood it to be a known issue that Sophos are investigating and it might be relating to the time settings needing to be set as UTC rather than GMT. Though they have a UTM device which is not the same product as ours, so it may not be a related issue. If anyone else has the Sophos XG330, have you been experiencing this sort of issue?
  17. I couldn't demist my car this morning, even with the blowers on full and windows down a crack. It was raining quite a bit, so I couldn't open the windows more without getting drenched. I had to pull over a couple of times as visibility was getting bad!
  18. It came from our computing teacher and I believe it was from JCQ. They see a risk of students using ChatGPT et al to generate coursework.
  19. We had instructions from an exam board a few month ago to block access to specific AI/ML sites due to cheating concerns and ChatGPT was obviously one of those. It's a best effort job anyway, we can only control access on school owned devices, not their personal devices.
  20. We have a FTTP line from a supplier using Virgin's network and another FTTP line from a supplier using OpenReach's network, that way we aren't limited to an an area issue with a single ISP. The main issue that we're experiencing at the moment is 100% CPU on our Sophos XG, which knocks out all Internet traffic, including MIS (Bromcom), telephony (3CX), etc. It looks like a DDoS attack, but we aren't seeing the interfaces being flooded, only the CPU. Our supplier is investigating the issue, but as of yet, no resolution. One possible solution would be an additional unit in failover or loadbalancing mode, but who's to say that wouldn't also suffer the same issue or also be overwhelmed? There's always going to be a point of failure and it can cost an absolute fortune to mitigate, so it's a case of doing the best we can with what we have/can afford.
  21. Presumably agents means helpdesk users/technicians/etc, rather than end users submitting tickets/interacting?
  22. I've set it to run every day and delete items older than one day. That user is definitely in today and is logged into multiple computers. I could just manually delete all the items myself, but I'd like to get the automated process working if possible!
  23. I'm finding that the $RECYCLE.BIN folder in our user's home folders are not being emptied by storage sense. I have specified the seting to be 1 day, just to clear everything out and then I'd set it as 30 days, but I can see one user's $RECYCLE.BIN is still 34GB with some files last modified in 2016.
  24. For anyone wondering, you can use ProcMon and filter for MsMpEng.exe, which will show you in real-time what it's accessing. It's also confirmed what I suspected - the scan is taking at least several days, impacting server performance. I will have to consider changing how our scans are scheduled. Currently, it's a weekly scan with on-access scanning enabled...should that be changed to monthly with on-access enabled?
  25. Are you accounting for a failover scenario, such as a host failure? Would you have enough physical CPU resources on one host to run all your VMs if necessary?
×
×
  • Create New...