SchoolsBroadband
Sponsor-
Posts
1,450 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by SchoolsBroadband
-
Monitoring search engine usage
SchoolsBroadband replied to Julian1's topic in Internet Related/Filtering/Firewall
All decent filters should do this. Lightspeed does so long as you do ssl decryption. Dave -
I recall something similar to this a long time ago when I used to be an engineer. For some reason spanning tree comes to mind.... maybe something to do with bpdu in particular. Is the device on the other end of the patch panel a switch or a router? Dave
-
@sigma it's ultimately up to you if you wish to block or allow access to DDoS information. Our partnership with the NCA has so far been successful on a number of fronts which ultimately helps to protect schools against unwarranted attacks and also educates children on what's against the law. There is a lot going on the background with various government departments trying to work together regarding security for schools whereas in the past it's been a bit disjointed. As we're larger than most and an ISP with our own network, we've first-hand experience of this and work with a number of agencies to protect schools and children when online. Dave Dave
-
is the switch plugged into the carriers NTU or are you plugging the switch into the ISPs router which in turn is then connected to the carriers NTU?
-
Phishing phone call spoofing local numbers
SchoolsBroadband replied to Ditto's topic in General Chat
not to my knowledge no... -
Phishing phone call spoofing local numbers
SchoolsBroadband replied to Ditto's topic in General Chat
It's incredibly easy to spoof your number via some SIP trunk providers. Yes its against the law to do so and the carriers should ensure that any customer has signed an agreement saying they won't do it but fraudulent companies sign up, spoof loads of calls then don't pay their bills and do a runner. Dave -
When you start turning all the fancy deep scanning, IPS and other fancy processor intensive on lots or all traffic streams then any hardware vendor can start to have issues. Perhaps look to put the IPS on only certain traffic destinations you don't trust. I can't speak for Sophos but Fortinet give you what in theory the max throughput can do with a single "thing" e.g. SSL decryption can do and they also give you a typical setup and what the likely throughput will be with most things deployed but not for all traffic. This gives a decent indication of what a box can actually do. Sometimes though firmwares have bugs in them so also look at the firmware release notes and release notes of newer firmwares to see if any bug is fixed that could be the issue you're seeing. Are you able to see on a per policy basis which policy is using up all your CPU / memory? Again Fortinet can do this but I'm not sure about Sophos. This will help you to diagnose where the issue may be. Dave
-
Have you checked your sync speeds to see if it's a local BT problem rather than an ISP problem? if its sync speeds then a fault should be raised with Openreach and they can try a line reset. If its the path of the wholesale carrier then Exa will need to raise with them (I think they use Zen and Talk Talk but I may be wrong). Dave
-
Leased Line Circuit backup
SchoolsBroadband replied to ITGURU's topic in Internet Related/Filtering/Firewall
Yes we should be able to Matt as we can do our services over any ISP network although ideally we only do this when we peer with them. Do get in touch with Craig and we'll get our new pre-sales man to give you a call but essentially we can tunnel traffic. Thanks Dave -
Leased Line Circuit backup
SchoolsBroadband replied to ITGURU's topic in Internet Related/Filtering/Firewall
Make sure you buy the roaming bolt-on Matt otherwise it might not working when going to different sites. We've used Starlink ourselves and top speeds i've seen have been about 300Mbps download and 50Mbps upload. Its really good from experience. Dave -
Leased Line Circuit backup
SchoolsBroadband replied to ITGURU's topic in Internet Related/Filtering/Firewall
When using our MPSL or VPLS WAN services by default on our network we move all IPs onto the backup connection via BGP. This means that all your firewall rules continue to function as they were on the primary circuit. I'd always recommend using 2 routers to get rid of the possibility of total hardware failure too. We are also starting to see a few customers take SD-WAN with onsite firewalls that doesn't allow the failover of services if you use 2 different ISPs (which is the advantage of SD-WAN). As to what backup connectivity you use, that ultimately depends on your requirements and also what's available to you. We see some secondary schools starting to take resilient leased lines from different carriers. Personally I'd recommend a leased line as a primary connection and an FTTP as a backup (if you can get it) for secondary schools. For primary a leased line or FTTP for primary and FTTC or 5G for backup. If you need any advice do send me a PM. Thanks Dave -
Yep we take L2TP from some mobile providers so can put on real world static IPs and terminate the connection into our hosted FortiGate solution as well. Great for backups to leased lines, particularly when FTTC or ADSL is poor. With unlimited data plans there's a lot to like about 5G, if you can get it of course. Dave
-
Schools Broadband/Fortinet - Any Users?
SchoolsBroadband replied to LeMarchand's topic in Internet Related/Filtering/Firewall
we've already started the ball rolling it out to some MATs and will then go general release for everyone Dave -
Schools Broadband/Fortinet - Any Users?
SchoolsBroadband replied to LeMarchand's topic in Internet Related/Filtering/Firewall
Fortinet when used with FortiAnalyzer or a new reporting engine we are about to release (sits on top of Fortinet or Netsweeper) is very good. @PaddyNewman is right that old versions of the Fortigate interface wasn't the most intuitive in the world for non technical people but the new v7 FortiOS really does add to it and when used in conjunction with our new education focused reporting engine is excellent. Fortinet fully supports remote SSL VPN access and integration with 2-factor authentication for remote access. If you've any questions to do send me a PM or I can get one of our techs to give you a call to discuss. Thanks for considering us. Dave -
Good IT Hardware & service provider ?
SchoolsBroadband replied to JamesParker's topic in General Chat
Hi @JamesParker we look after quite a few schools in Devon already for phones and broadband. Some direct and some via our local partners who have "boots on the ground". We'd be happy to give you a quote or pass you onto one of our local partners? Do send me a DM if interested. Thanks Dave -
Hi @liamrobinson others have made some good suggestions on here. We can also block QUIC at the firewall level but we generally do this by default for all new installs anyway. That doesn't mean that QUIC is the issue though. We have sometimes seen new URLs randomly added from YouTube which Netsweeper has to play catch up on but that's rare. Please do give the team a call on 0 11 33 222 333 and they'll look into it for you. Thanks Dave
-
The reason I'm here is because I was when we were a tiny company. We are now the second largest commercial education focused ISP behind only RM. In my opinion you should never abondon your roots and principles which is to help people if they have an issue. I could just get one or numerous of my employees on here instead of me but i dont ever want to forget our roots from where we came from. My customers are not just a number theyre everything to me and it upsets me when they arent 100% happy. I enjoy speaking and listening to people. It also allows me to hear what people really think and is one of my ways to look through and interrogate the stats I am given regarding our support which I have many of. One thing I have learnt is that unfortunately no matter how much you try some people just don't like what you offer or who you are which is a shame but that's life. It won't though stop me from trying to turn them around and help them as they pay good money to use my service. We have a lot more happy customers than unhappy customers that's for sure. Just the happy ones tend not to be as vocal as the unhappy ones and I appreciate all the PMs and emails I get from my customer saying what a great job we've done and thank you all for those of you that do as you know who you are. Maybe we should have a poll and see if people want me to reply and try help my customers or not or if i should just disappear forever !? Dave P.s before I forget we give you all an escalation matrix in your sla document we give to you during onboarding. If you're not happy with something then you can use this and speak to the relevant person for each department who is there to listen to any issue you have and ensure its resolved. If you have lost it, don't have it or it may have been sent to the wrong person then please let me or the team know and we'll send it through to you again and they'll take ownership. We sometimes find people don't escalate things or vent their frustrations at our management because they don't know the correct channels or ask for them. Sure in an ideal world it should never get to that but it sometimes does unfortunately
-
It sounds like not if he's unhappy with something but caring about our customers comes all the way to the top and all of my staff should be caring for our customers as best we can. If they're not then that's when I or our team makes changes. You can't beat speaking to your customers (hence why I'm quite vocal on here) to get honest feedback whether good or bad. Thanks for everyone's comments good or bad. I'll leave it at that so I don't hijack the thread any more Dave
-
Hi David, I know you're based just up the road from us. You're more than welcome to come and meet the team that support you. In fact I'd be happy to host you and some other schools for some free Fortigate and Netsweeper training sessions that we've also done in the past. I can assure you all firewall, filtering and VoIP support is done in house at our office in Ilkley. Thanks and chat soon. Dave
-
Yes Paul I wanted to say hello to address your concerns as you never answer my pms on here when I try and get in touch to help! Nothing sinister whatsoever.... Dave
-
Morning folks, the issue is now resolved. We have numerous Fortinet WAFs protecting our Netsweeper clusters for all HTTP and HTTPS traffic. Something happened to one ot these. We've done diag dumps and these will be sent off to Fortinet to figure out why the firewall did what it did. The decision was taken to reboot the firewall as normal commands were not having an impact. The Fortigate firewalls have been extremely reliable since we installed them some 7-8 years ago (i can only recall one other issue relating to a software upgrade) so we're very surprised this issue occured. Please watch out for an RFO that will be sent via the hub as usual. Thank you for your patience. Dave
