Jump to content

ahuxham

Members
  • Posts

    1,139
  • Joined

  • Last visited

Everything posted by ahuxham

  1. Hi Pete, Reverse proxy sure, but not into an internal server. Clients connect to 192.168.0.xx on port 3128 which in turn I want to redirect into Dansguardian, which in turn goes back out to the internet. I'm pretty competent with google, and iptables and routing etc, but this has me stumped, too many variables in the mix, iptable, dansguardian, squid conf files. Any help would be greatly appreciated
  2. Hi All, Came in this morning, to a non working mail system, restart the services, half wouldn't go, giving error messages, rebooted the server hoping some configuration needed to take place, got an error message and a "service failed to start" checked event log error code 0x80040154 which Technet relates to a missing SMTP service. Alas following technet i re-installed SMTP, (how the hell does it just fall off the face of the planet) and the services restarted. Everything is now running regards services, however nothing is being sent or delivered, I send a test mail, and it just sits in drafts, no error messages or the likes. Now, I assume this is related to IIS, both default website, and our external website, as we cant seem to start either at the same time. Internal uses TCP80 SSL443 (dont use SSL) External uses TCP80 SSL443 (enforce SSL) Only one will start at a time, due to common ports, however changing the ports starts both websites. Sending externally into school I get a "Unable to relay 550 5.7.7.1 error message" Anyone have any ideas as to why nothing is delivering or sending?
  3. Round 2: After finally getting dansguardian to process urls and activate, ive now stumbled into another fiasco, it disabling all internet when I had the iptables rule. dansguardian.conf Network Settings: filterip = 127.0.0.1 # ?? filterport = 8080 #DG Port proxyip = 127.0.0.1 #Squid Loopback proxyport = 3128 #Squid Port Now that means that it listens on 8080, accepts URL and than tells Squid to deal with the query. I thought using the following iptables command, I could force all incoming 3128 traffic onto port 8080 where DG would do its thing, and than re-route through localhost(Squid) and back out. Is there maybe an infinite loopback occuring here? Squid is set to allow locahost iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 3128 -j REDIRECT --to-port 8080
  4. Few errors and messing around. '' Error binding ipc server file '' So I removed the /tmp/.dansguardianipc folder, than '' Error binding something else " so i removed everything in /tmp/.* and dansguardian is now start, however only with the removal of anything in bannedsitelist Just about to unhash a file and see if it restarts. Likely cause being dodgy tmp files? EDIT: Unhashing is now processing urls. Must have been related to not being able to lock the ipc and lipc files in /tmp/
  5. Pete, Followed you advice, and couldn't find any, so i did a updatedb and searched for .processed and the only reply was /blacklists/porn/domains.processed Is there anyway to find out if Dans Guardian is actually processing the URLS?
  6. Doesn't read them into memory as far as I can tell, as starting the process off, doesn't spike any memory usage.
  7. Existing install, but new implementation of Dansguardian, I did unpack a huge chunk of blacklists, however should it take 30minutes+ reading them all?
  8. Debian Etch. It's rather annoying and frustrating waiting for it too load, if it's ever going to load that is.
  9. Hi All, Anyone care to shed some light on my little problem. Layout: INTERNET (port) > SQUID (8080>3128) > LAN All incoming traffic redirected to 8080 for Dans Guardian, than onto Squid and the lan, via IPtables, however dansguardian will not start, or well its starting At present its been "starting up" for the past 22 minutes just sitting there waiting for the prompt to say its start, chewing 90% processor and a nice chunk of memory. Any ideas why it isn't starting, or isn't giving any error messages saying its not starting?
  10. The only way I'd deem it illegal if it were images of Children under 16, otherwise its dealt with here, either through ICT, and Deputy Head, no need for the police to be contacted.
  11. Head of ICT, who is more senior than NM and IT techs, has access to all this, and you alert the head about this, and she realises that the default £14k a year IT tech can read EVERYTHING.... How is she going to feel about none SMT members having such access.
  12. Polyvision boards are pretty robust, cheap and do the job well. Softwares fault proof as well, and the customer service is second to none. Sanyo CPC/DABS seem to be running some nice deals on the projector front as well.
  13. It can be configured to scan for certain types of hardware in the configuration, it still scans the whole subnet. And you need muchos processor power when its done, and trying to create its mangled spider diagram.
  14. There's no real way to pre-empt this sort of behavior, without spending masses of time finding a solution (ours being Network Access Control). You can only digest logs and than disable offending users accounts. Yourfreedom and Ultrasurf are both anti-censorship, even if it harms children in schools.
  15. DHCP SCOPE [iP] > SCOPE OPTIONS > OPTION 003 (ROUTER)
  16. Nice find!
  17. Could you explain how this is done Mike, one of the downfalls is we feel students arent able to save favourites due to having mandatory profiles. Specific registry key perhaps?
  18. Moved away from tapes personally, and now have 300GB+ worth of backups onto local drives. On the tape front. I'd assume with general knowledge, that larger files limit compression. I 30GB single file database wont compress into much, but you'd get more compression from 30 x 1GB databases. Volume of single (not-easily-compressed) files can thwart the whole process. (To get your files onto those 2 x tapes, it may be advisable to compress the files pre-backing up, which in turn would assure you have adequate space.)
  19. Oh, they are auth'd against AD, ISA ties all its groups and authentication through the DC's. However, "quirck, bug, general annoyance" it doesn't always authenticate properly. I remember an instance a while ago where specific boarders were using "Your Freedom" a paid SSL tunnel to get through ISA, and I still cant figure out why, the only reason they were caught, was the IP address showing massive traffic in logs, upon tracerting, and resolving the IP's we found them to be proxies. How a java based applet running on machine could instantly bypass ISA authentication (required) via SSL is beyond me. And now as per post... another major point is trying to limit traffic through facebook uploads, another point to add, with upcoming VLE implementation, traffic limitation is now a key priorty to providing a quality QOS inside and outside school (If our lease line bid goes through, everythings going to go through a debian squid box, tied into AD, and specific delay_pools setup to limit facebook traffic to around 100kb/s down, 15kb/s up at most. Which would resolve all these issues, but can't guarntee its going to be approved)
  20. You mean my daily ban list? Sure, at present with ISA reporting there are some variables that go a-miss. I.e. "requires authentication" however most of the time through some genius method only an IP address is shown, rather than student. Any chance of usage per NETBIOS name? or associated an account with NB name?
  21. RM 2MB non-lease lined 20/1 contention, our incoming/outgoing email line, after 5p.m. you cannot access mail externally due to the lack of speed on the line. Our Fundraising database also accesses various things out of school on the same line (We are Independent), which in turn slows this down.
  22. Create it all, renamed from .dat to .man for the change. Copy .man onto your machine, load as a hive into your registry, make all registry changes needed, add a few things as well if needed, unload hive, move .man into profile directory, re-map students profile paths. Sorted.
  23. Hi All, Would anyone know how to block uploads on facebook, as of last-night, we've had enough, we're averaging around 4.5GB into facebook a night, due to being a very large independent boarding school. We have a deny access between 8am-4pm, however after its open. I cant seem to get my head around it. RM Safteynet ignores my ban on http://facebook.com/editalbum.php (where photos go in) Any one have any luck doing this on an ISA server?
  24. More along the lines of the URL down the bottom. Not the site name if you care to read correctly, of if you have, phrase your reply correctly.
×
×
  • Create New...