-
Posts
209 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Shaun_Dark_Lord
-
I'd like to not bother, but the Finance department are insistent.
-
Apologies if this is not the right forum, but I couldn't find a more relevant one. We're a year into our managed print project, and are starting to scrap printers as their toner runs out. The fax machine in the main school office does not have much time left, so I need to decide whether to install a fax card in the nearest MFD, or if I can instead go for a fax-email service. Has anyone found a good fax-email service provider? Thanks
-
Senior Network Technician - Part Time - Bexley
Shaun_Dark_Lord posted a topic in Educational IT Jobs
Post Title: Senior Network Technician School: Blackfen School for Girls Location: Sidcup Status: Permanent Hours/Percentage of Week: 25 hours per week Weeks per year: 42 / 52 Grade: £14841.95 Post Start Date: ASAP Closing Date for Applications: 04/01/2013 The school is committed to safeguarding and promoting the welfare of children and expect all staff and volunteers to share this commitment. Offers of employment are subject to a satisfactory enhanced CRB disclosure and other employment checks. The school is committed to equality and diversity in employment practice and service delivery. For further information about the school please visit the school website: http://www.blackfenschoolforgirls.co.uk We are seeking to appoint a part time Senior Network Technician on a permanent basis to join our IT Support team. For further details regarding this vacancy and/or an application pack please contact Shaun Neighbour at [email protected] References will be requested for those short listed ONLY and prior to interview. Only those shortlisted for interview will be contacted. -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi Eric I completely agree. Virgin Business do indeed do DDoS mitigation at their end. Why Atomwide are convinced that they don't is beyond me. -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
I can see why they would not allow an any/any for SSH - The majority of naughty traffic now runs over SSH to avoid detection and processing by last-gen firewalls and content filters. It's the kind of traffic that has to be controlled. I assume that you're running your own firewalls inside the LGfL2 firewall to handle the SSH traffic, and the any/any rule was just to allow you to add additional firewall interfaces in the future? If so, just add some unused addresses to the MIP, and they'll be ready when you need them. Not sure about the static IP issue - What were you trying to setup? -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Getting a Handle on DDoS ‹ Palo Alto Networks BlogPalo Alto Networks Blog -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi Adam The main cost is time - The next gen firewalls do so much more that you will be looking at a few weeks to get everything up and running. With the Palo, there's also annual support and software subscriptions which cost a fair bit. Do you mean the internal or external IP ranges? Internally, you can use whatever you want. Externally, you'll get a new range of IP's, and and MIPs you have setup will be removed, so you will need to make DNS changes for anything you're hosting. Atomwide reduced our TTL, so we had all of 5 minutes downtime for the DNS changeover. Shaun -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
You pretty much sold me on Palo before I'd even tried the kit. Everything else we demoed either had Palo's features "coming soon" or were cloud based because the box couldn't handle it. I'm also loving SSL decrypt - That more than doubled the amount of dropped traffic from our student's BYOD vlan -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi Eric Yes - We understand the risks, which again is why decent next-gen firewalling is essential for all sites considering Option 2. Have you considered that LGfL 2 Option 1 is a far more attractive target for a DDoS attack, and that Atomwide's plan to just turn off connections and wait for the attack to stop isn't really ideal in the event of a large, coordinated attack? Only time will tell. I know we shouldn't really compare LGfL2 with LGfL1, but how much of the LGfL1 Option 1 downtime was due to internal/external attacks, and how much was due to reactive last-minute global policy changes which were not published until after implementation and broke something important? Shaun -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi Adam We went for the 2050, as we're looking to upgrade to 1Gb fairly soonish. Shaun -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi David I understand their stance. They don't want everyone signing up for option 2 without understanding the risks. Not all schools have the technical capability to implement this in-house, and there's a huge risk to outsourcing your edge security. Option 2 works brilliantly. But I would never have seriously considered it an option without a enterprise class next-gen firewall or the ability to manage it myself. Shaun -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi All A quick update on where we are. We've been running LGfL2 Option 2 since the beginning of September with no issues. Remote support and mail hosting are working fine, and our new Palo Alto firewall is the dog's doodahs! Attached should be the latest powerpoint from LGfL giving a very rough overview of the service. Happy to answer any questions. Shaun Option2LGfL20121011.pdf -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
I'm not alowed to give any details, but they are now listening, and I will be allowing an LGfL 2 connection to be installed after next Friday. -
Firewall recommendations
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Thanks Soulfish - I'll have a look at the Palo-Alto -
Firewall recommendations
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi cpjitservices Thanks for your response. We've been running several squid/dansguardian firewalls for over ten years. Even on decent hardware, they can bottleneck our current 100Mb contended connection. We need guaranteed performance, and a proxied content filter just won't deliver. Thanks anyway. -
I'm currently looking at Cisco's 5550, and HP's F1000, but the base models don't really offer too many bells and whistles, and adding on the bells and whistles gets quite expensive. Is anyone else using a "Next Gen" firewall, and if so, what did you get for your money? I'd like IPS, L7 application control, and fast (close to line speed) content filtering if possible, to go with our 200Mb connection (possibly upgrading to 1Gb). Thanks Shaun
-
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Us too. Although i know of one school in Bexley that was let out of the contract with no penalty fees. I suppose a judge would have to decide if this sets some kind of precedent, allowing the rest of us to leave........ -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi jacksonwalsh. In short, we're screwed. There is no flexibility, we can either take it, or pay a huge wad of cash to try and get out of our contracts. You can setup the filtering at a very basic level, and authenticate against an external IP - So you can run everything behind your own firewall. But this does mean the same filtering will apply to all users behind that IP. So either setup multiple firewalls for different types of user, or do your own filtering internally (Which is what we'll do). More worrying still, I've heard from some schools that have converted over that their previously approved MIP requests are now being rejected for "Security Reasons." If you are running any services on site requiring ports to be forwarded, make sure that everything is running before turning off your LGfL1 connection. Our LA have decided to revoke our wayleave, so who knows what happens in a few weeks when the Synetrix contracts end........ -
Free filtering software?
Shaun_Dark_Lord replied to mtillbrook's topic in Internet Related/Filtering/Firewall
IPCop + DansGuardian - Nice GUI! -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Just got a really good price for 1Gb from Virgin.......... -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Brian did confirm that schools in Bexley have a Synetrix contract expiration of 31/04/12, so we theoretically have until then to bail out. Obviously if Virgin turn up next week to install LGfL 2, then it's too late. -
LGfL 2.0 Problems
Shaun_Dark_Lord replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Right......... This was a misprint/error/whatever you'd like to call it. LogMeIn is banned on LGfL 2.0. Other remote access solutions are not. In response to our emails, LGfL have purchased an additional product to replicate the functionality of LogMeIn in a secure fashion. They called in Center Stage, but I believe it is this product; Fast, Secure Remote Support | CentraStage That means RM/EIS/Capita/whoever else can be sent a link and code by us, and get a remote session - Similar to LogMeIn123, but in reverse. I'm fairly happy with that solution. Filtering will still have to go through LGfL, but can be turned down to the bare minimum. There will be no Option 2 - Any schools wishing to do their own firewalling, will still have to use LGfL firewalling too, and will have to put in change requests for ports to be opened. Atomwide will not accept requests for all ports to be opened. LGfL have agreed that their communication is not adequate. I have requested that in addition to various blogs and documentation that are currently produced, that the contents of such blogs/documentation is summarised in an email to all nominated contacts. For the sake of skimming through one extra email a month this should prevent any more surprises. The three day changeover period from LGfL 1 to LGfL 2 is a minimum. Depending on when your Synetrix contract ends, you may get additional time to switch your services over. LGfL are working with Capita (who own Synetrix) on this issue, and hope to be able to offer a better solution. So when you get your installation date, it is worth contacting LGfL to find out exactly how long you have to change your DNS/IP/Proxy settings etc. I think that's about it. I'm looking into Virgin Media's SLA, so we can compare it with BT's excellent offering. We'll then be in a position to decide what to do. -
Dire internet speed, SWGfL area. help!
Shaun_Dark_Lord replied to PrimaryTech's topic in Internet Related/Filtering/Firewall
Hi Firstly - is this on downloads from multiple sites or one specifically? Some downloads from even big companies like Microsoft and Novell can take ages, as their sites are so busy. Have you tried Speedtest.net - The Global Broadband Speed Test ? Is this at certain times of the day? You are probably on a contended (shared) connection, so it could be that there is heavy traffic from other schools in your area slowing you down. If you are certain that all of your internal networking is good, try running speedtest at regular intervals during the day. Log the results and see if there is a pattern. If you are getting poor speedtest results, to prove that it's nothing internal, disconnect your network from the internet, plug in a laptop, and rerun the tests. -
Well I just tried all three domains, and am unable to access. Either your hosts have a problem, or you have some really bloated/buggy sites that don't want to load. As i said, try a different host. You could probably find a free hosting trial from someone. Even try hosting yourself at work/home and see if you run into problems.
