AlanD
Members-
Posts
1,102 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by AlanD
-
Smoothwall - Psiphon VPN
AlanD replied to stgoodyeara's topic in Internet Related/Filtering/Firewall
OK - but how do you block IP addresses? In Guardian's "Core Blocked Content" ? How do you specify a general numeric IP format? -
ZoneDirector & Smoothwall Filtering
AlanD replied to CHiLL's topic in Internet Related/Filtering/Firewall
Smoothwall can use radius to identify the user. So instead of a single WiFi code - you set the access points to use Enterprise authentication and users put their username and password into their BYOD device/phone. You radius server (which can be smoothwall itself - in fact I would do this) then passes the information to smoothwall. And provided DHCP is setting smootwall to be be gateway - and you have smoothwall set to be a transparent proxy for the traffic on that wireless VLAN - there is no proxy configuration. And they probably never need to re-enter their name and password - so everytime they use their own device it automatically knows who they are.... Captive portals are - sadly - necessary for shared devices...but such devices were never intended for sharing...and don't expect to be subjugated to a captive portal...and are a pain when working with apps.... -
Smoothwall - Psiphon VPN
AlanD replied to stgoodyeara's topic in Internet Related/Filtering/Firewall
Block bare IP addresses.....this is in Guardian? ...because all other traffic will be just IP addresses once they have done the DNS lookup.... So this would cause a problem with any web site which has links that just contain IP addresses...but I agree that is probably not very often...and specific ones can presumably be allowed later...(not quite sure how that would be done if block all as precedence...) Don't understand what "validating" a certificate would ensure for the client or SW....except that their https traffic might be potentially monitored.... -
Never quite understood the fascination and obsession with the cloud. Some seem to think its way we must go...or its cloud based then you must go for that. To be honest I don't care if its cloud based....but I do care how easy it is to deploy and use. If cloud delivers that in a way not otherwise deliverable - then great. I like like the way - for example google classroom any teacher can set up a class on their PC/device...get a code number ...and when students typew that code number into their device...get access to the shared files/folders you created for them....doesn't need any infrastructure...other than wireless or 4G access. If they can get monitored in a similar fashion by joining a class...great.. Language lab type functionality would be good....to pair devices automatically - or manually for conversations...to listen and add your own answers to questions in an audio file...etc.
-
Anyone using u2f security keys to secure G Suite
AlanD replied to TwistedHelixis's topic in Cloud Services
...Are these gamil accounts - school gmail accounts.....if they are personal phones....how are you going to wipe them if lost to ensure there is no school data on them? -
I'm not saying that the existing tools are fine...or that they are not overpriced....or even that there is isn't room for a competitor...because there is nothing quite like a competitor to sharpen up what these products deliver. But I can't help but feel that you are coming from behind...and without some kind of "edge" its going to be difficult to break into the market and difficult to make up lost ground. I use netsupport (rebadged as RM Tutor)....and it does the job of viewing class screens, limiting which applications (to one if necessary) , controlling access to the internet...white board...etc. etc... and doing same - albeit with cloud management isn't alone going to get me (nor anyone else I guess) to change. Mobile device "supervision" on the other hand might make me take notice...because RM tutor can't see ipads are doing...but I'm guessing that is because iOS doesn't allow that to happen...but its certainly something class teachers repeatedly ask for....So an app that would allow a BYOD device to "join" a class and become locked to that class and under the supervision of a controller during that lesson until "released" would be great. Maybe its possible with Android....
-
Selecting a Web/Content Filtering solution
AlanD replied to Ditto's topic in Internet Related/Filtering/Firewall
Well..don’t base your decision on what other schools say or do...but by all means take some of that into account. Only you know what is important...so you probably need to get some test kit in place to trial...and yes that’s a pain. Some wish to keep router, firewall and filter functions all separate. I think functionality overlaps these days...although I don’t think there is truly a product out there that manages this integration well...often a single box with separate menus inside....For example you might wish to allow Spotify. So you tick a box in the filter to allow streaming media services or whatever...and it doesn’t work. You then discover the filter doesn’t include rules for Spotify so you add a list of urls. It still doesn’t work...and you have to add some firewall exception rules in completley separate menu. And because it’s a mobile wireless device you later discover you need to add some https interception inspections. Finally it works...but you can’t see the usuage because you had to add the exceptions. All is well for a couple of months, and then it stops working. You discover you have to change and add urls to the filter, change inspection rules, etc, etc.Later you decide to remove access to Spotify...but you can no longer tell or remember which exceptions or URL’s belong to Spotify..because they are just part of a long list for various services you added. You would be thinking why doesn’t the filter privider provide this granularity and do it once for all their customers...but the reality is that once they have sold you their kit it’s only then you begin to see its limitations. I’d like to see the ability to create a filter set of rules for a particular app which includes urls, firewall, and exceptions in one place...and tick or untick it’s ability to work. Better still have that named rule set download and be updated from the filter supplier. Why every school has to separately google the firewall and filter rules and individually add them is rediculous. We wanted reverse proxy capability...because we host the odd thing from inside school...to allow access to home folders, etc. That started to limit our choice. And while we took a long look a cloud filters it always seemed somewhat convoluted to get our AD credentials visible...and often firewall functionality for cloud offerings were seemingly limited ..and in particular the firewalls were unaware of AD groups...and we like to say to the firewall let staff use this port or whatever...but not students. Some required cloud identification like RM unify. Then we wanted good prevent strategy reporting. So we needed to see google search details...not just this site was blocked. And we wanted to report different year groups to different year heads...not simply have one big report. Several global produced filters barely delivered on this front...and while all sorts of hand configurations and setups were possible...they would probably take half a lifetime to setup. We wanted full prevent strategy reporting out of the box. Then we wanted a box which would take 2x ISP connections with load balancing....and at least 300mb/s throughput...and at least the possibility of a fully redundant system with a second box with failover capability.. For us it eventually came down to Sophos or smoothwall....which are both pretty awful in many respects...and rediculously expensive...especially as neither are capable of stopping VPN clients drilling straight through them. And by the time you have finished adding exceptions for mobile apps you will wonder why you bothered with any filter, because there will be no prevent reporting on usage. Be prepared to drive a very hard bargain....and make it clear you are going for a different choice unless there is a significant discount. And don’t let let make you thing you are getting a fantastic deal because they offer you free set up or an additional year. Make them agree to several extra years ...and guarantee a future renewal price no more than current charge...and to come back 9 months after install for free to iron out problems. Most suppliers think schools are a soft target to sell into because unlike industries they often don’t have competence to make technical demands...and don’t have the balls to negotiate a bargain. We did quite like the way smoothwall has integrated DHCP, DNS and radius....as well as a captive portal...all of which makes it as easy as it ever can be for wireless devices..and we use it to route between our VLans because it is AD aware of IP addresses and so can allow staff but not students to access airserver to projectors for example. ...and that’s what we went for.....but you need to make your own decision based on your requirements and focus of importance. -
PM'd the sales exec who sold us it. We use smoothwall - because at the time of installation - nothing came close to it in terms of reporting for "Prevent" strategy....and we wanted a firewall where we could control traffic by AD groups - not just web filter by AD groups...because ots of stuff doesn't use web protocols... That's not to say that smoothwall gets a ringing endorsement from me...I think most filtering products have a long way to go and are still stuck in the past with user interface tweeks rather than genuine steps forward in useability. And note...filtering is NOT the ultimate requirement. Simply blocking all unsuitable traffic is NOT what we are being asked to do.....although this is widely not understood by filter providers...nor schools. Its the ability to monitor and report on internet use that is the important bit. Nearly anything can filter - for example a DNS filter costs you about £40 a year....and blocks essentially all adult sites...gamblings.. violence....etc. ...but doesn't satisfy what we are being asked to do. However, you and others will correctly point out that they can access anything they like using "eat as much as you can" using 4/3G connections....or for that matter drill through even the most sophisticated firewall and filter you install using a VPN connection and become completely invisible and access all those sites you spent a fortune to imagine you were blocking.
-
We have what is now a 300MB/s (with 20Mb/s upload) which we installed as a backup.....but it proved so good - and so fast - that we direct all our BYOD traffic though it now. Actual speed tests are well above 300Mb/s and well above 20Mb/s for upload too....and with very little (none that I can detect) signs of contention during the day. Yes - its perhaps 20% slower in the evenings.....but of course....we don't use it at that time....Cost us more than the advertised price because apparently public sector businesses can't get the same deal as other businesses because its "sold" from an off shore account - for tax benefits....so its around £80 a month - or £1000 a year. Much faster than a 100Mb/s leased line and a fraction of the cost.
-
OK...so its probably worth a reset of ALL the access points before pushing out anything new. I assume this can be done from the hive manager (such a long time since I've used it...) That should stop them having to be factory reset - because I can completely understand that that is an enormous pain - even if its a small percentage...by the time you walk all over the school with a ladder or whatever...The trouble is when you get 300 APs updating - even a small percentage failing is really irritating. You suspect the random crashes - are load related....and possibly memory related too? And there is no pattern to this - like always one of a particular set of access points (...which it might be because of load)....but I think I'd be swapping some access points around to see if the problem then goes away from that area. I am conscious that AP120 units are quite old now - we still have lots though....and as I said they seem to work fine. Its the 320 and 330 that are prone to PoE issues if I forget to set higher power levels when reconfiguring or replacing a switch. Can you see memory use with hivemanager? I've just looked through mine....and no AP120 is using more than 60% of memory ...but there are no APs supporting more than 30 concurrent connections....and those with the higher numbers of connection don't seem to be the ones using most memory - nor is it the ones that have been powered up for longer. And apart from the odd AP (which I know about - because either the power has been off or have been uplugged)....all mine have been working for over 13 weeks. (Wondering what happened 13 weeks ago.....perhaps there was some overnight power outage...only our core switch have UPS.... I think there is a limit of 64 connections to any AP120 anyhow....or maybe that is to one radio.... ...I still don't understand why Aerohive are not monitoring your access points and making an effort to understand exactly why they are crashing.
- 62 replies
-
- recommendation
- system
-
(and 1 more)
Tagged with:
-
Smoothwall - Psiphon VPN
AlanD replied to stgoodyeara's topic in Internet Related/Filtering/Firewall
Hmmm....well maybe the firewall needs to at least sample outgoing traffic...and if it’s going somewhere not ok maybe it Ed’s to isolate that client and report on it. I can understand it can’t do this for every packet....but a sample should soon pick up vpn usuage...and there probably needs to be closer integration between filter and firewall so firewall knows what the filter has permitted. -
Perhaps Aerohive have effectively given up on you...because they know that even if they now get it right...you will still leave them. From your detailed reply it looks as if you have made a concerted effort .. and much more effort than Aerohive. I can’t help think that anyone reading these forums thinking about a new wireless systems will be putting a red line through Aerohive as potential supplier. So it’s not just your supplier getting themselves a bad name...it’s all those that sell Aerohive. Aerohive seems to work fine...just works....hardly ever check on it. And it clearly works well for lots of people...so they really need to be doing more to narrow down the source of your problems. You describe the crashes as happening when pushing out the configuaration...does it happen at random times even after they have been working? When they crash ...do they reboot? Can you still use putty to talk to them?
- 62 replies
-
- recommendation
- system
-
(and 1 more)
Tagged with:
-
..I'm not even sure it can be done on an individual school scale. Modern VPNs are so good (..or should that be bad..) that any BYOD device with one can drill straight though smoothwall and as far as I can tell most other filtering solutions....completely invisible...in fact ...it is that invisibility which allows me to know they are running a VPN! And even for those without a VPN you have to add so many exceptions (its almost become a full time job) to allow mobile apps to run - by making them exceptions to https inspection.... And eat as much as you like data packages on devices of course mean that most students can get faster speeds staying on their 4G connection rather than using school wireless...In fact I think they should allow us to use 3G/4G blockers....
-
Personally....I'd prefer to use a transparent proxy at the gateway address - for mobile devices - Do you need the gateway address to be different from your proxy address?
-
300 APs...ok...that’s a serious implementation...I thought our 100 APs were plenty...and a script isn’t that bad..because you can automate its distribution...but I agree it wouldn’t be a solution I would recommend....but it is cheap! We don’t use the aerohive radius...we let our smoothwall handle that...and it handles our dhcp and dns for wireless. So I can’t comment on how well..or badly the APs might do it. I’ve always rather liked the autonomous capability of the Aerohive APs to fully function in the absence of a connection to any controller/hivemanager....but perhaps that communication is part of the problem for you. And we don’t use the bonjour capability either...never really thought bonjour has sufficient granular layers to control which printers appear on which devices..so we use QR codes with printer manufacturers Apps..and some rules in smoothwall to control permissions to printer vlan. But...I would have expected all that to work...universities probably have larger implementations...but yes possibly off load radius. But ..I would still be holding the suppliers hands to the flames....because they need to earn their support costs...it’s not money for nothing...and Aerohive themselves need to back them up...and that may cost them money...especially if they don’t have competently trained staff to narrow down and identify what is going wrong for you. I assume you have raised this on Aerohive community site and making lots of noise there. Annual costs for 300 APs must be thousands of pounds...and I bet your predecessor paid for several years upfront...which you less leaverage...but you could you usefully start to make noises about taking proceedings against the company... I assume you are hosting the controller on a VM and...you have checked it’s been given plenty of resources...? Have you tried ...turning off layer 7 stuff ..which we don’t use because it we think it’s better done with smoothwall at the perimeter..so don’t see the point of doing it at every AP? And we don’t use Aerohive’s captive portal either..again that’s pushed to the smoothwall perimeter....because it’s smoothwall that needs to know the user...couldn’t care much if AP knows who it is or not. Ah.. you mention power. We do find power demands critical. Yes, all manufacturers claim their AP is 802.11 compatible...but being compatible often means the AP is limping along...especially the 3 and 4 stream, multi Ethernet APs. We find our APs randomly reset unless we up the power on the poe switches...in fact we set ours to 802.1at...and while they don’t use 30W they must just trip over the 15W. Maybe this is somewhere to start...get some inline “at” injectors see if they help.
- 62 replies
-
- recommendation
- system
-
(and 1 more)
Tagged with:
-
I can never understand how a school - or a business should have a complaint like this. Frankly (assuming you are paying for cloud subscription/support) Aerohive should be rushing out their best engineers with flowers (for the wife) and chocolates and offering you money back if they fail to fix it in 6 hours. You pay an eye-watering annual charge - so demand something for it. Make sure to change your supplier to someone else that does Aerohive. Scream louder - because clearly you are not being heard. As for "not powerful enough to do the tasks expected of them"... well to be honest I partly blame you if that is the case. I would have wanted to be confident that was being proposed by a supplier would actually do the job. All too often....suppliers read the specification...and interpret it rather too liberally. They read "Supports up to 500 clients".....and " speeds of over 1Gb/s" ...and schools think they are going to replace desktop suites of computers with laptops. Remember that those high speeds are only deliverable when using a wide channels (160MHz) and chances are (a) your clients don't support that (b) proximity of other access points means you need to use narrow channels © large numbers of clients means a collision domain that will decimate you traffic speeds (over 20 clients). Then there is the claim that MU-MIMO delivers to 4 clients at once...it kind of does...but actual real world throughput is only around 20% more...(its only 80% more in a theoretically perfect world because remember its only half duplex delivery)..and multiple streams which might raise the notional UDP transmit speed to x2 or even x4 (I bet you don't have any of those as client devices) while making the numbers look great in windows connection speed and AP connection speed - doesn't turn out to actually deliver such data rates....which are again only around 20% more - with diminishing returns as you add streams. One access point in One classroom (yes I know there are claims that access points don't need to be deployed that densely.....but they will if you intend to deliver useful speeds to adjacent classrooms all with devices/laptops) is probably a good starting point. And they need to be in the centre of the classroom ceiling. Out the corridor through a wall and the benefits of multiple streams, Mu_Mimo, high MCS values and the rest become academic - because those only work in extremely high signal to noise ratio circumstances - which is around 3 to 5m of air (no bodies or wall in the way)....yes even thin walls can be surprisingly dense to 5GHz waves....all you will get is 54Mb/s shared between 30 devices...with 25% loss for collision domain.... Yes if you discover that you can use a wider 80MHz channel by taking one access point away from a block of classrooms - then you can start to reduce that number...but even multiple 80MHz channels depend on DFS/wether radar channels being free - and noisy clients and accesspoint often give rise to false detection so thos channels effectively stop getting used as the day progresses. I use Aerohive - and they are fine...(although I don't use their cloud subscription....just use command line programming...). But if I had to start again I'd be looking really closely at Unify.
- 62 replies
-
- recommendation
- system
-
(and 1 more)
Tagged with:
-
This is not anything to do with meltdown updates and new microcode that Intel produced and then withdrew in January is it? Which causes...expected lockups....and is delivered either via firmware updates - or Microsoft updates....
-
Meraki brilliant - fantastic web interface...Aerohive wonderful...can be configured in all sorts of useful ways and directly programmed via command line...Ruckus absolutely solid...but they are all a bit like buying Bentley or a Rolls Royce. Not only is the initial cost eye-watering - but the ongoing service costs alone would buy you a second car. Is unify as good - possibly not - it doesn't come with a drinks cabinet nor a VIP lounge while your purchase is serviced...and no supplier is going to come and hold your hand to set it up - well unless you pay them - because there is no money it for them. I think Unify is what might be described as a market disrupter - because it doesn't come with frills...and stuff you never really needed......but it is enterprise quality - despite what competitors say - and does all the stuff you want in a school..... without ongoing annual charges...and at half the initial cost or less.
- 62 replies
-
- recommendation
- system
-
(and 1 more)
Tagged with:
-
Well I'd be going the HD Unify access points...because they support AC2...and therefore have the potential of wider channels, more streams (4x4) and of course MU-MIMO. None of these things are life changing of course. Wireless is wireless....its not a replacement for wired delivery in a classroom environment - regardless of hype. And yes they are more expensive..but not nearly as expensive as the access points from the big names.
- 62 replies
-
- 1
-
-
- recommendation
- system
-
(and 1 more)
Tagged with:
-
Smoothwall - Psiphon VPN
AlanD replied to stgoodyeara's topic in Internet Related/Filtering/Firewall
Thanks for the informative reply. I think I’m beginning to see why it’s difficult..but I still can’t help thing these packets have IP addresses...and stuff leaving your firewall for a destination that doesn’t match that of any allowed site should be blocked. -
Smoothwall - Psiphon VPN
AlanD replied to stgoodyeara's topic in Internet Related/Filtering/Firewall
I, for one, don't really understand this VPN problem. I had to close/block all outgoing ports on smoothwall (not sure why the default position was open...). And so only traffic from our email or other specific devices is allowed out on any port - and usually only to a known destination. So if smoothwall is decrypting https traffic ...well it can't be doing a very good job of that if traffic is still being let through...and if it doesn't understand it - why isn't the default state to block it? Or is traffic getting through the ports I blocked? -
Yes...persistence and patience are great attributes...(I have little of either) :-)
-
ZoneDirector & Smoothwall Filtering
AlanD replied to CHiLL's topic in Internet Related/Filtering/Firewall
...well I wouldn't use (and don't use) captive portals for BYOD (...but yes probably necessary for shared devices/tablets). I would use radius/enterprise wireless authentication - using smoothwall as radius server (which in turn talks to Active Directory). I use Smoothwall to provide DHCP for BYOD (which of course are isolated from the rest of the network). Smoothwall is the gateway for BYOD traffic - so no proxy configuration - and most BYOD devices are happy to remember their clients details. Captive portals are a pain with devices/tablets - because users might not actually go to a browser (and the session may time out without them realising it). And they might for example have a "google APP" - which fails to work because they have not been on a browser (and don't understand the difference between using a browser and using the google app). And its a pain if they are using an APP like word - and the captive portal session times out. But you do need a certificate installed of course... -
I don’t think any AP mauafacturer claims “sustaining” such large numbers of clients. Yes that number might be able to connect but getting any meaningful amounts of data to that number of clients ...even to support background data ...would be impossible. The problem stems from the single collision domain which has no collision detection method. So if 1 client could get 200mb/s using a unify HD ap (and this is actual tcp type data, not the udp connection rate which is misleading)you might have 5 clients getting 40mb/s. You might even get 10 clients with 20mb/s. But once you get to around 20 clients instead of the expected 10mb/s you only get around 5mb/s, and 40 clients might struggle to get even 1mb/s. I’d be getting an HD ap and setting it up, nothing to lose...sell it again on eBay if it doesn’t make a massive improvement. Get a free meraki ap to test, most wireless APs can be tested for free. There is no magic right way to deploy APs, but if you want highest speeds 3 to 5 metres unobstructed is what the best claim to get sufficient signal to noise. Yes it will go through walls, but all those high QAM multiple stream speeds disappear. You can compromise, with some rooms without APs but surrounded by other rooms with APs.
-
Did you use FTTP because there was no FTTC enabled cabinet serving the school? How much was the installation cost? Do you know how far they had to put the cable in? (The Draytec 2830....assume you used the WAN connection - although it also supports ADSL...I note the latest 2862 supports higher speed throughput...)
