Jump to content

Opendium_Steve

Members
  • Posts

    385
  • Joined

  • Last visited

Everything posted by Opendium_Steve

  1. The MAC address of the original sender (workstation) is only visible if the receiver (lightspeed) has layer 2 (ethernet) connectivity with that sender (i.e. they would both need to be on the same VLAN). As soon as the packet gets routed (layer 3 - IP), the original MAC will be replaced with the router's MAC. It would be unusual for the filtering server to have layer 2 connectivity with all of the VLANs on a reasonably sized network, so I don't think Lightspeed would usually require this? I'm not terribly familiar with lightspeed, but based on how our own filtering system works, the exception I can think of is if you're using RADIUS accounting *and* your wifi controller can't provide the "Framed-IP-Address" attribute (Ruckus and Meru can provide that attribute, Ubiquity UniFi and Meraki can't). In that case, the only way to link network traffic with a particular RADIUS session is by MAC address, which means you'd need the filter and the user's device on the same VLAN.
  2. This is the problem with trying to integrate the ISP and the filtering into a single product. We have always thought it much better to keep them separate - our customers seem to like being able to change ISP without having to change their whole filtering system, and rely on our filtering expertise instead of being restricted to only ISPs that understand schools.
  3. Squid doesn't play nice with upstream proxies if it is doing transparent HTTPS proxying or HTTPS interception. Its happy to blindly pass CONNECT requests from the client straight onto the next proxy, but it doesn't know how to make CONNECT requests itself. It *usually* isn't a big deal though since pretty much all of the RBCs offer transparent proxying these days, so you can just let Squid send HTTPS traffic via the upstream transparent proxy instead.
  4. Ouch - the pricings I've previously seen for Smoothwall put the remote installation fee at £450 (which still makes the £500 we charge for sending someone on-site for a day to do a web filter installation seem pretty reasonable There seem to be a lot of complaints about the quality of Smoothwall's support at the moment - there seems to be something of a price war going on in the filtering market at the moment and I wonder if they have cut the quality of their support to compete on price a bit more? (Lightspeed and Smoothwall seem to be about the same price at the moment, from what I've seen).
  5. I think that all this depends a lot on the size of school and how their internal ICT staff handle stuff. As an example, if you're a tiny school who has decided to outsource to a part-time third party instead of having your own ICT staff, you need to look at how quickly those staff will respond. There's no good complaining about the LEA being slow to block a site if most of the time is actually taken up waiting for your ICT people to even tell the LEA there's a problem. On the other hand, if your school has a good staff who can react quickly, complaining about the LEA's speed might be justified. That said, obviously you can't let a single school have control over the global block list that is applied to the whole LEA, but it does seem a poor system if a school can't block or allow a site for their own network, without waiting for the LEA staff to get their finger out. The DoE's draft Keeping children safe in education: Statutory guidance for schools and colleges document specifically says that you need to be able to "identify children accessing or trying to access harmful and inappropriate content online". I think this calls into question any system that doesn't automatically link a user (rather than IP address) with their web accesses. Identifying what a specific workstation has been accessing should be easy, so it's concerning that the LEA doesn't know if they can do that. But it's probably more important to go the other way - filters automatically producing reports of concerning behaviour so that staff can follow up with the individual users involved. Producing these kinds of reports is much harder of course. If those reports only identify IP addresses rather than users, that makes following them up much more difficult. True, you can probably trawl through the logs and figure out which user is responsible, but that's a lot of work and is surely going to reduce the number of reports that will actually be followed up. Systems such as Iceni, Smoothwall, Lightspeed, etc. will produce these kinds of reports, it seems that many LEA filters won't. My opinion is that this is the best way to go, and there are cheaper options than Smoothwall (but I'm probably biassed, since that's the line of business I'm in). As other people have pointed out, this is a decision for the people at the top, rather then the ICT team. But the decision makers should certainly be taking input from the ICT staff, and people from outside the school - people like the Internet Safety Centre, for example. Or even the filtering providers themselves, so long as you take their obvious biases into account - we're always happy to talk to folks about this stuff, even if they aren't actively looking to buy from us. Whether or not you do BYOD at the moment, it's something that isn't going away so I think you're setting yourself up for pain if you opt for something that requires apps to be installed on the myriad of hardware that might be connected to your network in the not so distant future. Any filter that intercepts HTTPS traffic (and you really should be using one) will require a certificate to be installed on each device, but that is at least something that all devices support. Remember that whatever system you use, it is never a "fit and forget" thing - realistically, safeguarding children requires staff to work proactively. You need to keep an eye on the reports that these systems generate, and actually follow up any concerns that they flag. They were a similar price last time I checked. Its worth noting that the filtering market has become quite competitive of late though and prices have dropped across the board.
  6. Out of interest, does the "enhanced care" change anything in real terms in your experience? I've heard reports of BT Wholesale not even trying to meet the enhanced care SLA - it sounds like although BT Wholesale offer a 24 hour fix SLA, they don't actually have an agreement with OpenReach that would allow them to meet that SLA. Thankfully, although dealing with BT has often been an almighty pain for installation, we've never had to convince them to fix a fault with an existing connection so I've not found out for myself how true those reports are.
  7. The IWF could easily run a DNS based filter similar to the various anti-spam DNS blackhole lists. That would keep the list itself hidden whilst allowing URLs to be checked against it at access-time.
  8. I believe LS does some filtering on search phrases, but that's about it. I presume they do off-line content analysis to keep their block lists up to date, but that doesn't help too much with dynamic websites. I believe Iceni and Smoothwall are the only systems which do real-time content analysis (someone correct me if there are others).
  9. We've got a good number of customers using BT leased lines. The initial setup can be a bit of a battle at times (too many managers and too much red tape - once you actually get to talk to someone technical things seem to go pretty smoothly but it can be a fight to get to talk to someone technical). Once the line is up and running it seems very fast and reliable though. So I guess my advice is - plan well in advance for the pain and delays of installation but once it's in you should be fine
  10. This is something I've always wondered. To be honest, I think it should be free to any organisations with a good reason for needing it and the foundation itself either funded through donations or directly by the government. At least the IWF have clarified their funding model these days - when the IWF was first set up, they advertised that they were funded by "voluntary donations", but what wasn't made quite so obvious was that in order to gain access to the block list, organisations were required to make a "voluntary donation" of a set amount (sometimes tens of thousands of pounds, depending on the size of the organisation). They have at least now started using the term "membership fee" for the mandatory payments instead of "voluntary donations".
  11. Yep, but that's the Safer Internet Centre's interpretation of the requirements, not the requirements themselves. Admittedly if something happened, someone might point at that and expect you to justify why you weren't using the IWF list, but that's not the same as it being mandatory.
  12. The requirements are pretty open to interpretation - I think there are only vague statements about ensuring children are protected from inappropriate or illegal content rather than a specific requirement to use the IWF list. As you've noticed, the IWF list is tiny compared to other block lists - the IWF list only includes (probably-)illegal content, so it is not a substitute for other filters. A lot of ISPs have IWF filters anyway, so you may well already be filtered (but obviously without the ability to generate reports). I don't believe there is any way for individual schools to have access to the IWF block list. At least, you'd probably need to pay a membership fee.
  13. Does anyone know what Smoothwall's "Service Essentials" is? I've seen it mentioned a few times but Google's not turning anything up so not sure what it actually is
  14. I've heard of it, but not come across anyone with any experience of it yet though. It appears to be very new (started in 2013) and very US-centric.
  15. I dunno, I've seen BT take an age to fix problems on some leased lines. Getting a pair for completely independent asymmetric connections (e.g. FTTC and Virgin) is potentially a reasonable strategy, rather than a single leased line - you can use them concurrently normally, but if one goes pop you can just fail over to the other. Very much depends on the size of the school. IMHO Virgin's 50/5Mbps connections have a disproportionately slow upstream, which is becoming increasingly important as cloud services become more common (storing data in the cloud == more uploads), and a saturated upstream can limit downstream rates too. But at the end of the day if no one is complaining about things being slow, there's probably no need to proactively look to upgrade the existing connections.
  16. I'll echo this suggestion - if it's an all-in-one bundle then you're in for hell if you're dissatisfied with any one part of it since you have to change the lot. Although getting quotes for individual bits is more effort at the start, I think there's a big benefit to doing so.
  17. Is this a new Smoothwall box? If Smoothwall won't even help you get up and running with a new box, I can only see things carrying on going down hill even after its installed so might be worth returning it and buying something else?
  18. Seems pretty poor all round - I would have expected Bloxx to proactively inform all their customers (how hard is it to send round an email?), but I do remember a lot of their resellers complaining at the time that they hadn't been informed and were caught completely off guard by the announcement.
  19. Obviously no excuse for not having backups, but I wonder if this kind of thing will start to make ZFS based file servers popular, for their ability to just roll back the changes when ransomware hits...
  20. Depends on how big a school it is, but I'd agree that 6k sounds fairly astronomical for most schools...
  21. Dare I ask what you're using? Maybe you can use this as leverage
  22. Sounds to me like they expect: 1. Children to be authenticated (and their web traffic be logged against their identity) 2. Staff to be alerted to children who's web traffic is being blocked by the filters. 3. Probably also staff to be alerted to attempts to access inappropriate content even if it doesn't trigger the filters. I guess you could achieve this be trawling through the logs manually, but sensibly you'd want your filter to be able to produce summary reports on a regular basis for staff to review and follow up on. Pretty much all of the mainstream commercial on-premises filters (Iceni, Smoothwall, Lightspeed, etc.) will do these kinds of reports. The third part of this probably requires monitoring web searches. I can think of a few LEA systems that would fall short though - they often don't authenticate the users, so even if you get a report it can be hard to identify the user responsible. I also note paragraph 76 - "As part of their safeguarding and or child protection policy governing bodies and proprietors should have in place a clear policy on the use of mobile technology in the school." You could just ban mobile devices entirely, but my feeling is that this is going to be widely ignored and therefore much less effective than properly supporting BYOD through your filters.
  23. That's correct. LightSpeed rely entirely on a big database of categorised web addresses; Smoothwall and Iceni both do the same but also augment that database with real time content analysis. Smoothwall and Iceni therefore use somewhat meatier hardware than LightSpeed, since they need to do more work to analyse the data on the fly. LightSpeed does a pretty good job of filtering out sites that are dedicated to dodgy content, but you can't realistically filter stuff like social networking sites without content analysis, since the content is tailored to the individual user. Content analysis requires SSL interception, but most of the time there's no real problem with doing that. The only time SSL interception is really a big no-no is for guest devices, and then you can always fall back to only using the database of categorised websites.
  24. Doesn't your internet filter also provide an audit trail of what the users are doing on the web? Or is this nor what you mean?
  25. Or use a web filter that examines content instead of relying entirely on a URL database.
×
×
  • Create New...