Jump to content

Netsweeper

Members
  • Posts

    12
  • Joined

  • Last visited

Everything posted by Netsweeper

  1. Netsweeper's core competency is using our patented techniques to categorise every URL that passes through our deployed systems (including https://www.duratex.co.uk/cable-protection/19-cable-mat.html). Netsweeper performs dynamic categorisation via our CNS system used by Schools Broadband. This proprietary technology analyses the content of all newly found URL’s and existing URL's in multiple languages (47) and matches to one or more of our existing categories before applying the appropriate action determined by the filtering policy table. Unlike traditional URL filtering systems Netsweeper analyses the entire page (i.e not just the URL trail) and scans for content (the physical words on the page in all 47 languages), context (in which context they are used), and construction (what features are present on the page). This heavy duty classification is carried out in real time for all Netsweeper user. This is why you would have seen the block page initially, due to the "New URL" category. Netsweeper analyses the URL usually within 4-6 seconds, assigning one or more categories, in the case of https://www.duratex.co.uk/cable-protection/19-cable-mat.html we assigned the category "General". Users in this case need to do nothing as a Netsweeper/Schools Broadband deny page will refresh after 6 seconds, depending on whether the categorisation is allowed on your policy Netsweeper/Schools Broadbands will either show the URL or display a block page depending on the content.
  2. They are two different things. The captive portal can be thought of as the "backstop" or catch-all. If the connecting client does not have an identity already (because it has expired) it will be matched by its IP address only, usually against a subnet entry. The match against the subnet will place that device into the filtering group that triggers the captive portal. There are many combinations of methods that can be used to obtain "identity", and there are many permutations. Each Netsweeper platform operator will deploy in a slightly different way that they believe is best for their customers and their methods of support. This is why it is important to follow up with your service provider.
  3. Hello, it sounds like there might be a configuration issue with your WAgent installation. From your symptoms, it sounds like the initial client/IP registration is expiring after a period of time. The Wagent is typically configured with a retransmission timer set to half that period, this guarantees that the client/IP registration is always refreshed before the expiry time. The values are configurable. Therefore, you will need to work through your normal support channels with your service provider so that they can diagnose your issue properly.
  4. Good morning Caffrey, Have you had chance to speak to your platform operator in relation to his? I have included a link to our documentation explaining how this works, however you may not have access to all of these depending on the setup of the platform. I would highly recommend speaking to them and we in turn can assist them should they require our help. https://helpdesk.netsweeper.com/docs/6.2/#t=Configuration%2FRadius%2FRADIUS.htm
  5. Hi Joanne We have been working very closely with BTLS on the migration project with minimum disruption to the schools a key priority in the project. With that being said, inevitably with a new solution there will be new changes to the way certain aspects are configured and as mentioned earlier in this forum we are going to be running regular webinars over the coming weeks with the intention of demonstrating the new solutions interface, key features including reporting and enhancements of the BTLS filtering platform and I would encourage you to join the webinar. If any schools would like to join the webinar please speak to the BTLS team about arranging a suitable time for you and we will look forward to speaking to you. Our team is highly experienced in migrations and will be on hand and readily available to assist the BTLS team throughout the transition.
  6. Hi snagrat, Yes, we do support this. Have a look at our docs for Azure here: https://helpdesk.netsweeper.com/docs/6.2/#t=Directory_Sync_Docs%2FAzure_Directory_Sync%2FAzure_Directory_Sync.htm There are a few options we can discuss depending on your current setup. It sounds like you are a customer of Schools Broadband, I would recommend speaking to them and we can work together on your requirements.
  7. Hi, One misconception on decryption is that you can't filter HTTPS sites if you're not decrypting. That is not true. A capable web filtering solution will be able to block HTTPS sites at the domain/hostname level without decryption, it typically identifies the sites using SNI or Reverse DNS lookup if the SNI is not available. Decryption is only needed if you want to block/allow HTTPS pages at the URL level e.g. allow specific YouTube videos only. Decryption will also allow the filtering system to analyze the encrypted content for duty of care and security purposes. But a good filtering database will already have URLs for virus, malware, phishing, extremism, hate speech and other negative content that you should block by category for security & safeguarding purposes. If you want to a different policy for students vs staff (without having authentication), then you can segment the network by IP (and Wifi SSID) and set the policy accordingly in the filtering system.
  8. Hi Snagrat, The issue is usually due to clock drift. Could we ask you to please check the clock synchronisation between the client computer and the server running the IIS service. Also compare those times to the NSProxy. The Schools Broadband support team should be able to assist. Many thanks Netsweeper Team
  9. Hello Blue_Cookeh We would like to say thanks to j_mckeague for sharing those URLs. From the Netsweeper perspective, you can use your policy list processing to allow those URLs (use either your Local List, or a Shared List) Create a new list entry for classdojd.com ensure the Action is set to allow. There's no need to add an item for each host if they share the common domain (unless you want to be specific of course!) Add similar entries for classdojo.pubnub.com and dojophotos.s3-accelerate.amazonaws.com. For these two you probably do want to be exact (otherwise the scope would be too wide, i.e. "all of pubnub.com" is probably not what you would want - but it's your decision). Note: the scheme-less entry that allows classdojo.com will also turn off SSL inspection (compared to an entry with a scheme, e.g. https://classdojo.com) Thanks, Netsweeper Team P.S you can always contact the Schools Broadband helpdesk team for this type of help and assistance.
  10. Hello, if you have downloaded the chrome extension can you check the policy server is set to a policy server where you have a user properly provisioned by your platform provider. If the default settings on the device are left you will be going to the wrong policy server. We have built a brand to automatically install and point to the policy server for schools broadband (if you use them I am not sure by your email) otherwise please log a ticket with your provider and we can work with them on getting this working for you. Kind regards, Ben
  11. Hello 04garwood, We are extremely sorry to hear you have had these issues and not had the best experience with Netsweeper. We are committed to helping you resolve this. We would like to know a bit more information so we can liaise with the platform provider. Please PM us on here as this is not the experience customers usually have. We would like to know some more details so we can discuss how we can resolve these for you, and we will review accordingly. Kind regards, Ben
×
×
  • Create New...