-
Posts
389 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
I do a bit of friends and family support, because my family are very 1 finger typing style. Rustdesk is now hosted on my local microserver and I believe its free commercially. Whether it does everything.... but its free and allows unattended. Im just a remote in and fix it jobby but also let's me get to my machine from my mobile thru starlink, only reason I touched it.
-
KCSIE 2026 - Filtering & Monitoring Reviews
PaddyNewman replied to fiza's topic in Internet Related/Filtering/Firewall
I won't get too involved as it makes me sorta angry, yearly checks feel like a tick box for gov to say 'well we did ask' and schools to absolve themselves. Checks should be done often. The Internet isn't sitting still. People make mistakes, human error causes open holes. My boiler is serviced yearly, my car MOT is yearly, my teeth are checked 6 monthly... Kids safety is more important than all of those, but check their safety net once a year, good job /s Honestly if I was in schools rather than ISP side, machine in every vlan and capable of being on every individual policy, constantly checking known endpoints, alert for any anomalies, weekly audit of filtering changes, termly firewall checks. Costs a little setup but you have the answers whenever you are questioned. With DSLs supposed to be taking control of whats allowed, but maybe tech level not so high, the risk of changes going squiffy is high. I know some schools check often, I know some haven't made a single change in 3 years and just expect it to keep working. Im genuinely scared at some points. I'll now retire to my hole and rest! (Obviously its my personal view, not the company view...) -
Forgive me as I haven't touched a Smoothwall in years and even then, it was light. Are you just sending items to the Smoothwall for filtering and giving that as the gateway for clients? VLAN100 should be tagged for it to pass to the Smoothwall if so, but this all sounds odd to me. Your next hop is in the same subnet, so just changing gateway could bypass no? I would probably set it up differently but I really am struggling to draw this out on paper,presumably due to my lack of SW knowledge. How does the sonicwall connect to the smoothwall, 1 physical port with a trunk loaded with vlans? I feel it could be simplified but like I say, struggling to work out the actual topology.
-
Issues with Sophos and Wireless Casting
PaddyNewman replied to SJ98's topic in Internet Related/Filtering/Firewall
Multicast streaming? Different wifi/vlans? No mDNS repeater. Only thing thats ever really scuppered stuff was that when I was doing fun stuff at home with casting. -
iPads - Web Filtering - URL Redirect
PaddyNewman replied to Tefters's topic in Internet Related/Filtering/Firewall
Our "HomeProtect" offering, its Netsweeper under the hood. Blocks correctly iPad browser only mode and full device filtered iPad mode. -
iPads - Web Filtering - URL Redirect
PaddyNewman replied to Tefters's topic in Internet Related/Filtering/Firewall
Had to test because that would be concerning if it was that easy... For my local filter, ipad, bitly to tiktok, it redirected and I got blocked. On my raw home feed with our cloud filter on ipad, I get the same, redirects to tiktok.com and blocked. using "bit.ly/4bksbnG" as my test. -
Offsite Internet filtering
PaddyNewman replied to Alastairb25's topic in Internet Related/Filtering/Firewall
To not derail this too much as this is definitely something SBB can handle, but for our homeprotect stuff, happy to hear some ideas/what to do different via DM or support case -
Same as above theres a few ways, I have some form of this in a doc somewhere from a recent customer call.
-
Backup Internet - Filtering
PaddyNewman replied to Alastairb25's topic in Internet Related/Filtering/Firewall
Worth noting Starlink do not subscribe to IWF nor CTIRU/PIPCU. Its as raw as raw can be, ideally you want traffic to go over it via a tunnel to a filtered endpoint, nuke the local wireless etc. -
Do you not have a dumb switch and spare public IP? Just pop a switch in middle and out you go with a static IP. Its why I always like an Internet vlan so you can just slap another port into that vlan and get past everything for testing. Plugging a box directly into the router means you cant do testing without dropping the lan (if its that big a problem though, tough cookie, its going down at 4pm. Its literally 1 minute of downtime. Work out how slow it's being and what its costing them in time... Admittedly it's only 1 website, but its handy to have for the future, only possible if you have another public IP to static yourself with though.
-
Does dev tools suggest its loading anything?
-
Cisco Umbrella and Intune
PaddyNewman replied to Bugzi's topic in Internet Related/Filtering/Firewall
I guess you could test by running testfiltering.com as the school option and check your report, should give you adult/porn, terrorism, profanity and IWF denies at a minimum. Always handy to test to know where you are at base. -
Cisco Umbrella and Intune
PaddyNewman replied to Bugzi's topic in Internet Related/Filtering/Firewall
Its deployable in multiple methods. If you've got full decryption rather than their grey list inspection, thats better, but they also make use of DNSCrypt which is counter intuitive to the ECH breaking methods you should have to view obfuscated DNS lookups. Its a trust thing. I trust Cisco to make switches and firewalls, same as FortiGate. I wouldnt use either as filtering, its a 2nd thought add on, not a purpose built filter. Sounds harsh, but theres a reason there aren't hundreds of firewall big names, same for filtering big names. Also, OK to use vs compliant and accredited are very different. My home filter is fine and would stop the bad stuff, I wouldn't have it in a school or somewhere that has a degree of safeguarding responsibilities. As long as you feel you can meet the requirements to correctly filter users based on age, provide different policies and be age appropriate, report on a per user basis and can decrypt their traffic, you are ok, but its just not accredited. Horses for courses etc. -
Cisco Umbrella and Intune
PaddyNewman replied to Bugzi's topic in Internet Related/Filtering/Firewall
https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering/filtering-accreditation-scheme-for-uk-schools I certainly wouldnt use Umbrella in education. -
YouTube Ads - Removing
PaddyNewman replied to cwuk100's topic in Internet Related/Filtering/Firewall
Sadly not, the ads are served on googlevideo.com which you cant block. Google/YouTube need some serious pressure applied to them to sort this, otherwise schools will feel they need to continue breaking ToS.- 35 replies
-
- 1
-
-
- youtube ads
- youtube
-
(and 1 more)
Tagged with:
-
That IP has refused connections on port 25 from all my test endpoints, doesnt make it impossible, but ive tried to say hi from multiple sources and they've timed out each time. That range is expo-e so customer of theirs i guess. That mail server looks less mail servery right now.
-
Schools Broadband Internet Issues
PaddyNewman replied to JazzFlute's topic in Internet Related/Filtering/Firewall
As a quick bodge, yes. It would be horrible longer term and just adds another method of failures happening. Another hop to potentially ruin your day! -
Smoothwall inappropriate Sponsored adverts
PaddyNewman replied to Sheridan's topic in Internet Related/Filtering/Firewall
Should be something similar to the old Vimeo safety net, rather than vendors having to change stuff. Either make it so they need to have a google admin and any logged in user gets YT no ads (along with public IP verification) and charge them £10 a month or make it free, or at least free with the beefier google admin. They aren't making money from the ads, they aren't selling teachers and kids anything with those ads because they hide them from view. The public IP stuff is already implemented at some level as they do not serve ads to Albanian public IPs... -
Bambu Lab - School Network Considerations
PaddyNewman replied to robyholmes's topic in Internet Related/Filtering/Firewall
Don't suppose you have that link to hand, all I can find is vague as sin and about as secure as leaving the front door open. We get some come through and I have manually captured each one as the doc they gave me was a book of lies. Cheers -
Schools Broadband Internet Issues
PaddyNewman replied to JazzFlute's topic in Internet Related/Filtering/Firewall
Not to invade on this post too much as I am an LGfL employee, but we can help to a degree with reconfig should you want to come to us. Transfer your filtering, id even do that for you etc. I try to make it as touch free as I can. happy to chat if you want. People switch 1 way or another, some take it as an opportunity to tighten the holes, ive seen some relaxed firewalls in my time from all vendors when they come to us... -
I've been on Starlink forever, I've had multiple Xboxes at once (playing Rust with friends staying over) and play competitive FPS on PC with zero issues on Starlink. They do it a lot better than mobile providers I feel. I plug my PC direct into the Starlink router with zero problems. That and the 400+ Mbps keep me happy. Only time I've ever really had issues was when I had my router behind the SL router and was using 10.x which NAT to 192.168 then NAT again to the CGNAT stuff, going via the router direct is clean.
-
What do you struggle with? I am starlink due to location and game a lot behind that, ive never had issues in games, voice or anything, pc or xbox. I would say its proper worth it if you need to game.
-
Routing issues - Layer 3 switch & Smoothwall
PaddyNewman replied to mikkydoos's topic in Internet Related/Filtering/Firewall
Can the smoothwall not be configured as a transparent in-line? I'd expect your Cisco to have all VLANs and have a static route of 0.0.0.0/0 to your actual next hop, with your next hop having a "schools network via your core" route to get traffic back, the MAC of which can be learnt through a transparent bridge. I would imagine thats a basic feasible item with Smoothwall. It can just filter on the line, didn't know they enforced some routing on there? If the Smoothwall needs to route, create a new VLAN on your end on a /30, your IP in one, the smoothwall in another, route between yourselves and have the Smoothwall route your school ranges back and default route to next hop. it either is your LAN or next hop, 1 single route in and 1 route out.
