-
Posts
389 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
Anyone using Starlink?
PaddyNewman replied to MatthewL's topic in Internet Related/Filtering/Firewall
Yes, using at home as my primary internet connection. Feedback - Aside from having to set it up on my own up a ladder, drill holes through my house and having a rather large cable coiled up in my room, its great. Was delivered quickly. Its been pretty reliable, few basic outages. I get a disconnect from my VPN maybe once a week currently but its a minor blip. I have it because my ADSL is like 15Mb down and 1Mb up, which is pants for more than some TV streaming and general browsing. I game a lot and downloading 100GB on 15Mb is going to take till my 40th birthday. I think its a worthwhile investment for me, would cost £15k to install fibre to here, which is 14 years of Starlink. I won't be here more than 7-10 years, so works out. Speeds - Mmm depends. Last night when I was sorting some stuff I did a test and got 190Mbps down and 30Mbps up with 34ms unloaded / 95ms loaded. I routinely see 200+ down and ~30 up. I had a very brief spot where I was hitting 300, but I presume that is just them testing capacity. Router - Using theirs, wifi only. I really don't want to pay for the adapter. There is no port forwarding stuff anyway, my 'Starlink' wifi is my work PC and my personal PC. That is it. Everything else uses the ADSL so its not too stressed or anything like that. I have no desire to install another router in the way, frankly the power draw of the dish is enough to make me cry, adding another item to the wifes list of 'why is the electricity bill x' isn't a wise move. It uses, right now, 97W of draw, when it was snowing/real icy, -2 here, it was at 101W. If I moved to another rural home, I'd grab it again if 35/67Mb wasn't available via copper. If I could get a reliable 50Mb, I would scrap it as my primary. Been a godsend though when my ADSL went out, similarly, the ADSL sorted me out when Starlink had its worldwide outage. -
Anyone on LGfL use 3CX phone system?
PaddyNewman replied to fiza's topic in London Grid for Learning (LGfL)
@tonyuk2283 your 3cx reseller should provide you with the SIP endpoints. Usually 93.x.x.x/24 and 146.x.x.x/27 - can vary on the host and even more so if they use Gamma SIP on top of the 3cx platform. Do you have an on prem SBC also, or just pure cloud. I do have a specific ruleset for ports, but the provider must provide the endpoints. -
Feel free to call in and ask for me if you need something - just pop through the normal support number and ask for me and I'll try to assist - if you want a full reason posted in here, let me know and I'll do that instead. I'll have to watch what I say but I certainly will try to detail as much as to why we do what we do Apologies for the delayed response also, I was travelling/working!
-
Can you see the phones traffic in a capture/report?
-
Indeed, I moved away from London and surrounding areas to Lincolnshire, the internet a few miles down the road is fibre, but it stops dead the second the town ends and the country road begins, so we have on a good day 17Mbps and about 1Mbps upload over copper. 4G, pah maybe H+ and 1 bar at that! Starlink for me, has been a godsend. Looking at my usage, right now I am 28ms, loaded 133ms and my currently download is 235Mbps, actually using 22Mbps (house/IoT runs on it) and aside from last nights global outage, its never been down for more than 5 seconds and they are maybe once a week. I game on it, use VoIP, do everything you would typically do. My view is that for a school, they are a fantastic way to keep you afloat should anything go wrong, but for the monthly cost/fact its going to sit there 99% of the time idle... you'd be better off getting a leased line, backup FTTC, diverse route line in. Only thing I have really noticed that is bad with Starlinks is its connections. Most firewall/home router appliances multithread internet connections. The Starlink 'may' do that, but from what I have experienced, it doesn't. Even if I throttle my game updates (say I can reliably get 200Mbps and I force 150Mbps) the rest of the house is suffering, seriously struggling and getting few hundred, even 1.x seconds of latency. It is very noticeable and the reason I run work and home separately, can't have my wife downloading updates for her phone and it kill my VPN, which it does if I load both machines and download something on my personal pc. I value them as a short term solution for school/business but for rural folk, they are a game changer. Obviously just my view on it having lived with it for 6 months!
-
I'd rather not be reliant on a person and their house/should they move/I heavily use my Starlink and would hurt their experience (unless they got a second line entirely) but being reliant on a service provider feels far less intrusive. Apparently its due to collapsed ducting from what the BT engineer that came out to install my super fast 10Mb line... its been that way for years. Unfortunate.
-
I am very rural and they wanted £15k to consider getting me fibre (which is available 5 minutes down the road) I figure leased line is just posh words for your own high speed/fibre line, which would be the same issue, no fibre - mega cost to you etc... happy to be wrong, but I went to various people as a "business" and best I got was bonded ADSL lines, no one came close to getting any form of FTTC/FTTP without a seriously big investment from my pocket.
-
I use Starlink as my primary ISP and given the recent launches, more population of LEO sats, I'm seeing regular speeds of 250-280 down and 35-40 up. In busier times (5pm to maybe 11pm) I see closer to 150/160 down and 30 up. It's viable for me, but one big download or hog and that quality goes in the toilet, for example if I download a game update, voice comms are dead in the water. Teams call and Windows update, game over. Otherwise it's viable, if you just need a 'keep me afloat for 4 hours' connection in a school, sure I would take one. But £75 for the if and when, as well as having it fully powered on and ready, as well as needing an absolute crystal clear sky sight... I'd rather go 80/20 VDSL
-
Chrome top of screen randomly goes black
PaddyNewman replied to Sonic007's topic in Internet Related/Filtering/Firewall
Exactly the same here, Dell machine, Intel UHD 630 graphics. That was a few years ago though. The first time it stopped was version 25.20.100.6617 for me, I keep note for obvious reasons -
Smoothwall blocking O365 on our Guest Wifi
PaddyNewman replied to kennysarmy's topic in Internet Related/Filtering/Firewall
If you static your DNS to 8.8.8.8 does it work then? Sounds so DNS-esque its horrible, and I work with if it can be DNS, its always going to be DNS Presumably the guest FW rules allow DNS and you force them to use public ones so they don't touch internal ones. -
Smoothwall blocking O365 on our Guest Wifi
PaddyNewman replied to kennysarmy's topic in Internet Related/Filtering/Firewall
What DNS servers do you use for Guest. Not seeing a request is typically a DNS failure from my end on a non Smoothwall proxy setup. Can you go on guest, nslookup for http://www.office.com ? Do you get results... -
Smoothwall blocking O365 on our Guest Wifi
PaddyNewman replied to kennysarmy's topic in Internet Related/Filtering/Firewall
Wireshark would be my go to if using a Windows laptop. See where its going, what does a report say though... if you aren't performing HTTPS inspection, that just sounds like something silly, matching a blocked word, blocked URL rather than allowed. You shouldn't really need to use IP ranges as exemptions. -
Exchange SMTP TLS - Do I need to setup 587?
PaddyNewman replied to mscott's topic in Internet Related/Filtering/Firewall
Make sure there is a valid PTR record in public DNS for your advertised mailserver name, otherwise people will get unhappy! It will be held by the people that look after your IP addresses applied to that, not your own public DNS. -
How does it work with DNS over HTTPS? Does it category block these/how does it know Things like DoH and QUIC are just sods, but never seen how one of these clients handles it.
-
How to manage 2 VDSL lines for internet provision
PaddyNewman replied to Ditto's topic in Internet Related/Filtering/Firewall
Draytek will be cheaper than bonding. I looked at bonded ADSL for my home (rural so basically carrier pigeon is faster than the net) and it was more expensive even with the option of buying through my current employer and just paying a man to bond from their end for 30Mb than it was to just pay monthly for Starlink and get a (surprisingly stable) 10Mb backup line through BT. But yeah another vote for Draytek. -
YouTube Modes work in various methods. https://support.google.com/a/answer/6214622 Obvious one is DNS based which you were probably used to in LGfL. The other is Header Rewrite which is what SSL decryption capable filtering can do, which MAY be what they are doing there. Can check it here - https://www.youtube.com/check_content_restrictions Does sound very '2000s' with options for filtering and not having full customisation. Can't see the documents, but I'll shudder if its "set your proxy server address to ..." because we should be well past that these days!
-
youtube subtitles not working, RM filter??
PaddyNewman replied to chazzy2501's topic in Internet Related/Filtering/Firewall
Browser suggests its goes to; hxxps://www.youtube.com/api/timedtext?v=oWFaxHnsDh8&caps=asr&xoaf=5&hl=en&ip=0.0.0.0&ipbits=0&expire=1663881760&sparams=ip%2Cipbits%2Cexpire%2Cv%2Ccaps%2Cxoaf&signature=C7ABDA32D2276E0EA259F14EC9266FDCE47A056B.D6C54A2C2EED49F33EFCB569F0480475D34A0FA4&key=yt8&lang=en&fmt=json3&xorb=2&xobt=3&xovt=3&cbr=Chrome&cbrver=105.0.0.0&c=WEB&cver=2.20220921.00.00&cplayer=UNIPLAYER&cos=Windows&cosver=10.0&cplatform=DESKTOP Specifically looking at the timedtext part, if you decrypt YouTube are you being very specific. Unsure how RM works, but thats the URL of a random PC build video, and appears when I hit the 'cc' subtitle button. -
Filtering for home and children
PaddyNewman replied to Sonic007's topic in Internet Related/Filtering/Firewall
My home is explicit proxy, I know there is a weird way to filter in iOS, but I don't intend to pay for a filtering service as I think I can meet the basic needs locally, and I don't think its offered to home users anyway! I did enquire with a filtering provider for a filtering system for home and the answer was 'no' -
Filtering for home and children
PaddyNewman replied to Sonic007's topic in Internet Related/Filtering/Firewall
I currently do full inspection on my home devices and exempt apple/android core stuff and the heavy lifting like Disney+ and Netflix, but the rest is ripped apart and works OK. Children are children, back in school I just worked my way round things and kids these days... I have seen them, I don't have any myself but plenty of nieces and nephews, but they learn fast and really do just work it out to the point where even I am a little worried! With iPads, the screen scrape stuff can be a pain with Apple being the God of its own world, but you can do certain things. As I say I run full inspection on any wifi based device here and any of the family iPads that kids have access to and I have no issues, but your experiences may differ! That is interesting, does it integrate with Apple iOS/Android/ChromeOS nicely? -
Filtering for home and children
PaddyNewman replied to Sonic007's topic in Internet Related/Filtering/Firewall
As in your own children? Local Pi with squid proxy and keyword / URL filter using e2guardian is how I do it. Mines actually hosted on the net so family are filtered wherever they are. Sure, its not as robust as others as they are constantly learning and industry level, but given the experience I have in filtering, I think I have a decent enough local keyword block list and have various public blacklists I grab from once a week. You can't be 100%, but it definitely works a treat, also allows me to log and report on it when something is not working as intended, can also run local bind and PiHole to stop ads and nasties. I could probably do something different for inside the network to outside, but it works, so no worries. Obviously everyones mileage differs when it comes to this, but something is always better than nothing -
Ideally, fully automatic and nothing needed by the end-user, I imagine everyone has plenty other important tasks! Might be a good feature request to Sophos? I have no contacts within Sophos, however I imagine its as simple as a 'Clear cached certificates' button that simply runs a service/command to clear the folder.
-
Looks to be just SSHing to the XG Chose »5. Device Management Chose »3. Advanced Shell Identified the certificate(s) in /var/certcache/ and removed the cached files (if its just a Linux box, then ls | grep google and find the right one, rm name-of-file) Then went to Protect > Web in the Web Management Interface an clicked Apply on »HTTPS Decryption and Scanning« without changing any setting there
