Jump to content

PaddyNewman

Members
  • Posts

    389
  • Joined

  • Last visited

Everything posted by PaddyNewman

  1. Does Sophos have a cache of certs it's faked up, might be worth clearing that if so?
  2. Real-time scanning can do this, had a customer recently that was seeing 950 upload, but download was crippled to around 100. Turning off anything real-time as a test gave them full speeds.
  3. Not according to your post, it expires today? 2 years 3 month certificate length, that is 800 days on the dot, which sounds like a manually made cert.
  4. For me, I didn't like the Smoothwall UI, I didn't like how vague things were and I like to be very clear and specific when I decrypt and don't decrypt, that is where Netsweeper works for me. I use it aggressively though, its literally so flexible, but I can't voice an opinion on the selling/overselling, I personally don't deal with that stage of it, I just 'gotta make it work' which is fine, mostly enjoyable.
  5. Agree 100% on the consistency of it, I know there is a lot of black-art wizardry that happens with website categorisations that I am definitely not knowledgeable in, but some things that look logical don't seem to add up or match. I think the 1 thing I saw on a Smoothwall was the content scanning, so it actually read the page at each visit, but that comes at a processing cost..
  6. For ref, I am checking another instance which is 'bleeding edge' rather than the live one, I tend to not want to run queries against that as we do indeed change stuff when requested. Looks like they have been switched now? I can investigate if not! @sigma Indeed, they are streaming, but so is YouTube and Vimeo etc etc, our current system doesn't have streaming as a category, it does have Streaming Media however... I still don't feel its the right category. I'd probably be throwing it under questionable/piracy or similar. I do agree with you, it should be snipped before it gets to the school which leads me to... I don't have access to another filtering platform, but it would be good to see a comparison on varied systems to see what is out of line. I should add all I do is check the sites for our clients and customers, not for/with Netsweeper at all, its just the only filtering product I have access to
  7. From my end; http://talk.chat General + Web Chat-200 http://ww2.1primewire.com General + Redirector Page-8144710 http://primewire.live General + Entertainment-200 http://primewire.today General + Entertainment-200 http://primewire.id General + Entertainment-200 You can reclassify within Netsweeper, but those look 'correct' ignoring http://ww2.1primewire.com and the legalities of live streaming movies etc.
  8. I use Starlink as my primary home ISP and have done for for 6-7 weeks now. What I would say is that it can struggle if someone occupies the downstream, be that with Windows Updates or large downloads. I get ~230Mb down and ~50Mb up currently and whilst that is really decent (when my DSL is around 13-16Mb) it does absolutely destroy the connection when I hit any download. Its almost getting to the point where I think I need QoS switching inside to prioritise everything but generic web browsing and downloading as it can crash my teams sessions if I crack on with Windows Updates or even a throttled Steam game (say throttling at 3MB/s) it seems to saturate the signal. It is definitely viable though! I love it, despite the costs for residential! Needs a very clear sight to sky though!
  9. Depends on the VoIP system, can use mine from anywhere, but its an authenticated cloud setup. If its an older one that relies on you supplying the source public address, then it will be a problem.
  10. Few days old... I'll give that a test now, awesome!
  11. Agreed, there is something odd with the agent and I know I am not the only one experiencing it! I have it running on a schedule now for our problematic clients but its not a proper workable solution. I think what is irksome with Smoothwall is its too vague and there are too many steps. I like efficiency, its just who I am, Smoothwall felt like I was having to decide 15 times what to do with YouTube or something, I want to allow it, I just press allow now, I don't need to say who or when or where, I know that already. I think it definitely serves a purpose in some places where you want absolutes, but I just can't deal with that But no, you have reminded me I need to prod about the agent again.
  12. SBB will probably answer more specifically about their offering but I do not (personally) rate Fortinet for anything but their hardware stuff, start doing filtering via it and its not a suitable set up for education, other people may disagree, but its definitely pointed towards a business set up than an educational one. If its Netsweeper under the hood of SBB connection, I highly rate it, some hate it, some love it. Once you know how it works its perfectly fine, but as with anything....its got a learning curve and whilst it may not be as robust as something like Smoothwall, its not the cost of Smoothwall. I've had 10 years with it though, so have seen and used it a fair bit! I have also tried all the other major players and for someone who wants to get things sorted fast, nothing has worked better for me than Netsweeper. They also are simple to allow the remote products you want, just allow the URL. Splashtop can be done with 1 entry, or 2 if you don't want to decrypt it etc. The setups I use don't "alert" as its a filtering system, not a monitoring one, but I definitely have set up scheduled reports on certain terms, categories, students at 1 minute intervals. No emails unless they hit the options. There are a few other options to you though... quite a few in fact
  13. Minecraft tends to need ports. is your firewall actually being a firewall or just ticking the box of 'we have a firewall' Deny anything for students other than HTTP and HTTPS, if they need more, be very specific.
  14. Does it support regex rather than wildcards?
  15. Things have changed somewhat, the Head can designate a techy user to make the techy decisions now so its a 1 time sign off, also change requests are just raise it and we'll change it, just need to be a nominated user to do so, maybe you had a much older version of LGfL before the LGfL2 side of things became the common use setup? With the subnet thing, if we can fit you in, we will, but we use 10.x for schools, our hosted/core stuff is 172 ranges and 192 is used elsewhere, so the whole 10.x/8 is for schools. If you dont use that, NAT and do your own filtering/NAT to specific LGfL provided IPs for staff/students etc, you lose the benefit of user based filtering though. We do try to slot you in and re-use though, sometimes a school is already using it and we can't up and lift them! When it comes down to it, re-IP is less than a few hours in a secondary and even less so for a primary, but we do have a finite amount of IPs and we can't just hand out bits and bobs from across the range
  16. I did write a decent post but mobile seems to be so buggy! More than happy to chat and go through what you might need if that helps? @Aprice I totally understand, sometimes local control is the way for you, but I've seen some requests that make me worried for the security of schools, so whilst we do need a change request, I feel that's part of the managed service and adding to the protection of schools, your mileage may vary of course
  17. I would suggest you decrypt it and if it breaks remove specific ones that break. Without actually decrypting all your content, its always going to give you spurious results like this. Google can be fickle with this though, so make sure QUIC and the like are also denied.
  18. Try blocking what I threw above and if SBB can confirm it's blocking it but you can still get there, I'd be very interested to see!
  19. It's not Netsweeper, otherwise we would be in big trouble! Do you have the ability to amend your firewall as I suggested a few posts above? I'd be keen to see what's actually going on as I know 100% it's not going to be Netsweeper if the reports show denied, or worse, doesn't show the request.
  20. We would typically URL block their relay FQDNs and deny TCP/UDP 80+443 to them at the firewall too. Then 17.0.0.0/8 is allowed undecrypted but firewalled to their service ports only.
  21. Indeed, are you using LGfL @LostITEnthusiast - if so feel free to PM me!
  22. If they read this and are re-issuing...you can just set the datetime to 2019 and manually make a 10/20/30yr cert, they trust them before a certain period. Works fine from this end with random unmanaged Apple devices, does mean the cert looks a lot older, but works so easy win. Does seem weird though as it shouldn't affect admin-added root CAs...
  23. I'd be keen to actually see what is configured as Safe Search should be enforced, as long as its in the denied category list. It sounds like something is misconfigured as the problems you have are simply resolved with Netsweeper, especially category stuff..
×
×
  • Create New...