-
Posts
389 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
Netsweeper - am I being unrealistic?
PaddyNewman replied to sigma's topic in Internet Related/Filtering/Firewall
For me, I didn't like the Smoothwall UI, I didn't like how vague things were and I like to be very clear and specific when I decrypt and don't decrypt, that is where Netsweeper works for me. I use it aggressively though, its literally so flexible, but I can't voice an opinion on the selling/overselling, I personally don't deal with that stage of it, I just 'gotta make it work' which is fine, mostly enjoyable. -
Netsweeper - am I being unrealistic?
PaddyNewman replied to sigma's topic in Internet Related/Filtering/Firewall
Agree 100% on the consistency of it, I know there is a lot of black-art wizardry that happens with website categorisations that I am definitely not knowledgeable in, but some things that look logical don't seem to add up or match. I think the 1 thing I saw on a Smoothwall was the content scanning, so it actually read the page at each visit, but that comes at a processing cost.. -
Netsweeper - am I being unrealistic?
PaddyNewman replied to sigma's topic in Internet Related/Filtering/Firewall
For ref, I am checking another instance which is 'bleeding edge' rather than the live one, I tend to not want to run queries against that as we do indeed change stuff when requested. Looks like they have been switched now? I can investigate if not! @sigma Indeed, they are streaming, but so is YouTube and Vimeo etc etc, our current system doesn't have streaming as a category, it does have Streaming Media however... I still don't feel its the right category. I'd probably be throwing it under questionable/piracy or similar. I do agree with you, it should be snipped before it gets to the school which leads me to... I don't have access to another filtering platform, but it would be good to see a comparison on varied systems to see what is out of line. I should add all I do is check the sites for our clients and customers, not for/with Netsweeper at all, its just the only filtering product I have access to -
Netsweeper - am I being unrealistic?
PaddyNewman replied to sigma's topic in Internet Related/Filtering/Firewall
From my end; http://talk.chat General + Web Chat-200 http://ww2.1primewire.com General + Redirector Page-8144710 http://primewire.live General + Entertainment-200 http://primewire.today General + Entertainment-200 http://primewire.id General + Entertainment-200 You can reclassify within Netsweeper, but those look 'correct' ignoring http://ww2.1primewire.com and the legalities of live streaming movies etc. -
Leased Line Circuit backup
PaddyNewman replied to ITGURU's topic in Internet Related/Filtering/Firewall
I use Starlink as my primary home ISP and have done for for 6-7 weeks now. What I would say is that it can struggle if someone occupies the downstream, be that with Windows Updates or large downloads. I get ~230Mb down and ~50Mb up currently and whilst that is really decent (when my DSL is around 13-16Mb) it does absolutely destroy the connection when I hit any download. Its almost getting to the point where I think I need QoS switching inside to prioritise everything but generic web browsing and downloading as it can crash my teams sessions if I crack on with Windows Updates or even a throttled Steam game (say throttling at 3MB/s) it seems to saturate the signal. It is definitely viable though! I love it, despite the costs for residential! Needs a very clear sight to sky though! -
Schools Broadband/Fortinet - Any Users?
PaddyNewman replied to LeMarchand's topic in Internet Related/Filtering/Firewall
Few days old... I'll give that a test now, awesome! -
Schools Broadband/Fortinet - Any Users?
PaddyNewman replied to LeMarchand's topic in Internet Related/Filtering/Firewall
Agreed, there is something odd with the agent and I know I am not the only one experiencing it! I have it running on a schedule now for our problematic clients but its not a proper workable solution. I think what is irksome with Smoothwall is its too vague and there are too many steps. I like efficiency, its just who I am, Smoothwall felt like I was having to decide 15 times what to do with YouTube or something, I want to allow it, I just press allow now, I don't need to say who or when or where, I know that already. I think it definitely serves a purpose in some places where you want absolutes, but I just can't deal with that But no, you have reminded me I need to prod about the agent again. -
Schools Broadband/Fortinet - Any Users?
PaddyNewman replied to LeMarchand's topic in Internet Related/Filtering/Firewall
SBB will probably answer more specifically about their offering but I do not (personally) rate Fortinet for anything but their hardware stuff, start doing filtering via it and its not a suitable set up for education, other people may disagree, but its definitely pointed towards a business set up than an educational one. If its Netsweeper under the hood of SBB connection, I highly rate it, some hate it, some love it. Once you know how it works its perfectly fine, but as with anything....its got a learning curve and whilst it may not be as robust as something like Smoothwall, its not the cost of Smoothwall. I've had 10 years with it though, so have seen and used it a fair bit! I have also tried all the other major players and for someone who wants to get things sorted fast, nothing has worked better for me than Netsweeper. They also are simple to allow the remote products you want, just allow the URL. Splashtop can be done with 1 entry, or 2 if you don't want to decrypt it etc. The setups I use don't "alert" as its a filtering system, not a monitoring one, but I definitely have set up scheduled reports on certain terms, categories, students at 1 minute intervals. No emails unless they hit the options. There are a few other options to you though... quite a few in fact -
Blocking downloaded games on BYOD
PaddyNewman replied to enjay's topic in Internet Related/Filtering/Firewall
Minecraft tends to need ports. is your firewall actually being a firewall or just ticking the box of 'we have a firewall' Deny anything for students other than HTTP and HTTPS, if they need more, be very specific. -
Sophos XG Firewall V19 Wildcards
PaddyNewman replied to ConTheITGuy's topic in Internet Related/Filtering/Firewall
Does it support regex rather than wildcards? -
Things have changed somewhat, the Head can designate a techy user to make the techy decisions now so its a 1 time sign off, also change requests are just raise it and we'll change it, just need to be a nominated user to do so, maybe you had a much older version of LGfL before the LGfL2 side of things became the common use setup? With the subnet thing, if we can fit you in, we will, but we use 10.x for schools, our hosted/core stuff is 172 ranges and 192 is used elsewhere, so the whole 10.x/8 is for schools. If you dont use that, NAT and do your own filtering/NAT to specific LGfL provided IPs for staff/students etc, you lose the benefit of user based filtering though. We do try to slot you in and re-use though, sometimes a school is already using it and we can't up and lift them! When it comes down to it, re-IP is less than a few hours in a secondary and even less so for a primary, but we do have a finite amount of IPs and we can't just hand out bits and bobs from across the range
-
I did write a decent post but mobile seems to be so buggy! More than happy to chat and go through what you might need if that helps? @Aprice I totally understand, sometimes local control is the way for you, but I've seen some requests that make me worried for the security of schools, so whilst we do need a change request, I feel that's part of the managed service and adding to the protection of schools, your mileage may vary of course
-
We would typically URL block their relay FQDNs and deny TCP/UDP 80+443 to them at the firewall too. Then 17.0.0.0/8 is allowed undecrypted but firewalled to their service ports only.
-
If they read this and are re-issuing...you can just set the datetime to 2019 and manually make a 10/20/30yr cert, they trust them before a certain period. Works fine from this end with random unmanaged Apple devices, does mean the cert looks a lot older, but works so easy win. Does seem weird though as it shouldn't affect admin-added root CAs...
