-
Posts
389 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
Student Smoothwall Bypass For Youtube
PaddyNewman replied to TriggerHappyUK's topic in Internet Related/Filtering/Firewall
Just block UDP 80 + 443 on your firewall, be specific when opening UDP 80 and 443 to other locations. If you can FQDN, makes it easier, but bulk deny on UDP 443 is all we do, if you NEED it, provide the destination etc. -
This sounds like QUIC, if its not got the certificate that you are signing with and shows the normal MS one, which apparently today is the Microsoft RSA one, then its bypassing filtering and thats a firewall problem which probably needs nipping ASAP as its going to become a huge problem. Can probably check by running wireshark on a machine that gets the ability to access stuff without the certificate and see if its connecting via TCP or UDP.
-
Sorry, my filter bypass is not the netsweeper one, I'd never touch that list, its just bypassing filtering in general. Missing certs should give you errors, if you aren't getting errors then its using the normal cert assigned which usually means its bypassing decryption or not using TCP 443. Do you have a global deny on UDP 80 and 443 on your firewall? I would also block https://dns.google within Netsweeper and deny 8.8.8.8 and 8.8.4.4 on TCP 443 on the firewall, just because its an easy way to walk round Netsweeper.
-
That sounds a little fishy to be honest! Be good if you can replicate. I've only seen things walk past Netsweeper when either QUIC was used or the decrypt scheme wasn't in place, but sounds like it is as you can get results from other search engines. The fact you see nothing for the Bing images which are from bing.net I think, screams filter bypassing to me...
-
Are they actually decrypting Bing? Its classified as a search engine (or should be) and would need to be decrypted fully unless you DNS bodge it. We amend it in the core because education, might as well lock the door, but if its set to search engine and safe search+search keywords are denied as categories, then that 'should' do that. Just checked my side and its listed as; so unless its changed on your end?
-
I do feel you may have had a baste taste with Netsweeper, but it all depends on how its set up/whats being used/support etc - I won't ever speak ill of anyone, but Netsweeper "under the hood" is a challenge when its not by the book, and its rarely by the book in any instance, everyone has different needs. I deal with it every single day and I actually love it, everything has its faults, even the FortiGate side of things aren't perfect. For perspective without giving anything away I had a case with Netsweeper and Fortinet for the same problem with a specific application going through filtering, Fortinet haven't fixed it, Netsweeper fixed within 3 hours. This was in 2017, and its STILL not fixed Obviously personal experience can sway you, but if you get the option to try Netsweeper with another provider/different variant, I would give it a go. Our core one has been running since 2010/2011 with minimal problems! To the original question though... if you move away from us you'll need to move your domain if we host DNS for it and grab a copy of your rules on the deployment page. I won't attempt to talk you out of it as I don't work for LGfL, but is there something specific making you want to move / something that is missing that you really need? Feel free to fire a PM if you'd rather not advertise!
- 8 replies
-
- lgfl
- mis support
-
(and 1 more)
Tagged with:
-
With our customers its both ways, same speed at the same time. The numbers mean means you are 300Mbps over a 1Gbps bearer. A leased line is typically both ways, same speed, same time, however can vary from supplier to supplier. We can apply policies to traffic in either direction, so worth checking with your provider as it can vary.
-
Indeed, something I had issues with before was the Teamviewer app. The requests came through as unauthenticated, but all other user requests from the same machine were the IP and username, Teamviewer was just IP. Some things can't respond to NTLM requests like that. Removed that mess when we got rid of an explicit proxy setup!
-
Smoothwall filtering issue
PaddyNewman replied to chekmate1984's topic in Internet Related/Filtering/Firewall
It is more than likely this ^ QUIC is a royal PITA, you can tell by capturing and seeing it in Wireshark, you can turn off in Chrome (chrome://flags - search for QUIC) or just binning it at the firewall as suggested, which works if you are using non Chrome browsers. it'll fall back to standard TCP. -
Setting up VPN with Unifi USG Pro 4
PaddyNewman replied to hallb15's topic in Internet Related/Filtering/Firewall
I would always ask why they NEED a VPN, and why a TS or similar is not suitable. VPNs, unless you lock down ports, are very open and can be fairly relaxed at most times. A VPN in with all ports... I'm sorta not keen on that unless you know what you are doing and you know the machine is clean. For clients I look after at least, they have access to the 'curriculum LAN' VLAN and at that point they only have RDP ports enabled on the VPN, so they must RDP via name to their desktop, that is it. The desktops are locked down to the user that uses it, not really useful for hot desking staff, but lets face it, people use the same machine day in day out. Do you really need a hole into your network right now? But thats just cynical me;) -
Thanks @john - I did see on the PDF I got my colleague, seems to be making one day a bit longer! We all know the smart ones go Friday for that covert half day ...sadly I'll be noticed but hey!
-
Confirmed to be there Friday from 9.30am till they boot us out / 6pm unless techies hold me hostage! Please feel free to bring all queries about the LGfL filtering/firewalling/what you would like to see/tell me how this works etc, more than happy to go into detail and also keen to hear what you need and if we can do it.
-
In a school, I would want 100% accountability. Goes for business environments too, but school has a fair bit of safeguarding around it. Lets say for absolute arguments sake, you have someone with a less than desirable link on their end that triggers an IWF/Home office alert, it happens. The ISP and yourselves are likely going to be asked a few questions... one of those would be 'who went to this'. I'd not want to be the one to say I don't know! In short, whats wrong with a first and last name visitor pass. Depending on the wifi/sign in system at the school, you could integrate that with a 1 time use QR/user+pass which links to that user and boom, user tied to IP, date and time in your logs which you obviously back up and maintain within GDPR regulations. When someone comes knocking, I'd want the answer to be available because they do knock! Thats a worst case scenario in my eyes, especially when it comes to any child protection/RIPA requests! As above though, a QR to a captive portal with first/last/number or something... they could lie, but you've "done your bit"
-
No traceability or accountability, its a hard no from me.
-
I am potentially making an appearance on Friday for all the LGfL (and non LGfL!) schools to ask questions to a techie, on the AdEPT Education stand... I intend to mingle with as many as I can so please do come say hi I welcome any and all, especially if you want to tell me where we can do better
-
Sounds like they need to think about their hosting locations
-
79.133.176.212 belongs to the Zhejiang Taobao Network ASN, as does their cdn (west.cdn.mathletics.com - 47.246.44.225) so they definitely do use a random cdn that floats around Russia and the US, but also China - TAOBAO also owns/supports Alibaba.com I'm glad they know where they are hosting their data...
-
Langogo Translation device
PaddyNewman replied to bigstan48's topic in Internet Related/Filtering/Firewall
Call in to the support team and ask for me when you are able to reboot the device or similar, I'll get you running (if you haven't already)
