Jump to content

PaddyNewman

Members
  • Posts

    389
  • Joined

  • Last visited

Everything posted by PaddyNewman

  1. Captive portal with a link to cert and a very clear and obvious statement that you are ripping random peoples traffic apart? Unsure if Aruba has that option for captive portal, but last one I handled had a captive portal redirect on HTTP and gave you a privacy policy and a link to a site that was on HTTP with a link to the cert (was the business own site hosting so http://domain.com/public/cert.crt etc) and they just grabbed from there. If they didn't it would just be a crap experience for them. They switched it off in the end;) We blame Chromebooks.
  2. That will cause very similar problems, if you have multiple addresses going out and a device is going over that constantly, it will ring alarm bells somewhere. I don't know the infrastructure there, but if the option to NAT all your school based traffic to 1 non changing address is possible that would stop the flipping between IPs, load balancing/multiple routes out? However, could be a number of things depending on routing, firewalling or filtering. Depending on the Netsweeper set up, you'll could see various NAT IPs depending if you aren't in explicit modes or full source IP maintaining transparent modes, but likely something for SB to look at rather than poking my nose in too far
  3. Bear in mind ANY Chrome/Android based device is doing chit chat to Big Goog' and when a lovely student/visitor with an android device rocks up with naughty VPN software on there, the device has 2 connection mechanisms... you might have seen them when installing certs, WiFi or VPN and Apps. Its talking home on BOTH of those mechanisms, when one (VPN and Apps) talks on public IP 1.2.3.4 and WiFi talks on 2.4.6.8, Big Goog is suspicious and will likely trigger this. We've demonstrated this, tested and confirmed this is what happens locally, hell of a load of chit chat from Android devices, my Pixel is constantly talking and I mean constantly... I have nothing to hide, but VPNs do, and Google does not like your traffic to be obfuscated or amended in any way so they can't shape those adverts and results. I would also look at that as a possibility, sometimes it isn't even a student, but a visitor/parent/staff member. I see it maybe twice a month over a few thousand schools, reports show odd activity. Given BYOD/Guest and lack of SSL inspection, that is my go to investigation point.
  4. I have no SSL inspection, like I say I am absolutely raw on the net aside from inbound restrictions and I am seeing it, its annoying as there is nothing in the way, its a completely clean browser, no blockers etc...
  5. No fix, I'm raw on the net, I'm getting that for various sites currently
  6. Are they like this? Error 1020 Ray ID: 6da6666daeed549f • 2022-02-08 16:57:58 UTCAccess deniedWhat happened?This website is using a security service to protect itself from online attacks.Cloudflare Ray ID: 6da6666daeed549f • Your IP: xx.xx.xx.xx • Performance & security by Cloudflare
  7. I wouldn't say its bashing, everyone has different ways of working. I will state though, my biggest worry is not the adults on the network, its the kids, I was one and I was a sod in school when it came to IT and they have only got smarter! Adults tend to stay on the right path, kids less so and devote their time to digging round anything that gets in their way! But to answer your queries... Happy to hear about what could make things clearer? We try to make it clear but if there are UI changes that could make things clearer, we can always take a look and see what can be done. So, I've queued up the change to your firewall for the VirginMedia/NTLWorld FQDNs and their associated ports, the word 'secure' means nothing to me personally, you are only as secure as you think you are All email does need those ports open, however some like Office365 and Exchange can be connected via the ActiveSync or Exchange connection over TCP 443, which is open by default, otherwise you'd have no internet at all. Anything is open to abuse, as stated you can tunnel over any of the open ports, but we obviously can't restrict endpoints for 80/443 as thats simple HTTP(S) and we would be stopping your internet access, I don't think schools would like to work on a whitelist only method! My email is always monitored, and I am happy to help if anyone is stuck anywhere relating to any of our services. Support isn't my direct job, but if you are truly stuck and feel something has stalled, always feel free to ping me. Actual direct changes or things that need me to do anything that would affect your school however, I would need a case for audit purposes, but info and basic pointers, I am happy to provide. Meraki rules are needed, we have a default rule for these, I can make note in your support case and we can open the required ports for you to allow the devices to call home when on site if you want.
  8. A rant is all good! Happy to have a chat about it and see if there's something we can do, or even if you can give us some ideas, always game to throw some feedback to the relevant folk! Agreed on Meraki, it's on my list! Any other key items that you haven't mentioned? If you are happy to chat, feel free to buzz me/pm and I'll get my DDI to you, and no, I'm not going to attempt to stop your tunnel, you do you, I would too!
  9. @Koldov you can always drop me a ping on here or call me if you are having issue. We block all ports outbound aside from a handful, otherwise nothing would stop me opening my Pi at home on TCP 993 and tunnel my school machine through it, bypassed the firewall with ease. We open them to known hosts, if you have the server addresses you can send us those and we'll open them. We know the ports needed, that isn't a problem.. pm me the case ref and I'll knock it out for you ASAP. EDIT : Scrap that, found it, lets arrange a time I can reboot it
  10. Recategorised in LGfL/NGfL, thanks for the heads up.
  11. Are you fully decrypting or are you selectively doing so. Also, presumably (I don't know the behind the scenes configs) they have blocked UDP 443 to anywhere (and TCP 443 to 8.8.8.8/8.8.4.4) to prevent QUIC and HTTP/2 stuff, as well as Chromes inane ability to tunnel Google stuff to its own DNS servers over HTTPS for fun... On Chrome, if you type chrome://flags and search for QUIC, set to disable and close/re-open the browser, does it stop it then? You'll see the deny request because its going to send that initial message via TCP, I see it every single day and as such I perma-bin UDP 443 as QUIC is a PITA.
  12. Yes. Very often. I have a start up batch now to force it, but has the WAgent MSI been changed to use WAgent as a service? There is an option in the MSI under the Property table called NS_WAGENT_SERVICE, default is 0, I set this to 1. Its worked on 99% of our machines, however I still use the script in one instance and it just runs the installed EXE with the the WAgent args, works perfectly fine, but its a simple start "" etc. Its been that way for me since like February 2021
  13. Exactly that, well put!
  14. I've used all of them... it truly depends on your needs as no filtering system is perfect and one size does not fit all. For me, Netsweeper does what we need at the scale we need, but I like the usability of Smoothwall, but I really rate the support of Sophos XG and the features. Usage wise, my personal opinion for my 'generic school needs' and usability within my comfort levels are... Sophos is better than Lightspeed Lightspeed is better than SurfProtect Smoothwall is better than Lightspeed Netsweeper is better than Lightspeed Lightspeed is better than Fortigate Obviously its a personal thing and if I was running the full thing, as above I'd be fighting between Sophos, Netsweeper and Smoothwall, depending on what the needs of the school are, SLT are picky and might want x y z reports, techies might want to be super specific within what goes through SSL, what they pick up and where they get stuff from/how they integrate into their core/ADs etc.
  15. I'll drop a contact number in a PM, if we could arrange a time that would be great!
  16. It is categorised as an undisclosed blocked category for us. I won't be changing it personally unless forced by powers above, its like Google Translate, great in theory and super helpful, but its open to misuse... and as a student I used it for that purpose!
  17. Happy to have a chat over the phone if it helps? Readdressing is key, it's a shared platform so if you clash with another school, we can't route you across the WAN, you'd need to NAT to the provided range.
  18. Hiya, 0208 255 5555 option 3 then 1. Just ask for me and they will pass you through.
  19. Do you have any devices on site that appear as a different SB provided public IP? Unsure if they operate the same as us, but all inbound services get their own IP as we 1-2-1 NAT. Worth seeing if it's that or if they can flip your public address quick to test.
  20. Probably worth responding a bit more in-depth when I'm not hustling around a shopping centre for some last minute stuff! I'm happy to discuss certain aspects of logging with you, I see location is West Mids, so our Outside London/NGfL platform I assume, which we recently rebooted so it should be pretty responsive. Let me sort my stuff out today and I'll probably drop a PM with some school specific items if that's ok? But... There are changes coming, I feel our reporting is pretty quick given the size of the files and extraction of said data but if it's not just the time and more the output and the quality of said data, that's another thing
  21. Calendar is free all Monday. Feel free to buzz me then or Tuesday, definitely clear after 9am for both days, happy for our call to be relayed here, also please do feel free to think up and throw some ideas our way, we occasionally entertain them Just to point out the 1st line part. They are our defence between calls and support, if I'm upgrading a school to SSL inspection, I need to be on the ball, so they are essentially defending us from calls, otherwise I'd love to have a direct dial in to help, I appreciate you want your issue fixed asap, me too! Perhaps something I can chat with people about, can't promise anything but I appreciate sometimes we have more technical folk on the phone. I/management also do try to upskill the entry point of calls, our team is constantly learning so if there are skills you think they need, feel free to give me some ideas and I can feed back to their manager who is all for upskilling them.
  22. Plug a dumb switch between LAN and firewalls internal port, leave a machine with a static assigned IP in there looking at Google for DNS (exclude the IP from DHCP obviously) If LAN surfing dies and that laptop dies, its ISP/router problem, send straight to them, its a router/line issue simple as Means you can use the same port without removing your LAN, much easier.
  23. @xicor if you find some time to give me a call, I am around tomorrow and Wednesday from 9am, feel free to give me a buzz to go over these items (this is to all LGfL customers also, if you have a query or idea that we may not have on our ever growing wishlist)
  24. How does your NAT work? I assume you are provided a static address to the net. Is it just yourself? I query as I run a handful of instances and every now and then, from the BYOD LAN (which now has its own NAT rule for this reason...) they get Google captcha, turns out a pesky child had an android device with a VPN. Android talks home from the device using the VPN and also over the non-VPN side, if you capture you'll see the occasional android client check in through the filtering, Google spots that and thinks something is sus with the public IP. We have it in our non-HTTPS inspection networks also, and its instantly recognisable. Worth having a quick look, if its wider spread though then something may need looking at, assuming you are each running your own public NAT and you aren't (hopefully) brought to a core to be NAT'd and share that NAT rule! I appreciate that, thank you!
  25. Are you willing to share to a non-customer what version you are on? I query as I have multiple instances, multiple versions and upcoming upgrades... be keen to know what is affected. Or at least can your Netsweeper support agent reach out to myself also/provide a reference?
×
×
  • Create New...