-
Posts
390 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
Routing issues - Layer 3 switch & Smoothwall
PaddyNewman replied to mikkydoos's topic in Internet Related/Filtering/Firewall
Can the smoothwall not be configured as a transparent in-line? I'd expect your Cisco to have all VLANs and have a static route of 0.0.0.0/0 to your actual next hop, with your next hop having a "schools network via your core" route to get traffic back, the MAC of which can be learnt through a transparent bridge. I would imagine thats a basic feasible item with Smoothwall. It can just filter on the line, didn't know they enforced some routing on there? If the Smoothwall needs to route, create a new VLAN on your end on a /30, your IP in one, the smoothwall in another, route between yourselves and have the Smoothwall route your school ranges back and default route to next hop. it either is your LAN or next hop, 1 single route in and 1 route out. -
Netsweeper, Entra and Chromebooks
PaddyNewman replied to snagrat's topic in Internet Related/Filtering/Firewall
How I would do it is for my IP policies, so the base level, dont decrypt Google with the decrypt://www.google.com or decrypt://google.com to cover the lot, then the policy that your Chromebooks get authenticated against (via the extension assuming you are using that?) You decrypt www.google.com again, so the exemption is only pre authentication. If you aren't using the chromebook agent, this would save you for that. I dont want to tread on many toes as this is likely a competitors Netsweeper, but thats how we manage that side of Chromebooks, agent, no syncing of users, just push chromebooks to the policy of choice via the agent config. This is the list https://support.google.com/chrome/a/answer/6334001?hl=en&ref_topic=3504941#zippy=%2Cenrollment%2Cauto-updates%2Cchromeos-sign-in Googleapis is another domain that we do not decrypt in general, breaks a lot. Oh and the decrypt://google.com is an Allow entry to stop decryption and Denied to enforce it. -
Netsweeper, Entra and Chromebooks
PaddyNewman replied to snagrat's topic in Internet Related/Filtering/Firewall
So you weren't secrypting Google searches by default? There is a big list of dont decrypt these by Google outside of *.google.com one, ill see if I can find it. I know www. and accounts. absolutely hate it on transparent mode. -
Netsweeper, Entra and Chromebooks
PaddyNewman replied to snagrat's topic in Internet Related/Filtering/Firewall
Obviously you'll want to decrypt www. Because searches, but for the initial login, if you remove that for a test device and log in, you can decrypt again after. Its finding the way to not decrypt that until you have authenticated. We do it a different way here but its still netsweeper under the hood. -
Netsweeper, Entra and Chromebooks
PaddyNewman replied to snagrat's topic in Internet Related/Filtering/Firewall
Are you explicit proxy or transparent? Transparent doesn't like you decrypting www.google.com or accounts.google.com and it will just loop round. You don't need to exclude, but you do need to not decrypt when a user is not logged in (and set the client expiration for something like 3-5 mins refreshing every 2) -
Not suggesting they wouldnt have looked but theres not a silly cron job going on outside of work hours?
-
Broadband Recommendations
PaddyNewman replied to 6Foot3's topic in Internet Related/Filtering/Firewall
If you need more, we can look at providing more btw, just reach out and we can have a look Thanks all for the LGfL support! -
LGfL - YouTube Ads and Macs
PaddyNewman replied to Bankesy's topic in Internet Related/Filtering/Firewall
I've got a Mac, ill test when im working tomorrow. What are you seeing exactly and I'll try to replicate. Chances are we can do very little, but id rather see first and confirm after. If you dm me your case I can reference it. -
Schools Broadband and Xelion
PaddyNewman replied to gpjt's topic in Internet Related/Filtering/Firewall
Your other school thats all fine, does that have the same firewall, I would assume fortigate and different vdom but the same physical hardware? The lines, are they presented on prem to a single router and is there any qos on the router (assuming its just an NTU/router on prem with 2 feeds in) Unsure what to suggest without seeing captures and the like, it just sounds like theres a problem that ISP and VoIP company need to lock together with, captures and debug on sip to see what's going on. Raw sip and rtp captures usually give you significant info, unless SIPS then...ugh. -
Schools Broadband and Xelion
PaddyNewman replied to gpjt's topic in Internet Related/Filtering/Firewall
Is your firewall on prem? Packet capture not giving you any hints? -
WAN File Transfer Speeds
PaddyNewman replied to ITGURU's topic in Internet Related/Filtering/Firewall
What does a UDP iPerf give you? I have seen previously on a specific connection that was ~27ms going to our DC for iPerf was hitting 550Mbps constant, never higher. A change of traffic path bringing that down to 15/16ms gave us the full banana. UDP iPerf seems to show the full speed, but TCP being the full handshake, window scaling, seeing what it can do over that connection, it will see limitations. Odd SFTP is fine though. -
Hopefully we aren't one of the big 2 with downtime - I would hope we keep our downtime to an absolute minimum and that it rarely affects customers! Button pushed by the way, should be working now (it was well tested also...😉)
-
Emails flagged as SPAM
PaddyNewman replied to networkmangler's topic in London Grid for Learning (LGfL)
Thanks @sigma @networkmangler drop me a message, I can get this looked in to for you. -
EE WiFi Calling - IP Ranges
PaddyNewman replied to Zoom7000's topic in Internet Related/Filtering/Firewall
Id potentially be blocking the mask addresses for the relay if you have a domain whitelist. It will play havoc with various bits. -
My fridge, ring, alexa, govee, blink cams and my random alibaba light controllers for the garden are all on an IoT network which has no access to my other LANs, and I have opened the firewall outbound as its just a hassle to maintain. I WFH so I split all this off years ago and keep my work machine split from everywhere, but I hate IoT with a passion and hate doing loads of rules, so just shoved em on their own network away from the home and work stuff, but its anything that is install and I never touch. If I need to touch or use it, its on my home network, but I tend to know what its doing and its off if I am not using etc. I don't think its something many care about, but I don't like the amount of noise on the network and the amount they just talk out to random folk.
-
EE WiFi Calling - IP Ranges
PaddyNewman replied to Zoom7000's topic in Internet Related/Filtering/Firewall
would also check you didn't incorrectly add an allow for icloud.com somewhere, that will allow the relay to just work and is suggested by Apple and some MDMs to just whitelist that domain. -
LGFL and Paxton Entry App
PaddyNewman replied to TLARWise's topic in London Grid for Learning (LGfL)
@TLARWise Yeah I can help, ping me a message with your school name/dfe code and IP of your paxton kit I will check for you. Thanks @Zoom7000 -
UK VW Golf Mk7 2.0 TDI – Heating Issue & Diagnostic Advice
PaddyNewman replied to ranj's topic in General Chat
I've had odd heat and airlock failures with dodgy thermostats and broken filler caps. I was convinced my water pump was leaking on my old Seat, but it was when pressurised it was almost steaming out of the filler cap. That's my instant go to now. -
If you are an LGfL school, you might be entitled to HomeProtect. Even if you aren't we can probably quote you for it, it's Netsweeper and you'd get access to manage it etc.
-
I personally have never dealt with one for filtering, but given non EFG / UDM pros barely handle layer 3 without collapsing, I'd not add inspected traffic and vpns to one. I feel you need a filtering engine, dedicated but if kit to be close to compliant. There's a lot of half baked efforts in firewall/gateway devices that does not really match what schools need. At a push, a fortigate does, but it's as flexible as steel.
