Jump to content

PaddyNewman

Members
  • Posts

    390
  • Joined

  • Last visited

Everything posted by PaddyNewman

  1. Can the smoothwall not be configured as a transparent in-line? I'd expect your Cisco to have all VLANs and have a static route of 0.0.0.0/0 to your actual next hop, with your next hop having a "schools network via your core" route to get traffic back, the MAC of which can be learnt through a transparent bridge. I would imagine thats a basic feasible item with Smoothwall. It can just filter on the line, didn't know they enforced some routing on there? If the Smoothwall needs to route, create a new VLAN on your end on a /30, your IP in one, the smoothwall in another, route between yourselves and have the Smoothwall route your school ranges back and default route to next hop. it either is your LAN or next hop, 1 single route in and 1 route out.
  2. How I would do it is for my IP policies, so the base level, dont decrypt Google with the decrypt://www.google.com or decrypt://google.com to cover the lot, then the policy that your Chromebooks get authenticated against (via the extension assuming you are using that?) You decrypt www.google.com again, so the exemption is only pre authentication. If you aren't using the chromebook agent, this would save you for that. I dont want to tread on many toes as this is likely a competitors Netsweeper, but thats how we manage that side of Chromebooks, agent, no syncing of users, just push chromebooks to the policy of choice via the agent config. This is the list https://support.google.com/chrome/a/answer/6334001?hl=en&ref_topic=3504941#zippy=%2Cenrollment%2Cauto-updates%2Cchromeos-sign-in Googleapis is another domain that we do not decrypt in general, breaks a lot. Oh and the decrypt://google.com is an Allow entry to stop decryption and Denied to enforce it.
  3. So you weren't secrypting Google searches by default? There is a big list of dont decrypt these by Google outside of *.google.com one, ill see if I can find it. I know www. and accounts. absolutely hate it on transparent mode.
  4. Obviously you'll want to decrypt www. Because searches, but for the initial login, if you remove that for a test device and log in, you can decrypt again after. Its finding the way to not decrypt that until you have authenticated. We do it a different way here but its still netsweeper under the hood.
  5. Are you explicit proxy or transparent? Transparent doesn't like you decrypting www.google.com or accounts.google.com and it will just loop round. You don't need to exclude, but you do need to not decrypt when a user is not logged in (and set the client expiration for something like 3-5 mins refreshing every 2)
  6. Not suggesting they wouldnt have looked but theres not a silly cron job going on outside of work hours?
  7. Its phones and VPNs, always is. If you have multiple public addresses, put your BYOD on a different public IP to your clean network and let them ruin it for themselves and not the school overall
  8. If you need more, we can look at providing more btw, just reach out and we can have a look Thanks all for the LGfL support!
  9. The agent is for on prem, all traffic with the agent will follow your basic route to Internet. Its just a basic auth item, only tells the username, won't govern the traffic. Client filter is what you'd need, still Netsweeper, your ISP might provide that.
  10. I've got a Mac, ill test when im working tomorrow. What are you seeing exactly and I'll try to replicate. Chances are we can do very little, but id rather see first and confirm after. If you dm me your case I can reference it.
  11. Your other school thats all fine, does that have the same firewall, I would assume fortigate and different vdom but the same physical hardware? The lines, are they presented on prem to a single router and is there any qos on the router (assuming its just an NTU/router on prem with 2 feeds in) Unsure what to suggest without seeing captures and the like, it just sounds like theres a problem that ISP and VoIP company need to lock together with, captures and debug on sip to see what's going on. Raw sip and rtp captures usually give you significant info, unless SIPS then...ugh.
  12. Is your firewall on prem? Packet capture not giving you any hints?
  13. What does a UDP iPerf give you? I have seen previously on a specific connection that was ~27ms going to our DC for iPerf was hitting 550Mbps constant, never higher. A change of traffic path bringing that down to 15/16ms gave us the full banana. UDP iPerf seems to show the full speed, but TCP being the full handshake, window scaling, seeing what it can do over that connection, it will see limitations. Odd SFTP is fine though.
  14. Hopefully we aren't one of the big 2 with downtime - I would hope we keep our downtime to an absolute minimum and that it rarely affects customers! Button pushed by the way, should be working now (it was well tested also...😉)
  15. I mean, reach out and I'll see what we can do in SchoolProtect, theres many ways to peel an orange.
  16. Thanks @sigma @networkmangler drop me a message, I can get this looked in to for you.
  17. Id potentially be blocking the mask addresses for the relay if you have a domain whitelist. It will play havoc with various bits.
  18. My fridge, ring, alexa, govee, blink cams and my random alibaba light controllers for the garden are all on an IoT network which has no access to my other LANs, and I have opened the firewall outbound as its just a hassle to maintain. I WFH so I split all this off years ago and keep my work machine split from everywhere, but I hate IoT with a passion and hate doing loads of rules, so just shoved em on their own network away from the home and work stuff, but its anything that is install and I never touch. If I need to touch or use it, its on my home network, but I tend to know what its doing and its off if I am not using etc. I don't think its something many care about, but I don't like the amount of noise on the network and the amount they just talk out to random folk.
  19. would also check you didn't incorrectly add an allow for icloud.com somewhere, that will allow the relay to just work and is suggested by Apple and some MDMs to just whitelist that domain.
  20. @TLARWise Yeah I can help, ping me a message with your school name/dfe code and IP of your paxton kit I will check for you. Thanks @Zoom7000
  21. I've had odd heat and airlock failures with dodgy thermostats and broken filler caps. I was convinced my water pump was leaking on my old Seat, but it was when pressurised it was almost steaming out of the filler cap. That's my instant go to now.
  22. If you are an LGfL school, you might be entitled to HomeProtect. Even if you aren't we can probably quote you for it, it's Netsweeper and you'd get access to manage it etc.
  23. I personally have never dealt with one for filtering, but given non EFG / UDM pros barely handle layer 3 without collapsing, I'd not add inspected traffic and vpns to one. I feel you need a filtering engine, dedicated but if kit to be close to compliant. There's a lot of half baked efforts in firewall/gateway devices that does not really match what schools need. At a push, a fortigate does, but it's as flexible as steel.
  24. Do you have an edu provider or are you just getting a line from someone like BT? If it was an edu provider, I would imagine they'd be open about issues / you'd hope. I like trying to sort these sorts of problems with customers so its a shame they gave you the run around!
  25. Where do trace routes go to those IPs? Does one take a weird route?
×
×
  • Create New...