Jump to content

PaddyNewman

Members
  • Posts

    389
  • Joined

  • Last visited

Everything posted by PaddyNewman

  1. I've never really seen any Meraki kit outside of MX / WiFi stuff, personally I'd be wanting a proper filtering item and firewall, but not sure of your scenario etc. Senso should be decrypting and stopping the refresh also, so that would be a mild concern for me but something to potentially think about.
  2. I would recommend getting a web filter that does decrypt, otherwise you can't really meet safeguarding requirements. Having some form of MITM means you can't beat a reset, unless the proxy is useless, as it's the one who makes the connection on your behalf, can't be served the wrong cert back and it's likely denied before the connection is even made at the other end. Plus, you cant really filter without inspection. That's the worst bit.
  3. Its to do with ciphers and some proxies when using MITM throwing ciphers that are unexpected/not what the browser initially wanted to connect with. Weird, must have toggled something last week.
  4. Are you decrypting traffic? If not, you only have to beat the RST packet which F5 can do if you hammer it. It was a weird bug raised a long time ago but not with Meraki, more Netsweeper and even then, an old version.
  5. Can you see the hold-down settings? Unsure if your ASA is like mine, but show threat-detection services has a hold-down feature, I can't force mine to break as I have turned all that off, but perhaps when the device wakes up/tries to re-establish it just fails and marks them as dodge?
  6. Hardcoded proxy with saved creds on a device/application that needed proxy settings?
  7. WAN interface MTU difference? I've seen weird stuff recently with MTU. Perhaps jumping the gun a bit but check to see if the old one is configured slightly differently.
  8. What TLS errors do you get? I thought most expo-e lines were just DIA and you ran your own firewall, that was the instance at some schools we used to support, the primaries went to a hosted fw but the secondaries had their own on prem firewall. I wonder, do you get the same TLS errors on non managed devices, mobile phone/BYOD for ex?
  9. Got any logs/URLs attempted for vpns? Do they tie to byod/users mobiles. Rise of vpns for 'reasons' will be a factor in captchas which will likely rise when term starts...
  10. Shortly followed by the worldwide Starlink outage. Times are good.
  11. Starlink would work if you've got clear sky. Just make sure you disable the WiFi as it's not IWF/CTIRU compliant.
  12. That is ECH as far as I can see, I recognise the domain from a support case. https://www.nslookup.io/domains/www.arealme.com/dns-records/https/
  13. Just a heavy user to be honest, lots of downloads, a heck load of streaming. Game updates are 10s of gigs a pop, it eats data fast. This month I look to have used 3.1TB according to my router but 3.5TB according to my usage counter in grafana so...it's 3.something with a week left. Id be upset if that cap spreads to residential!
  14. I would assume this is business Starlink? I average 5-8TB a month on home usage and I've not been restricted, very annoying that Starlink did change this though and can appreciate the problem it puts you in. Weird that non personal ones are being targeted but I guess business = you have more money = we'll take it.
  15. Technically it is internal, its an internal server talking to another. You can limit sources on Windows firewall and remove NLA, problem with NLA and a remote source such as F2R, you are required to store credentials.. which feels a bit worse to me!
  16. I will take a look, but 2 things break that RDP via F2R, NLA enabled or Windows firewall can whitelist the sources to lock it down more if you want. Afraid Cyber Essentials requirement forced the update, it had a serious CVE which fails Cyber Essentials. Have heard some devices getting in a fiddle though when non-admin!
  17. Thanks, can see the problem, will update the support case then you are welcome to feed it back here if you wish
  18. Thanks, I've got that. Can you double click the failed loading files (the every-logo_sm.png) would be a good one to try and load.
  19. The failure to load "https://auth.every.education/images/every-logo_sm.png" is weird. Can you DM me the case ref so I know the school and will check some logs.
  20. Developer tools > Network. What's failing to load? Got a case, I'll look at it for you.
  21. Worth trying this on your browser. Open dev tools > Network > on the table, right click the header row and add protocol. In the same tab, go to https://cloudflare-quic.com and see if it says h3, if it does, QUIC is enabled and you have more problems than Google safe search if not, its not QUIC or http/3 enabled.
  22. Trace route to the IP from the school, then trace via a different source IP. 9/10 its going to be them blocking you at the hop before. If your ping works from another public IP (mobile hotspot etc) then i'd bet it is that.
  23. I'm not a Sophos user or aware of prices so my presumed price point was that it'd higher than £1500/1800 for a 10G Forti appliance and 3 years FortiCare and FortiGuard licencing. I won't probe your practices, but it sounds like you experience similar requests and try to push them down the right path too! In terms of small or even medium primaries with little to no IT, managed services really help them and stop them falling into the voids, but if I was a techy in my own school at primary level I'd have a FortiGate as the firewall, personally
×
×
  • Create New...