-
Posts
389 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
On-Premise firewall alternative
PaddyNewman replied to discoveranother's topic in Internet Related/Filtering/Firewall
FortiGate is what I'd have. I don't know the cost of Sophos firewalls but I'd presume costly. FortiGate for basic school firewalling and perhaps a bit of filtering is more then enough for primaries. A firewall, regardless of features, will have some faults somewhere, nothing is perfect. Keeping items updated is key, but updates contain exploits, need another patch etc. happens to Cisco, happens to Fortinet, probably somewhere at sometime a fault was found with Sophos/Smoothwall etc. The biggest flaw in firewalls from my side is relaxed rules. They are more costly and destructive than a potential fault with a potential service within a firewall. I've seen plenty of any source any destination on random ports, or inbound 3389 from the world, those to me are the scariest thing, not a minor weakness in something that's known and patchable. Obviously I speak for myself, but bad rules and bad filtering are the things I see often enough to make me consider giving up IT. -
I'm not in a position to give the absolute correct statement so don't take my word for it, but its going to be the same as SBB above. Our DCs are the same (in terms of redundancy/have alternative power sourcing etc) but you do have items in the middle between DC and your presentation, the national networks, peering partners, altnets, or even aggregation nodes - they have different recovery plans and may not be as resilient as a datacentre in terms of size of generator as their loads are lower on the whole but also their downtime is expected to be for maintenance or upgrades, not just full failure..
-
No problems
-
Failure decrypting gd-games-in.s3.eu-west-1.amazonaws.com Added and tested with the IT Lead, looks to be OK.
-
Does the support ticket end in 416? If so, be good to know the source IP and time.
-
Made a quick change, let me know if thats all OK
-
I have found the support case @XiJ so I will jump back in.
-
Happy to look, ping me your school/DFE code in private messages and I'll take a looksies. I recognise the domain.
-
Chrome - blocking internal IP addresses
PaddyNewman replied to ITGuyNW's topic in Internet Related/Filtering/Firewall
GPO firewall rule to drop all private addresses apart from your own. Purposely put null routes on your WiFi if they are doing via mobile or force client isolation. -
Cisco ASA not working after reboot
PaddyNewman replied to Sheridan's topic in Internet Related/Filtering/Firewall
I dealt with FortiGates when they started to introduce their web filter. My support case from 2017 closed with 'no fix' and I think it's still the case to this day. Their protocol detection leaves a lot to be desired. Their filter itself has got better over the years, I still don't personally believe it's fit for education but they have come on leaps and bounds since 2017, it used to be almost unusable! -
Cisco ASA not working after reboot
PaddyNewman replied to Sheridan's topic in Internet Related/Filtering/Firewall
You could use Netsweeper as the firewall, but you'd be on iptables or similar and it's not exactly user friendly. But yes 100% budgets and also supporting of said item often becomes the pinch point! -
Cisco ASA not working after reboot
PaddyNewman replied to Sheridan's topic in Internet Related/Filtering/Firewall
For me, personally, there has never been a good firewall that also was a good filter. I think Smoothwall is probably closest to the best you could get, but I feel a firewall should be its own entity, it should do the job of yes/no, not have an alternative role to play. Obviously it's my preference though, everyone's different. -
Cisco ASA not working after reboot
PaddyNewman replied to Sheridan's topic in Internet Related/Filtering/Firewall
Assuming you enabled and it's all still the same password. Only got one boot image on there? The change to SSH key requirements makes it feel like it's gone to an older software, I got the same from my 5510 when I forgot to remove the old bin file. Without seeing it, you never know what's gone on so I am just guessing -
Filtering Interactive Boards?
PaddyNewman replied to Driftingashore's topic in Internet Related/Filtering/Firewall
Reserve them/vlan them off, set them to student+YouTube via their IP? Probably the quickest method. -
Smoothwall not blocking https sites
PaddyNewman replied to Sheridan's topic in Internet Related/Filtering/Firewall
Why not just hard block UDP 80 and UDP 443? Open to the destinations you need rather than the world (I would assume people block those ports by default anyway?) -
Smoothwall not blocking https sites
PaddyNewman replied to Sheridan's topic in Internet Related/Filtering/Firewall
100% would allow to only TCP80/443 via the filter and DNS via a service that scrubs ECH, not Google DNS, not quad9, but ideally your own internal one that you control. Easiest way out is a relaxed firewall and whatever DNS. For all other ports, please see your nearest 4G mast. -
Smoothwall - Allow remote management
PaddyNewman replied to snagrat's topic in Internet Related/Filtering/Firewall
Whilst it's possible, there are fewer things I'd expose to the internet than the focal security point of my network. Note the need to risk assess inbound connections. That said, if it was just your filter and you can live with it being Ddos'd... -
Ruth Miskin New Video Domain
PaddyNewman replied to JonnyAlpha's topic in Internet Related/Filtering/Firewall
I would assume the Smoothwall supports referrer header, it seems to support most things. That does away with allowing loads of URLs, if it comes from ruthmiskin.com etc, it allows the content. You might need some cool bits to make it work but we certainly don't suggest people allow the URLs specifically. -
Ruth Miskin New Video Domain
PaddyNewman replied to JonnyAlpha's topic in Internet Related/Filtering/Firewall
Exactly snagrat, using a Referrer URL is the way. -
Smoothwall Radius Accounting
PaddyNewman replied to supportman's topic in Internet Related/Filtering/Firewall
Aha all good, glad it's working! -
Smoothwall Radius Accounting
PaddyNewman replied to supportman's topic in Internet Related/Filtering/Firewall
All that happens is an accounting packet gets sent, I would assume they read the username and framed IP, and tie the two up. Going back to my other post, are you sure, 100%, SW is accepting accounting on 1812 and not the standard 1813. Transparent works, at least in Netsweeper which I imagine has a less refined (although functionally sound) RADIUS setup. Its a super basic concept. -
Smoothwall Radius Accounting
PaddyNewman replied to supportman's topic in Internet Related/Filtering/Firewall
Sorry if being a sausage, but do you not want 1813 for accounting. -
I see comic sans, I close. I did have a look through some of their stuff, personally its not something I'd consider. There's a reason the bigger names exist.. I'd be tempted to fire one up behind my firewall and see what it's doing. You don't keep up to date without talking to somewhere for updates...what else is it doing etc. Cynic in me, that's the edge of my secure network, security is paramount. A degree of trust is needed. I can't trust that.
-
Starlink resellers?
PaddyNewman replied to Blue_Cookeh's topic in Internet Related/Filtering/Firewall
That sounds decent, especially for your requirements. My Starlink has averaged 200/20 over the last 3 months when it runs its random speedtests and about 33ms but I am on the residential standard dish (I can't justify the cost of high perf for home use!) You get a decently lower ms and I would assume prioritised traffic during busy times, handy bits of kit!
