Jump to content

PaddyNewman

Members
  • Posts

    389
  • Joined

  • Last visited

Everything posted by PaddyNewman

  1. Would probably be one the last things I'd close. Block it for yourself and only your machine and perhaps your personal device on BYOD. I've seen some HTTP calls on Win11 to some random places that when blocked, destroy the taskbar. Why....no idea! I mean, try it, but I imagine it's the least of your worries!
  2. 100% filtering there, you will have an abundance of twimg entries blocked. I would imagine thats the same as a non inspected silent drop.
  3. We have never changed our UDP timeout from Cisco standard. We've got every VoIP provider under the sun on our end and it's never been too much of a problem. Seems an odd way to do it rather than just send shorter timers from the devices..
  4. Tell them to use their mobile. Your responsibility is to filter all school feeds regardless of user.
  5. It's a bunch of firewall rules I 'think' If you are an LGfL school drop me a PM and I'll assist if I can, but I'll see if I can find the recent change I did for this service.
  6. FWIW I compare heating oil (as do most I feel) when it comes up for fill up time, "boilerjuice" tends to be OK if you are in a bind but not the cheapest. Lincolnshire has very specific companies that handle it, but "YourNRG" has been the cheapest routinely for me - unsure if they have a place near you but whilst there is only maybe 1-2ppl difference, that adds up when you buy 1000l, and most want a minimum 500l fill up, understandably. With my last top up, 750l was 52.57ppl, right now it showing as 55.32ppl ~ £435 which would last us from now till probably start of next cold season if I switch to immersion for showers over summer. If your house is as old, we have a void under the living room with an aging wooden floor, which is no longer sealed. When it gets breezy and cold, you basically have aircon coming through the floor. I need to get the floor done but for this year, I will settle for a temporary carpet!
  7. We have 2 loft tanks > immersion tank with the element isolated so we only power on via mains juice when we have boiler work done but the timed heating and hot water is done via the oil/kerosene/red diesel burner. Reason I haven't gone combi - I just can't be bothered if I am being honest, we are remote enough that you can't find our house with a postcode and a huge sign, having builders attempt to come out is pain. Spent 3 months finding a bathroom fitter that was happy to travel and install/scope. When we get round to sorting the garden and extending, it will come up as we do need to smash the wall down where the boiler is against so.... potentially. We currently have a Warmflow boiler which works great and was about a year old when we moved in and sits at a 65 degree setting all year round, seems the best heat for £. Usage is measured by a flow meter (technoton dfm S7) which helpfully feeds telematics into a Pi which then displays on my home graphing to let me know flow rate/hr and then our bodged in thermostat lets me know when its on/off and how much the flow was for the last hour and I feed it £per Litre and it works out how much it cost. I like the DIY tech route and as above, our tanks solely hold the hot water side and refill via the mains. Our cold taps are all pure mains feed and we have absolutely crazy pressure, if your cold is gravity fed, you'd overcome that with a thumb, we most certainly cannot and have been drinking this water fine for over 2 years. We also happen to have a 2nd spur off the mains water pipe for our outhouse which is helpful when we are having water turned off in the house, we can still maintain a sensible life, such as when our bathroom was ripped out, I could still wash happily without having to trek 30 miles to a friends. But everything works... basically aint broke don't fix is how we are running this house:D ... don't get me started on internet provisions...
  8. Yeah we have a huge bath also and it was purging fast. Before adding the pump it was OK, but I would rather have a powerful shower than something just past dribbling
  9. I moved into a rural place, again oil burner, header tanks and now, a power shower (by that, install a pump) ... best thing you can do I had an additional water tank added, got 2 large ones up there, worth getting hands on and checking them and popping a lid with a bit of weight on there. Few mice have entered and not left in the 2 years I've been here! Oil burns fairly fast if you keep it on for long, I've got a pretty decent flow and am half way through my 1200l tank since January this year and it does my hot water for 4 hours a day, my heating (now its cold enough apparently, she says) is on for 3 hours at night and I imagine we won't need a refill till Feb/March
  10. You can allow the videos on that site without allowing Vimeo on SchoolProtect by the way. Embedded content tab, you will need HTTPS inspection but you'd be wanting to roll that out anyway. More info in the training course, but it's a piece of cake
  11. There is a fear of netsweeper for sure, I've built plenty of instances and had very few issues, all filtering platforms have some nuances though! Fortigates used to have pretty rough filtering but they look to have changed over the years, but it's a firewall first and foremost with a filtering product tacked on. Smoothwall is a filter with firewalling capabilities. I guess it's all down to budget and what you need, I've not really seen any proper content mod or filtering stuff outside of a Smoothwall.
  12. When you say it stops at the Smoothwall, can you see it hitting the inside interface? What's behind the unifi, are you using your own NAT addresses. All experiences from unifi acting as L3 have been excitingly bad, unless it's a newer one, they had this fantastic tendency to force you to use a specific vlan and IP range, which doesn't fly in most instances. Im happy to set up captures on the LGfL side if you need (unless it's the raw offering, then it's not something we can see) Be good to know what your Smoothwall sees, if it's aware of routes and whether it's actually sending to next hop or just doing nothing with it and putting in the bin.
  13. DNS filtering is a sticking plaster, I'd personally consider it absolutely lowest tier backup filtering. Most DNS filters see the domain, and only the domain, no path or anything. Want certain Wikipedia pages, no go, want to allow BBC but block iPlayer, no. Unless this one is better, but assuming no search terms means they don't decrypt. Plenty of easy/cheap filtering platforms around, but this feels similar to the light touch webtitan filter. Fine to be quite forceful with blocks but limited flexibility.
  14. I don't know the Google intricate working, I tend to never touch that, I am more behind the scenes than front of house management of things. Surely if must = 1, just bang a school video on there only? If its zero, why allow YouTube at all? Perhaps I am misunderstanding
  15. We enforce safe search via DNS for Google/Bing/DuckDuckGo/Ecosia and don't rely on the filtering to do that, as not everyone enables SSL inspection so hitting at the DNS level helps.
  16. Welcome to the internet! Indeed it's going to be full of non educational stuff, but can't be expected to let the filter do the heavy lifting, there's something to be said about classroom management which was how it was done when I was at school! Referrer stuff to keep it working on the sites they need access to, blocked elsewhere if you don't want them accessing. Depends how you want it done, but referrer header stuff will do the 'only on approved embedded sites' or specific YouTube URLs, or Google workspace controls.
  17. Referrer header if you want source sites to work without opening YouTube. Header modification if you want strict mode for kids and higher for Staff.
  18. If you wanted to be quite brutal block all ports outbound. Only allow DNS to your FortiGate. Allow HTTP/HTTPS/mail ports to specific FQDNs. That's using ACLs and not the inbuilt we filter, just a 100% no on the firewall except to certain endpoints. Could get into the web filter, but it feels a waste as you are blocking 99.999% of the internet , so just kill it on the way out.
  19. Indeed, they aren't always technical - it is recommended that they are as its a contact that is able to call in and request changes via support.
  20. Correct with the NC role, or at least 99% correct - some odd things do happen. Announcements not going via email puts a reliance on logging in so having that content in an email would be helpful (if that is what you are suggesting) - if so I can 100% feed that back. I can't remember (this week is a blur already) but I think LGfL sent direct comms to contacts, but I will seek clarification for you! More comms on issues is what I am hearing though right?
  21. What do you think we could do better @Koldov - do feel free to reach out for a chat. Open to hearing what you think is missing I (personally) wasn't aware of Redstor outages, definitely not my area sorry both yourself and @networkmangler Netsweeper issue was not a direct impact on us, but we did make sure we weren't affected by mitigating some of the chances of our systems seeing the wider outage by locking policy changes for a short time. This was raised at time of announcement and resolved at 2pm UK after calls with Netsweeper to ascertain scope of the issue.
  22. I've never used chrome in Windows with a school account so quite likely entirely my fault, but the OS filter in Netsweeper will block it from Windows Chrome. I've had very little dealings with Google and it's admin, but would assume it would only target managed devices hence the need for those licences.
  23. I'm either confused, or mistaken. Pc should have MSI. Chromebooks have extension. Don't mix, no problem.
  24. Netsweeper can categorise URLs and domains, but if you 'allow' something like cloudflare.com as a URL type, that's that. Everything *.cloudflare com will work. If you have decryption off, everything *.cloudflare.com/porn will work too. It may still work with it on, but at least you can filter on something past that to override the allow. Allow lists should be incredibly specific, being lax with them will open more than intended.
×
×
  • Create New...