-
Posts
389 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
Thinking about blocking HTTP ...
PaddyNewman replied to MatthewL's topic in Internet Related/Filtering/Firewall
Would probably be one the last things I'd close. Block it for yourself and only your machine and perhaps your personal device on BYOD. I've seen some HTTP calls on Win11 to some random places that when blocked, destroy the taskbar. Why....no idea! I mean, try it, but I imagine it's the least of your worries! -
Trouble Viewing Twitter/X.com In Browsers
PaddyNewman replied to Iain.Faulkner's topic in Internet Related/Filtering/Firewall
100% filtering there, you will have an abundance of twimg entries blocked. I would imagine thats the same as a non inspected silent drop. -
Sanity check - UDP session timeout
PaddyNewman replied to haci's topic in Internet Related/Filtering/Firewall
We have never changed our UDP timeout from Cisco standard. We've got every VoIP provider under the sun on our end and it's never been too much of a problem. Seems an odd way to do it rather than just send shorter timers from the devices.. -
FWIW I compare heating oil (as do most I feel) when it comes up for fill up time, "boilerjuice" tends to be OK if you are in a bind but not the cheapest. Lincolnshire has very specific companies that handle it, but "YourNRG" has been the cheapest routinely for me - unsure if they have a place near you but whilst there is only maybe 1-2ppl difference, that adds up when you buy 1000l, and most want a minimum 500l fill up, understandably. With my last top up, 750l was 52.57ppl, right now it showing as 55.32ppl ~ £435 which would last us from now till probably start of next cold season if I switch to immersion for showers over summer. If your house is as old, we have a void under the living room with an aging wooden floor, which is no longer sealed. When it gets breezy and cold, you basically have aircon coming through the floor. I need to get the floor done but for this year, I will settle for a temporary carpet!
-
We have 2 loft tanks > immersion tank with the element isolated so we only power on via mains juice when we have boiler work done but the timed heating and hot water is done via the oil/kerosene/red diesel burner. Reason I haven't gone combi - I just can't be bothered if I am being honest, we are remote enough that you can't find our house with a postcode and a huge sign, having builders attempt to come out is pain. Spent 3 months finding a bathroom fitter that was happy to travel and install/scope. When we get round to sorting the garden and extending, it will come up as we do need to smash the wall down where the boiler is against so.... potentially. We currently have a Warmflow boiler which works great and was about a year old when we moved in and sits at a 65 degree setting all year round, seems the best heat for £. Usage is measured by a flow meter (technoton dfm S7) which helpfully feeds telematics into a Pi which then displays on my home graphing to let me know flow rate/hr and then our bodged in thermostat lets me know when its on/off and how much the flow was for the last hour and I feed it £per Litre and it works out how much it cost. I like the DIY tech route and as above, our tanks solely hold the hot water side and refill via the mains. Our cold taps are all pure mains feed and we have absolutely crazy pressure, if your cold is gravity fed, you'd overcome that with a thumb, we most certainly cannot and have been drinking this water fine for over 2 years. We also happen to have a 2nd spur off the mains water pipe for our outhouse which is helpful when we are having water turned off in the house, we can still maintain a sensible life, such as when our bathroom was ripped out, I could still wash happily without having to trek 30 miles to a friends. But everything works... basically aint broke don't fix is how we are running this house:D ... don't get me started on internet provisions...
-
Yeah we have a huge bath also and it was purging fast. Before adding the pump it was OK, but I would rather have a powerful shower than something just past dribbling
-
I moved into a rural place, again oil burner, header tanks and now, a power shower (by that, install a pump) ... best thing you can do I had an additional water tank added, got 2 large ones up there, worth getting hands on and checking them and popping a lid with a bit of weight on there. Few mice have entered and not left in the 2 years I've been here! Oil burns fairly fast if you keep it on for long, I've got a pretty decent flow and am half way through my 1200l tank since January this year and it does my hot water for 4 hours a day, my heating (now its cold enough apparently, she says) is on for 3 hours at night and I imagine we won't need a refill till Feb/March
-
There is a fear of netsweeper for sure, I've built plenty of instances and had very few issues, all filtering platforms have some nuances though! Fortigates used to have pretty rough filtering but they look to have changed over the years, but it's a firewall first and foremost with a filtering product tacked on. Smoothwall is a filter with firewalling capabilities. I guess it's all down to budget and what you need, I've not really seen any proper content mod or filtering stuff outside of a Smoothwall.
-
Smoothwall X Unifi Routing
PaddyNewman replied to moneill's topic in Internet Related/Filtering/Firewall
When you say it stops at the Smoothwall, can you see it hitting the inside interface? What's behind the unifi, are you using your own NAT addresses. All experiences from unifi acting as L3 have been excitingly bad, unless it's a newer one, they had this fantastic tendency to force you to use a specific vlan and IP range, which doesn't fly in most instances. Im happy to set up captures on the LGfL side if you need (unless it's the raw offering, then it's not something we can see) Be good to know what your Smoothwall sees, if it's aware of routes and whether it's actually sending to next hop or just doing nothing with it and putting in the bin. -
DNSFilter - Agent-based and network-based filtering
PaddyNewman replied to gsk's topic in Internet Related/Filtering/Firewall
DNS filtering is a sticking plaster, I'd personally consider it absolutely lowest tier backup filtering. Most DNS filters see the domain, and only the domain, no path or anything. Want certain Wikipedia pages, no go, want to allow BBC but block iPlayer, no. Unless this one is better, but assuming no search terms means they don't decrypt. Plenty of easy/cheap filtering platforms around, but this feels similar to the light touch webtitan filter. Fine to be quite forceful with blocks but limited flexibility. -
Netwseeper - Youtube, what do you do?
PaddyNewman replied to TheRobins's topic in Internet Related/Filtering/Firewall
I don't know the Google intricate working, I tend to never touch that, I am more behind the scenes than front of house management of things. Surely if must = 1, just bang a school video on there only? If its zero, why allow YouTube at all? Perhaps I am misunderstanding -
Netwseeper - Youtube, what do you do?
PaddyNewman replied to TheRobins's topic in Internet Related/Filtering/Firewall
We enforce safe search via DNS for Google/Bing/DuckDuckGo/Ecosia and don't rely on the filtering to do that, as not everyone enables SSL inspection so hitting at the DNS level helps. -
Netwseeper - Youtube, what do you do?
PaddyNewman replied to TheRobins's topic in Internet Related/Filtering/Firewall
Welcome to the internet! Indeed it's going to be full of non educational stuff, but can't be expected to let the filter do the heavy lifting, there's something to be said about classroom management which was how it was done when I was at school! Referrer stuff to keep it working on the sites they need access to, blocked elsewhere if you don't want them accessing. Depends how you want it done, but referrer header stuff will do the 'only on approved embedded sites' or specific YouTube URLs, or Google workspace controls. -
Netwseeper - Youtube, what do you do?
PaddyNewman replied to TheRobins's topic in Internet Related/Filtering/Firewall
Referrer header if you want source sites to work without opening YouTube. Header modification if you want strict mode for kids and higher for Staff. -
If you wanted to be quite brutal block all ports outbound. Only allow DNS to your FortiGate. Allow HTTP/HTTPS/mail ports to specific FQDNs. That's using ACLs and not the inbuilt we filter, just a 100% no on the firewall except to certain endpoints. Could get into the web filter, but it feels a waste as you are blocking 99.999% of the internet , so just kill it on the way out.
- 1 reply
-
- firewall rule
- firewalls
-
(and 2 more)
Tagged with:
-
Correct with the NC role, or at least 99% correct - some odd things do happen. Announcements not going via email puts a reliance on logging in so having that content in an email would be helpful (if that is what you are suggesting) - if so I can 100% feed that back. I can't remember (this week is a blur already) but I think LGfL sent direct comms to contacts, but I will seek clarification for you! More comms on issues is what I am hearing though right?
-
What do you think we could do better @Koldov - do feel free to reach out for a chat. Open to hearing what you think is missing I (personally) wasn't aware of Redstor outages, definitely not my area sorry both yourself and @networkmangler Netsweeper issue was not a direct impact on us, but we did make sure we weren't affected by mitigating some of the chances of our systems seeing the wider outage by locking policy changes for a short time. This was raised at time of announcement and resolved at 2pm UK after calls with Netsweeper to ascertain scope of the issue.
-
netsweeper / sbb / chrome agent
PaddyNewman replied to SirAlan's topic in Internet Related/Filtering/Firewall
I've never used chrome in Windows with a school account so quite likely entirely my fault, but the OS filter in Netsweeper will block it from Windows Chrome. I've had very little dealings with Google and it's admin, but would assume it would only target managed devices hence the need for those licences.- 10 replies
-
- filtering
- netsweeper
-
(and 1 more)
Tagged with:
-
netsweeper / sbb / chrome agent
PaddyNewman replied to SirAlan's topic in Internet Related/Filtering/Firewall
I'm either confused, or mistaken. Pc should have MSI. Chromebooks have extension. Don't mix, no problem.- 10 replies
-
- filtering
- netsweeper
-
(and 1 more)
Tagged with:
-
Netsweeper false positives on UK Cloud
PaddyNewman replied to danrhodes's topic in Internet Related/Filtering/Firewall
Netsweeper can categorise URLs and domains, but if you 'allow' something like cloudflare.com as a URL type, that's that. Everything *.cloudflare com will work. If you have decryption off, everything *.cloudflare.com/porn will work too. It may still work with it on, but at least you can filter on something past that to override the allow. Allow lists should be incredibly specific, being lax with them will open more than intended.- 3 replies
-
- 1
-
-
- false positives
- filtering
-
(and 1 more)
Tagged with:
