-
Posts
389 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
netsweeper / sbb / chrome agent
PaddyNewman replied to SirAlan's topic in Internet Related/Filtering/Firewall
Yeah that is an option. I would imagine that you should only roll out the chrome agent to chrome devices and the MSI to windows devices.- 10 replies
-
- filtering
- netsweeper
-
(and 1 more)
Tagged with:
-
netsweeper / sbb / chrome agent
PaddyNewman replied to SirAlan's topic in Internet Related/Filtering/Firewall
Perhaps I'm confused, but you say PC agent and Chrome... Do you push the chrome agent to pc versions of chrome? If so I'd probably not do that and stop that extension being pushed to windows pcs, wagent is enough.- 10 replies
-
- filtering
- netsweeper
-
(and 1 more)
Tagged with:
-
BYOD Firewall Policy
PaddyNewman replied to klssandman76's topic in Internet Related/Filtering/Firewall
Isn't that just open, so farewell to any security. I'd be turning up with a VPN everyday. Or connecting to one of the millions of open proxies, or just setting my DNS to somewhere else. Web filters are using 80/443 only. I'd be locking that down personally as that's open to abuse. -
LGfL/Google app in-browser issues
PaddyNewman replied to aimsme's topic in London Grid for Learning (LGfL)
If you are able to pm what school you are from (and any other affected ones) I can take a look and see what is going on for you -
Chrome v124 - ERR_SSL_KEY_USAGE_INCOMPATIBLE
PaddyNewman replied to BOOT's topic in Internet Related/Filtering/Firewall
The registry is a direct attack, there are various other "sane" options utilising the Chrome/Edge ADMX provisions in group policy. Same item, just pushed out to all machines rather than registry. Might give you more success if you hammer the browser shut directly as its going to force the flag (chrome://flags - search "kyber") to be disabled. -
Chrome v124 - ERR_SSL_KEY_USAGE_INCOMPATIBLE
PaddyNewman replied to BOOT's topic in Internet Related/Filtering/Firewall
I've started seeing stuff relating to v124 however not via HTTPS inspection/proxies, just an older instance. Chrome v124 has re-added the previously experimental quantum jiggery pokery. X25519Kyber768 key encapsulation for TLSProtects current Chrome TLS traffic against future quantum cryptanalysis by deploying the Kyber768 quantum-resistant key agreement algorithm. That is in the release notes and changing this for a machine resolved our issues... A quick fix/test is to add this to registry. Path: SOFTWARE\Policies\Google\Chrome\PostQuantumKeyAgreementEnabled Type: DWORD Value: 0 Path: SOFTWARE\Policies\Microsoft\Edge\PostQuantumKeyAgreementEnabled Type: DWORD Value: 0 See if that helps your browsing I guess... -
Chrome v124 - ERR_SSL_KEY_USAGE_INCOMPATIBLE
PaddyNewman replied to BOOT's topic in Internet Related/Filtering/Firewall
Indeed, our CA is 10y expiring 2032 and I haven't seen a single report of this on our estate. -
Internet Failover
PaddyNewman replied to chekmate1984's topic in Internet Related/Filtering/Firewall
I use Starlink daily and its great if you aren't overpopulated there and you have very clear sky access. -
Chrome v124 - ERR_SSL_KEY_USAGE_INCOMPATIBLE
PaddyNewman replied to BOOT's topic in Internet Related/Filtering/Firewall
That is what i would expect with a self signed CA that hasn't had the right details passed when generating the cert. Obviously changing it will affect everyone but can you recreate a cert using OpenSSL? Something like [font=var(--ff-mono)]openssl req -x509 -nodes -newkey rsa:2048 -keyout private.key -out ca.crt -days 3650 -addext "keyUsage = digitalSignature, keyEncipherment, dataEncipherment, cRLSign, keyCertSign" -addext "extendedKeyUsage = serverAuth, clientAuth"[/font] Thats a 10 year valid self signed that would work in newer browsers, I imagine its not including the keyUsage part by default, the extended is optional I think... -
Chrome v124 - ERR_SSL_KEY_USAGE_INCOMPATIBLE
PaddyNewman replied to BOOT's topic in Internet Related/Filtering/Firewall
When you load your specific cert (self signed I assume) under Details > Key Usage what parameters do you have in there. It should be stating something along the lines of "Digital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)" - maybe the self signed generator in your product is not adding the key usage params correctly. We aren't seeing problems currently using this certificate across our estate. -
Internet Failover
PaddyNewman replied to chekmate1984's topic in Internet Related/Filtering/Firewall
I can probably help if you want to PM me, I can get a teams call together? -
Are you decrypting? Openai.com does not like decryption.
-
Firewall / Reseller Recommendations
PaddyNewman replied to itguy77's topic in Internet Related/Filtering/Firewall
Agreed, you can't go wrong with a FortiGate as long as you purchase the right one for your network size. I'm personally not a fan of the filter, but I know it's changed over time and definitely has some features that it was missing ~3 years ago! -
VLAN / Smoothwall question - Help!
PaddyNewman replied to mikkydoos's topic in Internet Related/Filtering/Firewall
I'm no smoothwall expert but I've had more than 1 instance of Smoothwall absorbing all private addressing, assuming you have a static route of your LAN to the L3 switch? -
Google Workspace - GMail - changing 'Mail Relay' (currently LGfL)
PaddyNewman replied to Koldov's topic in Cloud Services
All mail that is accepted by the relay is allowed outbound towards the internet, but you definitely want to define it in your SPF as it will be seen as coming from LGfL rather than Google. -
Random question - Firewall log sizes
PaddyNewman replied to mdrabble's topic in Internet Related/Filtering/Firewall
I was supporting a site that used 2GB a day. You can probably work out a way to syslog the majority from FortiAnalyzer and compress heavily though for future investigation but I'd think about what you actually need the logs for, then work out if its worth it -
Starlink resellers?
PaddyNewman replied to Blue_Cookeh's topic in Internet Related/Filtering/Firewall
I've never experienced any data limits as a residential user, and I would consider myself an excessive use individual. Aside from billing and the increased price... I can't see the direct benefit of business, aside from the fact they probably prioritise your traffic if you cell is well populated. I certainly do not see any slowness at any time. I've got speedtests that run every 30 minutes and over this week never has it come back less than ~180Mbps (I put in place because they were doing weird throttling to around 50Mbps when you hit a certain amount of traffic a day, that has gone though) -
Its renewal time, web filtering options?
PaddyNewman replied to TheRobins's topic in Internet Related/Filtering/Firewall
A school I was a tech at junked them in favour of lightspeed. They didn't rate it and they appear to focus on US customers, can't hurt to trial it though. If they are US targeted, do they receive the UK lists from IWF, PIPCU and CTIRU, those would be my initial concerns. The ISP under the hood might, but belts and braces, my ISP doesn't. -
Oh it's an option. It's patchy in some areas, but to be honest I get solid connection in Lincolnshire, around 200-250Mb down and 50Mb upload.
-
It's my primary internet connection. I work from home but we also install in schools as interim connections. 4/5G is great, but I don't even get phone signal, and my ADSL is 8Mb. Starlink smashes it out of the park.
-
Agreed, its a bend in policies and comes with risks!
-
An account 'should' reflect an individual. Its for traceability as if their account is compromised, you can locate the source. Sharing an inbound account can be problematic. I'm not saying people do not share these accounts, but typically I imagine their support team is a sensible number of people and they have a 'manager' as it were. They could register and just maintain their support team with USO accounts or as I say... they could bend the rules and we would be none the wiser, I know it happens.
-
You can be a registered 3rd party, get allocated an account and MFA then you can add their account no problems.
-
Google Workspace - GMail - changing 'Mail Relay' (currently LGfL)
PaddyNewman replied to Koldov's topic in Cloud Services
Point 1 - Yes as long as we are aware of sending IP and from address/domain Point 2 - Google has really tightened up unauthenticated email (thats email without authorised sender lists, not actual authentication) and we see it daily! -
Google Workspace - GMail - changing 'Mail Relay' (currently LGfL)
PaddyNewman replied to Koldov's topic in Cloud Services
For clarity as my wording was pony... Port 25 = closed to the outside world. Port 25 = open to our 'semi authenticated' relay, semi in the fact its based on source IP and from address with an imposed limit of mail per minute to prevent spam and sender blacklisting. "Messages missing a valid Message-ID header are not 550-5.7.1 accepted" Typically means missing SPF on the sender domain - GMail do love to drop unauthenticated mail.
