David Keenleyside, BSc CS & IS, CTech
ITP Associate
EFF Member
ICT Technician
Glenfield College
PO Box 40176 (Kaipatiki Rd)
Glenfield, Auckland City 0629
DDI: +64 9 441 9779
Email: d.keen...@gc.ac.nz
https://www.linkedin.com/in/david-keenleyside-626871/
The Three O’s of Backup: Online, Offline, Off-site.
The Three RA’s of Cloud: Run Anywhere, Run Anytime, Run Agnostic.
--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/d92f3130-368b-4f7a-b5da-3a0ba9a2b924n%40googlegroups.com.
Kind regards,
Alistair Baird
IT Manager
|
P
06 354 4198 1 Holdsworth Avenue, Milson |
David Keenleyside, BSc CS & IS, CTech
ITP Associate
EFF Member
ICT Technician
Glenfield College
PO Box 40176 (Kaipatiki Rd)
Glenfield, Auckland City 0629
DDI: +64 9 441 9779
Email: d.keen...@gc.ac.nz
https://www.linkedin.com/in/david-keenleyside-626871/
The Three O’s of Backup: Online, Offline, Off-site.
The Three RA’s of Cloud: Run Anywhere, Run Anytime, Run Agnostic.
--
You received this message because you are subscribed to a topic in the Google Groups "Techies for schools" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/techies-for-schools/h2JmhbJkemI/unsubscribe.
To unsubscribe from this group and all its topics, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/85c5d189-dcc9-494b-b07d-c5d2ac4f9c53n%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/73207374-CEAC-4794-A5C9-61D6F4086507%40mahurangi.school.nz.
David Keenleyside, BSc CS & IS, CTech
ITP Associate
EFF Member
ICT Technician
Glenfield College
PO Box 40176 (Kaipatiki Rd)
Glenfield, Auckland City 0629
DDI: +64 9 441 9779
Email: d.keen...@gc.ac.nz
https://www.linkedin.com/in/david-keenleyside-626871/
The Three O’s of Backup: Online, Offline, Off-site.
The Three RA’s of Cloud: Run Anywhere, Run Anytime, Run Agnostic.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/5d8a201b-302d-4926-9cfe-516f059b6bb7n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/E2B9438C-EA02-445F-B8F2-3F0659FCBE66%40mahurangi.school.nz.
David Keenleyside, BSc CS & IS, CTech
ITP Associate
EFF Member
ICT Technician
Glenfield College
PO Box 40176 (Kaipatiki Rd)
Glenfield, Auckland City 0629
DDI: +64 9 441 9779
Email: d.keen...@gc.ac.nz
https://www.linkedin.com/in/david-keenleyside-626871/
The Three O’s of Backup: Online, Offline, Off-site.
The Three RA’s of Cloud: Run Anywhere, Run Anytime, Run Agnostic.
Hi all, we had this issue last week at one of our larger high schools.
TLDR & YMMV; N4L FortiGate was blocking TLSv1 packets as they were being categorized as “X-VPN” traffic under the Proxy Avoidance category.
The issue was related to v124 of Chrome where X25519Kyber768 was being enabled by default (see here: https://chromestatus.com/feature/5257822742249472). When running packet captures, we could see that TLS version negotiating wasn’t getting above v1 when attempting to connect to sites that were serving certs with X25519Kyber768 enabled (i.e. https://mail.google.com). Strangely, the test site https://pq.cloudflareresearch.com/ was working fine and was telling us that we were “post-quantum secure”.
Our best guess, based on reading: https://tldr.fail/, was that the TLSv1.3 connection was being broken somewhere on the N4L side. This possibly led to the TLS negotiating packets dropping down to v1 which subsequently got caught up incorrectly as VPN traffic.. and blocked.
As soon as the N4L put their firewall into transparent mode, the issue stopped immediately. Current filtering at this school is done on their own FortiGate.
This school’s internal network is setup like the below:
Internal School Network à School FortiGate à N4L FortiGate à Internet
I hope this points you in the right direction or gives you somewhere else to look. If anyone would like a hand troubleshooting this.. more than happy to share some more details on what we were seeing with Wireshark captures and N4L FortiGate logs.
Thanks,
Scott
|
Scott Simpson |
|
|
|
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/0615e75d-4a7c-45a0-8361-1ad97a035d2en%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/0615e75d-4a7c-45a0-8361-1ad97a035d2en%40googlegroups.com.
David Keenleyside, BSc CS & IS, CTech
ITP Associate
EFF Member
ICT Technician
Glenfield College
PO Box 40176 (Kaipatiki Rd)
Glenfield, Auckland City 0629
DDI: +64 9 441 9779
Email: d.keen...@gc.ac.nz
https://www.linkedin.com/in/david-keenleyside-626871/
The Three O’s of Backup: Online, Offline, Off-site.
The Three RA’s of Cloud: Run Anywhere, Run Anytime, Run Agnostic.