Slashdot Mirror


Packet Filter On University Network

sachsmachine explains: "I'm a student at a major university where the network admins are thinking of moving to a packet filtering system, one that would block non-university computers from connecting to machines on the student subnets. There will be a meeting to discuss the proposal on Tuesday, but to be fully prepared going in, I'd like to be sure what impacts the move would have. Some of the things that might be broken (depending on what ports get left open) are pretty clear -- remote logins of various sorts, file sharing, Web sharing, instant messaging, Napster and everything else P2P -- but are there any important/unusual/cool/academically useful applications whose ports we should lobby to protect?" By the nature of university (and corporate) rule making, once a policy is in place, it's much harder to dislodge or amend than it might be beforehand. Steve has listed a fair number of applications which could be tossed out by this; how would you suggest saving university bandwidth without losing them all? How would you convince a skeptical audience that remote access is not all of a piece?

16 of 36 comments (clear)

  1. Public University by davidu · · Score: 2

    If it is a public university, point out the stance Michigan and Wisconsin(Madison) have taken:

    Both have said that as public universities, they will not filter content, and if they need more bandwidth, then they will get it. (I assume, to a point)

    At my private university, the student government has a major role in the network (or can if it wants to) -- so if the suit behind the admins is making poor choices that aren't what the student body wants, chances aren't that slim that said suit will be looking for work. Our school actually passed a resolution to the effect that nothing can be done to the network which inhibits students ability to use the internet just as if they were using an ISP. (since the university is our ISP) -- since then, many of the filters and packet shapers have disappeared almost completely.

    -Davidu

    --

    # Hack the planet, it's important.
  2. Re:Remember FTP! by mlc · · Score: 2
    Sadly, though, my guess is that there aren't too many accademic reasons for putting a server in your dorm room instead of using a university managed server - other than to try to put up a server which doesn't fall under the normal AUP. Sure, it's a fun project and teaches a lot about administration - but it provides little academic gain that setting up a university-wide-only server would not.

    Certainly there are useful reasons. For example, I've got PHP and MySQL on my personal machine, whereas the standard university servers that I have access to do not. I was thus able to develop and demo a web application for a volunteer cause, show it to them, and make changes before obtaining the permanent box (outside of the university) that it'll run on.
    --
    // mlc, user 16290

  3. Many cases the University is justified by bawheid · · Score: 2
    This is always a tricky one. I work as an admin in an engineering department of a british university. Much of the stem of these problems are due to the fact that when people have "unlimited" access to the network, they tend to use it in ways that stress the network to the limit, or go beyond the terms of acceptable use. One showcase in point occured recently within our department, when two PCs in one room were accounting for one quarter of the whole University bandwith!! Needless to say, the work was not academic - playstation CD images and MP3s. Several abuses of the kind have resulted in a set of new guidelines being introduced, which go as far as to say that machines should not be networked unless absolutely necessary, and that students are not allowed to admin machines any more.

    I don't know what the case is for American Universities, but nowadays in Britain, the Unis are coming under tighter and tighter financial restraints. Many universities probably don't mind too much about people using the available bandwidth in moderation, but these kind of abuses of the priviledge (and it is a priviledge to use to the Uni network for non-academic purposes), make it impossible to justify why free access should be given when there is no (financial) need for it -especially when cash-constricted departments are having to bear the cost of non academic browsing, without having money available to pay for it - which was less of a problem in the older days, when money was flowing more freely within the universities, and general network usage was lower.....

    Try to understand the awkward position that many of these universities are in in this respect. Often, it not necessarily the desire to curtail the usage of the network out of badness that is the problem, but external influences such as cost and protecting themselves from prosecution, which the Universities don't have to resources to meet.

  4. Conference and IP-by-phone by Stavr0 · · Score: 2

    I would deem those as essential services. A reasonable case can be built that students need NetMeeting to communicate with family members as an alternative to long distance telephone. This is especially important to foreign students who simply cannot afford the dollar/min or more to reach South America, Eastern Europe or Asia.
    Real life example: My brother's GF is Peruvian and regularly uses ICQ and NetMeeting to keep in touch with Lima from Canada. We spend 90 min on the webcam last New Year's eve; something impossible with a telephone. I dare not think how much that would've cost in LD charges.
    ---

    1. Re:Conference and IP-by-phone by jmaslak · · Score: 2

      The Univeristy won't consider these essential services if the University runs the dorm's telephone service (and, thus, makes a cut off of the long distance)...

  5. Three problems by coyote-san · · Score: 2
    There are three problems with this argument:

    • The students can still obtain bandwith at a private ISP, just like all other citizens. Even if the students can't use the dorm phone lines to connect to their private ISP (common in university-run phone systems), they can almost certainly still telnet/passive ftp into it via their broadband access.
    • Suppression of ALL political speech is generally considered more acceptable than suppression of SOME political speech, since there's no risk of favoritism. Students do have alternatives to their campus-run ISP.
    • The student's community, to a large extent, is the university itself. It sounds like this policy will still allow dorm-room servers to be set up, but they will only be visible from within the university.

    The university's actions will certainly impose a modest burden on the student's political speech, but it doesn't seem to be an unreasonable one.

    --
    For every complex problem there is an answer that is clear, simple, and wrong. -- H L Mencken
  6. You're probably stuck by orev · · Score: 2

    Depending on how they set things up, it probably won't affect most things that are deemed "what normal people should do". ICQ and AIM will work fine, except generally for file transfers. You might also have trouble with voice-IP apps. Other than that, there are answers to most of the arguments that can be made, mostly, "you should be using university managed machines for that."

    What it will do is shut down most of the pirates, which is probably why their doing it, and napster.

    Most universities pay discounted rates for their net connections, but some of the stipulations are that it only be used for educational purposes, and maybe a bandwidth limit. Lots of incoming traffic to the student net most likely means stuff is going on that shouldn't be.

    Probably your only real argument will be simply that in a university environment, you shouldn't restrict stuff because of free expression, blah blah blah... oh, and "once you do this, where does it end?"

  7. Re:Remember FTP! by shippo · · Score: 2
    Yes, remember FTP.

    Four or five years ago the current employer decided to sell firewalls. They put one in place at work to test it out, and caused all FTP access from a browser to be broken for at least 3 months, made worse by our major supplier using FTP urls in their call logging system. (To download a file we had to browse the web source and manually grab the file by a command-line FTP client which worked vua the other method).

    The team responsible for selling these firewalls never managed to fix it. In the end one of my collegues got hold of the firewall password and fixed in in a few seconds. I think this team only managed to sell 3, and all of the cancelled the support contract within 6 months.

  8. Easy answer by autocracy · · Score: 2

    I am almost certain that the school's reason for doing this is bandwidth related. In order to let students do what they want and keep the network running smooth, use prioritization. University run systems are true-firewalled, while student machines are DMZed and are lower priority than University machines. See QoS/fair (unfair!) queing.

    The problem with capped Karma is it only goes down...

    --
    SIG: HUP
  9. Re:Arguing for services by raju1kabir · · Score: 2

    Everywhere I've seen (granted that comes to about 10 universities total) students are required to fill out a form acknowledging not to do anything particularly bad before they can plug in. This could be handled when they're picking their login ID (and if your school doesn't let people pick their own login IDs either, well, I guess we have nothing further to talk about. Hmph.).

    In any case, it could be done online with - get this - electronic forms. Cost pretty much approaches zero. The list of who goes where can be fed by a web app into the DHCP server. Likewise they get automatically dumped onto the mailing list. A machine runs nessus against the machines in the no-filter pool, dumps the results to a $9/hr work study student, who sifts through and picks out the ones with lots of red, which are handed to a $12/hr student consultant. This is a dirt-cheap project.

    --
    "Patriotism is your conviction that this country is superior to all other countries because you were born in it." -- GBS
  10. Re:Arguing for services by raju1kabir · · Score: 2
    Well, first I would like to applaud the university for doing something, anything to help protect their students and departments. They might not be going about it exactly the right way, but they're trying.

    If they were trying to protect students, there would be a space on the dorm ethernet sign-up form that said:

    Would you like your system to be protected by our campus firewall? This will help prevent outsiders from breaking into your computer, but may also prevent you from running certain types of servers in your room. Students who answer "no" will be required to provide an email address that will be subscribed to our mailing list of vulnerabilities, and to repair these promptly. There will be spot checks of your computer systems using remote security analysis software, and if it is found that you have failed to address vulnerabilities or apply fixes as required, you will forfeit your connection for the remainder of the school year.

    Student machines would be tossed into one of two address pools depending on their answer.

    All they're trying to protect are their own behinds and budgets, at the expense of the students' learning environment.

    --
    "Patriotism is your conviction that this country is superior to all other countries because you were born in it." -- GBS
  11. Remember FTP! by jmaslak · · Score: 3

    Outgoing FTP (connecting to an off-site server) causes the FTP server to initiate a connection back to you.

    While it is true that many firewalls have logic to allow this, simple packet filters do not and can not - you have to allow anything with a SOURCE port of 20 to connect to ANY high numbered port. But, this argument against packet filters only works if they really are using a packet filter - and not some sort of smart firewall.

    As far as a university denying connections, make sure that there is some way to gain exceptions to this policy, just in case there are accademic reasons for doing something down the road. For instance, they could require a proposal signed off by a department head, which indicates the academic value of opening the port and what precautions you are taking against abuse.

    Sadly, though, my guess is that there aren't too many accademic reasons for putting a server in your dorm room instead of using a university managed server - other than to try to put up a server which doesn't fall under the normal AUP. Sure, it's a fun project and teaches a lot about administration - but it provides little academic gain that setting up a university-wide-only server would not.

    Find out what their reasons for doing this are. Are they trying to reduce a security threat? Or is it really bandwidth? Make sure your argument addresses their - legitimate - concerns.

    1. Re:Remember FTP! by raju1kabir · · Score: 4
      Sadly, though, my guess is that there aren't too many accademic reasons for putting a server in your dorm room instead of using a university managed server - other than to try to put up a server which doesn't fall under the normal AUP. Sure, it's a fun project and teaches a lot about administration - but it provides little academic gain that setting up a university-wide-only server would not.

      I couldn't disagree more. Almost all of the current crop of gifted internet technicians (at least those that I'm aware of) learned their stuff by running servers in their college dorm rooms. Throwing static HTML up on a central web server isn't even the same ball game.

      I would furthermore suggest that any university that imposes restrictions such as those mooted in this article is not serious about providing residence hall internet access as an academic resource, and is instead doing it for one of three reasons:

      • They think it's "the thing to do"; all the schools are doing it
      • It's cheaper than providing sufficient public terminals for web browsing in the library (don't get me started on web "research")
      • They see it as a competitive factor in drawing students (like a fancy lobby and nice donuts in the campus information building)

      Sure there's abuse. So throw on some rate limiters. What's far more important is the amazing collaborative learning that takes place in this environment; students with no technological ability learning from others how to become content providers and participants in the internet information space just like huge corporations (CNN, Amazon, etc). It's empowering, it's educational, it's a crucial step toward preparing students for the real digital world past the campus gates.

      As an undergrad, I attended a university with a strong technological focus and a solid commitment to exposing students to IT (U of Michigan). When I look at my classmates, and compare them to less fortunate students at other schools, the difference is shocking. My fellow alum are totally comfortable with email, with the web, with their computers, with the changes in the world around them. Ten years later I went to grad school at a university with basically no on-campus technology (Yale; though they have finally wired most of the dorms at least). Ten years later, with all this technology supposedly so much more pervasive, and the students at Yale don't have anywhere near the comfort with it. They're intimidated by computers, and just as important, they're BAD at using them.

      --
      "Patriotism is your conviction that this country is superior to all other countries because you were born in it." -- GBS
  12. Arguing for services by Lish · · Score: 3
    Well, first I would like to applaud the university for doing something, anything to help protect their students and departments. They might not be going about it exactly the right way, but they're trying.

    To make an assessment of how you should approach them, you need to know what their motivation is for doing the packet filtering. Is it for security? Is it to limit bandwidth consumption for nonacademic purposes? Is it to stop piracy? Knowing their reasons will help you make your arguments for allowing those services you want.

    Now, if it's being done for security reasons, you'll have to argue that the services you want to keep open don't provide a security threat. Maybe get some statistics on number of attacks that utilize the different ports you're after.

    If piracy (software, music, whatever) is their reason, you'd want to demonstrate the academic uses for what they're trying to block. In this case you're probably SOL on Napster, but you might get FTP to fly. The only "academic" use I can think of for Napster is a Music Performance major who makes his personal works/performances available through Napster. Show the legit uses for the medium.

    Bandwidth consumption is a sticky issue. You'll again have to show an academic need for the service, but also that it does not consume an unacceptable amount of bandwidth. Maybe get some logging statistics for the network, find out what protocols are hogging the network; are the problems being caused by only a few people? There are better ways to control bandwidth use than wholesale blocking incoming packets.

    As for "what ports to keep open," the easiest thing to do is survey the students on what network programs they use. It's easier to argue that X should be open because lots of students use it than some obscure program with limited value to the community from keeping it open.

    It's really not so important what ports are open now as that there is a means of petitioning for ports to be opened in the future. That will allow you to make changes as new programs are developed using new ports.

    Good luck, I hope they consider your case well.

    --
    "This message is composed of 100% recycled electrons."
  13. If All Else Fails, Be Creative by BigDogKelly · · Score: 3

    Being a fellow college student who spends most of his time doing computer stuff (yes I am guilty of being a CS major), I share your fears. I didnt like it when they blocked Napster- unfortunatly they had a good reason-bandwidth. We tried going to the Admins but were denied. Luckily, being the good CS geeks that we are, we found ways around it.

    When you go before the Admin group at school, have your battle plan laid out. Know your strong points and be able to defend your weak points. Be sure to bring friends who share your concerns. If your Teachers agree with you, bring them along too. The bigger your group and more importantly, the better your arguments are, the better off you look to those in charge. If they see that you are not alone they will be more likely to deal fairly with you. Even if your solid, logical approach at this meeting fails, get creative. If the packet filter gets installed, experiment with different ways of getting around it. Now, I am in NO way promoting the idea of doing any type of damage to it or even causing more work for the admins., but see if there are certain things the filter misses. When you find that out you may be able to use it to your advantage. Just remember, try the system first (it may actually work) but there are always other ways.

    --
    -Life is a Journey, --Not a Guided Tour! ---Trust me, I've already looked for the guide book.
  14. Make your case with legit reasons by Patman · · Score: 4

    The worst thing you can do in an academic setting
    is imply that you are using the network connection for anything other than direct academic uses.
    SSH/telnet ports should be easy to keep open. Explain that you're using them for remote access to email or whatever.
    Many students put up personal webpages for their job search - resumes, downloadable snipepts of code, etc. Point out that that will be gone.
    Pick your battles, though. You may not win on http, but shoot for ftp, or vice versa. Don't throw down over Napster or the like,
    becase from an academic standpoint, there is not much use.

    Good luck!