Slashdot Mirror


Ask Slashdot: Dealing With University Firewalls?

An anonymous reader writes "My university only provides access to the web, via a restrictive content filter and proxy service. There is no access to the wider internet. I was wondering if this is common, and if anyone has any suggestions on how to go about protesting the issue. I've spoken to the lecturers and they have the same frustrations I do. I've also spoken to the head of the IT department who spouted lines about 'protecting the network.' This is very frustrating, I've seen a number of students making use of 3G/4G dongles to get access to the net and this just seems crazy. The restrictions applied to the web are draconian, with sites such as hackaday, hypberbole and a half, somethingawful, etc being blocked." What would you do to get better access?

15 of 582 comments (clear)

  1. ssh is permitted? by tanveer1979 · · Score: 5, Insightful

    In that case buy a ssh shell minimal hosting account for 2-3$/month.
    Create a tunnel.
    And browse.

    If paid public VPN services are allowed, you can also subscribe to such services. Of course, your browsing will be slower.

    --
    My Aurora : http://www.youtube.com/watch?v=o91ZsGwJYyg
    FB : https://www.facebook.com/TanveersPhotography
    1. Re:ssh is permitted? by Anonymous Coward · · Score: 5, Informative

      The solution then is to use port 443 to run SSH. I have a free trial of Amazon EC2 I use for that kind of thing. The speeds are good, you can even watch YouTube with relatively little buffering. If anyone is interested I have it set up:

      Browser
      v
      SSH Socks Proxy
      v
      corkscrew (software to send ssh through an http proxy, you can also use PUTTY on windows for this)
      v
      CNTLM (you may not need this but I do because the proxy I go through uses NTLM authentication)
      v
      SSH server running on port 443.

    2. Re:ssh is permitted? by mverwijs · · Score: 5, Informative

      sslh for the win!

      Just 'apt-get install sslh', have it run on port 443. It will forward HTTPS traffic to your apache server running on whatever port you run it on, while forwarding ssh traffic to sshd.

      It's just.... beautiful.

  2. Tributes by Anonymous Coward · · Score: 5, Informative

    Become friends with a member of the IT department. Alcohol can go a long way in beginning an IT related friendship.

  3. Re:It's their bandwidth ... by mattventura · · Score: 5, Insightful

    If the university's IT department isn't providing the services that students and faculty need, then the issue should probably be raised above the IT department. The purpose of an IT department is to provide a service to the organization, not to make the organization bend over to the IT dept.

  4. Re:It's their bandwidth ... by Anonymous Coward · · Score: 5, Interesting

    I have been in the position of having to block internet to a college in a previous job. There were constant battles between the marketing and academic departments about blocking and unblocking social media sites. In the end the marketing department won and they were unblocked. The tutors didn't like it because they relied so much on computers for their lessons rather than using good old fashioned methods like lecturing and demonstrating.

  5. Re:It's their bandwidth ... by Miseph · · Score: 5, Insightful

    Unless the author has a full ride scholarship including room and board... I'd say there is at least a partially legitimate claim to some rights here.

    Anyway, yeah, campus networks can be like that. It's bull. It's also, in my experience, rarely something the IT people are terribly fond of; most of them are at least passingly familiar with how the internet works, and ultimately it requires far more work to maintain a ridiculously locked-down network than one with minimal restrictions. Usually, that comes from higher up in the organization, from some old administrator or trustee or something... IT takes order in academia just like they do in business.

    The best bet for getting a change on this is actually o complain to higher administration, and perhaps as well to school and/or local publications. Putting things in writing usually works well. Bring up issues of censorship and academic freedom, and be sure to mention how this new-fangled internet thing is a really important part of the future. Keep in mind that the details of what is or is not filtered is, largely, irrelevant... it's easy to lose a non-techie audience by getting into the weeds. The point here is to engage them on the emotional level: these decisions are not made because there are clear-cut rational arguments for them, they are made because somebody doesn't like ______ which they believe to be on the internet. Again, getting too logical or specific will just make eyes glaze over, so keep it rhetorical and abstract.

    --
    Try not to take me more seriously than I take myself.
  6. Which University? by JambisJubilee · · Score: 5, Interesting

    I'd say the university isn't fulfilling its role, and you should definitely rally to change things. The purpose of the university network (besides supporting research communications) is to allow you to learn.

    During my undergrad the university I attended provided full firewall-free internet with a *public* IP from their block for everyone who plugged in (and no-questions asked CNAMEs). The wireless was of course NAT'd but I had no problems.

    This all worked because of the genius way they solved problems was genius. If IT detected any funny business, a tech would physically show up at your lab/office and ask you what was going on and make you fix the problem right then and there.

  7. Didn't you know this going in? by slimjim8094 · · Score: 5, Insightful

    As a /. reader, I can only assume you're rather technical. Isn't this something you discovered before going there?

    Frankly, I wouldn't go to a school that did this. And I didn't. Thankfully, my first choice doesn't do anything like this. Traffic is unmonitored, but for legal reasons you have to register your MAC address to your university credentials to get out of the VLAN. This happens automatically with authentication to the wireless network, or manually through a captive portal for Ethernet.

    As required by law of all ISPs, they will use this to forward DMCA notices, which happens pretty frequently. I can't exactly fault them for that. They'll also notice if you're really hammering the network with worm traffic or something, in which case they'll kick you off until you get the system cleaned up, which I can't fault them for either.

    But other than that, they're pretty much out-of-the-way. They definitely view themselves as more of an ISP than anything academically-relevant, which is good. The university structure also places them at the same level as the individual schools (liberal arts, engineering, business, etc), and each school has its own school-specific IT that runs their own email and webhosting and so on, all of which helps keep them pretty much service-oriented. They pretty much provide internet access and server space to any university department that wants it (and pays for it, in one of those interdepartmental money-shuffling schemes), and otherwise back off from content management. Individual schools are free to filter whatever they want, but only in the school-managed network. In practice, none do. Even if they did, the dorms are separated out from that.

    Not to mention the university is almost as liberal as they come in terms of information freedom.

    But in any case, the university is your home for the time you're there. I wouldn't live somewhere that did this, and I wouldn't go to a school that did this. Not even because of the inconvenience - think about what that suggests about how they view academic and intellectual freedom.

    --
    I have developed a truly marvelous proof of this comment, which this signature is too narrow to contain.
  8. Re:get over it by MobileTatsu-NJG · · Score: 5, Insightful

    Because youtube and torrents are part of using the internet.

    What part of education do you not understand?

    --

    "I like to lick butts!" by MobileTatsu-NJG (#32700246) (Score:5, Informative)

  9. Re:get over it by Peter+Bortas · · Score: 5, Insightful

    "draconian" restrictions are there because someone in IT/management is lazy or has twisted viewes about what moral powers they should have over students. In other words because they are bastards.

    /ex-University sysadm

  10. Speaking from the other perspective.. by GoLGY · · Score: 5, Insightful

    As a member of an IT systems admin team for a faculty we've often got specific mandates which services we must restrict, and to what end. What you may also be up against, other than 'unprivileged' access - is politics. Students do Naughty Stuff (tm) - that's just a fact that keeps on proving itself true time and time again. Even if you can speak for you, your friends, or your entire course - I can bet dollars to donuts that there's someone out there trying to do something shifty. Case in point: I was seriously asked to relax the restrictions on banning Steam so a student could "download 10 or 15 gig so i didn't have to do it over dial-up". On-campus living - sure, i can see where restrictions like that may diminish any sort of sanity saving software platform ( Valve fan \o/ ), but I'm not going to open up a faculty network just so you can play games. It's an education facility, not your personal high speed connection to the 'net. If you were a postgraduate student researching something that required access - then by all means get your supervisor to approve your request and I'll be more than happy to make it happen.

    That being said - outline a clear case of why you need certain things re-classified and you may have a better case to work with. I am not suggesting that this tactic will work - as there's probably more to the story ( see - plug and play filter lists/software/appliances which remove the need to dedicate an entire FTE to putting classifications on traffic going out ) than you really know, but it will certainly stop you from seeming like a whinging student and more like an intellectual who is using sound reasoning. Hell - if you are able to find clear, repeated examples of wrongful clasification of websites, you may be able to enact a reconsideration of what's being used to deny you access or relax the level in which things are blocked.

    Of course, they might not care. Who knows?

    --
    --- perl -e 'printf("%s\n", pack "H*", "7369670a676f6c677940676f6c67792e6e65740a2f736967")'
  11. Re:get over it by icebraining · · Score: 5, Insightful

    Because, funnily enough, important education content like Stanford's machine learning lectures are available exactly via Youtube and torrents: http://see.stanford.edu/see/lecturelist.aspx?coll=348ca38a-3a6d-4052-937d-cb017338d7b1

  12. Re:University IT usually gets run by morons by Anonymous Coward · · Score: 5, Funny

    Students always know about barley. After all, their favorite drink is made using it.

  13. Re:It's their bandwidth ... by mindcandy · · Score: 5, Interesting

    I am security@ a large public .edu .. and I can say that their approach is quite *uncommon* among my peers in the industry.

    Education is typically a very open environment, and IT will happily provide (within reason) anything that doesn't interfere with something else.

    For example, we have several "hacking labs" on campus, where students are free to do basically whatever they want, regardless of how malicious. Granted, those networks are firewalled off from the rest of campus (and the Internet). We also have PlanetLab, TOR (which I run myself), and a few other projects.

    As for Internet access, we don't have "wide open" like your home DSL (email, for example, must go through our servers for obvious reasons) .. and we block common things like tcp/6666 and tcp/445 outbound .. but other than that, we reguarly field calls from folks that just got $shiny_new_game for their $toy and want to know if we can figure out why voice chat (or whatever) doesn't work.

    Last year we actually had students bring their PS3/Xbox units into a conference room in the IT department, hooked up to our projectors, and had then all plug into a switch where we were running a sniffer .. we had the network engineers, security team, etc. all assembled and basically told the students "go for it" and made several ongoing tweaks to things to ensure they got the best experience (gaming is a latency-sensitive application, we just needed to figure out how to prioritize it with QoS and the packeteer).

    In short .. tl/dr .. sounds like your Uni has a sucky policy. Take it up with the provost .. you are paying to be there, and Internet access is part of your campus experience. If it's not up to par, they need to make changes.