[identity profile] jimbojones.livejournal.com posting in [community profile] techrecovery
The major function of our (very well paid) intern seems to be to stream video all day long, grinding our internet access to a halt. After the billionth time discovering I couldn't get patches downloaded in a reasonable amount of time because our T1 was getting hammered by the intern watching YouTube videos, I hit the router and slapped an output filter on youtube's netblock. This was a couple weeks ago. Surprisingly, I never did get any questions about "hey is the internet working?" (although the coworker across the desk from me did.)

Today, I got this cut and paste from said coworker:

(14:25:00) Coworker: help us all ... here goes the bandwidth
           (14:24:27) Intern: yea its getting on my nerves
           (14:24:33) Intern: im bored maybe i will watch a movie on netflix


O RLY? Fuck that, I have source to download and packages to build. AKA, you know, "work".

/me slaps an output filter on netflix.com's netblock

Hey, somebody wants to IM me!

(14:46:51) Intern: is something wrong with the internet?
(14:47:08) Me: nope... why do you ask?
(14:47:16) Intern: it keeps saying problem loading page
(14:47:26) Me: what page are you loading?


My coworker and I are howling laughing at this point. How ballsy is our fearless intern? Will she go for it?

(14:47:32) Intern: netflix


Hell yeah she will!

(14:47:46) Me: that's because netflix is blocked
(14:47:56) Intern: blocked?
(14:48:03) Me: blocked.
(14:48:15) Intern: well how can it be blocked if i was just looking at it like 5 mins ago
(14:48:53) Me: I dunno... try youtube
(14:49:16) Intern: i was just updating my movies 
(14:49:17) Intern: its cool


BOFH: 1. Bandwidth hog: 0.

Date: 2007-10-19 07:26 pm (UTC)
From: [identity profile] gholam.livejournal.com
Thumbs down on the brute force approach. Traffic shaping to restrict streaming video bandwidth to something like 1kb/s would be ever so much more insidious :P

Date: 2007-10-19 07:33 pm (UTC)
From: [identity profile] mogaribue.livejournal.com
Agreed. We've found the best way to deal with this is use QoS/Squid Delay pools. Let them watch their movies, just very, very slowly.

Date: 2007-10-19 07:41 pm (UTC)
From: [identity profile] gholam.livejournal.com
Step 1: Replace it with something made in the 21st century.
Step 2: ???
Step 3: Profit!

Date: 2007-10-19 07:51 pm (UTC)
From: [identity profile] gholam.livejournal.com
Well, if you have a spare box with a pair of network interfaces and enough CPU/RAM (which shouldn't be too much), you can set up squid or something similar on it and put it as a transparent bridge in front or behind the existing router to add needed functions (traffic shaping, content filtering, spam filtering, etc).

Date: 2007-10-19 07:59 pm (UTC)
From: [identity profile] gholam.livejournal.com
This approach depends upon you killing video sites faster than the user can find them, and there are a lot to go around; then there's question of proxies, VPN connections, etc, etc. Of course it requires some technical knowledge on the part of the user, but hey, apparently they have nothing better to do...

Date: 2007-10-19 08:18 pm (UTC)
From: [identity profile] gholam.livejournal.com
True that, but if network admins were the ones responsible for firing people, the world would've been a much different place :)

Date: 2007-10-19 09:14 pm (UTC)
From: [identity profile] gholam.livejournal.com
That depends on how the management relates to network admin and the employee in question. In, unfortunately, too many cases, it's the admin who will be told to stop screwing around :(

Date: 2007-10-19 09:31 pm (UTC)
From: [identity profile] gholam.livejournal.com
There's management, and then there's management. What do you do when it's your immediate boss, who happens to own the business, hogging all the (quite limited) bandwidth by emailing porn to a list of a couple hundred people? True story there, except thankfully it wasn't my boss.

Date: 2007-10-19 10:14 pm (UTC)
From: [identity profile] dagbrown.livejournal.com
Ah, that would be "polish up the resume and find new job" time. If the company's boss spends all his time looking at porn instead of working, the company's doomed.

Date: 2007-10-19 10:16 pm (UTC)
From: [identity profile] gholam.livejournal.com
Owner's habits notwithstanding, they've been in business for quite a long time, and show no signs of closing down.

Date: 2007-10-20 04:06 am (UTC)
jecook: (Default)
From: [personal profile] jecook
+1.

Our company has a nanny filter installed on our T1 to the net that filters, (among other things) LJ. It's specifically mentioned during employee orientation that everyone who gets a network account that internet useage is monitored heavily, and that mis-using it is ground for disiplinary action and/or termination. Trying to get around said nanny filter is grounds for an instant termination.

Strangely enough, though, things like craigslist and youtube are not blocked. (I know that You tube used to be blocked, but someone managed to talk the network admin into deblocking it. go figure.)

Date: 2007-10-20 09:56 am (UTC)
From: [identity profile] benatwork.livejournal.com
The nanny filters here used to block livejournal.com. But *only* livejournal.com. username.livejournal, community.livejournal, all of those still worked. It only lasted about a week, though, since it was a new filter that is a whole lot less effective and badly configured than the old one.

Date: 2007-10-19 11:18 pm (UTC)
From: [identity profile] mouser.livejournal.com
Only if you can.

My current business won't let me do more than give them an official verbal warning. So, I just shut off ALL external access.

I'm in a one-deep position here, so they really are welcome to fire me.

Date: 2007-10-20 01:25 am (UTC)
From: [identity profile] superbus.livejournal.com
Easy:

"Sir, your intern is killing my bandwidth and seemingly has nothing better to do. Here are my packet logs."

Date: 2007-10-19 11:15 pm (UTC)
From: [identity profile] mouser.livejournal.com
The router may work, but it's ten years old. There are too many was around for a serious line of defense.

Time to move on, and reuse it somewhere else.

Personally, I like my SonicWall firewall. Especially since there is another group of people creating long lists of Proxy sites, pr0n sites, advertising, etc. that I can block.



Date: 2007-10-19 11:30 pm (UTC)
From: [identity profile] mogaribue.livejournal.com
We use a Squid proxy with delay pools, offending sites get dumped in there. We also use a Fortigate to block pr0n and do AV filtering.

Date: 2007-10-21 01:59 am (UTC)
From: [identity profile] erikarn.livejournal.com
People still use Squid? Cool.

*duck*

Date: 2007-10-19 07:26 pm (UTC)
From: [identity profile] http://users.livejournal.com/hub_/
priceless :-)

good job :-)

Date: 2007-10-19 07:28 pm (UTC)
From: [identity profile] arabwel.livejournal.com
*appalause*

Date: 2007-10-19 07:39 pm (UTC)
From: [identity profile] nem0.livejournal.com
Oh zing.

Same thing happened to me today, heh. Except the user's out until Monday, so I can't lay the smackdown on him yet.

It was kind of funny. I did a speed test on our network, got shitty speeds, traced which cable going into the switch panel was connected to his machine, yanked it, and ran another speed test. Our network instantly kicked back up to optimal speeds.

Remember, kids, don't mess with your BOFH.

Date: 2007-10-21 12:47 am (UTC)
reddragdiva: (Default)
From: [personal profile] reddragdiva
This is why keeping an antique 1baseT hub around to put between miscreant's cable and the switch is always useful. Half-duplex, of course.

Date: 2007-10-19 07:53 pm (UTC)
From: [identity profile] snarl817.livejournal.com
ROFLMAO!


I remember when I was an admin. The Sr. Network Engineer was a friend of mine, and we had just finished moving our datacenter to a new location, but the internet feed was still going out of the main office in Minnesota. One day he walks over to my desk and asks, "Hey, USWest has just finished connecting our dual T1 to the Internet. It's being used right now by me and the DNS server. Do you want a static NAT?"

Yeah. LOTS of bandwidth, and NOBODY to complain. I downloaded a LOT of porn from USENET using tin, and transported it home on ZIP disks.

Date: 2007-10-19 09:14 pm (UTC)
brotherflounder: (Default)
From: [personal profile] brotherflounder
A true BOFH would have accidentally forwarded these conversations to the intern director.

Just sayin'.

Nice smackdown, though.

Date: 2007-10-19 09:47 pm (UTC)
brotherflounder: (Default)
From: [personal profile] brotherflounder
BTW, where are you working? If it's *at* USC, I now know why said intern gets away with that...

Date: 2007-10-19 11:20 pm (UTC)
From: [identity profile] mouser.livejournal.com
I don't know the Netopia R9100 - can you close all ports and JUST open the 4-5 you really need?

Date: 2007-10-19 11:24 pm (UTC)
From: [identity profile] mouser.livejournal.com
(Quick search)

Ah. You should be able to block ports except for mail, web, and anything else you SPECIFICALLY need.

Date: 2007-10-20 01:28 am (UTC)
From: [identity profile] superbus.livejournal.com
Basically, lock down to 80, 443, 25, 110, 23, and maybe a port for VPN?

Date: 2007-10-20 03:00 am (UTC)
From: [identity profile] dagbrown.livejournal.com
23? I believe you misspelled "22" there.

Date: 2007-10-20 03:03 am (UTC)
From: [identity profile] mouser.livejournal.com
There are POSSIBLEY a few others you need, but not many, and should be checked on a case-by-case, but 10-20% of the CRAP I deal with is "off-port" stuff.

Date: 2007-10-20 02:45 am (UTC)
From: [identity profile] the-rkd.livejournal.com
Nicely done. Now accidentally forward the logs to the boss from the users email pretending to complain and blame the PFY

Date: 2007-10-20 04:01 am (UTC)
From: [identity profile] the-s-guy.livejournal.com
So is every external request coming from that intern's machine now being automatically logged, sorted by total bandwidth use to that site, and presented in a nice little Kill Now? list for your attention?

And no doubt there has been a policy document signed by the Higher Ups which, when translated from businessbabble, gives you the authority to block these sites? And if not, there is one being produced right now?

Date: 2007-10-23 12:21 pm (UTC)
From: [identity profile] the-reda.livejournal.com
Isn't there some spare pointless filing she could do? I am sure the colleagues can come up with some ;-)

Profile

techrecovery: (Default)
Elitist Computer Nerd Posse

April 2017

S M T W T F S
      1
2345678
91011121314 15
16171819202122
23242526272829
30      

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Mar. 19th, 2026 09:00 pm
Powered by Dreamwidth Studios