stop hogging my damn bandwidth!
Oct. 19th, 2007 02:56 pmThe major function of our (very well paid) intern seems to be to stream video all day long, grinding our internet access to a halt. After the billionth time discovering I couldn't get patches downloaded in a reasonable amount of time because our T1 was getting hammered by the intern watching YouTube videos, I hit the router and slapped an output filter on youtube's netblock. This was a couple weeks ago. Surprisingly, I never did get any questions about "hey is the internet working?" (although the coworker across the desk from me did.)
Today, I got this cut and paste from said coworker:
O RLY? Fuck that, I have source to download and packages to build. AKA, you know, "work".
/me slaps an output filter on netflix.com's netblock
Hey, somebody wants to IM me!
My coworker and I are howling laughing at this point. How ballsy is our fearless intern? Will she go for it?
Hell yeah she will!
BOFH: 1. Bandwidth hog: 0.
Today, I got this cut and paste from said coworker:
(14:25:00) Coworker: help us all ... here goes the bandwidth
(14:24:27) Intern: yea its getting on my nerves
(14:24:33) Intern: im bored maybe i will watch a movie on netflixO RLY? Fuck that, I have source to download and packages to build. AKA, you know, "work".
/me slaps an output filter on netflix.com's netblock
Hey, somebody wants to IM me!
(14:46:51) Intern: is something wrong with the internet? (14:47:08) Me: nope... why do you ask? (14:47:16) Intern: it keeps saying problem loading page (14:47:26) Me: what page are you loading?
My coworker and I are howling laughing at this point. How ballsy is our fearless intern? Will she go for it?
(14:47:32) Intern: netflix
Hell yeah she will!
(14:47:46) Me: that's because netflix is blocked (14:47:56) Intern: blocked? (14:48:03) Me: blocked. (14:48:15) Intern: well how can it be blocked if i was just looking at it like 5 mins ago (14:48:53) Me: I dunno... try youtube (14:49:16) Intern: i was just updating my movies (14:49:17) Intern: its cool
BOFH: 1. Bandwidth hog: 0.
no subject
Date: 2007-10-19 07:26 pm (UTC)no subject
Date: 2007-10-19 07:33 pm (UTC)no subject
Date: 2007-10-19 07:38 pm (UTC)no subject
Date: 2007-10-19 07:41 pm (UTC)Step 2: ???
Step 3: Profit!
no subject
Date: 2007-10-19 07:48 pm (UTC)no subject
Date: 2007-10-19 07:51 pm (UTC)no subject
Date: 2007-10-19 07:54 pm (UTC)"Kill video sites" is more than granular enough to meet my needs for traffic shaping at the moment.
no subject
Date: 2007-10-19 07:59 pm (UTC)no subject
Date: 2007-10-19 08:17 pm (UTC)The correct response to users who proxy or VPN around blocks to watch videos is not to play technical one-upsmanship with them, it's to fire them.
no subject
Date: 2007-10-19 08:18 pm (UTC)no subject
Date: 2007-10-19 08:27 pm (UTC)Dude, I might or might not be able to get somebody fired for watching streaming video at work. (I most likely could, but I would almost certainly not try.) Someone who deliberately contravenes security measures, on the other hand, is fucking toast.
Slapping down a netblock is like locking my house. It's a hell of a lot harder for a 10 year old kid to stammer excuses about why you found him in your living room when he's holding a bigass screwdriver and the sill is broken on one of your windows than if he just walked in through the open front door. "Oh um I saw a cat... in the yard? And I thought it was yours?" Nice try junior, now you and me and that big fucking screwdriver are going to go have a talk with your parents.
no subject
Date: 2007-10-19 09:14 pm (UTC)no subject
Date: 2007-10-19 09:21 pm (UTC)no subject
Date: 2007-10-19 09:31 pm (UTC)no subject
Date: 2007-10-19 10:14 pm (UTC)no subject
Date: 2007-10-19 10:16 pm (UTC)no subject
Date: 2007-10-20 04:06 am (UTC)Our company has a nanny filter installed on our T1 to the net that filters, (among other things) LJ. It's specifically mentioned during employee orientation that everyone who gets a network account that internet useage is monitored heavily, and that mis-using it is ground for disiplinary action and/or termination. Trying to get around said nanny filter is grounds for an instant termination.
Strangely enough, though, things like craigslist and youtube are not blocked. (I know that You tube used to be blocked, but someone managed to talk the network admin into deblocking it. go figure.)
no subject
Date: 2007-10-20 09:56 am (UTC)no subject
Date: 2007-10-19 11:18 pm (UTC)My current business won't let me do more than give them an official verbal warning. So, I just shut off ALL external access.
I'm in a one-deep position here, so they really are welcome to fire me.
no subject
Date: 2007-10-20 01:25 am (UTC)"Sir, your intern is killing my bandwidth and seemingly has nothing better to do. Here are my packet logs."
no subject
Date: 2007-10-19 11:15 pm (UTC)Time to move on, and reuse it somewhere else.
Personally, I like my SonicWall firewall. Especially since there is another group of people creating long lists of Proxy sites, pr0n sites, advertising, etc. that I can block.
no subject
Date: 2007-10-19 11:30 pm (UTC)no subject
Date: 2007-10-21 01:59 am (UTC)*duck*
no subject
Date: 2007-10-19 07:26 pm (UTC)good job :-)
no subject
Date: 2007-10-19 07:28 pm (UTC)no subject
Date: 2007-10-19 07:39 pm (UTC)Same thing happened to me today, heh. Except the user's out until Monday, so I can't lay the smackdown on him yet.
It was kind of funny. I did a speed test on our network, got shitty speeds, traced which cable going into the switch panel was connected to his machine, yanked it, and ran another speed test. Our network instantly kicked back up to optimal speeds.
Remember, kids, don't mess with your BOFH.
no subject
Date: 2007-10-21 12:47 am (UTC)no subject
Date: 2007-10-19 07:53 pm (UTC)I remember when I was an admin. The Sr. Network Engineer was a friend of mine, and we had just finished moving our datacenter to a new location, but the internet feed was still going out of the main office in Minnesota. One day he walks over to my desk and asks, "Hey, USWest has just finished connecting our dual T1 to the Internet. It's being used right now by me and the DNS server. Do you want a static NAT?"
Yeah. LOTS of bandwidth, and NOBODY to complain. I downloaded a LOT of porn from USENET using tin, and transported it home on ZIP disks.
no subject
Date: 2007-10-19 09:14 pm (UTC)Just sayin'.
Nice smackdown, though.
no subject
Date: 2007-10-19 09:47 pm (UTC)no subject
Date: 2007-10-20 12:51 am (UTC)no subject
Date: 2007-10-19 11:20 pm (UTC)no subject
Date: 2007-10-19 11:24 pm (UTC)Ah. You should be able to block ports except for mail, web, and anything else you SPECIFICALLY need.
no subject
Date: 2007-10-20 01:28 am (UTC)no subject
Date: 2007-10-20 03:00 am (UTC)no subject
Date: 2007-10-20 03:03 am (UTC)no subject
Date: 2007-10-20 02:45 am (UTC)no subject
Date: 2007-10-20 04:01 am (UTC)And no doubt there has been a policy document signed by the Higher Ups which, when translated from businessbabble, gives you the authority to block these sites? And if not, there is one being produced right now?
no subject
Date: 2007-10-23 12:21 pm (UTC)pointlessfiling she could do? I am sure the colleagues can come up with some ;-)