SlideShare a Scribd company logo
1 of 11
Internet Filtering
for E-Rate CIPA Compliance and Cybersecurity
Filtering
The Router
DHCP
DNS
Gateway
NAT
WiFi
Methods
Device Level
Network Level
Cloud
Device
Cybersecurity
Filtering
Packet Inspection
E-rate
CIPA
What’s Required
Disabling
The Router
(It’s so busy!)
• The Modem & Gateway – connects the ISP’s
(Internet Service Provider) network to the
library’s LAN (Local Area Network)
• DHCP (Dynamic Host Configuration Protocol)
• When a device boots/powers up, the DHCP server
provides all the network addressing info
• DNS (Domain Name Server, port 53)
• The Internet’s phone book
• URL (Uniform Resource Locator) to IP (Internet
Protocol) Address
• Caching for speed boost but delays change
propagation.
• NAT (Network Address Translation, port 5351)
• Leases a Private IP Address to a device
• Library’s Public IP Address from the ISP
• Static & Dynamic
• The dreaded CIN (Copyright Infringement Notice)
letter from your ISP/RIAA/MPA.
• Block BitTorrent app!
• WiFi Server
• and the VPN (Virtual Private Network) Server?
Whew!
• Add an “edge” router and/or WAP (Wireless
Access Point) to improve WiFi performance?
Device Level
• PCs will automatically use the DNS server DHCP
tells it to by default
• The PCs can be set to use a different DNS server
• Change it in Windows
• Safe Search on the browser is not a CIPA
compliant filter.
Cloud Based
• Free filters can be too restrictive with no ability to modify them (use
OpenDNS Home, maybe NextDNS?)
• DNSFilter (Basic cybersecurity. NLC provided solution!)
• Cisco Umbrella (Strong cybersecurity. Expensive.)
• Pricing may be an issue since many cloud options are per user. Talk with
your vendor about pricing for a library and education discounts.
• At a minimum, use Quad9 for free cybersecurity.
DNS Filtering Methods
Network Level
• Change it on the Router
• All devices using DHCP
• VLAN (Virtual Local Area Network)
• Requires a high-end router or firewall
• Leave the Public WiFi unfiltered?
Local Device Based
• Firewalls have it as a built-in feature. (Ubiquiti’s Dream Machine
firewall uses free CleanBrowsing and it’s too restrictive.)
• App on the PCs. CyberSitter is a popular one.
• CyberSitter BLACK (New! $195)
• Raspberry Pi based on Pi-hole ad blocker distro
• Squidguard is another Raspberry Pi option
Modifying DNS Network Settings
• On a PC (Windows 11 Network Properties) • On a Router (Netgear Orbi)
DNS Filtering (outbound)
• DNS
• Domain (google.com, wikipedia.org)
• Subdomain (www.google.com, en.wikipedia.org)
• Top Level Domain (Russia, *.ru)
• IP4 Address (32-bit, 142.250.191.206)
• IP6 Address (128-bit, 2607:f8b0:4009:81a::200e)
• Utilize IP4 address of your DNS filter vendor’s DNS server
• Whitelists (good places)
• Blacklists (bad places)
• Block Screen issues (HTTP vs HTTPS)
• Load DNS filter vendor’s certificate on PCs to fix
Firewalls (inbound & outbound)
• DNS Filtering
• Stateful, packet inspection
• Stateless, packet filter
• App & Port blocking
• Deep Inspection is the new standard
• Examines the entire packet in detail
• Has to be high performing ($$$) so as not cause lag
• NGFW (Next-Generation Firewall) throughput in
mbps is a measure of throughput when IPS
(Intrusion Prevention Services) and AC
(Application Control) are running
Cybersecurity
Filtered Website Results
HTTP or HTTPS with the DNSFilter Certificate installed.
This is the “block” screen. The block can be bypassed with the
use of the bypass password. Once bypassed, NO filtering will be
performed for the duration of the browser session.
Filtered Website Results
HTTPS and the DNSFilter Certificate is not installed.
Recommend installing the DNSFilter Certificate on the Public
PCs to get the block screen.
Filtered Website Results
The Dynamic IP address changed. The DNSFilter deployment (library) has to
be updated with the new Dynamic IP address for Internet access.
Request a Static IP address from your ISP to prevent this. If the ISP
can’t provide one, Dynamic DNS can be utilized.
CIPA (Children's Internet Protection Act)
• Internet Safety Policy
• Public Notice and Hearing/Meeting
• Technology Protection Measure
• “a specific technology that blocks or filters internet
access.”
• “that protects against access by adults and minors to
visual depictions that are obscene, child pornography, or –
with respect to use of computers with internet access by
minors – harmful to minors. “
• Enabled on all library owned devices with Internet access
Disabling the filter
• “the library may disable the technology protection
measure during use by an adult to enable access
for bona fide research or other lawful purpose.”
• Disable via app/client on the PC?
• Use the DNS filter’s bypass password?
• Add to DNS filter account’s whitelist?
• Login to DNS Filter account to add
• Not instantaneous with caching
• Modify DNS setting on the PC
• Ethernet or WiFi?
• Switch to Manual
• Use Google’s IP4 DNS servers
• Preferred: 8.8.8.8 and Alternate: 8.8.4.4
• Requires Admin login to save
• Will need to be switched back to Automatic (DHCP)
• Reboot/Restore in place? (It should be!)
E-Rate
What’s required (USAC)?
• ALA (American Library Association)
• FCC (Federal Communications Commission)
• NLC ( Nebraska Library Commission)
• USAC (Universal Service Administrative Company)
My contact info:
Andrew “Sherm” Sherman
Library Technology Support Specialist
Nebraska Library Commission
402-471-4559
andrew.Sherman@nebraska.gov

More Related Content

Similar to NCompass Live: Pretty Sweet Tech: Internet Filtering For E-Rate CIPA Compliance And Cybersecurity

CWNP The Evolution Of Guest Access
CWNP The Evolution Of Guest AccessCWNP The Evolution Of Guest Access
CWNP The Evolution Of Guest Access
Ali Youssef
 
FYP%3A+Peer-to-Peer+Communication+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communication+Framework+on+Android+PlatformFYP%3A+Peer-to-Peer+Communication+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communication+Framework+on+Android+Platform
Tianwei_liu
 
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+PlatformFYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
webuiltit
 
FYP: Peer-to-Peer Communications Framework on Android Platform
FYP: Peer-to-Peer Communications Framework on Android PlatformFYP: Peer-to-Peer Communications Framework on Android Platform
FYP: Peer-to-Peer Communications Framework on Android Platform
webuiltit
 
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+PlatformFYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
Tianwei_liu
 
FYP%3A+P2P+Bluetooth+Communication+Framework+on+Android%0A
FYP%3A+P2P+Bluetooth+Communication+Framework+on+Android%0AFYP%3A+P2P+Bluetooth+Communication+Framework+on+Android%0A
FYP%3A+P2P+Bluetooth+Communication+Framework+on+Android%0A
Tianwei_liu
 
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+PlatformFYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
webuiltit
 

Similar to NCompass Live: Pretty Sweet Tech: Internet Filtering For E-Rate CIPA Compliance And Cybersecurity (20)

Forefront UAG
Forefront UAGForefront UAG
Forefront UAG
 
CWNP The Evolution Of Guest Access
CWNP The Evolution Of Guest AccessCWNP The Evolution Of Guest Access
CWNP The Evolution Of Guest Access
 
MVA slides lesson 6
MVA slides lesson 6MVA slides lesson 6
MVA slides lesson 6
 
98 366 mva slides lesson 6
98 366 mva slides lesson 698 366 mva slides lesson 6
98 366 mva slides lesson 6
 
heng+hong
heng+hongheng+hong
heng+hong
 
FYP%3A+Peer-to-Peer+Communication+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communication+Framework+on+Android+PlatformFYP%3A+Peer-to-Peer+Communication+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communication+Framework+on+Android+Platform
 
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+PlatformFYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
 
FYP: Peer-to-Peer Communications Framework on Android Platform
FYP: Peer-to-Peer Communications Framework on Android PlatformFYP: Peer-to-Peer Communications Framework on Android Platform
FYP: Peer-to-Peer Communications Framework on Android Platform
 
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+PlatformFYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
 
FYP%3A+P2P+Bluetooth+Communication+Framework+on+Android%0A
FYP%3A+P2P+Bluetooth+Communication+Framework+on+Android%0AFYP%3A+P2P+Bluetooth+Communication+Framework+on+Android%0A
FYP%3A+P2P+Bluetooth+Communication+Framework+on+Android%0A
 
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+PlatformFYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
FYP%3A+Peer-to-Peer+Communications+Framework+on+Android+Platform
 
Denial of Service - Service Provider Overview
Denial of Service - Service Provider OverviewDenial of Service - Service Provider Overview
Denial of Service - Service Provider Overview
 
Vp ns
Vp nsVp ns
Vp ns
 
Should I run my own RPKI Certificate Authority?
Should I run my own RPKI Certificate Authority?Should I run my own RPKI Certificate Authority?
Should I run my own RPKI Certificate Authority?
 
DDoS Mitigation using BGP Flowspec
DDoS Mitigation using BGP Flowspec DDoS Mitigation using BGP Flowspec
DDoS Mitigation using BGP Flowspec
 
Iphone App in 30 Minutes - Barcamp Nashville 2011
Iphone App in 30 Minutes - Barcamp Nashville 2011Iphone App in 30 Minutes - Barcamp Nashville 2011
Iphone App in 30 Minutes - Barcamp Nashville 2011
 
Elements of Connected Products
Elements of Connected ProductsElements of Connected Products
Elements of Connected Products
 
LAN Security
LAN Security LAN Security
LAN Security
 
Web Application Debugging Webinar
Web Application Debugging WebinarWeb Application Debugging Webinar
Web Application Debugging Webinar
 
Etherfast3828
Etherfast3828Etherfast3828
Etherfast3828
 

More from Nebraska Library Commission

NCompass Live: Auditing Library Websites
NCompass Live: Auditing Library WebsitesNCompass Live: Auditing Library Websites
NCompass Live: Auditing Library Websites
Nebraska Library Commission
 

More from Nebraska Library Commission (20)

NCompass Live: Program Planning with a Marketing Mindset
NCompass Live: Program Planning with a Marketing MindsetNCompass Live: Program Planning with a Marketing Mindset
NCompass Live: Program Planning with a Marketing Mindset
 
Big Talk From Small Libraries 2024: Afterschool Meals Program: Sign-In Sheet ...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Sign-In Sheet ...Big Talk From Small Libraries 2024: Afterschool Meals Program: Sign-In Sheet ...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Sign-In Sheet ...
 
Big Talk From Small Libraries 2024: Afterschool Meals Program: Sign-In & Out ...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Sign-In & Out ...Big Talk From Small Libraries 2024: Afterschool Meals Program: Sign-In & Out ...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Sign-In & Out ...
 
Big Talk From Small Libraries 2024: Afterschool Meals Program: Leftover Meal ...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Leftover Meal ...Big Talk From Small Libraries 2024: Afterschool Meals Program: Leftover Meal ...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Leftover Meal ...
 
Big Talk From Small Libraries 2024: Afterschool Meals Program: Daily Meal Cou...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Daily Meal Cou...Big Talk From Small Libraries 2024: Afterschool Meals Program: Daily Meal Cou...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Daily Meal Cou...
 
Big Talk From Small Libraries 2024: Afterschool Meals Program: Allergies & ...
Big Talk From Small Libraries 2024:  Afterschool Meals  Program: Allergies & ...Big Talk From Small Libraries 2024:  Afterschool Meals  Program: Allergies & ...
Big Talk From Small Libraries 2024: Afterschool Meals Program: Allergies & ...
 
Big Talk From Small Libraries 2024: Memory Cafés: A Community Program
Big Talk From Small Libraries 2024:  Memory Cafés: A Community ProgramBig Talk From Small Libraries 2024:  Memory Cafés: A Community Program
Big Talk From Small Libraries 2024: Memory Cafés: A Community Program
 
Big Talk From Small Libraries 2024: Genrefying your Public Library
Big Talk From Small Libraries 2024:  Genrefying your Public LibraryBig Talk From Small Libraries 2024:  Genrefying your Public Library
Big Talk From Small Libraries 2024: Genrefying your Public Library
 
Big Talk From Small Libraries 2024: Case Study: Implementing an Afterschool ...
Big Talk From Small Libraries 2024:  Case Study: Implementing an Afterschool ...Big Talk From Small Libraries 2024:  Case Study: Implementing an Afterschool ...
Big Talk From Small Libraries 2024: Case Study: Implementing an Afterschool ...
 
Big Talk From Small Libraries 2024: Farmer’s Day Fundraising
Big Talk From Small Libraries 2024: Farmer’s Day FundraisingBig Talk From Small Libraries 2024: Farmer’s Day Fundraising
Big Talk From Small Libraries 2024: Farmer’s Day Fundraising
 
Big Talk From Small Libraries 2024: Towering Bookstacks and Heavy Doors: Less...
Big Talk From Small Libraries 2024: Towering Bookstacks and Heavy Doors: Less...Big Talk From Small Libraries 2024: Towering Bookstacks and Heavy Doors: Less...
Big Talk From Small Libraries 2024: Towering Bookstacks and Heavy Doors: Less...
 
Big Talk From Small Libraries 2024: Accepting Credit Cards with PayPort
Big Talk From Small Libraries 2024: Accepting Credit Cards with PayPortBig Talk From Small Libraries 2024: Accepting Credit Cards with PayPort
Big Talk From Small Libraries 2024: Accepting Credit Cards with PayPort
 
Big Talk From Small Libraries 2024: Leveraging Student Projects and Organizat...
Big Talk From Small Libraries 2024: Leveraging Student Projects and Organizat...Big Talk From Small Libraries 2024: Leveraging Student Projects and Organizat...
Big Talk From Small Libraries 2024: Leveraging Student Projects and Organizat...
 
NCompass Live: Winning Grants for Your Library Programming
NCompass Live: Winning Grants for Your Library ProgrammingNCompass Live: Winning Grants for Your Library Programming
NCompass Live: Winning Grants for Your Library Programming
 
NCompass Live: ConnectEd Nebraska: Bridging the Digital Divide through Innova...
NCompass Live: ConnectEd Nebraska: Bridging the Digital Divide through Innova...NCompass Live: ConnectEd Nebraska: Bridging the Digital Divide through Innova...
NCompass Live: ConnectEd Nebraska: Bridging the Digital Divide through Innova...
 
NCompass Live: WiFi In the Library
NCompass Live: WiFi In the LibraryNCompass Live: WiFi In the Library
NCompass Live: WiFi In the Library
 
NCompass Live: Best of the Best Teen Reads of 2023
NCompass Live: Best of the Best Teen Reads of 2023NCompass Live: Best of the Best Teen Reads of 2023
NCompass Live: Best of the Best Teen Reads of 2023
 
NCompass Live: Auditing Library Websites
NCompass Live: Auditing Library WebsitesNCompass Live: Auditing Library Websites
NCompass Live: Auditing Library Websites
 
NCompass Live: Meet the NLC, Part 2
NCompass Live: Meet the NLC, Part 2NCompass Live: Meet the NLC, Part 2
NCompass Live: Meet the NLC, Part 2
 
NCompass Live: Meet the NLC, Part 1
NCompass Live: Meet the NLC, Part 1NCompass Live: Meet the NLC, Part 1
NCompass Live: Meet the NLC, Part 1
 

Recently uploaded

The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
heathfieldcps1
 

Recently uploaded (20)

Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
 
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptxSKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - English
 
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfUGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
 
HMCS Max Bernays Pre-Deployment Brief (May 2024).pptx
HMCS Max Bernays Pre-Deployment Brief (May 2024).pptxHMCS Max Bernays Pre-Deployment Brief (May 2024).pptx
HMCS Max Bernays Pre-Deployment Brief (May 2024).pptx
 
Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...
 
How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17
 
REMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptxREMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptx
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptx
 
Micro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfMicro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdf
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
 
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
 
Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.ppt
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 
Fostering Friendships - Enhancing Social Bonds in the Classroom
Fostering Friendships - Enhancing Social Bonds  in the ClassroomFostering Friendships - Enhancing Social Bonds  in the Classroom
Fostering Friendships - Enhancing Social Bonds in the Classroom
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
 

NCompass Live: Pretty Sweet Tech: Internet Filtering For E-Rate CIPA Compliance And Cybersecurity

  • 1. Internet Filtering for E-Rate CIPA Compliance and Cybersecurity
  • 2. Filtering The Router DHCP DNS Gateway NAT WiFi Methods Device Level Network Level Cloud Device Cybersecurity Filtering Packet Inspection E-rate CIPA What’s Required Disabling
  • 3. The Router (It’s so busy!) • The Modem & Gateway – connects the ISP’s (Internet Service Provider) network to the library’s LAN (Local Area Network) • DHCP (Dynamic Host Configuration Protocol) • When a device boots/powers up, the DHCP server provides all the network addressing info • DNS (Domain Name Server, port 53) • The Internet’s phone book • URL (Uniform Resource Locator) to IP (Internet Protocol) Address • Caching for speed boost but delays change propagation. • NAT (Network Address Translation, port 5351) • Leases a Private IP Address to a device • Library’s Public IP Address from the ISP • Static & Dynamic • The dreaded CIN (Copyright Infringement Notice) letter from your ISP/RIAA/MPA. • Block BitTorrent app! • WiFi Server • and the VPN (Virtual Private Network) Server? Whew! • Add an “edge” router and/or WAP (Wireless Access Point) to improve WiFi performance?
  • 4. Device Level • PCs will automatically use the DNS server DHCP tells it to by default • The PCs can be set to use a different DNS server • Change it in Windows • Safe Search on the browser is not a CIPA compliant filter. Cloud Based • Free filters can be too restrictive with no ability to modify them (use OpenDNS Home, maybe NextDNS?) • DNSFilter (Basic cybersecurity. NLC provided solution!) • Cisco Umbrella (Strong cybersecurity. Expensive.) • Pricing may be an issue since many cloud options are per user. Talk with your vendor about pricing for a library and education discounts. • At a minimum, use Quad9 for free cybersecurity. DNS Filtering Methods Network Level • Change it on the Router • All devices using DHCP • VLAN (Virtual Local Area Network) • Requires a high-end router or firewall • Leave the Public WiFi unfiltered? Local Device Based • Firewalls have it as a built-in feature. (Ubiquiti’s Dream Machine firewall uses free CleanBrowsing and it’s too restrictive.) • App on the PCs. CyberSitter is a popular one. • CyberSitter BLACK (New! $195) • Raspberry Pi based on Pi-hole ad blocker distro • Squidguard is another Raspberry Pi option
  • 5. Modifying DNS Network Settings • On a PC (Windows 11 Network Properties) • On a Router (Netgear Orbi)
  • 6. DNS Filtering (outbound) • DNS • Domain (google.com, wikipedia.org) • Subdomain (www.google.com, en.wikipedia.org) • Top Level Domain (Russia, *.ru) • IP4 Address (32-bit, 142.250.191.206) • IP6 Address (128-bit, 2607:f8b0:4009:81a::200e) • Utilize IP4 address of your DNS filter vendor’s DNS server • Whitelists (good places) • Blacklists (bad places) • Block Screen issues (HTTP vs HTTPS) • Load DNS filter vendor’s certificate on PCs to fix Firewalls (inbound & outbound) • DNS Filtering • Stateful, packet inspection • Stateless, packet filter • App & Port blocking • Deep Inspection is the new standard • Examines the entire packet in detail • Has to be high performing ($$$) so as not cause lag • NGFW (Next-Generation Firewall) throughput in mbps is a measure of throughput when IPS (Intrusion Prevention Services) and AC (Application Control) are running Cybersecurity
  • 7. Filtered Website Results HTTP or HTTPS with the DNSFilter Certificate installed. This is the “block” screen. The block can be bypassed with the use of the bypass password. Once bypassed, NO filtering will be performed for the duration of the browser session.
  • 8. Filtered Website Results HTTPS and the DNSFilter Certificate is not installed. Recommend installing the DNSFilter Certificate on the Public PCs to get the block screen.
  • 9. Filtered Website Results The Dynamic IP address changed. The DNSFilter deployment (library) has to be updated with the new Dynamic IP address for Internet access. Request a Static IP address from your ISP to prevent this. If the ISP can’t provide one, Dynamic DNS can be utilized.
  • 10. CIPA (Children's Internet Protection Act) • Internet Safety Policy • Public Notice and Hearing/Meeting • Technology Protection Measure • “a specific technology that blocks or filters internet access.” • “that protects against access by adults and minors to visual depictions that are obscene, child pornography, or – with respect to use of computers with internet access by minors – harmful to minors. “ • Enabled on all library owned devices with Internet access Disabling the filter • “the library may disable the technology protection measure during use by an adult to enable access for bona fide research or other lawful purpose.” • Disable via app/client on the PC? • Use the DNS filter’s bypass password? • Add to DNS filter account’s whitelist? • Login to DNS Filter account to add • Not instantaneous with caching • Modify DNS setting on the PC • Ethernet or WiFi? • Switch to Manual • Use Google’s IP4 DNS servers • Preferred: 8.8.8.8 and Alternate: 8.8.4.4 • Requires Admin login to save • Will need to be switched back to Automatic (DHCP) • Reboot/Restore in place? (It should be!) E-Rate What’s required (USAC)? • ALA (American Library Association) • FCC (Federal Communications Commission) • NLC ( Nebraska Library Commission) • USAC (Universal Service Administrative Company)
  • 11. My contact info: Andrew “Sherm” Sherman Library Technology Support Specialist Nebraska Library Commission 402-471-4559 andrew.Sherman@nebraska.gov