Category: RM

RM Unify AD Sync

There is an important update regarding RM Unify AD Sync and upcoming changes from Microsoft that may impact your service.

Microsoft Azure are ending support for Transport Layer Security (TLS) 1.0 and 1.1 ending 31st October 2024. For more information, please read the blog from Microsoft:

https://azure.microsoft.com/en-us/updates/azure-support-tls-will-end-by-31-october-2024-2/

This change directly affects how the RM Unify AD Sync service communicates with RM Unify. Without action, RM Unify AD sync may stop providing user updates to RM Unify and other services, for example, RM SafetyNet.

Action Required:

You will need to run an application on your server to force a minimum version of TLS 1.2 in advance of the deadline imposed by Microsoft on 31st October 2024. Please follow the link to this RM article for instructions to install the update on your server:

Security update for RM Unify AD Sync

(There is no further action for schools that have a HFL technical support contract as this change has been carried out by our engineers)

Network maintenance and change freeze in July

RM have purchased some new hardware and it will be used to replace the existing central firewall clusters. The existing hardware is approaching full capacity so this work obviously needs to go ahead. The new hardware will be the latest model with a lot more capacity and it will be a direct swap out.

The work will involve copying all the firewall config data and then over three nights (2nd, 3rd and 4th July) the platform will be updated. I am assured that it is “low risk” particularly as the same software version will be used on the new hardware. However, if there are problems, it will be straight forward enough to quickly roll back the changes.

Both RM and HFL are keen that this work goes ahead now rather than waiting for the summer holidays. This is because if in the unlikely event that there are issues, they may not present themselves until schools return in September, when there is high traffic.

This event will incur a change freeze meaning that new firewall rules cannot be created from Monday 1st July 9AM through to Friday 5th July 10AM. This will allow RM to copy over the up-to-date firewall config data. With this in mind, over this period we will not be able to create new firewall rules. This includes RM making firewall changes as well as HFL/School IT Support updating access within SafetyNet.

If you have any queries or concerns, please get in touch with HFL Broadband Support and/or Kevin Crawley.

Planned upgrade of firewall

In the early hours of Thursday 21st April, RM will be carrying out some work to upgrade the firewalls. If this work doesn’t go ahead, the current version of the software on the firewalls will reach end of engineering support with the vendor. This means they will only provide fixes for industry wide critical issues and vulnerabilities. With this in mind, RM need to upgrade the software version to maintain full levels of vendor support.

RM and HfL have discussed this in detail and RM are confident that normal service will continue without any service disruption. RM and HfL will be fully staffed with the relevant resource should anything unforeseen occur. If you have any concerns or queries in relation to this work – either before, or after the upgrade has been carried out, please get in touch with the HfL Broadband Team.

Thanks,

Kevin Crawley
HfL Broadband Lead

Proxy issues?

In the early hours of this morning, RM engineers added some new SafetyNet Load Balancers into service. This was planned maintenance work to ensure the service remains stable. We have received some reports this morning advising us that there are problems browsing the internet today. This is back with RM who are investigating…

I’ll add another update shortly.

Thanks,

Kevin Crawley

Speed issues

We believe this has now been resolved. It looks like there were two simultaneous issues;

  • RM’s transit to Google was being maxed out. RM will be implementing new routers with 100G links to deal with the increased traffic volumes. RM is hoping for this will be completed by the end of the month.
  • There were also six minor DDoS attacks to the proxy farm IPs at the same time of high utilisation of Google traffic. RM is working with a third party company to mitigate these attacks. As they were minor attacks, it didn’t trigger the automatic mitigation system. RM will be working closely with their third party to investigate what went wrong and to make sure this doesn’t happen again.

If there are any further queries, please contact the HfL Broadband Team.

Possible Google update and reports of slow internet

Yesterday afternoon (18th October) we received some reports of slow internet.

RM suspect that there was a Google update released which resulted in higher than usual volumes of traffic – and this in turn would cause a slow internet experience. Typically, the RM transit (for Google) utilises at a maximum of 8Gbps, but yesterday it went over 10Gbps.

In fact there were three instances yesterday where the transit bandwidth utilisation exceeded the capacity, timescales for which are updated below.

8.48-9.08
11.25-11.40
13.55-14.03

RM is closely monitoring the situation.