Message-ID: <14420423.1182488864336.JavaMail.joeescobar@joe-escobars-computer.local>
Date: Wed, 6 Dec 2006 02:52:35 -0800 (PST)
From: timmerst
Reply-To: Online
Subject: Re: Possible solution for secure testing IP address lists
Mime-Version: 1.0
Content-Type: multipart/mixed; 
	boundary="----=_Part_1091_12056456.1182488864335"
GWItemID: 4575CE03.LCC-Mail.MC_PO3.100.1346735.1.266A.1

------=_Part_1091_12056456.1182488864335
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit


Hi Joe-- 
I can type in the new list tomorrow into my IP test Quiz and see if the outreach folks can test it on their computers.  I want to make sure we don't have a problem with the tests being viewable from students' home computers before we make the changes. 
TT 
 
>>>Online 12/05/06 6:29 pm >>> 
 
Great work David, 
 
If you have verified that this does, in fact, work, then we can make this change on the Moodle server default page for Quizzes (where I have the current, longer list).  Obviousely, our goal would be to minimize typing of IP addresses.  
 
 
My fix only works for newly created quizzes which use the template.  I'm guessing that any class backed up and restored from a previous term would NOT have the correct numbers inserted automatically.   
 
 
So, might I suggest a database search and replace during the first week of the term.  That should get most people, any new tests will be correct from the template, and Toni can warn the rest of the instructors (those who don't restore a backup during the first week) to get it right. 
 
 
 
Joe 
 
 
 
 
 
>>>moodleadmin 12/05/06 1:14 pm >>> 
 
Toni, 
 
 
If you want to cut down on the number of characters in the IP address lists, the following would handle all of the machines you included in your practice quiz (Toni's Testing > Quiz): 
 
 
10.1.0.167,10.9.129.33,10.22.0.142,172.20.33.161/29,172.20.32.15/27 
 
 
I think the range concept probably didn't work before because you specified the ranges as 172.20.33.161/65 or 172.20.33.161/165 or something like that.  The number after the slash isn't the last address of the range, but is actually a subnet mask, which works very differently.  I entered the range above on your practice quiz on our test server (not production), and it successfully blocked my machine from taking a quiz.  If you like, you could experiment to verify that it works at Florence, et al by putting this in for your test quiz and seeing whether they can access it. 
 
 
The one caveat is that subnet ranges aren't very granular; by their nature, they specify predefined blocks of addresses, which may include some addresses that you don't want to allow.  The 172.20.33.161/29 range, for example, includes 172.20.33.161 - 172.20.33.167, the second one 172.20.32.0 - 172.20.32.31.  I may be able to work with Thad to make sure that these unwanted IP addresses aren't actually used in Cottage Grove and Florence (so that opening up the range won't be a security breach), but if you're dealing with a large number of different ranges, then this could become a problem. 
 
 
I'll take a look at expanding the size of the database field for Winter so we aren't so limited in what we can include, but let's also keep in mind that the more we grow this list, the more prone we'll be to typos and such from faculty members. 
 
 
David 
 
 
 
---- 
 
David Walton 
 
Web/Moodle administration and identity management 
 
Information Technology 
 
Lane Community College 
 
Email: waltond@lanecc.edu 
 
Voice: 541-463-3367 
 

------=_Part_1091_12056456.1182488864335--
