Gaz Posted April 5, 2016 Posted April 5, 2016 I was in a meeting today centred around internet and network access at our new site we are due to move into later this year. The site will have WiFi site wide with only 3 rooms being cabled for CAD suites. The WiFi will be installed and managed by a 3rd party and I won't have access to it, I've been told that there will be 2 wireless networks a secure network and a BYOD type open access network. It was raised at the meeting that that may not be the most flexible solution. The 3rd party as we shall call them was going to buy all the tablets for the students, but that would mean they would need to control them and that is costing too much money. They proposed that we buy the 70 devices but when I asked if we could have access to install a server or access to the WiFi I was told no. So the jist of that is that they thought we could buy 70 devices and have no means of centrally managing them. We do have 2 remote networks that they could be linked back to, to be managed but thats the bit I'm clueless on. I could use remote desktop so they could access all the applications on the remote server but I don't know how thats mean't to work over the internet as its an application that gets loaded once you log into Windows. So I guess what I need to know is how do I link these devices back to the remote network. Sorry it sounds like I'm waffling but this is unfamiliar territory to me, I'm used to a server onsite that I can use to centrally manage the devices. If anything needs explaining better please ask and I'll try. I'm a bit miffed at the whole thing because at one point this wasn't anything to do with me and now its just been dumped on me with no time left to do anything properly.
Areku Posted April 5, 2016 Posted April 5, 2016 Ok, I'm a little confused why the "3rd party" has told you, the customer, that you are not allowed something? If the customer wants a physical management server on the same VLAN as his clients, the customer should be allowed to do so... devices with no management on them? regardless of the "remote" options is..... imo a mistake, and any managed service provider suggesting this should be shot. but then, having dealt with a managed service provider,(for over 3 years) with as narrow minded scope as yours seem to be having, we where only left with one option... showing them the door. not much help i'm sorry, but when i see people struggling with these company's... it really grinds my gears...
twin--turbo Posted April 5, 2016 Posted April 5, 2016 I can see this going one way. Starts with B and ends with adly. Sounds like a loosely defined project, a 3rd party that will sell you not a lot but charge a fortune for doing the least they can, and a high likley hood that the project is just been barrelled through. Connecting the two sites could be done with a p2p vpn. but you have to have decent bandwidth, and then you also introduce a whole heap of horrors in the security and safety of your own infrastructure. TT 1
forkies Posted April 5, 2016 Posted April 5, 2016 How are the 3 cabled rooms getting connectivity back? Surely you could do the same for the wifi network...
forkies Posted April 5, 2016 Posted April 5, 2016 Also see this for connectivity between two sites https://business.bt.com/products/networking/ethernet-point-to-point/
Meldrew Posted April 6, 2016 Posted April 6, 2016 Ok, I'm a little confused why the "3rd party" has told you, the customer, that you are not allowed something? If the customer wants a physical management server on the same VLAN as his clients, the customer should be allowed to do so... devices with no management on them? regardless of the "remote" options is..... imo a mistake, and any managed service provider suggesting this should be shot. but then, having dealt with a managed service provider,(for over 3 years) with as narrow minded scope as yours seem to be having, we where only left with one option... showing them the door. not much help i'm sorry, but when i see people struggling with these company's... it really grinds my gears... I'd bet that the 'customer' in this case is the company building the new site. I was only discussing the other day how the whole tendering process for new builds is fundamentally broken. The main contractor sub contracts the electrical work to an electrical company who subs networking to a telecomms company to do any data work who are virtually clueless about real needs of the school and who's main aim is to find the best way of gaining extra revenue, eg keeping control of everything, then charging massive rates for any changes to the system. Meldrew.
twin--turbo Posted April 6, 2016 Posted April 6, 2016 I'd bet that the 'customer' in this case is the company building the new site. I was only discussing the other day how the whole tendering process for new builds is fundamentally broken. The main contractor sub contracts the electrical work to an electrical company who subs networking to a telecomms company to do any data work who are virtually clueless about real needs of the school and who's main aim is to find the best way of gaining extra revenue, eg keeping control of everything, then charging massive rates for any changes to the system. Meldrew. I have worked through two rebuilds £50M & £30M .. At that point the I.T. Contractor was appointed separately. The only I.T. Related work done by the main contractor was the structured cabling ( and yes there were elements of that which went wrong) .. In our case we were cut out of the latter stages of both of the I.T. procurements by a member of SLT, that lead to problems later down the line that we had to battle and work against. TT
Gaz Posted April 6, 2016 Author Posted April 6, 2016 Maybe a little more background is in order. We provide FE/HE courses for a business who have a managed services provider who dictate to them what they can and cant do with regards to IT. The business isn't happy with that however they do need to use their secure network but they agree that isn't flexible enough for college use. The WiFi will be managed by the service provider which will effectively have 2 SSID's a secure one and an open one, we (the college) will only have a access to the open one. The 3 cabled rooms will be on a secure connection again not under our control. At the meeting I was asked to come up with a solution to deliver what they wanted, a network without restrictions (this doesn't mean unmanaged devices/network) that allows them the flexibility they need. The problem is that I don't have enough control to deliver what they want. The only way I can see a solution is to do something remotely but thats very messy and as has been mentioned has lots of security implications. The meeting went something like this.
Gaz Posted April 11, 2016 Author Posted April 11, 2016 OK so after a 5 minute Google, Direct Access looks like it would do the job but could you realistically run a college using just direct access?
RobD Posted April 11, 2016 Posted April 11, 2016 We use direct access for several thousand users, its brilliant. 1
Gaz Posted April 11, 2016 Author Posted April 11, 2016 (edited) OK so it looks like its a viable solution then. This is going to need extensive testing in a virtual machine. I was just reading this article. http://blogs.technet.com/b/canitpro/archive/2013/03/19/step-by-step-enabling-directaccess-in-windows-server-2012.aspx What does it mean when it says. Obtain two consecutive public IPv4 IP addresses and configure them on the external adapter of the server. These addresses must be unique. Are they for the remote devices to talk back to the DA server? Why 2 of them? Edited April 11, 2016 by Gaz
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now