Jump to content

Recommended Posts

Posted
3 minutes ago, colly72 said:

You could add Aerohive and Meru into the mix too!!

 

We had Aerohive for 9 years, and in that time they switched from an expensive AP model, with cheap licensing, to a cheap AP model with expensive licensing, thereby fleecing us both coming and going. That betrayal stung on each renewal cycle tbh, as much as the hardware did it's job perfectly wellk.

 

So then we scrapped that and got Cambium, with no ongoing license fees and lifetime warranty. Until last week, anyway.

 

Please don't let ask me to choose another wireless supplier any time soon, I'm not sure I could bear being wrong a third time 😂

  • Like 1
  • Haha 2
Posted

Whelp, I don't think going local is the answer unless I've missed something.

To install the local appliance, it needs to connect to the cloud - and it refuses to do that due to missing cookies. I've pushed some Maryland's into the floppy drive but it's still not having it despite it making clear "nom nom nom" noises.

 

 

  • Thanks 1
  • Haha 2
Posted

Update - that's my misunderstanding and should sometimes take the time to RTFM ;)

Needed to create a user specifically for onboarding (click profile, create account, select "Anchor" (not an anchor being so unfortunately Hugh Jackman isn't going to arrive)

That's done the job immediately so now I'm down to seeing how enrolment works and exporting/importing setups. Naturally I'm documenting the process for our trust so I'll share the same process here in case it saves someone else a lot of trial and error, but with luck it won't be needed.

 

  • Thanks 2
Posted
14 minutes ago, synaesthesia said:

Update - that's my misunderstanding and should sometimes take the time to RTFM ;)

Needed to create a user specifically for onboarding (click profile, create account, select "Anchor" (not an anchor being so unfortunately Hugh Jackman isn't going to arrive)

That's done the job immediately so now I'm down to seeing how enrolment works and exporting/importing setups. Naturally I'm documenting the process for our trust so I'll share the same process here in case it saves someone else a lot of trial and error, but with luck it won't be needed.

 

This would be massively helpful here please. We're just stuck in a mess of resignations and ipads at the moment quietly panicking about the wifi!

  • Like 1
Posted
17 hours ago, synaesthesia said:

So far they know about as much as we do - our CtC install is still effectively ongoing, but both our framework supplier and the end installers have been entirely transparent. When they get more information I'm confident they'll pass it on. It seems like difficulty is stemming from the parent company's lack of transparency and/or communication on it, which speaks volumes.

Hopefully, once they have more information and if the on-premises solution proves to be the best option, they will contact all of the schools they have previously worked with and offer it as a service.
  • Like 2
Posted
16 hours ago, DavR said:

 

We had Aerohive for 9 years, and in that time they switched from an expensive AP model, with cheap licensing, to a cheap AP model with expensive licensing, thereby fleecing us both coming and going. That betrayal stung on each renewal cycle tbh, as much as the hardware did it's job perfectly wellk.

 

So then we scrapped that and got Cambium, with no ongoing license fees and lifetime warranty. Until last week, anyway.

 

Please don't let ask me to choose another wireless supplier any time soon, I'm not sure I could bear being wrong a third time 😂

I got stung with Aerohive too and just crossed my fingers everything kept working but couldn't see or manage annything!

Posted

At least the Aerohive kit can be used singularly to good effect - I had a pair of Aerohive APs running my home wireless until I replaced it with UniFi (and may end up going back to it if we need to put the unifi back in at school! ;) )

  • Haha 1
Posted

Spoke to our reseller today, plus another larger reseller. Both said the DfE didn't know any more than them about this (which is very little) and that they can't see a resolution in form of a buyout after speaking to distributors. ☹️

Posted
3 hours ago, synaesthesia said:

Statement from Cambium:

https://www.cambiumnetworks.com/wp-content/uploads/Cambium-Networks-Company-Statement-Sep-16-2026.pdf

 

Probably the most pertinent bit:

The intention is that cnMaestro Cloud will continue to operate at least through 1 October.

 

I know they had a UK company registered but I thought this was headquartered in the US so I'd expect a statement out of there?

 

Posted
Just now, RobFuller said:

 

I know they had a UK company registered but I thought this was headquartered in the US so I'd expect a statement out of there?

 

Unlikely, there seems to be a lot of heads in sands over there especially if what's been said by the ex employees is true. Plus the whole organisation seems a bit odd especially after the supposed offloading of EMEA in march. 

The more I look into it, the worse it looks and I suspect the US branch isn't long for this world either.

  • Like 1
Posted
15 hours ago, synaesthesia said:

 This gets you up to the point of having a device enrolled on your newly created local install on a blank canvas - my next job is to try and work out exporting/importing configs.

 

 

From what I can see, the stuff you can and I've download so far is >

 

Wi-Fi Profiles > AP Groups > Download any of the Profiles here ( I have Default Indoor Profile and Default Outdoor Profile)

 

and

 

Wi-Fi Profiles > WLANs > Download each of the WLANs config from this tab.    These are JSON files that seem to contain all the config for each SSID your transmitting, including for our RADIUS Auth server info, including Secret Key.

 

I'm going to work through your bits you've documented myself (thank you @synaesthesiaover the next few days (workload this September though seems through the roof compared to most years).  However, the bit about creating a new account for the Anchor is all fine and dandy at the moment, but will this still be available after 1st October ?  And, is the Anchor account only needed on the initial setup of the On Prem server or will this try and call home on a regular basis?

 

Pete

 

 

  • Thanks 1
Posted
Just now, FragglePete said:

 

From what I can see, the stuff you can and I've download so far is >

 

Wi-Fi Profiles > AP Groups > Download any of the Profiles here ( I have Default Indoor Profile and Default Outdoor Profile)

 

and

 

Wi-Fi Profiles > WLANs > Download each of the WLANs config from this tab.    These are JSON files that seem to contain all the config for each SSID your transmitting, including for our RADIUS Auth server info, including Secret Key.

 

I'm going to work through your bits you've documented myself (thank you @synaesthesiaover the next few days (workload this September though seems through the roof compared to most years).  However, the bit about creating a new account for the Anchor is all fine and dandy at the moment, but will this still be available after 1st October ?  And, is the Anchor account only needed on the initial setup of the On Prem server or will this try and call home on a regular basis?

 

Pete

 

 

It's a good question and something I hope to test in time. I've suggested to our trust IT leads that we all assume the 1st is cutoff if there's no rescue and we need to at least have gotten a controller up and running by then.

Once the anchor account is done then the controller is up and running and can effectively be shut off without consequence BUT I could not get an AP to pick up it's subscription status without it phoning home. This might not be an issue for some of the consumer grade kit but from what I understand the enterprise units like the X7's need Tier 3 subscription. This might all be moot if they won't be manageable without that cloud connection, the only way I can think around that at the moment is by pre-emptedly going entirely local before the 1st which seems a bit drastic.

  • Like 1
Posted

Even if cnMaestro goes offline, the APs should continue to work as is just without being manageable. So as long as we know the local admin password then resetting/manually changing config should be possible?

Posted

I'm a little surprised that there hasn't been, or at least that I haven't seen, any official communication about this from the DfE, vendors, installation partners, CTC partners, or other stakeholders.

There is also nothing displayed within CNMaestro itself, which I would have thought would be a relatively straightforward way of notifying customers if there is a potential "cliff-edge" situation approaching.

 

Had I not come across this forum discussion, I would have been completely unaware of the issue, and I suspect many schools are in the same position. It all seems rather strange given the number of schools likely to be affected and the fact that, for many, losing Wi-Fi connectivity would have a significant impact on day-to-day operations.

Posted
5 minutes ago, snagrat said:

Even if cnMaestro goes offline, the APs should continue to work as is just without being manageable. So as long as we know the local admin password then resetting/manually changing config should be possible?

Haven't got a clue or no documentation regarding local AP Usernames/Passwords.  Maybe they are all default when installed🤷🏻‍♂️

Posted
Just now, JazzFlute said:

Haven't got a clue or no documentation regarding local AP Usernames/Passwords.  Maybe they are all default when installed🤷🏻‍♂️

You set it in the configuration. So get that changed before cnMaestro goes offline and you'll then know it

Posted

Indeed the APs will continue to work, but you'll almost certainly be voiding your RPA insurance policy (whether they take into consideration if it's relevant or not is another matter, assume like most insurance companies they'll consider it against you anyway)

Really isn't difficult doing the local controller so it's worth it but still no guarantee that will work after the 1st. Again, prepare for the worst and anything else is a bonus.

 

Posted

I think the insurmountable issue here is ongoing compliance.

 

A local controller will solve the immediate problem of the cloud controller going dark, but how long will it be before a security vulnerability is discovered in either the controller itself or the WAP firmware? If that vulnerability carries a CVSS score of 7.0 or higher, there goes any realistic chance of maintaining Cyber Essentials or Cyber Essentials Plus accreditation.

 

Unless there is a buy out from a competitor I don't see how schools will be able to continue with this solution for anything more than a stop gap.

 

Out of interest, how many others are in the same position as me, having had a brand-new Cambium deployment installed as recently as August? I'm massively regretting not sticking with Ruckus now 😭

Posted

Ours was August and we're still waiting for stock of 4 external points ;)

 

And yes, that's true for CE although one positive is I doubt anyone sensible is CE certified in anything except further ed. I've been working on it being a failure for RPA insurance in case of incident.

 

At least for the DfE's requirements, the local controller is more than sufficient as the centrally managed solution so it complies there. There's going to be a LOT of hoping and finger crossings for firmwares, security updates etc. We can at least be thankful we still have our unifi AP's in a box in storage and the cabling has been done, so we can rip & replace easily in a pinch. Our UniFi replaced Ruckus and was a massive improvement, and the Cambium is far far better than both ever were. Really hope something/someone pulls through!

Posted

We finished deployment in Easter.

 

I need to change the AP passwords and our switches powering them.

 

Thank you @synaesthesia for the guide. I will try and stand up the local controller appliance. 

Posted

We are CE+ certified here and are 11-18. Just coming up to our third renewal. Personally I don't think it will be too long before the DfE mandate CE in Schools as part of their digital and technology standards. Although I know some schools just "tick the boxes" where CE is self certified - my daughter's new school for example are CE certified across the whole trust but her account doesn't have MFA enabled....

 

Anyway, back on topic - we received all of our APs, we're just waiting for a single PoE injector for a single 55X AP which is in a dense room as our switches are PoE+ not PoE++. Might have to scour eBay!

Posted (edited)

No worries. I've done a bit more this morning. Once you're up and running with the controller and connected to your cloud account, create a new site (sites > new site) with an appropriate name. Export the AP group(s) and WLANs from WiFi profiles (thanks @FragglePete) from your cloud account and import them into the local - do the WLANs first then the AP group second. Those include radius settings, but if you use easypass you'll need to reset that up manually.

Move devices into the appropriate site as you onboard them and manually add them to your AP group(s).

 

@smarties11 yeah I do wonder how some are pulling it off without MFA. I suppose thinking about it any school with 1:1 or have devices all with biometric readers or cameras can do it relatively easily. Others not so much - clever doesn't/shouldn't count :) I imagine CE is a bit like a car's MOT though, it deems it safe when it turns up for testing but if anything changes the minute it rolls out with a pass certificate.. :D 

 

Edited by synaesthesia

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...