Jump to content

Recommended Posts

Posted

Right - the jokes over :(

 

What my schools need is reliable ICT.

 

The most unreliable bit seems to be me and their Internet access :)

 

Given that they can't replace me, I'd like to do something about T'internet.

 

What I'm after is a magic solution that will give me a secondary internet feed when the main RBC one fails.

 

It has to be capable of full or semi-automatic operation e.g I might want it to be on full auto or I might want it to be easily switchable on by an ICT co-ord without me being on site.

 

And most importantly, its got to be invisible to the anyone working on the dark side so they don't know that we've managed to carry on teaching while they're arguing amongst themselves as to who's knocked what switch off :)

 

I'm thinking the simplest/easiest way is to use 3G as a backup. My schools only have 2MBs (if they are lucky and on a good day) so 3G would be OK I think as a backup.

 

We could always move to an ADSL feed or even cable if needed in the future. (Bit harder to hide that sort of thing though when the sith come calling) :)

 

Now to start with, It doesn't need filtering as its an emergency backup but if the project gets going, then we're going to need some filtering but not to start with I think.

 

Now, young padawans - who's up for working on this - I don't want to stiffe invovation but I think we going to need some *nix skills here cause it will have to be run on an old 386 box with 4M of RAM :) (Well maybe a Celeron 2.0G with a bit more memory )

 

And if it gets to trial stages, we'll need to go underground with anonymous monickers, TOR proxies etc and secret handshakes to avoid infilltration by the other side :)

 

But to start with, it would be a completely technical "what if" discussion :)

 

Of course, someone may already have a VM ready to go to do the job :)

 

regards

 

Fred

Posted

if you are planning this you MUST have filtering in place as schools have to show a duty of care with regards to internet access, there was a thread on this the other day with regards to having unfiltered IPs.

 

Isnt the best solution to phone and harrass your RBC each time it goes down.

 

I would probably reccomend smoothwall as the router, it supports multiple connections though I'm not sure how it works with two external connectors.

 

its also not too far off your requirements either, P200 128MB ram:)

Posted
Or if you're unixing it up anyway, squid+dg combo will do filtering quite nicely. Still even on a 3g mobile broadband, the bandwidth is going to take a hammering. You'd have to be careful about usage caps etc. I seem to remember 1.5GB/mo being a normal sort of cap, and if you loe internet for a day a school full of teachers will soon nuke that. In theory I guess the easiest way would be pointing all internal traffic at a false gateway, that switches between your RBC and hidden links easily.
Posted
Isnt the best solution to phone and harrass your RBC each time it goes down.

 

There are no emoticons available to me to show how I feel about the utter utter futility of that approach.

 

There is no feedback mechanism in place to cause them discomfort when we lose service. They have no concept of an SLA with penalities.

 

f you are planning this you MUST have filtering in place as schools have to show a duty of care with regards to internet access, there was a thread on this the other day with regards to having unfiltered IPs.

 

No - we must have filtering in place as a requirement to placate certain groups. WE DO have a duty of care but this can be acheived in other ways, in the same way that we don't stop children crossing roads, we hold their hands while doing so :)

 

But it would be nice to have filtering as soon as possible but for technical testing purposes we can live without it. :)

 

Our RBC lifted some of their filtering in the past fortnight in an attempt to provide us with a so-called service so I think sauce, goose and gander applies :)

 

(I have extra filtering in lots of my schools anyway - so I'm only having a philosphical discussion with you :) )

 

regards

Fred

Posted
Or if you're unixing it up anyway, squid+dg combo will do filtering quite nicely. Still even on a 3g mobile broadband, the bandwidth is going to take a hammering. You'd have to be careful about usage caps etc. I seem to remember 1.5GB/mo being a normal sort of cap, and if you loe internet for a day a school full of teachers will soon nuke that.

 

MY thoughts on 3G is that I can cheaply buy a dongle and try it out without asking for any money.

 

I don't know what normal traffic is - we just use simple online activities like education city, schools BBC etc normally so I'd thought it wouldn't be too bad (as long as I'm not downloading iso's anyway! :) )

 

In theory I guess the easiest way would be pointing all internal traffic at a false gateway, that switches between your RBC and hidden links easily.

 

Right - so how to can I translate what you've just said into simple speak/actions :)

 

Out setup is we have 2 networks curric and admin going into 1 combined switch router that sends the combined traffic down an SDSL link to the RBC.

 

I just want to do this on curric side as admin network is more controlled by others.

 

We are allocated a 10.xxx.yyy.0/24 subnet for the curric network and normally set client ip's gateway address to the RBC router (10.xxx.yyy.1) and broswers are set to use their proxy name proxy.blahbah.uk port 8080 (or presently actually using an auto-config url supplied by them but I'm kicking that into touch after half-term as its not worth the grief its given me :( )

 

regards

 

Simon

Posted

I think you should be very careful here as you are about to open up a can worms. I'm pretty certain you will have a contract with the Sith that you can't add an additional gateway in this manor.

 

As far as the Sith are concerned you will be introducing an unprotected entrypoint on to their network. What if someone 'hacked' into your network via this new link, hacked past the Sith proxy/router on your network and the had open access onto Sith.net?

 

We are lucky here! The Sith have agreed to increase our main gateway to 100mbps and are going to install a 10mbps ADSL backup themselves.

 

You need to do one of two things.

 

1) Convince someone at your LEA to put in an ADSL line and set up your router/proxy to use this fail over link.

 

2) Convince your head/board of governors to leave your LEA/RBC internet provision and go it alone. You can then install two ADSL lines and route between them at will. If you do this you will be fully responsible for filtering.

Posted

 

Right - so how to can I translate what you've just said into simple speak/actions :)

 

Out setup is we have 2 networks curric and admin going into 1 combined switch router that sends the combined traffic down an SDSL link to the RBC.

 

I just want to do this on curric side as admin network is more controlled by others.

 

We are allocated a 10.xxx.yyy.0/24 subnet for the curric network and normally set client ip's gateway address to the RBC router (10.xxx.yyy.1) and broswers are set to use their proxy name proxy.blahbah.uk port 8080 (or presently actually using an auto-config url supplied by them but I'm kicking that into touch after half-term as its not worth the grief its given me :( )

 

regards

 

Simon

 

Ok, off the top of my head (and seeing how all this is still theoretical)

 

Client PC gets it's gateway from DHCP server. Let's say you config a box on the network with an IP 10.xxx.yyy.5 (let's call this FGW for False GateWay) which has two network cards bridged together and is told to "allow sharing of internet connectivity". Don't know really, guess WIN XP could do this happily enough.

 

So FGW is configured to point at the RBC gateway normally, but in the event of an outage you can reconfig the NIC on the outgoing side to point at your 3G routing box and that's the switchover done.

 

Just set the DHCP server to point clients to the FGW machine instead of the RBC gateway.

 

Admittedly I've never done anything like this myself, but can't see any reason for it not to work. HTH.

 

TZA

  • Thanks 1
Posted

If the links were set to only be connected one at a time it may be slightly more acceptable for them although from the sounds of the experiences of others their contracts are quite nefarious and swing well towards the dark side in terms of anything but revenue protection.

 

The technology that you are looking at is probably NAT with load balancing/fault tollerance in Cisco routing terms at least. You set up an internal address as your default gateway and then set up a NAT pool that maps this to one of two actual gateways out to the internet.

 

The other way to do it which is probably better would be to set up a secondary PPP dialer link on your router that would only dial up the internet if the primary failed. You would use something called a floating default route that has a lower priority/higher cost than the RBC route. When the primary link fails that link also fails and its cost goes up to infinate hence the next route is used instead. This in conjunction with a dialer rule for calls to the assigned IP address of the PPpoE capable 3G modem would trigger the device to call out and extablish the conection which will cese to be used and disconnected (depending on timeouts) when the lower cost RBC route comes back up again. This method relies on your actual RBC interface disconnectiong when there is a fault.

Posted

Hey Si...

 

I've grappled with this particular problem like you for over three years now and after trying to have both I've had a couple of interesting discussions with head teachers and we're now moving the first school over to a completely different network.

 

At present the county are offering nothing that cannot be received over a standard DSL connection so the approach is three prong.

 

1. Get in ADSL (ordered and pending)

2. Buy in the School Guardian filtering system and host this on a box in school.

3. Get it up and running and then bill the county provider for the cost because their existing system has not worked for the past four years without falling over every other week.

 

The approach is pretty much down to the fact that overall reliability has been around 50% with packet loss, blocked sites, educational resources blocked and naff all centralised control with everything blaming everyone else. At £4k+ a year it's a joke especially when the solution we're going with is around £850 for the first year including the BT engineer to fit the filter to our phone system.

 

I was going to try and have a failover system but I've realised there's absolutely no point with slower speeds, packet loss, poor filtering and lack of control.

 

If nothing else we may find that the school gets the long promised upgrade to a hard wired network connection and they may even resolve all the other stuff but I'll be honest I think when push comes to shove there are enough schools fed up with this dog n' pony show that they want the money to be spent on other things now.

 

That's just my take and more political than anything but certainly when I compare the cost of having me in, abandoned lessons, etc... I figure £850 is actually quite low in comparison.

 

I do know that if it works out the other two schools that I service in the same LEA will be doing the same thing.

 

 

Oh and perhaps a more relevant point but the key reason I went with School Guardian is that it removes me as a point of null redundancy. If I can't resolve a problem the support with School Guardian can, so it doesn't all fail if I get the number 9 bus pancake treatment.

  • Thanks 1
Posted
I agree with Contink, his solution sounds good to me and i'd hope to do the same myself, my suggestion would be an ADSL feed in to a nice Smoothwall UTM box, connect your RBC and your ADSL as 2 external ways out, and set it that if Interface X (RBC) falls over then re-route all to Interface Y (ADSL), the box will do all that for you automatically, still be filtered the same and work the same with no notice really to the end user.
Posted
Given the limited bandwidth on 3G it might be a better failover solution for admin. A lot of the business end of admin seems to require internet access these days. I've made this suggestion in our school. Perhaps connected to a pc or laptop thats not connected to the network to cover security issues. I've heard things like exam related stuff could actually cost the school money if they're not done at a specific times.
Posted

Just concentrating on a tech bit for the moment- will commment later on the political :)

 

Client PC gets it's gateway from DHCP server. Let's say you config a box on the network with an IP 10.xxx.yyy.5 (let's call this FGW for False GateWay) which has two network cards bridged together and is told to "allow sharing of internet connectivity". Don't know really, guess WIN XP could do this happily enough.

 

Well WinXP won't cut it due to restrictions on number of ip connections but maybe w2k3 running on a desktop machine would - does anyone know how/where to do the bit "allow sharing of internet connectivity" as proposed above.

 

Could this be tried as a VM? (pref using VMServer as I'm familiar with it)

 

So FGW is configured to point at the RBC gateway normally, but in the event of an outage you can reconfig the NIC on the outgoing side to point at your 3G routing box and that's the switchover done.

Just set the DHCP server to point clients to the FGW machine instead of the RBC gateway.

 

So effectively making the FGW a configurable router? - is it that easy to make a router? Presume FGW machine just has static IPs and real router set as gateway.

 

Can the reconfiguration of IP be scripted and invoked by a teacher?

 

regards

 

Simon

Posted (edited)

Okay here's how I'd try to do it...

 

I'm assuming your LEA setups equipment in the same way as mine with a proxy server that all web connections must go through before hitting your router.

 

Set up a new PC/VM with three NIC's running Linux. NIC1 is your internal network. I'd use a new range separate from the ones provided by your LEA. All machines on your internal network are on the same range as this NIC and use this as their gateway address.

 

NIC2 has an address on your LEA provided IP range. You have an ADSL router on a third IP range and NIC3 is on the same range as the ADSL router.

 

NIC2 routes to your LEA gateway and NAT's port80/443 requests to the LEA supplied proxy. NIC3 routes to the ADSL router. NIC3 has an higher cost than NIC2 thus will only be used when NIC2 is busy/not responding.

 

Finally I'd set my DNS servers to point at OpenDNS rather than your LEA's DNS service.

 

 

The last time I set up a new private IP range and routed between them as above (without NIC3/ADSL Router) I got by nuts chewed off because I "could have added the 3rd NIC/ADSL Router without it being visable to the LEA network and adding a security risk". I wouldn't minded but we had run out of IP's and the LEA wanted to charge us £££'s for a new range :mad:

Edited by tmcd35
Posted
Set up a new PC/VM with three NIC's running Linux. NIC1 is your internal network. I'd use a new range separate from the ones provided by your LEA. All machines on your internal network are on the same range as this NIC and use this as their gateway address.

 

New range is going to be a problem (or maybe not)

 

We have a Network Edge Device (NED) supplied by the RBC that is updated once a week with content from Espresso. It is set with a static IP by the RBC within our 10.xxx.yyy.0/24 subnet (10.xxx.yyy.250 to be exactly) and we are told it HAS to be directly connected to a specific port on our RBC supplied CISCO router/switch (No-one's every given me a technical reason for this but maybe it is true :) )

 

The espresso content has to to be available during RBC outages.

 

regards

 

Simon

Posted

I just had an idea - could I use my 3G Samsung Omnia (WM6) as a modem?

 

Under Linux?

 

It would save spending money on 3G dongle - no-one seems to do true pay-as-you go, any data bought seems to have a 30day sell by limit whereas my phone comes with 500M/month of which I've used an average of 14M in the past 2 months so I've a fair bit of capacity to use for testing :)

 

regards

 

Simon

Posted
New range is going to be a problem (or maybe not)

 

We have a Network Edge Device (NED) supplied by the RBC that is updated once a week with content from Espresso. It is set with a static IP by the RBC within our 10.xxx.yyy.0/24 subnet (10.xxx.yyy.250 to be exactly) and we are told it HAS to be directly connected to a specific port on our RBC supplied CISCO router/switch (No-one's every given me a technical reason for this but maybe it is true :) )

 

The espresso content has to to be available during RBC outages.

 

regards

 

Simon

 

I don't see this as a problem (unless it works differently to how I'd normally expect.) You'll probably have to NAT traffic to the NED as it's unlikely you can get into the setting to add another gateway to it. I assume it web content that is chached on the NED. If so I'd go for two NAT rules (unless the NED and Proxy is the same box) rule maps port 80 requests to the proxy and rule 2 maps port 1080 requests the NED.

 

If the content is caches as expected it should remain available during outages, but the content will not be updated until the RBC connection resumes.

Posted

So effectively making the FGW a configurable router? - is it that easy to make a router? Presume FGW machine just has static IPs and real router set as gateway.

 

I've done similar before as a test at home, and pointed my borther's machine to a FGW type device (actually a WINXP box sitting in the garage). The XP box then pointed traffic at the proper router. Was just for messing around really, no real milage and a little while ago, but I'll see if I can make something similar work when I'm back at school next week.

 

Can the reconfiguration of IP be scripted and invoked by a teacher?

 

As I recall you can change IPconfig with a batch file, can't remember the specfics, but I used one to switch the school over from static to dynamic IPs last year. There's plenty on google. Guess you'd need to grant the teacher(s) admin rights over the FGW.

Posted (edited)

Sorry about delay - I got sidetracked with other issues and trying to set up Ubuntu on my Samsung NC10 (its got wired, wireless and Bluetooth so I thought it would make a great little testing router device :) )

 

But no :(

 

The wireless doesn't work with default install and it took two re-installs to find the combination that worked.

 

And then I tried to get the bluetooth to work as a modem (like it just works in XP!) but after a day I think its too much of a black art and I don't think I'll be lucky enough to get it working.

 

It makes me doubt what would happen if I bought a 3G dongle - would that work in Linux.

 

So I'm thinking I'll just try setting up a Linux VM on a server with multiple net cards and see if I can get the switchover working.

 

I'd like to keep existing machines on RBC assigned subnet if possible so it would be easy to restore to standard setup.

 

With regards to the going the whole hog and getting a Smoothwall box and 2nd line or auto-Cisco router - I'm sure this would work but I need a proof of concept to show my headteachers - most of whom don't even know that the problem exists because they are of the generation who taught without internet - so most think - I can teach without internet - why can't you :)

 

(I can use an abacus to multiply 4 digit numbers but I wouldn't expect others to :) )

 

I need to show that it does work and then let them decide whether to have the political fight or not.

 

@contink - have you changed over/bought the kit or just talking about doing it :)

 

regards

 

Simon

Edited by SimpleSi
Posted

The question of whether you can keep your infrastructure on your existing subnet depends largely on whether or not you have a local proxy server and if so if you have access to it.

 

In our set up the LEA provide us with a Proxy server they set up. ALL web requests maust go through that server. We have no control over changing any setting on the web proxy.

 

If you have a proxy server like this in place, the question becomes are you able to edit it's gateway setting? It will need to use your FGW instead of the router as it's default gateway. If you can't set this then all web request will go through your RBC connection regardless.

 

The only solution I can see is NAT'ing web requests from another subnet.

Posted
Could this be tried as a VM?

 

Yes, that's what we do. We have a VM "router" server that does filtering, DHCP and DNS. It runs on a physical machine that has two network cards, both of which are then connected to the virtual machine. One network card connects to the internal network, the other to the router provided by the Internet connection. This, handily, also gives you a DMZ area you can put stuff like web servers and whatnot in. If something conks out (in our case, mainly due to power failure) you can simply move the running VM to a machine hooked up to a different Internet connection (or just have a third network card in the machine hooked up to your second router and switch over to that).

 

Actually, if you just had the one computer doing the routing, with three network cards (one to your network, one to each of the network connections) all you would need to do is write a script to periodically ping an external address (Google?) to see if it was reachable. If not, switch to the other connection by removing the current network connection from the VM's network bridge and adding the stand-by one's. Should take a couple of seconds, tops.

 

--

David Hicks

Posted

Probably not going to do the job, although maybe for your admin network, but I'll mention it anway - you can get a (domestic type) router that has a USB port into which you can plug a 3G dongle, and it can switch between the network and 3G if there is a failure.

 

Buy Edimax 3G-6200wg wireless 3G / DSL router 3G-6200Wg from CCL - Online Retailer of the Year 2008, 2007 & 2006 for laptops, desktops and computer hardware

Posted

I've knocked up a simple diagram using Gliffy viewable here, that will maybe give a clearer picture of my setup with a couple extra machines in to do switch-over/routing.

 

(Please feel free to pm me an email address and I can give you editing access rights)

 

regards

 

Simon

PS _ if there is a better shareable diagram resource - let me know and I'll switch to that

Posted
you can get a (domestic type) router that has a USB port into which you can plug a 3G dongle, and it can switch between the network and 3G if there is a failure.

 

That's cheating :)

 

I don't want to spend any more money than I have to on this - I'm trying to avoid even using a 3G dongle by using my phone as a modem :)

 

regards

 

Simon

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...