-
Posts
12,747 -
Joined
Reputation
44,515 ExcellentAbout synaesthesia

Recent Profile Visitors
26,804 profile views
-
Unlikely, there seems to be a lot of heads in sands over there especially if what's been said by the ex employees is true. Plus the whole organisation seems a bit odd especially after the supposed offloading of EMEA in march. The more I look into it, the worse it looks and I suspect the US branch isn't long for this world either.
-
This is a quick and dirty guide to setting up cnMaestro local appliance and enrolling an/some APs - please excuse formatting, doesn't much like copy & pasting from google docs. This is also a work in progress as I've been going along and some parts may or may not be necessary. I don't know if you need to create an onboarding user if setting the onboarding details locally on the AP, have yet to test. This gets you up to the point of having a device enrolled on your newly created local install on a blank canvas - my next job is to try and work out exporting/importing configs. For reference, our devices are X7-35x and 55x on the latest firmware, with local appliance version 6.0 (latest version available to download) Creating a new cloud anchor account Log into cloud cnMaestro click profile name then Create Account. Go through the process of making a new account, doesn't matter if it uses same email address/contact details as any admin/yourself in cloud. For Cambium ID enter something like SCHOOLNAME_LOCAL_CNMAESTRO. Account type must be Anchor. Account view Enterprise. Log in to new account, and under Onboarding note the Cambium ID and Account ID, these will be needed for the local install. Using the virtual appliance Download the local appliance from Cambium - as of 16/9/26 latest is cnmaestro-on-premises_6.0.0-r6_amd64.ova If using VMWare, extract the OVA (any zip extractor will work inc 7zip) and grab the two VMDK files. Create a VM with both disks, disk1 is boot drive. 2 CPU, 4GB ram recommended. If using HyperV, use SolarWinds V2V converter to convert those VMDKs to VHDX. Create a Gen1 VM, 2CPU, 4GB ram, attach both drives (IDE) and fire it up. For networking, use the same IP range as the management IPs of the APs. Follow installation instructions from the userguide - "cnMaestro On-Premises User Guide 6.0.0.pdf" and set up with relevant network address, set passwords etc - default is cambium/cnmaestro Log into the UI via the set IP address, default credentials are admin/admin. It will immediately prompt you to connect to a cloud account for provisioning. Enter the cambium ID and password set for the created anchor user. Onboarding Access Points (Might not be necessary if onboarding manually?) In local cnMaestro UI: Add user for onboarding devices - Administration > Users > Add User Onboard > Settings > tick Enable Cambium ID based auth to onboard devices Add user and enter onboarding key (create your own), click Save Onboard > Claim device > Select device type (usually Enterprise WiFi (X7 Series)) and enter or scan mac address(es) in box. Click claim devices Click Approve All On local AP to be onboarded: Assuming the AP is factory reset AP should receive IP via DHCP. Browse to it with https://ip. Default user/pass is admin/admin If it’s still present in cloud cnMaestro it will warn as such on the first page - ignore and click through to login page. They may need removing from Cloud beforehand otherwise they will sync up again and pick up config again including login credentials. For note - factory reset by holding AP reset button in for over 10 seconds Default credentials are admin/admin If device is in place and not reset you may be able to do this assuming you have the local credentials for SSH access to the AP (Couldn't get this bit to work but assume this should be correct) Log into UI, configure > system > set country Code to United Kington, put in the admin password, tick remote management and validate server certificate, entry https://server_ip for cnMaestro URL, your cambium ID created above and the key in relevant boxes, hit save. Only worked for me doing it via the ap's CLI with following commands: country-code GB cambium-id CAMBIUM_ID_HERE CAMBIUM_ONBOARDING_KEY_HERE management http management https management cambium-remote url https://server_ip management cambium-remote validate-server-cert
-
Statement from Cambium: https://www.cambiumnetworks.com/wp-content/uploads/Cambium-Networks-Company-Statement-Sep-16-2026.pdf Probably the most pertinent bit: The intention is that cnMaestro Cloud will continue to operate at least through 1 October.
-
DfE refreshes the digital and technology standards manual
synaesthesia commented on EduGeek's news article in Articles
Yeah but if anyone doesn't have MFA in for all staff already, regardless of SLT opinion, they are failing the school and the school are failing themselves. I'd have my "gun and badge" on the table before they brushed that off. -
DfE refreshes the digital and technology standards manual
synaesthesia commented on EduGeek's news article in Articles
Not all that much has changed which is likely to cost anything, there does appear to be clarification on cyberessentials as the DfE is very specifically not saying anything about MFA for pupils so CE is absolutely entirely a choice for anyone other than FE. That at least has removed one of the bigger concerns. -
At least the Aerohive kit can be used singularly to good effect - I had a pair of Aerohive APs running my home wireless until I replaced it with UniFi (and may end up going back to it if we need to put the unifi back in at school! )
-
Clever - QR code Sign In for Chromebooks
synaesthesia replied to Planehazza's topic in ChromeOS & Cloud Based OS
That's the one thing Clever should absolutely be used for, it's awesome for primary logins and could easily be implemented for older SEND or medical need students too. Just don't like seeing it used in the same sentence as MFA, because whatever the marketing says, it isn't. -
Update - that's my misunderstanding and should sometimes take the time to RTFM Needed to create a user specifically for onboarding (click profile, create account, select "Anchor" (not an anchor being so unfortunately Hugh Jackman isn't going to arrive) That's done the job immediately so now I'm down to seeing how enrolment works and exporting/importing setups. Naturally I'm documenting the process for our trust so I'll share the same process here in case it saves someone else a lot of trial and error, but with luck it won't be needed.
-
Whelp, I don't think going local is the answer unless I've missed something. To install the local appliance, it needs to connect to the cloud - and it refuses to do that due to missing cookies. I've pushed some Maryland's into the floppy drive but it's still not having it despite it making clear "nom nom nom" noises.
-
So far they know about as much as we do - our CtC install is still effectively ongoing, but both our framework supplier and the end installers have been entirely transparent. When they get more information I'm confident they'll pass it on. It seems like difficulty is stemming from the parent company's lack of transparency and/or communication on it, which speaks volumes.
-
I believe so as the configuration is run directly from the device. However without the cloud controller you have no visibility of the devices so you're not longer proactively managing them, you're possibly no longer KCSIE/CE compliant if you can't track what devices are where and used by whom, no guest portal. However if the cloud service goes, will they automatically say NOPE if they can't verify their own license? I think it's frankly daft to just sit and do nothing assuming it'll all work out - dereliction of duty if anything especially if there's a reasonably simple workaround and even more so working entirely on the assumption that the cloud dropping means everything just ticks along as normal - are you *sure* the licensing isn't strict and only set to cater for short outages of say, 12 to 24 hours?
-
Quite right - probably should have said agree to a point It's been a long couple of weeks! Ruckus was also similarly thought of in the late noughties/early tens, and even now it's nearly always the name on the tip of peoples tongues ahead of the bigger enterprise players. Not sure why, never could stand that damn finickety system! But still better than Aruba Central
-
Enterprise WiFi and Androids
synaesthesia replied to synaesthesia's topic in Mobile Devices & Tablets
BYOD - school devices are easy thanks to MDM. Inspection certs as mentioned are also easy, installed as they normally would be (manually) and indeed users must have traffic inspected. Unless, which is quite possible, I'm misunderstanding and the 2 can be linked? -
If running Hyper-V, extract the OVA appliance and use the solarwinds V2V app to convert the VMDKs (x2) to VHDX. Secure boot off.
-
Enterprise WiFi and Androids
synaesthesia replied to synaesthesia's topic in Mobile Devices & Tablets
Decryption is the "easy" part - that's still handled by getting them to install the smoothwall cert via the /getmitm URL as always, it's just this initial bit for authorisation which is adding yet another step. I'm not aware that Easypass would make it any different regarding inspection, it'd just allow connection similar to NPS with authentication to Google, visible by Smoothwall for monitoring/filtering purposes but still (AFAIK) needs the certificate installing manually.
