Jump to content

synaesthesia

Members
  • Posts

    12,751
  • Joined

Reputation

44,517 Excellent

4 Followers

About synaesthesia

Recent Profile Visitors

26,820 profile views
  1. No worries. I've done a bit more this morning. Once you're up and running with the controller and connected to your cloud account, create a new site (sites > new site) with an appropriate name. Export the AP group(s) and WLANs from WiFi profiles (thanks @FragglePete) from your cloud account and import them into the local - do the WLANs first then the AP group second. Those include radius settings, but if you use easypass you'll need to reset that up manually. Move devices into the appropriate site as you onboard them and manually add them to your AP group(s). @smarties11 yeah I do wonder how some are pulling it off without MFA. I suppose thinking about it any school with 1:1 or have devices all with biometric readers or cameras can do it relatively easily. Others not so much - clever doesn't/shouldn't count I imagine CE is a bit like a car's MOT though, it deems it safe when it turns up for testing but if anything changes the minute it rolls out with a pass certificate..
  2. Ours was August and we're still waiting for stock of 4 external points And yes, that's true for CE although one positive is I doubt anyone sensible is CE certified in anything except further ed. I've been working on it being a failure for RPA insurance in case of incident. At least for the DfE's requirements, the local controller is more than sufficient as the centrally managed solution so it complies there. There's going to be a LOT of hoping and finger crossings for firmwares, security updates etc. We can at least be thankful we still have our unifi AP's in a box in storage and the cabling has been done, so we can rip & replace easily in a pinch. Our UniFi replaced Ruckus and was a massive improvement, and the Cambium is far far better than both ever were. Really hope something/someone pulls through!
  3. Indeed the APs will continue to work, but you'll almost certainly be voiding your RPA insurance policy (whether they take into consideration if it's relevant or not is another matter, assume like most insurance companies they'll consider it against you anyway) Really isn't difficult doing the local controller so it's worth it but still no guarantee that will work after the 1st. Again, prepare for the worst and anything else is a bonus.
  4. It's a good question and something I hope to test in time. I've suggested to our trust IT leads that we all assume the 1st is cutoff if there's no rescue and we need to at least have gotten a controller up and running by then. Once the anchor account is done then the controller is up and running and can effectively be shut off without consequence BUT I could not get an AP to pick up it's subscription status without it phoning home. This might not be an issue for some of the consumer grade kit but from what I understand the enterprise units like the X7's need Tier 3 subscription. This might all be moot if they won't be manageable without that cloud connection, the only way I can think around that at the moment is by pre-emptedly going entirely local before the 1st which seems a bit drastic.
  5. Unlikely, there seems to be a lot of heads in sands over there especially if what's been said by the ex employees is true. Plus the whole organisation seems a bit odd especially after the supposed offloading of EMEA in march. The more I look into it, the worse it looks and I suspect the US branch isn't long for this world either.
  6. This is a quick and dirty guide to setting up cnMaestro local appliance and enrolling an/some APs - please excuse formatting, doesn't much like copy & pasting from google docs. This is also a work in progress as I've been going along and some parts may or may not be necessary. I don't know if you need to create an onboarding user if setting the onboarding details locally on the AP, have yet to test. This gets you up to the point of having a device enrolled on your newly created local install on a blank canvas - my next job is to try and work out exporting/importing configs. For reference, our devices are X7-35x and 55x on the latest firmware, with local appliance version 6.0 (latest version available to download) Creating a new cloud anchor account Log into cloud cnMaestro click profile name then Create Account. Go through the process of making a new account, doesn't matter if it uses same email address/contact details as any admin/yourself in cloud. For Cambium ID enter something like SCHOOLNAME_LOCAL_CNMAESTRO. Account type must be Anchor. Account view Enterprise. Log in to new account, and under Onboarding note the Cambium ID and Account ID, these will be needed for the local install. Using the virtual appliance Download the local appliance from Cambium - as of 16/9/26 latest is cnmaestro-on-premises_6.0.0-r6_amd64.ova If using VMWare, extract the OVA (any zip extractor will work inc 7zip) and grab the two VMDK files. Create a VM with both disks, disk1 is boot drive. 2 CPU, 4GB ram recommended. If using HyperV, use SolarWinds V2V converter to convert those VMDKs to VHDX. Create a Gen1 VM, 2CPU, 4GB ram, attach both drives (IDE) and fire it up. For networking, use the same IP range as the management IPs of the APs. Follow installation instructions from the userguide - "cnMaestro On-Premises User Guide 6.0.0.pdf" and set up with relevant network address, set passwords etc - default is cambium/cnmaestro Log into the UI via the set IP address, default credentials are admin/admin. It will immediately prompt you to connect to a cloud account for provisioning. Enter the cambium ID and password set for the created anchor user. Onboarding Access Points (Might not be necessary if onboarding manually?) In local cnMaestro UI: Add user for onboarding devices - Administration > Users > Add User Onboard > Settings > tick Enable Cambium ID based auth to onboard devices Add user and enter onboarding key (create your own), click Save Onboard > Claim device > Select device type (usually Enterprise WiFi (X7 Series)) and enter or scan mac address(es) in box. Click claim devices Click Approve All On local AP to be onboarded: Assuming the AP is factory reset AP should receive IP via DHCP. Browse to it with https://ip. Default user/pass is admin/admin If it’s still present in cloud cnMaestro it will warn as such on the first page - ignore and click through to login page. They may need removing from Cloud beforehand otherwise they will sync up again and pick up config again including login credentials. For note - factory reset by holding AP reset button in for over 10 seconds Default credentials are admin/admin If device is in place and not reset you may be able to do this assuming you have the local credentials for SSH access to the AP (Couldn't get this bit to work but assume this should be correct) Log into UI, configure > system > set country Code to United Kington, put in the admin password, tick remote management and validate server certificate, entry https://server_ip for cnMaestro URL, your cambium ID created above and the key in relevant boxes, hit save. Only worked for me doing it via the ap's CLI with following commands: country-code GB cambium-id CAMBIUM_ID_HERE CAMBIUM_ONBOARDING_KEY_HERE management http management https management cambium-remote url https://server_ip management cambium-remote validate-server-cert
  7. Statement from Cambium: https://www.cambiumnetworks.com/wp-content/uploads/Cambium-Networks-Company-Statement-Sep-16-2026.pdf Probably the most pertinent bit: The intention is that cnMaestro Cloud will continue to operate at least through 1 October.
  8. Yeah but if anyone doesn't have MFA in for all staff already, regardless of SLT opinion, they are failing the school and the school are failing themselves. I'd have my "gun and badge" on the table before they brushed that off.
  9. Not all that much has changed which is likely to cost anything, there does appear to be clarification on cyberessentials as the DfE is very specifically not saying anything about MFA for pupils so CE is absolutely entirely a choice for anyone other than FE. That at least has removed one of the bigger concerns.
  10. At least the Aerohive kit can be used singularly to good effect - I had a pair of Aerohive APs running my home wireless until I replaced it with UniFi (and may end up going back to it if we need to put the unifi back in at school! )
  11. That's the one thing Clever should absolutely be used for, it's awesome for primary logins and could easily be implemented for older SEND or medical need students too. Just don't like seeing it used in the same sentence as MFA, because whatever the marketing says, it isn't.
  12. Update - that's my misunderstanding and should sometimes take the time to RTFM Needed to create a user specifically for onboarding (click profile, create account, select "Anchor" (not an anchor being so unfortunately Hugh Jackman isn't going to arrive) That's done the job immediately so now I'm down to seeing how enrolment works and exporting/importing setups. Naturally I'm documenting the process for our trust so I'll share the same process here in case it saves someone else a lot of trial and error, but with luck it won't be needed.
  13. Whelp, I don't think going local is the answer unless I've missed something. To install the local appliance, it needs to connect to the cloud - and it refuses to do that due to missing cookies. I've pushed some Maryland's into the floppy drive but it's still not having it despite it making clear "nom nom nom" noises.
  14. So far they know about as much as we do - our CtC install is still effectively ongoing, but both our framework supplier and the end installers have been entirely transparent. When they get more information I'm confident they'll pass it on. It seems like difficulty is stemming from the parent company's lack of transparency and/or communication on it, which speaks volumes.
  15. I believe so as the configuration is run directly from the device. However without the cloud controller you have no visibility of the devices so you're not longer proactively managing them, you're possibly no longer KCSIE/CE compliant if you can't track what devices are where and used by whom, no guest portal. However if the cloud service goes, will they automatically say NOPE if they can't verify their own license? I think it's frankly daft to just sit and do nothing assuming it'll all work out - dereliction of duty if anything especially if there's a reasonably simple workaround and even more so working entirely on the assumption that the cloud dropping means everything just ticks along as normal - are you *sure* the licensing isn't strict and only set to cater for short outages of say, 12 to 24 hours?
×
×
  • Create New...