psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Ok, now I'm off reading the docs. I'm sure I was supposed to be doing something else this morning.... So it seems that tn HP Procurve /HPE Aruba Provision universe, loop protect and loop guard are different things. Use Loop protect for edge ports, and Loop Guard for ports that are involved in Spanning Tree. (at least on the 16.x software) https://techhub.hpe.com/eginfolib/Aruba/16.06/5200-4826a/index.html#s_Loop_protection.html https://techhub.hpe.com/eginfolib/Aruba/16.06/5200-4826a/index.html#s_STP_loop_guard.html On older stuff, one reading of the docs implies that loop protect is only for ports where bpdu protection is enabled (likely ports connected to end user devices, that should never be (but may accidentally become) connected to other switch ports) https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=c02563813 (search for loop protect). The inference that they are referring to edge ports only comes from in the examples they give ports 1-10 for loop protect, but for examples of configuring spanning tree they use ports like A1 (typically module ports or stacking ports).
-
If you've got RSTP why loop guard on switch uplinks? I thought it more suitable for edge ports where there is a very real risk that an end user in a random office might create a loop. (as previously alluded, I am not a network engineer, so my understanding is almost certainly weak/wrong it at least some areas)
-
The word used was Procurve. That's a brand that hasn't existing for 12 years. Most people using that brand did/do not have access to network switch management tools. They are/were notoriously finickity and capabilities and bugs varied wildly between models. Hand management was the norm by necessity. The only 'properly' centrally managed procurve network I have seen was an absolute disaster, that was only fixable through "hand management" as you put it. And with kit that old, I doubt any modern management platform will have much luck standardizing configs. FWIW I do have change management on ours - but with the variety and ages of the kit we alter configs by hand and use the NMS to track changes, monitor for problems and offer roll-back. Its a mess (but reliable). Could it be better, yes but we'd need to employ a network engineer with a procurve background to get there, and if we had an audit that made recommendations around config changes that seems to have very little rhyme or reason, I'd want to bounce them off others who might have more of a clue too.
-
Was poking around our portal today and found 2022 missing too. It was actually one tab over in a list of every software package we've licenced in the last 19 years. Not sure what the two lists represent or why some software appears to be missing in one of them.
-
We the teams created through SDS?
-
If we really need a bare metal re-install we use a USB Stick. We tend to use the current version, or the previous version. We have to do this a lot because of changes made to autopilot a couple of years ago require us to take it back to bare-metal and re-enroll devices if we want to reset them. Once re-enrolled we almost never need to go back to a USB deployment. FMMV.
-
Sanity check - network folders to Sharepoint Online
psydii replied to BJG's topic in How do you do....it?
Each Department / functional team/ area of operations gets their own Team. This gives them a 'distribution group' a shared Document Library (in a SharePoint Team site), and a chat/collaboration space. It is a flat structure, no subsites and nothing too clever going on with metadata or any of the fancy things you could do with Sharepoint back from 2000-2013. Keep it simple. For the departments/functional teams/areas of operations that regularly published information to the whole school or a significant subset of the whole school, we have a parallel set of "Communication" sites, each functional area that need one gets a communication site that the manage more as a webpage than a document library. All staff have View permissions to these communication sites. The relevant functional area are set as owners of these sites. Depending on how they want to operate (presenting live data vs snapshot) they either copy documents to these comms sites and make a pretty webpage, or they link directly to the live document in their Team Site (with appropriate sharing permissions set on the specific file/folder). We use the Hub site functionality to provide a pseudo-hierarchic structure to assist people in navigating these comms sites. -
Yes. We have other priorities for SLT time, and the 'problems' of sims are mitigated by various systems that aspiring SLT members run. I've certainly got better things to be doing with my time than winning hearts and minds for a change that will upset at least three extremely influential and powerful people here. We have to reprocure properly in a couple of years, and some staff (both teaching and admin) have already have positive experiences of non-sims MIS's, so grass roots support for change is growing. If external pressure also gets applied I'm sure change is coming sooner or later, but it really isn't for me to drive it. I've done an MIS migration in the past, and it didn't have the support of SLT (we had to, our MIS was shutting down), and my take away is: this is an SLT lead project - a Deputy head has to own it. I'm not going to push for it until they do.
-
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
psydii replied to Koldov's topic in Cloud Services
Can you not request that they forward emails sent to those addresses to a domain/address you do control? and by request, I mean you write the technical bit, and the Head Teacher sends it, 'ccing the Director of Education at the LA? -
Andrew Tate and school filtering
psydii replied to sigma's topic in Internet Related/Filtering/Firewall
This is basically how I've always done it too. Requests come to the service desk. I have authority to make arbitrary changes. If a request would be potentially contentious, I ask the teacher to take it to the DSL for review - I could of course do that myself, but a better discussion is had if the teachers engage with senior management about filtering levels. The change is made in the platform and the ticket number recorded in the notes field. My line manager (who has always been either the DSL or the Head Teacher) reviews changes monthly(ish). In the last 3 years there have been almost no changes to filtering from our side, despite the number of classes using IT in lessons rising by a third. The categories and keywords used by LGfL/WebScreen/Netsweeper seem to very well defined these days. However, LGfL is about to make some major changes to the back end (under the rebrand to SchoolProtect), so we may well find that request go way up next year. -
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
psydii replied to Koldov's topic in Cloud Services
Its only been rolling out on old tenants recently. -
Here is what we see in settings: And if we click into the Wonde Licence section: And gotcha! The Activity Log is a chargeable service. Which was news to me.
-
Apparentlty "Activity Log" is a premium/paid for feature. I think for us it is under account settings?
-
student to teacher private folder within a MS Team
psydii replied to chrisjako's topic in Office Software
Look in the "student work" document library. The Assignments app creates these folders just the way you want. We have entire departments that ignore the Assignments App UI and just use these folders. (Though the majority of department do make use of the UI and additional capabilities of the app). To be clear, the assignment app, when the first assignment is created (this can be a dummy/placeholder assignment) creates all the folders. The teacher / owner can see all the folders, but a student can only see their own. -
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
psydii replied to Koldov's topic in Cloud Services
A detail in this makes me wonder whether @steve_forbes recently spotted that domain being used. -
Andrew Tate and school filtering
psydii replied to sigma's topic in Internet Related/Filtering/Firewall
This is definitely the right approach to the Tate Brothers. We fall towards the latter two, because we have a robust PSHE programme and encourage discussion of issues in safe manner. On AI vs keywords filtering. The edge cases (but perhaps not quite as subjective as general Tate Brother's content) is exactly where the AI can do really well. Trained on the general set of categories, then refine it based on local opinion where local opinion disagrees with some of the classification... and it does really quite well. or so I am told by someone working with people who did the foundational work on this a decade ago. ..also Communication Compliance in Microsoft Purview seems to be built around this technology. I get alerts about non-compliant comms (probably keyword/phrase based) and on the dashboard it advise me the nature of the transgression - correctly identifying that two students discussing a set text that contained profanities as "neutral" while a chat where another two were "discussing" why one of them had kicked the other out of a discord server was identified as negative. Also, staff reporting on student transgressions (including the handwritten reports that contain the offending keywords / phrases) is were also given "neutral" sentiment, yet the initial transgression (that in part occurred in Teams) got picked up as negative. Clever stuff. -
Andrew Tate and school filtering
psydii replied to sigma's topic in Internet Related/Filtering/Firewall
Except most pages these days are dynamic, so that "once per url" strategy is not as effective as it once was. There'd still be a delay as it evaluated the page, modern consumer cpus have their tensor / neural engine cores and would probably be fine at this, but a network level system would need a serious amount of grunt to process 1Gb/s+ of web traffic. Cool. I'll just knock one up. BRB 😂 -
Andrew Tate and school filtering
psydii replied to sigma's topic in Internet Related/Filtering/Firewall
I'm pretty confident that AI/ML can easily be excellent at categorizing previously unseen pages, however it can't current do it fast enough to be real time without an enormous power requirements and at the scale required for a trust wide / regional system. For a single site, sling a couple of Nvidia Grace Hoppers in a rack in each school and you'd be good. -
a dozen or so 15 year old Smart UPS 2200 around the site for the switch rooms and two 10 year old Smart-UPS SRT 10000 with a load of batteries for the server room. (there used to be a *lot* more kit in that room than there is now) The big one gives us at least 40 minutes of run time, we've never come close to the ups shutting down the servers since its commissioning test (when it only gave us 10 minutes or so for the loads at that time)
-
If the power goes out, you're on a timer to a graceful shutdown.. so monitoring the temperature is moot at that point unless your runtime is measured in hours? But I'd have thought that over temperature alarm on a UPS could be configured to trigger a graceful shutdown or shedding of load too so... but to return to your actual question: I have no idea about SIM based temperature sensors. FWIW we don't shut down on over temperature and we've had things running for hours at 43C+ on more than one occasion (air-con failure, power still on), and I would say it's never done anything any harm, but we've had two random server failures (out of six) and half a dozen disks go (out of 40) over the 10 years we've been running the facilities (all the server/storage assets are the same age) so take that with a pinch of salt, YMMV etc etc.
-
Temperature sensors are often optional accessories of a UPS. We have ours deployed so our internet stays up with the servers until the UPS gives out, which affords us the opportunity to take action. The UPS handles sending the alerts to us. If the UPS can't get the message out, then we can't remote in either ::shrug::
-
A4 Mono / Colour - the now discontinued PageWides (and some M401s) until they fail. A3 Mono/Colour - some repurposed Sharp MFDs that were underutilised in their initial deployment. We used to have a few CP5525's but eventually they gave up after 12 years and one too many teachers changing toner. We've tried a couple of HP M404 for A4 mono, and they are fine but way more expensive to purchase and run than the M401's we used before Pagewide For the bulk of A4 and A3 printing we just use our photocopiers or the Risos. It's a balancing act on costs though. Riso's are way cheap to print colour too, but less competitive at mono, and unless you are printing *volume* through them, the capital/lease costs can outweigh the potential savings c.f. photocopiers/printers. The same is true for more traditional photocopiers but you can usually have more of them than the Risos before the sums start to look bad. But then you've got to consider capability and requirements across the estate - we've got half a dozen or so people who shouldn't have a printer by the logic of the spreadsheets, but functionally they are *way* more productive being able to print a sheet a couple of times a day to their desk rather than having to walk 2 minutes to the photocopiers and back while risking interruptions. If we did full cost recovery on just their device for each print we'd be looking at charging £1 per a4 side! It all gets smoothed out across the estate though. As it stands when one considers the entire estate, printing through actual desktop printers be they old laserjets or the newer pagewides, is almost a rounding error compared to the volumes (and thus costs) going through the photocopiers/MFD.
-
Half that number but twice the beasts + 2 Riso , 3.01 million pages. Got to say your per page charge is quite a bit better than ours. How long have you been on that contract / lease?
