Jump to content

synaesthesia

Members
  • Posts

    12,745
  • Joined

Reputation

44,509 Excellent

4 Followers

About synaesthesia

Recent Profile Visitors

26,801 profile views
  1. Statement from Cambium: https://www.cambiumnetworks.com/wp-content/uploads/Cambium-Networks-Company-Statement-Sep-16-2026.pdf Probably the most pertinent bit: The intention is that cnMaestro Cloud will continue to operate at least through 1 October.
  2. Yeah but if anyone doesn't have MFA in for all staff already, regardless of SLT opinion, they are failing the school and the school are failing themselves. I'd have my "gun and badge" on the table before they brushed that off.
  3. Not all that much has changed which is likely to cost anything, there does appear to be clarification on cyberessentials as the DfE is very specifically not saying anything about MFA for pupils so CE is absolutely entirely a choice for anyone other than FE. That at least has removed one of the bigger concerns.
  4. At least the Aerohive kit can be used singularly to good effect - I had a pair of Aerohive APs running my home wireless until I replaced it with UniFi (and may end up going back to it if we need to put the unifi back in at school! )
  5. That's the one thing Clever should absolutely be used for, it's awesome for primary logins and could easily be implemented for older SEND or medical need students too. Just don't like seeing it used in the same sentence as MFA, because whatever the marketing says, it isn't.
  6. Update - that's my misunderstanding and should sometimes take the time to RTFM Needed to create a user specifically for onboarding (click profile, create account, select "Anchor" (not an anchor being so unfortunately Hugh Jackman isn't going to arrive) That's done the job immediately so now I'm down to seeing how enrolment works and exporting/importing setups. Naturally I'm documenting the process for our trust so I'll share the same process here in case it saves someone else a lot of trial and error, but with luck it won't be needed.
  7. Whelp, I don't think going local is the answer unless I've missed something. To install the local appliance, it needs to connect to the cloud - and it refuses to do that due to missing cookies. I've pushed some Maryland's into the floppy drive but it's still not having it despite it making clear "nom nom nom" noises.
  8. So far they know about as much as we do - our CtC install is still effectively ongoing, but both our framework supplier and the end installers have been entirely transparent. When they get more information I'm confident they'll pass it on. It seems like difficulty is stemming from the parent company's lack of transparency and/or communication on it, which speaks volumes.
  9. I believe so as the configuration is run directly from the device. However without the cloud controller you have no visibility of the devices so you're not longer proactively managing them, you're possibly no longer KCSIE/CE compliant if you can't track what devices are where and used by whom, no guest portal. However if the cloud service goes, will they automatically say NOPE if they can't verify their own license? I think it's frankly daft to just sit and do nothing assuming it'll all work out - dereliction of duty if anything especially if there's a reasonably simple workaround and even more so working entirely on the assumption that the cloud dropping means everything just ticks along as normal - are you *sure* the licensing isn't strict and only set to cater for short outages of say, 12 to 24 hours?
  10. Quite right - probably should have said agree to a point It's been a long couple of weeks! Ruckus was also similarly thought of in the late noughties/early tens, and even now it's nearly always the name on the tip of peoples tongues ahead of the bigger enterprise players. Not sure why, never could stand that damn finickety system! But still better than Aruba Central
  11. BYOD - school devices are easy thanks to MDM. Inspection certs as mentioned are also easy, installed as they normally would be (manually) and indeed users must have traffic inspected. Unless, which is quite possible, I'm misunderstanding and the 2 can be linked?
  12. If running Hyper-V, extract the OVA appliance and use the solarwinds V2V app to convert the VMDKs (x2) to VHDX. Secure boot off.
  13. Decryption is the "easy" part - that's still handled by getting them to install the smoothwall cert via the /getmitm URL as always, it's just this initial bit for authorisation which is adding yet another step. I'm not aware that Easypass would make it any different regarding inspection, it'd just allow connection similar to NPS with authentication to Google, visible by Smoothwall for monitoring/filtering purposes but still (AFAIK) needs the certificate installing manually.
  14. Cheers, no worries - I did see the Trust on First Use option on the Android 16 device I was trying this morning, but it didn't seem to work. I didn't spend much time on it though, so I'll grab it later. MDM is out of the question, these are personal devices. With luck the cambium setup gets sorted out and I'll make use of easypass which will allow SSO via Google
  15. Starting to have a few more issues with PEAP authentication with newer Android versions and Samsung devices. Up to, I believe, Android 15 it seems quite easy - forgo the CA certificate, provide username and password and remove "anonymous" from the anonymous identity and everything connects hunky dory. Iphones are even less hassle - username, password, trust the smoothwall certificate. end of. However on newer devices and Samsungs, it won't progress without either using a system certificate or installing one, adding yet another step. It's easy to say I'd love to ditch BYOD and I still think it's days are numbered but mobile signal round here is non existent. I'd also love to be able to leverage the options in Cambium but.... we all know why that's probably not worth pursuing at the moment. So for certificates, what exactly are others doing please? I've tried using system certificate and our local domain but that doesn't work, and not a clue what actual certificate to provide for connecting in the first place. Documentation to this effect seems to be all over the shop and my brain hurts
×
×
  • Create New...