-
Posts
12,747 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by synaesthesia
-
Unlikely, there seems to be a lot of heads in sands over there especially if what's been said by the ex employees is true. Plus the whole organisation seems a bit odd especially after the supposed offloading of EMEA in march. The more I look into it, the worse it looks and I suspect the US branch isn't long for this world either.
-
This is a quick and dirty guide to setting up cnMaestro local appliance and enrolling an/some APs - please excuse formatting, doesn't much like copy & pasting from google docs. This is also a work in progress as I've been going along and some parts may or may not be necessary. I don't know if you need to create an onboarding user if setting the onboarding details locally on the AP, have yet to test. This gets you up to the point of having a device enrolled on your newly created local install on a blank canvas - my next job is to try and work out exporting/importing configs. For reference, our devices are X7-35x and 55x on the latest firmware, with local appliance version 6.0 (latest version available to download) Creating a new cloud anchor account Log into cloud cnMaestro click profile name then Create Account. Go through the process of making a new account, doesn't matter if it uses same email address/contact details as any admin/yourself in cloud. For Cambium ID enter something like SCHOOLNAME_LOCAL_CNMAESTRO. Account type must be Anchor. Account view Enterprise. Log in to new account, and under Onboarding note the Cambium ID and Account ID, these will be needed for the local install. Using the virtual appliance Download the local appliance from Cambium - as of 16/9/26 latest is cnmaestro-on-premises_6.0.0-r6_amd64.ova If using VMWare, extract the OVA (any zip extractor will work inc 7zip) and grab the two VMDK files. Create a VM with both disks, disk1 is boot drive. 2 CPU, 4GB ram recommended. If using HyperV, use SolarWinds V2V converter to convert those VMDKs to VHDX. Create a Gen1 VM, 2CPU, 4GB ram, attach both drives (IDE) and fire it up. For networking, use the same IP range as the management IPs of the APs. Follow installation instructions from the userguide - "cnMaestro On-Premises User Guide 6.0.0.pdf" and set up with relevant network address, set passwords etc - default is cambium/cnmaestro Log into the UI via the set IP address, default credentials are admin/admin. It will immediately prompt you to connect to a cloud account for provisioning. Enter the cambium ID and password set for the created anchor user. Onboarding Access Points (Might not be necessary if onboarding manually?) In local cnMaestro UI: Add user for onboarding devices - Administration > Users > Add User Onboard > Settings > tick Enable Cambium ID based auth to onboard devices Add user and enter onboarding key (create your own), click Save Onboard > Claim device > Select device type (usually Enterprise WiFi (X7 Series)) and enter or scan mac address(es) in box. Click claim devices Click Approve All On local AP to be onboarded: Assuming the AP is factory reset AP should receive IP via DHCP. Browse to it with https://ip. Default user/pass is admin/admin If it’s still present in cloud cnMaestro it will warn as such on the first page - ignore and click through to login page. They may need removing from Cloud beforehand otherwise they will sync up again and pick up config again including login credentials. For note - factory reset by holding AP reset button in for over 10 seconds Default credentials are admin/admin If device is in place and not reset you may be able to do this assuming you have the local credentials for SSH access to the AP (Couldn't get this bit to work but assume this should be correct) Log into UI, configure > system > set country Code to United Kington, put in the admin password, tick remote management and validate server certificate, entry https://server_ip for cnMaestro URL, your cambium ID created above and the key in relevant boxes, hit save. Only worked for me doing it via the ap's CLI with following commands: country-code GB cambium-id CAMBIUM_ID_HERE CAMBIUM_ONBOARDING_KEY_HERE management http management https management cambium-remote url https://server_ip management cambium-remote validate-server-cert
-
Statement from Cambium: https://www.cambiumnetworks.com/wp-content/uploads/Cambium-Networks-Company-Statement-Sep-16-2026.pdf Probably the most pertinent bit: The intention is that cnMaestro Cloud will continue to operate at least through 1 October.
-
DfE refreshes the digital and technology standards manual
synaesthesia commented on EduGeek's news article in Articles
Yeah but if anyone doesn't have MFA in for all staff already, regardless of SLT opinion, they are failing the school and the school are failing themselves. I'd have my "gun and badge" on the table before they brushed that off. -
DfE refreshes the digital and technology standards manual
synaesthesia commented on EduGeek's news article in Articles
Not all that much has changed which is likely to cost anything, there does appear to be clarification on cyberessentials as the DfE is very specifically not saying anything about MFA for pupils so CE is absolutely entirely a choice for anyone other than FE. That at least has removed one of the bigger concerns. -
At least the Aerohive kit can be used singularly to good effect - I had a pair of Aerohive APs running my home wireless until I replaced it with UniFi (and may end up going back to it if we need to put the unifi back in at school! )
-
Clever - QR code Sign In for Chromebooks
synaesthesia replied to Planehazza's topic in ChromeOS & Cloud Based OS
That's the one thing Clever should absolutely be used for, it's awesome for primary logins and could easily be implemented for older SEND or medical need students too. Just don't like seeing it used in the same sentence as MFA, because whatever the marketing says, it isn't. -
Update - that's my misunderstanding and should sometimes take the time to RTFM Needed to create a user specifically for onboarding (click profile, create account, select "Anchor" (not an anchor being so unfortunately Hugh Jackman isn't going to arrive) That's done the job immediately so now I'm down to seeing how enrolment works and exporting/importing setups. Naturally I'm documenting the process for our trust so I'll share the same process here in case it saves someone else a lot of trial and error, but with luck it won't be needed.
-
Whelp, I don't think going local is the answer unless I've missed something. To install the local appliance, it needs to connect to the cloud - and it refuses to do that due to missing cookies. I've pushed some Maryland's into the floppy drive but it's still not having it despite it making clear "nom nom nom" noises.
-
So far they know about as much as we do - our CtC install is still effectively ongoing, but both our framework supplier and the end installers have been entirely transparent. When they get more information I'm confident they'll pass it on. It seems like difficulty is stemming from the parent company's lack of transparency and/or communication on it, which speaks volumes.
-
I believe so as the configuration is run directly from the device. However without the cloud controller you have no visibility of the devices so you're not longer proactively managing them, you're possibly no longer KCSIE/CE compliant if you can't track what devices are where and used by whom, no guest portal. However if the cloud service goes, will they automatically say NOPE if they can't verify their own license? I think it's frankly daft to just sit and do nothing assuming it'll all work out - dereliction of duty if anything especially if there's a reasonably simple workaround and even more so working entirely on the assumption that the cloud dropping means everything just ticks along as normal - are you *sure* the licensing isn't strict and only set to cater for short outages of say, 12 to 24 hours?
-
Quite right - probably should have said agree to a point It's been a long couple of weeks! Ruckus was also similarly thought of in the late noughties/early tens, and even now it's nearly always the name on the tip of peoples tongues ahead of the bigger enterprise players. Not sure why, never could stand that damn finickety system! But still better than Aruba Central
-
Enterprise WiFi and Androids
synaesthesia replied to synaesthesia's topic in Mobile Devices & Tablets
BYOD - school devices are easy thanks to MDM. Inspection certs as mentioned are also easy, installed as they normally would be (manually) and indeed users must have traffic inspected. Unless, which is quite possible, I'm misunderstanding and the 2 can be linked? -
If running Hyper-V, extract the OVA appliance and use the solarwinds V2V app to convert the VMDKs (x2) to VHDX. Secure boot off.
-
Enterprise WiFi and Androids
synaesthesia replied to synaesthesia's topic in Mobile Devices & Tablets
Decryption is the "easy" part - that's still handled by getting them to install the smoothwall cert via the /getmitm URL as always, it's just this initial bit for authorisation which is adding yet another step. I'm not aware that Easypass would make it any different regarding inspection, it'd just allow connection similar to NPS with authentication to Google, visible by Smoothwall for monitoring/filtering purposes but still (AFAIK) needs the certificate installing manually. -
Enterprise WiFi and Androids
synaesthesia replied to synaesthesia's topic in Mobile Devices & Tablets
Cheers, no worries - I did see the Trust on First Use option on the Android 16 device I was trying this morning, but it didn't seem to work. I didn't spend much time on it though, so I'll grab it later. MDM is out of the question, these are personal devices. With luck the cambium setup gets sorted out and I'll make use of easypass which will allow SSO via Google -
Starting to have a few more issues with PEAP authentication with newer Android versions and Samsung devices. Up to, I believe, Android 15 it seems quite easy - forgo the CA certificate, provide username and password and remove "anonymous" from the anonymous identity and everything connects hunky dory. Iphones are even less hassle - username, password, trust the smoothwall certificate. end of. However on newer devices and Samsungs, it won't progress without either using a system certificate or installing one, adding yet another step. It's easy to say I'd love to ditch BYOD and I still think it's days are numbered but mobile signal round here is non existent. I'd also love to be able to leverage the options in Cambium but.... we all know why that's probably not worth pursuing at the moment. So for certificates, what exactly are others doing please? I've tried using system certificate and our local domain but that doesn't work, and not a clue what actual certificate to provide for connecting in the first place. Documentation to this effect seems to be all over the shop and my brain hurts
-
No sorry, I meant that people used to think they were a bit risky - very much like Cambium, I recall having to convince people that it was a good system especially for the money, and that many local authorities were using them (both in schools and on here).
-
Disagree to a point, Cambium were a very strong prospect. It wasn't that long ago even on here where people thought the same about Ubiquiti who share the same roots, and many people would choose the latter over many of the "big" players regardless of the financial aspect. And it's not like the tech at least wasn't from a strong background, if the name was still Motorola people wouldn't bat an eye. However it's clear the writing was on the wall in this instance from at least March this year. No apparent updates overnight unfortunately but some research has given me a slightly clearer understanding of the setup. Whilst the US arm "disowned" the UK/EMEA arm effectively it was still the controller/parent company. Section 11 bankruptcy in the states isn't as bad as it sounds, it allows for a large scale restructure which in their case is the dissolution without any severance pay of 53% of their entire global workforce and closure of the EMEA arm as expected. In March when they were delisted from NASDAQ, they had appealed this - a decision which was refused finally just at the back end of August so they remained delisted despite having apparently caught up with their filing records at SEC (US counterpart of Companies House), they were clearly not convinced by the state of the financials - https://www.sec.gov/Archives/edgar/data/1738177/000119312526389901/cmbmf-20260911.htm There's some good reading here about the devices/platforms themselves - https://wirelessnerd.net/2026/09/14/cambium-s-radios-will-outlive-the-company-the-last-great/ and a few sources on Linkedin are saying that whilst it's absolutely technically possible to migrate over to local VM, it does still need someone to "flick the switch" re licensing, very much worth doing just to cover ourselves as the future of things like cnMaestro is entirely unanswered and uncertain.
-
This is available by default in Bromcom, with the right permissions this can be a widget on the home screen and then by extension with the bromcom trust management (vision?)
-
Jamie at Atom has posted the following on ANME which might offer a slight bit of reassurance: "Spoken to a few people this morning, including UK distributors about this. Short answer is don't panic yet. I won't bore with all the details, but they do expect things to sort themselves out. If I learn anything else, I'll update here"
-
Yeah already have, 7.2r1 for our X35s
-
I have reached out to our CtC framework supplier and the DfE as ours was installed over Summer, and we're still waiting a couple of external APs. So far they've not got any more information than we have, but we're trying to cover ourselves in case the worst case scenario happens. I *think* we can remove the APs from auto provisioning and manually enrol them in the local system but there is zero information about doing that, only to enrol to each out of the box. Huge shame - it's only been running a couple of weeks and I love it.
-
https://support.cambiumnetworks.com/files/cnmaestro/
-
Yeah, it's the basic "essentials" version apparently. Regardless, I'm downloading both that and the AWS images now just in case.
