Jump to content

TheHyperTechie

Members
  • Posts

    699
  • Joined

  • Last visited

Everything posted by TheHyperTechie

  1. Quick question, All of our access points (~20) have statically assigned IP addresses. When creating the 'Wi-Fi' VLAN for them to reside in, would I just request my ISP to create a range for where they start and end. E.g .21 > .41...?
  2. Great, thanks. So essentially unless I add in any ACLs on the router, devices will still communicate freely between each SSID and VLAN. I suppose this is fine, to be honest it would be the 'Guest' SSID I would want isolating. Thank you for explaining, you have helped understand a lot.
  3. Great, thank you for such an in-depth response. It helps a lot! You have ALOT of addresses haha! We have 1022 addresses within our main subnet. I see what you mean about having the separate Wi-Fi VLAN too. It just makes it a bit neater and groups all of the UniFi kit together as well. I would then make the native VLAN on the ports connected to the WAPs 'Wi-Fi' but allow all of the other VLANs (SSIDs) through them? This way devices would still receive an address from that particular VLANs subnet, and the access points will be able to communicate between all 3 SSIDs... I hope this is right? please tell me if not! If I follow this route, would the devices not be able communicate between the VLANs? or would they as I am allowing all of the VLANs through the WAPs/switch ports?
  4. Ok... I think I understand what you mean. So it would be best practice to actually have a separate VLAN for the WiFi points themselves? Then I would tag the ports with all of the separate SSID VLANs so it allows traffic through them all...? If I am assigning the SSIDs to the VLANs anyway, would it not just work without this extra step e.g creating another VLAN named WiFi. Again, sorry if the answer is obvious, I am just trying to gain as much info as possible Thanks!
  5. Thank you so much for such an in-depth response, it helps a lot. One question, you stated 'Once all wired ports are tagged you can, as you rightly stated start to create SSID with VLAN tags on your Wi-Fi infrastructure' If I am just starting with the SSIDs, do I really need to tag all of the ports? I will be assigning each SSID to the relevant VLAN created on the switch. Doesn't this mean that when a client connects it will receive an IP address from that subnet and then in turn be on the correct VLAN? - This may be a silly question, but just wanted to confirm Thanks!
  6. Ah ok... I know what this is now. Sorry for the confusion, so with this feature, I assign a password to a particular VLAN. So when a device connects to the single SSID, it will check what password it used to join, and subsequently place them in the corresponding VLAN? This sounds like exactly what I need. Thanks for explaining
  7. This is an interesting take. Didn't think about this method, although, having 3 SSIDs doesn't bother me that much. I just push the SSID out to devices anyway (Chromebooks, iPads etc) I also think it 'seems' more organised in my head, although probably not technically haha!
  8. Hi, thanks for your reply. We currently have 3 SSIDs. ****-STAFF ****-STUDENT ****-GUEST. So you would advise not having these on separate VLANs? I don't want to go over the top (heard/seen horror stories in the past) I do have access and control over the IP space, so I can supply the ISP with the subnets I would like to use. We don't have any routing enabled on our switches currently, so yes, the VLANs would be configured on the router/firewall then I would add them to the UniFi console (This is for the SSIDs). I could then setup port tagging at a later date once those VLANs are configured. Thanks.
  9. Hi all, When I inherited our network nearly 12 months ago it was just a basic/flat setup. We have about 450 wireless clients, and about 30 (mixture of voip phones, printers, desktops) wired devices now live on the network. I have been wanting to implement VLANs for a while, but just struggled to carry this out, amongst the long list of other stuff I have to do. My first goal is to separate each SSID and place them onto their own VLAN. So when someone connects to Guest for example, they recieve an IP from that dedicated subnet. I can then adjust the filtering and add these separate subnet ranges so devices get the correct filtering automatically. After setting these up, I will then look into creating VLANs for our wired devices, but currently we rely much more on our wireless system, so I believe this takes precedence. As our DHCP and DNS is all hosted router side by the ISP, I guess my first task is asking them to create these VLANs with the correct ranges and enable DHCP on them? I can then go into UniFi and add the VLANs and subnets. This will allow me to assign each SSID to the relevant VLAN. Can anyone see any further issues I might run into? Thanks.
  10. Hi all, When I inherited our network nearly 12 months ago it was just a basic/flat setup. We have about 450 wireless clients, and about 30 (mixture of voip phones, printers, desktops) wired devices now live on the network. I have been wanting to implement VLANs for a while, but just struggled to carry this out, amongst the long list of other stuff I have to do. My first goal is to separate each SSID and place them onto their own VLAN. So when someone connects to Guest for example, they recieve an IP from that dedicated subnet. I can then adjust the filtering and add these separate subnet ranges so devices get the correct filtering automatically. After setting these up, I will then look into creating VLANs for our wired devices, but currently we rely much more on our wireless system, so I believe this takes precedence. As our DHCP and DNS is all hosted router side by the ISP, I guess my first task is asking them to create these VLANs with the correct ranges and enable DHCP on them? I can then go into UniFi and add the VLANs and subnets. This will allow me to assign each SSID to the relevant VLAN. Can anyone see any further issues I might run into? Thanks.
  11. I would say they have definitely done this out of ease. So all devices connected to that switch can communicate between the VLANs. The VLANs can then be adjusted on a 'per port' basis if and when you require them.
  12. We have 1:1 chromebooks for years 5 & 6. We filter them at home using RMSafetyNet Go. It copies the the top level (on-site) policy and applies it to the Google users (students) we pull through. So they have the same policy and filtering level applied at school and at home. I saw recently that they released a version for IOS which I believe can be deployed using JAMF school (if that is your MDM). I believe there are quite a few companies offering this kind of solution at the moment, (Senso, Securly etc)
  13. If I understand correctly, you could just commission the new DC (3?) and then configure a DHCP failover from the DC you are removing. This should replicate the scopes across to the new DC. Then it may just be case of going in manually and sorting it out.
  14. I have used Stone desktops a lot in the past. They normally offer a *free* 3 year next business day warranty. Saved me quite a few times in the past
  15. Hi all, I was wondering if anyone here uses device only intune licenses for their laptops? We are a google school, but I am looking for a new MDM solution for the remaining (roughly ~20) windows devices we have on site. I currently use Google's MDM but I believe it may be cheaper and a more viable option to use Microsoft Intune. I am not interested in getting them A3 licenses etc, and they won't use the services. We want to continue using Gmail, Google drive etc. My plan was to use a DEM and enrol the devices manually. Do the users logging into the intune devices also need a license? This was a bit unclear online when researching. Thanks
  16. Jamf school... used it in my old trust of about 30 schools. Central Apple School Manager tenant with each school as a location. Then a central jamf tenant with each school as a separate instance. Worked very well.
  17. Might depend on the model you have, as not all of them have the add-on available. But yes... I use it for Google Workspace, backs up our user drives, shared drives, calendars, mail, contacts. Have a read here: https://www.synology.com/en-global/dsm/feature/active_backup_office365
  18. A Synology NAS running active backup will be your cheapest solution. But this would be on-site. You could however, then back up the NAS to a cloud solution like backblaze or wasabi though
  19. I would probably wait until you are in a position to migrate all DHCP scopes for each subnet to the firewall. It sounds like things could get messy... If you decide to proceed, I imagine it's just a matter of removing the scope for the specific subnet you want to migrate from the Windows DHCP server. Additionally, you might want to consider adjusting lease times to ensure devices pick up an address smoothly from the firewall. I did a similar thing a while ago, glad I did as DHCP/DNS seems to be solid on our juniper box.
  20. I use a Blink doorbell. I managed to pick one up for £35 in the sales after Christmas. For the money, I think it's great. Mine isn't hardwired, as I just wanted a cheap solution without the added stress. I also have mine connected to Amazon Echo devices around the house, which act as 'chimes' when someone presses it. Picture quality is good (for £35!!), the battery has been going for a few months now, and motion detection is pretty good too. If you aren't on a budget, I would probably recommend a reolink, eufy, tapo.
  21. +1 for Phoenix. Used them for ages, their support is (in my experience) top notch
  22. I was in a similar-sized Trust as you in my previous role with roughly ~30 schools. They decided they wanted to consolidate Office 365 tenants and merge every school into one. This meant we had multiple domains inside the central tenant with this format [email protected] We were only a small team of about 7; there was no way we could have handled a migration like this ourselves AND still provide a top-notch support service with fast response times along with juggling tickets on our helpdesk. We paid for a company to do it for us, school by school. Usually, one or two a week so it gave us time to provide support to that school(s) regarding the migration. Some schools had always used Google, so they needed extra, whereas some schools didn't really need any as they used O365 previously, and the only thing that changed for them was their email address. Something like this requires a lot of planning, and I won't lie, with only 4 technicians, it would be very stressful. If the budget allows, I would see how much it would cost for a 3rd-party company to do it. Yes... you and your team could probably do it for cheaper, but it is one less thing for you to worry about. As I am sure just providing support for it might cause some headaches!!!
  23. I had a demo/meeting with verkada a while back, and to be fair they looked awesome. But pricing was scary...
  24. Forgot to mention that on my previous reply... central email system (O365). In the end, we had about 30 schools in one tenant with a MAT format e.g [email protected] Only caused a few headaches, especially for schools that had been fully google/g-suite for years...
×
×
  • Create New...