-
Posts
27,412 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by localzuk
-
Disaster recovery - recover to Azure?
localzuk replied to localzuk's topic in Thin Client and Virtual Machines
Recovery is getting everything back up and running again. So, getting temporary accommodation in place, including client devices - which, yes, will need to be kept up to date. It isn't in our "critical services" tier, so wouldn't be spun up day 1, but it would be recovered at some point. -
Disaster recovery - recover to Azure?
localzuk replied to localzuk's topic in Thin Client and Virtual Machines
The thing with RDP is that it gives device agnostic instant access to a working environment for staff. Those that don't have laptops etc... So its somewhat key to the whole DR process. -
It is aimed at everyone suddenly rushing to get remote teaching capabilities set up from scratch in the relatively short timeframe we have. I'm not being aggressive - if that's how you read what I said, I apologise, my writing style is pretty blunt. Introducing any remote learning environment or tools requires careful planning, with risk assessments and a proper understanding of the privacy and data protection implications, as well as the safeguarding implications. I would say that anyone looking at a tool they don't already use, now, ready for potential closure in the next week or so, is rushing it. We have taken a year to work through the implications of rolling out G Suite here, and there are still things that are being raised now.
- 43 replies
-
Disaster recovery - recover to Azure?
localzuk replied to localzuk's topic in Thin Client and Virtual Machines
OK, so I'll play along for a bit. We have the following services running: 2 x AD DCs - running AD, DHCP, DNS, Google Sync and Office 365 Sync tools 2 x NPS radius servers 1 x Print server 1 x Antivirus proxy appliance 1 x Antivirus VM scanning consolidation appliance 1 x Veeam server 1 x certificate services server 2 x file servers 1 x RDS license server/KMS server 4 x RDSH servers 1 x RD connection broker 1 x Zabbix server 1 x SAML server 1 x 3CX server 1 x RDS gateway/web access server 2 x SCCM servers (1 is the database, the other runs the other services) 2 x IIS web servers 1 x WSUS server 1 x Xibo server 6 x SIMS servers There's some other legacy stuff but it isn't important. You're saying that all that will use less resources as containers than it does as VMs? Even when VMs can scale down to very small levels - eg, our DCs currently are using 1GB RAM each, and an entire 80Mhz of CPU (I still find the VMWare way of measuring CPU usage odd, haha). A VM for each of those comes in at about £8pm. (The big cost ones are the remote desktop servers and SIMS servers) -
Last I checked, you weren't the OP in this thread @paulkerton - who appears to be rushing to do this without clear guidance or knowledge of the implications (which is why they're posting on here)... So, my points may not apply to you, but there have been a LOT of posts on remote teaching related stuff on the site recently, from people rushing to get something working asap. I would be worried about such significant new systems being introduced on such a short term without thorough investigation of those consequences.
- 43 replies
-
Well, no, not entirely. Our jobs are to run the IT in our schools and fulfil reasonable requests. Opening safeguarding risks and providing livestreams during a quarantine are not exactly "reasonable" in my view. Especially in the short timeframe being dumped on everyone, so you don't have the time to properly check out all the risks associated with it. Rolling out something like G Suite to people in a matter of days, getting people to use Meet with nearly no notice or training, and without any safeguarding in place? Seems like overkill.
- 43 replies
-
- 1
-
-
I am struggling to understand the thinking behind using something like Meet. If the school is closed, it is closed - you cannot enforce children turning up to sessions outside of school - you can't register them, the school is closed. You can set homework, and have recordings for them to play maybe (even then, a simple reply of "we don't have a working computer" kills the idea off instantly, as there's no way to argue against that. You end up creating work for those who have stuff at home, but those that don't are now immediately disadvantaged. I just don't see any of this being enforceable.
- 43 replies
-
Disaster recovery - recover to Azure?
localzuk replied to localzuk's topic in Thin Client and Virtual Machines
I'm still struggling to see the advantage of running a Windows network in containers. If someone fancies writing something up saying why it would be better than simply running VMs, like most of us do now, that'd be great. As it stands, it seems to just be adding a layer of complexity. -
Disaster recovery - recover to Azure?
localzuk replied to localzuk's topic in Thin Client and Virtual Machines
Pretty much none of this would be possible with a normal Windows network like ours - Windows network services don't live in containers, Microsoft doesn't support that. Eg. Windows DHCP, DNS, file server, etc... -
Depends on the size of the drones. Small drones? Swarm. Big military sized drones? Nightmare.
-
How much support do you have and need?
localzuk replied to Sonic3's topic in Learning Network Manager
When we were a single school, I had similar to you (same in terms of size, kit etc...) and there was just me. Now, we're a Trust of 6 schools and 2 nurseries (and 2 pre-schools that are part of their schools), 1600 children, 300+ staff, 1000+ client devices, and there is me (IT Manager), senior technician and technician - all full time. We manage quite well now, as we rebuilt everything from scratch, so its all running well. -
I run 2x 8 vCPU VMs, each with 16GB RAM and that works well for 30 computers. So near enough 1GB per session for basic usage.
-
Disaster recovery - recover to Azure?
localzuk replied to localzuk's topic in Thin Client and Virtual Machines
Simply running the VMs, and a VPN to access them. Basically, it'd be spinning up our entire infrastructure in Azure. -
I'm now in the process of rewriting our slightly out of date disaster recovery procedure for our network, and have come to the point where I am not sure which direction I should go with the recovery procedure. We backup everything with Veeam, then weekly upload that to Azure archive tier storage - so in the case the building burns down we have that data. Now with recovery, we have the option of downloading it all (it is split into 4 tiers of importance) and rebuilding it back on hardware on-prem. This means getting replacement hardware asap - which can take a day or 2, along with power and internet connectivity. The other option, is recovering to Azure. We'd have a VM sat in Azure, spun down, which can mount the Azure blob storage, and allow us to restore the data direct into Azure. This would be considerably faster - we wouldn't need to download 11TB of data so we could get everything up and running very quickly. Including a RDS setup accessible via VPN. We could then later migrate each VM on to the new on-prem servers as we got them. To run our setup like this in Azure looks like it'd cost us around £5000 a month, so we'd not want to run it too long like this. What are others doing? Would you go for the super quick, but expensive option, or go for the slower but cheaper option?
-
Biometric fingerprints - polish school fined!
localzuk replied to Jaymate's topic in Data Protection & Information Handling
The law disagrees, as the original article shows. Poland's data protection rules are based on GDPR, as are the UK's so it is likely applicable here too. And that is what matters in this discussion, as we work in professional environments where we have to abide by the law. This isn't just about fingerprints either. A Swedish school was fined for using facial recognition - even though the school got permission from the parents, the school were still fined as the Swedish equivalent of the ICO didn't consider this to be adequate for the reason they were using the data, and that there were less intrusive ways of achieving their goal. -
Why would you lift and shift basic services like that to the cloud? If you're just looking to migrate existing workloads into the cloud you're doing it wrong. Not to mention, DHCP in the cloud, would be an odd idea IMO. DNS in the cloud? There are cloud DNS services, so I would question running a dedicated anything for DNS. The only one of those things I realistically see as being suited to containerisation is the web applications (note, the applications, not the servers). Most schools I know don't run their own websites or parental engagement tools - they pay a service provider to do that, so I can still only see limited scope for their usefulness even with your explanation. If you think containers are how school IT is going to be provided in the future, I think you missed something - most school services are moving to a subscription basis provided by their makers. MIS? Cloud subscription. Library software? Cloud subscription. The number of services you'll be running yourself will shrink. Not to mention, nearly nothing on a standard Windows network is in a container - not DNS, AD, print services, file services, remote desktop sessions, etc... So, I'm back to "why containers in education?". If you're migrating away from the old standard Windows network, then migrating into what would be a very custom setup with containerised systems, instead of cloud services, seems to be looking at it wrong IMO. If I look at my entire network, I can see maybe 3 packages that would be suited to containerisation - Xibo, our SimpleSAML installation, and Passbolt. Out of 47 VMs.
-
I'm struggling to see what a school would need containers for. As far as I've experienced, we don't run software that works in a containerised way. We don't need it to scale very much either. So, why containers? Average network DHCP, DNS, file storage, radius server, MIS, etc... I can see their value for organisations that develop software and/or scale software across providers and want a nice controllable environment, but for a school network? Just can't see it.
-
Biometric fingerprints - polish school fined!
localzuk replied to Jaymate's topic in Data Protection & Information Handling
Because you can change a PIN, you can't change your fingers. -
We have 2 VM servers for our Trust's files. 1 hosts home drives, desktops, application data etc... The other hosts shared drives. We have 2 physical devices storing the data - 2 QNAP applicances with VMs stored on them via iSCSI.
-
[windows software] Student RDS Server 2012 CALS? Anyone got Crayons?
localzuk replied to JRA's topic in Licensing Questions
See, when I looked at it, I was told that children aren't classed as employees, so come under the definition for external users. -
Biometric fingerprints - polish school fined!
localzuk replied to Jaymate's topic in Data Protection & Information Handling
I believe it depends on how you're processing it - it becomes biometric data when you're using it as such. Biometric data is classified as "special category data" when it is used for identification purposes. So, a photo stored on a PC of a fun event - not biometric data used for identification. A database of photos used for matching faces when they walk around the school? Biometric data for identification purposes. -
Biometric fingerprints - polish school fined!
localzuk replied to Jaymate's topic in Data Protection & Information Handling
The law disagrees with you I'm afraid. All data is stored as numbers. A photo on a computer? Just binary data. The output of a fingerprint reader? Binary data. The Protection of Freedoms Act 2012 stipulates that fingerprint data can only be used in a school with consent from both the child and the parents. The definition of fingerprint data includes your long numbers. -
Biometric fingerprints - polish school fined!
localzuk replied to Jaymate's topic in Data Protection & Information Handling
You can get EM4100 cards for less than 20p a card. -
Biometric fingerprints - polish school fined!
localzuk replied to Jaymate's topic in Data Protection & Information Handling
That's the thing - there are other alternatives - we use RFID cards and PIN numbers. Personally I don't like the PIN number part, but I was overruled (it carries a risk of "unknown theft" that a physical object doesn't). Sure, we have to print new IDs pretty regularly, but the system generally works. Fingerprints aren't necessary. -
Biometric fingerprints - polish school fined!
localzuk replied to Jaymate's topic in Data Protection & Information Handling
You are basing that on what you know, but not what may be possible at some point soon. Take the problem of the DNA companies in the USA. Those ones you send a swab to and it tells you which part of the world you come from, and what illnesses you are predisposed to. Sounds like a nice service. Except, the data has been used by police in recent years, because it has lower protection requirements than forcing someone to hand over their DNA via a warrant. So, whilst you may not recognise a way to use the fingerprint data here and now, the law recognises that this can change very rapidly, and we should all fall back to the default position - you must adequately justify collecting and processing that data, and it must be proportionate to the sensitivity of that data.
