Jump to content

Blue_Cookeh

Members
  • Posts

    1,485
  • Joined

  • Last visited

Everything posted by Blue_Cookeh

  1. I really wish I could go to A&A, they seem like a stand up company that know what they're doing - just a shame on the really low usage limits
  2. Which begs the question if the likes of Ubiquiti can do it, why can't/aren't Meraki, who are considerably more 'enterprise-y' and expensive.
  3. Our UniFi system certainly knows the IP address of the connecting client and passes it on through RADIUS Accounting just fine... I'm assuming it passes it along after all the authentication is done and a connection is established, but it's there.
  4. Had tons of issues with Virgin Media and their broken 'bandwidth management' system and proxying, which seems to break YouTube regularly. How about stop messing with my traffic? Their tech support couldn't work out why we were being throttled down to 0.2Mbps every day (despite being on their 200Mbps plan) and just went silent on the issue so I got them to terminate the contact since they couldn't deliver their service. Been with BT for a good 3+ years now and they've been flawless really. Started out on their employee plan and went over to normal consumer when I left, never had problems. Just now looking at EE Home broadband since it's vastly cheaper, and my parents haven't had any issues with them either. The key thing with any home broadband provider is don't use their supplied router if you can help it, they're complete junk every time. I bought a £10 Openreach modem from eBay and hooked up a Wireless AC capable router running DD-WRT and our connection has been rock solid, our router & connection uptime is nearing 200 days now.
  5. I think no matter what, you're going to end up wasting IP addresses if you want to route them internally like that. 1. Router external 2. Router internal 3. Firewall external 4. routed devices What firewall are you using?
  6. Does your firewall not have PPPoE capability? I know Sophos SG/XG, PfSense and most others do. I got a cheap Openreach VDSL modem from eBay and then put our PfSense firewall behind that. PfSense now does the PPPoE and I can do whatever I please with the IP addresses without wasting any. We did the same with Sophos, but our license ran out hence the switch
  7. I'll grab the configuration off our 2530 rack switch tomorrow for you
  8. You need to deploy the relevant group policies and the edits to make them point to your OneDrive library URLs, you can then use SSO. Users will still get the first run wizard when they try to open OneDrive, but it should be mostly automated anyway. https://support.office.com/en-gb/article/Deploy-the-new-OneDrive-sync-client-in-an-enterprise-environment-3f3a511c-30c6-404a-98bf-76f95c519668?ui=en-US&rs=en-GB&ad=GB
  9. Ruckus are correct. The users need to accept the certificate themselves unless a valid public certificate from a major vendor (Comodo/Symantec etc) is usable for whatever you're trying to do.
  10. In what way isn't it working? Have you bonded the four ports in Server Manager in Windows, and set the bonding type to LACP?
  11. I think people that buy first party SFPs are daft, the compatible ones haven't ever failed me, and cost single digits compared to the likes of Cisco and HP who wanted towards triple digits for them. If it's counterfeit routers and switches etc then fair game to the police and Cisco.
  12. Just out of interest, since you use SCCM - why are you deploying VNC? SCCM has a Remote Control console built right in with auditing and a configuration policy (through the SCCM client policy settings)
  13. Are you using a Zone Director or standalone APs? Is band steering turned on? AFAIK roaming between 2.4 and 5GHz isn't seamless, so you need to force them onto one or the other, or configure band steering/roaming properly. This is typically why a lot of APs will split the two frequencies into different SSIDs.
  14. You don’t NEED certificate services. You only need it if you’re running your own PKI for internal web services, SCCM, DirectAccess etc. It sounds like you need to clean stale DC entries and seize FSMO roles. FYI there’s no such thing as a PDC anymore. https://www.petri.com/delete_failed_dcs_from_ad https://support.microsoft.com/en-us/help/255504/using-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control
  15. It looks to me like that switch should be able to do basic Layer 3 routing with directly connected networks. Can you ping between VLANs if you have a host in each one with the gateway set as that DLink switch? If all else fails, then yes, you can use the 2920 switch you have as a L3 core switch, that’s what we’re using.
  16. ding ding ding, this is what we do, and it works flawlessly for AirPrint on iOS. You need to remember the bonjour part of this is *just* for discovery, it isn't for data transfer. I setup avahi and then watched our firewall logs as I tried to print something. I believe I just needed to allow access to TCP/443 from our Mobile Device VLAN to our AirPrint-enabled printers. I dare say this is the same for mirroring/screen sharing on Apple TVs or AirServer too, but we put those on our mobile VLAN too anyway since they're considered iOS devices.
  17. - Ethernet ports for access points - Ethernet port in the middle of the wall behind interactive displays - Ethernet ports and four power along teaching wall for laptops (usually wireless but you never know) - Teaching wall should have USB, HDMI, audio, VGA connections in DADO with above - Ethernet and dual power in DADO trunking along three other walls - Ethernet going to external wall for exterior CCTV Use Cat6 where possible. Then double up on how much ethernet you'll think you need! This is what I've just done for our new Primary classrooms.
  18. LAG would improve that. I'd look at getting a quad port NIC and initially bonding two of the links on a switch located somewhere in your network that has decent uplinks to the camera switches. Also FWIW we see a lot higher speeds on our gigabit links, typically over 500Mbps on our SCCM server when imaging machines... and that's a Hyper-V VM.
  19. We went with Sophos when we did this 3 years ago. Loved the Sophos UTM (NOT XG) software and would recommend it. We only stopped using it because we got Lightspeed and FortiGate with our SchoolsBroadband connection. FWIW Smoothwall were quoting prices 4 or 5 times that of Sophos.
  20. We were using an SG115 in our primary school, with about 100 devices with two FTTC connections of 20/10. It was doing internal routing, firewalling, VPN, filtering (before we moved to SchoolsBroadband), WAF etc. The CPU never went above 50% and RAM hovered around 75%. Most of them are just standard Intel computers. Plug a KVM in and you can install any OS on them you want. Our SG115 license is expiring this summer and I've just stuck pfSense on ours.
  21. FWIW I agree with others, even if you don't want to spend any money look at WDS and MDT. You can do all this stuff (and plenty more) using Task Sequences. Sysprepping machines is so buggy and old, I'm surprised MS haven't deprecated it yet.
  22. That report was written by Ruckus, so what do you expect? These large company are pooping their pants at the sight of Ubiquiti with their price vs featureset. Guest passes can be authorized by an Administrator, as with any Wireless system the authentication can be pretty much anything you want thanks to Radius (although UniFi has guest tokens built in already). Also you shouldn't ever let your Wireless solution do automatic channel switching and power levelling, you should be doing that yourself to suit your RF environment, but even still I think Ubiquiti may have this built into their newer models (since they have monitoring radios). My only qualm with Ubiquiti is the lack of "enterprise" support options, the hardware will perform superbly if configured properly by someone who knows Wireless and RF... the same as any Wireless vendor. I think all these enterprise-y managed solutions hide away the more advanced config behind management portals and automation, yet they usually do a pretty poor job of it... but just *good enough* to hide their shortcomings. As with anything you'll find people who love/hate different stuff, from my point of view we've had no trouble what so ever with our (now aging) UniFi setup in the last 5-6 years, this is with Radius and multiple SSIDs/VLANs with all kinds of random devices. Of course, I won't even go into how TERRIBLE the hardware was on our old Netgear system, but I think that's a given hehe
  23. I've been through this with Cisco, Meraki, HP, Ruckus, and AeroHive and none of them understand Primary school budgets at all, Meraki in particular. I can't afford £350 per AP + licensing to cover our school. I'm looking at replacing some gen1 Ubiquiti UniFi APs around our school and to be honest we've been nothing but happy with them - they only need replacing because we're becoming more Wireless-oriented and would benefit a lot from 5GHz, AC, and MIMO. I think for the cost of the Access Points I'll be replacing them all with Ubiquiti again, only this time going for the UniFi AP AC Pro or UniFi AP AC Lite models. No yearly licensing charges, no ridiculous pricing, and they're so cheap if one or two die outside of warranty we can just buy another to replace it. We've even used their kit to provide outdoor coverage now that the kids are taking iPads outside for Forest schools etc. To be honest, I wouldn't feel comfortable leaving a school with a burden like "pay Meraki or brick your network infrastructure", but that's just me.
  24. It's not just Windows it's setting up, it's also doing things like making sure GPOs are applied, user profile set up etc. You could enable verbose logon messages to see what stage it's actually at. I keep those verbose messages on by default across our domain, it gives users more confidence that Windows is actually doing something and not just sitting there stuck.
  25. Sounds like you need to take control over your network back off your LA. I don't see any need for LA controlled or provided services nowadays, generally they're worse than that you could do yourself or buy in from private companies, and cost more too. This was the case for us, anyway. Your LA was right, you can't really install your own SCCM instance since it *does* hook into Active Directory a lot, although I think (I could be wrong) you could do it under a child domain. You won't be able to run your own WSUS server since SCCM relies on that as a core function of it's updating and compliance functionality, so the LA will manage that on your behalf. I wouldn't trust an LA with SCCM access, though. There are plenty of cases of people doing dangerous things with SCCM and wiping out entire orgs.
×
×
  • Create New...