Jump to content

Blue_Cookeh

Members
  • Posts

    1,485
  • Joined

  • Last visited

Everything posted by Blue_Cookeh

  1. I don't think there would be nearly as much of a problem if the FortiGate boxes had died 3 times - what's taking the biscuit in this situation is the amount of issues there were initially with Lightspeed (we've had at least 4 periods of downtime, if not more due to those) ON TOP OF the FortiGate problems.
  2. Yes, I'll be kicking up a fuss about this once I can actually get through on the phones. We rely on our connection for just about everything nowadays, the biggest thing being Office365 and Integris MIS. Not only is this downtime costing our kids' education time, it's costing all our admin staff time too. Our backup line with Eclipse Internet has more uptime than this - I'm contemplating putting our Sophos filtering back in place and pushing our traffic over that connection until SB sort their issues out. Not an acceptable solution. At all.
  3. Been down for an hour and counting so far. We'll be looking into our SLAs and contracts today, this is completely unacceptable during the school day. I appreciate FortiGate are working on the problem, I appreciate it might not be SB's fault and that they're working on sorting their network out, and I totally appreciate how unreachable I've been when it comes to having a talk with them, but this is starting to negatively impact our school on a large scale. What's the escalation process on complaints?
  4. The thing to bare in mind with sticking that many clients on a network is your wireless infrastructure will suffer. Each device connected to a WAP is going to have to send and receive broadcasts on that VLAN. If you have a trolley full of iPads/laptops on an AP on a VLAN with 1500 devices, you're probably going to start seeing performance degradation.
  5. I'd argue the way @FN-GM suggests would mean you need L3 switches on the edge too. If you have a L3 core and L2 edge switches there's no reason VLANs can span multiple switches, just make sure your uplinks are solid. The other thing is we span VLANs across switches so we can get point to point links and things from one side of our building to another without relocating equipment. Not necessarily the best solution but you have to work with what you've got. One step at a time.
  6. This won't make any difference. BT as a company already go into Openreach exactly the same way external companies do. In my short stint at BT we had Openreach employees working at desks literally opposite us, but we'd get into trouble for even mentioning business in conversation with them. They take regulation inside the company extremely seriously (three hours of my life I'll never get back after the regulation presentation I was given...). I honestly think it'll make things worse. No one bid on government funding other than BT, no one else can be bothered extending rural networks, and Sky/TalkTalk/Virgin etc all have their own agendas and use BT as a scapegoat for anything.
  7. What OS? Are you running SCCM? Where are the files stored and what sort of files? MsMpEng.exe is part of the Windows Defender/Microsoft Antimalware/SCCM EndPoint protection programs like you say
  8. Tbh I'd focus on getting a consistent infrastructure first, the different quirks when it comes to terminology and setups regarding VLANs across Dell/HP/Cisco/Netgear/D-Link/Juniper/ is going to give you some huge headaches. But yes, I really would look at VLANs with that amount of clients, I'm honestly surprised you're not seeing terrible network performance already, especially with WiFi and the amount of broadcasts there must be! We have around 150 clients on our network, laptops/desktops/phones/servers/CCTV/doors and I VLAN'd everything up about two years ago.
  9. Stick your guest network on a new SSID which is on a new VLAN (which you should be doing anyway!). This will use a new subnet so you can free up addresses on your old one, and give as many as you need to your guest network. If you have managed switches (HP and Cisco do this I know) you can tell them to forward DHCP requests from one VLAN to another so you can just add a new scope in your existing DHCP server.
  10. Is anyone bothering to get iPad 2's fixed nowadays? I've got a couple of iPad 2 and iPad Mini devices at school that have smashed screens (urgh... we had them before we bought Griffin Survivor cases) and am trying to decide wether or not it's actually worth doing
  11. The issues in this thread with SB generally always seem to be about Filter11 or a Fortigate cluster. Perhaps, as a service provider, if a specific set of hardware is causing continual issues then said hardware should be taken out of service? I can understand downtime with broadband like this, or that equipment fails, but 5 measily minutes at home? fine. 5 minutes in a school lesson? Now that's really disruptive.
  12. We've not come across this issue, have you guys used the tools on MX Lookup Tool - Check your DNS MX Records online - MxToolbox to check Blacklists, SPF records etc are all in order?
  13. When did you sign up to Meraki? We're on the 100 device limited free tier (signed up maybe 4 years ago?) and can push apps out silently. They made this so much easier with iOS 10. Basically you need to order enough licenses for the app through Apple's VPP portal, link your VPP account to your Meraki account, refresh it's license count in the Meraki control panel, and then assign apps to devices and tick the 'Use VPP license' box. I could be wrong, but the iOS devices may need to be supervised using Apple Configurator 2 for this to work, I've not tried it without but thats the way we do it for remote worker iPhones and classroom iPads. This should push the apps to the iPads as soon as they're awake and check into Meraki.
  14. Really? We've deployed using AC2 supervision and Meraki MDM for the past few years
  15. "Bridge (pass) a single IP address or a whole public subnet" Vigor 130 ADSL/VDSL Modem I do this in school without the Vigor. Eclipse Internet > Openreach Modem > Sophos UTM. Passes our public IP block through fine.
  16. Just because PuTTY shows a blank screen with a cursor doesn't mean it's made a connection either
  17. Could you unblock it for specific users? (i.e. Media students) This would stop the majority of time wasters.
  18. Sophos UTM works fine in a VM so long as your underlying infrastructure is sound.
  19. Look at a Sophos UTM appliance, VERY competitive pricing and does everything Smoothwall does and more. I feel like I rave about it, but honestly I've never regretted it. They offer appliances, software for your own hardware, or a VM.
  20. tbh, if this wasn't outlined in any contracts, I'd be querying why it has to be an 0844 number when you can get other non-geographical numbers.
  21. We found that quite a few machines were a bit useless on Windows 10 because Intel didn't update various integrated graphics drivers for them, still worth a go but something to watch out for
  22. Well! Working at a non-academy... I think one of the keys really is to keep ongoing costs down and give the budget holders a long term plan. When I can get an Intel NUC + peripherals/monitor for something like £320 each (from what I remember) and expect to get 3/4 years of life if not more, leasing just doesn't make sense. The only on going costs are MS licensing/backup/printers/internet connection in my budget.
  23. I think people need to reiterate the fact that we're in 2016 and IT is a necessity (it's one of the departments that span all others). No matter where you are or what industry you're in IT is going to be one of the biggest budget holders. You see this a lot in primaries, they don't value IT enough to make it worthwhile and do things like OP's school. How can you provide a decent education to the future with 5 year old hardware? Maybe if academies can't afford to keep up to date, they shouldn't have become academies. EDIT: Just to add on, maybe people should look at spreading costs of licensing among the departments? If a year group want a yearly subscription to XYZ, it doesn't come out of IT's budget.
  24. I haven't had any issues with the one I played with briefly a week or so ago. I believe the Edge line runs a fork of Vyatta/VyOS anyway so there should be plenty of community support also. I've been pretty impressed with Ubiquiti in general in our school, using their cameras and APs in production.
  25. Agreed! But yes, you need different licenses for client/servers. On OVS-ES the Client CAL Pack includes CCM licensing, and on the server side there's a similar sort of suite you can buy that includes it too. I believe going that route will mean you're licensed for DPM etc too (but I could be wrong, we don't use it). EDIT: Also you don't need SQL licensing, SCCM includes a license for SQL Server Standard so long as it's only used for SCCM.
×
×
  • Create New...