Blue_Cookeh
Members-
Posts
1,485 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Blue_Cookeh
-
Classic Shell no longer in development. Source code released
Blue_Cookeh replied to Arthur's topic in Windows 10
Are people really still clinging to this old style? The start menu isn't coming back! -
You're completely ignoring how cloud environments work in reality. Virtual servers in all cloud environments ARE NOT open to the Internet by default. Google, Microsoft, and Amazon put network security rules in front of them. You have to actively go and make a bad decision to make a change (as you would on site) to open your services up to the Internet. If you've opened your SIMS SQL database up to the Internet you can't blame the cloud for that, you only have your poor sysadmin skills to blame, just as you would on site. Of course, I'd hope if you were putting your SIMS SQL DB into something like Azure you would be using site to site VPNs.
-
If your coverage was mapped out, the likelihood is you'll get good enough coverage so long as you pick an access point that meets your requirements. Considering you're looking at Ruckus again your budget could easily stretch to Ubiquiti UAP AC Pro access points. You'd be doing your budget a massive favour.
-
If you're in a position where that's a possibility you haven't thought about your cloud design enough - Azure and Google Cloud (and I assume AWS) have very restrictive network security groups by default. If you prefer you can make them private only and force them to go through a cloud-based firewall. There are plenty of vendors (like Palo Alto, Sophos, Cisco) that provide templates for firewalls on Azure for instance. Our NHS org is lifting and shifting as much of our stuff out of our datacenters and into Azure as possible as of about 6 months ago. We're only allowed to purchase datacenter hardware in very specific circumstances now, anything new should be "cloud first" (Azure in our case).
-
Agreed. Going serverless doesn't mean there's no job, it means the job has changed. "Serverless" means your servers are in the cloud, either running typical services like AD, or moving to container/cloud based solutions using something like Kubernetes or services like Azure AD Premium. I'm working towards a serverless school too - all users are now on OneDrive redirection, mail in Office365, now looking at moving shared drives into SharePoint. The next step will be looking at whether or not to ditch AD for Azure AD, or ship it into Windows Servers hosted in Azure. There's most definitely a job still there.
-
1. Move your DNS over to Cloudflare 2. point it at eSchools 3. turn on Cloudflare's auto SSL functionality 4. ???? 5. PROFIT! (... or 0 cost, anyway)
-
I'd let stuff die or shut down to reinforce the point before spending my own money
-
DDOS Protection / Mitigation Software
Blue_Cookeh replied to edie209's topic in Internet Related/Filtering/Firewall
DDoS services are so cheap nowadays anyone can buy enough capacity to take out a school's internet connection. No amount of software will help with that, you need to stop the problem either politically (catching whoever is organising it) or by working with your upstream provider (i.e. BT) who can blackhole the traffic or put you through a traffic scrubbing device like those Arbor make before that traffic ever hits your connection. BT ought to do it, I can understand why they want you to pay $$$ (DDoS mitigation is *expensive*), next time I would make it a requirement on your RFQ when you look at changing suppliers. -
Someone fancied a brand new network? (Fire at West Sussex school)
Blue_Cookeh replied to Andrew_C's topic in General Chat
Now I'm just getting jealous... -
Teachers access to OneDrive at Home
Blue_Cookeh replied to MrWrighty's topic in Data Protection & Information Handling
You can use Azure conditional access to stop that. https://core.co.uk/blog/restricting-access-office-365/ -
Also it lacks very basic features like iCloud lock bypass (unless it's changed a lot recently)
-
[windows software] Moving an OVS-ES agreement to another supplier
Blue_Cookeh replied to jslate1980's topic in Licensing Questions
Absolute rubbish - you can move your agreement at any time. Talk to your new supplier only and cut off all contact with the old one if you so wish. -
Get off my lawn! You kids with your pesky Ethernet, back in my day we had token ring and we damn well liked it!
-
I realise I'm probably harping on a bit but it seems that we're talking about a cab uplink. For the cost of a couple of SFPs (15 quid a pop) and the fibre (the same as cat6a) it seems silly not to future proof yourself. On a four core fibre run you're getting at least x2 runs out of that cable rather than the x1 the same length of cat6a would provide with fewer options for future proofing. Cab uplinks don't need to carry PoE and never in my life have I had to clean ST or LC connectors that have sat in switches for 5+ years. Again, it's a permanent cab uplink, there should be minimal chance of breaking the fibre.
-
Once the fibre has been installed you'll find you'll have far more flexibility into the future, particularly as you'd usually pull 4-12 cores at a time. Schools aren't likely to hit it, but OM3 over 100m can potentially give you up to 100Gbps uplink iirc (or at least 40)
-
VeryPc - Hardware supplier recommendation
Blue_Cookeh replied to MrGAWilson's topic in Recommended Suppliers
Realise I forgot to mention service and thought they definitely deserved the praise. Colin is always crazy quick and helpful with our day to day stuff, Ross was brilliant with our A/V stuff last year, and John managed to figure out the mess that is Microsoft licensing for us a month or two back - all top notch people over there -
VeryPc - Hardware supplier recommendation
Blue_Cookeh replied to MrGAWilson's topic in Recommended Suppliers
Maaaaate we all know you'll end up spending it on an eventful night out -
https://www.fs.com/products/39041.html @caffrey customise it to 50m, LSZH jacket, 2.0m breakout leg (so you don't need a fibre patch panel) with the connectors you need on both ends - roughly 50 quid.
-
Cab to cab is always fibre for me. Ideally 8 cores to our L3 cab, and another 8 to one of our other access cabs for redundancy since you can buy 16 port fibre patch panels. You never know what the uplink requirements are going to be and it's a lot easier to pull a cable once than it is a second time in 10 to 15 years' time. Some OM3 fibre will last a lot longer than Cat5e or even Cat6a (assuming the run is <100m). This gives me an easy way to connect everything back to our L3 switches, even if a cab ends up with multiple routers/switches in, so daisy chaining is limited.
-
I'd argue the value for money out of UniFi is far greater than anything Ruckus can provide nowadays so I'd agree with them DNS filtering on a "clean" Internet connection sounds ideal. @mikkydoos they need a VLAN, the Guest network shouldn't ever be able to talk to your internal network.
-
This is always a problem on BYOD/Guest networks that require SSL interception. If you havent got big bucks to spend on something like Aruba or Ruckus' onboarding systems then you're pretty much stuck with offering the users the ability to install the certificate on the captive portal page. IMO your best option is to look into a method of providing Guest WiFi that does not have SSL inspection, removing the need for a certificate. We have a secondary FTTC connection coming into our school for this purpose and only do content filtering based on URL. Just an FYI - if you're in a school that uses laptops etc make sure you deny access to the Guest network on those devices somehow. There's a group policy setting to block devices from connecting to specific SSIDs.
-
Moving from Meraki (free) to MS Intune (via EES). Works out dirt cheap since it's done on staff count rather than device and they both have similar featuresets. Arguably Intune handles certificates/users/802.1x better.
