Jump to content

sramdeen

Members
  • Posts

    15
  • Joined

  • Last visited

Reputation

20 Excellent

About sramdeen

Personal Information

  • Location
    London
  1. Afternoon, We have an opening available for a mobile IT tech, with a focus on Apple and Google technology, to cover schools based predominantly in north London, Harrow and the middle of the city. Travel across the London area may be required as the makeup of our customer base changes over time. The post is up on LinkedIn, please message me with any queries. https://www.linkedin.com/jobs/view/3627273525 Thanks Stuart **APPROVED**
  2. Found this thread via a search. I support quite a few schools using parentmail and there's a common theme across the board - they are all extremely frustrated with the support experience. The latest episode in October where parentmail devs pushed out a fix for one thing but then broke something related to parent email addresses (a pretty fundamental thing for the product!!!) has been the last straw. Most schools are now asking me for advice on an alternative product. Searching on here I have found SchoolComms, which seems to be the one that pops up when this question is asked. Interestingly, the strategy on the SchoolComms website seems to indicate that they aware of exactly how much pain schools are going through with ParentMail: "Switch to first class support" and they claim that switching to SchoolComms midway through a contract with another supplier will result in no fees payable to SchoolComms until the existing contract expires. Quite the offer if true! Before I start telling schools to investigate SchoolComms for themselves, I just thought I'd ask if anyone has managed to achieve a resolution with PM support or even get hold of anyone via the phone, preferably in the UK. These schools in question are using SIMS. I'm no MIS expert but I do find it incredible that SIMS doesn't appear to have this functionality built in. My Arbor using schools are very happy with the built-in comms system. Thanks
  3. Sorry for the late reply, I've just seen this notification. After a few months of being immersed in Aruba stuff I must say that things are going very well. Unfortunately the AP-3xx series was discontinued and this was their 802.11ac wave 2 stuff that we were putting into small primary schools as we felt it would fit their needs for many years, especially if their broadband was no faster than around 200Mbps. We've done a few AP-5xx installs (802.11ax) and have a load more lined up for this summer. So far so good, it seems to 'just work'. We did have major stability issues with our first AP-515 network in a large 1:1 deployment primary school, but it turned out to be the case that the newer Aruba Instant firmware is buggy (8.8 and a certain build of 8.7). Throughput would simply grind to a halt on devices even though they would show strong signal, no interference, etc, etc. Nothing in the Aruba logs indicated that there were any issues. Other members of the Aruba Airheads forum are now starting to complain of the same symptom with this firmware. Downgrading to the generally available stable build of 8.6.something resolved all issues and it's been rock solid for months. I will certainly approach firmware upgrades with more caution going forward as it seems that no company is immune from introducing big bugs! For anything other than large schools with 1:1 deployments we've found that the 'entry level' AP-505 does a brilliant job and if you have a good relationship with an Arbuba partner (we are now one ) then you should be able to obtain these for a discount over what a regular box shifter like Insight (£289 I think) or Misco (£similar) sells them for. There are educational discounts to be had, Aruba have been very good to our customers in this regard. Hope that's of some help. I'm still learning new stuff almost daily and there is certainly lots to take in. If you want a simple network then the wizard will do a good job to give you a baseline from which you can further tweak to your requirements.
  4. We have this at a couple of our schools. Out of our dozen or so schools that use Unifi, we appear to have been lucky with the issue affecting only two sites. The latest site to be bitten by this had 10 new nanoHDs installed two Mondays ago and the following day was plagued with DHCP timeout issues and complaints from staff. What a great way to start with a brand new wifi system that was put in to resolve issues with the school's Meraki setup that not even Meraki support (third line) could resolve... The first thing I did was move off of the latest general release firmware and on to the latest beta that is supposed to address the issue (we've heard that before). It was better but certainly not fixed. Monday just gone we saw 1515 DHCP timeout errors on the wifi metrics page. This was better than the previous Friday but still very problematic and causing actual issues for the teachers and pupils. Exasperated and fed up of reading about the problem on the UI forum I bit the bullet and downgraded to 4.3.20, as suggested by many people. A couple of days in I've just checked in with the school and they said that things are much better although there were still connectivity issues in one class which required the teacher to yank out the Ethernet cable and reboot the unit. This immediately got things up and running for them. Looking at the controller as of now the current 'today' period of timeouts is sitting at 111. DHCP server is a 2012 box, nothing fancy, no VLANs, etc just a regular primary school flat network. Unifi settings were all factory fresh with nothing tweaked outside of the default. Since installing and trying to troubleshoot, 'AI' has been disabled. We've had enough. Just these two clients have been enough to give me a few new grey hairs. With something as critical as wifi I don't think we can afford to try and go down the cheap route anymore. I've already ordered some Aruba APs to evaluate. I don't think we'll ever put in another Unifi AP again. I'm also now on the fence about the Edgerouter and Airmax devices, given that we use those at quite a few sites. I must say that they have been relatively stable (especially the edgerouters), but I dread to think what support we would have received had we had issues with them. If it's anything like the support people are getting with the DHCP timeout bug then I suspect the units would be in the bin fairly quickly. It's a real shame, as they used to make stable equipment that was clearly heads and shoulders above stuff like Netgear (average) and DLink (truly hideous, I still have nightmares). For most schools it was an excellent choice and avoided them having to pay for Meru, Aerohive, Ruckus, etc (I'm going back a good few years here). Aruba pricing seems to have come down dramatically over the last couple of years and so I hope that we can now standardise on their kit. We've been installing nothing but Procurve switches for the last 15 years, so fingers crossed HPE/Aruba wifi is just as good.
  5. Just touching on email still: Has anyone managed to get Atomwide to allow IMAP? On the example sheet of the MIPs request form it gives email as an example service, indicating that they will unblock the necessary ports if requested. However, one of my customers has just sent this to me in despair: teacher: support desk: What an upgrade!
  6. The Security Guidance document located at http://files.lgfl.net/LGfL/Policies/LGfL%20Security%20Guidance%20April%202012%20v1%201.pdf makes no clear mention of blocking outbound ports. The only section regarding port blocking is: IMO any sysadmin reading this would interpret it to mean incoming connections not outbound. So with the Mac version of the CentraStage client still in beta, LGfL has left schools with Macs out in the cold. If they want to use a supported, sanctioned method of remote access Mac users are currently out of luck. If a school has Macs and they need their support company to gain remote access to troubleshoot a problem, what are they mean to do? Luckily there are workarounds available until a permanent solution is found... With all of this heavy handed security, one question comes to mind - Just what was wrong with the LGfL1 security policy? How many security breaches were there on the old system and how many children were harmed as a result? Seems to me this new policy involves a lot of stick and no carrot. Normal end users are going to be frustrated when things don't work and network admins are going to find ways around the security measures put in place supposedly to protect the network. I for one know this is already happening at a couple of lgfl2-connected secondary schools, so the whole security policy goes out the window. grump grump grump
  7. ahhhh, I love consistency. After getting some ports unblocked at one of my schools and thinking things were getting better, a request for exactly the same ports at another school came back this morning: So if I interpret that correctly they are now saying that there is NO email access from email clients such as Outlook, Mail, Thunderbird etc and that everyone has to use webmail. I'm just off to a corner to simultaneously cry and laugh.
  8. What annoys me is that this policy wasn't mentioned to schools in the technical literature that went out before the schools signed the contract. I'm sure most people would have presumed the firewalling policies would have been the same or very similar to Synetrix's. They do seem to be unblocking ports as requested but are reluctant to do so when the destination is listed as 'any' rather than to a specific IP address. In most cases limiting access to a range of addresses just isn't viable. Most large scale stuff is delivered via content delivery networks that are forever adding servers in different geographic locations as and when the load changes. For example, It's all well and good to unblock all of 17.0.0.0/8 (Apple) but when Apple use Akamai's CDN then what do you do? Same goes for many offsite backup providers. Host names are often round robin'd and are subject to change. I hope they relax this policy as it's causing some pain at the mo. Soulfish, do you happen to know or have in writing what their 'security guidance' is? Otherwise it's fairly ambiguous.
  9. And now for something positive I thought it might be useful to list a few common OUTBOUND ports that most schools rely on. Perhaps others could contribute to this list? The format is source, destination, protocol, description: [table=width: 500, class: grid] [tr] [td]Source IP(s)[/td] [td]Destination IP(s)[/td] [td]Port(s)[/td] [td]Protocol (TCP/UDP/Both)[/td] [td]Description[/td] [/tr] [tr] [td]Any[/td] [td]Any[/td] [td] 2195, 2196, 5223[/td] [td]TCP[/td] [td]Apple Push Notification (iMessage, app updates, app notifications, etc)[/td] [/tr] [tr] [td]Any[/td] [td]Any[/td] [td]25, 110, 143, 587, 993[/td] [td]TCP[/td] [td]Email access via email client e.g Outlook, Apple Mail, Android, iPhone etc[/td] [/tr] [tr] [td][/td] [td][/td] [td][/td] [td][/td] [td][/td] [/tr] [/table] Other things to think about: Offsite backup, other apps that don't use ports 80 or 443 such as video conferencing, databases etc.
  10. A quick update: School A: Waited three weeks after the system was supposedly 'live' to get a functional connection. I'm not talking about filtering or firewalling, I'm talking about any form of connection to the Internet. I lost count of the number of times I called Atomwide, and the number of promised call-backs that never materialised. I was completely ignored by the contact at Virgin Media. Two changes were required to the configuration of the Virgin router. I raised the ticket requesting the first of these on 29th March. It took over 3 weeks to carry out. I have no idea why it should have taken so long. School 'A' now has a working connection but are now starting the fun process of getting their email and other services unblocked. School B: Connection was installed 11 April. Onsite head of IT logged a call a few days later over the Easter break regarding services that no longer worked. The school rely on: Filemaker, email (IMAP & SMTP) and an offsite backup service (CrashPlan). The helpdesk keep coming back saying that the changes have been made but they haven't. The ports are still well and truly blocked. This is all outbound not inbound. The school's nominated contact asked the person on the support desk if she could pass the phone over to me and that she was giving me authorisation to talk to them about the problems. They refused so instead we put the phone on speakerphone, I told the head of IT what to ask them and she relayed it to the helpdesk. They could obviously hear what I was originally saying. It's absolutely insane.
  11. Sorry, this was me having a rant but is nothing to do with the lgfl2 content of this thread so I shouldn't have posted it. It's been one of those days! FYI from this particular site (nothing to do with lgfl), all recursive dns requests from clients are blocked, submission/587 - No chance, IMAP won't work due to DNS being blocked and IMAP closed off at the firewall in any case. The requested port was for some offsite backup software to obtain a license from a central server. Anyway, apologies for the slight thread hijack. Back on track!
  12. I'm at a school today that's recently switched over (tunnelling through their connection in order to access stuff that I need to!!). The IT office has been inundated with staff and students coming in to complain that they can't access websites or their email or other online services. Sorry, edited for clarity, the following, unlike the above, is nothing to do with lgfl2, just a general rant about poorly managed IT :-) I've been dealing with muppets all day and am fed up with it. I spoke to one central IT department that looks after IT for a group of 50 schools and they are refusing to open a port OUTBOUND on one school's firewall because they insist everything has to go through their ntlm-only poxy proxy server. They don't even have a route to the Internet, DNS requests from clients are blocked and the only service their users (inc staff) can access is filtered http and https. It's the BOFH's dream.
  13. Yes, simple things like that should be fine from what I read in the documentation.
  14. Just found this thread. I am currently assisting a few dozen schools in London with the switchover and so far it has been nothing but trouble. We have a few schools that run their own filtering and firewalling (option 2 with Synetrix) and they are basically up #### creak. Nowhere in the technical documentation that the schools received does it state that they will not be able to continue this type of service on the new network. It was only after an extensive phone conversation with someone at LGfL headquarters that it came to light that there is no 'connection only' option nor is there the ability to have a clean feed even to one IP address or username. ALL traffic will go through the Internet Watch Foundation's filters, which on the face of it seems like a good idea but we all know that no filtering is 100% effective. Atomwide will then apply their own four categories on top of this filtering to limit access even further. It is an absolute joke that out of the box the standard LGfL 'Internet connection' (can it really be called this if all it allows access to is filtered web?) doesn't even allow email access. Last time I checked that was a pretty crucial part of the Internet. Also seems a bit fishy that the remote support system that is used by the SIMS helpdesk (A Capita company) is banned for 'security reasons'. Who owns Synetrix? Oh yes, that'll be Capita as well. I was annoyed when Capita/Synetrix implemented a blanket port 25 block across the whole of the LGfL but Atomwide's policies are on another level entirely. If you are not happy please make your feelings known. One of my schools simply phoned up Synetrix and asked if they could continue the service with them and they were only too happy to oblige. They halved their bill from 27k to 12k for a three year 100Mbit connection. If the Atomwide network was actually secure that would be one thing but I've demonstrated to others that I can access absolutely anything I want (pornography, AIM, FaceBook etc) through their connection using one freely available tool. Once kids know this it will be an endless game of cat and mouse as LGfL play catch up and blocks even more of the 'Internet'. My last point in this rant (I'll stop soon, I promise) is that some of the Virgin engineers that are installing the kit are clearly totally incompetent. I have pictures of installs that would make you cringe. Routers hanging out of the front of cabinets, doors that if shut would crush the MTRJ fibre connector to pieces etc etc. This is kit that's been installed into cabinets that were on LGfL's 'approved list'. Don't even get me started on why a primary school of 200 users needs a 2U £7k+ cisco firewall.... All of this enterprise grade equipment is not free, you and I are paying for it somewhere down the line...
×
×
  • Create New...