-
Posts
975 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by seawolf
-
Yes, I do absolutely and it blows the doors off of Smoothwall. We use the iBoss by Phantom. I have found nothing that even comes close to it. It can also provide that secure filtering everywhere the iOS device goes and not by using the hokey reverse proxy method of the Smoothwall. I tried Smoothwall, and after moving to the iBoss 3 years ago, I can't for the life of me figure out why so many people are so loyal to Smoothwall.
-
Oh boy. You don't need an Apple based infrastructure to use iPads or Macs. Even Apple doesn't use an Apple-based backend. You just need systems that aren't designed to operate just like it's 1999. And no, he doesn't need a Mac Mini, but even if that were absolutely necessary a whole $670 bucks, wow. Anyway, that's not what this topic is about so let's drop it.
-
Don't equate the proxying issues that occur with the Smoothwall as the fault of iOS. Smoothwall proxying is not overly good IMO and seems to break many things.
-
What version of Windows are you running for your backend, 2003, 2008, 2008R2, 2012, or 2012R2 - particularly your AD infrastructure? If you aren't on 2012 or 2012R2 you would want to plan an upgrade before diving head first into Windows 8/8.1. Otherwise, you will be frustrated with your limited ability to configure and control the Windows 8/8.1 experience for your users (and your sanity would suffer). The Surface is a great bit of hardware, but expensive as you'll need the Pro version. If you want to stick with Windows 7, then the Samsung Ultrabooks are very nice. So, are several of the Lenovo units. I think Android is a rotten mess from a management standpoint. I would stay away from that except for BYOD where all that's needed is WiFi. iPads are cheaper than the Surface Pro and Ultrabooks (don't know where the comment from another post came from about iPads being the most expensive option). If you can wait to decide until iOS 7.1 has been released and you can test it, then you might find managing the iPads to be a piece of cake with MDM. That's if it ends up doing everything it's supposed to with the new features in 7.1 In fact, my advice would be to test any unit that you are considering buying before making ANY recommendations. Recommending something from the marketing brochures, based on specs, or even word of mouth doesn't amount to a hill of beans if they end up not working as expected in YOUR environment for YOUR purposes. If a supplier won't provide a demo unit for you to test before placing a big order then look to another supplier. Try, then buy.
-
If you do go this route, don't use the built-in Windows iSCSI, use the Starwinds iSCSI stack as every performance test I've read shows it thumps Windows iSCSI. Yes, the GUI in FreeNAS is quite good. Nexenta too. The best GUI and best performance/reliability would come from a Sun ZFS box (hybrid storage), but price might be a limiting factor for you. A second best alternative IMO is a commercially supported TruNAS system from ixsystems, or A BYO SAM-SD system built on HP Proliant hardware if you are so inclined. I'm also keen to get my hands on a Nimble storage unit (hybrid), but they aren't cheap so that will have to wait a while. They look very good though. Like most things, the answer is - it depends. If you have TBs of SMB shares you need to provide then use the SAN directly, if you have 1TB or less required then managing it through a VM file server is easier. Go larger than that though and your Veeam backup or restore times go up dramatically for the VM. All of the ZFS systems I have used can bind to a domain just fine. Yes, we've been here before haven't we. All I can say is that you only choose the risky or lower performance option if cost is the primary deciding factor. And then, you have to choose whether it is performance OR reliability that you are willing to sacrifice to save money. Choose wisely.
-
No worries. The open SSID problem is easily taken care of by simply forgetting the provisioning network once everything is configured. We didn't find it to be a problem as we put this step in our BYOD instructions.
-
Yes, we use both logical and geographical VLANs. We have at least two VLANs per building one for desktops and one for VoIP phones. In buildings with computer labs we have a VLAN per lab as well. We have 13 buildings. The we also have the logical VLANs such as network, server, admin, backup, printer, and multiple WiFi VLANs.
- 12 replies
-
- management
- tagged
-
(and 3 more)
Tagged with:
-
I've tested and used quite a lot monitoring tools over the past 6-7 years. Here are my conclusions: 1. PRTG - this is a fantastic and relatively low-cost monitor with a lot of flexibility, is easy to setup, and customisable. Our current monitor of choice. 2. Splunk - this tool goes way beyond just searching logs now. There are an abundance of apps and configurations that can provide world class security monitoring and threat detection, and provide more insight into your network than you could ever imagine (including your AD infrastructure). Expensive, but the pricing has just (yesterday improved a fair bit). We use Splunk to capture all of the logs from our switches and firewall and will be setting up the AD monitoring soon. Again, expensive, but man is it good. 3. Nagios - a very powerful and nearly infinitely extendable monitoring tool, but it takes a lot of effort to get it all setup to provide the information you need, and once it is setup you need someone to maintain it and make changes to it or it will fall into disrepair. If you go this route, I would recommend getting Nagios XI to ease the pain on this front. It's worth the small cost. 4. OpManager - a very good if somewhat expensive monitoring tool for larger environments. The vSphere monitoring is exceptional and it is possibly the easiest to setup monitor I have used in regards to effort vs. results. This, and integration with other Manage Engine products are its strong points. It's weaknesses are the limited ability to customise or extend OpManager, and lack of integration with 3rd party tools. 5. Op5 - A very nice alternative to Nagios based on the Nagios code base. It used to be fairly expensive, but I think the price has come down. Worth a look. 6. UpTime - It's been many years since I've used it, but this tool was better than all of the "enterprise" monitoring tools from the big vendors, and a fraction of the cost. Easy to setup too. Expensive compared to PRTG or Nagios XI, and even OpManager, but wow was it good! 7. The Dude - a good, free network monitor. 8. Spiceworks - Effective, and if free is a must definitely worth a look. The weaknesses I found were the speed and the fact that it is far more than just a network monitor, and so wasn't as good at the as systems focused on just doing that. We already had a great help desk, and inventory systems so these features were no use to us. The ads also were a downside.
-
It depends on what fit you intend it for. If performance and proven, enterprise reliability are essential, then perhaps not. The biggest market I see Storage Spaces shaking up are the NAS vendors such as Drobo, QNAP, and Synology. As an alternative to these solutions, SS may prove to be a lower cost, more widely supported alternative. SS still does not compare to good Hardware RAID or ZFS in performance and proven reliability. It may work out all fine, but it is risky to trust a still relatively unproven solution for 1st tier storage. It is good enough to start using for 3rd tier and maybe even 2nd tier storage (backups, less important SMB shares). But it would be a good idea to get very familiar with it first hand and find where all of the warts are before using it for 2nd tier. That's probably the only thing SS has on ZFS. But, given the rock solid reliability of Solaris vs. Windows I don't actually see that as a good thing when evaluating a 1st tier storage solution. But, I do understand the attraction for someone with mainly or primarily Windows expertise. I just don't think it's quite "there" yet.
-
Yes, I do - http://forums.servethehome.com/windows-server-hyper-v-virtualization/2470-serer-2012-r2-storage-spaces-tiering.html
-
I wouldn't recommend using Storage Spaces for critical storage in a production environment. As a secondary backup location or non-critical SMB storage pools, or for home / SMB use, sure. Firstly, Microsoft has never done software RAID all that well. Storage Spaces is not ZFS light or ZFS made simple. Secondly, Microsoft don't even recommend it for critical storage in their own technet blog: http://blogs.technet.com/b/askpfeplat/archive/2012/10/10/windows-server-2012-storage-spaces-is-it-for-you-could-be.aspx Use it for testing or non-critical storage, but I think you're gambling to use it elsewhere when there are much more robust solutions easily available (some such as FreeNAS for free).
-
How much do you keep for emergencies/unplanned for events?
seawolf replied to dany2010's topic in General Chat
There's the key guys. Make sure your manager takes a shower every once in a while before discussing budgets with the bosses. It's hard to be convincing when all people can think about is "what died in here". And if he refuses to bathe....the lot of you will just have to hold him down and break out the Brillo pads and pine sol. :-) -
I would create a NETWORK or SWITCH VLAN rather than an INTERNET vlan. You will want your switches, routers, firewalls, APs, and web filters to all to be untagged be on the NETWORK vlan. Your WiFi APs should be untagged on the NETWORK VLAN and tagged on all of the VLANs used for any WLANs (SSIDs).
- 12 replies
-
- 1
-
-
- management
- tagged
-
(and 3 more)
Tagged with:
-
How much do you keep for emergencies/unplanned for events?
seawolf replied to dany2010's topic in General Chat
And 25k is your normal annual budget? I don't know how you keep everything going on that. -
How much do you keep for emergencies/unplanned for events?
seawolf replied to dany2010's topic in General Chat
How big of a school? 25k seems like a small budget unless it is a small primary school. I normally wouldn't set aside more than 5% of the total budget towards emergencies. Your emergency fund is exceeding 10%, which is probably justified with such a low overall budget. -
Neither the tablet NOR the laptop will do any good if the school does not have (1) a well thought out strategy of integrating them into the curriculum (2) well defined student outcomes to aim for, and (3) teachers who are capable of and committed to accomplishing these two things. iPads are capable of providing excellent educational outcomes and are better in some things than a laptop, and worse in some things than a laptop. But, like any tool it must be fit for the task at hand. It does no good to try to use a hammer to fix a pipe if a spanner is required, or to use a spanner to try to hammer a 10-inch nail into a post.
-
Brand new Active Directory - From scratch
seawolf replied to karlr's topic in Windows Server 2008 R2
...and the pot calls the kettle black. I guess you just bring out the abrasive in me SYNACK. -
This might be helpful to you then - http://theruckusroom.typepad.com/files/byod-with-ruckus-0712-3.pdf
-
Brand new Active Directory - From scratch
seawolf replied to karlr's topic in Windows Server 2008 R2
I thought I was quite specific with my generalisations. And they are hardly unfounded as they are based on empirical evidence from my environment, which having a Windows Server 2008R2 backed should favour a Windows client over anything else. We do, the PCs are equivalent in spec to the Macs, and the PCs do login relatively quickly. Just not as quickly as the Macs, both for a user that had never logged on before as well as for a pre-existing user account. However, if we had a .local domain, the PCs would win that battle by a country mile (again based on actual empirical evidence). My IT axe was forged in the hell-like fires of 20 years experience in the defence, manufacturing, retail, finance, and education industries. It should last for quite a while. -
Brand new Active Directory - From scratch
seawolf replied to karlr's topic in Windows Server 2008 R2
Then, please provide the specifics of those solutions. If they are good ones then you will find support here. I for one, would tell someone with a .local domain to fix their domain first before integrating Macs. Most Windows sysadmins don't have the experience to do the workarounds required to make them work tolerably and usually have a bias against Macs in the first place. If you set Macs up to fail with a .local domain at the start, those sysadmins will use every problem as an example of how Macs won't work on a Windows domain. Several schools have told me that Macs can't be integrated successfully into a Windows network, and it's always because of experiences with Macs on a .local, combined with inexperience with Macs. -
Brand new Active Directory - From scratch
seawolf replied to karlr's topic in Windows Server 2008 R2
My bad, I took your statement below to mean that it took you a while to work out all of the changes that were required to your DCs and Mac clients to make them work properly in a .local domain. I call changes to standard functionality or workarounds to make something work "hacks". Let me be candid here. I don't know what the point of your original post was for. To prove that it is possible to use a .local domain? Sure it can be done, but let's not encourage anyone to do it because they WILL run into problems and it will never work optimally, in fact it handicaps the Mac right from the start. Let's encourage people to not use .local domains and to know beforehand that they will have problems at some point if they use a .local domain. That is the advice I will always give anyone who asks and it is backed up by fact and experience. Let's not encourage people to go down a road they shouldn't walk. -
Brand new Active Directory - From scratch
seawolf replied to karlr's topic in Windows Server 2008 R2
Your Macs should login faster than your Windows PCs if everything is working properly. Ours login in half the time the PCs do on a Windows network (it is not a .local domain however). And, you have confirmed that you have had to "hack" your DCs and Mac images to make it work. How does that show that using a .local domain with Macs is a good idea? You wouldn't have needed to do any of that if you had something other than a .local domain. And, what about the next OSX update or Windows server update that breaks your hacks? Yes, you can certainly get Macs to work on a .local domain, but they will never run as well as they could and you will always run into issues down the road. It's like running a race while carrying a 20K pack on your back. You'll get there eventually, but you sure are making it hard on yourself. -
Brand new Active Directory - From scratch
seawolf replied to karlr's topic in Windows Server 2008 R2
No, these problems do occur due to issues with DNS and a .local domain. Slow mounts are NOT due to mounting AD folders and indexing on the fly. It's fantastic that you seem to have no issues with these things; although, I suspect you maybe just don't realise that you do have problems because a .local domain may all you've ever known in regards to Macs. If so, then what I would liken it to is a man who was the fastest runner in his hometown and thought perhaps he was as fast as anyone, until he saw Usain Bolt run the 100m and then he realised that he was actually much, much, much slower than a real sprinter. With your .local domain, you are probably running a 14 second 100m and thinking it's pretty good when you could be running a 10 flat. I'll quote AntonioRocco in his recent explanation of .local domains and how and why they cause problems: -
You can do the same with Ruckus. It's stories like this that make me think some people have misconfigured networks and they would have the same problems with ANY system....
-
[ipad] what ipad air charging / trolleys are you using?
seawolf replied to RabbieBurns's topic in Mobile Devices & Tablets
Yep, looks like they are branded as Lock n' Charge overseas http://www.lockncharge.com/uk/where-to-buy/
