Jump to content

seawolf

Members
  • Posts

    975
  • Joined

  • Last visited

Everything posted by seawolf

  1. Choose your poison I suppose. I've never seen any issues here with any applications when IPV6 is disabled.
  2. Disabling IPV6 is just a tick box in the adaptor properties. How would a BIOS update be less thorny. Seems much more risky and time consuming to me?
  3. Argh! Adobe Flash is COMPLETELY worthless. I await the day I can dance on Flash Player's grave with glee.
  4. Interesting findings with Optiplex 9020s. Have you considered just disabling IPV6 on the adapter in Windows. We do this as part of our standard image, if you aren't using IPV6 there's no reason to have any IPV6 traffic on your network that aren't necessary.
  5. Can't comment on the overpriced RBC connections in the UK. However, SSL works just fine with a properly configured transparent inline bridge/proxy (no certificate errors). Forced upstream isn't really a "transparent" proxy, it's just an automatic proxy, thus the problems with SSL.
  6. We use a Transparent Inline Bridge configuration for our web filter, which means that it sits in between the core network switch/router (LAN) and the firewall. So, all traffic HAS to flow through the filter to get from the LAN to the WAN and vice versa. This is a bit different than what some have called a transparent proxy in the past, which was really more of an automatic proxy mode rather than being an inline proxy, because traffic is intercepted and redirected (causing problems with SSL) with that method. NAC systems don't act as proxies, they control access onto your network. My comment was more regarding the issue I sometimes see where network managers see explicit proxies as a way to restrict access to the network (or WAN access at least) and that is why they won't look at the transparent inline bridge/proxy option. However, that's not what a proxy is for and using proper NAC such as NPS or packetfence are the proper ways to achieve access control to your network.
  7. seawolf

    lacp on mac mini

    Yes, but whether it would make sense depends on what you're using the Mac Mini for. If it's as NetBoot/imaging server (DeployStudio, Casper) or a file server it might improve performance as long as the disk(s) were fast enough to use the extra bandwidth (fusion or SSD).
  8. seawolf

    lacp on mac mini

    Feasible, but I've never tried it, and I wouldn't recommend it. You'll get better throughput form the single 1Gb NIC.
  9. A bit off topic, but I have to ask. Why are so many of you still using an explicit proxy setup rather than a transparent proxy? Using an explicit proxy is an enormous headache, some systems don't play well with it or at all, and as many of you are finding PAC deployment is not very simple or reliable in a BYOD or heterogenous device environment. On the other hand, a transparent proxy eliminates all of those headaches and still ensures that all traffic flows through the correct path (the filter). If you are using an explicit proxy as a form of network security to prevent unauthorised clients form joining, there are better ways to do it including MAC filtering, NPS, Packetfence, or other NAC systems. Anyway, off-topic post finished.
  10. What version of the Ruckus firmware are you currently using and what model of ZD and APs do you have? The ZeroIT works excellently on both iPads and Macs. Ruckus has one of the more robust BYOD setups I've used. Everything is likely going to be inconsistent on Android devices if you are using a wide mix of hardware and OS versions...that's what we've found.
  11. I've used Linux from the early days when there were only Debian, Redhat, and Slackware and their early derivatives. Mandrake was my favourite distro back in the late 90s for ease of use. For the past 5 years though, I've pretty much stuck to Ubuntu, which I think is the best all around mainstream distro that's come down the pipe. I've toyed with other distros, but I keep coming back to Ubuntu and Ubuntu or Debian are all that I use for my servers (minimal VM with no GUI that is) with the exception of one SUSE server that I didn't have much choice about.
  12. True, so true. Better to say no than to be saddled with frequent calls from an unsatisfied customer who won't spend what's necessary to do the job right. Let it be someone else's problem...
  13. In that case, the best solution would be to use a secondary WAN connection (ADSL, Fibre, Cable) for the guest WiFi with its own router and AP (and subnet) so that it is totally isolated from the business network. This also simplifies many things and allows the owner to keep track of the bandwidth/download consumption over the guest WAN link.
  14. What additional "layer of protection" does your customer expect to be achieved by connecting WiFi APs (I assume that is what is meant)?
  15. OK, fair enough I can go with that.
  16. You mean kind of like a blackberry trying to be a smartphone?
  17. What, you want me to call it a CMS or something? It's a blogging platform that tries it's best to be a CMS - but it ain't. That's not what it was designed to be. It was designed for blogging.
  18. If you're going to do something so radical, why not consider using Sharepoint as a VLE instead (http://blogs.msdn.com/b/ukhe/archive/2008/10/02/using-sharepoint-as-a-vle.aspx)? At least you'll have something that is scalable, flexible, and widely supported, and that will integrate with Office natively. Using a blogging platform as a VLE - whew. Hey if it's blue sky thinking for VLEs, maybe even Confluence or DocuWiki should get a look. Or, if you wants something familiar and intuitive maybe Edmodo.
  19. Multiple VLANs, IGMP turned on for the VLANs where we do multicasting.
  20. Unless you are actually using IPv6, I would recommend disabling it in the clients. We do.
  21. We had a single faulty NIC on a desktop that began flooding the network with broadcast traffic. It would cause the switch it was connected with to become completely non-responsive and then the traffic would slowly begin cascading across the network. We identified it with PRTG and the top 10 bandwidth report. Fixed the faulty NIC and solved the problem. Maybe you have a bad batch of NICs (low probability) or mismatched drivers and OS, or an incompatibility with the motherboard, NIC, OS combination.
  22. Welcome to the club!
  23. Wide Area Bonjour is usually implemented with unicast DNS Service Discovery (DNS-SD). It means you aren't routing multicast traffic across subnets (which defeats the purpose). http://www.grouplogic.com/Knowledge/PDFUpload/Info/WanBonjour_1.pdf http://www.dns-sd.org/ It's a pain in the rear to setup initially, but very reliable. We are only using it for AirPrint currently. The ability to rebroadcast AirPlay from one subnet to another with the Ruckus bonjour gateway is interesting though. I assume it is using some sort of bonjour proxy to accomplish this. Have you analysed your network traffic to see what the effect is on the VLANs you rebroadcast the traffic on, and the load on the ZD Or APs themselves? I just wonder if it puts strain on them or floods the VLAN with multicast traffic.
  24. Has anyone compared the bonjour gateway in the 9.7 release to a wide area bonjour setup? We set up wide area bonjour (non-multicast) and it has been very reliable. The initial setup was a bit of a dog, but since it's done I don't know the bonjour gateway would give us anything. Might be less effective?
  25. Is there something in the 9.7 released that you really want or any bug fixes in it that you need? If so, then backup, try it after hours first and if it breaks roll it back. I took a pass on this current release as there were some problems that resulted on the first build being pulled and issues with upgrading the Zone Director in some cases. I'm going to sit it out for a while before upgrading. Other schools here seem to be doing the same. If it works, don't break it.
×
×
  • Create New...