-
Posts
975 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by seawolf
-
Here's my suggestion since you are using 10.7-10.9 clients. Either use OD fully for managing the users and Home Directories as AntonioRocco suggested, or eliminate OD from the equation and use AD and NAS / iSCSI storage for home directories along with profiles on the Mac Server for managing the Macs. For a small number of users, you could spend $2,00-2,500 for a decent FreeNAS server that can provide AFP and SMB shares with AD integration (and 8-12TB storage), or you could buy something like the Drobo B800i connected via iSCSI to your Windows server to provide storage for your user home directories (you can do the same with FreeNAS as well, it also supports iSCSI). Basically Apple has left the SMB/enterprise server market, but has tried to make it easier to just use Windows (or Linux) servers on the back end. You can still use a Mac mini server and the Server app for a SOHO or small business network, but otherwise you should probably only look at using the Mac server for profile manager, netinstall, and caching server.
-
@rich_tech I don't think Canonical intends for every Ubuntu phone to dual-boot to Android. The OS is still under development and the dual-boot option allows developers or beta testers to install the OS on an Android phone without wiping Android (and likely upsetting some people). Ubuntu phone will not have the app ecosystem initially of iOS or Android, but I'd say Canonical are going to be working to get some of the big apps developed for the platform. As for Ubuntu desktop, you don't need to dual-boot to access Windows apps. This can be done using Virtual box or WINE. I doubt iTunes will ever be ported to Linux, and in fact the future of iTunes is likely to be a client-less or browser-based app/cloud service. Also, I don't think Canonical wants to have the market penetration of Windows. They likely wouldn't mind having the Macs market share, but if you go much over 20% market share you have to start catering for and pandering to every feature request under the sun from users. That's why I hate some of the recent changes to iOS - they are purely consumer driven while some of the long-sought after features by us tech heads are ignored. I do hope that Ubuntu improves support for the more popular apps and continues or improve the platform but I also hope that it never becomes a dumbed down OS designed to cater to billions (unless that can be easily turned off).
-
I'm not a big fan of these sort of compromise devices. If I were to get something like this I would go for a Surface 2 Pro. I don't really like the current versions of Android on a phone. I think they are a bit too complicated and unintuitive on a device that you just want to work quickly and to be dead simple for making calls and messaging (that's the main function of a phone after all). There are obviously a lot of people who feel differently based on sales figures for Android phones, but each to their own. I think Android works better on a tablet and if I couldn't have an iPad I would probably get a Nexus 7 to take the place of my iPad Mini. The Nexus 7 is a solid device, but since a Mini does exist I would choose it every time over the Nexus.
-
I don't know, a high quality Ubuntu-based phone and/or tablet are about the only things that would make me forgo the iPhone and iPad. I've been given Android tablets to trial in the past and was vastly underwhelmed. I recently won a Surface RT and while it has a few nice features (keyboard mainly) and great build quality, the constant and obtrusive updates made me feel like I was still in the 90s (really, MS, I can't read a news article until I update the App? No choice in the matter...sheesh).Then, there was the Blackberry tablet that was the worst tablet ever built. No email, really? And, for the life of me I couldn't even figure out how to use the blasted things. Did anyone actually try one before they put them up for sale? The iPad on the other hand (Air especially) - nothing like it for great quality and user experience. And nothing will match it or beat it for me until a fantastic Ubuntu tablet arrives. I can't wait to see them, hope the hardware companies do the OS justice.
-
Not being an expert in HyperV I can only tell you what I would do if it were vSphere. 1. First, I would configure the existing servers to both use the new SAN in a cluster 2. Then I would migrate the VMs to use the SAN. 3. Taking backups at this point of the VMs as well as the HyperV servers just in case would be next. 4. Now, remove one of the servers from the cluster after moving all of its VMs to the other server 5. Install 2012R2 on the server you've removed from the cluster and configure HyperV. 6. Next, join the new HyperV server to the cluster (I'm assuming this can be done, it should), and test that the VMs work fine on it (upgrade templates if needed). 7. Move all of the VMs to the new 2012 server and then remove the 2008 server from the cluster 8. Install 2012R2 on the second server and configure HyperV. 9. Join the second server to the cluster and test. 10. Configure failover, load balancing, etc. 11. Backup everything again after you've finished the config. My opinion is that it's a bad idea to just blow away two VM hosts if not necessary and it also means extensive downtime, especially of there are problems. The method above means little or no downtime and very little risk.
-
Well, can't help with the Windows DHCP issue if that's what's causing it. I've always used a Linux dhcp3 server. Far more flexible, reliable, and powerful in my opinion. Plus, the whole server is only 8GB in size so can be vmotioned in a flash, or restored from backup in minutes if it all goes pear shaped.
-
I don't understand why you've set up a second DHCP server just to hand out IP addresses on a new VLAN? You should only need (and only should have) one DHCP server on a network. The DHCP server can hand out IP addresses as required for any VLAN, we have 35 VLANs here and only one DHCP server. We also have 6 SSIDs all using a different VLAN and VLAN-based filtering for devices like Chromebooks and iPads. We can easily correlate an IP address to the device name from the DCHP lease records if needed. I would generally recommend a similar setup for most people in filtering these devices rather than static IPs, etc.
-
Was the MacBook on 10.8 and now it's on 10.9? If so, that's not an update, that's an upgrade and not one that's recommended for a commercial environment. Much like any other OS, I generally wouldn't advice using the dot zero release of anything except maybe in your own home or in testing. One other thing I'm confused about - what are you using to AirPlay on Windows (e.g. AirParrot) and is the Windows image on the same laptop? Also are you AirPlay-ing to AppleTV or AirServer, etc? There seem to be a few variables at play here.
-
Good idea. I might do that this summer after I get through my big list of projects. We're three days from the end of the school year here so it's pretty busy now and for the next couple of weeks until Christmas.
- 79 replies
-
- 1
-
-
- firewall
- recommendations
-
(and 1 more)
Tagged with:
-
This is another reason the iBoss 3550 has been a winner for us. It supports the following authentication methods: • Active Directory, LDAP, eDirectory, Open Directory, and OpenLDAP • Transparent Single Sign-on for Active Directory using server-side plugin, proxy, or NTLM • Mac OSX logon/logoff scripts (controlled server side) • Real-Time Directory Server Sync • Individual User Login Creation (SuperUser) - Web portal capture page for BYOD devices - Mobile agent can also be installed on laptops if desired We are using the AD plugin installed on our AD servers and Mac logon/logoff scripts - both work very reliably. The iBoss works seamlessly for Mac, Windows, or Linux. We are also able to set default filtering for our WiFi VLANs for iPad filtering and you can use the capture portal page with mobile devices as well. Additionally, iBoss has the MobilEther solution for MDM and filtering that will follow the device wherever it goes. I make not a single dime from telling you this because there is not a single distributor for the iBoss in all of Australia - I have never seen any web filter even approach the functionality of the iBoss, and they are fantastic value at twice the price for what they are capable of doing. I don't care what you are using, the iBoss is worth a look.
- 79 replies
-
- firewall
- recommendations
-
(and 1 more)
Tagged with:
-
@IKWeb You've gotten some good advice here from all. I agree that upgrading to Mavericks on a large scale bears some risk. I have been running 10.9 on my laptop since it was released (gotta eat the dog food first) and have found a few bugs that affect its use on our network (and just niggly client side ones). The problems are big enough that I decided not to roll it out on our network yet. I'm hoping 10.9.1 will have enough improvements fixes to resolve the issues holding us back from rolling it out, but at least a month of testing post-release will be required before I would decide on that. So, you may want to hold off, but I would certainly encourage testing how you're going to deploy it en masse and if 10.9 hasn't caused any problems at your site and your setup, then let us know how the deployment goes!
-
You're going to be doing some walking. However, if you use this opportunity to apply config profiles to the Apple TV ps using Configurator then it will be easier next time around: http://www.classthink.com/2013/08/31/managing-apple-tv-with-apple-configurator/
-
Here's an article for doing just this sort of upgrade to Lion and should work in principle for 10.9 http://derflounder.wordpress.com/2011/09/08/upgrading-to-lion-with-deploystudio/ With 200 clients you are at the point where an investment in Casper Suite or similar may be worth serious consideration. DeployStudio is great (and free), but it can only do so much before you start to see its limitations.
-
Well, there are zero distributors of iBoss in Australia, but I requested a demo unit and they sent me one within a week for a 90 trial. Turned out they just sent out a brand new unit and after two weeks of testing I decided to buy the unit they sent for the trial. The support provided for setup and configuration was excellent even though it was remote support. I was given the name and direct number for a tech as iBoss provide 90 days implementation/configuration support. They remoted in and walked me through everything. They really knew their stuff and weren't just some kid reading from a script. Now, two years later I did have a hardware problem with my iBoss (seemed to be the NIC). Again, the remote support was great and when they identified that it was a hardware problem, Phantom shipped a brand new unit to me and it arrived in 3 days (from California to Australia). They didn't even want me to ship back the old unit (I asked) because of the expense of shipping it. Yes, there are no distributors here, but I can't complain about support! Now, I am currently trying to convince one of my best suppliers to become an iBoss distributor because yes it would nice if there were local contacts over here. However, the iBoss was that much better than every other solution that it didn't really concern me that much. Many of their appliances are sub $2,000 or just over (we have 3550 unit and it was just under 2k) and subscription costs work out to $6 per student per year.
- 79 replies
-
- firewall
- recommendations
-
(and 1 more)
Tagged with:
-
I recommend Phantom iBoss 100% over every other web filter I've used, including SW, iPrism, and Watchguard. In the past three years I've had a couple of vendors come trying to sell me their solution. Then, I show them what the iBoss can do and they soon realize they are the Goliath that has met their David with no hope of matching the iBoss even for 10 times the price. Yes, the SmoothWall is usually cheaper than the iBoss, but I see tons of techs on here stuffing around with their SW trying to figure out how to get it to do things the iBoss does out of the box with its eyes closed. Can't comment on the LightSpeed unit one way or the other as I haven't touched it, but you should trial both the LightSpeed and iBoss before deciding. I would be really surprised if the LightSpeed beat it. If it does, let me know and I'll look at it myself if it's THAT good.
- 79 replies
-
- firewall
- recommendations
-
(and 1 more)
Tagged with:
-
I would highly recommend placing staff and student wifi devices on different WiFi SSIDs and VLANs to segregate the traffic. Place the AirPlay devices on the staff wifi VLAN and you won't need passwords on AirPlay. If you don't do that you're only option is passwords on AirPlay. If you are running iOS7 and using MDM then you could setup policies that would set the AirPlay access and passwords on staff iPads.
-
I was able accomplish that using the "block snapchat" feature in our iBoss web filter. I think the snapchat application blocker feature in our Watchguard XTM firewall also blocks it. As for the exact URL or method that is being used by the iBoss or Watchguard I'm not sure. Neither one blocks snapchat on iOS though because the iOS app is routing through Apple and/or Verisign servers based on what I'm seeing in my logs.
-
Do NOT do this. If I may be so blunt, your Academy's new data protection policy should be renamed to the data LOSS policy. Instead, do this. 1. Create a password policy in AD that requires a minimum of 8 characters and strong passwords, as well as a password change at least once a year (more frequent is better, but I understand it is teachers and students you're dealing with). 2. Install a password manager such as the ones from Netwrix or ManageEngine. These will enable your users to setup security questions they can answer to reset their own passwords if they forget them and a delegated admin account you could provide to any techs or even the librarian to reset user passwords securely. These also work great for tablet users who never or rarely log onto a computer on the network to receive alerts about expiring passwords. Netwrix also provides software that will send reminder emails to users when their password is expiring to give them a heads up. 3. Document the new password policy and how to use the password manager and reset passwords. Advertise the heck out of it to your users. 4. Burn the Academy's current Data Loss Policy and create an actual Data Protection Policy based on what you've just implemented. Sometimes it's better to beg forgiveness than ask permission. Especially when you're begging forgiveness for ignoring bad policy and implementing a solution that actually works.
-
Zendesk is what we have used for the past 4 years for IT, facilities, and OHS help desk. The iPad and iPhone apps are very good and Zendesk meets all of your requirements and then some. We have ours integrated with Screensteps Live for Tutorials and Mindtouch for knowledgebase. There are the forums and built-in knowledge base as well. Yes, it is a bit more costly than some solutions, but from an economic labour vs capital decision making process, time is more valuable than money and Zendesk can save you a lot of time. Other solutions I have used and can recommend are ServiceDesk Plus (Manage Engine) and OnTime (http://www.ontimenow.com/bug-tracking). OnTime is designed for use in software development and bug tracking, but it is highly configurable and makes for a great general purpose project/task management and help desk system. EDIT: Looks like OnTime has now split the product into a software development tool and a dedicated help desk http://www.ontimenow.com/help-desk - it has been over 4 years since I used it, but I suspect it will be even better than it was then.
-
Actually, a flat tax properly implemented without any loop holes or tax deductions would most likely increase tax revenue because the disincentives that exist in the current tax structure would be eliminated. More importantly, companies or individuals would not have to make the decision on whether to produce or not produce more goods or services when at the "margin" of the next tax rate, or make investment or purchasing decisions primarily based on reducing or deferring taxes. There would be greater individual and corporate compliance, and much less money spent on administration and enforcement of an obscenely complicated tax system. Corporations would be far less likely to funnel money through any legal loopholes possible and might actually repatriate profits (e.g. Apple, Google, etc.). There would also be less much less "cash in hand" payment of workers, meaning more taxed income. Although not a good example in many other areas, Russia has shown leadership in tax reform and economic management over the past 10-12 years (http://www.forbes.com/sites/markadomanis/2012/01/20/attention-mitt-romney-russia-has-a-flat-tax-and-almost-no-debt/). How ironic.
-
Spiceworks is a very good free one. The Dude is also a useful free network scanner. If you use a Mac then SpotMaps from Equinux looks promising - http://www.equinux.com/us/products/security/spot/index.html
-
You're school purchased several HUNDRED top of the line Mac Pros?? What in the world do you use them for? You must have an IT budget that would get some countries out of debt.
-
Slow login when a whole class logs in over wifi
seawolf replied to Jollity's topic in Wireless Networks
The only way I've found to get Symantec to behave is to uninstall it. Good luck! -
We use a Mindtouch server locally hosted that we have re skinned and customized. Works fantastic. We started out using the free version back when it was available and supported, but purchased an Edu license for the commercial version in a short window when they offered such a thing before they took it to a hosted only version and jacked the price up considerably. The open source version is still available, but updates are going to be almost non-existent in future. A shame too, because Mindtouch platform was one of the best things you could build an Intranet on. Still is IF you can afford Mindtouch TCS.
-
Cheapest Mac Laptop for Apple Configurator
seawolf replied to CommodoreS's topic in Mobile Devices & Tablets
I suggest you buy a used 2010 or 2011 Mac Mini unless you have a particular reason for needing a laptop to do this.
