Jump to content

seawolf

Members
  • Posts

    975
  • Joined

  • Last visited

Everything posted by seawolf

  1. Avast! SOHO edition. It's less expensive than Sophos, easier to deploy and manage, and we haven't had the royal stuff ups that occurred on two occasions in 2012 with Sophos. Then there were the occasional false positives of programs that were clearly not malware (Mozilla Firefox - really Sophos?). I had used Avast! for a business for 3 years between 2006 and 2009 and it never gave me problems then either other than from the unintuitive management console, which the SOHO console fixed.
  2. We've had a dedicated IT office and adjoining working space (benches, storage) for several years now. The Library staff office is next to us though, and the Head Librarian and I want to knock down a couple of walls, commandeer another office and turn a more open working area into a shared Library/ICT Office with a Help Desk window for IT and service window for the Library. With all of the integration of IT into the Library and the fact the Head Librarian is also the school's eLearning coordinator it makes a lot of sense. It also gets IT more face-time with teachers and students because it will make it easier and more inviting for them to come for assistance (rather than the "IT is back there behind the Library" that happens now).
  3. If you are going to have that many clients, then you will need more than just DS and you won't want to use Profile Manager as it won't be able to scale and grow to the level you'll need. You may also want to try to find a 2012 model Mac Pro to use as your distribution point/server rather than a Mac Mini. You should be able to find a well-spec'd Mac Pro (not the latest model) and it should serve you well for years even with several hundred clients as @crt404 is doing (and us). Munki or Simian are definite options for you if you want to save money in the long term. Munki was developed by Disney Animation and Simian is a Google fork of the project. I've been looking into these myself, but haven't gone this way yet. There are many successful implementation in the wild though and there are several companies in the UK with experience helping people roll these projects out. http://www.amsys.co.uk/munki-whitepaper.pdf Using Munki to Manage Apple Software Updates » Amsys However, you still will need MDM for the iPads. You may wan to consider one of the free MDM solutions out there or take a look at the iBoss Web Filter / MDM solution. It provides outstanding MDM features and the best web filter in the business.
  4. I know the idea sounds nice, but I don't think the time is quite right for co-location of servers off-site, at least not your main infrastructure. The costs for hosting can still be quite high and in this example, you would be limited to a 30Mb connection to the servers and core storage rather than 1Gb+ (or 300Mb for 802.11n WiFi) that you would normally have for locally hosted servers. That's quite a lot slower. Less than 1/3 a 100Mb network. There will come a day when co-location is a preferred option, but I think that day is when we can get closer to 1Gb dedicated connections to data centres for co-located servers.
  5. CAT6a is the way to go, but it is best to use foil-shielded rather than UTP as it is thinner and more workable. As you say normal CAT6a UTP can be a pain. I think there will come a time within the next 10-15 years when 10GbE will become more commonplace (and it will definitely be required for uplinks to WiFi APs much sooner). The cost of CAT6a over CAT5e is negligible, so I think it makes sense to use it in any new installations. I wouldn't necessarily go and retrofit existing installs unless the cabling was CAT5 or less.
  6. I've copied an extract from our network cabling standards below. If you can afford it, I would recommend using similar standards as it will provide the longest lifespan possible for your core network. If you are a small school, then 10Gb may be over the top, but you will want the option of going to 10Gb because it may be needed in the future. Use minimum 1Gb switches (PoE preferably) with fibre uplinks between them. If the switches can be upgraded to 10Gb uplinks in the future even better. Make sure your core switch as redundant power supplies and adequate backplane. Choose a good WiFi system from the start. I suggest Ruckus or AeroHive. Unifi if you are strapped for cash. Use plenty of VLANs. Good network cabinets and UPS are essential as well and good cable management should be made mandatory since you are starting from scratch. Server and storage-wise - it really depends on how much money you have, but virtualisation is strongly suggested. Make sure your servers have lots of CPUs and RAM. Two VM hosts are recommended as a minimum. Storage really depends on sizing requirements and money. Tell me how many clients, etc. in total you'll have connecting and amount of data you need to store (# users x allowed quote, etc.) and I'll give some recommendations. This is how we've transformed our infrastructure in the past 5 years - http://www.edugeek.net/forums/hardware/131322-evolution-server-room.html Optical fibre cable, connectors, and patch cords http://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif Optical fibre cable typeshttp://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif Inter-Campus Links (between campuses)http://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif All installations of optical fibre between campuses (or distances over 300 meters from the core distribution point) will be OS1 Single-mode. All installations shall follow the existing Infrastructure pathways if available and must be specified in the planning stages in consultation with the ICT Manager. Intra-Campus Links (between buildings)http://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif All installations of optical fibre between buildings on the same campus that are no further than 300 meters from the core distribution point will be OM3 Multi-mode. Buildings shall NOT be connected in a daisy chain configuration, but must be directly cabled to the main Network Distribution Rack (network core) for each campus. All installations shall follow the existing Infrastructure pathways if available and must be specified in the planning stages in consultation with the ICT Manager. Optical fibre core quantitieshttp://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif Optical fibre cable shall be installed with a minimum of 12 cores between any two termination points (Racks). Smaller core configurations may be considered for low density buildings after consultation with the ICT Manager. Optical fibre connectorshttp://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif Optical fibre infrastructure is installed using SC connectors to the fibre trays and LC connectors to the network swtiches. The SC connector shall comply with AS/NZS 3080: 2003 or later. Optical fibre patch cordshttp://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif SC to LC patch cords are to be used for all connections to fibre trays (termination points) and network switches using SFP+ modules (10Gb). LC to LC patch cords are to be used for trunking connections between network switches where required. Stacking modules should be used in preference to fibre trunking where possible. The shortest fibre patch cord practical for the job must always be used. Unshielded Twisted Pair (UTP) cable and Telecommunications Outletshttp://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif In all cases the use of plastic cable ties are not permitted for securing cables (Fibre or Copper). Where Category 6 is specified in this document, this will include Category 6a (ISO/IEC: 11801:2002 Class EA). Where UTP refers to Category 6a cable this is to be F/UTP (Foiled Twisted Pair). UTP cable category requirementshttp://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif All UTP cabling other than that used for patch leads must be solid core and not stranded wire cabling. All new buildings or campuses shall be installed using Category 6a solid core cabling. All Category 6a cables installed in any buildings, whether new or old, will use foil shielded cable (F/UTP). Note: F/UTP cable is smaller in diameter, is easier to work with, takes up 21% less volume in cabinets, and prevents alien crosstalk to a greater extent than the equivalent CAT6a UTP cable. UTP Backbone cabling The communications cabling between floors or segments of buildings shall be installed with a minimum of 25% spare capacity above project requirements to allow for future expansion. CAT6a Ethernet cables will not be used in cable runs exceeding 90 meters and are NOT to be connected in daisy chain configuration, but directly cabled to the main Network Distribution Rack in the respective building. Where cable runs exceeding 90 meters are required, OM3 Multi-mode fibre cables must be used to extend the network using a 10Gb trunk between network switches. Horizontal UTP Cabling and Wall or Ceiling Data Points (Outlets)http://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif Quantity of Wall Outlets In all office spaces, a minimum of 3 per work station (1 x digital phone, 1 x computer, 1 x printer/scanner) + 1 per room entry point for Door Access Controllers In Computer Laboratory spaces, 1 per computer workspace + 2 for printers/scanners + 2 for TV/Projector + 1 for Wireless Access Points (AP), + 1 per room entry point for Door Access Controllers + 1 for IP Intercom Systems. In all General Purpuse Learning Areas (GPLAs), a minimum of 2 for printers/scanners + 2 for TV/Projector + 1 for Wireless AP, + 1 per room entry point for Door Access Controllers + 1 for IP Intercom Systems. In all large foyers, staff rooms, and reception waiting areas, 1 for Digital Signage + 1 per room entry point for Door Access Controllers NOTE: Consideration must also be given to providing Wall Outlets for IP Secrity Cameras, Wireless Access points (APs), Video Displays (digital signage), additional Door Access Controllers, additional IP Intercome Systems, Building Management Systems, etc. Category of Wall Outlets In new buildings or for complete rewiring of existing buildings, Category 6a shall always be used. UTP Patch Panelshttp://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif In new buildings or for complete rewiring of existing buildings, Category 6a patch panels shall be used. All Category 6a patch panels shall be of 24 port capacity. The voice ties (telephony integration panel) may use 36 or 48 port patch panels. UTP Patch Cableshttp://intranet.bcc.vic.edu.au/skins/common/icons/icon-trans.gif Category 6a patch cords must be used for all new buildings or the complete rewireing of existing buildings. Existing buildings using Category 5e patch panels may use Category 5e patch calbes or Category 6a patch cables. Patch cords should be stranded wire (not solid core) to enable easier routing and more frequent bending and moving of the patch cords into patch panels and network switches. The shortest patch lead practical for the job must always be used.
  7. Watchguard makes an excellent firewall (I've owned three of them), but the web filter service (web blocker) is not very good.
  8. I would recommend taking a look at the iBoss web filter and firewall solutions. You can get a web filter/reporter appliance for under 2k and a firewall that integrates with the web/filter and reporter for about the same. I've said it before and I say it again - the iBoss web filter is the best there is. Their firewall is also very capable. It is more basic than some that you can buy, although I'd say many people only use 20% of the features of the high-end firewalls, and what the iBoss firewall does it does well, especially the logs and reporting, and ease of config and ongoing maintenance,
  9. Have a read of this. http://www.edugeek.net/forums/mac/133492-mac-deployment-management-tools.html NetBoot over WiFi is possible, but it can be flaky depending on how well your network is setup. Also, there is the speed of imaging over WiFi to consider, which won't be great. I would recommend using Thunderbolt to Ethernet adapters to do your imaging. The cost of these is a once off and will more than be made up for in time saved to you. Unless you have 100 clients or more, I wouldn't bother with Casper Suite, FileWave, Absolute Manage, etc. DeployStudio, ARD, and Server app on a decently spec'd Mac Mini (i7, SSD or Fusion drive, 4GB-16GB RAM) will be all you need until you hit about 100 clients. After that the other solutions start to come into their own.
  10. Really? You're going to continue to believe its a good idea, and that using something like my.company.local makes a difference from company.local? If you want to use local.company.com that will work just fine, but even MS cautions strongly against domains ending in .local Selecting the Forest Root Domain But, go ahead and do what you want. Good luck finding the 30 year old official doco from IBM, etc. that recommends this practice.
  11. RFC 3927 is an industry standard contributed to by Sun, Apple, and Microsoft. Have a read. Zero-configuration networking - Wikipedia, the free encyclopedia Microsoft has never been great help in my experience either, but that doesn't stop most people. Macs do provide quite a lot of useful feedback in the log files, but of course you have know what you are looking at (console logs, safari debugging mode, etc). This applies more to Macs than iPads, which are a bit tight lipped about what's going on under the hood as a result of the sand boxing, etc. You know, I run into issues with Windows servers and clients (and other people's software) on a regular basis, but I don't feel the need to damn Microsoft to oblivion every time something stuffs up (sometimes Windows stuffs up quite majestically). It is quite interesting to watch the meltdowns occurring from the cheese being moved.
  12. How can I say this as kindly as possible? Perhaps by saying that zeal without knowledge is not good. .local has never been a good idea for many reasons. I have worked on UNIX networks since before the first web browser existed and I can't remember a single one using .local so I don't know where you got that idea from. Here's but one article as to why. Just because everybody and their uninformed brother does something doesn't make it a well thought out plan. Why you shouldn't use .local in your Active Directory domain name.
  13. Since the laptop is receiving an IP address apparently from the DHCP server, are you able to ping it from another computer? If not, then there may be a firewall causing problems on the laptop. If you can ping the laptop from another computer, but can't ping anything from the laptop then you may want to make sure the Lightspeed or your WiFi system isn't somehow isolating the IP or VLAN your laptop is on. I've seen this happen before on Ruckus WiFi as there is a client isolation mode that can be enabled. You should check the iP in Lightspeed as well to make sure it isn't blocking traffic or hasn't placed it in a rogue clients list.
  14. An app on an iPad constitutes curriculum delivery? If schools are there to teach kids how to use a particular piece of software or are dependant on a particular piece of software to teach, then it is a slippery slope we are going down indeed. Perhaps its time to wind back the amount of technology we have going into our schools.
  15. I'm very sure you can do your job. However, I also know the attitude of most Windows admins is to attribute any issue with a piece of Apple hardware or software to "Apple gear just sucks!" rather than doing the same type of troubleshooting they would do on a PC. I know from a significant amount of experience that i7 Mac Minis don't run as slow as you describe unless there is something wrong with them either in a hardware problem, network issue (DNS issues or .local domain), or more rarely a problem with an application or a corrupt account - as it is not normal.
  16. So, do you really think the average joe knows what they are doing when it comes to computers? Android has the highest level of malware in the wild by far of all mobile OS. Unless you aren't letting the staff and students download whatever apps they like (filtering them), then it is they not you who are the ones who will do stupid with bells on. Android still triggers the most mobile malware, says F-Secure - CNET I didn't realise that people having their iCloud account compromised because they used the same password on every site they visited or had their data stolen from one of the myriad of hacks that have targeted Target, eBay, Yahoo, etc. was indicative of a security issue with iOS? The problem with iMessage also has nothing to do with malware or hacking, but is an iMessage bug.
  17. That's correct, you don't want to run software RAID solutions such as ZFS on top of hardware RAID. It can cause conflicts and provides zero benefit. Whether using hardware RAID or ZFS, your best performance and reliability option is RAID 10 (Mirror in ZFS). However, with the amount of storage you apparently need RAID 10 would be costly. So, second best option would be RAIDZ3 (triple parity ZFS RAID). Third best is RAIDZ2 or the hardware RAID equivalent RAID6. I have not personally played around with Storage Spaces so I can't really comment on it's suitability for your requirements one way or the other. It is a fairly new storage technology though, so my instincts and experience tell me that it would be wise to hold off on trusting it for mission critical data until it matures and there is more real world data to base a decision on. SS may prove to be a very cost-effective and reliable storage solution, but there's just not enough history to make that call yet - for me anyway. It should be more than suitable for non-mission critical data though.
  18. You don't need to buy an MDM solution to install a couple of apps on an iPad without "touching" them. You just use Configurator. "But wait, that means I have to buy a Mac" you say. OK, so how do you manage the PC without a server? Because without a server, you are still at best using Remote Desktop and then "touching" the computer from afar. Same same. For the consumer, who is the largest purchaser of computers by far - iPads do just work. Nothing "just works" on a mass deployment scale without considerable work on the backend. Even Chromebooks require an existing Google Apps account and a reasonable amount of setup to get everything just right. So, let's see you just "get" (i.e. buy) a Windows server (but no special hardware required...oops wait) and licensing including CALs (don't forget those), spend a considerable amount of time configuring it, setting up DNS, DHCP, AD, GPOs, WDS, etc. Test, test, test. Tweak this, tweak that. Oh, wait you've never setup a Windows AD server before - pay someone to do it (so you don't stuff it up). Test, test, test. Tweak this, tweak that. If it doesn't do something you want it to, you can script it (except for Windows RT, which requires an MDM type solution...er em.) Yep, just works out of the box. Or, you just "get" (i.e. buy) a Mac to function as a server, pay $20 for Server.app and nothing for CALs. Spend a considerable amount of time configuring it, setting up DNS, DHCP, OD, Profile Manager, DeployStudio, etc. Test, test, test. Tweak this, tweak that. Oh wait you've never setup a Mac server before - pay someone to do it (so you don't stuff it up). Test, test, test. Tweak this, tweak that. If it doesn't do something you want it to, you can script it (for Macs not iPads) So, in the real world management of all devices on a mass scale takes some actual hardware and considerable effort. Imagine that. Those CALs can cost a pretty penny for the Windows server too.
  19. iBoss MDM (MobilEther) can lock down iPads to a great extent. Even removing the App Store, heavily restricting what can be installed, and forcing web filtering on the iPad no matter what network a student tries to connect it to (including their phone) try as they might.
  20. You should take the leap to Android then. Enjoy the malware...
  21. This example only demonstrates the lack of preparedness and organisation of the teacher and nothing more. If a teacher came to me just before or during a lesson wanting me to push out a bit of software for ANY device whether it be a PC, Mac, iPad, Android tablet, or anything else I would tell them to go to Plan B - because it wouldn't be happening, not ever. Do it once, even if it is possible, and you've just created a rod for your back. Even if you could, it wouldn't be a good idea because if its a new bit of software you (1) should really be testing it first; and, (2) should be considering the impact on your network of a bunch of devices downloading software all at once.
  22. Sound like you had a dying hard drive. They don't go that slow.
  23. You might want to look at the MobilEther MDM solution by iBoss. With the iBoss MDM/ Web Filter solution, you can remove the default App Store from the iPad replacing it with a filtered version, and also blacklist certain apps so that they either cannot be installed or removing network access until the app is removed (user is informed and is effective no matter what network the user tries to take the iPad onto). MobilEther also provides the capability to tie devices to web filtering that goes wherever the device goes on any network, including 3G/4G.
  24. Do you, by chance, use a .local domain?
  25. Yes, but Microsoft does the same thing. "In order to register on the Windows Store you need to be 18 years of age or the age of majority in your location and have a Microsoft Account and have a credit card account." I agree it is stupid and a pain in the rear. However, all of the App stores out there (Apple, Windows, Google) were designed specifically with a consumer focus, not a business or education focus. And that's where it all falls down for us.
×
×
  • Create New...