ToyHeartsFan
Members-
Posts
292 -
Joined
-
Last visited
Reputation
312 ExcellentAbout ToyHeartsFan

Personal Information
-
Occupation
ICT Operations Manager
Recent Profile Visitors
The recent visitors block is disabled and is not being shown to other users.
-
SIMS Licence Expiry and access thereafter
ToyHeartsFan replied to Warwick_Tech's topic in MIS Systems
Years ago I was at a school where the Business manager purchased some single user licence to allow her to continue using SIMS after we migrated to another MIS I think it was very expensive and some people were critical saying they could access the database directly... I can't imaging many schools have staff that can query an SQL database directly or that would want to even if they could. I think the main problem these days is that MIS systems are more likely to be cloud based and you can't expect them to keep hosting data if you stop paying so you just have to migrate everything to the new MIS. -
What are you talking about, the online safety act forces certain websites to verify users age nothing else has changed. If your filter is blocking a url / ip address then you cant get to the page for their age verification to kick in. User enters the URL at this point your filter should block it from opening so no redirection scirpt on the "bad page" can run because the "bad page" is never opened. If you want to test a URL in school get permission from your head, inform your filtering provider & DSL what and why you are doing and test it in a location where it can't be viewed by children ideally with a witness such as your DSL.
-
They will have worked with the known filtering providers as well as the IWF and CTIRU and had those addresses added to their respective block lists. How exactly do you want them to test filtering, by hosting illegal content on a page and seeing if you can access it and thus you risk being arrested when you run the test if your filter doesn't work? Yes the test is a bit mehh and on my mobile connection it only passes the CSAM test despite the fact that adult content is blocked by my mobile provider. But I've no idea what filtering solution my mobile provider uses and testing my mobile connection is outside of the scope the test was designed for although it could be a useful feature for parents to test their kids phones. As for being redirected to an age verification page no why would that happen your filter should be blocking you from opening the "bad page" so it should never get to the site for age verification to kick in.
-
By default Virgins superhub 3 had one SSID that broadcast on 2.4Ghz and 5Ghz and their was a seperate "Guest" SSID for visitors. You could change it so the 2.4Ghz and 5Ghz frequencies had different SSID's, there were also options to change the channels, the channel widths and set the security settings WEP / WPA-PSK / WPA-PSK2 and turn off the pair / connect button that on the front of the router. So he could have renamed the SSID's, changed the password and security setting on any of the SSIDs, hidden a SSID, tweaked the channel width to get the best performance for the device hes using etc... "I thought it might not be transmitting on 2.4GHz for some reason" My guess is that hes renamed the SSID's and used the 2.4Ghz frequency for the ring doorbell, possibly hiding the SSID as well leaving just the 5Ghz SSID visible. 802.11n i.e. the first 5Ghz support was 2008 and 802.11ac with more 5Ghz bandwith has been around since 2014 so it does sound like the laptop is long overdue for replacement if it only works on 2.4Ghz. The brother might be able to enable the "guest" SSID on 2.4Ghz so she could use that, otherwise get her a 5G WiFi dongle as suggested or a new laptop.
-
In place upgrade from ISO just means running the setup file from within windows rather than booting from the ISO; either use a tool to mount the iso in windows or create DVD / USB media. I can't recall trying it with an LTSC version but it should work in the same way as regular windows with the previso you might need to launch it from the cmd line with the product key if the upgrade option is grayed out: https://learn.microsoft.com/en-us/windows/deployment/upgrade/windows-upgrade-paths Small SSD's hardly cost anything now so as its a major change and might break InVentry I would create a disk image of your PC first (and make sure it works) so you can restore it if it goes pear shaped, I would also want to export a backup of InVentry as psydii suggested if possible. The ISO's should be in your VLSC account, some times they don't list everything in VLSC that you are licenced for if you contact Microsoft they will probably add the IOT ISO for you. Note: as far as I know you cant upgrade LTSB / LTSC from windows update.
-
If there was a surge it would have bypassed the UPS so if you want the servers connected to two different supplies then you need 2 UPS units. It's not impossible the UPS is faulty and fried the servers but I'd put my money on it being the unfiltered connections. As regards your 14 year old server that you can't get parts for its scrap and you shouldn't have been using it for anything critical due to its age, something like hosting WSUS or WDS though would have been okay at a pinch because its easy to replace and doesn't impact the end users if it dies. 1. Buy a new server move the roles from your working server to the new one then use the older one to host the roles of the dead one. 2. Buy a refurb (but not as old) server to replace the dead one. 3. Search ebay etc for a 14 year old untested server motherboard, psus, RAM etc and swap them out until you can boot it again... 4. Do away with the dead server and move the roles to the cloud.
-
"Staff mainly just use ActivInspire on their PC's" If you switch to a different solution how loud are the teachers going to shout when you tell them they are no longer licenced to use Activinspire and you have uninstalled it? RE the OPS add on, IMO smart screens are getting too clever for their own good at least with the Promethean OPS they had an mdm to manage them. Otherwise screens with built in browsers that bypass the likes of smoothwall monitor and dont even require user authentication are potentially a big safeguarding issue in schools. It was the old style boards that caused more problems for me, they dropped support for them, there were known issues which caused them to crash and they didn't officially support W10 although not long after the warranty expired on one of the new panels we had the lens diffusers started falling off the backlight leds.
-
Individual user accounts/profiles on a single iPad
ToyHeartsFan replied to Caffeine11's topic in Mobile Devices & Tablets
If you search the old threads someone else was setting up iPads for shared use but as others have said it wasn't a simple process and required some third party authentication. There's also a potential issue with the number of profiles you can have on an ipad because of the limited amount of storage they have. We had iPads for staff, the device name was the teachers name and we used Policy central (now called smoothwall monitor) which replaced the browser; it was pretty awful but there's a Smoothwall rep on here that has said they have updated it and the browser is now based on Firefox but I've never used it so can't comment on how much better it is. We mainly used PCs and banks of laptops which worked well with Policy Central monitoring along side our RM safety Net internet filtering. We did have a bank of android tablets but these were managed with Maraki in KIOSK mode with the APPS that we needed, there was no web browser on them. There were a handful of childrens iPads but again these were restricted to a handful of sites like childrens BBC for foundation stage children. Do note that Filtering and Monitoring are not the same thing, if a child types in Word that he wishes he wasnt being bullied etc... a normal internet filter isn't going to detect it you would need something like Smoothwall monitor for that but with the previso that it works best on PC, e.g. Apples eco system is far too locked down for them to offer the same level of protection on iPads as on a PC. It depends how invested you are in Apples eco system and how you currently use the iPads, it would probably be far easier to get a set of laptops and a monitoring solution like Smoothwall Monitor running and remove the browser from the iPads than it will be to setup the logins and manage the profiles on a set of iPads. -
Individual user accounts/profiles on a single iPad
ToyHeartsFan replied to Caffeine11's topic in Mobile Devices & Tablets
They might be the only MDM provider to include it but they aren't the only internet / filtering provider that provides a filtering solution that follows the device so the devices internet connection is filtered outside of the school. RM SafetyNet Go - is one example The Dfe laptops (if you can call geobooks laptops) also had a cloud based internet filtering solution pre installed when they were delivered to schools. Even Sophos had an option for basic cloud based filtering. Smoothwall Monitor used to have a filtering solution built in but after Smoothwall purchased it from Policy Central / Future Digital they removed the filtering so now its only a monitoring tool. -
Individual user accounts/profiles on a single iPad
ToyHeartsFan replied to Caffeine11's topic in Mobile Devices & Tablets
Eeek I dont know how your DSL is ok with that setup it's impossible to identify a child if theres a safeguarding concern, Ofsted might want a chat if they ever visit. I managed the networks at 2 large inner city primary schools: Nursery and Reception had a generic login with internet access restricted to a handful of pre approved sites they could not just browse the internet. Once Reception children had settled in they were given individual logins with a very simple password. Years 1 and 2 individual logins with slightly more complex passwords. Years 3, 4 ,5 and 6 individual logins and they created their own simple password. English was the second language for a lot of the children, unless you are a SEN school I can't see any reason why the children are sharing accounts, even at a SEN school I would expect the children to have individual accounts and the Teachers / TA's to help them login. -
School Security Audit Issue Flagged
ToyHeartsFan replied to talksr's topic in Learning Network Manager
Do you like working there and how much do you want to rock the boat? "the site manager had other ideas and we now have about 5 different NVRs spread all around the building" At the very least the school business manager would have processed the official order and it would have to have been approved by the head, most likely he was told by the head or a member of SLT that they wanted more CCTV cameras and SLT didn't feel the need to consult you. "The consultant now states that the three cameras I have in the server room, must also be added to the site manager's computer." I assume the consultant works for the company that installed the other kit, he has the ear of site manager and as far as the school is concerned the site manager is the CCTV operator. "The head has been passed this report and said can I either give the site manager access to these cameras or just have them disconnected and removed" That tells me the head doesn't really think it's your job to manage the CCTV and they might not want you to have access, is CCTV in your job description? You could just remove it as instructed and then wash your hands of the CCTV system, you don't have access and it's no longer your problem. The CCTV consultant might then decide the server room should have CCTV and install a system of their own... "On a site note, I regularly walk into the site manager's office to find he has left the CCTV viewer for one of his NVRs open and in full view of anyone who can walk into his office and he has either gone or left other colleauges watching it who are not listed as being able to view the CCTV on the School CCTV Policy." Can you prove this or is it his word against yours? You could: Make a formal complaint against the site manager to the head. Raise it with the school data protection officer. Make a formal complaint to the governors. Make a formal complaint against the school to the ICO. At one extreme the site manager gets fired, the other extreme is SLT don't believe you; expect any job requests you submit to the site team to get lost, any deliveries for IT to be left in a pile in the corner for a week before you get them and your bins never to get emptied. I even heard of a site manager that stuffed a dead mouse behind a classroom radiator when a teacher upset him... "we would have no way to identify if someone comes in and takes hot swappable HDDs from the server or steals our Paxton Access server." So the school uses Paxton and putting mag locks on the server room and site managers doors would be a lot cheaper than replacing 5 NVR's, suggesting it might even earn you browny points with SLT if you pitch it the right way. "We were advised that every time we access the CCTV system, we should log the date, time, what we were on it for and if anything was downloaded. This is listed in the school CCTV Policy under System Log. I have kept an Excel sheet from day one and I list everything, even firmware updates to cameras I perform as I am still accessing the cameras which show images." Great that you do all that, I was told to create CCTV accounts for the head, the business manager and both the caretakers who then decided they needed more monitors so they could leave the screens on despite being told that they are only supposed to be checked if theres been an incident or to check they are working correctly... Before I started the CCTV was managed by the site team then the site team changed, I had a new tech and when the police turned up etc... the site team would bring them to me to view the cam's or export footage for SLT. Then the head got a bee in her bonnet, the business manager got a council approved CCTV compmany in and NVR's started popping up all over the place. The approved CCTV company were given carte blanche to do what ever they wanted, they wired cam's into the back of existing network sockets leaving the socket in place, they set static IP's causing IP conflicts on the network, they set a password on the individual IP cam's that were causing the IP conflicts so I couldn't check or alter the settings and they refused to give the password to me saying they can't because they use the same password at every school... they ran unmarked cables all over the place plugged into comms cabs without permission, added their own mini network switches and left no documentation... "The site manager has no log at all" Suggest that as the site manager is now responsible for CCTV it would be a good idea for him to undertake training to obtain a SIA CCTV Licence. "and regularly leaves live camera views up for all to see on his desktop." Why doesn't his desktop screensaver lock the PC after a few minutes? Even SLT incuding the ICT lead would do this at the school I was at despite explaing why they shouldn't; I set a timed screen lock on all office user network accounts, at one point I did try it with teacher accounts with a longer grace period but was told by the head to remove it because too many teachers complained. Based on my experience with the council approved CCTV company, some installers are grossly incompetent; I explained to the lead installer multiple times what a DHCP server was and that dhcp reservations are needed. It went in one ear and out the other and he continued installing cams with static IPs with no reservations causing more IP conflicts. Only you can decide how much to rock the boat and whether the fall out is worth it; do you even have the time to manage the CCTV should they take the job off the site team and say its now your resposibility? When I complained to our business manager how many problems the cctv installers had caused she just said well you can fix it can't you... Well sure if I had nothing else to do for two weeks I could have gone round the whole school to find where the cams were, factory reset and reconfigured each one, traced and replaced their dodgy cabling. But at that point I was working on my own and simply didn't have the time, the best I could do was use the device Id's, try and find the mac's listed in dns and make dhcp reservations to mitigate some of the problems until the next time they came out and broke something else. One time I found foot prints on top of the server because they had been standing on it to access a NVR another time they stood on a monitor shelf in the server room ripping it off the wall. The week I left when I was made redundant the caretakers were begging for CCTV training, I didn't have the time with the jobs the head asked me to do before I left and my post had already been downgraded so training staff wasn't in my job description anyway so not my problem... Schools don't value ICT staff, they often don't listen to them when they give advice even when they are in a senior IT Operations Manager GR4 role but will fall over themselves when an external installer that doesn't even know what a DHCP server is clicks his fingers. It won't change until senior IT roles become part of the SLT team which is unlikely to ever happen in small schools with the constant budget constraints. -
Is that plastic cable protection in the plaster? I've only ever seen steel which is quiet resistant to masonary drill bits in case someone attempts to hang a shelf / cupboard / TV stand etc... in the wrong place.
-
An electrician doing some work for my landlord managed to put a screw through a cable when he replaced a kitchen extractor fan which immediately tripped the RCD so he repaired it... Fast forward probably more than a year and the RCD tripped for no appararent reason, switched all the MCB's off, reset the RCD and switched them back on one at a time until it tripped again. It was the lighting circuit that also ran the extractor, pulled the spur fuse for the extractor and the RCD didn't trip. When they fitted the new extractor fan instead of using one that was the same size or plastering the hole first they had used a piece of plywood screwed to the wall to mount the fan. Got the multimeter out and there was a short between live and one of the screws holding the plywood. So the screw had been live since the electrician had fitted the fan, the RCD had tripped because it had been raining a lot so the normally insulated live screw was now imbedded in bricks that were damp enough to trip the RCD. Is the hob isolator switch on the island or on the wall, if it's on the wall you could disconnect the cable there which would help narrow down where the issue is. 1. Kitchen fitter screwed through a cable -- my money would be on this as well but you should be able to check for a short between the screw heads and live / neutral if they are accessible 2. Cable under floor was some how damaged when it was fitted but has got damp so is now tripping the RCD 3. Rats, mice, squirrel under floor have chewed a cable
-
Dell Poweredge T440 - Green Flashing LED on Drives
ToyHeartsFan replied to timbo343's topic in Hardware
You can't rebuild a RAID 0 array, RAID 0 means theres Zero redundancy. You also can't just move drives between bays in an active array, the controller stores details of the virtual disk config on each drive in case the controller fails so that the controller can be replaced and the "foreign config" can be restored. One of the pages I pulled up said you can't hot swap drives when they are configured in RAID 0 and you have to reboot the server after any changes, so you should have probably used idrac to delete the failed drive then shut the server down before trying to replace it and make a new array and virtual disk. I'm guessing its an 8 bay server and the OS is on 1 drive with no redundancy and the other 7 bays were used for the 10TB sata data drives in Raid 0? In which case you need to rebuild / reconfigure the server, the OS needs to be in raid 1 as a minimum you can then use the remaining 6 bays in raid 5, 6 or 10 for your CCTV storage. I dont know if your raid controller will let you convert a standalone drive in to a RAID 1 pair but you will probably need to either reinstall the OS or restore it from a backup (if you have one). As others have said if the bays are faulty you need to contact Dell there's nothing anyone on here can do to help you; if the array config has been messed up by the failed drive and you then moving drives around you should be able to delete the virtual disks / array but might need to initialize / erase each drive using idrac but I can't tell you the exact steps from memory alone. You could always pull the lot stick them in a USB dock and erase them, delete all the configs on the raid controller, put the drives back in and start again. https://www.dell.com/support/kbdoc/en-us/000131039/poweredge-tutorials-physical-disks-and-raid-controller-perc-on-servers#disk https://www.dell.com/support/kbdoc/en-us/000131039/poweredge-tutorials-physical-disks-and-raid-controller-perc-on-servers#perc You will also need to speak to your DPO and tell them your CCTV system has failed and you have lost 60 days of CCTV because it was incorrectly configured, they will then have to decide whether it is necessary to inform the ICO. The DPO should also review the retention period because 60 days seems excessive and you have to be able to justify keeping the footage that long, once you have configured the CCTV array to use raid 5, 6 or 10 and the OS to use RAID 1 you will have less storage anyway. -
Dell Poweredge T440 - Green Flashing LED on Drives
ToyHeartsFan replied to timbo343's topic in Hardware
I doubt that they are SAS drives if they are 10TB each and I don't think SATA supports the same level of diagnostics. If you can't see the drives in iDrac they are probably toast but you could try pulling one and sticking it in a USB caddy to see if Windows detects it in disk management before you throw it in the recycling bin. Do you need 70TB of storage, thats a lot of cam footage you have lost which can't be recovered because it was in RAID 0.
