Jump to content

ToyHeartsFan

Members
  • Posts

    292
  • Joined

  • Last visited

Everything posted by ToyHeartsFan

  1. Years ago I was at a school where the Business manager purchased some single user licence to allow her to continue using SIMS after we migrated to another MIS I think it was very expensive and some people were critical saying they could access the database directly... I can't imaging many schools have staff that can query an SQL database directly or that would want to even if they could. I think the main problem these days is that MIS systems are more likely to be cloud based and you can't expect them to keep hosting data if you stop paying so you just have to migrate everything to the new MIS.
  2. What are you talking about, the online safety act forces certain websites to verify users age nothing else has changed. If your filter is blocking a url / ip address then you cant get to the page for their age verification to kick in. User enters the URL at this point your filter should block it from opening so no redirection scirpt on the "bad page" can run because the "bad page" is never opened. If you want to test a URL in school get permission from your head, inform your filtering provider & DSL what and why you are doing and test it in a location where it can't be viewed by children ideally with a witness such as your DSL.
  3. They will have worked with the known filtering providers as well as the IWF and CTIRU and had those addresses added to their respective block lists. How exactly do you want them to test filtering, by hosting illegal content on a page and seeing if you can access it and thus you risk being arrested when you run the test if your filter doesn't work? Yes the test is a bit mehh and on my mobile connection it only passes the CSAM test despite the fact that adult content is blocked by my mobile provider. But I've no idea what filtering solution my mobile provider uses and testing my mobile connection is outside of the scope the test was designed for although it could be a useful feature for parents to test their kids phones. As for being redirected to an age verification page no why would that happen your filter should be blocking you from opening the "bad page" so it should never get to the site for age verification to kick in.
  4. By default Virgins superhub 3 had one SSID that broadcast on 2.4Ghz and 5Ghz and their was a seperate "Guest" SSID for visitors. You could change it so the 2.4Ghz and 5Ghz frequencies had different SSID's, there were also options to change the channels, the channel widths and set the security settings WEP / WPA-PSK / WPA-PSK2 and turn off the pair / connect button that on the front of the router. So he could have renamed the SSID's, changed the password and security setting on any of the SSIDs, hidden a SSID, tweaked the channel width to get the best performance for the device hes using etc... "I thought it might not be transmitting on 2.4GHz for some reason" My guess is that hes renamed the SSID's and used the 2.4Ghz frequency for the ring doorbell, possibly hiding the SSID as well leaving just the 5Ghz SSID visible. 802.11n i.e. the first 5Ghz support was 2008 and 802.11ac with more 5Ghz bandwith has been around since 2014 so it does sound like the laptop is long overdue for replacement if it only works on 2.4Ghz. The brother might be able to enable the "guest" SSID on 2.4Ghz so she could use that, otherwise get her a 5G WiFi dongle as suggested or a new laptop.
  5. In place upgrade from ISO just means running the setup file from within windows rather than booting from the ISO; either use a tool to mount the iso in windows or create DVD / USB media. I can't recall trying it with an LTSC version but it should work in the same way as regular windows with the previso you might need to launch it from the cmd line with the product key if the upgrade option is grayed out: https://learn.microsoft.com/en-us/windows/deployment/upgrade/windows-upgrade-paths Small SSD's hardly cost anything now so as its a major change and might break InVentry I would create a disk image of your PC first (and make sure it works) so you can restore it if it goes pear shaped, I would also want to export a backup of InVentry as psydii suggested if possible. The ISO's should be in your VLSC account, some times they don't list everything in VLSC that you are licenced for if you contact Microsoft they will probably add the IOT ISO for you. Note: as far as I know you cant upgrade LTSB / LTSC from windows update.
  6. If there was a surge it would have bypassed the UPS so if you want the servers connected to two different supplies then you need 2 UPS units. It's not impossible the UPS is faulty and fried the servers but I'd put my money on it being the unfiltered connections. As regards your 14 year old server that you can't get parts for its scrap and you shouldn't have been using it for anything critical due to its age, something like hosting WSUS or WDS though would have been okay at a pinch because its easy to replace and doesn't impact the end users if it dies. 1. Buy a new server move the roles from your working server to the new one then use the older one to host the roles of the dead one. 2. Buy a refurb (but not as old) server to replace the dead one. 3. Search ebay etc for a 14 year old untested server motherboard, psus, RAM etc and swap them out until you can boot it again... 4. Do away with the dead server and move the roles to the cloud.
  7. "Staff mainly just use ActivInspire on their PC's" If you switch to a different solution how loud are the teachers going to shout when you tell them they are no longer licenced to use Activinspire and you have uninstalled it? RE the OPS add on, IMO smart screens are getting too clever for their own good at least with the Promethean OPS they had an mdm to manage them. Otherwise screens with built in browsers that bypass the likes of smoothwall monitor and dont even require user authentication are potentially a big safeguarding issue in schools. It was the old style boards that caused more problems for me, they dropped support for them, there were known issues which caused them to crash and they didn't officially support W10 although not long after the warranty expired on one of the new panels we had the lens diffusers started falling off the backlight leds.
  8. If you search the old threads someone else was setting up iPads for shared use but as others have said it wasn't a simple process and required some third party authentication. There's also a potential issue with the number of profiles you can have on an ipad because of the limited amount of storage they have. We had iPads for staff, the device name was the teachers name and we used Policy central (now called smoothwall monitor) which replaced the browser; it was pretty awful but there's a Smoothwall rep on here that has said they have updated it and the browser is now based on Firefox but I've never used it so can't comment on how much better it is. We mainly used PCs and banks of laptops which worked well with Policy Central monitoring along side our RM safety Net internet filtering. We did have a bank of android tablets but these were managed with Maraki in KIOSK mode with the APPS that we needed, there was no web browser on them. There were a handful of childrens iPads but again these were restricted to a handful of sites like childrens BBC for foundation stage children. Do note that Filtering and Monitoring are not the same thing, if a child types in Word that he wishes he wasnt being bullied etc... a normal internet filter isn't going to detect it you would need something like Smoothwall monitor for that but with the previso that it works best on PC, e.g. Apples eco system is far too locked down for them to offer the same level of protection on iPads as on a PC. It depends how invested you are in Apples eco system and how you currently use the iPads, it would probably be far easier to get a set of laptops and a monitoring solution like Smoothwall Monitor running and remove the browser from the iPads than it will be to setup the logins and manage the profiles on a set of iPads.
  9. They might be the only MDM provider to include it but they aren't the only internet / filtering provider that provides a filtering solution that follows the device so the devices internet connection is filtered outside of the school. RM SafetyNet Go - is one example The Dfe laptops (if you can call geobooks laptops) also had a cloud based internet filtering solution pre installed when they were delivered to schools. Even Sophos had an option for basic cloud based filtering. Smoothwall Monitor used to have a filtering solution built in but after Smoothwall purchased it from Policy Central / Future Digital they removed the filtering so now its only a monitoring tool.
  10. Eeek I dont know how your DSL is ok with that setup it's impossible to identify a child if theres a safeguarding concern, Ofsted might want a chat if they ever visit. I managed the networks at 2 large inner city primary schools: Nursery and Reception had a generic login with internet access restricted to a handful of pre approved sites they could not just browse the internet. Once Reception children had settled in they were given individual logins with a very simple password. Years 1 and 2 individual logins with slightly more complex passwords. Years 3, 4 ,5 and 6 individual logins and they created their own simple password. English was the second language for a lot of the children, unless you are a SEN school I can't see any reason why the children are sharing accounts, even at a SEN school I would expect the children to have individual accounts and the Teachers / TA's to help them login.
  11. Do you like working there and how much do you want to rock the boat? "the site manager had other ideas and we now have about 5 different NVRs spread all around the building" At the very least the school business manager would have processed the official order and it would have to have been approved by the head, most likely he was told by the head or a member of SLT that they wanted more CCTV cameras and SLT didn't feel the need to consult you. "The consultant now states that the three cameras I have in the server room, must also be added to the site manager's computer." I assume the consultant works for the company that installed the other kit, he has the ear of site manager and as far as the school is concerned the site manager is the CCTV operator. "The head has been passed this report and said can I either give the site manager access to these cameras or just have them disconnected and removed" That tells me the head doesn't really think it's your job to manage the CCTV and they might not want you to have access, is CCTV in your job description? You could just remove it as instructed and then wash your hands of the CCTV system, you don't have access and it's no longer your problem. The CCTV consultant might then decide the server room should have CCTV and install a system of their own... "On a site note, I regularly walk into the site manager's office to find he has left the CCTV viewer for one of his NVRs open and in full view of anyone who can walk into his office and he has either gone or left other colleauges watching it who are not listed as being able to view the CCTV on the School CCTV Policy." Can you prove this or is it his word against yours? You could: Make a formal complaint against the site manager to the head. Raise it with the school data protection officer. Make a formal complaint to the governors. Make a formal complaint against the school to the ICO. At one extreme the site manager gets fired, the other extreme is SLT don't believe you; expect any job requests you submit to the site team to get lost, any deliveries for IT to be left in a pile in the corner for a week before you get them and your bins never to get emptied. I even heard of a site manager that stuffed a dead mouse behind a classroom radiator when a teacher upset him... "we would have no way to identify if someone comes in and takes hot swappable HDDs from the server or steals our Paxton Access server." So the school uses Paxton and putting mag locks on the server room and site managers doors would be a lot cheaper than replacing 5 NVR's, suggesting it might even earn you browny points with SLT if you pitch it the right way. "We were advised that every time we access the CCTV system, we should log the date, time, what we were on it for and if anything was downloaded. This is listed in the school CCTV Policy under System Log. I have kept an Excel sheet from day one and I list everything, even firmware updates to cameras I perform as I am still accessing the cameras which show images." Great that you do all that, I was told to create CCTV accounts for the head, the business manager and both the caretakers who then decided they needed more monitors so they could leave the screens on despite being told that they are only supposed to be checked if theres been an incident or to check they are working correctly... Before I started the CCTV was managed by the site team then the site team changed, I had a new tech and when the police turned up etc... the site team would bring them to me to view the cam's or export footage for SLT. Then the head got a bee in her bonnet, the business manager got a council approved CCTV compmany in and NVR's started popping up all over the place. The approved CCTV company were given carte blanche to do what ever they wanted, they wired cam's into the back of existing network sockets leaving the socket in place, they set static IP's causing IP conflicts on the network, they set a password on the individual IP cam's that were causing the IP conflicts so I couldn't check or alter the settings and they refused to give the password to me saying they can't because they use the same password at every school... they ran unmarked cables all over the place plugged into comms cabs without permission, added their own mini network switches and left no documentation... "The site manager has no log at all" Suggest that as the site manager is now responsible for CCTV it would be a good idea for him to undertake training to obtain a SIA CCTV Licence. "and regularly leaves live camera views up for all to see on his desktop." Why doesn't his desktop screensaver lock the PC after a few minutes? Even SLT incuding the ICT lead would do this at the school I was at despite explaing why they shouldn't; I set a timed screen lock on all office user network accounts, at one point I did try it with teacher accounts with a longer grace period but was told by the head to remove it because too many teachers complained. Based on my experience with the council approved CCTV company, some installers are grossly incompetent; I explained to the lead installer multiple times what a DHCP server was and that dhcp reservations are needed. It went in one ear and out the other and he continued installing cams with static IPs with no reservations causing more IP conflicts. Only you can decide how much to rock the boat and whether the fall out is worth it; do you even have the time to manage the CCTV should they take the job off the site team and say its now your resposibility? When I complained to our business manager how many problems the cctv installers had caused she just said well you can fix it can't you... Well sure if I had nothing else to do for two weeks I could have gone round the whole school to find where the cams were, factory reset and reconfigured each one, traced and replaced their dodgy cabling. But at that point I was working on my own and simply didn't have the time, the best I could do was use the device Id's, try and find the mac's listed in dns and make dhcp reservations to mitigate some of the problems until the next time they came out and broke something else. One time I found foot prints on top of the server because they had been standing on it to access a NVR another time they stood on a monitor shelf in the server room ripping it off the wall. The week I left when I was made redundant the caretakers were begging for CCTV training, I didn't have the time with the jobs the head asked me to do before I left and my post had already been downgraded so training staff wasn't in my job description anyway so not my problem... Schools don't value ICT staff, they often don't listen to them when they give advice even when they are in a senior IT Operations Manager GR4 role but will fall over themselves when an external installer that doesn't even know what a DHCP server is clicks his fingers. It won't change until senior IT roles become part of the SLT team which is unlikely to ever happen in small schools with the constant budget constraints.
  12. Is that plastic cable protection in the plaster? I've only ever seen steel which is quiet resistant to masonary drill bits in case someone attempts to hang a shelf / cupboard / TV stand etc... in the wrong place.
  13. An electrician doing some work for my landlord managed to put a screw through a cable when he replaced a kitchen extractor fan which immediately tripped the RCD so he repaired it... Fast forward probably more than a year and the RCD tripped for no appararent reason, switched all the MCB's off, reset the RCD and switched them back on one at a time until it tripped again. It was the lighting circuit that also ran the extractor, pulled the spur fuse for the extractor and the RCD didn't trip. When they fitted the new extractor fan instead of using one that was the same size or plastering the hole first they had used a piece of plywood screwed to the wall to mount the fan. Got the multimeter out and there was a short between live and one of the screws holding the plywood. So the screw had been live since the electrician had fitted the fan, the RCD had tripped because it had been raining a lot so the normally insulated live screw was now imbedded in bricks that were damp enough to trip the RCD. Is the hob isolator switch on the island or on the wall, if it's on the wall you could disconnect the cable there which would help narrow down where the issue is. 1. Kitchen fitter screwed through a cable -- my money would be on this as well but you should be able to check for a short between the screw heads and live / neutral if they are accessible 2. Cable under floor was some how damaged when it was fitted but has got damp so is now tripping the RCD 3. Rats, mice, squirrel under floor have chewed a cable
  14. You can't rebuild a RAID 0 array, RAID 0 means theres Zero redundancy. You also can't just move drives between bays in an active array, the controller stores details of the virtual disk config on each drive in case the controller fails so that the controller can be replaced and the "foreign config" can be restored. One of the pages I pulled up said you can't hot swap drives when they are configured in RAID 0 and you have to reboot the server after any changes, so you should have probably used idrac to delete the failed drive then shut the server down before trying to replace it and make a new array and virtual disk. I'm guessing its an 8 bay server and the OS is on 1 drive with no redundancy and the other 7 bays were used for the 10TB sata data drives in Raid 0? In which case you need to rebuild / reconfigure the server, the OS needs to be in raid 1 as a minimum you can then use the remaining 6 bays in raid 5, 6 or 10 for your CCTV storage. I dont know if your raid controller will let you convert a standalone drive in to a RAID 1 pair but you will probably need to either reinstall the OS or restore it from a backup (if you have one). As others have said if the bays are faulty you need to contact Dell there's nothing anyone on here can do to help you; if the array config has been messed up by the failed drive and you then moving drives around you should be able to delete the virtual disks / array but might need to initialize / erase each drive using idrac but I can't tell you the exact steps from memory alone. You could always pull the lot stick them in a USB dock and erase them, delete all the configs on the raid controller, put the drives back in and start again. https://www.dell.com/support/kbdoc/en-us/000131039/poweredge-tutorials-physical-disks-and-raid-controller-perc-on-servers#disk https://www.dell.com/support/kbdoc/en-us/000131039/poweredge-tutorials-physical-disks-and-raid-controller-perc-on-servers#perc You will also need to speak to your DPO and tell them your CCTV system has failed and you have lost 60 days of CCTV because it was incorrectly configured, they will then have to decide whether it is necessary to inform the ICO. The DPO should also review the retention period because 60 days seems excessive and you have to be able to justify keeping the footage that long, once you have configured the CCTV array to use raid 5, 6 or 10 and the OS to use RAID 1 you will have less storage anyway.
  15. I doubt that they are SAS drives if they are 10TB each and I don't think SATA supports the same level of diagnostics. If you can't see the drives in iDrac they are probably toast but you could try pulling one and sticking it in a USB caddy to see if Windows detects it in disk management before you throw it in the recycling bin. Do you need 70TB of storage, thats a lot of cam footage you have lost which can't be recovered because it was in RAID 0.
  16. ^This^ I would update all the servers, network switches, Net2 controllers, WiFi controller / AP's, Computer Bios and Promethean boards during the school holidays not that anyone would ever notice; but I doubt any of that has been done since they made me redundant considering it was more than a year afer leaving when I was contacted by the school asking which phone I had used for Apple School Manager 2FA... So much for leaving them 3 sheets of A3 with all the login details on, not only had they disconnected the IT office phone it had been so long since anyone had logged in all the certs between ASM and Meraki would have expired
  17. Have you actually asked your suppliers what drives they have available in the capacity and speed you want because there might not be a lot of choice? SAS ? 2.5" / 3.5"? 7,200 / 10,000 /15,000 ? 6Gbps / 12 Gbps ? If you need 4TB drives for your array then SSD is probably out due to cost but its what I got the last time I ordered a server. What RAID configuration are you using, how many drives are in the array? 4TB drives are going to take a long time to rebuild if one fails, does your array have a spare hot swap so it rebuilds itself if one fails in the middle of a school holiday? I would also consider what drives your server manufacturer provide so they are supported by their firmware update tools rather than just grabbing third party ones. I've had drives fail in brand new servers just after it had been commisioned and I've had 10 year old servers never skip a beat; I don't think anyone can say ohhh you must get a Seagate or go for Fujitsu it won't fail because someone else will come along and tell you of the time their DC or MIS server went down because drive x failed and it took them 3 days to get an official order approved and another 2-3 days before it was delivered. I think I got a bunch of large seagates for an old raid 10 NAS when I needed more space for backups and got one spare that sat on a shelf until needed (which it was) but they were just enterprise class SATA drives and I would only use SAS in an actual server. 4TB+ 10k+ SAS drives are going to cost a pretty penny and you should consider getting a spare and leaving it on a shelf even if your array includes a hot spare for fall over even if you have an understanding business manager that's willing to order a replacement drive on the school credit card for next day delivery when one fails which is almost guaranteed to happen eventually. Just saw your update "Need something robust." Hate to tell you but there's no such thing, you spin something at 7,200 - 15,000 RPM eventually or within hours as I've had happen in a brand new server its going to break regardless of what name is on the label.
  18. I don't know MAC OS but does it let you reduce the size of the partition ie if you change it from 1000 GB to 10 GB is the apply button still greyed out?
  19. The school I was at wanted to live stream a RSC performance which was hosted on everyones favourite platform Vimeo. We were using RM safety net and there were quiet a few URLS that needed adding to the allowed list but from memory I managed to get it working so the live stream worked but they couldn't browse other videos. The advantage of RM safety net being that I had four different proxy / filtering levels to play with so I could make changes to one only applied to my network account for testing until I got it working the way I wanted. I think RM safety net also had a scheduled override option so the change only applied during a set time frame after which I removed access again. First thing I would do if I was in your boat and got another similar request would be to very clear with the teacher and DSL why Vimeo is normally blocked then if possible I'd try to get the tech support from the site they are trying to use to work directly with the ISP / filtering provider so you don't end up having to manually allow hundreds of videos. I can't remember which urls I allowed and which I blocked but I probably blocked the main Vimeo.com URL then added exceptions they have got url's for their cdn networks etc but I wouldn't blindly add them all becasue of the content they host; it would be a lot easier if Vimeo created a sub domain for approved educational videos: https://help.vimeo.com/hc/en-us/articles/12426098107793-Network-and-browser-requirements-for-viewing-streams I just had a quick look at the site and some videos won't play without being logged in becuase "this video isn't rated" which is a step in the right direction for safeguarding but I still wouldn't trust the site enough to unblock it. https://help.vimeo.com/hc/en-us/articles/12426157083537-Content-ratings
  20. If the two networks were already communicating over a WAN of some sort then the windows devices should already be able to connect to the existing DC on the other site. If not then they need to look at the Routers, firewalls, access controll lists on switches, and VLAN configurations, first step would be to contact the ISP for help but the two sites might not even have the same ISP...
  21. I’ve been a Technician, Network manager and ICT Operations manager in the education sector for more that 15 years then I was made redundant. Even with my experience this question leaves me scratching my head. When a teacher is off sick they will gladly pay hundreds of pounds a day for cover without even thinking about it but they don’t want to pay for ICT support. We all start some where but who are you a parent, governor, the schools ICT co-ordinator, the heads mate from down the pub that once fixed his laptop? There are an abundance of third party ICT companies for schools that will take on projects like this but there is a reason that they will charge £600+ a day. Are the two sites connected via a dedicated fibre link or point to point Wifi, do they have some sort of wan configured by the ISP, do the sites have layer 3 switches, are they using VLANS, what firewall is in place is it on site or cloud based, do the two sites even use the same ISP? You aren’t going to get a step by step answer for a question this complicated with so little information. At the second site, either the router or layer 3 switch will be providing DHCP and DNS to their chrome books so why can’t they use their windows devices? Laptops can be configured to cache login details when the DC isn’t available its why they still work when teachers take them home. If you mean the users can’t connect to their home directories or shared drives or get updates from the WSUS server that’s not just a matter of having a second DC all that will do is provide authentication and take over DHCP and DNS from the router. Yes its perfectly possible to connect multiple sites but its not something many of us will have had to do. Even then I would also be considering using something like Always on VPN instead particularly if there is a possibility of more sites being added in the future. The results I got from a quick google search on your suggested server showed they had SATA drives; I wouldn’t even consider a server that used SATA even if they are enterprise class SATA lacks features that SAS provides. I’d be looking at a server with SAS drives and a RAID controller as a minimum. If it is only being used as a DC and not as a file server then it doesn’t need anything like 2TB of storage and smaller enterprise SSD’s or NVME’s and a RAID controller would be a better solution.
  22. Yes you have made it clear that your school doesn't follow DfE guidelines and doesn't use a monitoring solution but in the LEA area I worked and in others it has been mandatory for years and no devices without the monitoring software installed are allowed; at some point your school will have to play catch up and improve its safeguarding. "If mobile or app technologies are used then you should apply a technical monitoring system to the devices, as your filtering system might not pick up mobile or app content. " Regardless changing the OS because the hardware is garbage doesn't stop the hardware from being garbage; ICT funding should be as important as staff funding SLT that thinks otherwise isn't fit for purpose.
  23. Monitoring is a DfE safeguarding requirement I don't know of any software the equivalent of Policy Central / Smoothwall monitor that runs on Linux if there is one tell us what it is. At the end of the day this is about SLT not funding ICT then complaining when the schools ICT is garbage.
  24. I use Mint at home on one of my computers and have spun up various edu distros over the years to look at them but are you really suggesting Linux is suitable in a school? How are going to manage them without group policy, AD etc? DfE guidelines say you should use monitoring as part of your safeguarding, the schools I worked at used Policy Central / Smoothwall Monitor which required client software installing on all of the windows PC's there was no equivalent Linux solution so how are you monitoring the PC's, what about teacher tools like Netsupport school and Printing solutions like Papercut will they and everything else the school uses including your MIS solution run on Linux? Depending on why they don’t meet W11 requirements you can use Rufus etc to install 11 but really schools need to accept that using 10 year old PCs is no longer acceptable and provide adequate funding. If schools had real ICT development plans instead of playing lip service to data protection and safeguarding then there shouldn’t be ancient computers in the school that don’t have TPM etc.. If you are getting rid or the servers wouldn’t Intune make more sense?
  25. I'm not a PAT tester but my previous microwave was stainless steel so the missing paint is unlikely to cause it to spark / get hot. I believe previously PAT testers were required to carry out radiation leak tests on Microwaves but this might of changed: "The IET Code of Practice has removed microwave leakage testing from its Fourth Edition, citing that it’s not an electrical problem. However, microwave leakage hazards still exist, and PAT testing companies may supplement their equipment with microwave leakage detectors." However that doesn't mean that microwaves in the workplace are exempt from leak tests, do you have the equipment to test them for radiation leaks? Personally I would say it failed visual inspection and tell them to buy a new one they aren't expensive. Reasoning: 1. Rusty surface will be hard to clean – food poisoning risk. 2. Rusty and deteriorating condition particularly near door increases risk of microwave radiation leak in the near future even if it currently passes. 3. Rusty surface could result in food being contaminated with metal particles.
×
×
  • Create New...