Jump to content

emdrum

Members
  • Posts

    19
  • Joined

  • Last visited

Everything posted by emdrum

  1. It's not necessarily the access points that you need to worry about. iPads are aimed at the domestic market and as such will "hang on" to a wi-fi signal from an AP even if they can barely see it and you are standing next to a much better AP. This is because in a domestic environment you don't want them trying to hop onto your neighbour's Wi-Fi, you want them to stay attached to your home router, but in a school this is a disadvantage. What you need is a controller that will look at the signal from the AP and if it gets weak, bounce the iPad off that AP onto another one with a better signal. The controller has to do this because the AP cannot tell what other APs the iPad can see. There are controllers from Fortinet (Meru) and Ruckus that we have tested and manage this well, and some other manufacturers, but most Wi-Fi is intended for an office environment where people stay broadly in the same place - completely unlike a school. We regularly have 1,300+ devices on a campus-wide network covering five sites and it's fine.
  2. Hi jahilton2002, I don't want to teach my grandmother to suck eggs, but in my opinion there is a difference between capacity planning and future-proofing. Capacity planning necessarily involves a degree of speculation about what the future is going to be like, but is based on the best information available and is tied into your future strategy. Future-proofing is a marketing term to promote stuff that may never be used. In all my experience the future has never looked like I expected it to, and it probably never will. There is no proofing against it. And by the time you get to the future, their will almost certainly be options available to you that are not available to you now. So the first question is, how much of the 4Gb are you using at the moment? Are you utilising what you have? A good way of testing this is to mirror the ports that connect your edge switches (the LACP trunks) and put that traffic through an analyser such as Colasoft's Capsa. That will show you what is actually going on. You could also use some SNMP tools such as the free versions of Spiceworks or ManageEngine. Unless your Edge links are at least at 50% utilisation then you don't need 10Gb and more importantly it won't solve the problem that's driving the purchase.. If they are greater than 50% utilisation, then the second question is why? How much of that traffic actually needs to be there? Are all your edges on separate VLANs so that you don't have broadcast traffic from one area drowning out the traffic from another? If you haven't segmented your network successfully then upgrading your switches is unlikely to help. The third question is, what are you expecting to do that will use the 10Gb bandwidth to your edge switches? How will this bandwidth be used. Bear in mind that if your strategy includes the Cloud then whatever you do with that part of your infrastructure will be limited by your Internet connection. A UI will only take you so far. There are options in the CLI that will never be fully exposed in the UI. It's worth the effort to learn it and understand it. Bear that in mind. There are plenty of people willing to help, here and elsewhere. Hope that helps. Thanks Mike
  3. Hi jahilton2002, I don't want to teach my grandmother to suck eggs, but in my opinion there is a difference between capacity planning and future-proofing. Capacity planning necessarily involves a degree of speculation about what the future is going to be like, but is based on the best information available and is tied into your future strategy. Future-proofing is a marketing term to promote stuff that may never be used. In all my experience the future has never looked like I expected it to, and it probably never will. There is no proofing against it. And by the time you get to the future, their will almost certainly be options available to you that are not available to you now. So the first question is, how much of the 4Gb are you using at the moment? Are you utilising what you have? A good way of testing this is to mirror the ports that connect your edge switches (the LACP trunks) and put that traffic through an analyser such as Colasoft's Capsa. That will show you what is actually going on. You could also use some SNMP tools such as the free versions of Spiceworks or ManageEngine. Unless your Edge links are at least at 50% utilisation then you don't need 10Gb and more importantly it won't solve the problem that's driving the purchase.. If they are greater than 50% utilisation, then the second question is why? How much of that traffic actually needs to be there? Are all your edges on separate VLANs so that you don't have broadcast traffic from one area drowning out the traffic from another? If you haven't segmented your network successfully then upgrading your switches is unlikely to help. The third question is, what are you expecting to do that will use the 10Gb bandwidth to your edge switches? How will this bandwidth be used. Bear in mind that if your strategy includes the Cloud then whatever you do with that part of your infrastructure will be limited by your Internet connection. A UI will only take you so far. There are options in the CLI that will never be fully exposed in the UI. It's worth the effort to learn it and understand it. Bear that in mind. There are plenty of people willing to help, here and elsewhere. Hope that helps. Thanks Mike
  4. All gone. Thanks.
  5. Hi All, We have a bunch of HP MSM wireless kit which is surprus to requirements and are offering it free to collect from Bedfordshire. It includes MSM460s MSM466 with the external aerial connections and even a couple of MSM466R ruggedized external APs, along with MSM765 dual controllers. They have to go, so PM me urgently if you are interested. Thanks, Mike
  6. +1 for Meru. One of our schools is getting rid of Aruba after a number of issues. We have a Meru solution with 1000+ users and it performs well. Performance is dependent on so many variables, wall thickness and material, other networks, internal infrastructure, etc etc...
  7. I echo what Chris has said. Ubiquiti NanoBeam are inexpensive (less expensive than an AP) and work well.
  8. We have a Meru system (I'm not associated with the sponsors, and this was before the Fortinet acquisition) with over 90 APs and primary and fail-over controllers across two different sites. You can roam seamlessly across the full campus without missing a beat (and people do). We regularly have over 1,000 users on the wireless at once and it copes beautifully. Management works well, and it integrates with the rest of the network very nicely. When we have any issues (which is rare and mostly caused by something else not functioning correctly) there is uproar because our staff and students have the expectation that wireless 'just works everywhere'. We also looked at Ruckus and they were our second choice. A good solution and similarly priced, with an excellent management interface, but Meru won out on the virtual cell technology and seamless roaming for tablets and laptops. Hope that helps.
  9. Does the Aruba tunnel traffic back to the controller, or does it bridge it onto the local LAN? That would affect the architecture that you implement. If it's tunneled then you should route everything back through the core as that's presumably where your Aruba controller is plugged in. You could then get the core switch to route the traffic onto the appropriate wired vlans so that they can use AirPlay. If you set up vlans for each physical area then the traffic for that area will be re-routed back to that area and you'll achieve a level of compartmentalisation. If it's bridged onto a local vlan then there's no advantage to routing through the core and you could implement localized subnets between the wired and wireless devices so that the internal traffic never leaves that switch and only routes server and external access through the core. Each of your local subnets then becomes an independent broadcast domain. Hope that helps.
  10. Hi Emil, It sounds like you have got the laptop configured to use the local windows authentication for the 802.1x. It may then be trying to use the local user to authenticate to the domain. Manage Wireless Networks - Properties Security Tab 802.1x Advanced Settings Specify the authentication mode - depending on the way you are set up Remember the laptop may need network access to authenticate, and may use different authentication for the laptop than the NPS. You may have to set up a machine authentication VLAN which then switches to the user VLAN when the user logs in. Hope that helps.
  11. It would help if we had more information: What's the IP address, netmask and default gateway of the devices you are pinging from and to? Are they on different subnets? Is routing enabled? Have you tried running traceroute to the device - if so, what result? Are there multiple vlans? If so what is the vlan status of each of the ports between your PC and the printer? How many other devices are on the same subnet? What kind of devices are they? From what you said, it sounds like you have your printers running on the same subnet as your laptops and as your access points. My own guess is that you've got either a rogue device broadcasting rubbish or a broadcast storm on your network. If you watch the lights on the switches, are they flashing on and off or are they on pretty much all the time? If it were a network loop then I think we'd see a much greater level of disruption. Spanning tree would be a good idea in any case, but it won't fix a broadcast storm.
  12. Hi SebD, This sounds like a routing issue to me, though I would need a better understanding of your topology to be able to diagnose the issue better. It sounds like you should be routing the different subnets to some sort of core switch and then directing that through your Smoothwall as default gateway from there, rather than using DNS to give different IPs for the Smoothwall on different subnets. I may have misunderstood, so forgive me if I'm not addressing the issue properly.
  13. Hi Meldrew, Yes, we discovered the bonjour problem during the trial (which was well worth doing as we learned a lot from running it) and we now hav a network segmented into VLANs with a bonjour re-broadcaster selectively broadcasting bonjour information between VLANS where appropriate. It works very well, though it took us a litle while to work out how to zone the network so that if you were on the wireless in a classroom you saw only the devices near to you. Works great now, though.
  14. We have had iPads in school for over two years - initially as three classroom sets in trolleys, subsequently with a single year group on a 1:1 basis as a trial, and now being deployed as a 1:1 device throughout the school. We currently have in the region of about 700 iPads in the school. Yes, we have made mistakes but we have learned how to manage them and what can and can't be done. Like anything else, it has its advantages and disadvantages. I sense a lot of hostility towards iPads in the forum and it seems that most see them as a headache. This is true of any new technology that is introduced into an environment it was not originally intended for. We have all had PCs for decades, but I remember when laptops were introduced and all the same worries were present - people would break them, they would lose them, they wouldn't be reliable, etc. And this was true to an extent until the technology matured and the tools to manage them became available. With iPads it's still early days, but we're getting there. Managing them as class sets is an issue because they are a 1:1 device. They are designed to give a personal experience, and if you are changing the person using it at every lesson then you are unlikely to get the best from them. Having said that, they have the best ecosystem of apps for education of any device out there. There are far more apps suitable for use with children and students on the ipad than there are on Android, and those are the only 2 eco systems with any traction. The ipads become the electronic school-bag, with your homework planner, your classwork, your reference books, your email conversations with your teachers, your trip plans, your projects. It's all on one device. And yes, a percentage will get broken until they learn to look after them. That happens with netbooks and text books and everything else. The students are still children and will require just as much supervision and guidance as they always did. Good cases are essential. Making use of the Apple volume purchase programme helps with the budgets. A good wireless network is critical and you need to be able to manage it. Good control over your internet access, with filtering and logging is essential. You have to be able to diagnose issues as they occur - the last thing you want is for someone to be doing something brilliant and innovative only to be told it won't work on the school network. The tablet is a natural device for education, though. The first time you get the kids to video their science experiments, or interview each other for a history project, or take them out onto the field to help coach them for sports, you see the difference. All the older students already have phones and they're used to carrying their world around with them. It feels natural to them. The real challenge then becomes how you tap into that enthusiasm and use it to accelerate their learning and improve their opportunities in life.
  15. One of the problems that we found with apps is that they will request a port range from the destination server - eg: apple.com:6500-6600 with the expectation that the server will respond with a port allocation. This is to enable load balancing and increase throughput, and applies particularly to things like the App Store etc. but also to other services - YouTube is a classic example of this. The proxies are generally not configured to allow port range requests - they want a source device to request a particular server on a specific port eg: apple.com:6510, which is not what is happening, so while it isn't exactly blocked, it doesn't work either. Try enabling port range requests on your proxy and see if that helps. Cheers.
  16. We had issues like this, but we are not using Smoothwall. The issue is that the devices are requesting ranges of ports, which many firewalls do not allow by default. If you can enable port range requests, do so, then try again. Hope that works.
  17. Just thought I'd post this in case anyone else encounters the problems we've been having with the playing of media content on iPads in school. This may affect other tablets too, but I haven't been able to test others. Issue: Netbooks and computers can use YouTube, but iPads fail with a message "This video is currently unavailable". This can happen with some of the stranger formats uploaded onto YouTube, but this was across the board. There were very few pieces of content that would play and those that would play were very old. There is a huge amount of discussion about this on the internet, much of it pointing the finger at either Apple of Google as the party at fault. One of the key things for us, though, is that this worked outside school - teachers could use YouTube at home, but not in the classroom. However, there was no issue with playing the same content on netbooks, laptops or desktop computers. The problem was further compounded when iPads were not able to play sample material from iTunes - song clips, that kind of thing. This would simply not play, but again, worked fine outside school. Resolution: The issue was finally resolved by changing a setting on the firewall to Allow Port Range Requests Through Unmodified. Apparently both YouTube and iTunes on iPad request a port range rather than a port, and this gets blocked unless this setting is enabled. Having enabled it, all of these problems have pretty much evaporated. It's worth checking that your firewall allows port range requests if you're having these sorts of problems. All the best, Mike
      • 2
      • Thanks
×
×
  • Create New...