Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

smarties11

Members
  • Posts

    647
  • Joined

  • Last visited

Reputation

2,789 Excellent

About smarties11

Personal Information

  • Location
    UK

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. Good news on the cnMaestro side, particularly where they mention migration to on-prem, hopefully confirms their commitment to a new on-prem release that isn't cloud anchored. For us though the biggest issue is still lack of support and inability to maintain ongoing compliance. This could change I suppose if there is a buyer for enterprise Wi-Fi but I fear a buyer might dump support for existing products once they've reached any minimum periods agreed in a sale.
  2. I think cnMaestro going with the point to point stuff tells us all we need to know about enterprise WiFi. Clearly there will be no rescue for this element now 😞 If cnMaestro is maintained by Airspan for a while then it gives some breathing space, but we've still just bought a brand new enterprise WiFi solution that is dead in the water. DfE state that all hardware and software should be in active support as part of their technology standards and the same is true of CE/CE+. Compliance cannot be achieved. I still can't believe the timing of this, only 4 weeks ago we were mounting the new APs 😞
  3. Oh no 😞 Our experience on the deployment side has been really positive. And it's performing really well. But that's not much use if the whole ecosystem is shelved 😞 Is there anything I can help with? Could it be interference - have you scaled back your radio power at all. Redway recommended the following for us (with an AP in each classroom) - 2.4ghz - 8 to 14dBm, 20Mhz channel width - 5ghz - 11 to 17dBm, 40Mhz channel width (with channels 144 and 165 turned off) - 6ghz - 12 to 18dBm, 80Mhz channel width
  4. We are CE+ certified here and are 11-18. Just coming up to our third renewal. Personally I don't think it will be too long before the DfE mandate CE in Schools as part of their digital and technology standards. Although I know some schools just "tick the boxes" where CE is self certified - my daughter's new school for example are CE certified across the whole trust but her account doesn't have MFA enabled.... Anyway, back on topic - we received all of our APs, we're just waiting for a single PoE injector for a single 55X AP which is in a dense room as our switches are PoE+ not PoE++. Might have to scour eBay!
  5. I think the insurmountable issue here is ongoing compliance. A local controller will solve the immediate problem of the cloud controller going dark, but how long will it be before a security vulnerability is discovered in either the controller itself or the WAP firmware? If that vulnerability carries a CVSS score of 7.0 or higher, there goes any realistic chance of maintaining Cyber Essentials or Cyber Essentials Plus accreditation. Unless there is a buy out from a competitor I don't see how schools will be able to continue with this solution for anything more than a stop gap. Out of interest, how many others are in the same position as me, having had a brand-new Cambium deployment installed as recently as August? I'm massively regretting not sticking with Ruckus now 😭
  6. There is an onprem version of cnMaestro, however in my quick research this evening it looks like it has to be activated via Cambium servers first. It might be worth spinning one up now and activating and then powering down in case it's needed in the future? The biggest issue I think is ongoing development and bug fixes. If this is abandoned then how long will it be until the solution is effectively useless because there are so many bugs / incompatibilities with newer devices etc? We ditched Ruckus for Cambium as it represented a ~£4k total saving Y1-Y5 and then at least £7k total saving Y6-Y10 once Ruckus annual support became payable. I really hope we haven't made the wrong decision. We're really happy with it as a solution, it has been straightforward to deploy and has been performing really well. If it does get purchased by a competitor then presumably the competitor will just want to integrate the APs into their own cloud platform (like Cambium did when they bought Xirrus)
  7. FFS, how typical is this after deploying our solution over the summer 🙄 Fingers crossed that there is an interested buyer. Might be wise to buy a few spare APs for any future warranty issues!
  8. Anyone seeing issues today with local SIMS? This morning SIMS was really slow for users and occasionally hanging for a couple of minutes. Noticed that the CPU usage was constantly high for sqlservr.exe on the server. Rebooted, has been fine all day - now it is doing the same. Just wondering if there has been another issue with the Services Manager or anything else?
  9. Hi Rob, Thanks for your insights! If we can't get the captive portal working then I think we will likely go down a similar route. In addition to lockouts, we also enforce password changes every 45 days, so we'd likely need to consider not doing this anymore and being less aggressive on the lockout policy. As you say, with Entra / MFA these things are less important now, but I feel still a consideration for the case of an on-site brute force from another student etc. Appreciate your input, it's definitely some food for thought 🙂
  10. @FragglePete @RobFuller Thank you both! Are you doing this with an 802.1X SSID or are you using OWE with a splash page (captive portal)? We are trying to achieve the latter and it all works beautifully on a single AP but when you roam the client to the next AP, internet connection is lost. SmoothWall then sees the traffic from that client as unauthenticated. So there is an issue with the authentication/accounting packets when roaming. I have Lee at Redway and Cambium looking at it for us, just wondering if there was any knowledge here from someone who has achieved the same. We are using full 802.1X radius to NPS and accounting to SmoothWall for our staff SSID and that roams fine. But reluctant to use this method for students as it's more complicated for them to sign in, and when users change passwords and forget to update wireless profile on all their devices it triggers our account lockout policies. Plus there's nothing to stop a sixth form student (BYOD allowed) signing in a lower school student (BYOD not allowed), a daily captive portal sign in hinders this. The account lockout is already a bit of an admin burden on our staff SSID although we have them fairly well trained now! Thank you ☺️
  11. Hi All, I was just wondering - those of you who replied to say you are using Cambium - are any of you using a splash page for your student BYOD Wi-Fi, sending RADIUS auth to NPS and then RADIUS accounting packets to SmoothWall (or another web filter) to apply filtering policy? This is the only bit we're struggling to get working correctly and I wondered if anyone has any tips to share 🙂 Thanks Andy
  12. Thank you to everyone who has responded. The overwhelmingly positive support of Cambium has been really reassuring, and we have decided to go with them for our new deployment 🙂
  13. Yes, we have received an alert since turning off DEX.
  14. You are an absolute legend! Turned off and my frozen session immediately opened. Thank you 🙂 This is bad news for SIMS, though. They're already in dodgy territory by forcing us over to Next Gen for certain modules when the whole system is far from ready. Thanks again
  15. We're seeing login issues with SIMS (local) today. I rebooted the server first thing, that fixed it. Then it happened again later on. Again, a reboot fixed. Happened again since, so I am looking now for the cause. Users logged into SIMS are not affected. They can continue to work no problem. But new users can't login. There are no errors; it accepts the password (and tells you if it is wrong) and then you just get the SIMS splash screen forever. No clues in the event logs. I have logged a case with SIMS but I am wondering if anyone else has seen this issue?
×
×
  • Create New...