-
Posts
910 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Alis_Klar
-
PrimarySite under Juniper have fixed many of the issues with the old CMS and the designs are as good as anywhere else really . I was over-ruled on the choice as SLT wanted the Ofsted Detector function. Greenhouse are still very good for design and CMS is good. If anyone know if I will still be able to access my old site for a while after DNS migration that would be great!!
-
Hi, We are migrating from PrimarySite to Greenhouse for schools. Has anyone migrated away from PS before and know how they handle allowing access to the old website once the DNS migration has occurred. Do they have a temporary URL where we can still access the old content?
-
I thought passkeys did away with passwords altogether. How do we remember passwords generated by a password manager? I think it will fall back to password resets over e-mail so the e-mail account will remain the honey pot for attacks and users will probably have to remember the password for that account only. Or carry a FIDO U2F on their keyring as a backup. Not sure if Microsoft are merging "passwordless" with Passkeys? Keeper have written a critique of MS passwordless here https://www.keepersecurity.com/blog/2021/10/11/microsofts-passwordless-login-isnt-all-its-hyped-up-to-be/ Also ArsTechnica have a good article and the comment section is illuminating https://arstechnica.com/information-technology/2022/10/passkeys-microsoft-apple-and-googles-password-killer-are-finally-here
-
https://passkeys.dev/device-support/ Ah! This site is very helpful. Cross device support seems a bit of a Hodge-podge currently but it's got to get better.
-
Hi, Looked into this a bit more. If you have FIDO U2F stick Windows will store your Passkeys there. Also chrome on iOS uses the iOS keystore not its own internal/Google one AFAIK. There is a site here to try out Passkeys in a sandboxed safe environment. It seems to rely on sending you a 6 digit code by e-mail to register if hardware fails etc. Not sure if other developers would take this option or what protocol allows for account recovery etc. https://www.passkeys.io/
-
Has anyone started using passkeys instead of 2FA on their personal Google accounts? https://arstechnica.com/information-technology/2022/10/passkeys-microsoft-apple-and-googles-password-killer-are-finally-here/ https://www.androidpolice.com/google-passkeys-replace-passwords-guide-setup/ https://developers.google.com/identity/passkeys https://developer.apple.com/passkeys/ How could we deploy passkeys in schools in future? Will we require a cheap FIDO device or similar? Also I see a weak link in that device biometrics fall back to a lock screen PIN so are all our creds protected by a 6 digit or 4 digit pincode? How does it work when I loose my only phone?
-
Hi, Just to update, went with MikroTik Cube pre-configured pair. They basically work out of the box although their documentation is DIRE! Which would be ok but the user interface (RouterOS) is very confusing. https://mikrotik.com/product/wireless_wire_cube_pro These work at 60GHz (802.11ay) and fall back to 5GHz Wifi in bad weather. I had trouble finding out the max eirp of the MikroTik from their specs so they can be used without a 60GHz OfCom licence as they're below 40 dBm eirp. See https://www.broadbandbuyer.com/advice/4527-60ghz-ehf-ofcom-licensing/ Not tested the 5GHz fallback in snow yet but although MikroTik have poor documentation their stuff seems rock solid. Problem I had was I changed the wifi password from the default one and it broke the Wifi link (60GHz link was unaffected) and couldn't work out how to fix it. I used their support and they advised that resetting the units restored the pairing from factory. I was worried it might fully wipe the config but support were correct.
-
Looking at this again, sorry for bump. I enquired with Exa and they quoted me nearly as much as a new school connection for FTTC. There will only be <5 people working from this annexe! Need something barebones cheap. Was thinking of getting Daisy Business Broadband and use pfSence NetGate to direct all traffic to the VPN. I tested this out from home connection and unfortunately pfSense assumes IPsec peer to peer tunneling. I haven't been able to work out what of the myriad of options I can use on the pfSense I wanted to make use of Exa's remote access VPN using FortiGate but the only credentials they supplied were: Remote Gateway Preshared key Account (in form of e-mail address) Password They were able to accommodate an iOS client by disabling "perfect forward secrecy" on their gateway end for our school. So perhaps they would help me out but think that a permanently on VPN may be misusing this facility. Also a permanently connected VPN would be more vulnerable to attack with a short password and short preshared key. pfSense seems only capable of connecting to a IPsec tunnel or a OpenVPN for NordVPN etc it does not seem geared up for remote access type VPNs. I may contact EXA again and ask if they can setup VPN tunnel rather than remote access type tunnel which would be more secure and also technically possible.
-
Could be TLS/SSL inspection/certs causing the issue or proxy filtering. Need to whitelist all Apple APNS and MDM servers.
-
We switched from Lightspeed to JAMF and biggest thing we noticed was when you make a change it happens on the iPad immediately not after a minute wait as with Lightspeed. Also no more slow interface. Also it works more like GPOs where you can apply multiple profiles to a single group or device. Jamf is just better than Lightspeed in most ways.
-
Sorry off topic but please share how you did that as we deployed 1:1 Chromebooks during lockdown and still have O365 but want them to work better together with some type of SSO arrangement.
-
I have been having exactly the same thoughts since I rolled out 1:1 Chromebooks at my large primary. Chromebooks were the only choice during the pandemic for rapid roll out. No way could we have deployed 500 windows devices and my confidence/experience with InTune Azure etc is poor. Google admin is slightly frustrating in terms of surfacing user activities. We have the same issues with breakages and not bringing them into school. They are still seen as free time devices primarily by teachers. I'm pretty tempted to convert our existing Windows shared machines to Chrome too as the log in times are fast enough.
-
Thanks everyone for their valued input. Can anyone recommend a installer of PtP Wireless in the Midlands?
-
If they were both EXA why did you need the VPN? Can't they do an internal static route? Or is the VPN their way of doing this? Also did they configure the DHCP helper and NAT for you or was this all on your own?
-
Yes we do have line of sight. I did think about WiFi p2p but was worried that poor weather would affect it and it might end up being nearly as expensive as fibre. https://store.ui.com/products/ubb-xg seem pricey but they do cheaper one too. https://www.4gon.co.uk/ubiquiti-airmax-powerbeam-c-193_981_935.html Anyone used these?
-
PLAN A We have taken over an adjacent small building and need to expand the network. We had an extortionate quote for a fibre link. I had the ideas of going to our ISP (EXA) and asking for another broadband connection and having a static route so it appears as a subnet so it appears on our LAN. There won't be alot of devices in the new building and it may even be empty a lot of the time. PLAN B EXA haven't come back to me yet but could I use any ISP (£50/mth for Daisy FTTC (not leased line) and buy a router with a VPN client on it and create a site to site VPN between the sites? For home working we already use EXA's IPsec VPN. How can i do NAT and DHCP relay etc. I am thinking of getting a pfsense hardware router which features a IPsec client. E.g. https://shop.netgate.com/products/2100-base-pfsense We need to have cloud based VOIP and filtered internet working via EXA. We will also have a Wifi AP and 1 copier using PaperCut. There will be 5 people max working from this building.
-
Me Too! Great suggestion. Did you try requesting this feature from ScholarPack. I wonder since they have been taken over by Arbor they will pull in more code/features from them. I guess it's pretty hard to do a full merge more likely they will replace SP with Arbor going forward.
-
Aaaahhh Rite. Never actually installed a new wall mounted Cab. Only ever done tall server ones which also had depth adjustment. Thanks for rapid responses
-
Is there some sort of adapter to mount a 1U switch deeper in the cabinet so closing the door does not trap cables so much. For some fibre connectors they protrude more than copper and closing the door risks breaking the fibre. I found these adapters but they only seem to work for 4 port server installs where the server is too short to reach back posts of a deep server rack. https://uk.rs-online.com/web/p/rack-mounting-hardware/1863277 Failing that are there cabinets where you can adjust the depth of the 19" rack fixing posts (wrong term I know) but this doesnt' help where you are adding a new switch to a previously populated cabinet and you don't want to rip everything out.
-
Get a good fitter. Don't fit them to really old doors. They prefer new straight doors with new door frames. If you get PaxLocks always get them with Key Override as they break down especially if they are not fitted perfectly. You can fit matched cylinders so multiple doors can be opened with one key. Also do not press the handle before scanning your card/token/fob as it will break the mechanism eventually. Keep on top of battery replacements too.
-
Great tip, more professional looking than I was expecting from QNAP. Although I think only recent QNAP models are supported.
-
Give Microsoft FancyZones PowerToy a try
-
Yeah that's my setup. Although I have upgraded one of the pair to 19" 16:9 as lots of apps assume widescreen these days. I need to try two widescreen monitors in vertical orientation some day but finding mounts is expensive.
-
If a supplier says it follows the Framework can you go directly to them without a tender etc. Some say they follow the Direct Award option. IF I go though the Tender how many companies will quote? Can you restrict it and will you get harassing sales calls etc?
