-
Posts
1,738 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by IrritableTech
-
Google docs accidental sharing
IrritableTech replied to JohnRMoore's topic in Network and Classroom Management
We both set a profile picture for our pupil accounts - the school logo with School Name and Pupil written across it. We also add "School Initials Student" to the first name field of the account. For example... KHS Student Joe Bloggs would appear in the contact list. The profile picture is easily set for all members of a group using GAM. -
We’re currently deploying twenty odd EDUs because we needed a PA and we’re also having to deploy more densely due to audio levels rather than WiFi. Our intention is to reduce the 2.4GHz power, but leave the 5GHz as it is. There are more channels to play with at 5GHz and it travels less well. Having three or four to test should give you the info you need. Just be aware that it looks like the UK distributes are selling off their EDU stock, presumably because they’re not popular. Ubnt haven’t announced them as EOL though.
-
Unifi, SSID and VLANS: some newbie questions
IrritableTech replied to newpersn's topic in Wireless Networks
We’re just in the process of putting in a unifi wireless network. We’ve basically set the ports as such... Untagged in a Unifi Vlan (for AP comms) Tagged in each vlan which is assigned to a SSID (or in our case dynamic vlan). So I expect you’d set your AP switch ports to untagged 2 and tagged 6 & 8. Then you can create your SSIDs and tag the appropriate vlan in the wireless network settings. All our unifi kit came from linitx because they had the stock we needed, but you have to pay up front. Did buy some test equipment from MSDist and they’ll happily send an invoice. -
I've had similar trouble. The last two years I've bought Grafters Contractor 4 eye safety shoes and they've lasted almost exactly a year until they crack along the ball of my foot. This year I decided to get some Grafter Uniform Safety Shoes which have very similar soles to Dr Martens they've split in the last week - I started wearing them in January :-(
-
The original UAP is still supported which has been out years and years. The first wave of ac points aren’t going to be supported for long, but I’m not sure how many really sold. So it’s hard to say. I suspect the ac-pros will be supported for some time. Fingers crossed because we’ve just bought 20 of them.
- 62 replies
-
- recommendation
- system
-
(and 1 more)
Tagged with:
-
We’re currently replacing a ruckus system (which has served us well for six years) with a unifi install. The list of features isn’t as long as the big brand names, but the bang for buck is hard to beat. The unifi controller is limited to 1gb of ram by default, unless you unpick the conf files.
- 62 replies
-
- recommendation
- system
-
(and 1 more)
Tagged with:
-
Google GSuite and GDPR - Your view
IrritableTech replied to rad's topic in Data Protection & Information Handling
Google allows your users to remain compliant as long as they follow your procedures. The service it's self can be compliant, users making their google sheet of their class progress list open to 'anyone on the web' would be a breech. -
We’re pushing a more dense deployment than we might normally due to the audio level of the EDU units - so we don’t need the additional device capability of the HD units. The EDUs are essentially a AC-PRO unit with a speaker attached. I’m not convinced that the HD units will sustain the 500+ clients in a real environment, nor the 200+ claimed of the PRO kit, better to add more APs on lower power in most situations I think if you have a dense device environment. As for speed, both only currently use a single 1gbit up link to my knowledge. Unifi is priced so that if you see a pinch point in a year or two it’s cheap enough to upgrade these areas without a large cap ex bid and you can run a mixed environment easily. You might argue to help with continued improvements and development we should keep buying the hardware. Would it be ok swapping netgear for unifi - probably. Depends on the feature set you’re used to. I’d be interested to hear of heat mapping software too. The tool I used to use is well out of development now.
-
WPAD is automatic configuration - no user involvement. I think you;re confusing this with PAC or manually setting a proxy.
-
Depends on your infrastructure. We could for example block port 80 and 443 at the edge firewall and only allow a proxy port.
-
WPAD is implemented at the DHCP and DNS level of your network rather than the unifi controller. This is a handy starting point... https://findproxyforurl.com/wpad-introduction/
-
WPAD has nothing to do with the Unifi guest portal - it's a DHCP thing. From the reading I've done and the last few years of experience I don't believe WPAD works on android - are you suggesting otherwise, because if so I'd be keen to hear?
-
You can use WPAD which will work for most apple and windows devices. Sadly Android doesn't support it though and the user must manually configure a proxy.
-
The single SSID really. I think it was Meraki who released a white paper explaining that more than four SSIDs is a bad idea - it creates a lot of interference broadcasting all the SSIDs on multiple APs. Having a single SSID for 95% of my clients seems sensible. All our domain connected pcs, all our byod devices can just connect to ‘school wifi’. Guest will connect to a guest network though so we can use the captive portal and issue vouchers. The only other ssid we may need is one for our cashless catering.
-
I can only go on what we paid six years ago for the ruckus (25 7363’s and a ZD3000) which was nearly £25k and today the 20 ac pros, 23 ac edu’s, five ac mesh, five US-8-60w switches and 2 NSM5s which was a little over £7k. We’ve spun up a new server for the unifi, one for radius and another for freePBX (so we can tannoy to the EDUs from our voip system) but these didn’t cost us anything per se. Using radius you can dynamically assign a VLAN based on various parameters, but we’ll do it based on security group. Except in the case of our school owned WiFi machines which will be achieved based on their domain membership. So users will sign into our WiFi, and depending on if they are admin, staff or post 16 they’ll be assigned a different vlan. This will segregate their traffic, allow slightly different access lists on our switch and obviously filter the internet accordingly. Machines will to be assigned a vlan which will allow them to connect to the network in the same manner as wired clients. I think we’ve seven now... hope to leave just three.
-
In the next few weeks we’ll be replacing 25 ruckus APs and a ZD3000 with 43 unifi access points. 20 AC Pro and 23 AC EDUs. A couple of our buildings don’t have a tannoy, so this will tick a couple of boxes - although the uk distributors seem to be dropping the EDUs from their stock lists. We’ve also got a few AC-Mesh to mount outside, a M5 point to point link and a few of the little 8 port PoE switches to manage as well. We’ll be reducing our SSID count by using radius and dynamic VLANs. All the testing has gone well and fingers crossed the deployment will as well!
-
Netsweeper with Schools Broadband
IrritableTech replied to TMBS's topic in Internet Related/Filtering/Firewall
Thank you @BrotherSidious that is extremely useful to know pre-migration. Does anyone have answers and experience of the following? Can we use our radius server to authenticate our BYOD users against the filter? Or from reading the post above does the auth portal have to get involved to convert the username? I know there is an issue at the moment with the auth portal and BYOD and that the current work around is to setup an additional un-authed proxy port and set traffic to be filtered at a particular level. Can one proxy be used to filter two IP subnets at two distinct filtering levels (I'm thinking Staff BYOD and 6th form) or will I need two additional proxy ports? Is it possible to bypass the proxy (assuming fortinet isn't blocking 80&443) if we find a piece of legacy software or a device that doesn't like proxies? -
You should be able to achieve this with IFTTT. If new photo on instagram by me Then create new photo post on wordpress.
-
Ruckus - BYOD with Netsweeper and SchoolsBroadband
IrritableTech replied to tj2419's topic in Wireless Networks
Actually it is in the hot spot service settings (or at least it is on our old firmware) now I've had chance to log in. -
Ruckus - BYOD with Netsweeper and SchoolsBroadband
IrritableTech replied to tj2419's topic in Wireless Networks
I’m not at work (snow day) but the wlan settings allow for a ‘once the user has logged in send them to their original request or here...’ The same page can offer the info for the proxy in case wpad doesn’t implement. We’re just about to scrap our ruckus for Unifi and will be moving from lightspeed over the same holiday - so our users are going to be very confused! -
Ruckus - BYOD with Netsweeper and SchoolsBroadband
IrritableTech replied to tj2419's topic in Wireless Networks
Our intention is probably to deliver the users to a “thank you for signing in now please install this certificate” page. You can do this through ruckus quite easily. Different devices might deal with that in different ways though. We’re keeping a close eye on the user authentication to netsweeper which we hope will develop before Easter -
Proxy/Guest Networks/Ruckus
IrritableTech replied to Tesla's topic in Internet Related/Filtering/Firewall
You can setup your firewall to only allow BYOD web traffic to go to your proxies IP... Or in fact on Ruckus you can setup an access list to do the same. It is tricky however with BYOD and wpad it seems intermittent - and then there is the certificate you need to inspect secure traffic. -
I had to go through this same process a few months ago. HPE gave me the best upgrade route which meant I had three to apply. All went well except for the last one - the switch didn’t reboot successfully. The next morning I reset the switch and that was fine, but our hyper-v cluster wasn’t happy because each server had been isolated from each other for a number of hours. After that issue we created another route for the cluster traffic to add some redundancy. Different switch, different issue, but if you’re in a similar situation it may be worth considering.
-
I'll give you £25 for it :-)
-
Never used it and I'm not really answering your question but are you aware of any AD schema updates since June 2016? I bet there are loads of powershell scripts hanging around the web which will do the same thing for free as well.
