Jump to content

IrritableTech

Members
  • Posts

    1,738
  • Joined

Everything posted by IrritableTech

  1. Your school has a duty to keep other peoples information confidential therefore they have put restrictions in place to ensure you can't access sims. Attempting to circumvent this may leave you in breach of the computer misuse act as well as your schools policies. If you are allowed in free rooms then speak to your admin team who I am sure will assist you.
  2. Us too - didn't know there was an app though thanks. mPort is pretty cheap but not as cheap as a Pi. However it's a plug and play solution you can have running in half an hour. We bought the current sensor to keep an eye on the power to the room as well - but I didn't think and it needs installing on a single core live or neutral which I didn't fancy. Instead we got a 9v DC adapter and hacked together a quick script and used another port on the mPort. If the power goes, it sees a fall in the voltage on the pin and alerts.
  3. So it's been running two years, then suddenly... To confirm, your VMs are running and your users are going about their day? The issue is that you're seeing errors in your cluster setup and clearly things aren't optimal? Your SAN network in Fail Over Cluster Manager is still partitioned? Personally I wouldn't have setup this network allowing cluster traffic as well as iSCSI - Do we know why they did that? In MPIO Properties is you SAN listed as a Device? Is iSCSI enabled under Discover Multi-Paths and is this the same on both hosts? My compellent SAN did this when I set it up - I guess yours might be different. In iSCSI Initiator are you seeing the same targets on both servers? What does the management interface of the SAN tell you - is it complaining that a path has dropped, has it got permissions in for both servers, does it show the correct iSCSI targets for the servers? Personally I'd start sketching the physical layer out on a bit of paper, noting IP addresses etc. and then start thinking about what that means in relation to the NIC teams and such. Grab a console cable and look at the config on your cisco switches, they may well be blank but something may have been configured. Then I'd probably think about the OS side of networking - NIC driver settings, Team settings, iSCSI Initiator, MPIO. Finally looking at application layer and your cluster / hyper v setup. As a newbie to Hyper-V clusters (we built one this summer) I found it a little hard to get my head around all the various places you need to configure different elements. Hyper-V Manager - Virtual Switch Manager, iSCSI Initiator, Fail Over Cluster Manager - Networks, Storage, Nodes, MPIO Properties. etc. etc. etc. We're not teaming NICs though so that was one thing I didn't need to contend with. I'm rambling and not helping...
  4. I'm behind on this and this may be of no help, but I'd be questioning the documentation or setup. Both Server 2 and your SAN are documented as using the same IP address for iSCSI - 192.168.0.106 [edit] Reading it again it seems that you have eight physical NICs in each server, four teamed for your VMs, four using multipath for iSCSI and one for management? It doesn't add up - the documentation is awful, it looks like it's been copied and pasted from other documents rather than written with your install in mind from scratch. The two servers have different references to what we assume are the same functions. vEthernet(BYPER-V-LAN) & LAN - Windows 2012 Team etc. It's a bit of a mess to be honest. When did this company install? Have you contacted them?
  5. Just upgraded my phone to iOS 10 and tested this - it's working fine both on our hotspot BYOD service and our guest network. We're on even older firmware than you too... 9.7.1.0 build 17 We did have the blank guest page though the other day - a reboot of the controller fixed it. It had been running for months though...
  6. We switched over eight primaries (I think it was eight) from the old RBC provider to Schools Broadband FTTC circuits within term time and some within the school day. Except for one which took a client GPO update to remove the old proxy server (internal issue with AD not SB) the switch over from one to the other was quick and painless - on average only taking half an hour including all the testing. We'd pushed out the lightspeed agent before hand. It was something I was nervous about, but in the end it wasn't really a big deal.
  7. Now I did contemplate mentioning this option - cheap leased line, add a filter, add a firewall but then it doesn't really come under the comparing apples with apples scenario I was suggesting. The original poster was comparing EiS with Schools Broadband, both providers who offer a complete service. For many schools contemplating the jump from an RBC they've never been given access to filtering or firewalls and staff may prefer a middle ground to start with. All options available of cause and all opinions valid!
  8. ISPs are ten a penny but you need one that understands the education sector. Our users are often trying to circumvent protections in place, we need to comply with various documents from the DfE as well as the prevent duty. Your bog standard lease line reseller may not have the expertise required. We recently renewed with Schools Broadband across our MAT but we also support other schools not in our MAT and have helped them negotiate on contract renewals too. We've found there have been a few hiccups over the last three years but that was really all that they were. The support team are generally very good and I really can't complain at all about up time or bandwidth. Schools broadband are one of the few companies I've found who will either do everything for you (super in a small primary with little technical knowledge) or will let you have the keys to everything and let you get on with it - although they are still there to help if you stuff it up! Remember to compare apples with apples and saving money really isn't the final reason to choose one supplier over another - safeguarding has to take priority. Then it's up to you which comes next, price or service.
  9. We generally use google forms, but then we are a GAfE school. Be mindful of what info you ask for though. Remember you are trusting this data to third parties and you may need to consider your ICO listing. Probably not an issue for a training feedback form to be honest but worth a mention I think.
  10. Filters should be blocking the destination not the frankly useful shortening service. A number of our teachers use bit.ly or goo.gl to make it easier for pupils to all get to the same destination.
  11. Try turning off all the eco power saving options in the NIC driver advanced settings. Don't allow the OS to power it down in power management either.
  12. I wonder how many of the end products changed hands in the marketing campaign?
  13. For anyone else who took longer to sort this than they should have done, here are the steps I took. If nothing else it will help me if I need to do it again in the future! Install Install stunnel on the civica/corero server from stunnel.org Run a command prompt as administrator and run Which will add it as a service. Get a certificate You need to make a cert request on the civica server. I ended up running the following command (taken from stunnel.org but adapted slightly) I took my certreq.pem and took it to StartSSL.Com and got a free 1 year certificate. You'll need to validate a domain name and go through the wizard - pretty self explanatory. You'll also need to have setup your DNS entries for the server eg. civica.school.county.sch.uk I received my signed certificate as a *.pem Open this file in notepad and add the stunnel.pem contents to certificate before the certificate data - it'll end up something like this... Save it as Civica.pem in the C:\Program Files (x86)\stunnel\config folder. Configure Stunnel Right click on the GUI and Edit Configuration. I commented out everything a wrote my own entry: Finally right click on the GUI and reload Configuration. Check that there are no errors in the log. Fire up your firewall and block port 8000 and open 443.
  14. It shouldn't really and I presume you'd like to fix the issue as you came here. Disconnect a switch for a minute and look at the activity of the others - has it decreased? No - then reconnect it and move onto the next. Yes - then start working through individual connections on that switch. You could look in the GUI of each switch to see if you can see any which have usually high traffic on them.
  15. Anyone with questions over the new guidance would do well to read Rebecca Avery's ( @esafety_officer ) blog post: https://kentesafety.wordpress.com/2016/06/06/online-safety-within-keeping-children-safe-in-education-2016/ It should dispel any myths that unscrupulous companies may use to their advantage.
  16. I'm using plusnet fibre and have to say I'm pretty pleased with it. 78Mb down - 19 up - I'm quite close to the cabinet. They let you have a fixed IP for a one off fiver fee too which is handy. The only gripe I have is that I think their DNS servers are a bit slow - but you can find alternatives.
  17. It's an interesting time to ask that question. Surf Protect has just been upgraded to version 3 - a fully rebuilt product. I haven't used it in anger but the hour I spent sat down with the head developer was extremely interesting. I think Exa will admit that version 2 was in desperate need of replacement and version 3 answers a lot of the short comings of the old product. Be a bit careful with feedback you get over the next few weeks - the product has changed considerably and it might take users a little while to see the full advantage of the upgrade.
  18. If you're referring to the update for KB3170455 - I was suggesting to remove it. We've had to as it was causing an issue with some printer drivers being installed by normal users under point and print restrictions.
  19. It's also worth checking for a windows update which causes issues with point and print restrictions... KB3170455
  20. Good luck Dan. My school went through this twelve years ago and before my time here. You'll create a tight bond between all the staff who are going to go the extra mile and keep running. It'll be hard, but I think the first bit is the hardest - not sure what to do first. Take it one step at a time and everyone involved will realise that there are a lot of steps to go through before they start logging on. In the days of the LEA, they had companies who could get portacabins on site within 48 hours and my school had it's temporary accommodation reasonably quickly - will the LEA help even though you are an academy under these circumstances?
  21. If you've got them already written up I am sure some members will find it useful (there's a chance I might actually) with lots of schools moving to academy status and changing names.
  22. Have you talked with Schools Broadband support? They have used gamma for some of their telecoms in the past so I am sure they'd be able to get it up and running.
  23. Just having another thought... I found the intermediate certificate import doesn't work correctly on my version of the ruckus firmware (we're using an old one now so yours might not be an issue) and I had to manually build one certificate to import from the three certificates. Let me try and explain... Make a copy of your supplied certificate wifi.schoolname.sch.uk.crt Open the copy in notepad. It will show something along these lines: -----BEGIN CERTIFICATE----- LoTs/0F+RanD0M/StuFf+Fr0M/Your+CerTif1c4tE -----END CERTIFICATE----- Now open the Intermediate certificate as supplied by StartSSL in notepad and copy every last character. Paste this immediately below your new copy of your certificate. It'll end up looking like this... -----BEGIN CERTIFICATE----- LoTs/0F+RanD0M/StuFf+Fr0M/Your+CerTif1c4tE -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- LoTs/0F+RanD0M/StuFf+Fr0M/THe+InTerMedi4Te+CerTif1c4tE -----END CERTIFICATE----- Finally do the same copying exercise for the root certificate supplied by StartSSL... -----BEGIN CERTIFICATE----- LoTs/0F+RanD0M/StuFf+Fr0M/Your+CerTif1c4tE -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- LoTs/0F+RanD0M/StuFf+Fr0M/THe+InTerMedi4Te+CerTif1c4tE -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- LoTs/0F+RanD0M/StuFf+Fr0M/THe+R00T+CerTif1c4tE -----END CERTIFICATE----- Then import that into your Ruckus controller. It may well be a DNS issue, but I know I need to remember this process every year or two so it's handy to pop here anyway even if it doesn't help anyone else!
  24. And you have a wifi.schoolname.sch.uk entry in your local DNS servers? Otherwise it will be looking to your public DNS servers for schoolname.sch.uk for a wifi A name and getting nothing.
  25. We used a free certificate from StartSSL. As long as your build a full certificate using the intermediate certs it works fine on all devices we've tested.
×
×
  • Create New...