Jump to content

IrritableTech

Members
  • Posts

    1,738
  • Joined

Everything posted by IrritableTech

  1. The quote we had at this price included net support school. Hope that helps.
  2. Firstly are you trying to change your login domain? If so you can't - you'd have to migrate to a new google apps account based on the new domain. Secondly, how have you created your accounts in the past - does your google apps synchronise with an active directory for example?
  3. Lightspeed can cause this with secure sites. With an insecure site it will respond with the blocked page, however it simply breaks the connection on https sites. Try another secure site you know to be blocked to confirm. tumblr.com is blocked on our lightspeed rocket I'd be speaking with your provider.
  4. Yeah we've done the same - a small transport subnet with just the fortinet and our core switch. They fire all traffic at each other and each end sorts it out from there.
  5. [edit]Sorry it seems I missed the second page on updates! Whoops
  6. Or presuming you don't have another switch just lying about I'd try to simplify your config and build upon a working one. Keep version histories and go backwards if something doesn't work properly. Start as simple as possible - something like... [color=#333333]ip routing [/color][color=#333333]ip route 0.0.0.0 0.0.0.0 10.66.28.1[/color] [color=#333333]vlan 1 [/color] [color=#333333]name "DEFAULT_VLAN" [/color] [color=#333333]untagged 3-15,17-18,21-24,25-28 [/color] [color=#333333]ip address 10.66.28.39 255.255.252.0 [/color] [color=#333333]tagged 1-2,16,19-20 [/color] [color=#333333]exit [/color] [color=#333333]vlan 32 [/color] [color=#333333]name "Guest_WiFi" [/color] [color=#333333]ip helper-address 10.66.28.42 [/color] [color=#333333]ip address 10.66.32.4 255.255.248.0 [/color] [color=#333333]untagged PORT_NUMBER_TO_TEST_SINGLE_MACHINE[/color] [color=#333333]exit [/color]
  7. Just to confirm... in your config file you have [color=#333333]tagged 1-2,16,19-20 You've placed the vlan ID into your ruckus SSID right? And when you tried a machine plugged directly into the switch the port you used was untagged in Vlan 32?? [/color]
  8. Ok - that's interesting. I know this shouldn't be needed normally - but have you restarted your switch? (sorry for the turn it off and on again type suggestion but I did have a similar issue with an HP switch once).
  9. Could it be an issue with your ruckus SSID and or access lists then? You could eliminate Ruckus for now by physically wiring a pc to a port untagged in vlan 32
  10. From a device in the effected VLAN ping the gateway 10.66.32.4, then the switches other IP 10.66.28.39, then your fortinet address 10.66.28.1 - which one fails? BTW - that's a huge subnet for wireless - do you plan to subnet within that range?
  11. In your DHCP range for the new subnet have you set 10.66.32.4 as the gateway address?
  12. Comms Express Fruity Cables Or recently I've had some decent quality Cat6a cables from Kenable - cheap too.
  13. Out of interest has your netsupport quote been based on the edugeek member deal? EduGeek.net - EduGeek Members NetSupport DNA - Exclusive Offer!!
  14. @Al_NetSupport To confirm, if we apply for the trial the pricing is fixed for us past August 31st? I.e. we sign up now, but can use it as a trial in September and order in October? Also can you confirm if the lifetime licence is transferable from machine to machine - so when we replace machines the licence can transfer to the replacement machine.
  15. Live register has just sent us new note readers today - just swapped them out ourselves. No mention of any charge for hardware. :-)
  16. Yup this was a problem for us which we've had to work around. I created the DNS entries a bit differently from you however... I created a new zone for each of the five URLs and created a DNAME for restrictmoderate.youtube.com If your servers are acting as the SOA for the parent domain youtube.com for example, they may not be returning all the other required subdomains - a.youtube.com, accounts.youtube.com etc. etc.
  17. We're in a similar position at the moment - researching solutions. We had join.me recommended by a local expert as well as Splashtop. Although we're looking into the new GAfE tool - Cast for Edu: https://support.google.com/edu/castforedu
  18. I think you are correct with your analysis in the first point - schools, LEAs/RBCs and private companies need to sort out any filter that doesn't allow the schools to see reports. What's more I think any filter in 2016 needs to actively monitor and inform. IE. we need an email saying, user x has attempted to look at site y or user x has searched for the term z. I've seen these reports on a number of occasions allow CP staff to intervene and possibly prevent harm. Many schools, LEAs/RBCs and private ISP do have these tools but some do not. Some schools are using systems that can do this, but they don't know about it. Some companies aren't pushing the fact that their solution does do this type of active monitoring. Sadly a few companies are saying they've dealt with prevent, but they've simply blocked a few sites. The head teacher (or someone instructed by him or her) has the power to confiscate or examine anything which a pupil brings into school - now I'd suggest confiscation, and examination with parents in the room if the material is not thought to be illegal is best (If there is any suspicion the material could be illegal then hand the sealed device straight to the police). So a suspicion that a pupil is providing a hot spot can be confirmed and dealt with under usual school sanctions. Presumably your student AUP or home school contract includes something along the lines of 'any attempt to circumnavigate the filter or safeguards is a breach of this agreement..?' I said earlier in this thread two important points as I see it. Firstly monitoring is not just a technical solution. Our prevent training talked mainly about social changes within a person - who they mixed with, if their appearance changed, spending more time at school, less time, a change in their contribution to discussions. All this tends to happen well before a change in their views. None of these things are going to be identified by a filter. Secondly, opening up student access to your wifi - and perhaps allowing a little lighter level of filtering will undoubtedly give your school access to more information to highlight any pupil involvement with extremism. You'll increase your monitoring of those devices typically under the desk and out of sight. Now this type of access has to be well managed and not impact (but possibly improve) learning but it does help you fulfill your organisations prevent duty. Add to the above some good training for staff and parents and you're doing well as a school. It's worth remembering however that peers will probably notice changes in their friends much sooner - education for our pupils on how to spot changes may also be of benefit along side a well established route to report any concerns - anonymously will help here too.
  19. We've shoved in a Ubiquiti mFi with a temperature sensor, a door sensor and a home made power sensor (just a 9v power brick and a custom sensor script). Like all ubiquiti stuff it's as cheap as chips but needs a server to run the management side. If I had a bigger budget to play with I'd expand this to a couple of other locations.
  20. https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/526153/Keeping_children_safe_in_education_guidance_from_5_September_2016.pdf Worth reading @esafety_officer 's breakdown that @elsiegee40 posted near the top of this thread too.
  21. Prevent was already in place last year. This is new guidance - and although I'm not sure it goes far enough, it is welcomed. As @elsiegee40 says it's worth remembering that prevent is not all about technology and technology is not the only solution here. Can we disable a pupils mobile phone from accessing radicalization sites over their 3/4G network on school site? No, not with our technology, but if the school has a policy which is known to the pupils that using such networks in school is a breach and will result in sanctions - the school is starting to comply. If the school has well trained staff who monitor the pupils use in the dining hall or play ground as well as the classroom and uphold the policy the school is monitoring and looking for signs. I think prevent actually adds to the argument that getting the pupils on the school wifi is a good thing. You can monitor their activities more easily and can ensure the worst of the internet is blocked. It allows you the opportunity to intervene and educate far sooner.
  22. I'm guessing it should end up here? RM Easymail
  23. We use groups. Enter an email address in your standard AD security groups and GADs will create a google group (distribution list).
  24. You could just rename these different groups as required in your active directory?
×
×
  • Create New...