Jump to content

IrritableTech

Members
  • Posts

    1,738
  • Joined

Everything posted by IrritableTech

  1. We've done this by creating vlans. The ruckus controller can tag all packets on a specific SSID with a specific VLAN, or using radius, you can have it dynamically assign a vlan to your clients devices. You can then add access lists on the ruckus controller and be reasonably confident that your BYOD traffic is separate to your wired traffic. IP's will still need to be served by your DHCP server - the ruckus kit can't help here. Proxies are a different matter. Ruckus have implemented a system to hand out a WPAD file. It can either be hosted on the controller, or a web server. However it can only have one WPAD file for all the SSIDs (unless that has changed very recently?). Unfortunately, WPAD is not a silver bullet. iOS devices wont use it, Android devices wont use it and I couldn't get them running with OSX if memory serves. Windows machines do like WPAD though (as long as automatically detect settings is enabled in the internet lan settings). When we had an LEA proxy to deal with, we ended up using a combination of Pac files for OSX/iOS devices, WPAD for Windows and manual proxy settings for Android. So what's left - transparent proxy sounds good? But sadly it's not that straight forward either. Happy to answer any questions about our journey with ruckus and porixes. You might find some more useful info on my blog... WPAD | IrritableTech
  2. Thanks for these, some nice shots. I always think the best camera in the world, is the one you've got to hand.
  3. I'm doing a presentation to some of our students this week covering the same info. The teacher in the class needed to cover the "LO2 Understand the issues related to use of information" (OCR I think) He sent me this from the syllabus Legal issues: data protection legislation (e.g. Data Protection Act 1998) Freedom of Information Act 2000 other relevant legislation (e.g. Computer Misuse Act 1990) copyright considerations. Ethical issues: • examples of ethical issues (e.g. moral, whistle blowing, disability, use of information) • codes of practice (e.g. email,internet, internal policies, intellectual property, content) • other (e.g. reporting bad practice or breaches). Operational Issues: • security of information (e.g. backups) • health and safety (e.g. processes,procedures,regulations) • organisational policies • costs (e.g. for development, modification, training, system upgrades) • continuance planning. I think relating it to a real organisation will help their understanding. The only thing I would note is your students should be well aware of the answer to question 3!
  4. You can set up different WPAD files per vlan which can be handy, but the vlans don't make it any easier.
  5. Me? Yes, and access lists.
  6. As @soveryapt suggests a WPAD file via DHCP is the most seem less route (there are issues with devices seeing a transparent proxy as a man-in-the-middle attack). Unfortunately, WPAD support is limited. I wrote a couple of blog posts on my findings around this subject which may be of some help? Try this one for starters... http://irritabletech.co.uk/2012/06/byod-infrastructure/#more-549 You need to offer the full suite of options to cover the most devices. We ended up with WPAD, hosted pac files and manual proxies. Ended up creating handouts for the different devices. We've ended up now removing the proxy altogether. Previously only the more IT savvy users were managing to get online, now it regularly hits the 100 mark.
  7. I've recently heard two numbers. Either of them or neither of them might be correct. 62 schools in total - two of them high schools 60 schools in total - one of them is a high school.
  8. ICT4Leeds is going ahead. They installed their first line the week before last at one of their schools. Didn't go very smoothly from what I hear with numerous people sat around waiting for virgin to convert the line. Other schools are being contacted to be informed of some downtime. The 'routers' in schools need to be reconfiged prior to migration day. The email claims around 15 minutes outage. As for as I am aware, the only plan for FAB, SAP etc. is vasco tokens - which have ongoing costs. Also infobase will be chargeable.
  9. I agree with @mrbios. A hands on test of fixing and replacing parts in a computer is not suitable for a 2nd/3rd line job. We do a written test, and a two stage interview process. One formal, one less formal. One of the most interesting questions we ask in our written test is along the lines of "these jobs are on the helpdesk, how would you prioritise them and why?" Create half a dozen tickets submitted by different people across the school and mix up the seniority and t&l importance.
  10. Download the latest version from http://www.ubnt.com
  11. They are managed via a controller. The controller software can be run on a PC, and doesn't need to run the whole time. Once you've set up the wireless SSID you can switch the controller software off.
  12. We use J4858c in 2510s over our multimode links. If the switches are close, like others have said I'd just use copper if I were you. Same speed, much lower cost. Do bare in mind that if you plug a fibre module into slot 24M - you won't be able to use port 24T. If you are looking to use fibre because you've run out of copper ports, you're out of luck.
  13. I've just popped a third Ubiquiti Unifi AP into my house. Did it need three - not really no, but I like tech. It's a tall house rather than large. I've ended up with an AP on each level. Once set up you can switch off the software controller and the APs will sign and dance all on their own until you decide you want to change something. I got them for about £58 each. Bargain in my mind.
  14. @LeonDan Gald to hear Ruckus is proving a good solution for you. We've had guest access working here in the past when behind a proxy. Wpad and pac files are what you need but to be 100% honest, it's not at all perfect. I wrote a couple of blog posts about our experiences... WPAD | IrritableTech If you move ISPs be aware that proxies whether transparent or not, do cause additional issues for devices you can't control. If you can avoid the proxy issue - which we've now done - it's so much easier for your guests.
  15. I don't know of what can and can't be done on 1&1. But it sounds like you might need to move your DNS to somewhere more useful. I use cloudflare for my personal DNS hosting.
  16. Perhaps put your subdomain in as an A record rather than a redirect? Or have a missed something?
  17. I had intouch reinstalled last week after migrating servers. When the capita engineer was checking everything I mentioned the exact same entry in the service setup page. He said that was fine, and the test messages we sent all went through. Will see if the attendance texts go through ok this morning...
  18. This was my biggest worry with Exa when we looked at their offering - the lack of monitoring options with their bundled filter. However I do believe they can supply a NetAsq box, which will do some reporting on usage. How good or bad it is however - I do not know. In my opinion, the monitoring of the usage is the single most important part of a filtering solution.
  19. The lightspeed shouldn't be getting in the way at all as previously stated. It sounds like it was a local routing issue, or a browser not correctly determining the protocol correctly. Any chance it is http/https traffic over a none standard port? If it was, always ensure you type http:// eg. http://10.1.2.3:9191 We use the lightspeed client on 450 PC's and 20 Macs - if you had any questions @Edu-IT ?
  20. We've got a MD3000i dual iSCSI controller SAN. Connecting via two HP E2910AL's and Qlogic dual port HBAs. A few months ago we bought a QNAP TS-1279U-RP 24TB as an additional lump of slow storage for stuff that isn't accessed very often. It performs surprisingly well though.
  21. Much the same story here as @FragglePete. Installed nearly four years ago using 5.6. We have three servers in our pool. We recently upgraded the ram in them to host more VMs. They run the whole school infrastructure except for backups and our fog server. We've never paid citrix any money, so haven't had HA. We've now got a dozen virtual servers running over the three physical connected to a SAN and a NAS over iSCSI. The system is designed so that two physical servers can host all VMs, which allowed us to increase the RAM during the normal school day without anyone noticing. The whole thing was designed, installed and commissioned in house.
  22. Thanks @SpuffMonkey that's good to hear. We have gone for the extra testing ends too. If we are running cables we generally try to pull more than we need, so the extra ends will save some time. @mikeyd101 Would have loved a fluke, but we couldn't justify the cost.
  23. You've not left yourselves a huge amount of time to find another provider. There is a lot to consider. Connectivity, filtering/monitoring, email, data between yourselves and your LEA, phones perhaps? It is easier to move to a provider who can offer a more complete package. If you end up looking at three companies for connectivity, three filtering products, three email etc. it's a big job. We've been through this in the last few months. We left ourselves around 9 months to look at all the options, but then again we did it for eight schools. We too are using Schools Broadband, but looked at a number of local providers. Happy to offer help where I can. Have you exhausted all options with your current provider? Do they know how fed up you are and how keen to jump ship? This document was created by a working party in Northamptonshire. It's an excellent starting point for schools thinking of moving provider. Not everything will apply, but it will probably highlight something you've not yet thought about! http://www.thedustonschool.org/sites/tds.aetweb.org/files/attachments/Schools%20Broadband%20connectivity%20and%20servicesv1%200.pdf
  24. Thanks for the feedback. A bit half and half. I think we're going to go for a more advanced testing unit. Too many times have we replunged both ends two or three times to find it still isn't right. A length tester will at least save our legs a bit. The ability to identify what's connected at the far end (device or switch) and whether PoE exists would come in handy also. We've jumped in with both feet and we're going to order the following... NC-500 NETCAT PRO 2 - GREENLEE TEXTRON - NETWORK TROUBLESHOOTER | CPC CTX200P - BYTE BROTHERS - NETWORK CABLE TESTER WITH PROBE | CPC The idea is these items give us effectively two testing units - one advanced, one simple - and the tone generator & probe we need. We cover numerous sites, so it's quite possible one unit would be out when we need one back at the office. I'll try and feedback our experiences once we've had a play.
  25. I was wondering what you folks use for cable testing and location. We've had basic continuity testers on the past, but they've all been lost or broken now. We were wondering if we should replace like for like or grab something more advanced. We run the odd cable here ourselves, and diagnose faults every few weeks. I can see an advanced tester that returns cable length and breaks would be handy, but the jump in price is quite large. We've also got a fluke tone generator to locate cables in cabinets but we're not sure if it's had it's day. Can you suggest what tools you use - and why it's good or bad? Thanks in advance.
×
×
  • Create New...