-
Posts
1,738 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by IrritableTech
-
Split VLAN 1 Server/DHCP
IrritableTech replied to Vellocet's topic in Network and Classroom Management
I think the short answer is, yes, it should work. So if your first nic is assigned 192.168.0.1 and receives a DHCP request, your DHCP server will allocate one on the range 192.168.0.0/25 and if the second nic is assigned 192.168.0.129 the server will allocate an IP in the 192.168.0.128/25 range. DHCP uses the request info (which network it came from) to help assign an IP. We use the same principle to assign IPs across our VLANs, although we use a router, rather than multiple NICs. -
Does the firewall allow traffic to and from your sql server? TCP/IP port numbers required to communicate to SQL over a firewall
- 2 replies
-
- connect.ini
- database
-
(and 3 more)
Tagged with:
-
Network Speed problems
IrritableTech replied to newpersn's topic in Internet Related/Filtering/Firewall
You've not given us a lot to go with there... Have you run wireshark or similar to check what is happening to packets? Have you got excessive broadcasts on your network? Is DNS performing as it should? Are your internal switches telling you anything? You mention your VLAN - is your router working as it should? Is it hitting cpu/memory limits? Come back with some more info, and someone will be able to help. -
We have ruckus setup here with a provisioning wlan and separate SSIDs for pupils, sixth form and staff which are also in separate VLANS. We don't use smoothwall but have set our filter to filter the traffic based on IP address. Therefore a user logged into the sixth form wlan - vlan - ip range gets sixth form level filtering without authenticating to our filter. Our filter doesn't know who the devices belong to - but our ruckus controller does, and the logs are sent to a syslog server so they can be cross referenced if any issues arise. You are correct about the auto network jumping. It works quite well on Macs and iOS devices, but not at all on others. We don't use the prov.apk on android because different browsers deal with the file differently and users need to have 'third party app stores' allowed in their security settings. It was all too complicated so we just tell android users to click the manually set up your connection link on the ruckus portal, copy their unique key, and connect to the correct wlan and paste the key in. To restrict pupils from utilizing the BYOD facility, we only allow users with the AD security group BYOD_Pupils to access the pupils SSID using ruckus groups. We then assign users rights in AD by adding them to the group. We're on 9.5... I'll leave it a bit before upgrading. I'm not far from you @timbo343 if you want to pop down and see how ours is working for us?
-
I think for those who know what sch.uk means, yes it is a little more professional. @GrumbleDook wrote a blog on why schools shouldn't give up their sch.uk addresses which gave some positives for sticking - EduGeek.net - The Importance of Domains The biggest advantage I can think of is that only schools can register a sch.uk domain. Therefore nobody can sit on a typo domain and grab your traffic (schoolA.com - schoolAA.com), and if you forget to renew your domain a drop catcher can't pick it up and hold it to ransom. It also gives geographical info on the school, which may help identify the correct school when dealing with common names. Sadly the advantages are rather outweighed when you have to tell someone over the phone what your email address is.
-
BYOD Considerations - What is required?
IrritableTech replied to MrPARRman's topic in How do you do....it?
There are two sides here... The technical implications and the safety/educational use/policy side of things. I talk in brief about both sides on my blog. Perhaps it'll answer some of your questions, but feel free to ask here if I can help further. http://irritabletech.co.uk/tag/byod/ -
They've left that to subscription services like hoot suite I think.
-
Problems setting up Ruckus guest access
IrritableTech replied to bulletv1's topic in Wireless Networks
Have you set up your access list for your guest network? Can they access the gateway and proxy server? Also wpad files don't work with much - pretty much only windows to be honest. Apple devices need a proxy.pac file (same file actually, but need to be told where it is located) and Andorid generally need manual proxy info setting. -
[android] Can Jellybean use wpad
IrritableTech replied to sparkeh's topic in Mobile Devices & Tablets
Nope. Can't on our nexus 7 with jellybean anyway. -
Nice one thanks. Is this the point to create a new joke... how many network managers does it take to find a password?
-
Thanks for your input @PhilNeal. I've returned to support net with renewed energy, but still can't find a reference to the password, or download link. I'm grateful for your reply, but do you think there could be an easier way to communicate this with the end users in future?
-
I'm guessing this request was deemed to be against either the edugeek rules, or capitas. Sorry for the trouble, but capita do need to make this easier now there are multiple updates to run. Please refrain from posting the update or the password until somebody in authority comments.
-
Thanks @zag but there is no link in that doc. Anyone else?
-
I'm going around in circles trying to find the Sims Discover ISO on here and support net. Can anyone be kind enough to share the link & pass? It always seems backwards to me - my support company issue the core update over solus, capita email me the intouch update, but I rely on the good folks here for discover. Seems badly organised. Anyway... thanks in advance.
-
It's pretty good. We decided to use it because it was so integrated into sims.net. There is a pause (definitely first time, possibly more often [sorry Phil]) opening it up, but we can live with it. We do have an issue every 6-8 weeks where one of the services wont communicate with capita any more. We've had it today, but after restarting IIS, OpenVPN and pinging the capita servers everything comes to life again. I think it's a routing issue as a result - which I need to look into again.
-
User account and password migration to new 2012 domain
IrritableTech replied to FishCustard's topic in Windows Server 2012
There are a million tools to export and import users, bulk update home directories and the like. I like Active User Manager, Wisesoft Bulk AD users and csvde (all free). However passwords is another matter. They are encrypted for good reason. -
Just found this article published today, which is quite relevant to the conversation. Is it worth splashing out on cables? - Features - Gadgets & Tech - The Independent
-
Just remember O2/BE have just been bought by sky. Many customers are being encouraged to migrate over, some are sitting it out to see if they can keep their static IPs and Annex M. Sky are thinking about static IPs and using your own equipment according to the Q&A sessions they did with O2/Be customers. Currently on Sky, but have used UKFSN (enta.net), Zen all of which I'd recommend for different situations.
-
Primary school Internet Filtering
IrritableTech replied to Jawloms's topic in Internet Related/Filtering/Firewall
The smootwall express / dans guardian combo is still being used by some I'm sure, however it has been hanging around for some time. They are free, but only have community support and aren't updated very often (if at all?). Smoothwall also make commercial products which do the job much better, and come with support if things go wrong. With the renewed interest by ofsted in esafety (the teaching of online safety) and the continued importance of safeguarding (the school keeping the pupils safe) I'd probably suggest to look at one of the commercially available products on the market. Each have their positives and negatives as well as their differing price tags. I've been looking at Smoothwall, Lightspeed and Bloxx and found the one that best suited our needs. -
Redirecting emails from old provider to Office 365
IrritableTech replied to themightymrp's topic in Cloud Services
The perfect solution, however our LEA don't allow pop/imap. It's a security risk they say... Thanks anyway James. -
Redirecting emails from old provider to Office 365
IrritableTech replied to themightymrp's topic in Cloud Services
Just another thought I had... You've got spare space on your old email account right? -
Redirecting emails from old provider to Office 365
IrritableTech replied to themightymrp's topic in Cloud Services
Sorry @themightymrp I fairly sure it won't. Its the original senders spf record that needs adapting (or the LEAs) not your school domains. -
We installed our own (including the wiring) and it was straight forward. I'm sure you'll be fine. You'll need to buy the equipment with support, so there is always someone you can phone if you get stuck configuring the controller.
-
Redirecting emails from old provider to Office 365
IrritableTech replied to themightymrp's topic in Cloud Services
The issue is that the LEA servers, when set to redirect, send the email on as if it has come from the original sender. Making it easier to reply to, and looks neat in your new inbox. So email from [email protected] sent to [email protected] is actually sent by LEA.net to [email protected] So when school.uk (in this case office 365) checks who has sent the message it finds it came from the IP of the LEA server. When it checks the DNS record for abc.com, the spf record doesn't mention the LEA servers IP address, so it treats the mail as suspicious. I'm not sure I've explained that very well though. It's good to have an spf record on your domain anyway, but it's the original senders spf records you'd need to update to get this working, which of cause we can't. -
Redirecting emails from old provider to Office 365
IrritableTech replied to themightymrp's topic in Cloud Services
I'm afraid @john we haven't filled in all the gaps... We are Leeds schools who have been using our LEA email platform provided by Capita. The Leeds authority is pulling the plug on the Capita contract, and have proposed moving to Office365 - Individual tenancies for individual schools. Unfortunately (unless someone can tell me differently) they are not helping people migrate their inboxes, but letting everyone start again. Those staying with the new LEA provision are unfortunately in exactly the same position as those moving to alternative providers with regards to email. Some schools are jumping more quickly than others and having their LEA email forwarded to their new addresses. Ie. [email protected] forwarding to [email protected] or some such other domain. We hope this will give us enough time to let people know our addresses are changing. I bet its an spf issue @themightymrp after looking into it again.
