-
Posts
1,738 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by IrritableTech
-
I’m not impressed by the lightspeed do this, oh does that not work response but... Presumably your dns server are set up to use opendns as forwarders? In which case that may not get hammered that much and technically you’ve only got two or three ‘users’ querying them. I hope lightspeed are more helpful tomorrow.
- 9 replies
-
- filter
- lightspeed
-
(and 3 more)
Tagged with:
-
Ubiquiti Unifi AP reset now can't find it!
IrritableTech replied to johbreaking's topic in Wireless Networks
Has it got an IP from your router or whatever hands out your addresses? If so ash into it and set the inform address. Otherwise plus in the reset button while powering it up. Hold it on for around ten seconds to be safe. Then it should broadcast that it’s ready to be adopted. -
I looked into this when the AA sent me a similar email. I found this interesting exception... https://ico.org.uk/for-organisations/marketing/
-
I completely understand and respect those points. However hopefully you accept my point - we don’t get support directly from Microsoft generally, but our networks are full of their products. With such a large potential deployment you could save a considerable amount going down the unifi route. Buy a couple of access points and try them. You can sell them on again if you decide it’s not for you - they’re very popular. Oh and if you need paid support, you know where to find me - reasonable rates apply ;-)
-
What more do I need? Probably nothing, but only you can say. Compare the features list. Will these APs be adequate? Spec the right AP and the answer is probably yes - test one, they're cheap. Do they have good support? No. Primarily it's community support, but you have come here so I'm guessing you are used to that. I bet you do this with Microsoft support as well - and you pay them lots of money every year most likely. Can I pick up the phone and shout at someone when they go wrong? The short answer is no. Can I get them easily replaced if and when they die? Yeah, new units are being developed lots - that is the whole point of the business model, sell cheap hardware and develop it regularly then people keep buying kit. It's much the same as the mobile phone market. We recently ripped out an aging Ruckus system and replaced with Unifi which cost us a fraction of the price (and we've expanded at the same time). We've had to rethink the way we've implemented wifi to our users a little bit, but actually the rethink has ended up being a much better solution.
-
Changing your subnet isn't too difficult as long as you plan and account for everything that may have a fixed ip. Firstly though you need to consider your edge router whether you configure it or someone external to you does. Your router needs to know of any additional subnets so it can route traffic to it.
-
We have a working ACL assigned to our staff-BYOD vlan which is something like this.... ip access-list extended "BYOD" 10 permit udp 0.0.0.0 255.255.255.255 10.15.110.16 0.0.0.0 eq 67 20 permit udp 0.0.0.0 255.255.255.255 10.15.110.16 0.0.0.0 eq 68 30 permit udp 0.0.0.0 255.255.255.255 10.15.110.16 0.0.0.0 eq 53 40 permit tcp 0.0.0.0 255.255.255.255 10.15.110.16 0.0.0.0 eq 53 50 permit udp 0.0.0.0 255.255.255.255 10.15.110.17 0.0.0.0 eq 53 60 permit tcp 0.0.0.0 255.255.255.255 10.15.110.17 0.0.0.0 eq 53 70 permit tcp 0.0.0.0 255.255.255.255 10.15.110.9 0.0.0.0 eq 80 80 permit tcp 0.0.0.0 255.255.255.255 10.15.110.9 0.0.0.0 eq 443 90 deny ip 0.0.0.0 255.255.255.255 10.15.96.0 0.0.15.255 log 100 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255 exit Then in our BYOD vlan... ip access-group "BYOD" in So we've allowed specific services rather than just open up a whole server. Lines 10 & 20 allow DHCP, 30-60 allow DNS requests to two of our servers, 70-80 access to an internal web server, 90 deny access to any other internal address (and log), finally, permit any other request (Ie. internet). Now you'll note that we do not have a line in for any routers - they are not needed. This is protecting inter vlan traffic and is processed by your switch acting as the router. So ACLs won't for example isolate your clients in the 10.15.109.1/24 subnet from each other.
-
Getting staff to take it seriously...
IrritableTech replied to Gongalong's topic in Data Protection & Information Handling
One of my users said sometimes in an emergency situation (first aid call for example) they didn't have enough time to lock their computer. I asked if that emergency came in whilst you were on the phone would you not replace the handset as it takes about the same time? Had a cartoon image in my mind of a puff of smoke, a pair of legs running away and a handset falling to the floor. -
Getting staff to take it seriously...
IrritableTech replied to Gongalong's topic in Data Protection & Information Handling
We've started a sticker of shame scheme. When we come across an unlocked machine and the staff aren't in the room we lock it and place a sticker on their monitor informing them they have been caught. Our senior leaders have agreed that those repeat offenders may be issued a management instruction as a first stage. -
SSL Certificate Domain Verification
IrritableTech replied to pbad's topic in Internet Related/Filtering/Firewall
Usually if no authentication is required you could pop in any old rubbish. Are you sure that smtp server is available externally to your RBC without any auth though - I'd imagine that might get abused? -
Yeah - they really need to fix that by default, I can't really see a good reason to have it there. You can create WLAN groups in the Wireless Networks area of settings. Click the pen in the top right of the page to add another group and clone the SSIDs over (if required). May do what you're after.
-
He was interviewed (kind of) by the Project Binky guys a while ago and I think Edd said he had something in the pipe line. By the way - if this stuff interests you and you've not seen Project Binky, subscribe now and watch their back catalog. https://www.youtube.com/badobsessionmsport
-
The cloud key is excellent (I have one at home) but I think they are sold as supporting no more than 25 devices. We use the windows unifi controller for our 45 APs. It's just best to move the install out of the user data and up the memory available to the java process - out of the box it is limited to 1GB. I don't believe the second port is currently supported - for future expansion is my understanding at the mo.
-
By offering secure storage for that data they immediately become a data processor. As others have said, we’re talking about a parents want to see their child in the school play. We all work in schools. We’re not entering a contract for a seat to watch a musical with a billed b-list celebrity and a no refund policy. The parent needs to give consent for this type of data to be processed. They don’t like the means in which it collected and is going to be processed. So let’s just do what schools do and adapt to specific pupil and parent needs so that everyone gets the same opportunity. The law has been created to allow users more control over their data and more transparency for who holds what. It’s not designed to stop parents celebrate success with their child, the internal school process is causing the issue - so I’d suggest the school changes the process, either for this one parent, or for all.
-
Exactly - consent must be freely given. You can't say we won't sell you a ticket unless you consent to us processing your data in this manner. As a data subject you are being forced to consent so you can watch your child perform. I can't see another legal reason to process this data so I think this boils down to common sense - you've asked for parents to complete this process to make your life easier or ticket allocation more fair. One doesn't wish to share their data with a third party processor on this occasion. You'll have to make alternative arrangements for this person.
-
Yeah the US-8-150w should have plenty of power across the eight ports for what you need. In areas where you need less poe ports the US-8-60w saves you a few pounds. Both are wall mountable, centrally managed, vlan aware and pretty cheap.
-
I'd have a conversation with your council support services first. Their router does not have any idea about where 10.100.110.0/23 is or how to reply to it.
-
Another vote for laptops direct. Had some refurb Lenovo’s from them recently and they’ve been excellent. I’m afraid I’ve had issues getting in touch with the guys at ict direct - I guess they are a victim of their own success.
-
Netsweeper with Schools Broadband
IrritableTech replied to TMBS's topic in Internet Related/Filtering/Firewall
Sorry. I’m making suggestions on limited knowledge. Thanks for clarifying. -
Netsweeper with Schools Broadband
IrritableTech replied to TMBS's topic in Internet Related/Filtering/Firewall
Not entirely. If you can identify what IP was being used by whom at any one time the results may not be instant, but they are still available. If you had either radius or your Wifi network tracking users to IPs you can quickly cross reference. There is an issue with school owned iPads which get hands about though - not sure of the best solution here. -
You should only need to change the gateway in DHCP and the IP address given to your 5406zl within that subnet assuming your routing is done on the 5406.
-
GDPR & Students (Secondary)
IrritableTech replied to mhw1970's topic in Data Protection & Information Handling
We will be gaining consent for images for marketing purposes - one important point we raised recently though was the school prospectus or other printed marketing media. If a child or parent removes their consent after publication, either the investment in printing is lost or potentially the publication is already ‘out in the wild’. -
Room Booking systems - 2 week timetables
IrritableTech replied to mdrabble's topic in How do you do....it?
My lead tech set this up here... https://www.bookedscheduler.com It does everything you want except the import timetables from sims, but the new import from csv is possibly help here with a bit of scripting. We use it for booking It rooms, resources, conference facilities and our mini buses. -
Technology is no replacement for policy. The instructions to all staff which have access to the document should be clear on what can and can't be done with it. Failure to comply will result in a management instruction being issued. If you don't trust your staff to follow those instructions don't share with them - and consider their suitability to their job.
