Jump to content

TechMonkey

Members
  • Posts

    7,551
  • Joined

Everything posted by TechMonkey

  1. We have 3 accounts, may be going to 4. 1) Day to day account. Same as everyone else 2) local admin for elevating access on PCs 3) server admin for server work 4) looking to setup 365 admin accounts as currently using our daily drivers but this is very bad practice. On a different note, if you can do get a decent remote support software. Not knowing your site but being able to solve an issue in 5 minutes by jumping on to their machine is a lot better than wandering across the site, especially if you then find they are not there and having to return later. Even just jumping on while you are on the phone to look at an error or to talk them through something saves so much time. Makes you and your team more efficient so will probably save you money in the long run.
  2. Oaktech's solutions are the ones I use and have used. We moved to a central queue and it makes it all so much ssimplier. Previoulsy did the deploy all printers and filter based on location/group/user using targetting.
  3. So - the collection of sites / search terms etc - the legality of collecting this data. - AFAIK there is no legality of collecting this beyond GDPR. Organisations have been doing this since internet proxies were first introduced. As long as the school and company you are dealing with follow GDPR (getting rid of data in a reasonable time frame, encryption, etc) there is no issue. MITM attacks (ie our request for students to install a certificate onto their personal devices). - Not sure their issue. If you were asking the student to install all certificates then taht would be an issue, but you are asking for a single one. If the parent does not trust the company issuing that certificate, that is another issue. But is the parent asking to review every company the school is using? Goes beyond any 'reasonable' implementation of the requirements. - What do they feel is reasonable? That is a very hyperbolic statement. It is a standard implementation across many sectors and industries. Exposure to future legal and financial risks: * what if the company sells on the data? * what if the company is breached (and this data become available)? * what if we 'punish' a student for what they are looking at (by collecting this 'illegal' data) - I'm presuming the school has a contract with the company. What does that say? If the company did do that, then I imagine they would be in breach of GDPR so there would be a legal case against them. - Yes this is a real concern. But the company should be able to supply information on what they do to prevent this. - What of it? If a pupil is looking at porn, or bullying someone else, or looking at things they shouldn't it is part of the AUP (it is part of the AUP right?) that they get punished. Ultimately it comes down to, as part of the agreement to use their device on your network they install this certificate. If the parent does not agree with this, the choices are to use paper and pen or go elsewhere. Harsh take but that is the choice, unless you are willing to bend or ignore the rules for one pupil/parent. If you are then why not break them for all pupils? At which point why have the policy you have? If you want to be more concilliatory you can ask them wht their ultimate objection is and what are their concerns? Then try and allay them.
  4. I would say it depends on your definition of monitor. And KCSIE isn't explicit. Having MITM means you can see searches, sub pages and videos being looked at, Smoothwall can alert on suspisious things. It isn't just filtering it, it may even not block some things, but it can alert the DSL.
  5. Just gone live this September. We have gone fulll BYOD, hands off, pupils devices. * Wireless info - what system do you use? how many clients? -- We use Ruckus. Got around 550-650 clients. Peak for the last week was 915. We were doing year group help sessions with 80-90+ pupils in a single room and the system didn't blink. Well no one screamed that they had no wi-fi. * Did you need to do any specific backend upgrades to support the transition? -- Yes but our backbone and infrastructure was not suitable in any way, shape or form. We ran new Fibres, replaced all swtiches, removed daisy chains and put some proper stacks in. Ruckus again to try and standardise. * What devices are people using for their students? Any recommendations? -- We made the choice to set a spec and let parents get the device they could afford or had. we did set up a portal with Dell 3340/5340/7340s, a bag, stylus and accidental damage warranty/insurance. It did make the devices look expensive but I think it was quite a good deal. Ultimately wasn't where I wanted them to be, price point wise, but quite a few parents got them. * Did anyone who's gone down this road use any external companies that have helped/are supporting the transition? -- We went with a supplier and a third party that supplied the portal. All I'm going to say is the process wasn't smooth for various reasons. I do think the three way split between the manufacturer/supplier/portal did add to the complication. I'm not sure if we will run the portal again. Still weighing up the benefit over pain. The companies were all very helpful though. Do ask lots of questions and make sure they are transparent about the process. One company we worked with suddenly let slip that the payments would run through the school and ultimately we could be on the hook for non-payment. This was specifically something our Finance head did not want and we had been up front about this so it was very disappointing to come out at the final stage. We had lots of assurances that other school sdo it like this and that it never falls to the school, but it wasn't what the finance team wanted to deal with and I wasn't goign to try and overrule them. * Do you have any recommendations or warnings for implementing a 1 to 1 scheme? I am torn still. If we had gone full 1:1, school owned devices, we would have had full control over them and be allowed to do what we want with them. But we would have had to be a lot more hands on, a lot more logistics and I think we would have had a lot more stick from parents. Make sure you get everyone on board as soon as you can, mostly to foresee non-technical things you wouldn't think about. Lockers for example, they will need somewhere secure to store devices and we didn't have the capacity, which nobody thought to ask about. Make sure you get staff carried along, get someone in management to develop or oversee a training program. It shouldn't be your issue, you will have enough to do. Staff will probably be the biggest issue. Make sure you get parents informed. Hold some information evenings. Make sure your team is up to speed and rock solid, processes and planning. This will take an enourmous amount of time and resources. Remind everyone, pupils do not fall out of the womb knowing IT. They will need support as well. Parents will bring up all kind of issues you never thought of. We had parents talkign to us about pre-pubescent skeleo-muscular development and how laptops will make them into hunchback dwarfs. You will get a lot of flack. Parents who think you should go BYOD as they have a device will pipe up if you supply them. Parents who think the school should supply the device will scream if you go BYOD. Parents will pipe up if you don't go Apple, and if you do. Etc, etc. As you have already identified, make sure your infrastructure is rock solid. Get a survey done if you are unsure. At least you will be able to wave a piece of paper to show everything is ok, or have something to show you need funds. Don't say yes until you are sure and happy it is going to work. Nothing worse than a scheme that fails and you have to get everyone to trust the system again after major issues. Happy to answer specific questions here, DM or real world chat. Good luck!
  6. I've looked at Smoothwall alternatives a couple of times in my Education career and my biggest concern is always the lack of Education focus from alternatives. This is validated by the number of times something is posted on here that needs filtering and when I check it is either already in a filter list or is caught by content filtering. Education filtering is very different to corporate filtering. I'm not saying this is a reason not to go with other options, but our time is precious and a limited resource, so anything that saves me time is a winner in my view. I don't think the lists provided by Smoothwall can be overlooked as a massive feature and benefit.
  7. I have a 3 year plan I'm happy to share if that is the kind of think you are after. I've sent it out lots, & I'm hoping some have found it helpful. Drop me a PM with where to send it.
  8. Thanks drewp, yes this basically the issue but across a wider context.
  9. Solved my own issue I think, must have been talkiing to the Duck. For future reference, there was no HTTPS Inspection Bypass category, and the HTTPS Incompatible Sites category had been added to the bypass auth category group. So created HTTPS inspection exception category so we can be more specific, not use Auth Bypass for troublesome apps.
  10. I've been trying to get a grasp on an install of Smoothwall I have inherited. They appeared to have one category that they used for Auth bypass and general URL exclusion. This seems like a bad idea to me as you can't tell who has visited the sites you have unblocked, whether they have HTTPS issues or not. So I've seperated them out and come across an issue I have never encountered before, and I'm not sure why. If a site is in the Bypass Auth list, obviously, a user is unknown so it drops to the unauthenticated IP, which is generally locked down. So how do you let a staff user through to a Bypass Auth site? Or do you not and I never notcied before? Use case: Facebook. Needs HTTPS bypass for the app to work, but we only want staff to access it. Same for Whats App.
  11. We use the Dell Hub monitors (this one I think https://www.dell.com/en-uk/shop/dell-24-usb-c-hub-monitor-p2422he/apd/210-bbbg/monitors-monitor-accessories) and I think it does all you want. Speak to Dell rep as the price on the website is nowhere near what we paid. Worked out cheaper than HP hubs and a screen but a mile. Looks smart and you end up with an uncluttered desk.
  12. The only reason I can think of is if any part is not supported so not getting security or functionality. So a rolling program of replacements so they never fall out of EOL could be set up. EDIT: & definitely move away from one key to be shared by all.
  13. That looks really good fun. Great twist (that isn't really a twist but the main concept).
  14. I don't do a form but I do send after action emails if we had an outage or incident. Normally only if it has affected operations, but something like weekend work would definitely get one to highlight it was done. Nothing grandiose, just the facts with timings and work carried out. EDIT: If your help desk is ITIL based it should have a incident section that can log this.
  15. Ohhh, as you are here, when someone inevitably loses their remote, where do we get new ones? I've checked your website under accessories and they aren't there.
  16. So you want private teams created but not public?
  17. Is this a recent change? I'm almost certain we don't have E5 and we are stopping creation.
  18. Nope. It was open, to all, before I came and the amount of silliness and duplication was ridiculous, and it wasn't the pupils. Now we have a service request in our help desk that asks all the right questions. When I get five minutes (HA HA HA HA HA HA:rofl:) I'm going to integrate it with a workflow that will ask approval and then create the team if agreed by the IT Team.
  19. That's the one. Speak to your supplier, you can set it up to pass the username and accounting info. I didn't set it up but it is possible.
  20. When you say Ruckus DPSK, is that through CloudPath? If so you can make it so the DPSK gets the username and authenticates using that. We have it set up so the user only logs in when generating the DPSK.
  21. I think your issue there is going to be the "don't break the bank" requirement. A decent multi-site solution will cost. If you cheap out you will end up with frustrations or limitations. I would look at getting as many areas of the MAT included as possible as it is much easier to see value when a system is used by facilities, IT, HR and finance. Not a MAT but we use FreshService across 3 sites, one non-education, for IT and facilities and started using it for HR. It is flexible to do what we want and we are finding more uses as ideas come up. Not going to say it is perfect but it certainly does what we need it to do. We also looked at TopDesk but that was more money for an even bigger system.
  22. Is anyone using Smoothwall content modification on YouTube successfully? I thought we had it all set but we are suddenly getting reports of adverts and comments appearing. Just wondering if it is something odd with us, if Smoothwall changed something or if YouTube have countered it?
  23. What are you trying to achieve? Or what do you want to specifically protect against or prevent? I would be very careful about developing narrow policies in reaction to the next big thing ™. Most issues I have seen people raise about using AI apps should already be covered in other policies. For example, Staff should not be putting pupil data into apps without proper risk assessments due to your Data Protection policy. You may need to point out to staff the application of current policies to new apps, or update some policies, but a whole new policy may be unnecessary.
  24. Woodbridge School is looking for an eager IT Technician to help support and move IT forward across the organisation. Woodbridge School is part of the Seckford Trust, and is a unique opportunity to support a prep school, independent secondary, and sixth form and a care home. For more information and the application form, please go to the Woodbridge School website vacancies
  25. Filtering? HTTPS bypass tried?
×
×
  • Create New...