Jump to content

pirran

Members
  • Posts

    68
  • Joined

Everything posted by pirran

  1. bump. I've had a few discussions with potential candidates. My business email is on the advert for enquiries and I'm happy to jump into a Google Meet/ Teams call if you'd like more information.
  2. Hi all, We're replacing our phone system this year, however due to the change in work practices we already have a LOT of phones to get rid of. Are there any schools/colleges out there that could make use of a large batch of this phones? avaya-1608-i-ip-phone I'm guessing we have around 50 to go initially. If you're interested then please PM me, we're based in Plymouth, it'll be collection only and it would need to be quite soon. I'm trying to avoid scrapping them all! https://commswarehouse.co.uk/buy/avaya-1608-i-ip-phone/?ppc_keyword=avaya%201608-i&gclid=Cj0KCQiA9OiPBhCOARIsAI0y71BRCAIWIaSXjgqfdoYRclK1HPvnq60qp-uwPfYgBZwvu1ww6a4G09YaAuVjEALw_wcB Thanks, David
  3. We're a small Uni / College (Arts). We've around 2000 students on roll, however with video, game design, photography etc. we appear to rack up storage use! Due to the 'free' space, we also have a huge video archive from a plex server that pulls down a lot of UK broadcasts for the library.
  4. We're using just shy of 200TB here and although we have some enterprise licences too we're going to get hit hard. At least we have a year to reduce our storage usage. It looks like our Alumni are going to miss out the most though, which is real shame. One thing that isn't clear to me quite yet is: When running storage reports we can see the total space used, however this is for drive, email etc. Presently i'm not 100% on whether this actually includes google docs, sheets etc as that hasn't counted in the past. I suspect it does, i also can't imagine they account for much of our storage utilisation!
  5. As the outgoing Network Manager of Saltash.net (whose last day is today), I'd like to add that this is an excellent, enjoyable and progressive school to work for. I've been in employment with Saltash.net for three years and the site has been modernised from a failing CC4 network to a more de-facto configuration: Dell VRTX server platform. VMware VEEAM for backup and replication Separate replication server with associated SAN Separate NAS backup Server 2012 DCs Cisco managed wifi with Aerohive on the way. Smoothwall has just arrived. Essentially there's lots going on and a good sized team to provide the support required. The Network Manager who's been appointed as my replacement is exceptionally capable and already has an in depth knowledge of the types of systems we're running. Many thanks, David Jones
  6. DEP - yes LocalzUK, it's wonderful when it works, we've around 120 devices registered with DEP and sitting with Meraki MDM it's a lovely solution. Unfortunately Apple haven't figured out (or just don't care) how to manage certain devices yet even if purchased in the past through a registered supplier. For example, AT Computers went bust and some of the kit they provided us (iPad 2) historically can now not be added to DEP as it's the supplier that has to carry out this action. Do Apple want to know about the problem, to be blunt, no. :\ That said, DEP and Meraki MDM is truly wonderful from a management perspective.
  7. I've been pretty tempted by the edgeswitches, however the lack of warranty has so far kept me away. HP Procurve/ Aruba = lifetime, only 1 year for unproven reliability could make these things very expensive in the long run. Specifications look great, I just need more convincing!
  8. +1 Nexusos - One of my team has done the SCCM course with Nexusos, good training (and food) apparently . I recently went on a Prince 2 foundation and practitioner workshop with The Knowledge Academy in a Plymouth Hotel and the trainer was really experienced. +1 for Global Knowledge too, although I'm not sure if there's a centre in the region.
  9. Vmware on a dell VRTX box, big raid array. vSphere replication using a separate dell server with a Dell SAN attached (iScsi) - separate physical location on site to main servers vSphere also has a Synology 8 disk NAS as a target - separate physical location vSphere twice yearly backup - USB 3, manual task. Users also have access to the 365 environment although the majority of data is local storage. Emails are hosted in the cloud only (365). +1 for vSphere from me, best solution i've used yet
  10. little update: I've modified the RSSI values on the AP's (new firmware and controller) so this has been done through the GUI. I've currently set this to -15dbi which is very very low, after a quick wander around it seems that I'll definitely have to adjust it. From documentation it looks like -25dbi is a good place to start? It's been a few years since I looked at wireless surveying, what I'm surprised at is how quickly signal drops off within the same room (2.4Ghz). 30dbi under an AP to 55dbi within the same classroom, no obstructions. I think we're going to need to mount new APs in the centre of ceilings, our old kit with adjustable antennas seemed to cope a little better being wall mounted. I've also found it's very easy to assume that existing wireless systems are 'ok' in areas where they really aren't. There's so many dead spots(v.low signal) around the school that existed prior to my arrival and persons have just worked around them for years. I'm starting to think that the expensive pre-existing cisco system doesn't cover a wider area per AP after all. We're definitely going to have go down a single AP per classroom = 30 students BYOD, 1 teacher byod + school owned devices = 62 devices connected minimum, we're pretty much one2one throughout the school. It seems that even if we go with Ruckus that 'may' support 120 concurrent devices, that's going to be pushed over x2 classrooms! to get 5Ghz into each classroom I'm guessing we need to have a single AP per room.
  11. Sounds good, do you mind if I ask how many APs you have vs device count connected? I could really do with ZHO but have been a bit scared of running it on the Unifi kit (we run it on our current Cisco gear). Ta
  12. Take a look then post up issues and i'll try and help. Thanks
  13. I've just updated a thread on our Unifi Radius setup, I've dumped a load of screenshots with some details which might be useful for anyone reading about Unifi kit (or wireless in general I guess). http://www.edugeek.net/forums/wireless-networks/159690-setting-up-ubiquiti-unifi-wifi-radius.html
  14. Hi, Thought I'd add a few screenshots of my test setup. You'll notice that for the Cisco WLAN controller we only have the single IP added, this is because the controller communicates with the radius server rather than from the APs as with the unifi setup. For the Unifi AP's each IP has to be added as a Rad Unifi settings config to hit the radius server: Group policy is one profile containing two SSIDs, this is because our Cisco kit also hits the same Radius server and uses a different SSID (same authentication method).
  15. Ok, well this is part of what i recently setup. Firstly you need to do a bit of reading on NPS (network policy and access services) Understanding and Configuring Network Policy and Access Services in Server 2012 (Part 2) Essentially you'll need a radius server, I installed the NPS role on one of our server 2012 R2 VMs. 1. run a NPS server - This is the tricky bit, i'm happy advising but you'll need to have a read about it all first. There's loads of guides on the web and it's not a difficult as you might think. https://technet.microsoft.com/en-us/library/dd283091(v=ws.10).aspx 2. setup a couple of SSIDs: @dry this first one would solve your problem, remember - no user input whatsoever. Once deployed you could just switch off your old SSID, all client computers connect themselves to your new prefered network. one of these is going to permit connections from your AD joined machines, you'll need to setup a certificate that's deployed to all client machines. You can use a standard GPO to connect to the wireless SSID using peap. This means that all your AD joined machines will automatically have the wireless profile added for the SSID you have already created, they'll authenticate and require no input from the user to connect to the wireless SSID you're broadcasting, it can be hidden if you like. Second network is for BYODthis uses the radius server to authenticate clients using their AD username and password. What you end up with is domain joined machines that just authenticate and connect to your prefered secure wireless SSID, and then another SSId that's broadcast that only permits users with an AD account that exist in a particular security group. That for me at least ticked a few boxes. Obviously you could also run a guest SSID hitting a captive portal etc. Best practice would be to VLAN off your different SSIDs too to keep your domain secure... I'm happy to do some screenshots etc or provide more info.
  16. Hi, @Chris_ - I'm currently working with x30 Cisco Aironet dual band APs with a hardware management controller that will support up to 50. Since Cisco purchased Meraki their focus has changed somewhat and our particular controller doesn't have many supported APs left on the market. Unfortunately with no redundant PSU and licencing from Cisco at the moment the controller it's a nasty single point of failure(it would also cost 5k+ to replace). For testing purposes I'm running a 8 port ubiquiti toughswitch that apparently supports the 802.3AT standard (their 5 port doesn't support this), I realise these square units draw a lot of juice and we're running x2 of them from supplied POE injectors. I dipped my toes in with a set of 6 Unifi units with the thoughts that if they're not suitable for the secondary, they probably/hopefully would work for a primary I support (70 on roll). @Blue_Cookeh - between 27 and 35 devices connected to an AP with almost all of them on 5Ghz and authenticating using 802.1x back to a windows radius server. Today after updating the controller and firmware (hadn't updated since before xmas) we ran a test with 32 laptops all streaming youtube and bbc iplayer, no problems to report so far. The kids are back in tomorrow so I should get more feedback this week. Changes made - I've now assigned manual channels to the APs as we're not running ZHO and I'm pretty sure the auto function wasn't doing a lot for channel selection, I mapped it out nicely. RSSI has now been set to -15 which is obviously a bit low, i'm just being cautious. Any other ideas? Does anyone run zero hand off in a secondary with a lot of devices? I got he impression this could cause some performance issues with the unifi kit. All suggestions welcome! THanks again.
  17. Hi, These are my current experiences of Unifi kit: Testing out x6 Unifi AC Pro AP's (square ones), running x3 SSIDs two of which hit a windows radius server for AD authentication methods (computer and certificate authentication for school owned computers and then AD user account auth. for BYOD). We got off to a good start, setup was simple and everything seemed to be going well. Zero hand off was turned off, we're broadcasting on 5+2.4Ghz. The APs are running from an 8 port Ubiquiti toughswitch(PoE ), unfortunately when heavily loaded an AP just stops broadcasting and seems to freeze/restart. A simple power cycle from the switch fixes things once the AP comes back up...very odd behaviour which pointed to insufficient PoE supply as these units can pull a lot of juice, the switch in question is designed for the job though so we ruled this out. Over the half term just gone we updated the controller and firmwares on the APs as it was a good few months out of date, we're just about to start testing again now. So all in all a bit disappointing so far, I had really high hopes and wanted to start phasing in a lot more of the newer APs. Fingers crossed it's a firmware issue that's now been resolved, a little scary though when we have around 2000 devices connected at any one time. Without initially intending to highjack this thread, has anyone else had problems? Thanks
  18. Hi, bit of an old post but I've just implemented a windows radius server for AD computer and byod/AD username authentication methods (x2 SSIDs) for some Unifi gear. Let me know if anyone needs a few pointers. Ta
  19. Our feet are moving, not fast enough for my liking due to contracts. Yet again today, transparent proxy will not allow Outlook to connect to 365 and users can't even access the 365 website. Tested externally, tested on non-transparent proxy = fine. Connection issues are sporadic with some machines working others whilst others don't. No notification of issues from RM and this is the 'new higher capacity service' (I've lost track of the number of times I've been told it's been improved). It looks like we're going to manage to get a smoothwall UTM in place before the end of our SWGFL contract and then request a bypass for the proxy farm. RM or @AJWhite1970 how about refunds for a service not being provided?
  20. Hi Steve, are you saying you have a customer who uses SWGFL's internet connection but an alternative proxy and filtering solution? I thought this wasn't up for discussion, by that I mean SWGFL wouldn't provide an unfiltered connection? If we could implement a Smoothwall UTM appliance before we exit SWGFL that might work out ok for us (all be it an additional cost). Thanks
  21. Not me! Unfortunately it was a business decision that started before I came into employment.
  22. Thanks for the reply Jamie, however our connection was down long before 8am. I'm guessing it was only noticed just before 8am because that's when people who check these things are employed from, or thereabouts? Is there some kind of support available outside of the usual hours (£2k a month connection here) are we just to wait if our service goes down on a busy morning, evening or weekend? Our problems for the last few years seem always to have been with the proxy service, no line faults I'm aware of. Last week I received a random call from SWGFL to assure us 'you've been moved to the new higher capacity proxy service'. I wasn't aware this was going to happen and we'd supposedly been 'moved to a new proxy service' earlier in the year. PL12 4AY is our postcode if you'd like to take a look at service log details. Thanks for all your help, I honestly do realise that as individuals you all try to provide a great service. It just feels like the machine 'SWGFL' can't provide a reliable proxy connection, we've already a planned solution in place but being tied in contract limits my current options to well, none. It's frustrating when I look at the solutions Smoothwall UTM and similar products provide.
  23. Sorry I should perhaps have added that the chap that we spoke to on the Technical Service desk was also helpful and polite. I certainly have no problems with the helpdesk persons, they provide for what they can a great service IMO. In fact individuals at SWGFL (not just helpdesk) I've dealt with have pretty much always been very polite, they just aren't in a position to 'fix' the on going service problems we have. The reason for a wait at 7:50am is their opening hours, which is however a big problem when staff turn up from 7am and leave late in the evening and I'm sure this is the case with many school. When we're paying over 20k for a service that does go down far more frequently than it probably should (I'm referring to the proxy generally), having a non 24hour support line is very frustrating. My home internet connect has less issues that our premium SWGFL service and it's 40 times cheaper, I realise it's not the same type of connection but at least the service is there! SWGFL: Our Service Desk is available 8.00am - 6.00pm, Monday - Friday.
  24. SWGFL down again early this morning for us. It happened before 8am so a great service as always (tinged with sarcasm): 1. No update on status page 2. Support line not open till 8am 3. No call or notification from SWGFL once they were open. 4. Eventually got through on the phone support and was told there had been a 'major proxy outage'. How bad does a 24k pa service have to be before we should be permitted to exit with no charges outside the contract period? Am I over-reacting, opinions welcome. Rant over.
×
×
  • Create New...