Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Primus

Members
  • Posts

    2,232
  • Joined

Everything posted by Primus

  1. They're not going to replace a core switch, but for edge switching for most schools they're perfectly adequate and they're so cheap you can have plenty of cold spares - of course if they don't have the functionality you need then you can't consider them but if they do then I'd definitely recommend them - we run them across all of our schools for edge switching and WiFi. We have the smaller brother of the 5412 at the core of many of our schools - the 5406R zl2.
  2. Can you share the details of the repairer please - we've got loads of these and we've only ever had 1 with a dead PSU and it died with in 2 weeks of install so was a simple supplier replace job, but I know it's only a matter of time given how many we have (we've plenty of cold spares so waiting for a repair etc isn't an issue as it would then come back into stock as a cold spare).
  3. localzuk is right, you can rearchitect this with Smoothwall - we run 2 UTM virtual appliances that are child nodes hosted in our ISP's data centre at two different Internet breakout points for us and an S14 physical appliance (due to be replaced with an S15 soon) as a reporter/parent node. Across the trust every school is on our WAN, every school has a 1Gb MPLS connection back to our ISP who handle routing at this level - each school has a preferred breakout but can failover to the other in case of an issue with one. Every school then has a further 1Gb point to point leased line link to the nearest school in the trust to it - we then make sure that each school is effectively connected to both ISP data centres - eg. School A connects to data centre A and to school B. School B connects to data centre B and so across their two links can hit either breakout. We make filtering changes on the parent and it pushes them to the 2 child nodes - the only thing it doesn't do is firewall changes - you need to do these on the 2 child nodes. It's stable and reliable.
  4. Has that changed as I think previously you only got back the tax you had paid on the fee rather than the whole fee?
  5. Indeed many of us at the time used expressions such as "don't throw the baby out with the bathwater" and "be careful what you wish for". Have CS by all means, but having CS doesn't mean we have to remove IT/ICT - I say that as an experienced teacher with a CS background. Little by little the qualifications we have available to us have shrunk and had really good components removed, we've seen a steady decline in students wanting to complete the limited qualifications that are left and the challenging nature of CS means there aren't enough teachers willing or able to teach it whereas lots of them were probably quite at home teaching GCSE ICT for example. The attitude at the time from BCS was very led by people who seemed to specialise in telling serving practitioners what both the problems were and the solutions whilst sticking their fingers in their ears when those practitioners tried to put them right.
  6. It's not about quibbling, it's about proper use of resources, why spend more than you have to?
  7. Hold up, are you actually using iSCSI?
  8. Hi all, the TV licence guidance is (probably deliberately) vague - are any of your trusts licencing the trust rather than the individual schools?
  9. You need to find the iSCSI IP addresses, the management ports are unlikely to carry the iSCSI traffic so adding them is unlikely to have worked I would have thought.
  10. I generally follow the manufacturer's guidance, they say not to use it so we don't. If we ever needed to get support the first thing they'd say is you shouldn't be using LTSC.
  11. Microsoft say you shouldn't use if for general purpose devices. "The Long-Term Servicing Channel is not intended for deployment on most or all the PCs in an organization. The LTSC edition of Windows 10 provides customers with access to a deployment option for their special-purpose devices and environments." I'm sure we've seen issues with LTSC not supporting the latest CPUs and being unable to be installed on them previously - back when it was LTSB possibly? You're getting zero feature updates/upgrades and falling further and further behind the experience people are used to from their personal devices.
  12. I totally agree, people shouldn't be using it on general purpose PCs but sadly I think we might see people starting to use it because of the October 2025 end of life of 10 SAC.
  13. We've seen nest AD groups not work at all over the whole time we've been with Smoothwall so we made sure our filtering groups weren't nested as a result. This is mapping through AD but using iDEX to track user log ons etc.
  14. I'll be the killjoy - unless they're on a totally isolated vLAN and even then - is it wise leaving such old and long unsupported devices connected to your network?
  15. It's appeared here too, I haven't had that error message however.
  16. Yes it very much sounds like organisations that want access to your social media account beyond what can be seen publicly are massively over-reaching.
  17. It still hasn't shown up for us (Google Workspace for Education Plus) - is it rolling out gradually?
  18. Very annoying, not least as it doesn't follow the NCSC guidance.
  19. This is normal when you use iSCSI on a NAS. However you can plug the NAS into any server and map the iSCSI again and everything will be accessible.
  20. Strange - we never saw this issue when we used the Smoothwall to provide DHCP for our guest network (we don't use the Smoothwall for this anymore but not because we had issues) and we've got loads of AC Pros and guest network users.
  21. You're totally correct but it involves re-architecting networks and putting in place ACLs etc. As it stands guest networks cannot touch anything other than the Smoothwall. To move to using NPS for this we would have to allow limited traffic to flow - opening any routing or holes from the guest network is potentially problematic and even more so with Cyber Essentials and scoping of devices etc. Far simpler to just have the vLAN the guest traffic sits on not route and only hit the Smoothwall.
  22. For lots of us though that's not really an option as we isolate guest networks completely from the server infrastructure so that all they can hit is the Smoothwall unfortunately.
  23. Unifi U6-Pro APs - circa £153 each - £3366 - no need to buy a controller as you can simply run it as a VM on (hopefully) existing infrastructure.
  24. If you email [email protected] with the name of your school(s) and URN(s) they will confirm if you are or aren't included. It's not just schools who are RI or I - it's all schools in Priority Education Investment Areas - no matter their grade. The requirement to be RI or I only applies if you are in an Education Investment Area (not a Priority one).
  25. Eligibility is based on either being in a Priority Education Investment Area in which case all schools in that area are eligible or being in an Education Investment Area with an Ofsted grading of 3 or 4. I believe they are calling schools forward in waves to try to stagger the demand.
×
×
  • Create New...