Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Primus

Members
  • Posts

    2,232
  • Joined

Everything posted by Primus

  1. Your expectations are way too high for the price you're paying for Unifi equipment. However you get a minimum of 1 year notice a product is going EoL and it seems to be a minimum of 5 years support from launch but for some products has been longer I think.
  2. The issue with Meraki is the licencing is expensive and, unless they've changed it since the last time we looked, your Meraki equipment stops working completely 30 days after your licence expires if you don't renew it. Which Unifi APs have you been annoyed with going EOL? All manufacturers will mark equipment EOL after a certain amount of time.
  3. If you've got time to concentrate on it, understanding of how to configure switches and the documentation you need then it's not hard. I configured our core - it took a little longer than I was hoping but that additional time was measured in hours not days! I spent some time prior to this reviewing all our documentation and reading the implementation manuals from HPE carefully. I also found some YouTube videos of others setting up the same switch useful to visualise things prior to the kit arriving etc. Ultimately if you get stuck someone one here will help you out but if you're at all concerned I can recommend SwitchShop as I know they provide kit at good prices but also have support available if you get stuck (they'll often even do some assisting for free for schools too!)
  4. Primus

    VSCODE

    Ok, so for argument's sake let's say you have an eSafety application running such as NetSupport DNA - if you grant access to Task Manager students can now forcibly quit this application. How do you prevent them from doing that?
  5. Primus

    VSCODE

    If you block CMD properly then you can't get around it. There is of course a balance, however under the Data Protection Act you are under a legal obligation to ensure that certain data is protected etc. I don't consider blocking CMD and PS to be harshly locking down a workstation. Even if your users are entirely harmless, there's nothing to stop them accidentally infecting your network with ransomware etc.
  6. Primus

    VSCODE

    Ok, so I'm assuming you also don't block CMD?
  7. Primus

    VSCODE

    Do you block access to PS?
  8. Primus

    VSCODE

    There are ways around this such as signing your scripts.
  9. Primus

    VSCODE

    For context - as well as managing our infrastructure I'm also HoD for Computer Science so I get the balancing act that's needed and you can't be too restrictive! However there's no way I'd allow access to PowerShell to any of our end users.
  10. Primus

    VSCODE

    I'd seriously look again at this, if you're not limiting their access to PowerShell then there's a whole range of exploits available. Out of interest do you limit their access to CMD?
  11. So what are you using device access policy to do? RADIUS is supported and works fine here with Smoothwall. WPAD is not something that is supported by your WiFi - it's a network level configuration so Unifi obviously supports that. Unifi is vLAN aware. What AD integration are you looking for - this is usually tied to RADIUS through NPS which works fine. Meshing works but I wouldn't do it - with any provider! DHCP relay is supported. If you want to use intrustion detention or prevention you'll need a USG - what are you wanting to do IDS or IPS on and where in your network do you currently perform this?
  12. Primus

    VSCODE

    Interesting. So do you limit what they can do with PowerShell then?
  13. Primus

    VSCODE

    I mean I agree with asking what exactly wants to run in PowerShell but I'd consider blocking PowerShell to be pretty standard in education settings - asking why it's blocked isn't helpful.
  14. There have been issues yes, but you could say that about almost any vendor. If you take steps to mitigate such as hosting the controller locally and not connecting it to the cloud, using MFA etc etc then you'll be fine.
  15. Which services in particular are you wanting to know about since that's just a screengrab of a UI as far as I can see?
  16. Unifi supports RADIUS, BYOD etc. I've got nigh on 100 APs in a decent sized secondary school with loads of Chromebooks and other WiFi devices and it hasn't had a single issue. If you list all of the features you need someone on here will be able to identify if there are any Unifi can't do (unlikely). When I went with Unifi for ours I had all the horror stories from other vendors, the usual bad-mouthing of alernatives and upstarts like Unifi. In the end it saved us an absolute packet and has been (touch wood) spot on. When I'm replacing the WiFi at other schools I'd obviously get quotes for all the possible options but given how cheap Unifi is and how good it's been for us I wouldn't hesitate to go with them again.
  17. We use Ubiquiti Unifi WiFi and edge switching and we have a pair of HPE 5940 switches at the core.
  18. Before you spend money on an AP do you know what speeds your GB powerline adaptors are actually giving as it can be quite low in practice.
  19. Shock, teachers have actual names. The kids know their names anyway.
  20. No, you can't change just for Classroom. The only thing you can do is change their firstname on Google Workspace for Education to Mr, Mrs, Miss etc.
  21. What was the price for named user licences? We've been paying £20.10 per licence for shared device licences.
  22. There must be a reason why Google are repeatedly flagging them.
  23. This isn't Google making mistakes here - CPOMS have to be doing something odd at the very least for this to keep happening.
  24. Isn't the law that 50% of the sides have to be open?
  25. In the past we took the view that if we supplied the device and the connection (eg. a 4G hotspot) then we would filter and report, if we only provided a device on loan then it was up to the parent to ensure filtering etc at home and we had paperwork for this. However when the DfE Covid scheme happened it became clear their expectation was that all devices that were loaned were filtered and reported on when offsite - even if we weren't giving them a 4G hotspot. So we changed our processes to fall in with the DfE's expectations - now any device loaned to a student is filtered and reported on in the same manner whether it's onsite or offsite and our documentation makes this clear.
×
×
  • Create New...