-
Posts
1,977 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by FragglePete
-
That's something I'm trying to understand right now. The configuration obviously goes down from the controller to the APs themselves, so for PSK it'll work. I'm wondering what will happen in the case of WPA3 Radius? Is it the controller doing the authenticating with our on-side NPS Server or are the APs with the configuration doing to direct talking to the NPS server and authenticating users? So, if the controller does go pop over night, will RADIUS authentication still work? Pete
-
So, do we start panicking yet ? Downloading what I can, but the only thing I can export from cnMaestro is the Wi-Fi Profiles Config. Seems to be no way for an end user to 'backup' their cnMaestro Cloud set up. Pete
-
Interesting article, and it makes some good points on the Cambium Stuff. It's good hardware. It works, and it works really well. Since having it installed over three years ago, we have had zero problems with it. No issues. No one has complained about Wi-Fi performace or any dead spots around our site, the only issues we've had has been down to the NPS server onsite with RADIUS authentication after a dubious Windows Security Update. Upgrading the firmware on the APs has always worked with no fuss. Just updated all 94 APs we have to their latest firmware over night, and I've come in this morning with all APs up and running. Interestingly, I'm getting a new notice in cnMaestro about an update to 6.3.0 happening on Wednesday. Automated? Or is someone still plugging away at it. Hope it gets rescued in some form or other. Pete
-
Hmmmm..... Not happy. I've shouted about how great Cambium is/was for years - let's hope something gets sorted. From what I can gather, to convert from Cloud to On Prem, you need to get your database exported by Cambium Support to then import into your On Prem device. What are the chances of support actually still there at the moment? I'm still looking. Also, the download for OnPrem is for 6.0.0, whereas the cloud version is 6.2.0. Ours was installed during the Summer of 2023 - disappointing if we have to find something else - Governors are going to hate me. Pete
-
Guilty as charged! Fell off ladder cutting one rouge branch off a hedge at home - only a few rungs up. Snapped Achilles Tendon on landing resulting in operation to repair and twelve weeks on crutches..... then four years later an infection from the internal stiches results in what was described as 'limb reconstruction' by the plastic surgeon, 15 nights in hospital! Still plays up from time to time some tens years on. Get a tower; do it properly. Pete
-
Should be a alluminium tower and you'll also need to get your PASMA certification that certifies you to build and climb it. Without that, your breaking all sorts of Health & Safety Regulations. PASMA should only be day out in a classroom with the afternoon actually building the tower, most builders merchants run the courses and has be renewed every five years I believe. Pete
-
Raised a call, and 'Vizzy' told me it's being passed to a human - since then, I've heard nothing... zilch. Na-da. Very disappointing. Pete
-
Same here, just 802.1X authentication. The captive portal is in place for users accessing the Guest Wi-Fi and we generate printed tokens handed out to visitors primarily. Agreed that Chrome/Android devices are a pain to get enrolled on WPA3, so I give a rare hat tip to Apple for making their implementation really easy. Password lock outs can be problematic - we lock out accounts after 3 incorrect passwords and if users don't update the password on their device then their account is continously locked. We get a notification from our DCs when a lock out occurs so we can usually deal with it quickly if need be. Users are becoming more educated about it and we make a point of telling them when we do a password reset they need to update their mobile devices as well. We monitor usage on Cambium to see if we have multiple devices assigned to one particular user, and can tell if they have devices logged in at multiple places across the site which would indicate password sharing has occurred. We allow our Sixth Formers BYOD access and they have been known to share passwords to the lower school, who then shares it to their friends, etc, etc. In these cases, BYOD access is revoked permanently.... no excuses. Pete
-
Also RADIUS auth via NPS server (which requires a certificate to be installed). Only downside is the logs are not great unless you pay for the cnMaestro X license which also opens up better authentication methods I believe. You also need that for Azure SSO authentication. Ours was configured by Lee at Redway Networks. Pete
-
We have Cambium that was supplied and configured by Redway Networks a couple of years back. Superb kit for the price point, we've essentially had zero wi-fi issues since having it installed. I would like a bit more reporting and proper access to logs but this does involve buying the cnMaestro Pro licenses to get this (and more), but the free version works well enough for us. Pete
-
Net2ADSyncServer - Inventry to Paxton to AD to Papercut?
FragglePete replied to AlphamaleZed's topic in How do you do....it?
We've been using Net2ADSyncServer for several years now. Does the job for us quite nicely. The process for us is that a user (be it staff or student) is given their badge which they have to register on a MFD (running PaperCut) using the AD account. This creates the Card ID number in PaperCut. I have a script that runs automatically every 30 mins of so that dumps a userlist with their card ID number and this is copied into the Fax number of their AD account. The Net2ADSyncServer system then generates the necessary user account in Net2 based on their User Groupings in AD. However.... Net2ADSyncServer has recently been acquired by another company and are moving over to a subscription based version of the software to support the newer version of Net2 (2.7 I believe?) and claim their current version won't necessarily work on the newer Net2 installs. Before that it was just a perpertual license with free updates.... remember those days? I'm looking to rethink this now in the future, as we use Locker and I know we should be able to use this to create accounts in Net2 which will mean that we will have to manually register the cards against the user - just something I won't enjoy doing for the influx of Sixth Form students each year. Pete -
Which suppliers in the UK have these in at the moment? I usually use Broadband Buyer and/or 4Gon as we have accounts with them and the pricing has always been good with those guys, but they don't have them listed yet. I can buy them directly from the EU Store with Ubiquiti but that may prove difficult with a school credit card, etc. Pete
-
I'd be interested to see if someone testing these can try this for me: Spray some deoderant in the vacinity of these and does this cause an alarm? We tried a Vape Guardian sensor a while back and this could be triggered by an aerosol deoderant which caused all sorts of embarassement and hassle with a parent who we accused their daughter of vaping. SMT spray a deoderant near the sensor and that caused an alert - the system was pretty much deemed useless from that point forward. Vapeguardian claimed they could tweak the settings but by that point, the damage was done and no matter of tweaks made any difference. If this Unifi solution is as good as it claims, I can see the likes of Vapeguardian not existing for much longer. Pete
-
yep, thanks - that worked. Did see that elsewhere but it just seems a messy solution to muck about with registry tweaks with GPOs. Still, it's in and it works - thanks. Pete
-
Well, <sarcasm> this was a nice surpise from Microsoft </saracsm>. The latest security update (2026-06) has been applying to PCs around our school and it completely changes the way the Start Menu works! All the Apps now appear within 'Category' blocks at the bottom of the Start Menu, which you can change to Grid or List. Start policy settings | Microsoft Learn In a way, I think overall it does work better - but why as a security update has this happened? I downloaded the latest ISO from Micrsoft (May 2026) and installed this thinking it was part of that release, but no, it's only when it applied the 2026-06 update did the start menu change. FFS! Playing with this, it would appear the .json method of pinning items now does appear to work correctly (and doesn't break the start menu like it did before), but the GPO to 'Hide Category view in the Start Menu' which should default to Grid View which shows installed apps as a proper list does not appear to work. Well, I can't get it to work. Is it just me? Anybody else slightly miffed at this? Just trying to sort our install for Summer and where I normally just give MDT the latest .ISO to work with (I know, I know, but it works for us for now) and let it install the updates as it goes, this 'security' update seems to take an absolute age to apply during the task sequence. So, seeing if a Sysprep and Capture will work now to get things working quicker. Pete
-
Can you not just do e-mail alerts, or do you have to have an audible alert device configured? Pete
-
Do you route between VLANs at all with this setup? Pete
-
While I have the sort of green light from Governors to get our Core Switch replaced and I have a 'rough' budget to work too, they're still querying how much it'll actually be - engaging suppliers on what will be a small tender competition is only going to p*** them of if I don't go through and I know pricing for hardware is volatile at the moment, so a quote I get may only be limited for a short period of time; not enough time for when the finance committee meet again - it's bit of a joke really; the joys of internal public sector finance. Ours core switch is a 5406zl - running since 2009 (!) and the modules have been upgraded over the years (with re-conditioned units) to give us some 10Gb connectivity to the Servers and some 'heavy use' Edge switches. I've got some options I'm looking at, with some feedback from suppliers and what I've garnished on here. Option 1. Get a new 5412zl2 which is still supported and sold by Aruba, so the warranty will follow their 'Limited Lifetime Warranty End Of Sale + 5 Years' - which at a minimum will be 5 years and possibly more as there is no published EOS date yet - almost a like to like new replacement for our current switch but with more capacity for getting all our edge links to 10Gb along with Dual Managment Cards, Multiple PSU, etc meeting from what I can tell the DfE Specs (although I need to confirm the finer details). Fully populated, it'll completely use up our 'rough' budget leaving nothing left for other projects I would like to get done. Option 2. These 5412zl2 's are popping up on eBay from various refurbs companies, and fully populated are a third of the cost of new - come with a warranty from the suppliers of at least 3 years, and who knows, it may fall under the Aruba LLWE-EOS + 5 Years warranty. Option 3. eBay again, but find a 'cold spare' of a 5406zl that we have as I know some people on here are doing this - but, it feels like it's just kicking the can down the road especially as the Firmware is not being updated for these devices so would fall foul of things like Secure Schools philosophy in running up to date supported firmware of all hardware. Massive saving, but just delaying the inevitable. Option 4. Stack Baby, Stack! Again, as mentioned on this thread, get something like a few CX6300's and build a stack with MLAG and build a Core with no single point of failure but will need a fair bit of reconfiguring of the network to do this. Cost wise, looking at @Mr.Ben's post, this could be cheaper than a new chassis based in terms of hardware. Option 5. Move to something like UniFi for the Core Switch - over the years, I've been replacing our aging HP ProCure Switches with UniFi switches purely because the cost savings - but would I trust their line up for the Core? Could be a big saver, and get everything on to that 'Single Pane of Glass' that the DfE are keen for us to have on things like this. I'd have to get assistance from a UniFi expert to help get this in place. Or, something else ? Appreciate anybody reading this. Just a bit of sanity check. Our current Core does our Inter-VLAN routing with ACLs in place to control access where required - and from what I've been reading up on, this approach may be outdated and some reading indicates this routing should be done on the Firewall, but our Firewall (Sophos XGS) forms part of our managed Internet Connection so not wanting to touch this as it may change if we ever change provider, etc in the future - we just have static routes setup for each of the VLANs on it to allow Internet traffic to flow. I need to now put together the documentation to send to suppliers and see what comes in, but would welcome any input here which judging by the number of 'core switch upgrade' posts over the years on here, may help others too. TIA Pete
-
Vodafone used to have a system called Femtocell - which enable mobiles phones to latch onto it's own mobile phone signal hooked up to your Internet Connection - I think with the advent of WiFi Calling, it's long discontinued.. My neighbour and friend was the programme director for this system many years ago. Pete PS. Sorry - not a helpful post
-
These were Atlas TT7520ER, TT-7521Q and the Lyra Series Models - so no, not C Series but overall we've been happy with Newline. Pete
-
Newlines here - installed about 80 a few years ago. No major issues - a few quirks but people got used to them. Stone Computers supplied and fitted ours. Pete
-
Same here, been running a 5406zl for some 16 years+ now.... but I've just heard (unofficially) that governors have approved my request to spend a lot of money in getting this replaced with something. Undecided what to do right now - what is the current thinking these days with Core Switches. Ours acts as the core and does the L3 routing between VLANs with ACLs in place to control access for various parts, with it being the gateway for each VLAN. Do I replace it with something similar in the Aruba line doing the same role? Or go for somesort of Unifi Ag switch - alot of my edge switches are Unifi and I'm slowly replace older units to be UniFi Or get spares from eBay to act as a cold spare (not ideal, with it not being officially supported now) Pete
-
Bodet here also. Installed it ourselves. Software is clunky AF but once set it just looks after itself. Have to ensure that Multicast is enabled on your network for it to work correctly, especially if you have VLANs in place (IGMP Snooping if you use Ubiquiti switches). We have it sitting on it's own VLAN. Pete
-
Juniper Education - Ts and Cs warning - Auto purchase of products
FragglePete replied to Synkrox's topic in Cloud Services
Ask for a copy of this so called 'feedback', with actual schools that gave it - bet it doesn't exist except the in the mind of the marketing guy. Pete
