Jump to content

catch21

Members
  • Posts

    122
  • Joined

  • Last visited

Everything posted by catch21

  1. Are you housing "everything" in one location? You need to consider carefully your 19" rack layouts, temperature control and UPS provision. I'm not seeing why you need so many servers or why wireless isn't right up there at the top of your list. It's a real problem-solver.
  2. I like the thinking.
  3. I've a dilemma. I'm replacing the core switch at my school. [i can re-use the existing switch as an access switch if necessary so that's staying in the rack.] I need PoE so I can directly connect our 12 no. Ruckus APs to the core. Clearly the server is going on the core, plus the firewall connection, photocopier, cache server etc and that's about it. Just about everything uses the network over the wifi nowadays. All the children's laptops, staff laptops, most everything which means the copper network is basically redundant apart from WAP backhaul. Great news then I've gone down from three core switches (loosely arranged in a stack) to one. If I buy a 28-port switch (£600) it will be about 75% used on day one. If I buy a 52-port switch (£1100) I'll have a load of spare ports but they may never be used. The safe decision with someone else's money is to go for the 52-port switch. I don't always do safe decisions very well. If I buy a 28-port switch and genuinely need more core ports I'll buy another 28-port switch and interconnect them with 3 or 4 links in a LAG for example. If I need more access ports next week I'll re-ignite the old core switch and re-deploy is as an access switch. I don't know how two 28-port switches linked together would perform as a n/w core compared to a single 52-port although I would assume when the n/w is hugely busy, not as well. I can't see an obvious decision here, 28-port or 52-port, do you have any thoughts?
  4. Sorry I've come a little late to the thread. I know precious little about all this in relative terms but I have just put a Ruckus wireless solution in my school and its superb so there must be some configuration issues. We can have two laptop trolleys (60 laptops) in the same area of the school (two APs) and have no issues whatsoever.
  5. I goofed with the switch ID folks, sorry. Its the other two that are 4228. The one I'm working with at the moment is a 3Com 2928, which I think does have IPv4 static routes in the Network tab.
  6. Apologies for the triviality of this, I'm trying to understand stuff. If I have made 2 Vlans, nominated which port on the switch is on which Vlan (3Com 4226T), I just make an IPv4 static route to connect them, is this right?
  7. I'm sure you're right, but I'm quite a strong swimmer
  8. Thanks. It's the point of convergence of the networks that causes the conflicts then. I hadn't quite got to that part - clearly! This isn't exactly hypothetical. I'm a facilities manager with a background in the field but my knowledge is somewhat out-of-date. I've just installed a new wifi network and just coming back up to speed. Next is to upgrade the switch core. For some reason I haven't been able to figure out, we are told what IP address range to have on the private side of our network by our broadband/service provider. They also provide firewall and filtering so our delightful children do not download anything that might shock the teachers and I'm guessing this might have something to do with the restriction. Up to now we have been issued with a /24 address i.e. 256 hosts and I considered this may not be enough (!) with the explosion of mobile devices that is just hitting us out here in the sticks. (We're not really at the cutting edge of technology here.) Our new address range is /22 i.e. 1024 hosts, or 1022 if you exclude the reserved ones. With nearly 500 children and 40 permanent FT or PT members of staff I guess this'll do us for a few more months. With the new vlan-aware capabilities of the ethernet switches I am planning, I'm trying to figure out how (even if) to partition the network. The new wifi is ruckus ZD1100 and 7636 APs incidentally. I guess where I am at is that if I am partitioning the local network into vlans I will be splitting the host id part of the IP address, but then all hosts would have to share the same DHCP server etc, so I don't see how it will all fit together?
  9. I have read "you cannot configure two vlans with the same IP address range". Why not? I thought the whole idea of vlans was to effectively implement two networks on one switch, by the addition of tags containing a vlan id? So why can't I have red 192.168.0.0/24 on vlan 10 and blue 192.168.0.0/24 on vlan 20? I know there's a good reason, but I can't figure it out at the moment.
  10. Thanks. 52 port is 350mm depth max. Can only fit a 600mm deep cabinet in the closet. Good enough I hope.
  11. Genius idea, thanks .
  12. This question is all about laying out racks. I've the greatest job in the world at the moment: replacing the entire ethernet and wireless access networks at our school. I'm working with the legacy cabling which is a bit naff but at least terminates in labelled patch panels mounted in a 12U 19" rack high in the comms cupboard. Underneath the 12U rack I'm going to floor-mount a new 28U rack (with trunking in between) and lay it out with: 1 x 52 port switch (1U) 2 x 10 port PoE switches for the wireless APs (2 x 1U) 2 x WAP controller boxes (2 x 1U) 1 x mains distribution outlets from the UPS (1U) 2 x mains distribution outlets (2 x 1U) I'm looking at a variety of cable-management products and I'm guessing what they're good for: a) brushed cable entry (neatly gets from inside the cabinet to the front) b) ducted cabled management (neatly moves vertical cables side-to-side at the front) c) cable tidys (bunches cables to move them off sideways - can't see a lot of use?) I've kind of got a plan to install the main core 52 port switch about 2/3rds of the way up with brushed cable entry panels above and below, then install one 10-port access switch above it and one below etc. One rule I have determined I'll need is to label every patch cable at each end with a unique reference number, probably using a simple label-printer label wrapped around unless there's a better solution? Does anyone have any design guidelines for laying all this lot out please? Any thoughts?
  13. Superb, thanks. I must have misread or misunderstood something along the line as I thought I could go from 9.4 to 9.5. Its working at the moment so fingers crossed.
  14. in trying to upgrade from 9.4.0.0 build 110 to the current, "Not enough memory". I can scarcely believe there isn't enough memory on the box so am suspecting another issue. Does anyone know a quick fix to this problem please?
  15. This is the old two-dresses problem. "I've seen a dress for £80" ...that seems a lot... "but I bought one for £40" ...thank goodness for that... I like the fact it says £15,000 for a 500-pupil school, that way at £8000 I can do it for half the price. Where's the Ruckus catalogue gone?
  16. Guests are not students but visitors to the school.
  17. Thanks for the help. I should have explained myself better. I intend to have 3 types of access: 1) School-owned devices (internet, printers, file servers etc) MAC acl, WPA/WPA2 2) Staff-owned personal devices (internet only) MAC acl, WPA2 3) Guest devices (internet only) via Captive Portal, no encryption I was trying to build the MAC lists easily for 1). But now I see, should I care about guest packets being sniffed?
  18. Because I want to limit it to staff only, rather than have a free-for-all with 500 kids and potentially a couple of hundred parents at any one time. This basically shows my lack of knowledge I appreciate, but how else do we retain some sort of control over who is getting onto our network and using our internet access? Sorry, just edited to add: not everybody knows everything about everything. Y'all seem to be getting cross with me for being a bit clueless.
  19. Not all devices will be windows. I do want to (safely) open up a staff BYOD SSID for internet-only access plus a guest pass system for bona-fide visitors on a guest SSID. It will predominantly be windows but also Android and Apple devices.
  20. So essentially all I can do is what I am doing at the moment, i.e. WPA and WPA2? I feel that once the passphrase is out in the open which is only a matter of time, any child can come along with their own device and get onto the network? I'm not trying to build Fort Knox, just a garden shed with hinges bolted through, a decent padlock and maybe a battery operated alarm. Just enough to deter the opportunist and maybe slow someone down. I'm guessing MAC addresses can be spoofed and possily intercepted to make finding a valid one easier but if someone is that determined they're going to get in somehow.
  21. This is for 100 plus school-owned devices rather than BYOD. Various problems exist not least of which is my lack of knowledge, and IT Techs lack of capacity to locate all the devices in the building and set them up individually. My way of thinking was that any device that hadn't got onto the WLAN in four weeks wasn't worth worrying about (for example we have two members of staff off on maternity leave at the moment). I was hoping that any device that had gained access might be recorded somewhere, maybe exported as .csv and re-imported as an ACL. Incidentally if MAC based ACLs are pointless, what is the solution bearing in mind we have a wide variety of equipment,some of which does not even have WPA2?
  22. I've just replaced our ageing wifi with a Ruckus system of 1100 controller and 7636 APs. We've 100+ school-owned devices out there but never before had access control and need to implement this. With that number of devices to get through is there an easy way of collecting data on everything that attaches to the network over the next month say, and use this as the basis for the access control list? The ZD is running 9.4 at the moment to be updated shortly.
×
×
  • Create New...