Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. What's the problem disabling early TLS? As I understand its a risk... And has been for some time....
  2. I think it’s county rather than town in the url. .I assume you mean mx records? I’m not sure that google would be hosting these anyhow.....but I don’t know who does host them...the DES registers and keeps the .sch.uk domain Have you tried an mx look up for your domain? Does it point to your google domain?
  3. "The new DPO has told us to use passcodes!" Who is "us"? And why? Did you challenge this? If not why not? It may be the right thing to do - but I would want to know what "private" data is being held on these ipads that would make it necessary. And if its private data...and I assume the ipads are shared....and the same common password used....its not going to prevent...for example an ipad being taken home and any pictures on it being viewed....(assuming you allow use of the camera....) ...and if your ipads are "managed"....you can remote wipe... Thinking...world is going mad about GDPR...
  4. ..well I'd be making sure its was networkable to start with...to avoid the problem with the remote control. And yes - I'd be looking at 5000lumens or more. We have an Hitachi model.....
  5. ...well I'd start by asking why....and wondering who is making this request. It may the right thing to do....but simply because you are being asked to do it...doesn't make it a good thing to do. There is quite a lot of useful discussion on line about setting this as policy.....and there is quite a lot of evidence that forcing users to change passwords ends up with users choosing to simply modify passwords numerically - such as password123, password125, password126 - or to rotate passwords depending on the number allowed in the history.... Far better to educate users about what makes a good password in the first place....and reminding users never to use the same password for different systems/logons...so that a compromised password does not make several systems vulnerable. ...now if you were arguing for 2 factor authentication...I might give some support for that.... Those with technical knowledge should not simply and blindly follow instructions...but use that knowledge to challenge whether what is being asked is the correct solution to the problem.
  6. Try tabpilot...there is a free trial available...
  7. Are you getting smoothwall to provide dhcp and DNS on this new VLAN? Or using a static IP and gateway pointing to smoothwall?
  8. There are several ways of filtering YouTube...all well documented...and yes smoothwall and probably most other filters can do it...but no, smoothwall doesn’t do it “out of the box...” and you would need to follow the guides...and probably do even more work if you want to make work with tablet devices...and yes it would be good if smoothwall simply had ticks to enable/disable these things... In fact...I’d be very surprised if your existing filtering doesn’t support safe YouTube access...what are you using? There are..and will be...problems with YouTube clips which are not categorised as you might expect..so a useful clip wanted by a History class about weapons in WW2 might get blocked....and so you will need to work on how you will handle exceptions... There are moderate and strict categories...and with smoothwall, you can do real-time analysis...although I’m not sure how good it is on videos... And no, you don’t need to use google...although it’s free and you can sync your active directory usernames and passwords, use free on line storage...cloud printing and loads of other useful stuff... At a push...you could just use the dns method...if you have no access to modify your we filter other than block/ Allow YouTube.
  9. ...we use D2D2T ...so we have the option of taking tape off site...but actually we keep tapes in a remote and separate building... Don’t think I would be looking at more expense by paying for cloud space....rather buy a few 10TB disks and use windows server backup...and usb 3 connector ...which I think is a much overlooked piece of software.... I’ve always thought that it would be particularly tedious if you had to recover a whole server via an internet connection...much quicker if you actually have a disk with backup on....and you wouldn’t have to worry about using your bandwidth...
  10. ... If you are paying for a managed service... I'm wondering what that "management" covers... Because its sounds to me as if it doesn't include any management.... And I would want a service I was paying for to include management of ports and services... But I can also see that if its part of a managed Internet connection there might be some limits on the number of changes... And if its managed.. I wouldn't expect them to allow you to make changes yourself... Because you could mess those up.. And then expect them to fix it.... You can't have it all ways..
  11. Yes, filtering needs to be age appropriate...with a focus on monitoring and reporting ....simply deciding to block everything is not what we are asked to do....nor do I think its our job - or technologies job to act as beating stick for students...if they play computer games in a lesson the teacher should treat it as a discipline issue as if they were kicking a ball around... There will be some debate - about content delivery sites which often contain unmoderated - but loads of potentially useful material - like for example pinterest.... We allow this for older students - but use the "warning" page of facility of smoothwall ...In theory - smoothwall has content recognition capabilities...but you couldn't rely on it 100%....The fact that some material can be shocking/offensive/unacceptable or whaever is to some extent part of a student's education.
  12. ...and I’d use captive portal with a timeout= length of your lessons for any shared devices ...like tablets. It’s not without problems...because if you don’t open a browser you are not challenged for logon...and apps don’t work...or worse stop working without warning if the session expires. But...it’s probably the only practical solution...
  13. The ballast unit is prone to failure on some projectors...particularly Epson EB440 units for us.....and although a replacement epson ballast is only £40, it’s a nightmare to replace... To be honest, our Hitachi projectors have been good purchases...had to replace gears on some A101 models which have a mirror which automatically folds down and up....but no lamp issues... And we are experts at clearing the dust from SMart projectors when the colour wheel jams... In the early days...we had to work quite hard to persuade teachers not to turn projectors off by the power switch...but use the remote....which of course they lost. The resulting premature failure would prompt us to nothing to replace the projector for an extended period of time citing poor usuage as an excuse....which resulted in other staff taking a lot more care....
  14. AlanD

    broken amp

    ...I'm kind of surprised if the amp has failed...because modern amps usually have good protection even against dead short cables being connected.... We have, in the past, managed to kill speakers - by connecting a cassette player (I know...you are all too young to remember such things...) which produced a lot of high power high frequency on rewind....we couldn't hear a thing from the speakers as they got fried..... The trouble with a lot of the stuff these days - in that unless you are buying well branded (often = expensive) kit - they can be unserviceable - because you just can't get replacement chips...Its the same with some TVs...they produce a batch of bespoke chips...use them all to make the devices...but if they break down...there are no spare chips....Very much a throw away approach...
  15. Getting more than 1Gb/s out of a server with 10K or even 15K disks in a RAID can be a challenge...well unless you have some very serious kit...and/or have M2 type SSD storage. A single disk rarely delivers more than 200Mb/s -and less under "typical" load conditions when latency is always working against you. Although we have a 10GB backbone, we only connect each of our servers as aggregated 2x1GB links -to separate switches in the stack (because the cost of a 10GB server card wouldn't give any increase in throughput). So by all means use a 10GB connection - but at least the aggregated solution means we still have connectivity elsewhere in the school should a core switch (or server port) fail. In our case the aggregated solution cost nothing....
  16. If you change the GP - the next user that logs on will get that policy - there is no need for any script.... I'm not sure that you would want to use transparent filtering....because if you do - how is smoothwall going to identify the user? (...Perhaps you are going to use Smoothwall's Idex tool? But personally I would have left the proxy setting - or at least change the proxy setting to point to smoothwall...because that would mean that I didn't have to push out Idex to all by devices....and proxies will work with devices like tablets too...not sure what smoothwall has done for devices...) ...I would use transparent filtering for any BYOD though...and use radius authentication with AD logons to the WiFi...and forward that to smoothwall. And yes....and device that is going be filtered will need a certificate installed. Again this can be pushed out to domain PCs via a GPO (google how to do it...) ...but its a pain for BYOD users - because they don't like the hassle of having to install a certificate (and enable it in the case of iOS)… Smoothwall usually include doing most of this as part of their setup/installation as part of the cost....
  17. ...Well...if a device was always available to everyone...why would there be a need to share? ...I think I get what you mean - but I am a little surprised to hear it given the "1:1" label. So its a bit like every classroom has sufficient tablets for any class that arrives there....but when students go to the next classroom they have a different device - so they need to logon all over a again to google or O365 ...tedious but doable.... And without apple's classroom management bit...the next student will find the previous student's details cached and sessions open....and will have an eclectic mix of messages and pictures left for them to discover.... 1:1 as interpreted by Apple would mean every user has their own device.
  18. You need to watch the film "A few good Men". It it does not make it OK to do a job because you are directed by your line manager or Headmaster - and you can - and definitely should decline. But you should raise this issue first - and explain that you are changing what perhaps has become as seen to be common practice. I'd also put the importance of backups into this category. If backups are not working - you need to get them working as a priority - regardless of what else SLT demand of you. Putting a visitors machine on your network is a risk....a potentially serious risk you have no way to quantify or evaluate. You could mention GDPR because its in everyone's headlights- but in fact it was the case with the previous Data Protection Act. In fact if I arrived as a governor and asked for WiFi access - I'd be alarmed if I was anything but restricted internet access. You might be shocked to discover how many schools are completely locked out of the network every week because of ransomware that spreads from infected computer to infected computer. It is your job to make them understand the risks...and that those risks cannot be taken. And while SLT might say they are prepared to take responsibility...they don't have that responsibility and can't assume it - which is why you are doing that job. Why would anyone want such access your network? If its just "free" access to the internet - I'd be inclined to tell them to use 4G. If SLT really want to offer free internet access to guests - then you need to set up a VLAN back to your router/firewall via a separate SSID on the access points assigned to that VLAN. Nobody should be able to connect their own device, phone tablet or laptop to your network...not yourself...or technicians.
  19. I'd expect it to work with any combination of 62.5 or 50u patch or modules... But not with 9u single mode fibre... And equally... I wouldn't expect LR modules to work well with Mm fibre... But it might work over short distances...
  20. ... Are you saying you allow any device.. With any possible infection... To connect to same network as domain devices as a guest? If so, I'd rather not offer any advice just incase I was held responsible for aiding construct a configuration that could easily compromise privacy and security.
  21. Airprint works via bonjour services on the print device. Normally devices expect to be on the same network subnet and VLAN. You can advertise bonjour on different subnets and or vlans.. Via DNS or bonjour relays... But these would not be affected by proxy settings... Might be affected by gateway settings though if you are routing between vlans and subnets....
  22. ..I thought this was 1:1 ... I agree, iPads have not had any facility for this - prior to their new "classroom" app...which is so greedy on memory - you can only shared them between a small numbers of students before you run out of space...needs to have the "user space" sync'd and loaded from the cloud.... ..and that's with a 32GB ipad….almost impossible to use 16GB iPads,....
  23. ...Yes, but chrome books have access to internet/email...even to use google docs.... Is it possible to limit such use for exams....by using your web filter? I'd be concerned that you would have to allow access to various gooigle domains and that would allow access to web searches - indirectly if not directly....
  24. ...well I could understand state schools having a difficulty with the cost of the iPad route....but there are certainly independent schools that do it...usually making students buy an iPad - or iPad mini when they join the school in Year 7. Despite being an avid defender, enthusiast and support of Android and Chrome, I would have to admit there is something slick and polished about the whole iOS platform...stuff just works...and works well...from sync between phone and tablet to airserver...airdrop...airprint....icloud, etc etc. And while the same things are "do able" on Android and Chrome..there is always a learning curve and not as intuitive. And although they are late to the party - the Apple classroom app with its ability to monitor screens and manage multiple users is beginning to look like the kind of product that is required in the classroom. I have a contact with a school in spain - who have a 1:1 chromebook scheme...which I thought was brilliant....but the reality is that the kids truly hate it...alarmingly so.....and for that matter so do the staff. At any and every opportunity they sneak out their iphones and mini ipads and use those instead of the chromebooks they are issues with....I don't understand the logic of what is wrong with their chromebooks or why they hate them so much...but if I wanted a scheme to work - that experience would make me think twice about not using ipads - even if they were twice the cost.
  25. I think you need to start by making a list of features you require. Like whether it needs to Provide and integrate with web filtering. For example to make some websites work you might have to add urls and separeately create firewall port rules. With an integrated solution you might hope just to tick a single tick box for say Spotify,not write rules in several places. And you need to thing about reporting..and the prevent strategy...useful if all reporting is together rather than separately for web and other other data access. Whether you want reverse proxy because you host some web sites...or own...or web access to Remote Desktop services or whatever. And does that reverse proxy support SSO For users connecting to your services? Whether you want BYOD integrated with Radius and firewalll...and whether you are going to host any dhcp and/or dns services on the same box...or want to have a stack of separate server boxes for each servuice. And you will want to think about bandwidth. 100mb/s often isn’t enough for most schools..with 300mb/s or even 1Gb/s not rare...but delivering that through a firewall can be challenge. And if even if you gpfont have that bandwidth now...you probably with in 3 years...and don’t want to replace it. And you might want to consider loadbalancing and redundancy between multiple ISP connections ...even if it’s a cheap fttc backup...and maybe you would want 2xfirewalls with failover support. And do youbwant it to do packet analysis for antivirus? Anti ransomware for email traffic? And do you want it to prevent VPN traffic for rogue pc/laptop/BYOD device (good luck if you do...because modern VPN traffic is almost impossible to block) Do you want layer 7 visibility? Do you want traffic shaping...to limit or create QoS filters ?And if so...are those only going to cut in when you reach your capacity apor is it going to throttle all your users annoyingly even when overall use is low? My thoughts are that there is not nearly enough creative thinking going on i the minds of those that are still marketing firewalls based on clunky, free Linux based software...often charging a fortune for the resulting jumble of components in their solution. And do you want it to integrate with you AD so that your firewall rules can be applied to AD groups..to ..for example...allow staff to do something that you might not want students to do.
×
×
  • Create New...