Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. I'd reiterate that. I know you are paying for this service...but its not as simple as connect and go....and you need to understand what needs to be done to get the user authentication to work - which seems to be at the heart of this issue.
  2. ...I have never quite understood this obsession with wanting to block block block. Students have always played games...yes in my days it was done by passing bits of paper around...and if you got caught there were disciple procedures...and you spent you lunch time sitting in a corridor or whatever. If students misuse the computer system...and attempt to play games...which we don’t block by the way...but can see the evidence in the logs...then they get disciplined. It’s simply not appropriate to play computer games in lessons. End of.... In fact there is danger of turning an obsession with blocking into a game itself and therefore encouraging it. And in any case I bet you could go into most classes and find at least one with a phone between their knees and the desk. Report it...and move on....but don’t turn it into a game...especially one you are likely to lose.
  3. ...thinking that if I was working in a Suffolk school...I’d be planning to move away from using them...there are choices out there in the wide world...and too often bad, and often costly suppliers rely too much on baseless loyalty to keep their customers. Internet and web filtering requirements are changing all the time, and are being used as cash cows...
  4. We use S8 too. I like it’s prevent reporting. I think it falls short in other reporting areas when doing an investigation...I like it’s BYOD radius option which provides easy authentication...DNS...DHCP if you want it....and AD group based firewall rules are possible. ...oh and it does reverse proxy. But it is extraordinarily expensive...as it’s larely based on free Linux stuff and if you bothered to write suitable reports you could do much the same for free with a bit of effort. Take a good look at Sophos UTM which isn’t as good at reporting in my opinion, but otherwise has some nice extras including SSO for internal websites behind reverse proxy. Light speed is also worth looking at. While I don’t like locking filtering and ISP together, RM broadband can be good well supported product...even if you like nothing else about RM. And I’d be looking carefully at internet provision. A few years ago a leased line was often the only viable solution, but faster download speeds are available for a lot less, using FFToD, or Virgin Zoom at a fraction of of cost and even with contentionfar outpace a 100mb line. ....internet providers don’t like losing their lucrative leased line market...so don’t be too taken by their negativity. And don’t rule out load balancing several FFTC lines ...again collectively faster than a leased line for a lot less ...balancing which smoothwall and sophos etc do well.
  5. ....so how are they doing their user identification....by joining to your domain...or by your clients installing and running an identification module...or by using some form of cloud identification service? When you say it’s affecting your domain machines.and not your office machines...are you saying your office machines are not domain machines? And how are they being identifies?
  6. ...which is absolutely fine until a fault in a firmware upgrade brings it all crashing about you.... "Shit happens"...and it doesn't matter how much you spend or what procedures you put in place....as many of the biggest IT infrastructure providers in the country will tell you....can guarantee your system won't go down.....and yes its possible that it can happen twice in 9 months....after all somebody wins the lottery every week.... I'd be checking and asking careful questions about what was done last time.....was it really the controller that had failed....did they really replace it? Was the original still in fact working.....if so perhaps it was a power related issue....or some unexpected disk issue that the controller did not handle well....did anyone actually look at the logs....are there errors which look similar this time? Had it simply lost or corrupted its internal configuration? I'd be pretty nervous if (a) the supposedly failed controller - seemed to start up just fine on a clean system...(b) they simply replace the controller ...because they are following a menu script without doing any further work to identify the problem ...because if either or boh of the above are true....I be willing to wager a small bet (and I'm not normally a betting man) that your SAN is going to fail again.....
  7. Not sure what your "Everyone allowed " category is assigned to ...but authentication is not the same being allowed..... Typically white listing bypasses authentication and any block.... According to their web site Schools Choice uses "Protex" filtering...not smoothwall. So I don't understand why you are quoting smoothwall problem..... Does their Protex system produce "Prevent" strategy reporting - reporting by username on Violence/racism/ etc.... its not one I've looked at....
  8. We start with 4G for staff and 2g for students...but increase as and when we get requests and the longer they stately in school some staff have 20gb or more...technology....but students are within 6gb even by 6th form. With enterprise onedrive which no longer syncs folders we hope to make better use of cloud storage.
  9. Is your server used for Authentication....guess it might me....but clients should be able to logon with cached credentials for a while.... You could try openDNS to provide at least an illusion of filtering (but perhaps that is done externally).
  10. Ah so that is our pens get to when students take them...they sell to other schools on ebay...
  11. Well...you can just assign static IP addresses on computers...and as long as you have an internet connection - you can use google DNS directly.... In fact...what did you want a server for if your files were all externally hosted? And I assume your email? (MIS too?) And you could use Google's printing service.... No definitely don't have to have a server on site... but there may be some benefits...
  12. You need “monitoring” to meet the prevent strategy so you can report on the racism, violence, site access by user name. Filtering...you can do for free...numerous solutions...even dns filtering works pretty well...especially if you block IP address patterns. You can pipe email through google ...office 365 too with transport rules...and filter emails...for free....well google tenancy is free...you might even decide to host you email there too. Are you still using onsite exchange? Some enterprise AV solutions have add one for email. Be wary of locking yourself into bundled solutions because you can’t later shop around so easily...especially when components have staggered lifetimes. And take a good look at the increasing range of internet solutions. High speed 300mb/s virgin cable...and FFTPoD...can offer much higher speeds than a 100mb leased line despite contention ratios....and for a lot less. Even 2xFFTC lines into a load balancer can make a good value internet supply compared to cost of 100mb leased line.
  13. There are lots of good reasons to use VLANs....Printers for example generate loads of broadcast traffic...and while that doesn't comprise a large volume of data its a lot of small packets constantly bombarding devices - and slowing them down....And you'd almost certainly want to segregate any BYOD staff of student devices because you have no control over what malware they might have...and you might want to segregate accounting and possibly other administration groups (even if you provided appropriate but restricted routing between those and your servers)....And yes usually you would decide to keep your CCTV and VoIP traffic segregated from student/staff networks.... I think a surprising number of school use a flat network...because it just grew that way rather than an intentional plan....and largely get away with it because students have for the last decade had such poor programming skills that couldn't coble together even a simple piece of code to do a DOS attack...but that might change if the current currlculm gives the opportunities to show what they can do...
  14. OH! Just be careful here....if the user has damaged a device - I am pretty certain the small print says that they are not liable for that. My experience is that you get a certain amount of goodwill, so unless its common occurrence they may over look such an event. When you lease - someone else is making money off your back....because you can be sure that they will end up better off... But when leasing you can be pretty sure you are going to get a device that is pretty solid....because the last thing they want is lots of call outs.... Maintenance contracts too will almost certainly be to the financial advantage of those supply them... But its useful to have know fixed costs - especially if you are a small school but you might not easily manage unexpected costs. For a large school - it might well be beneficial to pay for devices and pay for repairs as they are needed (assuming you are not paying ridiculous call out charges..)...although even in these cases managers like to manage costs more predictably even if it does cost more.
  15. Yes lighting was the greatest cost by far when we "did the math" for our campus. Even fluorescent strips lights (which are significantly better than incandescent lamps) are pretty energy hungry compared to the latest LED panels and strips. And depending on whether you have to contract out refitting or not, new LED fittings can pay for themselves and turn a profit...They are not going to save the financial shortage facing most schools, but there are savings to be made. With PCs - I find the best thing is to set them to sleep after 5 (or 10) minutes of lack of use..and make sure they go off at the end of the day. (We still like them to come on early enough to install any updates to windows and AV before the school day starts though.
  16. ...well, overlooking that keeping important data on a disk without any backup copy is pretty careless...my "bette noir" is students and staff saving an updated file with the same filename so that it overwrites the previous version only to later discover that this later version isn't intact...I always keep telling them never to click save, always "save as" and increment a version number at the end....despite endless reminders I am beginning to realise that its not until they lose their work they start taking my advice. Its the same with those that won't buy screen protects and covers for mobile phones. Why do they always buy them after they have cracked the case or cracked the screen? But my son as teenager (now a senior programmer...) took his disk which had failed (tick ..tick .. ticking...) and shoved it in a freezer overnight...then put it back in his rig...to discover it worked fine ...for long enough to copy the data off ....I was impressed with his ingenuity... so its worth a try I guess....
  17. We use the DrayTek filter behind smoothwall....so that if smoothwall (and its aassociated cable connection fails, our FTTC connection (normally load balanced into smoothwall) can still supply internet which is at least filtered....if not monitored. So its a bit of a belt and braces approach...in fact its pretty rare for anything to get through smoothwall and be blocked by the Draytek solution....but for £50 a year it provides us with peace of mind that we can at least continue to filter even if smoothwall failed. ...I've not tried openDNS..which seems a simple make do for now step....its not going to be robust of course...because users could just use IP addresses (unless you disallow this - but guessing even if you do - its done in the lightspeed rocket...)
  18. What's wrong with Apple classroom - tap the screen - to see what is on any student't ipdad...and its free....
  19. What about monitoring what they are doing with other apps...like messenger....or are you ONLY looking at things that are browser based- and possibly denying access to other apps?
  20. ...Absolutely agree with that. If anyone's idea of "research" is simply follow someone else on the basis that they say it works - so I'll assume it must be the right choice for me would be certifyably negligent. Get some test kit in...and get it working with Radius, BYOD or whatever. All the big players will be only too happy to lend you kit..but you will have to buy a couple of Unify (I'd go for top of the range HD ones...because they give you the speed benefits of MU-MIMO, 4x4 etc at a fraction of the cost of the others)...no one is going to lend you these for trial...but you will almost vertainly be able to sell them on Ebay for much the same as you bought them for! (which wouldn't be the case for many others...) But also keep in mind that no wireless is going to deliver you "wired" like performance in a dense classroom deployment. Co channel interference, single collision domain, etc, etc - whatever is promised....
  21. You can write games in any coding language.... And doing so can be good motivation....(possibly less so for Girls...) Block programming, like scratch, for example teaches basic structures, variables, etc and its relatively trivial to put together a tennis game or racing car track.... And I tend to like stuff that is already in every PC (usually anyhow) like pressing ALT-F11 in any Microsoft Office program brings up the VBA programing stuff....which allows you to do stuff with office - that office hasn't provided you a button to do...or for that matter make it insert a userform and write a complete application. And yes JavaScript is really good these days - even to do graphical stuff with canvas. And writing stuff with google apps can be interesting and rewarding too. I often think it seems completely unnecessary to look for some abstract additional environment - when you probably have what is required on your computer all the time. The problem - if its a problem - is that most trying to teach this stuff only have the most basic ideas of how to program - and often not even that. So its often a case of the blind leading the blind in many schools. Even graduates of that survive a 3 year computer science course are surprisingly and alarmingly weak at putting together any kind of useful code without careful supervision and guidance.
  22. ..when you say "monitor" do you want to remotely "see the screens"....and trigger alarms for keywords etc...
  23. Why is it that some people think that if you pay less - you must get less.... Basically wireless access points have exactly the same chip sets as a laptop wireless card....and they all have the same microcode/firmware that does all the hard work - otherwise they wouldn't get the 803.22 accreditation. Yes - it may have antenna structures (usually on the circuit board...and yes there will be management software to do authentication and the like. And yes - some (like Meraki) do layer 7 stuff really well...but you probably have that visibility at your web filter/firewall so there is not much point in duplicating it - and probably better to keep it all in one place. Yes - if you buy a rolls Royce solution you get your hands held nicely to get it all installed - rather than it all turning up in a large brown box. And yes - often the subscription cloud based services lock you into hardware replacement guarantees - which effectively lock you into that supplier. But as far as end users of devices are concerned - they neither know nor care - and would be unable to detect any small differences (and there are only small differences) in performance. In fact - its often the more expensive "clever" stuff that ends up causing more problems...
  24. I can't help but think that we need clear statements from government on what we should collectively do....rather than having government abdicate any responsibility and let schools come up with their varied policies and reasons for holding or not holding on to data.
  25. I don't think there is - or should be much difference between what can be kept on paper - and what can be kept electronically. You could argue either way that one might be more secure than the other....perhaps in reality its easier to lose paper records (either by theft of fire/water) than electronic ones...but yes, electronic ones could be distributed easily... I think there are real problems with "X years"....often a figure associated with financial records is quoted as being appropriate - but without any logical reason why this should be the case. Why should it be X and not X+1 or X-1 is almost impossible to come up with a logical reason. An when you hear of current (albeit abuse cases) going back decades - its not inconceivable that schools might be asked for records going back ...and indeed most would have had records going back decades - held in filing cabinets...I don't see why such a time scales might not be appropriate for electronic records - provided - that encryption and restriction of access is appropriately controlled. All this becomes particular relevant when we hear of the destruction of the Windrush landing card documents - which would have been so helpful today to establish the rights of so many. There seems to be a race to destroy as much as possible - to avoid thinking about GDPR - which might involve policies and justification....and sometimes that justifcation doesn't become clear until much later. My own belief is that have records have been made - fo a good reason at the time - then it is appropriate to look after those records so that later if there is a need to look for evidence and justification - or indeed blame - then that that evidence remains - rather than speculative memories of what people vaguely remember.
×
×
  • Create New...