Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. We do a 1:1 BYOD scheme...adopted at a time when we were able to update our ADSL line to FTTC (Costs us around £50 pm) and added a second (Virgin) 300Mb/s BB line (cost around £80 pm) into a smoothwall router. We don't let students have any access to streaming services like Netflix, iplayer etc....(why would you?) and block HD access to YouTube....but allow YouTube with safesearch and with comments turned off etc... Oh...and we don't allow access to content servers (especially unmoderated ones) that iTunes use to stream stuff.... the result is that even when streaming youtube...its typically under 2Mb/s per device and our typical bandwidth use is well within our limits...although we are not a large school. Thought I might have had to put quotas and restrictions...but either way they can be really annoying....so pleased not have done this. Ideally we would like "elastic" speed restrictions which only get to start be applied when say - broadband use starts to approach 90% - and then for them to be applied progressively...(in reality - of course that is what happens - but it affects all users and desktops - which is not what we would like - and what I am guessing you would like to avoid). ...but filters and routers are still very basic boxes when it comes to satisifying what we need today....even expensive ones like smoothwall... Our wireless would also allow policies about bandwidth - but again they are crude - and not linked to overall bandwidth in use in school...and so would be applied completely unnecessarily at times of low usage. Maybe a good option would be to allocate students wireless to a particular internet provision - like a Virgin BB connection which will provide speeds well in excess of 100Mb/s leased lines...for relatively little money....or their own FTTC line if you can't get cable..
  2. Well....you can still get a new AP5010 off ebay....but they want £180 ...and I think an "n" access point is probably worth £18. Don't know how they are "managed"...perhaps it requires extra licences... Think I would just get a couple of Unify AD access points which would offer "ac2" connectivity going forward...and use that as a start of replacement program over the next few years. ..In fact I would probably be tempted to put the Unify APs in heavily used area - and move the existing APs... (And yes, I know load balancing wouldn't work well between different types)
  3. Logitech - yes, and Microsoft - here. They seem to last the course while in-badged budget ones are replaced 2 or 3 times. My complain would be that every year they seem to make the cables 10cm shorter - so that the mice never quite reach where you want them on the desk - which means they get tugged. And then the cable breaks (usually inside the mouse). You can fix that easily of course...but then the lead is even shorter. And they seem to use cables which are mostly plastic and each wire has 3 of the finest strands of copper so it doesn't take much for those three strands to break. Keyboards never seem to suffer in the same way...
  4. Perhaps its me...as I get older understanding new things seem to get harder. But I don't understand Microsoft Licencing. And Perhaps I'm mistaken, but I'm not sure our supplier understand it either....and every time I read the lengthy and convoluted descriptions on the internet, often in Microsoft's domain sites....I wonder if Microsoft actually understand it. Anyhow I read If you have a paid subscription to Office 365, Microsoft Dynamics CRM Online, Enterprise Mobility Suite, or other Microsoft services, you have a free subscription to Azure AD. Although you can use Azure AD to create and manage user and group accounts, it's a good idea to you use the Office 365 admin center. For example, even if you can add users in the Azure management portal, you still need to add licenses in the Office 365 admin center. You have to activate your subscription to access the Azure management portal. So we have the usual school agreement - or whatever its now called - (and changing names doesn't help clarify the situation) which as I understand allows us to deploy the latest OS and Office 2016...etc...and with a further free (but you have to order it) subscription we get the full Office 365 with APPs for tablets and downloadable products for users. So Am I correct that this also gives us a free (OK, its not free, but its part of what we pay for) Azure AD capability? And can this be used to provide SSO? Or do we require some extra component/licencing? And to make this work - is it simply a matter of uninstalling our Azure AD connect (..well unless they have changed its name again) and doing what they describe as a special install we then get SSO? Is it also therefore true that we don't then need to do all the routing/certificates and other things that used to be necessary to get Azure AD to communicate with our on-Site AD - because it happens via AD connect?
  5. ...and I'd still be taking a VERY good look at what else is out there...because you may be shocked by how good they are (Meraki) or how much you could save (or indeed give a much better dense coverage) by looking at Unify. It would be negligent of you not to consider a range of options.
  6. I noticed that our postcode now comes up as "FTTP on Demand available". Even with 10 ot 20% contention the 330Mb/s would be a lost faster than a 100Mb/s leased line which costs a lot more. And the upfront installation costs would soon be reclaimed by the savings in not paying for a leased line. Anyone done this? What provider did you use (every provider I've asked says they don't do FTTP ...do any provide the service - or is it figment of Openreache's imagination)
  7. There are a number of "meru" related threads...glad to hear its working OK for you...because that would not always seem to the case. http://www.edugeek.net/forums/wireless-networks/179826-802-11ac-dfs-channels-radar.html While I understand how MERU manages the "single channel" solution - and can understand that for various reasons it was probably a good solution for longer range 2.4GHz and a single trolley of laptops moved between a classrooms in a block...I'm not convinced that it is the way to go when you have realtivley short range 5GHz and much higher density of devices in every classroom at the same time. I have head of a number of schools who have abandoned the single channel bit...and if you are not going to use that feature - you may as well take a good look at a selection of different wireless solutions...because they are different to use - and considerable different in price when you look at Unify ....with little difference in throughput.
  8. Hosted systems are fine...until you start wanting to do things with tablets and mobile devices - which often require exceptions from the kind of rules that PC web browsers work fine with....and some "apps" require certain ports to be open on a firewall which isn't always so easy if they are managing that and locked it down. You will need to investigate how they identify users - whether its transparent (after logging on to a PC) ...or require a separate logon...and how it identifies users on mobile devices (tablets) using an App - which might not use a browser to force a captive logon page.
  9. I'd be interested to know whether you use their "Single Channel Architecture" or just use them as "normal" access points. I bet you don't get anything like 1200Mb/s in real world (wired) data speeds....partly because I bet your clients don't support 160MHz channels...and while dual stream might a double UDP transmit rate - you rarely get more than 20% more in actual data dates - assuming clients have dual stream wireless cards.
  10. If we are nit picking about inaccuracies...I don't think I said they "ALL" could only operate one radio - merely that they "ALL" made some compromises and did not fully function with all bells and whistles on 802..11af. And its not that 802.11n clients operate any faster...its just that they get more air time....assuming a mixture of clients and that they are not fighting to get MU-MIMO because mixed clients more than undoes any advantages that might bring. And in a busy environment - its quite possible that that "ac" clients won't get a wider channel - and may not have the signal to noise ratio to benefit from the higher QAM (Unless the student is sitting under the access point) ...so in reality - if not theory - schools may not see much advantage. Yes, I am trying to be provocative (and possibly failing) ...the point I am trying to make is that new wireless systems are oversold....and too much is promised. The greatest advantage of ac and ac2 are the wide channels (160MHz) - but - in a dense deployment of a classroom block - with several classrooms using sets of laptops - you can't use wide channels (Yes - its great for a home - or to cover a single office space...or even an assembly hall). In fact - you are even unlikely to deploy using 80MHz channels because there are so few of them - you run into the same kind of problems as you had with 2.4GHz radios....and "noise" from distant radios (and clients) is treated as DFS in use - reducing the number of DFS channels during the day one by one until there are none left. And while some high end tablets support two streams - almost all the "school" laptops - are single stream. Hopefully 802.11ax - with its two way MU-MIMO and other enhancements might provide a better "school "solution....but its always the case that there is something better coming next year. So a new school deployment will have to invest in "ac2". But I'd be very weary about replacing a well deployed "n" wireless and expecting miracles. Too often access points are deployed too sparsely in corridors, so that none of those high speed (QAM) connections at 5GHz make it through the walls - often with clients getting little better than 54mb/s. Replacing these with "ac" access points - isn't going to make much (yes - it will make some) difference - and certainly not unless there are so few you can use wider channels. I strongly advise schools to get some test kit installed. Don't just test with a handful of clients in one room with an access point - try two rooms fulls of client laptops with the access point in a third room (unless you are going for a 1:1 classroom deployment of APs). Compare with what you have now AND compare with several over suppliers. Yes this will take time. Don't buy kit from supplier "X" because you have always done that....or that posh school down the road has those access points. And don't imagine that by paying more you are getting something better. You MAY have to pay more to get something better....but paying more does not guarantee that. And you will only know if you have actually done the leg work and tested it.
  11. ... And keep in mind that all new access points that do ac2 require 802.11at capable poe+ switches. Yes, they are 802.11af "compatible" but are only so by turning off a radio, or multiple streams, and or second ethernet socket. So if you want the benefit of higher speeds and capacity don't bother investing in access points unless you invest in what is driving them. It's also worth mentioning that buying devices with single stream wireless cards tends to make the expensive access points a waste of money too.
  12. AlanD

    USB PENS

    Pen sticks? How wonderfully retro. Wondering why same pdf files are not uploaded to school web site...or put in google or office 365 both of which are free, etc....
  13. School "filtering" needs to meet the prevent strategy. So logs and reports for students and staff need to be able to identify who they are, what they accessed and when (and probably which device) . You need age related filtering - and to be able to demonstrate it - so you might have a "kids search engine" for early years...and only allow safe google searches for older children. And you need to produce reports based on the prevent strategy needs - such as radicalism. Note: that the requirements are not always about blocking and filtering. In fact - there is positive encouragement not so simply block every thing (...obviously you would for adult sites...) - and its only by allowing some freedom you get the chance to signs of abuse/radicalism/bullying/etc - and armed with this information you can educate suitably.
  14. Forgot to say....I'd be wanting to check - by looking at some graphs/switch data ...exactly what the problem with the existing system is. No point in investing in 10G core and new wireless - if the real problem is that your external internet bandwidth is limiting...or the server is just providing the data fast enough. It can be surprisingly difficult with random access to get 1Gb/s from a RAID array of non SSD disks....
  15. Sync tools.... you mean stuff like AD connect? to replicate users and passwords?
  16. We have a 300Mb/s Virgin broadband line (20Mb/s uplink) and a plusnet 80Mb/s FTTC connection for resilience. We notice very little contention during the day (less than 20%)..and both together cost use around £120 a month. Thought about leased line - but our upload speeds doesn't justify it....despite using Office 365 and Google.
  17. ...don't you want to use the exchange 2010 as a relay server - for devices (printers etc) in school that need to email?
  18. HP switches...they're great...maybe not the "Bentley" solution (=Cisco) but certainly Rolls Royce. Do you not think as a school you need to look at a Ford Mondeo type of solution....I'd be taking a good look at Unify Switches ...possibly netgear both of which would work fine - and infinitely better than what you currently use. Don't expect a solution provider to be rushing to recommend either - because their margins would be really small..and they probably have no experience of using or installing them. Get a test switch (you could sell it on Ebay later if you decided against it...and probably get 80% of the cost back). We use 10GB netgear core switches with 2x 1GB LAG connections to edge switches...with vlans...and it just works.... Wireless...well I'd be very wary about Meru. I don't think their single channel architecture gives you the kind of data bandwidth/density you need in a school and if you are going to pay for such a "premier" solution - I'd be taking a really good look at Meraki (the web interface will blow you away) - and/or for that matter Aerohive, Aruba or Ruckus. Personally, I wouldn't choose any of those until you have tested a Unify HD access point (no annual charge...and half the price of premier brands). Is it as good? Probably not....but you'd require a stop watch and some exhaustive testing to spot the difference - only to dsiver there was little in it. Keep in mind that (a) all access points have the same chipsets and 802.11ac2 software at their heart (otherwise they wouldn't be 802.11 compliant. And they all do load balancing, band steering and radius authentication etc etc. (b) All those super fast data rates quoted in the literature are largely ficticious. You are not going to get gigabit rates delivered to your chromebooks and/or replace wired desktop suites with domain wireless laptops that work just as well. Think somewhere between 100Mb/s and 200Mb/s for the whole access point in terms of wire speed. And halve the figure is you have more than 30 clients hanging off a single access point because of the size of the collision domain. © You will need the access points in the centre of the ceiling of most classrooms. Out in the corridor is not going to give you any of the high "ac" data rates - because they only work for 3 to 4 metres in open space at those rates...and going through even thin walls or bodies will drop the signal to noise ratio to make such speeds impossible. ..and no; your supplier isn't going to tell you all this bad news...because otherwise they wouldn't be able to sell you their over priced stuff and continue to charge you every year for cloud subscription costs. ..and don't get taken in by the promise of MU-MIMO delivering data to four clients at once....it only works "one way" - download and with overheads the best theoretical improvement is x1.8 And ... in reality you get around x 1.2 and then ONLY when all clients are ac capable...with mixed clients its actually slower than non MU-MIMO (...bet they won't tell you that either...) Make absolutely sure - that you test a Unify HD access point. You will be able to afford twice or three times the number..and there are no on going costs. If you decide against it some people sell them on ebay for more than they paid for them.....but given the very large number of schools using Unify very successfully...I'm pretty certain you will keep it/them. (actually I use Aerohive...over 100 APs .... and just use their command line code to deploy....becuase there is no way I would be paying for their subscriptions costs...which are great for a small business - perhaps one with several offices....but don't seem to be the right kind of cost model for a school...but I'm not suggesting this is the solution for everyone)
  19. I'd be investing in my main network making it more resilient, And add bandwidth that could be more useful all around....because what you are spending could benefit more than just new cameras. So I'd be putting in "trunk" links (LAGs) between core and edge switches....10GB between core switches ..or heavily used ones to computer suites...And I'd be thinking about future (gigabit) wireless use when it comes to PoE...and I'd be using midspan injectors rather that PoE for when you just need a 2 or 3 PoE outlets. I'd prefer to a use a bigger switch with more outlets rather than daisy chain another switch to manage. You can get 8xoutlet injectors provided total output can power your cameras....I tend to buy cheap "Chinese" SFP and SFP+ modules for £10 each...seem to work just fine...well in fact better than fine - the only modules that keep failing are the badged ones....which cost a relative fortune. Yes - I would the CCTV on a VLAN...to isolate multicast traffic and help prevent direct access to the cameras from the main network....and would cost nothing apart from a couple of hours setting it up.
  20. We use Ac2 ...and I often describe it as the worse piece of software ever written....and there is a quite a lot of competition for that spot. Its fine for setting up new ipads with the apps you require....but once your ipads come back in various states of completion and requiring different updates....it nearly always collapses in heap of error messages before locking up. (Note to self...best to wipe them and start again) Of course it is free...but then why shouldn't it be something Apple provide. Everyone tells me MDMs are a better way to go....but there are annual costs....
  21. So...is it not more cost effective...to leave a cluster of computers turned on....or set to WOL....rather than by licences for RDS...and that will avoid the hassle of installing apps (and often making registry changes) to allow them to run concurrent copies on server...
  22. Ah yes...everything works fine at half term when the kids are not using it.
  23. ...So is RDS what used to be called "terminal server"? Or is it like Guacamole acting as a gateway/host between a remote desktop/browser and a real PC somewhere in school. My concern..given that RDP is known to be vulnerable...is how to make it secure.... I'm guessing you wouldn't use it without some kind of VPN?
  24. The elicencer works OK for us.
  25. We like Schoolbase. (You probably never heard of it). Its pretty comprehensive - and includes things like "librarian" and "music instrumental rotas". If I had a niggle it would be that the user interface has always seemed to be afterthought....but the functionality is always spot on. And like All MIS systems....it does seem to cost quite a bit..
×
×
  • Create New...