Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. So maybe a general solution might be to provide a guest SSID - with redirect or CWP which is able to get to smoothwall certificate page (which doesn't have the correct instructions for the current iOS by the way!). Explain that it needs to be installed...following various guildes and instructing user to join a different RADIUS network using the AD credentials after which it should just work.
  2. Sounds as if you are using a captive portal with Ruckus...better to use radius authentication either by using Smoothwall's radius server - or passing the information to smoothwall to avoid a second login... The certificate hassle is a pain...and very soon it may well be that no filter will be able to use this method of interception...and then essentially everyone will be invisible (...well maybe DNS filtering will still work...) Android 8 devices for example won't let you use a certificate for MITM interception ....or at least not unless you use a golocal certificate - and that would be strictly against the usage permissions for such certificates. In any case - APPs increasingly use certificate pining and you have to create exceptions for them to work - including the google search app - so we won't be able to monitor this.
  3. So RM also support vanilla installations - and will "remove" CC4 from existing servers leaving behind a vanilla installation (for a price of course). Its something we have been looking at....but we would want to be assured we have some kind of external support - which needs to be really good ...and that can prove to be expensive - particularly when vanilla installations are randomly configured... I do think RM support is not cheap - but I'd have difficulty complaining about their lack of expertise and capability - which has always been first class and spot on.
  4. ....so the SSID remains visible ...and accessible? And this is a laptop issue...not wireless....so other devices can connect to wireless..or even other laptops...
  5. Sorry - we use some free software - that no longer seems to be available....and like most systems - is too complicated in some aspects - and not all the functionality I'd like in other areas. The only real solution is to test as many as possible and come to your own conclusion as to which fits your particular set of circumenstances. My biggest complaint would be that users rarely take the time to describe the problem....and say "My computer doesn't work - I left a message on the answering machine yesterday, but no one has fixed it".....They did indeed leave a message, but neither told you who they were or which of the computers they might have used has the fault. In fact you still don't know which computer it is....so you update the ticket accordingly. They eventually reply giving you the information, you go there..and it seems fine..and update the ticket. Then you get "...its the MIS that doesn't work..."...and go there a second time..to find the MIS system seems to work fine....and update the ticket. Then you get "when I do X and Y Z doesn't happen on the MIS"...which as it turns out isn't true - and only eventually when you catch the person at the computer and are able to see what they are doing notice its their inability to make a selection before doing X and Y that stops Z from working. Ah well...given how well computing and ICT seems to be taught these days - often by those with neither a degree and seemingly no expertise we can look forward to perpetuating another generation of luddites to keep us in a job.
  6. This is much in line with our experience. SSD make a makes a big difference - not only in an old machine - but also in a new machine. 2GB is tight, Just the OS, AV and Edge with a few windows open can easily use it all up. Doesn't run much or noticeably faster with 4GB - especially if you have an SSD (which you will want) because paging works relatively quickly. Note: OP specified CPU speed of 3Ghz - which doesn't really tell you much - because some of the latest i5 kabylake might only run at 3.4MHz - but seem like 2or 3 times faster than say the first generation of i5 CPus. And i5 with 4 real cores - certainly seems to help more - because there is a lot more multithreaded code in Win 10 etc. We found our core 2 duos (now some 8 or 9 years old) had to be retired
  7. Monitoring...and reporting...are important...and there should be evidence that safeguarding lead is getting these details...and acting on it (and should be able to show documented evidence of this over a period of time). Monitoring and reporting will show evidence that filters are in place...which should be "age appropriate"...so older students might be given access to - say pinterest...with some warning to them...and the very youngest (in reception of a primary) are probably in a walled garden - and probably have a "kids" search engine by default. Reporting on "searches" often tells you more than simply a list of sites which were blocked to students. They will (and do) ask students of course...and "blocking" which gets in the way of learning would be disapproved of....even if it came with some risks. Games and the like...they wont care about (some schools seem to spend most of their time chasing these down...)
  8. Firewall on client? On same subnet?
  9. I think DirSync becomes end of life - and unsupported and may not work from the 31/12/17. Its a relatively simple and painless matter to upgrade to Azure AD Connect....just run the install and it reads the current settings and imports them...
  10. ...and there is nothing wrong with netgear, or at least not anything that would make me tear it out. Yes, some of the older stuff has a somewhat clunky, inconsistent and slow web interface....really slow in some models. Could not fault their support...after a switch failed during a firmware update I had to phone them...and they readily agreed to send out a replacement to arrive the next day....then I suggested updating the boot code in the switch which they talked me through patiently...after which the firmware went on fine and switch booted correctly. I particularly like the the way you can extend the core switch via fibre modules to remote switches in a virtual stack with single management...and yes I’m aware this is pretty standard now with other makes. And I note the original POster refers to a 10g link...which can be 20gb...if they completed the “ring” in the core switch. Maybe I wouldn’t choose netgear if starting from a green field site, but this is a school, I assume. ..and there is a CLI.....
  11. I think I’d want to be very clear what I was trying to achieve...and indeed whether the switching infrastructure was in any way a bottle neck....and I’d want to know afterwards that I had successfully met that target. Simply and randomly spending money in the vague hope that more modern kit might give you improvement is....well a shot in the dark...and potentially a waste of money. Have you looked at the logs and bandwidth...do you use snmp graphing or anything....I’d be thinking about using lags between the core and edge swiches to start with...because apart from the cost of fibre modules...and I’d recommend the cheap Chinese ones every time in preference to the overpriced badged ones....it’s not a major cost ....well assuming you have spare fibres.. And I’d be checking that the servers are actually capable of delivering the kinds of speeds you are looking for...without SSDs it’s surprisingly difficult to fill a 1gb connection. You could rate the odd edge switch to 10gb Back to the core...but I’d be betting ...well a small bet...now one could tell the difference...and even a contrived test with SSDs in the clients might be difficult to show any improvement except with server cached sequential data.
  12. Virgin - as I understand...have problems with their broadband when using static IPs because the data has to come through a Virtual network (which provides those static IPs) and that network is...well....even the virgin staff will not be surprised when you complain...however the 50/5 seems like a poor offering...We have 300/20 from our virgin line although it does cost £100 a month (not the £50 you will see it advertised for - because apparently public sector can't get it for that money because they off-shore that to supply businesses - which they apparently can't do for public sector - seems like a scam to me). And while we don't always see the full speed - its pretty close to that during business hours (but a noticeable drop in the evening if you can be bothered going back into school). We also have FTTC - both into a load balancing firewall. I would be interested to know if the speeds are better for the first hour or so after restarting the virgin router....because we used to have progressive degradation (which went away if we did away with static IPs on that line) and restarting the virgin modem overnight helped enormously. I'd also be chasing Virgin (and it will be an uphill struggle - because they will want to sell you a leased line - and I partly wonder if they deliberately make it difficult...be prepared to sweat tears and shed blood) for an upgrade to their business Voom service. So if you only get 50% of the speed - it will be a lot more than you get now. Once upon a time leased lines were the only realistic way to get say 10Mb/s ...but FTTC and Virgin asymmetric broad band is fine for most schools - often say with virgin - faster than 100Mb leased line - and only a fraction of the cost. And you can load balance 2 or more FTTC lines for a lot less than leased lines too - providing welcome redundancy in the process - especially if they come from different road cabinets (I guess this is not an option for you). I assume this is a virgin cable connection (rather than a resold openreach line through virgin) you have. Somewhere in your testing - you need to find where the bottle neck is. If you can get 50Mb/s through the modem consistently...then maybe its the filtering that is a problem (too many clients/schools on a low spec/d filter...) or maybe the upstream connections from LEA etc are poor. I know you don't make friends this way - but I'd be threatening to remove myself from Council services unless they got their act together. And I'd be investigating what and how other schools are connected and what their performance is like.
  13. So tell us what kind of connection has Virgin provided (leased line...normal business broadband?)...are you a college? And how does the "fault" manifest itself? Does the line have static IPs? Do you have a your own router behind the virgin one? Are you trying to use Virgins box in a "modem mode" rather than router mode? Things can get very difficult and convoluted when you have VPNs inside VPNs...especially if IP addresses of "internal" subnets along the way are not unique.
  14. faulty connection?....exactly what is the problem. (partly thinking the problem is that you seem to have 4 suppliers involved in supplying you a broadband connection - which allows them all to point their fingers at the others) Step 1: Does the virgin connection work - plug in laptop to their router can you browse? (guessing there is some issue with the way Virgin deliver static ip addresses via a virtual connection......does it work for a while and then go really slow...then stop? If so - I'd put the router on a timer - and get it to switch off and back on once a day over night)
  15. Someone has to pay for this.....If you choose to live out in the country ...then poor internet connection is likely to be a consequence of this. If you choose to live in a large urban town....then road traffic will be really slow....there are benefits and consequences. Either you have lots of fresh air or you have a good choice of supermarkets..But there is a social entitlement issue - because the internet is an increasingly important part of our society (whether we like it or hate it)...and its not "economic" to provide this out in the country as far as BT is concerned...and so something needs a push...and I would have had severe doubts about leaving it to the goodwill of openreach....so I like the sound of the legal entitlement. And yes - I think some of that extra cost needs to be from the customer....as it would if they had to get a mains water connection. And yes 10Mb/s is too slow....and hopefully Openreach will be thinking of planning to provide more than that or less they will be facing another legal requirement in 10 years time when the minimum becomes 100Mb/s.
  16. 802.11n gets you a UDP connection rate of 300mb/s (..well with 2 stream....450mb/s with 3 streams...but you would need clients with 3 stream support). This is not the same a wired speed measurement of 300mb/s which is fully duplex..and its the speed to ALL of your clients from the access point not to EACH and every client at the same time. Think more like half that say - 150mb/s in terms of wireless traffic speed for comparison with wired with a single client. So it should be no surprise that large numbers of clients have a pretty detrimental throughput on wireless.. Yes an access point "support" 100 connections - or several hundred - but don't expect to get useful data rates to these clients at the same time - because the collision domain - as you point out - gets to be pretty chaotic when you have over 20 clients. I have seen 60 clients playing video clips (around 2 to 3 mb/s each) but that's about your limit...and for various reasons in most high density school environments it doesn't get much better even with the latest "ac" wave 2 stuff because you won't be able to deploy 80 or 160MHz wide channels in blocks of classrooms. (Great for home use though..) Access points that support 5Ghz of course give you a significant gain - because there are lots more channels - and you can use wider 40Mhz channels.....and can therefore deploy more access points in the same building without worrying about co-channel interference....but you will need access points in the same room - and ceiling mounted because 3 to 4 m or so in unrestricted space is the maximum range before all those higher QAM rates start to fall away. And yes - there are senarios where you might not need an AP in every room - especially if its surrounded by rooms clients can connect to several access points from. I am guessing - that your two neighbouring clients with wildly different data rates - may be because they don't even support "n"....or maybe you have Bluetooth stuff nearby (which uses exactly the same 2.4GHz band)...
  17. Here is my two penneth worth take on this matter. I use smoothwall - so have some kind of vested interest in their success - not least of all because the kit is new and I've paid for several years worth of upfront support/licence. I don't think its fantastic...although I did think it was the best option for us at the time - the least worst of what was out there (Sophos was a close second choice for us). I think they lost their way by investing a huge amount into a product for "monitoring" PCs (along the lines of impero and others)....and I guessing very few bought into it..not because schools don't need it or wouldn't like it ...just they can't afford it. I think it would have been MUCH better - for the, to have contacted all their end users to tell them what was happening - promising reassuring views on how it will tighten up of and quality of quantity of their support capabilities (even if these promises couldn't be fulfilled). I think they (and this applies to most UTM solutions) need a much more ground breaking and imaginative solution because firewall, filters and BYOD (and possible Email spam and AV filters) are all now tightly bound together (as much as some would wish they were all separate products). As an end user I want to tick a box to "allow Spotify" on BYOD. I don't want to create a load of firewall rules and exception, then separately create various categories and policies for the web filter and then further add customisation on BYOD interception/inspection of https rules. And worse still I don't want to update these various parameters 2 weeks later when Spotify decide to change something. They should be rolling this out automatically to end users as a simple tick box and they should be updating the necessary ingredients to keep it working. Currently it all looks like it did 10 years ago...except now much added to in ways that were not originally envisaged. Get this right...and maybe users would stop complaining about the horrendous cost of smoothwall....and they might get a lot more customers. Schools will and do pay for good stuff...but it has to be really good stuff.....and adding extra bits to a products to support additional functionality does not necessarily add value to it (which is a mistake complaines often make)...those bits just mean that the product will continue to sell at the same price.
  18. I wouldn’t be wasting time...it’s new....get smart to fix or replace it....or tell your supplier you will be returning it. Of course..it’s possible you damaged it yourself if you did the install.... I hear the “why not buy a panel” cry. The problem is that teachers really like a large screen, 95inch promethean given a free choice and while they are expensive they are not nearly as expensive as large panels. And replacement projector lamps are no longer the cost they once were. It’s a bit like why don’t I buy an electric car...I’d love to, but anything affordable is tiny and has limited range...and anything that would be a useful size and range is twice the cost or more..
  19. ..well its certainly possible to write a VBA script in excel to highlight them, count them...or do whatever else you like.
  20. Do you get a particular error - or is just that the user doesn't get the profile they expect ...perhaps non working internet...or not the correct start menu items?
  21. No; I think this is exactly how its supposed to work. The switch gets a load of bad packets from a client and decides the best thing to do is isolate traffic that that MAC address on that port. Moving another PC to that port allows it work fine...as does moving the original PC to another port. But ...you won't have "fixed" the problem - which is likely to reoccur - and will either have moved with the PC. Taking note of whether you physically moved the PC - or used different sockets, patches should allow you to isolate what the problem is.
  22. For us a corrupt profile is usually because the user has interrupted the logoff process in some way - possibly by pressing the reset button - sometimes because they can't be bothered to wait for some process to complete, and don't realise the consequence. Wiping the local cached profiles is not much help, because the resulting corrupt profile fails to load from the server, and worse still then makes the local profile match that corrupted one. We minimize what is stored in the local profile to make it load/save as quickly as possible, but like to offer some customisation (pined task bar items, bookmarks, recent files etc) because that can add significantly to usability. So you will need to do more than wipe the local copy....such as restore the server copy from a backup - or wipe it (much to the chagrin of the user - who will lose what they regard as important bits).
  23. I continue to buy second hand network kit off Ebay - often less than £100 for 10G switch with 48 ports. Whack the latest firmware in and off to go with a Chinese SFP module (£10). Keep a spare switch or two in the cupboard...bought the same way - ...never had to use them (actually that's not true - I took the fans out of one because a set of new fans were more than I paid for the switch).
  24. What I would like...and perhaps its possible...is to backup to cloud/azure...and in the case of a disaster to be able to recover that backup to a temporary server in the cloud with VPN connection back to our network. And while our internet bandwidth wouldn't allow the same user experience - it would allow office and key users access to a working system until the onsite server was replaced/repaired. Then to copy/clone the temporary server back to the onsite one.
  25. get the kids to operate it...will need help and support to setup of course...even young kids can do a great job.
×
×
  • Create New...