Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. First...everyone...especially SLT and governors need to know an understand that IT systems can and will fail. And it doesn’t really matter how much you spend or how well it’s managed. A SAN between 2 hyperV servers with dual SAS controllers can and have been known to fail. And unless you have some sophisticated transaction logging for redundant databases you will lose data too....so office staff need to keep track of what they are doing between backups. Software and firmware updates can be lethal and unexpectedly end up with data loss on a live seemingly fully redundant system even when you thought you tested them first. The ONLY backstop is backups...and you might need some archived data because you might not know you have lost data from one day to the next...possibly not for a week or longer. So single backups - like virtual images - might get you back a working server, but not your data. Coreswitch failure can take your network down for a couple of days by the time you get a replacement and reprogram it...especially if it’s a different model...as you wouldn’t want to spend new money on an old model. Once everyone is happy that you have backups ..and that there is the potential for ...possibly several days disruption...then focus on things that are likely to fail...and disks must surely be the least reliable component. I think a RAiD is a must...and I wouldn’t be without a dual psi...although I have never lost one on a live server. I shut a server down at half term .and a day later the PSU wouldn’t start...no one knew..but it served to remind me that you can’t be certain these things won’t let you down.
  2. I think I would uninstall the network cards...and reboot. Have you checked services? And event logs?
  3. Do you not see their Radius Logon username? (...wondering if you are just using a WPA code...and are unable to identify users by ID?)
  4. I think a common "base" password - possibly including digits followed - or prefixed by a personal few characters which makes it relatively robust against an external attack - although if there was a hack the pattern would be spotted.....but I'm not sure that is a significant risk. I think there is potential for personal QR codes stuck in the books or something.
  5. ..I still think...in as far as holding a finger up can detect anything...that this is related to certificates..possibly an intermediate one which has expired...It sounds very similar to a problem I saw a couple of year ago when seemingly inexplicably safari wouldn’t connect to our web portal, but other browsers were just fine.
  6. ...so...need to identify if this is wireless....or web filter. Does it work with a cable?
  7. Not just the chipsets are the same...all the microcode is the same...I found it very difficult to measure any significant or repeatable data rates between AP s that we used for testing...
  8. OK. Managed to fix this. Having had no help from supplier who sold us the ipads (other than an offer to charge us over £1000 for remote support) and no response from tech users on this forum...started to grope around on the internet and into the murky world of keychains and passwords. Eventually it seemed that allowing "all apps" permissions to use one of the certificates (I don't know which one...because I did them all) in the system chain and restarted configurator2 the pop ups asking for username and password went away. Tried just adding configurator 2 permissions - but it wouldn't seem to save when adding that.
  9. Definitely sounds like MERU (..or rather Fortinet as now is) need to take a look at logs. Do you have other new ones (same models) that work OK? Is it because these later iPads have different WiFi chipset - perhaps supporting "ac".
  10. Apple seems to have tightened up on certificates...so if you are using a certificate for https inspection it’s no longer trusted...and you need to specifically enable that trust.
  11. Do you also have band steering enabled? I often find that troublesome...client starts connection....AP discovers it’s 5G capable...and shoves client off ....only for the 5G signal to be too weak to be useable. It’s a fault of bandsteering implementation really. Anyhow...Meru should be able to interpret the logs and tell you exactly what’s happening...and advise what parameters to change to mitigate against this.
  12. Not sure why you would want a machine to switch users ...vaguely useful for a shared desktop I suppose.... I find a virtual pc useful to use as a student workstation to test stuff....hadn’t thought of switching instead...
  13. Same iPads show this consistently..but other iPads are OK? And have you completely reset iPads ...tested...Without reinstalling apps and profiles and problem is still there (not app related) If so...then is it signal strength, or band steering...have those iPads been repaired?
  14. As soon as I start Configurator 2 - with iPads attached - I get a dialogue box saying - "MacOS wants to be make changes. Enter an administrator's name and password to allow this". followed by "MacOS wants to use the "System" keychain and a username/password box. If I only have one ipad connected - and enter my username and password around 20 times (correctly) - it eventually stops re-popping up...and I can add an "APP" or make some change to the ipad - but immediately it does that change - the pop ups start again for 20 times.... If I put in 10 ipads...well I never seem to be able to stop the pop ups.... And without entering details Configurator won't proceed.... Tried deleting various keychains and making new ones - but it won't let me delete the system one its trying to access. Don't understand why it doesn't remember my username/password once entered the first time. As usual - Apple Support seem pretty clueless....or perhaps they have not understood what I am describing...
  15. I hate it when big business or government starts deciding for you what you will want.... There are lots of really useful - and appropriate YouTube clips - for example say on the WWII that are perfectly suitable for - well certainly older children - especially under class guidance. The requirement for filtering is to be "Age Appropriate" and simply enforcing youtube safemode doesn't deliver that requirement. I'd like to see RM listen, discus and debate with users what their requirement might be rather than simply decide for them.
  16. Assuming your wireless devices do not connect on the same "network" VLAN as desktops you will need some kind of firewall rule with specific access to teacher stations/protocols etc without allowing access to - for example servers. ...but of course allowing such access - with teamviewer or otherwise is always going to be a potential risk.
  17. WOW! That all sounds rather expensive....Surface Pros for the teachers....very nice.... Is the 121 scheme founded by parents or by the school? And the plan for them to keep those devices as they progress up the school?
  18. Are you opening those documents directly from the email link - or have you copied them to your own local folder first? I rather suspect that they are being opened from some remote platform/storage.
  19. Welll...if your are using PCs....I doubt Microsoft are going to help you get rid of your servers....PCs still need to do domain logons....with machine GPOs etc..which need to come from somewhere. And User settings and profiles will need to load from somewhere after logon - and probably (almost certainly) before any connection to File stream has been established. You might persuade your server to connect to Filestream and then pass that on to clients via a network share......Logon only needs to be done once then at the server. With new versions of Win10 without local copies of roaming profiles (...but you still have profiles) I'm sure there is a future in this direction..... And of course - we are already there if you choose to use something like Chromebook.....but that is too big a leap for some users....maybe if you run a Terminal Server and a browser based RDP session you could get windows applications to a chrome desktop. But I think it would be an uphill struggle to wean users off Microsoft all together in a school.
  20. First - understand that an "SLA" (Service Level Agreement) does not guarantee any kind of connection. Yes - it guarantees that someone will come out and look at the problem - swap the router, check the connections etc but if a digger has dragged through a cable in the road don't expect the connection to be fixed for the next 6 weeks (possibly longer). Often Leased Lines are taken on the mistaken understanding that there is a guarantee of such a service via an SLA - and its simply not true. I've always been an advocate of two connections - we have an FTTC and a Virgin Cable connection - originally into a load balancing router (Draytek) - then TMG and more recently smoothwall. Generally no one notices if a connection goes down (which isn't very often - but it DOES happen) except for the odd comment that the network seems a little slow today. If you are not covered by two different technologies - then try to get 2 x FTTC connections into different corners of the school from different roadside cabinets. The cost FTTC lines are peanuts in the grand scheme of things. There are companies that provide "bonded" services to multiple connections which you might prefer to loadbalancing which may have some advantages - its worth looking into. In your case - it sounds as if the problem was essentially internal - your CAT6 cable presumably between router and school network - so it was presumably easy to identify (plug laptop into router - is there a connection....is there a connection the other end...no....must be the cable.... Or were you using a CAT6 to carry VDSL between BT socket and the router. Either way - hardly a difficult fault finding exercise. I think I would keeping the router next to the BT socket to ensure best data rates rather than carry VDSL any distance. And you could then arrange for a LAG (trunk) with two cables to carry the network to where its required so that if a cable failed it wouldn't matter. I try to have LAGs between all our switches (especially fibre ones with modules that are prone to failing). Ultimately, of course it doesn't matter what you do. Things will always go wrong and fail. In which circumstances there is no substitute for a good network manager that should have it sorted in no time.
  21. Thinking about this overnight (strange what the brain does...have enough of my own problems to worry about and end up up thinking about someone elses')... Do you still get a connection if you disconnect the AP ? (I'm thinking your client connected to some more distant AP...possibly because ...well perhaps this AP has its 2.4G radio turned off...and your client doesn't eupport 5G .....or perhaps VLANs aren't correct....or.... ). Definitely need to spend a day playing around to isolate and identify what is going on....
  22. Do you not get support from Meru....I thought they charged annually for this.... How are you measuring the speed? I assume this is not just the “connection” rate? ....so you know the cabling up to the AP is fine? Directly connect laptop works fine? And works fine if it’s ip/vlan is the same used by wireless? ...and the wireless is fine elsewhere? ...and that AP works ok if you swap it with one somewhere else? ...so either it’s a lot of noise ..Bluetooth, microwave ovens, DECT phones? Someone running tethering on a mobile? Rogue access points, nearby wiresless audio systems in use? I assume you are using Merus single channel...can you change the channel...is the problem on both 2.4 ghz and 5ghz? Seems to me you need to do some work to isolate the issue before it can be “fixed”.
  23. Don’t forget that you will still either need to run exchange locally as well ..or an smtp relay.. to cater for local devices that “send” emails .... like photocopiers, printers, etc.
  24. ...I kind of wondered how long it would be before someone quoted these articles....not long as it turn out. And I agree - that some careful thinking about usage, channel widths, etc is well worth stopping to think about. And it might well be that by taking away an access point in a room surrounded by others with access points is going to work. Certainly turning off some of the 2.4GHz radios helps a lot - because those left can use higher power settings. It may also help in really dense environments to use APs with programmable radios and use 2 x 20MHz radio channels on a single access point to split the collision domain in half. No - it doesn't give you the greatest speed to a single device - but it does give you a better overall bandwidth throughput to a classroom full of devices. All too often schools have resorted to using the most expensive access points (on the often mistaken grounds that you get what you pay for) but can then only afford enough to widely space them along corridors. In practice they would probably (and again - I'm all for testing in situ) be better off with twice as many cheap and cheaful APs (dare I say like Ubiquiti) placed in classrooms. And I agree - that wireless itself is often a source of noise - and indeed distant access points (and ineed clients) often trigger false DFS detection preventing APs from using the full number of channels - which is really annoying in dense environments. So yes - if you can remove an AP so that you don't end up reusing a 40MHz channel further down the corridor it might be a good thing to try,
  25. I am with you as far as "serious consideration" is concerned....and I agree that wireless in schools is often poorly designed, poorly maintained - with no maintenance budget. Often...wireless growth is organic - a single wireless access point to cover the odd room or two becomes stretched to cover a whole school by adding a few more - which can be fine for the odd staff laptop, but is then suddenly expected to support a classroom full of devices - because someone tested one device and said - look wireless works fine....which is true - for a single device! But the point is not whether £25 (or £16) a year per access points is reasonable - its whether £0 a year even for what might be a slightly inferior product might not be a much better investment especially if you can deploy a few more access points to cover the school better. To start with the eye watering cost of 4x4 MU-MIMO access points from the likes of Meraki, Cisco, Ruckus etc is is likely to limit the density at which access points are deployed and all too often schools simply don't deploy enough of them to support classrooms full of devices. And locking yourself into a 10 year contract is a luxury few state/academy schools could commit to. There is no guarantee that some of these wireless manufacturers will be around after 5 or even 3 years. You only have to look at the take overs in the last couple of years to see that. My mantra and advice to everyone is not be lazy. Don't depend on any suppliers recommendation, don't go for whatever the school down the road has (although by all means get their views)...get some test kit in and try it out with a class set of devices. You can have a wireless survey done if you want - but if you are going to use class sets of devices you are probably going to need to go for something like an access point in the centre of every room - because 5GHz attenuates really quickly even through thin walls which makes the higher QAM rates impossible to achieve through a wall.
×
×
  • Create New...