Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. Sounds as if you are using Captive portal? With school owned/shared devices? There is always going to be some kind of compromise here. Either you set a "long" lease - but then the second user to use the device is still identified as the first user....or a shorter lease - in which case, for a second user browsing (or an app) can unexpectedly grind to a hlt because smoothwall wants them to re-authenticate - but apps (or a process in the browser) are not aware of this. We use Enterprise/Radius for BYOD mobile devices....and AD integration for desktop machines - and it seems reasonably OK....but still, not perfect I agree. I have had complaints about embedded videos too...and I've seen browsing come to a halt for no good reason - and starting a new session works just fine.
  2. I would definitely advise taking a good look at ubiquity kit. Lower cost, and no on going annual charges...and a perfectly useable management console for free. Are they as good as the top stuff? possibly not, but you’ll need a stop watch to tell the difference. And because you can afford more of them you will be able to position them more liberally so that the cover you get operates at a higher bandwidth. The single channel virtual cell architecture was great when you had a localised , but dense deployments of a class of laptops but when you have several classrooms using laptops and/or tablets it’s not going to deliver the same bandwidth as a range of 40 or 80 MHz channels. And I don’t think the current chips sets allow the virtual cloning of Mac addresses to deliver the virtual cell without loss of packets so meru’s inovative technology doesn’t produce the same gains with ac chip sets. Don’t expect suppliers to come rushing to sell you ubiquity kit, because they make much less margin compared to selling you the Meru/meraki/Cisco/ruckus/aerohive stuff.
  3. ...there is no guarantee that replacing the access points , which presumably are “n” and possibly 3x3, with “ac” ones, wave 2 or otherwise is going to give any improvement. If you have 5 spaced out access points, presumably not in the classrooms you are not going to benefit from the higher Qam rates of 5ghz because that requires very strong signals with APs in the classroom. You’ll get great speeds in the corridors next to them though. You would be able to use wider 80Mhz channels on 5Ghz but it doesn’t work well through walls. If you use more access points, you are probably back to 40MHz, but you would get stronger signals. And keep in mind that if your devices don’t support “ac” you are wasting your money investing in new APs because no one will know.
  4. ...I think the reporting is better for smoothwall..but I’d like to see ready made categories for all the social media stuff and mobile devices without having to do it yourself.
  5. ...but if they don't have a certificate which they have installed in their device - regardless of whether they logged in to Sophos - the traffic would essentially be invisible to sophos because it would not see any of the websites or details of any web searches - because they are hidden by ssl encryption....so the only thing you would see is the good stuff...
  6. Despite having said it - I largely agree with you, at least to the extent that the worst of such material needs to be blocked. And of course - you might ask "what is the point of blocking it - if they access anything they like via 3G/4G on their phones which now seem to come with download limits and speeds that would be difficult to match with a leased line shared between users". But the fact remains that the requirement is "monitoring" and "protecting" and if doesn't always mean blocking everything. Indeed as they get older we are required to have age related accessibility/blocking - and you might have to decide whether to block an increasing number of really useful but unmoderated sites like Pinterest....
  7. WHAT???? !!!!! you MUST get your wireless users to install a certificate - and block all traffic from devices without a certificate - otherwise you are seriously in breech of government "prevent" requirements. Remember, its NOT sufficient to "block" unsuitable web sites - you must "monitor" access - and be able to identify those staff/students at risk - or radicalisation, violence, sexual grooming or whatever. And it may well be that simply blocking access would not enable you to track such risks. So you can't have a connection like you would at home - with a shared WPA code that staff (or students) use to join wireless and away they go. Either users need to identify themselves individually by using an enterprise wireless logon using a radius server (which if you are using Sophos should be easy...) or you need a captive portal (if for example you have shared devices connecting to wireless) - which is a pain - because users need to use web before using an app...and you need to set a timeout so the next user will not be using the first user's authentication. If you don't use a certificate on the device you won't be able to monitor or block any of the https traffic which will be completely invisible. (Actually - that's not quite true- because you could be using a DNS or IP filter.... but it wouldn't be a very robust method)
  8. You don't need to be on the same network/Vlan to use Airprint...but printers will not automatically appear in "i" devices sitting in a different network. That might be a good thing - otherwise all your printers for the whole school appear in a drop down list. There are various mechanisms for readvertising airprint servers selectively - including "hard coding" printer details into say apple configurator (or possibly an MDM depending on its capability). ..I still prefer using a printer's "App" and a QR code stuck on the device.
  9. Sorry - I think the only way to run this in school is to do so in a virtual environment. And why wouldn't you do this?
  10. Our SLT are asking if they can send a message to all computer stations. (To warn/advise of lockdown or some other emergency) Currently, I use RM's "Display Message" within RMMC to, for example, warn users of an unexpected server reboot (if I have to do one urgently, for example). I guess I could use NET SEND .... or rather I think its MSG using our 2008R2 servers (Would NET SEND from a client Win 7 workstation work?) ...but do they need admin permissions to send a message (currently they wouldn't even be able to open a command window...) Perhaps I could provide a web/tool/app that asks them for a message and sends it from a server ...but not sure about permissions. Anyone do anything like this?
  11. Yes the problem with Unify is that suppliers don't make nearly so much money out of it...and don't get their slice of the annual hosting charges (completely rip off)....so they are going to paint a bleak and uninformed picture. If you took out a Merkai AP or Ruckus from a classroom and replaced it with Unify no user would notice a difference....you'd need a stop watch to see any difference....and randomly, that difference sometimes show the Unify AP is faster.
  12. Well - I highly approve of you doing a trial....don't take anyone else's words for how good something is. I've always thought all wireless systems - yes including the latest all singing dancing Wave2 "ac" stuff - are essentially rubbish in that they are often asked to do a job in a school that is beyond what wireless technology can really deliver. Wide channels are great and will deliver really quick speeds in that room - but only if you don't have to put in lots of access points in neighbouring rooms - because then you will need to use narrow channels and you lose most (...not all I agree - but the significant part of) the benefits of "ac". And all access points - by any manufacturer use only one of two different chip sets ...because only two chips sets have 802.11 licencing. More than that - they have to use the same microcode as well - to get that licencing. So in "raw" packet terms one access point is much the same as another - apart from the management layer. True - Management makes a difference - but its not life changing. 30 laptops in a classroom is going to be slow - regardless of whether you have the highest cost AP or cheapest. There are some bells and whistles with those at the high end of the market...but I bet most never use them once they have played with them for the first week...and probably end up deciding that the default settings actually work best of all. Roaming is interesting. Because with "n" chipsets AP management software used to migrate clients from one AP to another transparently by cloning and masquerading MAC addresses of the AP (so the client was unaware they had moved). This transparent roaming meant you never lost a single packet- when say - using VoIP. "ac" chip sets don't support this...so roaming is typically achieved by one AP dropping a connection and the client taking a look at see what else it can connect to. This used to work really badly because old clients tended to reconnect to the same access point and hold on regardless of how weak that connection had become. Modern clients behave much better. So, unless you have some old kit - I would expect roaming to work just fine. If this really matters to you - you would do well to look at an even cheaper "n" access point. You still get to use 40MHz channels - and 2x AP using 40MHz channels in a single area will give you more throughput than a single AP using 80MHz with large numbers of clients because the collision domain for each access point only has half the number of clients....but no....for single client the speeds would be slower.
  13. “They are suppose to be quite powerful and can handle upto 50 devices per AP but when I have 30 laptops going through 1 ap I seemd to struggle on a 1gb switch”....... There is a lot of widespread ignorance and hype surrounding wireless. Much of the time this originates from those selling it, and is quickly adopted by SLT ...yes...and sadly network managers that don’t do their homework, but simply read the headline gloss of AP promotions. For example..you might believe that “ac” is going to deliver gigabit speeds and replace wired computer rooms (queue much laughter from this in the know....). Yes, if you have an “ac” router at home with 160MHz channel width you might get 800Mhz rate.....but that is UDP....and you will want to compare this with wired full duplex...it’s going to 400MHz. But you won’t get 160Mhz on an enterprise AP (there are lots of reasons for this...the UK has 5minute delay time on weather radar DFS channels...and in UK there isn’t the same uni band allocation..less generous than USA....and in any case you will have neighbouring access points ). So you might decide on 80MHz channels ...but in a classroom block you will probably be using 40MHz...so we are down to 200 or 100Mb/s in terms of what wired delivers. And that is not 100Mb/s to every clients it’s 100Mb/s to all clients. So your gigabit switch...even if a poor one is not going to be a problem. Then you will ask “what about multi streams...If I have a 3x3 AP I will get 3times the data surely?” Well, yes you transmit rate in windows or on the AP will show 3 times the rate..but that is no guarantee that the client gets 3 times the data. Multiple streams depend on stream separation, and the only way to get complete separation is to place the separate aerials of your clients and APs several metres apart or on different sides of a wall. Yes higher QAM rates helps “ac” resolve these spatial streams, but only when signal to noise ratio is very high do you get significant increases with multiple streams. Think 20% more rather than double for two streams, as a rule of thumb....and for 3 streams...well you might not notice any difference because of laws of decreasing returns. In any case, I bet you have nothing better than 2 stream clients. Multiple streams do help with maintaining data rates at further distances..so don’t dismiss it...but it’s not going to give you significantly higher data rates. And what about MU-MIMO? Yes...it’s worth having..as long as your clients support it. But it’s not 4 clients being served at once...for all sorts of complicated maths the best theoretically is x1.75 and in practice, closer to x1.2 And to get these rates the AP needs to in the room with the clients and on the ceiling with no bodies in the way.... So you are thinking 150Mb/s or maybe over 200Mb/s if you you have a relatively isolated classroom where you can use a wide channel. No...I forgot to mention single channel collision domain.....Some of you won’t remember the days of networks joined up by coax cables or using hubs rather than switches. With a 100Mb/s hub one client might get 100Mb/s from a server....two clients might get 50Mb/s each...ten clients might get 10Mb/s each. ....but once you get to 20 clients they don’t get 5Mb/s each as you might expect but only get 3Mb/s each. What has happened to the other 40Mb/s? Well...network collisions start to get really messy when you have 20 clients...and your 30 clients is even worse. And just in case that isn’t bad enough there is no collision detection mechanism in wireless...so a client on the far side of an AP can be transmitting at the same time as your client is transmitting and neither client will know about the other apart from the AP which fails to receive both packets and has to wait for timeouts and retransmission. So your 30 clients are going to get 3Mb/s each...which can be surprisingly fine for 30 tablets browsing, and maybe even 30youtube clips playing...just.....but your laptops will be painfully slow from startup. It’s not going to be gigabit networking as we know it. You can help mitigate this with classroom planning. Go to the start of lessons with a teacher..make sure laptops are switched on an running before the lesson starts...the teacher can’t do this. It’s going to be a disaster if it’s the first switch on of the day and virus updates are going to install in the bacground...or worse...windows updates.... And then computer group policies are going to install. Allow 30 minutes for all this. Then encourage the teacher to get the class to pick up and logon to to laptops as they arrive..no queuing outside the door ..nor waiting in the lesson for some key point and telling the class “now all open your laptops and logon”. And make sure they don't close/shutdown laptops at the end of lesson otherwise the next class will have a long wait. Log off...and sleep or hibernate only...configure your laptops to do this when lid is closed. You know these wireless vendors are spinning lies when they start talking of speeds up to... or theoretical speeds...etc Yes, some of the APs have dynamic channel allocation, airtime fairness, QOS, beamforming, load balancing, roaming, etc etc....and they all help..a little...but nothing is going to get over the fact that wires is not going to offer anything like wired when it comes to dense deployment of high bandwidth.
  14. ...well...you could set them to DHCP (is that what they are set to now...and just coming up with some random 169. address because they are not connected to network)....let them connect to DHCP....then use the DHCP management to switch their addresses to "fixed"/reserved ones. Then go through that list looking at the name of the computer (assuming you have a naming convention that tells you where it is) and change the reservation IP (it would save visiting each computer...albeit perhaps via remote desktop).
  15. I think you need to explain how and why the IP addresses are what they are and why you want to change them. We used to use fixed IP addresses assigned in geographic locations through the school - I thought it was useful to know where a PC was from its IP address. But then I decided to go for DHCP leased addresses and so IP addresses are seen to change after a period of inactivity over the summer. Once when we went through a server change we built a new network using different leased addresses because we wanted to change the scope. I still use fixed IP addresses for switches - just in case they can't see the DHCP server for some reason....and for servers. And I assign IP addresses to MAC addresses via DHCP for Access points (because of Radius configurations), printers and projectors.
  16. I think I am right in saying that rhere are only 2 WiFi chip sets and they come with their own micro code which has to be used to get the 802.11 compliance. So AP manufacturers have to work quite hard to distinguish themselves from competitors. I tried a range of access points and found little real difference in tests with 30 clients ....all in fact quite disappointing with quite a significant drop of overall bandwidth courtesy of a single collision domain. Some had a better dashboard, some worked a bit better through walls, some were a bit better with video streams, some were a bit better at load balancing, but largely they were all much of muchness...and not a good replacement for wired networks, especially in dense deployments...but great for a handful of clients or a larger number of tablets.
  17. Yes, I'm not sure the lack of stacking should be a deal breaker.
  18. Well, I'm king of glad to hear others complaining about configuration ...v2...because I was wondering if I had missed something. I wouldn't say it was the worst piece of software ever...but it's certainly amongst the worst. For an initial set up from a completely erased Ipads it does the job...until either some iPad throws a wobbly or you have random collection of iPads with different apps all requiring updates and random errors pop up...and it's very easy to mess up the profiles without realising it. But it is free....
  19. ...so make sure you can support 802.11at rather than the low power 802.11af - because most of the new "ac" access points (and even some of the older "n" multiple stream ones) don't run at full speed on the lower power. Yes - I know the "tech" specs will say 802.11af compatible on the box - but they "forget" to tell you that you don't get the full feature set if you only have the lower power. ...and yes, FWIW I subscribe to the 2xCACP bonds ...but I do prefer 2 x smaller switches in a stack with one of the cable/fibre bonds going to each switch to mitigate against failure.
  20. I always try to put switches in pairs and so would use a stack of 2x24 ports rather than 1x 48way. Then I always use a trunk/lag to feed them...and take trunks/lags off to any edge switch...and of course team network connections from servers into multiple core switches. This way any link between switches ..such as fibre module...can fail and network continues to operate. Even if a switch fails anywhere, network still works to edge swiches with only clients on failed switch that lose connectivity.. Needless to say, because I've gone to some trouble I've never had a switch fail....but it's good to know the redundancy is there.
  21. I've always bought second hand switches..saved a fortune. Bought ones with 10G backbone. No, you don't get a lifetime guarantee. In fact no guarantee at all. But I can afford to buy a spare switch to keep on the shelf when they are £100 each. In fact I've got two. Needless to say, I have never had to use them. And yes, I use cheap, £10 Chinese fibre modules too. Never had an issue for over 10 years. I always think schools need a second hand mondeo solution not the brand new rolls Royce solution.
  22. Kyocera fans here...from laserlife. They lease us the printers ...for free, provided we buy their toners. And of course they send out their engineers if they don't work.
  23. We use netgear. Excellent value for money. Usually buy them second hand. The last 10GB were £100 each, easily upgraded to latest firmware. Don't buy any genuine fibre modules...rip off prices...£10 Chinese ones work flawlessly and have never failed - unlike the genuine netgear ones. And yes, I hear the cries of horror....such as the Web interface is so S L O W...and yes it is especially on the older switches...but its not unliveable with.
  24. No - I think you need to read carefully. _Eligible_ students and staff can sign up....but the organisation needs to have licences because without them they will have limited functionality. What is free is "Office Online" bit via a browser (I think) ....but that doesn't include "apps" which can create documents nor can you download 365 application for windows.
  25. First my apologies...in that I was deliberately looking to raise your hackles.... And so it might surprise you to know that I work in the Independent sector to - although a day school rather than boarding (but have worked in the later too) And I am often keen to point out to suppliers that money can be extraordinarily tight in a private school....and indeed pride myself in being really careful with what I spend. But it would seem reasonable that a school offering boarding should be providing reasonable internet access for their boarders - and that might be several FTTC or Virgin cable broadband lines into a load balancer for every boarding house - or a multi-gigabit leased line connection if boarding houses have connections to the rest of the school. As you point out every user often has multiple devices and often use streaming video services. Bandwidth demands moves on at a pace and expectations will continue to increase. I think most schools - and boarding schools do understand this and need be constantly raising the bar. If you fail to keep pushing for this - you will get the blame because internet is so slow as to be unusable. No one will thank you for saving a couple of thousand pounds here or there, despite their objections when you propose spending more. Getting a reputation for not meeting student demands will ultimately drive students elsewhere.
×
×
  • Create New...