AlanD
Members-
Posts
1,102 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by AlanD
-
No difference between BYOD and schools own devices. Users are identified via AD credential ... using radius...and monitoring and filtering is in place. I've always wanted the school to agree to "test" that phones or tablets with 3/4G are at least filtered by the provider...but SLT think we can't do that....possibly because they want to avoid confronting parents. Does seem a nonsense that we spend thousands filt earring and monitoring...but at the same time they can go and do what they like via 4G. I think government needs to think about empowering parents..and smart phones held by children should be totally supervisable by parents ...and during school hours the school..and apple and android need to build this into their OS. At the moment they are working really hard on things like end to end privacy...and I don't think this is appropriate for young students.
-
Considering the rather extraordinary large cost of boarding, it would seem the very least you could do is provide them with decent wifi coverage. If they could live st home they'd probably have a 30mb openreach fibre connection for themselves, and providing them with something similar should be seriously looked at. I am slightly surprised that you are just using what appears to be a personal wpa code to connect....much better to use the ad/radius enterprise connection so that they are identified clearly. Assume you must have a captive portal...but they are such a pain when you just want to use an app because you have to go throug a browser first...and presumably it operates for a fixed time before reauthenticating. Seems they were the enterprising ones...and you are doing to be wanting.....
-
I'm not so sure about the demise of a hard controller. Things seem to go around in cicles, and while it's true cloud based solutions have some current advantages, particularly for managing multi sites, it is not so attractive for pro active layer 7 montitoring and filtering where for even a small site significant amounts of external bandwidth is lost simply managing the access points. If access points are empowered to communicate and negotiate independently of a controller then a cloud enabled "manager" can work well..and continue to work if external internet fails. But if you want cut down access points that defer to a controller to decide which clients connect to whic access point and when to roam clients you might decide that functionality is best kept on site otherwise any failure in your internet connection would probably mean wires did not work to even local servers.
-
To do it properly you need 2x fibre converters and a length of preterminated fibre. Or..if it's a single ip camera termination in the garage then you might consider a wiresless bridge.
-
When someone stops on the road and asks you the way to X it's always tempting to offer the reply "well, I wouldn't start from here...". Ideally you need to design access points, controller, radius and filtering all as one solution. Putting together a random combination, regardless of how good and well designed each product might be does not guarantee that they are going to work together. You need to get each supplier to explain how they are going to integrate their component with the rest your network components. I am pretty certain, assuming fortinet/Meru controller is on site, that you can integrate that with any standard radius controller. Get that working first so that wpa enterprise connections authenticate using ad credentials via your radius server. Not sure if it's sufficient to have a shared key on every access point or whether it's sufficient just to have it for the controller. Then you need radius accounting to pass details of the logo and is addess to light speed. Not sure whether light speed supports an on site relay to pass this on or whether you will need to write firewal rules to do it directly....or maybe light speed doesn't support using radius accounting....you will need to talk to light speed. Don't let each supplier make you decide to repeat the logon process via a second captive portal...that would be plainly annoying, especially for apps that don't even open a browser. .
-
Aruba 200 series POE Injector alternatives
AlanD replied to Shadow_Walker's topic in Wireless Networks
The ONLY access point that I am aware of which requires its own PoE injectors are the earlier Ubiquiti ones which are 12V (or is it 24V?)....but you get them delivered with the access points. As far as I know all other access points are the standard 48V ones. This is a the voltage that PoE switches deliver..... But, you do need to think about power. Because "standard" PoE delivers around 15W (802.3af)....and while this was OK for most 2 and some 3 stream "n" access points it tends not to be enough for many "ac" access points - which ideally require 30W. (802.3at). You need to read the small print carefully - because even access points that claim to work on 802.3af you will find don't work fully with that power level. Either they can't support both radios, and/or they can't support more than 2 streams, or MU-MIMO or they can't support the second Ethernet port. And if you are unable to use these features because of that you might start wondering why you invested in those expensive new access points. CAT6 and its later variants tends to be much better at getting PoE to the access point because the wires are typically thinker. CAT5E works for limited length runs. Sometimes I move a PoE injector out of the cabinet to be near the access point for a long run....which is fine until someone turns off the electric to it. -
What irritated me when we had a problem with our FTTC line was not the delay in sending engineers but their inability to fix it. In our case we had a "connection" and high signal to noise ration but do data. The Openreach team came and tested the line (waste of time) and announced there was not fault. But my internet doesn't work I complained to openreach. Must be your router they said - well actually ) said its your router - and anyhow I had tried 3 routers. They sent another team - obviously not next day because by now it was to late to schedule that. The next team....tested the line again and announced there was no problem. Why are you testing the the line I asked - and the answer was because it was the only thing the team could do. More calls to open reach. More accusations it was our router. The third team to arrive (after a weekend now) again could only test the line again - but one of their young guys said you could ask them to do a "lift and shift" in the cabinet....but they weren't tasked to do that - clearly above their pay grade. So eventually a fourth team came - after a lot of abuse on the phone to openreach (well actually - it was to my provider to be fair were doing their best - and didn't have "lift and shift" as an option. And of course after a lift and shift it worked fine. And this highlights the problems of separating openreach from internet supply....because openreach reach keep getting their money all the time. If we were able to stop openreach getting money when our internet stops they would have some financial motivation to to fix stuff.
-
Onsite Smoothwall vs Hosted Lightspeed
AlanD replied to The_IT_Guy's topic in Internet Related/Filtering/Firewall
We use a smoothwall appliance. It does Load balancing between 2x ISP for us. Its runs DHCP for our wireless BYOD - and RADIUS too (integrating these two allows for one sign on - with no subsequent logon challenges to establish who the user is). And of course it allows us to write firewall rules between our VLANS based on username. Its pretty good at "prevent" reporting - probably its strongest point. My repeated annoyance is that when you tick the box say allow access to "google docs" - it works fine for desktop PCs...but not BYOD - when you end up having to create and write separate rules....in fact you end up writing rules for most BYOD access because the desktop ones don't often work for mobile devices. Don't understand why smoothwall doesn't produce a separate set for mobile devices. And of course it does VPN connections (for our MIS system to talk to on line web server)...and it does reverse proxy for running our internal web sites... So I quite like smoothwall....but I looked at a number of others....and I always recommend others should do the same. Never make a choice because you hear a handful of people say a good thing about a product. By all means use that information to include it in your decision as to which products to test - BUT - you need to mae your own decision based on your own priorities. Smoothwall is horribly expensive - for expensive - and there are free products like PF sense that many use and it does a fine job for most things. Most offer free on site trials. Don't omit this stage of testing with you top selection - especially based on a reluctance to spend the time on it....i -
Is BECTA's 1:50 (IT staff:Physical Devices) Ratio still relevant?
AlanD replied to elsiegee40's topic in General Chat
This is the "how long is a piece of string" question. And the answer is that it depends what you want that string to do. Typically - teachers can be quite "needy" and are happy and grateful if you are there ideally every lesson they use ICT to hold their hand. Clearly this degree of close support would be generally impossible - and affordable. You might try to argue that a school with practically zero infrastructure - no servers - externally managed wireless and say chromebooks - requires no one on site for weeks at a time....and indeed many primary school effectively work this way. So I guess, ultimately its up to the head teacher to decide - and for SLT to oversee what the IT staff (if there are any) are doing and give some guidance to how priorities are to be met. And its getting those priorities sorted that prevent 80 hour weeks. Sometimes there is a rush to "lets get XXX company in to fix/sort that" to free up a technician's time - but the reality can be the technician or network manager has to be on hand practically all the time the company is on site - and in the end may on site staff may well have done done the job quicker and better. Often problems stem from jobs taking longer - sometimes much longer than were originally envisaged. These are the ones I hate - and end up putting in extra hours on - because running late on these jobs often causes a crisis if the next job doesn't get started on time. And then there are jobs like "documenting the system" that keep getting put back for a rainy day when there is nothing else going on...but of course that day rarely arrives and eventually you get challenged about why you haven't done these important tasks. I particularly hate getting asked to do important jobs (important in the eyes of those asking) at last minute which prevent other tasks which you had promised to have finished to those who had asked in a timely manner. -
We try to buy projectors that have LAN support - and therefore come (usually anyhow) with a "web" pop up remote - and we provide a link to that via a staff web portal (with some asp code that selects the correct projector relating to that teacher PC)....and never give any user a remote control.
-
Yes ...rm onedrive does sign on automatically and does assign a Drive letter...and it occurs in the background after logoff...and certainly for us it takes a good minute or more... which is somewhat irritating...but it does give a familiar feel to use once it's there. Still need local storage for profile settings of course Because it's not there until after logon...which I assume is true for most such utilities.
-
No idea, but I'm thinking...just go and try one. You can always move the ceiling mount....tedious but surely not more than hour's work.
-
We provide OneDrive, by which I mean RM's onedrive for students and staff to use as an equivalent to a pen stick. I find logon slow...although to be fair doing any office 365 login is tardy so perhaps it's not surprising, but it's irritating nevertheless as if you open a browser while it's connecting, the browser window closes when connection completes even though you are in the middle of something. We dont use it instead of local network storage...but I suppose we might do so in the future. I'd probably put a read only document in their Drive named "Don't save any files here" and put a shortcut to the O: Drive. For us, shared areas use more space than users documents, and it would be good to have something equivalent that works like O: Drive mapping, but nothing quite delivers that, or at least not anything I have seen. Most users are somewhat reluctant to use it despite the ease of connecting at home or from mobile devices to access the same material. But it's only been in for a year so perhaps it's still early days.
-
Why use a captive portal? Surely most devices just use Apps for stuff...and it's just annoying to open a browser and go through a logon process first. Why not use enterprise wpa? ....which does work with radius. If it's not for BYOD but to use School provided shared devices where a logon only lasts 45 minutes or whatever, then I would be looking for my web filter/monitor to provide a captive portal. In our case smoothwall does this....and I think many if not most other solutions do this. Ultimately it's the filter that needs the logon details...the wireless doesn't really care.
-
I'd be interested to know what your traffic graphs actually look like. Do you find that "upload" is as much as "download"?
-
The big debate: Should we be moving to Linux in Schools?
AlanD replied to Wubbalubbadub's topic in Blue Skies
I always think red lights should start flashing whenever a conversation about IT starts moving towards hardware or infrastructure. That's not to say the "right" hardware does not make a difference - but there are may "right" solutions and I agree that familiarity with several platforms leads to a better understanding as to what IT is about. Too many teachers still focus on "what button do I press to insert a new line into a spreadsheet" - and believe that teaching this is delivering an ICT skill....or that the fact they don't know which button to press somehow prevents them from delivering ICT skills in the classroom. One teacher complained he couldn't use iPads in the classroom because he had never used one and had only been taught to use windows. It was interesting to observe that he used an iphone at almost every spare moment during the day. The skill students need is to learn to follow their nose when using ICT...yes they may need to pick up a few tips from teachers or more likely from classmates. They need to be prepared to explore a user interface and hunt around for the option required. Its much more important they learn this skill rather than specifically being taught how to "insert a row in a spreadsheet" on one particular kind of platform. So YES - not only do I see nothing wrong with using Linux, it would get my vote of approval. BUT don't expect using it to gain any credit - because its the ICT skills that you deliver which count....which would be "Can students demonstrate they can code"...or "construct a spreadsheet for compound interest". No one will care what platform they used. And while there might be an argument that Microsoft Office skills are worth having - you can deliver those with Office 365 on Chromebooks, Linux, Android iPads - or Windows. There are lots of schools using chromebooks well without a single PC in sight - and I don't see why using Linux would be any different. Personally - I would be using Linux via thin clients because I'm not sure that the management tools exist to "lock down" individual linux workstations (but perhaps I need to do some more research). And the thin client solutions would allow you to make use of some old workstations (or ones others are throwing out). -
Roll-out BYOD, Internet and printing access only
AlanD replied to san_narula's topic in How do you do....it?
Which is why you need certificates on their BYOD devices - and block traffic that his "hidden". Then you can see (block and filter) all google searches - smoothwall for example will tell you exactly what they typed in when using https - and provide "prevent" information back to safeguarding leader based on this.- 14 replies
-
- byod
- networking
-
(and 2 more)
Tagged with:
-
I kind of did this - as an experiment - but it was ten years ago. We used the Linux terminal Server project....and so used stripped down old PCs - no hard drives with PXE boots off the linux server. Used WINE to get Microsoft Office (and some other Microsoft programs) to run on the linux desktops - as well as the usual linux stuff. I think the browser actually ran locally. Everyone moaned about what they called the "non standard" linux desktop (...as if that mattered when they were still using Microsoft programs...) and insisted that students needed the Windows experience. Today - with ipads, and Android tablets - and cloud based apps like Office 365 and Google Docs it should be less of a problem to sell such a package to users. Maybe I should revisit this. But - there are areas - like Design and Technology - with its CAD/CAM programs and perhaps Music with things like Sibelius which are clearly not possible on thin clients.
-
I wouldn't use AirPrint with iPads. Bonjour is a nightmare in a school. The last thing you want is 50 printers showing up and users choosing the wrong one. I would recommend using the printer manufacturer's APP which usually allows you to stick a QR code on the printer and when you want to print at that printer you just point the camera at the QR code and send the document to the APP. You need firewall/gateway rules between you wires lol and printer network of course as you would for Bonjour.
-
"but by then MS may have already lost a lot of users to Google Drive, which seems to have less issues in comparison" The problem with google drive is that you can't "map" it to a drive letter - the best you can do is to sync it with a local folder - and that is poor for school networks with users logging on and off. I like the RM "OneDrive" where every desktop user gets an "O:" drive that behaves like a penstick....but one they have access to anywhere - including mobile devices. I think IAM cloud does something similar. No local caching. Increasingly users make this their "default" storage location. Slightly alarmed to hear that Microsoft are changing OneDrive...I wouldn't want to lose this functionality.
-
Top Concerns for this academic year.....
AlanD replied to Becky-Impero's topic in Network and Classroom Management
Gee....i3 2120...those are really old - possibly 5 years old.....a complete life time for many businesses....and I've always argued that schools' uses are more demanding that that of most businesses. A contemporary i3 would run rings around it - and save you £30 or more pounds of money depending on how long you keep them in terms of electricity used. I suppose the SSD is worth £50 so that doesn't make the PCs too expensive....but they are end of life rubbish really eeked out as sluggish machines for another 3 or years. I always try to arrange for senior management to have some of the oldest and slowest machines....it helps them to make a good decision when it comes to IT purchases. When they complain how slow they are starting up (make sure they have to start them ...don't do a WOL for them...so they can see how slow they are...remind them that classes are doing that 5 or more times a day) There is ALWAYS money to be found - maybe not enough money for all their want list...but you will be surprised what can be found when they need to find it. I don't think there is a much mileage left in projectors either. I try to get Flat Panel replacements when projectors fail or new classrooms need fitting out. I know that means discarding an otherwise good touch board sometimes....but the lack of shadow and the ability to use them without drawing the blinds and turning the lights off is a great bonus. Again you are looking a say a ten year investment. -
Top Concerns for this academic year.....
AlanD replied to Becky-Impero's topic in Network and Classroom Management
...nothing wrong with 9 year old computers. We have some Conroe Core 2 Duo machines still doing service of that age. There were a few eyebrows raised and challenges when they were originally specified as they cost almost £50 more than the "budget" AMD single core "school computer" that had been recommended by the supplier. In fact I think they were the first generation of computers we had with the faster SATA drives. £5 extra per year per computer really doesn't seem to bad for a computer that was lightening quick when new, more than capable when middle aged and still useable when ten years old. I've always questioned the "replace every 5 years" strategy when applied to a budget computer which is moderately slow when new and painful to use after five years - better to invest in something that will last and give a better long term return on money invested. The trouble is that long term for a school is often 2 years not 10 so convincing those with the purse strings is not easy. Keep in mind that some of the current CPUS are 65W or even 45W. That can save you up to £50 in electricity over the life time of a computer. Remember to add that figure to a second hand computer which some schools seem keen to buy. -
There is something really weird going on....because we use netgear throughout - and don't get DHCP issues. ...and we use a couple of those GS752TS in a stack. You have upgraded the firmware in ALL the switches? And the latest firmware is the actual working version (There are two firmware images in each switch). The DC itself has a statically assigned address? On the default or some other VLAN And its not a stacking issue? You have tried it with a single switch? Netgear have always been very good with support on the very few occasions I have needed to use them (a bricked switch after a firmware update..for which they were ready to send a replacement switch until I offered to try reinstalling the boot code - which they were happy to let me try - and then it worked)
-
Roll-out BYOD, Internet and printing access only
AlanD replied to san_narula's topic in How do you do....it?
"I have been asked (told) we roll out BYOD for students across all year levels" .... I'd be interested to know if this itself is the "objective" ...or exactly what the educational objective is. I'm not suggesting that BYOD might not be the solution to the educational objective - but how you implement BYOD may make the educational objective a success or a disaster. Focus on the Educational objective NOT the BYOD means of delivering it. There is a very real danger of having a brilliant BYOD system - but one which no one befits from. Its going to need to include training for staff....and students....with time allocated to this...and boots on the ground to support staff/students. Not just training to make it work - but training as to how to make good use of it in the classroom. Don't assume that because a teacher or student can use facebook or snapchat that they could actually create a spreadsheet in Google apps. And just using an APP (such as for vocal testing) is definitely not delivering ICT skills. If students (and staff) bring their own devices - then yes - they could contain all sorts of malware that you would want to protect your network against...and other BYOD users. Most wireless systems allow you to isolate wireless devices from each other - even if they have common access to a gateway. This wireless network needs to be on a VLAN. No question about that. So you need smart switches that support Vlans and wireless access points configured to use it. And you need something like smoothwall with multiple "networks" , filtering, monitoring, firewall, rules etc. to act as a gateway. It needn't be smoothwall - but it probably needs to be a hardware device (maybe virtualised). "connect to the school wireless network without IT even touching their device". Well IT might not need to "touch" the device - but users will have a learning curve. Its NOT going to be as simple as typing in an WPA code as you might at home and away to go. To start with you are going to need meet the "Prevent Strategy". Its compulsory...or an obligation. Or whatever words you would like to use. This requires you to "monitor" what users (staff and students) do. You cannot ignore this requirement. This is either going to require you to use "Enterprise" logons using Radius (or direct AD) with your access points - or ... you might consider some kind of captive logon screen using a browser. On second thought - you don't want a captive portal - because users will want to use "apps" and they will find it a real hassle if they have to open a browser and logon before using an app. And you will require your web filter/monitor to "talk" to your radius server so that it can identify the user logon and allocate age appropriate filtering rules (because that is another requirement). And if you are monitoring (and you will be) - they will need to have a certificate installed on their device. There is no way around this. Its is essential for https traffic to be monitored. No you don't need it at home for your home WiFi - but you will need this in a school. You can tell them they need to download it from a location on your school web page or whatever - but they are going to need to install it.....and you will probably end up doing it for at least some staff as well as many students because its a step too far for many....and users are confused because they think its working after the initial wireless connection because they can get to some web pages. And installing the certificate on Android is not always straight forward either - depending on the version of Android in use. Often you need to download it as a first step then find it and install it as a second step. Most Android users have no idea where to find the certificate after they download it - even when you give them step by step guides (they can't be bothered reading them). ...and making an Enterprise connection with Android can be a nightmare too - sometimes requiring you to make changes such as making it NOT require a certificate to make the connection to your access point....and choosing the correct PEAP/MSCHAP options... Still - in theory - if you give them picture book guides some will manage to make this connection without "IT touching their device". Finally - you will soon find that using your BYOD with the likes of filter devices like smoothwall is a nightmare. You tick boxes to allow them to use Google Apps, Office 365 or for staff to use social media - boxers that work fine for desktop PCs....but as you will soon discover are not going to allow things to work for mobile devices. Chromebooks are going to need even more work. Certificate pinning are going to stop YouTube working, and things like Spotify and Snapchat are going to require you to make changes to your firewall settings too - because they don't use http(s) ports for all their activities. (You might imagine that the likes of smoothwall would have added all these things and provide ready made configurations for mobile devices - but you'd be wrong.) Yes these things can be made to work - but only by a lot of configurations and trial and error....and a lot of irritated users. And of course you need to consider the impact on your external internet bandwidth. And while you might allocate a quota - that won't be very helpful if when a student requires to use BYOD in the first lesson after lunch they can't because its all used up. I'm an advocate for BYOD really - but its not an end in itself. Delivering ICT skills needs to be the objective...and too often school management (and IT departments) somehow get side tracked into making the infrastructure the objective without nearly enough thought as to how to deliver those ICT skills (possibly because the teachers don't have those skills and are not capable of delivering them) And if you do not have Office 365 and Google Docs set up - with sync tools (free - except for the time to implement them) you will probably want to set these up. And you will probably want to think about printing and how to use Airserver/Chromecast so that BYOD devices can show their screens on a classroom projector. Its really very difficult to explain to students what to do if you can't actually show them. I like using QR codes with manufacturer's APPs for printing - as it saves 50 printers appearing in a dropdown list using Air print. Google's Cloud print is worth setting up too. Give yourself about a year to se this up. Its not a week of fortnight task - especially if you are still doing the day job of running a school computer system- 14 replies
-
- 2
-
-
- byod
- networking
-
(and 2 more)
Tagged with:
-
Use the latest firmware...and turn off STP. Are you sure you need to use STP? I've always preferred to leave redundant cables that would provide loops disconnected...as I prefer to go around and connect one up if I lose connectivity in some outlying area and need to re-patch a route to it. STP is always capable of tying itself in knots if connections get a bit "iffy" especially when power outages (usually a over enthusiastic caretaker or cleaner) keep turning things off - especially if they turn them back on again shortly afterwards.
