Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. ....Still think that using them as thin clients is the way to go....You could pick up a server of Ebay - if you don't already have something suitable - for a couple of hundred....and fill it up with memory chips (once you are happy it works) and install the Linux Server Terminal Project. I've used it with PXE boots running on old clients - but you should be able to get a Linux terminal server completely inside that 4GB SSD which should save on book times further. Then you can run Chrome, firefox or whatever ...I even had MS Office running under WINE. using clients that were so old they couldn't run windows.
  2. In the days of 2.4GHz only - wireless surveys were pretty much essential - and often you would struggle to fit 1xAP per classroom because of co-channel interference in buildings with lots of classrooms. It is possible in some scenarios today to survive in a classroom without an AP but only provided the APs in surrounding classrooms can use maximum power - and in senarios where they won't be using wireless heavily at the same time. If you want the high data rates often promised (but not delivered) by "AC" then you need a very strong signal - so the AP and client need to be 3 to 5m away at most, and no walls or even bodies in-between - because 5GHz is absorbed really easily and you soon loose all those multiple streams and MIMO capabilities which require a really high signal to noise ratio to work. Some wireless access points have software configurable radios - so you can program them for 2 x 5GHz radios - which is great in a classroom because using 2 x 40MHz channels in a "busy" network environment is much better than 1 x 80MHz channel when the single channel collision domain takes a real hit on the traffic when you start going above 15 or 20 laptops. And while there are cheap non enterprise access points - there are also expensive enterprise wireless systems that don't necessarily give you anything better than one of half the cost. Like all things - you don't actually get what you pay for.
  3. In my experience external contractors for cabling can be very hit and miss. Sometimes you get someone good - but I have had contractors use Cat5 sockets with Cat6 cable (caused us no end of problems a year later when cables started coming off connections in the back of sockets - which was when I realised what they had done). And whether good or bad they charge an absolute fortune for each connection completed - almost certainly more per hour than you get paid. Its worth insisting on proper documentation of testing with something like a fluke tester which is at least some guarantee that a reasonable job has been done if you do contract it out.
  4. ...and you do have the latest firmware on these netgear switches? We are netgear throughout - and have been for some time....but its funny you should flag up these (strange) issues as we have had a series of finger pointing issues with these GS752TS switches of which we have several. There has been a number of times when things suddenly stopped working when adding VLAN configuration to a port and there is now a known issue with using modules in ports 47 and 48 which cause port 50 to stop working completely (even when you stop using 47 and 48.. And once screwed up - I have had to reset the switch complete...put back the configuration it crashed with - and then its fine. It makes me nervous every time I need to change a configuration on them. But each version of firmware does seem to get better...
  5. Would they work as discless clients such as Linux terminal server client ....yes you would need a server....and maybe you would need some boot code in that 4gb. No chance of running an app locally, but .... this does seem like a back to front solution. First identify what you want to achieve in rather classroom, then decide on hardware required to deliver it....but guessing you are looking at a load of kit wondering how can we use it.
  6. OK - so http/RDP stuff works...if a bit slow. You use this for what? To allow teachers to access their desktop in school? Students too? Is this considered safe if the home computer is compromised. And do you use the password sync/remembering for students? Office 365? Google? Kerboodle? Does it work OK? File upload/download? So this allows students and teachers access to their "my Documents" and Shared Areas? So can students use this from a VLAN'd BYOD with tablets to access their files?
  7. ..Isn't it called Active Directory and GPO
  8. ....and notice that you can have these long delays with leased lines too. What about the guarantee of service I hear you ask? The guarantee is NOT that the line will be fixed....only that you will get "service" (probably someone on site) in under 4 hours. The best "guarantee" is to have two connections - into different corners of the school from two different cabinets....or 2 different technologies. We use a Virgin (asymetric, contended) line - originally installed as "backup" but now used for extra BYOD bandwidth and FTTC into a load balancing router. We have had several instances of one or other line being down...and no one notices...except for the odd complain that the internet seemed a bit slower. And we rarely see any evidence of contention during school hours.
  9. I agree...they are good and their web interface is one of the best...but the ongoing annual costs are difficult to justify when the there are other access points that work just fine - with no annual cloud managed charges.
  10. Does it have SMART or ActivInspire? (I hate it when "decisions" are made...without consultation....and then everyone is expected to support that decision)
  11. Big Mistake. Huge mistake. Wireless is not capable of replacing wired networks for classrooms of PCs/laptops with domain logons (apart from in the minds of suppliers and senior school manager). Yes its fine for BYOD where there is no downloading of group policies, virus updates and user profiles at the start of lessons. And increasing use of multimedia data files isn't great with classrooms of wireless kit either.
  12. I think many school budgets have been squeezed so much in the last year or two, that spending on anything that isn't absolutely essentially to keep things going has evaporated to almost nothing during the year. So when some money is found suppliers are caught out.
  13. I am now wondering how my smoothwall and Aerohive combination work. I use smoothwall as a radius server for wireless - and for DHCP (For wireless only). From what you are saying - Aerohive passes on authentication to Radius...the client connects....the client picks up a DHCP address.... Nothing has "told" the AP what DHCP address has been allocated...if it needs to know (and it normally displays an IP address) I presume it does some kind of look up. Does the Meraki web interface show IP addresses of clients (I assume it does). I'm guessing that smoothwall associated the Radius/username/device/DCHP with the client and maybe doesn't have to worry about an accounting packet from the access point.....or maybe it does get an accounting packet with the IP address.....I just don't know.....but it does work. ...I'd be very surprised if Meraki schools are not able to do SSO with wireless ...perhaps they are using AD authentication directly. Would this be an option for meraki? And would that pass on IP address as required?
  14. OK...but you don't actually need certificates for 802.1x authentication...are you trying to ensure that the WPA2/PEAP process is secure during the client logon? Is this process not handled by Meraki access point...which then in turn...passes the details (again encrypted...but over your cables) to ClearPass. I'm not disputing that fact that Meraki are at fault....indeed they seem to be admitting to that....only they are asking YOU to raise it with developers....it would seem sensible if they were raising it with their own developers. Still can't get my head around what ClearPass is providing you with that is so key to your requirements. I'm sure lots of schools use Enterprise WPA without individual user certificates.
  15. "Certificate on boarding".....exactly what is meant by that? I'm still thinking that Clearpass is something I would not be using for the Meraki kit if its not providing what Meraki requires from a radius server. Not sure what it actually offers you as far as MDM is concerned. Does it provide MDM functionality? Again there are plenty of alternatives. I can see that Network Access Control - such as testing that remote clients have Windows updates and current antivirus might be useful - but to be honest - I wouldn't be allowing anything to directly connect to my internal network apart from via published webservices in my DMZ. , sorry - don't understand why you are wedded to ClearPass.
  16. Ok, NAC.... so you check machines connecting have MS updates, AV, etc? Before you allow them to connect..so you are using it between the firewall and your internal network? Does it do reverse proxy? ...single sign on ? Just wondering what it's doing and how important those functions are. Presumably..and it would be annoying...but perhaps pragmatic...if you used another radius server..or indeed a secondary one working off clearpass...could wireless still pass through clearpass as well or would that force another authentication? And...are you using a captive portal or just the 802.11 authentication? I know I was gutted when TMG was end of life because nothing provided reverse proxy, SSO, NAC, radius ...as well as dNS and DHCP in a single package...nor indeed as tightly integrated...but apart from SSO for incoming connections we have managed to cover most things with different products...and maybe getting something else to radius for wireless might work..and cheaper than replacing wireless kit.
  17. I've no wish to defend or condemn Meraki, but I am surprised to say the least. I'm not sure why Meraki is looking for or requires this attribute - but it would seem "intolerant" of it at best. I am sort of surprised that Meraki are not helping you by suggesting another means of supplying Radius - because there are lots of stuff out there that can do radius using AD as a database - which I assume is what is required...and Linux ones for free. Yes it wouold require someone with some enthusiasm and a little know how....but they are not in short supply. I'm not sure why you would want a firewall (assuming the firewall is multihomed and is acting as gateway between a VLAN'd wireless network and other stuff) AND an Aruba ClearPass device - which must duplicate a lot of what meraki is doing in terms of identifying devices and traffic. Are all these access points on one site? or is this a multisite arrangement. I use smoothwall for Radius - but have used Microsoft TMG in the past - and use Aerohive access points. It never occurred to me that there might be incompatibilities with some vendors. These are supposed to be "standards" so I would expect interoperability or at least tolerance when things are not quite as expected. I like the meraki interface a lot - and thinks it sets a high bar for other vendors to match. Really gone off Meraki hearing the tone of their unhelpful response.
  18. Ordered a 65inch touch screen from RocheAV this morning at 10:31am By 14:00 RocheAV were on site delivering it.....having brought it come via Leeds to the Wirral...which is pretty good going. Is that a record or what? Even faster than Amazon. ..and their price beat everything else I was quoted as well. Don't know what they are paying their delivery boys...but its not enough.
  19. I like the idea of large parts of the web site being content driven - which allows several contributors to be able to modify generic files which are then picked up and displayed by the web site - without that contributor necessarily knowing how to write in HTML on anything about a special editor. Some form of tracking (probably using cookies) is useful - to get feed back about what is being looked at....or never looked at. It has been known that schools know when they are about to be inspected because of tracking web site activity!
  20. We use RM's Portico - which gives access to personal and public areas via a drag and drop web interface. ...and of course, we have some cloud shared areas in Office 365. If its only between the ipads - then cloud would seem to be the vision.
  21. Ever since my ridiculously expensive genuine Netgear ones started failing I started looking around - and since finding some cheap compatibles I have never looked back. Genuine ones continue to fail...and not one of the compatibles have failed despite lasting years longer.
  22. You are opening a can of worms here. Personally - I think they are all rubbish....but most have some feature of merit which might attract you to adopt them but at the cost of losing a feature in a rival product. The eye-watering cost of some of them makes you wonder what you are getting for your money. It would be good if MIS systems actually provided you with these capabilities - because those systems have full access to user/staff/timetable data. Any third party product has to rely on what that MIS system provides as external connectors (like group call). And it depends what VLE means to you. To some it means parent/school communication. To others homework assignment/setting/markbooks. Some want it to include parent meeting planning and room/resource booking. Some want "messaging" integrated. And to do these things well probably needs a full time manager to support staff and students in using it. (= twisting their arms to use it in some cases). This won't happen so everyone will be given half a days training and told to get on with it and learn as you go. I usually paint a red line with such software installations (and this goes for MIS systems too) in that its not my job to be an expert in the timetable, managing the school diary, homeworks etc. My job is to maintain the computer system. If the VLE works - its up to someone else how to put data in, change it etc. We are just about to install Firefly (..no its not a VLE....but it has some functions that a VLE might have). In some ways is fairly limited - but what it does do it does quite nicely. It is going to replace our home brewed web portal which linked up to our MIS via SQL and VB.net. I quite like google classrooms - and several staff here use it and it seems to work well. Again its not a VLE - and could be customised to do most things....but I don't have either the enthusiasm nor the time that it would require to do everything we would like. While Office365 and sharepoint could be used - its always seemed really clunky and difficult to customise - partly because potentially its complicated. Microsoft has withdrawn their "classroom" bit - perhaps recognising that it was awful - and nowhere near as good as google's offering. But you can still use "Teams" to do much the same if you were wedded to this. (I'm guessing there was a not a single school using their classroom app). Always thought the RM unify could be expanded by RM to provide some VLE functionality - as its a portal that is commonly used. Magellan is another platform albeit not so well known which provides better functionality....but again not really a VLE. What you can up with can be hotch-potch of several different portals/VLE/MIS systems - and of while this can provide the best of each functionality its all pretty confusing for staff/students/parents.
  23. Yes. I like the optional Airserver Connect App - which allows you to connect via a QR code displayed on the PC running Airserver. Avoids having to use Avahi (Or wireless management) to repeat all the bonjour broadcasts between VLANs (assuming you segregate your wireless traffic from domain traffic....of course you do). We use smoothwall to route airserver connection back to desktops - and only allow it for "staff" AD groups. Only wish you could do the same for AirPrint...and that the connection made would disappear automatically after use....so that you don't print to the previous printer after you go somewhere else. Yes - I know there are printer apps which use QR code and you can "Send documents" to the APP which then prints them but that is not quite so intuitive...and again once a printer has been selected it stays there. In fact with some printer apps there is no way of removing the printer from the list....other than resetting the ipad... Bluetooth and/or NFR are promising for the future...but our printers don't support these.
  24. I find its often the lighting. So it can be surfaces near a window which catch the sun. And although I've not noticed this with mice - I have noticed some of our remote controls for projectors are particularly sensitive to particular kinds of "daylight" fluorescent light strips. When the light is on - the remote doesn't work.
  25. We try to use 2x1GB fibre (or copper) links back to the core switches (a virtual stack - a ring actually)...with each fibre going to a different switch in the core of the stack. So a failure in a stack switch - or in one of the fibres...or their modules....does not loose connectivity for the edge switch. We have never lost a core switch....(yet...)...but have lost the odd edge switch...and several modules have failed (until I discovered cheap ones from china which seem much more robust). Apart from backups and copying large files or folders its surprisingly difficult to fill even 1x1GB link with random access data.
×
×
  • Create New...