Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. FWIW I've not had a good experience with Band Steering. Devices that support both bands often "see" the 2.4GHz from good distances away - and perhaps in offices away from classrooms which get a strong 5GHz signal. But band steering recognises the devices capable of 5GHz - and drop the connection, after which they attempt to connect at 5Ghz - but because the signal is weak (because 5Ghz doesn't go through walls so well) the client soon drops the 5Ghz (or barely gets any data through the connection...and finally reattempts to connect at 2.4Ghz and so the process goes on with a very poor experience for the client. Tried turning down the 2.4Ghz power even further - but that resulted in no connection (or poor connection) at all for devices outside the classrooms themselves. In the end we decided it was better with band steering left off and allowing the clients to decide for themselves - which they do a much better job than they used to with more modern WiFi cards. We do use load balancing and it seems pretty good at shunting a few users in classroom onto weaker but lightly used APs further away which gives greater total throughput in bandwidth in a dense deployment. What is best for the occasional user is not the best configuration for a dense number of users - and I guess its a good test for the management software who well it copes with dynamic channel widths. It would be nice to image that they are capable of noticing a single AP under heavy load - and say giving it an 80Mhz channel temporarily while surrounding ones are 40MHz....but changing what it does temporarily kicks all the clients off onto poor neighbouring APs addining to loss of bandwidth by the time they are forced back again to the wider channel being advertised.
  2. In your dreams....I'd very (but pleasantly) surprised - and happy if an "ac" access point and clients managed even 250Mb/s of actual successful data transmission - to a browser, fileloading, or loading a domain profile. Yes instantaneous transmission rates will be higher...but not successful reception rates which are figures that should be quoted. Put 10 laptops in a loop with some script loading a file and printing out data per second at end of each file loaded....and you will see figures of 20Mb/s on each laptop or less even when using an 80MHz channel. If you use a 160MHz channel....well you won't be using a 160MHz channel unless you are home - complete waste of time and often not supported by enterprise Access points anyhow. Only the people selling them and gullible purchasers believe otherwise. I'm not saying "ac" doesn't give some benefits - it does clearly...but they are benefits that will be seen only by getting out your stop watch, because in practice to users it won't feel any different to using "n" kit.
  3. In dense deployments such as classroom blocks with tens of connections per access point 'ac' offers few advantages because you can't use wider channels effectively in those conditions. Basically you are stuck using 40MHz channels which 'n' does well. Multiple streams and mu-mimo give some benefits ...typically up to around X1.5 depending on getting really strong signals from APs in each class room to provide spatial separation...and you may not have those signal strengths if you have to turn down the power to reduce the size of the collision domain and co-channel interference. So yes , generally it's not worth changing from n to ac. Personally I thing the annual charges for cloud managed AP solutions...even at 10 for price of 5 is still staggeringly high, especially when there are other proven APs which are really good with no such on going costs.
  4. Looking at these eye watering figures makes me understand why RM now have their own cloud backup solution which they recon is cost effective. No annual charges for WSB...and no licence cost...but yes, you have to buy new disk now and then...and remember to swap them around.
  5. ..Yes I promise myself every day to do this...and some how the end of the day arrives and its never happened.
  6. I would use configurator (2) to erase and then re-install the apps. In fact I'm guessing you will have to do this. I often describe configurator as the worst piece of software ever - although I'm sure there are some others that come close. When everything works its fine - but sooner or later a profile won't install or an app won't delete (or install). Currently my issue is that seemingly randomly I am told that I have an app which is preventing the update (of other apps). It doesn't tell me which of the 50 or so apps installed is the problem...and its probably not one of those apps - because they are installed on the other ipads which update just fine. I would say they deliberately make it this bad to "encourage" you to buy a third party MDM. I would use profile manager - but every time I spend a day to set it up there is something not registered or setup or correct....and I have to give up. It even makes Microsoft software look good.
  7. I (accidentally) stopped paying for Symantec D2D2T support two years ago.. When I discovered I mistake I offered to pay from the back dated date - but Symantec wasn't having any of it and insisted that I bought new licences (only 3 months overdue). I have used it without problems since - and the money I saved has more than paid for renewing the licences (such is the high cost of support). I'm not rushing to do that. Yes - I don't get updates....but continue to do test restores and everything seems fine. I also run Windows Server backups to local USB/SATA drives just to be doubly certain. In honesty - I think Widnows server backup is rather good. I'm not sure whether I really need to keep D2D2T and I could get by in having a larger number of rotation disks for WSB. you get a lot of those disks for £1000 a year!
  8. The trouble with bonjour services - is that you end up with tens - possibly hundreds - of printers and/or airservers turning up in your selection lists. And its quite a "noisy" service using up potentially significant parts of your wireless if not wired bandwidth. Yes - some wireless systems allow you to selectively advertise different services from different access points - but its usually fairly crude and labour intensive to setup - and then some clients/access points remain connected when you expect them to pair differently and so the expected list of services isn't what you want them to be. And using Avahi you lose that ability to selectively advertise different services to different clients/wireless access points. All in all - Bonjour services are a mixed blessing - and often less than ideal in larger enterprise deployments. I'd like QR code systems like "airserver connect" for printers - but there doesn't appear to be anything that is universal - or which doesn't cost what ends up being quite a bit of money.
  9. One morning a week is not enough to sort a problem like this....and the trouble is that IT doesn't scale according to school size - it often takes the same time to manage things for a small school as a school twice the size.... Maybe you need to spend 3 days concurrently there - and not go in for 6 weeks afterwards - or tell SLT they need to invest in more support. However, I'd also be wanting to roast RM's support guys into sorting this. Give them remote access - show them adding a user - and then that it doesn't appear. Not wishing to let them off the hook - not least of all because we don't use RMunify - but I do see Microsoft's Azure Sync seemingly fail sometimes (never quite sure what the user has done - of course - sometimes they manage to set a their password to blank for internally - but it doesn't sync to that value) Seen problems with google GAP sync too. In bot cases resetting the password has allowed the user to proceed of course.
  10. There is a free APP called "Airserver Connect" which works by Airserver displaying a QR code on the PC which when you show it to the Airserver connect app will connect the ipad to the desktop. It works across VLANs (assuming you have some kind of routing - we use smoothwall - which applies group rules to only allow staff to connect )...so no need for Bonjour when using this. As far as Airprint is concerned - I've yet to see a similar application that is generic - but various printer manufactures provide a QR app. I've played with the Lexmark one but not found it as easy to use.
  11. This is all interesting - even though I don't want to deploy this stuff.... I hear what is said about lower resolutions and slower frame rates - but from the odd cameras we use - I find they are often used to cover large areas with a lot going on - and while I would be happy to sacrifice highest frame rates I would want to keep the resolution at HD. So it looks like just a "couple of disks" is not going to work - or at least not work well for 60 cameras. You will need more disks - even if they are smaller capacity....and I would say they need to be 24x7 capable "video" drives (or better still enterprise disks) - probably 7K2....not cheaper desktop drives. Desktop drives typically don't work well in RAIDs - especially when sectors start to go bad and get remapped - which is a normal and expected process...because desktop drives keep trying to read bad sectors and these retries - which may work - but degrade the performance of the RAID which might lead to "stuttering" in Video playback - or worse recording. I'd be nervous about the impact of 320Mb/s taken out of any existing 1Gb/s capacity links - so I would be considering setting up some LAGs between my switches to provide extra capacity....unless you already of 10G links of course.
  12. Sorry - I have little experience with CCTV except for the few we have - which are not IP based ...and not HD or high frame rate. I'm sure if boxes are sold which support 64 video streams they will work - or at least will work provided you install the correct "Video" if not "Enterprise" disks as they require. A back of the envelope calculation tells me that video streams are potentially around 5Mb/s (without compression and dependent on frame rate of course). 100 cameras are going to potentially take away half of your 1Gb/s networking ...and writing 500Mb/s is seriously quick - but should be possible with sequential access to RAID 1 disk set. In practice I am guesing that with slower frame rates and compression its going to be a lot less than this..perhaps under 100Mb/s. I'd be asking about exactly how much data is being transferred per camera per second to check its impact on the network.
  13. Setting up a Team/LAG between server and switch seems like a no brainer....I'll assume its a core switch and cameras are well spread out between the ports and edge switches so there is no other potential bottleneck. I'd be interested to know what the data rate is per camera, Its possible that the problem is with the Disk IO - which might well cope with sequential read/writes of the amount required - but are probably writing to 85 different files at a time - so the access time and IOPs begin to get critical....especially if these are non enterprise SATA disks in the raid....perhaps running at 7K2 Its also possible with non enterprise disks that there are "poor" sectors which are not marked as failures - but are causing re-read/writes, ...and then if you want to view a file at the same time as all this is going on ....
  14. We have been using Eclipse.net for some years. To be honest, I'm not wildly enthusiastic about it...always hassles syncing users from MIS to it.....but it works. I also think its vastly over expensive for what it does. It still uses silverlight. They have talked about HTML5 version...but I've not seen anything that suggests its more than something that is talked about. They have a hosted solution - which is dead slow. Apparently when schools complain they say its the school internet connection - but say this even with its 100Mb/s leased line with no one else using it....so I suspect they have too much loaded onto a skimpy server in the cloud. Speed seems fine hosted internally. I'm not a fan of hosted solutions unless there are clear benefits in terms of cost and usability. There are still too many thinking "cloud is the way to go" without examining the justifications of it. Currently we are looking to move away to using a Library management system that runs on our MIS system (we use something called schoolbase - no SIMS here!) which costs almost nothing extra - probably isnt quite as polished...but will do the job.
  15. We are talking about a "wired" not "wireless" implementation here aren't we?
  16. I always hate feeling I need to step in to defend RM....because I am quite critical of what they offer - or at least what they charge for it. But to be honest - I support both the concept and largely - the product itself. Usually when I hear complaints on this forum about CC4 its from schools who having invested in CC4 either (a) choose not to continue with support payments and so, unsurprisingly don't get advice, critical patches and fixes or (b) insist on doing things the "non RM" way and then complain it doesn't work well. I agree - that CC4 does have an "overhead" on what the desktop PC does...as does adding AV, Netctrl, or any other additional software. Group policies can be particularly sluggish - but if you want a fully locked down vanilla PC you apply the same ones with the same speed hit. And Roaming policies are generally used - which again are often slower than mandatory ones. We have 9 year old Core2duo Conroe PCs with 4GB (increased from originally 1GB by cannibalising older machines as they are retired) and they are just fine....under 2 minutes to logon. We actually think 2 minutes is a long time - or target time is under a minute which all our newer machines manage - but most of them have SSD. And yes - I'd be knocking on RM's service desk every hour of the day until I understood why logon times were not as expected. And as it would appear you have a service contract presumably you are doing this - and presumably RM are actively supporting you - because again - RM support are good - actually they are really good - or at least generally. If I had to moan (and I do - very often) it would be because they don't always listen or believe you. For example I complained on and off since CC4 went in that MS updates were not installing everywhere. When I'd find a machine with missing updates - they would say rebuild it - which of course fixed it. Then I'd find some more and they reinstalled WSUS on the server - and then (some) updates went on....but not all. Eventually they reinstalled WSUS a second time....still some PCs missing seemingly random updates.....Then a couple of months ago they recommended CC4 managers should check a setting in WSUS - and hey presto after changing that - all updates now appear to be going on just fine. And yes there are irritations (=bugs) with the CC4 console ... and resuming a suspended task after it misses its next timeslot doesn't work - for example. But generally its a very "safe" and dependable way to deliver desktops to users albeit that it puts the network manager in a straight jacket requiring things to be done the RM way. So if you have a problem with logon speeds...it might well be RM related - in which case get them to fix it.
  17. Oh...this sounds really good...if I understand it correctly. And does it mean that I no longer need to have a third party service like RM unify to provide SSO? And for apps in RM unify? If so that is a £1000 extra saved per year.
  18. Top of you list should be to meet the "prevent" strategy - because you are required to do that by law (or...at least if not actually a law....you would come in for heavy criticism at least...and at worst inspectors would have a field day...) The prevent strategy does not actually require you to filter...(but you probably would want to filter obviously)...but does require you to monitor usage and identify that usage to individuals according to categories including "self abuse"...."radicilisation" ....etc and you need to be able to report on that. Almost certainly you would need to be able to demonstrate that filtering is "age appropriate"...simply banning loads of categories from everyone is not good enough you need to be show that older students for example - might be allowed access to some material - possibly with a warning page...and that might include unmoderated pages like Pinterest which you would have to block for younger students. Filtering - can be done for free - with stuff pfsense and guardian etc....or may be part of packages like Sophos....but rarely so these meet the prevent strategy without a lot of work on behalf of a network manager.
  19. ...to deliver their service? What service? Are we talking ...something like credit card readers? or identity card/registration stuff? Security cameras? I had to fight...not exactly tooth and nail ...but it wasn't easy...to argue that we didn't need another internet connection when we already had a better one (with backup) for running our security cameras (and later our eco boiler system...which automatically "orders" more fuel....and a credit card system). Suppliers were not particularly happy - because clearly they were going to make a nice packet on the side annually because needless to say the additional internet connections - and routers and management etc all came with an annual charge that made leased lines look cheap. But once they understood they wouldn't get any of the contract without agreeing to use our existing services - they gave in - and it soon become obvious that they worked with other clients in the same way... To be fair - perhaps it is less complex for them to support a solution which is entirely under their control. I'd be less happy - well not happy at all in fact - for suppliers to start installing any wireless kit - not least of all because wireless is at best far from ideal and the last thing you want is other stuff cluttering up your airwaves. BUT....as long as its not something like security cameras - and only a small band width demand it probably won't make much difference. Wireless is designed to coexist with other wireless stuff.... I'd be encouraging them to use existing cabling (and demonstrate saving in cost) and putting their stuff on an isolated VLAN.
  20. The problem is not other APs using a channel not compatible with 1,5,9,13 ....or rather that is a problem too....but thise channels are just to narrow for the othoganal spectrum used when 'n' technology started using it. Worked fine for 'g'. So ...I guess in high density deployments there might be a solution where limiting the ap to g speeds and using 4xap rather than 3 might give more throughput...but thatwas not suggested by the cisco research paper I read...which looked in detail...too much of it mathematical for me to fully understand. But its conclusion was clear...you would always be worse off using 4 channels because the challen separation was not sufficient to avoid interference between neighbours. A common misunderstanding is the graphs which some wireless analysers draw which show amplitude decreasing towards end of channel...which is not the case for orthaganaol tranmissions for n wireless.
  21. SSID Overhead Calculator ? Revolution Wi-Fi Just in case you don't want to take my word for it.....
  22. Oh dear....you do NOT want to be using more than 4 x SSID....and if you can get away with 3 or 2 (or even 1) so much the better. Better to use RADIUS accounting based on user groups to allocate the user /device in the appropriate way. The reason is that SSID broadcasts are always done at the slowest (possibly "b") rates and can take up a significant part of your high speed "ac" bandwidth. I have seen tables and graphs showing how 4 x SSID can consume as much as 20% without sending any data at all! Yes - you can usually configure these beacons to be shorter and less often if you know what you are doing, but often they are left on their default setting even in an "enterprise" setup. So its probably a good thing they limit you to 4 x SSID.
  23. Exactly what is meant by a "proper managed solution"? It's surprisingly feature rich to be honest. Ultimately, and this is always a test worth applying, it works. Lots of schools use ie it successfully and on relatively large scale. It's not really surprising as all access points from every vendor use identical chip sets and ... fir that matter ...the same "micro code" to allow it to meet the 802.11ac spec. Unify' controller is feature rich. I agree power management is not what some other AP s give you, but few clients have power control, and turning down the power on an AP but not on the clients doesn't give you the control over cell size you would really like. 802.11h is rarely implemented on clients anyhow and along with TPC, Ciscos proprietory DTPC has not been shown to be significant in real world implementations. I've known a school advised to rip out ubiquity, because of wifi shortcomings, only for the expensive replacement to have exactly the same sluggish domain laptop logins in the classrooms from access points far to sparsely spaced outside in corridors. My advice always is buy a couple Unifi APs and get meraki, fortinet, or whatever lend you some kit. Test them in a demanding environment. Will you prefer the meraki interface , absolutely. Will Aruba's beamforming give you a better data rate further away? Yes it will, but nothing like the significance their figures suggest. Will fortinet's single channel give you better video streaming in a dense environment? Yes it will. Would I like all of these things? Yes, I would...but you will need a stop watch to measure the differences...but when you look at the price and the fact that you get all the essential features with unify...its difficult to justify the cost of some vendors products ....and even more difficult to justify their annual maintenance charges.
  24. Ubiquiti supports all the standard enterprise features. If you can't do it Ubiquiti...then you can't do it with anything else either. Yes you need your wireless for any BYOD segregated using VLANS. Ubiuity access points wont do that. No access point does that. You will need smart switches to so it - possibly ubiquiti ones, but most vendors have ranges of switches that will do VLANS. Yes - you will probably link it to your active directory using a radius server. Some access points can run as a radius server for other access points...we run radius on smoothwall - there are lots of ways to do radius. SOme access points - including Unfi - I think will authenticate directly with AD. You will need to think carefully about guest access - and how you make it available - because students will use it in preference to AD authentication - especially if its not filtered or monitored. (And you MUST monitor it by username to satisfy the prevent strategy). Again monitoring and filtering is not a feature of access points but is probably something you already have a facility for. Ubiquiti has guest features which allow registration etc....but there would be no way to prevent a student using it. I suspect you would require "guests" to signup or to be given an account from a database of accounts already set up in AD and record their details. You couldn't automate this.
×
×
  • Create New...