Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. Aldi and Lidl crept into the UK market with what has proved to be a market disruptive model. At one time they were (probably unfairly) associated with "poor" food sold cheaply. But, come the financial crisis the middle class started looking at what they sold - and were pleasantly surprised. The food was good - really good. Sometimes off the same fields and farms but merely packaged cheaply and and sold not just for less - but for a lot less. At the same time the high end supermarkets either withdrew or raised the prices on the "basic" ranges. The result was the start of a mass movement of customers. Yes, if you want a microwave ready "Meal for One" you will get a nicely packaged product from M&S or Sainsburys. But if you are doing the family shopping for a week no one at the table will care or notice that the rice came from a brown paper bag. And now they have their foot through the door, these bargain basement supermarkets are supplying high range products too - and at half the cost. School don't need Rolls Royce solutions - they need the Ford Mondeo - and probably a low milage second hand mondeo. Are Cisco, Meraki, Aerohive, Meru, Ruckus and Aruba more feature rich than Ubiquiti? Absolutely. And they also cost three times the price (or more) and have on going annual costs. But keep in mind that they have identical chipsets inside. And indeed - the underlying driver/firmware which is produced by the chip manufacturers is also the same. I've said this before - but I'll say it again anyhow. Meraki has a fantastic user interface - I still drool over it - its layer 7 visibility is fantastic. But in a school - you'd probably be better off with this visibility at the firewall/web filter. A Ruckus access point in a corridor outside a classroom will give twice the data rate on 5GHz as its competitors. But twice 2Mb/s is 4Mb/s - and that is pretty much unuseable for a class set of devices. You will need an AP in every classroom, and then you will get speeds of several hundred Mb/s with any of those access points - often more than your leased line or servers can provide. Meru will work better (slightly) with lots of devices, but you will need to contrive some pretty untypical tests to show this. Aerohive has a bespoke PPSK key system....but I for one can't see the point in it if users have AD logons its much easier to use a Radius server. To classify Ubiquity as a "home use" access point would be like those customers who continue to buy their bags of rice in Morrisons. But don't take my word for it. Buy one. Put it in a classroom and see how it performs. Do the same with one of the costly branded devices (they are usually happy to lend you one on trial). I bet users will never be able to tell the difference. (Sorry - just realised - you are not asking about a school deployment....but my advice would still stand. Get one and try it. You are the only one at the end of the day who has to take responsibility.
  2. Our core core switch used to a single switch, but we now have two stacked with 24gb stack cables. The servers have 4x 1gb cables going into the original switch. Would it be better to split these between the two swiches so that each switch has 2x LAG cables? Would that mean that if one switch failed...hopefully not...the other would still serve up what remains connected? In fact should I split the LAG fibre cables that go off to edge switches between the 2 core swiches?
  3. Start by looking at your traffic graphs. When the best you get cheaply was ADSL the only option was a leased line. Now that business FTTC can deliver 80Mb/s and Virgin Cable can deliver 200Mb/s (actually 300Mb/s in some areas) at costs of around £50 per month schools are beginning to realise (some later than others) that they can save thousands of pounds every year. Yes its contended, but day time contention is almost immeasurable. And Yes, you can get static IP addresses. No you don't get q the same SLA (although there is widespread misinformation that you get a guarantee of "service" with leased lines...but in fact all they are guaranteeing is that you will get a engineer response in that time....and you can get that with FTTC to from ISPs like plusnet. I guarantee if a digger rips out your cable - you will be without your connection for weeks). Even with VoIP (works fine on FTTC etc) and cloud services like Office 365/google the lower upload speeds usually between 15 and 20 Mb/s are fine - and rarely will the graphs show 1/10th of that). Yes if you are running a MAT with domain traffic between schools or doing backup to the cloud (good luck if you ever have to recover a SAN!) then maybe a leased line is the right answer. But start with the right information...get some traffic logs/graphs.
  4. RM has always been expensive, but I certainly resent their assumption that if they put up prices we will just pay up. Cc4 costs up 7% this year....can't see any justification for that....and virus protection and mail security increases by several multiples of annual inflation. Now looking to see what we would save moving away.
  5. Can't help but think...I wouldnt be allowing any folder on a school network for user created executables....how would you stop them putting any other executable there? Surely the solution to this is a virtual PC ...and one which does not have any access to the network.
  6. I don't think you can complete the migration once you have elected a hybrid solution. It's not supported by Microsoft and you will have problems with management. Yes you can take away your on site exchange after moving ...not really migrating... users. And yes you can manage users via your AD, but ...as I understand ...you don't get the same control as if you do a migration. Or at least that was what I was told...and had some doubts...but they seemed to know what they were talking about.
  7. +1 ubiquity. Brilliant value for money. Think about what your internet bandwidth is...and if it's the only source of data...and if it's 100mb/s or less you probably have little to gain by using "ac" access points...may as well use "n" type of access points.
  8. It may be late to tell you the...but hybrid might be a mistake. Once you go down this route you are practically committing yourself to keeping your on site exchange. If you had migrated you would be able to fully manage exchange in cloud. By going hybrid first you will need to retain onsite exchange...which may be ok because you would need an smtp relay otherwise. If you have a hybrid, and move all accounts to cloud then turn off your exchange you don't get full management in the cloud.
  9. I assume both networks have a default gateway which I am guessing might not be same as the gateway you are creating. Once you create a route from one network to the second, you must also add a route back from the server on the second network to the first. So on the server in a cmd window type route add network1 mask gateway. Where network1 is something like 192.168.0.0 and mask is 255.255.0.0 and gateway is the network2 gateway address if it's not the default gateway.
  10. My advice to everyone - including myself - is to set up a trial and test. You want to use a class set in a room - you need an AP in that room (because 5Ghz is useless through walls ...not even good through bodies....so the AP needs to be on the ceiling). Don't use wide channels where there are several neighbouring classrooms - you probably can't use wider than 40Mhz channels successfully. I'd be trying to turn off 2.4GHz channels on every other (or more) access points as that signal does go through walls - and set that to 20MHz channel (unless you only have 2 access points within ear shot of each other in which case one of them could be a 40MHz channel). Most APs will adjust their own power level = but if not it needs to be down low for areas with lots of classrooms. It doesn't matter how good your wireless APs are - if your client devices don't support "ac" an "ac" access point is not going to help! And if your devices don't support 3 or 4 streams even if they are wave 1 "ac" you are just as well off using an "n" AP. Only the very latest APs support wave 2 "ac" - and with that you get MU-MIMO - which if your devices support it is worth having. All too often - teachers have 2 (or 1) seam radios in "cheap" laptops or tablets having invested tens of thousands in wireless AP kit..and then complain students can't login in under 10 minutes. If you don't have decent client kit wireless does not work that well. And even with the best at both ends don't expect it to work like wired kit....because it won't.
  11. My bad experience was paying over £200 each to begin with for genuine ones, then they failed....and only later did I discover that cheap ones not only worked as well - but they didn't break down.
  12. I wouldn't have a concern using them internally on the network in a school. From what I have seen - it appears you can run all your ZyXel switches as a single "virtual" switch through a single web interface. Makes visibility and configuration a breeze. If we weren't already a "netgear" site I would be using ZyXel switches - and spending the thousands (and more) on other stuff. Not sure I would use a ZyXEL firewall/router - there are lots of options for that role - again without spending a fortune. Perhaps for a university or something - then I would be looking for something more robust.
  13. Any ddos attack is likely to come from a single weakness ... so you would expect if one of the traced back attacks was from a zyxel device...you could bet the others are. In this case, it's a switch in a school behind a firewall or gateway...and is not going to be greatly at risk. If it was a bank ...ok...I'd spend a lot more. Schools shouldn't buy a new BMW for teachers ..they need a ford mondeo. Value for money is everything.
  14. Anyone using Google or Office 365 to relay mail through to an on site Exchange server? (Set up a connector between Exchange and Cloud and point MX record at the cloud - seems to be on-line instructions detailing how to do this) Does it filter spam when its operating like that? (I'm told it does...but don't always believe what I am told) And is the spam filtering any good? Can you write rules to - say stop emails with attachments with executables? Or selectively not stop emails with specific attachments types from specified senders? Or can you divert emails to a quarantine area? Just in case you are wondering - we are thing about not paying for an antispam product on our exchange box - but not yet ready to migrate emails to the cloud completely (partly because we would still have to run some kind of on-site relay - which may as well be the exchange box...and we can do proper backups with our on-site exchange...)
  15. What web filter are you using? Not smoothwall is it by any chance? Far from smooth when using apps on mobile devices....
  16. I feel that we filter and the prevent strategy are used as another way to raid the funds of schools. To filter the internet...you can do it for £40 a year with a dns filter on a draytek router, or for free with pfsense. It comes included with sophos protection...without buying their UTM. But when you start to want reporting and filtering...and you need it to work withmobile devices...and few products are actaully customised in any useful way to meet the prevent strategy - smoothwall is to some extent. You'd expect whe delivered to a school you tick a school configuration...and you go to an exam board ..and will it download an exam paper. No ..not without creating a rule of it. You tick a box to allow social media for staff..and on the desktop it works..but it doesn't work on any mobile device..unlesss you write more rules...usually ones to bypass inspection..so you can no longer monitor them. Up and down the similar rules are being written every day in every school. You might imagine that filter suppliers to schools would be harvesting these changes and using them to build a better more customised product for schools...but it's seems to me they are just taking the money and running.
  17. I don't use it - but Google for Education has an inclusive "free" MDM - and I think there are others - including Apple's own "profile Manager" - which again is free (but no, I don't use it). There are lots of benefits of using an MDM - to start with you can just deliver apps and updates over the air without having to plug them back into configurator. You can allow use of a single app only (on the fly). So you definitely need to get an MDM sorted. Browsing history...doesn't give you much of a picture....do you stop them putting it into "private" browsing mode? You get no idea of what they typed into any search engine - or into any website.... and increasingly some web pages won't work with man in the middle monitoring. Difficult to see how you could say you were meeting the prevent strategy.
  18. "Don't really want to be tied MDM side of things.." Are you saying you don't use an MDM? How do you deliver APPs to these? Why wouldn't you use a MDM? I don't see why Light speed could not filter/monitor - but you might need to enforce a proxy setting or something which would be difficult without an MDM. I don't see why it would have to be LightSpeed's MDM.... a free one would probably be fine. I would be surprised if Lightspeed could not deliver a captive portal page to identify the user....or perhaps if you are primary...can't be with 100Mb leased line....that would be silly. The current problem with iPads is that it is increasingly difficult to monitor anything on them. You can no longer monitor what is typed (into search, or email, or even pages)....so meeting the prevent strategy - which requires us to monitor (rather than filter/block) is almost impossible. And increasingly iPad apps prevent any kind of inspection with certificate pinning and the like which makes man in the middle observations difficult if not impossible even for sophisticated filters with enforced certificate use. This is probably why Link2ICT has its own browser I suspect.
  19. This Sophos price seems to cover Antivirus AND (Exchange) Spam AND a webfilter! Have put RM on notice that I will not be renewing at the current prices. And if other RM schools have any sense they won't be renewing at those prices either....and I can't imagine customers returning once they have left.
  20. Are these both V1 or v2 hardware? Or a mix? I don't think you can upgrade V1 to version 10.X firmware ...or at least I don't think its supported.
  21. Are these both V1 or v2 hardware? Or a mix? I don't think you can upgrade V1 to version 10.X firmware ...or at least I don't think its supported.
  22. Yes. Noticed this a while ago, and had a very unhelpful reply from lego when I complained about it...and I was trying to be helpful by pointing out that this was a poor design for multiple user PCs.
  23. In a few places, we use extended desktop, two monitors and a projector in several locations - using either a splitter - or using the "out" signal from the projector back to the second monitor. Occasionally there is a problem when calibrating the whiteboard - because it thinks its on the "other" output....and yes when playing movies we have had to change it back from extended to duplicate mode - as not all packages seem aware of extended mode. I'm always surprised how much students "learn" about staff and school from emails being opened by a teacher on the desktop PC when its connected directly to a projector. Teachers seem to thing that students won't notice when the class is supposed to be engaged in some other activity....and of course - email alerts sometimes pop up with messages that students are not supposed to see.
  24. Get a complete backup (in fact get two backups) - possibly just using windows backup onto USB/SATA drives. Get someone to verify you doing this. Then if something "goes missing" you can show that it wasn't there at the start of your tenure ship. You may need to shut down services to do this backup - because if there are running databases - your backup for them will be un-useable. (Of course if you have virtualised servers you might take and keep complete snapshots instead) Change Passwords for any "administrator" - local or domain.....especially if there are local administrator accounts on workstations. (But doing this can cause problems for tasks and operations that required administrator privileges to work - so be prepared for backups to stop - for example - until you change their credentials). Try to manage expectations....and start by putting those expectations really low. You might want to start with supporting "administration" computers only for a week - or two. Be prepared to find that every Tom, Dick and Harry (not to mention Jane) may have been given complete autonomy over several workstations - if not the whole network. Licencing won't be in place - and there will be no budget for it. Web Filtering might be so open that any attempts to close the doors on it will be met by a torrent of derision. Take some time to survey everything (even if you are getting shouted at for not getting this or that running). Once you have sketched out what you have identify weaknesses. Send an email to all staff (you might need to get permission for this) Ask them to list what doesn't work, what doesn't work well, or indeed what does work and they would be unhappy if you took it away. Insist on "detail". Its not much help having a response that says "IT stuff is rubbish" - when in fact their problem is the monitor has a cracked screen or the CPU fan is noisy). You might like to offer some external companies a chance to look the network over and help you with these. Most are usually willing to give you a day or half a day when there is a prospect of business. Get them to document their responses, and use them to put together a report. Do this earlier rather than later - because SLT will be thinking that hiring you has solved all their ills and the network (which will still have 100Mb unmanaged switches, no space disk capacity, slow internet, no anti virus, and a load of other shortcomings) is now going to fine. You need to show SLT Windows 7 support will be coming to an end, and that their workstations will not run Windows 10 or whatever. There will need to be a clear spending plan. You are used to RM. Get RM in. They will certainly come up with a spending plan that will give SLT something to think about!! Whatever they have offered to pay you - you will soon discover that it is not enough to compensate for the time and stress this is going to give you.
  25. We use RM CC4. I have often defended RM, but that is not to say their solution is panacea for everyone. I think its a "SAFE" solution for schools. It works. It still has some annoying faults/bugs and short comings. But that is not to say a Vanilla solution would be equally safe if well set up and managed - or indeed not without some problems. We often have teaching staff who come to us from other schools comment on how reliable the network is compared to the school they came from. (Sometimes - when I get in touch with their previous school the network manager tells me they have a brilliant network ...but it clearly wasn't the experience of their users....and there is a lesson there for all of us network managers). However, I have now asked for quotes from suppliers to move away from RM. The massive, eye watering increases in support costs have tipped us over the edge. Support costs have gone from £3500 to £5,500 pa ; RM's antivirus and mail security has gone from £1200 pa to £3800 (!!). So I've started to plan not be an RM school by next year and first quotes rolling in look very tempting. And these price rises are over a period with practically no inflation, no wage increases (and I bet RM aren't paying their staff the extra money). It seems to me they are plugging a hole by asking their loyal customers to pay more. I required 4 replacement disk drives for server. RM wanted £400 each for the drives - which I can get from any other supplier for £200 - and they will be glad of the profit they make on them - and another £1000 for an engineer to fit them. And they won't fit the drives if I buy them independently. Frankly - all that is just taking the mickey. Does their greed know no bounds?
×
×
  • Create New...