Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. Thanks (I think) for the challenges to my statements, Yes we use HTTPS decrypt....although I seem to have add sites daily to bypass it (or at least by pass the authentication requirement - not sure why you need to add them because the rest of browsing works OK - and its authenticated for that to work) in order to work - especially for mobile devices (its not quite so bad for desktops). All the social media stuff needs to work for staff (or I get lynched) and it needs to work on mobile devices. You might think that ticking to allow social media would do the trick - but you soon discover that you need to do some others like allowing unmoderated sites - or creating your own category - and manually entering sites - because things like Twitter don't work otherwise. I confess I wasn't aware of the dynamic real time filtering - which probably explains why some sites for blocked - then later seem to be allowed. It wasn't something I felt was terribly important when comparing solutions (as there is always going to be some stuff let through). Parent Pay was the last thing that I couldn't get to work - worked all the way until you actually got to the point of making a payment. Nothing appears as "blocked" for the user - it just doesn't work. I still think its probably the best product out there at the moment - despite some criticism of it (and overlooking the price - which is not easy). Believe me - I would be more critical of lots of the other stuff out there - most of which don't seem to even know what the prevent strategy is asking us to do. And yes - I'd like clearer view of Layer 7 traffic (Every web filter can filter http/https - the up and coming problem is to monitor and control what other apps are doing using other ports)
  2. Did you ever solve this?
  3. Does anyone have the CC4 installer for this?
  4. Hmmm...OK as you say, certainly looks like a significant number of false positives. (And sounds as if you are ahead of my thinking on this) I guess a half term or holiday (are you a college/school?) will help identify if the weekdays ones come down....but I'm quite alarmed at even the number during the weekend - which would seem to be either somebody's device (if they are in working at that time..) or (and more likely) the access points themselves. Again I would be nagging the hell out of Meru/Fortinet about it. I have been thinking about the power reduction strategy.....and I'm not sure that is the best option with Meru's single channel - and the reason is that clients always transmit at maximum power and I'm not sure how that affects Meru's strategy. Might be better to set up layers so that one block of rooms (possibly a whole floor) is on one layer (use a 40MHz channel) and next block a different layer, etc - only reusing the first channel when some distance away (of course without DFS you soon run out of layers...and of course you lose the zero hand off - although devices are pretty good at migrating these days)...clearly you can (and have done) waste a lot of time experimenting with this. I am thinking/wondering that maybe Meru's strategy is good with a high number of clients on one or two APs - because it significantly reduces the numbers of collisions) but when you have a very large number of rooms each with an access point that can see many of the others - perhaps it begins to fall apart....but that's no excuse if the APs are creating their own false positive radar detections - they really need to do something to stop that.
  5. Aerohive units are good. We use them. Don't like their subscription costs though - so tend to think Ubiquiti is a more cost effective option. I think I would be using MAC keys for identification for the school's own devices. Yes it will be faff to enter all those mac keys ..actually you can probably just connect all the laptops and then authorise those MAC keys - and then deny everything else. Then use a separate SSID with a key if you want to support other devices. Then students have nothing to steal.
  6. I certainly agree with - "go and see the problem first hand". Sometimes a little more patience and class organisation is helpful. If they dish out laptops and are simultaneously told to open them and logon and wait - then even 3 minutes seems an eternity when no one is doing anything in the classroom - and after two laptops have luckily got to their useable desktop the remainder decide to restart theirs rather than hanging in for another couple of minutes. Better to get the class to collect the laptops and stagger the start up leaving the laptops to the side of their desk while the lesson starts with some other activity. Get the teacher to work with the limitations of wireless technology rather than work against it. I think there is a wide spread misconception that wireless is now so good you can replace fixed ICT suites with cabinets of mobile laptops and its going to work just as well. If you are sharing an AP between two rooms - you might find the second room has next to no 5GHz coverage - or perhaps with band steering - are only getting very low speed connections at 5Ghz. An while a connection to a 2.4Ghz radio next door is OK its limited to a 20MHz channel - and may have co channel interference from other rooms and worse - other laptops in other rooms. A 50Mb/s might seem fine when you test a singe laptop - but remember its not 50Mb/s to every laptop at the same time - and 50 Mb/s to 25 laptops is only 2Mb/s each (and that would be in an ideal world of no packet collisions - so probably more like 1Mb/s in practice) - which is a disaster for anything - except perhaps BYOD. We certainly find 5GHz is pretty poor at getting through our walls and the cost of deploying 1 ubiquity "ac" AP per class room is low enough for it to be a no brainer. And then its just as important to choose laptops with suitable WiFi cards. Ideally I would insist on at least 3 stream cards (often only found in the highest grade laptops) - or change the WiFi cards in the laptops if you buy budget ones. Even with 3 streams and a strong 5GHz signal (which probably means having an AP in every room) you will struggle to get anything like wired performance. Finally take a good look at the power settings. Often a laptop works well when connected to its charger - but disconnected in the classroom the processor works at half speed - and the wireless connections may not even try to connect at 5GHz to save power. Disabling these features brings a helpful relief to logon times - but you will then get complaints the battery charge doesn't last very long in those budget laptops.
  7. No. You definitely don't want to use 1,5,9, and 13. This was often tauted in pre "n" days when spectrum usage at the edge of the channel was low. With "n" data rates - higher QAM etc the use at the edge of the channel is as high as anywhere else. And you WILL get significant cross channel interference using 4 channels. And your total through put WILL be less than using 3 channels with better spacing. There might be an argument for using Channels 1, 7 and 13 because that will give you better separation - but not all clients can connect using channel 13. Remember channels are not completely confined to 20 to 40MHz - there is always overspill - and that overspill will degrade data rates in the neighbouring channel. There was a CISCO paper on this showing all the maths and graphs - and their conclusion was Don't use 4 channels.
  8. I think quite a number of wave 2 access points require POE+ to work at their full capacity. Many are advertised as "will work with 802.11af" - but they don't tell you that it will only be two streams at 40Mhz. In reality of course - in a dense classroom environment - its impossible to deploy access points that are going to use 80 or 160MHz channels - so "ac" and "ac wave 2" are never the magic wand for providing you with gigabit wireless (OK...maybe with the exception of Meru's single channel architecture)
  9. Yes, I often think that those idealists who have a vision of doing away with ICT suites and using cabinets of laptops are misguided by the wireless salesmen. Yes - you can get gigabit speeds - in a large hall away from other APs, but not in neighbouring classrooms. We use 40MHz channels (Aerohove) and let the APs decide - and to be fair Aerohive seems to do it well. I suppose I might be looking to see if the radar detection was limited to certain channels and use a script to avoid the AP using them.
  10. "By splitting across Ch1,6,11 on 2.4ghz, setting to 40Mhz channel spacing​" I don't use Meru, so don't fully understand the implications of the single channel system...but....if you are using a channel width of 40Mhz on Ch1 then surely you can't use Ch6 because it will get trampled over by the wide Ch1 transmissions. So By using a "wide " channel - you only have capability to add one further layer on Ch 13. So either use 3 Layers with narrow 20Mhz channels on Ch 1,6, and 11 or use a single wide channel on Ch1 with a second narrow layer on Ch 11.
  11. ...but if its a leased line - you are guaranteed the bandwidth....I would have thought you just need to make sure your gateway router has QOS - or a dedicated 10Mb/s (or even 5Mb/s) set aside for SIP by setting a limit on your other bandwidth use of 90Mb/s or whatever.
  12. You use a separate line for SIP???!! Clearly money is no object for some schools.
  13. If I am investing in hardware at the same time - new firewall, server, access points etc I have no objection to longer term contracts because I have pretty much committed myself to the hardware. And if the maintenance cost can then be capitalised with the hardware - then its all magic money as far as the accountants are concerned and doesn't eat into revenue costs. Of course - finding that capital cost is another thing....But I'm not so keen once its 3 or 5 years old - because I have no wish to be locked into long maintenance contract when I am looking around for a new deal on upgraded hardware - which might might be with a different supplier. They know this - of course - and so are really keen to lock you into another 3 or more years - and...if they offer me a really good price I might stretch to that....but it has to be a really good price....or else I threaten to move away completely.
  14. I keep coming back to this. Are you really sure you need a leased line? If you can get Virgin - I am guessing their Async service at 200Mb/s (or 300Mb/s) with a 15Mb/s will be just fine....certainly is for us as a (yes smaller) secondary school....Take a look at you bandwidth usage. No - if you have remote Active directory servers or something, or cloud backup it might not be enough but otherwise you'll probably find webrowsing and downloads much faster - we certainly do.
  15. Will be interested to know how well Unifi works out for you. Seems to be a much cost effective solution than many of high annual cost competitors.
  16. Virgin and plus net who we are with both claim not to restrict any traffic during the day time. Typically, ISPs don't need to shape traffic until the evening...when iPlayer, Netflix etc start to soak up capacity. We certainly see very little sign of any impact on the maximum advertised rates.
  17. No - contention does not make the line useless - but I agree it takes a hit (and its pretty rare for us to nocice anything) ....but then so does £6 a year! Our 200Mb/s broadband service has dropped to 100Mb/s at such a time - but its still 100Mb/s despite that contention.
  18. That sounds eminently intelligent. I think RM is proabbly the right choice for us...it may be the right choice for other schools - but it may not be, One technician here - 450 PCs and dozens of laptops and tablets - easily managed. Problems - other than the obvious get fasttracked to RM's support - and usually they connect remotely and fix it. Not sure the annual charge is worth another technician - but its certainly worth something. Yes there is a cost....but some pay over a thousand for cloud managed wireless alone...and then pay for managed print services (we use RM printer credits) ... and often another thousand for web filtering....so you have to look at as one of those costs.
  19. I may have misunderstood - but the guarantee of service level merely means that you get a service call support out to you in 4 hours or less. There is no guarantee of a service - as such. And if the diggers rip up your fibre by mistake it can and will be weeks before you get your service back. So, there is no guarantee of actually getting internet - only a guarantee of getting support for your outage. You can pay for such support for broadband business connections too. I hear everyone talking about how much fast upload speed WILL be with leased lines...and potentially it is. However- I strongly recommend that you look at your bandwidth usage. Even BT fibre broadband (business) offers 20Mb/s upload - and despite hosting webservers - and using cloud service like Google docs and MS 365 - we come no where near to that...and see little evidence of contention duing the daytime...and only a 10% or so hit in evenings. I think many schools bought leased lines wihen broadband was only 2Mb/s, or "up to 8Mb/s". These days FTTC and Virgins DOCIM broadband services offer speeds of yo ti 300Mb/s for download and you would probably save thousands of pounds per year. Don't take my workd for it.....look at at band width usage....and make an informed decision.
  20. Smoothwall can act as both DHCP and Radius server. So its really easy for BYOD - and we use aerohive with smoothwall. Students use their AD details on their device for wireless authentication...and that's it. They don't get challenged again, and webfiltering automatically knows who they are. You can "isolate" wireless users from each other (although there are some apps which make use of peer to peer connections - although you might not want to encourage that). But without vLANs, BYOD devices would able to connect to see your domain servers and PCs with risk of spreading infections. I wouldn't be advising that at all. They could for example - bring down your network with a DDOS attack. My feeling is that its pretty important to keep all your BYOD traffic on a separate VLAN (and IP subnet) and add rules to permit any connection to a particular internal web server /port/printer.
  21. Why use captive portal for BYOD? The trouble with captive portal is that apps and the like don't work until they use the browser and logon. And, assuming you have captive portal for school devices too - you probably only allow the authorisation for an hour (or less before they logon again). For BYOD, I would say it makes more sense to use Enterprise WPA with a Radius authentication, because their devices just work without needing to go through repeated logons. I don't think any WiFi vendor makes any effort to be "compatible" or share data with any other so they are not going to share data, but I don't think that matters especially if you keep the access points in separate blocks of the school. Yes with Captive portal it might need another logon as they move between classes - but if you insist on captive portals then this might happen anyway.
  22. Now that "broadband" asynchronous connections are so much faster - you can get 200Mb/s or even 300Mb/s from virgin for a fraction of the cost of a leased line. Even FTTC with 76MB/s download and 20Mb/s upload would probably be faster - and certainly cheaper than a leased line. Have you actually looked at your traffic graphs? Even though we host several onsite servers, and make use of Office 365 and Googole Docs our school stays well inside what can be delivered by an Async service. And there is almost no evidence of contention that can be noticed during the day time (...yes its 10% or even a bit slower during the evenings). With FTTP on the horizon as well - I think the days for needing leased lines are over.
  23. ...you can't the pick keys off iPads. I think tablets is how many "experience" and use IT in the real world now - as consumers of ICT - not necessarily as producers of it. As such I think they should be encouraged in schools. Work really well with things like Google classroom. Why would you want to use laptops?
  24. By the way, if you think of moving to RM I'd advise you to drive a massive bargain with the cost of CC4 and its licences...because they are going to be very happy with the annual charges (actually.... Possibly there is no capital cost up front any longer...but there was when we adopted it). I guess the real litmus test is to visit (ideally randomly) some schools with RM CC4 and some with Vanilla networks - and talk to a some teachers who use ICT (ideally not those who manage the network). Get a feeling to see if there is pattern. I'm sure there are some badly run RM networks (with clowns in charge who are forever fiddling with stuff) and brilliantly run vanilla networks with an MSCE in charge who lays down the law upsetting lots of users by not giving them permission to install their own software. But I'd be willing to place a bet (well..a small bet anyhow) that in main, the RM stuff just works - albeit with maddening limitations...and vanilla schools will be characterised by random but regular disruption - and employ at least one extra technician. But don't take my word for it...get out there, and take a look.
  25. I keep coming back to ... get some test kit in. Its a no brainer. A free Meraki AP. A free Aerohive AP. I'm sure (...well I know its true because I've done it) Meru will lend you kit .... but do buy an Ubiquiti AP too (sell it again on ebay , you'll the price you paid for it if you don't keep it...). Test them in a classroom with a full class set - with the AP on the ceiling. You won't need a wireless survey if you go for one AP per classroom. My guess is that you will decide Ubiquiti does the job perfectly well for a fraction of the cost....but don't take my word for it, or anyone else's...especially not someone trying to sell you their kit.
×
×
  • Create New...