AlanD
Members-
Posts
1,102 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by AlanD
-
Schools Broadband - experiences
AlanD replied to 2097's topic in Internet Related/Filtering/Firewall
Keep in mind ...that with all FFTC services everyone is at the mercy of Openreach. Twice we have had things fail and had outages of several days before Openreach could be persuaded to do a "lift and shift" in the cabinet - basically giving you a new connection. Doesn't really matter whether you are with PlusNet, Zen, BT, ...or anyone. Maybe some have better contention ratios. We use PlusNet - can't say we see much evidence of contention - whenever you run a speed test its pretty near the maximum. Still can't understand why some schools are stuck with 10Mb/s leased lines when you can get so much better with a broadband service. -
RM computers (Yes - that much maligned School computer company) do their OneDrive for free with CC4.5...so you do get something for your money! Works in much the same way (seemingly) as IAM - in that all the authentication and cookies are handled invisibly from the user and it uses WebDAV - and so does not try to cache the whole of your online drive with local profile. Just appears as another drive letter on the desktop like magic. So you can have all your student (and staff) files in the cloud instantly accessible anywhere - and useable with Office 365 from anywhere - or on a desktop in school. Not sure I would want everyone using it as an alterative to on premise storage without increasing our external bandwidth - especially for users doing lots of video/sound/graphics stuff. But yes, it would work brilliantly for Office type applications. ...and No I don't work for RM, and only secretly confess to others that I actually use CC4.
-
Meru/Fortinet with HP Chromebooks G3/G4/G5 (connectivity issues)
AlanD replied to Bruce123's topic in Wireless Networks
Just browsing through this stuff....really surprised that MERU/Fortinet are not really keen to get this sorted for you. They charge a fortune in annual charges so they should be all over you to get systems working reliably. I have always quite like the MERU concept of single channel architecture and it does seem effective at delivery to classrooms of devices - but clearly not in your case. They are not going to sell stuff in schools unless they prove themselves capable of sorting this. I understand that using their architecture require the APs work at max power. This means that they see lots of neighbouring APs ... and they work cooperatively to minimize co channel interference by backing off transmit in a co-operative fashion. Nevertheless - I am wondering what you physical arrangement is when they see 50 other APs! I suspect you need to turn off the 2.4 radio on a good number of APs. Only use it in an area where there is no AP in a room to prove 5GHz....but really its for Fortinet to sort this. You can "layer" stuff so use multiple channels to provide greater total bandwidth - if bandwidth is an issue - so that additional APs are on a different channel...no ...definitely a massive black mark for Fortinet here. -
After doing a ridiculous number of webinars and on-site trials we eventually decided on replacing our TMG box with Smoothwall to (help) meet the prevent strategy. It comes ready with categories for bullying, radicalisation, self harm etc - wheras most (all?) of the American/global solutions seemed unaware of exactly what the prevent strategy is asking for - in terms of monitoring but not necessarily blocking sites. And we also wanted visibility of Layer 7 and what apps are being used. To be honest I don't think Smoothwall has this covered - but neither do most other firewalls. Certainly no firewall yet gives anything like the visibility Meraki does with its wireless access points. No - its not cheap. But we wanted a better product for "prevent" - and we required load balancing between multiple ISPs (Virgin and Openreach) we wanted reverse proxy for our internally hosted sites ...and its ability to run DHCP and radius means that BYOD is simply a breeze to deliver without captive portals and other hassles (although smoothwall can cover that too). Whether its good value will now depend on how good their support is.
-
New to Smoothwall & Very Confused
AlanD replied to 45_6d_6d_61's topic in Internet Related/Filtering/Firewall
We have just had smoothwall installed (although not yet setup by their engineers...we have it running)....we bought an S8 UTM. Happy to share what little knowledge I have. When you say you are using SSH login - you have decided to use a captive portal? Including a captive portal for PCs? I'm not sure I would choose to do things that way. I assume (perhaps incorrectly) you have a server and Active Directory. I would set it for proxy authentication for PCs - and either push out a GPO with the proxy settings - or use a proxy.pac file via DNS or DHCP. This avoids computer users logging on to the PC and logging on again via a captive portal. All our tablets are BYOD - so we use enterprise authentication on are access points with smoothwall as the radius server. Smoothwall then knows from the wireless who is at each device without further logons. I guess for school tablets you will need to use a captive portal (do you lock the wireless to allow only these MAC addresses - or do you prevent users looking at the wireless code?) ...which I have not tried - but what you are suggesting sounds sensible. My recen hassles have been with https inspection - because seeminly quite a number of things don't like this - and while they may not be "blocked" by smnoothwall - the apps may not work without adding a shed load of URLs to bypass https inspection.- 6 replies
-
- help me please
- smoothwall
-
(and 1 more)
Tagged with:
-
Fwiw... we have just replaced our tmg box with smooth wall. We spent some time looking at what else was out there, bearing in mind the prevent strategy and the need to monitor not just block and filter traffic....and that traffic might not be web traffic...I don't thing smoothwall is completely there, but it seemed to cover most things as well if not better than anything else. Layer 7 is not nearly as good as meraki's wireless apps..but some filters don't even see non web traffic. Not cheap..well quite expensive, especially as most of the software uses guardian squid and other open source components.....and you will need to add manual exceptions to get social networking, and office 365 to work smoothly.
-
"...though a wall perfectly well...." - to be honest - is not my experience. But it may be due to the fact that most of our buildings are old - and the walls are at least two bricks deep. Yes - you can connect on the other side of the wall - but only at fraction of the speed on the side the AP is positioned. We have some more modern classrooms which have paper thin walls - and we do share the odd access point between these rooms successfully - but we also have some thin walls which have some kind of metal grid in them that won't let through any signal. My advice would be to get an independent expert in to measure the signal levels with proper reports of what speeds to expect on both sides of walls. I have read independent reports about the Ruckus beamflex in real world senarios - and had one on test. They are certainly better than other APs at providing a better signal...but you have to remember that its not just how good the access point is....because the client has to talk back to the access point - and they don't have beamflex to help their transmit side. I couldn't detect any real world increases of bandwidth on the other side a wall of more than 10% - which agreed with the studies. Still - if you are installing premium APs - I'd be happy to choose Ruckus because of that. There have been several reports about whether 1 AP is really required per classroom - and with careful planning I'm guessing most schools will find there are places where the odd access point could be shared. But I also know - without the expense of a proper wireless survey that 1 x AP per classroom ceiling always delivers the goods really well - especially if you want to run domain logon laptops and high bandwidth apps - and you can pay a several extra APs with the saving on a cost of a survey. What's more you needn't then be so fussy about employing expensive APs - because as many school have discovered cheap Ubiquiti APs work really well when deployed this way. Don't take my word for it. Don't take anyone else's word either. Get the free Meraki AP, and the free Aerohive AP (Meru, Ruckus, Aruba and any others you can get) - and buy a Ubiquity AP. Test them with a class of laptops on the right and wrong side a wall. Google and download some speed test software - make them all run YouTube clips in a loop. My guess is that Ruckus will work best on the wrong side of the wall but with a large drop in bandwidth. Meru/Fortinet will give you the highest speeds on the right side of the wall (because its the only one that can use wide channels in dense deployments) The Meraki interface will blow you away make you dribble over how good it is. Ubiquity will give you the poorest speeds - but not significantly so - and will be a tiny fraction of the cost. The others will be much of a muchness. Make sure you understand how they are going to integrate and work with your web filtering/monitoring/|Radius/DHCP/VLANS and DNS. There is a new 802.11ah proposed standard that uses 900MHz - (much bigger waves) than 2.4 or 5GHz. This is likely to drive WiFi through all the walls in a building.
-
...and I wouldn't take too much notice of what a County Council advised....because their experiences can be pretty narrow. Meraki will give a you a FREE access point (with some conditions) for doing trial....and so will Aerohive I think. You are going to need them integrated with your VLAN, RADIUS, DHCP and of course filtering. And yes - I'd definitely buy a ubiquity access point because they would save you SO much both annually and up front capital cost. Sell it off on Ebay later if you decide you don't want it....someone may even give you the close price you paid for it - because they are good value for money! Don't be stingy about how many access points you require. If you are going to use 5GHz (and there would be no point in buying current generation APs otherwise) remember unlike 2.4Ghz, it doesn't go through walls, doors, windows - or even bodies very well. So you will need 1 x AP per classroom - and really it needs to be on the ceiling to avoid bodies. And you will require 2x CAT6 cables to every AP to provide the bandwidth they are capable of using. Remember wireless needs to be done as a complete integration to work well within your school - otherwise you are wasting your money and won't get the results you want regardless of the devices you buy. Just tacking up the odd wireless AP here and there scattered about randomly will not allow you to use class sets of laptops or tablets reliably. Its one thing getting a 2Mb/s into the corner of a remote classroom for a single device - but remember its taking the whole AP the whole of its time to deliver that. If you have 20 or 30 devices requiring 2Mb/s or better you need an AP in the room. And despite a notional 1Gb/s with "ac" access points don't expect to get anywhere near that in reality in a high density environment because of wireless "collisions" (well...unless you have MERU which does its best avoid them....)
-
I guess its difficult for anyone to answer this - other than Fortinet and Ruckus....and I can't understand why you are not tasking them with this. Assuming Ruckus is using VLANs....and are you trying to do this with Radius Accounting? or Captive portal? It should be possible - but if Rukus is new - I would have insisted that they demonstrated that they could get this to work before committing to using their kit.
-
I'm always slightly embarrassed to own up to using RM CC4. I used to run a vanilla network (pre CC3) and was largely against our move to RM (on cost basis) but I think I have at least arrived at being neutral now and possibly even pro RM. The big thing is that RM provides a kind of straight jacket in which you run your school network. I hated that at first. And I found it difficult to justify of the cost was worth it. But that straight jacket provides a kind of insurance for the school. If something happened to me - RM could remotely (or come on site) and take over or fix anything really easily. Yes - I know there are plenty of MCSE qualified network managers that could do a good job taking over a vanilla implementation - but without knowing or understanding the way it was set up can lead to delays or mistakes. I usually do my best to leave RM support deal with problems - which saves me a surprising amount of time - because often they have seen the issues before and I don't have to keep reading and filtering all the latest tech updates from Microsoft. A vanilla system might be the right choice for large school with a team of qualified technicians, but its difficult for a smaller school (we are 800 ish) with a single technician and network manager to be an expert in SANs, servers, desktops, switches, VLANs, wireless and I am quite happy to relinquish some of the core responsibility for this to an external agency. I do like the station BUILD capability of CC4 (yes it CAN be done on a vanilla network too). I like the package deployment capability and monitoring (yes - you CAN do this with a Vanilla network of course...perhaps not as visible as CC4's tick boxes though). I like the printer deployment and print quota system (yes you CAN get great third party tools for vanilla systems). I like their integration with Microsoft's One Drive (yes - there are third party tools for vanilla systems). I love the way all of these things are pulled together in one user interface with computer and user profiles, GPOs, user management, task scheduling etc. I quite like their Single Sign On with RMunify but as we already do O365 and Google with AD connect and GADS/GAPS it doesn't seem worth the extra money. No - its not perfect. There are still maddening bugs in CC4 management - I hate the way right clicking periodically stops working. Scheduled tasks won't resume after they are suspended if they miss a slot. If you move a user they won't subsequently delete without messing about with RM's database. In fact - I reckon at least half the calls I make to RM are because of issues with the RM management software itself. But they do listen - and things do - eventually - (usually anyhow ) get fixed. And no - I'm not sure its good value for money - but it is worth something. We are constantly told by new teachers coming to our school how reliable everything seems and how different it has been from their previous schools where network were often off line - sometimes for days at a time...so perhaps that says something.
-
Well...we have just been through an agonising time to replace our (unsupported) TMG box running websense (now forcepoint). We looked at Forcepoint's offering, Sophos UTM...PFsense (its free)....Fortinet...Bloxx...OPenDNS...Cloud solutions, virtual solutions....we did online webinars...we did on site trials (relatively easy with virtual solutions)...but in the end decided that Smoothwall was the closest to ticking all the boxes when it came to meeting the prevent strategy....providing an on site firewall without a separate box....providing reverse proxy ...acts as a radius server....and a DHCP server...and DNS server.....load balancing...etc Yes - its eyewateringly expensive (to borrow that Robert Peston phrase). Its not brilliant at everything. Its basic web filtering is not great -and probably uses little more than the "free" guardian stuff. I had to add several URLS to get it to handle facebook and instagram correctly (you would have thought they would be all over this kind of stuff)....and I've seen it let through stuff websense blocked. Of course it has no real time web content analysis to speak of. Its user interface is clunky. Its layer 7 visibility really needs a lot more input on their part to get anywhere the visibility you get - say with Meraki's wireless stuff. I quite like its reporting on what was typed into Google searches...Visibility of Instant Messenger....categorisation of "bullying", "Radicalisation", "Adult" etc with Alerts by SMS and emails etc. Whether it turns out to have been a good investment will - I think - depend on how much the product keeps pace with the changing expectations over the next few years. I had some confidence that smoothwall are focussed on addressing the demands of the UK market and the government's prevent strategy which demands monitoring rather than filtering and reporting which some products are limited to. We are still wondering if we need to have something like "Impero" on our desktops and laptops - because if we are to "monitor" we need visibility/triggers when emails are used inappropriately (or any web site which allow chats/comments)...noting that we are being specifically asked not to ban such sites outright but to monitor usage...although when they can do anything they like with 3G/4G enabled mobiles makes me question whether we shouldn't insist parents agree to monitoring on their devices too.
- 33 replies
-
- firewalls
- smoothwall
-
(and 1 more)
Tagged with:
-
Whoops - sorry consfused network addressing .../23 is only 512 addresses....which would seem to be too small for most schools - as I guess students have at least a mobile phone in addition to any BYOD tablet. I think I would want a lease time of at least a working day - 8 hours, because of a change of IP address (if a renew resulted in one) would force a re-authentication.
-
I think ICT suites are always a bad idea. It fuels the perception that ICT is some separate activity from normal school work. ICT should be integrated into normal school work - and not require a class to "move house" to perform an ICT related tasks. There are lots of laptops that have tamper proof keys, SSDs and hardened glass screens- and triple stream networking - which needs to be 5Ghz - although not necessarily "ac". Don't buy laptops that don't meet this requirement - however cheap they seem - because they will turn out to be more expensive in the long run. We still have 8 year our core 2 duo laptops (admittedly originally with non SSDs) which are still working just fine - well better than fine. Ipads are great - and can be used for lots of ICT activities - although chrome books are probably a better buy.
-
I've been thinking about doing more VLANs on our 450 PC network. We already use a VLAN for BYOD (...that seems like a no brainer....would seem pretty irresponsible to allow any potentially infected device onto your domain LAN). The driving force for me - is to be able to isolate networked projectors and printers from both domain and BYOD and selectively allow access by to staff with firewall rules (and to prevent bonjour printing on tablets to the "wrong" printer). The downside - we experienced one morning when domain PCs started picking up DHCP addresses from BYOD VLAN. Took us a while to realise we had an issue, then to figure out what was going on....then how to located the cause of it. All happened after a switch mysteriously rebooted and reset itself...
-
Office 365 - Going full cloud and removing the hybrid environment
AlanD replied to rich_tech's topic in Cloud Services
If you are running your exchange in hybrid mode - then its NOT possible to do away with your on-site Exchange and retain any sensible way of managing your email. Its one of the downsides (possibly the only one) of running exchange in hybrid mode. The normal and supported way is to migrate your users to the cloud - then turn off your local exchange. Once you switch on hybrid mode - there is no way to switch it off and revert. And Microsoft will charge you for what is effectively going to be setting up a new tenancy (yes - with the same name as you have now) to get exchange working with Office 365 in the cloud. Pf course keeping your exchange box on site - even if it holds no users - will solve your problem of providing an on site relay for emails (from devices like printers, etc) -
I think most of the premier tier wireless kit is going to work just fine....Aerohive, Meraki, Aruba, Ruckus, Meru(not Fortinet) etc. I also think the APs are eye-wateringly expensive and all lock you into an annual (often cloud managed) solution which is great for businesses with multiple premises - but seems difficult to justify the cost of for a single site school. Meraki - has a brilliant web interface (but I bet you never look at it from one year to the next once you get over the initial fascination of using it), Ruckus has beamflex - and might tempt into believing that you won't really need 1 AP per classroom using this if you believed all their claims. In practice - it does typically offer faster wireless traffic - but you'd have to be using a traffic monitor to notice the difference. Meru (not Fortinet) offer their single channel architecture. In dense deployment areas like blocks of classrooms this clearly has a USP and works well in practice (so much so that the most of NI schools went for it en-block) - but it has a pretty awful user interface and its layer 7 visibility is nothing like Meraki's. I'm kind of surprised that you haven't looked at Ubiquiti. Its not as good - but seems to satisfy most schools that are using it....and its a hell of a lot cheaper with no annual costs.
-
Did you find an answer to this?
-
...if your BYOD network is /23 .... that would mean 8 million addresses are being used up. I'm thinking something is not correct with your Aerohive units if you keep eating up this number of addresses.
-
How do we use UNIFI for BYOD and our own Assets?
AlanD replied to ccadit's topic in Wireless Networks
I'd certainly add my name to those who think that all these "managed" wireless systems are difficult to justify the cost of. I'm not suggesting that they are not good - indeed the Meraki web interface is fantastic - but once you have finished playing with all the knobs and switches and being nosy into what everyone is doing you soon find that you don't look at it for weeks - months - possibly for whole year - because it just sits there and works. You care still doing to need some kind of web filter/monitor - so there is little point in paying for duplicating those firewall type features in wireless management systems. Yes - some of the cloud managed APs work better with large number of clients - but when you start installing 1 AP per classroom - and you probably can't avoid this with 5GHz as it barely goes through thin walls - its no big ask to support up to 30 devices with Ubiquiti devices. I use Enterprise WPA with a radius server for BYOD- although we do expect users to enter their AD logon details to connect - which are cached in most devices and rarely require re-entering. The radius/DHCP data is used by web filter/firewall to identify the user. Our own devices connect via a different VLAN with a WPA "key" - with a GPO that prevents the key being read. You can limit and/or force DHCP addresses to known MAC addresses regardless of which wireless system is in use. Ubiquiti APs are so cheap - best plan would probably be to get one and try it...although you might need some external support to set up VLANS, DHCP, RADIUS etc, if its not your area of expertise. -
BYOD Filtering - Same filtering on Untrust as Trust
AlanD replied to Arcolite's topic in Internet Related/Filtering/Firewall
Well - we use enterprise WPA with Radius/LDAP for BYOD devices to connect to the wireless, and as the Radius server is our Smoothwall box - which also hands out DCHP addresses to BYOD devices there is no need for further authentication. The problem with captive portals is that devices often need to use wireless traffic for email, and apps (including the google search app) without even starting up a browser or visiting a web page....and that makes it really annoying if your emails and notifications are not even getting to your device. And requiring users to set a proxy (even if its only to tick a box to allow automatic configuration via a proxy pac file) is little better - because - again - there may be no authentication information passed as far as "apps" are concerned - and most apps don't even know how to use a proxy even if they use http With Radius - once a user has entered his details in their device ... it just works...and ...in our case smoothwall logs all their useage against those credentials. Yes - you need users to install a certificate to inspect their https traffic - but that is going to be necessary for whatever method you use. We have an internal portal that everyone uses - with a link to the certificate to make this really easy. Having said that...some android devices seem to install certificates in a very round about way, failing to do it directly through the browser. -
New Smoothwall install - WPAD.DAT
AlanD replied to synaesthesia's topic in Internet Related/Filtering/Firewall
I'm a bit concerned that you are having any issues with a new SMOOTHWALL setup. Not least of all, because its one of the solutions we are looking at. And we have been led to believe that they look at all our requirements and setup it up to work as we require it to work. From what you are telling me - it seems to be you doing some fairly essential configuration. BYOD and proxies are a potential nightmare. Lots of stuff - with mobile devices - either don't work - or don't work well with proxies. So, for example (and I agree - you might decide to block these anyhow) things like instragram and whatsapp may use port 80 - but not for http traffic. Typically - you would block port 80 if redirecting traffic to a proxy....but have no way of knowing if its a web fetch - or some other traffic which you want to allow. Yes - with layer 7 "visibility" - and I get the feeling Smoothwall is only just getting there with Layer 7, it is possible to be more selective. Would be really interested to know how well you get on with Smoothwall....particularly with regards to the requirements of "monitoring". ...does it generate alerts when certain words are typed in google as a search for example? And or - does it pick it up if using wrorrying voculary sent via iMessage on BYOD wireless? -
Note - the other posts here. Filtering is NOT sufficient any more. You MUST monitor. If you just want to filter - using PFsense as a gateway - will do it for free. Use a draytek router and add their filter (used in many German schools) for £50 a year (which is a DNS type of filter). There seems to be the general opinion that those that deliver ICT in schools will get questioned by Ofsted - and will be expected to show monitoring - for example getting warnings of trigger words being used by identifiable individuals in a google search.
-
I think all schools will need to re-evaluate what they are doing about web filtering because of this new guidance/law...because filtering by itself is no longer sufficient. You need to be able to monitor - although its not always clear what is meant by that. And I suspect many of the commercial products used by schools are weak at this - some are barely capable of identifying which user has been filtered from what. (RM safteynet - for example - is almost certainly not sufficient). If you want to - and I think you probably do - identify what has been typed by whom into search engines and get alerts when they use certain words or phrases - regardless of whether the resulting site is blocked - few commercial products are up to scratch...and I know...because I've been looking. But there is an issue which no one seems to want to talk much about - which is that any student can access anything via a 3G/4G connection. What is more that can set up their phone as an access point - even giving it the same SSID as your school wireless - and give any student or group of students using laptops to tablets unrestricted access. And yes, I know some access points are good at detecting and blocking rogue access points. I see little point (yes... I see some point) in blocking and monitoring school wireless when they can effectively access what they like with mobiles devices. I wanted to make form teachers insist on checking every mobile phone that a suitable phone operator filter was in place (no = it would be monitoring - but at least it would be filtered)....but that seemed to make everyone in SLT jumpy about whether we had the right to do that....at best they agreed we could ask/tell parents to check.
-
Unrestricted Internet Access
AlanD replied to e-class's topic in Internet Related/Filtering/Firewall
I see no reason for teacher filtering to be much different - or any different - from student filtering. For one thing, it causes real confusion if a teacher is able to get to a web page only for them to discover later in class the site is blocked for students. What I might be persuaded to do - is to impose a WARN/CONFIRM screen - possibly one which requires them to type in a password to proceed. Our Websense filter allows us to do this - but I don't think I have ever used it. And certainly "NO FILTER" might allow access to compromised websites. I have had teachers complain to me that they can't download this or that because the content or site has been classified as compromised or known to contain malware. I've even known school websites to contain malware and been - wisely - blocked by filters. They seemed rather surprised when I would not create an exception rule(!) - and even had an argument with one teacher because - while the download clearly contained malware (well documented malware when you googled it) the teacher seemed to think it would be must be OK because the web site had a respectable name! No; the more I think about it - apply the same filtering - and possibly add exceptions with WARN/CONFIRM before continuing to odd exception groups. -
Microsoft to move out of the education market?
AlanD replied to Dave_O's topic in Licensing Questions
I don't see a long term future for school ICT technical departments. I think onsite managed servers will disappear. Schools will just buy into a service - albeit one with a 1Gb leased line. MIS systems will be in the cloud only. Office will only be in the cloud. This won't be cheaper for schools - and probably not as flexible or as creative. I think RM can see this coming - and products like Unify are clearly there to give RM a position in that market - but there may be no place for them at all. You can begin to see what its like with apple - so that when you buy an Ipad its instantly registered into your deployment area and you just click boxes on line and apps just appear like magic on your devices. Yes, I hear you asking what will happen with teacher X as a problem with this or that? Switch it off, reboot and it will work is the vision....not sure about the reality though!
