Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. Too late to tell you, but it’s best to reduce the to value before you make a change to mx record.
  2. Hmmm... my guess is that nothing like this happens...even MOD stuff is probably riddled with code that has the potential (and that is where the weakness lies) in compromising the operation of devices. I can't see any firm being too happy about allowing anyone to inspect their source code - as its likely to contain material of a business sensitive nature...and nearly all stuff (including Windows) now includes telemetry which in theory allows them to detect errors but of course could be misused. And while it might seem on the surface safer not to allow a foreign company to supply critical stuff - there is nothing to say that home grown and developed stuff is not equally compromised.
  3. I agree that Mu-MIMO - having played with it - is not what you my might expect from the hype in the advertising. Sending data to 4x clients at once....yes...but getting the spatial separation for error free transfer requires a really good signal to noise ratio. And its one way only - so at the very best you only get x1.8 increase according to the technical docs....and in practice I had difficulty in seeing x1.2 And worse still, if you have some non ac2 clients in the mix on the same access point its actually worse that not having Mu-Mimo. But yes, one day when every client supports in it will give a marginal improvement. And yes - its worth keeping an eye on power requirements. Lots of Access points claim to work with PoE 802.11af but in practice they only manage this by turning off some of their features. To get the full feature set - you need 802.11at which might require new switches. I think this is why the Ubiquity HD-nano is popular - because although it does sacrifice the higher speeds on 2.4GHz band you do get the full hit on 5GHz. I'm not a total fan of expensive surveys - although I agree - you will be more certain of appropriate coverage. And while there are exceptions....one AP per classroom is a pretty good guide line if you want every class to be able to get the highest speeds. Take an access point away - if it allows you to use wider channels without co channel interference.
  4. Stop. New Bands (new brands?...or what bands are you talking about? 5GHz has been around for more than a decade....is that a new band? There are talks about removing some of the licence restrictions currently in place for point to point to allow for more 160MHz wide band bands as in the US, but its not happened as far as I know...and yes there are experiments with higher microwave bands - which are VERY short distance). Perhaps your Aruba kit is 2.4Ghz only. So yes, new kit (or even second hand kit) will therefore have 5GHz bands. BUT...that is a higher frequency, shorter wavelength and that does NOT make coverage better...in fact it makes it a lot worse compared to 2.4GHz. Yes - new kit (if you are comparing it to vintage stuff) has orthogonal support ( or "n" type ) ...and yes "n" and "an" tend to give higher data rates over longer distances when compared to "g"....or heaven forbit..."b" type transmisstions. And yes, newer kit even on 2.4GHz tends to work better at larger distances because of improvements in signal to noise etc. But alone its not a massive improvement. If your access points are out in the corridor and the 5GHz has to go through a wall - even a thin wall.... or if the access point is mounted on a wall so the signal has to passthrough bodies to get to the client you can forget those high data rates because they need a really good signal to noise ration. The latest kit supports "ac" which comes in a number of "flavours" "ac2" supporting MU-MIMO, wide channels, high QAM rates etc...and quoted data rates of 1Gb/s or more. BUT - and I simply can't say that loud enough....that doesn't mean you are going to get gigabit data rates as you would with a wired connection. And you certainly won't get those rates with better coverage....in fact most of those data rates require such fantastical signal to noise ration that you will struggle to get them within 2m of a ceiling mounted access point. So while it might be true that you can get the same coverage with 30 APs as your existing 70APs...that may well be at the same data rates as you get now....and my guess is that you will be wanting better data rates...and your clients will want much better data rates.... I would get a single (or a couple) of Unify HD-nano access points and run the controller on something temporary and check its going to work as you want. They will sell on ebay if you decide Unify is not for you, but a lot of schools use their kit and seem happy with it. I needed a stopwatch and some pretty demanding testing environments to detect any difference between Unify and the premier kit like meraki and aerohive and even then unify sometimes gave slightly better results.
  5. No. No executables...unless they are allowed by gpo or are in the program files folder that they don’t have write access to.
  6. Do you have WDS (Windows Deployment Service) running on this server? And if so - check it does not start automatically. WDS potentially shared the same ports as DHCP and if it grabs them first DHCP will not work. DWS should always be manually started later.
  7. Apples configurator and profile manager are free (...pretty awful actually, but can be made to work)
  8. Apple's profile manager (and/or configurator 2) are both pretty clunky - but can be made to work...and are free.....
  9. Ah ...found it... SSID Overhead - How Many Wi-Fi SSIDs Are Too Many? — Revolution Wi-Fi As you can see, 3 x SSIDs take a significant part of your traffic space. Not much point in in deploying expensive new APs, and then wiping out all the gains...
  10. I repeat....you do NOT want to have large numbers of SSIDs. Simply advertising all these SSIDs can take up a significant part of your bandwidth. Ideally use just one...and use your radius authentication and active directly groups to allocate rules subsequently to control who can do what. You can usually increase the period between broadcasts if you start meddling, but otherwise they advertise at the lowest supported rate - which might be "802.11b" unless you have disabled it...which would also be sensible. Meraki suggest a maximum of 3. I would make it 2...by using one for radius authentication...and the other for devices that connect only with WPA https://documentation.meraki.com/MR/WiFi_Basics_and_Best_Practices/Multi-SSID_Deployment_Considerations There are technical documents floating about on the web (of course I can't find one right now)...but once you have seen the impact of several SSIDs you will decide to do everything possible to reduce them to as low count as possible....certainly no more than 3.
  11. I looked carefully at Meraki - and drooled over its web management interface...but eventually decided that once I had got over the excitement of clicking on this and that I probably needed something that I would set and forget. I certainly question the marketing model of wireless solutions that have annual charges for schools - and while Unify may not have the edge on performance I had real difficulty in a classroom with a stop watch to decide whether it was actually any worse. In the end I bought some second hand Aerohive units (over a hundred of them) and managed them with command line rather than buying into their cloud management system (but it wouldn't be a solution for the feint hearted). If I hadn't done that I would have bought unify. I would recommend you buy a couple of unify HD models (you will be able to sell them easily on ebay - probably for as much as you paid for them!). Most of the annual charge merchants will be happy to loan you some kit - including Meraki, Ruckus, Aerohive and others. Yes - this will involve a bit a of effort....but it will tell you whether the premier (Rolls Royce) solutions offer you anything that is worth money compared to the Unify (= Ford Mondeo) solution. I've always been a great believer in second had ford modeo solutions for schools. And try to manage expectation of SMT. A new wireless solution (despite what those seliing it may try to convince you) may not deliver what they (or you) are expecting. "ac" wireless rarely offers higher bandwidth than "n" technology solutions in dense (= school) environments, especially if the devices you are using are not "ac" capable....or if they are "ac" capable are only single stream.
  12. AlanD

    Hard drive Done

    Well..I definitely wouldn't have opened it first....but I've always had success by putting a drive in the freezer overnight....but I'm guessing that would be a really bad idea with an open drive that already has air with moisture in it.
  13. If you are new to CC4, I would suggest you ask RM about a training/conversion course. Its not rocket science but if you don't understand and do stuff the RM way - then you WILL have problems. I assume the school is paying for RM support. I would check on that.
  14. No; its your gateway that needs to have a route. So when these (wireless?) devices connect - what is their gateway? Is this your internet firewall/UTM - or is it your core switch. Either way you will need to add a route in the gateway (and there needs to be a return path too). This has nothing to do with the APP, or the wireless AP. You need a route between the subnets/VLANs. Presumably if you have VLANs - you already have some routes - you just need to add another (assuming, perhaps incorrectly - that you already have stuff on one VLAN talking to stuff on another).
  15. I'd still want to test the connections individually to satisfy myself it wasn't the UTM....and replaced UTM or not. You should be able to remove one connection at a time from the UTM without stopping internet access for everyone. Yes - it will be a bit slower. Of course, if both FTTC connections go to the same street cabinet there might be contention issues at the cabinet - although I'd be a bit surprised if that was noticeable during the day.
  16. If you use the APP and it doesn't find the printer....then there can't be a route between the device and the printer.
  17. Most printer manufacturers have an APP that you can install - supporting both iOS and Android. You can then print a QR code and stick it on the side of the printer. On the device, start the app and show it the QR code. Then "Send" what you what to print to the APP (..no you don't actually choose print....confusingly). And yes it works across VLANS and Subnets just fine as long as you have rules - either in your core switch - or in our case in smoothwall (which is our default gateway). I quite like having the rules in smoothwall because its AD aware and you can therefore choose which groups are allowed to print to which printers. I don't find Bonjour particularly useful in a school because in our case 40+ printers would show up in a select list - and inevitably, students (and certainly staff) would pick the wrong one.
  18. SO ...what speed results do you get if you connect directly to the router/modem for each FTTC connection. So you see the same variation? (Would be good to take the UTM out of the equation...becuase maybe the loadbalancing isn't working well...or maybe the UTM has issues)
  19. I think you may need to expand your remit from just wireless...to how guest accounts are handled across the network. Its not just that might require access to the internet (in fact they can probably do that with 4G with less hassle) You may require them to have access to ...say ...airserver so that they can show their screen on a projector if they are giving a talk, or being able to print something...and those things might tie into rules to tranverse VLANs. Or there might be data on your network you need to give them (read only) access to. So I would make them use the wireless the same way as students and staff - with AD logins albeit temporary ones, which assign them to suitable (visitor)groups which have appropriate permissions depending on their guest status. Weird and wonderful guest vouchers and login portals are fine if its just internet access you want to give them...but my experience is their reason to connect to your network will be potentially more than that.
  20. Yes, sadly all the evidence points to schools and teachers abusing the controlled coursework element. Perhaps this is hardly surprising. I think extended course work allows a really good range of activities and challenges to be covered - so I think it would be a mistake to do away with it. But I would have thought it was possible to "moderate/scale" marks from such exercises using "exam" set questions. So that algorithmic work in a written paper - such as "produce pseudo code for..." should be used to compare and adjust marks from coursework.
  21. I'd be looking carefully at USB-C. And I would be looking to have on desk adaptors with a charger (for HDMI - or VGA, network and USB to smartboard or what ever, and sound). So the ONLY thing a member of staff has to plug in is one USB-C lead. Make sure the USBC-C connector on the laptop supports video (because not all do this).
  22. You just need to be clear about what additional services your LA might provide - particularly if you are locked into some kind of SIMs deal with a VPN back to the LA. And/or they might be providing safeguarding or other services. We use an Asymmetric (and therefore cheap) 300Mb/s (15MB/s upload) Virgin cable connection (£80 a month) and an FTTC 80Mb/s (20Mb/s upload) £50 a month into a smoothwall which acts a load balancer (as well as doing usual filtering and safeguarding....and firewall...and radius/BYOD). Smoothwall is not without its problems - "reporting" is surprisingly poor despite looking good on the surface. Safeguarding is better...although the whole thing is clunky and not as well integrated as it might be. But for us, is seemed the least worse of the offerings out there. Sophos might have been better - we would have quite liked its SSO capability for reverse proxy, but smoothwall had realtime content analysis which we thought might be good....not sure it has ever been that useful though. Looking at FTTP (330Mb/s) despite its high upfront cost to replace FTTC as it would be cheaper over 5 years and give more bandwidth. For us - our bandwidth pattern doesn't require the symmetric capability of a leased line - despite using Google drive and Office 365.
  23. Given that many of the legal cases that now get taken on go back decades I see no reason to delete or destroy records. Such data might be required to establish work histories, which classes and students that taught etc. Yes, access to such records should be locked down with no possibility of changing or amending them. Staff records don't actually take much space, so I see no reason to delete them as they represent what is believed to be a true record of their time at a school. Yes, I have seen suggestions that student records should be kept until they are 25, but there is no legal reason why this should not be (much) longer or indeed shorter. Historically paper records were kept in school often going back decades, and unlike paper records, computer records can be secured and access to them locked down making computer records rather safer to keep.
  24. Its very easy to knock together something - with wheels, shelves, or what ever you want using something like 25mm Square Tube System: Richardsons Shelving - Racking, Storage, Lockers, Steps and Platforms, Workbenches, Part Bins, Trucks, Trolleys and more. We used to build all our OHP trolleys with this sort of stuff... Probably cheaper than anything you can buy - and you will end up with exactly what you want. Wouldn't take an hour to put the whole thing together - less time than fetching one from a supplier.
×
×
  • Create New...