Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. ...its not just lightening...neighbouring houses in a street at fed by alternative phases....and usually different buildings within a site are on different electrical phases. Sometimes, the stage in a hall might have its stage lights fed by all three phases. This can produce a potential of 300V or so between buildings ...and while switches can normally tolerate this there is a risk of electrical shock...and while the path through ground is normally highly resistive I wouldn't like to put it to the test. So, copper between buildings is an absolute No No for safetly.
  2. ...and while I'm on my bandbox.. 30 laptop clients connecting to a single AP is not going to be a great experience. 30 clients in a single collision domain has a considerably detrimental effect on throughput. 30 tablets ...or even 60 ...is not too bad. Gigabit wireless is only possibly when using wide channels...and typically you can't use wide channels in schools - because you would want more than 4 access points and co-channel interference. And multiple streams.....are often not supported by clients unless you buy high end devices....and only offer improvement when you have really good signal to noise (access point in that room). And speeds quoted are UDP...not TCP rates.. So generally you end up with somewhere between 100 and 200Mb/s shared between your connecting devices. With a 1Gb/s switch, wired connections gives you 1Gb/s shared between the devices....a much better experience. The point I'm making is that wireless is a not a good replacement for fixed ICT suites....or at least not for laptops running windows off a domain server.
  3. The 2600 access points only support 25 clients or less. So no surprise if clients fall off those. The 8610 will support a lot more clients...If clients fall off...its more likely to be something like because you have turned on band steering...and as useful as it might be on paper....as load increases on the 2.4GHz radio ...which clients often connect to if the access point is through wall or some distance away...or whatever, the access points drop the connection to encourage the access point to connect to 5GHz radio...which some don't like to do because the client then uses more battery power...and the 5GHz signal is weak....and so attempt another connection at 2.4GHz...only to be unceremoniously dropped.
  4. ...you are upgrading after only 2 years! I try to keep my phones for 5 years....
  5. Yep, smoothwall running radius...and also running dhcp for the BYOD vlan from smooth wall. We include some rules in firewall to allow ..for example staff logon to print via qr code and printer app to printer vlan.
  6. OK...point taken..and I don't disagree...I'd like to have DHCP in one place...but decided it was sacrifice I'd make to keep smoothwall happy. I used to use NPS (pre-smoothwall) and decided it was an extra thing I could live without.
  7. What do you base this on? Where does such a mindset begin? Have you actually got one out - and put it next to ...aerohive...or meraki...or whatever ...in a classroom of 30 laptops doing a domain logon and running HD youtube clips? No; its not a rolls royce solution...and no; it doesn't come with the rolls royce price tag. But they are certainly not domestic wireless access points - and support roaming, airtime fairness, radius logons linked to Active directory, a nice dashboard to show you whats going on etc, etc. Where there is a difference...is that becuase there are no on going charges (either on going, nor upfront), no supplier is going to come on site for free to either install - or sort a problem out - or at least not without charging for it. Some charge even when their getting an annual matintenance fee. So if you don't know anything about wireless...and are thinking that ubiquiti is the at least the right cost solution for you - you might usefully decide to factor in some support cost. That - or know a colleague not too far away that might have the answers for you. There is nothing "wrong" with cheap solutions. There is something wrong with "expensive" solutions that don't deliver anything extra. You rarely get what you pay for. Doing so is no guarantee of getting anything better....but I agree - you sometimes do have to pay more for something which is better. Just make sure you are getting something better before you hand over the money.
  8. So, I would be using your smoothwall as the radius server...actually I'd be using it for DHCP on the wireless network too (I assume you have a the BYOD on a separate VLAN). Smoothwall then knows who is logged on at that IP address. (In turn Smoothwall of course - is linked to your Active Directory). In my experience - this works really well....just like magic, If you use a separate radius server (...and I can't see any advantage of doing this) you would need to forward accounting information to smoothwall. I believe this can be done - but I've not done it. Note: you will need to have a shared key between smoothwall and your access points.
  9. Don't see why those two issues are unique to boarding schools.... We do "letters" to parents - with recommendations about home internet and how to get suppliers to ensure its filtered....and for mobile phone filtering...and social media warnings....etc. And we do evening and twilight meetings - to cover much the same ground but with opportunities for them to ask questions - and for us to give examples of material we have seen around the school etc. regarding bullying, sexting (without example of course). Sometimes these are hosted by ourselves - sometimes we have had external speakers(which often carry more weight - and often have a very up to date take on such matter as radicalisation etc ...I thought all schools did this kind of thing....
  10. ...Can't understand why you are using a third party room booking system. Surely (...but perhaps not) your MIS can do this....and because that "knows" about the time table - when you book a room for a group - it appears in the timetable for that group on their web portal.
  11. AlanD

    Suppliers

    It never ceases to surprise me how much money can be saved by walking away from a deal. Admittedly - "middle men" often have little leeway - but if you can get further back the chain...which you often can when buying quantity - there are often serious saving to be had. And even small percentages add up to large sums when buying quantity. So saving an extra couple of percent when not buying from your usual supplier is worth a lot. The best deals are often when it involves whole projects - because while they might not be able to offer savings in equipment - any labour often has significant savings. So buying a projector AND getting it put up (...we usually put our own up....but its not for everyone) might mean that it looks like they put up a wall mount and calibrated it all for £100 and whole morning's work. If you quote separately - it looks more like £250 for the labour. Your account managers and suppliers are not your mates - despite their smooth talking - they are out to make money from schools....and I don't blame them...its their jobs to make as much as possible without losing the contract....giving you a good deal now and then keeps you on the hook - and likely to place a big contract with them - even when the price is not so good...
  12. ...as long as the 40m copper run is not between buildings which might be on a different "phase" of electric....I'd be wanting 2x copper....In fact...EI think I'd be wanting that even if it was 10G...because its really difficult to fill a 1Gb line of data - unless you have some serious kit...like a server loaded with SSDs. And filling 2x1Gb/s lines would be harder... But if its between buildings..or external and unshielded..then you are at risk of the switches at either or both ends failing....and probably breaking electrical regs too.
  13. Why use Win 7...its completely out of support by the end of next near....which probably means you will have changed over by the summer at the latest. Is this not the time to bite the bullet and start the move to Win10? Shove it on "Intune for Education"....in preparation for doing the same for all your computers and doing away with most of your servers (probably still need something on site to do DHCP - unless your core switches do it...and DNS...unless they do that too...)
  14. Did you open ports 139 and 445? ..if you whitelisted "all" the addresses listed by google (which seems to be a complete list of everything they possibly do)...I assume you no longer get any reports of what is being searched for in google....for example.... But, its encouraging to know that it can be made to work... So if you include your smoothwall certificate in the package...you no longer need to include "do not inspect" in the rules....only "do not authenticate"....but perhaps you have not tried to tighten it up further....
  15. No; not having any luck with this. Put the above URLs in authentication exceptions...and in inspection whitelist/don't inspect....and it won't connect. BUT it will connect...if I connect the PC directly to the router.......so it has to be smoothwall getting in the way. Added the certificates from smoothwall into the Filestream package following google's help...which makes it accept certificate for inspection...and NO doesn't work. Added the registry entries suggested by google so that it accepts any certificate...and no; it doesn't work. Did a support call with smoothwall....who added a load more of Google's URLs...practically anything and everything with google in its name...and opened two firewall ports not even mentioned by google,,,,,and no; it still won't connect. Can get a web based connection to work of course....but that's not much use if you want to use google's drive space directly..... Can't help thinking this should be standard stuff that fschool firewalls should be capable of supporting....without 7000 network managers each trying to fix it individually....
  16. ...so if your switches are at near capacity - even more a reason to invest to improve the single network....with LAGs, faster links, whatever.... BUT...I hear what you say.....Anyhow...I'd be choosing an address scheme that was "compatible" with the existing network - so that if you ever did decide to join them together - because you wanted to put an extra camera - where there happens to be an existing curriculum network access point - you can just plug it in. ....and I'd be VLAN'ing the new network from the outset in preparation.
  17. ...what?.... So you are going to have two physically separate networks in the school...and you are going to maintain both? ...I could understand you wanting to segregate the camera system onto its own vlan….and yes...I'd probably be wanting some LAGs (or possibly 10Mb/s links) between switches.... Why pay for two systems?
  18. OK, for just performance....you are not going to see much improvement....the same traffic goes through the switches and devices...its just segregated. Now...if you were to ask me...that you wanted BYOD/Guest wireless traffic isolated from your domain/server network...then VLANs would deliver that. If you were to want ipads used by students...not to be able to connect to printers....vlans might be the way to go... If you wanted to keep financial and/or management team traffic separate form students ...vlans might be the way to go.... Or if you told me that telephone calls were crackly/intermittent...it might be because their data would be better on a separate vlan which is given priority. Yes, its true that bonjour printer traffic and ...well printer traffic in general...can be surprisingly noisy....with lots of packets constantly being sent racing around your network...buty modern switches, servers, and PCs...are pretty good at handling such clutter. Personnally, yes - I'd want vlans...for security/privacy/guarantee of service for VoIP etc...but if you are thinking of doing it just for speeed reasons....my guess is that you won't notice any difference.
  19. I don’t use Ubiquiti...but would do it the same way... 1. Filtering done by existing...smoothwall filter...by connecting BYOD traffic to an isolated vlan port. 2. Users have to authenticate...we use smoothwall as radius...which connects to our active directory. I wouldn’t have more than one SSID. Mulitiple SSIDs can use a surprisingly large part of wireless bandwidth just advertising themselves. Smoothwall rules AD group rules determine if access is possible...and what that access allows. 3. Rule in smooth wall for that radius group...although....I think I would be allowing access to internal portal servers for everyone...for homework, timetables,etc. Yes, you will need users to install a certificate...and I’d include guests in that...and if that is inconvenient for them...tough...they can always use 4G.
  20. Coming to this rather late in the day...partly because RM have just released a client package for this....I thought I'd give filestream a go. We already have a tenancy, sync, etc, eetc.. So installed the client...and of course - it wouldn't connect. ...I'm guessing this is because google does not (unless you change the registry/GPO for Filestream) support MITM certificates for inspection Tried a wild card URL in the "Do not Inspect" policy list....for all google like domains...and that didn't work...perhaps it doesn't like authentication either (nothing appearing in "real time report" of course to help... What does filestream like/not like with smoothwall? Somebody must of have done this?
  21. ...eget some blank BIOS chips of ebay and a USB programmer?
  22. Many wireless systems now have "cloud" controllers.....considering they have access to logon names...and sites visited...does this represent a potential question mark. Should we be checking that controllers are hosted in the UK - or at least in the EU?
  23. Well ...it does 300Mb/s routing just for our internet data....which doesn't max out the CPU.... Internal vlan > Vlan traffic isn't that high for us...BYOD to internal servers certainly counts for some...but mainly BYOD traffic from internet has to come through smoothwall anyhow ...as does our internet to internal traffic. Yes there is a small amount of data to vlans for projectors...and yes some for printers.... It was a suggestion...I wasn't saying it would be the right choice for everyone...As I said, I particularly like it because smoothwall (like TMG which preceeded it for us) is "AD aware" and so rules can include AD groups for permissions....such as allowing staff logons from PCs (or BYOD) to get to projectors...airserver connections...etc - while students logons can't. Maybe some switches are AD aware too....but certainly not our negear ones. If I wanted to pass gigabits of data continuously between Vlans..well...I might have to sacrifice the AD permissions and use core switch routing...
  24. Just to muddy the waters a little...I’d be tempted to reconfigure so that smoothwall acts as the core router and gateways..so that it sees all traffic and can apply AD groups to rules for traffic between vlans.... ...or ...for devices which are not proxy aware can you assign them smoothwall as the default gateway via static entries in dhcp?
  25. ...I’d definitely be looking for a short throw projector...even if it cost me more. You get far les shadow...doesn’t shine in the eyes of user when they face the class.... Not keen on prometheans’s own UST projectors which are pretty feature less. I like stuff which has a network interface that can be used to provide a connection ...from laptop...wirelessly....and with web interface for a “remote control” because the physical one gets lost. We used to like epson440W until they all started to fail with the ballast unit needing replacing... We then started putting in hitach 251w models... ...and I wouldn’t put in less than 3000lumens today as everyone likes bright images...without having to close the blinds on a nice day... Quite like the specification for hitachi ax3005 Usually these short throw projectors come with their own wall mounts...
×
×
  • Create New...