-
Posts
3,274 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Ephelyon
-
We're not using a separate VLAN on our setup. Our SmoothWall has both non-transparent and transparent (redirect to SSL login page with session cookie) authentication policies on the main network. Our UniFi wireless network has an open Guest SSID with subnet restrictions so the only device that can be accessed is the SmoothWall box (which also works well for effective client isolation). On their first web request it directs them to log into the filter so we still know who's who and it ticks all the boxes for filtering and logging, just like on the main network.
-
... aaaand just waiting for the mirror image to appear on TES... :P But seriously, I like the idea! =]
-
Myself, I just make sure they're not forgotten. I've always imagined that for a teacher, some of the best work you do will be the little ways that you inspired or cared for people - but that can be very hard to quantify (almost makes you see the NUT's point about how to objectively evaluate a teacher's performance). So, to honour the ones who were good to me, I remember them. Mike Butler, Paul Barnes, Frances Whitehurst, Jan Jennings, Chris Dennel, Chris Jones, Chris Walker, Diane Waters, Dave Poynton, Zeta Emmett, Tim Lutwyche.
-
Sounds about right, unless anyone else knows differently as I've only done this procedure between ESXi hosts before myself.
-
Only if it's going to have the same IP/hostname. If it's going to manage the same servers, open vSphere Client for each server individually and disassociate it from the vCenter, then add them all back to the new one once it's up and running.
-
I agree with @GrumbleDook that a lot of this does sound like a shout-out for senior leaders to take more responsibility, but I do think it's also shot through with the type of libertarian ethos that works well in the right environment, but without those "controlled conditions" as it were, you can still run into problems. The other issue that I take with a lot of publications of this nature is the potential progression from what's written to, in some leaders' minds, the view that when a technologist "blocks" or advises against something, they need to be put in their place as they couldn't possibly have a full picture of the situation. I believe that's just as negative as saying a technologist should have the final say-so on all IT-related matters with no moderation whatsoever. But my responses to each point would be: 1) Absolutely. The Head and the Governors should have oversight of every "domain" of knowledge/activity within the school, and they must always retain the power of veto. Just as long as we're not confusing "oversight" with "taking the credit for other people's work". 2) Sorry, no. This technology always brings with it its own concerns (and laws), which don't outweigh the overall core purpose of the school - to educate children - but they may outweigh individual avenues of pedagogical practice. I also tend to find that the person with the "bigger picture" view of any IT-related issue in a school is more often than not the most senior IT person, rather than the most senior teacher. This would be different if we had leadership teams that didn't consist almost entirely of teachers (unlike in every other sector), but we don't. Balance is necessary in all things - my response to an Answers.com question here explains more of my view on this one. Ultimately, "educational technology" is just that: a fusion of technology and pedagogy. Likewise, the senior technologists and senior educators should ideally make decisions about it in partnership. There's no need to be so divisive; the technologist needs to remember that they're not the overall boss, while the Head needs to remember that they appointed an expert for a reason (right?). 3) Quite right - the issue is always with how the technology could be used. Just be sure you've thought of everything in that regard; oh look, you did actually appoint a technological expert within your ranks, didn't you? (You did, right?) Maybe what you call scare-mongering is the same thing your parents were doing when they advised you not to engage in X illegal/dangerous activity - and they were right, weren't they? (Trying not to stray into the realms of Transactional Analysis here...) 4) I'd have to disagree with this as it's the same kind of attitude that's led to there being no specific guidance available on e.g. how to assess risk arising through the use of technology. Sometimes the gadgets bring with them nothing fundamentally new; sometimes the possibilities are entirely new; or (most of the time) it's just a much faster and more private way of doing the same thing - which DOES warrant a rethink if you ask me. 5) Because of what the 5% might do; quite often this technology can bring with it consequences that are significant, immediate and permanent - to the extent that we really do need to think "safety first" a lot of the time I'm afraid. In fact, various laws will often oblige us to do just that. Also, I agree with @mthomas08 that, statistically speaking, YMMV. Finally, there is a fundamental misunderstanding of ethos here; we are not "penalising" the 95% in respect of the 5%, we are "protecting" the 95% from the 5%. This is based on a core principle that we often see in life: It Only Takes One™. One child, one time. Having actually BEEN that One on occasion in my youth (as quite a lot of younger technologists have), I'm very aware of this fact. Then, once you grow up, your approach to security tends to end up as "not on my watch". Is that evil? 6) In spite of the above, this is a very good point and we must be sure not to get overzealous with our safety - just so long as we don't throw the baby out with the bathwater. My problem with Scott's points is that they seem to be veering dangerously close to advocating precisely that. 7) The key word here is "reported". Also, on the subject of technology, grooming can occur in other ways; myself, I was one of the teenagers who was effectively "groomed" online by older hackers to misuse the school IT facilities, encouraged to find ways around restrictions, imbued with a rather sinister culture of "for the challenge" and "only playing for sport" that stands upon the edge of a knife. It took me a long time to get over that, and I certainly didn't report it. 8) I'm afraid in England we do have plenty of legal principles and precedents that demand the approach of seeking to eliminate the risk first, mitigate second. If you disagree with that ethos, then you need to look at "improving" the legal landscape FIRST, BEFORE you implement a new ideology. Trying to do it the other way around will end in tears (looking at you, Ofsted). 9) That's true, but you'll always get the ones who will do what they want anyway, regardless of what you expect of them. And I'm really not interested in all these arguments suggesting that that's a myth - it's not. Some people - perhaps even most - you can save. Others, you just have to contain. The restrictions we put into place are precisely for this purpose: containing those who will not be guided. Again, having been one of those myself and having seen a fair few others (the 5%), I'm not blind to their existence and I'm sure as heck not letting them compromise the system that provides such a benefit to the remaining 95%. Doesn't sound so silly now, does it? 10) Very often not true - it's just that the problems are hidden. Some Americans tried this approach with the geodesic dome communes decades ago; what they found was that the control element was still going on unseen (because, for the last time, it's human nature), but the damage was far less visible, often because (in the interest of "not expecting people to be bad") no-one was looking for it. 11) Agreed 100%. 12) Agreed again, as long as this term "overzealous" is defined properly. 13) Assuming this is in reference to taking a "whitelist" rather than a "blacklist" approach to the Internet, agreed again. 14) I think the interpretation here is too literal - "friendship" on Facebook is not the same as "friendship" in real life and this should be acknowledged. I don't believe it's appropriate for teachers and pupils to be "friends" while the pupils are still in school, but after that I don't see a problem. 15) Agreed that the first response should be "How can we make this work?", just so long as it's accepted from the outset that there might not be a realistic answer. Scott recognises the potential to be overzealous with the "blocking first" principle; I would ask him to recognise that it's also possible to be overzealous with the "educating first" principle. Again - balance. 16) Absolutely - but do also remember that there ARE other needs in any modern organisation too, and - oh look - you employ people to think about those, don't you? So stop ignoring them every time their answer (based on their measured professional opinion) isn't quite what you wanted for your latest pedagogical idea. They are probably just thinking more broadly than you; one key component of broader thinking in technology management is to put "what you want to achieve" in a box and add it to all the other factors, not place it on some high altar and have all the other factors worshipping it. If your technologist perceives that you're doing the latter, they will probably move to block it (assuming you can't be dissuaded) as they know where this is going. Arrogance? Experience. 17) Agreed in principle, but I'm afraid we do see some instances where staff actually aren't acting responsibly. Some of these were highlighted at an e-safety conference I attended last November. 18) Absolutely true. Ideally procedures should always be simple to navigate. 19) Again, that's a worry and a good point. 20) Agreed again. 21) Absolutely agreed, but then, if you want to use mobile phones in lessons while telling the children they shouldn't cyberbully - doesn't that sound like the kind of policy you can't enforce? Especially when you consider that mitigation after the fact may be less effective here than you think. If you truly believe in this principle, try analysing all your current technological principles and practices to see whether they would fit it. 22) Quite a lot of people actually. School's good too, but please stop seeing yourselves as the "last bastion" in this cause; the rest of us are laughing at you. 23) To be honest, the negative reaction Scott is implying here is the same one I feel when I watch those "hate piracy" adverts in cinemas - but I'd still admit that, were it not for the legal implications, I'd probably download music every now and then from artists who I know (or believe?) get enough sales. "Apprehension of consequences" is not in principle an ugly way of keeping society working - it's just how it gets used in practice that can be a problem (sound familiar?). 24) As long as you do so without ignoring those other arguments/concerns; without disrespecting them and their supporters; without believing your own goal or concern must always be "better"; without the arrogance to believe that there will always be a way to get what you want; and without forgetting that you might just learn something along the way. Just as Scott says it's difficult to understand the positive sides of technology without being familiar with it, it's difficult to understand its negative sides without being familiar with it too. But again, oh look, you did appoint somebody for that, didn't you? 25) Oh, come on - they've plenty of time, you know! There are many, many aspects of adult life that we "block out" for children (including teenagers up to 18) because they're not ready for it yet. Amazing how they don't all flounder the instant they're exposed to it - this is where the practice of introducing little bits of it gradually comes in. 26) No, it's not. It always, always SHOULD be, but that doesn't mean it is. Ultimately you may remove a risk by educating about risks, but what about the trail of devastation you might be leaving behind you - are you even thinking about that? Finally, we've seen throughout history what happens when it's left to one person to make the decision on things like this. A leader must lead, yes, but a leader who leads without proper regard for ALL their stakeholders is called a dictator. And as far as technology leadership is concerned, the only thing worse than a dictator is an uninformed dictator. As for the Bonus Point, my response is: it might look as if it's working for now, but Gorbachev had the same thought back in the 80s.
-
Our cats used to prefer underneath the car. One of ours would sit there quite calmly as a car reversed towards her as she considered it a friend - she slept on top of it in the afternoons so obviously she owned it?!?! Yeah, they know who's boss! xD
-
[ATTACH=CONFIG]16630[/ATTACH] My endearing little furball... =]
-
We use the pre-built one and it seems fine. Asks for quite a lot of memory but I don't know if that's the same on a Windows installation anyway.
-
It's a tricky one as if you were reinstalling ESXi you could use something like this to back up the existing configuration, then restore it again (I've had to do that when completely swapping out the disks in our backup host with larger ones), if you don't want the hassle of setting up vSwitch configs again and etc. But upgrading between versions can cause problems with restoring the backed-up configuration sometimes, and ESX to ESXi is a completely different kettle of fish. I'd just note everything down and recreate the configs from scratch tbh - that's what I ended up doing when we switched over.
-
Strategy groups are good, whoever they comprise, yes - but somebody will have to have it against their name and be ultimately responsible for it, won't they?
-
True, splitting the role in that sense can also work - in fact we do that here. The Head and I collaborate on strategy in the sense of merging "IT strategy" and "use of IT strategy" (which I don't consider to be the same thing), and we've recently set up (at my request) a strategic user group so that some of these issues can be considered more widely by the staff.
-
Could be an issue. For a senior position like that, teacher route or techie route? My personal view is that the techie route is really a must, but only after significant experience of working alongside teachers and a proven track record of actually being useful.
-
Couldn't agree more.
-
I'd ask the STRB. The context was the part of their presentation that considered the trend away from "locked down" to "managed" systems (interesting terminology as I'd personally call them "managed" and "unmanaged" respectively). The speaker referred to why we block things (not just in terms of web filtering but also e.g. blocking EXE files running from CDs / USB sticks, other GPO restrictions etc., not that they put it in those terms of course). The comment was that this was typically associated with the IT Technician who wants an easier life, whereas it would be better to let pupils make the mistakes and then mitigate afterwards through education and sanctions. Presumably this speaker didn't know that running a 0-day exploit payload against a SIMS server you haven't had time to patch yet and then finding out where all the teachers live is unfortunately a very real possibility. Or run a silent keylogger that doesn't require admin rights. Or display a fake logon box that doesn't either. Or that the reason I restrict the ability to e.g. search AD is so that an attacker can't obtain a list of usernames to start guessing passwords from. No, we know the rest of you don't know things like that... that's why we do it. The principle of least privilege has been around for nearly four decades I'm afraid. Comes back to my overall take on IT risk management in education: where the potential consequence arising is significant, immediate and permanent, then we block. Where it is not, then we educate. A questioner then piped up during the following Q&A session wanting to know more (I forget exactly what now)... and the same comment came up again. What annoyed me the most is that I wasn't the only IT Manager present (though there weren't many)... and I got the impression that none of the rest would've said anything if I hadn't. Don't worry, I said that too!
-
Masquerading as a teacher, you say... I might have to try that one sometime! Not the worst thing I've heard at a conference... "IT Technicians just want an easy life" (from NAACE) would have to take first prize in my list I think. They didn't get away with it though, cos I woz dere and woz like all up in dere face (or not)... xD On a side note, and not that you'd expect any different to be fair, I still get that from random other folk when they ask me what I do. I tell them I "work in a school" - "oh - what do you teach?"... Hmmm... we have about 110 staff, about 45 of whom are teachers... but as I say, joking aside, I guess that's not obvious to people outside the education sector and it doesn't bother me really.
-
Synaesthesia, or anyone else who's interested, I've developed a system not using SCCM (but making heavy use of scripting) that fully automates new/old computer naming, encryption (which we do with DiskCryptor, which is FOSS), domain joining and the works. As it's essentially been cobbled together it's a bit involved to explain in a forum post, but if anyone wants to PM me I can arrange for a screen-sharing session to demonstrate it.
-
Hi all, just wondering if anyone else is going to this event on Wednesday?
-
Accreditation for voluntary ICT Technician work at a local school
Ephelyon replied to KJK1LL3R's topic in General Chat
If you're not being paid, ensure that their liability insurance still covers you. -
Starting new job ICT systems Manager & Facilitator November 5th
Ephelyon replied to -sweet-'s topic in General Chat
It'll help that one of these servers is CC4 then. Just SIMS and stuff on the admin server I take it - are the two networks physically/logically separated? -
Starting new job ICT systems Manager & Facilitator November 5th
Ephelyon replied to -sweet-'s topic in General Chat
Much experience with managing servers/switches before your VMware setup? -
Starting new job ICT systems Manager & Facilitator November 5th
Ephelyon replied to -sweet-'s topic in General Chat
That sounds good! What have you been doing previously? -
Starting new job ICT systems Manager & Facilitator November 5th
Ephelyon replied to -sweet-'s topic in General Chat
It does vary on the person and the school; I became an NM at 23, only managing one technician though (who was an apprentice first), though this was more a confluence of circumstances than a position I actively applied for. I expect the school will have been fully aware of -sweet-'s age/experience when they hired him. Managing all of this on your own can be quite daunting (which only becomes apparent when you've done it for a time), but as long as the SMT has a support package on stand-by if there are any issues, and the EduGeek community responds as we've done before, he ought to get through it. I think it's valid devil's advocation, but if -sweet- leaves at e.g. 24 with a CV that speaks of full budgetary control, line management and significant skills in maintaining and developing IT facilities, it could set him up quite well for a job in a larger school or in industry. -
Starting new job ICT systems Manager & Facilitator November 5th
Ephelyon replied to -sweet-'s topic in General Chat
As Steve21 says, if you ask for training immediately it looks as if you don't think you can do the job. I'd leave it till you've had an opportunity to identify your own more specific areas for development, then find a way to link them to the school development plan or a teaching and learning outcome (I really don't think we should have to do the latter, but we often do), then take it to your line manager or senior management (if they're not the same thing). -
Starting new job ICT systems Manager & Facilitator November 5th
Ephelyon replied to -sweet-'s topic in General Chat
I think psydii's points above are very comprehensive, but can I add that in some schools the core administrative processes are completely tied into the IT facilities. If the financial management package is down on the day that the monthly salary claims are due to be processed, whereas elsewhere in the school there is a classroom computer not working and certain lessons can't be delivered... the teacher can wait. I'd imagine scenarios of this nature are less likely to occur in a primary school (I work in a secondary), but it's a possibility.
