Jump to content

Bruce123

Members
  • Posts

    432
  • Joined

  • Last visited

Everything posted by Bruce123

  1. Has anyone tried switching from Dalvik to the ART runtime on the Moto G (Android 4.4.4)? Bruce.
  2. Anyone heard any more about this?
  3. Does this basically meaning disabling AP<->Controller tunnelling and allow the APs to perform the tagging? In this scenario, the edge switch, and any intermediary switches, and the layer 3 switch would need to be aware of each VLAN (and the layer 3 switch would obviously need an IP range/IP address for each VLAN). That's not actually a problem as all APs are at the local site. I know what you're saying, 4Gbit sounds like plenty, but this is supposed to be future proof (i.e. last 8 years). Who knows what we may need it for in 2-3 years? Our Internet connection has recently been upgraded to 1Gbit (in 5 years it would probably be 10Gbit). Just on contention ratios: with 4x1Gbit ports available on the Controller we have 4Gbit uplink, which is 5% of the potential throughput from all 80 APs. Compare this to a typical 48-port 100Mbit edge switch with a 1Gbit (or perhaps 2x1Gbit) uplink. This would be 20% (or 40%) of the potential throughput. Thanks, Bruce.
  4. This is basically what I wanted to know (i.e. that not all wireless traffic goes through the Controller). I am however, having trouble understanding how this works. Once the client is authenticated, the only way I can see this working is if AP ends the tunnel and does the frame tagging on the edge (and is connected to a 802.1Q trunk port on the edge switch) E.g. Client A connects to Wireless1, frames get tagged VLAN 10 by the AP Client B connects to Wireless2, frames get tagged VLAN 20 by the AP Client C connects to Wireless3, frames get tagged VLAN 30 by the AP Then your Layer 3 switch does the Inter-VLAN routing in the usual way. Is this how it works? Many Thanks, Bruce.
  5. Ours does too. And I am assuming we can bundle these into an Etherchannel group, but it would still lead to a potential bottleneck (when you have say > 20 ac access points). Ideally, there should be at least one 10Gbit connection (e.g. SFP slot). Thanks, Bruce.
  6. Hi, I have a couple of questions about the Meru wireless that I hope people may be able to help me with. When the AP forms a tunnel to carry the VLANs (one per SSID), where does the tunnel terminate? I assume it terminates in the Controller? Is it possible for AP to form a tunnel with the Controller and once the client is authenticated and associated with the SSID then fall back to tagging on the edge (so traffic doesn't need to go through the Controller)? What I am concerned about is a bottleneck on the cable (1Gbit) from the Controller to the core layer 3 switch. E.g. What if you have 80x AP332i (802.11ac) APs passing all traffic via the Controller? That's potentially up to 80Gbit of traffic (in theory) over a 1Gbit cable. Also, I understand that Meru APs operate on one 'virtual' channel. What does this actually mean? Do the APs and clients literally operate on one channel and one channel alone, or do they connect on one 'virtual' channel and then get shifted to another real channel? Thanks, Bruce.
  7. Thanks for all the advice and information. When you say online Drive functionality works fine, do you mean saving to the 'drive' from within the web browser logged into Google Apps (i.e. no drive letter on the computer)? What I was actually thinking was have the Google drive software installed on the desktop (so users see a drive letter), but with no automatic synchronisation (as you said we don't necessarily want or need all existing files on their on-premise home drive synced). Also, relating to forwarding/relaying emails to on-premise exchange (for staff); does Google perform filtering on these (for spam/virus)? If so, how does it handle the emails that don't pass the filter and therefore aren't relayed? Can we verify what emails were blocked to confirm whether the sender really didn't send an email they claimed to have (or not)? I assume we can create white lists for emails that should be allowed (e.g. from a particular domain)? Thanks, Bruce.
  8. Thanks for answering some of my questions Jonah. One other question I meant to ask (Jonah and everyone) is about Google drive. According to Google documentation (and confirmed in testing) it can be run behind a proxy server (picked up from Chrome) but only if it is non-authenticating. The problem is ours (and I imagine the vast majority of Schools/College's proxy servers) are authenticating-only and don't allow anonymous connections out via the proxy. How have people addressed this issue? A) Not deployed the drive? Which would be a shame as I believe the virtual drive would help smooth the transition to Google docs (e.g. by allowing users to double click on a 'Google docs file' in the drive and have it automatically open in Google Docs, which is a method familiar to most users). B) Deploy it, but bypass this restriction in some way. If so, how? C) Other? It's a real shame Google haven't resolved this glaring issue with running the drive behind an authenticating proxy. I believe it's been on their 'to-do' list for 2 years now. Thanks, Bruce.
  9. After some toing and frowing we have settled on Google Apps (as opposed to Office 365) as our Cloud based productivity suite and I wondered what experiences other educational establishments have had with planning / implementation. The main reason for choosing it is the collaboration features it has over Office 365, perhaps making it more suited to students working together on projects/assignments both in and out of the classroom. We are keeping our on-premise Exchange for staff email, and students will use Google Apps (staff may also have Google Apps email too). Have people created their Google Apps domain within the same email address space as their on-premise email (e.g. [email protected]) or have they created a sub-domain for apps email addresses ([email protected]) or a completely separate domain? If the former, how did you handle discriminate routing of incoming emails (some to internal exchange and some to Google)? How have you sycned the Google domain with the accounts in AD? Have you used GADS or is there another method? If we use GADS how often do you run a re-sync? I am concerned that if it was too infrequent it would make the time to reset a password in AD to reflect Google Apps password unacceptably long. E.g. If it is run once per hour the student may have to wait up to 15 minutes for the password change to replicate to the DC that GADS points to plus 1 hour for GADS to re-sync to the Apps domain, so potentially looking at 1h:15m. When expecting the student to wait more than 15 minutes is too long. Do you sync passwords anyway or just accounts (with App accounts have separate password)? Is Single-sign-on possible? We have up to 30,000 student accounts, so would it even be possible to run it once per hour to resync? A big concern there is is how we can ensure Safeguarding (i.e. protecting young and vulnerable learners)? Obviously, the extra interactivity that comes with Google Apps can enhance collaboration and help students to learn and achieve. But how can we prevent things like Cyber bullying / sexual harassment ? E.g. a student from one class messaging a student from another? The Google Vault would allow us to retrospectively search for any message / email / chat and for us to define retention periods for those. But this is more reactive than proactive. Does it ultimately come down to training and awareness? Have organisations employed Google+ and Hangouts in the classroom? I understand from the Google blurp that this isn't part of Google Apps for Education so does this mean it isn't subject to the same safeguards and assurances (e.g. Google not scanning personal data for advertising)? And I also understand it isn't included in Google Vault data (yet). Then again, it offers great potential for collaboration / working from home. How did the teaching staff take to the "new" Interface and whole cloud based way of working? Did they get training? What about the learners? What level of support do they get and from where? I imagine after 20 years of Office it may have taken some a bit of to wean them off it? Did some staff just persist with using locally install Office and ignore Google Apps? Did you get an external consultant in to assist with planning and deployment? What is valuable in the end? I am really surprised about the lack of information online about these issues, when I do a key-word search on Google surprisingly little that comes up. Many Thanks, Bruce.
  10. The problem before was that it was very intermittent and when I rang them (another telecoms provider using Openreach) the lines happened to be OK (both green steady). But the problem is getting worse and worse, today they were down more than up. So it might be worth giving this a go. Thanks, Bruce.
  11. Bruce123

    CCNA

    This is really irritating, it's almost encouraging people to cheat (CISCO that is). Surely we're at a point in AI that exam questions can be adapted for each candidate, in such a way to not affect the difficulty, but makes trying to memorise the questions and answers pointless (if you will pardon the unintended pun!) Bruce.
  12. Bruce123

    CCNA

    Yes there seems to be quite a few mistakes (in the slides the tutor uses).
  13. Is there a common way to do this? I.e. is it usually box A socket 1 and box B socket 2, or some other combination? We've recently having all sorts of trouble with incoming and outgoing calls at one of our smaller sites. There are 2x ISDN2 boxes and I was slightly surprised to find just one socket on each box connected to the PBX. The green light is flashing on one box (although sometimes it's both) - the telecoms provider says it's a problem syncing which could be a problem our end or their end. If we call out an engineer, there is a "no fault found" charge if it's the former. Just can't work out whether it's our PBX failing or the ISDN at fault. It doesn't help that here appears to be no documentation (online) for this PBX (called iBox). Thanks, Bruce.
  14. Bruce123

    CCNA

    Hi, Is anyone currently studying for their CCNA (like me)? Is it what you expected? What are the most interesting/least interesting parts? I am just getting to close the end of Semester 2/4 (so almost half way through). We studying the "new" Syllabus. Is anyone else feeling like the proverbial Guinea Pigs for the new format/syllabus? Not too impressed with the Site Temporarily Unavailable site to be honest (poor user interface but the material seems OK). Just settled down to complete end-of-chapter exam and to catch up (much needed) and it responded with this rather unhelpful message: Site is Temporarily Unavailable We apologize for any inconvenience. Please check back soon. So I thought I would post this instead Bruce.
  15. Wow. That's some heavy duty/expensive kit. Why do you need layer 3 on the edge? Are you doing your inter-VLAN routing there? If each edge switch is 3750X you have enough capacity to put each client socket on it's own layer 3 routed port (for high security - probably not necessary in a school though). Going back to the original thread, as an aside, I think Cisco may originally have bought it from another vendor or bought the whole company.
  16. Bruce123

    QNAP ideas

    You mean the whole DPM server is no longer needed or just this particular NAS (which is presumaby setup as part of the D2D storage pool)? If you still have the DPM, I was going suggest you could use it as a spare to put in place if a live iSCSI NAS fails (DR for your DPM). Or you could use it to hold archive backups (instead of or in addition to using tapes/USB drives).
  17. It's just a PR stunt... designed to distract the the media / public from the bad PR created by the unedifying sacking (or not renewing the contract) of the Chairwoman of OFSTED, and just prior to that the suggestion by OFSTED that the Eduction Dept. was briefing against them. On Sunday the spin was about bringing back disciplin in the classroom and students doing lines etc. http://m.bbc.co.uk/news/education-26003722 I'm amazed the media get taken in. I guess it's their professional obligation to report and analyse statements from the Government / Ministers no matter what they think is behind them. Bruce.
  18. BUMP! I advised a friend who was on T-mobile PAYG to sign-up to T-mobile's SIM-Only monthly rolling contact for £10/month for 250 minutes. She doesn't make many calls ending up topping up by £10 every 3 weeks, so it won't save her that much but would have allowed her to make longer/more calls without worrying about the cost. Anyway, she went into Phones4U and explained she is already on T-Mobile PAYG and would like to keep the number, the friendly salesman said that once she signed up to the new contract she can simply ring T-mobile customer services and they can transfer the number from PAYG to the contract SIM. Anyway, she signed up there and then, but guess what.... On ringing customer services it was not possible to transfer the number from T-Mobile PAYG to T-Mobile contract. However, had she changed network then it would have been possible using the PAC code mechanism, but PAC codes can only be used between networks and not within the same network. The only option he gave was to go into a T-Mobile shop and get a free Orange SIM and (with or without their assistance) transfer the number to the Orange SIM and then back into the T-Mobile contract using PAC codes. He said that had Phones4U treated this as an "upgrade" then she could have kept the number, but they get less commission than a new line (i.e. new customer). He said it's quite common when purchasing from independent shops acting as agents for T-Mobile. Anyway, she did as they advised but went to Phones4U instead (as it was them who "mis-sold" the contract). They begrudgingly assisted by going down the Orange PAYG SIM solution and was quite rude. Anyway, for some reason the number didn't transfer to the Orange SIM. So now she's thinking of just keeping the T-mobile PAYG SIM and cancelling the new contract with T-Mobile, it will cost her £20 but it all got too complicated and was getting stressful. 1) How counter-intuitive it is that transferring a number from one network to another is easier than within the same network. The customer services guy mentioned it was due to OFCOM regulations but I suspect it's more that T-mobile's systems don't allow them to do it. 2) Unscrupulous sales staff who would happily screw you over for an extra £5 commission. 3) If you plan to do this yourself go to a T-Mobile shop and specify an UPGRADE. Or do it online as I think there is a tick-box to say you are an existing T-Mobile PAYG customer. Anyway, back to my original post, I still haven't decided which contract I am going to choose, but I thought I would let everyone know about this issue. Many Thanks, Bruce.
  19. My 12 month SIM-only deal from T-Mobile has come to an end and I was looking at other options. It's amazing what you can get for £5 or £7 a month. I notice Virgin mobile do a VIP deal £15/month unlimited minutes, unlimited texts, unlimited data. I wanted to see what unlimited data meant and came across this hidden away in their terms and conditions Unlimited mobile internet is subject to a fair use allowance of 1GB per month. If your usage exceeds this amount then we reserve the right to charge you for the excessive element of your usage at the daily rate for your tariff outlined in our Tariff Table. Unlimited use is within the UK and is for your personal, non-commercial use only. It doesn't include making internet phone or video calls, peer to peer file sharing, using your phone as a modem, or while you are abroad and any of these uses will be charged at the daily rate for your tariff outlined in our Tariff Table. Does Unlimited really mean 1GB per month? I hardly call this unlimited when other providers such as T-Mobile have 3GB/month (which they don't claim to be Unlimited). To make matters even worse they have other SIM-only deals with "1GB Data" (not called "Unlimited Data"). So here we have 1GB Data and Unlimited Data, whereas it appears they are both infact the same data plan???? Surely this cannot be legal under Trades Descriptions? Bruce.
  20. In this scenario it wouldn't because a new certificate would need creating on-the-fly for each SSL site visited by the end users....
  21. This has been discussed and the staff/students are informed about it, I appreciate it's not ideal (I had the same thoughts on Internet banking myself) but it does enable us to filter on SSL enabled content. I think as you said for BYOD certificate SSL/TSL decryption/re-encryption doesn't seem practical. That may still leave some College managed Android devices. Thanks, Bruce.
  22. I didn't get any further with this, they are still using paper forms as far as I know. Just going back into the information I recorded in the call on this; I did find a cloud-based roaming ID service: Digital Signatures for Roaming ID, Adobe Reader - Roaming ID Adobe really aren't helping themselves if they want people to use this as they as I couldn't find any information on "Roaming ID" (on Adobe website or elsewhere); how to implement it or how it works... Good luck. Thanks, Bruce.
  23. Hi all, We have a particular problem with certain devices and our wireless BYOD setup. Essentially, users connect to an open network and authenticate via a captive portal (AD integrated) for Internet access. The connection is filtered and goes out via a firewall at layer 3/4. All's OK apart from when the user tries to access an SSL enabled website. The firewall decrypts the SSL session, re-establishes an SSL session replacing the real certificate with a SSL certificate generated on-the-fly by the firewall. The problem is the BYOD devices don't trust the certificate (can't be verified) as they don't have root certificate installed. Is there a simple way to resolve this issue? Is there any easy way to push out the root cert to user's devices? I wondered if we could place a copy of the root certificate on our website, that users could be instructed to download using the URL e.g. go to website.com/root.cert? I know one way is to copy the certificate to the SD card, but our users would find this too complicated. Any advise is much appreciated. Many Thanks, Bruce. PS The connection goes via Bloxx (filtering) and Watchguard (firewall) but I can't quite remember which is performing the SSL decryption/re-encryption.
  24. Thank you John and Chris. I will start looking at SCOM.. Do you (or anyone) know of any other server monitoring software (perhaps third party) that might meet our requirements as well? Maybe not so shouty... I don't like the sound of endless alerts... Bruce.
  25. From memory you have to add a NAT rule explicitly on ASAs. Also, why not disable the 'catch all' deny rule (assuming there is one). Once you get oubound connections working, maybe start locking down outbound connections and setup inbound 'port forwarding' rules. Sent using my Google Nexus S Don't bother with
×
×
  • Create New...