Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

StephenPink

Members
  • Posts

    338
  • Joined

  • Last visited

Everything posted by StephenPink

  1. I wasn't aware Grandstream made networking equipment - have only come across them from the telephone side. Have always favoured Yealink over Grandstream due to quality/warranty so not sure how I'd feel about Grandstream switches/wifi... If you're keen for the single manufacturer, I've heard of a few places using Unifi Talk and enjoying it. I'm not sure there's much else out there better value than Unifi on the networking front - and don't forget, the lack of any ongoing costs/subscriptions is a huge factor to consider. Cheers
  2. Moving to Unifi - the ONLY NVR I found that was capable of being backwards compatible with the eclectic collection of cameras we had (Merit-Lilin, Samsung/whatever they were branded before and after Samsung). And exceptional value for money - both NVR and Camera wise.
  3. That's what I was about to say - keeping a close eye on these, as the 2U Pro seems VERY good value for money. I'm hoping the range will be expanded soon; both to a slim 1U model for network cabs, and a larger capacity/full length model for server cabs. They support clean server shutdown via NUT apparently *but haven't got one yet to test as too small for my use cases currently
  4. StephenPink

    26H2

    Yeah but it's only might so should be fine right?
  5. PM me and can chat pricing/supplier if it helps... I'm not sure I'd want to try and use CloudPath with another vendors APs. I've also been speaking to Unifi about their Endpoint app - as that can do one-click WiFi provisioning, but currently can't deploy certificates...
  6. R670s/T670s. Nah - for Visitors we use the Guest Portal in R1 instead, with voucher codes that are issued by IT/Reception. No SSL inspection on that network - Securly Guest DNS filtering only. Voucher codes so that it can't be used by students. Cheers
  7. Yeah you still need to install the root that signs the NPS cert for some Androids, tis annoying. Makes sense - am in the same boat. Will easypass also hand certificate distribution? That's the pain point (still)
  8. We've recently gone to the Ruckus CloudPath route due to this issue exactly. And still not perfect, but a smidge easier - Android is the worst, not helped by the amount of variation between manufacturer versions as well. The other route is enrol in an MDM... i can share instructions from pre-CloudPath if it helps? Again they were reasonably vague though to try to cover the majority of devices without taking into account the specific variations. Cheers
  9. GPO details below (not sure the scheduled task deletion actually worked, but the reg keys definitely had the desired effect) I will however also make clear - this is NOT a fix - these devices DO need to replaced due to age, but we are where we are unfortunately... Computer Configuration > Preferences > Windows Settings > Registry: - New > Registry Item: ○ General: § Action: Updated § Hive: HKEY_LOCAL_MACHINE § Key path: SYSTEM\CurrentControlSet\Control\SecureBoot § Value name: AvailableUpdates § Value type: REG_DWORD § Value data: 0 (Decimal) ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No - New > Registry Item: ○ General: § Action: Updated § Hive: HKEY_LOCAL_MACHINE § Key path: SYSTEM\CurrentControlSet\Control\SecureBoot § Value name: HighConfidenceOptOut § Value type: REG_DWORD § Value data: 1 (Decimal) ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No Computer Configuration > Preferences > Control Panel Settings > Scheduled Tasks: - New > Scheduled Task: ○ Task: § Action: Delete § Name: Secure-Boot-Update § Nothing else configured ○ Schedule: § N/A ○ Settings: § N/A ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No
  10. Just in case it helps anyone else - we had this on Win 10 and 11 machines - freezing ~10 minutes after boot, whether logged in or not - it was the Secure Boot certificate updates. Specifically, trying to update them on machines that couldn't take it.
  11. Recently gone through Procurement Services to get refurbished hardware; LOT 2 here: IT Hardware, ITAD & Associated Services The framework was quick and easy to use. Definitely easier than trying to get like for like quotes with refurbished kit - quick spec sheet, RFQ out and short turnaround - ended up awarding to BornGood and Tier1 - so far so good. Cheers
  12. Have found 2 genuine HP J9150A, the rest are all FS and were working in either a 5412zl or 8212zl Cheers
  13. Also generally recommend FS.com for everything - and the reprogramming side of things! More specifically though, I've been taking out a lot HP/Aruba switches and 10Gb SFPs so @Olliedawg if you confirm the exact part numbers you want I'll have a rummage and you're more than welcome to any I have? Cheers
  14. Makes sense! Yes absolutely a great reference - fills some gaps in the standards as well. Appreciate you finding and sharing.
  15. This is super interesting actually - how did you find this?? and thank you for sharing!
  16. Yep all seems fixed now. Only details that were shared to us was "It seems there was an update released overnight which was the cause of the issue. We are working on rolling that back ASAP to resolve the issue." Not the first update in recent times that's caused disruption unfortunately.
  17. Yes - we've got the same at several sites, and have a ticket with Securly. Seems to be related to an update yesterday - no details from them yet. Shame as recently there have been a number of disappointing incidents with Securly.
  18. Android devices are definitely a pain these days - more so if a 802.1x network! My notes regarding the "no internet" message are below; those URLs need to be excluded from filtering and ideally decryption too. HOWEVER be careful if you exclude the generic one, that as it contains google.com as if you the way it is excluded isn't specific to the exact URL, then there goes all your monitoring of Google searches... Below are the identified Connectivity Test URLs so far (these are required for devices to "think" they have internet access, regardless of if they actually do or don't have access to the rest of the internet) These URLs require adding to the "Custom allowed content" category, which means no filtering, and no decryption Android URLs Generic - google.com/generate_204 Huawei - connectivitycheck.platform.hicloud.com Huawei - connectivitycheck.cbg-app.huawei.com Oppo - connectivitycheck.gstatic.com Oppo - connectivitycheck.android.com Cheers
  19. Yep Shared iPad still not good enough. For the Junior school, we have 120 "Student iPad" accounts - 1 for each iPad. So they are setup as 1:1, and then the teachers have a record of student name to iPad for filtering/other issues. Then there's no password/code issues either as the teachers know the Managed Apple ID password if required (federated to the Entra account) and these are also still unique per account. No passcode on the iPads, managed layout via Jamf School etc too. Cheers
  20. We've been moving to Ruckus - so far so good. Previously an Aruba house, and as others say the Central costs are insane...
  21. SmartPAC We also have the DNS configured as well, as fallback
  22. I only have 1 Securly extension - I didn't think there were different ones for ChromeOS vs Chrome browser? Currently we are only deploying to Chromebooks though - when there were issues last year, it was removed from Chrome and has never been re-deployed. We have our Chrome devices in a separate OU so it only deployed there at the moment. Cheers
  23. I can log in fine from sites using Securly - so might be a you specific issue I'm afraid!
  24. Thanks both, good to know! I'll reach out to Redstor for futher info. Appreciate the response
  25. Question for those currently backing up Google - what are you using, and how does it handle Google Classroom? We have a lot of coursework that "lives" in Google Classroom, and so there is pressure from exam board regulations to ensure that all exam/courswork is backed up. The providers I've been looking at don't seem to specify Classroom, only Drive so not 100% if that would work. Cheers
×
×
  • Create New...