Aprice
Members-
Posts
624 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Aprice
-
If staff have to search for it, then they definitely won't read it.
-
Main site we're at has a Word doc for every day saved on Sharepoint. Staff are free to add to it. At about 9AM one of the admin team converts it to a PDF and emails it out to all staff.
-
We used to keep ours in a small biscuit tin. If you can take the container to the car and the car doesn't acknowledge it I think it's probably good enough.
-
They'll give you a subnet, and a default gateway address. I'd suggest asking for something like a /26 subnet (255.255.255.192) which would give you 64 addresses. Also the same for the WiFi SSIDs if you want them on their own VLANs then each will need their own range. Maybe 192.168.4.0/24 192.168.5.0/24 192.168.6.0/24
-
Yeah, the address size you've got was a common thing we've seen with these LGFL / KCOM type networks. There are ways around it and some creative options, but it's just another reason we don't like working with them. This way devices would still receive an address from that particular VLANs subnet, and the access points will be able to communicate between all 3 SSIDs... I hope this is right? please tell me if not! The access point won't route traffic between the VLANs (unless it's doing L3 on the AP, which yours almost certainly are not). But your site router will route it between unless something is put in place like an ACL or firewall rule to stop it.
-
I'd say it's best practice to put the APs on their own, that way access to the management interface can be controlled easily. And management traffic kept separate from everything else. Our 'Standard' network for a Secondary maybe has 20 odd VLANS maybe more depending on the site. Here's an example of one of our older templates, they vary a lot depending on site layouts and the services they have. When we plan these networks we add a lot of extra capacity, for example they might only end up using 3 of the desktop VLANs but the extras are there. Often these end up repurposed later on for other things. You could not bother creating a management VLAN for the WiFi points and just dump them on VLAN 1, but it's so little extra effort to create it that you might as well. When we need to make firewall changes so that the APs can phone home to Aruba or our Unifi controller, we just make the change on the firewall to allow the whole of 10.20.12.0/24 to that destination. [TABLE=width: 1110] [TR] [TD=colspan: 10] Main Subnet - 10.20.0.0/19 [/TD] [/TR] [TR] [TD]VLAN ID[/TD] [TD]VLAN Name[/TD] [TD]Range[/TD] [TD]Mask[/TD] [TD]Bits[/TD] [TD]Gateway[/TD] [TD]Broadcast[/TD] [TD]Start[/TD] [TD]Finish[/TD] [TD]Hosts[/TD] [/TR] [/TABLE] [TABLE=width: 1110] [TR] [TD]1[/TD] [TD]Default - To be disused[/TD] [TD][/TD] [TD][/TD] [TD][/TD] [TD][/TD] [TD][/TD] [TD][/TD] [TD][/TD] [TD][/TD] [/TR] [TR] [TD]2[/TD] [TD]Guest_WiFi[/TD] [TD]10.20.0.0[/TD] [TD]255.255.252.0[/TD] [TD]22[/TD] [TD]10.20.0.1[/TD] [TD]10.20.3.255[/TD] [TD]10.20.0.2[/TD] [TD]10.20.3.254[/TD] [TD]1024[/TD] [/TR] [TR] [TD]3[/TD] [TD]Staff_WiFi[/TD] [TD]10.20.4.0[/TD] [TD]255.255.252.0[/TD] [TD]22[/TD] [TD]10.20.4.1[/TD] [TD]10.20.7.255[/TD] [TD]10.20.4.2[/TD] [TD]10.20.7.254[/TD] [TD]1024[/TD] [/TR] [TR] [TD]4[/TD] [TD]Devices_WiFi[/TD] [TD]10.20.8.0[/TD] [TD]255.255.252.0[/TD] [TD]22[/TD] [TD]10.20.8.1[/TD] [TD]10.20.11.255[/TD] [TD]10.20.8.2[/TD] [TD]10.20.11.254[/TD] [TD]1024[/TD] [/TR] [TR] [TD]5[/TD] [TD]WiFi Management[/TD] [TD]10.20.12.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.12.1[/TD] [TD]10.20.12.255[/TD] [TD]10.20.12.2[/TD] [TD]10.20.12.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]6[/TD] [TD]Desktops 1[/TD] [TD]10.20.13.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.13.1[/TD] [TD]10.20.13.255[/TD] [TD]10.20.13.2[/TD] [TD]10.20.13.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]7[/TD] [TD]Desktops 2[/TD] [TD]10.20.14.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.14.1[/TD] [TD]10.20.14.255[/TD] [TD]10.20.14.2[/TD] [TD]10.20.14.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]8[/TD] [TD]Desktops 3[/TD] [TD]10.20.15.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.15.1[/TD] [TD]10.20.15.255[/TD] [TD]10.20.15.2[/TD] [TD]10.20.15.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]9[/TD] [TD]Desktops 4[/TD] [TD]10.20.16.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.16.1[/TD] [TD]10.20.16.255[/TD] [TD]10.20.16.2[/TD] [TD]10.20.16.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]10[/TD] [TD]Desktops 5[/TD] [TD]10.20.17.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.17.1[/TD] [TD]10.20.17.255[/TD] [TD]10.20.17.2[/TD] [TD]10.20.17.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]11[/TD] [TD]Desktops 6[/TD] [TD]10.20.18.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.18.1[/TD] [TD]10.20.18.255[/TD] [TD]10.20.18.2[/TD] [TD]10.20.18.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]12[/TD] [TD]IP AUDIO[/TD] [TD]10.20.19.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.19.1[/TD] [TD]10.20.19.255[/TD] [TD]10.20.19.2[/TD] [TD]10.20.19.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]13[/TD] [TD]Cashless Catering[/TD] [TD]10.20.20.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.20.1[/TD] [TD]10.20.20.255[/TD] [TD]10.20.20.2[/TD] [TD]10.20.20.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]14[/TD] [TD]BMS[/TD] [TD]10.20.21.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.21.1[/TD] [TD]10.20.21.255[/TD] [TD]10.20.21.2[/TD] [TD]10.20.21.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]15[/TD] [TD]Access Control[/TD] [TD]10.20.22.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.22.1[/TD] [TD]10.20.22.255[/TD] [TD]10.20.22.2[/TD] [TD]10.20.22.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]16[/TD] [TD]Servers[/TD] [TD]10.20.23.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.23.1[/TD] [TD]10.20.23.255[/TD] [TD]10.20.23.2[/TD] [TD]10.20.23.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]17[/TD] [TD]Switch Management[/TD] [TD]10.20.24.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.24.1[/TD] [TD]10.20.24.255[/TD] [TD]10.20.24.2[/TD] [TD]10.20.24.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]18[/TD] [TD]IT Office Network[/TD] [TD]10.20.25.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.25.1[/TD] [TD]10.20.25.255[/TD] [TD]10.20.25.2[/TD] [TD]10.20.25.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]19[/TD] [TD]Printers[/TD] [TD]10.20.26.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.26.1[/TD] [TD]10.20.26.255[/TD] [TD]10.20.26.2[/TD] [TD]10.20.26.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]20[/TD] [TD]VOIP[/TD] [TD]10.20.27.0[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.27.1[/TD] [TD]10.20.27.255[/TD] [TD]10.20.27.2[/TD] [TD]10.20.27.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]21[/TD] [TD]CCTV[/TD] [TD]10.20.28.1[/TD] [TD]255.255.255.0[/TD] [TD]24[/TD] [TD]10.20.28.1[/TD] [TD]20.20.28.255[/TD] [TD]10.20.28.2[/TD] [TD]10.20.28.254[/TD] [TD]254[/TD] [/TR] [TR] [TD]700[/TD] [TD]Transit[/TD] [TD]172.16.10.0[/TD] [TD]255.255.255.248[/TD] [TD]29[/TD] [TD]172.16.10.1[/TD] [TD]172.16.10.7[/TD] [TD]172.16.10.2[/TD] [TD]172.16.10.6[/TD] [TD]6[/TD] [/TR] [/TABLE] Personally we dislike having ISPs managing firewalls for us, we prefer the flexibility and ease of having local access. We've had a lot of frustration in the past where what we asked for was not what was implemented by the ISP, then proving this and the back and forth just wastes time and causes a lot of frustration. In your case though creating 3 or 4 new VLANs for some WiFi I wouldn't have thought would be a problem.
-
The typical setup is for any WiFi point to be untagged on it's management VLAN, and tagged on all VLANs that SSIDs will be broadcast. e.g. WiFi MGMT - VLAN 20 - 10.20.0.0/24 Student Devices - VLAN - 30 10.30.0.0/24 Staff Devices - VLAN 40 - 10.40.0.0/24 Trust Devices VLAN 50 - 10.50.0.0/24 On the WiFi point switch ports you would have: untagged vlan 20 tagged vlan 30,40,50 In that example the AP would have an IP in the 10.20.0.0 range and a device connecting on Trust Devices - VLAN 50 would get an IP in the 10.50.0.0
-
Help implement an efficient wireless structure
Aprice replied to Username101's topic in Wireless Networks
Smoothwall alerts from some 'websites' -
Help implement an efficient wireless structure
Aprice replied to Username101's topic in Wireless Networks
VLAN assignment via Radius would be our preferred. We do strongly advise against staff WiFi for personal devices, we've been aware of a number of alerts that originated from personal devices most of the time with a completely innocent explanation. Its just a problem nobody needs, and risks a lot of embarrassment. Genuine Guest SSIDs do have their place. -
SnipeIT, although we're in a situation where we also have to use Parago as the school uses that for everything else. It does mean having to duplicate stuff which I hate, but Parago is so painful to use & we needed a system that actually fit our needs. Parago seems to tick all the boxes for functions schools need, but accomplishes it the most frustrating way possible.
-
Where budget permits we tend to put Aruba in (full fat rather than the Instant ON range) Where it doesn't we'd start to look at alternates like Cambium or Ubiquiti. I've learned to stay away from Instant ON after a load of dead switches, and the older Cisco small business switches drove us all up the wall.
-
Just looks to be a poor setup to be honest, as everyone else says only tag what's needed.
-
The Synology solution works pretty well, we've been running it now for a few years with no issues.
-
pool.ntp.org for most sites, I did install a Mikrotik at one site a while back with a GPS receiver that was setup as a time source for one of the DCs, that worked quite nicely.
-
If it's going on a wheeled stand, I'd probably save on the install cost. It sounds like you're fairly happy with the two options you've said, I would maybe consider some other options though. We've had a really good run with HiSense, as they've been really great value options. One of our schools is pulling out all their SMART panels at the end of their lease to replace with HiSense.
-
Pretty easy to do, just remove the scope on the Windows Server for that subnet. Remove the IP Helper / DHCP relay to the Windows server from that subnet as well. (just doing that should stop it working, assuming that's how it's setup) Activate the DHCP server for the new VLAN on the firewall.
-
Personally not a fan of pass thru RJ45s. Once you've done a couple of hundred of the normal ones it just becomes second nature. Also found them to be a bit more reliable, especially if there's any risk of moisture. That said for new starters the pass thru is likely easier. Main pinch point for me is the ends fouling when trying to get the RJ45 into the crimps, closely followed by the ends not cutting close enough to the body of the RJ45
-
punch downs, however joints should be avoided wherever possible.
-
I'd agree with the above, I wouldn't waste any time on something like that BT kit, which looks pretty obsolete. I'd have a look at a propper VOIP system like 3cx which is probably free for the number of ext you need.
-
Sixth Form Signing In for Fire safety
Aprice replied to jonathan.lees's topic in How do you do....it?
We've used sign in app before, no complaints really. It did the job and was easy to manage Our main site is with Inventry which I'm not a fan of, We've got a bent paperclip cable tied to it so I can reset the thing whenever it's decided to crash out. They have a QuickScan unit that the Sixth Formers scan their MiFare cards on, which does sort of work. Another school we look after has EntrySign which I put in the same sort of boat as Inventry. I'd stick with Sign in app, it sounds like a 'user' error issue -
Support does seem to vary a lot throughout the year. Last ticket we put in was with it not filtering certain games sites despite it saying that they were blocked. We had a session with them which didn't resolve the issue, then a while later it was just closed. For us I really think the appliance option needs to improve fast, we've asked about Chromebook authentication and were basically told they need Smoothwall cloud filter to authenticate Chromebooks.
- 22 replies
-
- internet filtering
- smoothwall
-
(and 1 more)
Tagged with:
-
Mix of Mosyle free and Meraki across customers. Meraki I've found to be a bit more responsive with devices. On the other hand we've done some big deployments in the thousands using mosyle free.
-
One of our sites believes that they aren't allowed to use live view or would need some sort of licence for this. Does anyone know about this or is it something someone's just misunderstood?
-
There's definitely benefits. One thing maybe to consider though is if a school leaves the trust how do you get them out of your new 'super' tenant and back onto their own.
