Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

CrootUK

Members
  • Posts

    303
  • Joined

  • Last visited

Everything posted by CrootUK

  1. Was hoping to do leeds-72 this weekend but not showing up for us only leeds-71. have logged a ticket.
  2. Hello, we have lacp on our dual links to each smoothwall/core works great. for your question about gateway ip on a single internal interface, either change the gateway ip for your network to the new ip on the bonded interfaces vlan or just move the ip address. (just be mindful of any firewall rules)
  3. Hello All, Anyone noticing more videos being blocked than usual when using Smoothwall since leeds 70? Many thanks.
  4. We have two supermicro s14s that have had some custom work to get them to 10Gbps capable. our broadband is 10Gbps link but 2Gbps to the web, so I have only been able to test 10Gbps using iperf over our MPLS and it did get very close to that, but obviously this will just be the “firewall element” with no ips enabled. It manages 2Gbps fine through filtering with https inspection etc
  5. Big LOL! this consultant should be ashamed of suggesting that! AV will not cover a CVE in the OS itself! silly! regs switching same as all previous comments, seconardy l3 at core, l2 at edge. primaries can quite often get away with just l2 and use isp router for any additional l3 stuff.
  6. DualCom by CSL Group are the units alarm providers have been installing here, completely disconnecting that analogue line, it has dual sims as well as an RJ45 port for backup. They can also do antenna runs for schools with poor signal.
  7. If your on about this https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults to my knowledge there is no “excluding” this is where conditional access is used as you can apply the same policies in “Security Defaults” but more granularly eg to different groups, some such as block legacy auth can also be applied to students for example.. Just make sure you have and exclude a break glass account from some of these policies. you’ll need atleast one A3 or Entra ID P1 licence to get started.
  8. Can highly vouch for E2BN! Their web-filter (Protex) is a little outdated/ has its limitations but works great.
  9. Richo and Lexmark for all our schools via ASL on papercut It’s super hard to say anything positive about a printer, but they’re OK more reliable than I’d like to admit. ASL are great though..
  10. I only see the first part of this on mobile app, came to disagree but glad it turned out the way it did lol! they are [emoji90]
  11. Used UniFi for years in primaries, still do but CTC has allowed us to start moving to Meraki. Secondaries are Meraki, understand the licensing isn’t for everyone but it pays off in many ways, thats my recommendation anyway.
  12. Medhurst https://medhurst-it.com
  13. Wanted to bring this up again, hope thats OK.. as our renewal is this year, still keen to hear peoples thoughts. We are smoothwall at secondaries and LA/ISP filter at primaries, we have a MPLS connection at 1GB between all but two schools where it’s only 100MB. We are yet to go out to providers, but we are building a list of potential ones and what are must haves / nice to haves are. we are looking for a central solution, whether thats a box at each school then managed via cloud/master box or a pair of boxes at secondaries and everything is split through them. (need something that can manage guest/byod (non managed) onsite) I have been digging in palo alto / cisco meraki subreddits asking about their https inspection/dynamic filtering but really keen to hear more from people using anything apart from smoothwall… eg fortigate/iboss/watchguard/sonicwall/sophos/securly/lightspeed/impero content keeper/palo alto/meraki mx? etc I hear some products need things like fastvue or netsweeper to be practical in edu, interested to hear more about that also. really would prefer a filter/firewall combo but appreciate we cant have everything lol. thanks for your time.
  14. I dont see how they can completely get rid of onprem filter? getting students/staff/guests to install a cert is hard enough let alone a custom browser/app and expect them to use that and only that whilst at our schools…. onprem filtering is going to be around for a long time yet…
  15. https://www.ct.co.uk
  16. Tried Fujitsu direct? seems to be a hard part to come across. Unless you want to buy an entire controller / san second hand.
  17. https://www.ess-sims.co.uk/resources/blog/mis-migrations-setting-story-straight
  18. Ours is up mid year, wanting to look at iBoss.. anyone here used them before?
  19. 3CX and Yealink. Great combo deployed it to nine schools now… steer clear of Fanvil!
  20. We used these for our most recent core/edge replacements. https://www.everythingict.org
  21. Updating Paxton to the latest version will migrate the database to SQL2017 i think? In paxton configuration utility it should show which server/instance its pointing to for the database …
  22. No onprem at all? what do you use for unattended remote control? printing? etc Don’t get me wrong intune has its place, we are co-managing with it via sccm for 10 sites and its handling various bits itself but on to many occasions when trying to do something that should just be simple hasn’t been possible with Intune or its behind a pay wall.. Autopilot has never worked well for me either, but that could be down to previous configs that capacity hasn’t allowed to be reviewed.
  23. Not usually one to debate, but until InTune is an equivalent to Group Policy and SCCM i see servers sticking around for a while yet..
  24. Zabbix
  25. because you provide external ips / domains etc they do checks their end to my knowledge, very similar to NCSC early warning service
×
×
  • Create New...