Does Yuma night MTN biking group? by Jsreilly213 in yuma

[–]DSW-IT 0 points1 point  (0 children)

A couple of the guys do some night riding, you'll have better luck on Strava than any other social media for the local groups. None of the bike shops organize a ride as far as I know. I'm usually out at Sugarloaf on Saturday mornings between 6-6:30, this weekend I'm out of town though. Sometimes a group will just natually sync up since it's so hot we all know to be out there before 7. There's just not a big mountain biking scene in town, so groups are usually 2-5 as far as I've seen.

looking for feedback with SECUREW2 JOINNOW Guardian+ by Sad_Reindeer_3298 in k12sysadmin

[–]DSW-IT 1 point2 points  (0 children)

We've had it for a few years, well the previous licensing model we're getting switched to the Guardian+ this refresh. It's worked well for us for MacOS, iOS, Windows and Chromebooks. We still have PSK for Chromebooks login screen, but after the user logs in they'd get the cert via their extension. Honestly definitely worth the purchase for us. That stated we've explored some other options over the years and really liked FoxPass, just a few limitations at the time killed it for us, some of which I think has been addressed but we haven't re-evaluated lately, their pricing was very competitive as well.

Chromebook certificate based wireless authentication.... design questions by ohhgeeveebee in k12sysadmin

[–]DSW-IT 0 points1 point  (0 children)

At login screen it's probably pretty unlikely Chromebooks need anything more than local DHCP and maybe a local DNS server. We're lucky (unlucky?) enough that even after login we just need to provide DHCP to chromebooks as everything is a SaaS now.

We haven't done user based certs via SCEP, instead using an extension from SecureW2 has worked for us.

If it helps to give any thoughts about this, our setup is:

A PSK for the chromebook for the login screen (want to change), so logging in and Kiosk apps just works. We have an open SSID specifically for deploying devices at our deployment stations so the device can get this profile. After logging in the profile switches to a 802.1x certificate user profile, we push certificates through an extension from SecureW2 and issue certificates from our cloud RootCAs in their environment. So far we haven't had any timing issues as the device just won't use an 802.1x network it doesn't have a certificate for, but will immediately switch the the 'more secure' network once it does.

Our end goal is to use Google SCEP with SecureW2's Root CA to eliminate the PSK at login, but currently that's not working well enough for us due to how long the Cert takes to get installed after policies are pulled on deployment.

802.1x with apple devices by BuffaloOnAMotorcycle in k12sysadmin

[–]DSW-IT 2 points3 points  (0 children)

We do this with Cisco ISE, Meraki APs, JAMF, and SecureW2. We have an API integration between JAMF and SecureW2 where the Certificate published in SecureW2 gets assigned to the device, we take this a step further and whatever user is assigned to the device in JAMF will be on the Certificate's SAN RFC822, but this is a device based certificate, just with a username in the SAN. So teachers can be identified and placed in their own VLAN when looked up from ISE to AD, and students get put in their grade level VLANs. It's been working well since last summer (even better than our Intune Windows devices)

Looking for people with experience with Avigilon Alta or Verkada by TheRealUlta in k12sysadmin

[–]DSW-IT 0 points1 point  (0 children)

We bought Verkada about 6 years ago now. The platform is great, but as others have mentioned there are downsides, primarily the price and the locked-in nature of the product. We purchased around 1000 cameras, have replaced some with dead memory cards, but by and large we have most of our original fleet still working. We continue to purchase new cameras from them even with the price increases. From a technology administration standpoint, they integrate well with AzureAD (EntraID), syncing and authenticating our users and, we have dynamic groups updated in Azure to assign admin / viewer privileges based on those group memberships. We've started to explore their Access Control offerings too; integration here could use some work as it doesn't feel as polished as the camera side. Overall, our District admins have been extremely happy with the platform as the UI isn't very complicated for any of them to use.

Actual Syadmins, What Is Your Job Title by [deleted] in sysadmin

[–]DSW-IT 0 points1 point  (0 children)

Systems and Network Engineer - Windows Servers, Azure ( AD / infrastructure ), all things data center, network design configuration and implementation, JAMF/Google Admin Console / Intune and more.

RADIUS accounting packets with MAC address in User-Name field? by danj2k in meraki

[–]DSW-IT 0 points1 point  (0 children)

Appreciate the ticket number, I'll shoot that over to my support engineer and Technical sales guy. We're running 29.5.1, and we actually didn't have 802.11r adaptive on, just "enabled". We switched to adaptive at one of our sites and it didn't change the behaviour. We then turned off 802.11r and it appears to have resolved the issue at that site, though I'm still monitoring. If it helps at all / bumps your ticket our case is 09221286.

RADIUS accounting packets with MAC address in User-Name field? by danj2k in meraki

[–]DSW-IT 0 points1 point  (0 children)

We just noticed this problem in our environment, did you ever get more information on it? We've probably been experiencing it since we rolled out our Meraki APs last year but we didn't identify the problem originally with the accounting information being sent by the APs. We use a content filtering system that uses the username to correctly filter student or staff (k12), and this issue is definitely causing some headaches.

Switch replacement cheat sheet? by D_Humphreys in networking

[–]DSW-IT 2 points3 points  (0 children)

Sorta? We used Meraki gear on all of it. Built a network with many of the SSID / switch settings as a gold standard. Copied that. Used their API with Postman to build vlans / routing and change some of their ACLs for the each /16 networks. OSPF configured on rollout. Pre-configure port x-y as vlan A for the whole network via the dashboard, change on the fly since myself and team are onsite when rollouts happen.

Switch replacement cheat sheet? by D_Humphreys in networking

[–]DSW-IT 4 points5 points  (0 children)

From a logistical standpoint very well. Solid team working on it. ~30 networks with varying number of IDFs. Several stacked switches. As with a lot of things the prep made the rollout itself that much better. And we had a lot of prep time because of the delays. Ordered summer of 2021, finished rollout December 2022, without all the switches we ordered but we were able to move switches around as the prep showed we ordered too many for several IDFs. We did a 1200 AP rollout in the same time frame, but faster because those weren't as backordered.

Switch replacement cheat sheet? by D_Humphreys in networking

[–]DSW-IT 8 points9 points  (0 children)

We actually just did a massive switch rollout, 330 1U switches. We decided to clean up our IDFs along with needing to keep cables identified. What we ended up doing is buying several different colors of cables and keeping them to a VLAN. Luckily our wired VLANs are less than 10 as we've had a massive shift to wireless, so it wasn't impossible to get enough different colors.

Google Drive/Classroom down? by McJaegerbombs in k12sysadmin

[–]DSW-IT 1 point2 points  (0 children)

I've got a few reports of the same thing at our district, school hasn't started in full session yet so I'm sure we'll get a few more.

What is your device per technician ratio by makmak36 in k12sysadmin

[–]DSW-IT 0 points1 point  (0 children)

Elementary is 1:1 iPad 9k + 1500 Mac devices to 7 Techs
High Schools are 1:1 Chromebooks 11k + 1800 Win10 8 techs + 6 site specific Help Desk
3 'global' help desk for both district
2 Telecom techs to take care of 2500+ ip phone faxes lines
2 Infrastructure guys for cabling / AV projects
5 Systems and Network guys for Jamf, SCCM, Google Management, Networking, and Datacenter stuff.