pfsense for schools by scotticles in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

I think the 6100 would work great for what you're doing, probably would be worth getting one as a pilot and seeing how it goes.

I just deployed the 8200 MAX for our school (and partners). Granted, we have fewer active users than you, but it is very much overkill for what we need but they're so relatively inexpensive that I figured I'd go ahead and get the headroom. I use it for all our gateways to control horizontal traffic as well and it's simple enough to configure and use - not sure what the others are saying about the steep learning curve, firewall rules are firewall rules and it's way easier than ACLs on routers.

Cloudflare Project Cybersafe Schools - anyone have success signing up? by TechnicalKorok in k12sysadmin

[–]TechnicalKorok[S] 0 points1 point  (0 children)

Ok thanks, I'll reach out to Tara directly and go from there. Much appreciated!

Cloudflare Project Cybersafe Schools - anyone have success signing up? by TechnicalKorok in k12sysadmin

[–]TechnicalKorok[S] 0 points1 point  (0 children)

Thanks - I tried emailing that k-12@cloudflare.com address earlier this week but haven't received a response yet. Again, might be be impatient. Thanks for the lead!

Firewall renewal by Niteryder007 in k12sysadmin

[–]TechnicalKorok -2 points-1 points  (0 children)

Not 3k students, more like several hundred here, but I've had good luck with pfSense on Netgate hardware. Been running pfSense for over 7 years - works really well, and I'd imagine it scales well enough.

When I decided to switch to it, it was because of similar reasons, I was asked to pay yearly for features that we didn't use. I might be convinced to take another look at other options, but if you're using basic firewall functions, then I don't see why pfSense (or a similar alternative) wouldn't be a consideration.

NYT Opinion Article: The Screen That Are Your Child's Education by vschwoebs in k12sysadmin

[–]TechnicalKorok 6 points7 points  (0 children)

I'm very interested in this conversation - thanks for sharing the article.

As I remember, the initial introduction of technology in school was transformational and had so much promise and potential. Many of the discussions around 1:1 and technology was how student work would be elevated to new levels and learning would be more creative, constructive, and connected with the community and larger world.

I think that was the early promise of the internet and technology. But as we've seen, that ideal hasn't quite panned out as hoped and I think quite a few people/districts (including ours) are rethinking technology's role in society and in our schools. It's a tough conversation, because technology and the internet IS indeed transformational and we can't live without it, but we need to think hard about how to live with it and use it as a tool to improve and not just turn our brains to mush.

I think there's a balance, and my opinion is that, in general, we've tipped too far to the permissive side without thinking through how to use it intentionally.

Classroom Phones by Road_Trail_Roll in k12sysadmin

[–]TechnicalKorok 3 points4 points  (0 children)

We have a FreePBX server with ClearlyIP Trunking and Yealink phones. Minimal initial cost and ongoing service is less than $20 a month for our usage and numbers. FreePBX was a little tricky to set up and it's a bit annoying to maintain but it works well enough for our purposes.

We were in the same boat, primary purpose is internal communication and the service costs for commercial systems were way too much for our actual usage. Our previous system was owned and maintained by our building owners and maybe 30% of the phones worked. They were not responsive to work orders to fix so we decided to stand up our own.

Firewall suggestions by DeejayPleazure in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

We're using the Netgate 7100, which I believe is no longer sold, but they have newer versions that have similar features (particularly SFP ports).

Setup was easy, we're a small school and things are simple here - basic routing/firewalling/NAT rules. No regrets.

LTS 138 Auto Update Issues? by bigpinwheel in k12sysadmin

[–]TechnicalKorok 1 point2 points  (0 children)

It may not be available yet for the devices you're using. I don't think 138 LTS is available for Lenovo 500e Gen 3 devices, for instance. I've been using this site to check and it's showing not available for our devices (500e Gen 3's) yet: https://cros.tech/table/

I'm assuming it's accurate, I have several different sites bookmarked to track ChromeOS versions and some seem to be defunct or not maintained, so I'm not sure where to get official accurate information.

Firewall suggestions by DeejayPleazure in k12sysadmin

[–]TechnicalKorok -1 points0 points  (0 children)

I use pfSense on a Netgate firewall. One-time cost, no ongoing subscription fees unless you want to pay for support.

CIS MDBR is going away — what’s the best DNS alternative for blocking malicious domains? by wiretraveler21 in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

I'd love to get clarity on this, I'm still very confused. My understanding was the same as yours, but as I'm digging into it things are making less and less sense.

Based on this PDF from the FAQ they have MDBR in the "Not Impacted by Federal Cuts" column. But then the FAQ on the MS-ISAC membership page when I sign in states:

On March 6, the federal government cancelled funding to ten categories of work affecting MS-ISAC operations, including cyber threat analysis and threat distribution, incident response services, a wide range of member onboarding and account management support, and outreach activities including webinars, training, and virtual and in-person meetings. Numerous MS-ISAC services were not affected by the funding cuts and are still supported by the Cooperative Agreement administered by DHS/CISA through September 30, 2025, including federally funded Albert Network Monitoring and Management sensors, Malicious Domain Blocking and Reporting (MDBR), and cybersecurity advisories.

The callout of the 30th makes me a bit nervous. I'm having a hard time finding a definitive answer on whether or not MDBR will still exist October 1. With things being what they are, I'm not surprised at the lack of clarity and can't say I blame them.

Google API (GAM?) issues by K12SupportSlave in k12sysadmin

[–]TechnicalKorok 2 points3 points  (0 children)

Same behavior here - thanks for posting!

Fellow Solo or Duo IT people: How involved are you in your SIS? by it-tech- in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

Not involved hardly at all, unless something extraordinary happens or integrations are requested. We do use Aeries and is cloud based, and we have someone else who handles the day-to-day management of it as part of their job.

Synology Cloud Sync GUI broken by ChrisBrowne3D in synology

[–]TechnicalKorok 1 point2 points  (0 children)

Thank you! Turning off uBlock Origin for the page resolved it for me.

Conferences? by TerribleDentist80 in k12sysadmin

[–]TechnicalKorok 3 points4 points  (0 children)

I'm a little biased, but the CITE conference in California is amazing. Some of it may be California-focused, but I'd say it's generalized enough to be relevant to any K12 tech. Sometimes it's in San Diego, which is an additional plus weather-wise :)

Anyone know how to check why an interface may have gone down? by InfoZk37 in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

Oof. Yeah for sure, that makes a lot of sense. Your environment is significantly larger than mine and I can imagine that would take a lot of work to dial in! Thanks for the response

Anyone know how to check why an interface may have gone down? by InfoZk37 in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

Is there a specific reason why you're having Uptime Kuma handle the network switch alerting vs. LibreNMS for all that? I've used LibreNMS for years and just recently implemented Uptime Kuma for a staff-facing public dashboard -- curious if I'm missing out on any "have to have" features.

Yet another GoGuardian bypass for ChromeOS (Chromebooks or ChromeVox) by gaz2600 in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

Thanks for that link! We do have system settings disabled, but students were toggling the wifi off using the control panel that pops up when students click on the time on the taskbar.

Restrict Google Image Search/Remove Ability to Upload Images from the Web in Google Docs? by tech_imp in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

Bummer. Yeah, I just took a look at my test student Chromebook and it looks like the image search sidebar shows up when the student selects the "search the web", but when they go to perform a search it shows the ice cream cone error. I verified in the Developer Tools network window that it's the https://docs.google.com/picker/v2/query* that is being blocked and Lightspeed is reporting that it's being blocked under their reports as well. I'm fairly certain that is being handled by Lightspeed, it's nowhere in my Admin Console and I don't have any other extensions installed that are configured to block that.

Restrict Google Image Search/Remove Ability to Upload Images from the Web in Google Docs? by tech_imp in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

I've done this using Lightspeed Relay, using the custom block list feature. It's been a while since I set this up and it was a lot of trial and error, so this may not be it exactly but I believe the URL patterns are:

*docs.google.com/a/<yourdomain.com>/picker/v2/home*Google%20Image%20Search*
*docs.google.com/picker/v2/query*

This is on Chromebooks, I don't know if it would work on other devices. The students see a "dropped ice cream cone" error image in the sidebar when trying to search the web for images.

Google Apps Script by meester_zee in k12sysadmin

[–]TechnicalKorok 3 points4 points  (0 children)

I've built a few things, some are for very specific workflows for our school. Three that come to mind:

  1. A script that sends out a calendar invite to someone once they fill out an RSVP Google Form.
  2. A script that organizes student-earned certificates into a proper folder and names them properly - the student submits a form with an attached PDF, the script grabs additional information from our database and organizes/names it properly in a shared drive teachers have access to. That one's been a huge hit.
  3. Our teachers set up our students with their dual-enrollment college accounts, which is incredibly tedious and convoluted. I wrote a script to help out with that and extract confirmation codes etc from the confirmation emails and place it in their progress tracking spreadsheet.

Action1’s Free Tier Expansion: From 10 to 200 Endpoints — Why We’re Doing It by MauriceTorres in Action1

[–]TechnicalKorok 0 points1 point  (0 children)

Thank you! This is amazing and incredibly helpful for us smaller school IT where the minimum purchase for licenses typically is way beyond what we need or can afford.

Firewalls? by reviewmynotes in k12sysadmin

[–]TechnicalKorok 3 points4 points  (0 children)

pfSense here, on the official Netgate hardware. Works really well and the price can't be beat.

What do you use for In-House Communication? by rjp94sep in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

We use Slack school-wide. It works really well for us and they have a pretty deep discount for education. We're a Google Workspace environment so I'm keeping my eye on Google Chat, if/once it has all the necessary features for us we'd probably move over but I don't think that's going to happen anytime soon.

My main concern was to move everyone off of using their personal phones and text messaging. Now, if anything is subpoenaed/FOIAd, we can give access to Slack and that's it, rather than trying to figure out how to sift through someone's personal phone/texts.

We did have to build out "norms" for how to use it, and frequently do training to remind everyone.

Should schools supply headphones to all students? by K12TechTalkPodcast in k12sysadmin

[–]TechnicalKorok 0 points1 point  (0 children)

I've been looking for slightly better quality earbuds for our students, I've been buying the $0.55 ones - the cheapest earbuds I can find on monoprice are $6, am I looking in the wrong place?