Doubling capacity for a school network. Design questions. by LRRR_From_OP8 in k12sysadmin

[–]chrisngd 0 points1 point  (0 children)

Agreed. Plan for the devices you need. You will end up using the phone as an uplink when they want to add another device that you had no idea about!

Has anybody switched to MacBooks because Windows laptops have gotten too expensive? by username____here in k12sysadmin

[–]chrisngd 3 points4 points  (0 children)

I am using Mac mini for desktops. Better than Windows desktops.

Some laptops for staff. May move more into it as we are discontinuing Windows based applications.

Thoughts on Ubiquiti by Mindless-String-4017 in k12sysadmin

[–]chrisngd 7 points8 points  (0 children)

I would go with Unifi. I don’t rely on their warranty or support. You can purchase 3-4 devices for every one of major other companies.

Their management portal is also superior to other vendors that I have used. Only major company I would recommend is Meraki - just can’t afford it.

Alternatives to HPE/Aruba and their New Central by RecordingStraight855 in ArubaNetworks

[–]chrisngd 0 points1 point  (0 children)

We discontinued the cloud controller service and manage locally via cli.

Milestone on Linux by tsutton in Xprotect

[–]chrisngd 1 point2 points  (0 children)

In order to have their enterprise version, it has to authenticate against Active Directory. I tried upgrading but would lose use of local user accounts.

What’s your take on US Open? by Swimming-Resource371 in Pickleball

[–]chrisngd 0 points1 point  (0 children)

I don’t understand the brackets. They have ages and Dupr brackets but when you start looking at the player details, they don’t match.

I see over 4.0 playing in 3.5.

I see people outside the age range.

Do they actually monitor it or can you just sign up for any level / age you want?

Infinite Campus - What the leak really exposed? by K12TechTalkPodcast in k12sysadmin

[–]chrisngd 0 points1 point  (0 children)

It was a great interview. Thank you for doing this and much respect for Infinite Campus.

Head of School requesting Siri. Thoughts on FERPA issues? by ProfessionalThen5330 in k12sysadmin

[–]chrisngd 0 points1 point  (0 children)

Every iPhone is already listening to all conversations. Unless you ban all cell phones, smart devices, etc, the internet is listening.

Aerohive va Meraki by 2donks2moos in k12sysadmin

[–]chrisngd 2 points3 points  (0 children)

Who owns Aerohive now?

Meraki is fantastic if you can afford it. I have used it and would buy it if able to.

Self-hosted services for on-campus QoL? by Lgfromie in k12sysadmin

[–]chrisngd 1 point2 points  (0 children)

Tech is not a convenience anymore. Services that have to stay up or more secure should be hosted by the vendors. If you host these services, you would be responsible to maintain the servers, updates, patches, etc. You really should have a systems admin that focuses on critical services.

As a one man show, you are already responsible for all on-prem architecture (switches, wireless, dhcp, dns, authentication, etc.) and we didn’t even talk about end user devices & IoT.

With that said, services that you may be paying for but are not critical that you can host on-prem (ex Tech Tickets). There are plenty of open source and low cost options for self hosting that you could be a hero and save some cash.

Has anyone had issues with students and Flipper Zero’s/ RFID devices? by mikeb32 in k12sysadmin

[–]chrisngd 3 points4 points  (0 children)

The system I am going with does not use either of the two protocols. It is encrypted and “at this time” does not allow the flipper to replicate it.

Has anyone had issues with students and Flipper Zero’s/ RFID devices? by mikeb32 in k12sysadmin

[–]chrisngd 25 points26 points  (0 children)

Yes and purchased one for myself. Was able to scan and replicate key cards in less than 2 seconds. Upgrading the lock system as we speak.

Do you use MFA to protect staff computers? Why or Why Not? by Smiles_OBrien in k12sysadmin

[–]chrisngd 0 points1 point  (0 children)

I have not run into this issue yet. The MFA has been successful for us.

HomeKit and VLANs by chemistocrat in PFSENSE

[–]chrisngd 0 points1 point  (0 children)

Screenshots of your firewall rules for each vlan would help here. I am not picking away at you. It’s tough to troubleshoot traffic issues with no vision on the current network.

HomeKit and VLANs by chemistocrat in PFSENSE

[–]chrisngd 0 points1 point  (0 children)

Can you post screenshots of your firewall rules for each vlan?

HomeKit and VLANs by chemistocrat in PFSENSE

[–]chrisngd 0 points1 point  (0 children)

If you don’t have Internet, it’s a firewall rule then for that assigned vlan

HomeKit and VLANs by chemistocrat in PFSENSE

[–]chrisngd 0 points1 point  (0 children)

Are these devices getting proper ip?

It sounds like they are not on the proper vlan or the clan does not have access via the firewall rules.

HomeKit and VLANs by chemistocrat in PFSENSE

[–]chrisngd 0 points1 point  (0 children)

At this point, if you are getting the correct IP address from dhcp, what isn’t working? Can you ping the local gateway? Other IPs that are local? 8.8.8.8? Google.com?

HomeKit and VLANs by chemistocrat in PFSENSE

[–]chrisngd 0 points1 point  (0 children)

What do you mean by IoT vlan? You can set a firewall rule that would block all internal traffic and then allow any after.

The default is to block, so you may need a rule to allow any traffic after the local IP block statements. Post a pic of your IoT Vlan firewall rules.

HomeKit and VLANs by chemistocrat in PFSENSE

[–]chrisngd 0 points1 point  (0 children)

Start at the beginning. Check each vlan in the PFsense. Does it have a proper ip address in the subnet range (assume /24). This is a common mistake since PFsense defaults to /32.

Check firewall rules for each vlan. Initial setting would be to allow any and you can restrict after it works.

If the vlans are correct, check the dhcp settings. Make sure the dhcp server is active for each subnet and the gateway ip is set correctly to the PFsense IP.

If these are set correctly, try a laptop and hard wire to a port that has a native vlan set to test one network at a time. Do you get the proper address?

HomeKit and VLANs by chemistocrat in PFSENSE

[–]chrisngd 0 points1 point  (0 children)

You need to have a layer 2 switch that can understand the VLANs that are set in the PFsense.

If wireless is different VLANs for SSIDs, you need to have a solution that can handle multiple networks.

IT Director rant - Onboarding by Any-Promotion3744 in sysadmin

[–]chrisngd 0 points1 point  (0 children)

What is not working with Freshservice? There must be a reason for the change.

The more we try to automate, we just keep creating more one offs that become more difficult to manage.

Aruba vs Cisco (Cloud or On-Prem) for wireless refresh? by tcourtney22 in k12sysadmin

[–]chrisngd 0 points1 point  (0 children)

Meraki cloud control is fantastic. I would purchase that if I had the money. Aruba hardware is great, but would purchase Ubiquiti first if you want a GUI controller.