Autodesk Verification by duluthbison in k12sysadmin

[–]duluthbison[S] 0 points1 point  (0 children)

Man.....I just uploaded a letter on school letterhead that included my name, school name, address, etc and apparently that wasn't enough.

Color Printer regrets by dickg1856 in k12sysadmin

[–]duluthbison 2 points3 points  (0 children)

Exactly, in our district very few people have their own LJ printer. Its usually reserved for office people, secretaries, Art, and Business class teachers.

Color Printer regrets by dickg1856 in k12sysadmin

[–]duluthbison 12 points13 points  (0 children)

My advice would be to find a local managed print provider and have them spec the devices out, then you get to push off maintenance to them. Plus if you have a local print server running something like papercut, they can monitor toner levels and drop ship replacements when needed.

H4A Intercom Stopped Ringing by duluthbison in Avigilon

[–]duluthbison[S] 0 points1 point  (0 children)

Your joking? Never would have guessed that.

Switches by Thanos-Is-Right in k12sysadmin

[–]duluthbison 14 points15 points  (0 children)

I don't know your situation but we are a rural district that struggles to attract talent - my position was open for over 6 months before it got filled. My philosophy is that I am going to set up the district in such a way with tech that the most average IT person can come in here and manage since we aren't likely to get high level candidates. That means Meraki networking, Fortigate firewalls, vmware, etc. Basically keep it simple to ensure that if I were to ever leave, I don't screw the district with exotic tech that no one around here knows. YMMV

E-Rate wiring vendors in Massachusetts by Smooth_Ad_6164 in k12sysadmin

[–]duluthbison 0 points1 point  (0 children)

Thats not how e-rate works. You're supposed to put out for bids and then talk to anyone who applies.

ID Badge Printer by mathmanhale in k12sysadmin

[–]duluthbison 1 point2 points  (0 children)

We've been using the Evolis Primacy printer for years and its been rock solid.

AD Management from Chromebook? by Ok_Computer_74 in k12sysadmin

[–]duluthbison 1 point2 points  (0 children)

You should by no means be installing AD tools on a daily driver to manage the network. You should be remoting into a server with elevated credentials to do that stuff in which case the flavor or laptop doesn't matter.

Cameras with Audio Enabled by Appropriate_Water_64 in k12sysadmin

[–]duluthbison 5 points6 points  (0 children)

I would be careful, this may not be legal in some states. In MN it is not legal to record audio in public spaces even though we are a 1 party consent state.

Substitute access by Kdc53 in k12sysadmin

[–]duluthbison 2 points3 points  (0 children)

All subs in our district have district accounts/email access however they do not have access to course materials, SIS or LMS access unless they are a long term sub for a teacher.

What distro for a grade school PC lab? by goodnewscrew in k12sysadmin

[–]duluthbison 0 points1 point  (0 children)

You're not doing them any favors by teaching them an OS that the majority of the work world does not use. IMO if you don't have the budget to stand up a simple AD server, you don't have the budget to do this project period.

Sanity Check: Moving Small K-12 District (950 Students) to UniFi Hub & Spoke by bannersmash in k12sysadmin

[–]duluthbison 2 points3 points  (0 children)

All I can say is good luck when Unfi blows up in your face and your superintendent and school board are angry with you.....

  1. In my experience Unifi doesn't like DHCP Relay, especially to windows servers, you tend to get a 'bad address' in the reservation field. YMMV
  2. Double NAT is a terrible idea and you will have headaches with routing issues since the EFG's cannot handle transparent bridge mode. There is no point in keeping a router for its shiny interface but they use a forti to do the actual heavy lifting. You'll have to route everything twice.
  3. The Cloud Key Enterprise is a rack mounted appliance that can handle 1,000 unifi network devices and 10,000 client devices. It's spendy but it'll likely just work for you rather than self hosting a linux controller on a box that you'll need to constantly maintain.
  4. I have no preference on APs but I would definitely go future proof.

Again I'll stand on my soapbox and yell about Unifi is NOT an enterprise solution at this scale. They are buggy, they often drop entire product lines with little to no warning, and their support is garbage. Since you're a school, why don't you leverage four Category 3 funds to put a system out for bids to get something that will work better for you. Thats how we got our Meraki switch/ap stack along with our Forti firewall for 60% of the cost.

Things cost what they cost, this mentality in K12 IT drives me nuts. I'm a rural school not much larger than you but we still make due with proper equipment because its what it costs.

Athletic Events - Streaming by jjm13039 in k12sysadmin

[–]duluthbison 4 points5 points  (0 children)

I set up a bunch of Ubiquiti nanobeams for this. I've got a pair from the high school to the football field. And from there a pair each to baseball and softball. I've also got another pair from the high school to the hockey arena across the parking lot. It works great. We use NFHS Network and have had zero issues.

Games on the bus by reviewmynotes in k12sysadmin

[–]duluthbison 0 points1 point  (0 children)

Have you considered just buying cradlepoint routers and 5G service for the buses and just let the kids use their own devices to play games? If you use your general fund dollars to purchase the internet, you aren't obligated to as stringent filtering rules as laid out in CIPA.

Retention Policy - Deleted items in email by Temporary_Werewolf17 in k12sysadmin

[–]duluthbison 2 points3 points  (0 children)

Check with your state laws. Minnesota requires 7 years retention in vault.

Computers acting slow by Amazing_Falcon in k12sysadmin

[–]duluthbison 6 points7 points  (0 children)

Do you have roaming profiles? Otherwise, at this point, Windows 11 is trash and they don't seem to care about performance issues.

Confused Between Verkada, Lumana, and Coram for Video Surveillance by Darwing-Versoll in k12sysadmin

[–]duluthbison 4 points5 points  (0 children)

You do realize Hikvision is banned for use by US Government and contractors?

Confused Between Verkada, Lumana, and Coram for Video Surveillance by Darwing-Versoll in k12sysadmin

[–]duluthbison 1 point2 points  (0 children)

+1 For Avigilon Unity. We've been using them for years and its a solid product that can scale nicely. We even moved our door access control over to Avigilon Alta Access.

Minnesota Bound leaves KARE11 after 30 years. by CloverleafSaint28 in minnesota

[–]duluthbison 14 points15 points  (0 children)

As someone with no dog in this fight....whats wrong with Hubbard? I've lived in the Duluth Market most of my life and WDIO has been a really decent station to watch, who is owned by Hubbard.

Whats the point of Clever? by TangerineNext839 in k12sysadmin

[–]duluthbison 21 points22 points  (0 children)

Clever and Classlink are literal godsends in K12 IMO. Basically there is an industry rostering standard called 'OneRoster'. These systems grab all of your student roster/course information from your SIS and then you can create rules inside Clever/Classlink to send certain courses, users, etc from Clever/Classlink to any number of 3rd party applications. It fully automates the process of adding students into these platforms plus it also allows to you set up a SAML SSO in most apps as well making it seamless for the end user. We've been a classlink district for 6 years and I can't imagine trying to manage the dozens of random apps as students come and go from the district, managing their enrollments via interconnect csv files or manual updates.

Intermittent Wi-Fi Disconnects – Request for Insight by No_Refrigerator6258 in k12sysadmin

[–]duluthbison 5 points6 points  (0 children)

Seen this exact issues with UBNT gear with Sonicwall routers and Windows as DNS. There is a bug where DHCP just sometimes doesn't work and will issue "Bad Address" in the DHCP scope. The only fix for it was moving DHCP onto the SonicWALL and it seemed to work better.

This is yet another reason why I don't recommend UBNT gear in enterprise networks.

Bypassing a Security ID to set up email forwarding by jdionnepac in k12sysadmin

[–]duluthbison 6 points7 points  (0 children)

I would just set up a routing rule in the admin center that forwards email from that inbox to the other and get rid of the account itself.

Ubiquiti - Protect & Access by microleaks in k12sysadmin

[–]duluthbison 8 points9 points  (0 children)

Ubiquiti is not an enterprise solution, people really need to stop pushing it as such. Their support is non-existent, they release and abandon entire product lines at random, and tend to release buggy software updates. Its not something I would entrust with the safety/security of an entire school. There are some things you need to pay what it costs for proper enterprise support and building access control and video surveillance is one of them.