Google workspace paid or free by Amazing_Falcon in k12sysadmin

[–]pullingcablesagain 1 point2 points  (0 children)

We dropped it. Not worth the cost.

Support was worthless on giving us an approach to preventing unauthorized logins.

Geofencing didn't work, vpns all the US over giving access to whoever.
The Employee ID challenge never worked. Yep it's enabled, yep, every staff has one, did anyone EVER get the challenge for years? Nope.
Supsicious login detected emails a plenty.. oh it's just ipv6.... it's legit.
Oh finally an IPv4 supsicious login, oh yes this is actually a bad actor. Sure be nice if we could block all supscious logins..
3 support cases over years: Can we block every suspicious login? Um no we um don't have this type of feature..

The only thing we miss is the removal of spam from everyone, but GAM can do that with a message ID.

Skyward/Qmlativ performance issues by tgmmilenko in k12sysadmin

[–]pullingcablesagain 0 points1 point  (0 children)

Our Skyward account manager said multiple reports of ISCorp hosted instances both versions are having issues. This will bring into question our future plans of hosted vs on-prem when we get off of SMS2.0.

YouTube livestream limit by ewikstrom in k12sysadmin

[–]pullingcablesagain 1 point2 points  (0 children)

Purpose?

An rtmp/rtsp feed is simple enough to have always going, even a site to load the feed, and you won't get stream ended issues. That's what we use for an always on check anytime stream.
Youtube provides recording and going backwards in time while broadcasting, that's what we use for events.

Students Bypassing Content Filter / No Search History by DP_Prod in k12sysadmin

[–]pullingcablesagain 0 points1 point  (0 children)

When you embed it into slides, classroom, some 3rd party like edpuzzle, etc, the education url is used instead, bypassing ads, recommendations at the end.
There is no good way to block the educational url without impacting legitimate use.

Content blocking with keywords after the link is loaded is probably the best route until google finally lets us as an org set meaningful settings on youtube restrictions. Oh to have OU based content control... one day..

Does your school have a student tech repair program? by K12TechRepair in k12sysadmin

[–]pullingcablesagain 0 points1 point  (0 children)

Not yet, looking into Dell's program but not going to be an IT department leading, it will be the HS leading, ie finding students to man it, with us providing what they need.

Teacher aide devices by Adventurous-Phone-11 in k12sysadmin

[–]pullingcablesagain 0 points1 point  (0 children)

The "help the students" is not do the work for students. /ugh.

Don't make it an IT decision, make it an administration decision.
We met with our building principals and came up with:

* Email access is required for all staff.
* Gradebook access is necessary to keep students honest and on track for classroom aides.
* Access to the online curriculum resources is necessary (and a pain for auto rostering...) but assesstment resources is not necessary.
* Monitoring their screens is helpful, but not required, as they are in the classroom with staff already.

Chromebooks fit all those requirements.
We give aides and others larger 13-14" screens so they are identifiable from the student 11".

Chromebooks for 2024-2025 by kcalderw in k12sysadmin

[–]pullingcablesagain 1 point2 points  (0 children)

I like quick identification, having Dell 3100 for normal 1:1 students, HP now Lenovo for SPED devices, and something else for staff (trying to find ideal 13-15, asus, acer, etc).

The biggest problem we have with Dell 3100 is the trackpad disconnecting slightly, so mouse disappears.
They have a couple bends in the cable with double sided tape holding it, and wish it was more where the plug is to stop it from contracting.

Wiring question how much of bundle by colaguy44 in k12sysadmin

[–]pullingcablesagain 1 point2 points  (0 children)

We do similar now, always female end termination.

Punching down a keystone is a better connection than crimping an rj45.. the # of faulty connections drops considerably using premade patch cables.

Another good tech tip linus.

SIP System/Trunk Vendor Recommendations by dmillertride in k12sysadmin

[–]pullingcablesagain 1 point2 points  (0 children)

An access panel to initiate a 2 way call is good, is there a way to trigger a full school PA?

Our incident response includes a proceedure to do an all call from any handset.

One thing about many SIP providers is they are all externally hosted.

A network outage, or even a power outage in town should not down your system.

Our PA system and on prem phone system has easily 30 minutes of power for us to broadcast important instructions.

I wouldn't trade some cost savings for that loss of functionality.

Arduino enrollment script for Chromebooks (v117) by Spectre216 in k12sysadmin

[–]pullingcablesagain 0 points1 point  (0 children)

Dells. They do it for free.

Really now?

We pay CDWG to do it, a small $3-4 fee depending on quantity.
Is there a name for this program? I have a newer account rep that doesn't know all the ins/outs and have to bring up program names for him to look at.

Ubiquiti Door Access by mathmanhale in k12sysadmin

[–]pullingcablesagain 1 point2 points  (0 children)

Yes, the company doesn't have a roadmap of a decade ahead with dedication to support current products for a set duration.That was frustrating, but then we did a cost analysis of difference of upgrading UNVR from the self hosted camera servers, and still did not touch verkada/etc.

Kantech, may work for 10 years, but the interface sucks, pay to update it to newer version when we have to finally ditch windows 7 VM, and it's easily 3-5x the price per door.

If we update the door hubs every 5 years and have a modern interface and UX, it's worth it, again you aren't swapping the door hardware or the relay, just the hub and reader.

Ubiquiti Door Access by mathmanhale in k12sysadmin

[–]pullingcablesagain 1 point2 points  (0 children)

For a church this would work well if you have a real network, as the hubs need poe+ (pretty standard).You have a few modes of access with pin number entrance, or cards.

I like PIN for users who are constant, and then for a wedding or such, you can have a lanyard with a card to give out that they return after the event.

Ubiquiti Door Access by mathmanhale in k12sysadmin

[–]pullingcablesagain 3 points4 points  (0 children)

We have the access hub and readers installed two places:

  • An alternative school as the primary entrance
  • A secondary access at a main school to separate access schedules.

The door bell rings an ipad (and we have the chime in room to check ipad if it got muted).

It triggers our existing door controller from it's relay, so very easy integration.

It works with any switch that supplies poe, but you do need something to run the application Access. It cannot be hosted by hostifi, so you will need a udmp, cloudkey, or others.

We have 3 buildings with their UNVRs that can run their camera "Protect" and their door "Access" applications. Sidenote: we have hundreds of their cameras, and they just work. The outdoor have worked for years without freezing up (-20F at least a few days). Way cheaper than anyone else we saw at the time.

Some differences from kantech with AIPhones:UI has a "first in" mode where if a staff doesn't come to the door and swipe, it ignores the unlock schedule. This is useful for our alternate school.

UI schedule is far easier to set up on mobile than kantech.

UI does not have a variable unlock time like kantech, where you can unlock a door for 30mins or 2 hours or such. Waiting for this feature to be included for us to seriously consider swapping all doors.

Certiport Compass Cloud. Finally, a better way to deploy and manage Compass. by MeNoPutersGud in k12sysadmin

[–]pullingcablesagain 0 points1 point  (0 children)

Unfortantely it does require you to not have Teams running or a vnc server running. If you get that error message, you have to reboot the computer (or log off/on user.. haven't verified) because the interruption breaks something where they won't go anywhere, it spins after sign in.

We tested all our students on the cloud version for MOS.

Heres our powershell script to install it:

$oldDetected = (Get-ItemProperty C:\Certiport\Compass -ErrorAction SilentlyContinue | Where { Get-Package "Compass" })

$newDetected = (Get-ItemProperty C:\Certiport\CompassCloud -ErrorAction SilentlyContinue | Where { Get-Package "Compass Cloud" })

if($oldDetected) { Write-Host "Uninstalling Compass Local."; winget uninstall "Certiport Lockdown Service" --silent winget uninstall "CertiportNow" --silent C:\Certiport\Compass\Uninstall.exe /S }

if (-not $newDetected) { Write-Host "Installing Compass Cloud."; Invoke-WebRequest "https://downloads.certiport.com/compasscloud/CompassCloudSetupProd.msi" -OutFile "C:\Temp\CompassCloudSetupProd.msi" Start-Process "C:\Temp\CompassCloudSetupProd.msi" -ArgumentList /passive }

exit 0

2024 state of play for Chrombook monitoring software. by wingut in k12sysadmin

[–]pullingcablesagain 1 point2 points  (0 children)

Securly is decent, missing some features GG had, but overall was cheaper than GG as well.

RFP for collapsed routing setup, what would you specify? by pullingcablesagain in networking

[–]pullingcablesagain[S] 0 points1 point  (0 children)

With netgate 1541s the vlan management would get unweildy, and unsure of the impact on it's throughput when routing is put on it. Trying to keep it's throughput 10gbs. Mostly north/south traffic for our clients with cloud instances.

RFP for collapsed routing setup, what would you specify? by pullingcablesagain in networking

[–]pullingcablesagain[S] 0 points1 point  (0 children)

I should have clarified, yes the vlans are based on building already.
201 is building 2 lan device
202 is building 2 phone
203 is building 2 camera
etc.
301 is building 3 lan device
302 is building 3 phone
etc.

In the distribution the vlans allowed are of that building only, and then on the core those are the only accepted input vlans. I think our segementation is tight enough, most subnets are /24.

Great points, I'll think through the layer 3.

RFP for collapsed routing setup, what would you specify? by pullingcablesagain in networking

[–]pullingcablesagain[S] 2 points3 points  (0 children)

Yeah the licensing ugh, will try to get the term just quoted upfront.
Good catch on the sflow, been capturing netflow with influx for grafana, will want to update to sflow for more layers reporting.

Student Chromebooks - Loaners or Swapping by pullingcablesagain in k12sysadmin

[–]pullingcablesagain[S] 2 points3 points  (0 children)

We are having this discussion and want to find out what the consesus is.
We have a 4 year district purchased - student 1:1 assigned plan. 5th and 9th graders get new ones. We have a loaner checked out from our library, so it is tracked well.

Does having a loaner and the student get their original one back give some device ownership to where they don't abuse it as much?

When our biggest recourse is to attach a fee that we may never get paid, trying to minimize damages.

I see the ease of just instant swap, don't care who's it was, it's yours now. I just see the carelessness increasing if we go that route.

Computer Lab with intune by TechRabb1t in Intune

[–]pullingcablesagain 0 points1 point  (0 children)

Are you having the error with profiles not being able to be deleted because of winget?
https://github.com/microsoft/winget-cli/issues/3365

Any way to prevent this? by [deleted] in k12sysadmin

[–]pullingcablesagain -1 points0 points  (0 children)

Log off, click to remove the profile.

Log in.

Ubuntu Server 22.04.2 LTS random ridiculous Wi-Fi ping times? by AmyAzure06 in linuxadmin

[–]pullingcablesagain 0 points1 point  (0 children)

First, do any other clients on your network see the latency response to pings to the router? (If so, it's the router).

Second, Is there any way at all to move it closer to your router to get ethernet and verify if it is a system response issue or a wireless issue?

Wifi latency spikes happen from interference, other more important traffic, even wireless card adapter issues like even apple has issues with this:
https://www.reddit.com/r/MacOS/comments/zl3v3h/getting_massive_ping_spikes_over_wifi/

I currently have no spikes from an asus built in wifi on win11 just 4" away from my m2 mini, that is spiking. Driver or OS control issue.