Committee meeting - November 26, 2020

Carol Lu â¶Ä¯Ìý
Secretary to the Committee â¶Ä¯Ìý
November 26, 2020 â¶Ä¯Ìý
 â¶Ä¯Ìý
Present: Steven Bourque, Bill Baer, Erick Engelke, Paul Miskovsky, AndrewÌýMcAlorum, Greg Smith, Trevor Bain, LoriÌýPaniak, JasonÌýTestart, Greg Parks, Robyn Landers, Pratik Patel, Lawrence Folland, Don Duff-McCrackenÌý

³Ò³Ü±ð²õ³Ù²õ: Matt Verlis, Shah ChandonÌý
Ìý
¸é±ð²µ°ù±ð³Ù²õ: Andrea Chappell, Adam Savage, Daryl DoreÌý
Ìý
´¡²µ±ð²Ô»å²¹â€¯â¶Ä¯Ìý

  1. Presentation: New ONA live demo (Matt Verlis) [20 min.]Ìý
  2. Chair’s remarks (Steven Bourque) [5 min.]Ìý
  3. Approval of the minutes of the meetings of Thursday November 12, 2020 [5 min.]Ìý
  4. Registering permanent devices on the network with static IP addresses (Erick Engelke) [10 min.]Ìý
  5. 2FA transition + VPN tool (Robyn Landers) [5 min.]Ìý
  6. WVD/Azure Billing Model (Steven Bourque) [ 5 min.]Ìý
  7. Other business and roundtable discussion – all [30 min.]Ìý
  8. Next CTSC Meeting [Will be held Thursday December 10 at 1:30 p.m.]Ìý

Presentation: New ONA live demo (Matt Verlis)Ìý

  • Matt Verlis gave a demo of the new ONAÌý

Comments and discussion Ìý

  • Do you have to have a Connect email account in order to subscribe for email alerts? Ìý
  • No, email alerts will also work for Office 365 email accountsÌý
  • Can update the blue banner in the new ONA to include thisÌý
  • Can the synchronization of a switch be interrupted if you accidentally close the browser tab? Ìý
  • No, the sync will still occur however the front-endÌýprogramÌýwill not recognize that the sync happened. This will result in other users not being able to make changes as the synchronization lock will not be releasedÌý
  • GUI is based onÌý.netÌýframeworkÌý
  • There is a direct database with read-only access that will be distributed to the CTSC mailing listÌý
  • Database is on SQL serverÌý
  • Is there an option to stop the processing ofÌýsyslogs?Ìý
  • May be possible to implementÌý
  • How can users input a planned offline maintenance? Ìý
  • Users can email IST's Network Services to add a planned offline maintenance window in the new ONAÌý
  • HP switches will not be added to the new ONA; they will stay on the old ONA on a newer serverÌý
  • There are only a few switches that span across more than one building (e.g.,ÌýEV1, EV2, EV3)Ìý
  • SegmentationÌýis implemented on a building level Ìý
  • The new ONA is relatively mobile-friendly,ÌýwithÌýtheÌýexception ofÌýsome pagesÌý
  • Is there documentation or best practices for using the new ONA? Ìý
  • The comments field can be used for anythingÌý
  • Note: data jack and room are separate fields andÌýauto populatedÌýin the description Ìý
  • Do not use the description field since the information will beÌýauto populatedÌý
  • Initial workflow may be slightly different if youÌýhave toÌýinput the data jack and room informationÌý
  • Once data jack and room information is added, workflow should be relativelyÌýsimilar toÌýthe old ONAÌý
  • Please email Matt with additional feedback and commentsÌý
  • When 1.0 is ready, Matt will send an email to the CTSC mailing list to collect the names of users who need access to the new ONAÌý

Chair's remarks (Steven Bourque)Ìý

  • No remarks.Ìý

Approval of the minutes of the previous meetingÌý

  • The previous meeting’s minutes were accepted as distributed. â¶Ä¯Ìý

Registering permanent devices on the network with static IP addresses (Erick Engelke)Ìý

  •  Running into issues when registering permanent devices on the network with static IP addresses and IPv4 subnetsÌý
  • IPv4 address space is available but there are not enough subnetsÌý
  • This will continue to be an issue as Engineering 8 is being builtÌý

Comments and discussionÌý

  • IST recommends using dynamic IP addresses wherever possibleÌý
  • Dynamic addresses are more effective;ÌýdynamicÌýIP addresses cannotÌýresolve toÌýActive DirectoryÌýnames at this timeÌý
  • IST will investigate creating a dynamic DNS to match the domain nameÌýsometimeÌýnext yearÌý
  • This would be beneficial in helping IPv6 be more transparentÌý
  • Might be helpful to put printers on private subnetsÌý
  • NAT IP addresses should only be used as a last resort if you run out of addressesÌý
  • Registrations need to be managed betterÌý
  • Should come up with a way to identify addresses that are stalling Ìý
  • Science has some VLANs that are full and some that are emptyÌý
  • Unused blocks could be used more efficiently if blocks could be movedÌýor spanned across multiple buildingsÌý
  • Dynamic IP addresses are not NAT addresses by defaultÌý
  • Wi-Fi and Residences areÌýNAT,Ìýbut most addresses are notÌý
  • Contact IST Network Services if you are interested in doing aÌýclean-upÌýof IP addressesÌý
  • IPv6 inbound is blocked by default but you canÌýrequest exceptionsÌýfor server roomsÌý
  • IPv6 uses the default firewall settingsÌý
  • Pings are allowed inboundÌý

2FA transition + VPN tool (Robyn Landers)Ìý

  • Some users had difficulty locating the 2FA instructions to troubleshoot VPN Ìý
  • Most documentation available only covered the Duo app but did not cover the other 2FA options Ìý
  • The email sent to generic accounts regarding mandatory 2FA did not include the name of the generic account in the email Ìý
  • Users who have access to multiple generic accounts or mailbox forwarding rules were confused by which generic accounts were being referred toÌý
  • This confusion may have led to the low response rate; would be helpful to include the specific user ids in futureÌý
  • Math has created a tool for users to check their UW VPN connection: Ìý
  • Includes 2FA second password information and links to IST Knowledge Base articles for additional troubleshootingÌý

Comments and discussionÌý

  • Users need to accept the DUO push on their devices within 10 seconds, otherwise multiple prompts will appearÌý
  • Timeout cannot be increased from 10 seconds; 10 second timeout is requiredÌýforÌý2FA to work with Cisco VPNÌý
  • Using a passcode from the DUO app,ÌýYubiKey, or Duo token prevents multiple prompts on your deviceÌý
  • One-time codesÌýseemÌýto be more reliable than other 2FA methods Ìý
  • Voice calls would have to be disabled in order to eliminate multiple promptsÌý
  • In Safari, 'Prevent cross-tracking' and 'Block all cookies' need to be disabled in Privacy settings in order to enable the 'Remember me for 30 days' featureÌý
  • Typing 'phone' as the push method will result in multiple callsÌý
  • Cisco AnyConnect Client does not allow for the pop-up message to be shown before the user authenticates Ìý
  • The VPN articles in the IST Knowledge Base should be easier to find for usersÌý
  • The 2FA website has a lot of useful information but it could be more user-friendlyÌý
  • Duo admin page shows a higher login failure rate after work hours, which suggests students could be having more 2FA log in issues than staff Ìý

WVD/Azure Billing Model (Steven Bourque)Ìý

  • IST would like to keep the Windows Virtual Desktop/Azure billing modelÌýin lineÌýwith the À¶Ý®ÊÓÆµ Budget ModelÌýand ÌýavoidÌýdoing chargebacksÌý
  • With the À¶Ý®ÊÓÆµ Budget Model, the cost would be proportional to the usageÌý
  • /waterloo-budget-model/details/academic-support-units-costÌý[IST has requested and updated version]Ìý
  • This model would be for labs and other client-facing uses, notÌýData Centres orÌýhigh-performance computingÌý

Comments and discussionÌý

  • Does this mean an extension of the Microsoft agreement is not being pursued? Ìý
  • Multiple options are being looked at concurrentlyÌý
  • If Microsoft agrees to an extension, it will still be temporaryÌý
  • On-prem VDI is licensed for staff but not for studentsÌý
  • It is recommended to start migrating to Windows Virtual Desktop now if possibleÌý
  • In Engineering,ÌýmanyÌýsoftwareÌýcannot beÌýlicensedÌýin the cloudÌý
  • A last resort option may be to buy licenses for studentsÌý
  • Should considerÌýwhetherÌýstudents want to use computer labs at all in the futureÌý
  • In Arts the labs are not used heavily; these spaces may be modified in the future to just have ports, Wi-Fi, etc.Ìý

Other Business/RoundtableÌý

Client Services, IST (Andrew)Ìý

  • TIS and ISS have come up with a process to prevent retirees O365 and Connect accounts from being deprovisionedÌý
  • Process is a temporary solution until a more long-term fix is implementedÌý
  • Note: retirees who take the lump sum pension option are not includedÌý
  • Members have been selected for the Jira Service Management governance committeesÌý
  • Kate Wood and Daniel Allen are joining the operations committeeÌý
  • Lawrence Folland and Don Duff-McCracken are joining the steering committeeÌý
  • A communication will be sent out this week about the IST Service Desk moving common request forms from RT to Jira Service ManagementÌý

Math (Robyn)Ìý

  • Regarding the communication from IST about the removalÌýof info.uwaterloo.caÌýand strobe.uwaterloo.ca - confirmation that all important content has been moved from these systems? Ìý
  • There isÌýanÌýIST project on theÌýdecommissioningÌýof these systems, this would have been checked during the projectÌý