Search This Blog

Monday, December 19, 2005

Label your equipment

I was just browsing the Extended Outreach Site Visit October 2005 Report (which answers the question, "What do E-Rate consultants do for fun?") and came upon this nugget under the Applicant Outreach section: "Applicants are not aware that they should label their Universal Service funded equipment."

Uh, yeah. Of course applicants are unaware of it; I haven't heard anything about it in any training, and there is no mention of it on the SLD Web site (except in the Site Visit reports). How would we become aware of it?

By the way, if you don't like the look of the new Web site, you can also see the October 2005 Report in the old style.

SLD Web site redesigned

The promised redesign of the SLD Web site has appeared. Of course, I don't like it. I knew where everything was, now I'm hunting around. However, the information that a beginner needs is easier to get to, so I won't complain.

One change I don't like: changing www.sl.universalservice.org to www.universalservice.org/sl/. There are bookmarks to the old address all over the place, many of them in print. And I just don't see a compelling reason for the change. And old pages seem largely to still be there, and do not send users to the new page, if a new one exists. (For example, www.sl.universalservice.org/apply/step2.asp does not send the user to www.universalservice.org/sl/applicants/step02/technology-planning/default.aspx.) Now they'll have to edit every old page to make it send users to the new pages.

The Search tool seems to work a lot better. However, the text boxes blend into the header a bit, and when you go to the "Search Tools" page, there is no mention of the Search page or the Advanced Search page.

Wednesday, December 14, 2005

FCC OIG report

I just browsed the FCC Office of the Inspector General's semi-annual report. It's not that enlightening, but at least it's short. Two things interested me:

First, the only audits completed were of 3 Catholic schools in the Virgin Islands, and it looks like they're going to get back something like $500,000 total. I have two problems with it.
1) OK, the schools did a bad thing back in the year 2000 (it looks like maybe they tried the old bill-the-SLD-90%-and-never-pay-the-rest scheme), but the each school has between 92 and 250 students, so a fine of $130,000 is likely to be the end of those schools. Meanwhile, the gain to the program is only $500,000 (minus the cost of the audit), if they are able to take it out of the hide of the little schools.
2) Virgin Islands. Hmmm.... Why not investigate a school in, say, Maryland?

The second thing thing that interested me was the list of ongoing audits. A few observations (please note, I just did quick counts, so I could be off on some of the numbers):

106 audits by my count, 101 being done by KPMG.
Here are the top 10 states in population, listed in milliions, along with the number of audits:
StatePopulation (millions)Audits
CA3417
TX2119
NY195
FL166
IL121
PA120
OH112
MI102
NJ82
GA82
NC80
VA72

Meanwhile, South Carolina, with 4 million people, has 5 audits. I don't want to draw any conclusions, since it's not a very complete sample. But I were a district in TX not currently getting audited, I'd count my lucky stars.

I'd like a little more info on each investigation: When was the investigation started? What funding year is under investigation? How much funding is under investigation? What I'd really like to know is why each investigation was started.

The FCC floated the idea of requiring regular audits for the largest applicants, and the large applicants were understandably cool to the idea. But they're already on the list: NYC, LA, New Orleans, Detroit, Boston to name the first that struck my eye. I'm glad to see that they're not only going after small schools on tropical islands.

Monday, December 12, 2005

A use for VPNs

I was reading a magazine for network professionals and I thought of a use for VPN hardware that a lot of schools could use: securing wireless networks (WLANs).

Many wireless networks are secured using a VPN, since it provides more robust security than WEP, WPA and the other 802.11 standards. Security-conscious network administrators make all wireless connections go through a VPN concentrator, which means all devices connecting wirelessly would need VPN client software installed.

The central hardware necessary to create a VPN on your WLAN would be eligible as long as you're only using it within an eligible location. So if you're looking to buy a VPN server, VPN concentrator, wireless gateway, firewall or other security appliance to lock down your wireless network, it should be at least partially eligible for E-Rate funding.

Wednesday, November 23, 2005

Careful with your VPNs

The new Eligible Services List says VPNs are eligible. Great! Except that you still can't use VPNs for most uses. The two most common uses of VPNs are not eligible. Take a look:

1) You say VPN to a network engineer, the first thing s/he'll think of is creating a virtual link between two locations by sending encrypted packets across the Internet. Now eligible? Hold on. The definition of Telecommunications in the ESL, from 47USC153(43), is: "the transmission, between or among points specified by the user, of information of the user’s choosing, without change in the form or content of the information as sent and received." So a point-to-point VPN is a telecommunications service. The service runs over IP, and the ESL says: "IP-enabled services are...not eligible for funding." So a point-to-point VPN looks ineligible to me.

2) The next use a network professional will think of for a VPN is remote access to network resources. However, remote access is allowed only from eligible locations. So it may be that if someone in School A wants to use a VPN client to connect to a VPN concentrator in School B to access School B's network resources, that would be eligible. Except that I'm sure the SLD would say it's only eligible if the person in School A is making the connection in order to use School B's Internet connection. (Take a look at the new rules for Terminal Server.) So the person from School A would be sending encrypted packets out of School A's Internet connection to School B, where they are unencrypted, sent out over School B's Internet connection, and then the response is received over School A's Internet connection again. I can't imagine a scenario where that architecture makes sense. A^Net^B-Net-B^Net^A (where ^ is an encrypted (VPN) link, - is an unencrypted link).

At a recent conference I did talk to a district that may have hit on an actual allowable use for a VPN. They have a leased fiber WAN set up as a loop throughout town, and some non-district sites are on the loop, so they'd rather their traffic over the WAN were encrypted. I think the equipment they'd need to set up that VPN would be eligible. (If they can get Priority 2 funding, which may be tough given the super-priority of Katrina-affected applicants.)

I voiced my concerns to Phil Gieseler, the eligible services guru at SLD, and I hope he'll come out with a clarification soon.

Window crashing in

Still nothing on the SLD Web site this morning about the Eligible Services List being released. Could it be that the SLD was as surprised as I was that the FCC essentially said, "We know we promised to give you 60 days notice of the opening of the window so you wouldn't be blindsided, but instead we're giving you 3." (7 calendar days, but only 3 working days for schools.)

What will USAC do? Apparently they aren't required to open the window on Dec. 1, but if I were over there, I think I'd do what the FCC wants.

I'm steamed. The FCC sits on the ESL for 3 months, then waives their own rule about warning, and not in a small way. The rule says 60 days, they give us 8 days. They reduced the period by more than a factor of 7. That's like an applicant saying, "I know the application window was only 70 days long, and it took me 500 days to get my application in, but hey, I was really busy, so could you please waive your rules and let me submit this application a year and half late."

I'm expecting a drop in the number of applications, though Katrina may raise the dollar amount requested.

Tuesday, November 15, 2005

The PINs are coming! The PINs are coming

Whew! In a dramatic shift from their normal terseness, the SLD is barraging me with notifications that I will soon be getting PINs. In trainings, in newsletters, in emails and now in a stack of letters, they're telling me that the PINs are on their way. OK, OK, I got it. My client database has a "PIN" field ready and waiting. Now send me the PINs.

I did get one piece of new information in the latest notification: on Dec. 5th, existing PINs will no longer work, and the new ones will.

It's also nice to know that the PINs will be mailed to the certifier (me) at the contact person's address (my office), rather than to the certifier (me) at the billed entity's address (as the quarterly reimbursement reports are, creating confusion in mail rooms at client districts). Of course, it would be nice to have the PIN mailed to the certifier at the certifier's address, but at least the current redirection works for me.