Jump to content

No AD Filtering with Lightspeed for now


Recommended Posts

Posted
Eurgh .. Might be worth (I know the coverage map is primarily Lancashire) contacting someone like Boundless (see my previous post) to see whether they have an option as they do FTTM (Mast) options, so may possibly be able to do something, but it all depends on what cost you're paying for that fibre line from OCL. I don't suppose (thinking out loud) you're anywhere near the B4RN project are you (b4rn.org.uk) as that could be another option, though I think they're more North Lancashire than Cumbria.

 

We're not really close enough unfortunately. :(

 

I'm resigned to the fact that we are going to be with OCL for a while longer, having said that however I've just looked at the connecting cumbria site and our exchange upgrade date has been brought forward to by the end of 2014 instead of end of 2015 now so that is looking more promising...

Posted
We're not really close enough unfortunately. :(

 

I'm resigned to the fact that we are going to be with OCL for a while longer, having said that however I've just looked at the connecting cumbria site and our exchange upgrade date has been brought forward to by the end of 2014 instead of end of 2015 now so that is looking more promising...

 

Fingers crossed for that one then - hopefully you'll know for sure before the 31st December so you can hand notice if needs be .. :)

  • 2 weeks later...
Posted

Contacted OCL today as in my last post I was told it was going to be a couple of weeks but alas todays reply:

 

Unfortunately we have no news with regards to this as of yet.

 

I live in fear now that OCL are going to announce that they have made a better AD filtering system working with lightspeed that mirrors the basic service of the NED instead of the service we use now with the lightspeed AD filtering.

  • 3 weeks later...
Posted

ITS FINALY WORKING!!!

 

Come in today and my test machine is now authenticating by itself with the lightspeed agent! Deployed it out to the entire site and its working a treat on every machine to get it so far.

 

You need to set the ID_SERVER to filter.education.btlsl.co.uk this can be done either with a transform file on the MSI or a GPP registry setting.

Posted

Hmm the log says:

 

04/22/14 11:06:11.0321 | [iDENT] OnIdentifyLogonUser: Successfully reported user information to Identification Server (filter.education.btlsl.co.uk)

04/22/14 11:08:00.0120 | [!] Update: Error 404 downloading update package info => http://filter.education.btlsl.co.uk/api/user_agent/updates/ua_update_x64.md5

04/22/14 11:26:40.0317 | [iDENT] Session change: WTS_SESSION_LOCK; SessionID=1

04/22/14 11:36:00.0439 | [iDENT] SendHeartbeat: Successfully reported user information to Identification Server (filter.education.btlsl.co.uk)

04/22/14 11:59:57.0006 | [iDENT] Session change: WTS_SESSION_UNLOCK; SessionID=1

 

Which apart from the update error tells me it got my username successfully but this doesn't seem to have been picked up by my browser (IE 11/Chrome Windows 8).

Posted
Hmm the log says:

 

 

 

Which apart from the update error tells me it got my username successfully but this doesn't seem to have been picked up by my browser (IE 11/Chrome Windows 8).

 

Odd, I just deployed it to another site and its fine here.

 

Is it still saying Unknown User in the top left of the block page?

What does the Identification History report say?

Posted
I am having an issue where my authentication source is school.local but the agent is reporting as SCHOOL\user to fix it you have to change your authentication source to SCHOOL and then replace all your assignments.
Posted
My username does appear in the log as action login but I'm still not logged on in the browser. I made sure require authentication was on and this spent about 30 seconds thinking about it and then went to the web login page (which works fine).
Posted

Very odd mines just worked fine at 2 sites now.

 

Can't think why, I'm getting entries for every IP the machine has etc...

 

My authentication settings are:

 

Require Auth: Never

Allow Users to auth: Always

Posted

I haven't had time to play with the client today but I am seeing all sorts of weirdness regarding logging on. More than once now I have seen a block screen and when I look at who's logged on it's a teacher who is logged onto a completely different computer !

I don't think it's handling the fact that my traffic is all from one IP address, but I don't see why this should be that much of an issue, it's not exactly an uncommon set up!

Posted
I haven't had time to play with the client today but I am seeing all sorts of weirdness regarding logging on. More than once now I have seen a block screen and when I look at who's logged on it's a teacher who is logged onto a completely different computer !

I don't think it's handling the fact that my traffic is all from one IP address, but I don't see why this should be that much of an issue, it's not exactly an uncommon set up!

 

OH

 

That is an issue, a big one.

 

Because the Rocket is at OCL they have just given it your CLEO range only, reporting that you are logged in as FOO on 192.168.0.23 means nothing to it.

 

I worked with a secondary who had a router and then a few 192 ranges for stuff in school and OCL said that wasn't supported at all way back before lightspeed was even mentioned.

Posted (edited)

I'm going to play with the terminal server client, see if that makes a difference.

 

* edit hmm looking at the instructions I think this idea is a non-starter.

Edited by ChrisH
Posted
Well after playing with various options on my firewall my clients all now map to their own valid intranet address which shows up in the logs and stops all the issues with the web auth getting confused, unfortunately this will not fix the client issue as they still report their internal IP so I made some progress but I think I have got as far as I am going to get.
  • 1 month later...
Posted
Very odd mines just worked fine at 2 sites now.

 

Can't think why, I'm getting entries for every IP the machine has etc...

 

My authentication settings are:

 

Require Auth: Never

Allow Users to auth: Always

 

BTLSL have now published documentation and the User Agents for download on the Schools Portal

 

I followed the guide today to configure AD integration at one of the sites i support. I've deployed the user agents, via GPO, to as many clients as i could, but was unable to access each and everyone, to ensure it was installed. Therefore i have left the Required Authentication method to Never, to allow access without an Authentication popup on the workstations which haven't had the agent installed yet. BTLSL have recommended changing the Authentication method to Require Authentication : Only when their identity is unknown . However, I'm going to need to add Exceptions for the standalone computers in our Nursery and our Photocopiers to connect online without authenticating - a job for next time.

 

Arcath - Is the Require Authentication something you plan on changing?

  • 2 weeks later...
Posted
Arcath - Is the Require Authentication something you plan on changing?

@TomTomGo not with the number of iPads etc... we have would just cause more issues than in solves with non-domain laptops etc... that staff bring in. Its also a whole tier setting so in most of our schools where the Admin machines aren't on the domain they would have to login some how every day.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...