Jump to content

KenZ

Members
  • Posts

    9
  • Joined

  • Last visited

Reputation

0 Neutral

About KenZ

Personal Information

  • Occupation
    IT Guy
  • Interests
    Things
  • Location
    Cheshire
  1. Hi allI've built an on-prem Server 2016 RDS Farm (CB, RWeb/RDGateway and multiple RDSH Servers). This has been running over 1.5 years and everything has been fine, but recently I've been told that local client printers are not appearing for users.The settings in the RDS collection is ticked to allow Client printer redirection, along with use easy print first to get around the issue of multiple different printer drivers.To see if the problem is GPO related, I moved one of the RDSH servers into an OU and blocked inheritance (and rebooted it) to stop all GPOs applying and that made no differenceIf I log on as a domain administrator through RDWeb, I see all the local client printers appearing for the session, so it's not a driver issue and the Easy Print print driver is doing it's job.If I log in to the same RDSH server (I've got a test RDSH server in it's own collection) from the same client device via the same RDWeb browser but using a domain user account instead, no local client printers get mapped.To me this appears as a permissions thing but I can't find where this might be set.I've now built a brand new RDSH Server from scratch using my notes from the original build, so it's identical, but without any applications installed, and put it in the same OU as the others so that all GPOs are applying, and that allows client printers to map successfully for domain admins and domain users. I can't see any of the applications that are installed on the original servers as causing this issue though. All standard stuff (Office, Acrobat Reader, etc)Anyone seen anything like this before and/or can point me in the right direction for a solution?The servers are patched and the AV is Windows DefenderRegardsKen Z
  2. A better solution might be to use item level targeting.
  3. Hi there are some known issues with using IKE/IPSec tunnels used by DirectAccess and NAT firewalls, and one of those is with SPIs (e.g. https://www.networkworld.com/article/2288666/chapter-4--common-ipsec-vpn-issues.html?page=6) My view would be that with the increased number of users using DirectAccess via your LEAs firewall, this has caused additional event log messages which has triggered the DA console to generate this warning. There may be a way to either increase the threshold before this generates the warning (only putting off the issue) or disabling the warning altogether. Regards Ken
  4. Hi Yes, aware you can do that, and the issue isn't on the RD Session Host, because there's a setting in the collection for that too - BTW you shouldn't set group policies that overlap with collection settings as that generates errors in Server Manager when editing the collection. The issue isn't with sessions being left logged on the session host - those are being closed down cleanly. It's to do with the RDGateway losing track of what's what. While the session might have been cleanly logged off the session host, RDGateway is still reporting as the user being connected, days after they no longer are. Initially we got around this issue with nightly reboots of the RDgateway server, which cleared up the confusion, but for other customers that work 24x7, that was not feasible. In the end we stopped using HTML5 Regards Ken Z
  5. Hi looks like no one has answered your query, but... we've stopped using this, as we've had horrendous issues with it. users are not logging off properly, just closing the tab/browser, and occationally the RDGateway isn't registering that the users has disconnected, leaving them marked as still logged in in the RDGateway. If users are logged in for over 24 hours the RDGateway can get configured and we ended up having to reboot the server. Once we disabled HTML5 things went back to normal. Regards Ken Z
  6. Hi have you tried building two standalone RD Session Hosts, installing Microsoft NLBS and configuring a load-balanced IP address? All you need to do is connect to the LB address (or name if you add it to DNS). You can use something like Remote Desktop Commander (RDPSoft) free edition to monitor and control users. Regards Ken
  7. hi free780 Only if the Home drives are accessible from the internet... can Impero categorize photos and videos on the fly? To be honest, the reason I started this thread is to find out how other admins are "controlling" what gets stored on OneDrive when it is used as a principle storage device for coursework, and hence generally accessible from all internal devices. The same issues would generally apply to other cloud storage solutions such as Google Drive, Dropbox, etc. There must be a generally available "solution" to this problem, otherwise this is a huge vulnerability in the defences of schools as regards content filtering. What's the point in installing expensive internet content filters if the students can download the stuff from home, store it on their cloud storage space, and access it from any internal school device? Regards KenZ Regards Ken
  8. Hi ZeroHour unfortunately blocking extensions is not an option. They will need to be able to store pictures and videos onto their drives if it's part of their coursework. Regards KenZ
  9. Hi Guys since more schools are using onedrive to allow students to store files, how do you block restricted content? For instance, a student uploads a pornographic video or picture to their onedrive storage from home. The next day at school, they accesses their onedrive and the video/picture gets downloaded to the device within the school, bypassing any content filters that might be in place for normal web browsing. Once the video/picture is on the device, he can display it on the computer or email it internally. So my question is, is there any way to block content on a OneDrive account in the same way you can block content from the internet when someone uses a browser? Thanks KenZ
×
×
  • Create New...