Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

_techie_

Members
  • Posts

    434
  • Joined

  • Last visited

Everything posted by _techie_

  1. You have to tag every VLAN you want to use on each access points port on the switch for traffic to flow, not just the controller. The APs are the RADIUS clients, not the controller. I put my APs on their own VLAN too so that's untagged. Unless you are using the Guest portal feature the controller can be powered off. We leave ours running because of this plus it provides some monitoring. The controller really is a configuration push-er.
  2. Hi. Thanks for replying. I'm assuming that with Office 365 your talking about the office suite only and not use of one drive/exchange online? I'm guessing the issues you faced were around shared computer activation, and learning about the change in managing updates? Do you have static computer suites/labs as well?
  3. Hi. I'm currently doing things in an old fashioned way, but they seem reliable, and we often get compliments from PGCE students about how good our systems are compared to other schools in the area. Windows Domain with DFS, GPO and network mapped drives. WSUS and WDS on separate VMs. (Sat on a Vmware vsphere essentials 3 host cluster including mostly file storage. Backups to NAS using VEEAM). Exchange on prem in hybrid mode for use with Exchange Online protection. Smoothwall providing web filtering, HTTPS Inspection and firewall. PDQ Deploy and Inventory (Deploy doing package/app deployment). Perpetual Office 2016 on Windows 2019 Enterprise LTSC, maybe looking at Office 2019 next summer to align with our increasing Mac AD joined estate. Papercut with some pull me printing in place. ABtutor 8 Citrix XenApp 7 1808 for thin clients using Ncomp N500 and Chromebooks in kiosk mode. Some services moved to cloud hosting: planet estream Library (Accessit) Mosyle MDM for MacOS and iOS management using Munki for non VPP app deployment. Google classroom with SSO using ADFS 3.0 Only a few minor compaints from a few staff about lack of storage space for files and emails. Always get told I shouldn't be using LTSC for production but every time I look at edu, it doesn't seem to offer anything over and above what LTSC offers apart from one or two tiny features (sticky notes, Metro photo app that allows printing of photos onto A4). Convince me to start using SCCM/Config manager. Seems like a sledgehammer to crack a nut in my honest opinion. Im already covered in most respects by PDQ, WDS and WSUS. Any other suggestions welcome.
  4. I'm having issues deploying 2004 out from WDS 2012 R2 - giving me an issue about joining the domain. 1909 works fine however. This is on old kit (9 years old). Any ideas? Haven't really had time to look at it yet but 1909 works fine, joins the domain and does its job. Not really fussed to be honest, as we have a working and stable Enterprise LTSC 2019 rollout.
  5. GREEAAT, that works perfectly! What does this behaviour do differently to the normal Allow Transparent HTTPS Compatible sites? I'm interested in how this works and whether I should be allowing it or not? Thanks,
  6. Hi. I'll give that a whirl and see what gives. Cheers Mark
  7. Nope, set to allow Transparent HTTPS compatible sites for that location on the transparent.
  8. Still the same issue with the room loading and getting stuck, grr how frustrating! Still same https://IP Address issue when the room is loading!
  9. Hi. Just checked the IP against the HTTPS inspection policies. I had forgotten I had recently changed the IP of this PC, so the range wasn't included in the HTTPS inspection policy, to do not inspect. Just updated this, and will come back to you. Thanks,
  10. Hi. Yes, this is using proxy settings set in the browser. However, I have also set an "Ident by location" on the IP range/CIDR that the PC is sitting on (this is mainly to deal with Teamviewer requests) to match the users Group. The user group is set not to inspect on HTTPS traffic (so this should allow the PC through without inspecting too). The issue seems to stem from a rotating https non compatible site IP that changes each time the adobe connect meeting is launched. I'm baffled on this one to be honest.
  11. Hi. Trying to resolve an issue with Adobe Connect, STEM Learning, and Hosting a meeting using the Adobe Connect App. I have basically given everything I can give to the user who needs this (including removing HTTPS Inspection for the user and PC). This is without bypassing Smoothwall itself via 4G - my backup plan. The issue seems to be when trying to launch a new adobe connect session (using the app) and haults at about 80% at 'preparing room'. Deploying the app worked fine by the admin MSI from Adobe (it seems the version we are on is: 20.10.26). Running the diagnostic afterwards: Test Meeting Connection passes without issue. I have added in adobe.com and adobeconnect.com to our Exceptions URL's list on Smoothwall to remove some 407 errors from the PC's IP address, but so far no joy. The only thing I can see from the web-filter logs seems to be a few https://IP Address here entries, which keep changing. I keep adding these into the https transparent incompatible sites category, but no joy so far, as they keep changing. About to try with a laptop, and 4g hotspot, so here goes. Anyone else struggling to get STEM Learning and Adobe Connect to work? Cheers
  12. Hi Ben. Yes I'm already there on the provisioning network/SSID and have already set one up for us to use on one AP, with a basic PSK. Its how I setup the remaining items that is causing the issue, particularly the requirement to use ADFS (so a startup network connection is required to access the ADFS connection, or am I overthinking this?). Is it possible to push RADIUS auth to ident on Smoothwall, or do I just need to use connect for chromebooks? I can easily push out the required certificates for SSL inspection etc via Google Admin console. Regards
  13. Turned out to be an issue with the vNic dropping random pings. Managed to get a new vNic added and back up and running within the hour. Thanks for your help though, learnt a lot in the last few days.
  14. Exchange 2013 CU 23 on-prem slowness with outlook 2016 on Windows 10 LTSC 2019. I'm struggling a bit at the moment with slowness of Outlook 2016 on on-prem domain joined machines. Slowness occurs during outlook loading and when navigating the application. Takes around 45-60 secs to load the application. Occurs with most staff using mandatory profiles using outlook in non-cached mode (online with exchange). If I enable cached mode to test, loading times improve to around 10-20 secs and using navigation (now usable). If I stick with non-cached mode, using outlook in safe mode, the app loads in around 6 seconds. But navigating around is still troublesome with frequent hangs of the application. Only changes of late are to: 1) Enable MAPI over HTTP on the exchange server (to remove a prompt for password that was occuring when loading outlook). 2) install .net 4.8 on clients and on exchange box. 3) update ESET security product on clients and exchange box. Any ideas as to what's happening/causing slowness? Cheers
  15. I have been given the task of setting up the wifi for a 1:1 chromebook scheme, for use for students in and out of school. We have an existing Windows network of PC's. We have Unifi and NPS Server setup, with WPA2 enterprise setup (currently using MSChap with a single AD account for shared chromebooks, used as Citrix Thin Clients in Kiosk mode). We also have to use ADFS as the windows computers will still be in place (I don't want to use the Google domain password sync, and install that tool on my domain controllers). SSO is in effect on our windows domain PC's by enforcing auto sign in to our ADFS URL. SLT have requested that we have safeguarding/tracking in place on the chromebooks, so I will need to put the HTTPS certificate and a proxy settings onto the chromebooks (I know you can do this through the g-suite admin console). I can add the HTTPS cert, and proxy settings, and connect for chromebooks extension from g-suite, but my question is: So how do I connect the students usingto the internal wifi network WITHOUT MSChap? If I use EAP-TLS and a certificate, how do I get the user certificate onto the device without an internet connection first using Wifi? Any help would be good with this, as I don't have anything in place for this issue. Cheers Mark
  16. Hi. We have a classroom suite of iMacs that are bound to the domain. Safe to say most settings for students are applied, and the system is mostly reliable and we have a good handle on MDM setup (using Mosyle). Upon login for students their home drive is mapped, dock is set and system appropriately locked down. My main issue is backing up of students iMovie Library projects and media. Even if I had sufficient server space on the Home Drive SMB shares (Windows Server NTFS Shares), the iMovie project runs so badly across the network, the application is unusable. Aside from putting in symbolic links for documents, downloads, and desktop, I still can't really use move the iMovie Library files, as they are too I have investigated using Apple school accounts and enabling iCloud drive, but this doesn't back up the iMovie Libraries (as far as I am aware). Not too sure how well this works in a shared lab environment either. Any real solutions out there (or just use something else, other than iMovie?) Thanks Mark
  17. Struggling to get Win10 shared laptops to connect to WPA2 enterprise via RADIUS (NPS). I need to have the laptop connected to WiFi at boot/pre login as it will be shared by many users. Trying to use a public wildcard cert, and have setup a DNS zone for public namespace. I get correct DNS response. Cert chain and key is installed on NPS server and deployed to trusted root cert authority on Windows 10 client by GPO and can see cert on device. Am I doing something wrong or is this not possible...?
  18. Yes I’ve already setup the proof of concept with a single session host on VMware running server 2019 via the RDS Gateway and enabled web client too to run on a chromebook. Only have to open 443 on the firewall for the web client to run. It’s just the individually assigned VM’s vs Physician hosts I’m querying now... I don’t think you can do RDP access to a single machine using a collection on the RDS broker, but that was my question.
  19. Yes it’s just for remote access. We set this up temporarily for a few staff using our current XenApp, and creating an RDP file per user to double hop, once logged onto Citrix as they had specific software we didn’t want to install on our XenApp session hosts. Not ideal by any means. O I did a trial of XenDesktop and you can install the Citrix VDA on physical machines and present them in Storefront. I didn’t want to open up port 3389 to the internet you see by using direct RDP access.
  20. Hi. I recently setup a proof of concept RDS farm, which was fairly successful to move away from Citrix as a possible cost saving. I am looking at dealing with possible 1:1 VM assignments for our office/admin staff, and was wondering if anyone had setup RDP connections in the farm to physical endpoints. I know you can do with this with Citrix, but can't seem to find out with RDP. I know you can do Virtualisation hosts and individual VM's on that host, but that will require us to buy some new hardware! also, can you only run a virtualisation host on Hyper-V? We currently ran the Session host on vmware, which was fine. Any ideas? Thanks Mark
  21. Hi. We are replacing our Wifi system with Ubiquiti and have some shared chromebooks (acting as Citrix thin clients using Kiosk mode) that I would like to auto connect to the Wifi automatically at boot based on a device certificate. This method I would also like to be used going forward for any shared iPads and Windows laptops that are school owned and managed. I have got most of the Ubiquiti system setup including: 1) Wifi Windows VM with Unifi management software running to manage AP's. 2) NPS Server running on MS Server 2016, with successful connections using PEAP/MSChap and an on-prem AD Account to join the Chromebook to the wifi (without a certificate - something I'm not too happy about). The device is joining the appropriate VLAN and gaining an IP and basic transparent proxy internet access (needed to allow me to manage the devices via the Google Admin Console). I have successfully pushed out the MSChap settings from the google admin console to the laptop, and its connecting to the wifi fine. 3) A wildcard certificate on the NPS Server (but no PKI or local CA on-premise). No need to filter the devices per user, as they are connecting to a citrix farm which uses AD based web filtering by smoothwall, post login at our Netscaler. I am only unsure about what to be using for the identity field for EAP-TLS (and why its required for the device)? I can see the wildcard cert I am using and have assigned to NPS is also being pushed down to the chromebook by the Google Admin Console (its under Chrome://certificate-manager. I have setup a network policy on NPS that specifies smart-card or certificate but I simply cannot get the Chromebook to connect manually when using the EAP-TLS method. I just get network connection error. The Chromebook isn't domain joined in anyway, only enrolled in the Google Admin console. Any ideas as to what I'm doing wrong? Thanks
  22. Hi. Looking at the future of Win10 in our environment, looks like it will be with us a while. I've gone down the on-prem LTSC 2019 route here as we don't buy bulk Windows laptops at all really, and the odd ones we have are kept on site for projector trolleys. All data is held on site, apart from users starting to use Google Classroom more since COVID-19. For remote working, we just provide Chromebooks to staff for remote working with our Citrix system in Kiosk mode with no local data stored between sessions. We also haven't purchased any new PCs in bulk, since 2016 (Intel NUCs) and they are all shared devices in classroom labs with mandatory profiles, onsite WSUS and GPO managing everything. Right now we have a stable and working system. Has anyone moved over to Intune to manage school devices, (which seems to renaming to endpoint admin). I have been researching Autopilot, and Intune for education. Intune seems to lack some of of the fine tune control that we have with GPO ATM. I had to build a Windows laptop yesterday and it took up most of my morning due to a specific application that the Chromebook wouldn't work with (Adobe Connect). Just feeling that this process could be streamlined by Azure Hybrid Domain join and Intune. It's only a basic setup really: office 2016 with Mak key, bitlocker enabled OS Drive, Citrix workspace app and a local user account. Comments/thoughts!
  23. Hi. We are possibly considering moving to a school owned 1:1 device per student plan, due to a few things. This is mostly however that our new Y7 might not be in school and we need to provide some kind of school system that they can use in school. We already have managed Chromebooks in school, so just expanding on this slightly with the new intake. I have done some work on delivering this to students but just needs refining. My questions are: 1) do we enforce timed hours of use (not useable between 10pm and 7am?) 2) do we setup connect for Chromebooks using Smoothwall so that a filtered connection and reporting/safeguarding, even when at home? 3) offer a choice of devices to give done options? 4) deal with: a) Johnny forgot to charge his Chromebook, can he have another one? b) Johnny sat on his Chromebook last night can he have another one? etc etc Thoughts and experiences please?
  24. Yes followed that to the letter. Did a bit more testing last night from home, seems the device I am testing on, never got the planned support for Android Apps (Asus C201PA). Its one of our oldest devices, and support stops this summer (June 2020). I guess we will continue using them for basic Citrix access on site, using the HTML5 receiver. Thanks for the link though, the steps are clear enough.
  25. Hi. I can manage the user experience for students signing into their personally purchased chromebooks including, open tabs, setting homepage, and adding managed favourites, as well as other great settings. I can also push Android/Play Store apps (such as Word, Powerpoint, Excel, and Outlook) to personal devices, when they are signed in with their organisational accounts, to these personal devices. Great! Am I missing a trick when trying to use an enterprise enrolled Chromebook device, and a student school account. All the other settings come across, including the bookmarks, and homepage, yet the Play Store Apps don't appear. I have allowed Android/Play Store Apps to be deployed, and they are assigned to the same user(s), but when logging in as a managed student account to an enterprise device, those apps never appear, even with a few reboots. I can see the device checking into g-Suite admin, so its definitely picking up policies. Is this some kind of Google "thing"? I seem to remember an email from Google about stopping enterprise apps, but it was a while back, and we weren't using chromebooks in force then. This is just something I am trying, as a possible way of providing managed chromebooks to students. I know the obvious answer to this, is to use Google Docs/Slides/Sheets and managed assignments in Google Classroom, but we need a stop-gap until that happens! Oh, moving away from a completely managed Windows network with Microsoft Office, and using Google as a VLE is fun to home learning. I was just tasked with making this work when in school, oh well. Anything you can tell me would help, so I can write this off as limitation of how enterprised managed chromebooks are supposed to work, or we need to update our procedures. Personally, I think this is way we should be working, but its a massive shift in how the school will operate. Cheers Mark
×
×
  • Create New...