_techie_
Members-
Posts
434 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by _techie_
-
Exchange 2013 hybrid O365 - smtp outbound issue
_techie_ replied to _techie_'s topic in Enterprise Software
Think I might have found the issue, if I try and telnet to "our-domain.mail.protection.outlook.com", I get redirected back to our Smoothwall UTM box on ESMTP Anti-spam!!! I'll try turning off the anti-spam and relay before sending out again after changing the MX record... Cheers! -
Exchange 2013 hybrid O365 - smtp outbound issue
_techie_ replied to _techie_'s topic in Enterprise Software
Hi. Can I just check how you have your send connectors setup on your on Prem exchange, and inbound to O365? Also your accepted domains for on-prem and O365? Also your MX and SPF records (on your Public DNS) would be good too. Cheers _techie_ -
Exchange 2013 hybrid O365 - smtp outbound issue
_techie_ replied to _techie_'s topic in Enterprise Software
Hi. Yes going through Smoothwall Box, Port 25, 465 and 587 (as well as HTTPS) all open to Exchange Online IP's from our on Prem exchange box. Screenshot for firewall rule and queue attached... -
Exchange 2013 hybrid O365 - smtp outbound issue
_techie_ replied to _techie_'s topic in Enterprise Software
Right, ran a few tests again, and the message queue itself is in a retry state, but all messages held within the queue are in a ready state with SCL of -1. The last column titled error is again blank with nothing showing up. -
Exchange 2013 hybrid O365 - smtp outbound issue
_techie_ replied to _techie_'s topic in Enterprise Software
Hmm yes I have a few times... also added in a second send connector with O365 as a smart host for all other public mail (e.g. *) -
Exchange 2013 hybrid O365 - smtp outbound issue
_techie_ replied to _techie_'s topic in Enterprise Software
Hmmm didn't really look at that! In the log for the messages that are getting stuck leaving on Prem exchange, the "last error" is empty. I have tried updating my SPF record slightly to include the protection.outlook.com part... still no joy though. I am not using the UTM relay at all, just trying to send out from On-prem exchange through O365. Incoming mail is working fine from public and O365 mailboxes into on-prem exchange, just not outgoing... I'll try a bit later and see if I can see any error in the queue... -
Exchange 2013 hybrid O365 - smtp outbound issue
_techie_ replied to _techie_'s topic in Enterprise Software
So you went straight to full O365 mailboxes, no on premises mailboxes? Cheers -
Exchange 2013 hybrid O365 - smtp outbound issue
_techie_ replied to _techie_'s topic in Enterprise Software
Currently, yes (our UTM box). Part of the project is to move away from that relay and use Exchange Online Protection. After changing the MX record, the old send connector that points to this relay is disabled on Exchange On premise. -
Hi We are moving away from our current mail/anti-spam system due to it being removed by the vendor. I have setup the following: Exchange 2013 CU 21 Ran Azure AD Connect and users synced correctly with Hybrid Exchange Mode enabled in Azure AD Connect. We are using password sync for O365 currently. Current Certificate (wildcard) in use and valid. Its using the new SHA256 that's compatible with Google Chrome v70 and above. Firewall IP's for Exchange Online Protection and Port 25 open to those EOP IP's inbound and outbound on the firewall. Run Hybrid Exchange Wizard. Wizard created connectors on Exchange On-Premises and on O365. Validated outbound from O365 to On Prem connector is working in Exchange Admin Center on O365. Send connector for On-Prem to O365 using direct MX lookup (NOT SMART host). Test prior to full migration Send connector for existing relay and outgoing SMTP disabled. MX records and SPF records changed to ones provided on O365 (but not autodiscover) and mailflow then tested: 1) O365 mailbox to public (iCloud) is WORKING and vice versa. 2) O365 to On-Prem is is working, but NOT Vice Versa - outgoing mail from On-Prem to O365 or Public (iCloud/GMAIL) is not working. Its not even leaving the On-Prem Exchange box and is sat in the queue with Retry. The queue message is attached to this post for perusal, but it doesn't even give an error! I can't even see anything hitting the firewall/filter for this from our Exchange On-Prem IP. Some brief research meant I tried adding in an additional Send Connector for public mail flow (via O365 as a smart host). I have even tried disabling and enabling the internal relay option on Accepted domains on O365, but to no avail. This makes me think its something to do with my send connector on my on Prem exchange, but what? Any ideas, I'm stuck on this one!
-
Consistently poor experience with EXA Networks
_techie_ replied to epoch_roots's topic in Internet Related/Filtering/Firewall
Agree with localZuk here... buy feed from Exa and then provision your own filtering solution from someone else. We use EXA and Smoothwall UTM. Can’t fault EXA tbh. Smoothwall do cloud filtering if that’s your option.. -
I am in a similar position to ITGURU here.... but having moved away from LA based Internet provision to an external supplier (EXA) with a direct connection, cloud services are now a real possibility. I can see where a number of points from both sides, and we use internal email hugely more than external email... and losing your internet connection (if going fully O365) would be bad news for heavy users of internal mail! However with EXA we do have a backup ADSL link that could be used for basic services, that falls over automatically so everyone going to O365 probably wouldn't cause that much of an issue. We also have SLA with EXA for under 1 hour downtime or compensation would be due to ourselves. So far we have only had 1 outage and was resumed in under 1 hour in 18 months of the agreement. Currently we have just provided mailboxes to all students, even after raising it as discussion points for the past few years as a necessary need to educate students in the appropriate use of email, along with a move away from Moodle to Google Classroom as our choice of online learning platform. For me, the biggest change to moving to cloud services, was the reliability/failover/support of our broadband speed and reliability, as well as control and monitoring over the firewall. Moving away from LA Broadband was the first step in going more cloud based. Our next stop is moving to a hybrid spam filtering through Exchange Online Protection as a first step, possibly moving student email boxes over to O365 (without the need for backing them up). We may also move archive mailboxes for staff to O365 as well. I feel quite uneasy with moving to O365 fully just yet, without some kind of provision for backing up of staff mailboxes (especially finance and admin teams, and SLT). We use VEEAM for backups and whilst this is great with on-prem exchange currently, the costs to buy O365 backup for VEEAM is cost-prohibitive as of yet (yes thank you UK GOV)... as we would need to buy additional licenses to facilitate this. We have purchased Exchange 2013 a few years ago so not a massive cost. If the user experience is currently better with on-prem for ITGURU, he is probably better to do this for now, until he sorts his LA/Broadband provision out, as well as the possible backup issues (which maybe a policy/requirement of his school)... I would agree with Michael's post and KK20 too. Solve your internet latency issue first, this seems to be causing the biggest issue. You may also save cash too, as moving to EXA Saved us significantly over the LA over a 5 year period. Our current issue with downtime really exists around the potential power failure/power cut scenario as this then means that all computers, and services are out of use (kind of balances itself out if you think about it!). I'll let you know how I progress with EOP implementation, currently about to move MX records during the Xmas break! Wish me luck...
-
They did via an email... I'll try and dig it out and post the content... - - - Updated - - - Important notice about your Anti-Spam Dear customer, We are emailing to inform you that Smoothwall intends to sunset the on-premise email Anti-Spam component on January 31st 2019. For customers who are currently using this product, we will offer a free of charge upgrade to our new cloud Anti-Spam solution, powered by Mailroute. This will cover the life of your current contract. Smoothwall will continue to support an on-system mail relay for at least the entirety of 2019, however the Anti-Virus and Anti-Spam capabilities will be disabled. Our partnership with Mailroute allows us to offer a much more complete product, which is easier to use, and offers significantly better levels of protection. We understand that our on-premise Anti-Spam is only just capable of keeping up with today’s most sophisticated spammers. So faced with a choice of diverting investment from our core mission: safeguarding young people, and a partnership with an exceptional organisation like Mailroute, this was a natural decision for us. For customers identified as still using the Anti-Spam product, we will be in touch by the end of November. If you haven’t heard from us by then, please open a support ticket. Yours sincerely, The Smoothwall Team
-
Hi. Having been playing around with LTSC 2019 1809 in the last few weeks, I have come across a few issues. You need to create a specific StartLayout.xml new file based upon LTSC 2019 1809. The startlayout.xml file assigned via Group Policy will probably contain %ALLUSERSPROFILE% paths. The shortcut files (*.lnk) need to be in this location, as well as in any redirected desktop location if this differs from C:\ProgramData\Microsoft\Windows\StartMenu\Programs... and you have the GPO: Remove Common Program Groups from the Start Menu is enabled. If your using default network profiles, or mandatory profiles, any start menu customisations are forgotten. You need to specify the Start Layout file is readable by users (mine xml files are located in NETLOGON, on the domain controllers). Anything else, just ask, and I will test for you. Cheers Mark
-
Hi, We have been given the notice that Smoothwall will be withdrawing their Anti-Spam product on UTM that we currently use. I am now going through the process of moving away from the Smoothwall Spam filter to Exchange Online Protection, as part of our current O365 subscription. I have come across an odd issue with getting mail flow to work outgoing via EOP from our on-premise Exchange 2013 CU 21 box. I have used the Exchange 2013 Hybrid Wizard in full hybrid scenario. This has worked fine and has created the two send connectors on Exchange Online. Mail flow is currently working fine in the following scenarios: 1) O365 mailbox to Public outgoing (e.g. to iCloud.com/gmail.com addresses) 2) O365 mailbox to On-Prem Exchange Mailbox 3) Validated send connector from O365 to On-Prem and mail is flowing as per step flow. I have an outgoing firewall rule that allows SMTP/SMTP over SSL and SMTPS from On-prem exchange IP to MS O365 Exchange Online IP's. I have port forward that allows SMTP/SMTP over SSL/SMTPS from MS Exchange Online Ips on Port 25 into On Prem Exchange. I am now stuck at moving away from sending outgoing mail via Smoothwall UTM Mail relay. Even quick testing with an existing send connector to O365 from OnPrem does not work... How are everyone's send connectors on their On-Prem servers configured to route outgoing mail? Using a Smart host config or via MX record. I am nervous about this step, as I do not want to change my MX and SPF records until I am comfortable mail is flowing out via O365/Exchange Online, to O365 mailbox from OnPrem and all the way through from OnPrem to Public Mail services. Obviously now incoming mail will flow from Public Mail servers until I change the MX record... :-) Any help please.
-
[ltsb, 1607] Changes to Folder redirection not applying, after altering GPO
_techie_ replied to _techie_'s topic in Windows 10
definitely not DNS, both fully qualified and short hostnames of the server respond from the host/endpoint PC with the issue..... Its also not one PC thats the issue. Plus im using %HOMESHARE% in the GPO for the folder redirection, which isn't responding in RSOP after subsequent logons. First time logon is showing up folder redirection logs and RSOP is responding correctly. subsequent logons show nothing, not even an error, like the actual event of folder redirection isn't taking place. pinging said host from Domain controllers also works! Odd one this! - - - Updated - - - definitely not DNS, both fully qualified and short hostnames of the server respond from the host/endpoint PC with the issue..... Its also not one PC thats the issue. Plus im using %HOMESHARE% in the GPO for the folder redirection, which isn't responding in RSOP after subsequent logons. First time logon is showing up folder redirection logs and RSOP is responding correctly. subsequent logons show nothing, not even an error, like the actual event of folder redirection isn't taking place. pinging said host from Domain controllers also works! Odd one this! -
Using Windows 10 1607 LTSB here with latest CU installed. We are running 2008R2 DC's. Admin templates applied to SYSVOL and replicating. Windows 10 Users have following folders redirected: Desktop (UNC Path) Start Menu (Local Folder) Documents, Vids, Pics, Music, Favourites all to home directory (Path populated and mapped in AD). Maps at logon. Local Profiles (Profile path in AD not populated). No Appdata redirected and these users do not hot desk, so not really an issue. No fancy WMI filters or scope groups (just Authenticated Users). No system centre, nothing like that. Upon first logon to machine with clean profile, folder redirection occurs fine and event viewer and RSOP show this as working! Recently moved from 2008R2 File Servers for Desktops and Home Directories Home Directories changed in AD and applied immediately at logon. Changed desktops last night, and upon login this morning, the old path is still stuck in the profile for the desktop. I have since tested this on a new logon and it works fine, so perms are fine. Upon deletion of the broken users profile and retry, its working fine, and again I can see that folder redirection is working and to the new location fine. No other changes made apart from deleting the local user profile. Why is folder redirection only applying once? Anyone else seen this? Subsequent logins don't even show folder redirection applying in eventvwr. RSOP shows no folder redirection entries at all (even though its clearly working as I can test this by placing temporary txt files to the users redirected desktop...) Bizarre. Any ideas?
-
[ltsb, 1607] Folder redirection failing on second login?
_techie_ replied to LRSFC_DanJ's topic in Windows 10
Same issue here. 2nd login doesn’t even show folder redirection occurring in eventvwr if local existing profile on PC. If I delete the profile and user logs on again it re-applies fine. Seems some kind of optimised logon is occuring. I’ll keep playing and come back to you!- 3 replies
-
- folder redirection
- group policy
-
(and 1 more)
Tagged with:
-
Hi both. Was only running classic start menu, not explorer or the other components, and still had issues. Only running local profiles and still experiencing these hang ups. Only certain staff complaining about explorer issues but removing classic shell and going back to built in Win10 menu have stopped the build up of explorer threads which was causing the issue. Have decided to pull the plug on it now as not being able to configure CS means it’s a no go on Citrix as we run XenApp so need to remove the shutdown button. So far apart from the poor appearance of Win10 menu, I have managed the following: Removed ability to shutdown or restart the PC/Citrix Prevent any messing about and customisation of the start menu and tiles Redirect to a read only folder on the local PC for users (separate for Staff and students). I have populated this via preferences or at install of apps. I am now working on search results and controlling indexing via GPO to limit this to the Start Menu only for pupils to stop them wandering off into Windows etc Hope this helps!
-
Hi. Been rolling out in a small scale Win10 LTSB 1607 to our Admin, "Non-hot desking" offices. Everything has been going as planned with the exception of the start menu! I had classic shell rolled out and working with a combination of the ADM templates and the registry key settings, but some users have reported issues with the dreaded explorer.exe thread counts going through the roof (identified through resource monitor) causing their machines to hang momentarily. Only solution was to close explorer if possible, or a force remote logoff and back on again to reset explorer.exe Testing has shown that any configuration of ClassicShell Start Menu has been causing the issue, with explorer threads waiting and remaining open. Removing any classic shell start menu config via registry or ADM templates has resulted in stability. So far I am fairly happy with this and my admin users are now not moaning at me, however it leaves me with a very unlocked start menu (not really suitable for students or even teaching staff!) So where to go? I have managed to get a standard Win10 LTSB start menu that is fairly locked down now, which is suitable for students. We also use Citrix, so I am now considering my options for these Office users to login and get a working start menu, without letting them shutdown the XenApp server, without configuring the start menu using Classic Shell. I tried applying s start menu layout and settings to LTSB using Group Policy: 1) Create layout as appropriate on PC 2) Export Layout using powershell ExportLayout and XML file created. 3) Apply Policy to Start Layout pointing to created file in readable location, but my settings don't seem to apply! This in terms of the icons applied to the left hand side of the menu itself. I didn't pin any items to the start tiles... Yet to try on anything but LTSB, but is this a limitation of LTSB (I had activated Windows BTW). Do I need to be on 1703/1709 + for this to work? This leaves me in a sticky situation with Citrix as Server 2016 is only 1607 equivalent. Ideas/suggestions welcome! Thanks _techie_
-
Smoothwall receiving forwarding requests from NPS 2008 R2
_techie_ replied to _techie_'s topic in Wireless Networks
No I didn't, in the end, I just worked around the issue, and setup separate VLANs for Staff Wifi (MAC Auth their device to the Wireless) and 6thForm use the Wireless Captive Portal. Staff are happy, 6th Form are not complaining, apart from when the Wireless Captive Portal stops working. Will be switching to Smoothwall captive portal during Feb half term to see if the issue persists. Our Wifi controller is pretty old now. -
Server 2012, KMS, Windows 10 and Office 16
_techie_ replied to uffy2000's topic in Windows Server 2012
Pretty sure you need a Windows 10 KMS Host Key (although I seem to recall that this is included in a Server 2016 KMS Host Key, which when installed to your KMS Host, allows Win10 to activate.) The other thing is that you used to need 25 PC's running Windows 7 to allow KMS to work, so I suspect you need the same for Win10. As far as Office 2016 goes, you need to get hold of the KMS Host Key for Office 2016 and install (slmgr /ipk "PRODUCT KEY" to your KMS Host). This should all be available on your MS Licensing Login. Hope this helps. Mark -
Hi, Got Planet Estream here and trying to get IP multicast routing working across VLANs for freeview for live TV. Can get VLC to open udp stream on default VLAN fine. Have 5308xl as L3 switch with VLANs Dg's here. Default VLAN has Freeview encoder on and can see Multicast Groups on that VLAN for each channel. Have enabled IP routing, IP Multicast routing, router rip, enabled IP IGMP on both default VLAN and other VLAN we want to utilise. Is there anything else I need to do?
-
Fixed this in our school by stopping using proxy mode on smoothwall, and moving over to transparent proxy. Hope this helps!
