Tom
Members-
Posts
25 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Tom
-
I have had to also disable slow link detection (computer-system-group policy-configure slow link = enabled,0) in addition to setting the hardened UNC path values. I have pushed out the hardened unc values by GPO rather than by script/registry (it is in one of the windows 10 admx files), along with slow link disable. One reboot on the wire makes my wireless clients work again! - So doing it before domain join isn't necessary in my case. They are not logging anything about slow link (and gpresult always says it is not slow!), but setting it seems to be required anyway....
-
Nice one @themightymrp! - That appears to fix it! first reboot after setting those and it ran through all the computer policy settings including the software installs! I have just properly read your link which you posted right at the start of this thread. I wish I had read this all earlier! The way that it only seems to be affecting some models and not others had thrown me off. I'm back on site again tomorrow so I can try this live on all the windows 10 devices. It will be interesting to see if the slow link settings are also required or if they just 'mask' the URL hardening issue somehow for user GPO's. I shall stick the URL hardening settings in via registry from a USB stick, and then reboot some devices and see if they start picking everything up properly on the wireless. I was testing with a flat install of win10 edu x32 today direct from the install.wim on the CD. No windows updates installed. My other image had some more apps in and was updated up to last week.
-
I have reinstalled a couple of my devices and get them working on a test domain with minimal gpos and got the same issues. I've also installed some different tablets with the same windows 10 image and get the same problems. However, thanks @GuyJD - looks like it is slow link related. It isnt reporting a slow link in event viewer but fully disabling it by GPO (and then restarting them on a wire to get the new settings) seems to make user logon work properly and always apply the GPO's. I cannot however make it apply any of the computer GPO's over wireless. I have forced things like software installation on over a slow link in the same GPO. always just gives GPT.ini errors against the first GPO in the domain and then seems to give up. I think there are slow link detection issues with wireless connections in windows 10...
-
my devices are not properly processing the user GPO's every time either. Seems to always fail on the first logon after boot, most of the time on ones after that. flawless everytime when i plug a wire in! (and on other devices). Something wierd is going on as if I try to run the GP RSOP wizard on a machine that has failed GPO's I cant see the user logon to run it against. If I do an RSOP wizard after an on wire bootup and logon everything is there as expected.
-
I have looked at multiple DC's and cannot find a corrupt copy of this gpt.ini file. No other machines are complaining about it. I think this error is a consequence of some of these issues rather than the root cause of this problem. The GPO is on the root of the domain (and is the bottom one in the list when you do gpresult /r /scope:computer) - so it looks like it is the first one it should be applying. I am also seeing errors from WLAN-autoconfig in the system log that seem to happen on bootup just before the gpt.ini errors saying "WLAN extensibility module has failed to start c:\windows\system32\Rrlihvs.dll". I asssume this is part of the realtek wireless driver. Annoyingly I cant seem to un-install the current version of the driver so that I can go back to an older version (which has worked on many other drivers on this tablet) as it has no checkbox to uninstall the driver files! I am not on site to try this right now. Can somebody else give it a go? I do have a device offsite though and have checked. IIPv6 is enabled at the moment, but there is no wired lan interface on it (I have been using a USB dongle) so the wifi is top of the list above Remote Access Connections.
-
I put mine on max performance and it makes no difference. I am also seeing an error about a gpt.ini in the event log. Always seems to be one that is at the domain root. However other machines are getting it fine and it gives no error on the affected laptops when on a wire. I am getting some errors in the event log from the wireless card on these devices which don't seem to be happening on others. I had these tablets working perfectly on the wireless on monday - but they were missing some drivers. It is since the driver update that they have stopped working.
-
Im currently experiencing this on some linx tablets with win10 on. I think it is wireless driver related. These things were fine until I reinstalled a load of drivers to get other things working in device manager. I have other models of device with the same windows 10 image on and they are not experiencing it.
-
I've done hundreds of C50's since my last post!. They deploy at normal speeds for me. I am now using the windows 8.0 x32 boot image in WDS 2008/2012, and have option 66 set to the WDS server IP and option 67 set as above. I am putting windows 7.1 x32 images onto them
-
If anybody is still trying to get these stupid laptops to PXE boot, we have found the problem and a workaround for it and I have a support case open with Toshiba where they are replicating it which will hopefully lead to a proper fix. Amusingly this is taking a while since our laptops shipped to us with bios version 1.20 which hasn't been released to Toshiba UK support yet! The issue appears to be that the C50 isnt able to use more than one DHCP server for the boot process - so if you have a DHCP server giving out an IP and a seperate WDS server giving out the PXE options (60,66 and 67), it doesnt get the responses from the second server - so fails with the file not found error. If you have WDS on the same server as DHCP it works. You can specify options 66 and 67 on your main DHCP Scope and force it to work - set option 066 to your WDS Server IP address/FQDN and 067 with the following string "\boot\x86\wdsnbp.com". this will work for x32 boot images (win7 or win8) on wds 2008 and 2012. We have deployed win7 x32 onto ours quite happily. This issue is affecting 2 different 'sub-modles' of the C50 which we have - so don't buy any new ones without expecting it.
-
I think there are different sub-models (as with all the Toshes!). I also have C50-A-15Q's which come with windows 8 x64. They were supposed to be C850's but they went EOL before the order got there and somebody decided that these would be an equivalent replacement
-
I encountered these horrible laptops this week and ended up removing the HDD's to image in another PC. I have another 60 of them to do next week! would rather not have to remove them all to image! I couldnt even get them to boot from a USB stick with secure boot off & CSM on. didnt try forcing the boot order though. If you have wds2012 you can UEFI network boot them from a windows 8 x64 boot image - but then cant deploy x32 windows 7 images Andyase - Did you create your discover boot image from an x64 or x32 windows 7 boot.wim? I want to deploy an x32 windows 7 imstall image to these things.
-
Does anybody have the url for the ftp upgrade? they will only post out the CD now and i dont want to wait!
-
I've just fixed the problem in the OP thanks to this. Error started when i moved a sims server between domains. Deleting the My sims documents folder from my documents and letting it recreate it fixed it. Also, in addition to the originally described error where you cannot logon as a normal sims user, you can still logon to sims.net as SYSMAN, but when you go to tools-setups-document management server option it crashes here instead.
-
Cheers Tom, The support guy i spoke to was great! It turned out that it was an authentication issue, and either the people reporting it broken before i changed that were lying, or something else had happened to refresh the user accounts on my smoothwall before i added the new DC. I had got the VPN users in my domain in 2 AD groups which the smoothwall knew about, a std proxy one and a VPN allowed one. It used to pick up the VPN one in preference to the normal one, and thus auth them for the VPN connection. It was now picking them up as the normal group and failing them when they tried to VPN in. Have created some local user accounts for them to use just for VPN access and these work.
-
I've got a smoothguardian and am using the SSL openVPN connections. At some point over the last couple of days (not sure exactly when) it has stopped working. When I try and connect from my client PC, openvpn fails on authentication, and doenst let anybody on anymore. There are also errors showing in the log on the server. Can anybody offer any advice as to if this is a server issue or a problem with the broadband connection into the smoothwall? It goes through various LEA routers and NAT stuff to get into the school. Yesterday I changed some authentication settings on the smoothwall (but no other settings) to point to a new windows DC rather than an old one which is being retired (it is authenticating from an active directory, and i changed the primary servername in smoothwall) It is authenticating fine internally for web browsing after my changes, and the tests run through fine. Do i need to do something to the VPN settings to make it resync with the new DC? I didnt change any AD structures about just pointed it to another DC. It still has all the correct VPN groups showing on the smootwall. The VPN users can still browse the net internally in school without auth errors. The client openvpn log shows Wed Jul 29 18:16:51 2009 OpenVPN 2.1_rc4 Win32-MinGW [sSL] [LZO2] built on Apr 25 2007 Wed Jul 29 18:16:54 2009 LZO compression initialized Wed Jul 29 18:16:54 2009 Control Channel MTU parms [ L:1558 D:138 EF:38 EB:0 ET:0 EL:0 ] Wed Jul 29 18:16:54 2009 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ] Wed Jul 29 18:16:54 2009 Local Options hash (VER=V4): '22188c5b' Wed Jul 29 18:16:54 2009 Expected Remote Options hash (VER=V4): 'a8f55717' Wed Jul 29 18:16:54 2009 Socket Buffers: R=[8192->8192] S=[8192->8192] Wed Jul 29 18:16:54 2009 UDPv4 link local: [undef] Wed Jul 29 18:16:54 2009 UDPv4 link remote: :1194 Wed Jul 29 18:16:54 2009 TLS: Initial packet from :1194, sid=30840c0b 4f80c0bf Wed Jul 29 18:16:54 2009 VERIFY OK: depth=1, /CN=www..sch.uk/O=/ST=cheshire/C=UK/L=crewe Wed Jul 29 18:16:54 2009 VERIFY X509NAME OK: /C=UK/O=/CN=www..sch.uk Wed Jul 29 18:16:54 2009 VERIFY OK: depth=0, /C=UK/O=/CN=www..sch.uk Wed Jul 29 18:16:55 2009 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key Wed Jul 29 18:16:55 2009 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication Wed Jul 29 18:16:55 2009 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key Wed Jul 29 18:16:55 2009 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication Wed Jul 29 18:16:55 2009 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA Wed Jul 29 18:16:55 2009 [www..sch.uk] Peer Connection Initiated with :1194 Wed Jul 29 18:16:56 2009 SENT CONTROL [www..sch.uk]: 'PUSH_REQUEST' (status=1) Wed Jul 29 18:16:56 2009 AUTH: Received AUTH_FAILED control message Wed Jul 29 18:16:56 2009 SIGTERM received, sending exit notification to peer Wed Jul 29 18:16:59 2009 TCP/UDP: Closing socket Wed Jul 29 18:16:59 2009 SIGTERM[soft,exit-with-notification] received, process exiting Wed Jul 29 18:17:00 2009 OpenVPN 2.1_rc4 Win32-MinGW [sSL] [LZO2] built on Apr 25 2007 Wed Jul 29 18:17:05 2009 LZO compression initialized Wed Jul 29 18:17:05 2009 Control Channel MTU parms [ L:1558 D:138 EF:38 EB:0 ET:0 EL:0 ] Wed Jul 29 18:17:05 2009 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ] Wed Jul 29 18:17:05 2009 Local Options hash (VER=V4): '22188c5b' Wed Jul 29 18:17:05 2009 Expected Remote Options hash (VER=V4): 'a8f55717' Wed Jul 29 18:17:05 2009 Socket Buffers: R=[8192->8192] S=[8192->8192] Wed Jul 29 18:17:05 2009 UDPv4 link local: [undef] Wed Jul 29 18:17:05 2009 UDPv4 link remote: :1194 Wed Jul 29 18:17:08 2009 TLS: Initial packet from :1194, sid=a36eed89 d4718734 Wed Jul 29 18:17:08 2009 VERIFY OK: depth=1, /CN=www..sch.uk/O=/ST=cheshire/C=UK/L=crewe Wed Jul 29 18:17:08 2009 VERIFY X509NAME OK: /C=UK/O=/CN=www..sch.uk Wed Jul 29 18:17:08 2009 VERIFY OK: depth=0, /C=UK/O=/CN=www..sch.uk Wed Jul 29 18:17:09 2009 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key Wed Jul 29 18:17:09 2009 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication Wed Jul 29 18:17:09 2009 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key Wed Jul 29 18:17:09 2009 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication Wed Jul 29 18:17:09 2009 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA Wed Jul 29 18:17:09 2009 [www..sch.uk] Peer Connection Initiated with :1194 Wed Jul 29 18:17:10 2009 SENT CONTROL [www..sch.uk]: 'PUSH_REQUEST' (status=1) Wed Jul 29 18:17:10 2009 AUTH: Received AUTH_FAILED control message Wed Jul 29 18:17:10 2009 SIGTERM received, sending exit notification to peer on the server, the SSL VPN log is showing the following: System Logs 17:42:33 openvpn event_wait : Interrupted system call (code=4) 17:42:33 openvpn SIGTERM[hard,] received, process exiting 17:42:37 openvpn OpenVPN 2.1_rc4 i686-pc-linux-gnu [sSL] [LZO2] [EPOLL] built on Nov 19 2008 17:42:37 openvpn WARNING: file '/modules/tunnel/settings//vpn/pemkey' is group or others accessible 17:42:37 openvpn WARNING: file '/modules/tunnel/settings//vpn/ipsec.d/host1key.pem' is group or others accessible 17:42:37 openvpn WARNING: This configuration may accept clients which do not present a certificate 17:42:37 openvpn TUN/TAP device tun0 opened 17:42:37 openvpn /sbin/ifconfig tun0 10.1.0.1 pointopoint 10.1.0.2 mtu 1500 17:42:37 openvpn UDPv4 link local (bound): [undef]:1194 17:42:37 openvpn UDPv4 link remote: [undef] 17:42:37 openvpn Initialization Sequence Completed 17:43:09 openvpn event_wait : Interrupted system call (code=4) 17:43:09 openvpn SIGTERM[hard,] received, process exiting 17:43:10 openvpn OpenVPN 2.1_rc4 i686-pc-linux-gnu [sSL] [LZO2] [EPOLL] built on Nov 19 2008 17:43:10 openvpn WARNING: file '/modules/tunnel/settings//vpn/pemkey' is group or others accessible 17:43:10 openvpn WARNING: file '/modules/tunnel/settings//vpn/ipsec.d/host1key.pem' is group or others accessible 17:43:10 openvpn WARNING: This configuration may accept clients which do not present a certificate 17:43:10 openvpn TUN/TAP device tun0 opened 17:43:10 openvpn /sbin/ifconfig tun0 10.1.0.1 pointopoint 10.1.0.2 mtu 1500 17:43:10 openvpn UDPv4 link local (bound): [undef]:1194 17:43:10 openvpn UDPv4 link remote: [undef] 17:43:10 openvpn Initialization Sequence Completed 17:43:14 openvpn :3054 Re-using SSL/TLS context 17:43:14 openvpn :3054 LZO compression initialized 17:43:15 openvpn :3054 TLS Auth Error: Auth Username/Password verification failed for peer 17:43:15 openvpn :3054 [] Peer Connection Initiated with :3054 17:43:16 openvpn :3054 TLS Error: local/remote TLS keys are out of sync: :3054 [0] 17:43:17 openvpn :3054 TLS Error: local/remote TLS keys are out of sync: :3054 [0] 17:43:18 openvpn :3054 TLS Error: local/remote TLS keys are out of sync: :3054 [0]
-
We also do almost exactly as Sted is saying. Our schools are mainly on half a day/week or /fortnight. We dont hang about on site if there is nothing to do. If there is nothing on the list, and you have spoken to the ICT coordinator/staff and done your usual system checks and maintenance you may as well go elsewhere and do something useful. They are happy with this since you can do extra visits and emergencies with the spare time. We just throw emercency calls in (Once it is set up properly, emergency calls are not that common). It averages out over the whole year as the emergency calls come out of the unused time. Emergency call outs for projector maintenance are a seperate issue. You should make sure you bear those in mind when time planning and also in your contract if necessary. Many places now seem happy to pay for these seperately. You could include things like cleaning filters in your normal support but projector maintenance can be a PITA if they have some historical crappy installations with non standard bracketry..
-
Change a DC from old network to member server on new
Tom replied to speckytecky's topic in How do you do....it?
If you are planning on using this as a WDS server you might want to go with server 2008 rather than 2003R2. You dont get the same multicast support with WDS under 2003 as you do with 2008. -
WDS is very easy to use once you have got the initial tricky setup done and got your head round how it works.
-
IT Technician - Immingham - North East Lincolnshire
Tom replied to MatthewL's topic in Educational IT Jobs
They have a great setup! This is a really nice academy to work in, if anybody here is applying. -
OK - Its all working now! It was as simple as reseting all the file permissions and share permissions, and reconnecting to the sims share. also ensuring that all the files in sims\system\station.10 (10 is my server) were correct. It now works from the server and from additional workstations once i map the S: drive, give them a LANID and run the old WSSETUP on them.
-
Its looking like you are closest! I have found that i can run launcher and personell from the local drive letter on the server but not from the mapped S: drive. ive given everyone permission on the share and the file permissions are obviously right as i can do it locally. I've obviously missed something else!
-
It's in a site that has moved over to cmis, and personnel is the only bit left in sims. Unfortunately the sims server is very flakey and unreliable so I was hoping to move it over to a different server which was spare. It has been pointed out many times that they should stop using personnel but were determined to carry on I think I will point out that unless they want to pay for some capita support they are going to have to take their chances with the old server and push the migration more urgently
-
Unfortunately that aint gonna happen and i need to get the old one back up. I'm sure i used to have a list of sims error codes from back in the old DOS days, but its long since gone. Any ideas?
-
I am trying to move a SIMS setup onto a new server. I have done SIMS.net moves a few times - and this is all now working on the new server. I can get on SIMS.net and do everything properly. however - they still want to use the old DOS personnel program from the old sims launcher. It has been a while since i last did anything with the DOS modules. I have added lines into config.nt, set a LANID environment variable (using the same ID as the old server), and i can now run the launcher and log in. However, when i click on personnel i get an error: "windows error (id=5) attempting to run personnel" error I get the same one for most other modules. Can anybody advise me of what step i have missed out? or what this error ID means?
