Eric
Members-
Posts
71 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Eric
-
I have always had problems with users losing part of their Staffmail logon credentials and this is continuing now we are using Office 2010. Specifically some users constantly have to re-insert LGFLMAIL\ in front of their username. It is fairly extraordinary that LGfL support documentation explains how to set up a Staffmail user "by hand," when we are working at the enterprise level. Getting better automation of email account setup is one possible attraction of moving to our own Exchange server, which would significantly diminish the utility of Staffmail.
-
By the time the dDOS traffic reaches your firewall it has filled up the pipe (your "last mile" if you like.) It doesn't matter how much bad inbound traffic Palo Alto drops for you: your usable downlink bandwidth is hosed. This is why your referenced page says: and this is why I said, "Doesn't protect you against dDOS ..." Effective dDOS mitigation has to be done at the edges of an ISP with an inbound capacity which dwarfs the traffic which the DOS perpetrators can achieve. This means that your ISPs inbound capacity is still sufficient to supply you, and all the rest of its customers, after dDOS traffic has been removed. I believe that some dDOS attacks are now generating such large amounts of traffic that finding an ISP that can cope (and is willing to try) must be getting harder.
-
Doesn't protect you against dDOS, though. I agree, we don't really know what caused LGfL1's downtime. It didn't need to be coordinated dDOS, though: it could easily happen as a result of an attack on a particular IP in a school. The continuing risk with Option 2 is that an attack like that will still take you down. As you say, time will tell.
-
One thing to consider when you take up Option 2: there are ten internet trunks into Option 2 and your connection will be on one of them. This essentially means that you have a 10% chance of being taken out by a dDOS of an Option 2 site. dDOS used to be a significant problem for LGfL 1 - have you considered this risk for your site?
-
At a primary school I support, SMT want all teachers to have laptops. It is envisaged that this will make life easier all round: teachers would carry everything they need with them and would plug in (or use wireless? I hope not!) to IWBs when they need to. One good thing: we will purchase a quality wireless solution. I can see support, maintenance and security issues, but would welcome others' advice. There would be around 15 laptops initially and we are also talking seriously about iPads. In regards to the security issue, we have four new Dell Latitudes with fingerprint readers. Unfortunately these have proved hard to set up in a useable and secure configuration. Frankly, I prefer remote desktop/thin client for access outside of school. I don't particularly want to stop this switch to laptops, but I want to be able to warn of any pitfalls in advance and to explain to the school how much extra of my time this is likely to take up.
-
OK, so I have "ePIPS Software 2012-13" from CEM (cemcentre.org) and it has ridiculous instructions for installing and configuring by hand on a whole ICT suite of machines. It's an msi so I'm hopeful that there's someone out there who's been through the pain and can help me do it the quick way ... The old version has to be uninstalled by hand as well, it would seem (I didn't install it ) Is anyone able to help me, please?
-
Hm. We are all desktops at the moment, but teachers want laptops so that they can "carry their work with them." Apart from the re-calibration issue (not too hard in a primary school) please can someone give some detail as to why laptops are not such a good idea - I do realise that my maintenance issues will go up ... I'm also interested in resolution/image ratio issues. We have recently bought mainly Promethean 378 Pros recently, but Misco are suggesting that, with laptops, we might want to look at the the 387 Pro. The projectors are all 1200x800 native, so I'm not sure what the difference would be. If anyone can enlighten me, I'd be very grateful.
-
I accept your correction regarding the safe environment in a school. However I do not see (although this is somewhat irrelevant, given the foregoing) how providing a connection to the wider internet can be confused with the distribution of illegal images.
-
Contrary to what Atomwide were telling people until recently, there is no legal requirement to block paedophilia sites, just as there is no requirement on the telephone company to block you from calling up a criminal and indulging in criminal behaviour. This is a common mis-conception, often encouraged by the Internet Watch Foundation. The issue of Remote Support Tools and LGfL is a much thornier issue.
-
You really need to create, and use, your own filter set(s). When you do this, none of YouTube, Facebook nor Twitter need to be blocked. I am afraid that you are doing yourself no favours by refusing to go on the filtering course.
-
Who did you use as internet service provider? The last time I priced things up LGfL were pretty competitive ...
-
Why ever not? Actually, I can guess.
-
One particular piece of ridiculosity which has just emerged: it is impossible to view any sites which mention VNC, let alone download the tool. This is in spite of the fact that LGfL/Atomwide agree that it is a legitimate tool for us to use. I have just had this confirmed (that it's "legitimate" in their eyes and that they are "unable" to re-categorise such sites so that we can access them) in a support ticket. This is, of course, the point: who are LGfL to decide what is and what is not a legitimate tool for us to use on our own networks?!!
-
Actually, I am not surprised. He is very opinionated.
-
I agree, Staffmail isn't very useful at all. It's exceptionally bad at coping with people who change roles and incapable of helping when people change their surname. It's antideluvian, which may well derive from the Microsoft technology it's based upon.
-
I suggest that you contact Martin Coulson - he may be willing to tell you the email rate limits.
-
I don't particularly wish to defend Atomwide's filtering policies, or the responses which people are currently getting from Atomwide support. However, I was in a session at the recent LGfL conference at which Martin Coulson (CEO of Atomwide) responded to some criticisms in this area. He made it clear that the current rate of switchovers from LGfL 1.0 to 2.0 has put constraints on the flexibility with which their support operation can respond to requests. As you can imagine, LGfL has always had problems with spammy outbound connections resulting in blacklisting of tranches of their own outbound IP address space. This is why there are messages-per-minute rate limits at their email relays. Apparently these will rise after a couple of weeks, once it is clear that a particular customer IP range isn't sending spam. Of course, the limits for a declared school mail relay should start off much higher. From the discussion, I would judge that these algorithms are being tuned at the moment and will probably need adjusting some more. One of the problems with the current load on Atomwide support is that subtle problems may not be escalated to people who can do something about them (Martin.) This is clearly unsatisfactory. Maybe a direct email to Martin Coulson (probably at [email protected], or maybe [email protected]?) will do the trick for you. I would observe that email message rate-limiting is a perfectly sensible approach to trying to limit outgoing spam. It's quite common amongst ISPs these days. I would also question whether a single Exchange installation is actually a reliable way to send email.
-
That's simply a question of how Zimbra has been put together. The processing steps are done by separate processes, instead of threads, which is probably what Exchange does. Exchange is monolithic and sometimes suffers as a result. Linux programs are usually more loosely-coupled than Windows programs, which can often be beneficial, especially when it comes to understanding what is going on. It really doesn't matter how many Received: lines Zimbra adds: messages crossing the internet can often acquire thirty or more these days.
-
Surely it's inevitable that you will get the internal IP there, because that's the address the other internal server received it from, inside your own network? The external IP only appears once the message leaves your immediate network. Frankly, there is absolutely no problem revealing the internal IP address of one of your servers. It's meaningless to anyone else.
-
It's not really a "Zimbra feature." All Mail Transfer Agents (MTA) add lines like these. The intention is that email should be traceable, and to help troubleshooting. Each hop will normally add another line looking somewhat like the one that you want to edit. This collection of "Received:" lines ("timestamps," or "trace fields" in the standards literature (rfc2821)) is invaluable when trouble hits, though it is important to understand that they can be forged along the way. One important use of them is to stop email forwarding loops: every MTA scans incoming messages for its own timestamp - if it finds it, then there is a forwarding loop.
-
TBH I wouldn't worry about your internal IP address - it won't be of any interest to anybody outside your own network. If you would still like to remove it, you could try something like this: match on: /(.*)[1-9]+\.[1-9]+\.[1-9]+\.[1-9]+(.*)/ replace with: /$1$2/ Obviously the "/" characters are simply to delineate my regexps: they may not be needed in your application.
-
I'll bite, though I don't use Zimbra and I'm not even sure if this RE usage is within Zimbra. There is a space after the final ".uk" in the bracketed part of the match (i.e. what you re-use as $1.) Maybe this isn't always there in your input. Also, the final ".+)" in the bracketed match means "match at least one further character, or more." It may well be that you don't know how may characters follow ".uk", or even ".uk[sPACE]" and that sometimes, or always, there are none at all. If you replace ".+" with ".*", then, if this is like the RE systems I have experienced, this will work and mean "zero or more characters." I hope this helped.
-
This is only half helpful. Can you use the "at" command and dsmod? I used to do something like this for deleting files in a couple of weeks time. Maybe something like: at 12:00 /next:thursday dsmod group "cn=schema admins,cn=users,dc=example,dc=microsoft,dc=com" -rmmbr "cn=mary baker,cn=users,dc=example,dc=microsoft,dc=com" Only half helpful because I haven't tried this.
-
According to what I just have read of the HP docs, the 53XX series does allow you to allocate un-authenticated ports to a guest VLAN, so 802.1x authentication should work for you, but this is likely to require all of your printers, etc to be set up for 802.1x. An alternative would be to use MAC-based authentication and a RADIUS server (to specify which VLAN a port should be assigned to, based on a MAC address list held on the server.) You should really hold a list of MAC addresses for your authorised equipment in any case (and your DHCP logs can give you a head start in defining one.) You would then need a transparent proxy, or WPAD(?) to support the devices on your guest VLAN. Something like a Routerboard (inexpensive) should be able to do either of these, but I haven't tried this myself. Apparently there are drawbacks to using 802.1x on the HPs - if the switch goes off-line, then all the devices attached to the network will need to re-authenticate before they can use the network again. Though I think that this may be due to problems with the freeRADIUS server in particular. A problem with MAC addresses is that an attacker can spoof a valid one and get on your authorised VLAN, but this may not be a big risk for you.
