Jump to content

mrwoberts

Members
  • Posts

    634
  • Joined

  • Last visited

Everything posted by mrwoberts

  1. Crossed a similar bridge recently. Some of the reasons we didn't go for a TV were: Screen protection (not toughened glass), accidental damage is definitely not covered. This was probably the biggest factor. Touchscreen built-in 'Android' OS is actually helpful at times, when you just need to write stuff down, or go straight to Google Earth to look at something... No need for the teacher to leave the laptop in the room. (As others mentioned) Warranty is a grey area when the unit is used in a commercial setting, although we could have bought a 'commercial' grade TV. Just having the ability to touch without having to think about it is probably a bit underestimated - will the tablet 'just work' without any issues. Had major problems with a friends Wacom tablet in a previous version of Windows 10 !
  2. That was the question our LA posed to the bursar in a cold call this afternoon. This was following our decision not to buy-back into their SIMS support, £1,000 per year - we almost didn't use it last year. For a moment I thought this has to be a joke, but now I'm wondering whether this is true? If we don't pay our LA for SIMS telephone and upgrade support, will Capita not release the patches to our Solus server?? EDIT: We are part of a 4 school MAT, currently hosting FMS (what a joke) through Capita, but on-premise SIMS at the moment. No unified response from the MAT leaders so each school are having to sort out their own provision for SIMS.
  3. Good question. In short, yes they do. Here's a link to the Filtering Provider Response on the SaferInternet site. https://d1afx9quaogywf.cloudfront.net/sites/default/files/Filtering/Monitoring/2017%20Untangled%20-%20Filtering%20Provider%20response.pdf It's worth noting that you will see an amber box in one of their responses, but when I delved deeper it I found a few items that satisfied the requirements... Untangle.com are the manufacturer of our firewall/web filter. The filter automatically receives updates from a company called Zvelo who are members of the IWF. The UK government CTIRU filtering list, not a public list, is provided to Zvelo, who use this in their database, which Untangle uses. Categories Terrorism/Extremism are included in Hate Speech Untangle category. Helpful forum posts https://forums.untangle.com/feedback/38032-feature-request-web-filter-iwf-uk-government-ctiru.html https://forums.untangle.com/web-filter/38129-web-filter-categorisation-anomalies.html -- EDIT Added bullet point
  4. I had a trial run of it and was impressed. It provides the protection we need - firewall, filter, reporting, cloud management Aside from that, it actually turned out lower cost than other providers we approached. It certainly helped that we had some kit to reuse, otherwise we would have had an additional £ 500+ for hardware to factor in.
  5. Yes. It has a Policy Manager (linked to AD) where you specify what policy is applied to a group of users. You can also create rules based on IP address, hostname, pretty much anything. I love the granularity. I get reports (daily/monthly..) and instant alerts (triggered events). I'm in the process of looking at the AD-connector script because I think it associated a device with an incorrect IP address. Other than that we get the kind of protection we've been looking for. -- EDIT Forgot to mention, you can block websites, allow but flag them, or block and flag. This is useful when trying to keep a balance between 'blanket blocking' and effective monitoring.
  6. It sure does, in a most excellent way (said in my best Bill and Ted voice) Take a look at the live demo... Untangle
  7. +1 for Zen - excellent UK business. We ditched the LA recommended ISP - BT Unicorn (Global). Speeds and lack of control were crippling us. Moved the line to Zen FTTC Unlimited Office (includes Critical Care). £ 912 per year, includes line rental. Purchased a Public Sector license of Untangle, which is a license for up to 150 unique devices. £ 1,000 per year. Installed Untangle on some half-decent kit we already owned. With this new setup we are so much happier than we've ever been. Filtering, Monitoring and granular controls really satisfy the Leadership. -- EDIT School has 210 children, 30 staff Advertised speeds for our FTTC line, 76 down, 19 up Download speeds regularly above 60 Mbps. Upload speeds regularly above 15 Mbps
  8. Couple of things to try... Are the client and Server network types appropriate? The server is almost certainly going to be 'Domain', but when testing the client (externally) what network type is it set to - It should be Home/Work and not Public. Also, in the configuration setup of the VPN, I personally untick the 'Use default Gateway on remote network' - this prevents all internet traffic going through VPN. Please could you capture the output of this command, and obscure/change anything that is sensitive, before posting the results here. ipconfig /all
  9. I haven't used the 1803 templates yet, simply because I'm not interested in 1803 at the moment, I'm barely keeping my sanity with 1709. However, the problems with using the latest templates can arise when you simply copy and paste over the existing central store templates, and in some ways you may have a mix-n-match. A better method is to backup (rename or move) the existing central store, and then use the new templates exclusively, into a new (empty folder) central store, along with the matching locale subfolders (en-us, en-gb...) OPTIONAL It might also be worth refreshing the servers policy definitions folder (C:\Windows\Policy Definitions) with Server 2016, for example. Again, backup the existing folder and paste definitions from 2016 - you'll probably have to nab them from a .wim file or running installation. EDIT: Here's a script I occasionally use to see if I have any missing .adml files - note you'll need to adjust the locale, which is currently only looking in en-us subfolder. @for /f %%G in ('dir /b %windir%\PolicyDefinitions\*.admx') do @if not exist "%windir%\PolicyDefinitions\en-us\%%~nG.adml" echo %%G
  10. Would it be possible to fire up a server with Untangle installed on a 30 day trial. I'm in the process of switching to Untangle (paid) and they offer a 30 day trial, which would help you in the short term. You don't need a super-powerful server, just multiple NICs and a half-decent PC. Another option could be to grab yourself a Draytek router, on next day delivery, and purchase a WCF (Web Content Filtering) add-on - something in the region of £ 50 per year. Comparison All the best EDIT: Draytek Vigor 2762n (Amazon Prime - delivered Tuesday 8th) You can also have a 30-day trial for the Draytek Content filtering product - accessible from the webui of the router... EDIT 2: Just remembered that OpenDNS operate a free (no signup required) blocking service called Family Shield which will always block domains that are categorised in their system as: Tasteless, Proxy/Anonymizer, Sexuality and Pornography. To use this, simply set your DNS forwarders to: 208.67.222.123 208.67.220.123 Note, this is different to their sign-up (also free) service - they use 208.67.222.222, and 208.67.220.220 Reference: https://www.opendns.com/setupguide/?url=familyshield
  11. 1803 ADMX templates https://www.microsoft.com/en-us/download/details.aspx?id=56880
  12. @talksr Just landed... 1803 ADMX templates https://www.microsoft.com/en-us/download/details.aspx?id=56880
  13. You're going to need to update your PolicyDefinitions (ADMX) GPO templates. Here is a link to the 1709 admx templates https://www.microsoft.com/en-gb/download/details.aspx?id=56121 However, now that 1803 has been released, it makes sense to either grab the definitions from an installation of 1803, or wait for the release of 1803 admx templates.
  14. Now you've corrected the internal DNS zone records, could it be just a matter of refreshing the clients DNS cache. ipconfig /flushdns ipconfig /registerdns If you use Chrome, you may also have to flush out its own DNS cache... type this in the address bar chrome://net-internals/#dns Then click clear host cache.
  15. I use this... DesktopApplicationLinkPath="%APPDATA%\Microsoft\Windows\Start Menu\Programs\File Explorer.lnk" Size="2x2" Row="0" Column="0"/> EDIT: After I've move the File Explorer.lnk into to the Programs folder
  16. Interesting, I'm now just wondering what Smoothwall is doing since it has to pass the traffic to a second proxy. What features are you using in Smoothwall? How are the clients told to interact with Smoothwall? Proxy/DNS?
  17. Any chance you could draw us a better picture of how things are setup. When you say, upstream proxy, would the Smoothwall connections also be passed on to that upstream proxy???
  18. One thing to mention is to make sure you are using the 'English International' iso/wim. The plain 'English' is en-US, where as the 'English International is 'en-GB. Then, in your autounattend.xml file, you can specify the following... [b]en-GB[/b] [b]0809:00000809[/b] [b]en-GB[/b] [b]en-GB[/b] en-US [b]en-GB[/b] Creating unattend xml files can be done in a number of ways, but mostly through the Windows System Image Manager included in the WAIK/WADK, however, here is an online generator Windows Answer File Generator
  19. There is a way to prevent the app being provisioned - totally unsupported I should add. Basically, remove the Microsoft.Windows.HolographicFirstRun.... subkey from this location HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\InboxApplications and it will be skipped during first login of any user. @Arthur was the one who first told me about that method.
  20. This might help... setlocal EnableDelayedExpansion for /f "tokens=2 delims=:" %%G in ('ipconfig ^| find "IPv4"') do (set IP=!IP!%%G)
  21. Bother! Looks like it requires the host to have a TPM module...
  22. Thanks again for taking a look at that. You're right, encrypting the SIMS vm disk is something I was mulling over, however, I'm finding it particular difficult to find a TPM 2.0 module for the board I wanted to use, and rather unhelpfully, SuperMicro won't say whether that board will work with non-SMicro TPM modules. I guess it is entirely possible that I could use a BitLocker password/pin since I am installing SIMS... on EDU/LTSB?? Many thanks
  23. Thank you 3s-gtech The server is in a locked (ventilated) comms. cupboard. The custom config that I'm going to offer, alongside other configs, includes the following... Supermicro X11SSH-F board Intel Xeon E3-1220 v6 processor 32GB 2400-DDR4 2 x 480GB SSD (Intel DC4500 or Samsung PM863a) in RAID 1 1 x 1TB WD BLACK as an internal backup Synology DS918+ with 4x 4TB WD RED disks in RAID 10 or RAID 6 (not yet settled on that) Kind regards
×
×
  • Create New...