Jump to content

lafleur1977

Members
  • Posts

    263
  • Joined

  • Last visited

Everything posted by lafleur1977

  1. We actually use Network Policy Server and RADIUS to authenticate wireless devices but have struggled with non network devices which come up with a certificate error when trying to connect. All inherited and I am new to NPS/RADIUS/certificate services. I can see how this would be better in that the device would require the certificate to gain access to the network. Thanks for your reply.
  2. Hello, I am trying to stop users from connecting their personal devices to the network as every time they do they are given a DHCP lease. We disconnect unused network ports but some users use the active network ports or wireless network. For the wireless I can probably deny mac addresses on our WLAN controller but I am looking for a more effective method if possible. The DHCP server runs Windows Server 2008 and I am aware that R2 has mac filtering built into DHCP. I have been looking at DHCP Server Callout DLL for MAC Address based filtering (DHCP Server Callout DLL for MAC Address based filtering - Microsoft Windows DHCP Team Blog - Site Home - TechNet Blogs) but have not been able to get this to work successfully using the following syntax: #MACList.txt MAC_ACTION = {DENY} #List of MAC Adresses: 0014858b482e #PCNAME Anyone know were I may be going wrong or of any alternatives? Thanks
  3. Just curious as to whether its best to perform a clean OS install for a server rather than use a server startup disc? I have always performed a fresh install of windows server and then downloaded the latest drivers/required software from the manufacturers website. Never had any problems and I know exactly whats installed on the server. I setup a new server recently but my colleague says to use the server startup disc rather than a clean install. Not sure of the reasoning but I just wondered what everyone else normally does? Thanks.
  4. Hello, We have a wireless network setup which has been configured with radius/NPS by a previous colleague. This is working well for computers which are part of our domain but we are looking at using radius authentication for guest devices and are struggling to get them to connect. We have setup a guest SSID and XP devices fail to connect requesting a certificate, whilst W7 devices ask for credentials but does not work when we enter AD credentials. We have tried installing a self signed certificate manually from the server it resides on to no avail. I do not have much knowledge of NPS/Radius and certificates - has anybody tried something similar and can you offer any suggestions? Thanks
  5. Hello all, Has anybody had any dealings with an IT company called Softcat http://www.softcat.com? They contacted me and seem nice. They provide various IT services and solutions and we are currently considering taking out an EES agreement with them. Obviously, having not used them before I am just looking to see what they have been like with other people. They pride themselves on customer service aparrently. Thanks
  6. Thankyou, thats great
  7. Hello, We have a backup solution which myself and my colleagues have inherited: backup exec 12.5. We do not have extensive experience with the software and are having some real trouble with it. Allow me to explain its setup... File server is connected to a SAN with 4.5 TB of storage being used as one partition for file storage. It is also connected to another device called a disc shelf which is similar to the SAN and has about 5 TB of storage again seen as one partition by the server. Backupexec 12.5 is installed on the file server and is configured with: - Daily differential backups (mon - fri 2 - 4) which backs up to disc on the disc shelf. - Fridays 2 - 4 differential backup to disc then duplicates to tape every friday (currently 1 lto 3 tape). - Friday 1 is a Full (monthly) backup which backs up to disc on the disc shelf. This then duplicates to tape (currently 4 lto 3 tapes). All the backups include system states for 10 servers, files and shares, and 1 exchange server. All originally all backup jobs had a 27 day overwrite period but recently we have had to lower it to 14 days due to space running out on the disc shelf. The problems we are having is mostly to do with the size of the backups and the time they are taking. The differentials are taking around 17 hours to complete and the full backup around 40 hours. Tape backups vary as we only have one tape drive so we have to swap the tape the next day, so I think an tape loader with multiple tape drives in will help this. Another problem is all backup jobs are configured to compress (hardware if available, otherwise none), but for each job history report every server says: compression type: none. So we suspect the backups are not compressing at all. Personally I would replace backup exec but currently at least this is not an option. We also do not have a support contract so symantec will not talk to us. If anybody can suggest anything that may help us regarding our configuration of backupexec and the server that would be great. Thanks
  8. Finally fixed it last week. I had 4 different people look at it from TWC and they were unable to fix it so I got in touch with sophos. As it turns out my enterprise console was updating but the console wasn't updating the information for me to see. I was advised to re-register the consoles DLL files. If anyone else has the same problem here are the steps: 1) RE-REGISTER THE ENTERPRISE CONSOLE DLLS: Open a command prompt (start > run > cmd) and change directory to 'c:\program files\sophos\enterprise console' cd "c:\program files\sophos\enterprise console" Then re-register the DLLs in this folder by running the following command: for %i in (*.dll) do regsvr32 %i /s 2) RUN 'SERVERINIT.EXE': Browse to 'c:\program files\sophos\enterprise console' and double-click on 'serverinit.exe' SUM is updating - - check there are files in the CID location. Re-start server (Not in the steps but I had to re-start before the console started working again). Thanks for all your replies guys.
  9. Yep a couple of times but it still won't update.
  10. Hello, We have recently had a problem with sophos enterprise console 4.5 which has stopped updating. The server had some problems so we decided do a fresh installed of windows server 2008. Installed sophos enterprise console and all was fine for a few days until it stopped updating again. Its configured exactly as the westfield centre's instructions and our update source is sophos2.lancsngfl.ac.uk. The westfield centre can't fix it and passed mke onto sophos directly. Has anybody else been experience the same problem? Thanks
  11. No probs, thanks anyway
  12. I was installing WSUS on the same server but with a fresh install of Windows.
  13. Thanks for your replies guys. I decided to just configure it from scratch rather than try importing. Setup went fine and everything's coming back in. Just got to re-approve some updates now :|
  14. Hello, I am currently re-setting up one of our servers due to a problem with the OS it was having. Previously one of its roles was WSUS and I am wondering if it is possible to re-import all the updates and approvals from the old WSUS installation. I have backed up all the WSUS content files before re-installing the OS on the server but I have only been able to find articles regarding moving WSUS from a old to a new server, not using the same server. Thanks
  15. We have a microsoft select agreement currently. We have shadow copies enabled on the file servers which work great. Will have a look at it anyways, thanks for telling me about it.
  16. Wow that sounds really good. Whats the recovery process like? Does it do anything along the lines of a OS backup/image? Will certainly have a look into it but I think I will be stuck with backupexec for a while yet.
  17. Is that part of microsoft system centre? How does it work?
  18. Hello, Inherited a network and am trying to make some minor improvements in the short term... I am having a problem with backupexec 12.5 and the length of time backups are currently taking (around 24 hours for backup2disk differential and full backups). I am told they were much quicker when the software was configured initially however there is now more data - around 2 TB of files, system states of 10 servers and exchange/SQL backups. I am reading the administrators manual currently when I get chance and a couple of things I have noticed are: Regular de-fragmentation: No server maintenance at all was being carried out and I have now implemented this which has helped a little bit. Priority: would setting this higher improve speed? I would assume it would require more of the servers resources. Thanks for any help and suggestions.
  19. TheMinster: I agree about the everyone group fully.I would always use a custom security group or authenticated users however I am still figuring out this network so do not want to change too much. Ultimately I think the file server needs to be changed from what I have seen so far - its a mess with questionable permissions and file duplication. Also yes security groups are setup for students and teachers. Jamo: That sounds great but would I be able to do this with the same security group or would there have to be 2 different ones as I would be setting different permissions at the same level e.g. each year group. Thanks for both your replies.
  20. Hi, Inherited a network and am trying to make some minor improvements in the short term... I am having a problem with restricting staff members access to students home directories. It is currently setup in the following way: Home directories (shared - everyone - full control) 2006 > users home directories 2007 > users home directories 2008 > users home directories 2009 > users home directories 2010 > users home directories Teachers > users home directories I want to allow staff members to only read data in the 200# directories but be able to read & write in the users home directories. The trouble is the home directories share currently has students and teachers together so I can't change the permissions at that level. Currently each 200# directory has a staff security group with modify permissions. I changed this to a special permission (subfolders and files only) but this stopped staff from being able to access the 200# directories. I hope I have made this clear. Thanks for any help.
  21. Hello, We had heard about the problems with deploying SP1 for windows 7 via wsus when it was first released. Does anybody know if it is safe to deploy it in this way now? Thanks
  22. Hello, We are running a SAN which is directly attached to a server (windows server 2008) for file storage on our network. Its purpose is for storing users home folders, shared folders, etc. It is currently showing as one 6 TB volume to the server. I am quite new to SAN's and I am just wondering if anyone has any comments on this setup or best practices, advice, etc for me. Also, could it be split up into multiple partitions and would this be beneficial? Thanks
  23. I disagree. Mac OS X is just a susceptible to exploitation as a Windows PC or another device. It is purely down to MAC OS X's low market share that there are less viruses however with its market share increasing, it is very sensible to consider anti-virus for MAC OS X. Apple and Sophos both recommend it, with Sophos having several articles on their website. Have a look at this: Apple anti-virus advice was nothing new ? The Register
  24. Thanks for all your reply's guys, I will try them out on Monday
  25. Hmmm WSUS should install all the additional roles it requires (and tell you what they are). Could you remove IIS and then try installing WSUS? I presume you are trying to install WSUS from server manager?
×
×
  • Create New...