digone52
Members-
Posts
67 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by digone52
-
teachernet.gov.uk does not resolve
digone52 replied to digone52's topic in Internet Related/Filtering/Firewall
A very good question. I think that the person who reported this to me is going for a lie down! I suspect no more to be done. -
We have a user who needs to access teachernet.gov.uk DNS lookup of that domain fails with non-existent domain. It has been down for the last two weeks evidently. I wouldn't know who to contact. Any thoughts? Ta.
-
Windows NT 3.1 boxed copy on the study shelf - lots of floppy disks! Not Windows memorabilia, but memorabilia nevertheless - in the garage ... I loved my Model B!
-
We use Papercut, and it's been a fantastic product to track printing by department by pupils and staff. However, after implementing Papercut and a chargeback mechanism to try to keep costs under control, our printing costs may have actually gone up 2014-2015. There are suggestions of scrapping the chargeback as it costs to administer it. Can I therefore ask if possible - to reduce the printing costs of a school, is it reasonable in your experience to expect people to print less volume on an existing infrastructure (with many printers), or are the cost reductions more to do with centralising and reducing the number of printers?
-
Have you looked at services.msc to see what is set to automatic start and has not started, and event viewer to look for errors? This is where I'd start.
-
Tablets for students - A Framework to choose one
digone52 replied to Davism1993's topic in Mobile Devices & Tablets
Hi Jason. I think that what you've done is great. At our school we have yet to go down the tablet route, but I think that your chart would be really valuable when we have to come up with a choice. I did try to fill in your questionnaire, but fell foul of the "Which device platform did the framework suggest for your school" bit, as you are forced to say what your school chose - which ours hasn't done. -
Hi. Thanks for the reply. We do, but in the "admin" domain we wish to merge into the one with the .local address - hence I want to get it right before merging. Doing an Exchange transition will be painful enough though I'm sure.
-
There is a recipe to rename the domain here https://mizitechinfo.wordpress.com/2013/06/10/simple-guide-how-to-rename-domain-name-in-windows-server-2012/ which I guess we can follow in our test environment as we are using Microsoft Windows 2012 R2 for DCs, but just to confuse me even more, in this example it illustrates how to move to a .local domain name!
-
Hi. Excuse if this is the wrong forum for this topic. We have a .local domain which we are about to move our "admin" domain resources to. I'd prefer that we have the domain name right before performing this move. I've been reading on Edugeek and elsewhere that .local domains shouldn't be used - that ideally we should be using a subdomain of our .sch.uk domain. Presumably we should therefore use something like "local...sch.uk" as a suggestion? I know there are issues that you can't get certificates for .local domains, but so far for us this has not been an issue. Two questions then... * What are the full implications of having a .local domain? Are we storing trouble up for ourselves in future going forward with a .local? * As long as we test-test-test, should we rename our ".local" AD DNS domain before performing our "admin" domain merge? Many thanks.
-
Suggestions for handling video storage
digone52 replied to craigw's topic in AV and Multimedia Related
I had a go at some of our video stores, and took down the space utilised from 300GB to about 100GB, so probably worth it. I used the divx converter, in batch mode, going through folder by folder. It has a queue, but you unfortunately need to go through a folder at a time, so is time intensive. I also found that some .wmv files ended up with a time lag with audio, so I put them back to the originals. A reliable tool to do this in one hit would be excellent - *even* if we have to pay! -
We stage everything on disk before sending it to tape. I believe that full backups on remote systems straight to tape can work well. Incrementals can be more problematic. When writing to tape, I think that to stream effectively, you need to keep the tape streamer fed with data, so have a good path from remote system, across the network and to the tape drive. Bottle necks can cripple backup performance. Loads of small files can cause issues too.
-
In Schools internal ICT departments that get busier and more pressured as time goes on, are customer SLAs important or not? The reason why I ask is that we may soon be under an SLA. We have happy customers, but we need to be more visible and accountable evidently. I assume that when you're under an SLA, then you have to document everything you do, and do so promptly to ensure that job opening and closure is logged. While we have a helpdesk portal already, it does not exactly drive our jobs in this way. I'm concerned that while the job is extremely pressured already, we will have added burdens of doing an enormous amount of logging, looking over our shoulder to ensure that SLAs are being met, producing management reports to ensure compliance, and so on. This all adds to a job that cannot be fitted into the number of working hours already. I'd be interested in your views.
-
SSL Intercept Legal and Acceptable Use Implications
digone52 replied to ReBoot's topic in Internet Related/Filtering/Firewall
You've summed it up. Google's safesearch may not be wholly appropriate, but try an unblocked HTTPS search engine without safesearch. They're out there. SSL interception is far more important for these IMHO. -
Hi. Thanks for the info. What is the impact if they do forget to change the password before the holiday. Is it just email access stops?
-
Hi folks. We do not currently have a password change policy. We are thinking about having a password expiry policy to force members of staff to change their passwords regularly. If we do this, I'm considering what will happen if the password expires during a holiday. We have an Exchange OWA which can be configured to allow staff to change their domain passwords when away, which will sort out email issues with the password expiry (currently this is disallowed). However, we have about 150 laptops, all with the staff logging in at home with domain credentials. If a member of staff is away from the school (summer hols for example), and their password is set to expire, what happens with the logon to the laptop? If the member of staff cannot login at that point, then how do other schools handle this? Thanks.
-
I had this issue before the summer holiday. Personally, I don't want pupils running their .exe's on the domain in any shape or form. I considered running virtual machine images on the local PC with the vm images coming from the network, allowing the user to roam, but this was a dead end for a number of reasons. Really pleased with the solution - a Windows 2008 R2 box running terminal services and Visual Studio, with 12 cores and 24GB of RAM, all data held locally on the server, and the server is a standalone. Only Comp Sci pupils can access the box as they can only run the RDP client by group membership. FSRM on the domain prevents them from copying executables to their home dirs, but using RDP they have access to local drive letters and printers, and can even use a memory stick to take home their work. NOTE I believe that a 2012 terminal server needs to sit in a domain, so I think you need 2008 R2, at least in the way we have configured it. With this spec, we've had 20 or 30 concurrent users, no issues, no speed problems, everyone happy.
-
Hi. Here we have policies where if a user is a local admin of their computer, UAC is on. If a user is not an admin of their computer, UAC is off due to SIMS.NET updates. If your users are local admins of their computers, I don't think that switching off UAC would be a good idea, as obviously they will be running under the administrator context all of the time.
-
Hello. On certain pages within fronter we use HTML A tags referencing content on networked drives local to our school pointing to video content which is too large to run off or load onto Fronter. This has always worked up to when recent updates were applied to Fronter. Now when we click on a link to the videos from Fronter, there is no response at all from the browser (both IE 9 and Firefox, both XP and Win 7), although if you hover over the link, it appears to be correctly formed, and if you copy the link and paste it into the address bar, it functions. On running wireshark, it appears that the fault is rather technical - for me at least. It appears that a request is sent to the fileserver "QUERY_PATH_INFO, Query File Basic Info" on a path of the file, but with ":Zone.Identifier" appended to the filename. What comes back is an error "QUERY_PATH_INFO, Error: STATUS_OBJECT_NAME_NOT_FOUND". This is where the conversation between client and file server ends. If you do a similar scan outside of Fronter, this request is not sent, and the video loads. Any ideas why this behaviour has started to happen, and if we can fix it at all? Thanks.
-
[sims] Auto install of SIMS - UAC - securing the server share
digone52 replied to digone52's topic in MIS Systems
Thanks. I don't have a SupportNet account yet, but have registered, so hopefully will get the creds tomorrow so I can take a look at the documentation. -
[sims] Auto install of SIMS - UAC - securing the server share
digone52 replied to digone52's topic in MIS Systems
Sorry to be a bit green, but I don't know much about Solus 3. It was mentioned earlier in this thread that it is a service so the install does not happen under the user context but one of an admin equivalent (I think), so if I could use Solus 3, presumably it gets around permissions issues. However, if Solus 3 is a push technology, so you have to wait for the computer to be on-line and then push the update, then I can't see this working at all. If in some way once the Solus 3 service is on the network and can see the update, then it can pull the update down in some fashion, then that might work as long as the user doesn't have time to use SIMS.NET and mess things up in the meantime. The thing is, this really shouldn't be difficult I feel. UAC has been around for years, and so has the idea of hibernating laptops. Using these technologies is good practice, as is not giving users local admin. If with SOLUS 3 the computers have to be on the network at the time of update, then surely laptops can't be used with SIMS.NET? If Capita expect that their users are not allowed to hibernate if using SOLUS 3, be local admins or not use UAC if not using SOLUS 3, and on top of this unless you use SOLUS 3 have the network admins open up permissions on the local computer to allow for updates - well, I hold my head in my hands in despair. On top of this, on our SIMS server all SIMS users have modify access to all files on the SIMS share, and our help line inform us that that's the way it has to be. Surely this can't be the case? I'd love to know the thinking behind all of this. Excuse the rant! -
[sims] Auto install of SIMS - UAC - securing the server share
digone52 replied to digone52's topic in MIS Systems
Hi vikpaw. Thanks for the suggestions. I'd really love to leave UAC on. The solution can't give them local administrator, as I want to keep a strict policy that they are not local admins of their computer at any time. I'm more concerned about the installation of software that replaces the software we install by policy. I know that this happens currently with the XP laptops where they are local admins, and with a strict policy under Windows 7, there will be no way that our users can replace components of the build, or install products such as VNC which I'd object to. If users are told to shut down and not hibernate, I think that more than half wouldn't follow the instructions to be honest, and a mess would ensue. I know that my messages go unread at the best of times, and then a lot would forget anyway. We have a lot of machines and few staff, so to be rushing around the morning after an upgrade fixing computers is not ideal. I was looking at WPKG | Open Source Software Deployment and Distribution yesterday to deploy. I had a quick look, but it looks like this product might have issues with Windows 7. Might be worth investigating though. I've also contacted our support to see whether Solus 3 will do the job, and if so I asked them when we can have it. -
QUESTIONS 1. Did any of you have to upgrade your switches / network backbone prior to virtualizing. Our switches are probably at least 5 years old and having a current issue with switches crashing when running large backups across the network using backup exec with a backup server at the opposite end of the school. 1a. What speed switches, type of cabling, bandwidth do you use on your virtual network? We kept the existing network in place (HP Procurve - quite old) for clients, but implemented an iSCSI network at gigabit speed between SAN and VMWare servers, and enabled jumbo frames on the iSCSI LAN. The VMWare servers needs lots of NICs - more than one connection (for redundancy) on every connected network. Ours have 10 NICs each, all running at gigabit. 2. Would you go for one physical DC and 2 virtual servers (both DC’s) and a SAN? Or would you approach it differently? We have two domains with two DCs on each, and have virtualised everything. If we completely lost our DCs, well, we'd be in a big mess, but in terms of DCs, you could even restore the vmdk images of the DCs and temporarily run them on a standalone exsi server (if vmware), god forbid. We implemented the SAN first, connected to physicals, and virtualised subsequently. I beleive that you'll need the SAN if you want centralised storage and a high level of fault tolerance - all of your servers can see the SAN, so if one physical dies, anothers can take over, and moving virtualised hosts between physical servers is easy (like VMWare's VMotion). 3. How long do you keep your desktops? We currently refresh most after 3 years but I was thinking we could probably get 5-6 years out of them virtualized as the demand on the actual desktop is less. We have a lot of obselete kit, and I can't say demand on the desktop has changed really in our case. I'd say we virtualised more for the cost, power and fault tolerance rather than performance to be honest. 4. How do you know what spec servers to get for a virtual setup? There is software out there to find out loading on servers from clients and to do analysis in terms of what you need. We were offered software and consultancy, but the costs were so prohibative. We would not have been able to afford the virtualisation if we'd have scoped the project carefully, so it was more wet finger in the air, and so far it has worked for us. Hope that this helps.
-
Did you manage to fix this? If not, then do your users usually have to authenticate against the ISA server? Is you internet connection using a transparent proxy? Last summer our ISP changed, and our connection changed from a transparent proxy to a non-transparent proxy, and all of a sudden all computers needed to use the ISA server as an explicit proxy server rather than just using it as a default router. This change meant that programs such as you mention needed a proxy set. Our pupils need to authenticate using integrated authentication (so they are not aware they are authenticating), whereas the staff connection is anonymous. Whether you force authentication against the ISA server or allow anonymous connections is set up within the ISA configuration. If possible I'd try to put a computer upstream to the ISA server and see if the responses you get are as expected. Hope this helps!
-
[sims] Auto install of SIMS - UAC - securing the server share
digone52 replied to digone52's topic in MIS Systems
It does look like I'm going to have to find out more about SOLUS 3, even though our support don't currently use it, and in the meantime switch off UAC if that's what it takes. As you say Arthur, it isn't a good idea, but I think necessary in the short term to get SIMS upgrading unless there is an avenue I have not explored. Presumably I can leave UAC enabled on the few users who are local admins?
