computer_expert
Members-
Posts
1,188 -
Joined
-
Last visited
Reputation
5,397 ExcellentAbout computer_expert

Recent Profile Visitors
The recent visitors block is disabled and is not being shown to other users.
-
Migrate from KMS to embedded license activation
computer_expert replied to CHiLL's topic in How do you do....it?
Remove the DNS srv record which points to KMS/ADBA. Set the device to use the firmware licence afterwards to stop it obtaining the licence from KMS/ADBA. KMS/ADBA will still be active if you need to switch back but you will either need to set the KMS details manually on each device or reinstate the srv record. -
A long time ago the R210ii servers were shallow compared to the R310/R410. Have a look at the R250 too: https://www.dell.com/en-uk/shop/ipovw/poweredge-r250
-
I've got an 8 port 1930 and I really miss the CLI. I find the local UI cumbersome especially when using VLANs (not sure what the cloud portal is like for switches as you lose a large number of features when linked to the cloud).
-
Can I use idrac card from Dell PowerEdge T420 in T430
computer_expert replied to TwistedHelixis's topic in Hardware
The idrac licence is tied to the servers' service tag in 12th gen and newer servers (your T420). 11th gen machines with idrac 6 (eg. the R710/T710) were the last ones where the licence was stored on the plug in idrac module. The 12th gen plug in module is just the extra ethernet port and SD card slot (if you have idrac enterprise with the SD card bits). -
Managing ipads - for the first time
computer_expert replied to timbo343's topic in How do you do....it?
You'd be better off managing the iPad via Intune. Intune isn't great for managing iPads/Macs, but google workspace is much, much worse for managing iPads (when I last tried it a few years ago. Not sure if it's improved since). I went with the paid version of Mosyle to manage our iPads and that has been going strong ever since. I found I had to to a lot of hands on set up with each iPad on workspace compared to Mosyle. -
Micro-server to host DNS and DHCP
computer_expert replied to TheHyperTechie's topic in Cloud Services
I would at least go for something server grade such as the HP microserver gen10 plus. Bonus is that it has iLO for out of band management and better quality components that are built for 24/7 operation. My original microservers (N36L circa 2011) lasted a very long time and were bulletproof. Sadly not quite as cheap as the optiplex you linked but will do the trick. -
Not if you delegate permissions to the AD account (or non privileged group) to join the domain. Example, with script here. This script will only help with the permissions for AD domain join account. For the MDT access denied message, you need to verify the user/group has access on both the file/folder permissions AND share permissions for your deployment share. Also if you use the following settings, ensure they are correct in bootstrap.ini: UserID= UserPassword= UserDomain= PLEASE NOTE - the settings above are stored in plain text on the ISO and in boot.wim I would also try fully regenerating the boot image (there's a check box to force a full rebuild of boot.wim when you update the deployment share) and ensure that the hyper-v vm is pointing to the correct ISO. I've seen force rebuilding the boot image to help with credential issues on the odd occasion.
-
Check that your HBA/RAID cards, NICs and any other add in cards are supported on the VMware HCL posted above. Also check BIOS and firmware revisions of the servers and SAN are not too old as well. Make sure you have good backups of vCenter (as @Davit2005 mentions). Due to complications with our VCSA 6.7 to 7 upgrade we had to deploy a new VCSA 7 system which worked out better as it allowed me to cut out years of rubbish and slim down the size of the appliance. Once you have updated VCSA to 7, and the hosts to 7.0U3, make sure you update both the appliance and the hosts so they have the latest security baseline (like the monthly windows patches as a similar comparison). For the ESXi hosts, you can use the Update Manager tab in vCenter to apply the latest ESXi security baseline. Don't upgrade the VMware Virtual machine hardware version until you are absolutely certain that all your esx hosts are running the same version (and that you won't be downgrading to an earlier release of ESXi)
-
I'd use a managed apple ID instead. Take note of what services are not permitted though.
-
I guess you could have as many instant on switches as you want if they are not connected to the ION portal, but management may be a bit of a headache. If you connect them to the ION portal, then you can only have 50 devices per site, but you could have multiple sites (a site per building/floor etc). The switches also do not have a CLI and are web managed only. The switches can be managed outside of the portal, but the access points cannot (for that you would need to move up to the Instant (IAP) series of AP)
-
It's been increased to 50 devices recently (e.g 49 switches & 1 AP or 20 switches & 30 APs) per site with a max of 150 sites I believe. The instant on switches can be locally managed (and give you a lot more features than when connected to the ION portal).
-
Stop Aruba InstantOn from acting as DHCP server.
computer_expert replied to Rob_D's topic in Wireless Networks
The AP22 is connected to a POE capable HP 2530 with multiple VLANs tagged on the port the AP is connected to. Each of the SSIDs has a VLAN tag assigned in IP assignment on the instant on portal. Example: AP management - VLAN 100 (untagged on switch), no management VLAN set in instant on AP settings SSID1 - VLAN101 (tagged on switch port), also set as VLAN101 in instant on portal SSID settings SSID2 - VLAN102 (tagged on switch port), also set as VLAN102 in instant on portal SSID settings Have you tried the old trick of rebooting the AP11 to see if it pulls down the config changes from the cloud? -
Stop Aruba InstantOn from acting as DHCP server.
computer_expert replied to Rob_D's topic in Wireless Networks
I've got a similar setup with another server handing out dhcp to clients and it appears to work fine. I'm piping all the traffic from an SSID into a defined VLAN though. I've just tried on an AP22 and it appears to be working with a test SSID set to: Usage: Employee network IP/Network assignment: same as local network (no VLAN) Network access: always Bandwidth: unlimited Wireless: 2.5 & 5GHz The client IP is leased from the DHCP server running on that subnet without any issue edit - the test SSID was WPA2 only for security -
At least it tells you that the machine may not be compliant with security policies or software updates if you have short cert lifetimes (e.g. a few months). In the case of laptops, then it's even better as it tells you who brings them in regularly. We changed the SSID on our wireless network in October and are still finding people who ignored the repeated emails to bring them in so they find their laptops have been cut off when they are on site. I'm all for 802.1x on the wired ports. Helps if you forget to disconnect a patch cable from the switch end...
