computer_expert
Members-
Posts
1,188 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by computer_expert
-
Migrate from KMS to embedded license activation
computer_expert replied to CHiLL's topic in How do you do....it?
Remove the DNS srv record which points to KMS/ADBA. Set the device to use the firmware licence afterwards to stop it obtaining the licence from KMS/ADBA. KMS/ADBA will still be active if you need to switch back but you will either need to set the KMS details manually on each device or reinstate the srv record. -
A long time ago the R210ii servers were shallow compared to the R310/R410. Have a look at the R250 too: https://www.dell.com/en-uk/shop/ipovw/poweredge-r250
-
I've got an 8 port 1930 and I really miss the CLI. I find the local UI cumbersome especially when using VLANs (not sure what the cloud portal is like for switches as you lose a large number of features when linked to the cloud).
-
Can I use idrac card from Dell PowerEdge T420 in T430
computer_expert replied to TwistedHelixis's topic in Hardware
The idrac licence is tied to the servers' service tag in 12th gen and newer servers (your T420). 11th gen machines with idrac 6 (eg. the R710/T710) were the last ones where the licence was stored on the plug in idrac module. The 12th gen plug in module is just the extra ethernet port and SD card slot (if you have idrac enterprise with the SD card bits). -
Managing ipads - for the first time
computer_expert replied to timbo343's topic in How do you do....it?
You'd be better off managing the iPad via Intune. Intune isn't great for managing iPads/Macs, but google workspace is much, much worse for managing iPads (when I last tried it a few years ago. Not sure if it's improved since). I went with the paid version of Mosyle to manage our iPads and that has been going strong ever since. I found I had to to a lot of hands on set up with each iPad on workspace compared to Mosyle. -
Micro-server to host DNS and DHCP
computer_expert replied to TheHyperTechie's topic in Cloud Services
I would at least go for something server grade such as the HP microserver gen10 plus. Bonus is that it has iLO for out of band management and better quality components that are built for 24/7 operation. My original microservers (N36L circa 2011) lasted a very long time and were bulletproof. Sadly not quite as cheap as the optiplex you linked but will do the trick. -
Not if you delegate permissions to the AD account (or non privileged group) to join the domain. Example, with script here. This script will only help with the permissions for AD domain join account. For the MDT access denied message, you need to verify the user/group has access on both the file/folder permissions AND share permissions for your deployment share. Also if you use the following settings, ensure they are correct in bootstrap.ini: UserID= UserPassword= UserDomain= PLEASE NOTE - the settings above are stored in plain text on the ISO and in boot.wim I would also try fully regenerating the boot image (there's a check box to force a full rebuild of boot.wim when you update the deployment share) and ensure that the hyper-v vm is pointing to the correct ISO. I've seen force rebuilding the boot image to help with credential issues on the odd occasion.
-
Check that your HBA/RAID cards, NICs and any other add in cards are supported on the VMware HCL posted above. Also check BIOS and firmware revisions of the servers and SAN are not too old as well. Make sure you have good backups of vCenter (as @Davit2005 mentions). Due to complications with our VCSA 6.7 to 7 upgrade we had to deploy a new VCSA 7 system which worked out better as it allowed me to cut out years of rubbish and slim down the size of the appliance. Once you have updated VCSA to 7, and the hosts to 7.0U3, make sure you update both the appliance and the hosts so they have the latest security baseline (like the monthly windows patches as a similar comparison). For the ESXi hosts, you can use the Update Manager tab in vCenter to apply the latest ESXi security baseline. Don't upgrade the VMware Virtual machine hardware version until you are absolutely certain that all your esx hosts are running the same version (and that you won't be downgrading to an earlier release of ESXi)
-
I'd use a managed apple ID instead. Take note of what services are not permitted though.
-
I guess you could have as many instant on switches as you want if they are not connected to the ION portal, but management may be a bit of a headache. If you connect them to the ION portal, then you can only have 50 devices per site, but you could have multiple sites (a site per building/floor etc). The switches also do not have a CLI and are web managed only. The switches can be managed outside of the portal, but the access points cannot (for that you would need to move up to the Instant (IAP) series of AP)
-
It's been increased to 50 devices recently (e.g 49 switches & 1 AP or 20 switches & 30 APs) per site with a max of 150 sites I believe. The instant on switches can be locally managed (and give you a lot more features than when connected to the ION portal).
-
Stop Aruba InstantOn from acting as DHCP server.
computer_expert replied to Rob_D's topic in Wireless Networks
The AP22 is connected to a POE capable HP 2530 with multiple VLANs tagged on the port the AP is connected to. Each of the SSIDs has a VLAN tag assigned in IP assignment on the instant on portal. Example: AP management - VLAN 100 (untagged on switch), no management VLAN set in instant on AP settings SSID1 - VLAN101 (tagged on switch port), also set as VLAN101 in instant on portal SSID settings SSID2 - VLAN102 (tagged on switch port), also set as VLAN102 in instant on portal SSID settings Have you tried the old trick of rebooting the AP11 to see if it pulls down the config changes from the cloud? -
Stop Aruba InstantOn from acting as DHCP server.
computer_expert replied to Rob_D's topic in Wireless Networks
I've got a similar setup with another server handing out dhcp to clients and it appears to work fine. I'm piping all the traffic from an SSID into a defined VLAN though. I've just tried on an AP22 and it appears to be working with a test SSID set to: Usage: Employee network IP/Network assignment: same as local network (no VLAN) Network access: always Bandwidth: unlimited Wireless: 2.5 & 5GHz The client IP is leased from the DHCP server running on that subnet without any issue edit - the test SSID was WPA2 only for security -
At least it tells you that the machine may not be compliant with security policies or software updates if you have short cert lifetimes (e.g. a few months). In the case of laptops, then it's even better as it tells you who brings them in regularly. We changed the SSID on our wireless network in October and are still finding people who ignored the repeated emails to bring them in so they find their laptops have been cut off when they are on site. I'm all for 802.1x on the wired ports. Helps if you forget to disconnect a patch cable from the switch end...
-
I think I found what I want for my birthday
computer_expert replied to mikeprice's topic in General Chat
I guess you could always ask the Top Ground Gear Force team how their cooked food tasted (How was it nearly 15 years ago this aired???) It might end up like James' shed and the aforementioned food in TGGF... -
Is there a touchscreen, IWB, touchpad or any other touch input type device connected that's providing a possible erroneous input?
-
[22h2] SCCM win 10 22H2 enablement package
computer_expert replied to mdrabble's topic in Windows 10
Have a look though the following log files - https://support.microsoft.com/en-us/topic/log-files-that-are-created-when-you-upgrade-to-a-new-version-of-windows-9ec8aa31-0cc1-a0b2-2d98-e9c6714349b9 See if you have any hard blocks/safeguard holds on any machines - https://www.systemcenterdudes.com/windows-10-update-hard-block/ I've had a couple of hard blocks which resolved when certain software was upgraded as they were incompatible with the version of windows I tried to upgrade to. -
Home devices and ever increasing Disk Space
computer_expert replied to penfold's topic in General Chat
Phone photos & videos are synced to a local nextcloud VM. The nextcloud VM is backed up via Veeam B&R along with a few other VMs and physical boxes to a NAS. The first NAS is backed up to a second, offline NAS Everything is stored on the first NAS where possible. I do have a tape drive but haven't got round to seeing where that fits in. Yes, this is a home environment and not your local data center! -
You can deny print spooling over a certain size using the 'Restrict the maximum spool size of a print job' setting in NG & MF. Not sure if you can do it in the free Mobility print though.
-
Are all the devices you have plugged into the same switch exceeding the POE budget? SSH into the switch and look at the output from the commands here: https://techhub.hpe.com/eginfolib/networking/docs/switches/WB/15-18/5998-8162_wb_2920_mcg/content/ch03s05.html
-
I built a MDT server today using the Win11 ADK and did the following: Install Windows 11 22H2 ADK and windows PE addon from here - https://learn.microsoft.com/en-us/windows-hardware/get-started/adk-installInstall MDT x64 from here - https://www.microsoft.com/en-us/download/details.aspx?id=54259 Patch the DLLs as described above Create the deployment share Use mkdir to create a blank folder as the W11 22H2 ADK causes MDT console to crash (due to x86 ADK no longer being shipped in W11 22H2) [1] mkdir C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Windows Preinstallation Environment\x86\WinPE_OCs Unticked the x86 support in the deployment properties (also untick the x86 iso image generation) Applied the HTA applications workaround from here - https://learn.microsoft.com/en-us/mem/configmgr/mdt/known-issues Loaded the latest VLSC windows 10 ISO into MDT Configured Customsettings.ini/bootstrap.ini with my site specific settings Imported applications to be deployed during task sequence Created task sequence to deploy W10 image imported in step 8 Updated the deployment share to generate the litetouch image Loaded MDT boot.wim into WDS on a server Boot the client into MDT, run the task sequence (...and 1st time round, watch it fail to install the imported applications due to a typo in a silent install command. Oops!) [1] (search for Ismael here)
-
Apply the fix from Microsoft to program files. If you have already created the deployment share, copy the new x86 DLL to DeploymentShare\Tools\x86 and the x64 DLL to DeploymentShare\Tools\x64. Update the deployment share, making sure the option to completely regenerate the boot image is selected. Once MDT has built the image, load it into WDS and see how you get on. I've never needed to use the mentioned script to get MDT working once I installed the patched DLLs. Would it be worth creating a new deployment share (for testing) once you've installed the patches?
-
I've been forced to use spiceworks cloud after doing a POC of freshdesk (and finding freshdesk better in almost every way). I can't get my head around an IT company that says the work on MFA isn't imminent as of 2 months ago Either way, this won't help the OP. @APMerry, what do the log files in /var/log/tron/sidekiq/current say after you try sending an email from spiceworks? you may need to search those files for smtp and look at the lines before/after. You'd also have to check to see if the mail daemon bits on the spiceworks image can speak with tls settings that office 365 requires(/demands) as I can only find references to end of life versions of ubuntu and help desk server.
