computer_expert
Members-
Posts
1,188 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by computer_expert
-
It looks like the Assessment and Deployment kit entry underneath sophos to me.
-
As Steve21 mentioned, you'll need to remove all of the ADKs you have installed (both the windows 8 and windows 10 ones), then reinstall both parts of the latest windows 10 ADK.
-
Then the machines will just be switched off at the plug rather than shut down properly... I agree with ricki that this isn't a good idea at all (also safeguarding - what happens if a student discovers an unattended PC logged in as a member of staff?).
-
Have a look in SMSProv.log around the time of the failure and see if that gives you any hints. Open the log file in CMTrace rather than notepad (easier to read with CMTrace)
-
Use the English International ISO from VLSC as it has the UK regional settings as default. English: US settings English International: UK settings
-
Having used both, I'd say Hyper V for Education. VMware locks down some of the APIs in the free version of vSphere (of which VM backup is one of them) VMware may have better management tools (vCenter) but MS is catching up fast with Hyper-V (Windows Admin Center). Plus with Hyper-V you don't have to pay for the vSphere license cost on top of the windows licence. With Server Standard, you get 2 VMs included with the base licence (2 Windows Server Standard VMs and the host running only hyper-v).
- 11 replies
-
- hyper v
- primary school
-
(and 3 more)
Tagged with:
-
Do you know if your 4G provider uses CGNAT? If they do, you may well be out of luck with port forwarding. I think most mobile networks in the UK do use CGNAT sadly. Is the 4G router WAN IP the same as your 4G public/external IP? This isn't quite clear in your original post but will be a good indication if you are behind an extra layer of NAT further upstream.
-
I've used RUM before. You can optionally use AUSST to download the updates to a local server and point the clients to that (rather than reaching out to adobe) for updates. https://helpx.adobe.com/uk/enterprise/package/help/using-remote-update-manager.html https://helpx.adobe.com/uk/enterprise/package/help/update-server-setup-tool.html Reading though the docs for AUSST, it looks like it has improved a lot since I last looked at it!
-
I've only got 1 2016 VM left (and that's only because the software vendor doesn't yet support 2019). It's worth upgrading to 2019 just for the time savings when installing windows updates that MS seem to have no interest in fixing it in 2016...
-
Smoothwall alternatives
computer_expert replied to Steveduk's topic in Internet Related/Filtering/Firewall
I wanted to go XG, but we were using the letsencrypt feature of the old UTM at the time. Over 3 years later, and they are still 'considering it' ( https://ideas.sophos.com/forums/330219-xg-firewall/suggestions/13368852-let-s-encrypt-integration ) despite it being the most requested feature ( https://ideas.sophos.com/forums/330219-xg-firewall/filters/top ). After playing around with it at home, it wasn't up to par then (a few years ago). When looking for a new home firewall last year, I gave it another go, and yes it had improved since I last tried it but isn't quite there yet in my eyes. I will give Sophos credit for the way they dealt with the recent SQL injection vulnerability (and subsequent RCE) though.- 44 replies
-
Smoothwall alternatives
computer_expert replied to Steveduk's topic in Internet Related/Filtering/Firewall
Having had some experience with the Sophos 'We're working on it' XG, I'd avoid. The older UTM was much better. Plus the've recently annouced lots of job cuts (partly due to the pandemic): https://www.theregister.com/2020/06/04/sophos_100_redundancies_naked_security/ Have a look at Fortinet Fortigate as an alternative too.- 44 replies
-
You'll never have a totally secure network whatever industry you work in. You can mitigate threats by keeping software up to date (as well as firmware/bios - see the spectre/meltdown vulnerability from a few years ago) and reviewing the system hardening guidance that Microsoft and the UK government, amongst others, publish. I think separate domains for curric/admin are a relic from the past. With the things that microsoft suggest (PAW and the Active Directory administrative tier model) you should be able to keep one domain and save the headache of managing two domains and the assocated infrastructure. User education is pretty important too. Rather than using technical terms, break it down into simple things that users will understand e.g. Would you leave your house/car key in a visible space in your garden whilst popping to the shops? This is the same as leaving a book full of username/passwords on your teachers desk. You'll get people who won't listen/take note, but what can you do if they are set in their ways and refuse to change? Then you've got the poorly coded software that relies on a prehistoric version of flash with more holes than swiss cheese (despite being released last week) to deal with as well.
-
I use the DB pretty much in the same way as boredguy. I use the service tag here (dell) as I find it more reliable after machines have had a NIC swap when the internal one self destructs! Be careful if you use lenovo machines, as they do some weird and wonderful stuff with WMI (where MDT gathers some information from) The roles part is quite handy as I can then say that dells get (for example) the command update suite of programs and HP get their management utilities. You can then break it down further so that elitedesk 800s get put in a certain OU with a specific admin password and optiplex 3070s get put in a different OU with a different admin password and organisation name.
-
Meraki cloud controller and config question
computer_expert replied to Scifigirl's topic in Wireless Networks
Unless you want to add more access points where you have to pay for a cloud licence per AP (not including the price of the hardware). We ended up moving away from meraki due to the costs of renewal and new hardware. -
Meraki cloud controller and config question
computer_expert replied to Scifigirl's topic in Wireless Networks
The meraki devices reach out to the cloud to download the config. There's a very limited UI on the devices themselves as all config is done in the cloud controller (providing the UI hasn't been disabled in the dashboard). Once you add the devices to the organisation (see here) they will download and install the config once they have internet access. Edit - changed terminology and added a link -
Yep, Only single packs come with the POE injectors. Both the single packs and 5 pack boxes have the mounting brackets. The assumption with the larger 5 pack is that you have a POE switch to power them all. Double check with supplier as old single pack stock won't have the injector. I can't remember when it was changed to include the injector (but was at some point in the last few years). Edit: The above applies to UAP-AC-PRO models
-
Checked any old mobile phones/tablets with old wireless network details/old exchange details saved? Any windows services configured to use your username/password to run? Any scheduled tasks also configured to use your old credentials? Any manually configured mapped drives using old credentials?
-
Providing you have managed switches (that support 802.1x) everywhere, you should look at enabling 802.1x with certificate based authentication as that will stop people from connecting their own machines and gaining access to your internal network.
-
Block PC on network if it has no antivirus
computer_expert replied to andydis's topic in Windows Server 2016
It was Network access protection I think. However, MS deprecated it in Server 2012R2: https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-top (see the blue important bit just above the "Windows Server Editions and NPS" section) -
Mosyle MDM and apple school manager (for DEP enrolled devices) are both free I think. Profile manager is a pain in the arse once it stops working. Do the problematic devices have the profile manager Root CA certificate imported? Are the server's certificates still valid? I think you can check this in one of the top sections of the server app (It's been a while since I last used a mac server so can't remember the correct terminology)
-
If you don't want SCCM to use a drive you can create a blank file in the drive root called NO_SMS_ON_DRIVE.SMS to stop this. I'm not sure if it applies after SCCM has started using a drive though but may be useful for future reference.
-
The SQL collation was going to be my next suggestion (but I had the impression this was for a standalone WSUS box!) Unless that's a typo, I think you may be using the wrong collation for SCCM. I think it should be SQL_Latin1_General_CP1_CI_AS. One of the SQL setup scripts for WSUS also lists this as a requirement too.
-
I managed to get past the error in the first post by running the following in SQL management studio: C:\Program Files\Update Services\Database\UpdateSchemaVersion.sql After running that it then threw up a load of other errors which I wasn't able to fix by running other scripts in the directory above. I ended up deleting the DB via SQL management studio (but not removing the WSUS role/content directory) then running the command below in powershell which seemed to get it into a usable state. wsusutil.exe postinstall SQL_INSTANCE_NAME=server\SQLEXPRESS If none of that works, maybe try a fresh install but leave it in a workgroup until after WSUS is set up to see if you have a GP setting causing issues somewhere.
