Jump to content

Blue_Cookeh

Members
  • Posts

    1,485
  • Joined

  • Last visited

Everything posted by Blue_Cookeh

  1. It sounds to me like someone setup DHS-CORE as a Certificate Authority, then decided to remove the role/server without properly cleaning all the references out of AD. You'll need to go through your Active Directory schema and remove any references to DHS-CORE. See this guide on how to go about it, it's still relevant for 2008/2012: https://support.microsoft.com/en-us/kb/889250 You'd know if you had another CA, since there would be references to it all over AD like this one. Can I also suggest that if you're going to be setting up a new CA yourself, you do your research and properly plan it? Many people just go around sticking a CA on a DC and call it a day, when in actual fact you should be looking at offline Root CAs and things to keep it secure.
  2. I don't think it's particularly fair to look at it like that. Primary schools for example don't have the infrastructure to support RADIUS. Sure I can deploy it and our kit is capable of it, but it aint gonna be pretty.
  3. AFAIK SP1 adds full support for Win10, so it's recommended you upgrade.
  4. I thought I was going to have to investigate our firewall, good to know it's not just me! Just finished our SCCM task sequence for Win10, ready to deploy on Monday!
  5. I'm not trying to be an Apple fanboy, but just bear in mind Android seems to suffer from a horrendous "slow down" problem over the span of a couple of years (speaking from a lot of personal experience!) even if you install stock Android ROMs etc. Personally I just moved from an S4 to an iPhone 6 and haven't looked back If you do go down that route just remember the iPhone 6s is coming in September. It'll be hard to get hold of for a few months and it'll only be a minor spec bump (always is in the S releases) though. Sure, I miss being able to tinker with my phone and install custom ROMs but on the other hand my camera is awesome and I've had ZERO app crashes since I've owned the thing!
  6. Generally, no. You need to tag the uplink port as a trunk, which the other switch wont know what to do with so it'll only pass traffic on the uplink's untagged VLAN.
  7. Blue_Cookeh

    AD CA

    Generally you'd want to plan a CA deployment before installing the role so that you maintain full control over any of the certificates it gives out, hence why keeping your root CA offline is generally a good thing!
  8. As the title says! Has anyone got any ideas how I can do this? Obviously SCCM can inject Windows updates into the WIM, or even apply them during the OSD but I'm honestly not sure how to shove all existing Office updates down. The last piece of the Windows 10 deployment puzzle for us
  9. Blue_Cookeh

    AD CA

    Can it if it hasn't issued anything. If you need a local CA, do it properly with an offline root etc. You might find having one is beneficial later on down the line, we use ours for auto enrolment on our domain computers so that can communicate with SCCM more securely, and automatically trust our SSL inspection proxy.
  10. Office doesn't like authenticated proxies, add a list of exemptions for MS/Office sites on your proxy. The "mini install" I'm almost certain can be gotten rid of if you setup all the relevant Office MSP customisation and group policy objects. If you don't want to whitelist those sites from authentication, then disable Office's online functionality: https://support.microsoft.com/en-us/kb/891158 It's been a while since I deployed Office 2013, but we don't get that installer at all on new users.
  11. Import them manually most likely. You can usually find them in the C:\windows\PolicyDefinitions folder on the Windows client install. IIRC you must then use RSAT from a Windows 10 install until Server 2016 is out and deployed in your environment.
  12. Hi Guys, I'm looking at improving our monitoring situation at the moment and was wondering what you guys use in your environments? So far I've given Nagios and LibreNMS a go, Nagios was nice but it was far too time consuming to configure and right now LibreNMS seems pretty slick albeit basic. Any other suggestions? I'm looking for something that can do Windows/Linux/HP switches/Ubiquiti (hopefully?) gear and possibly tie back into our UPS' and iDRAC Enterprise cards.
  13. If you're going down the VLAN route you need to use different subnets on each one since you'll have to route between them somewhere to keep the WiFi traffic separate. Not splitting the subnets up is going to cause you a major headache later on when it comes to firewalling/routing the VLANs. Your DHCP server can cater for all VLANs using IP Helpers on the switches. Otherwise, stick all your WiFi traffic on one switch, PCs on another switch, then connect each server to both switches. You'll still need different subnets so the servers know what to do.
  14. Is this the freebie from a webinar? A couple of close friends tell me if you tell them it's for your lab use they'll grant you another 3 years, but I suppose it's pot luck.
  15. Both device and Apple certificates are fine on mine, most still don't check in... Looks like we're alone so far @enjay! I'm tempted to deploy an on site MDM at this point.
  16. This. See more info here.
  17. It's a complete PITA to get Meraki through a firewall, take a look at their port ranges and IP addresses https://dashboard.meraki.com/manage/support/firewall_configuration I've punched umpteen holes through our proxies and firewalls. I've watched our logs in realtime and there's NOTHING being blocked, yet 95% of our devices don't check in.
  18. We don't have the connection or kit for redundancy.
  19. Is there any plan to allow this when not using ADFS? I would still like the SSO aspect but we're using Directory Sync.
  20. Is this a subnet provided by your local LA/ISP? If so I would look at firewalling them off and using your own subnets. If you absolutely have to do this I'd do: 1. Servers 2. Workstations 3. Infrastructure (last since it's only management, unless you use L3 switches in which case do Infrastructure first) Just my 2c.
  21. We do this with our county connection and our external ADSL so we can do things like NTP and SMTP without punching through county firewalls. We use a Sophos SG115 UTM to dot his, but it won't be true 'bonding' (since this has to be done at the ISP's end), it'll be load balancing for outbound connections. I like to think it's pretty good at it too, you get a lot of control over what traffic goes where.
  22. What's your budget looking like for this? We're a relatively small school and I found that a couple of Dell R220 servers spec'd up with more RAM, iDRAC Enterprise, and a couple of SSDs in RAID work out wonderfully for a 2 node HyperV cluster. You can then back the VMs up to a NAS or something each night and call it finished.
  23. Installed the XJ-A130 models here a few years ago (the original models of Casio's LED line I think?) and haven't looked back Maintenance is simply wiping the dust off the edge every so often and the image is fantastic... although we did just replace them all for TVs!
  24. Back up your config, but I'm pretty sure if you stop the service, run the new install, then start it again it will keep all your info and migrate it to the newer version.
  25. Arguably he should be using VLANs for QoS/some form of security if he's running IP based CCTV anyway, so broadcasts become a moot point.
×
×
  • Create New...