Blue_Cookeh
Members-
Posts
1,485 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Blue_Cookeh
-
It sounds to me like someone setup DHS-CORE as a Certificate Authority, then decided to remove the role/server without properly cleaning all the references out of AD. You'll need to go through your Active Directory schema and remove any references to DHS-CORE. See this guide on how to go about it, it's still relevant for 2008/2012: https://support.microsoft.com/en-us/kb/889250 You'd know if you had another CA, since there would be references to it all over AD like this one. Can I also suggest that if you're going to be setting up a new CA yourself, you do your research and properly plan it? Many people just go around sticking a CA on a DC and call it a day, when in actual fact you should be looking at offline Root CAs and things to keep it secure.
-
"WiFi Sense" in Windows 10 - share WPA keys with friends...
Blue_Cookeh replied to pete's topic in Windows 10
I don't think it's particularly fair to look at it like that. Primary schools for example don't have the infrastructure to support RADIUS. Sure I can deploy it and our kit is capable of it, but it aint gonna be pretty. -
AFAIK SP1 adds full support for Win10, so it's recommended you upgrade.
-
I thought I was going to have to investigate our firewall, good to know it's not just me! Just finished our SCCM task sequence for Win10, ready to deploy on Monday!
-
I'm not trying to be an Apple fanboy, but just bear in mind Android seems to suffer from a horrendous "slow down" problem over the span of a couple of years (speaking from a lot of personal experience!) even if you install stock Android ROMs etc. Personally I just moved from an S4 to an iPhone 6 and haven't looked back If you do go down that route just remember the iPhone 6s is coming in September. It'll be hard to get hold of for a few months and it'll only be a minor spec bump (always is in the S releases) though. Sure, I miss being able to tinker with my phone and install custom ROMs but on the other hand my camera is awesome and I've had ZERO app crashes since I've owned the thing!
-
Generally, no. You need to tag the uplink port as a trunk, which the other switch wont know what to do with so it'll only pass traffic on the uplink's untagged VLAN.
-
Generally you'd want to plan a CA deployment before installing the role so that you maintain full control over any of the certificates it gives out, hence why keeping your root CA offline is generally a good thing!
-
Can it if it hasn't issued anything. If you need a local CA, do it properly with an offline root etc. You might find having one is beneficial later on down the line, we use ours for auto enrolment on our domain computers so that can communicate with SCCM more securely, and automatically trust our SSL inspection proxy.
-
Office doesn't like authenticated proxies, add a list of exemptions for MS/Office sites on your proxy. The "mini install" I'm almost certain can be gotten rid of if you setup all the relevant Office MSP customisation and group policy objects. If you don't want to whitelist those sites from authentication, then disable Office's online functionality: https://support.microsoft.com/en-us/kb/891158 It's been a while since I deployed Office 2013, but we don't get that installer at all on new users.
-
Import them manually most likely. You can usually find them in the C:\windows\PolicyDefinitions folder on the Windows client install. IIRC you must then use RSAT from a Windows 10 install until Server 2016 is out and deployed in your environment.
-
Hi Guys, I'm looking at improving our monitoring situation at the moment and was wondering what you guys use in your environments? So far I've given Nagios and LibreNMS a go, Nagios was nice but it was far too time consuming to configure and right now LibreNMS seems pretty slick albeit basic. Any other suggestions? I'm looking for something that can do Windows/Linux/HP switches/Ubiquiti (hopefully?) gear and possibly tie back into our UPS' and iDRAC Enterprise cards.
-
If you're going down the VLAN route you need to use different subnets on each one since you'll have to route between them somewhere to keep the WiFi traffic separate. Not splitting the subnets up is going to cause you a major headache later on when it comes to firewalling/routing the VLANs. Your DHCP server can cater for all VLANs using IP Helpers on the switches. Otherwise, stick all your WiFi traffic on one switch, PCs on another switch, then connect each server to both switches. You'll still need different subnets so the servers know what to do.
-
Is this the freebie from a webinar? A couple of close friends tell me if you tell them it's for your lab use they'll grant you another 3 years, but I suppose it's pot luck.
-
Meraki MDM - Devices Not Checking In
Blue_Cookeh replied to enjay's topic in Internet Related/Filtering/Firewall
Both device and Apple certificates are fine on mine, most still don't check in... Looks like we're alone so far @enjay! I'm tempted to deploy an on site MDM at this point. -
This. See more info here.
-
Meraki MDM - Devices Not Checking In
Blue_Cookeh replied to enjay's topic in Internet Related/Filtering/Firewall
It's a complete PITA to get Meraki through a firewall, take a look at their port ranges and IP addresses https://dashboard.meraki.com/manage/support/firewall_configuration I've punched umpteen holes through our proxies and firewalls. I've watched our logs in realtime and there's NOTHING being blocked, yet 95% of our devices don't check in. -
Office 365 - Outlook and ADFS SSO - Disapointment
Blue_Cookeh replied to FN-GM's topic in Cloud Services
We don't have the connection or kit for redundancy. -
Office 365 - Outlook and ADFS SSO - Disapointment
Blue_Cookeh replied to FN-GM's topic in Cloud Services
Is there any plan to allow this when not using ADFS? I would still like the SSO aspect but we're using Directory Sync. -
Is this a subnet provided by your local LA/ISP? If so I would look at firewalling them off and using your own subnets. If you absolutely have to do this I'd do: 1. Servers 2. Workstations 3. Infrastructure (last since it's only management, unless you use L3 switches in which case do Infrastructure first) Just my 2c.
-
Sophos UTM Bonded ADSL
Blue_Cookeh replied to karldenton's topic in Internet Related/Filtering/Firewall
We do this with our county connection and our external ADSL so we can do things like NTP and SMTP without punching through county firewalls. We use a Sophos SG115 UTM to dot his, but it won't be true 'bonding' (since this has to be done at the ISP's end), it'll be load balancing for outbound connections. I like to think it's pretty good at it too, you get a lot of control over what traffic goes where. -
Starting Over WITH Virtualisation...
Blue_Cookeh replied to GRitchie's topic in How do you do....it?
What's your budget looking like for this? We're a relatively small school and I found that a couple of Dell R220 servers spec'd up with more RAM, iDRAC Enterprise, and a couple of SSDs in RAID work out wonderfully for a 2 node HyperV cluster. You can then back the VMs up to a NAS or something each night and call it finished. -
Back up your config, but I'm pretty sure if you stop the service, run the new install, then start it again it will keep all your info and migrate it to the newer version.
-
Arguably he should be using VLANs for QoS/some form of security if he's running IP based CCTV anyway, so broadcasts become a moot point.
