Jump to content

karlr

Members
  • Posts

    82
  • Joined

  • Last visited

Everything posted by karlr

  1. Centrastage sounds a tiny bit like Spiceworks. Do you know if they offer an on-premise version or is it just cloud-based? What is the remote support tool like (I've read that they include VNC in their agent)? Does it includes things like remote screen blanking? Also any rough ideas on the pricing or licensing front - I've seen things around on the web suggesting its something like £1/month/managed device for the "business" package. What would count as a managed device, just something you can install the agent on? (I'm assuming it can pick up things like switches, printers etc. via SNMP and the like).
  2. I have been tasked with researching/proposing a new solution that includes a help desk, asset management, and the ability to remote support (e.g. VNC) to users on site. We currently have none of these. I'm just looking to get a feel for what sort of solution others may be using (this is for an independent school), and get some feedback on what I'm currently looking at. Help desk For the help desk/ticketing component, I am currently considering: Spiceworks SysAid (On-premise) OSTicket Kayako (Download) Web Help Desk (SolarWinds). Spiceworks is probably my favourite pick right now, simply because it is so easy to use + customise/brand, and generally seems geared specifically for IT. Having a good experience for our end users is very important, and the fact that Spiceworks seems to supports Active Directory SSO for the user portal with very little fuss is great. Dragging and dropping to design the portal, and being able to create custom ticket forms + attributes/fields is also quite nice. As for e-mail queues, this seems to be quite robust as well, and taking a look at the E-mail templates/variables I think some very professional looking notifications could be created. I'm also quite fond of OSTicket, having used it in another project. I'm glad to see the newest versions are getting better. This could be customized to our hearts' content, considering it is open-source. I am a little concerned about the help desk aspects of SysAid and Web Help Desk; the whole category soup that users would click through to identify their problem seems designed to help route a much larger ticket volume than we would anticipating and would likely confuse our end users. One advantage SysAid has is that it integrates the ticketing, asset management, and the remote support into a single product. Kayako is certainly a solid solution for ticketing, although like SysAid and Web Help Desk, if you want to customise the look and feel it seems all you can do is download a pack of HTML + CSS and make your changes to that. Asset Management On the asset management side of things I'm looking at: Parago School Asset Manager Spiceworks SysAid Web Help Desk (SolarWinds). Kayako "Advanced Assets Module" The first two, Parago and School Asset Manager, are not really "IT Focused". These would certainly be very useful to the school as a whole, but probably aren't the best place to start since our project is IT specific, especially considering the pricing structure. We have had on-site demonstrations for both and were particularly impressed with Parago, with the way it organized assets and provided a virtual representation of the school. Spiceworks again seems to handle asset management quite well (I only tested it in inside a virtual environment so far, so haven't inventoried things like switches or printers). I have seen other spiceworks users complain about performance/impact of scanning on the network so I'm a little concerned about how well this would work in production. The tools you get in Spiceworks for assets are a bonus too (WOL, one click-VNC, etc.) I did have a few issues getting SysAid to properly WMI scan and deploy its agent to assets. This seems to have been eventually resolved when I pushed out some firewall exceptions (though I had been trying with the client firewalls disabled at one point). I haven't played too much with Web Help Desk's asset management so far, although I can see it does include a WMI scanner alongside its integration with 3rd party network discovery tools. Remote support Products I've looked at for remote support: VNC (RealVNC Enterprise, UltraVNC, TightVNC) ABTutor Impero SysAid Dameware Mini-Remote Control (SolarWinds) VNC is an obvious choice, although unfortunately the open-source versions are a little flaky with encryption/AD integration which would be nice to have. UltraVNC does have a screen blanking feature however, which not even RealVNC Enterprise fully supports (you would need to toggle the blanking on the server settings and then reconnect for this). I have used ABTutor v6 quite a bit in a past role, and generally found it to be quite a nice solution. I did encounter issues with the mirror driver on Windows 7 however, preventing Aero from working and more importantly breaking some D&T designing software. Hopefully the situation is better in v7. It's also a shame that AB doesn't seem support any form of authentication other than the connection password.. though perhaps we could configure the windows firewall to only allow connections from a management subnet/VLAN etc. It would also be nice if AB supported a command like argument to directly connect & watch a client; this way we could integrate for example Spiceworks using CustomURL to do a one click from ticket/asset to remote support (the best AB can do right now seems to be the -g flag to bring up a specific group). Impero is quite popular and seems to be packed with a lot of features. Unfortunately as some others on the forum have pointed out, it does come with a premium price tag. SysAid does come with a remote support aspect, however it appears to be licensed per channel, and isn't cheap. After getting it working, I discovered that it is merely a customized UltraVNC plus a more limited HTML5 client. Paying £100s more just so we can run more than one UltraVNC session at a time doesn't sound great. The Dameware remote control solution seems nice, including its own enhanced protocol as well as being able to connect to VNC/RDP. --- Bit of a long post I know, but if anyone currently has such a solution, is working on one, or has any experience with any of these products it would be useful to hear from you. Thanks, Karl
  3. Have run memtest86+ on the laptop as well as a disk surface scan; it happens on multiple different laptops too.
  4. We don't have sccm sadly. In terms of taskmgr it doesn't help us much after the fact and there's nothing out of the ordinary prior. As far as I know the staff member uses the laptop in a static location and thus I don't think it will be hibernated as a matter of course (not sure if you're speaking about special sccm functions or bog standard windows functionality). We indeed have run a virus scan on the user's home drive, and nothing is found. Although it appears that we do now receive some false positives regarding a bunch of PDF files from a specific vendor only while they're in the CSC (Offline files) directory. I'm assuming it's just a something dodgy in a recent definitions update (We're using AVG Anti-Virus Business Edition 2011). I am logging on the laptop with the teachers own credentials as well as my own in an attempt to reproduce the behavior. Don't think differing chipsets or drivers could be an issue, as we are testing this out on the same physical laptops with the same build that the teacher experiences the problem with.
  5. We have been rolling out Windows 7 Enterprise on Toshiba Tecra A10 laptops to certain members of staff. In general this has worked out very well, our build seems to be running smoothly and there are very few complaints about the system itself. However, one particular member of staff is suffering a reoccurring problem whereby the system will very much freeze; the mouse cursor will still move, but the UI will not respond at all. Ctrl+Alt+Del doesn't do anything either. The hard drive light is constantly on, which is why I suspect the system may be badly thrashing. To try to resolve this problem initially, we simply swapped out the laptop, and then tried swapping out hard drives (we have some spare laptops/drives with identical builds ready to go). This freezing was apparently happening daily and could only be resolved with hard power-off, which of course could further damage the state of the laptop. We've had to give this member of staff their old Windows Xp based laptop back for the time being as the problem was so severe. We have deployed several of these laptops, with identical builds. No-one else appears to be suffering a problem of this sort. We have also tried reproducing the freeze ourselves on the build and the specific laptops used by the staff member. The only method we have discovered to put the system in this state is by running prime95 and testing "lots of ram". prime95 attempt to allocate about 1.5gb (system has 2gb). This causes the system to grind to a halt before it can even start stressing the CPU. When starting up scores of applications however, the system seems to cope quite well. We opened everything we could think of/find on the start menu, including the entire office suite, adobe reader, serif photoplus, various MMC consoles, a few educational applications, starboard, and a lot more. Ended up with two whole rows of applications on the taskbar. To top it all off I even ran prime95 in it's CPU stressing mode (only tests some ram), and starting playing animations in PowerPoint 2010. The system remained perfectly stable and even far more useful than one of our old Xp laptops. Note that we are running the x64 version of Windows 7, and I understand that this might not be the best thing for a machine with only 2gb of ram, but we are keen to try to standardize on x64. As I've mentioned above however, it doesn't like it would impact a generous workload. Does anyone have any experience with otherwise happy systems thrashing like crazy? It seems as though this teacher must somehow be allocating massive amounts of ram, but we can't figure out how this is possible with the applications they are using. It seems all we can do is give the teacher another freshly built laptop, but with various performance monitoring/application logging configured to try to discover where and when the problem manifests.
  6. Hi, We're currently using Google Apps for student and staff e-mail. Between the GMail interface and Google Apps Sync for Outlook, it isn't half bad. Unfortunately, because the Google Apps domain is effectively county wide, we're apparently unable to make use of any of the shared address book features. Thus we've had less than ideal solutions in place for staff to look up the addresses of other staff, ranging from looking in an excel spread sheet, to importing a CSV file to GMail or Outlook. Naturally an import will quickly become out of date. Our head is now interested in a real centralized address list, complete with distribution lists. Has anyone else had any experience with setting up global address books without Exchange? (and preferably without throwing any money at the problem!) My first thought was to try to emulate the Exchange GAL by having Outlook query an LDAP server. As Outlook does not appear to support integrated Windows authentication when binding to LDAP, using Active Directory directly would be problematic. Thus I created an AD LDS/ADAM instance and enabled anonymous binding - this seems to work well for individual contacts, and syncing it with the staff addresses in AD would likely be a case of creating a scheduled task that invoked ldifde (and did a bit of cleaning up). Unfortunately I can't for the life of me figure out how to store distribution lists that Outlook recognizes - there's a few guides on emulating the GAL in OpenLDAP, but nothing definitive on how to create proper lists. There's also the fact that this address book would likely be unavailable if the user is not connected to our network - i.e. they'd be unable to get the list of contact when they take their laptop home. So the second solution would be to write some sort of login script that utilises Outlook automation - querying a directory, and creating the appropriate contacts and lists inside outlook (hopefully in a special contacts folder so as to not disturb the user's own contacts). This seems like it would be the simplest and most robust solution. There will be a small learning curve however (the API itself seems quite good, but I haven't yet found what I'd call a good reference). From what I understand we're looking at deploying something this week... So, anyone else tackled/tackling the problem?
  7. I suggested a pie in the sky solution to my network manager the other day that involved sticking a cheap 16 port switch on the trolleys so that the laptops would be manageable over a wired connection when not in use... I then managed to kill my own suggestion by pointing out that teachers have enough trouble just plugging in the power cables!
  8. We've just started using MDT in production. It can take some fine tuning, but works really well when you've got it set up. What we're deploying now is essentially a "thin" image of Xp (plain install with just updates), and then using the MDT windows update functionality to ensure the system and apps are fully up to date (actually had to do a slight tweak and run both Pre and Post application install updates twice to get it to really install all updates that were applicable...ZTIWindowsUpdate flags a lot of updates as installed when they're not really... In terms of installing applications, if you can install it properly using a single command then it should work fine on MDT, so you should be set as far as MSIs or well known installers go. In the worst case scenario you could create a standalone AutoIt script that launches and clicks through an installation wizard... Having MDT hooked up to a database is a must have if you're looking for unattended installations to multiple different computer types. We've simply added a room full of computers using their MAC addresses as their identifier, and assigned them to a role specific to that room. The role picks up the OS, drivers, and applications specific for the room/hardware. Using WDS (a CD/USB would work just as well, but would be more painful), all it then takes is pressing the network boot key on the computer, and we're done with it. 1h 30m later the computer will shutdown and be ready for use the next time someone turns it on. For reference, we're deploying the following software to this particular room off the top of head: AVG 2011 Business Adobe Creative Suite CS3 Web Standard Adobe Reader X Adobe Flash Player Adobe Shockwave Adobe AIR Java JRE Microsoft Office 2003 Professional (with 2010 Pro Plus ready to go) Codec Packs Office 2007/works file conversion packs Note that Office 2003 and components get updated to SP3 and updates applied as part of the MDT update process. The only real caveats I've come across so far are the fact that a computer will require deleting and re-prestaging (or moving) in Active Directory as certain Group Policies can break MDT's automation, and the fact that systems in the middle of deployment are vulnerable to people sitting down in front of them and getting access to stuff they shouldn't be or just breaking the process (as people are trying to mitigate throughout this thread). I have managed to get the process working without using Domain Admin Credentials however, which lsessons the security implications somewhat (special accounts have been set up to access the DeploymentShare and join computers to the domain). Might look into writing an app that both locks the workstation and executes some UI in the WinLogon session so our energy efficient teachers don't then turn the computer off... I'm guessing there will still be a brief window between logon and the lock taking effect however.
  9. How do you handle laptop trolleys and wireless connectivity? We've had an ongoing issue with the performance of wireless connectivity when serving laptop clusters. This often manifests in extremely long logon times, missing group policy/drive mappings, and the network suddenly being unavailable just as the student is going to save the coursework they've been working on all lesson. This typically only occured in one or two particilar rooms, so although on and off research was done on the issue, it wasn't priority one. Now, over the easter break four of our laptop trolleys (15 laptops each) were reimaged with our shiny new Xp image created and deployed elsewhere at the end of last year. Unfortunately due to the age of the image, these laptops were now in need of many updates. So naturally, when the teacher has the students fire up 15 (or in some cases 30!) laptops in a room, they all start downloading a 100mb of updates all from the same poor AP, naturally crushing the wireless performance and any chance the students have of being productive. Considering how limited the bandwidth of even a perfect A/G WLAN is and the number of laptops in use, it's becoming clear that we will need to consider disabling automatic updates for our laptop clusters (or give them a subset of updates in WSUS). In this case we'd have to either perform some sort of scheduled maintenance on the laptops by hooking them up to ethernet, or leave them as they are (something I wouldn't be overly happy with, especially not for our Windows 7 laptop cluster). Now, in terms of the wireless configuration we've spent some time researching basic best practices as well as trying to understand our particular APs (HP ProCurve 530). The existing configuration that was in place seemed to be a mix and match of b/g/a, with channels set to same in neighboring rooms and power reduced all the way down to 2dBm in some cases. What we're looking at now is running an 802.11a (5 GHz) only network, which in theory should prevent issues from bluetooth mobile phones etc, and allow for the use of more channels (augmented by the shorter range). Initial tests with inSSIDer indicate that we can get a strong signal (as good as -41 RSSI, which I understand might be TOO strong) from each AP in each respective room. Rooms typically get a very poor signal from the APs in other room (apart from two rooms that are seperated by a false wall). Following advice, we set the APs to auto channel selection, however they all seem to have chosen channel 38 despite being brought up one at a time. Presumably this is because the individual signals are not reaching the other APs, or isn't strong enough to warrant a different channel? Assuming the wireless works just fine, we now come to the problem that 802.11a can only support a maximum data rate 54mbit (20~mbit of actual throughput). When we get teachers doubling up on trolleys and handing out 30 laptops in a classroom, this obviously doesn't leave much bandwidth to share, especially in this age of whizz-bang VLEs, interactive education, and the Internet. I was optimistic to think that the 802.11a WLAN might have enough reach such that we could load balance laptops across multiple APs, but sadly this doesn't seem to be practical at all due to the range limitations (no doubt g would fare better, but then we get the problem of 2.4GHz interference and the fact that we have 5 APs in five adjacent rooms). We're also thinking about the option of roaming profiles for students (or at least making a more robust mandatory profile) which could potentially take us back to square one as far as logon times go. So how do the rest of you in the precarious situation of having laptop trolleys cope with wireless connectivity and performance? Without spending any money of course...that's naturally all reserved for replacing the shredded power cables for the laptop PSUs and the various missing/destroyed keyboard keys. It's all just normal wear and tear though!
  10. Unless they're running other counties using domains other than LpPlus.net, then yes it will be down across the UK and beyond. In theory the domain is in grace period now so should restored very quickly when they push the "renew" button. Not sure if e-mails to OWN and other LpPlus hosted targets will be ending up in a black hole though!
  11. Hi, "ComputerName=%MACHINENAME%" in [userData] works just fine for our Windows Xp Sysprep.inf. There will be something very similar for the Windows 7 Answer file - WDS will substitute the the variable for the actual computer name assuming the computer is prestaged in AD with the GUID or MAC address (check to see if the computers have a "Remote install" tab in their AD properties). We currently have a setup for our Xp machines where we can just run a VBScript for a specific image, passing in the desired computer name and the MAC address of the physical machine - this prestages the computer in AD, which lets WDS know to accept boot requests and use the correct WDS unattend file. Boot the machine from the network once, and then walk away for 30m/an hour. You'll have a login prompt when you get back barring a slow network connection WDS unattend find takes care of partitioning the drives as needed, WDS modified sysprep.inf takes care of entering the volume license key (or vendor specific keys for our Xp downgrade licenses), naming the computer based on the pre-staged AD computer, setting timezone etc, and automatically joining the domain using non-domain admin user account which the sysprep.inf has the username/password for. This non privileged account was given the specific ability to join this particular computer to the domain in the previously mentioned VBScript (which is just a wrapper for the wdsutil command). Naturally you should be set up something even more powerful with less fuss for Windows 7! We're just about to start getting ready to deploy Windows 7 to our infrastructure, so I'll have to get up to speed with the Windows 7 unattend stuff sooner or later.
  12. Hi, Will server literally be just A PDC Emulator; no Global Cat and such?). Also, are you looking to run the server under Xen right now, are you going to migrate the physical server over to virtual later in the day, or are you looking to host virtual machines on this box (never used Xen, so not sure if it depends/runs on a full Windows/Unix host, sorry). In our environment we currently use 146gb 10K SAS drives. We set them up in a configuration of: 2x drives in RAID 1 for OS drive (C drive); n drives in RAID 5 for our data drive (E drive), n being a minimum of 3, and scaling up depending on what the server is used for. However, strictly speaking I'd give a 2008 box a minimum of 64gb to play with. Our OS drives tend to use around 25gb. Best wishes, Karl St Clement's High School
  13. Thank you for your responses. Regretablly the domains that GotoAssist uses isn't plainly obvious, and as such I didn't get far using the domain exception list. However I did discover the exception list/port 801 which is ideal for servers and cases like this (though obviously this raises a security concern for the workstations in question). GotoAssist works fine using port 801 without causing any fuss for the user or IT staff. Using ProxyCap with NTLM for GotoAssist resulted in the regular proxy returning error 403 (on ports 80 and 443, for a user with unfiltered access) which suggests that Smoothwall filtering doesn't like this particular application creating a non-http connection.
  14. I'm involved in the backend of a high school IT network, and we have recently deployed Smoothwall School Guardian to our network, and are now getting live usage by staff and students. We opted to use NTLM Authentication along with Active Directory integration as it appeared to be the less intrusive option for general usage on Windows clients. While NTLM is working very well for browsing all around, we are having trouble when it comes to applications that do not support NTLM (GotoAssist in this case, something heavily used in the support of our new MIS). We have a number of solutions to get around them, but none of them are overly attractive: * Give the user the ability to directly connect through smoothwall to get at the CachePilot proxy and manually change proxy settings when needed. * Attempt to add the relevant domains to the "Do not allow authentication for these domains" list (this is currently being tested, but has the potential for security problems). * Use something such as ProxyCap to NTLM-enable the application. Would cost £20/license and would be troublesome to get an invoice for. As I understand, NTLM requires authentication for each request (but remembers the user logged in at the IP for firewall rules). SSL login seems to remember the IP/user association for the proxy as well, however cannot be used as the same time as NTLM - and we're keen not to give up the transparency that NTLM offers. A client that runs silently and authenticates users with say Kerberos and maintains a connection to the smoothwall box to identify the user/IP association seems like it would be very useful as an authentication mechanism.. Does anyone else have any experience with the NTLM authentication with smoothwall? Are there anyknown alternatives the solutions I've mentioned above? Best wishes, Karl
×
×
  • Create New...