Jump to content

mdrabble

Members
  • Posts

    2,704
  • Joined

  • Last visited

Everything posted by mdrabble

  1. Another one for ubiquiti. I have the Edge MaxLite range - these are the non cloud versions as my edge switches. I have some FS switches to replace some UniFi ones that died and I couldn’t get replacements and I much prefer the UniFi ones! Core is a 2 x DLink DGS-3600S, 24 port 10gb switch which are stacked.
  2. We were previously/currently with M247 on a 1GB/1gb connection. Signed with Wave9 to use an AltNet 2gb/10gb connction - this was due to have been done and dusted back in Jan, but due to issues outside of Wave9 control things have taken time. Main work was completed quite quickly by sadly we had 7 blockages on the run to the street cabinet which brought things to halt. Credit to Wave9, they have kept me in be loop and kept pressure on to get this resolved asap. Work was due to take place last week to clear these blockages but as I’m currently away for the week and have poor internet I’ve not check on things. So would recommend Wave9 for broadband. Filtering - this was a big surprise to me as we have smoothwall which is due to end at the end of May. Had demos and trials of different solutions, had head, DSL and assistant DSL in for all demos etc and they opted for Fortinet with the RepLog safeguarding option from SwitchShop. SwitchShop were great in the process - they were not the cheapest but they offered a solution the Head and DSL people liked. Hope that helps.
  3. Thanks for the info about FortiAnalyzer Now have a question about FortiAuthenticator. Do you use it? Do I need it? If yes, Why do I need it? Currently we have mainly desktops (no staff laptops currently but may have plans to switch to staff laptops for Sept 2025) Approx 100 x Laptops which are solely Domain Joined on WIFI, for class bookings. BYOD - authenticating against Windows NPS. No VPN (but may have plans for Sept 2025) RDS - uses Azure MFA Cheers
  4. Currently going through quotes for firewall/filtering and interesting question came up and that was what size of log files would be generated daily? Reason for asking was for FortiAnalyzer and do we go with a 5gb option or scale up to 10gb? Approx 1300 users, 500ish Devices plus any number of BYOD Currently have Smoothwall, so have no idea how to find that info....... plus I supposed it depends on what you are logging etc. We could go with 5gb and then scale up at a later date but would rather get it right first time if possible. For those who have Fortinet/FortiAnalyzer, what you say you sizes are? Cheers
  5. Recently we are experiencing issues - no network config changes have taken place - and I'm putting this down to a potential smoothwall issue (waiting on 2nd line to pull their finger) Has anyone ever given their network a health check? No idea if such a thing exists or can be done. I want to see if there any issues on the network such as bottlenecks, misconfiguration of switch configs, vlans etc..... Also looking to throw in a Wifi Survey as well as current Unifi Nano HD Access Points are now 6 years old and things have now changed in terms of wifi usages, so would this be a contributing factor? Most edge switches are core to edge 10Gb and then 1Gb to desktop. Any recommendation welcome :-)
  6. Ticket been passed to 2nd line, and I've done some more investigating. I've turned on the additional auditing and instantly I can see devices (Domain Joined devices) on my network talking to this IP but not getting the reply. What is even more confusing is that a PC that was flagged was sat at the logon screen. It is all upto date with updates, edge, onedrive client etc - so I have no idea what is going on! Anyone else seeing traffic from 23.219.197.246 on their firewalls? Cheers
  7. Nope, we manually import them still
  8. Well isn't Cloud Connect as they got back to me and confirmed their IP addresses used. That IP does resolve back to a23-219-197-246.deploy.static.akamaitechnologies.com which is a MS server. All updates stopped, removed all desktops from Intune, so now only managed via SCCM on prem. Since I have now arrowed things down, I've got smoothwall support involved as I've tried to put a rule in to allow it and that is being ignored. Hopefully, the more clever people than me can help resolve this.
  9. Well after hours of digging around - it isn't me or any of the settings I have in place, was beginning to doubt my own sanity! It looks like may be down to Cloud Connect - on boot, the agent logfiles show that it validates its config and sync a profile on boot. Going to contact them and double check it is that - but fingers crossed
  10. Got to the point where I am thinking I have no idea what I am doing. Did have a day off with the wife and spent most of it going over in my head what i have configured and what could be causing it. Might try and spend some time on it tonight and go over things again. On a side not - what would happen if I delete the stations from intune/azure? Would the Domain side carry on as normal?
  11. New box setup and configuration restored didn’t have time to install last night. Remoted in last night to do some investigating and It’s now looking like a workstation issue where when turned on they try and doing something with Intune/Updates which is causing Smoothwall to grind to a halt for a short period of time. I started a thread here - Hybrid Joined SCCM Devices and Intune Woes! /showthread.php?t=237095 Talking about anything from 23,000 - 66,000 access with 15 min according to the dashboard summary. I’ve no idea what they are trying to do - not had time to look that far yet. I’m off today and then will dig in again tomorrow. May have to give support a call
  12. I can’t see tell if devices are checking in or trying to do something else, all I see on smoothwall is that IP address hitting smoothwall and being dropped/rejected. Approx 450 devices are hybrid join and the policies were a combination of some packages being deployed and updates. I would say so as windows starts the fun begins. We have power saving enabled so if any computers not being used are shutdown after 15 mins. This explains why we were seeing this happening at the same times during the week. I’ve paused the updates via endpoint manager and set the packages to untuned devices. Packages are already deployed via SCCM image deployment, so no errors showing in deployments. All devices were coming back as compliant. Very last resort will be stop them being co-managed and reimagine them during Easter break.
  13. Not sure where to post this as covers Cloud and On Premise Recently I noticed that all hybrid joined SCCM clients were no longer being managed by SCCM and instead being managed as Intune devices via endpoint manager. This in turn has had a massive knock on effect when they are powered on - more noticable in the last month as they connect to Endpoint to check in and Smoothwall grinds to a halt for a short period as it tries to deal with over 25,000-60,000 access over 15 mins. After contacting ISP and Smoothwall, finally worked out it could be due to Windows updates - or a MS Service using IP 23.219.197.246 I jump on Endpoint Manager and realised I had some Intune settings set to all devices, I've changed these to just Azure Groups containing Intuned Laptops and then reinstalled the SCCM client on the on prem devices. Endpoint manager see these as Co-Managed and to see See ConfigMgr - so all good there. After a few hours of changing things when I reboot all the computers, the internet still grinds to a halt as Smoothwall tries to deal with the influx of connections. Slowly pulling my hair out! Not to mention the grief I am getting from staff and the head! Anyone with SCCM and Hybrid Joined devices and Intune - come across anything like this? I'm at the point where I am going to start approaching companies to see if they can have a look at my setup and see what is going on and point out the error of my ways! Anyone recommend companies that deal with SCCM and Intune? Cheers in advance
  14. I’ve managed to resolve this - helps if you actually check your definitely network settings are not being restored! Fresh restore and now manually adding interfaces and various rules etc Next is to update from Leeds 65 from the base install to Leeds 68
  15. Ticket been moved to 2nd line and not seeing the NICs so wanting to see how best to proceed.
  16. Just done a search on the knowledge base and found link to download the iso - so will have a play.
  17. While I wait for support to reply, as I have pointed out we have a valid support contract.... quick question for people and @tom_newton IF I have a valid Smoothwall support contract, surely Support should be able to tell me if I can reinstall Leeds 68 on a 3rd Party Server such as a HP DL380p and provide the ISO The reason being is our S8 is out of warranty and is playing up - with 2 months before we either renew our smoothwall contact complete with new box or move to a different provider Support have told me to contact my account manager..... not sure why.... All I want to know is - is it possible to install Smoothwall (Leeds 68) and restore the config (without the networking ports) as a temporary replacement on a HP DL380p? Cheers
  18. Paxton got back to me with the following information - which works a treat. I set up a time zone where I added times where the button is disabled and I am one happy bunny. Cannot fault Paxton support.
  19. Sadly this didn’t work. Back to the drawing board
  20. Thank you EduGeeker! You pointed me in the right direction - Tiggers and Alarms https://www.paxton-access.com/wp-content/uploads/2019/03/AN1067-ZA.pdf Going to give the following a try......... Set the push button not to open the door via Doors -> Alarms -> Do not unlick door when exit button is pressed. Set a trigger so when a push button is pressed on those doors during a timezone, it unlocks the door. Fingers Crossed.
  21. Good idea - but reader 1 and 2 are both in use, so not sure this would be possible.
  22. Morning all Is it possible to have the Push to Exit Buttons set to operate only at certain times? Reason for question is a long one, so just wanted to know if possible - via Paxton or by some other external means. Cheers
  23. If I create a custom report for IDS, it shows Data. Might have to contact support.
  24. Yep, that where I'm going and get 404 error. Whats the url for yours? mine is /modules/ids/cgi-bin/log/snortidslog.dat
  25. Where do I find the IDS logs on Smoothwall? Reports -> IDS : Give a 404 error When I use the search feature from the Dashboard, it takes me to the same place. Cheers :-)
×
×
  • Create New...