Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. @CM786 - I would still be interested to know if you were seeing Kerberos errors in the event logs on the PCs. I've had Kerberos errors on every PC which has displayed the SIS900 problem.
  2. Interesting. I might try that next time I hit the problem. For the record, though, on the sites where I've had SIS900 trouble and fixed it with the XP SP2 driver, I have NOT had to disable the firewall. I usually configure the firewall with GP, opening the odd port here and there for things like Sophos, NetOp and UltraVNC.
  3. I use Group Policy to ensure all scripts complete before the next phase (can't remember if that is synch or asynch). It is a good point however and I will check to ensure the first script is completing prior to user logon. Both scripts write to logs and include the date/time so I should be able to see what is happening when.
  4. I have a script which uses PrintUI.dll to add a per-machine printer. This script runs as a 'startup script', assigned using Group Policy. I have another script which uses WMI to enumerate printer connections and set a default based on certain criteria. When I test the script by running it manually, it enumerates all local and network printers, including the per-machine printer added by the first script. When I assign the script as a logon script however, it does not 'see' the per-machine printer, even though it appears once the logon process is complete. Does anyone know of a good workaround (I can think of a few 'icky' ones)?
  5. I'm curious... 1 - Are you seeing KERBEROS errors in the event logs on the affected PCs? 2 - Are you running Sophos AntiVirus? The reason I ask this is that I could only reliably recreate the problem after install the Sophos AV client.
  6. I made mine work by using the driver supplied with XP SP2. There are registry you can mess with and these have helped some times, but reverting to the MS supplied driver has always worked for me.
  7. Here's a thought... 1 - Set up a temporary domain on another PC (physical or virtual) 2 - Use ADMT to migrate everything over to it (User Accounts, Computer Accounts, Passwords etc.) 3 - Wipe and reinstall the existing DC, create a new AD 4 - Use ADMT to migrate everything back to the original domain This method should retain all user & computer accounts, passwords, permissions etc. You get a freshly installed server and a new AD. If ADMT won't handle Exchange, I've a vague feeling that Exchange has it's own migration tool. Worst case is to dump Exchange database to PST files then reimport. Only hassle is that to migrate computer accounts, computers must all be switched on and have some kind of agent running. I've only use ADMT myself once, so I'm hardly even a novice. Maybe someone else could comment on how practical this solution might be.
  8. There are companies who make boot disks for NICs that are not already PXE enabled (Argon Technology, emBoot) - If you decide to try this, make sure you test it before shelling out big bucks.
  9. I don't think there is any easy solution for this. I've heard what ChrisH proposed referred to as a 'swing' installation (presumably 'cos the AD swings onto a temporary box then back to the real box). Thing is, if the problem is in AD, then this obviously won't get rid of it. You could export everything with LDIFIDE (or whatever it's called), but if you've never done it before, it could still be a major job. Even assuming you exported the entire AD then imported it into a fresh domain, there's no guarantee the clients would still work (I'm guessing the secure channel would be broken). GP can be backed up with GPMC and then re-imported. There are so many possiblities it doesn't bear thinking about. I guess what I'm suggesting is fix the existing DC. What's the problem with it anyway?
  10. I wondered how long it would take before DB pitched in with the 'roaming profiles are evil' line. If only he would use IMHO instead of TBH then I wouldn't have to keep harping on about it! It's odd that lots of admins seem to work with Roaming Profiles quite happily. I know they are not the best solution for everyone, but they do work and provided they are implemented and managed in the right way (just as with ANY other system), they do what they say on the tin. There's quite a bit of info on the Wiki about setting up roaming/mandatory profiles. For what it's worth, in My humble opinion, roaming profiles are not the right choice for students. Mandatory profiles provide a secure and manageable environment. Staff benefit from roaming profiles provided they are educated on the pitfalls. There. I've said my piece and will not turn another thread into a profiles warzone. TTFN
  11. I suppose if you really had to do it, you could write a logon script which asked the user to log on again, and then connect a drive to a share/folder based on the user they specify. You could also redirect My Documents to the same location. Can't for the life of me think of one good reason for doing this however. As others have said, mandatory profiles are there for this. Can you tell us a bit more about exactly what it is you want to achieve?
  12. If you are doing this for the reasons Mark has suggested, then you can limit potential damage by giving your Teachers the absolute bare minimum permissions in SIMS that they require (good security practise anyway).
  13. Creating a trust relationship will not synchronise usernames between the two domains, it will simply let you assign access to resources in one domain to users in the other domain.
  14. There must be some DIY HDD recovery solutions somewhere on the Internet. Just about everything else has been done...
  15. Thanks Russ. I know you are guys are really busy. Sorry If my post was a bit grumpy sounding! Can I humbly suggest something along the lines of 'View posts for the last X days' where X is a dropdown list with (1..31) in it, defaulting to 1. Thanks again and apologies for hijacking this thread. I' outta here!
  16. If the powers that be would implement the long requested 'view posts from last 24 hours/7 days etc' features, it would be less of a problem. The 'view posts since last visit' is useless if you log in briefly but don't have time to go through the whole list.
  17. What about using something like a Terrastation (inexpensive NAS box with RAID HDDs).
  18. That defeats the object of having the ground wires in the first place. Why? The wires are still earthed at one end. EDIT - BTW. What is the point of the ground wires. The whole point of twisted pair is that the signal in each pair of wires is subtracted in order to remove noise.
  19. Surely the problem was the redirected folders then, not the fact the the profiles were roaming.
  20. Ok, but could you not just snip the RJ-45 connector off one end and wire a new one up that does nothing with these ground wires?
  21. @Geoff: Hang on, surely the earthing is only the shielding, which is not connected to anything. The actual cores are all twisted pairs and as such carry inverse voltages to each other. They then pass through differential amps to cancel out noise.
  22. Re Groundloop. Why not just earth the cable at one end only?
  23. and probably a fair bit of corrosion Nah, just run it through a hosepipe!
  24. @Jake: Have you tried asking any networking companies how they would do it given the budget constraints?
  25. In answer to your question, YES. (You did ask Fair enough! My reason for wanting separation between Admin and Curriculum is to protect the data on the Admin network. Every software/hardware installer I've ever met on-site has always demanded the Administrator password. Keeping seperate domains means not needing to hand out a password which gives installers full access to all the student and financial data. Yes, I know I could create a user account with limited permissions but in my experience some installers won't settle for anything less than the actual Administrator password.
×
×
  • Create New...