Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. Have you created the folders on the server ahead of time or are you letting Windows create them as and when the user logs on. Microsoft reccomend the latter, but the permissions on the parent folders must be correct. E.g. If you are redirecting to \\server\userfolders\%username%\My Documents The permissions on the folder that hosts the userfolders share must be as follows; Administrators: Full Control (This folder, subfolders & files) System: Full Control (This folder, subfolders & files) CREATOR OWNER: Full Control (subfolders & files only) Authenticated Users: Special (Traverse Folder, List Folder, Read Attributes, Read Extended Attributes, Create Folders, Read Permissions) (This folder only) These permissions will allow windows to create folders for your users which they then become the owners of. You may like to read the Wiki How To section on roaming profiles...
  2. ajbritton

    PXE Boot

    Usual RIS tests apply (see many other threads). 1 - Do you KNOW your RIS setup works? (ie - Have you succesfully booted any PC using PXE) 2 - Are DHCP and RIS on the same server? If not, then there must be NO DHCP SERVICE on the RIS server
  3. Surely that would be 1GHits Doh! I must have been trying to work out a subnet in my head at the same time! Better check that too!!! :-)
  4. Surely it wil be more relevant when we reach the 1Mhits (1024 * 1024 * 1024)...:-)
  5. Not true. Although Microsoft do not recommend using multi-homed RIS servers, they can work as long as RIS/DHCP is authorised on all networks and all networks have an active DHCP scope. I'm using a 2003 server at the moment with the loopback adapter installed and I'm installing RIS clients on my main network and on the loopback adapter no problem.
  6. Is it possible to modify the site so that users who are already logged on go straight to the 'forums center block' page (can't see the link for this anymore BTW but I know it still works). I never read the 'Welcome to EduGeek' block and in my opinion it's a PITA. I often use EduGeek on my TV based browser which means I have to scroll down a page and a half to get to the list of recently updated posts. Also, there is so much activity on the site these days, that this list often does not show all the threads modified in the last 24 hours for instance. It might also be good to have pages which would show all activity over a fixed range of times (24 hours, 7 days, 30 days etc). If I'm stoopid and all these things are already possible, please tell me how to do it... Thank, and keep up the great work on my favourite site on the Internet. Andy
  7. Couple of points.. 1 - Is your RIS server multi-homed? If so, RIS must be authorised on all adapters 2 - Is DHCP Server installed (but inactive) on the RIS server? (check services list or add/remove programs, Windows components). If so, RIS will never work. If DHCP server service is on the RIS server, then it MUST be the active DHCP server also. If this is the case, you can try stopping and disabling the DHCP server service (a reboot might also help convince RIS that DHCP is no longer there). If that doesn't do it, remove the DHCP server component. 3 - I've installed RIS on dozens of sites and I've never had to mess about with the DHCP options. I'm not saying it's necessarily a bad idea, but it should not be necessary to get RIS working. 4 - Don't give up. It's worth the effort in the long run. When you do get it working check our AutoRIS (try a goggle search or look on the MSFN unattended site). It's another learnin curve but makes your RIS builds a lot slicker.
  8. ajbritton

    PolicyMaker

    I've been using it for a year or so. It's on the essential software list on the wiki. I use it in addition to .ADM files, to 'fill in the gaps' when I don't have time or can't be bothered to author a custom .ADM. It's easy to use and easy to roll out the extension (MSI based installer) to workstations. It claims to integrate fully into GPMC, but I have had difficulty with GPMC backup/restore procedures, so as always, the adivse is to test thoroughly before using in a production environment.
  9. @mark: I have added my two cents to the questions no the Wiki.
  10. Once again, thanks for everyone's input. It's interesting to hear the variety of experiences and opinions on offer. In summary it looks like running Virtual PC on a server would have a resource impact when in use (CPU, RAM and DISK) and is perhaps not the optimal product to run on a server. I only want to use Virtual PC very occasionaly for remote troubleshooting purposes. I already have RDP access to all the servers I support. As the servers are routinely upgraded and they will likely get 2Gb RAM, dual CPU and RAID 5 disk arrays at their next upgrade, I'm sure they can take the occasional resource hit although the customer may notice a slight drop in performance, but they will get problems fixed more quickly and would not lose access to a PC whilst work was carried out. Educational price of Virtual PC is negligable (~£30 inc media) when combined with the cost of a new server. I've been using Virtual PC for several years now (since before Microsoft bought it from Connectix) and have never known it to crash the host PC even when I've had 3 or 4 guest sessions running.
  11. Registry permissions are somehow embedded withing the NTUSER.MAN file. They are NOT the permissions ON the NTUSER.MAN file. The permissions can be set correctly automatically by using the Copy To function in the Windows User Profiles GUI, which sets file permissions AND registry permissions. It is possible to edit the registry permissions with REGEDIT on XP, BUT, it's not as simple as giving Full Access to EVERYONE. If you examine the permissions on a pukka user profile carefully, you will find that the owner of the profile does not necessarily have full access to all areas of it. The Policies section is one example where the System can write to but the user cannot. My advice: Always use the Copy To function. When copying a profile for use as a mandatory profile for multiple users, I typically assign permissions to Everyone. PS - I will look at the Wiki questions when I get chance. Got to go shopping now aargggghh.....
  12. I can see how the Virtual PC would use up some RAM when acutally in use, but can you tell me how just having the program installed but not active would affect the stability and security of the network?
  13. How did you copy the profile? If you just dragged the files using Explorer, then the permissions in the user registry will be wrong. You need to use the copy profile function from My computer, Properties, Advanced, User Profiles Settings, (select the profile), Copy To.
  14. is that it might be a bit tedious to cobble together 140 linux boxes!
  15. @Geoff: I support approx 140 systems!
  16. Thanks to everyone for there contributions thus far. Surely (at least some) these products are designed to work on servers for application consolidation and such like. If you read the blurb on the VMWare free server thing, it talks about using it to provision servers and quickly move servers from one platform to another. Where I work, and very large IT company came in to talk to us about consolidation. They proposed moving the entire organisation (several thousand users) to a thin client architecture and using virtualisation software to mop up all the applications that would not run in a thin client environment. Just to be clear, I'm only talking about using this occasionaly, not 24-7. If a user at the site reported an application problem or a workstation configration problem, I would remote into the server, fire up a virtual PC (at which point, I grant you it will grab some RAM and CPU cycles), sort out the problem, then shut down the virtual PC and disconnect. I know that Virtual PC installs some extra network components so it can hook into the network, but would these have much of an impact when not in use? Thanks again y'all
  17. It would be useful from a remote support point of view to have a copy of Virtual PC on a server at each site that I support. That way I could remote into the server and fire up a virtual workstation to test configuration and client software issues. I notice that the VMWare player (which would have been a nice free way to do it) warns against installing on domain controllers. Does anyone know a good reason why I should not install Virtual PC (the trial has installed and appears to be working) or even VMWare player. What issues might this cause? Thanks in advance,
  18. As I'm sure many of you are aware, it's possible to completely dump NetBIOS these days. I've never done it before but am considering doing so now. The site for which I'm considering this move is configured as follows... Single forest - Forest root domain (Admin) has single DC running Windows 2000 - Additional domain (Curric) has dual DCs running Windows 2003 DNS infrastructure all in place and working correctly All PCs are Windows XP SP2 Can anyone think of any good reasons to keep NetBIOS?
  19. Fixed by removing the Viglen supplied 2.x.y.z driver. The 1.x.y.z driver supplied with XP SP2 worked fine and no more errors. I did try the 2.x.y.z+1 driver available on SIS website but no better. Also, although the PC produced multiple W32TIME errors at boot, the Kerberos error only appeared when Sophos was added to the mix (I built 7 PCs with all possible combinations of Sophos, Windows Updates, Polcies and Software to test this).
  20. Geoff...How would that catch a virus brought in on a floppy or other removable memory device?
  21. We've noticed that Sophos seems to slow down various apps when the on-access scanner is set on its most draconian (scan all files, scan archives etc). What settings do other Sophos users recommend?
  22. Got a weird problem which only appears (AFAIK) on Viglen PCs with blue mesh panels along the bottom of the base unit. They are ASUS motherboards with SIS900 NICs. Occasionally (and only on some of the machines), the Group Policy fails. The following even appears in the System log (source Kerberos, event 7) I have enabled verbose USERENV debug logging and the only clue in the resulting file are lines which say I have searched high and low for a solution to this. There are a number of suggestions which relate to Kerberos problems, but none which really relate to my exact circumstances. There is an entry on Experts Exchange in their Hot Solutions section, but only registered members can view the solution. It's a vanilla 2K3 domain so the school does not have a software support contract with Viglen. Any ideas?
  23. It's saying this for ALL MSI packages? Anything else in the event logs?
  24. Thank you Sophos tech support here's how to do it!
×
×
  • Create New...