Jump to content

seawolf

Members
  • Posts

    975
  • Joined

  • Last visited

Everything posted by seawolf

  1. The something afoot is that much of the events in that article sound entirely fabricated. That is not how the NSA or GCHQ would take care of business. The computer(s) would have been seized and/or the Guardian network hacked without their knowledge and we would have never heard anything about it. Unless this bizarre episode was just a cover for what GCHQ was really doing at the Guardian...
  2. You're enduring a lot of administrative pain and overhead to gain what is not a substantial security advantage. If your organisation is like most places admin usernames and passwords likely follow a pattern (usernames more than passwords). So, if someone has gotten an admin login for one domain they can probably use the same techniques for getting the others. Once you know the username you're halfway there. Passwords can be broken without a great deal of trouble with the right software, time, and access. Compromises are more frequently from social engineering or carelessness though, and if an organisation loses one login that way, the others are likely to fall in the same way shortly afterward. If you have extremely robust and obscure usernames and passwords, change passwords frequently, and limit access to them to a very small number of people, the logins for both domains are not known by any single person, personnel are highly trained in security procedures and follow them, etc. - then it would heighten your security posture. That's not the case for most organisations though. A more simple, easily managed environment with time spent on security training and ensuring that reasonable and not overly complex security procedures are followed is the way to go for most organisations. I would definitely recommend a single domain for most environments. NOTE: I worked for the NSA for eight years (in the 90s) in the business of obtaining and analysing information that the other side was trying to keep secret and secure. Good security is hard and the human element is the weakest link. Having overly complex systems exacerbates any security weaknesses, we took advantage of this all the time.
  3. What security flaws do you believe there would be? Do you have two separate totally isolated networks as well that staff and students use? If not, then whatever additional security you think you have with using two domains does not really exist. If anything, it would create a false sense of security I fear and lead to security lapses in other areas on the network.
  4. The iBoss Enterprise units are the very best I've ever used and everyone I have demonstrated it to (including vendors trying to sell me something else) have walked away extremely impressed and knowing why I won't use anything else. http://www.iboss.com/ibwf_overview.html They are easy to configure, VERY flexible, fast, have outstanding reporting capabilities; great QoS/bandwidth shaping; Desktop recording on triggering of threshold (Mac, PC, and Linux); multiple authentication methods including: NTLM, AD proxy, AD plugin, mobile agents for Mac and PC, capture screen; MDM for iOS and Android (including remote filtering), and more. It can operate in various network configurations http://www.iboss.com/ibwf_integration_network_diagrams.html It's the only proxy/filter that I've seen working as well with Mac and Linux as PC. And has features that others just can't match without integration into additional systems or heavy customisation. You can request an evaluation before you buy. The support is fantastic before and after sales. p.s. I have no association with Phantom Technologies other than as a customer. I just think they are that good. There are no distributors for them in Australia, but they shipped out a brand new eval unit in short order. You won't go wrong with them.
  5. Try FOG. Doesn't take long to set up and bulletproof fast imaging once it is. Been using it with Win7 for past two years. Provides more than just imaging as well, including tracking login/logouts, printer mapping, etc.
  6. Here is a short, but good explanation of why 10GbE isn't just about bandwidth and throughput. There are major differences between the 1GbE and 10GbE protocols themselves. Its not just about speed. But, actually I do "have a need...a need for speed!" http://www.rtcmagazine.com/articles/view/100797
  7. Well, it's not really littering VLANs with "unintended" traffic since the IWBs are "intended" (here anyway) to be used with AirPlay devices used by the teachers. My point is that bonjour is a layer 2, non-routable multicast protocol not designed or intended to route across subsets or VLANs. All "solutions" to this problem whether they be from Aruba, Aerohive, Ruckus, or using a Linux "gateway" trunked to all of the VLANs are really just "standardised" hacks, kludges, workarounds, etc. rather than long-term solutions. Each one is susceptible to breaking in the future. What is needed is a real solution, which requires a change to bonjour and wide acceptance of a routable zero config protocol, which is currently under development (http://arstechnica.com/apple/2012/11/apple-working-to-make-bonjour-compatible-with-enterprise-networks/). Placing all of the bonjour related devices on the same VLAN can't break and it also reduces the risk the multicast traffic will start flooding across the entire network. That's why I said "choose your poison". Neither workaround is ideal, but they are all workarounds.
  8. Every method of routing bonjour traffic such as AirPlay across VLANS is a workaround and not a true permanent solution, including those on offer from Aruba, Aerohive, and others - http://www.networkworld.com/news/2012/110812-apple-university-264091.html Choose your poison. I like to keep it simple and not force things to do something they definitely weren't designed to do.
  9. Why don't you just configure the switch port the projector (computer) is plugged into onto the same VLAN as the WiFi? That's what we do. A VLAN can have both wired and wireless traffic on it...
  10. I hope you meant CAT6 or CAT5E and not CAT5 cables? If you've spent the money on a 10GbE fibre backbone (and associated switching) especially.
  11. You need to be more specific to obtain a correct answer. Do you want to know the file systems that are compatible to boot 10.8 from, or those that it can read/write to natively, or those it can at least read natively, or those that it can read or write to using various 3rd party plugins? The way you've worded the question is kind of like asking "How long is a piece of string?".
  12. I have to admit that I do agree with the logic of having a physical DNS server around. Maybe I'm just paranoid, but I have gotten caught with my pants down finding out that systems that should have no problem with DNS being down actually having lots of problems with it being down! Lets just say that unless you test EVERYTHING whilst DNS is down then it is a risk. Small? Probably. One I'm willing to take again? Not a chance. 1. Defence 2. Banks 3. Hospitals 4. Intel Agencies None of these should really be using anything OTHER than a VDI solution. In fact, that's what many of them are using. Government agencies and the military are the biggest customers Oracle has. Many of them are now spitting their dummies over Oracle killing the Sun Ray. Education is not on the above list because education isn't one of those use cases where VDI is the only answer. In most cases, it's not even the best answer in an Educational environment. VERY large deployments (10,000+) though - THEN it might be the only viable and cost effective solution.
  13. What does your environment look like? Are you running a Windows or Mac server environment? What version of OSX? are you using WGM or Profile Manager (or equivalent) to manage the Macs?
  14. See http://technet.microsoft.com/en-us/library/cc782142(v=ws.10).aspx for more info on possible ways to configure this.
  15. * Spammy post quoted removed * A subdomain is the current best practice, but using a "real" domain name for the AD domain does not in fact have to be a PITA. You do NOT need to duplicate all of the DNS records if you do so either. If you already have an external primary DNS server for your domain then all you need to do with your internal DNS server(s) is to make them the authoritative DNS for all clients of the internal LAN, but set them up so they forward all DNS queries for hosts they don't know about to your primary external DNS. So, for example, lets say you have an internal only Intranet server hosted on your LAN and you want to name it "intranet.somedomain.com", then you would create an A record in your internal DNS and that could be the only record you have in your internal DNS server with all other queries such as "www.somedomain.com" or "server.somedomaim.com" being redirected to the external DNS server just like it was previously. This works 100% if setup correctly and I've done it more than once for clients.
  16. Can you give a bit more information about the specific problem (e.g. Mac server Printopia is installed on if any, VLANs used on your network if any, what you're trying to accomplish with it)? The Mac where you have Printopia or Printopia pro installed has have the printers installed for Printopia to see them. Are you using Printopia to setup AirPrint for iPads or are you going to use it for your Mac clients?
  17. That article is way old and is four major versions of OSX outdated. I used both 10.5 and 10.6 with .local domains (again not optimal, but works out of the box). There was a problem with .local domains and the first version of Lion (10.7), but it was fixed and 10.8 has been fine. The 10.8.4 release version even included an improvement to login speeds for .local AD domains "Improves Active Directory log-in performance, especially for cached accounts or when using a .local domain"
  18. You can certainly bind 10.8.4 to a .local domain without a problem. I've done it numerous times. Using a .local is definitely not optimal or recommended, but it will certainly work out of the box and with a 2008R2 server as well. You should be using "school.local" as the domain name when binding and not "dc1.school.local". Check that the time on the 10.8.4 client isn't off more than five minutes from the server. If it is, you will never get the client bound. Set the NTP server on the Mac client to be the same as that of the server (or for the AD server to be the NTP server n the client if that server is the master NTP server for the domain - it probably is).
  19. The only way I think you could really have a "clean slate" is to create a new share location and re-image the clients affected. As for the problems you're experiencing with the Linux file server, I think perhaps you aren't doing something right. I've used both OSX Server and FreeNAS as file servers in this way without the issues you've stated. Take a look at this reference guide for setting this up http://wiki.samba.org/index.php/Samba_&_Windows_Profiles
  20. All of the Draytek SOHO gear is excellent, quality stuff. Well worth the money in my book. For WiFi, I like hooking a Draytek modem (no WiFi) to an Airport Extreme Base Station. They are one of the best SOHO WiFi units on the market in my opinion. That opinion is based on years of use in dozens of environments, including using one to extend a WiFi environment to a temporary building on a school oval that was about 200m from the nearest WiFi AP, the building was clad partially with steel sheetmetal (not good for WiFI) , and a VOIP phone and computer in an office in that building worked perfectly over WiFi for a year to my utter amazement. The only other WiFi solution I would trust in such an environment are the Ruckus SOHO (controller less) solutions you can sometimes find. The Ruckus is a step above everything else.
  21. With IP routing enabled, you can't use ip default-gateway in the config. RIP is dynamic and IP routing is static. IP routing is fine for simple LAN configurations. We have two campuses joined via fibre link and a more complex network. Using static routes would be far more prone to error and misconfiguration. Most of the examples HP provide on inter-VLAN routing make use of RIP for this reason. It's simple and more flexible than static routes.
  22. If you're using your Layer 3 core switch to route traffic and aren't using a standalone router for this instead, then you have to enable RIP or OSPF. RIP is simple, has low overhead and is perfect for small to medium size LANs. OSPF is harder to configure, can have high overhead, and in the case of the ProCurves you have to pay for a premium license to support OSPF (or at least that was the case last time I checked). You wouldn't want to use RIP with multiple routers though...
  23. I don't see how it would as long as the default gateway is set right and the internal DNS server is set to forward lookups to the LEA DNS server(s).
  24. Aw crap, you definitely need to be using IP address ranges OTHER than that used by your WAN provider, and a firewall. Use a completely different internal IP addressing range, set endpoint switches to default route to core switch, core switch to default route to firewall, and firewall to default route to your WAN provider (LEA?). Yep that's a lot more changes than you were planning, but you're about to configure yourself into a bloody mess. I'd recommend backing it out, planning a network reconfiguration more carefully and breaking free from using the LEA IP addressing internally - that's not good to do from a security standpoint and MANY other reasons.
×
×
  • Create New...