-
Posts
975 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by seawolf
-
The only problems I've seen with it are that some Windows clients (and all Xerox copiers) are unable to connect to an SMBX file share hosted on a 10.8 server. 10.6 and prior mac clients might also have problems, but I haven't tested that. I've found no issues the other way around though (Mac client to Windows server).
-
This is not an SMBX issue. If they are able to access shares they shouldn't then you don't have your permissions set correctly, it's as simple as that. The Mac is just exposing an existing permissions issue. Now, if you can see all of the shares on the server in the sidebar, but the user can only access the ones you want them to then its working correctly and your permissions are not a problem. That is expected behaviour.. I normally turn off the finder sidebar showing connected servers and computers so users aren't confused. That way the user can only see the shares they have access to on the desktop or by clicking on the computer icon in the sidebar. With SMB on a Windows file server, you do lose spotlight searching and speeds are slower than with AFP. We use ExtremeZ-IP to provide native AFP file services and spotlight searching on our Windows file servers. It makes using windows print services easier on the mac than PC as well. With ExtremeZ-IP our macs can mount shares and transfer files as fast as Windows clients and can search file shares far faster than PCs due to the spotlight indexing. Another alternative I like to use to host files in a mixed client environment is to use a FreeNAS server, which provides both SMB and AFP file sharing services as well spas excellent AD integration for authentication.
-
Mouse77e - if you are serious about getting the core infrastructure right then go back to my post from the 21st of July where I've given some specifics on what that should look like. If you want to get more specific or would like something clarified feel free to ask. Those basic infrastructure recommendations are based on 15+ years of experience and having turned around the IT departments and operations of multiple companies and schools, including the most recent that required doing a "from scratch" in-place mass upgrade for an existing school. And it's exactly what I would do if I were in your shoes. Get that base infrastructure right and you can successfully use whatever end-point devices you want. p.s. Whatever you do, if you ever want to use Macs at your school, don't use a .local AD domain or you will regret it (been there, done that, had to clean up the mess).
- 51 replies
-
- 1
-
-
- free school
- ideal
-
(and 3 more)
Tagged with:
-
I haven't seen any performance issues with GAPS, although I have seen some potential issues in using it with multiple AD servers (it worked reliably with 2, but not 3 for us). GADS will sync whatever OUs you specify and it will create user accounts based on the email address you put in the email address field of the user in AD. This is how we are able to use the same GADS to sync users for two different domains.
-
Can I create an Active Directory domain with external DNS name?
seawolf replied to link470's topic in Windows Server 2012
Why are you using the same FQDN for your website as for the domain controller? You're domain controller should have a FQDN of something.doman.com and the website should be either http://www.domain.com or somethingelse.domain.com. If you insist on the website having the same FQDN as you have given the domain controller, then yes you will have to make the DC the web server as well. You could use DNS to make it work externally (public domain), but all queries internally would still resolve to the DC and not the website otherwise. However, I've never seen such a thing done, am highly against it, and suggest you not do it.- 16 replies
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
Gotchas are to be very careful with your sync rules for creating, suspending, and deleting accounts. We have some OUs that contain accounts we only use for authentication and not email, so those shouldn't be picked up by GADS, etc. We use two different email domains for students and staff. We used to have a single one, but then we had the problem of people guessing staff email addresses and students receiving email meant for a teacher (ghhhrrr). The two domains solves that problem, but not the ignorance that caused it (guessing, not asking).
-
There are a few options that will work for this (especially for 1:1 iPads), but with class sets they do rely on users signing in and out of the service so that they have access to the right folder. If a user forgets to sign out it will be the same as if they had failed to log out of a computer. In order of my own preference for features and ease of use: 1. MobilEcho 2. File services on a 10.8 Mac Server (WebDAV based, but works well) 3. ownCloud 4. Dropbox
-
Now to address your questions. As a couple of others have stated, I would first be looking at the base infrastructure as it is the foundation of everything you do. If you have under spec'd servers, a slow network, or inadequate WAN speeds and bandwidth - nothing you do will be without big problems. Here's where I would focus: 1. Build a fast network with high quality managed Layer 2/3 Cisco or HP Gigabit PoE switches with 10GbE connectivity to the core. You will either need a router or Layer 3 core switch to handle routing for your VLANs (use a lot of VLANS). Buy the very best you can afford and have them configured by someone who knows how to build a fast reliable, modern network. 2. A virtualised server environment with 2-3 highly spec'd servers with at least 8 cores, 48GB RAM, and 10GbE connectivity to the core switch and a high performance SAN or NAS supporting iSCSI and/or NFS. Flash write caches and lots of RAM recommended on the SAN. Buy the best spec'd servers and SAN you can afford. 3. A high quality WiFi system such as Ruckus or Aerohive (my favourites) with either 802.11n or 802.11ac. 4 Well configured and spec'd VM servers, configured on a service basis (don't have two servers do everything from authenticate users to make a cup of coffee for them). 5. Good backup systems for VMs and end-user data (VEEAM, Zmanda, BackupAssist, NetVault, Symmantec - take your pick) 6. Buy as much speed and bandwidth as you can for your WAN - 100Mb fibre or faster is ideal. If you can't afford that get a 20-40Mb connection at least. Once you have all of that then you can think about the end user requirements. Seriously. For instance, if you decide to go with iPads, Chromebooks, Surface Tablets, etc. then you will find them all to be problematic without the base infrastructure (I'm not in agreement with the generic or multiple vendor Android tablet argument some have proposed on here - they are a nightmare to support and manage if you do that). Now, based on what end-point clients you do go with, then you will have to decide on what specific solutions you will need on the back end to support that. Examples are that you will need Google Apps if you use Chromebooks and it would be good to have an SSO solution for it so users only had one login with AD, etc. or if you go with iPads you might want to use something like MobileEcho for providing access to a Windows file server (or you might just use a Mac server to do MDM and file services). If you go with PCs and Surface tablets, you will want SCCM, with Macs you might want DeployStudio, Casper Suite, etc. Get the base infrastructure right and all of the rest will come together with just a bit of thought and work.
- 51 replies
-
- free school
- ideal
-
(and 3 more)
Tagged with:
-
First, let me say that I have a long history with UNIX (and Linux), Windows, And Mac systems. I use them all for both servers and end-point clients. Each has their strengths and weaknesses. I agree with trying to be device agnostic to a point, but if you go too far with this strategy then nothing runs very well or is well integrated. However, your statement about serious security holes in Apple devices needs comment. There are FAR fewer security issues in Macs or iOS devices than any Windows or Android device. To state otherwise is to mislead. The only true widely exploitable weaknesses in OSX are related to either Java or Flash, or other 3rd-party applications. iOS is still almost untouched malware wise, especially compared to Android. Now, Solaris and most Linux distros have even fewer security issues than Apple OS's and if you're truly building a secure, malware free system you'd choose those. But, OSX or iOS being in the same boat as Windows or Android? Not a chance. Maybe one day, but not anytime soon.
- 51 replies
-
- free school
- ideal
-
(and 3 more)
Tagged with:
-
2900 series are a good bet for what you're after.
-
Can I create an Active Directory domain with external DNS name?
seawolf replied to link470's topic in Windows Server 2012
We changed from a .local to a public DNS 7 months ago. All of the supposed downsides to doing so turned out to be illusions, but the benefits were substantial for us. We have quite a few Macs and iPads and improvements for those systems were immediate and dramatic (.local and Apple mDNS don't mix well, some other systems have similar problems). Besides that, it just makes maintaining DNS records easier with one less domain to update.- 16 replies
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
If you're referring to the Lefthand SAN units from HP, they are pretty solid. I have seen some firmware issues in recent months (one where it was causing a rejection of passwords using mixed case - not good). Performance wise, they are good, but not great performers as they are usually configured RAID5 or RAID6. Also, expanding storage means basically buying another unit. I find the GUI a bit unintuitive, but many SANs can be like that. Support from HP seems pretty good on these units. Best thing to do is get a demo unit from HP to try out for yourself, that's what I did. They usually have them available within 2-3 weeks for trial. Otherwise, I would recommend looking at the Oracle (Sun) 7120 or 7320. These have much greater expansion options and the 7120 has a built in 73GB write cache that gives a good performance boost. I know the Sun/Oracle units have gotten some criticisms on these forums, but most of this has been misplaced or was related to the early versions of fishworks back in 2009/10. I've used both the 7110 and 7320 and they have provided fantastic performance and reliability.
-
Oh, and FreeNAS integrates easily with AD or LDAP... Your budget is tight for anything reasonable, but you should be able to afford a FreeNAS mini or roll your own Microserver with AMD processor on that budget as well.
-
I would strongly recommend a FreeNAS system over QNAP, Synology, Drobo, or any of the black box NAS devices. You pay a premium and often get substandard performance with them. Most of them also don't have redundant controllers or PSUs. With FreeNAS, you can either get a pre-built unit from iXsystems if you need or want the commercial support. They have a Microserver version or will build bespoke tower or rack mount systems to your requirements and prices are quite reasonable. They normally use SuperMicro chassis and Intel MB and CPUs. Or, you can roll your own using high quality components and you'll know exactly what you're getting and can get as much performance as your wallet can handle. FreeNAS OS can run on a very small SSD, USB, or Flash card and you can use a combination of SSD and SATA drives for storage. You have the choice of ZFS or UFS storage (ZFS recommended). Services available in FreeNAS include SMB/CIFS, AFP, NFS, iSCSI, HTTP, FTP,SSH, etc.
-
Why do you use target disk mode, then use drag and drop data as your restore method when you could use the migration utility in target disk mode with far less manual intervention (manual file copies can fail, has happened to us no more than one occasion) and when it would also provide the option of bringing over the users custom apps and settings? If you do that the user would only have to renter passwords and not all of the othe setup and config tasks. Other than the fact it was a new laptop they would wonder of you had done anything at all - that's a big advantage unix based systems have over Windows in the migration/restore area - might as well take advantage of it. Also, why do you use target disk mode at all if you are just dragging and dropping files and not pulling apps and user config across when you have crash plan pro with all user data backups? If you have a near enterprise setup then you must be using Deploy Studio, Casper, etc. - just script a restore task at the end of your image using the crash plan backups.
-
We require that staff have a Time Machine backup for their laptops. Then when their laptop is ever re-imaged or migrated to a new laptop we ask for the TM drive and run a final backup, which usually takes only a few minutes. Then we image the Mac, and finally restore user accounts and apps from the TM backup.
-
List of advantages for staff to actually use our school email service
seawolf replied to titch's topic in Cloud Services
Well, to me it appears that your school leadership don't care if staff use the school email or not. If they did, then staff would be using it. At least they would if I were their leader, or they would be told "don't come Monday" (aka you're sacked). So, if the leaders don't care and use personal email themselves, then you're just wasting precious time fighting a battle you will never win. If the leadership do care, then all they have to do is stop sending emails to personal accounts and staff will quickly get in line because very soon staff would be reprimanded for not responding to important emails, ignoring announcements, missing meetings, etc. Your school appears to have a leadership problem, not a technical problem. -
jmak - if you plan to upgrade them with SSDs in the next 1-2 years I wouldn't waste the money on a 7200 vs 5400 HDD. Any SSD will blow either away.
-
Another option to consider are the X5A units from Xi3 - http://www.xi3.com/x5a-modular-computer.php
-
Microsoft Surface RT - accessing work from home
seawolf replied to Mr_J's topic in Mobile Devices & Tablets
They are only cheap because they aren't selling that well. RT still has limited apps support. As for that supposed advantage with printing and network file access, that's easily resolved. Just use Printopia Pro, which works across VLANS and we even have it integrated with Papercut printing through the printers on the Wndows 2008R2 print server. For file access, MobilEcho is brilliant and you can also do WebDAV, Goggle Drive, SkyDrive, etc. with our setup we can print and access files on network over VPN from anywhere and I can also Remote Desktop or VNC to servers and clients with the "Desktop" iPad app. -
I would be reluctant to move from iOS to Android. I don't see it solving the problems that do exist with iOS management and hardware cost, etc without creating a lot of other problems. The OS fragmentation and crapware loaded on Android OS by most of the manufacturers is a big roadblock to me. I don't see Surface as a great solution either with Surface Pro so expensive and Surface RT quite limited in apps and manageability in a school. Personally, I'm going to wait to see what comes out later in the year with iOS 7 MDM improvements, etc. and hardware updates (fingers crossed). I also would like to see what happens with Ubuntu Tablet http://www.ubuntu.com/tablet - this project holds more promise than anything I've seen since the original iPad and could be the answer for a lot of schools. But, Ubuntu Tablet hardware is currently just vapourware, so it could drop with a resounding thud. I would love to see Ubuntu have success in the Tablet market though, especially if the tablets aren't hobbled by OS update fragmentation and crapware.
-
If you're a Google Apps school then Chromebox might be an option. Depends on what the requirements are for the classes using the ICT suite though.
-
Sweet! I'm going to look into that...
-
If you plan on upgrading them in a couple of years anyway, don't waste the money now on the small performance improvement you're likely to see.
