GoldenWonder
Members-
Posts
430 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GoldenWonder
-
Unfortunately they don't treat the ICT rooms or their classroom PCs carefully at all! That bugs me a bit, the laptop is looked after because its 'theirs' but they allow the kids to trash the ICT rooms because its somebody elses problem!
-
We tend to pay for repairs ourselves, although the initial laptop purchase is by the department Generally the only problems we have are hardware failures and the rare 'lost' power supply. Otherwise they seem to take pretty good care of them here.
-
Setting different wallpapers with GPO for two different OU's
GoldenWonder replied to HMCTech's topic in Windows
I wrote a little vbs script for machine startup that I placed in a GPO. This copies over an image and sets the default background in the registry. As the rooms are organised in OUs in AD, I simply made different GP's for each room or area. Therefore whenever a PC is added or relocated it picks up its new background. Took a little bit of setting up and probably not the cleverest way but its now self-maintaining and it makes the ICT suites look nice! -
I was forced to unblock it for staff here by SMT, but not students. Now they can't teach without it! Despite the logs showing that 99% of the usage is music videos, football and 'funny' clips. The future of teaching is youtube....
-
On our network we run several VBS scripts on machine startup.These clear old files, install Quicktime etc and have been working on over 500 PCs for several years. Occasionally, one PC will start to generate an error for each one of these vbs scripts: Event Type: Error Event Source: UserInit Event Category: None Event ID: 1000 Date: 06/11/2008 Time: 14:11:11 User: N/A Computer: pc_name Description: Could not execute the following script delprofile.vbs. . I have tried everything to resolve this, and in the last 2 years have only found one resolution - reinstall windows! These scripts work fine when run directly on the failing PC, and work everywhere else! The scripts don't generate any errors, and even if I reduce the scripts down to just one it still generates the error. No matter whether I run 1 or all 3 I get the corresponding number of errors. The only thing I can see that is common is that they are all VBS scripts - other parts of the startup batch file are running (registry hacks etc) We do have Software Restriction Policies applied to users (never Machines) and I'm wondering if this is corrupting somehow for vbs scripts- other scripts (.bat etc) are still running OK. I'm at a loss now, any suggestions gratefully received?
-
If you bought Office under a Select/Open license then the At Home rights allow Staff (not students) to use a copy of Office on their home PC as well. This means they have the right to use it via TS as well. We only allow remote access to staff at the moment, so their 'work' pc and 'home' are the licensed ones. MS really need to look into this one - hwo on earth is anyone supposed to license Office over TS and keep it legitimate! I've spoken to about 5 different resellers and MS people and had about 5 different answers.
-
We check our main suites every morning. Nothing too comprehensive just making sure all are working and the printers are full etc. We don't have a checksheet as such, but any problems found (including vandalism) are logged into our helpdesk
-
We allow 20 a week for students and 400 for staff. Students then ask for more to 'print their coursework'
-
Did anyone else set delegation rights on the cachepilots AD object? I notice the DC has a load of the following errors when binding to the domain: Event Type: Error Event Source: KDC Event Category: None Event ID: 27 Date: 06/10/2008 Time: 16:23:09 User: N/A Computer: Description: While processing a TGS request for the target server host/-web., the account -WEB$@ did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of 8). The requested etypes were 2. The accounts available etypes were 23 -133 -128 3 1. If I set the cachepilots object to allow delegation for Kerberos these errors disappear, but it still fails to authenticate! Any more of this and its going out of the window, and a nice new ISA server will take its place....
-
Tempted to take the magnet approach! But without the internet the teachers could not teach
-
Equiinet say the box is fine We have a single domain - pretty straightforward setup really. The cachepilot logs show the bind works so I guess the details for DC and user account are OK (I've tried a limited user account and an Admin account with the same result) Haven't tried the .local on the domain name, I've been using the domain.org.uk FQDN version and the cachepilot gets the short version itself. As you say, theres not much else to do!
-
Time synch'd correctly. Global security group with same name as cachepilot user set up. Still no joy! I've been trying this for months now and have deleted and recreated the users/groups several times to make sure. Did you use AD or LDAP to authenticate? I've tried both.
-
Has anyone got a cachepilot to authenticate users from AD? We have a cachepilot 4.1 and have tried to set up the authentication using AD or LDAP. It binds to the domain OK and we've set up the users and groups etc as specified in the instructions. However, all the user gets is a long delay, and then a windows username dialogue box. No matter what credentials are in it stays at that point. Nothing shows in the cachepilot logs - apart from the sucesseful bind message! Equiinet weren't much help - they basically gave up on us. Its a bog standard Windows 2003 server domain so nothing weird!
-
Thanks for that - it will take some planning I guess. The core switch is L3 and the downstream cabinet switches are generally L2 stacking units so in theory I'm ready to go!
-
I'm toying with the idea of splitting my network into VLANS to cut back on the traffic. Basically we have a central cabinet, with all other cabinets meeting in that cabinet in a fibre/gigabit switch (netgear L3) using fibre cabling. The servers are on another switch, which feeds into that fibre switch using one port. Am I right in saying that I can just configure the main fibre switch ports to assign them to different VLANs? As this is the central point of all cabling this is where the geographical split would be. I.e Port 1 is the 'south wing' cabinet, does sticking port 1 into its own VLAN effectively put all traffic from that port (and therefore all ports in the south wing cabinet) seperate it from the others? (I would want the various cabinets to communicate with the servers, but not necessarily with each other) Am I over-simplifying this? Never really used VLANS before as networks I've managed have always stayed at under 500 PCs!
-
Will you be upgrading to server 2008 this summer?
GoldenWonder replied to FN-GM's topic in Windows Server 2008
I had intended to roll out a couple of server 2008 installations until I realised that I would have to buy all of the device CALs again. 500+ of them at £6 each makes it a very expensive exercise. Typical MS! Now I'm staying with 2003 until a) they change the licensing to allow 2003 CALS or b) BSF pushes me out of a job anyway! -
Its the same old IT scenario. Boom and Bust. Every sector I've worked in rushed to put in IT equipment and staff. As soon as they became reliant on it, they look to make it cheaper and then outsource it. Manufacturing, financial, call centers, local councils and now education. Its just our turn to be disposed of.
-
Setting up remote access to staff user accounts
GoldenWonder replied to firefox_2006's topic in How do you do....it?
We put a fully fledged system in using Citrix (Presentation server and an Access gateway) Works very well. Staff have access to home folders, the intranet,email and lots of networked applications that they normally use in school. Costs a bit though! -
Cheers - I'm going to try that Advanced Installer freeware and see how it performs.
-
I've been using the free version of WinInstall LE to create MSI packages for Active Directory deployment for a while. It works, but has its limitations so I'm looking to buy a proper version - does anyone have any advice/comments on the best one available for a reasonable cost? We're on a Windows vanilla network - no RM/CC stuff!
-
Must be the APs - I dug out an old Dlink DWL2000AP and set this up and I could fully manage/ping the laptop connected to it without any problems! Funny how both the DWL7000 and the Zyxels (which are a lot newer) cause the same problem, but the DWL2000 (which is as old as the DWL7000) seems to work OK, even though they are a 'basic' model!
-
Sorry for the delay in replying - busy week! In answer to suggestions: - tracert fails with 'timed out' error - rras dhcp is user because the radius server needs to pass the laptops dhcp requests to our dhcp server (seperate from the radius server) - the APs don't seem to have anything to block arp requests etc (i've tested both types, DLink DWL7000 and Zyxel G1000) Bizarre!
-
Just done another little test. Running a packet sniffer shows that the laptop is receiving the ping requests from the RADIUS server, and sending the Echo(ping) reply back to the Radius server, even though the pink originated from my admin PC. This may be correct - I'm not sure how this works right down at the packet level! Is there a way I have to route these packets in the same way as I had to route DHCP requests using RRAS on the RADIUS server? Another test - manually added the laptop NICs mac address manually into the PCs ARP table using arp -s, and I then get full connectivity! Now, I am really confused.
-
Cheers for the info guys but I'm still stuck! The APs are setup Ok - pretty much as ashok has described. We don't have MAC filtering enabled - theres not enough room in the tables! What seems bizarre is that the laptop has to establish the connection (on a one to one basis) before two way communication works. It seems to be at a lower level, ARP requests not being answered etc? For example, if laptop pings PC then PC can ping laptop - if I then clear the ARP cache on the PC (arp -d) then the PC can no longer ping the laptop (until the laptop pings the PC again)!! Edit: forgot to mention - tried on a different laptop connecting to a Zyxel AP and get the same problem.
-
Nope, they're pretty basic (DWL-7000AP) models that only have security options on for authentication (WEP/WPA etc)
