GoldenWonder
Members-
Posts
430 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GoldenWonder
-
TMG 2010 URL Filtering
GoldenWonder replied to GoldenWonder's topic in Internet Related/Filtering/Firewall
I'd be more interested to hear anyones experience of TMG's URL filter - no one out there using it? -
Has anyone here used Threat management gateway 2010's URL filtering subscription, and if so, how much did it cost and is it working well? I've been running an eval of smoothwall and its been pretty poor and the support hasn't been up to much either. As we're already running TMG2010 on a decent server it makes sense to use its own URL filtering rather than waste my life trying to get smoothwall to work properly. I've seen a price of $1,499 but not sure how it would equate in £s and Educational rates?
-
MS are really doing their best to push me towards Mac/Linux! Now I've discovered the firewall in W7 is useless. I have an app that everyone runs that connects to and SQL Server. But on W7 all i get the the usual Error 26 - 26 - locating server instance yada yada which bascially means it can't connect. Done everything as per MS - enable the App in the firewall rules, open the TCP/UDP port 1434 to allow SQL browser but to no avail. Logging is enabled in the firewall but the log file remains empty - yet as soon as I disabled the firewall the app works straight away. Honestly this OS is barely suitable for home use at the moment! Edit: proof positive that the W7 firewall is a crock, when you remove firewall policies from a GPO, they remain on the affected machines no matter how many reboots/gpupdates you do! looks like W7 will have to run with the firewall disabled - what a step backward
-
I do the same here, using 'Always' to enfore the preference. Make sure the Network Home is checked, and uncheck the 'Merge with users dock' option as that seemed to have strange results here (doubled up icons, missing icons etc - not what i was expecting) I've also added some SMB shares to Staffs docks - by dragging the link into the 'Documents and Folders' box - works a treat except it does take a good while for the Dock icon to become usable (it doesn't seem to respond to a double click for some time)
-
Very similar to ours - except My Documents is redirected to their root network share. Thats working fine, what isn't working is the offline caching of their redirected Desktop and Start Menu (which is why they get errors) .Offline files are working ok (I've tested by manually specifying a few). I've even set the redirected desktop folder as an Administrator specified offline file to synchronise in Group Policy but it still doesn't work! The redirected Desktop and Start Menu are on a read only share. This did work in XP, and Vista (how ironic!) but it fails on this in W7 and I'm going to have to find a workaround.
-
I've just started using Macs and to be honest find them about the same as a good Linux distro. What I have noticed I have the most problems with configuration in the order Mac>Win7>Linux>XP Win7 has too many broken features, the Macs have hung more than any hardware I've ever know (stupid spinning circle!), linux varies wildy and XP is pretty stable with many faults!
-
Right it seems to work with the Local My Documents now, with with folder redirection and cached logins it doesn't work. Something else that's broken in W7. If a user has a redirected desktop and start menu, and logs in with a cached profile (i.e offline) then surely that what the offline files part is supposed to replicate! My users just get errors that the desktop is not available etc.
-
Its a local profile (i.e created from Default user and group policy settings applied) Problem is the user can login with a cached profile, but it still tries to connect to redirected Start menus etc, which means an error pops up every so often! P.S Like the sounds of your new car!
-
I'm trying to setup some W7 laptops so that staff can login on the domain during the working day, and also at home offline. When online their My Documents is left redirected to the local drive, which means they can copy files to and from their network share. Works fine online, but when offline their profile doesn't seem to retain the setting that forces their My Documents to the local drive, it seems to create another copy of My Documents? Also, how does anyone else managed cached profiles when you have a desktop dished out from a server? As when the user logs in offline they get a message saying ''\\server\share\image not available' or similar? Ideally my offline users would just get their My Documents as normall (local) and locally installed applications - without the errors!
-
Well I've reached a sort of solution. Binding the Macs to OD and AD, and putting the OD server first in the Search order, then specifing the OD account name in the WGM seems to make the Macs pick up their Computer preferences. And it also seems to enable the access control. However the access control in OS X obviously can't copy with multiple group membership or it doesn't allow whitelist only type of restrictions. For example, if I only allow a certain group of students (who are also part of a large 'All' students group) then they can login,but end up with no Dock. So if anyone else is having problems - bind to OD, ignore Apples instructions as whitelists on Access Control simply don't work!
-
Mine seems to be consistent. When the Macs are bound to OD and AD, the machine prefs apply, the AD user can login but they get no prefs (just Finder!). When the Macs are bound only to AD and the OD server is specified users can login and get their correct prefs but the Mac gets no prefs at all! When the Macs are bound to OD, they appear in the 'local' computers in WGM (as opposed to finding them in AD) so I assume this is the right way to go, but something is obviously not right. Do the Macs need to be bound to OD to get their prefs, or can I use their AD accounts (in an OD group) to apply prefs?
-
One step forward, two steps back! I bound the Macs to OD and they then immediately started to pick up the access control policy, but it also mean the allowed users got no preferences (empy dock apart from finder etc) so I don't know what happened there!
-
Thats sort of what I'm trying to do. According to the documentation, if you add groups to the Access control list, only those groups that are explicitly allowed can log in. So I created 3 groups in OD, which contain AD groups of Staff,students and admins who are allowed to login. Result is still anyone can login! I'll try some deny settings but thats not how its supposed to work when reading Apples documentation. The AD group for student only contains a dozen users (which is linked to the OD group) and the Staff/Admins contains the single overall group for each. Because, as you say, Deny take precedence I wanted to create and Allow only whitelist type of restriction.
-
Hmm sounds like I have to Deny access, and then allow to selected users. However I don't think this will work as I want to deny access to students in general, but allow access to a specific set of students. But as they are members of students groups in general this might not work, as the Deny for 'all students' would include them!
-
Yes, its all Snow Leopard, all bought at the same time
-
Hmm tried OD and AD groups in the WGM and it lets any user login. I'll try the local setting and see what it does. EDIT: It seems our Macs just can't understand AD groups. If I set the preferences at the the WGM (using either AD or OD groups) it lets anyone login. if I set the preferences at the individual Macs (again using either AD or OD) groups it then doesn't let anyone log in! if I specify individual AD users at the individual Macs then it works, but thats not a useful option for me
-
Brilliant,just what I was after!
-
On our XP laptops (for Staff) we used to use a local policy to lockdown their local account (a different account to the domain, for use offline) which was done by simply using Gpedit and then denying access to the Group Policy folder for Administrators. Is this still possible in Windows 7? We do this to make sure they use the local My Documents when offline, and then My Documents is redirected to their network share when back online, otherwise we would just let them use their network account to login offline.
-
Cheers for that, thats exactly what I've done - added some AD groups into that list but in the WGM, but it seems to let anyone log in regardless. I might try it on the local computer just to see if that works.
-
I'm guessing the answer is no - what do the Access Control settings actually do then?
-
Quick question - is there a way I can restrict logins on our Macs (which use AD authentication) to certain AD groups? I use this quite a lot in windows, but haven't seen a way in Macs yet. I thought Access Control would be it, but it doesn't seem to do what I'm after.
-
That sounds handy, backing up the preferences on their own. How do i do that? I don't seem to haven stumbled across that yet.
-
Well I seem to have it working again after a reinstall. And recreating all of the preferences! Didn't think of asking the Apple reseller as I seem to spend a horrendous amount of time dealing with support personnel and getting nowhere!
-
Its got a 160Gb drive,of which 15GB is used - users don't store on it,its really only used for preferences and also OD/AD authentication
-
This was a brand new install from about 2 months ago, it has only been 'live' for a month. It has started hanging due to the startup disk message and now the permissions and access rights are all over the place. Even my ropey old Windows 2000 and Ubuntu servers can struggle on for a year without crashing!
