Jump to content

s1ndr0me

Members
  • Posts

    25
  • Joined

  • Last visited

Everything posted by s1ndr0me

  1. I'm sure you've all been losing sleep over this but I figured it out. After finally managing to get a support account I updated the firmware on the box. took a while as I had to go from 9.6 (shock) up to 9.12 in steps. Now the SSl works just fine. Theres also a ton of functionality. I've since ripped the whole lot down and just have a simple sign in based on on active directory with no provisioning portal or any of the other crap. Joy!!!
  2. Morning all. I'm having a spot of bother getting our wildcard SSL into our ZD. Well not so much getting it into the ZD but getting browsers to like it. Heres what I am doing. Generate New Private Key 2048bit. Generate New CSR. Upload CSR to SSL247. Once they email the cert I save as .crt and then import into the ZD. I also add the inter cert that is sent with the main one. However this gives me a cipher mismatch in chrome/android. Now the certificate clearly says its RSA256bit However when I scroll down it looks like this I'm guessing its something to do with the ZD. I recently bought our moodle inhouse and installed SSL in the usual way by generating a key and csr from openSSL and then pointing apache to the correct files. when i load our moodle in chrome its happy that the site is secure but it does still have the same error that I posted in image 2. Needless to say I'm a bit stumped, anyone else experienced this? Kind regards
  3. Many Cores, Such RAM, Much Spindles. We run 101 L300/350's from a single DELL R630. It has 96 GB RAM & 2 x Xeon E5-2630 v3 (2.40 GHz) RAID1 SSD for the host. The Dell is a Hyper-V host with two Server 2012r2's clients that the ncomputing boxes connect to, these VM's are on a 6 spindle SAS OBR10. If I was to buy again I'd defiantly do 128GB of RAM and have a 2U server that I could have more spindles in. If you're just running with 30 machines in a lab you wont need anything like that. We've run 15 l300's from from a 6 core AMD with just 16GB and 1 spindle. You'll need a Licensing server and the appropriate RDS CAL's The system does have a few niggles and USB drives are a bit hit n miss. apart from that its a cheap solution for most applications except video editing.
  4. Well I've had a couple of weeks off from migrating users as I didnt want mess anyone up during the exam period but I'm back on it now. I've noticed a problem with one of MS's scripts. ExportO365UserInfo.ps1 is generating strange results. I'll explain. I create a .CSV migration file which looks like this: EmailAddress [email protected] I then run it against the ExportO365UserInfo.ps1 file to get a returned cloud.csv file. Now heres the science. Un inspection of cloud.csv I can see that not all the data in the first column is there. the script returns this: LegacyExchangeDN,CloudEmailAddress,OnPremiseEmailAddress,MailboxGUID /o=ExchangeLabs/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Recipients/cn=43c6ab43f79d4c3dbbf7740464473ac4-Kevin.Algaw,,[email protected],0e2054e6-31c0-4c71-b80e-95564bdd0aaf The problem is that the script is not rendering the the end of the LegacyExchangeDN part. the line should read: LegacyExchangeDN,CloudEmailAddress,OnPremiseEmailAddress,MailboxGUID /o=ExchangeLabs/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Recipients/cn=43c6ab43f79d4c3dbbf7740464473ac4-Kevin.Algawattage,[email protected],0e2054e6-31c0-4c71-b80e-95564bdd0aaf It's adding an extra comma and truncating the name. Not sure what to do. Any ideas would be great 3k user migration is looking pretty grim right now s1n
  5. So I migrated myself today. by simply running the batch and then running the two scripts ExportO365UserInfo.ps1 & Exchange2007MBtoMEU.ps1. Now when i run the last one I get an error message about multiple primary SMTP's WARNING: Object school.sch/staff/other staff/it boys -own desktop/user.name has been corrupted and it is in an inconsistent state. The following validation errors have occurred: WARNING: There are multiple primary SMTP addresses. Please ensure there is only one primary address for each address type. WARNING: Object school.sch/staff/other staff/it boys -own desktop/user.name has been corrupted and it is in an inconsistent state. The following validation errors have occurred: WARNING: There are multiple primary SMTP addresses. Please ensure there is only one primary address for each address type. It then continues the process of converting the mailbox to an MEU. At the end it gives a red error of Set-MailUser : There are multiple primary SMTP addresses. Please ensure there is only one primary address for each address type. when I go into the mailbox on exchange it has one primary email address and thats the [email protected] as the Primary SMTP one and has the SMTP:[email protected] as the external email. To me this looks good. Mailflow is.....er, flowing and the mailbox doesnt error when opening it in exchange. I think I am good to start proper. csv files are made I just need to grow a pair and pull the trigger.
  6. hmmmm scratch that. I did the first part of the migration on my own account yesterday and didnt have to fiddle with AD to get mailflow working. I'll try with a test batch this morning and see what happens. fingers crossed. On another note anyone had any experience with SRV records and KCOM's dns panel. when i tried to configure ours for lync I couldnt get it to resolve. Autodiscovered SRV record: _sipfederationtls._tcp.school.county.sch.uk resolves to sipfed.online.lync.com.school.county.sch.uk, when expected value is: sipfed.online.lync.com. that doesnt bother me too much but i'm seeing that i'll need to add an SRV for exchange online autodiscover.
  7. Greetings all, My Office365 saga continues. Firstly, thanks to everyone in the community thats taken time to read my posts and offer support during their otherwise busy days. I'm attempting a staged migration as per Migrate Mailboxes to Exchange Online with a Staged Migration: Exchange Online Help. Once a mailbox has been migrated. There isnt any mail flow. looking at the mailbox properties on the exchange2007 server it seems that when O365 is tidying up it adds the target address attribute which is the .onmircosoft one but also adds that same address as a primary SMTP address. opening the properties of the mailbox on the server gives a warning about bad config. Sure enough both the vanity address (school.county.sch.uk) and the O365 (school.onmicrosoft.com) one are both highlighted in bold. I then need to uncheck the email policy box below and get it so that there is only the vanity domain as primary. Once that is done the flow returns. is this right? surely I'm missing something? There's 2k users to migrate!! oh the humanity! regards
  8. you sir are a legend!! I'll do that right now. many thanks!
  9. Hi all, hope theres a 365 guru around this morning, Got our office 365 proplus student advantage yesyerday. 'Microsoft O365ProPlusOpenStudents ShrdSvr ALNG SubsVL OLV NL 1Mth Acdmc Stdnt w/Faculty' Our active directory is synced with the 365 portal. The TXT record is in place and my users can logon with thier exchange email and password. I've assigned a test user the office package in the portal but they cant access Onedrive. For example logging into word using the 365 credentials then adding one drive as a service results in 'This type of account doesn't work with this particular service. Please enter an email address associated with a different account.' If I use the same credentials to signup for a standard onedrive account from https://onedrive.live.com/about/en-gb/ it returns this 'That Microsoft account doesn't exist. Enter a different email address or get a new account.' office 2013 onedrive for business is asking for a sharepoint location so confused there too. I noticed in the 365 portal advanced setup theres a check box for sharepoint but if I tick that and go through the process nothing much seems to happen. Do i need to signup for the free A2 plan to enable onedrive and web apps? many thanks (i'd go on but i'm now late for work) in advance
  10. ahhh ha fixed it. I simply took everything out of the walled garden except the link to the zone director. because of that it cant read the wpad file and then redirects. DISCO. Happy with that I've moved onto OSX and theres a problem. Connecting to the portal brings up the OSX capitive portal. I can logon. but cant download the configuration file. Deep joy.
  11. scratch that I added if (isInNet(dnsResolve(host), "172.21.0.0", "255.255.0.0")) {return "DIRECT";} which resolved the ip address. Probably a bit ham fisted but hey ho. still not working. If I kill the wpad by adding a syntax error. it redirects straight away. I think "ahhh ha fixed it" then connect to the staff WLAN and promptly can't get out.
  12. Thanks truebluesteve, Not using radius atm, although we have set it up in the past back on a more domestic G network. so this is where we are at now. Confident our wpad is working. heres how she looks function FindProxyForURL(url, host) { //check for local domains if (dnsDomainIs(host,"bryntegcs.sch")) {return "DIRECT";} if (shExpMatch(host, "cloud.*")) {return "DIRECT";} if (shExpMatch(host, "simsportal.*")) {return "DIRECT";} if (shExpMatch(host, "wifi.*")) {return "DIRECT";} //check for short host names if (isPlainHostName(host)) {return "DIRECT";} //else return proxy return "PROXY 172.21.147.2:5566"; } The DefaultConnectionSettings key in the registry is showing http://wpad.bryntegcs.sch/wpad.dat connecting to the portal the test browser is set with google as the homepage. The browser then waits for google to respond and then ends with "The proxy server isnt responding check your proxy settings 172.21.147.2:5566" However when I type the address of the zonedirector using wifi.bryntegschool.co.uk it redirects me to the https activate page. I really dont want my users to have to type in the ZD address. interestingly when i type the IP of the zonedirector it wont resolve. However using its internal name wifi.bryntegcs.sch and its external name wifi.bryntegschool.co.uk both do. So damn close!!
  13. made a bit of progress today. I'd missed a line in the wpad file. So now we are connecting to the portal and the browser is redirecting. We can authenticate and install the profile. The only problem now is when I switch over the to the staff WLAN i cant get out. pretty sure I am just a click away from a working wi-fi network. fingers crossed it will come together tomorrow
  14. Hi again, It doesnt seem to matter what the homepage is set to. http or s. or even directly typing in the address bar What I have noticed tho. If I uncheck the detect automatically option it redirects straight away. I can then logon and connect to the correct WLAN but have to set the auto detect box back to auto detect. So wondering if its something to do with the wpad file.
  15. Hi FN-GM well I've tried setting the homepage as our internal intranet, our external website and google and it fails to redirect. The zone director captive portal is https and it's secured with our wildcard rapidSSL cert (all seems work fine). I've had another little fiddle this morning. heres how the hotspot looks and one of the WLAN it sits in hope that helps s1n
  16. struggling with this and I cant work out why. So I have a WLAN called portal (provisioning) containing a hostspot. Windows users connect but when they open the browser it doesnt redirect to the captive portal. I had it working so the help bubble would appear by the system tray announcing that additional steps may need to be taken to complete the connection. It works fine with IOS and I can access the portal by manually entering the address into the browser. It fails to open in chrome either. What else? clients pickup a wpad when they open the browser from the address the DHCP server provides so I've had to allow those ip's along with the address of the ZD to thee list of allowed sites in the walled garden. Any ideas at this stage would be more than welcome. I'll be in work in a bit so can provide some more detailed info pretty gutted. Damn thing is so close to being signed off.
  17. Thanks guys, your help is appreciated. I think I fall into DMcCoy's bracket of users. TBH after this morning I've had a guts full. Got in and now cant get the captive portal page up unless all the windows lan settings are unticked including auto detect. once provisioned I then need to go back in and check the auto detect settings again. pain in the ...... probably something to do with the walled garden.
  18. Thanks for the reply seawolf, I've heard a bit about transparent proxies whilst trawling the boards for ruckus info. we just run a couple of explicit squids that authenticate with the counties ISA server, they take care of firewall/filtering duties. We are tied in with them for years and they are inflexible to say the least. Are you saying that NPS or packetfence act as transparent proxies? If you have the time could you explain a bit further? many thanks
  19. well i'm pretty much there with it. the video a few posts up really helped. I have 5 WLAN's. a bog standard WPA2 with MAC filtering for all school devices. schools ios devices are configured via apple configurator with WLAN, proxy and the mcafee firewall certificate which the county insist we use. then we have a portal/provisioning WLAN for the site. which handles the zero-it shenanigans and pushes the users to either the staff or students WLANS depending on their AD group membership. windows clients have autodetect settings for wpad and ios users have to manually enter the FDQN to a local IIS serving a .pac Finally and this is the stumbling block. the guest wlan. I'm trying to set it up and it it works ish. all the problems lie with ios and the inability to add cetificates and proxy settings to the zero-it mobile.config file. however the wpad deployed doesnt seem too clever on windows either. with ios i can add the .pac path to the WLAN before connecting. when connecting it will sometimes call the captive portal directly, sometimes i'll have to open safari and either type a random url or have to type the fdqn of the ZD activate page. today i felt all smug that it was working. we had to prep 8 netbooks for some training. the first one went in a treat and then it fell apart. they just wouldnt take the wpad. the worst part is these proxy files might be cached somewhere leaving me running around in circles trying to fix it. I think i might just create AD users for guests and just assign them login credentials via a laminated card. Just to get the job signed off for half term. A side note. we use owncloud to shovel files from ios to windows. works like a bought one s1n
  20. Thanks, this fixed it for me :-)
  21. Thanks, apologies for requesting help on something thats already been discussed.
  22. Hi Nick, I've got the beta myfiles working and I must say it's a vast visual improvement on the extended. There is a snag tho. While admins are free to upload/download files, staff & pupils get challenged with a restricted filetype box. This doesn't happen with either the html or extended file browsers. Can you think of a reason this might be happening? thanks in advance
  23. Ok just wanna say thanks, My sphincter isn't quite the same nor will it ever be. There is something quite disconcerting working on an exchange server but all went well. Cracking application Nickbro Pease pudding
  24. Thanks for the Heads up nickbro, I'm gonna have another crack once the kids have left tonight.
  25. Hi All, we're looking at HAP as an access solution for staff and students. Unfortunatly our only front facing server with SSL and IIS is our exchange 2007 box running 2003 x64. Our webserver is LAMP so is not an option. Obviously exchange is ASP 2.0, however when I install .net 4 and reboot. .net 4 is not available as a web extension in IIS 6. Can the two co-exist. any tips or links that might help me out. Kind regards S1n
×
×
  • Create New...