CapnPugwash
Members-
Posts
334 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CapnPugwash
-
Thanks for your answers, much appreciated. It's giving me a headache to be honest. At the moment we have no wifi so everyone is on computers and all computers are monitored by PCE. I know that when we have full wifi available , teachers will wanting to rush into BYOD, so very quickly it will be acceptable for kids to be using mobile devices in class. Smoothwall will monitor their internet usage but I don't think it will monitor the actual content of an email, so straight away, emails will be (in the main) unmonitored. Equally, I can imagine kids loading their devices with all kinds of images/videos from home. They can be showing these to classmates and can probably email them to each other without it being picked up by Smoothwall? I don't think there is a tech solution for this, it's going to be a combination of policies (that are clear and enforced) , user education and trust.
-
Hi, We currently have PCE installed on all our PC's. I'm not a huge fan, apart from it needing Java I have had issues with the level (lack) of support which hopefully they have resolved now. The reason we use PCE is SLT are adamant that it's the ONLY product that gives an adequate layer of monitoring... Next year we will be moving slowly towards BYOD. PCE doesn't support any tablet device and I think we would struggle to justify putting any kind of client on someone else's personal device. By the time this happens, we will be using Smoothwall , so web access should be locked down tight. We obviously have an acceptable use policy that covers mobile devices but at the moment students aren't allowed to have their phones out during lessons. If we go BYOD students will be encouraged to use their devices during lessons. Am interested to know what other people are doing , both in terms of monitoring software and policies.
-
Port forwarding is done at their end and is correct. The web page isn't actually blank... if I leave it long enough (FireFox) it comes back with a 'The connection has timed out' message... the URL stays the same in the address bar
-
Hi, We have Exchange 2010. Clients log in via OWA. We've recently changed ISP & domain hosting company & we have an email issue. I can load up a browser on a local network machine, go to OWA and login, send/receive emails without any problems. If I try this on an external machine, OWA doesn't load - I just get a blank page. Any ideas what I could look for? My SSL cert is fine, could this be permissions or something in IIS? Cheers
-
I know variations of this question get asked/answered all the time but ... I'm in a situation where I might have to kit out twenty rooms for AV - on a budget. Money isn't the only consideration, the life expectancy and maintenance of the kit is also a factor. I don't think interactive boards are a necessity - we've had lots of them and teachers rarely use them as they are intended. TV's look attractive because... less cables, built in speakers etc. A supplier has told us we need 'special' 24/7 TV's , which I find odd because we have several cheap TVs in school used as displays which are on all day / every day and have been for years.... Interested in peoples opinions, especially people who have made similar volume purchases recently
-
No VLANS or anything like that. It doesn't really make a lot of sense to me that it would be the new broadband router that was the problem... but it's so weird that this happened at the same time the router went in & VCenter doesn't seem to be in any kind of error state (apart from not being able to connect to it!) Also the Veeam error messages... Veeam is definitely trying to communicate via HTTPS and failing... If anyone has any other ideas of things I could check, I'm all ears!
-
I don't know & on my part it's pure guesswork based on: * this problem happened when we got the new internet connection * The VCenter itself looks fine in every way * It's not a DNS/DHCP error * The error messages from Veeam suggest traffic is being pushed to VCenter via HTTP/S It could be that I'm completely wrong but hopefully I'll find out today. Our VMware & Veeam were setup by a third party IT company
-
OK, digging in deeper : the logs make no mention of DB errors & the VCenter VM has plenty of disk space. I can ping the IP. I can open the host that the VCenter sits on, open the console and log in. If I check the services that are running; everything seems to be fine. if I look at the Veeam logs I can see the backups were running fine until I switched over to the new internet connection. The failure messages from Veeam say 'can't connect to http://VCenter:xxxx' I think the problem is the new broadband router is blocking traffic to ports that VCenter uses.. Getting the ISP to check this.
-
Hi, O365 / Exchange 2010 in Hybrid config Emails sent with attachments from on-premise Exchange to O365 account have attachments replaced with two txt files: one called msg-xxxx-xx and one called a variant of r1,c1 etc. If the same email is sent to a non O365 address , the attachments arrive without issue. If an email with no attachment is sent from the on-prem to O365 it arrives without issue. NOTE : we had this working great but we've just changed our ISP and domain hosting company.
-
Hi, we also use Veeam so can't backup. Our VCenter server runs as a self contained virtual machine so your solution wont work for me, unfortunately. Not sure where to begin with this. At a guess I'm going to have to log into the VCenter console and check services are running etc but I'm not really sure what to do.
-
Hi, Today I've been unable to connect to the vSphere vCenter server (VMware 5.5) via either the client or the web interface. The client returns a 'can't connect' message. A browser will return a 'Page can't be displayed' message. I've tried this on a number of different machines. I can access any of the ESX hosts via the vSphere client. I can access the host that the vCenter server sits on - it looks fine. I've restarted it but it's still the same. I can ping the address of the vCenter server and I get a reply as expected. Looking at the logs, the line line that sticks out is "System.Net.Sockets.SocketException: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond xx.xxx.xx.xx:443" The only thing that's changed in the last few days is we have a new internet connection / proxy server. Can anyone think of things that I can check? Cheers
-
Hmm... I tried getting another user to create a Group and they had exactly the same issue. Three hours later everything was back to normal and working as it should! During this time I didn't see anything in the admin portal / service health to suggest there was an issue
-
Hi, Today I created a group within (OWA) O365 for a project. Once it was set up I tried to add Notebook & Files. Clicking on either of these tabs brought up an error. Clicking on the help button gave me this message: "Unfortunately, help seems to be broken... There aren't any help collections in the current language for the site you're using." When I looked at the URLs for Notebook & Files, they looked wrong - they didn't point to the group site & looked a bit random After playing around for a while I decided to cut my loses and delete / recreate the group. I deleted it in the Admin Portal but it's still there in OWA! Has anyone experienced anything similar?
-
Does anyone know if it's possible to import a calendar into a an O365 Group?
-
Just been through this with Microsoft support (who, to be honest, have been consistently good throughout this process - put in a support request & it's guaranteed that someone will phone within an hour or so) & created a new send connector with TLS turned off & everything *seems* to be working fine Hope someone, some day, finds some of this useful!
-
But ... not ... quite "The IP address that triggered the message from Spamhaus is a router that our ISP push all 'badly configured' email through" so, this router that our ISP push 'bad' email through gets blocked by Spamhaus. But then someone will request the IP be unblocked and everything will seem fine. Until it's blocked again. And this goes on and on. So I thought I had my issue resolved but it wasn't, the IP of the honeypot router was just taken off the Spamhaus block list for a few hours. Digging deeper into my problem, I could see that (1) my ISP routes all email through a smart host and (2) my O365 send connector wasn't pointing to it. That's why the internal emails from an the an on-site mail account to a mail account in our O365 cloud were classed as 'bad' So I added the address of the smart host to the O365 outbound send connector & now emails sent from an onsite mail account to a O365 account... don't seem to go anywhere. I enabled verbose logging on the O365 outbound send connector, sent a test emails and checked the log. The outward bound email hits the smart host but doesn't get any further because: "Connector is configured to send mail only over TLS connections and remote doesn't support TLS" I opened a telnet session and connected to the smart host and sent an EHLO testing message... connection was successful but I don't get any info back about TLS (no STARTTLS etc) I have to say , this has all been very... trying.
-
Ah... all sorted. Something went slightly wrong when I migrated the test mailbox (it ended up with the wrong SMTP address) The IP address that triggered the message from Spamhaus is a router that our ISP push all 'badly configured' email through. I've migrated a bunch of other test mail boxes now with no issue. Phew
-
O365 & Exchange 2010 in hybrid config. Run the HCF without issue & have dirsync correctly syncing users/passwords with AD. Got my ISP to open relevant firewall ports (tied to relevant MSoft IP's) & change DNS records. Migrated a test users' mail box from within Exchange Management Console - no issues. logged into O365 as test user and sent emails to internal / external accounts & sent test emails from internal accounts to the test user. Everything is 'proper nice' for ... 40 minutes ... and then emails sent from an internal address to the test user are bounced back with this message: Your message wasn't delivered due to a permission or security issue. It may have been rejected by a moderator, the address may only accept e-mail from certain senders, or another restriction may be preventing delivery. The following organisation rejected your message: mail.protection.outlook.com. Client host [iP] blocked using Spamhaus; To request removal from this list see http://www.spamhaus.org/lookup.lasso> #SMTP# Checked Spamhaus & the IP (not one of our public facing IP addresses but definitely belonging to our ISP) was on a list. tried sending other test emails from the same address to Gmail, Hotmail, O365 accounts - all went through without issue. The only emails that triggered the Spamhaus bounce back were sent from Exchange to O365... Our ISP put in a request to Spamhaus to have the IP address unblocked and now everything is fine... but I don't understand : why it happened in the first place; why it happened shortly after having our DNS records changed (but not immediately) and why it seemed to only affect emails sent from [email protected] to [email protected] where user1 has an onsite Exchange mailbox and user2 has an O365 mailbox... Merry Christmas!
-
O365 / Exchange 2010 : Hybrid - Secure Exchange
CapnPugwash replied to CapnPugwash's topic in Cloud Services
In case anyone is following or in the same boat... This has been a real pain & we've got no one to blame but ourselves (or myself, as I'm the only one involved) Problems with the ISP/Firewall should have been anticipated sooner & prepared for... it's just another over familiar case of people wanting big things and wanting them TODAY! Our LEA is our broadband supplier. They lease the connection from someone else. I think the business relationship may have broken down somewhat as next year they are leasing it from another supplier so at a guess, this is adding more layers of complexity to the whole thing as my requests Ping-Pong between the two of them. This should have been a lot easier than it has been. Because I have to get things sorted RIGHT NOW! I've told them to open the relevant firewall ports and tie them down to the IP's in the current MSoft list. If the list changes and we have to pay another load of ££££ to put in another firewall request, that's just the way it will have to be. I am not confident that I can secure our Exchange server in the next 24hrs, so it's the only way forward. Once we have O365 working I can set up pfsense - an onsite firewall would protect Exchange (we currently don't have an on-site firewall or an Exchange Edge server) MERRY XMAS! -
O365 / Exchange 2010 : Hybrid - Secure Exchange
CapnPugwash replied to CapnPugwash's topic in Cloud Services
Ha! Yes. It's on the list. -
Setting up O365 / Exchange 2010 hybrid. Had a few problems with our ISP who charge a fair bit to make ANY change to the firewall. We've now agreed that they will open port 25 etc. and we will have to secure Exchange at our end to prevent it being used as a Spam Relay. The reason for this is if they handled the Microsoft IP range at their end, every time it changed they would charge me again (and again!) How do I go about securing Exchange? I've run the Hybrid configuration wizard and it has created O365 connectors with, what I presume are the EOP IP addresses.... not sure what else I need to do & everytime I speak to the ISP they raise the PANIC LEVEL!
-
You are not kidding about the price!
-
This is what's worrying me, especially as our ISP will charge us £147 for ANY change request! What our ISP is now suggesting is that they: Permit internally initiated traffic from IP of exchange server to any IP on ports 53 (TCP and UDP) and 25, 587, 143, 993 (all TCP) Permit Externally initiated traffic from any IP to IP of exchange server on ports 53 (TCP and UDP) and 25, 587, 143, 993, 80 and 443 (all TCP) Which will allow (almost) anything to come through to our Exchange server and then we do the IP restricting at our end (with a HUB receive connector?) - I've just taken a look and the O365 Hybrid config wizard actually creates an O365 connector with IP addresses so ... maybe that's one less thing to think about?! Our ISP is also saying that we may encounter proxy server issues (not sure if we will the Hybrid config wizard completed without issue and I've synced all users with AD, the only thing that could fall over now is mailbox migration?) & if they have to tweak our proxy server, they will be charging us again. Eek.
