-
Posts
1,598 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Duke5A
-
Best Practices for setting up a staff laptop that needs to work offline
Duke5A replied to tobiasclarity's topic in Windows 7
- Use a proxy pac file to set proxy settings in IE. This way when they take the device home they don't have to monkey with proxy settings. - Force the local firewall to always on in policy and only edit the domain profile. When the laptop is on the internal network your firewall exceptions will work, but when home those holes will close up. - If you can get away with it, only give them limited user rights. Local admin on a device that leaves the district can be a pain. - If the laptop is going to be spending a lot of time out of the district them enable the auto updaters for Flash, Java, etc... -
That is odd, I had to do the same thing to resolve an issue with 7/8 clients accessing shares on a 2003 Server install. As far as I understood it only afflicted SMB connections.
-
Dansguardian Authentication
Duke5A replied to Blue_Cookeh's topic in Internet Related/Filtering/Firewall
Office 2013 might be calling out to different domains then. Just monitor your Squid access log while you recreate the issue on a test machine and whitelist the domains that are getting blocked. tail -f /var/log/squid3/access.log | grep -
I wonder if it isn't waiting on antivirus or something. Any goofy add-ons installed? Maybe something to do with proxy settings as well. Do you have your intranet sites in the exclusion list? Maybe this didn't get set as IE10 would have needed a new policy.
-
@pete: You've given some really good pointers here. I've got a growing list of people I need to buy beer for if I ever get out to that side of the world. Thanks again!
-
Anyone here have a functioning IDS setup, or experience you'd be willing to share? I honestly haven't touched this stuff since college, but thought it worth looking into now that things are finally settling down. We really don't have any cash to plunk down on any additional equipment now so I was looking at Snort and OSSEC. Can't seem to decide between Windows or Linux either. I'm no stranger to a Linux CLI (I setup a couple Squid proxies internally here), but already have a few devices running Windows I wanted to utilize. Any thoughts? Thanks guys..
-
I've had goofy dealing with HP printers like this before. My personal favorite was printing multiple pages over a single page. In the end it turned out to be a driver issue on the local machine. Remove all the printers that share the afflicted driver, restart the spool service, use the print management snap-in to remove the driver bundles by hand, restart the spool service again, and add your printers back in. You may wind up with the snap-in complaining it can't remove the driver because it is in use at times, so you might want to bounce the machine if it does this. To this day I don't know what causes it to lose its marbles, but this always fixes it.
-
Policies might not be applied correctly; give RSOP a look on one of the problem machines. Outside of that I really think about leaving the firewall up on client machines. I remember spending an entire week cleaning out the Blaster Worm from a 4,000 machine network back in the day. If something gets loose on the inside and you're not patched (if one has even been released) the built-in firewall will be your last line of defense. I force the firewall on on all staff systems and only open up things I need for remote management to only specific subnets. Anyways, for WMIC through the firewall you're looking for Allow inbound remote administration exception.
-
- Windows Error Reporting Service - Program Compatibility Assistant Service - Themes (maybe depending on your needs) - Application Experience - Adobe updating services if you push updates yourself (Flash, Acrobat, etc) - Java updating services if you push updates yourself
-
I've encountered this as well as we have IE10 with proxies configured through GPP. I didn't spend a whole lot of time with it and in the end just specified the proxy in the Chrome GPO. Between all the proxy quirks and daily used district websites randomly breaking and I'm trying to push everyone onto Chrome anyways.
-
Never messed around with it. Home Access Plus was a better fit for our district so we went that route.
-
Does anyone have any experience with Adobe Connect? I've got a couple of college courses at the high school that use it, but it won't work this year. Last year it was fine. From what I understand it uses RTMP on port 1935, with a fallback to tunneling over 443 and then 80. I know that RTMP can't be proxied in it's native form, but according to Adobe the fallback should work in the event it can't connect over that port. The problem is, near as I can tell, it never even tries the other ports. Looking at my Squid logs they showed no connection attempts from the test computers. Using netstat on the client it showed an attempted direct connection to the outside server waiting in the wind on port 1935. It stayed that way for about five minutes until finally a connection failed message appeared in the browser. The whole time the proxy never registered any connection attempts from the box and netstat never showed anything else but a hung RTMP connection. If this is a bug it would make sense as the fallback worked last year with older versions of Flash. Can anyone confirm?
-
I used to support Front Motion Firefox and IE9 in the base image, but pulled FF out as it was getting to be a pain in the neck to administrate. We ran solo with IE for a while until 10 came about and broke a good number of the sites my staff uses on a daily basis. So Chrome got the nod to go into the image and it has been Chrome and IE10 since the end of last school year. Chrome is easy enough to maintain and the GPO templates are quite nice.
-
I was referring to VM drivers bundled in with VMWare Tools. Working in a VM without the mouse and display drivers loaded is a complete pain. Never had any issues otherwise in Windows 7 x32/x64 and Windows XP images doing it this way. I totally agree though, no other drivers touch the base image. All of that is loaded by the WDS box after imaging.
-
Interesting stuff! It's amazing the complexity of the work that goes into these salvage ops. These guys are awesome. More reading about another salvage operation from a while ago: High Tech Cowboys of the Deep Seas: The Race to Save the Cougar Ace Contains some salty language...
-
I just went through this with the Auto CAD suite (same developer). That is in fact the way their deployment wizard works. Either you can run the shortcut as a startup script via GPO, or just get it installing on the machine by hand, set a reboot timer, lock and walk away.
-
I'm relatively happy with our layout. The district is comprised of seven buildings and most of the VLANs go building first, then service, but a couple span the entire district. Each building has its own: - management VLAN for switches - wireless management VLAN for access points - wireless VLAN for instructors - wireless VLAN for students - instructional VLAN for student and staff wired systems - server VLAN - security VLAN for IP cameras District spanning VLANs are: - one for HVAC controllers - one for the phone switches The phone switches and HVAC controllers didn't number enough to warrant separate VLANs for each building. Having them in their own VLANs enabled us to limit remote access to just those subnets as well for when contractors need to get in. Most of the subnets have 23bit masks and the links between the buildings are all trunk links over private fiber. I purposely left all the classroom ports on one VLAN too. Room layouts change too often and I would be pulling my hair out trying to keep up with port assignments for staff/printer/student devices. First and foremost though as already stated, you need to completely document what you have, understand it, and have a plan before you start changing things. Going into something like this blind would cause much hilarity to ensue.
-
Dropping to a black screen with a cursor would make me think display drivers. Running the actual chip maker's driver instead of the MS one? Is there more than one display hooked up to these systems? I've also seen machines do this when detecting and setting up multiple displays (although it usually takes just a split second).
-
I agree, but you can load device drivers by hand without actually installing the tools. Start the tools install and you can grab the mouse and display drivers out of the temp folder.
-
I had a similar problem last year. Our phone switches were on the same subnet as instructional machines (don't blame me, it was like this when I got here) and were dropping calls like crazy every morning. I setup a rolling packet capture on the subnet with Wireshark and set a 500MB limit. As soon as the problem cropped up again I went into the capture file and discovered a ton of broadcast traffic coming from a teacher machine in the lab down the hall. It turns out the teacher was starting classroom management software that uses broadcast traffic for student computer discovery. Moving the phone switches over to their own VLAN solved the issue. TFTP is connectionless and the slightest burp will cause it to drop packets.
-
Dansguardian Authentication
Duke5A replied to Blue_Cookeh's topic in Internet Related/Filtering/Firewall
As Iain said Office only talks Kerberos now. Setting it up though can be a pain in the neck, so if you're just looking for a quick fix you can these domains to an ACL that doesn't require authentication. .microsoft.com .msecnd.net .windowsupdate.com I did this a while back until I had time to build new Squid proxies around Kerberos. -
Windows XP works just fine using a single base image across different machine types. It's a pain in the neck though sometimes! In a nutshell, create your VM with two processors and use this line in your sysprep inf for the HAL type: UpdateUPHAL="ACPIAPIC_UP,%windir%\inf\hal.inf" Next up is driver juggling for HDD controller support. This is a snippet of my mass storage config that covered a wide range of Intel SATA controllers, a few AMD, and the legacy IDE stuff. I would recommend hunting down the same driver versions I used in this list. [sysprepMassStorage] PCI\VEN_8086&DEV_2653&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\7.6.1.1002\iaahci.inf PCI\VEN_8086&DEV_5029&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\7.6.1.1002\iaahci.inf ; PCI\VEN_8086&DEV_2681&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_27C1&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_27C5&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_2821&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_2829&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_2922&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_2929&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_3A02&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_3A22&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_3B29&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_3B2F&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_3B22&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_1C02&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf PCI\VEN_8086&DEV_1C03&CC_0106=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaAHCI.inf ; PCI\VEN_8086&DEV_2682&CC_0104=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaStor.inf PCI\VEN_8086&DEV_27C3&CC_0104=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaStor.inf PCI\VEN_8086&DEV_27C6&CC_0104=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaStor.inf PCI\VEN_8086&DEV_2822&CC_0104=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaStor.inf PCI\VEN_8086&DEV_282A&CC_0104=%systemdrive%\Drivers\Common\SATA\Intel\10.1.0.1008\iaStor.inf ; ;AMD SATA Support PCI\VEN_10DE&DEV_0267&CC_0104=%systemdrive%\Drivers\Common\SATA\nVidia\nvraid.inf PCI\VEN_10DE&DEV_0266&CC_0104=%systemdrive%\Drivers\Common\SATA\nVidia\nvraid.inf ; ; Generic drivers pci\ven_8086&dev_2651&cc_0101=%systemdrive%\windows\inf\mshdc.inf pci\ven_8086&dev_2652&cc_0101=%systemdrive%\windows\inf\mshdc.inf pci\ven_8086&dev_2653&cc_0101=%systemdrive%\windows\inf\mshdc.inf pci\ven_8086&dev_266f=%systemdrive%\windows\inf\mshdc.inf pci\cc_0101=%systemdrive%\windows\inf\mshdc.inf primary_ide_channel=%systemdrive%\windows\inf\mshdc.inf secondary_ide_channel=%systemdrive%\windows\inf\mshdc.inf The last hurdle to complete is getting the image to work with both AMD and Intel CPUs. It's no problem really. In the VM disable IntelPPM by doing this at the command line: sc config intelppm start= disabled Next create a batch file with this in it to re-enable IntelPPM once the machine is imaged if an Intel CPU is detected: wmic cpu get Manufacturer | findstr /i intel if "%errorlevel%" == "0" (sc config intelppm start= system) Run this batch via sysprep as a runonce command in the sysprep inf. That should do it! The only pitfall is this image will not work on the older Pentium M chipsets found in D600 era Dell Latitudes. D610 and above will work just fine. And as far as Windows 7 is concerned you don't have to do any of this crap; it just works!
-
Hi Tim, we eventually moved over to IE10 and this particular problem cleared itself up. With IE10 you need to use group policy preferences for setting the proxy as the IE Maintenance settings are deprecated. IE9 supports GPP so I would try this instead of going through maintenance. -Mark
-
YouTube for Schools issue?
Duke5A replied to localzuk's topic in Internet Related/Filtering/Firewall
I haven't messed with it since last school year, but it did pretty much the same thing to me. Just really inconsistent operation and over goofiness while at other times working as it should. I wound up pulling the plug on the project and only allowing staff access to Youtube in its entirety. I too was using the URL rewrite method in Squid via a Perl script. I always wondering if it would operate smoother if I went with the header modification route, but never came back to it. -
@linkazoid: Sorry, I've been out for the last few days. The unattended XML in WDS you specify will trump the XML you use during sysprep. As far as the default user issue goes, this is exactly how I have mind setup. - I build my images in virtual machines. In my Windows 7 Enterprise x64 image I have two local users setup: one is the default local administrator account (this one has to be enabled) and the second is one that was created during the initial install of Windows. This second account is the one that I work out of and I only log into the default local administrator account to make changes in its profile that I want to be present in the default user profile. Whatever you do, do not join your base image to the domain. Let sysprep do it for you after cloning. - Here is a complete copy of the XML that I use (confidential bits removed of course): en-us en-us en-us en-us en-us en-us true Your Organization Your Organization true true true true true 33PXH-7Y6KF-2VJC9-XBBR8-HVTHH * yourdomain.com password JoinComputer yourdomain.com OU=Win7,OU=ComputersWDS,DC=yourdomain,DC=com en-us en-us en-us en-us en-us password false true 1 SecondAdminAccount true true Work 1 password false SecondAdminAccount Administrators SecondAdminAccount Eastern Standard Time true 5 C:\Windows\System32\sysprep\ClientSideClonePrepTool.exe Blank HW ID from Symantec Client 1 false cmd /q /c del /Q /F c:\windows\system32\sysprep\Win7ENTx64.xml Delete XML answer file 2 cmd /q /c del /Q /F c:\windows\panther\unattend.xml false Delete XML answer file false 3 "C:\Program Files (x86)\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPREARM.EXE" Rearm Office false 4 Activate Office cscript "C:\Program Files (x86)\Microsoft Office\Office14\ospp.vbs" /act - Some of these settings won't apply to you, but this is the entire XML I use. In the first logon commands section I would leave the two entries that delete the XML answer file from the image. Sysprep doesn't clean up after itself like it did in XP. The bottom two entries for rearming and activating Office you might want to keep too. The topmost entry you can remove if you're not using Symantec Endpoint for your anti-virus. - In the section that joins the machine to the domain, feel free to remove the MachineObjectOU line. This will place the computer account in an OU you specify as opposed to creating it in the default computer OU in AD. I did this because I wanted freshly imaged machines to have their own policies. I've got lower level techs that needed to be able to image and have local admin to those machines without giving them domain administrator access. - Windows and Office have limitations as to how many times they can be rearmed. This is why I build the image in a virtual machine so I can use snapshots and go back to a state right before sysprep was ran. I hope this helps...
