Jump to content

DEvans

Members
  • Posts

    81
  • Joined

  • Last visited

Everything posted by DEvans

  1. Update on this, as I don't want anyone else to go through a similar problem and find yet another unresolved thread on a random forum with no solution. * It's isolated to roaming profiles. Non-Roaming profiles work fine. * The Windows Media Player Cache files live within the roaming folder of Appsdata.
  2. Hey everyone, I have a school that (being the end of term) have discovered a major network issue. Turns out DVDs are playing video but the sound is of an extremely poor quality. Crackly, quiet and just broken. When you login as an administrator account though. Fine. Not a problem. Works exactly how it should work. It must be something to do with a permission or something to that affect, as why would it work on the unrestricted account and not the teacher accounts. Originally, we believed it to be a codex thing, but since it works on the admin account, it's evident that the DVDs play fine. Does anyone know any troubleshooting ideas for this issue? How does media player work in the background, does it need to save files to places? Before some of you say "install VLC", we have installed VLC everywhere, but have the Identical Issue. Oh and yes, we also have installed windows media player classic. That plays no sound at all. haha. So even worse. Might be the DVD? No, it's a school wide issue, every machine, different DVDs. As you can imagine, we are a little stressed in the Tech room. lol.
  3. Thanks CScott, Good to hear someone in a similar (if not identical) situation. Thanks everyone on your opinions, i've got a call coming my way this morning from Sean Lazenby at Smoothwall, looks pretty clear on what is the overall best solution for our situation. Much Appreciated! /Dan
  4. Interesting. I have heard of screen capturing software, another one that is used in our county is Policy Central by Forensic. I like the overall Idea of them, but the maintenance is a nightmare with so many false positives. Takes a long time to fine tune it, though I haven't played with those mentioned above, i'll have a look into it. I suppose with the ability to prevent attachment types etc within Exchange itself, there is little need for an firewall to monitor internal mail. I'm thinking too much e-safety and not network security. Thanks for the info.
  5. Oh you complete Legend! I've been looking at the hub transport in the "Server Configuration" part not the "Organizational Configuration", so I dismissed it early on. Turns out i'm a idiot haha. The rule had such a vague name also, I most likely would of completely overlooked it. Officially slapping ourselves in the office. Thanks So much! [PROBLEM RESOLVED]
  6. He appears in the GAL. He doesn't appear in the Students@ DG Members List. If you choose the Students@ from the GAL if you were to send an email and expand it, he doesn't appear in there, he is effectively hidden. As far as I am aware he was in charge of monitoring student to student emails, therefore he was on the list. But (this was before my time), because he was part of the list, if the kids expanded the group, they could remove his email from it. So I think some form of workaround solution has been done to hide him off that list, yet continue to have emails sent to him. I have checked all email forwarding and there is nothing setup. I'm trying to retrace steps led by the previous technician, if you wanted to hide someone from the distribution list but make sure they receive the emails, how would you do it and how would you reverse it.
  7. Hey Edugeekers, Really odd problem. We have a typical member of staff on the network who is NOT part of the Students@ email group. They don't need to be as they are not a student. They are of course part of the Staff@ DG. Staff@ works fine, they receive their email successfully. Everything on the account is working to what is deemed to be normal. However, even though they are not part of the Students@ DG, they seem to be getting email sent to them anyway. The annoying thing is that it affects just one account. If there is a setting somewhere within the server, simply recreating the account will most likely have no affect as from what I can tell the account is normal and somewhere there is some line saying, "ah another email to all students, i'll give this to this address as well because I like to be annoying" I know in Exchange 2003, you could hide people and stuff, but in Exchange 2007 they are not a hidden account and i don't think Exch does the hidden thing anymore. This is also not a migrated system, it was built as Exc 2007 with a new database. Any ideas? The intention is to get a list of things to check and even if i've checked them before, there's no harm is quadrupling my checks. Thanks!
  8. No Question is stupid if you don't know the answer. You have it in one. ----------------- Essentially, all that hassle of writing scripts for drive mapping, registry edits, printer mapping, control panel settings, proxy, local user, power policies.. well just about anything, now has a easy to use, advanced GUI to it all. What type of network do you have? Do you have Ranger, CC4, Vanilla Group Policy, CSE? When you go into your group policies, create a policy for your students and/or staff. Edit the policy and you'll notice there is a + sign next to two folders, Policies and Preferences. Open up Preferences under User configuration (for drive maps) or Computer configuration for other things, (thats dependant on what you want to do) and play with it. There is something known as Item Level Targeting which essentially creates you IF statements. e.g. IF User is Member of Staff Security Group, THEN map X drives, IF NOT do this, etc.. It's nice and easy. Works perfectly on XP and above, though for XP you need to install the preferences client side extension hotfix which makes XP aware of what preferences are and allows them to work. This is installed by standard on Vista, 7 & 8. Hotfix found here: Group Policy Preferences Client-Side Extension Hotfix Rollup
  9. Hey, Have you instead thought about changing that whole vbscript routine and moving to preferences. Since it's a 2008R2 network, it might be worth it and it'll give you more control over who gets what drive and what criteria needs to be met for those people to get said drives etc.. Vbscript is brilliant, I won't fault that, but it does make life tricky when it comes to permissions over certain things like naming the drives etc.
  10. Watchguard have been mentioned quite a bit, but like I said I think it doesn't provide the true needs of a school. Smoothwall does seem to be the ideal solution as their support for schools is also very good. We have looked at a hell of a lot. I just want to have a proper big brother of the network. Who did what, when and what computer. Sounds like a silly question but can smoothwall also monitor internal Exchange emails. We have Exchange 2007 (going to 2010 soon) and it's all well and good monitoring what comes from the outside world, but bullyinging etc occurs internally and we want the evidence to help crack down and punished the right students over situations like this.
  11. The filtering is by far one of the most important requirements of our solution. We need to have potentially three levels of filtering. One for Staff, One for Students during work time an one for the leisure network for students after hours. Don't want those hiding in their rooms playing the xbox all day. Unfortunately if Sonicwall doesn't perform that well, then obviously we won't be going that way. I don't want to mix and match firewalls, ideally one solution, one supplier, one support contract. Thanks for the info
  12. @glennda - I'll be getting in touch with Tom, thanks for the info. @psydii - That Fastvue look quite impressive, we'll certainly have a look at that. Since we already have TMG, if it can be improved, it'll save the cash. @FN-GM - I've heard some pretty awful things about sonicwall recently, I wasn't too impressed at BETT, Sales people tell you anything you want to here, though he stumbled when I asked why go for sonicwall over smoothwall.
  13. Hey Everyone, I work at a UK college that offers residency for the students and we currently have a crazy setup which is being effectively stripped out and started again. The current system involves a forefront's threat management gateway as the firewall solution and if i'm honest it's a right headache and isn't really a solution for a college. What we want is a solution that future proofs us and is well supported, ideally with a company that knows the education sector. The main contenders are obviously smoothwall and sonicwall. I've looked into others like watchguard but thats too enterprise for us, trying to keep it realistic. I've seen Netbox blue the "firewall solution designed for schools" but was a little unsure about it, doesn't seem to be much UK support. What we need it to do is: Act as a middle man between clients and servers (protecting the servers from the kids who call themselves hackers). Protect the Servers and Clients from the big bad internet Allow for both a domain network and a "leisure network". The leisure network acting as a lesser filtered internet experience. We offer residency to students, so xbox live, skype, games etc are common requests. To be able to control what times the leisure/domain network can be accessed etc.. Some form of indepth report, what students are up to, logging in times, general web filtering/policing Some form of policing of social networking websites Full Active Directory Syncing (aware of security groups etc) Support for mobile devices (PDA's, SmartPhones) Capable of managing a DMZ for Exchange OWA/Outlook Anywhere Managing secure VPN connections into the college. When it comes to the firewall, I'm not the most experienced if i'm honest, I have a lot to look at and plenty to read up on. I am in talks with colleges around the local area about possibly visiting them to see their solutions, as it's easy to talk to a salesman from a firewall company, but the word yes yes yes is easily said but when its comes to the technical nitty gritty, you find that some yes's mean "sort of". The firewall is now becoming the most important decision we need to make, as everything needs to connect through it. I'm interested into what you all have seen, work(ed) with, don't think because you don't offer residential to students (as i know not many places do) that you can't recommend something. I'm looking for simplicity mainly, but obviously if the company's offer training on their product, that's even better. The big word is also cost, ball park figures are always welcome, we are expecting lots of money so it won't be anything we didn't expect. Thanks for all your help! Looking forward to hearing from you all.
  14. Hey Jon, There are a variety of different ways to go about deploying Office 2010, since you are jumping from 2003 the difference is significant. Good old MSI deployment is no longer the way it works. There are different reasons to as why it isn't as straight forward anymore like that of Group Policy Deployment but its mainly down to technologies such as Microsoft Deployment Tools (MDT), System Center Essentials and full blown System Center Configuration Manager. You can either, as Michael said, simply add it into your WIM image and deploy it out with a MAK key installed for activation or alternatively you can follow the "microsoft way" and deploy it out silently and activate it from a central Key Management Server (KMS). Personally, we use the tools in MDT to push it out as an application which installs it silently while also keeping it seperate from the image itself. It installs silently using instructions from a .MSP file created within MDT OR the seperate Office Customisation Tool (OCT) Ref: Office Customization Tool in Office 2010 Before the likes of MDT, we used to deploy out XP clients through RIS, so we could of used the OCT and scripted the install, but we actually used the same method we did for Office 2007 and used the "config.xml" answer file to provide the instructions for a silent install. Yeh, there is yet another way to do it... Microsoft... enough said. We copied the entire contents of the Office 2010 CD to a designated packages share on the server, i'm sure you have one. We found the proplus.ww folder (assuming you have proplus edition) found the Config.xml and made a copy of that (for backup reasons) and called it config.xml.old We took the orginal config.xml file and opened it in notepad and changed the answer file based on the information we got from here: Config.xml file in Office 2010 We then created a script to check to see if office is installed and if it wasn't to run the setup.exe (which always looks at the config.xml for instructions when it runs) Personally, if I were you, if you are not using MDT, stick to putting it in the reference image like Michael said. It's far easier. If activation is still a problem download the Volume Activation Management tool (VAMT), think its on version 2 now. That will scan your network and find the office applications on the computers. You can then install the Volume License Key as well as perform the online activation required to complete the registration with microsoft every computer. Just simply type in your office key once and deploy it out to relevant machines. Hope this information makes some sense, haha.
  15. Not a problem, glad it worked. For Troubleshooting start with applications that don't officially say "Compatible with Windows Vista/7". 9 times out of 10 they are the cause, that or your anti-virus. We use Sophos at our schools and its created the illusion of a broken network card on multiple occasions after an upgrade/install, easily fixed with the command line however.
  16. A Common Fix for a lot of network issues that are a result of a software install is the following Command Line: netsh winsock reset Commonly Antivirus software, such as sophos, avg etc interfere with the network cards and can cause semi-networked states, whereby you can see servers, but have weird issues such as being unable to join the domain, but it certainly hasn't been limited to just AV applications. I've seen network cards fail because of all sorts of applications. Go to your command prompt and type in the above command line and restart your computer. It's not always 100% but you might be surprised, can't tell you how many times this has sorted out weird network issues with clients. Give it a try. Note: This resets layer 3 protocols, giving your network card a nice refresh. Removing corrupt data (if any) potentially caused by hardware or software installations not officially compatible with your version of Windows O/S. References: CCNA, Microsoft.com
  17. Ah, you didn't mention that. In that case no. It would need to be a scripted installation, you will need to look at vbs, from what I found on the net, command line just isn't suitable for the amount of modification you need to do. Surely before you take a snapshot of your image, you have created the "perfect" machine, with the correct icons in place. You can remove the common programs by a local group policy edit, saves you removing it all. Type Gpedit.msc in your run bar and go to the common programs policy in the same place I mentioned in my previous post. That will hide them all for you, not delete them. Might be worth setting that in your reference image.
  18. You ever played with folder redirection? Redirect the Start Menu (and Desktop if you want) to a share. Allows you to control what icons users have access to from a central location. I believe combining this with the group policy which removes the common programs, such as magnifier, remote desktop etc will give you the result you need. This is found in: Group Policy -> User Configuration -> Policies (if 2008R2) -> Administrative Templates -> Start Menu and Task Bar -> Remove Common Program Groups from Start Menu. Enable that policy. To explain further, you create a group policy (lets call it - Pupil Redirection Policy) You enter into that policy's editor and under the user configuration, you go to -> Windows Settings -> Folder Redirection -> Start Menu You right click start menu and redirect everyones folder to the same location. Let say that location is \\FileServer\StartMenus\Staff\Teachers Within that shared folder (this needs to be confirmed with someone at a windows 7 network, which I, at this moment in time, am not) you have a folder called "programs" and within that folder you have links to your Microsoft Word, Excel etc. Combine that with the policy I mentioned above about the common programs and this will remove all the default junk and just display your centralised start menu. Ensure your permissions restrict people saving files to the start menu, otherwise that will be shared everywhere, especially important if you do this to the desktop as well. If you want people to use the desktop as a place to save files, you may wish to redirect their desktop to their profile instead. It will then populate their desktop with the links you set to begin with then allow them to save and edit their desktop as they wish within their profile, not affecting anyone else on the network. Hope this helps. Need someone to confirm the "programs" folder bit, as XP and 7 are very different and at the moment I am at a windows XP school. -----Alternative---- You can also use a vbs to run as a login script to populate the user's desktop when they login. Though you need to have knowledge of vbscript to do this. I unfortunately do not have a vbs script to hand to create a bog standard start menu shortcut. I have seen it done however. As for a batch script, unsure. You could Xcopy premade links from one place to another, I don't know if you can create a shortcut in command line. Something is telling me you should be able to, but i've never seen it before. Bit of a Yah-Googley-Bing Job.
  19. We've encountered black screens, red screens & blue screens. It seems to rely on the image size. When your bmp exceeds a certain size it has a benny. The safest bet is to create an entire background and line it up. Updates & Service packs can cause the problem described by rschmidt. We searched the internet high and low to accomplish this with success one day followed by epic failure the next. Such a small cosmetic change is actually a right headache. It is certainly the authUI.dll that needs to be modified, but it is a very sensitive file which will bite your head off if you upset it.
  20. I look after a selection of schools and all have different requirements. Generally, if they do what I tell them, I have Dual NAS drives for a "LIVE" backup, seperated at the furthest corners of the school away from the server(s). So I can do quick restoration of data without needing to faff around with tapes. One NAS has a full weekly and a full fortnightly and one is a differential Daily. Then depending on how often I visit the school, we have a tape drive, setup in the exact way as JonWPS (Mon-Thurs & 5 Fridays) with the additional 1 for Holiday Backups. The Tapes are Encypted and kept offsite. I find with backups, the typical cause of failure is when you need to rely on someone to do it. Tapes are a pain unless you pay a fortune for an automatic tape library. Think the most common method of backup procedure is Disk to Disk to Tape, from I can gather from other technicians. People moan about Tapes still, saying its an old technology, but of course see if they say that when their "Super New Techno Solid State Hard Drive" fails and watch their faces as they slowly realise that recovering data from flash drives is next to impossible. As for Software to use. The Windows Backup Role isn't all that bad, but not ideal for Tapes, as they simply don't work with it. We use Backup Exec 2010R3 but only because it comes for cheap with a new server, its up to £400 otherwise and thats just for the basic edition. If you have exchange and other enterprise applications, you need addons. Also multiple DC licenses etc. It gets costly. Macrium Reflect is a good image backup solution, as you take a full blown snap shot of your servers and if they were to die you can do a "bare metal" like restoration. (You need to pay extra for features like that with Symantec). Macrium is cheaper but does not support Tape drives, unless your tapes can be mapped to a drive letter. You do however NEED to have an offsite backup. Think of the most unlikely event and plan for it. Floods don't tend to care if you have a single building school or a school split into many seperate buildings. Fire is the main one, as this the the most likely of unlikely events to occur. I believe in all our Backup Policies we mention general data protection jibberish. RAID, Shadow Copy, DFS Replication etc.. Just to keep everyone more assured their data is safe. Can even mention Anti-virus and references to any other policies you probably have in place.
  21. Just an FYI as Sted already posted the solution. The /quiet switch for .net 4.0 can cause all sorts of issues in MDT. So always go for /Passive. You'll have some where it will work, some where it won't but passive has never failed, not in my experience anyway. Also, put the /norestart switch in but I recommend ticking the box in the application to "restart after installation" in the MDT deployment workbench. I've had computers fall over because I didn't restart and I tried to install more applications afterwards.
  22. Haha. 2008 R1. Good save HallX, What spec is the server you intend to put the 2008 R2 (or R1) on. It might not be worth the hassle if the kit is old. Maybe drop down to 2003R2 and do 2008R2 in the future on a newer, higher powered server. (or if you wait long enough Server 2012). Ideally you just want the server to sit there and process requests, the actual GUI (technically speaking) shouldn't matter too much. Hence Core Edition.
  23. How are you going about doing it? I assume you are selecting additional drivers (or something like that) at the beginning of the 2008R2 o/s install wizard? Have you setup the RAID array? As if that isn't set up from the start, no matter what driver you put in you won't see your hard drives. Normally during the boot up of a server it will say press F (something) F6 is a common one to access the RAID controller. This occurs before it even begins to look if there is a disk in the DVD drive to boot from. There is no such operating system. 2008R2 is only x64. 2008 (the microsoft mistake) was the last server o/s in x86. You do have a point though, if the server is many years old, there might not be a x64 driver.
  24. Ranger... Your only issue here will be Ranger as the routine of simply adding a server to the forest is relatively simple. How well do you know 2008R2? 2008R2 has this server quick start configure manager that loads up when you finish the initial O/S install. I can't remember the actual name of it, either way its a nice list of all the things you should do before you start adding roles. Activate it, set time, Windows Updates, Allow Remote connection, Improvement Program opt-in, networking, server name etc.. All straight forward, complete all this then add the server to the domain, since the roles you mentioned don't need it to be a domain controller, you don't need to do a DCpromo. Though of course, Ranger however will need to probably tie into your Active Directory, so i'm wondering if it does need to be a DC. Your best bet is to talk to Ranger, its what you pay them annual costs for. Get their advice. Yet another example of how a third party managing product causes unnecessary complications. lol. A lot of us have all been there. Three Servers, how big is your school? I assume a High School or large Middle?
  25. I'm at the school tomorrow, I most likely have it written down in documentation somewhere. I'll update this post when I know.
×
×
  • Create New...