-
Posts
602 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by MicrodigitUK
-
Thanks I might have missed that one. I’ve had a look round RM support but can’t find it. Could you joust point me to the correct place?
-
We are running a RM CC3 network and I have followed all of the RM instructions to create a FMS package For permissions “Management information users” have full write access to “C:\Program Files\SIMS\FMSSQL” and the users in question are members of the security group. But still I am getting an error when trying to create a new JV the following error message appears. ptJVHeader:Field"Voucher_id"not found. On the capita support .net the solution is the usual “Please ensure FMS users have local administrator access rights on the workstation FMS is being used” I really don’t want to take Capita’s advice and unlock the users to have full admin on the workstation! Dose anyone have any other specific locations that permissions need changing to make this work.
-
Exchange or Zimbra - What do you use?
MicrodigitUK replied to jack0w's topic in Internet Related/Filtering/Firewall
We currently Use FrogMail as it came part of our Frog VLE but it really is like some old mail system from the late 90’s. For that reason we are moving to Zimbra. Iv been looking at both Exchange, Zimbra and we have decided to go for Zimbra. A couple of the main reasons we have chosen Zimbra are: Single sign on from VLE (just finishing off my signal sign on Frog Brick now) Ability to share calendars without administration involvement (Exchange requires an admin to change permissions vs Zimbra publishes a web link that can be put on VLE by users NOT ADMINS) Use our existing Postfix student bad word filter on Zimbra. And I really like what webman stated about it allows staff to enable/disable email access for the room -
We have been using Aruba for several years but have now started to hit its limitations with large classes of laptops in one area. I’ve got Xirrus in next week to demo the kit and they are leaving use some units to trial. I would be very interested in reading this document before they arrive.
-
Wireless network kit - suggestions please
MicrodigitUK replied to Kitkatninja's topic in Wireless Networks
We have been using Aruba for several years now and haven’t had any problems with it up until now. The main problem is that now we have full class rooms of 32 laptops in rooms in close proximity we have started to hit limitations. In the past it was just sets of 16 laptops it coped well. Also there new n equipment hasn’t evolved much from there earlier a/g kit. Don’t get me wrong it’s a good system it’s just we have started to hit its current limitations. Also the N access points and licences are quite pricey. We have started to look at our options and I had a look at Xirrus at BETT. They seem to have the right solution for our current needs and demands of large classes of laptops. I’ve got them coming in next week to set up a test section of our site with their kit and from watt iv seen so far it looks like it’s going to kick ass on any other systems out there. It rely depends on your needs and how much you want to future proof things. Aruba is fine for class sizes of say around 20 laptops in close proximity but once you start having larger and more classes of laptops in one area it starts to grind. I am also looking at Ruckus and might get them in for a trial also, but the Xirrus kit looks to be the best on the market at the moment. You also seem to deal witE Xirrus direct with no middle man so they know what there kit can do and how best to do it. 5 year warranty isn’t bad either. -
Wiltshire would be a good place to hold one
-
OK, I am trying to get some rough figures to put forward to SMT on the cost of implementing a new Zimbra server. I have an old server that could be used but would like to know what other people are running it on? How dose it perform when virtualized? Only reason I ask Is that I want to make sure that It can be easily moved if new hardware becomes available. To give you a rough idea: We have around 300 members of staff and just under 2000 students What size storage do people have for a modern day mail box and calendar system for that number of users? The old server in question is a HP ProLiant ML370 G3 with 2* 3.06GHz Xeons and 3GB RAM. Will this do or not? Is virtualizing it on top of that pushing it a bit?
-
LanView3 VNC password
MicrodigitUK replied to MicrodigitUK's topic in Network and Classroom Management
Managed to crack it. It turnd not to be the small green one. It was a telephone number of some other school miles away that I’v never heard of….. Suppose they must have packaged the version of Lanview that we use. -
Just an update to say I found the problem. It turned there was a student account with the username Sheldon witch is the name of the school so was in everyone’s email address. So I tweaked the LDAP search script to check the username starts with two digits and two non numerics. So it only pulls out users like 01test and 09test. ldapsearch \ -h $FULLDOMAIN -p 389 -l 60 -s base \ -b $BASESEARCH \ -s sub "(&(objectCategory=person)(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))" "sAMAccountName" \ -D $BINDUSER \ -y $PASSFILE | grep sAMAccountName: | awk '{print $2}' | grep '^[0-9][0-9][^0-9][^0-9]' > $STUDENTS_TEMP Also just to point out the blank line at the bottom of the student list doesn’t make any difference.
-
Can someone send me a PM with the LanView3 VNC password please. I am trying to use another application to view the stations but still want to use lanview as well so need to set them up with the same password. PS anyone got a copy of 4
-
I had this problem with a HP Color LaserJet CP1510 Printer series where the PCL6 driver would just crash the spooler on the server and desktops but the PostScript driver was fine. Every now and then we get the ode print where the fonts are different but the users can live with that. I did loge a call with HP about the PCL6 driver and was basically told the printer was not designed for large network use and aimed at small biasness and home market, that was that.
-
Ok I am still having some problems with the student list. It all looks ok but the filter is still running for everyone. I think it might have something to do with the last line in the list that is blank, so the filter is finding it in every ones emails. Any thought on this issue? Does your student list have a blank line on the end?
-
Thanks, Webman for that. I hadn’t even thought of a daily cron but that makes total sense. After thinking about this again, I realised that your approach to have a student list made more sense because mail accounts like netman, head and cover are not listed in AD but all of the students are. Then I came across the wonderful 1000 LDAP limit and had fun getting around that and reconfiguring the DC’s LDAP settings. Then due to other members of staff entering students I found that not all had email set in AD . But correct me if I’m wrong Webman but the whole address is not required by your filter script to use student list (well that’s how I read it). So I changed the ldapsearch to look for just the username and will sort out AD email another day. Webman do u think checking a list of 2500+ active student users every time a mail passes through will have a major impact on the filters performance? I haven’t implemented the new filter script yet but am slightly concerned about the size of the student list. Now I have come up with the following and have tested and it produced a list of all student usernames. #!/bin/bash # Bash shell LDAP query to produce text file with a list of student usernames. # It is to be used in combanation with: /usr/local/sbin/filter.sh # # If you have more than 1000 student users dont forget to change server LDAP defalts # # Changable variables # FULLDOMAIN=sheldon.internal BASESEARCH="OU=Students,OU=SHS,OU=Establishments,DC=Sheldon,DC=Internal" BINDUSER="SHELDON\ldapbind" PASSFILE="/home/.ldapcredentials" STUDENTS="/etc/students" # ldapsearch \ -h $FULLDOMAIN -p 389 -l 60 -s base \ -b $BASESEARCH \ -s sub "(&(objectCategory=person)(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))" "sAMAccountName" \ -D $BINDUSER \ -y $PASSFILE | grep sAMAccountName: | awk '{print $2}' > $STUDENTS exit $? That’s all ok, but I have spotted a potential problem. If all DCs are off (for say maintenance or god forbid failure) when the daily cron runs then the student list is overwritten with no users in the list. And hay presto unfiltered mail!!!!! How would I go about checking there are users returned before overwriting the file?
-
I have cut down on the words to make it less sensitive but further cut downs would make it almost useless. So I have taken the decision to allow staff to bypass the filter. Other people must have this problem that’s why the script was revised in the new “Zimbra content filter updated” wiki. I really wouldn’t like to get into an argument about if staff should be filtered or not. There must be one or to Linux scripter’s out there that can point me in the right direction.
-
I need a bit of help from a bash script expert. Or at least someone who knows what they are doing. I have used the “Zimbra content filter” wiki to build a postfix gateway server to filter bad words in emails. This is all working ok but the problem is it is filtering a bit too much for the staff. So I have made the decision to set it up to bypass the filter for staff users. I have looked at the new script on the “Zimbra content filter updated” wiki. This looks to be a step in the right direction as it has the functionality to have a student list in a text file and then only filters those users. But really I want something a bit more dynamic to prevent me from having to remember to update the student list. I was thinking instead of a student list have a staff list of users that bypass the filter and then use a LDAP search on the server to get this list instead of a text file. All of my users have the email filed populated in Active Directory on the server so this shouldn’t be a problem. I have got my LDAP search perfected so that it pulls out the staff and admin email addresses and then pipe it into “grep” to strip out the rubbish. Below is an example of the commands I am running: ldapsearch -h sheldon.internal -p 389 -s base -b "OU=Establishments,DC=Sheldon,DC=Internal" -s sub "(&(objectCategory=user)(|(memberOf=CN=SHS Teaching Staff,OU=SHS,OU=Establishments,DC=Sheldon,DC=Internal)(memberOf=CN=SHS Non-Teaching Staff,OU=SHS,OU=Establishments,DC=Sheldon,DC=Internal) (memberOf=CN=Domain Admins,CN=Users,DC=Sheldon,DC=Internal)) (mail=*))" "mail" -D "SHELDON\ldapbind" -w "mypassword" | grep mail: And that produces a list like followes: mail: [email protected] mail: [email protected] mail: [email protected] So my question is how do I pull it all together? I know it’s got something to do with “grep” and possibly some string manipulation but I have no idea where to start. Can someone please help:confused:.
-
This is a bit of a wired one but I want to script AJAX form responses to RM easy mail plus to automat it. Basic what I want to do is have a CSV with all of my email users and passwords in and a redirect email account. Then the Script would loop through all of the users in the CSV file log onto easy mail as the user and change each users “Forward incoming mail Destination” and log off. Basically the forward incoming mail destination is an alias on my new mail server. So that when we switch from RM easy mail to our internally hosted server none of the users louse any emails. Is this possible with AJAX and if so dos anybody know where I would start with this?
-
Here is the new sourceforge download location for SSL-Explorer: Community Edition http://ftp.heanet.ie/disk1/sourceforge/s/project/ss/sslexplorer/OldFiles/sslexplorer_windows_1_0_0_RC17.zip
-
Hi I’m a bit of a nube to Ubuntu but I have a server that I whant to set up as a content filter for students emails. Our setup is We have a Frog VLE server that will be used for students to send and access email . I won’t to put the Ubuntu server in between Frog and the ISP to filter out any inappropriate emails. E.g a swear word black list. I have had a small look at postfix and it looks like it will do what I what I need but I haven’t got any idea how or where to start. Could someone point me in the right direction?
-
Netgear WFS709TP & Full solution - worth £3.5k? Quotes?
MicrodigitUK replied to rocknrollstar's topic in Wireless Networks
Got 1 * NETGEAR WAGL102 Access point going cheep if u decide to go with the Netgear system. I only got it to test to see if I could get it to work with my Aruba controller. But unfortunately I couldn’t get it to provision because the ArubaOS database doesn’t know what a WAGL102 is. So they only seem to work with the OEM (ArubaOS 2.5) on the Netgear controller. -
Ok on the HP switches between controllers set any uplinks to other switches and controllers to be as follows: VLAN 1 (management) untagged and VLAN 2 tagged These settings will pass both VLANS between switches/controllers Now for all of the original devices that are connected (so all other ports on the switch) set them to the following: VLAN 2 untagged And that’s it. The whole moving original VLANs around all reverts back to the controllers DHCP server only working on VLAN1 so blame it on Aruba who wrote the OS for the Netgear controller. WARNING: Never untag two VLANs on one port or all hell will be unleashed.
-
Yes you will need to configure all of these switches. You can just leave the WAPSs on the original network (now VLAN2) and once all of the routing is sorted with things are changed over in original networks DHCP (default gateway settings to point to the Netgear master controller instead of ISPs router). Once VLANs are configured on switches between controllers, I would then concentrate on the routing and getting all of the networks to see and talk to each other. Worry about the missing access points last!
-
On the Configuration > Advanced > Switch > General > IP Routing page is there a box for “Default Gateway”. If so put your ISPs Routers IP address in there (this will be something on the old range so e.g something like 192.168.0.254). I think that should accomplish the same thing with the Gateway of Last Resort/ default route instructions that I gave above that an not working. One way of checking things for routes are set up correctly is do a “show ip route” on the command line but I don’t know if its possible to access it on the Netgear!!! Basically with the whole routing thing what we are trying to do is stick your master controller in front of your ISPs router to intercept traffic for your networks before passing out to the internet. @ dirtydogmitchell “Also I now seem to have lost all my access points” This will likely be to do with some vlan configuration problems. Don’t forget that you will need to configure the switches that the controllers connect to in the same way and VLAN2 has to connect into your original network at some point on route, to enable access to ISP’s router.
-
OK no problems first lets deal with the VLANS. For a port pump out one VLAN as a normal network port it must be untagged on that port. So if 0-7 have WAPS that you want to get IP addresses from your new network range they will be untagged on VLAN1. Or if you want them to get an Ip address from your original network (the network range running low on IPs) they will be untagged on VLAN2. Now 802.1q VLANS and the uplink ports between switches must be untagged on VLAN1 (management vlan) to carry all other VLANs between switches. Then all other VLANS are tagged to stop traffic from VLANs merging. So if I have 5 vlans to send between controllers on port 8 VLAN1 is untagged and VLAN2, 3, 4 and 5 are tagged. Just to confuse things, some switches allow you to tag all vlans but there will always be one untagged underneath it all or 802.1q can’t work (sometimes it’s hiden in the GUI called the primary VLAN instead of management VLAN). Any way VLAN1 must be untagged on uplinks on WFS709TP with VLAN2 tagged or it will not work. Same applyes for all other uplinks to switches inbetween the Netgear controlers. Now on to the routing and default route. I take it the NATing has worked but you may notes that things aren’t working correctly if you try pinging between networks. To fix this we must do the following replace the default router on whatever dishes out DHCP (your main server) on your original network (the network range running low on IPs) and set your ISPs router up as a static default route (or Gateway of Last Resort ) for the internet on the Netgear controller. This will case all computers to look at the controller first to see if it knows of a destination network and if it doesn’t it will get passed on to ISP router (Gateway of Last Resort/ default route) On the Netgear controller to set a default static route to ISPS controller do the following. 1. Navigate to the Configuration > Advanced > Switch > General > IP Routing page. 2. Click Add to add a static route to a destination network or host. Enter the destination IP and network mask (0.0.0.0 and net mask 0.0.0.0 for default route) and the next hop IP address (ISPs Router). 3. Click Done to add the entry. NOTE: The route has not yet been added to the routing table. 4. Click Apply to add this route to the routing table. The message Configuration Last thing to do is some ping tests from original network to new wireless network range and then wireless network to original range and finely ping http://www.google .co.uk from both networks to test internet connectivity. Good luck with the config you will get your head around it eventually.
-
Just spotted a couple of mistakes, you must also set the default route on the master controller to be your ISP’s router IP address so that traffic can get out to the internet and also so your original network can see the new one you should set the default gateway on DHCP and any statically set IPs on original network to point to the controllers IP instead of ISP’s router.
