Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. Sadly it looks like this won't work, just checked and the set of IP's has changed a few times, so its almost impossible to build a block list! Its only because they're hitting a couple of valid account names that its an issue - as they keep locking out!
  2. Thanks I’ll have a look at his, I’ve only really used the adsm so far I guess I can create a network group with multiple dodgy IPs and then apply the control plane rule to that I suppose at least it’s working, the accounts are locking before they even get a chance to mfa but as they know a couple of accounts it’s a pain when they’re constantly locking!
  3. I’m not sure as I’ve inherited this system and only really looked at the firewall rules which don’t apply to the vpn! Any help would be really useful if you can dump the commands here?
  4. I'm a bit of a newb with Cisco ASA kit, and it appears ours it being attacked on the VPN access side We have the ASA VPN set to Radius against a Windows NPS server, which then uses Azure MFA to authenticate. Works fine but we've noticed a handful of users accounts being locked out. This is from the NPS server being hit with external attempts to authenticate with these accounts (some of the accounts aren't even around anymore) Its only from a small number of external IPs, so is there as way I can get the ASA to drop anything at all from these IPs, as a firewall access rule is already in place - there must be a way to do this for VPN connection attempts?
  5. VPN, Leo and the wallet - these are disabled at GPO level. If I can't deploy it silently/for all users its a dead end anyway!
  6. Using brave doesn't affect the filtering or logging of activity - and we can manage the settings with a GPO. Plus, in this case its for a select few (Staff) users
  7. I'm trying to roll out Brave for some users using sccm - they offer a load of various downloads - the StandAlone one sounds like the right one but offers no silent install, and the StandAloneSilent installer works silently but only installs for the current user! Has anyone found a way to deploy Brave silently for all users?
  8. We have the following Content Mods on for Youtube: Comment Removal, Remove Adverts (which I understand doesn't actually work with on prem!) and Remove Siderbar and Disable Autoplay The 'in stream' adverts aren't so much of an issue, its the sponsored ones showing in the list that are a bit sus
  9. Is there any way to block the Sponsored videos that appear in Youtube with an on prem Smoothwall. For example a teacher here searched for a video (some engineering thing) and in the list of videos in the sidebar, the top 'Sponsored' video was a 'Find you soulmate' dating video, which amused the class a lot but is a) not remotely linked to the search and b) not very appropriate in a school! I can't see any way to remove these, I know Adverts can't be blocked using a different browser such as Brave but is that the only way?
  10. Ah that looks like it, I didn't set this wifi up (its been in a few years) and there appears to be a traffic shaping rule that blocks access to the LAN! I'll add a rule to allow the Smoothwall ip and test that!
  11. Can't see any firewall rules that would block, and the logs show nothing being dropped. Its all working as expected, apart from they clients can't access the smoothwall on the Guest IP (which is the same address that is being used for DHCP/router etc)
  12. We have an S9 with internal networks all working, but also with a Guest wifi directed to it - on this the guest wifi gets DHCP addresses etc from the built in DHCP server This all works fine, clients connect and get a DHCP address - but one odd thing is that when we use the splash page redirect to prompt them to install the certificate it just times out ( took too long to respond) This is using the http:///getcert of the address of the Guest port on the S9 - if I use the internal address (i.e what our network uses) then the certificate page loads fine The guest still get internet access OK, but do get cert errors when trying to access a https inspected page - so I'm not sure if I've missed something on the guest access side?
  13. Unfortunately my testing of this has also failed. I've removed a couple of users from the A1 Plus group, and added them to the A3 group Both users now show as an error in A3 as 'Conflicting service plans' and also still appear in the A1 Plus (even though they aren't in the group anymore) as 'Missing dependent service plans' So simply moving from license to another isn't an option either. And I can't remove them manually from A1 as it still shows them as a member via a group, which isn't true and I've check the synch has occurred correctly. What a mess. I'm so tired of this issue now
  14. Ah yes - these last ones seemed to work for me: optimizely.net mpulse.net 2cnt.net demdex.com Shocking how many tracking/advert sites it requires to work - especially as the adverts are in the stream anyway!
  15. I think that seems to be the only way - although you can technically have dual A1 and A3 (according to MS) it just won't accept it. I'm going to migrate a handful at a time every evening to see if that works!
  16. Even with that stuff enabled - Play just results in the spinning wheel Sometimes the DRM not enabled message appears, but not always Why are streaming services so crap these days!
  17. Has anyone managed to get Channel 4 streaming working through their smoothwall? I've allowed all the crud sites its seems to try and connect to - but all I get is the spinning wheel. Its obviously obssessed with adverts and tracking - but I can't see what else needs opening?
  18. I'm prepared to use our A3 licenses - it looks like th best option long term, but no matter what I switch on or off I get "Conflicting Service Plans" I don't think MS even know this works. I've got a test account with A1 and A3 - but I can't remove A1 as it says "To assign a license that contains Office for the Web for Education, you must also assign one of the following service plans: SharePoint (Plan 2) for Education, SharePoint (Plan 1) for Education." But that Plan 2 is in the A3 licence! I've been on this for 2 weeks now, have 4 unanswered tickets with MS - its really pushing me to GSuite more and more!
  19. Its goes from bad to worse - I've pruned our Staff list down for those who will need A3, synched the group and added the license to that group so they should have A1 Plus and also A3 - but it failed for every single user with the status of 'Conflicting service plans. Of course, MS don;t tell you what the conflict is. I've tried to switch off Sharepoint Plan2 as that's been mentioned as an issue, but it has the same error and switches it back on anyway! How on earth are you supposed to find the conflict, its such as mess of Plan 1, Plan 2 etc!
  20. That's exactly what we have, but as we pay for A3 on the FTE count we will be quite a bit short on the Faculty side of accounts (due to part time, supply etc accounts) So for example we have a good few temp Supply accounts, and they aren't included in the count, but need to be able to use 365 Apps on the desktop, but if we assign then just a normal A1 sub they can't I think you can opt for device based activation, but I guess MS will block these accounts from signing in via SSO as well
  21. Thats exactly what I have - but using a test account that only has 365 A1 for faculty and it won't activate as it doesn't have the 365 Apps for Enterprise - it only works if you have A3 etc
  22. Damn it - it doesn't like a user connect to 365 when opening the local copy of Word - they just get the error [h=3]"The products we found in your account cannot be used to activate Office in shared computer scenarios"[/h] God I hate MS and their licensing, it just keeps pushing me further and further towards GSuite
  23. One question I can't find an answer to is, if I switch a user to A1 for Faculty/Students (i.e what A1 Plus will default to next year) will that account be able to SSO into our locally installed Office (365 Current Channel) as we have our desktops set to SSO sign into OneDrive and Office etc Surely we don't need an A3 license for that? Or is this the way MS are going, although I'm not too bothered about a lot of accounts not being able to download the apps I would like them to be able to sign into our already deployed installations of 365 (down with SCCM and our EES license!)
  24. Ah that's done it, when I add the A3 to the existing A1 Plus users but with Sharepoint Plan 2 removed it works, so I might only have to switch off Sharepoint Plan 1 from A1 Plus and switch on Plan 2 for A3 at some point!
  25. Thats when I get the error - it won't assign until the A1 Plus is removed
×
×
  • Create New...