-
Posts
4,144 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Sheridan
-
Yeah its not the ideal setup as the firewall was in place, and the smoothie added just for filtering internally. Now this has changed, I'll have to create a new way to link the smoothie to the firewall I guess. Incidentally I did manage to use the SNAT policies to NAT traffic from Port 5 to Port 1 (not ideal but tests the theory) and the only thing that didn't work is the auto proxy config - set manually it worked ok though.
-
Sort of, on Port 1 the gateway is the firewall, which has a port with an internal IP and a port with an external IP (attached to our ISP's router) So Port 5 cannot see the firewall, and the firewall has no route to it - unless I NAT Port 5 through Port 1. Either that or redfine how the smoothwall routes through the firewall by maybe adding another port.
-
That sums it up, so I either have to find a way to NAT Port 5 with Port 1 or remove the firewall from the equation somehow! The smoothwall can see the firewall, but only from Port 1 as the firewall has no address on the Port 5 range. Looks like a rethink for me.
-
I think this is where I'm going wrong. I have two basic interfaces configured (Port 1 for internal traffic and Port 5 for BYOD) Both of these need to go out on a firewall which has an internal address (i.e on the same subnet as the Port 1) - which means I somehow have to route Port 5 to that, and that might not be possible and keeping seperation as well.
-
Hmm, I've got both trans/non trans at the moment and the auto config set on the Port 5 yet still get nothing. Might be time to restart the smoothie as well!
-
I've just got a transparent proxy on Port 5 - effectively I want the WLAN system to do most of the work and anything hitting this port goes out through the firewall with Student level filtering applied. I did have a non transparent proxy initially, but it seemed to be an over complication?
-
I'm not sure whether I've missed something along the way here but I'm about to add a BYOD WLAN to our wireless and point it to our smoothwall UTM. Currently our clients point to the smoothie as their proxy, which goes out through our firewall. Now, before I even add the WLAN (which is where the authentication will be done, so the smoothwall side should be simple!) I've added DHCP to Port 5 on the smoothwall and given that an IP address. The DHCP server is set to give out addresses in that range and set the Port 5 address as the gateway, with 8.8.8.8 as the DNS server. The interface Port 5 has its gateway set to our firewall (same as the Port 1 address used for 'normal' internal traffic) and has a transparent proxy set - so traffic on this port is given a default set of access rules (i.e 'Student') To test this, I've plugged a laptop into Port 5 where it gets the correct IP and gateway, yet nothing works, DNS won't resolve and no traffic is allowed. The smoothie can ping the laptop and vice versa but I must have missed something at this stage. Once this works I will set up authentication via the wireless VLAN and we should be good to go! Maybe I'm doing this an odd way, but as our smoothie is behind a firewall I want both normal and byod traffic to head out through the firewall, and the firewall allows all traffic outbound from our smoothie.
-
We've decided to grab a handful, put Edu on and give them a try. For the price and size they tick all the boxes. It doesn't matter what we buy as they won't be cared for so I'll see how long they last!
-
Sort of. The templates only work in win7 and not win10 as you have to use the default file association file and we never got that to work. As it happens we had issues with certain sites and mis systems with chrome so had to revert back to a mix of IE and chrome!
-
We've put a default file associations (xml) file on a shared folder for our test W10 suite to set IE11 as the default browser (or chrome - it doesn matter which!) but this seems to be ignored. Whenever a user clicks a internet shortcut on their shared desktop it simply comes up with the 'How do you want to open this website' Unless we specify the the actual executable for the chosen browser in the path we always get this. I never got the start tiles xml files to work so I'm wondering if this is more of the same?
-
Thanks, I do feel they are a litle bit fragile for education, but they give the Windows desktop the staff want in a compact size - for once they don't want ipads!
-
We're looking at possibly grabbing some of the last available Surface 3 Edu bundle for a mobile classroom. One thing that concerns me though is that they come with W10 Pro on, which in Microsofts crazy world means we can't use Applocker. Now I regard SRP or Applocker as essential so its either reimage them with W10 Edu, or look elsewhere. Has anyone here deployed Surfaces like this, have you stuck with Pro and used SRP, or imaged them with Edu/Ent versions?
-
Well for the first time in a long time I've had to call it quits on a problem. I've simply removed all traces of WSUS and reverted back, individual PCs now use automatic updates from microsoft directly. I don't think there is a solution to my problem, as there is no consistent pattern - since the WSUS server went to a VM it broke all the clients and they now will not comminicate with ANY wsus server regardless of OS or specification. Thanks for everyones advice and posts though, but after working on this for more than 3 weeks I've got to assume its mission impossible!
-
I've pretty much done that side on the WSUS server, and run through the post install. I then deleted all clients from the WSUS server, and force them all to reset their SUSClientID. This has resulted in a) No Windows 10 clients appearing at all now and b) the same mixture of Window 7 clients appearing/not checked in yet I can understand the Win10 ones not working, cos lets face it, nothing is right with 10 at the moment, but the Win 7 ones are all failing and the common error seems to be: Which makes it look like the client is connecting to microsoft.com for a cookie, rather than the WSUS server?
-
My server only had the KB3159706 on it, so I had removed that and restarted - that was back when I first started trying WSUS on 2012
-
Exactly the same here. Can't see a pattern on the ones that are working to the ones that aren't.
-
Basically yes to all! Firewall ports opne 8530/1 for server and clients for entire subnet.
-
Our PCs have a firewall rule to allow access on port 8530 to internal servers, and even testing with the firewall switched off seemed to make no difference. Is KB3145739 known to break wsus at the client end then? We have also noticed the ones that did check in to the new WSUS server a few days ago haven't checked in since! They are show clean logs apart from the error "WARNING: Cached cookie has expired or new PID is available" which crops up every time they connect.
-
I'm still in the same boat, back with WSUS on 2012 - about 2/3 have reported in, the others not. Exactly the same PCs and image in this case as I've limited the WSUS to just a specific OU. I'm still looking at it on and off but I'm awaiting some inspiration at the moment!
-
Well I've reopened the 2012 WSUS server and pointed a limite set of client to that. So far 2 have reported in - one working and one not yet reported! The second one is the 4010 error so I'll have to give it some time first!
-
Yeah I guess as its not working then I may as well drop wsus on 2008 anyway and start from scratch again.
-
Ahh cracked it - for some reason the repository (which is on a nas) was mounted on the server, and this seemed to lock it out. Unmounted the resposity and reran the upgrade and its working now!
-
I've been running Deploy Studio for a while now and needed to update it to cope with an updated version of OSX, so I tried to install 1.7.5 over our old 1.6.4 - this seemed to work OK However when I run the Admin tool it tells me the admin is running 1.6.4 and needs to be updated, if you choose to Upgrade it does the download\unpack\installation thing in seconds and then sits at a dialogue box that says 'Installation successful' but the 'Relaunch' button is greyed out and only the Cancel button works. Without this I can't proceed, anyone else havs problems with an upgrade like this?
-
I'm running WSUS back on Server 2008 and servicing both W7 and W10 - but only a dozen W10 machines. Now, the oddest part is that ALL of the W10 machines are checking in and updating correctly. Go figure!
-
Back to square one for me, some clients reporting in, some did once and won't anymore and most just won't report in with either the 80072EE2 error or lots of 0x80244010 if I login and try to run the updates manually. Changing the winhttp proxy hasn't made any difference, it must have just been a fluke on the couple that started working - even they haven't reported in since. Since the only thing I did was VM the WSUS server I'm completely at a loss to understand why WSUS has comprehensively failed on me!
