Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. Right, I get it. Thats whats I'm having the problem with - I thought that box shouldn't pop up and it doesn't seem to accept any credentials (even prefixing with domain name) I thought with RDS you could get away with a single login? We do with our old Citrix system currently.
  2. What do you mean by the RDS box? Sorry if I'm being dim here!
  3. No, I edited the login.aspx file to allow them to login with short login names. I might try reseting it back and give it a try.
  4. I've setup a test 2012 R2 RDS system (all the roles on one server purely for testing) so I can see how well RDS will replace our older Citrix system. Internally it works ok - staff login and launch apps fine (apart from the first initial app loading slowly) but when they try to use it at home the behaviour changes. They login ok, but when launching any app are given a dialogue asking them to enter their credentials for the RDS server - no valid credentials seem to work at this point! I've got a full domain wildcard SSL certificate on all the RDS roles, and on the TMG that it comes through - have I missed something about enabling SSO along the way?
  5. Thats what we tried, using both local xml files and on a network share. Still never worked consistently - i.e Office icons would appear, but something like calculator or Explorer would appear sometimes, or never depending on the login.
  6. How did you get the xml file to work? I tried everything (on a share like our Window 7 redirected menu and local copies, Edu,LTSB and Ent) but it never works consistently. I gave up and used the classic start menu, it really bugs me that I have to use a third party tool to fix a bug that MS can't seem to sort out!
  7. We're running a 2008/2012 mixed DC domain (until the older DCs are turned into 2012 VMs!) and we're about to upgrade a small IT suite, and 10 LSTB with the classic start menu is looking promising. Personally I think 10 is a missed opportunity to provide a new OS for the future. It started out as a cludged up Windows 8 clone and has slowly been messed about so we have a part-managed OS with two control panels and a browser that doesn't seem to even be finished yet! But until we jump into a 'live' use of 10 we won't know how good/bad its going to be, so we're regarding this mini upgrade as a test for us and our primaries.
  8. That was the only way we could fix it - as the Gmail App, and also Chrome don't work with MITM inspection. We could direct staff to use Safari for browsing but using the Gmail app was so much easier for their email that we had to modify our smoothwall to sort this out. With you having filtering through the LA I'm not sure how they'd do it, unless they can do it for a specific ip range.
  9. Are you using Smoothwall or some other HTTPS inspection based filtering? Thats what killed it on our ipads - we had to change the rules to let them avoid https inspection for the gmail apps.
  10. I guess it is down to trust (oh oh!) as we can enforce it, but it stops other things working, and the MDM is definitely the most important of the two for our staff ipad rollout.
  11. Just to revisit this - how do any of you GAFE users out there enforce a password policy on staff who use their phones for work email/drive/docs etc? I'd prefer just to use Meraki (or similar) but that only works for devices we own and control. Outside the school theres no way of stopping staff from linking their phones/personal devices to their school GAFE account - which is a potential problem if they don't have a passcode on their phone as anyone who picks up that phone can read confidential emails etc. So in the ideal world, GAFE would apply a policy to 'external' devices to simply say you need a passcode, and we deploy AC2 & Meraki to school owned devices to give them a full config for wifi etc. Or do you simply allow staff to connect their personal devices to GAFE without any restrictions?
  12. I don't know about you, but I cable these cabinets up with matching colours and the best intentions in the world, but a year later theres odd coloured cables, loose cables and missing cables all over the shop!
  13. Macrium Reflect free version. We use it for single images or hdd to ssd copying.
  14. Some of those 'before' shots look like our cabinets before last summer! We went through the main cabinet(s) and all the edge cabinets and recabled them with 0.5M patchs and 1M Patches for uplinks etc (different colours).Due to space shortages we couldn't get blanks or cable tidy trays so we used copious amounts of cable ties. Much,much better now and so much more aesthetically pleasing!
  15. Just to update - I got this sorted (with Netgears help!). It was a mixture of misunderstanding about rule priorities and also the terminology used, even Netgear had to check their notes!
  16. Hmm I've tried creating them as advanced rules and specified both IP and ICMP as being blocked incoming on that port, with a 'Permit all' at the end for everything else. This now blocks traffic & ping from everywhere, this is doing my head in now!
  17. TBH, I just think ACLs don't work on this model (M6100) - even using their wizard to create an ACL doesn't work as expected. Time for a rethink.
  18. This is a Netgear switch - according to the manual a 'simple' ACL blocks all ports (UDP/IP etc) unless you specify otherwise in an advanced rule. It should just be inbound - as you have the choice to apply the ACL Inboound, Outbound or both. In my case I've applied it Inbound only as I just want to block traffic from one subnet reaching another.
  19. I'm setting up some ACLs to apply to my new VLAn schema (currently just using static routing) and I've got 2 ports on the core switch - I want to allow incoming traffic one way but not another. Simple I thought, I'll apply an ACL to the port that is going to deny the other ports traffic. So the ACL Inbound on this port (simple ACL) blocks all traffic from the other port's IP range, but allows everything else (to override the implicit deny) Now, trying to ping devices on the port where the ACL is applied seems to have unexpected results. Devices from all IP ranges can ping it, even ones on the explicity denied range. If I remove the Permit All rule then NOTHING can ping devices on that port, and they can't see anything outside their own subnet! ACLs rules work top down until they match - no match means denied. But my Deny rule should block that particular IP range and allow everything else I would have thought?
  20. Yes I have the default VLAN 1 so I'd need that untagged on the uplink ports. I'm thinking of splitting the static routes into VLANs, so each edge cabinet will be one VLAN but will include a couple of APs on another VLAN, which I guess means tagging the APs ports as well as the uplink ports.
  21. Actually, am I overcomplicating this? Removing all the static IP addresses (and thereby the routes) from the fibre ports will mean I can then add a VLAN for each subnet and all I would need to do is Tag the fibre port for that VLAN to match the ranges I already have - as all of the kit 'downstream' from the core switch would end up on that single port/VLAN? I.e At the core switch fibre port 1 has the fixed address of 192.168.10.0 - with routes in place for that. If I delete that and create a VLAN 10/192.168.10.0 and mark Port 1 as Untagged for VLAN 10 it means the downstream switches and PCs etc will all arrive on that VLAN - I would have to repeat this for the other ports as well. It would then be a case of adding VLANS for the wireless but tagging the actual ports the APs are connected to. Or maybe I've oversimplifing it!
  22. On the netgear the VLAN is open and has Routing enabled once you create it. I think I'm missing something here as I've created a single test vlan on a spare port on the core switch and stuck a laptop in it. The new vlans gateway address is visible from other devices on the core switch, but not the laptop attached. I assume I've got the tagging wrong or missing here.
  23. Thats what I thought, but when I created a new vlan on the core server (for an unused ip range) it creates the route, but nothing plugged into that port can see anything - I would have though the vlan's gateway address should be pingable from a client on that newly created vlan!
  24. Yeah the part that I'm struggling with is converting the working static routes are the core switch to vlans that will correspond to a dhcp range - its not something I can easily test!
  25. I guess is going to be more tricky than I thought! My L3 ports having routing enabled, which I can disable and effectively set them to switch ports. Then the core switch would have no routing information so I would have to build the VLANs to correspond with our existing DHCP ranges althought I'm not sure how to tag the ports at the edge switch end to do this. Looks like this will be a summer job after all, its not something I can practice on a live setup!
×
×
  • Create New...