Jump to content

mrstrong

Members
  • Posts

    755
  • Joined

  • Last visited

Everything posted by mrstrong

  1. Not sure if this will help you but had a issue where dism couldn't repair as said "The source files could not be downloaded" In the end managed to fix by pointing at original install wim: DISM /get-wiminfo /wimfile:C:\install.wim to get index then: DISM /Online /Cleanup-Image /RestoreHealth /Source:WIM:c:\install.wim:1 /LimitAccess
  2. mrstrong

    new mac setup

    thanks, would you create a new apple id for AC2 and for getting apps from app store or should i just use our existing apple school manager (ASM) login ? bit more info, we have a lightspeed (payed) mdm but I'm also wanting to look at some free options e.g. mosyle Hopefully will be able to have ASM connected to two MDMs. E.g. have some old ipads I might add to DEP on new mac then load into a free MDM.
  3. just an update: not had any time to look into this (its not urgent as kids don't use gmail) anyway I opened a support case with google to see if they could help. The original support guy said I could send them a HAR file which I did and I also said we use a proxy. Just found out they've closed my case. This is the last "support" I got: Wish I could get away with a reply like that to a support ticket!
  4. just an update, before hols I rebooted the 8 port switch and thus the AP which is plugged in to it and gets PoE. Managed to get hold of laptop this week and test it and its working fine now. So good news but wish I knew why
  5. mrstrong

    new mac setup

    We've just got a new mac mini for admin use, e.g. for adding old ipads to DEP via apple configurator and to use as a cache server for ipad app downloads Having never setup a mac before I'm looking for a bit of advice. First impressions, nice and shiny but it only has two usb ports, so after adding PC mouse and keyboard I've got none left for a backup drive / plug an ipad in ? It's on Big Sur (not updated to Monterey yet, should I?). We have apple school manger (ASM) and a login account (not sure if this coutns as an apple id ?), so on the new mac should I use that ASM account to get apps from the app store or is it better to just create another appleid ? E.g not sure if I need/should link this mac to our apple school manager / DEP in any way.
  6. java and javascript are very different, java from Sun came first and Netscape tried to cash in on the "java buzz" by naming their language javascript (marketing / managers !) Javascript is used on client (and server these days) and is pretty much essential for most websites to work. All the main web browsers have a built in JavaScript interpreter which you can disable but then most sites won't work properly. I think java still gets used quite a bit for server side development but not so much on clients these days. The JDK (sometimes called the SDK) is what a developer downloads (e.g. download it from oracle) to write java code The thing we used to install on PCs etc was the JRE (java runtime environment) which runs the bytecode created by the JDK Some versions of JRE had security issues and chrome stopped supporting NPAPI plugins like the java plugin a long time ago
  7. annoyingly after being told yesterday this was "top priority" teacher has now disappeared with laptop presumed "working from home as wifi rubbish in school". So looks like will have to wait till new year as we all break up tomorrow.
  8. thanks all, will check driver though pretty sure other same model laptops have same driver version and work ok. Thats the weird thing, its just this laptop, could it be hardware issue on laptop? Did push out a few windows updates last week also (the ones that break printing ) The ssid that works ok is on a different vlan and smoothwall does dhcp for it (windows server does DHCP for other ssid that doesn't work). This AP also goes through an 8 port switch before uplink to main switch whereas other APs go straight to main switch. Might try rebooting all switches e.g. clear MAC tables. Wonder if could be some weird wifi issue, no expert on wifi but on ssid that worked it was showing as Channel 11 (11ng) but AP also does seems to have 5GHz on channel 36, wonder if I can try force channel 11 for other ssid (e.g instead of Channel 36 (11ac)) The AP is getting a bit of hammer, its a UniFi AP-AC-Pro, 10 guests, 80% memory.
  9. got an issue with a laptop that won't connect properly: it gets limited connectivity orange exclamation and a 169 IP. Weird thing is other laptops are fine on same network/ssid and access point (unifi). Also only seems to happen on this one access point, e.g. different room laptop connects fine. Doubly weird is that it will connect to a different wifi network (different ssid) via the "bad" access point though to be fair DHCP is done by a different server on this ssid. Apparently just started happening this week, "always worked before" (according to teacher anyway) Bit baffled, Any ideas what could be causing it ?
  10. found this: (from comments here https://www.papercut.com/kb/Main/PrintQueueSetUpOnWindows#print-deploy even though we don't use papercut) led me to https://support.microsoft.com/en-us/topic/managing-deployment-of-printer-rpc-binding-changes-for-cve-2021-1678-kb4599464-12a69652-30b9-3d61-d9f7-7201623a8b25#bkmk_enforcement So might try setting RpcAuthnLevelPrivacyEnabled to 0 on print server but "Not recommended"
  11. yes we have have 2012r2 print server and ltsc 1809 clients so was your fix to just roll back oct and nov updates ? Take it Michael's reg fix didn't work for you ? http://www.edugeek.net/forums/windows-10/223374-printing-issues-driver-update-needed-7.html#post1915622
  12. is this still causing people problems ? Not had time to go through all 20 pages but we are starting to see print issues after some windows updates. Not sure if it is this driver issue though: some people can print ok, others get "Access Denied unable to connect" and in event log for PrintService Win32 error code returned by the print processor: 283.
  13. had another quick look at this, now thinking it could be a dns issue. hopefully get a few hours next week to finally sort
  14. cheers will try if I get time later. Guess who just got the job of videoing /editing / uploading all the christmas performances back on topic, why is it we have to set "do not inspect" google stuff e.g. even when we've installed the smoothwall cert to enable decrypt and inspect via mitm ?
  15. added the failing sites from network_diag --hosts to "do not inspect" and "allow", so now have: two chromebooks, same model, same chrome os version, same user: one totally unfiltered (web filter exception IP) is working fine one via normal web filtering not working (this one now has no errors from network_diag --hosts e.g. all PASS)
  16. ah ok, so with a web filter block for playboy it would block it (based on the url I guess), even if you had it as do not inspect. But with "do not inspect" you are pretty limited as you can't see the page source ? Just looking under Guardian > categories > standard categories, I can see google drive and can edit it but no entries are visible, e,g, nothing in Domain/URL filtering, Search term filtering, URL patterns, File types, Video ID filtering Is that right / because its "built in" ? Is there anyway to see what smoothwall have included here e.g. for Domain/URL filtering ?
  17. so am I right in thinking if you have something in a "do not inspect" there is no filtering at all, i.e. no policies under Guardian -> Web filter would apply ? I suppose I'm trying to understand how the policies eg, HTTPS inspection and Web filter apply / interact.
  18. yes this was my worry, being too gung-ho and breaking search filtering. In general if you want a url /category as "do not inspect" (ie a policy under HTTPS inspection policies" do you also add a corresponding policy under Guardian Web filter policies (e.g. allow or "do not filter") ? Just using smoothwall's category search for a lot of the FAIL urls many are in the "Googeldrive and Sync" category Could I get away with having that complete category as "do not inspect" ? (just FYI this post came about from an ongoing issue with gmail: http://www.edugeek.net/forums/cloud-services/224810-gmail-not-loading-emails.html)
  19. yes I tried google support chat and went through 3 or 4 agents last week. The final guy sent me instructions on how to gather network logs on a chromebook which I did and sent off for "engineering team" to look at (no response so far) Had another email saying they were confused and was my google drive working now! Just having another look at this today, I'm now thinking it may be smoothwall again plus some weird "caching" See my other post here http://www.edugeek.net/forums/internet-related-filtering-firewall/225139-best-practice-filtering-chromebooks.html Where I'm at now is two chromebooks, same model, same chrome os version, same user, one unfiltered is working, other one through smoothwall not working (this one has errors from network_diag --hosts e.g. checking clients1.google.com... FAIL: non-Google SSL/TLS certificate) but last week when bypassing smoothwall completely via mobile hotspot and network_diag --hosts was all PASS the email was still failing with "Loading..." One other thing I found is on one that wasn't working if I remove account off chromebook and log in again this can fix issue hence why I'm thinking something cached. I guess on a PC you could delete the chrome profile of the user ? Difficult to concentrate on this at the moment without getting interrupted with all the usual pre-christmas madness.
  20. Sorry just got back to this. I'm actually trying to fix the filtering in school (not offsite with the extension). I also ran network_diag --hosts in crosh terminal and am getting some fails e.g. checking clients1.google.com... FAIL: non-Google SSL/TLS certificate so do I just need to add any failing URLs to a guardian HTTPS inspection "do not inspect" policy ? I suppose "do not inspect" implies "do not filter" so there is no need to and an explicit guardian web filter "do not filter" policy ?
  21. Hi, can anyone share what/how they handle chromebook filtering. Google's support chat have directed me to this page https://support.google.com/chrome/a/answer/6334001 We are using a smoothwall as web filter and firewall with HTTPS inspection (decrypt and inspect) for students. Is it enough "allow" all the urls in that google support page or do I need to go further e.g. set as "do not filter" and / or "do not inspect" (think do not filter implies do not inspect?) This is what I found on smoothwall's support site (whitelist is the old name for "do not filter")
  22. had another look at this yesterday. Ruled out internal networks / smoothwall by connecting to mobile phone hotspot Weirdly my account super admin works, ie I can open emails fine, so I created another user account in same OU as me and they can't open emails, just hangs on "Loading..." So in summary: 1. my super admin account on chromebook opens emails fine 2. new account in same OU as me on same chromebook can't open emails: can view inbox fine but click to open just hangs on "Loading..." (also hangs on "Loading..." when I try to "See all settings") 3. new account in same OU as me on PC opens emails fine ! not sure what to try next, maybe raise a ticket with google support ?
  23. As we have smoothwall in common, how did you "bypass it" to rule it out as the issue ? @ibpalle can you advise on best way to bypass smoothwall filtering etc when troubleshooting ?
  24. Yes I have had the same issue but not found a solution yet. We also use a smoothwall so thought that may have something to do with it but on checking web filter log nothing obvious like "denied", some http 204, 206, 302 but mainly 200 Strangely it seems to be ok on a PC but won't work on a chrombook so maybe a chrome os device setting ? Note we have PCs and chromebooks on different vlan. The only workaround I've found is to use the basic html version of gmail: https://support.google.com/mail/answer/15049?hl=en Hoping someone can shed some light ?!
  25. good spot! I'll approve for test group and see what happens
×
×
  • Create New...