Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

spc-rocket

Members
  • Posts

    800
  • Joined

  • Last visited

Everything posted by spc-rocket

  1. Hiya, One thing spring to mind (which you may have looked at already) is the Captivate Portal add-in for isa. Collective Software | Captivate Its around $308 per server so maybe around £250 or so but its not that costly + you get support on it as well. Ash.
  2. I'm assuming they have created vlans for network segmentation and security. Each vlan will have a subnet anyway which will be routed at a router or L3 switch. I don't know what creating subnets will achieve otherthan a bit more clarity but it will still be part of the same broadcast domain. Ash.
  3. Hi, You should not use DNS servers on the external NIC but instead configure forwarders to point to your ISP's DNS servers on your internal DCs to answer or relay the DNS queries. You will need an access to to allow DNS protocol from your internal DC (the one with the forwarders set) to external or your ISP's DNS server. Believe me it will solve a lot of other problems that you have not encountered yet. Ash.
  4. Or use power injectors if a few APs are to be powered via POE. Ash.
  5. Hiya, That's interesting because i thought you can't upgrade to the new version free of charge and have to buy the whole product again. We bought the web premium package for our school for CS3 through Ramesys. Can i ask did you pruchase some sort of support contract or something and thus making you eligible for free upgrades? Ash.
  6. Check out this symantec article: How to backup Exchange 2007 with Backup Exec for Windows Servers (BEWS) Ash.
  7. Web Folder integration with IE is dropped in IE8 so you won't be able to do this. The current workaround would be to get the user to add a shortcut in My Network Places but this will require going through the wizard and it may be too much for them . RM Easylink has the same problem and the current word from RM is that this is under investigation. Ash.
  8. Hi, Can i ask does the 4TB version uses SAS 15K or 10K disks? The problem is the capacity of the disks really because by the time you setup decent amoutn of raid protection i.e. raid 6 with DP or similar the 4TB is gone and will probably be down to 2.5 to 3Tb (usuable) at best. TIA, Ash.
  9. I'm also along the same opinion and did state in my prev. post on this thread. Ash.
  10. The oddessey client is a cost option, not sure about the cost but yes it is more configurable. I think most of the time the windows built-in supplicant is pretty good but its let down by badly written drivers by NIC vendors. The way odessey and other supplicant solve this problem is by installing an intermediate driver which communicates to the lower and upper level in TCP. Ash.
  11. spc-rocket

    Server offers

    A little bit suprised that Sun are only allowing a max of 146Gb disk, this seems low to me really as most sas drives can be up to 450Gb. It doesn't matter if its 14 x 146Gb (2TB RAW) which is still a lot of disk space but not that much esp. when you consider raid 6 DP etc (which in my opinion you should be using on san and not raid 5) so the actual usable disk space is reduced greatly. Again i don't know if you put the option to reduce cost or not and it may be that bigger disks are available as well. I'm not a fan of just showing JBODs into a enterprise level live san system. Ash.
  12. Have you disabled the FBA on the exchange server. You can't have it enabled on both ISA and the exchange server. Set the authentication to basic in exchange. It will still be protect as the traffic will be be going through SSL. Ash.
  13. Hiya, We just stated that only the software side of things will be supported and limited supported at that as well. The students are responsible for their own equipement and there are not many places where they can charge the laptops anyway so we just state that they need to have it charged from home (this does seem to be silly but it works for us). The parents seems to understand this and we have been approached by a number of parents requesting some help and guidance on which laptop they should buy for their child. The idea here is that they get a decent spec laptop or PC for that matter and use it in school on this restricted wireless network and also use it for university if they go into higher education. We're testing the Iphone with 802.1x authentication at the moment and early signs look promising so that might be a service we may offer. At the moment only windows xp and windows vista are supported. Macs are also under investigation as well but we stated that it must support 802.1x supplicant as without this security could be comprimised. We also install our CA's Root Cert into the device as well to cut out Man-in-the-middle attach with 802.1x. HTH, Ash.
  14. This is how we have done with our sixthform users who bring in their own laptops. A seperate vlan and an ACL on the firewall or core will do the trick. Ash.
  15. Hi John, I've just got back from Holiday yesterday so i'll update you guys on Monday. I'll inform the technician to post the beta of the program here so people can test it out etc. As always the manual and documentation is still in development so the instructions may be simple. Ash.
  16. Hiya, On the RM CC3 they have the enterprise CA installed on the forest root server so it does make it easier to request the certificates from the FR server. Because its enterprise CA, the root certificate of the CA is automatically copied to all stations that are joined to the domain so you don't need to use the GPO method to roll out the root cert. to stations. From memory i think RM calles the Certificate authority CA followed by the name of the school i think i.e. CA Wakefiled School. In your configuration on the laptop you should have a tick next to this certificate for it to identify the Radius server. The reason for this is that you want to know that the radius server you are connected is trusted and is not bogus otherwise there are potential for man in the middle attacks. So if you used your enterprise CA to obtain a Cert for your IAS server then you should be okay. If you are trying to authenticate stations that are not domain joined then you need to copy the root certificate of the enterprise CA and import it to the station (in the trusted root certification authority store). Can you try renewing the certificate to see if it cures the problem. I think its the cert that's the issue. I'm on annual leave from next week for about a month so won't be able to get back to you but do tell me how you get on. Ash.
  17. Hmm, interesting that it worked in the past but doens't now, have you check the cert on the IAS server to see if its nearing expiration. Also i think cisco Aironet APs had some issues in the past where the fast connect would not work but i'm unsure if they have fixed it in the last IOS for the APs. Have you tried it without using the fast connect or reconnect option and see if it works. Is there anything on the AP's log to suggest that the client has moved to another AP or on the IASs logs? Ash.
  18. Hmm, Just wondering if you certificate has expired or comming up to expiration. You can try renewing the certificate to see if it cures this problem. Also which cert method are you using? 1 Enterprise CA 2 Stand-alone CA 3 Self-signed Cert One other thing you can try is to create a policy for domain computer seperately and another seperate policy for domain users. Also check that the user has "control through remote policy" setting enabled on the dial-in tab of the user properties. Your domain functional level must be windows 2000 or 2003 for the above option to be available. Also make sure that the shared secret is correct at both ends on the AP or controller as well as its corrosponding entry in Radius Clients section of IAS as this will cause authentication issues if they don't match. Ash.
  19. It seems to me that the host is denied rather than the user i.e. the machine account is not allowed access for some reason. Have you got a policy created that allows computers to connect to wireless before the user logs in? - to sort of simulate the wired experience Ash.
  20. I know you cleared the profile but if app data is redirected somewhere else then deleting the normal.dot template file is something you can do. We had similar issues and deleting the normal.dot file cured it. HTH, Ash.
  21. This is what we are doing to save them the hassle of remembering yet another logon. The wireless network is completely isolated fromt he rest of the network and has ACL in switches (for that vlan) to only allow certain traffic i.e. www, dns, and https. We also configure the laptops by plaing the root certficate of our CA into their laptops and mobile devices and then Radius takes care of authentication and authorisation. Ash.
  22. I would use the Client IP and then replace the IP address of the client PC where the user is running the report from. Ash.
  23. Hiya, The Technician who has designed this is not in this week but when he's back next week i'll get him to send you a beta of the program so you can see how it goes. It designed around CC3 but can be modified to run on vanilla networks as well. Ash.
  24. Hello all, We have got the usual issues with the shockwave flash games at our place as well. One of my ICT Tech. have developed a client/server application that runs in the background that blocks the shockwave flash games. It does this by using the hash value of the game and then when the game is played in IE it closes this down if it matched the hash list. There is also an option to close the Adobe Flash player.exe to be killed as well. This does not affect the active x plug in so its okay. It doe rely on creating a file with a hash value so he has also designed a hasher program which will generate the hash value from a directory which contains SWF games. The program can also be told to copy a file (swf) to a central location that is not the list. This will capture all the swf files so it may include the legit flash movies as part of thier coursework. It doesn't remove the file just copies so if its a a game (manual check required) then you can create a hash value of it. Using the hash value gets around the problem of users renaming the files to something else. The program checks the file list on the server every 10 mins (can be changed in the ini file options) and updates its own file every 5 mins. I don't know much of the other technical details but i will get him to tell you guys more and release to educational establishments once its all sorted out. Ash.
  25. Hiya, You need to use the sharepoint administrator to configure the Alternative Access Mapping (AAM) in the site before publishing it. IN the public name put the external DNS name you given it and it should work. Ash.
×
×
  • Create New...