Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

spc-rocket

Members
  • Posts

    800
  • Joined

  • Last visited

Everything posted by spc-rocket

  1. Hmm i don't think this is actually true, we are running CC3 here and we have multiple vlans for various areas across the campus and all CC3 servers are in their own seperate VLANs. I think there are few things to the hosts file that needs to be changed in order to build stations on CC3 with VLANs but this is fairly simple to do. Ash.
  2. I would advise for a managed switch especially for as others have said for port trunking and bonding but also for jumbo frame support as on SANs these really do improve performance greatly. Ash.
  3. That is true, but surely if you are going to go for the management system with central controller you would have some hardware support and replacement contract so they swap it out. Ash.
  4. Hmm, not a free solution, i could say the same thing with cisco secure services client as well as odessey. The license costs a lot in my opinion, and even if its £15-20 a seat its still too much. Ash.
  5. Which version of MS Exchange server are you using? Ash.
  6. Hmm the Intel wireless cards are pretty good and follows all the standards with wireless etc so i would not put it down to the driver but some communication issues i.e. the controller is timing out or the card before its ready to process the traffic. The odessey or Cisco Secure Services client would also be ideal to test. You can download a copy and use it for 90 days. Ash.
  7. SFP is the miniGBIC i think.
  8. Completely agree with you. Ash.
  9. Of course to utilise the 8Gb ram you need an OS that is 64 bit so windows server 2003 64bit or 2008 64 bit would do here. Ash.
  10. Have about changing the port's setting to auto so it can auto negotiate the speed. I would only set it to manual if you can be sure that the router's ports is set to the same. Ash.
  11. My post looks like is lost again replied this morning. Ash.
  12. Hi I'm having problems accessing the new posts link to display all the new posts. Using firefox 3 and tried logging out and logging in again but its still the same. It states that there are no new posts in the last 24 hours. I have manually checked some clearly there are new posts so looks like there is some kind of issues on new posts link. Ash.
  13. Which ports did you open for SIP communications or its it a all open rule from source to destination? http://blogs.technet.com/accessdenied/articles/419279.aspx Ash.
  14. Yeah sorry a typo, i did meant a linked thread. Ash.
  15. Your're a bit out of luck with 2004 and 2006 because they don't fully support SIP which is a pain. However there are add-on that will do the jobs this is one of them: Collective Software | LCS-Bridge Ash.
  16. Hi, I think it would be best to create a lined thread so the salary stuff is discussed with regards to this post/advert rather than a generic salary thread which seems pointless. Ash.
  17. Hi Alex, Do you have users in a particular OU and does they have any other information set in the AD attribute to narrow down the list. If you do then you can do this with PowerShell script that will go through and disable the user's access to OWA. Ash.
  18. Hi, Both are fairly easy to achieve using the Exchange Management Console. You can't do it in AD anymore on Exchange 2007, you need to either using the exchange management shell (powershell) or GUI console. Disable the user's access to OWA 1) On you exchange management console expand the server to reveal the three branches for management. 2) Click on the last one called Recipient Configuration and then select Mailbox 3) You will see the mailboxes listed there. Select the desired user(s) and right-click and select properties 4) Go to the "Mailbox features" tab and select Outlook Web Access and select disable at the top. 5) Click on Apply and OK your way out of the properties screen OWA is now disabled for the user. Restricting emails for Distribution list Again this can be done by the EMC as well. 1) ON the EMC under Recipient Configuration click on Distribution Groups to list all the distribution groups. 2) Right-click on the relevant DG and select Properties. 3) Click on "Mail Flow Settings" and then click on "Message Restriction" 4) On that screen click the option at below which reads "Reject emails from..." Click on the + or Add button and browse for a security or distribution list that contains all students accounts. 5) Click Apply and OK The above procedure may require you to create another security group so you can use this group in the above procedure. This group should contain all student accounts. I'm writing this of the top of my head so some there may be error. Ash.
  19. Hi, For testing make sure the shared secret doesn't contain any special characters and use a normal phrase. Usually alpha-numeric combination is best for shared secret. Do you have a security group with the computer accounts in and is this group allowed access? You may need to have both the users and computers in the groups to authenticate them both. Double-check the certificate as this will cause issue. For testing purposes disable the certificate checking by going to the properties of the wireless network and click on the Authentication Tab and then click the Properties button next to Protected EAP (PEAP). Clear the tick box next to "validate server certificate". Ash.
  20. Hi you need to refresh the isa console after installing the certificate or alternatively come out of the isa management console and re-launch it and try again. I think you only need to place the certificate in the personal store. You would need to install the thawte root cert in the Trusted Root Certification Authority if its not already there. HTH, Ash.
  21. Surely schools will need some kind of backup connections if the main one goes down and in my opinion they should be from another supplier and not part of the same line. When school are told to use VLEs etc that may be hosted elsewhere it is imperative to have backup lines for internet access for things like UCAS, VLEs and emails etc. The notion of the second line infiltrating the main RBC/JANET connection is valid but they should offer so guidance on how a school can a have safe second connection as well as the main connection provided by RBC. Saying that the second backup connection is against the rules and is strickly not allows seems plain silly. It is restrictive things like the above that puts people off the whole RBC thing in the first place. My biggest grip about RBCs in general is that they are looking at bolt on bits i.e. add-on to the services rather than looking at improving the the reliability of the core services i.e. reliable internet access, reliable web filtering and reliable email access and filtering. Providing some flexibility of IP address assignment or network design would also help as well rather than dictating what the school should use. If this break the grand SSO and Federated services (i will be suprised if RBCs get this done until 2012 if that) then be it and let the school become one of the identity provider in the whole SSO framework. Gone of the topic here slighly but the above points do need consideration. Ash.
  22. I did reply to you a bit earlier but looks like that post has gone missing for some reason. Strange. Ash.
  23. One way to do this would be to append (staff) or (student) to the end of their display name i.e. is the display name of a staff is Mark Smith at the moment then you can use ADmodify to bulk append the postfix i.e. (staff) or (student) so it becomes Mark Smith (staff). What we have done at our place is just used the postfix (student) on the student user accounts so when searching GAL staff knows which are students and which are staff. The above does require the first name and last name of the users populated so the display name can be formed and customised. HTH, Ash.
  24. Hiya, Does it have the bubbles (kind of orbiting the icon) going around the wireless icon in the task bar (next to the clock)? Also is the connection in windows profile set to automatic rather than manual. Having it manual will not initiate the connection during start up or other times. My guess is that the drivers are not written very well by the looks of it. If it is possible can you use another laptop with built-in wireless card i.e. intel and then try it with that. This will hoepfull eliminate the radius and AP side of things. Also do you get any errors in the system log on the radius server? Ash.
  25. That looks okay to me. You could try using another laptop with another wireless card (from another vendor such as Intel) to see if the drivers for the realtek are no good. Driver updates play a big part in stable wireless connections, so far the intel wireless card are pretty good and reliable. Ash.
×
×
  • Create New...