-
Posts
800 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by spc-rocket
-
Hmm, Seems interesting, that realtek card seems to causes issues for a lot of people by the looks of it. Can you post some config the "edit profile" (screenshot you sent earlier). If the card is 802.11n capable can you disable this for testing to see if there are any issues with this. Also make sure that the device is not set to power off when not i use - this setting is found in the device properties in Device Manager. Ash.
-
Hiya, Yes you're right it is a vista hotfix. I'll update my other post. Thanks. Ash.
-
Hiya, Can you provide the following: - is the laptop/desktop joined to the domain? - what is wireless card vendor? Intel, Broadcom etc - If its a self-signed cert have to imported to the trusted root certification authority? some screenshots of the remote access policies would also help. Ash.
-
Have you created the Remote Access Polices and do they contain the right groups i.e. groups which has computer and or users. Also make sure that the shared secret is correctly entered on both the AP as well as the enty in IAS. The following hotfixes that i know of : IAS Server (2003) - 323538 - 931533 - 883659 Windows XP wireless fixes - 893357 - 917021 - 923154 Windows Vista - 932063 Ash.
-
Hi there, It seems that the policies that you have does not match the request that is sent by the clients so it uses the default deny rule which is to deny access. Make sure that your policies are correct and it catches the user you are tryign to login. You need to make sure that it ctaches the computer (machine) as well as the user. Ash.
-
These types of error are usually caused by bad termination in the cables, faulty NICs or cable length has exceeded the recommedede for cat5e and cat 6 its 100m so make sure that from one end to another it is not more than 100m. Also if its fibre then i would check the fibre modules (transcievers) as these can also go bad and you see this type of issues. Try the following: - Check the duplex and speed of the link - change the cables i.e. patch leads - change the fibre patch leads and the module if its possible. - Change the switch port and plug the patch lead into another port to eliminate faulty port on the switch - If you have any testers then meaure the length of the cable Also make sure that you clear the counters on the switches or at least note down the current counters for CRC errors, Alignment errors etc so you can compare after swapping the cables etc. Its a process of elimination i'm afraid. HTH, Ash.
-
Becta has some guidelines on the templates that you can use on CM process. We have implemented this during half-term (this week) where there is a simple access database that keeps track of changes to servers, printers, switches, AP, software installs etc. I have told all my technicians and senior ict tech. to update the CM database if any changes occur even reboot of servers etc. I would say that a new ICT suite could be added to this but this would be a kind of project rather than CM but of course you can still get the CM process involved when commissioning the new hardware in the ICT suite. Well done for tackling this as i think its one of the most important elements in the whole of FITS process. It saves so much time during troubleshooting problems with ICT related issues. Some info on FITS (Becta) -> Becta Schools Ash.
- 19 replies
-
- change management
- fits
-
(and 1 more)
Tagged with:
-
How easy is it to leave the EMBC?
spc-rocket replied to apinnard's topic in East Midlands Broadband Consortium (EMBC)
There are bonded sdsl solutions aroundf that are hell of a lot cheaper than leased line. I would expect around 12K.for email filter, web filtering and internet access. Ash. -
I completely agree with srochford. You want to make sure that the kit is capable of doing N at some point in future and this is not just the controllder but the APs as well if its possible. This will protect you investment and will allow you to migrate to N when it comes out and when you are ready deploy it. Ash.
-
802.1x Wireless User Auth w/ XP Mandatory Profiles?
spc-rocket replied to ChrisCole's topic in Windows
Hi, I don;t know if mandatory profile locks down the registry but with that setup the users will need access to HKEY_CURRENT_USER\Software\Microsoft\EAPOL\UserEapInfo Try to see if access is denied to this section of the registry. Ash. -
Hi, You should be able to do this using radius and as others have said placing this network into its own vlan. If you access point supports vlan you can also have different ssids on different vlans to allow corporate access as well as guest access using the same APs. Ash.
-
Hi, Yeah its a much better supplicant than the windows's one but obviously it costs. We're looking at the xsupplicant (open1x.org) as the next version will have machine authentication as well as the ability to lock the profile so users cannot modify it but may add other profiles (for home) etc. Ash.
-
This is interesting, can't say this is the cause of some of the laptops dropping off wireless but might be worth looking at. We are using WPA with TKIP using IAS as the radius server with multiple vlans. I think the password on computer accounts expire every 30 days. Ash.
-
Then again you would wouldn't you.
-
EMBC past, present & future.
spc-rocket replied to kmount's topic in East Midlands Broadband Consortium (EMBC)
Hi Kim, We moved away from EMBC about three years ago and went our ways and its been good as the control is there. One of the interesting elements of this is that there is more cost but its still not as much as people think. To go into the discussion side of things the NEN thing really gets me everytime someone mentions this as at the moment there really isn't much on it to justify going with EMBC for this facility. This will take off some time when the RBCs can work together and co-opperate with each other and this won't happen until there is some kind of standards that the RBCs must abide by. Just to give you some examples some RBCs charge for more public IPs, some don't, some just don't open the ports you need and some fail in the whole SLA chain. I know these points are all technical issues but the they still matter. The colloboration side of thing needs dedicate people whom meet to discuss the best way forward for this and keeping schools informed about it. I feel that if this is not done then many won't bother and will not even know about it let along use it. VLEs are slowley making their ways into schools and both staff and students are getting used to the idea but it will take time and once they grasped this idea then we are more likely to have the colloboration (within NEN and outside) take off. One other think i dislike about the RBCs is the handing out IP address for you to use. I still think the school's team should be give freedom to choose this to suit thier purpose. This will cut down issues when schools run out IP addresses etc. The RBC's connection should really end at the router/gateway. If the excuse is that this will break the grand centralised approach of apps not working at EMBC HQ then the whole centralised approach should be questioned. For larger schools i think the web filtering box should be local to save on the WAN bandwidth because if you image the number of students using the internet, they will try to access blocked site, the connection request would go through the embc web filter (through the WAN) and then will be replied by a blocked message. Multiply this by the numbers of students and the number of schools connected on EMBC and it really causes concerns. The video conferencing doesn't work (it didn't last year) as when we tried to VC with another school in Nottingham we couldn't the connection just dropped. The result of the investigation revealed that it was something to do with EMBC as schools located within EMBC network couldn't even do VC sessions, let alone outside it. On the future i think the SSO (from schools AD to other resourecs i.e. web filter sharepoint etc) should be developed so the need for WAT is removed. I think there is something being done about this using LANLogin but this will still require the users to be created using the WAT system. Remote Backup storage is another area that i think has potential as this would cater for the need to have the backups located off-site at remote location. This will give protection in the event that local tapes are not available, damaged or worn out etc. Apologies if the above points are more technical one only but for the moment its what my thoughts are. Ash. -
I think this would apply to it gobally which may not be ideal. Have you got a seperate store for students. If so you can create a policy based on that to restrict the students to certain amount of recipient. Another way would be to modify the recipient limit using ADModify, this would do it for bulk. Admodify.net support exchange 2000/2003 so you should be fine with this. The individual account's limit takes precedence over global so this might be the best method, its what we use it here. Ash.
-
I would have thought that enabling journaling would archive the emails comming and going out. This is how it works in Exchange 2007, one just enables journaling on the Transport section and it takes care of the rest. For speed and storage purposes it is recommended to store the journaling in a seperate disks or a location on network or another LUN on SAN. Ash.
-
As plexter said, you need to export the start-up config to a TFTP server and then copy it over to the running-config of the new AP. It should retain the settings, although make sure that the after the import (copy) you change the IP address of the new wap otherwise it may cause a duplicate IPs issue. Ash.
-
You could also use iperf. NLANR/DAST : Iperf - The TCP/UDP Bandwidth Measurement Tool Ash.
-
Thanks guys, The script works fine. Brill. Ash.
-
Hi Guys, I should have mentioned we need to do this in a automated way so a script is ideal. I'll have a go at the DMcCoy has posted. Thanks! Ash.
-
Hi all, Does anyone know how to delete the Microsoft image writer that gets installed as part of office 2003 pro. I know that one can use the mst file to get it to not install but the msi and package is provided by RM. This really annoys me as they should have taken care of this. Ash.
