-
Posts
800 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by spc-rocket
-
Yeah I agree, they are dominant but this is getting too much. I woudl rather see better negotiated deals so public sector can buy MS software and also other software i.e. from Symantec, Sophos, Adobe etc so its affordable. I still think the £31.50 for MS Office is too much and would be better at around £15-20 mark, so if they want to hit them then get them to lower the prices especially Adobe who are just numpties when it come to the prices of their products.
-
I would also get the EU to do the same thing on Google as well. Ash.
-
Hi there, I would use a security group and provide a restriction on the group. After you create the group mail enable it and then set the appropriate restriction. You can do it using admodify as well by selecting the appropriate OU and then adding all the users to the selection lists. Use the .net version of ADModify and then you need to use the custom attribute as the option is not available in the main listing. When you see the list of tabs in Admodify click on the "Custom" tab and then in the middle section put a tick next to "make a customized modification" and in the attribute name box type in Authorig without spaces or quotes and in the attribute value type in the full DN name of the administrator account i.e. CN=SystemAdmin,OU=Contractors,OU=Contractors,DC=HQ, DC=Company,DC=net In the above example the the SystemAdmin account resides in the OU called Contractors and that OU is below an OU called Contractors which itself is under the domain name of hq.company.net HTH, Ash.
-
I say it again, it would be better suited to allow schools to use thier own IP addressing scheme, this kind of issues from both the end user's to the synetrix themselves is a nightmare in a migration scenario. It would make life easier for both parties to allow schools to use thier own IP schemes. One can't blame synetrix for this beacause this was the old way of how Fujitsu did things and they just migrated across to reduce the migration time and to not have schools making too much changes, but the initial design seems to be odd in my opinion. I'm sure there are schools on EMBC networks that are using their own schemes and if you speak to them they will tell you its works and works very well and with less stress. I know people don't want to have these kinds of comments and i'm certainly not blaming Synetrix as the servcies and migration process is still not completed so its inevitable that there will be issues when such complicated services is being migrated not to mention the number schools and users connected to the EMBC network. Ash.
-
Looking at this thread and it seems that the way of giving schools ranges to ues seems a bad idea, power users etc what would be better for the providers is to stop the connection at the boarder of the school's network i.e. the local firewall or proxy server. I don't really see any need for the RBCs to go to the workstation ip address level for each school. Yes given it is a private network, but it would be better if they allow the school's to use their own ip addressing scheme internally. I don't see any issues with this regards to SSO, Federated services etc. I also think the centralised web filtering is undesirable sometimes because the fact the kids will be kids they will try and access the sites they can't get to, this will make a connection to the web filter service centrally using bandwidth only to be denied access again using up the wan link bandwidth. Multiply this by the number of users using the system and the number of schools utilising web filter it can put a heavy burden on the web filter service and i think this was the case when fujitsu were in control of netsweeper. Ash.
-
Have a look at the Microsoft's offering of NAP (Network Access Protection) as well which does require at least one windows 2008 server but this can be installed on your existing 2003 inftrastrure so its not a big deal. Windows XP SP3 will come with a NAP client so that should make it easier to control the policies. All these solutions relies on the 802.1x support on your infrastruture devices such as switches, routers and acccess points as well as WLAN controllers. If you are just worried about kids plugging their own laptops then the simple 802.1x authentication is enough but if you are looking to find out and screen for dirty/healthy clients then you need NAC or NAP. These technology takes the 802.1x concept one step further by screening the clients for various other criteria such as the correct SP level, latest virus definitions and other conditions such as client being a member of domain and or in appropriate groups. We are using the our main wireless system (for staff) using the 802.1x with MS IAS (Radius) server and hidden SSIDs. For 6th form students we offer free wifi on thier own laptops and this is again controlled using 802.1x (WPA/TKIP) and are re-directed to the web filtering/proxy server so the net access is controlled. In order to access their My Docs we use the easylink (webdav) and open 443 from the wireless VLAN to the corp network. This works very well and its secure as well. HTH, Ash.
-
I think there are standard protocol definition already defined in isa for this one if RTSP Server, the other one is MMS among others. Have a look at the the "Streaming" section of the protocols that comes pre-defined with isa. You may need to consider using server publishing rules rather than web publishing rules. Ash.
-
Ideally you want to enable port fast or fast start on ports that connect to workstations and servers. You disable the fast start on ports that connect from one switch to another switch. Ash.
-
Laptops dropping wireless connection at log on
spc-rocket replied to Dragon's topic in Wireless Networks
Yes i second this, updating drivers is a must for wireless cards as they are constably tweaked to improve stability and performance. If you have the intel 2200BG cards then do upgrade the drivers as the latest drivers for these are more stable. Ash. -
Hiya, Try Neos IT Training in worcester. They have educational prices and i think they have an exchange course comming up in May. Ash.
-
Hi There, Have you checked the filters section (In advanced tab) of the appropriate radio i.e. G. Then go into the filters tab and check the WLAN Partition and make sure the settings are correct. Make sure you are editing/viewig the correct band's settings in the partition i.e. IEEE 802.11g we have the following settings as: Internal Station Connection Enabled Ethernet to WLAN Access Enabled HTH, Ash.
-
Hi, Try show ip int brief at the priviliage exec mode (i.e. when you are at # prompt) This should show you the interface status and weather its down or up. Show controllers might also be worth a try Ash.
-
Hi there, Great app, looks great. Does this get displayed at every logon? and how does it know has logged on i.e. staff, student or are these settings customisable? Thanks! Ash.
-
Pupils, Computers & Techy Staff Ratio (Northants/Leics)
spc-rocket replied to kmount's topic in General Chat
- Just over 1600 pupils - 730 stations - 130 Laptops - 80 Admin network stations - 12 Servers - 1 x Autoloader - SAN - Cisco Infrastructure - 2 Technicians (FT) 1 x Senior ICT Tech and 1 x NM (FT) We only look after the cleaning of air filters and some other issues of projectors but don't get involved in installation or finding out who to get it installed etc managed by someone else - thank god! Ash. -
WAPs supporting upto 25 concurrent users
spc-rocket replied to raufdean's topic in Wireless Networks
Hi there, with the 2200 intel wireless the latest drivers makes a huge differance in keeping a stable connection. There are some tools available to diagnosie issues with RF interferance, one of them is something spy, i think its wi spy or similar which comes as usb stick lookalike device that shows you the RF interferance all sorts of stuff. I think they are around £150 - £175 but they are worth it in the long run as it helps with placing APs and doing site survey etc. Ash. -
Hi there, Have you tried resetting winsock, i'm not sure if this is only for internet related problems, but its worth a go. The procedure in xp sp2 is easier. http://windowsxp.mvps.org/winsock.htm Its just that you mentioned the tcp/ip not being installed that i thought of this as i fixed this type of issue on a home pc recently. HTH, Ash.
-
Yeah i figured this after pressed the submit button! doh! Ash.
-
Hiya, Are you using this via iSCSI or Fibre channel? Ash.
-
Hi Ozan, I don't know if this is any use but you may need to extend the tunnel port range - http://www.isaserver.org/articles/2004tunnelportrange.html The above article is for isa 2004 but i suspect it might work with isa server 2006 as well. Ash.
-
ISA should be able to do this, did you set it up correctly and if so what was the problem you were having? Going for the shiney new HW firewall for things like this is not ideal and they never match the packet inspection as the software FW do. I know a lot of people knock the isa firewall becuase it runs on on MS OS but with the right config and harderned server os using SCW you can get a really good solution using ISA server. can I ask what kinds of things were broken? when you tried to use link translation on isa. There have been lots of improvements to isa server 2006's link translatoion so you may want to try this out on virtual machine so see it the new version sorts out the issues you got. Ash.
-
Hi Guys, Where can i find the link to see recently updated threads? There was a nice link before just under the logon section before the changes. It would be useful to have it somewhere on the main screen post logon. Ash.
-
ISA Server 2004, Granting Users access to the internet when unauthenticated.
spc-rocket replied to FN-GM's topic in Windows
If its plug in and go then you need to create vlans on your network and users who are guest can go on that vlan and will have access to the net (providing you created rules) this will make it easier to create rule on ISA as you just create another internal network and make all the vlan's clients default gateway the ip address of the isa server. Ash. -
ISA Server 2004, Granting Users access to the internet when unauthenticated.
spc-rocket replied to FN-GM's topic in Windows
Hi Guys, For antivirus and servers you want to create rules specifically for this but then create computer set rules with all the static IPs of all servers and use this computer set in the "From" section so it only allows those servers access to the internet. This will make it easier on allowing all users as there are programs on servers that are not proxy aware and so need the all users rule. This is how we got it setup. HTH, Ash. -
What i like to know is at present (i.e. now) what content is available on NEN and if schools are not with RBC and therefore can't access NEN, are they really missing out?? Ash.
-
Hi there, Are you using Bromcom system with sims? Ash.
