-
Posts
800 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by spc-rocket
-
Hi Neville, You need to create the rules with appropriate categories on the where tab and then under who you can create Who lists to narrow down on groups of users. I'm assuming your isa server is joined to the domain, this is a requirement for seamless internet access. When classing users into groups use the NT objects rather than the Active Directory (the AD thing dosen't work) and use the groups in your AD to be inlcuded in the Who list groups. You can also add individual users to the group as well. For the users who are not allowed internet access deny them access to all categories and when create a who list with the group from NT objects and create another rule and add the who list to the who section. You can have a group in AD called No Internet Access and add/remove users as needed. For the specific you need to have another rule with time restrictions and a where lists which contains the websites you want to allow (i.e. your whitlist) and add the where lists to the where section of the rule. To modify the default deny page edit the page and copy all code (html) and then create another deny page and paste the code and ammend the html code as necessary. Once you done this use the new deny page in the appropriate rules. If you haven;t upgraded, upgrade to SurfControl 5.5 and apply SP2 and all post SP2 fixes. HTH, Ash.
-
Hi James, One of the way to block it wouldbe to use the hosts file on the isa server. Add an entry like following 127.0.0.1 rainlock.com Add the above line to the hosts file on the isa server as i said and then try it. I'm assuming you have tried banning using domain name sets. Ash.
-
Plays here, the advert plus the video Ash.
-
Yeah i second that, AV on access scanning does slow it down and there are no reason to scan the files you can exclude the BKF, EDB files and sometimes backup-to-disk folder as well. Also few things to check: - What is trhe RAID setup on the backup server i.e. 1, 5, 0 etc - what is the network connection link speed from the servers being backed up to the backup server i.e. 100mb/1Gb, Teamed, 10Gb ? - What is the RAID setup on the servers that are being backed up? Usually the slowness will be from the servers that is being backed up rather than the backup server. As Steve said its a good idea to defrag your backup server as well as the other servers, just schedule this so you don't have to remember. Also allow plenty of defrag window on backup server if you backup server has large amount of disk space. As the usual small files will always take longer to backup than larger ones and there is no anything that can be done to speed this up. HTH, Ash.
-
Hi John, This is not strictly true of surf control, because when it monitors the users when the users (irrespective of number of stations) reach the nuber of licenses purchsed it will put the extra users as non-monitored used and therefore the blocks don't happen the the student are able to browse to the sites. I think they are have changed this now but only recently after being taken over by websense. I think what they are doing is now generatng new license key for schools who have licenses less (i.e. per station) qty to match the number of pupils in the schools. For us this was done as no cost thing but i'm not sure about others. @tom_newton I welcome that smoothwall does it by per stations because as you said this does make it more affordable. So well done to you guys. Ash.
-
Hi all, Apologies if this already covered, but could it not be possible to excude the ICT side of things from the whole BSF project based on the descretion of the LA and the school being revamped? One possible way to do this would be to have the school rebuild as per BSF guidelines but then have consultants who talk to the relavent IT services people at the school/establishment and implement the changes that are required as a one off rather than streamlining this as managed services. I think this may an alternative as it gives the schools the chance to update/refresh the equipment and infrastructure and still get to keep the IT in-house which will be better in terms of support as the whole team (NMs, senior ICT techs, ICT tech etc) are based on-site. Having said this i think NMs are schools should also realise that there may be some things suggested by the consultants (as per BSF) that they don't want implement but this could negotiated rather than just denying the changes recommended. I think there are lots of NMs who still goes on the analogy that is my network and you are not going to do this and that, well for a start its the school's network and if this kind of attitude is shown then the ICT services improvement will be delayed and flawed. I think the NMs should be more activily get involved in the BSF process and start to think about possible questions, recommendations to headteachers, the LA representatives. Ash.
-
Yes I agree with the Registry method for setting the flag. If you are doing a new image then it probably worth to use the RunOnce settings as this should take care of it before the stations is commissioned to the user. Ash.
-
Hi, The thing that annoys me is that all most all web filtering companies use the per user licensing which is really bad for schools as the pupil number are far higher than staff in SMEs. Surf control as well as websense are also in this game as well and when you addd up all the user the cost goes up significantly. I would like to see web filtering companies offer site license or per server license for education as least. This will allow schools to purchase decent web filtering software and not rely on RBC provided ones which sometime are too restrictive and sometime too open. Ash.
-
@Tony I agree with the SNB and how it can be made to work but the problem with the central filtering is that many websites will be denied (rightly of course) but the request is still fed through the wan link only to be denied again taking up bandwidth that could be used for other things. Kids will be kids and will try to bypass and access sites that are filtered and when you get this situation from a lot of schools where the requests are being made but are denied sometime this could overwhlem the webfilter and unfortuantely this used to happen regurarely with our RBC filter. This would then go into block everything mode until the box was reset or rebooted. Clearly there are software and HW that will handle more connections etc but the idea of having a report of who accessed what and ability to give users different filtering levels based on their identity is highly required. Also the portal where users sign on could be down so there might be disruption to accessing the internet and again the same logic applies about many connections that will be required to be handled by the portal, bandwidth used i.e. we have 300-400 stations (out of over 800) that access the internet at the same time. In the above scenario there would be a need to have more bandwidth available and the 10mb connection may not be enough. I not having a bo at the RBCs or the idea of RBCs, i think its great but there should not be an expectation that everyone will adhere to the SNB because for some schools (larger ones) that have different requirements will find that SNB put too much restrictions or does not fulfill their needs. Ash.
-
Hi Tony, Yes the one you mentioned are some of the limitations but the really difficult thing with the central filtering is that the school will lose the ability to allow/disallow sites by users (unless i gues you could login to the portal) so teaching staff can access more sites than student say for example. At the moment out setup is working very well for us and we can choose the type of acces we give the students, staff, TAs etc. Now of course with the centralised web filtering this could be lost or difficult to implement. Ash.
-
I'm really wondering how on earth did NetSweeper bagged the BECTA accreditation. shocking !!!! Ash.
-
@plock, Yes it worked and out admin server the following day after applying the patch backed up sucessfully and its been working since then. Seems like the same issues to me but different error message. Have you tried applying the fix on the server? might be worth it as the patch cures lots of problems with VSS writers. Ash.
-
using 2 dhcp servers on different ranges & domains
spc-rocket replied to chrisjako's topic in Wireless Networks
Hi There, The way to do this would be to use the ip helper command (in cisco, other vendors probably have a diffrerent command for it) and this will tell the vlan i.e. for vlan 1 config you could have ip helper of the DHCP server and same for vlan 3 etc, the ip helper ip address will be the same for all vlans. The way it know which scope to assign an ip from is by inspecting the gaddr so when the dhcp request reacched the vlan interface it will be a broadcast but when it is sent to the dhcp server the packets are converted to an unicast address and because the packet came from vlan 1 say (e.g. valn 1 range is 192.168.1.x) then the dhcp server will know which scope (i.e. 192.168.1.0) range to allocate the ip address). HTH, Ash. -
using 2 dhcp servers on different ranges & domains
spc-rocket replied to chrisjako's topic in Wireless Networks
In mutiple vlan scenarious you can still get away with using just one DHCP by having multiple scopes defined on it to cater for all vlans. The clients in each vlan will getthe ip from the correct scope providing the vlans are setup/configured correctly. Ash. -
Hi would add Trapeze into the mix as well, heard lots of positive things about them as well. Ash.
-
Hi Tony, Yes i agree with this and for those schools the RBC "way of doing things" does come in handy for them. I still think for larger schools with higher skill set technicians and NMs there should be some flexibility in regards to this. The difficulties that arises is that when a schools runs out of the allocated ranges and they want to extend the range. If RBCs are playing their cards right then they should have a plan for this so this scenario is covered and a step-by-step guide is provided to school who's been re-allocated a new range of extended their range. This will allow the school's tech team/dept. to implement the changes as quickly as possible and with mimimal distruption. I still don't like the RBC/LEA want to see right down to the school's workstation level, i personally don't see any reason for this except the firewall/filtering, which can be handled at the school permiter. Ash.
-
Providing wireless internet access for student laptops
spc-rocket replied to meastaugh1's topic in How do you do....it?
Hi there, We have implemented this using the Cisco Aironet APs and it works well. We have completely seperated this network from the main network by using VLANs. The default gateway for the student's wireless network is the firewall which has filtering software (added addition NIC to the FW) and it filter the internet access all from single point i.e. the firewall (ISA Server). At the ISA server we also given the student ability to access their My Docs (via easylink) and their webmail (OWA) and Internet Access with heavy restrictions (via web filtering). It works well and the APs are used for the corp. network as well because it supports VLANs and multiple SSIDs. Regarding the DHCP server i would just setup a normal windows box with DHCP server on the same network as the student's wireless and let that dish out the IP addfess, this way its not touching on anything to do with the main network. If this PC/Server crashes then all that is lost is the student's wireless network. A Virtual server could also come in handy for this i suppose. To manage the non-domain laptops we use 802.1x authentication with IAS server to authenticate users using their normal network username and password. This has been a great success because they don't have to remember yet another logon credentials. HTH, Ash. -
The above IP range uses CIDR method (classless). Ash.
-
What i find really difficult is that the LEA or service provider goes all the way to the wqorkstation ip address level where they should just terminate the connection at the permiter of the school's network. This way the school can design and use thier own IP addressing scheme without any effect on other schools etc. There is absolutely no need for RBCs or LA to go down to the workstation level on the school's PCs. I understand from filtering control but still think they should just leave it at the permiter and allow schools to NAT their connections. I've seen so many implementation where the overlap in IP addresses has caused so much confusion and ongoing troubleshooting. Ash.
-
All i'm trying to highlight is that schools chooses which ever software works for them, of course people can suggest various alternatives but its up to schools on which product they go. I raised the point that the thread was going off topic. Zimbra may well provide the same functionality as MS Exchange but since someone raised the point of exchange licenses (not zimbra licenses or costs) i thought i get into the conversation. Exchange CALs can be user cal or device cal and from what i understand its best to go with device cals (this is of course different if you have less PCs and many users) The external connector license is not required for schools unless you want to allow third-party users to connect or use services hosted by exchange. If the user is part of school/institution then they will have an account on the network and it is this account that they will be using to access the email from outside i.e. via OWA. This is where external connector does NOT come in as many people are led to believe. This is because it is the pupil of the school/employee of organisation accessing his/her emails from the coporate mail server. Ash.
-
Yeah this seems to be your answer to mostly everything when the topic of e-mails comes up. Like it or not MS Exchange is used heavily in schools and industry around the world and so is Lotus Notes...zimbra implementation are not high as you may think. Sorry i just had to get that in, cos the topic is dropping off the subject. Ash.
-
I think the Broadcom NetXtreme cards are okay as well with TOE functionality. Ash.
-
@HodgeHi, Check out the following link and download the User Guide (PDF) and check the chapter 4 (Page 16) for configuring your switch to support link aggregation. http://www.linksys.com/servlet/Satellite?c=L_Product_C2&childpagename=US%2FLayout&cid=1175235463334&pagename=Linksys%2FCommon%2FVisitorWrapper&lid=6333422279B21 The link is not for the exact model of your switch but it should point you in the right direction in finding the link aggregation section on their web GUI. HTH, Ash.
-
Hi, Yes teaming is the way to go. What make are the NICs? INtel, Broadcom ? If its Intel then its very easy to create a team using their Intel ProSet software (now accessible by using the device manager). I would also download and use the latest drivers for your NICs as well as these will have better support for teaming. There are various options, the easiest is the network load balancing which will work on any switch, the other are where you need to aggregate the two or more ports together on the switch configuration i.e. PAGP, LACP etc. HTH, Ash.
-
Hi, Cisco have a power injector that will supply more power than 802.3af for thieir draft 802.11n access points - Aironet 1250, this is a properitory standard by cisco and provides up to 18W or so. I think the IEEE is working on POE Plus standard that will allow for more power to be put through the cable. Cisco own standard is called Enhanced PoE. While on the subject of 802.11n i think its also woth thinking about allowing a gigabit ethernet connection to the access point since 802.11n provdies more bandwidth than the other standards. Ash.
