-
Posts
800 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by spc-rocket
-
Hi all, We got this issue today on our admin server which is running 10d with SQL agent. One of my guys called symantec and they said that this is a MS issue with Shadow copy service and not symantec issue and that MS have a patch which will fix this issue. The patch to apply is KB940349 - it requires a reboot of the server. We have applied the patch today and will restart the server at the end of school today to see what happens. Ash.
-
This only means between the school and the local concentrator or connection endpoint. 100mbit of pure net connectivity would cost a fortune!, I suspect the RBC has probably 1Gb to the net or something to satisfy the requirements of providing internet connection to various schools. Ash.
-
Any companies with 3 years inclusive laptop support...
spc-rocket replied to rpycroft's topic in Budgets and Expenditure
Dell here as well, really have been brilliant. Can't say the same for fujitsu-siemens laptops that we had as part of the damn LFT scheme, the support centre takes ages to answer and it takes good few weeks before we get it back. It does have 3 years collect and return service though, we have now (since last year) moved to buying Dell hardware on servers, PCs, Laptops etc. Makes it easier as all their stuff come with 3 years NBD warranty is great. I'm tempted to go for their accidental warranty as well, anyone using this? Ash. -
Hi, How you tried to do a live update for symantec, it may be that they may have fix for issues like this. Is BackupExec 10d up to date with the SP and hotfixes? Ash.
-
The problem with wireless is the half-duplex issue, until they can sort this out it will be difficult have many stations connected to the AP and all of them working and having enough bandwidth. Managed wireless is the way to go as it certainly helps in sorting out the channel issues as well as only allowing x number of devices to an AP. If i were looking for any managed wireless controller or APs be sure that it support the future N standard via firmware or other methods because it will be a big thing for wireless and will allow better bandwidth with MIMO (Multiple IN,Multiple Out) technology. Ash.
-
I'm trying to download the application but there do not seem to be a download link. Ash.
-
I think they need to limit the no. of exhibitors because it can me overwhelming with so many people trying to grab your attention and tell you about their products. I think many people regard going to the BETT show as a bit of jolly and there is nothing wrong with this but the amoung of things one comes out at end is very little and this is probably as i said because of too many exhibitors and the rush of people trying to target everything. Ash.
-
Wake on LAN across VLANs/subnets - 3Com Layer-3 Switch 5500
spc-rocket replied to SSTechIII's topic in Wireless Networks
Hi, Did you have any luck with the command i posted in my last post? Ash. -
Wake on LAN across VLANs/subnets - 3Com Layer-3 Switch 5500
spc-rocket replied to SSTechIII's topic in Wireless Networks
Hiya, Try the following when you at the vlan interface level packet-filter vlan 3 inbound ip-group 3000 where 3 is the id of vlan and 3000 is the number for acl group. I'm not entirely sure if the above command should be run globally or at the vlan interface level. Try at the interface level and if not see if you can run it at a global level. Ash. -
Wake on LAN across VLANs/subnets - 3Com Layer-3 Switch 5500
spc-rocket replied to SSTechIII's topic in Wireless Networks
Hi, The inbound traffic means traffic comming into the vlan 3 (in this case of broadcast to all ports on vlan 3). The outbound means traffic leaving vlan 3 and crossing over to other vlans. So i would say you need to assign it as an inbound to vlan 3. As for the access list the 3com things do look more complicated than cisco but i'm sure they will have a implicit deny statement at the end of the access list. in your case the access list you created seems fine (stated under problem 2) section. Can i ask is there layer 3 routing enabled on both vlans i.e. does each of the vlans (1 and 3 in your case) have an IP address assigned to them. How is other tarffic routing at the moment or are both vlans isolated (i.e. workstations from vlan 1 can't talk to workstations in vlan 3). if it is isolated and you don't require routing from one vlan to other then you only need to enable the access-list that just allows broadcasts for wol and then take out the ip forward-broadcast command from vlan 3's interface. Since the access-list will be there you won't require the ip forward broadcast command. Looking at the config guide for 3com i would have thought that you assign the access list to an inteface by using the following command packet-filter inbound ip-group 3000 i.e. go to vlan 3's interface and then type in the above line. (assuming access-list 3000 is defined with the restriction you want) HTH, Ash. -
Wake on LAN across VLANs/subnets - 3Com Layer-3 Switch 5500
spc-rocket replied to SSTechIII's topic in Wireless Networks
Hi, Yes you are right you need the command ip forward-broadcast on the vlan because this is the layer 3 virtual interface that is actually involved in the routing. I'm not sure how to create an acl for 3com but for cisco it should go something like access-list 101 permit udp 10.65.1.0 0.0.0.255 10.65.3.0 0.0.0.255 eq 7 the above access list should be specified on the vlan interface for the 10.65.3.0 network as an inbound for it to work. This will allow udp broadcast packets using port 7 from 10.65.1.0 TO 10.65.3.0 The MCwol could be used but since you found the program that works for you you should probably use that. What we have at our place is oneserver from where a scheduled task (batch file) is created that shuts down the PCs and it makes the ACL easier as you only need to allow the broadcast packets from one computer rather than all but the above access list will allow all pc in 10.65.1.0 network to send wol This may help you in acl configuration on 3com: http://support.3com.com/infodeli/tools/switches/5500/DUA1715-0BAA01.pdf Page 191 - ACL Configuration HTH, Ash. -
Hi, Have a look at this topic: http://www.edugeek.net/index.php?name=Forums&file=viewtopic&t=14303 Ash.
-
Here's the completed step-by-step guide for configuring 802.1x wireless authentication using IAS and PEAP. Please feel free to provide feedback and suggestions for improvements. Thanks. Ash. ias_for_ashby_school_v1.1_200.pdf
- 98 replies
-
- 11
-
-
Wake on LAN across VLANs/subnets - 3Com Layer-3 Switch 5500
spc-rocket replied to SSTechIII's topic in Wireless Networks
Hi, Try using mc-wol which allows you to do subnet broadcast, we use it here and it works well. You also need to find out what port the broadcast (WOL) is sent so you can create an ACL for this. I don't ip directed-broadcast works on its own as this will only broadcast certain type of traffic. Ash. -
Hi Guys, There wre lots of people asking for guide on setting up wireless authentication using RADIUS server so here is a step-by-step guide on installing and configuring 802.1x wireless authentication using Microsoft IAS (Internet Authentication Services). The guide focuses on using PEAP with MS-CHAPv2 authentication. Please review it and feel free to comment back so it can be improved and expanded, if required. I have not completed the Troubleshooting section yet and will re-post it again once i done this but the rest of the guide is complete. Ash. ias_for_ashby_school_v1.1.pdf
-
- 21
-
-
Hi, Is the end switch has fibre connections if so it could be the fibre trancivers, these do have the habit of causing issues such as packet loss, slowness etc. Check for the usual culprits: = STP (spanning tree ptotocol) = portfast enabled on all ports which will connect to workstations or servers = Is there a loop formed when you connect the pc/devices to the switch? Ash.
-
Hi Richard, Yeah that was my next plan, is just to create a dummy domain name set and export it and paste the domain names with it. I also noticed in the various isa server forums is that sometime you ned to do *domain.com rather than *.domain.com don't know why but its something to do with how isa evaluates it. I'll give this a go on monday. Thanks! Ash.
-
Hi, The best thing to do is to install the Microsoft Firwall client that comes with isa and then confirm the proxy for automatic script setting (sorry don't know what exactly its called). The firewall client will automatically setup IE proxy to automatic script URL. You should find that then this will allow you to do authentication for not just web proxy and FTP but for other protocols as well. Ash.
-
Hi Richard, I've had a go at it and can't seem to apply the setting after importing into isa and then using this set in one of the rules. I've also noticed that the list contains entries in there with protocol i.e. http://www.whayever..com - i thik domain names are meant to be in the format with out www or http i.e. bbc.co.uk i tried to replace the list and tried again but still no luck. It imports fine but just doesn't complete the applying it to the rule(s). Ash.
-
Hi, I would like to see the 802.1x supplicant and WPA/WPA2 support. We've orderd one of these but have not recieved yet so can't really comment on what is already there and what is missing. Recently Asus annouced that they will sell these with windows pre-loaded say maybe a cut down version of windows so we'll have to see how things go in regards to making services available via linux (which ever type, Xandros, unbuntu etc). However its still worth looking into providing the services via linux just in case the users/institution does not want to have windows on it. Has anyone tried putting the bare minimum windows on thes eepc's? Our account manager told us that they had windows and office 2003 running on it and it was working fine. I think its also worth RM considering what asus's long term plans are regarding this product, i.e. larger HDD, more memory etc so they can cater applications accordingly, if they are serious about making inroads in getting these devices to be used extensevily by pupils and in education establishments. Ash.
-
Yes its a good idea to have first firewall on the outer ring to filter the usual really crap traffic but for intelligent filtering and stateful inspection ISA server is a very good product. The way we got it setup is that our cisco 2611XM router with the usual rules setup filter the grabage and then it hits isa so yes we do have outer and inner ring firewall. What i was saying is that you don't need to go for the expensive option on the outer there are cheaper options i.e. cisco 2611xm router with IOS that has firewall feature set say for example. This damn cheaper than the ASAs. Ash.
-
ISA is also available as an appliance so that could be something to look into as well. As for not trusting the isa as firewall, then you fallen prey to the usuall mumbo jumbo that HW firewall admins usually mutters out. Ash.
-
2 wireless networks and wired network
spc-rocket replied to a topic in Network and Classroom Management
Hiya, Yes you would need two NICs on the firewall one on the normal vlan 1 in your case and one on vlan 2 (this makes it easier to assign IPs at the firewall) and also makes creating rules easier. On you vlan 2 you will need a server as i mentioned. Now regarding the switches, the trunk port is usually configured on the uplinks between swicthes and this trunk port allows traffic from multiple vlans to be carried accross the link. The switches at each end need to be vlan aware so they would forward the traffic to appropriate ports (which are configured on the various vlans). So lets say you have swictehs as below: Core --------> Distribution ------------> Switch -------- AP All the dotted lines link will need to be trunk links i.e. the uplink to the distribution switch will need to be trunk and then the link from distribution to the switch as well as the link to AP. I'm assuming you radius server is on vlan 1, this is not a problem as you switches will and AP will be able to see the RADIUS server to authenticate clients. This way you can make policies on your radius server and get your users to use the same username and password as their normal logon so they don't need to remember yet another logon credentials. On your DHCP server (on vlan 2) configure the scope options to have short lease time i.e. 2 hours or something and also the Default Gateway which will the IP address of you firewall (NIC2) so all traffic is routed through the firewall. Regarding the ip address for vlan 2, what i was saying is don't assign vlan 2 an ip address (at your layer 3 switch) i.e. leave it unnumbered so it only operates as layer 2 and does not participate in layer 3 routing. Sorry if this sounds confusion. PM you details and i'll give you a call if you need any help with this. Ash. -
2 wireless networks and wired network
spc-rocket replied to a topic in Network and Classroom Management
Hi, Yeah you would need a switch that is vlan aware when you connect to your DMZ on your wireless. The thing to do on vlan 2 do not assign an IP address, this will stop routing to this vlan, so you unsecured users cannot access resoures (i.e. the traffic routing is stopped) and then you can assign access to resources at the firewall which is what you want i.e. able to select what the unsecured clients can access. Now i'm assuming your APs are connected to a port which is configured as trunk? On you vlan 2 you may want to setup a DHCP server and DNS and setup some forwarders to your ISP or your internal (coporate DNS) servers. This way when clients connect to the unsecured wireless network they will get an IP from this DHCP server as well as the DNS server. You can the create appropate rules on your firewall for internet access, e-mail, vle etc. Sorry its a bit confusing but vlans is the way to go in these kinds of situations. Let me know if you want to know more. Ash. -
Office Select Licenses - use at Home by Staff
spc-rocket replied to spc-rocket's topic in Office Software
Hi all, Yes the install will take place in Network Services (our dept.) i wasn't thinking of giving the CD away, but just wanted to make sure we are okay to do this. Ash.
