-
Posts
800 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by spc-rocket
-
Unessasary network traffic from printers.
spc-rocket replied to tosca925's topic in Wireless Networks
Agree with webman, turn off all protocols except for TCP/IP unless those protocols are needed. We have made this procedure the part of a new printer commissioning so its consistent across the network. Appletalk is the worse. Ash. -
Yes but you got to be daft to adopt an OS that's just been released into product. I agree with what they have said regarding the SP1 level. usually by SP1 the product has matured enough for adoption. Citrix or other companies are still working on full compatibility with Vista and this will be true for many software and with updates the problems can be ironed out. What i don't understand is why is there such a rush to migrate to Vista, what's wrong with XP and Windows 2003 combo. What is it that XP can't do that vista can give the requirements of schools, again lots of discussion on this topic but less answers. Becta for once has got it right about advising schools to wait. However this does not mean that schools should not purchase workstation without vista license or prepare for vista or test vista for that matter. A lot of people will be testing vista and finding out how best to incoporate the new OS into their organisations but many won't be interested to have fully working vista workstation in production. Ash.
-
Dell PC 19" 1GB Ram 320GB Vista or XP Dual Core 1.6 £209
spc-rocket replied to FN-GM's topic in Hardware
From my experience the call ends up in Ireland as opposed to India and never really had any problems. I suppose the Dell restore and utilities are a good thing rather than bad as it helps them and you also to solve the problems quicker rather than going through various things and trying out the suggestions etc. Ash. -
@Rattler Yes this is possible and is an ideal way to segment your network. What you need to do is work our how many vlans you will need and then assign each vlan a subnet. Its important to choose the correct subnet range i.e. the number of valid host on each subnet i.e. 192.168.1.x with a mask of class C default will give you 253 host available. .0 for the subnet identification .1 usually for the vlan id (you need to assign the vlan an ip itself as well) and .255 for the broadcast for that subnet. This decision will be based on how many PCs or devices you have in each section/block. You may want to have a vlan purely for managing the infrastruture devices i.e. swicthes, routers NMS etc, 1 for servers, 1 for printers, admin network if you have a seperate admin and curric network. At this point its also worth pointing out that you need to think about any future expansion and just setup a vlan for that as well i.e. wireless, VOIP etc. In order for intervlan routing you need a router (bad choice! unless you have one of those expensive routers) or a layer 3 switch which does routing at ASIC based and is much quicker. Check your core switch to see if it supports layer 3 functionality. The only difference between a layer 3 switch and router is that the router will have more routing capabilities in terms of routing protocols i.e. BGP, IGRP, RIP etc. However since your network will bring in all the vlans at the core it will know the routes to all vlans and hence you will not need to use any routing protcols and this just cust down the complications even futher. You will find benefits and broadcast reduction. We have got this kinds of scenario setup at our place and it works and its its a lot clearer to view the network and make decision on expansions etc. PM if you need more info. We use all ciso gear at our place so i can probably provide some advice on the way to go about it, but may not be much helpful in the configs of 3Com. Ash.
-
Getting internet working on domain after changing IP range
spc-rocket replied to tosca925's topic in Windows
I find it interesting that people have 1024 addresses allocated to them and they still run out of them when they should be splitting the network into multiple vlans to reduce the broadcast traffic. All that many host on one flat subnet will be draggig the performance of the network down. My advice is to use the range that suits you better and vlan the network. I know there are schools who don't have instrafcture devices that don't support vlans but managers/ICT techs should be pushig the management to budget for switch and router upgrades. Personally i like the RBCs to be cut of from the router onwards i.e. they just provide a ISP like service and after the router i.e. your corp. networks it shoudl be up to the schools to decide on which subnet they want to use rather than the RBCs going straight to the workstation level (right through the crop. network) and being able to ping, remote control etc.). We have 11 Vlans setup at our place with different subnets to hold all servers, insfrastructure, workstations and in different blocks/sections, printers etc. The routing between these vlans is achived by using a Layer 3 switch (i don't recommend a router for this but a layer 3 swicth for HW routing). The performance has gone up and both teaching staff and student have noticed the loggin in time and accessing the network resources. Ash. -
Dell PC 19" 1GB Ram 320GB Vista or XP Dual Core 1.6 £209
spc-rocket replied to FN-GM's topic in Hardware
This looks like the Pentium Dual Core and not the Core2Duo. Still not a bad price and the Core2Duo processors are not badly priced as well. I'm sure with a large quantity the 3 years warranty could be added without any cost and probably upped the RAM as well as well as the one of delivery so one shouldn't worry about the delivery cost that much. Ash. -
MAC Based vlan allocation with procurve switches (11x)
spc-rocket replied to AlexB's topic in Wireless Networks
Hi Alex, In order for the radius server to send the vlan id, configure the following options: Tunnel-Type = VLAN, Tunnel-Medium-Type = IEEE-802, Tunnel-Private-Group-Id = the VLAN ID or name i.e. 20 or Server-VLAN In order to the switches to talk to one another you need to configure trunk links with 802.1q encapsulation. HTH, Ash. -
Begs the question again!! who is actually using IPv6? if people are really desperate to run IPv6 (I can't think of any at the mo.) then install additional tool to block IPV6 and ipv6 supports authentication and its own security anyway (network layer security) so i don't really see how this is going to cause any problems. I don't see many people rushing to join the IPv6 revolution. Geoff are you slagging off the isa server because its from MS, smell like that to me here, get the penguins out your heads once in a while. Ash.
-
Good idea Russ, I'll come along, been looking forward to this kind of get together, it would be nice. Ash.
-
@Geoff, I meant how many firewall are actually configured to process ipv6 traffic not weather it supports it, understands it, decodes etc. Ash.
-
IPv6 will probably be supported in future service packs for isa server 2004/2006. I agree that at present there is no need for it considering IPv4 had NAT, QoS and few other tweaks that can be made one can really take ample time to upgrade to IPv6. I know all the JANET, UKERNA etc are using the combination of IPv6 and IPv4. There is a hotfix or patch/update for windows xp and 2000 that allows the use of IPv6. I like to pop the question regarding ipv6. How many firewalls either first ring or second actually processes IPv6 traffic in the world specific? not many i think so the fact that isa server supports ipv6 or not is not really that important. Ash.
-
If you solve it let me know i have been trying for 6months on exchange 2003 and yet to find a solution. Create another Global Address Book and create the filter for students accounts only and then setup the security permissions. Dissallow access to the default global address book by removing student accounts or student group from the ACL. You can also create another global address book for staff if you want to but we usually leave the default address book on for staff since they can see other staff as well as student list and so can send emails to both staff and students. In order to control the bulk emails to students or staff for that matter use the recipient limit and set it to say 2 or 3 email at a time say. This is a long process if you do it the AD way in exchange but fortunately some clever people come up with ADModify.net which lets you make bulk changes to user accounts (or other AD staff if you want) and the option to change the recipient limit is also present in the bulk modification properties. I think ADModify.net is compatible with exchange 2000 and 2003, not sure about 2007 you may want to check it out. Link to ADModify article: http://www.msexchange.org/articles/ADModify-Change-Exchange-Specific-AD-User-Attributes.html HTH, Ash.
-
Hi Tom, When i mentioned about the services being disabled, that is one aspect of it, there are other things it modified and therefore disables the other functionality of windows server say. This is done through selecting the role(s) of the server and depending on which role you select it configuring the back-end os for that role and nothing else. Your solutions may be easier may be better or worse but certainly commenting that isa is poor at perimeter or second ring is bad. I guess people decide on ease of use, deployment and administration and some may find it easier to configuring firewalls using web browser etc and some like to have proper front-end gui. There are also other people making comments about it being expensive, its not that expensive for schools i.e. £50 approx for the base server license, and £150 approx for the isa server itself so not too bad. Native MS AD support it good and if you're a microsoft shop then it makes it ideal. I'm only carrying on this debate because so far i haven't seen any advisories regarding isa server 2004 or 2006 but have seen many issues regarding hardware firewalls even from big guys. Agree with the PPTP bit some people are taking chances with this and should use something more secure i.e. L2TP/IPSec but that's the firewall admin being either lazy, or ignorant. Ash.
-
There is SCW wiazard that hardens the base OS by disabling the service and all you need to do is to select "ISA Server" and the Security Configuration wiaxrd will disable all services not required and keep the isa and thus hardening the server OS. This is the same sort of things that you guys do with you kernal modifications etc. Ashok.
-
@tom_newton I don't agree with statement, its a far better firewall than some of the so called HW firewall/packet filters. Just because runs on top of a MS os and software based is not a good or for that matter a valid reason to call it poor. I agree that one should have simple packet filter firewall at the first ring to cut own the real garbage and nasty stuff but for SPI etc and deep packet inspection its very good (isa server). Tom can you provide few points on why you think isa is a poor firewall please I am curious to know becaue we have got it running here (ever since we moved away from our RBC two years ago now) and its been fine and have not had any problems, we are using at the perimeter. Ashok.
-
That's interesting, i kind of know they based in london or soth east region but didn't know they provided servies for LGFL. Its fair enough about the NDAs etc as lots of things are still being negotiated. I'm slighly repeating myself again but i do hope they go for more of ISP with extra services role rather than we know what you want and this is what you are going to get. This would be slightly foolish as current EMBC did this and it didn't quite work out. Options for larger schools would be big advantage with the flexibility in IP addresses (i.e. let the damn schools control what their IP subnets should be and if they want to vlan and go for multiple subnets etc). Sorry had to get that in. Ash.
-
Hi, We use select agreement and have bought licenses from Ramesys and if you ask they usually they chuck in the CDs as well. As for wheather they are burned on normal CDs or proper MS CDs i just don't give damn really as long as its legal copies and you are covered i'm happy. They provide good prices have been really good to us with our license orders. As Tony has mentioned they provide really good prices that i don't mind not having the access to downlods or CDs. Ash.
-
EMBC Announce Service Provider
spc-rocket replied to GrumbleDook's topic in East Midlands Broadband Consortium (EMBC)
Hi Tony, That info on Derbyshire website makes interesting reading regarding the 3 year contract and ability to pull out of the contract etc. I just hope the new company provide flexibility in terms of allowing schools to select the servcies they need and of course services they can afford (thinking of primaries here). Some kind of tier system would be good where tier 1 could be just internet access Tier 2 internet, e-mail and tier 3 say internet, e-mail, web filtering, VLE hosted etc. Synetrix were one of the companies that were providing servcies in EMBC already probably, the network infrastructure and monitoring. Anyway lets hope they have listened to the concerns by schools and make their service(s) that really appeal to schools. Ash. -
Hi guys, What the agenda and what time do things kick off? By the way by RM HQ do you mean Abingdon? Ash.
-
Hi, You can do this in isa, create a new cache rule that is right at the top of the cache rule and then create a URL set or Domain name set which contains your site(s) that you want not to cache. In the cache rule, on the "To" tab use the URL set/Domain name set you created rather than the External network and select the option. In the "Cache store and Retrieval" tab sleect the top option and then under the "Store in cache" section on the same tab select "Never, no content will be ever cached", on the other Tabs i.e. HTTP, FTP, and Advanced make sure that the checkboxes are not ticked. This way isa will not cache the pages from the site listed in the domain name set or URL set. HTH, Ash.
-
Hi, ISA will only use the primary IP on its external NIC as the outgoing IP so make sure that you have the external NIC's primary IP as 172.21.138.180 and the rest defined in the advanced TCP/IP settings. Now since it uses this ip address .180 all the users going through isa may bypass the sites as with NAT you county's webfilter will think it comming from 172.21.138.180. Unfortuanely in isa you can do a web proxy forwarding with a 1:1 NAT so you can say if the traffic is comming from laptop then use the following external IP to send outbound and for other traffic (from other hosts) use another IP. By default the relationship between the internal network and external network is NAT. To check it is set to NAT follow the steps below: 1) In ISA management expand the server 2) Click on the configuration and select "Networks" 3) At the bottom of screen select the "Network Rules" tab 4) Check that the realtion between Internal and External is set to NAT. Ash.
-
In this case you need to assign more IP (external) addresses to your external interface and then create a NAT relationship and after this it should be fairly simple with the 1:1 NAT. I.e. if you external NIC has the the IP address 172.16.10.50 and the your laptop has the internal address of 192.168.10.15 then you create a simple server publishing rule to create a 1:1 nat with the protocols you like to forward. IN some cases you can also you the access-rules as well but these work slighly differently in handling protocols and forwarding the connections. Can you tell us the internal and external IPs i.e. what IPs are bound to your external NIC and which to your Internal NIC. Remember these must be on differernt IP subnets. Ash.
-
You need to use server publishing rule to publish your server or internal workstation to the outside world i.e. borough's network. If you are suing the single NIC scenario then you can't use the server publishing rule but if you habe the common LAN (Internal) and WAN (External) connections you should be fine. From reading your question i'm still unsure on what you are trying to achieve. Ash.
-
Which begs the question why on earth did RM have it as 8gb in the first place? This kinds of questions have cropped up so many times on the communities forums. I know RM (because they know they done a boo boo on this) have now made it 12Gb on new installs which is still less for my liking since the HDD sizes now a days are so big so give it 15Gb at the very least. This way people should shouldn't have to restort to using 3rd party tools and if they screw it up RM probably will say its not supported malarky! Ash.
-
Hi, I don't think isa is a crap just becaue its from Microsoft, this forum has got a lot of anti MS people here but lets face it which ever solutions works for the organisation should be the main aim when evaluating or passing judgement on products. We use ISA 2004 on our network with 2000 users and 800+pcs joined to domain and its doing the job very well. This is not to say that another solution would do the job better or worse than this. Ash.
