Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

spc-rocket

Members
  • Posts

    800
  • Joined

  • Last visited

Everything posted by spc-rocket

  1. Hi Russ, yes this would be good. I'll have a chat with the guys here to see if they are interested. Ash.
  2. HI, Not sure about the stress testing the network but this utility may be handy in troubleshooting network connections etc. You can do some testing by increasing the data size etc. Above all its free! http://www.ixiacom.com/products/performance_applications/pa_display.php?skey=qcheck Ash.
  3. @ICTNUT, I would seriously consider a Layer 3 switch to do the routing rather than the cisco router because layer 3 switch does HW routing (ASIC based) rather than software which is slower. I would advise you use something like the Catalyst 3550 or even better Catalyst 3750 series switches. You mentioned the IP helper command, the way it works it that when the switch recieves a request for an IP it then converts it to a unicast packet and sends it to the DHCP server's VLAN and the DHCP server will think its come from its own vlan but the gateway address is different and hence it will pick the correct scope to get an ip from and deliver it to the layer 3 switch which will forward it to the correct client on the correct vlan. you will not need to run any routing protocols as well this way becvause the layer 3 switch will have the routes available to all vlans unless you put an ACL to deny traffic from one vlan to another say. HTH, Ash.
  4. I Think exchange keeps the badmail somewhere on on the C drive or whatever partition you installed exchanged to. You can probably redirect your bad-mail to a particular mailbox, sorry i don't know how to do this. Google it to see if any one has done this. Ash.
  5. Hi, Yes this would be useful. Thanks! Ash.
  6. Hi, I believe the intel pro set software (now accessible using the device manager) also supports other network cards as well, but it needs to be all running on the same speed i believe. If the Adaptive Load Balacing is selected as the load balance option then this does work with any swictches and does not require the 802.3ad (aggregation or LACP). Other modes will require the switch to support the 802.3ad i.e. if using the LACP or PAgP. In all cases you need to download the pro-set software in order to create the team. Essentially what this will do is it will create three adpaters in Network Connections section where (if using two physical adapters and teaming them) 2 will be the physical interfaces and a third connection will be the team connection. It is the third i.e. the Team connection that you will be assigning the IP address on and not the the physical connections. We have been using this for the past 3 year with the exact cards Intel Pro/1000 MT Dual port server adapters and never had any problems. We are using cisco switches. Ash.
  7. Hi Guys, I forgot to include the salary details, it is as Russ has pointed out. £16,521 - 17,985 pay award pending. I don't know about the transfer from another LEAs but the minimum will be £16,521. Let me know if your guys need any more info. Staff Heirachy: 1 x Network Manager, 1 x soon to be Senior ICT Tech, 1 x Technician, and 1 more technician to recuit (i.e. this advert). Total staff: 4 inc. Network manager. Ash.
  8. Hi All, We have a IT Technician vacancy at our place. Full details here: --> http://www.ashbyschool.org.uk/vacancies/20070613_IT_Technician_spec.pdf Ash.
  9. Hi, What i would do is decrease the lease time on the existing scope to say 1 hour and then do deploy a startup script that will release and renew the ip address on the fly. The purpose of doing this is all the clients will then need to renew the IP address as it will be within their 50% of the lease time so when you setup a new scope and activate it the clients will try to get the IP address from the new scope(s). Otherwise what you may find is that client sticks to their old IP address because of the lease period is not within the 50% when they usually try to renew it. I woudl create the new scope and set all the options up but don't activate it. When all the clients are booted up and the start-up script has run, deactivate the old scope and activate the new scope. There might be more eligant ways of doing it but this has worked for us. Also you may find that some clients will stick to their IP even after renewal, if this is the case set that client on any static IP address and commit it and then set it back to obtain ip from DHCP and it should pick up the ip address from the correct scope. HTH, Ash.
  10. This can be done by selecting a LEA assigned IP to the external NIC of the isa server and just using the server publishing rule to create the reverse NAT to the correct IP i.e. if you lea is using 172.10.30.5 to dial into say one of your server which on the internal range is 192.168.10.5 then you can use the method i stated above to do this. Its a just a matter of configuring a NAT routing relationship between the Internal and External networks. Ash.
  11. We got freenas setup on a old box with a bog standard 40gb HDD to test and everything seems to be working except AD authentication. We can't get this to work for some reason. Also looking at the share permissions it seems that you can do read-only permission its either read-write or nothing at all which seems a bit silly to me. We are using the latest version with celeron 733MHZ and 256mb RAM (don't ask can't find a box with more up to date HW) Ash.
  12. Tosca, Its best to give them a call and tell them of your requirement and you budget and they will work something out. I have been on a course and all i have praises for the instructor (Alan Hutt) great guy and excellent instructor. Ash.
  13. Thanks MattX, I give it try and see what happens, if it works out then we just do a HW raid with a simple SATA controller to make it easier on the processing side as SW raid is good but resource intensive. Ash.
  14. @MattX, How does it handle AD authentication, the docs say its does support it but as with the terastation is it flakey or does the job well? I'll try out the latest beta and see what happens. Thanks for the info. Ash.
  15. Hi Guys, I've looked at the freenas and it looks good and want to try it out on a spare machine. How do you go about installing in an easiest possible manner. Not clued up on Linux too much so looking for a step-by-step instructions if possible. BTW i have downloaded the iso file from their website. Am I correct in that i should burn this to a CD and install it on the machine?? TIA, Ash.
  16. Our webfilter (surfcontrol) blocked as its listed under proxies and translator category which is banned for students. Ash.
  17. Google chat can be blocked at your proxy server we have an ISA 2004 server and on the hosts file on the isa server we use the following: chatenabled.mail.google.com 127.0.0.1 You will find that chat is now disabled because it using the loopback interface of the proxy server and will use DNS if it can't find it on the host file. This also disables the chat facility within google mail as well. Google mail should work fine but chat will be disabled. It should work for any proxy server, just need to make it look to the local loopback or any other ip address and not the ip address of the proper google chat servers. Google talk is interesting as it uses random UDP ports so that may be tricky, again with isa server it can be blocked by looking at the signature or HTTP header. Ash.
  18. Hi Andy, I would have thought that this is the issue with sql server not TS box. So in a multi-user network enviornment at school it would be the same issue. I thik the SQL server supports Strict two-phase locking and non-strict two phase locking as well as Update Lock etc so it takes care of issues of two exact records being update/modified at the same time be different users. If this functionality is not utilised by capita developers then its their fault really! cos they should be doing this to prevent this kinds of things happening. We use the full SQL server 2000 with our sims system and have never had a problem. I will however inform our local support people at LEA to see what they say and if they have heard of this problem. Ash.
  19. Hi Adam, Check out the link translation options in your web publishing rule. This will allow you to translate your links and may help you correct this issue. Ash.
  20. Th 802.11n draft 2.0 has just been agreed by IEEE members and the final draft should be completed in June 2008 so i would start planning but would not roll our N just yet. Wait till the later this year and if you are keen then buy the n kit as they will be able to be upgraded to full version when its ratified. I would also suggest that you buy the access points which support Gb uplink as opposed to 100mb because N standard does have a higher throughput than the rest otherwise the bottleneck may be the wired connection from AP to the Switch. Geoff is correct you need 802.11n compliant NICs to take full advantage and also it may be bit flakey to run it in backward compatibility mode. This is the kind of stuff i read on the net. I don't know if the NICs will be the mini-nics that you can swap out on existing laptops like the Intel 2200BG one. Intel may come out with the N standard one some time but its too early to tell. Ash.
  21. Webman, Yeah that's fine one you taken the image but when the new Service Pack arrives and it states you must rebuid all stations, it becomes a big problem, i'm comparing the process to something like Ghost or RIS, which we have on our admin network (vanilla network) and the station is build with all the apps etc. 34 mins flat even if you are building 50 stations at once from one server. I don't like to buy RM HW because its expensive so you need to add the third-party drivers which is fine and this works okay, until you apply one of their HSP which not only breaks the building on RM machines but also others as well. Also RM still can't explain why WKs goes into this reboot cycle and the only thing to do is to do a rebuild, which can't be done remotely because in order to this the station must be switched on and windows loaded (i think it then reboots automatically and carries on with the rebiuld process). However because of the reboot cycle of BSOD it doesn't reach the loading windows stage. I have been quoted £5000 (2 x 2500) to migrate 2 x DCs to new HW. So all i'm getting is the migration, because the £5000 does not include the cost of the servers!!. How can we pay £5000 for DC migration - this is the kinds of things that get me, why on earth does it cost £5000 for 2 domain controller migration. - You got me started on this now
  22. Hi All, My big problem with RM is the cost of the license, they just would not provide any details on what makes up a CC3 license. I would like to see the license debunked so people can choose the things they actually utilise on their network. We can all work out few itesm that may be included like CAL for server, RM tutor, VCD etc. but my point is that what if the school does not use VCDs or RM Tutor (such an awful title with the silly RM badge on it - come on give credits to the real developers (Net Support manager) not the guys in Abingdon) They are charging us all for things we don't utilise. I have written to RM about this and have consulted with my account manager (who sadly has left the company) but i haven't got any definative answer on the CC3 Client Access License. Server CAL = £1.xx from Ramesys Server 2003 Standard Edition - £49.xx from Ramesys Windows XP Licenses - comes with the new PCs you buy I think all people who have vanilla network have a higher skills set in their team to manage and improve the network. For smaller schools the RM solution works but that's about it, its doesn't scale very well with larger schools and its get time consuming building workstations that take 2-3 hours to build. This is another fustrating thing about RM - the build process is rubbish. This might change with CC4 but then again that's probably credit to Microsoft for bringing out new deployment technology and not RM who just uses this and charges schools for the priviliage. The solutions they bring out to make life easier doesn really work and that's evident of the number of peopel fustrated on the RM Communities forum. Tools such as RM Station Tidy, Local Support Tools etc don't deliver and oftern the system admins will use free or paid third-party tools to get the facility i.e. WOL. That's enough of the rant for today.
  23. network.http.proxy.pipelining Make it false which it should be by default network.http.proxy.version - this is probably set to 1.1
  24. Hi, Sorry if this sounds strange but why are you interested in deploying vista to their home PC? I would just give them Windows XP Pro which is more than enough even to run Office 2007. I just think people need to sit down and really think before jumping on the bandwagon of the latest stuff. Don't get me wrong i'm all for new OS etc but when planned correctly and the product has matured to at least SP1 level. Two things i don't really get at the moment, people upgrading to vista and office 2007 niether is honestly required in schools. There is nothing that Windows 2003 Server + Windows XP Pro SP2 and Office 2003 Pro can't do that the latest incarnation of MS OS does. I don't think MS will drop support for Windows XP yet - remember they extended Windows 98 support even after they ended so it'll be a similar thing that happens to XP. From a PC purchase wise yes its worth getting stations that are powerful enough to run vista as you would consider the lifecycle of the PC and in 2 years time you may upgrade to vista but it too early in my opinion. At our place the scheduled upgrade to vista is summer 2009!!. Ash.
  25. Norphy you beat me to it, i was going to mention the 2x application server and its something we are looking at our place at the moment. Its excellent software and it publishes the applications seamlessely so to the user it appears as though the application is running on the local machine but of course it isn't, its running on TS. 2X Application server provides the similar stuff to what Longhorn server will provide with its TS Gateway product but this is available now. I've enquired aboyut the licensing and found that 10 user license only cost 395 euros and there is a 20% discounts for public sector on top of this so its not a bank breaker as well. The wonderful thing about this is that you can use SSL connection between the client and the gateway/TS servers so only need to open up port 443 on the firewall. You can also configure it to run on 80 or direct mode. Its something that I will be making it available to SLT now that we've completed the testing of it. Ash.
×
×
  • Create New...