Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

spc-rocket

Members
  • Posts

    800
  • Joined

  • Last visited

Everything posted by spc-rocket

  1. Hi Geoff, Yes this is great idea, one section for security related issues and news and tips. Ash.
  2. I find that other non exchange emails systems lacks documentation and uses linux or some other open source crap. What do people do when they haven't got skills of linux or unix or other silly OSes. The thing with exchange is that you need to reserch on the solution and play around with it, i think its very flexibile esp. exchange 2003. Ashok.
  3. Hi, Yes you need to restart the BINL servcies if you make changes to the sif file. Also i think you would need to reassociate the file as well, but not too sure about this. Ashok.
  4. Hi all, Here's the script that will install the patch: 'sExePath = "\\admin_server\packages$\XPHotfixes\kb899409.exe" 'sSwitches = "/quiet /norestart" Set oShell = CreateObject("WScript.Shell") sRegKey = "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" ' suppress error in case values does not exist On Error Resume Next ' check for marker sRegMarkerValue = "" ' init value sRegMarkerValue = oShell.RegRead( sRegKey & "\Hotfix899409Installed") On Error Goto 0 ' to be sure update is installed only once, test on marker If sRegMarkerValue <> "yes" Then oShell.Run("\\admin_server\packages$\XPhotfixes\KB899409.exe /quiet /norestart"), 1, True ' create marker oShell.RegWrite sRegKey & "\Hotfix899409Installed", "yes" End If Set oShell = Nothing You need to replace the patch referenced in this code: oShell.Run("\\admin_server\packages$\XPhotfixes\KB899409.exe /quiet /norestart"), 1, True to the path where you patch is located - UNC path will do. The /quiet and /norestart will cause the patch to install silently and will not restart the computer. HTH, Ashok. Credit goes to someone, don't know where i found this script, somewhere from the net.
  5. HI all, We designed a vbscript to deploy the patch via the startup script. The problem we are having is that the script runs when you double-click on it but doesn't work when used as a startup script. Any ideas as to why this may be, i have give the domain computers read and execute access to the hotfix files etc. I'll post the script here on Monday when i'm back at work again. The script first checks to see if the hotfix is installed and if it isn't then it installed it otherwise it just skips it. Ashok.
  6. @Ric_, Probably but i guess i was thinking of our setup. I guess it all depends on how badly a school requires wireless, if it is justified then people should go for it, but if you can get away with it for about a year or year and half then you will get better speed and security with 802.11n when it is released. Another factor with this is that it gives you time to prepare for wireless as well not just from a technical configuration point of view but also from budgeting aspect as well. Stuff like RM CC3 doesn't work very well with wireless and it takes ages to logon and use it effectivitly. We tested these with two APs, but suppose with native windows network it may be a lot better, knowing RM they got all sorts of components that just kills the logon process!. The Bluesocket setup uses the wireless setup as switched wireless where the brain the main appliance and all you got is the dummy APs which doesn't have much config. I do see it wireless going this way because of the centralised management point of view. Ashok.
  7. My advice on wireless is to hold back a bit and wait for the 802.11n standard as this will provide better coverage and security. Of course this is easy said than done when's there manangement pressure etc. At our place we practically advised not to go for wireless as we already have a good wired infrastructure in place, but the management wanted it anyway, but we kepy trying to pursusade them against it. Even with the G standard the speed is still not that good and needs reliability. Hopefully the 802.11n standardised kit will be out by the end of this year or early next year. Most modern laptops have the mini-pci cards installed on them and i'm sure people like intel will develop the N standard wireless cards that fit into the existing laptops so there will be little cost involved but it should be worthwhile in the long run. Ashok.
  8. @sahmeepee Yeah we got few students who likes to plug in their own laptops on the network and also we're trying to tie down the ports from a security point of view. We use all cisco kit here and i'm trying to phase out older switches i.e. 2900xl and 3500xl which sadly don't support 802.1x. enabling the 802.1x on cisco siwtches is not hard, cisco also supports the stacking but i'd like to have them seperate because of the vlan logging and also managing them via AAA authentication. Ashok.
  9. Hi, Yeah i know the clients are actually APs. At our place we are trying to do both the APs and also the switches for (using 802.1x for wired connections) and we already have about 45 switches! and i know we will be drawn into the wireless bandwagon sooner than later i guess. You're right about installing more ias servers, this will solve the problem or alternativily use the enterprise edition - maybe an overkill. Regarding the certificate we tested it using the enterprise CA, so you may be right that if you use the stand-alone CA then it may not copy. Ashok.
  10. @sahmeepee Why would you need to roll out the certificate to the client if they use PEAP (MS-CHAP v2)? If all the clients are joined to the domain then the CA cert will be automatically be copied in the root authority of the client when they join the domain. I do agree with you point about only doing machine authentication, if people require more granular support then i suppose people should do both machine and user authentication. As for the Becta's WPA2 requirement, not all requirements can be fulfilled and i don't really see a reason for deploying WPA2 in school at the moment because WPA is good enough in my opinion. Shame about good old Microsoft supporting on a max of 50 radius clients on standard edition. The enterprise edition doesn't have any limit. Ashok.
  11. Hi, You may want to check out the Allway Sync, its free version is perfectly adequte for synchornising My documents etc. http://allwaysync.com/ Ash.
  12. @Hodgehi, My collegue is still working on the guide at the moment, he's completed the PEAP setup on the client and server, he's documenting the certificate authentication at the moment. The reason why we decided to document both is that the PEAP method is easily the flexible when it comes to deploying wireless but certificate based is more secure. You may want to start off with using PEAP. I personally think its secure enough for schools. I will post the guide here when he's completed it. Ash.
  13. They should take fujitsu out of the equation. Would sort out a lot problems.
  14. You RBC should help you in this and provide you with a smarthost to relay the mail to. You can also do it directly by the DNS method. This requires that whoever manages you domain to setup a mx record setup for you domain. They would create a mx record which would point to an A record which in turns points to your mail server's public ip address. You might want to chase up your RBC and use the smarthost just incase your normal server (DNS) method gets blacklisted, where as your RBC's host will not be blacklisted and even if they are they will be corrected quickly. HTH, Ash.
  15. We are have setup a mini test network for this and have managed to get the WPA access using RADIUS (Windows 2003 IAS). I got my colleague writing the step by step instructions for this at the moment. I will post it here when he's completed it. The guide is intended at setting up a wireless network where clients authenticates using RADIUS. The two things we tested were using the username and password authentication i.e. PEAP and the other was certificates and both worked. It is recommended to do both user and machine authentication to restrict user access and also computer authentication so GPO and startup scripts runs during the bootup. Few things that are required: - 802.1x supplicant support on the client, Windows XP SP1 and over has this already, Windows 2000 Pro - you can download hotfix which enables this functionality, linux,mac - don't know, never used it - Access points which support 802.1x ideally with WPA/TKIP or AES - RADIUS server (Windows server ships with IAS - Certificate Authority (this can be on the same machine as the RADIUS server) - Some time to test the damn thing HTH, Ash.
  16. Hi all, Just wondering if anyone has got an email from Remarc training about providing free microsoft training. Is there any truth in this or is another fancy marketing. Ash,
  17. We had so many problems with EMBC last year that we left their service and went with another supplier. The new connection is brilliant and never goes down and yes they have proper SLAs. We get paid compensation if it goes out of service or SLA drops below 99.5%. The problem with EMBC is that their new connection (10mb) is only to the local concentrator and after that everyone is on it, hence not a 1:1 contention ratio. Ash.
  18. HI Ric, Thanks for the info, but we haven't even got far getting the local station's details. Its running on Windows 2003 SP1 server with MSDE 2000 installed. I got the correct account and the server is part of a domain (member). I'll have a look at the event viewer to see if this shed any light on this. Ash.
  19. One other thing to do is to deplay 802.1x authentication on the switches and then only allow all managed computers. This was no unknown or rouge PCs or devices get on the network either wired or wireless. One requirement of this is that you need switches that support 802.1x authentication and also need to deploy a RADIUS server but this is not a problem, you can use the Microsoft's IAS which comes with Windows Server 2000 or 2003. For the clients you need to use Windows XP or Windows 2000. I'm not linux man so i don't know which linux os (there are so many distributions!!!) that supports this. This solution has another advantage is that not only it stops but you can log it to sql server for all the successfull and failed authentication to find out if anyone is trying to get into your network. To be honest i don't think its too much of an issue to open 443, i mean most corporates have it open for their webmail etc, so we are only working in schools. Ash.
  20. spc-rocket

    Help!

    We got FMS and sims.net installed on the Windows Server 2003 SP1 with TS running. To be honest we didn't have many problems installing the client but its was the usage of it that caused the issue, especially FMS. One thing we encountered was that when a window was open in FMS, it wouldn't allow the user to close the window and complained about unable to write to sims.ini file. This was just the permission issue so just give your TS Users write access to the sims.ini file which is located in C:\windows or C:\windows\system i can't remember exactly where it is. For the install, yes you need run the setup from the string 2005 CD i believe. Another issue we are experiencing is the the personnel module is not working very well and crashes often when using it via TS. I think its the NTVDM.exe that is causing the problem but haven't pinpointed the exact problem. Launcher is installed because our bursar requires access to Personnel module. I hope Capital sorts out the Personnel module and other 16bit and convert them to 32bit and for god sake have everything ins MS SQL server not the sybase crap.!! Ash.
  21. Just wondring what ports the neutex (netpoints) uses, We got it installed but its not displaying or capturing anything. We have setup the schedule but its just doesn't work. We got the windows firewall enabled on the workstations so need to know the ports this software. Just wanted to ask here before emailing their tech support. Any step by step destructions?? TIA, Ash.
  22. I think ISA Server actually looks at the content i.e. HTTPS traffic and then it reconstructs to sent to the appropriate server. SSL bridging scenario. This kinds of facilities are not offered by HW firewall such as PIX etc because they just allow 443 traffic but does not look at the content. ISA Server goes through the content even HTTPS (encrypted) checks for exploits if any then open another separate connection with the actual server and passes the original request. This is assuming the SSL bridging scenario i mentioned. You are correct if you just use the tunnel mode which just lets the HTTPS traffic pass to the relevant server, but you're got to be daft to do in the first place. Ash.
  23. If you have 443 open, you've blown a big hole in your firewall. Making it rather pointless. You can tunnel _ANYTHING_ over HTTPS. __________________________________________________________ Don't agree with this at all, if you have all the firewall rules in place and all IDS then there not much that can get in. ISA Server is a good example of this, you can securely publish OWA (Outlook web access) and still have the protection. Dumn HW firewall are useless in modern times and simple port block is not enough. You need to really look at the content that is going through by using stateful packet filtering firewall like ISA. With ISA you specify signitures and User Agent- strings to only allow the things you want and cut our the junk. Ashok.
  24. Ric, What company do you get the licenses from?, we're looking at getting TS client licenses and have been quoted at around £15-18 from Ramesys. These were for TS User Licenses. TIA, Ash.
  25. ICTNUT, £7,200 for 10mb leased line is not a bad price!. It states that this is the "from" range so this may be their starting price but still not bad. I agree with whoever said that 10mb is only to the local concentrator or proxy when it comes to LEA's solution, and yes it does appear that they are marketing it like this to get people onboard.
×
×
  • Create New...