Jump to content

stanwell

Members
  • Posts

    37
  • Joined

  • Last visited

Everything posted by stanwell

  1. Just a quick update to say that worked.
  2. No we don't have anything specifically restricting Program Files. I was just referring to default permissions and UAC. I've done a bit more testing and I'm hoping I may have found the problem. The stack trace I posted above references various interop methods for the Windows clipboard, so I started thinking about what else may be accessing the clipboard on those PCs. We have Veyon classroom management software installed in that room which uses UltraVNC. As you probably know, VNC is able to sync the host clipboard with a remote client so I tried disabling the Veyon service and was able to open Secure Client several times in a row without it crashing. I've only tried this on one PC so far but hopefully that's the answer. I'll try some more in the morning and see how I get on. Thanks for the help, I'll let you know what happens.
  3. I've just installed it in Program Files (x86) and still get the same crash if I run it as an admin. If I run without elevation I get an update loop due to the write protection on Program Files.
  4. In response to dfergusson: Thanks, I've done that too. The full error message looks like the issue occurs when they try to clear the clipboard: Application: Surpass Secure Client.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.Runtime.InteropServices.ExternalException at System.Windows.Forms.Clipboard.ThrowIfFailed(Int32) at System.Windows.Forms.Clipboard.SetDataObject(System.Object, Boolean, Int32, Int32) at System.Windows.Forms.Clipboard.SetText(System.String, System.Windows.Forms.TextDataFormat) at System.Windows.Forms.Clipboard.SetText(System.String) at BTL.Surpass.SecureClient.Clipboard+<>c.() at BTL.Surpass.SecureClient.Clipboard.(System.Action) at BTL.Surpass.SecureClient.Clipboard.ClearClipboardText() at BTL.Surpass.SecureClient.Clipboard+<>c.() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart()
  5. I've installed it in the default location "C:\Users\Public\Surpass\SecureClient_WJEC". The local users group has write access, but it crashes when logged on as a domain admin too, so I don't think it's permissions.
  6. Hi, I'm just wondering if anybody else is having this issue with Surpass Secure Client and if anybody has found a solution. When we open the software it immediately crashes (most times). The screen flashes white (I.e. the background of the Surpass app) and it just closes with no error messages etc. on screen. This doesn't happen every single time, but it does happen a lot. The Windows application log shows a .Net Framework error (see below). I've been speaking to WJEC who are communicating with the developers and so far they've just told me that it's because we don't have .Net v4.7.2 installed. However, we're running Win 10 22H2 which already has .Net v4.8 which is backwards compatible and it won't allow us to install an older version. I've sent the screenshot below (along with logs etc.) to WJEC/Surpass and I'm waiting for a response, just wondering if this is only affecting us? We've been fighting with this software for the last few weeks, but we have an exam on the 11th so I'm getting concerned. Even if we can get the software to launch, it doesn't fill me with confidence that it will be stable throughout the exam. Thanks, Dan
  7. Hi, Our network is running Windows and macOS clients all of which are joined to Active Directory. The Macs are all running Windows via Bootcamp. We were having issues which were being caused by our macOS clients because they were not registering PTR records. We were also having issues with stale records. I spent a lot of time researching DNS and DHCP configuration to try to resolve these problems and ended up thinking I had solved it with the following configuration. But I have now realised that we still have problems which I will explain after the configuration. Servers 2 x Windows Server 2016 VM's Both Domain Controlers Both running DNS Both running DHCP DHCP Config Failover mode: Load balance Enable DNS dynamic updates: Always dynamically update DNS records Discard A and PTR records when lease is deleted: Enabled Dynamically update DNS records for DHCP clients that do not request updates: Enabled Disable dynamic updates for DNS PTR Records: Disabled DHCP name protection: Disabled Lease duration: 2 days Dynamic DNS credentials are configured. Account is only a Domain User DNS Config Active Directory Integrated Zones Dynamic updates: Secure only Replication: All domain controllers in this domain No-refresh interval: 1 days Refresh interval: 1 days Scavenging period: 3 days Group Policy Computer\Administrative Templates\Network\DNS Client\Dynamic update: Set to Disabled Current Problems My aim was to get the DHCP servers to handle all DNS registration to solve the problem of macOS not registering PTR records. The PTR records are now being created but it looks like the macs are still creating their own A records as the permissions list the client instead of the DNS registration user. The macs obviously use the same ethernet or wireless card in macOS and Windows so the MAC address won't change. I assume when each OS requests an IP it will be given the same IP due to the MAC address and the DHCP server will update the client name. I'm not sure about DNS though; Will the DHCP server create a new A record because the client name is different? resulting in duplicate records for a single IP; OR will the the DHCP server try to change the client name on the A record with the matching IP in which case it will fail if the mac has already registered its own record. I don't know if/how I can tell the mac to let the DHCP server register the records for it (Our mac technician decided to pursue a different career path leaving us Windows tech's scratching our heads ). The second problem I'm having is that for some reason even the Windows clients aren't always registering correctly. I have a Windows only device which has received an IP from DHCP but has no A or PTR records. This device is affected by the Group Policy mentioned above, so it would be relying on the DHCP server to register the records for it. But I can't see anything in the DHCP-Server or DNS-Server logs in Event Viewer on the our servers which relate to this client name. The third problem, albeit minor is that any clients with statically assigned IP's don't register in DNS due to the setting in Group Policy. There are only a handful of these and we occasionally assign IP's temporarily for various tasks (as DHCP clients require proxy for Internet) If I have missed any important information please ask. Any help would be greatly appreciated.
  8. I was told it doesn't work in IE but when I tried it myself (logged on with the same privileges as a member of teaching staff) it worked fine :S
  9. Hi, We have exactly the same problem as you and we are also using Smoothwall. I've noticed in the real-time web filter report that some of the URL's for Bright Cove are showing multiple 407 responses (see below) so it could be caused by authentication not working for those domains. Creating an authentication exception for brightcove.com may solve the problem. I'm going to do some testing, I'll let you know what I find. 08:22:59 407 https://secure.brightcove.com Audio and Video, Staff allowed content 08:22:59 407 https://f1.media.brightcove.com Audio and Video, Staff allowed content 08:22:59 407 https://secure.brightcove.com Audio and Video, Staff allowed content 08:22:59 407 https://secure.brightcove.com Audio and Video, Staff allowed content 08:22:59 407 https://f1.media.brightcove.com Audio and Video, Staff allowed content 08:22:59 407 https://f1.media.brightcove.com Audio and Video, Staff allowed content EDIT: Shortly after posting this the videos started working again before I could start testing. So maybe Bright Cove have undone what ever changed. Has it started working for you? GCSE Pod also gave me this list of URL's which they recommend whitelisting: *gcsepod.com *.brightcove.com *.sharethis.com *.analytics.edgekey.net *.cloudfront.net *.jquery.com *.newrelic.com *.google-analytics.com *.googleapis.com *.akamaihd.net *.akafms.net *.llnwd.net *.llnw.net *.brightcove.net
  10. Hi psydii, Sorry for the delayed reply, I was on training yesterday so wasn't able to get on here. Very interesting that you had the same printer! They are on the same Ethernet broadcast domain, but it appears that the Meru controller is responding to the ARP request for the printer rather than the other way round. Thanks, Dan
  11. Hi, We have 2 Brother HL-6050DN printers both connected to the network via Ethernet. One of the two printers suddenly stopped working back in November. You couldn't access its web interface, couldn't get a ping response and couldn't print to it. We started with all the usual troubleshooting for connectivity problems, but happened to notice that when you ping the printer instead of getting the expected response e.g. "Response from {Local IP}: Destination host unreachable." we were getting this: Pinging {Printer IP} with 32 bytes of data: Reply from {Printer IP}: bytes=32 time=3ms TTL=60 Reply from {Meru Controller IP}: Destination host unreachable. Reply from {Meru Controller IP}: Destination host unreachable. Reply from {Meru Controller IP}: Destination host unreachable. Ping statistics for {Printer IP}: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss) Every time you ping the printer you get one response and then the Meru WiFi controller responds with "Destination host unreachable". If I check my ARP cache I see the MAC address of the Meru WiFi controller for the printer's IP address. I contacted Meru support who asked me to send them some logs. I was told that the Meru controller has an ARP proxy feature but they were confused why it was responding for the IP of the printer (which is wired, not wireless) and were going to look into it further. Meanwhile we couldn't leave the printer out of action and got it working by changing its IP. As a test we then went to the second printer and temporarily put the "broken" IP address on it; It instantly stopped working with the same symptoms. For the next 3 weeks we carried on as normal and totally forgot about the problem. Then all of a sudden both of the printers stopped working again with the same symptoms. Meru support did some more investigating and eventually said that the IP addresses of the printers were being registered with the controller from the wireless interface (I.e. for a wireless client, not a wired client) meaning another client must be using the printers IP. They did mention that the controller should be flushing its arp cache to remove any invalid entries which it wasn't doing. They manually deleted the entries to get the printers working again for now. To give you a bit of background information; Our network used to be entirely DHCP with the exception of one small scope for servers, switches, pritners and iPads etc. Due to a requirement for a configuration we wanted with a previous web filter we then split the network into DHCP and static addresses. The 2 printers in question had their IP addresses changed so they were using one of the new static IP's. We have now recently changed our web filter and decided to go back to DHCP. As a temporary solution we left the printers on the same IP's and then created DHCP reserves for them (even though they are still statically addressed) to stop anything else using their IPs. One of the printers stopped working again yesterday morning. As usual we pinged the printer but this time got: Pinging {Printer IP} with 32 bytes of data: Reply from {Printer IP}: bytes=32 time=3ms TTL=60 Request timed out. Request timed out. Request timed out. Ping statistics for {Printer IP}: Packets: Sent = 4, Received = 1, Lost = 3 (75% loss) So I'm not sure if Meru have changed anything to stop the controller replying. Based on Meru suggesting a wireless client is using the same IP we then looked at the associated devices list on the Meru controller and actually found a client with the printers IP. The MAC address of the client told us that it was an apple device, and the associated AP told us roughly where in the school the device was. So thinking there was a problem with the DHCP reservation or something we checked all of the Mac Books and Apple TV's in that area but couldn't find anything with the MAC address we were looking for. This morning we noticed the MAC address was using a static IP which belongs to a staff iPad. We have checked the iPad and it's configured with a static IP; The teacher said the Internet stopped working on it yesterday (our DCHP addresses don't have direct internet access) but he hasn't changed any settings. So we are now confused why an iPad which has a static IP would suddenly decide one day to use a DHCP address (more importantly a reserved DHCP address) and then the next day go back to static. When you switch between static and DHCP the iPad forgets all of the static IP address settings, so the teacher would have had to re-enter them if he had changed it and he said he didn't. We're also confused why it only appears to be happening to the IP addresses used by these two identical printers and to our knowledge nothing else. Any help would be greatly appreciated.
  12. Problem solved by setting VLAN 1 and 2 to untagged. I also decided to move VLAN 3 on to a separate interface.
  13. Hi, We have just moved our Internet connection from our LEA to Virgin Media but have encountered a problem. When we connect our network to Virgin Media's co-managed firewall (which is on site), the firewall reports a lot of errors on the 3 interfaces connected to our network but 0 errors on the interface connected to their router. We have connected a laptop direct to the firewall (in its own VLAN) and there are no errors. We've changed the patch leads, disconnected everything else from the switch (just leaving the firewall and laptop connected to it) and plugged the laptop and firewall into a different switch but cannot work out what is causing the errors. Virgin Media are saying that their firewall is configured correctly and because the direct connection to the laptop works without errors it must be our network. We have also tried turning off auto negotiation and setting the ports to 100Mbps Full Duplex which didn't seem to make a difference. We want to keep the ports running at 1Gbps however as our Internet connection is 200Mbps (The Netgear switch won't let us force 1000Mbps Full Duplex). The firewall is a Palo Alto PA2020, our switch is a Netgear GSM7328S v2 (Layer 3) and we have a Meru MC1500 wireless controller. We have 4 VLANS (lets just call them 1, 2, 3 and 4 to make it easier). Firewall Port: 2 Switch Port: 1 VLAN Membership: 1/T, 3/T PVID: 1 Firewall Port: 3 Switch Port: 2 VLAN Membership: 2/T PVID: 2 Firewall Port: 4 MERU Port: 3 VLAN Membership: 4/T PVID: 4 The only configurations I have made on our switch is its IP, NTP, IGMP Snooping + Querier, 1 x LAG and VLANS + Memberships. Routing is disabled and so is STP. Any help/suggestions would be greatly appreciated. Thanks in advance, Dan
  14. Hi, I have created an XP image with a single partition on a virtual machine. I then capture that image and deploy it to Dell systems using MDT. I have configured the "Format and Partition Disk" section in my task sequence as follows: Disk number: 0 Disk type: Standard (MBR) System (Primary) 50% of remaining space on disk. NTFS file system. Data (Extended) 100% of remaining space on disk. The Dell systems have 250GB hard drives. The task sequence is creating the primary partition with 100% disk space instead of 50%. Then when I open Disk Management on the deployed machine it shows an additional 100GB (approx) partition with no drive letter assigned and tells me that the drive is 350GB. If I delete this partition it then realises that the drive is only 250GB... Thanks in advance, Dan
  15. I think I've finally solved it! It appears to have been caused by Authenticode Settings which had been left in an old policy. According to the description the Authenticode Settings only work with IE 6. Thanks for the help, Dan
  16. Hi, I know that after giving a user full access to another mailbox they can right click their name in OWA and click Open Other User's Inbox. That Inbox then stays open on their OWA each time they log in unless they decide to remove it. My account has full access to all mailboxes. What I want to do is authenticate as myself against another users mailbox and then open a generic mailbox on their account for them so that the next time they log in it will already be there for them. Does that make sense? E.g. 3 Mailboxes. Myself, Joe Bloggs, and Generic. Open http://webmail.domain.com/owa/[email protected] but authenticate as Myself (which has access to all mailboxes) Right click on Joe Bloggs' name in the left pane (above Inbox) and click Open Other User's Inbox Open Generic mailbox. Next time Joe Bloggs logs in he sees the Generic mailbox already open as well as his own. The problem is when I authenticate as myself on Joe Bloggs' mailbox the Open Other User's Inbox option is disabled. (It's there, you just can't click it) Is there a way to either enable the option for me or maybe use PowerShell to open/link the generic mailbox to his OWA? I know it seems odd, why cant I just tell Joe Bloggs to right click his name etc etc. But there is method to my madness! Thanks in advance, Dan
  17. Sorry for leaving this post so long. The last couple of weeks have been so busy I just haven't had time to sit down and work on this problem. Today I was told about a machine which has been running on the network with no problems for a long time, which has suddenly started rebooting when somebody tries to log in. It appears to have exactly the same issue as we are having with clean images. So I enabled logging etc and found that "Internet Explorer Branding" was the problem; It's throwing a 0xc0000005 error. Whilst trying various things I had the same error several times. I then created an OU with blocked inheritance, manually linked all of our policies except for the one containing our proxy settings and moved one test user into that OU. I then managed to log in to that account with no problems. So I logged out and just to confirm, I logged in with another user which has the proxy policy applied and all of a sudden the same error occurred but in a different place! This time it was in shortcut preferences! I've attached part of the two logs here: Winlogon Snippets.txt Thanks, Dan
  18. Dr Watson has finally caught something: DrWatson.txt I will carry on with this on Monday. Thanks, Dan
  19. It appears to be "Always wait for the network at computer startup and logon" which is causing the problem. Which kind of makes sense as I said in my first post, one of the machines hung for about 17 hours at applying personal settings. But now the question is what is crashing or hanging all the time? I feel like I'm back at square one... All I've managed to do is verify that something it's waiting for is hanging or crashing, duh... I already knew that! So I'm back to looking for a needle in a hay stack, any more ideas? Thanks, Dan
  20. Thanks for your reply. My CD already has SP3, I didn't slipstream it though I downloaded it as an ISO from the Microsoft Volume Licensing website. My CD isn't scratched, I burned it specifically for building these machines to make sure I didn't have a bad disc. It's definitely a VLK version of XP and not a standard disc and i do have enough licenses for the network. I mentioned the GINA DLL because I was instructed to check the registry key you have mentioned from the TechNet article posted by kmount. But the key doesn't exist anyway. As for the antivirus, I can try that but I think I might be making "some" progress at the moment. Progress update: I logged in a user and watched the machine BSOD and reboot. I then moved that user along with 3 others into the OU I created with blocked inheritance and logged in again. All 4 of the accounts logged in perfectly without any errors. So I moved 2 of the accounts back to their original OU's and logged them back in and once again I had a BSOD. So it definitely has something to do with a user policy. As mentioned in my last post I have just installed XP using the same CD on a third machine (also an Optiplex 790) and installed the Ethernet driver but NOTHING else. Put it on the domain and logged in some users (which have their normal policies) and they all logged in without any problems... So all I can think of is that there must be a policy which is conflicting with a driver/software/update. So I'm now going to attempt to narrow down the user policies and see if I can find the one which is causing the problem. Thanks, Dan
  21. Thanks for the reply. Following the instructions you linked I have enabled Dr Watson but it doesn't catch anything on both machines. I've checked the registry key to see if there is a third party GINA DLL and the key doesn't exist so it's using the default DLL. I've tried last known good configuration and that doesn't fix anything either. I've also run sfc /scannow and that made no difference. I just created a new OU and blocked inheritance in group policy, so they're not loading any policies and they still have the problem. I'm going to get a third machine, install XP SP3 from the CD again and put it straight on the domain with no updates or software and see what happens.
  22. Hi, I have had this problem for a couple of months and its driving me mad. All of our existing machines appear to be running fine on the network but every time I build a new machine it hangs or BSOD's at "Applying your personal settings". I have had this problem on at least 2 different models of PC, possibly 4 (I can't remember now) - Optiplex 760, Optiplex 790 and also possibly on Optiplex 740 and Optiplex 780 (All of our PC's are Dell). But I have the same models working fine on the network, it's only when I try to install/re-install XP. So forgetting everything that I've done in the last couple of months to try fix it because I can't remember everything, here's what's happened in the last two days. I did the following steps on both of the Optiplex 790's at the same time. 1) Set up two Dell Optiplex 790's and installed XP Pro SP3 (using an ISO I downloaded from Microsoft Volume Licensing site). 2) Installed all of the latest drivers (from Dell's website using service tag) except for one of the chipset and the graphics drivers as they needed .NET Framework first. I also upgraded the BIOS at the same time. 3) Installed all available Windows Updates (excluding PowerShell, Windows Search, Browser Choice and Security Essentials or what ever it's called) 4) Installed last two drivers (mentioned in step 2) 6) Formatted D: drive. 5) Installed Adobe Flash Player, Reader and Shockwave from their website. 6) Installed Microsoft Office 2007 Enterprise from CD. 7) Installed Microsoft Updates and installed all of the updates available for Office along with Silverlight 8) Installed a driver from Microsoft Updates. I can't remember the exact name but it was something to do with Intel SOL. (I can probably check the update history if I need to get the name) 9) Installed Adobe CS5 Web Premium from CD. 10) Installed Adobe Acrobat 9 from CD. 11) Joined the computer to our domain and left both machines in the default "Computers" container in AD. 12) Logged in as the domain Administrator account. - At "Applying your personal settings" one machine rebooted (Probably a BSOD but they are set to reboot instead of displaying it by default) and the other just sat on that screen doing nothing for about 17 hours. 13) Logged in as the local Administrator account and enabled UserEnv logging and Winlogon logging, then rebooted. 14) Logged in as domain Administrator account and both machines logged in successfully... :@ 15) Logged out and logged in using my own account (Domain Admins & Administrators). Both machines rebooted. At this point I started using just one of the machines 16) Booted with it set to display any BSOD's instead of rebooting. 17) Logged in with my account and got a BSOD (0xC000021A) 18) Booted the same machine and used msconfig to disable all startup programs (then rebooted). 19) Logged in with my account and this time at "Applying your personal settings" I got a winlogon.exe error saying "The instruction at 0x7c911766 referenced memory at something. The memory could not be read". - When I clicked OK the PC rebooted obviously because winlogon was terminated. 20) On same machine logged in as local Administrator account again. 21) Used msconfig to disable all Non-Microsoft services and rebooted. 22) Logged on with my account and it rebooted again at the same place... As you can see these are clean installs of XP there is no imaging involved and they should only be loading our default policy which is linked to the domain and contains things like password expiry and "Always wait for the network at computer startup and logon". When I originally started having the problem I'm sure I remember that if you managed to get an account to log in by repeatedly deleting the local profile and logging back in until it worked, that account would always be able to log in to that machine in future (or so it appeared). So maybe it could be something to do with generating the user profiles. That's all I can remember right now, may think of other things later. If you need more information just ask Thanks in advance, Dan
  23. Thank you for your reply. I tried your suggestion but I still got the same error. I have just found the solution however, so for anyone else having the same problem here was the solution that worked for me: PXE-E55: ProxyDHCP: No reply to request on port 4011 Just in case it is ever removed from technet: Hope this helps somebody else. Dan
  24. Hi, Sorry if this is long, but I'm trying to give as much information as possible. I set up WDS and MDT using LiteTouch following the instructions here: MDT 2010 Setup Step by Step Part 1 - SharePointEduTechSharePointEduTech My setup is: server1(DC, DNS, DHCP), server2(DC, DNS, DHCP), server3(DC, WDS, MDT, WAIK + SP1 Supplement) I then imported a WinXP SP3 CD and configured a basic task sequence (No drivers, no applications, just XP). I then run a test using a Dell Optiplex 780 (not using any boot media, just telling the PC to boot from NIC) and everything worked fine until it got to the Windows desktop and failed because there was no NIC driver installed So I then imported a NIC driver and run the test again. This time it worked perfectly. Next I started to change the customsettings.ini and boostrap.ini to reduce the amount screens in the wizard. I restarted the PC several times (I had to stop the multicast transmission in WDS each time or it would continue with the last session) and repeatedly booted the LiteTouch interface to test my changes and at first my changes weren't working. The main thing I wanted to remove was the prompt for deployment share credentials. After some searching I found out that I had to replace the boot image in WDS with the updated file. After doing that all my changes worked. Now that I was happy with the wizard etc, I decided to import the rest of the drivers for the Optiplex 780, change the customsettings.ini to show the applications screen in the wizard and to use our WSUS server for Windows Updates. I also added a task sequence variable to only install drivers from a specific folder "Windows XP\%model%". This is everything I remember doing. I then updated the deployment share (completely regenerated boot files) but forgot to replace the boot file in WDS. This time when I went to boot from NIC I got the following message: I then replaced the boot file in WDS and tried again, but I still get the same error. I've searched for this message and see lots of people talking about DHCP options 60, 66 and 67 causing the problem but I don't have any of these set. The fact that it worked originally makes me think I don't need them set? At the moment my scope options are 3,6,15,252 and my server options are 6,15. Thanks in Advance, Dan
  25. Thanks for the reply. I disabled delegate access and then reset iis but it didn't remove the options Thanks anyway, Dan
×
×
  • Create New...