-
Posts
5,084 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Koldov
-
Walking the dogs through the 'neighborhood' through the dark winter evenings is always interesting, seeing what everyone is watching on telly... Not from just from an energy saving perspective, but for privacy I'm not sure everyone understands that most net curtains are see through when it's light inside and dark outside...
-
3 bed house here, gas combi-boiler central heating to radiators: January - Thermostat at 18c 24/7 - 1268kWh. February - Thermostat at 18c morning (2 hrs) and evening (5 hrs), 17c during the day and overnight , 1164kWh. @PotNoodleTech How old is your boiler? Was it you that was saying about lots of outside walls and are you top flat? Is it a block of flats or converted house?
-
Unfortunately until we get the correct ventilation in the house (trickle vents etc.), we leave our curtains open day and night to combat terrible condensation. Sounds strange but saw it on a Youtube video about damp and tried it, the difference was amazing due to air flow. Curtains closed overnight and the windows were full of condensation (top to bottom and pooling on the windows sill) in the morning, leave them open and just an inch at the bottom, sometimes nothing...
-
Long story... (as short as I possibly can): TL;DR Do firewall rules set by GPO overwrite or are they cumulative..? Short answer so far in my testing/research: Cumulative if they are in the same OU. Overwrite if they are from different OUs (in whatever precedence they have). How to have 2 RDP firewall rules in separate OUs with different settings apply to one machine? Long story... (as long as I possibly can): I have a VM and for reasons too long (and possibly irrelevant) to go into in this post, I have been running it with the firewall off (I know). Anyway, it niggled me so I turned it on and waited for the fallout (bearing in mind it runs WSUS and a print server)... but it never came. Fast forward 2 weeks down the line and I'd forgotten all about it when the Headteacher walks in to my office and said he couldn't get on SIMS (as he uses a MAC I put Microsoft Remote Desktop on and pointed it to a VM - yes this VM as it has a SIMS client on it - limited VMs available). It stumped me for a while and then I remembered I'd turned the firewall on! Quick fix I turned the firewall off and RDP on the MAC connected... turned it back on and nada... That's OK I thought, I'll just poke a hole in the firewall for his I.P. with a GPO for RDP... but as soon as I applied it my RDP session ended. I have a GPO applied for the Domain with RDP settings for the firewall, set to my work PC I.P. and a another range for something else, but as soon as I apply this other GPO just to the VM (in a separate OU) it overwrites my Domain GPO settings. I don't want to add the MAC I.P. to a Domain wide RDP firewall hole! So, how do I get this other I.P. to RDP through the firewall (without adding it to the Domain GPO) and stop it overwriting?
-
Hate to be 'that' person, but... Just be mindful of what type of tree you are planting and where you are planting them... Background: We don't use our front garden for various reasons (we rarely even use our front door - only for receiving deliveries and such) and as we have fake grass for the dogs and patio/gravel in the back garden we thought we'd try to even up the score by letting the front garden go semi-wild (we tried seeding a 'flower meadow' but it didn't work, so mostly just weeds), with bug hotels and bird feeders/water etc. Anyway, it's safe to say we don't actually go out there much (sometimes for months), but when I did recently I found a sizeable tree starting to grow extremely close to the house (might have just been a seed when we dug over all the grass, or of course it could have come from bird droppings or squirrels). Couldn't tell exactly what type of tree it was, but all the surrounding trees in the neighbourhood are quite large, so eventually (OK, I know it would be maybe a few years) it could have given us serious problems in the the house foundations etc.. So, moral of the story? Just remember nature is very powerful and given time can cause a lot of damage (yes, I know 'she' was here first)... Also, 'mighty oaks from little acorns grow'.... and 'roots, bl00dy roots'... EDIT: As a side-note, when we first moved into the house we had a row of conifers in the front garden next to a 2 foot wide, 6 inch deep concrete path. They'd grown quite big over the years and were too close to the house (according to the surveyor) so they had to come down (unfortunately conifers that big don't take well to harsh pruning as they grow from the ends of the branches and were pretty much dead and brown in the inside), but the roots had still managed to lift the path to an angle and makes you feel like a drunk person walking home from the pub late at night... EDIT 2: Although we are not exactly an 'inner-city' school, we are in an 'urban' setting and have quite a few trees around the outskirts of our field but when you walk up the path on the other side it's like a mini-rollercoaster with all the tarmac and paving slabs that have been lifted by the roots.
-
[ipad] iPad refuses search for 'Hot' - Safari/Google
Koldov replied to Koldov's topic in Mobile Devices & Tablets
Hopefully answering my own question.... if I've got it right... 'Screen Time' now (well since iOS 12) falls within the scope of 'Allow Configuring Restrictions' (needs iOS 8+): https://community.meraki.com/t5/Mobile-Device-Management/Disable-Apple-quot-Screen-Time-quot-on-iOS/m-p/85000 So, if you don't allow them to configure their own restrictions, they obviously can't enable 'Screen Time' and so it is greyed out and says 'Restricted'. Now, is there anyone at Apple that can answer why 'hot' is a word that needs to be censored...? -
Had a terrible experience with CCleaner, absolutely killed an old XP install back in the day... It 'may' be worth running something like that if it has a function where it just finds issues and displays them before doing anything... but YMMV, UAYOR! Having said that, concerning the OP about Python, I had it installed on the ICT suite computers years ago, but the teachers didn't like trying to learn it and troubleshoot it when the kid's coding went wrong (so it never really got used). I uninstalled it from each machine manually (small school so only 30 computers) and forgot all about it. Then for some reason whilst working on a machine much later I saw Python still sitting there (can't remember now where, might have been in add/remove programs, or the start menu or something) and uninstalling and rebooting didn't work. Anyway it was a long time ago and I've forgotten how I 'fixed' it in the end, but I do have a GPO that I remember I had to deploy to delete a reg entry and it states: Hive HKEY_CLASSES_ROOT Key path Installer\Products\8A2613682CCEAE53DB7F0EA94C651E46 You can see if that one is at that location at least...? I can't remember how I found that this particular entry was the problem or how it related to the Python install (I have in the past been known to 'Find' everything related and just delete it from the registry for stubborn programs - not that I'm recommending it, because that's no better than CCleaner ).
-
[ipad] iPad refuses search for 'Hot' - Safari/Google
Koldov replied to Koldov's topic in Mobile Devices & Tablets
Yeah I could possibly turn it off, but I have got to hope that someone at Apple realises that this must have been a mistake.... With the filter on, students can't even search for things like 'why is the sun hot?'.... I don't really touch these iPads if I can help it and haven't really kept up when changes in a new iOS version breaks something in Meraki SM or mean that we have to redo a lot of restrictions or enable/disable certain new things, so.... Just out of interest, can anybody also using Meraki SM (or other MDM) explain why as I can't see anything in Meraki SM to specifically set 'Screen Time' (which says ''Screen Time has been restricted") if there is another overarching setting that encompasses that now? -
[ipad] iPad refuses search for 'Hot' - Safari/Google
Koldov posted a topic in Mobile Devices & Tablets
Very strange issue here... Teacher brought an iPad to me yesterday after school and said a few of them are giving an error whilst doing a Google search for 'Hot Chocolate Drink'! Couldn't really believe it, but she handed me the iPad and it gave an error I've never seen before... Restricted Site You cannot browse this page at "google.co.uk" because it is restricted. Anyway I think I've narrowed it down, it really does come up every time you open Safari and enter the search term 'Hot' into the search bar.... I've done a filtering report and it appears to Deny this search based on the fact that it produces a 'Malformed ~URL' which the support for our filtering says points to a problem with Apple and not their filtering. They suggested 'Settings | ScreenTime | Content & Privacy Restrictions | Content restrictions'... but on our iPads this section is greyed out and says 'Screen Time has been restricted'... thing is I can't find anything in Meraki SM that says we can even restrict that! The only thing I can really think of is that we push out the Apple (?) 'Web Content Filter' set at default, but it's been like this for years and I doubt this is the first time anyone has searched with the term 'hot'... -
No worries as the thanks was for posting it, not working it out. Just lucky you posted it and I read it, otherwise I wouldn't have known where to start with 10 minutes notice! Looking at the screenshot from @kennysarmy and mine, I'm guessing it's a default wording email invitation, just with the company branding on top - so more of an oversight on the part of GoTo not to include that information? EDIT: But of course the cynic in me thinks they just want you to install their product...
-
Just to say I love EDUGEEK sometimes... and special thanks to @Jaan Just had a message from my Bursar and no word of a lie, I quote: "I'm trying to do this Webinar - starts in 10 minutes - and it's blocked the site I need to use as it's something i need to download, am i able to access it?" Followed by a 'User attempted to save GoTo Webinar Opener.exe to the Server: Unauthorized file from the "Executable Files" file group detected'. So, I would just like to add 'The Access Group' to the wall of shame... As @kennysarmy said, what education focussed supplier doesn't realise that networks and machines are getting more and more locked down and the average user won't be able to just click a button on an email and download/install random software...?
-
No real update unfortunately... Various culprits from Event Viewer appear like this: Error: during volume shrink initiated on volume DISK2 ( F: ) we failed to move a movable file extent. Diagnostic details: - The last unmovable file appears to be: \Random Folder\Random File.JPG::$DATA - The unmovable cluster of the file is: 0x74d619d - Shrink potential target (LCN address): 0x7477300 - The NTFS file flags are: ----D - Shrink phase: To find more details about this file please use the "fsutil volume querycluster \\?\Volume{9654834e-78fe-11e4-80bb-549f35045c60} 0x74d619d" command. Once that file is deleted it just picks another one... I did about 10 and then got to this one... "\$BitMap::$DATA" - (which just isn't going to get moved by Windows and might even be dangerous to move considering it's the map of where all the files are in NTFS) ...and then I gave up. So without wanting to install and try out various random 3rd party boot time defraggers or partition software with all the potential issues and everything they come with... I've seen something bootable such as GParted suggested, but I haven't been able to determine if it's RAID friendly or if it will be too aggressive with delicate Windows NTFS files. I am wondering if I can delete the partition, recreate it with a smaller size and use a backup to restore all the files (and hope 300GB+ of file shares all restore perfectly with all permissions intact etc).
-
Pretty sure it's nothing like that (could be wrong obviously), there aren't any OS or program files running on there. Worth checking though, how do you look for that? Think it's just a very old 300GB file share that's never been defragmented properly (it does have an 'optimise' scheduled task set, but even when I did that manually it said it had never been run)... Thing is there's obviously some kind of issue, because when defrag begins it says 7% defragmentation and then 0% when it's finished, then if I do it again it's back to 7%...
-
I'd read a few suggestions about page files, hibernation files and such but they aren't enabled (I thought they might not apply since it's a file share, not an OS partition?). I haven't enabled shadow copies/system restore etc.
-
Having trouble getting this F: partition to shrink, the drive is a partition on the server and only holds file shares, it's not an OS volume, so no other programs or system files. It is 565GB and has 254GB free space... However shrink fails with the error message and Event Viewer (confusingly says it 'Error: during volume shrink initiated on volume ( F: ) we failed to move a movable file extent'). Unfortunately the file is a '::$DATA' file, so more of an NTFS file than a file in the share that I could just delete... I've done all sorts of Windows Defrags and Disk Check with all sorts of /switches and in the GUI and CMD, but it won't sort itself out. I need this space freed up for some further work I have to do this weekend (without users on the server) and it's stopping me moving forward. Question is, as I guess I'm going to have to use 3rd party defrag software, what do you trust (not to mess it up or install other dodgy things)... also without boot time input as I'm working remotely?
-
Hopefully a quick and simple one with an easy answer... I shut down my VMs and changed the drive letter of the storage location ( E: > V: ). Then in the 'Global' settings of Hyper-V manager I changed the location of the Virtual Machines and Virtual Hard Disks to point to the new drive letter (V: ). I rebooted the server to allow the drive letter change to update and I thought Hyper-V would be cool with it... It was very not-cool with it! All virtual machines were in an 'Off-Critical' status and would not start, going through the settings again and it would not even see the disks (even though they were there). What is the correct way to accomplish this?
-
Holy Necro Batman! What am I missing? Is this related to the OP? Are you saying Bromcom use GoToWebinar? What does clicking on the big 'Join Now' button do, tries to open that software? We've had similar with various 'remote support' providers all using different software, saying "yeah just click that link and download the software onto your server"... You would end up with GoTo, WebEx, Zoho, TeamViewer, LogMeIn etc... I guess if they've signed up as a company to license a particular software, handed over the cash and done the staff training, that's what they're going to want to use?
-
Yeah, I have to say we don't need many unusual requirements, so I don't need to deal with this very often.... I too am quite glad the responsibility for the firewall configuration isn't on my shoulders, but as you say it does sometimes make a simple request more complicated. Our SIMS/SOLUS server is on a VLAN from within an IP range specified by LGfL. The VPN clients get an IP from a specific LGfL-managed subnet. I'm not completely up on the fine detail of how it all actually works, but simply put, our remote client uses a school laptop, this is configured with pre-auth (before Windows auth), so in effect they are signing-in to the VPN and then signing into Windows so the laptop should act as if they were at the school, I can see the remote (VPN) IP address in DNS with the correct hostname. Quite literally EVERYTHING else works, file share access is OK, SIMS/FMS clients work (if a little slower than on-site), our WSUS server can see the client, even printing... just not SOLUS. I'm going to bet on it being a port that needs opening in the LGfL firewall, it just seems to make sense now. I seem to remember hearing they run it along the lines of 'close everything and then open what's needed only when requested' (which in all honesty is fair enough)... otherwise I doubt the support response would have been, 'fill out a spreadsheet and let us know what ports you need open'. Although I would have thought they would have some database with what schools use for an MIS (like they have done with O365 & Google) and what ports they need open I suppose it isn't every school that needs this part configuring as it really is meant to be an internal network function, but ESS said they had lots of support requests about this over lockdown. Still I guess it comes down to 'even if we know, you are still going to have to request it'... and I can see their point . It probably should have been my first 'port' of call, instead of spending so much time trying to work out if it's a problem at my end... but I also seem to remember someone saying that previously they've had issues with the blame being put on the local network configuration... and I guess you can never actually tell when doing remote support.
-
Hi, thanks for the input! I tried last night from home as trying to test VPN from inside the school network, out and back in again is going to cause some crazy NAT and skew the results apparently... I cannot connect to c$ (from the SIMS server, through SOLUS - 'Open network path in explorer')... forgot to try via IP but I figure this should have worked if the connection from SOLUS to the client was good? I can ping both ways by hostname and IP (so ruling out DNS?)... I briefly turned off the firewall on both the server and the client and it made no difference (so probably ruling that out as well)... Would the user on the client need admin rights to install the FMS update manually? Anyway, last night I reached out to our ISP (LGfL) for support with the VPN and also to ESS for support with SOLUS to see if I can get enough information from their collective support to see how SOLUS works and if the VPN or our connection needs any extra configuration. I received a reply from LGfL at just after 08:00 to supply them with a MIP request... so for SOLUS to work through our ISP firewall do I just give them the IPs quoted in the post by @Esteban_Child_of_the_Sun ? LGfL have always been quite good with their support, but the problem is sometimes you seem to have to already know what the problem is and how to fix it, then just ask them to do it and 99.9% of the time they will. The problem comes when you don't have a clue and then it becomes a little more tricky to get things done... So, from the MIP request spreadsheet they've sent me does anyone know what I am putting and in which section? The way it's worded to me seems like it's a one-way thing in each section, but it also doesn't seem that's the way it should work? I presume if a port is open, it's open right (?), but the way the spreadsheet looks to me is that I have to fill one in for the server > out and then the other section for the client > in.... I'm a bit disappointed LGfL don't have this as a config, ready to go really... [ATTACH=CONFIG]67870[/ATTACH] ESS have also got back to me and (with the caveat that it isn't a supported configuration) in summary: IP of the workstation incorrectly being a local network IP and not a remote/VPN IP - I think this is working OK as DNS shows remote IP. The ports you will need to allow though are 52965, 52966 and 8739, these are all TCP - Are these the only ones I need to advise LGfL about, or best to go with the full list? Recommend adding specific allow rules for the ports as I have seen this fix issues even when the firewall shows as off in the UI. - I will see what happens when LGfL open the ports before I look at our server/client firewalls again. EDIT: If it turns out all this could have been fixed in 5 minutes by sorting the LGfL firewall....
-
I've tried putting in all those ports on all 3 network profiles, on TCP & UDP.... the firewall has so many holes in now it looks like a sieve... Then I even tried with the firewall completely off, still no luck so maybe not even firewall related and more to do with the VPN. DNS might be the thing (it registers in Forward but not Reverse zones - I even manually added a PTR but no help) but I also think the VPN itself might an issue (Cisco)... I ping the laptop's 10.132. address and get a TTL expired in transit from a 172.30 address... I found my old post from exactly 1 year ago... didn't manage to get it to work back then either!
-
Thanks, might be a little further along... The actual message now is: Although not known for their ease of understandable error messages (usually being very cryptic) could it actually be the firewall? I can't tell right now and don't know the answer, but does a VPN use a different connection type? If so, I wonder if the SOLUS ports that we open might only be for DOMAIN network connections and PUBLIC/PRIVATE ones aren't included. EDIT: Scratch that, I've just looked and those ports appear to be open in Public/Private firewall options too...
-
Pretty sure I've asked this before on here somewhere, but can't find it at the moment... We have a user working from home that cannot access FMS due to a recent version update. Although both SIMS/FMS work over the VPN, SOLUS just can't seem to contact the agent on the laptop and push the update to it. Possibly due to a DNS issue with the laptop being on a VPN (different I.P. than the one SOLUS has in it's DB)? I can see the laptop registered in DNS with the 'new' I.P. so I'm failing to see why SOLUS can't get it's head around it...
-
Todays forecast.... not a (Microsoft) cloud in the sky... Or is it 'Cloudy with a chance of... toast'...?
-
So this is a kind of on-topic-side-step... but bear with me... In a previous post I echoed what a few others mention here about how the core OS (talking specifically about Windows) is less important as other OS vendors start upping their game. Especially as more and more software is run within a browser.... This isn't what we do here, I am not really 'with the times' and I'm not with the movers and shakers of the I.T. world, so very little of our core functionality is run 'in the cloud'... Sure we have 'O365' based email and more 'learning platforms' for the children than we used to have, but the I.T. suites still have loads of software on them, MS Office is still a manual 'per machine' install, SIMS is sitting on a big old physical beast in the server room, as are the file servers with all the teacher's work on them etc. So what happens to all these 'cloud' based schools when the internet goes down or as what appears to have happened today, Azure gets nuked (today it's MS related but say tomorrow it's Google)...?
-
Ah yeah I see. Actually I can't see many developers wanting to use Windows unless they are developing specifically for it. Same for a lot of the other professions where the 'industry standard' software is heavily Mac based. I wonder how many big companies/web servers/mainframes apart from MS use the Windows Server OS (aren't they always IBM/Apache/Unix/Linux)?
