Davit2005
Members-
Posts
5,319 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Davit2005
-
HP Procurve mainly i.e. core, edge, distribution and aggregation but a few Aruba CX at edge. Only edge switches have end devices plugged in and all those have DHCP snooping enabled apart from a few that don't support it but those are back office switches (a.k.a top of rack) and all traffic is vlan tagged on those. Sorry for the double post, page did not refresh, lol
-
Firewall on the server?
-
HP all through at the moment. Procurve, some Aruba CX and a few Junipers at the core level. If you have core switches secure physically wise and/or disabled the ports you could potentially leave DHCP snooping off the core as long as no end devices plugged in which could lead to rogue DHCP servers causing issues.
-
All DHCP snooping does is prevent rogue DHCP servers, you add trusted ports i.e. the DHCP server and uplinks. There should not be any impact to DHCP performance. We rolled it out side wide to all edge switches after a few incidents, i.e. staff member bringing in his own router and thought he was smart by matching our IP range. Took 2 weeks to find the issue, did not go down to well, we were not very happy with him. On a worse day we would of binned it, lol. As it was we disconnected it and left a stern note.
-
Using existing NPS with MFA on new RDS server
Davit2005 replied to Sheridan's topic in How do you do....it?
Have you tried rebooting the server 🙂 -
We had this issue a few years back, clients would discover, get the offer but fail at request. Weirdly when we moved the switch to another module on the HP core it resolved the issue. It is not the first time I've seen a fault with a switch cause a DHCP issue though and the other case was a single dumb switch, the only switch in the network. I've also seen issues with switches that presented them selves as clients not been able to get to an SMB share.
-
Using existing NPS with MFA on new RDS server
Davit2005 replied to Sheridan's topic in How do you do....it?
Is it possible to restarting the RDG server? -
Using existing NPS with MFA on new RDS server
Davit2005 replied to Sheridan's topic in How do you do....it?
That is probably a better idea. When we had contractor set it up we already ran radius on servers for something else and they said not to mix it as it can cause issues so we span up separate NPS servers to install the extension. -
Using existing NPS with MFA on new RDS server
Davit2005 replied to Sheridan's topic in How do you do....it?
Would it not need to be installed on the NPS server? We used to use a MFA plug in for our MFA but we gave up. We now jus use SAML for Global Protect VPN, setup is a breeze. -
Using existing NPS with MFA on new RDS server
Davit2005 replied to Sheridan's topic in How do you do....it?
Have you seen this, suggests it is possible https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-nps-extension-rdg Use wireshark on both NPS and RDG if possible to see if request is sent by RDG and received by NPS server -
Occasional stalling logon script, during printer setup.
Davit2005 replied to kennysarmy's topic in Windows 11
It is jus troubleshooting, checking event logs. Yes MS don't help a lot with cryptic error messages. TBH I've used both the con2prt method and Group Policy Preferences with loopback to apply specific area printers successfully in the past in multiple orgs. MS has of course thrown a few hurdles in the way along with some printer manufacturers and driver issues. I even worked in a college and changed the way they setup enrolment printers to use GPP instead of sharing USB printers from one PC as that gave us no end of trouble. -
Blocking Co Pilot for Students under 13
Davit2005 replied to loxford01's topic in AI in Education & Enterprise
Licensing options? Years back I used to license users with a script and it was possible to limit applications that way. You could then have for instance banned users and jus allocate to a AD group for more control if needed. -
I used to run a complete AD at home with Azure for email, etc. but since I don't get involved in AD or VMWare anymore I only run Windows if absolutely necessary. These days I run ProxMox and only my Gaming PC and CNC PC run windows for compatibility whilst a MAC Mini does everything else. Work wise my role is network related i.e. firewall, NAC, WiFi, etc. and I have setup GNS3 at home for doing networking labs with Juniper and Aruba CX As you mention, go on premise you are limiting yourself to local AD. Whilst if you go Google/MS365 you are going to be limiting yourself to Cloud technologies/management, so do you setup all 3? So I'd look at the direction you intend to go. In reality employer should fund training if they require special knowledge but we know that unlikely happens. A previous employer did put me through CCNA, whilst I completed CCNA in 2003 previously and did a MCP many years back both off my own back and money even though that employer was not keen as saw it a threat.
-
Occasional stalling logon script, during printer setup.
Davit2005 replied to kennysarmy's topic in Windows 11
Anything in event logs? On effected PC 🙂 -
Another option might me to use a password protected zip file. 7-Zip can do that for you. I realize it means installing and managing an app 😞
-
As a BT customer I have recently gone down the process of replacing the supplied FTTP router purely because it was jus so limiting to what it could do. The router I choose was a MikroTik I had lying around (but any decent router should do it depending on how the service is provided) simply pulled the connection to the BT router from the BT ONT. I found some documentation/guides on internet. The BT router had no option for modem the intent being that you can replace the whole router with a 3rd party if you wanted to. Some ISPs don't work/think the same way, lol.
-
Are these MS surface? I've had success with the MS ethernet adapter a long time back. If not a USB adapter like the StarTech USB31000S2 might work. Will prob need to put the drivers into the PE drivers section.
-
MSM765 Firmware version: 6.6.9.0-23567 - Certificate expiry issue
Davit2005 replied to tybor86's topic in Wireless Networks
What do the license's show? These things are real old now, to put into perspective my previous employer put the same solution in before I started there in 2012. -
Same user, same device? Or random
-
Perfectly OK to restore DCs. If you are in DR situation. I've even done it with Backup Exec before now, some years back. Yes you can get issues with sync which is repairable. https://www.veeam.com/kb2119 The referenced article does speculate that it does not cover restore of Hyper-V though. To be safe I would rebuild the DC on Hyper-V and then join it to domain, migrate roles then build the 2nd DC on Hyper-V. You can then be sure you have a clean VM without any remains of VMWare. With DCs it is better to be safe than sorry as they can be finicky, I've always jus built new DCs TBH, and with Virtualization there is no need to have any thing else but the DC roles i.e. AD, DNS and DHCP services on a single VM and highly advise against it.
-
What’s the biggest barrier to upgrading switches/networking?
Davit2005 replied to TP-Link_Gary's topic in Wired Networks
I think the oldest Aruba 2930F switches we have are about 3-4 years old now, we have about 50 but no failures as of yet. Put in about 30 Aruba 2530s about 8 years back and not one failure. 80 or so Aruba 2540s and have had 4 of those fail. A lot of old HP 2650's but in middle of replacement project so they will all go, they are prob the least reliable with PSU problems but they are very old. HP 2810 or 2620's are next unreliable but again those switches are old. -
Migrating from VMWare to Proxmox
Davit2005 replied to 404_WolfNotFound's topic in Enterprise Software
Loads of (reputable) guides on YouTube, if you are setting up a cluster have 3 minimum for quorom. Don't be tempted to setup a q device and instead use a desktop and install proxmox would be my suggestion. I migrated to ProxMox from VMWare ESXi at home. There is loads of community support and paid for support options. Use best practices. Not personally done any iSCSI as yet. Personally I'd do below: Use separate vlans and interface for management and cluster traffic. Use separate interface for ISCSI Use separate vlans/interface for VM traffic Make vlans, bonds, bridges and interfaces consistent across all nodes -
As @mavhc mentions Active Directory-Intergrated Zones can be used if DNS roles are installed on Domain Controllers and makes the setup far easier as well as secure. https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/active-directory-integrated-dns-zones
-
Intel ProSet Adapter Config Utility no longer supported
Davit2005 replied to timbo343's topic in Windows 11
That is a shame. Thankfully I have a MAC which along with Linux it is very easy to add virtual adapters as they are useful. As I mostly WFH on VPN I can access devices on vlans that I otherwise would not be able to. I did have an update on a Windows 10 some time back that killed Intel ProSet, then had to muck around trying to get some basic networking back so I could install the proper driver then setup the virtual adapters again, happy days. -
As long as the new DC has DNS configured as all you are doing is giving clients a new DNS server. Nothing to do with DHCP been configured as long as when you do configure DHCP it has the correct DNS options set 🙂
