Davit2005
Members-
Posts
5,319 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Davit2005
-
They probably will but over 16s won't be blocked.
- 45 replies
-
- safeguarding
- social media
-
(and 1 more)
Tagged with:
-
Currently only under 16's effected for YouTube. People might have their own thoughts on this but this is probably not the forum to air them, lol. https://www.gov.uk/government/publications/fact-sheet-new-rules-to-protect-children-online/fact-sheet-new-rules-to-protect-children-online
- 45 replies
-
- 1
-
-
- safeguarding
- social media
-
(and 1 more)
Tagged with:
-
Is it an actual app? Do you use decryption on your firewall/filter? We had a library app that played up because it used ssl, in the end we found the fqdn and excluded it from decryption for specific users.
-
Backup Internet - Filtering
Davit2005 replied to Alastairb25's topic in Internet Related/Filtering/Firewall
Is it cloud based filtering? If so can you ask them if it is possible to add an extra public IP that been of a static IP for the backup connection? -
Soz was referring to the free version, lol.
-
I have used PRTG in the past but the only thing you will find is that you may quickly use up 100 sensors once you see what you can do with it. But prob one of the easy monitoring tools to setup but I think it only runs on Windows?? Zabbix can run as a docker so pretty easy to get up and running, I'd always setup a linux VM specifically for the docker though and not have it running direct on hardware. At home I use a combination of Zabbix and Uptime Kuma with notifications via home assistant and Discord. Uptime Kuma can do DNS lookups, https cert checks, website checks, SMB etc. and alert if any fail.
-
HP Microserver Gen10 AMD X3421 - Samsung EVO 870
Davit2005 replied to cishandfhips's topic in Windows Server 2022
Is it going to be your only DC? And only going to be responsible for AD roles? TBH If it is an additional DC personally I would be thinking not to bother with raid (depending on your org needs 🙂 ), the issue with raid on these is I'm pretty sure it is only software based raid and with the limits of the MicroServer casing it will be difficult to get a hardware raid card to fit. -
My home Brother HL-3150CDW bought March 2018, still on original toner and going strong. Paid £129.99 for it back then from PC World with 3 years Product Support for £30.99 . Personally for occasional printing I'd defo suggest a laser unless you need photo quality prints but even then you can just go into a supermarket/shop these days and get photos printed out easily enough if you really want them.
-
Skeptical on the Eco firendly part personally, lol.
-
Echoing the concerns if sports were ever to be played in the hall (or are played in the hall) a projector would be the safer option in some sort of protective casing.
-
Dual 1 U switches with MLAG or stacked at the core could be an alternative to a chassis switch. Surely the main goal to reduce Single point of failure, each switch has it's own management and redundant PSUs 🙂 But that obviously depends if you need edge ports (i.e. APs, CCTV, PCs, etc) with PoE on the core, personally I'd have a core switch with no edge ports if I could just handling connections from other switches and the connection to the firewall/router. You could then have a core switch at different locations next to a router/firewall with a 2nd internet connection depending on building layout, provisions, budget etc.
-
Some did, there is an online document somewhere for what is not and what is 🙂
-
7 x 5406Rzl2 running, 3 of them for 9 years. 2 are VSF stacked. Downtime only for updates/power cuts, no module failures. Most have UPS backup. Not using any of them for core (or what I'd call core i.e. intervlan routing). We have 4 x 8212's still doing core networking at the moment, running OSPF and multiple MSTP instances, two module failures in 10 years. Soon to change though 🙂
-
SmoothWall VM and Subnets
Davit2005 replied to sparktech's topic in Internet Related/Filtering/Firewall
Find the easiest thing to do in these sorts of scenarios is to break it down into smaller chunks Plug a laptop into a switch port configured as an access port for the vlan, see if you get an IP If you cannot get an DHCP IP then give the laptop a static address in correct range and ping the gateway (not sure if you need to allow ping on the interface for this) See if you can trace the MAC address of the laptop to the Smoothwall if possible or at least the physical switch port that connects to the HyperVisor, (what HyperVisor is it BTW). Do the APs need the extra vlan adding to the switch port where the APs plug into, some APs do including Unifi. -
Normally a different NAT rule using spare public IP for the source ip range/subnet, put it normally above the NAT rule that allows all other default traffic i.e. traffic that the rest of the wider network uses. If rules work top to bottom then it should apply the new NAT rule only to the source ip range/subnet then anything that does not match goes to next rule. Not 100% on Sophos but if rules work top to bottom the first one that matches traffic that rule is used then it should work 🙂
-
Slow Internet. How do you troubleshoot?
Davit2005 replied to Gongalong's topic in Internet Related/Filtering/Firewall
Doubtful about the use (not the usefulness) of AI sometimes, lol. -
You could use a reverse proxy with a wildcard from LetsEncypt with DNS so you don't need to open up ports and no need to setup a CA purely for accessing such things as admin consoles.
-
TBH I'd contemplate separating the DCs from the File and print services. Much easier to spin up a new DC, migrate roles etc. than having to rebuild a Print/File Server
-
Alternatives to mandatory profiles windows 10/11
Davit2005 replied to sledpath's topic in Windows 10
If you are redirecting appdata you may want to exclude certain paths. We had users who'd backed up their iPhones to there desktops and this equated to a sizeable chunk. I cannot remember how we did it as it was over 10 years ago now. -
PiHole been a DNS based blocker it does not block all YouTube ads. The only way is with uBlock or similar but then you are in merky T&C waters as others have said.
- 35 replies
-
- youtube ads
- youtube
-
(and 1 more)
Tagged with:
-
I've found that not sufficient due to the ads been embeded in YouTube and difficult to filter by DNS alone. PiHole is great though and been using it for years, jus moving over to Technitium at home for more flexibility and advanced features.
- 35 replies
-
- youtube ads
- youtube
-
(and 1 more)
Tagged with:
-
Connecting Androids to Wireless Network
Davit2005 replied to ChosenHillIT's topic in Wireless Networks
To test whether it is the SSL decryption could you put a bypass/exclusion in for a specific IP address and test it? The only issue I had with decryption was at a previous place when a piece of software did not work as it used SSL ports over 443, we created an AD group (our firewall was AD aware), we then put an exclusion in for those people members of that group that used the software then also added the destination address so those users would still have decryption but only when traffic was to that specific domain/destination. -
Prevent viewing network information at sign on
Davit2005 replied to WVtech's topic in ChromeOS & Cloud Based OS
TBH 802.1x is a better solution otherwise it is jus security by obscurity 😉 Not saying MAC filtering does not have it's uses but if relied on to solely keep devices off a network it is a bit limited and open for easy get arounds as you have found with MAC spoofing. -
Queue the calls that the clock does not work, you reply saying the battery ran out, they say but it said it was wireless. Been there, seen that 🙂
