Davit2005
Members-
Posts
5,320 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Davit2005
-
Fortinet MC3200 Vlan configuration
Davit2005 replied to HereIGoAgain2601's topic in Wireless Networks
Most of the time the APs need to be tagged yes. Exclusions to this are Aruba (not Instant or InstantOn for instance) and probably others where you have controllers which the APs form a tunnel to and there is no need to tagg the vlans. Is there no help function in the GUI or documentation? -
Same here, music is all I listen too. I don't touch the main stream media these days I find the right music much more relaxing.
-
Spent a 2 weeks sorting an issue caused by an application using 443 but in the end had to put an exception in to bypass decryption to that URL from specific internal addresses as lucky enough it was users from specific internal IP addresses.
-
Yep the issue :-) Our firewall will only log traffic if there is some sort of rule in place that being a deny or allow. If there is no filtering or firewall between the desktop and the Smoothwall it leads me to think the issue is with the Smoothwall. Is it the same device failing on wired and then successful on wifi? Can you try and do a tracert to the IP and FQDN from the desktop to see the route, this should get as far as the Smoothwall at least?
-
Does not make a lot of sense, lol. Have you tried a packet capture on the smoothwall. The reason why I ask is that our firewall will only log traffic which matches a rule and that rule is set to log traffic. On our firewall we can do a packet capture for dropped traffic. Is their any chance it could be SSL inspection if you have that enabled?
-
More Half marathon training but start long runs around 6-7am so plenty of time afterwards to relax, fall asleep and do nothing I'd wanted/needed/planned to get done :-)
-
Might be helpful if we had the context of the question from the OP. Is this to deal with a ongoing issue or for future posibilities but yes 802.1x would be the ultimate choice as everything else has a possibility of counteracted i.e. MAC spoofing etc.
-
Managed switch that you can interrogate the MAC address table on and locate the MAC address to a port. Or trace it from switch to switch if need be. Depends what switches you have how easy this is. We use iMC at the moment or do it the old fashioned way of going from switch to switch and we have 700+ switches, but we an normally track it down.
-
cable from building to unmanaged switch managed switch
Davit2005 replied to 5nowman's topic in Wired Networks
Maybe it of worked if you'd forced the ports to 10/100 both ends (apologies if you tried this already). Green and orange pairs normally enough for 10/100 even some extenders I've used in the past have only used 2 pairs and that is how those cable economizers normally work -
Some Edu settings might warrant a SAN but we (Uni) are moving to a hyper converged setup now using Greenlake. My last org was a college with over 150 VMs and had a san with multiple hosts/chassis and even our Citrix VDI shared the same SAN.
-
GPO will only accept msi installers. I'd also recommend setting up a specific shared folder for this too rather than jus using the C drive. You could setup a startup script to check if the application exists and if not install it.
-
We had a Fibre Channel SAN at the last place but had over 150 VMs, multiple blade chassis's and redundancy but hyper converged or other solutions mentioned above might suit the business as well and remove complexity.
-
Moving to 2Gbps internet connection -what router
Davit2005 replied to Westy1's topic in Internet Related/Filtering/Firewall
DHCP and vlans, should not be a big ask for a router/firewall. When it comes to intervlan routing, notably IDS/IPS that is when you are likely to see the impact. I'd too look at a some sort of solution that uses pfsense either a Netgate with pfsense installed or a third party appliance with pfsense installed with enough ports to satisfy your needs. MikroTik is an option but they can be quite complex but they are cheap for what you get, I've had many versions at home but always found the firewall side a bit hard to grasp so only use them for their 10Gb switches these days or core routers. -
cable from building to unmanaged switch managed switch
Davit2005 replied to 5nowman's topic in Wired Networks
Plug a laptop into the copper coming from the other building see if you get a light, then plug the laptop into the Cisco switch and see if you get a light if both show link lights on the laptop check if you need a crossover. Some switches have auto crossover and some don't as @FN-GM mentions. -
Whilst DNS can be AD integrated DHCP not so. As others have said you'd need to setup DHCP failover or do split scopes. I've only ever done split scopes 80/20 so 80% of addresses on one DHCP server and 20% on the other but this is going back to when DHCP failover was not an option without 3rd party appliances or software. https://www.reddit.com/r/sysadmin/comments/bx5ylt/difference_between_split_scope_dhcp_and_simply/
-
New ISP recommendations
Davit2005 replied to MisterTechMan's topic in Internet Related/Filtering/Firewall
Jisc might be worth a look. -
Can I use idrac card from Dell PowerEdge T420 in T430
Davit2005 replied to TwistedHelixis's topic in Hardware
I jus bought my iDrac full license for R730 home server off ebay, it was quite cheap. -
The way I did powershell scripts was to think of what I wanted to do, break it down to individual steps and thn research on the Internet how to perform those steps. It wasn't very efficient but I did not want to run random scripts from the Internet without knowing exactly what they were doing at each command. These days I jus look back at old scripts if I think I might of needed to do something. If the syntax changes should be able to update the command or a small section of the whole script to compensate. But yes you could jus spin up a new tenant and practice against that for basic scripts?
-
Removing a network switch from a basement, was dripping as soon as I started. Thankfully only pulling the power cable out and unmounting a 1U switch, lol. I sweat at the best of times and doing BJJ demonstrating at the front of the class with the instructor I'm like a melting lollipop.
-
I don't know about the NVR but some printers will not find a new IP without a reboot, but yep if you are not ultimately responsible for the NVR I would not reboot without speaking to the support that are. What happens if you plug a laptop into the same switch port, is it able to communicate with what it should be able too.
-
Personally I'd be inclined to carry on. See if you can get any grounds for re-compensate for time spent on this. Jus thinking this time it is a school with a team that has knowledge of such things next time it might be a charity or an individual that might not so much or wasting money on something is not been delivered. But yes it is using up time that could be spent on other things. It would be nice to say to HP that you might not look so favorable on their servers, laptops and desktops in the future but that might jus be me.
-
Firewall in between not allowing traffic, Gateway on NVR correct, using DNS or IP, IP routes if CCTV vlan is routed on firewall separately to name a few.
-
If you are running other services on DCs I'd take the opportunity to separate them. So yep build new and transfer FSMO roles, DHCP and DNS and leave none MS third party software where it is to migrate to a supported OS at a later date but you are running a risk with lack of security updates.
-
Something to be aware of as can effect insurance cover too. I can't drive other cars on third party cover because I'm not the keeper or owner on my lease vehicle but I have fully comp, 2 insurers have told me that so prob some truth. I only regularly have use of one car anyway apart from work vehicles which I'm covered for. Mind you been my age getting named driver on another policy is pretty easy and normally jus £10 if that.
-
I have some IDE cables and SCSI cables and Adaptec SCSI cards at home, I don't know why as I only have one server that has a PCI card left and one old PC that has IDE ports not used in a number of years :-)
