Jump to content

Davit2005

Members
  • Posts

    5,320
  • Joined

  • Last visited

Everything posted by Davit2005

  1. Thanks Michael, hopefully suggestions by external will fix the issues when we connect their switches to ours. Not going to lose too much sleep over it
  2. We had an issue where a loop formed when we connected switches running RPVST to the aggregation switches (logically separated) running MSTP that effected devices on vlans not even provisioned on the links to the RPVST switches. I may of seen something like this before but did not get much further with it as another solution was found. Has anyone else had this issue and if yes how did you resolve it on the switches. Spanning tree is not my strongest subject although I know what we have setup regarding MSTP more or less i.e. multiple instances with the roots on different switches to give some load balancing and redundancy.
  3. Too simply close a school for the MIS not available would be a bit far surely, to close a school cause the heating was not working a bit more understandable.
  4. Previous employments we deployed decryption and filtering on Palo's. We also ran all application based policies. We jus put a link to the cert on a web page people could get to as they joined the network for the cert, managed devices we deployed the cert via GPO or JAMF for MAC devices.
  5. With the AD join account setup a specific service account that has delegated permission to add computers to a specific OU in AD then configure MDT to put the computers into that OU as part of the AD join process. Don't be tempted to use a Domain Admin account.
  6. How many DCs would you normally have? I'd prob say once you have the DHCP migrated over. I've always gone down the route of having a split scope and never used windows DHCP failover.
  7. Get yourself a copy of Roadcraft once you feel comfortable with the highway code and the road signs. There is a specific version of Roadcraft for motorcycles as there are some differences. Should always be able to stop in the distance you see to be clear and if that is a single track country road you should cut that down to been able to stop in half the distance you can see. Also you should not put yourself in potential danger for a better view.
  8. Personally I've always kept the same IP addresses but used different names. 2 DCs migrate one at a time, give the new DC a temp IP address then change the old DC to a different temp IP address once DNS, DHCP is setup. If you keep different IP address for new DCs you'd need to potentially update everything that has manual DNS IP settings. I always leave a day before demoting and run DC Diag before start, during i.e. promoting a server to DC and when finished too. DNS wise, I always have setup Active Directory integrated zones, so whilst you still need to install the DNS role it is quite straight forward.
  9. If going for an external audio interface I'd go for one that has it's own power supply and does not take power from the PC USB connection as well. Same with USB hubs these days, I had noise issues with a Blue Yeti to the point it was unusable, fixed by getting a decent powered USB hub.
  10. I'd go down the route of getting your estates team or a carpenter to knock something up. A shelf as @jthompson mentioned above the PCs with shutters mounted to them, then shutters going down to the floor. Depending how many computers you want to be behind them it might work out cheaper than getting individual units.
  11. When we did this with RM CC3 we found a RM user account that was changing GP back to the RM settings. We did not go that much further than jus disabling the account. Then we rebuilt the DCs without the CC RM bits. Used new OU's, I think we created new policies I cannot quite remember it was over 10 years back. If you are removing jus note everything that CC is doing for you. Everything can be done by third party tools and/or , running MDT/WDS/SCCM for OS deployments, PowerShell can be used for creating user accounts, GPO used for deploying printers, etc.
  12. How far do they want you to go as far as testing. Do they need to know the cabling type i.e. CAT5, CAT5e, CAT6, CAT6a, shielded, etc. And whether the cabling installation is to correct spec, Crosstalk readings, cable lengths etc.
  13. What filtering do you use. Maybe you should add it of have it added/re-categorized to Proxy Avoidance :-)
  14. Yes we decided to shutdown desktop machines also for this as users used to leave themselves logged in but the machine locked.
  15. Enable logon audits on the DCs and use lockoutstatus tool https://www.microsoft.com/en-gb/download/details.aspx?id=15201 Using the tool will tell you which domain controller the user is getting locked out on then search the security logs for the user. This will most of the time give you an IP address where the account is getting locked out from. We used this a lot at my previous place. Do you have MFA on the account where possible??? Mostly this was caused by a mobile device logged into outlook with old password after user had changed password.
  16. Different vlan and IP range. Also switches can only be managed from specific IP addresses. Physical security is always a factor too. Disable core switch ports that are not used and always tag client traffic on uplinks. My dream would be for anyone to be able to plug a device in a wired port and it gets access based on the device/user. MAC address restrictions can still be got round by spoofing. And if you only provide DHCP via reservations someone can always guess an available IP.
  17. Yep HP switches and the Arubas that use the same OS as the older ProCurve it is simply a matter of untagging and/or tagging. The joys of the different switch terminology and the way they work, lol.
  18. Seems pretty OK on the Cisco to me. Not had a lot of experience on Netgear though can you post the vlan config of the Netgear for the uplink port that goes to the Cisco :-)
  19. Shadow boxing can be a good workout jus don't stand too close to the TV :-)
  20. I set this up many years back but I had to disable it during the day. They only had a 20Mbps ISP connection and using the stream killed the internet. Basically a NAT rule to a IP camera. Would I do that in the same way now prob not unless I could put the camera in a DMZ or completely separate from the network and do it that way. The YouTube Stream way might be an alternative as it will not involve opening any ports etc.
  21. Cannot see the problem, maybe you can limit this to specific groups but what is going to prevent students looking when they are not on the school filtering system. Surely we are not really saying they should go and do it but educating them on what it is etc.
  22. There are different types of Aruba i.e. below Instant On - Cloud or local management Instant AP - One AP can become a master Campus AP - Dedicated hardware controller and mobility masters available. We have 2500 APs, 3 Mobility masters and 2 mobility masters. The APs are paperweights without the controllers. https://www.arubanetworks.com/products/network-management-operations/arubaos/
  23. In that case create an ACL or if the BYOD is separated at the firewall use firewall rules to only specific services where necessary. At cost there are methods to use posture checking, etc. if you want to allow BYOD devices to access internal services and limit risk but I'd still separate by ACLs or firewall rules.
  24. British Gas smart meter remote display has not worked for 3 years. Given up trying apparently meters still reporting back to them, got the read out unplugged. I have a number of TP Smart plugs that monitor consumption, most of my stuff that is on (or plugged in) 24/7 is using smart plugs, some get turned off if I go to bed, leave home or work from home. No tumble dryer or dishwasher apart from me. All LED bulbs.
  25. Just try pinging 8.8.8.8 or Google and/or ping the default gateway if your gateway is setup to allow ping. See if it is dns or ip related then go from there. If you do not get a response from pinging external FQDNs at least confirm if it is resolving the hostname where it should.
×
×
  • Create New...