Davit2005
Members-
Posts
5,320 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Davit2005
-
Yes jus remember to keep them isolated from the Internet Not saying Synology or others are perfect and have a clear track record but I'd always limit access and highly consider stopping it connecting to the Internet altogether.
-
I would not want to touch Backup Exec with a barge pole personally. We had both Veeam and Backup Exec before Veeam supported tape many years back. Have you thought about getting a synology or similar NAS as a disk storage for not a lot of money for a backups destination for the Physical servers then have these additionally on tape/immutable/offsite as a last resort in DR or ransomware event. Jus tie the synology/NAS access to the Internet down, update regularly and only enable features such as external access if you really need them, preferably not use remote/cloud access at all.
-
That is a good one
-
I think there is a mentality of keeping place. You see it when traffic is supposed to merge from 2 lanes down to 1 and a driver has taken it upon himself to block cars using the outside lane not realising that it helps traffic flow. It is easy to understand a gripe against someone who is jus intent on jumping a queue instead of jus using the merge as it should be.
-
Surely windows firewall would not block outgoing ports for active directory. Firewalls generally deal with incoming traffic but I have known windows firewall to block icmp ping replies before now. There are about 20 or so ports for active directory some UDP and some ranges. I'll try and dig them out.
- 6 replies
-
- firewall
- group policy
-
(and 1 more)
Tagged with:
-
I've had issues as a cyclist where a car has overtaken and purposefully cut into the kerb in queuing traffic (obviously triggered by a road user making better progress), can you blame a cyclist for not going around to the right of cars in queuing traffic if there is enough room and it is safe to do so.
-
It is not only protecting cyclists but getting them respect of other road users, some motorists will have a problem with that for various reasons. People should not change lanes without checking mirrors and if possible a shoulder check of blind spots. Should also check mirrors before turning left or right or overtaking to make sure there is not a motorbike/bicycle overtaking in any case. Using indicator does not give the right to jus cut in front of another road user and never should. There is room for mis interpretation and the media should ask someone who knows what they are talking about without bias to speak about it.
-
I do think that cyclists should take up primary position if there is not enough room for a car (or bigger vehicle) to safely over take. A cyclist taking up primary position can also be dangerous. Say if car in front was turning and a car was waiting to come out of a side turning, it could be difficult for the car waiting to turning out of the side turning to see the cyclist as the cyclist would be possibly hidden by the car turning left. As a cyclist I'd want visibility to other traffic and that includes using front lights to be seen by cars pulling out and cars they may go past on the left. It is down to common sense they say but that is not a given these days, ego, emotions and other things can have an effect unfortunately.
-
Ashley is really good, I watch a lot of his videos, even as a driver for 30+ years can still learn things
-
That seems to be the case in a good proportion of drivers that I see sometimes, thankfully I have the ability to leave early for work before the rush hour and don't use the M25 so much so I prob avoid most of them Drivers in the wrong lanes for the direction they are going i.e. Traffic lights/Roundabouts marked left/right turn (sometimes on purpose to get in front of people). Impatient people that don't seem to think they need to obey speed limits or other rules i.e. bus lanes. I jus put them to one side mostly to not want the hassle of a brake check. The attitude of some drivers need to change but there is a lot less police enforcement and presence and some drivers will try anything because mostly they will get away with it leading to the sheep copying them.
-
Priority should be given not taken whilst there is a need to protect the vulnerable. Whilst you will have right of way it is best to be prepared for the unexpected as much as possible and if that means not going full speed into the unknown then that should be done. For example un the UK roundabouts with a give way sign is and indicator that some entrances onto the roundabout have reduced visibility, case in point there is a roundabout on the way to my work prob like many others that the visibility to the right is non-existent unless in darkness where headlights can be seen, not all roundabouts that have poor visibility have these. Planning and anticipation are ways to limit incidents on roads.
-
Look for a system off the shelf, don't over compiacte it or over engineer it.
-
GDPR - Students Doctors details
Davit2005 replied to markberry's topic in Data Protection & Information Handling
Does this have a conflict of interest. The DPO must be free of a conflict of interest. The tasks and duties of the DPO must not result in a conflict of interest, meaning that the DPO cannot hold a position or perform tasks within the organisation that leads her or him to influence the use of personal data. -
Hyper-V virtual machine - static MAC address...
Davit2005 replied to Koldov's topic in Windows Server 2012
I don't know about Hyper-V but VMWare published a range of safe MAC addresses that you could manually assign without fear of conflict but it's up to you to keep a record of what you assign to not get use the same mac address twice :-) . VMWare have a power shell syntax you can run to see what MAC addresses you have allocated I assume Hyper-V can do the same somehow. https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.networking.doc/GUID-ADFECCE5-19E7-4A81-B706-171E279ACBCD.html Some info here https://www.deploymentresearch.com/configuring-the-hyper-v-mac-address-pool-for-a-lab-environment-and-finding-duplicates/ -
Single mode SFPs are quite expensive, I've seen Aruba SM SFP+s 3 times the cost of multimode and if you want Aruba and not compatibles you are going to pay for them, mind you if you have Aruba 2930M you've spent quite a bit on the switch to start with anyway. We mostly run MM for internal cab to cab only using SM for building to building in nearly all cases.
-
Could well of been a switch reboot, I did see some issues before where a faulty switch caused the dhcp issue. It was a real cheap unmanaged switch though, cannot remember the name off my head. We also had issue with some HP 2650's on a specific firmware and it was not reporting MAC addresses on uplinks or the local switch. Update of firmware sorted all of those though.
-
Just setup Synology at home last night to backup my personal Office365 account. It was easy to a certain extent in that I have all the internet to and from my servers at home tied down, smarthome and wifi are segregated bedind firewall and servers access behind acl rules so had to play with the firewall rules a bit to get it working. I would say not to enable any remote access to the synology NAS unless it is strictly needed and you can install packages manually. You could place the synology behind some sort of proxy too. I'd make sure that the storage where the backups are kept is not shared (no reason to be honest) and permissions are not strayed away from the defaults. You can enable MFA on the Synology so that makes it a bit secure. I'm going to have a bit more of a look into it when I get home. I've tested restore of some emails already which worked well and pretty seamless.
-
Elvis Costello asks radio stations not to play Oliver's Army
Davit2005 replied to 6Foot2's topic in General Chat
What? Lots of decent music in the late 1970's including 1978 . Also the decade I was born (ok maybe no comment on that one ) -
My first job in a school we did not have a helpdesk system, I literally got a A4 piece of paper (that was a lot of 12hour days), then when a few more of us turned up in the team we got Sysaid setup and the staff took to it very well. I used the same argument if you could log it on the helpdesk save me forgetting or I'm on the way to fix an issue if you could put it on the helpdesk that would be great, of course we prioritised stuff and if it was an incident and more priority we'd jump on it straight away. We still had teachers sitting in the staff room complaining to each other that something is not working but as usual it hadn't been logged and they soon backed down when asked if they'd logged it. The other issue is getting staff to respond to tickets either with more info or to say the issue is fixed.
-
Jus started helping to look after an engineering firms IT systems whilst still a mechanical engineer myself, over 5 years before I changed career to IT. 2K never effected us even though we had systems running NT3.5, NT4.0, Exchange 5.5 and WinFrame 1.7 for remote offices and mobile users, that brings back memories though.
-
Jus migrated 2500 APs to a new managed cluster with 2 new mobility controllers and one of the existing controllers updated. Was a very long weekend.
-
Poll: Which firewall vendor?
Davit2005 replied to Paid_Peanuts's topic in Internet Related/Filtering/Firewall
I've played with PFsense, DrayTek, and managed both SonicWall, Cisco ASA, PaloAlto and Draytek in the past I used PaloAlto for years at a previous place. They had an ASA 5500 series non FirePower before that and comparing side by side I'd say the interface on the PaloAlto wins. Filtering in the logs and firewall rules is easy and as it is an object/zone based managing rules is really easy, jus assign rules to different zones have the same rule include multiple zones, inter and intra zone rules, all the security rules are in one place/page and filters can be used to rules based on source and destination zones, objects, rule name containing specific words, destination or source IPs, etc. Site to site vpns and the GlobalProtect client vpn. The one thing to watch is the log retention for traffic logs on the PaloAlto is not great and if you have a lot of traffic it can soon fill up and overwrite older traffic logs so suggest another external log collector. -
Jus keep it clean with jus the Domain necessary roles i.e. DNS, DHCP and the AD DS services. Or consider adding more RAM and storage and virtualize as others have said (if the host is suitable) but if you do virtualize I wouldn't domain join the host itself into the domain environment with the only DC on that host.
-
Personally I've never setup a DC with more than 8GB and that includes some used in a small college too with around 3k users but that was a few years back on Server 2012r2 For a more technical answer from MS https://docs.microsoft.com/en-us/windows-server/administration/performance-tuning/role/active-directory-server/hardware-considerations
