Jump to content

Davit2005

Members
  • Posts

    5,320
  • Joined

  • Last visited

Everything posted by Davit2005

  1. The best route is to set up a service account and then specify only the needed delegated rights to add computers to a specific OU. Then specify the OU in the answers. Don't be tempted to use a domain admin account as I've seen these compromised. The instructions I found on the www somewhere for the permissions needed. An example of my home MDT setup for joining domain. adjust to suit your domain JoinDomain=test DomainAdmin=serviceaccount DomainAdminDomain=test.local DomainAdminPassword=password MachineObjectOU=OU=MDT Deployed,DC=test,DC=local
  2. The way I have done this in the past is do a re-directed desktop to a folder that all the users only have read access to. This means you can drop specific items i.e. shortcuts on the desktop which can be handy. Done this in Windows 7 not tried in Windows 10, it was over 5 years back.
  3. Thanks for update and posting link :-)
  4. Yeah I am not convinced USB network servers will work in all situations, they are best suited for connecting storage INMO :-) . Good luck.
  5. Not the reply you are looking for but StreamDeck on Ubuntu is a PITA. There are issues such as Windows losing focus etc. I gave up and went back to Windows for Video work and CAD. Use Ubuntu as a daily driver other than that and apart from the odd issue in Teams/Zoom am pretty happy.
  6. Is there some sort of client to client block going on with the Velop?? Have you thought about jus using the Velop in non-mesh then using with your managed switch if possible as a test. Interesting what you say though, I know it is not much comfort but I have recently swapped out Unifi WiFi at home with some Cisco Small Business in walls (probably rebranded Linksys, lol) and now everything works apart from my Garmin smart scales which simply do not connect to the WiFi, need to troubleshoot that when I get some spare time. I'm going to investigate my issue with Wireshark eventually.
  7. Group Policy for managed Windows devices for Apple or others you may be able to use a MDM. If you have a public CA signed cert then you should not need to. However if this is for decryption I do not think you can use public CA signed so only option would be to put a link where people can download if they are BYOD or Guest.
  8. For BYOD and Guest I'd use public CA signed. For own devices there is a security case to use your own internal and distribute by MDM or group policy. I have in the past put a link to a cert on a web server that the BYOD/Guest users could get to but was a bit of a faf.
  9. Have you tried reaching out to Teaching Tech https://www.youtube.com/channel/UCbgBDBrwsikmtoLqtpc59Bw , Nerdly YouTube cannels or forums. Teaching Tech would defo be first option. So many people have these I jus cannot see it been a usual problem myself. Customer service should still be better so little consolation I know.
  10. Been using these quite happily for Aruba 2930f switches at home. Got about 6 of them https://www.amazon.co.uk/gp/product/B07B4992G1/ref=ppx_yo_dt_b_search_asin_title?ie=UTF8&psc=1
  11. I have a Teletonika 955 4g router for backup but it does not support IPv6 but good apart from needing a reboot every once in a while. I seriously considered going 4g at home but BT gave me a good discount compared to last contract on vDSL package after I negotiated due to lack of fttp in the area and the fact that 4g is faster. Maybe next year I will.
  12. Is Veeam 11 available in the Community version yet anyone know. Interested as from what I heard it no longer relies on snapshots. Fed up with 10+ snapshots accruing on some VMs due to Veeam.
  13. I was merely pointing out for clarity jus in case anyone were to see this thread later on May of mis-interpreted an earlier post apologies for that. We have deployed lots of VSF stacks now. From using 2 switches in a VSF stack as a top of rack design with the edge switches (non-stackable) split between both i.e. LAG from each edge switch using the 1Gb uplink split between each member switch in the ToR stacked switches or having multiple stacks of 8 switches connected to a 5406 and split top and bottom of each stack between different SFP+ modules using DAC cables. Going forward it will prob be our core design with a stacked core with layer 3 from closer to edge then do away with all our in depth Spanning tree setup, lol.
  14. It can do the issue is that you lose some redundancy i.e. if top and bottom switches are uplinked to something else and the middle member fails you then lose middle only. Ideal configuration for more than 2 switches is a ring then uplinks top and bottom to stop a member being isolated.
  15. It is not just management that can be a benefit of stacking, true there are switches that only stack for management. Some benefits of true stacking i.e. one logical switch below. Ability to configure LAG across different switches (normally spanning tree would block a link to avoid loops) Layer3 routing redundancy (no need to rely on VRRP for Layer 3 routing redundancy) Lack for need of complicated spanning tree setups to split load (i.e. mulpiple spanning tree instances) Traffic on LAGs split between different Switches Management Bear in mind that firmware updates depending on model of switch can be different experiences.
  16. Just as much MS bloatware then. Links to Spotify, News, messenger, etc. All things you prob don't want in school environment.
  17. If you have a HP/Aruba/Cisco or a switch that supports it also set the vlan used as a voice vlan on the edge switch where the phone is plugged in. It only needs to be on the edge port and not the core. The benefit of having physical VOIP handsets on different vlans is that it will limit interference and noise from network devices such as printers which can be detrimental to the quality of calls (I've experienced this with printers to the point where VOIP phones have been close to unusable)
  18. YouTube sometimes puts the ads on it's own server which means Pi-Hole will not always block adds. I'm using either Fire-TV or Apple TV which goes though Pi-Hole and have pretty comprehensive lists, I still get adds. Found the below but it is on reddit https://www.reddit.com/r/Adblock/comments/ibc6dd/no_ublock_origin_doesnt_block_youtube_ads/
  19. If they are AD accounts you could prob do a PowerShell script on a schedule to change the password to a random password then email that password to reception. Even if they are jus accounts based in Azure AD should still be possible.
  20. I've found the StarTech USB31000S to be quite good for network booting devices with no network cards but a double check on the www might be worth it before commiting. You are most likely going to be concerned with the chipset then as others have said you may need to add this into SCCM as a driver. Been a long time since I did that though.
  21. Agreed the Ender 3 is really customizable and compared to assembly of the Prusa MK3 looks easy (if you buy it in kit form), kit form of Prusa is a few days work unless you are really committed, dedicated and have the patience it is literally assembly of nearly every part but the instructions are pretty clear with a small pack of Haribo's to add a few sugary breaks :-)
  22. Wish we could lock down edu like non-edu org but it seldom happens (push from curriculum, budget, time, training, etc. ). And the higher up you go in edu the more difficult the balance is in keeping research pretty open but maintaining a secure environment. Defo not saying we should give up but there needs to be a workable balance whilst protecting sensitive information and systems. Patching, MFA, user awareness, desktop/server/infrastructure hardening, lateral movement limitations, best practices for vlans, rule of least privilege account practice, etc. should all be employed. Whilst vlans can be employed and if best practice used i.e. not having client/server vlans untagged/native on uplink ports, specifically defining vlans on ports and not leaving as auto or vlan 1, disabling lldp and cdp where necessary, etc. As well as management locked down and physical security around network infrastructure. IMO vlans if configured following best practice still have their place but are jus one part of the picture.
  23. With working surfaces I'd also look at getting some monitors mounted to wall or off desk on vesa swivel mounts so you can plug PC into whilst rebuilding or testing them.
  24. Had 2nd AZ shot last Monday, bit more of a bruise. Didn't get nausea 48 hours later like the first jab.
  25. Good to know, I have not been responsible for OS deployment for the last 5+ years, I got out of it jus in time before the Win 10 fun . I still run a MDT server at home (for lab/fun, lol,) although it needs updating now (, and another reminder to do that sometime).
×
×
  • Create New...