Jump to content

Davit2005

Members
  • Posts

    5,320
  • Joined

  • Last visited

Everything posted by Davit2005

  1. If you go into MDT you can set up WMI queries and selection profiles linked to your out of box drivers. These then get injected into the build at deployment. Dell made this easy with their driver packs, something other manufacturers could learn from. Mind you with Windows 10 now it seems very few drivers are needed (if any) post deployment. Haven't used ghost or imaging for deployment for around 7-8 years now, used to use it with Windows 7 and it was such a chore especially with different software requirements on top. MDT or SCCM is the way to go INMO. We were deploying rooms of 25 PCs in under an hour with the software installed at build time, was sometimes a lot of trial and error to get the builds done but we could then literally rebuild a PC during lunch if needed.
  2. No problem. Setting up VSF stack is very easy but slighly different if you have jus 2 members. Any switches to be added to the stack should be factory reset, you can pre-provision switches on the existing stack which is very handy if you have different port counts i.e. 24/48 ports as the vsf uplinks will likely be different for the SFP+ ports.
  3. I've only seen where people have setup local NVRs at each site. There is a link to a routine for Unifi Video but Unifi Video is not supported anymore. Have you considered bandwidth needed if using this between remote sites?
  4. Right click the deployment share, then click properties then go to rules. Take a copy of the rules and then as an example of mine which sets the locale, keyboard and time zone below just modify existing entries and add the new ones and test. I'd also recommend using an service account with delegated access for joining the computer to the domain rather than using a Domain Admin account. [Default] SkipLocaleSelection=YES UILanguage=en-GB UserLocale=en-GB KeyboardLocale=0809:00000809 SkipTimeZone=YES TimeZoneName=GMT Standard Time
  5. As long as the SFP is compatible with the switch, fibre is compatible with the sfp and you have not set specific duplex/speed settings on the port then yes (check to see if other end is matched). Just make sure any vlans are copied from the copper port to the sfp port on the switch should be fine. I've seen switches before which lose their vlan settings on removal of SFPs so one to look out for.
  6. Hopefully no more MS bloatware (Candy Crush, games etc. especially on Edu and Enterprise versions), I'm not holding my breath. No links to online MS Office 365 in the start menu etc.
  7. Crikes, well glad you got it sorted :-)
  8. Very wierd, I'd be inclined to leave it stacked if possible and see what they come back with. A stacked switch is best really as they act as one meaning that you can utilise a LAG split across both switches without spanning tree blocking a link plus you have IP routing redundancy too.
  9. Strange vlans/ports configured on both ports set the same? Anything show up on the logs? Can you see any MAC addresses on the port when connected to 2nd switch or anything by looking at the lldp neighbors, sorry not familiar with these switches just trying to run through some steps :-)
  10. Are you connecting edge switches to both switches when you do not get any traffic or is a switch purely connected to one switch only. As it is stacking ports once the stack is configured and showing working properly it should just act as one switch . You should be able to connect a switch using 2 links and use them both without one getting blocked by spanning tree if a LAG is setup.
  11. HP/Aruba through and through here with 700+ switches with older HP ProCurve core. Rock solid apart from some of the older HP switches like 15years+ (mainly fan/psu issues on specific models like the 2650s) but they still get replaced under lifetime warranty. Newer Aruba switches have less of a warranty, in some cases limited to one year but in others around 5 to the original purchaser so check first.
  12. Suggest a visit to Lawrence Systems YouTube channel. It has been mentioned in more than one YouTube video review that the UDM Pro are not really up to much more than Pro home use or small business. In the best scenario a firewall will generally block traffic by default which in my opinion is the best way to go as traffic has to be specifically be allowed. PfSense, Untangle and plenty other solutions out there but if you go pfsense whilst you can build on your own hardware for peace of mind I'd get a Netgate appliance. Depending what appliance you get these can be used and setup in a HA for very little cost in comparison to some of the top players. As you mention that you do not need the filtering package this will give you a good bit of choice as from my experience, very rarely is it able to find a firewall that has firewall and filtering to a very high standard i.e. filtering is generally easier for reporting and management on a dedicated filtering appliance. I've managed many different firewalls over the years including Cisco ASA, SonicWall, Draytek, PaloAlto and a few others. I don't think you can get much better than PaloAlto for usability, functionality and the tech though but it is not cheap with subscriptions for software and functionality. When it comes to firewalls there are a few different types on how they work i.e. there are Zone/Object based, Interface (vlan or physical) based or a sort hybrid possibilities where rules can be applied to multiple interfaces at a time which make rule management easier. For example a rule on a Zone based firewall should be able to be easily copied/applied to other zones whilst on interface based it can be a chore to apply the same rule to other interfaces. You can also get 4G routers if the option of installing a sim card is not available on the actual hardware it self.
  13. Think that is more than enough. Depending on your local supply failure rate. For Comparison I have a 1500 APC at home and power a Dell T620 (4 X SATA, 2 X SAS, 128GB RAM) with 2 X 750w, a Fujitsu TX1310 M1, A synology DS1517+ with 2 bay expansion, 2930f 24G SFP+, 2930f 8 port PoE+. With that lot running I get about 30mins run time. As Others have said I'd split the Server to different circuit/supply if it has 2 X PSUs, I'd also put one of the 2930fs and 2540s on a different supply too. This would give a possibility for maintenance of the UPS although changing batteries can sometimes be done without shutdown.
  14. There is a similar thread here which is worth a read http://www.edugeek.net/forums/wired-networks/221672-ubiquiti-inter-vlan-routing-options.html There is a review here by a YouTuber who does reviews and tech stuff Just implementing vlans itself will give limited security but can be added to by ACLs etc to provide greater security. There are also some best practices that should be employed with vlanning such as preventing vlan hopping etc.
  15. That is fair enough. But bear in mind if what ever you setup for some reason breaks, and a register is not taken you can bet it will be used as an excuse and the blame will be attempted to be pointed to you that is why I always say keep thinks simple. Don't over engineer and if you design something in house make sure it is fully documented for the next guy that may come along.
  16. If you have access to the back of the server or could pull it out on wheels you wouldn't need to bother about having a server that is on sliding rails either. You could look at getting some generic server rails, basically adjustable shelves, but bear in mind weight of the server when pulling out on a sliding tray or rails that this will not cause the rack to tip forwards. And also to make sure that cables do not get trapped when pushing the servers back into place.
  17. Keep it simple. Students arrive in classroom Teacher says good morning children/students etc. Teacher takes register What could be simpler than that .
  18. A vsf stack of 8 switches is the max supported by the 2930f range at the moment. You are probably aware that you need to keep the same port speed through out a vsf stack. In the server room personally I'd go for a stack with 10Gb connections. DAC cables would work out cheapest method I would of thought but you may need to be careful with DAC cable lengths on the smaller 1U switches, they do not seem to like longer than 3metre DAC cables.
  19. This reminds me of an issue I had with Internet at a previous school. The internet would absolutely trickle depending on usage. Turned out that the cable was hanging on a few strands. I'd suggest making sure cable is punched down properly into patch panels on either end. Testing wise a proper cable tester like a fluke that can test the actual connection and make sure it is up to spec. Have you tried swapping switch ports at all as a further test.
  20. I wouldn't think you'd need to open ports external on client. I've known occasionally the local firewall to block ping once or twice. Also maybe locking down the servers which can be done via GPO would be quite ideal.
  21. Yeah looked like a hack to do Linux to Windows but not other way and the thread has been going for over a year.
  22. Hi All, Been running a Ubuntu 20.04 as a home daily driver for a good few months. One of the issues I have is that I cannot have anyone control my screen whilst sharing. Give Control option is greyed out and It reports GPU Hardware Acceleration disabled but from what I have found it isn't. The check box in Teams is un-checked for Disable GPU Hardware acceleration and running the command glxinfo | grep "direct rendering" comes back with direct rendering: Yes Also have issue with Zoom which does not seem to run at all but that is of less importance and I can get around that quite easily.
  23. You need some sort of access if only read access. If the contract ties you down so you cannot make changes I'd do exactly what @djm968 says, find a company that can give you the flexibility. It is nearly always possible to get logging enabled and track changes. We had firewall on contract but had read-only access but then contract ended and firewall became ours but support company put up a fight to give us access so we could make changes and migrate rules across we got access in the end. By all means be careful on a live system, if you can setup a lab etc for networking where you can practice. You could download a free copy of Cisco Packet tracer, although the commands would be different you can do a hell of a lot in it like layer 3 routing, setup dhcp servers, setup dns servers, etc. In ideal world it would be ideal for your school to see value in training for you but if they don't/won't then just take it on yourself to do outside of working hours if you can. You can download evaluation copies of Windows Server and Windows 10 then setup a small network in Virtual box, etc.
  24. I cannot speak for the other Cisco routers but the ASA 5505 is quite old but not sure it is actually end of life yet. Cisco site suggests last date of support is August 2022. I still have 2 at home but getting the new version of software is typically Cisco enterprise i.e. no support contract no software updates. https://www.cisco.com/c/en/us/products/collateral/security/asa-5505-adaptive-security-appliance/eos-eol-notice-c51-738642.html
  25. Is the URL a subdomain i.e. subdomain.domain.com? I use a few PiHole servers at home, they seem to do a good job and can seem to do wildcards as well which a lot of firewall/routers have difficulty with. Just point the DNS of your clients to the PiHole (if you run a domain you will need to add the PiHole as a forwarder on your DNS server). They can provide DHCP services too which gives you more info on the clients.
×
×
  • Create New...