Jump to content

Davit2005

Members
  • Posts

    5,320
  • Joined

  • Last visited

Everything posted by Davit2005

  1. Use the same address that the server is set to in the scope, in that screen shot, if that is currently working and you have no vlans. The DHCP scope should be set to use the DNS server IP address (the local (LAN) IP address of the server running DNS) so clients use the DNS server, otherwise you will get AD issues on the clients.
  2. This ++ . The default gateway will be the default gateway for the vlan/scope you are configuring. For example say you had vlan 50 with IP range 10.1.50.0/24 and last usable IP address is 10.1.50.254 is being used as gateway on that vlan then on your DHCP scope you would set 10.1.50.254 as the default gateway. As long as you have the dhcp helpers on the vlan (normally on the layer3 switch where the vlan is being routed) and there are no firewall or access lists in place that should work. Hope that not too much info overload. Even if you have not configured any vlans there will prob be managed/smart switches set on the default of vlan 1. Are you running the config wizard from the server running the actual DHCP service??
  3. DSLRs have 30min time limits on Video which is pretty crazy and not a limitation of the storage.
  4. If you had an Application layer firewall you could probably do this easily. You could try blocking from BYOD range to 17.0.0.0/8 port 5223.
  5. Defo for either a DLSR or CamCorder with an external MIC. Personally if the recordings are going to be less than 30mins I'd go DLSR. I think budget for around £600 to £900 for a DLSR with a Rode VideoMic Pro. If you can get a DLSR with audio output like a Canon 80D you can record additionally to a external recorder or at least monitor the sound whilst recording.
  6. If I don't go visiting friends/family it will be first time in 25 years I have spent in my home town/county. So hopefully things will ease, I don't think I will be going away if it is against the recommendations/lockdown or if I feel ill. I'm not so much worried about myself catching but more worried about spreading. I had a mild bout back in April and still not back to pre-symptom fitness, would not want to pass it on to anyone else.
  7. I use PiHole at home. AD DNS is set to use the PiHoles in Fowarders, 2 of them for redundancy. The benefit being that you can see from a whole network rather than having it machine based.
  8. I can think of one scenario where captive portals will prob not redirect. We normally get users to open up something like NeverSSL - Connecting ... if they have issues
  9. https://docs.microsoft.com/en-us/troubleshoot/windows-server/user-profiles-and-logon/roaming-user-profiles-versioning Not sure if this is of any use.
  10. Another vote for Synology. Maybe more expensive than a DIY build but they offer a lot of functionality if of any use. I have 2, one DS1517+ with 2nd hand Samsung SM863s as main NAS and a second for offline local backup, 3rd backup of Important stuff goes to cloud all automated and easy setup. The other is a DS918+ . Both are full of RAM running a few VMs. Personally I cannot fault them. There were some issues with PSUs a while back and also some issues with CPU on the Atom chip I believe so to bear in mind.
  11. I've heard story at my first school where an outside person had come in and recommended specific make/model. Lets just say it went pear shaped. Whilst I'd have no issue recommending hardware to a relative or friend you have to bear in mind that if anything goes wrong you and the organisation can and prob will be blamed, it is just not worth it.
  12. Never recommend specific make or model. Give specifications only.
  13. The only issue with 64bit maybe plugin support, is it SIMS??
  14. In the past (about 5 years ago) I dumped a cert on a web server the users could get to and then put a link on a captive portal page to the cert. A bit of a faff but It seemed to work OK, worked better on iOS devices as in easier as it just installed the cert.
  15. They are nuisance calls, sales by scamming is not sales. Cold calling sales is different.
  16. Scammers are fraudsters, using basic tools to make people think they have real problem when they don't and then pay over the odds for little if any protection.
  17. ++ This If you are removing printers with GPP this in itself can slow login times. Another vote to move away from Roaming Profiles here though. From my experiences they are almost as much trouble as they are worth.
  18. Have you got a basic windows 10 desktop with no customisations or third party management tools installed? Try logging in a student with safe mode and networking and see if experience is any different.
  19. You still need to keep it isolated, protect your internal network, the users/data inside of it and put restrictions in place so students cannot use it to circumvent your networks filtering unless you are going to filter/intercept guest traffic as well. I don't think there should be any question about resistance to rushing through a system that exposes the risks for the ability of the odd guest or governor to access WiFi no matter how much the push.
  20. + 1, Terminating the Guest WiFi on the firewall is a lot easier to restrict/allow than working with ACLs on switches. Once you have enabled Layer 3 on a switch every vlan that has an IP address gateway on that switch becomes routable unless you have ACLs. If you have multiple layer 3 switches with dynamic routing then you could expose more vlans to the same risks.
  21. There are a number of mitigation options depending on the switches you use and the features they provide. DHCP snooping is another easily deploy-able option and can save a lot of headaches.
  22. I think PowerShell and/or some form of scripting is well worth learning and a skill that is being valued more and more by employers, maybe not so much for support in schools. PowerShell is used in so many ways by so many different solutions, nothing is quicker than scripting for repetitive tasks and it is so much more customizable. One thing to note would be to be careful just running any script found on the Internet and put comments in the script so you and others know at a later date what each bit is doing.
  23. Don't forget to secure console access with password as well as secure access to the switch physically wherever possible.
  24. Depends what you have setup, we have aruba wireless and clearpass and can do roles on the controllers then tie down the roles via ACLs. The WiFi is all on a different firewall zone so is very easy to manage access. But a different vlan terminated on the firewall would be a start then only allow specific traffic to your internal network where required. Switching wise at the most would include setting up the vlan on the ports then let the firewall do the routing. I have used a Ruckus system before which had it's own captive portal which worked well. Bear in mind with Unifi that if the controller is down there is no Unifi captive portal unless they have changed that.
  25. Not done it myself, yet, did the change the IP address thing which it did not accept because it already had one because had been configured for another replacement (didn't realise and just pasted the code in). Put replacement switch in place, connected up and wondered for 5mins why the other switch went down in monitoring before I guessed what happened, lol. I usually hit WR M after every 3 lines of code, lol.
×
×
  • Create New...