-
Posts
161 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by amfony
-
Hi Gang, Got a simple one that im really peeved at my self for not getting over. I guess, these things happen to crusty netadmins once in a while. I've recently found the need and time to give webHelpDesk a crack and found it be all sorts of lovley, so much so im hosting it (as a service provider to a few disjointed schools) at a rackspace cloud server (do i get paid for this advert edugeek? lol) So what ive done is on my ubuntu server up in the cloud created a ssh local port forwarding tunnel to my schoolA which is port forwarding port 22 on external IP through all fw's to land at a DC which has a SSH Server instaleld temporarily and the look for port 389 (the cli goes: ssh -L 2020:ssh.school.com:389). This works, but i do not like it. Id much rather have a SSH server acting as a proxy that would accept ssh connections from my rackspace hosted WHD then pass on this connection to DomainController:389. This removes a attack surface on the DC of an SSH server and also will help with consolidating multiple external requests for ssh to internal servers. Where ive falled and cant get up is the ssh proxy server part. I cant conceptually grasp what sort of port forwarding (is it local or remote now?) i need to achieve what i want. Truly just a bit stumped here. Thanks for any/all help guys and girls.
-
xenserver backup scenario + how to (help)
amfony replied to amfony's topic in Thin Client and Virtual Machines
andrew thank you very much mate. im suprised to hear that xen has such little third party support. Im not sure the market share percentage but id gather there is enough to warrant such backup solutions. also suprised to see there is not native functions to address this, not even with platinum support if i read correctly. -
hi Gang, I have 2 wonderful dl380's to use for virtualisation project for a new campus and have decided to install Citrix Xen Server on both (5.6 sp2). one of the servers (virtual hosts) will be sitting static to provide a poor mans DR (not fault tolerance) via a backup process of nightly or weekly backing up the VM's from VM Host A to VM Host B. Where upon issue with VM on live host A i would start up VM on host B and take down VM on host A. What i am after is how do i actually do this? i know that xen has poor 3rd party backup options and i know scripting seems to be the glue to everything in xen. I was wondering if anyone had experience with this or could suggest anything here? thanks in advance
-
Wireless - Active Directory - Radius - Pre-Login - Scripts - Ahhh!
amfony replied to fr4j0's topic in Wireless Networks
no with an if, or a yes with a but. yes, you can have a wireless laptop configured with WPA-PSK credentials that will allow it to participate on a WiFi network to allow it to authenticate (allow non cached users logons) BUT this is not an ultimately secure or scalable solution. no, IF you want premium security, scalability and granularity FreeRadius is a *nix based radius server, never used it. I know Geoff uses/used it and recommended it awhile back with packetFence. IAS (internet authentication service) is part of the windows 2003/2003r2 family and is free with the server license NPS (Network protection service) is part of the windows 2008/ 2008r2 family and is free with a server license HTH -
Windows 2008 r2 IAS/Radius Setup Guide -- any exist?
amfony replied to amfony's topic in Wired Networks
i couldnt find any but i did succeed to get it up and running (PEAP) for both mac (lion) and XP clients. Macs are authenticating via their AD binded computer account whilst XP swap from computer account to username upon logon. Cheers anyway -
is the finder window open last thing before restart or logoff? if your using lion i know it gives the option to re-open windows as they were pre-logoff
-
Hi there, are these mac's bound (rather then joined) to the OD master? Are they on the same or different subnet from the OD master? Have you configured these mac manually (configured computer accounts) and STILL does not show? (thats weird) ill probably be of minimal help but Ill be interested to hear how this is resolved
-
Hi Guys, Im just linking for the benefit of the group an apple discussion between myself and Mr Rocco (im sure he floats around here with the Neo avatar) regarding some changes to kerberos and OD / AD trangle-ing and also a previous link to a q i had about lion integration in general. Hope you find this beneficial. https://discussions.apple.com/message/16427819#16427819 Regards and Thanks to Mr Rocco
-
- 1
-
-
Hi Gang, Just wondering if there was a 2008 version of the wonderful 2003 guide written by the Ashby guys in the past in regards to WiFi Radius authentication. I did a search and found nothing just wonder if any existed. Thanks alot
-
IAS and certificate "weirdness" (WiFi Radius Auth)
amfony replied to amfony's topic in Wireless Networks
thanks spc i have checked that the cert has not expired and it was issues from a domain bound enterrpise CA (2003r2). I am at a loss but i will recheck all. The issue is definatley certificate related however and not anything else. Thanks for the help and more so thank you for guide. -
IAS and certificate "weirdness" (WiFi Radius Auth)
amfony replied to amfony's topic in Wireless Networks
ok well no info re: certs and CAs however i did deploy the cert via the Trusted Root Authentication Store in Group Policy which sent the certs out again and resolved all PC related cert issues. Thanks for the views atleast. -
Hi Gang, Got a weird one this week. I setup my WLAN Auth via the famous Ashby Radius doc thats floating around edugeek for quite a while now and it has been working flawlessly since. This week I got a report that some of our macs were dropping of the WLAN (ruckus) and via troubleshooting/investigating it appeared the certificate that was instaled on the macs (imaged) was no longer valid and i went around and manually installed the "same" certificate over the existing one and hey presto it worked. Same certificate, didnt expire, same method of installing into mac osx 10.6 (wifi system profile, certificate trust etc). Now my XP Laptops do occasionally fall off, its just the way its always been so i know quite well what needs to be done to resolve the issue. Via the guides help i know that i should expect a certficate (named here IASServerCert) in my trusted root store in my laptops because they are domain clients and the cert was issued via an enterprise domain-bound CA Now however the cert doesn't appear in the clients trusted root store, after many domain join-leave-rejoins. I can however export and install the cert without issue. This is not the point im more interested in why the cert is now longer in the enterprise trust store. Upon investigating i can see in the CA's personal managment, that is the CA's certmgr.msc rather then the domain CA interface that there are 2 certificates in the "intemediate cert authorities > cert revocation list" folder. This is definatley not expected but i definatley dont want to start moving/deleting certs particulary if i have to re-config all few hundred laptops. Can anyone assist here please? Any ideas how to troubleshoot? Thanks Gang, as always - mucho apprecaited.
-
In retrospect i should have posted this in the VM forum. Apologies. Hi Gang, This is pie in the sky project im setting for myself to complete. What i would like is some input and direction overall to acertain the validity, feasibility etc of this project, as follows: Inspiration for the project The bane of my existance in this network is differing hardware models and large number of clients. I would like to create a single "universal" virtual image i can deploy easily to clients when required. Im hoping to leverage the vanilla-bility of generic VM drivers and somewhat superior driver base of linux to overcome this. Requirments To update a single image/vm (per OS) and deploy to clients To allow multiple OS'es to be used at a student desktop (boot inbetween Windows XP and linux dsitro) To run with minimal additional cost as possible (vmware view/xendesktop too expensive/feature rich for a test project) To run on 32bit systems (with Intel VT) My thoughts so far ... Install (manually) a linux OS on each computer which i would then modify to automatically load KVM and hopefully leave at a menu structure to select VM of choice. I have no idea how to do this atm but im sure its possible. Also ive never used KVM before -- im assuming this is possible at all just by reading features sets off the net. What i need to work on How can i modify the linux base OS to automatically load kvm and load a "menu structure" How can i deploy the linux base OS with modifications to a lab without manually installing it Testing our software suites in the VM's of varying specced hardware (CAD, 3d modelling for example) Your input ... Always appreciated. I put this here for both feedback from the crowd and also for my own hitlist of things to accomplish. If there is no feedback thats also fine. Cheers
-
Restricted user needs access to folder on C:
amfony replied to mhundley's topic in How do you do....it?
i literally did this today. subst.exe command (im using XP) will assign a drive letter to a local folder/resource. I had the same requirement (for a different reason) and instead trying to allow C:\anything (GPO blocked this) via shortcut i instead made a Q:\ which points to C:\StudentData\TempSaveLocation. I ofcourse scripted the creation and icacl'd the folder as admin but the subst runs on a local startup script in a certain AV lab of computers. HTH -
ive got no positive comment other then "yes, ive had this issue as well" seriously -- i dont know if the nics support WOL/MagicPacket. Only cause i dont know much about the nic hardware at all. Either way id love to have this functionality
-
Thanks Guys, Andrew specifically -- that is exsactly what i am referring to. Not to make my clients desktops "thin clients" rather then allow them to leverage VMs opposed to traditional OSes installs. XenClient looks like it can achieve A,B,C of a total solution (with flexcast) but all im interested atm is step A. Thanking you both
-
hey gang, i was at uni the other day and i had to login into what was a pure *nix lab, now a multiple OS lab (win vista, centos, and another flavour of *nix). Computer booted into what i thought was centos/redhat -- dissapeared (monitor black) for 30 seconds then left me at a OS selector. selecting centos i noticed the OS loading within a window which leads me to think that this was a vm starting rather then parition selector type deal. ive come to the realisation that the base os is a hypervisor type deal or a *nix with custom startup into a vm manager menu. This is pretty sweet! can anyone enlighten me as to: this is popular within schools to provide ms/*nix easily and interchangably how would you go about deploying a lab like this? what os would be acting as the hypervisor/base os? would this make images (vm files) fairly "universal" to maintain (within the same os obv)? thanks guys -- any info / comments greatly apprecaited.
-
Hey Gang, Been quite a while, ofcourse i again will ask for help. I have minimal mac deployment experience, that said ... I have a mac server (10.6.5) netBoot server running with an image i use for netrestore working well. We received a new set of hardware and these imacs/macbooks wont "start" netrestoring. (yes to globe, yes to little spinning globe, no to anything after that and left in with a grey screen and apple logo) I created a new image updated to the latest update 10.6.7 then hoped that this would be able to be deployed. It is not deploying due to what i believe is a lack of "combo update" that should have been applied to allow other makes of hardware to be imaged if i understood apples website article correctly. So ive got an DMG of the source computer at about 20GB. If i cant deploy i still need to get this image to about 40 computers, ofcourse asap. My next route was to expand the dmg onto a client via the install dvd disc to open disk utility and "restore image to destination". This takes along time, like, alonng time and is tedious -- not so much the image expansion rather the booting from install dvd to access disk util. Can anyone give me any tips or tricks how i can get my dmg expanded to clients in the most effectve way. i understand that netrestore would be the best bet but thats not workingn atm. I would potentially like a script to boot into bootable usb and restore dmg onto disk 0 type deal. I do not know/think that is possible however. Thankns in advance if anyone can assist. If not, edugeek i still love your work.
-
Hi Gang, Another day another question. We run a Xenserver with a handful of utility type service VM's running, it was only ever a P.O.C and nothing of consequence runs on it at this stage. I backup the VM's to a physical file server via XenCentre which depending on the size of the VM can take 10 minutes to 30 mintues. My VM's are currently between 10GB and 30GB usually. I understand that in a mature solution the OS's and DB's would be virtualised and the raw data (CIFS, SMB) would be available and centrealised on a SAN/NAS, this is not that case. If the size of the VM increases significantly, IE 100GB how are backups addressed? As far as i know (limited): Snapshots are not 100% 100% guarenteed backups are achieved only when VM is unavailable VM size == size of data (no or limited compression) If these are wrong please let me know! So what i do see is this, you can only guarentee backup consistency via taking the VM down, if that VM is significant is size it will just take that long to backup it up to another location. Now i write this it all sounds so obvious but just looking for some concrete answers. Also does anyone know of any good XenServer literature, best practices etc. I know Citrix provide some good docs but i just hate their site lol. Thanks squadron
-
hmmm i dont really see a concensus here. I think there was a valid point made about HP pushing procurve ultimatley over 3com, making procurve a winner in this awkward situation. In addition the lifetime warranty is definatley a positive. Im never worked with HP firmware, however Im very comfortable with IOS and obviously the 3com older a new OS's. How different could it be? Based on reputation alone i dont have a problem pushing to move to a HP platform at all. Atleast ill have heaps of edugeek support haha. Thanks to all for participating.
-
Hey Gang, Just like to bounce some ideas and hear responses re: HP/3com and my situation atm. We are at the point now where our old 3com 100MB switches are going to be replaced with new 1GB switches. In total our switching layer occupies around 15 indivudual switches of majority 24 with minority 48 ports. So its time to upgrade. We have always been (for better or worse) a 3com shop. Weve had 1 switch fail in around 7 years and its been easy enough to work with so im actually quite pro 3com even though i know some arn't, specifically in this forum where procurve seems to be the default (might be a UK thing) However, since the HP buy out i am not sure of the longevity of 3com as a brand. IE should i be pushing 3com now for the next major platform, or should now be the time to move over to the procurve way of life that, i cannot ignore, seems to single handedly be running the UK education system without major issues. Just at a cross roads, any comments or suggestions are welcome. Thanks in advance.
-
Hi Guys, Simple question -- does anyone know if stonespire pureNAC is still in business? They looked like they were on the cheaper end of NAC products and videos on youtube looked promising but now their website: StoneSpire.co.uk going to a russian(?) site of some kind. Thanks guys
-
gentlemen -- top class assistance. Thank you all.
-
Thanks for the help guys. Thanks powdarrmonkey -- ive never utilised a reverse proxy before. Could this reverse proxy do host-header redirection as well as the wildcard ssl placment? Thanks again!
