Jump to content

Jaan

Members
  • Posts

    2,107
  • Joined

  • Last visited

Everything posted by Jaan

  1. 🥳 Success! Fixed Reverse Lookup Issue, but New VLAN Puzzle! 🧐 Hey everyone, Just wanted to share a quick update and give a huge thanks again —I finally fixed my reverse lookup issue! I realised I misunderstood the setup and needed to explicitly add all my ARPA addresses into my reverse lookup zones. Everything's sorted on that front now, which is a big relief! The New VLAN Conundrum (L2 VLANs without L3 VLAN SVI) However, as I'm finally starting to enjoy getting my head around VLANs and inter-VLAN routing, I've hit a conceptual roadblock that I just can't seem to figure out. Here's my current understanding that works: L3 VLAN (Inter-VLAN Routing): When I configure an SVI (Switched Virtual Interface) on my core switch (which acts as the L3 router), it has an IP address and subnet assigned to it. I use a DHCP helper (or IP helper-address) command on this SVI. When a device in that VLAN requests an IP, the core switch forwards the DHCP broadcast to my Windows DHCP server using the SVI's IP address as the source IP. The Windows DHCP server uses this source IP (the SVI's IP) to correctly identify the DHCP scope it needs to use. (The server looks at the SVI's IP and finds the matching scope). The Question: Pure L2 VLAN DHCP What happens if I just want a pure L2 VLAN without any inter-VLAN routing enabled on the core switch? In this scenario, the VLAN has NO SVI and NO IP/subnet configured on the core switch. How do the DHCP requests from devices in this L2-only VLAN get to my Windows DHCP server (which is usually in a different VLAN)? Crucially, if it does somehow reach the server, how does the DHCP server know which DHCP scope to use, since there's no SVI IP address to match it to? Is the only solution to have the DHCP server directly connected to this L2 VLAN, or am I missing a fundamental mechanism for getting L2 traffic across L3 boundaries for DHCP? I don't have any ACLs yet so all my L3 VLANs are inter VLAN routing. (not even looked at ACLs yet... i just know its a concept that exists) Thanks in advance for any insights! 🙏 Yes i did get Gemini to rewrite this to clearly get my point across! thanks again Jaan
  2. OMG heated blanket in a car is an awesome ideas!.....if you drive a auto i guess
  3. I agree its a joke. we used to be provided with electric heaters here also, until the demand on the system started to cause power trips...... we had a new heating system for the whole school last year!
  4. I'd be opening their office windows for them! 😄
  5. We have an onion skin approach. we still use sophos for staff. But for students, they are filtered by Securly..... however we also have a sophos rule which contains all the nasties you really don't want the kids accessing as a fail safe.....it's not as granular as securely. We also have Sophos AV web filter that does the same thing as the firewall web filter. The student filter kind works like this: Securly---Sophos AV web filter--- Sophos Firewall like i say, the filtering is working fine, but the a lot of the traffic that passes through the sophos i suspect is securly but it's wrapped in a "secure socket layer protocol" when looking at the XGS Dashboard. Drilling down on Sophos its FW rule 10 which is student AD account webfilter Sophos is reporting only 8% decrypted and looking at the SSL/TLS errors... "sslcheck.securly.com" comes back as "Couldn't validate server certificate (19007)"
  6. Hello everyone, I'm hoping to get some insight from others who might be running a similar setup. I don't have a critical operational issue, but more of an annoying bugbear with my Sophos XGS reporting. I'm finding that only about 13% of my SSL/TLS traffic is being decrypted, which means I can't see the vast majority of it in my reports. This seemed to start around the time we implemented Securly. I'm not sure if that's coincidental or the cause. When I check the SSL/TLS errors page on the XGS, I constantly see a: "couldn't validate server certificate (19007)" error against "sslcheck.securly.com All client devices do have the Sophos Certificate installed. However, because we're using the Securly Filter Extension for filtering, the Securly HTTPS certificate isn't necessary for the main filtering to work. Is anyone else using a Sophos XGS firewall alongside the Securly Filter and utilising the Securly extension for user authentication? I'd be very interested to hear if you encountered this same reporting/decryption issue and, if so, how you resolved it! Thanks in advance.
  7. yes it does. i missed it a £8.88 once!
  8. Spec and price if able? Thanks
  9. I paid £37 for mine but had to awhile from temu for it to arrive.
  10. I understand your pain, not only do i have to hear it all day in the school.... i have 3 kids also....... if find the best way to stop them saying it, is to say it yourself totally out of context as a "uncool dad"! 😁 "Sophia, can you pass me the remote please, 67!" ............. 🤣 "Wifey, do you want a brew, 67!"
  11. At least it wasn't 67 !
  12. What did you guys pay from amazon?
  13. Anybody able to share some pics?
  14. Hi all, We're at the beginning of our rolling IT plan, and we're looking at shaking up our hardware a bit. Right now, we've got Stone PCs in unistands (pic attached), but we're thinking about moving over to an All-in-One solution. I know a lot of companies make these (not just Stone; Very PC does them, too), so I just wanted to tap into your experience. Have any of you guys worked with AIOs before and have any feedback, good or bad? and the brands you're using The only non-negotiables for us are: We don't need touchscreens. Anti-tamper features are an absolute must-have. Any quick insights you can share would be a huge help as we start narrowing down options. *I don't want any suppliers to contact me with regards to this just yet. Cheers
  15. Funny you say that.... i had the same experience! started a new Cyberpunk 2077 game.
  16. Only issue i can see, is that anything i drop onto vlan30 (works fine) but i'm not getting anything in my reverse and forward lookup zones on the DNS server for that ip/subnet. Any ideas?
  17. I'm very happy with it. I'd go as far as saying best controller i've ever had..... after my 6 button Sega Mega Drive pads of course!
  18. Yepo mine arrived from temu. Its awesome very happy with it!
  19. It's due today 😁
  20. Its alive! I have now managed to create a new VLAN30 and i'm able to get a dhcp ip from the new IP Scope from the Windows DHCP server..... i've added static scopes to the core switch and XGS and i'm able to ping from the vlan30 client to the DHCP server/s, Sophos XG, the new SVI on the core and access the internet (once i created a new firewall rules for the test machine). Just wanted to say a big thank you to all the responded, especially @Davit2005 who has been extremely helpful in answering my noobie vlan questions..... thanks for your patience ...... also Google gemini has been really useful also. Think i'm gonna stop here and enjoy the rest on my last day until next monday! woohoo...... roll on the rest of the VLANS! Cheers
  21. I have LAN and interface settings on the firewall for the vlan 1 subnet already inplace from before i started messing. i can't see any static routes tho.
  22. Infact my current VLAN1 the flat network can access the internet even though its gw has changed from my firewall Ip to the SVI GW. My Firewall already knows about the VLAN1 subnet My newly created VLAN30 clients even though getting an IP can't access the internet. Their GW is the SVI of their vlan.... i assume thats because my firewall isn't aware on my new VLAN30 network..... i have set a static route on my Core switch back to the firewall ip. 0.0.0.0 0.0.0.0 10.15.20.2 (firewall ip)
  23. Yeah thanks for that, i'm taking small steps.... i'd like to get the VLANS in place then do the ACLs. slow migrate from the flat network to vlan with ACLs and implement instages. I guess my next step is static routes on the Core switch for the firewall/internet and also one on the Firewall back to the core switch
  24. i've added my existing flat network 10.15.20.0 /22 to my L3 switch svi and i'm now able to get dhcp requests for my new vlan from the dhcp thats on my "old" flat network. That network is on a different subnet so i guess adding an SVI to that subnet allows te switch to be aware of it. I haven't created a static route on anything yet. But i'm get DHCP and able to tracert to 10.15.20.111 from my client on the new vlan now. Internet next! Thanks for all your input, gonna step away from it for the moment a documents a few things before moving on.
  25. Update: This was a known issue by Google which has since been resolved. -------- Case Subject: Student account appears disabled on their Phones Case Comment : After reviewing the information you provided, we believe that you may have been affected by an issue that has already been resolved. Please review the details below to confirm that we've correctly identified your issue - A subset of customers in EDU domains are experiencing issues accessing Gmail mobile applications: Affected Product(s): Admin Console Status: Fully Resolved Description: A subset of customers in EDU domains are experiencing issues accessing Gmail mobile applications. How to diagnose: Affected customers may have experienced issues accessing Gmail mobile applications. Gmail web access is unaffected. Workaround: Customers can access Gmail from the web browser. Current update: At 2025-10-26 02:21 UTC (21 hours ago): The issue with the GMail is resolved for all the users on Saturday, 2025-10-25 12:05 PDT As per our preliminary analysis, the issue was caused due to a recent code change introduced to OneGoogle for Android and iOS apps. Our engineering team mitigated the issue by rolling back these problematic changes. We apologize to all who are affected by the disruption. We thank you for your patience while we worked on resolving the issue. Previous updates: At 2025-10-25 02:54 UTC (1 day ago): We are experiencing an issue with Gmail beginning on Friday, 2025-10-24 10:45 PDT. Our engineering team has identified the root cause and implemented mitigation measures. And, currently we are monitoring the status of mitigation. We will provide an update by Monday, 2025-10-27 11:00 PDT with current details. We apologize to all who are affected by the disruption. ---- At 2025-10-25 00:18 UTC (2 days ago): We are experiencing an issue with Gmail beginning on Friday, 2025-10-24 10:45 PDT. Our engineering team continues to investigate the issue. We will provide an update by Friday, 2025-10-24 20:30 PDT with current details. ---- At 2025-10-24 22:56 UTC (2 days ago): We are experiencing an issue with Gmail beginning at Friday, 2025-10-24 10:45 PDT. Our engineering team continues to investigate the issue. We will provide an update by Friday, 2025-10-24 17:30 PDT with current details. ---- At 2025-10-24 20:51 UTC (2 days ago): We are experiencing an issue with Gmail beginning at Friday, 2025-10-24 10:45 PDT. Our engineering team continues to investigate the issue. We will provide an update by Friday, 2025-10-24 16:00 PDT with current details. Please review your case and take any actions as requested. If you have any questions or require immediate assistance, please reply to this email to contact Google Workspace Support. Thanks for choosing Google Workspace. —The Google Team
×
×
  • Create New...