Jump to content

Sirbendy

Members
  • Posts

    2,371
  • Joined

  • Last visited

Everything posted by Sirbendy

  1. Heh..yes..ID badges... Yes... Hmm... You'd think we'd all wear them, wouldn't you...but I don't think most people have one. I have my one from 2001, but they haven't been redone since.
  2. I own several IT themed ties..heh..but no, they are an embuggerance in my view. As are dress trousers. Nasty lightweight flimsy snaggy material can take a running leap. Smart 'n' simple has worked for the last 8 years..heh. Non uniform days, again black jeans, black shoes, and black T-Shirt...all thinkgeek, all IT Themed. The head quite liked the "I have a shotgun, a short temper, and a raised floor in the server room. Do not trifle with me." one. Kids like the "STFU, Please.", and the missus likes the "I void warranties" one. Still got to find a suitable walking stick/cane though.
  3. We're having fun with Google and Altavista. Google has a PDA renderer built into it now that the kids have found bypasses bloxx filtering, and AltaVista has the "page translator"...they're using that to access sites now. Heh. Little sods.
  4. Staff dress respectably...thats about it. I wear a shirt and smart black jeans with black shoes. Steve used to do the whole suit thing, but after 3 weeks of dust he went the same way. Ties are only a formal occasion thing...I HATE having dangly things around machinery.
  5. We got done 2 weeks back. We're 98% sure it's a woman - saw a suspicious probable female coming into the site on CCTV with a hood up and face covered, then leaving about 45 minutes later at a fair rate of speed (timed it). Had a bag on her shoulder that looked fuller on the way out. Basically, she MUST have been somewhere on site for the 40+ minutes, which is frightening. Doorframe of the music office was forced, and she got away with a Turion laptop, and 2 staff purses with cards etc. Done with 5 minutes left before the gates were locked for lunch..totally brazen. TBH, there are so many ways in and out of here it's stupid. We've had a projector taken before by someone coming in with the cleaners and then hiding in an IT suite until IT goes home and the lights go out, then removing the projector and leaving through the suites (which is when he realised he was on 3 cameras and ran). THEN we hear that the weekend before, a black woman came walking into the school theatre where the theatre of gifted youth were, and took a cash tin off a small child who was part of it, then ran. All because they left the damned emergency exit open.. and THIS is why I've disabled the "pass through" latches on our IT keycode doors. Idiot teachers who circumvent the security REALLY annoy me.
  6. Computers in locked metal boxes TFTs in polycarbonate protective sleeves, bolted to the desk. Titanium coated desks for robustness. Everything screwed down tight Fixed, bolted, metal seating (grid wiring optional with "shock" button) Tiled walls for easy cleaning. Tiled floors for the same reason Autolocking timed doors with no teacher disable function GSM jammers to stop the kiddies phones. Automated building controls for lights/heating/aircon etc totally removing the teacher from control. That might be a good start..heh..
  7. Same here. Not IT Though, or a few maths rooms...they've been replaced with cheapy atomic setters. No point in going for old "manual" clocks now, IMO.
  8. offhand, it's basically: Net use x: \\ghostsrv\user x: ghost "ghostsrv" is a P2 box running "SME Server Linux" (or E-Smith, as I know it). I couldn't connect to a Server2003 box with it, as the boot disk doesn't support server03.
  9. That's odd...was the source PC definetly showing them? I set ours to not show "Administrator", or "ICT"..all they see is "Music Student" unless they hit CTRL-ALT-DEL twice and type it in.. It definetly worked in the test VMs...I'll recheck on Monday though..
  10. Same here. The child in question is a blackbelt and very, VERY good at martial arts as well, so we didn't dare say no.. I forgot the other day, and she came to my "stable door" service hatch to get some printing..I picked it up and said "is this it?"... .."I don't know Sir...I can't see it! it's me, Robyn.." "Ah....um...hang on, I'll let you in..".. :oops:
  11. I use DBAN if requested to (Heads home PC etc), other than that..we play football with them down the stairs, or the "lob it out of the window" game.
  12. We do it out of hours (teaching day ends at 4, ours at 5.15)..reimage if an old build is found or a machine is arsing about, otherwise a rota for cleaning projectors and SMARTboards, wiping screens/KBs/Mice, and every summer we crack open the rigs and blow them out using a compressor, then check and tidy all the wiring.
  13. I've done our site images for the last 5 revisions, and I've got it down to a finer art than the LEA now - they've been told they're not required to do it for us now, but they give us the latest builds anyway for opinions. I start by doing a 2 partition flat XP install, installing no drivers and using defaults only. I then "\\" connect to our network shares and install office and the software we use. Then I set up the printing files and autoexec for the mail server connection. Then I join the machine to the domain, install the AV and configure it for updates. After that it gets disjoined again, tidied up and slimmed down (hibernate and swap files off, .tmp etc gone, no sys restore points etc). Then I copy over my "C:\Drv" directory for the Audio/Video/Nics we have that windows can't autoconfigure, and copy over my sysprep directory to the C drive from my USB stick, along with the locallinks shotcuts to the curriculum packages and a hidden one to CMiS (enabled if needed) and the ICONtool display app. THEN, I go into device manager and expand "computer", and reset the driver from "ACPI" to "Standard PC", reboot, let XP sort out all the base hardware enumeration for that HAL, then shutdown the VM and copy the disk file to a safe place for reuse in "modifications"..I've also heard the "do not repeatedly run sysprep on a machine". Then run sysprep with my own Sysprep.inf, to integrate the drivers and reseal the machine/regenerate the SIDs. Then ghost the final "rollout" image to my physical PC or our poweredge print server, which will then run ghostcast on demand to dish it out. This image technique seems to work with everything..P2 to P4, AMD and Intel, one or many cores, laptop or desktop. It runs quite happily on all of them. Plus it's a damn sight quicker than the LEA builds..login is FAR quicker and the machine is much more responsive. Removing the 8 graphics packages (often outdated), and other outdated/unwanted packages and replacing it with Photoshop elements, StudioMX and Paint.net means my latest 0707v4 build comes in at a 2.5gb ghost image ready for 95% of our machinery. The LEA's "empty base" image comes in at 6..without installed software! Any special request packages get rolled out using either RAdmin or Netsupport when requested. We ghosted 8 machines on friday night to see how quick it'd do it...7 minutes to ghost, and about 15 to run through sysprep, request the machine ID and reboot to a useable state. Very pleased with that. This is the first time I've managed to get the "non included" drivers for NICs/FireGLs etc to install as part of the sysprep..with 0706 I kept them on a network share and had the machines log into that.
  14. I now work for an Academy, and it's meant that I've changed from being paid by the LEA to paid by the academy. Other changes..um..well, the school day is now 8.20am to 5.15pm (8.30-4 for kids)...and..that's about it. We're not quite there yet though..we've been through the "staff" and "kids" changes, but we're just starting on our new site/Academy building before we move over to it in 2009 and the existing building gets shut down and whatever happens after that.
  15. I was going to say, Steadystate. I only came across it last week, and i've just cloned 4 standalone music PCs with the same setup..identical hardware though, so no syspreping. God, do the kids give me grief now..."we can't set our own anything!!!"
  16. I use ghost 8 and ghostcast...but I do it a different way to the boot disk you describe... http://netbootdisk.com/ I used that disk to make a bootable CD that would autodetect/install the networking and whatnot, then copied Ghost to a network share and had the disk connect to that share using a NET USE, and run the ghost.exe. Damn good disk..spots all of our network cards with no hassle at all, and ghostcasts a treat. Bring on the new academy building...we may be able to go RIS/PXE then..
  17. We're using NetSupport School.
  18. I'll give that a shot tomorrow then.. I'll try the squid/DG bolt-in for CentOS (SME server base), and then if that doesn't work I'll grab one of the scrap P2 boxes from storage and Ubuntu it.
  19. It may only be a temporary solution...Bloxx uses AD integration to do the authentication automatically...I think we could manage without it. Staff and students needs vary, but using the bigblacklist lists would make a good start to both, and we can always finetune site access using Netsupport School.
  20. hmm. I have 3 options...VM it on the existing box, put it on a new box, or try and set my SME Server box up with Squid and DG then... Any good guides on configuring this sort of setup?
  21. The entry door into my office has an individual key, specially for that door. IT staff have them, site manager and cleaners. The office has an Axis cam in it as well. Lockup cupboards are used for laptops etc. The entrance into the IT Suites surrounding my office are code doors using "Keylex" locks. The server room has 3 keys..me, network manager, and site manager. There's a cam in there too, running into the network cab and off to the council IT offices. We're getting an office "extension" soon so myself and the Net manager can have our own area...THEN, we'll kit the security out. Lockable cabinets, cameras, stable door, and if I can salvage one, an electric release/yale lock.
  22. Jem and I have a USB lava lamp and a USB "Stress reliever"....which led to many humorous usage suggestions. I personally want the multi-fire rubber band gun from Thinkgeek. Does a network manager count as a novelty device?
  23. Hah, yes. I worked in infant/primary while I freelanced after the stint at the council...that was fun. Helping little people learn how to use RM windowbox and fingerpainting..I'd do it again! The roamers were just a kiddified Big-Trak, and that suited me fine. Secondary is OK, but at primary age the kids are so much less abrasive.. We get Lego Mindstorms though, so..it has compensations.
  24. We've been fortunate enough to convince our NGFL that Symantec Web Security is as much use to us as a cup of coffee in the back of a CRT. As a result, we've "retired" the box, and moved onto Bloxx. Now, Bloxx has been a 'mare. It blocks at will(and will not allow you to countermand the block), crashes if you ask it to report, and is generally no use at all. So, we've had enough (as have NGFL by all accounts). NGFL are trying to hammer out a pricing deal on some other solution whose name escapes me right now, but in the meantime we're having to use Portable Firefox (with restrictions) pointing at the retired SWS box for some things that Bloxx..well..blocks. As I say..'mare. I've been playing with Dansguardian/Smoothwall/IPCop on VMware on the SWS box to try and get that running instead. It's a headache. Here's the setup: SWS box and print server - Compaq Evo. SWS runs on port 8005 (had to change it as kids were using 8002 with "unauthorised programs). SWS then filters the request, and passes it onto another machine on port 80 for the data. Parent machine has ACL set up so that ONLY a machine with the print/SWS server name, fixed IP, and NIC MAC address can send/recieve data to it. SO: I set SWS (content license expired) to "guest mode", so no login is needed. I set the filtering to "Audit" so it's just effectively a "pass through" from the parent machine to port 8005 on the box. This works for me on Firefox and IE...pointing to the Evo on port 8005 gives me 'net access without authentication. Then I installed VMWare player and the various prebuilt VMs I mentioned above, and this is where I came unstuck. None of them seem to cater for our setup! Is there any solution out there, free, that can be used in a VM on the Evo or another seperate box and accept data from the machines on the network, filter it through dansguardian or similar, and then output it to port 8005 on the Evo for SWS to then in turn give it to the main proxy on the network? Everything I looked at seems to be "one green trusted nic, one red "bad"nic"..which makes sense...except that the untrusted NIC wouldn't in our case be connected to a physical router...but would need to send data to port 8005 on the SWS box instead. Is this possible? Sorry if it doesn't make much sense..it's been frying my head after a long week!
  25. I use SME Server 7.0 on a P3/500 to serve our ghost images..turnkey install and very "walk away and ignore it" after it's done.
×
×
  • Create New...