Jump to content

rjs_essex

Members
  • Posts

    13
  • Joined

  • Last visited

Reputation

5 Neutral

About rjs_essex

Personal Information

  • Location
    Essex
  1. Thaks for the extra info, much appreciated! Ok... I've done a little testing with this method and it seems to work well, except, the windows store apps fail to load with the usual 'You'll need a new app to open this' message. This is both good and bad... Good because it removes some of the things that there appears to be no supported way of removing - The 'Mixed Reality' app being one of them (I've tried various ways/hacks/etc but it always remains). The bad, because 'Calculator' is one app that I think people will miss! Ironically, Edge works using this method! Have you had any success yourself with this i.e. not breaking the built in apps? I tried the 'Copy To' method and have had issues with the profile loading at all. If/when it does the start menu layout breaks or the start menu doesn't load at all (which brings back memories of v1511 from days gone by)...
  2. What benefit would you see with this though? Aside from having a central profile that you could manipulate easily, would this not increase network latency? And is this not effectively creating a mandatory profile of sorts? I assume you plan to point users AD accounts to this profile location? I currently use roaming profiles and have a script that runs at shutdown/restart that looks in the users area and deletes any folder that exists with a numerical value in it (none of our staff accounts do)... This tidies up any that the system/GP settings miss if the students don't log off correctly. I'm desperate to get away from roaming profiles because a large percentage of support tasks my team have to deal with are corrupt profile related!
  3. I'm also very interested in this. So far I have: 1. Removed all of the bloat from the Windows 10 image. 2. Set up and configured UE-V and have this working exactly as I need now (ven in its fairly limited capacity). 3. Set up and configured start menus using redirection and custom .xml layouts 4. Configured various other Group Policy / Preference and locked down features using various other methods. The thing that I am a little stuck with, and stuggling to find a solution that will be furture proof, is profile creation. I dont want to use roaming profiles becuase Microsoft are turning their back on them. Mandatory profiles are also seeing limited support in the furture. So this leaves local profiles. But what do we do with thousands of roaming users that are only logged on for an hour at a time. My thoughts are: Staff: Use UE-V with local profiles. They all have their own laptop so a local profile will grow with them and aside from the odd time they need a laptop fixed or they forget to bring one in, I belive UE-V should do enough to see settings populated between devices for each user logging on. Pupils: Use UE-V with what????... Log on times aren't slow but they certainly aren't as quick as they could be with a mandatory profile... What do we use in its absence? I don't see how we can have each pupil log onto a computer and that machine create a new local profile each time. The defualt profiles that Windows 10 creates is like OP states, around 200Mb (mainly with a load of OneDrive tat). Or, do we do this and strip the local profile down as much as possible to make it as lightweight as possible? And then do we perform some sort of clean up routine at log off or when the profiles area exceeds a certain size? I currently script this to delete any roaming profiles that get left behind if a student just switches off a computer so could do something very similar.
  4. Is anyone currently using Smoothwall for filtering with Windows NPS for RADIUS authentication? I have a Ruckus wireless network and there seems to be a fair amount on the forum about using the Smoothwall as a RADIUS server, however, from the documentation I have read, the Smoothwall RADIUS does not allow for restricting certain users from joining wireless networks (i.e. if I only wanted the sixth form to access the BYOD network). I can see it would be possible to deny Internet access once a user is connected to a BYOD SSID however, this would mean an unnecessary traffic overhead from client devices joined to the wireless network that can't do anything. At the moment, my network denies access based on NPS policy/AD group membership. If the client doesn't meet a policy within a set time period the Ruckus drops the connection. Please let me know if I have completely misinterpreted this and am talking nonsense. Is it possible, but not many people are doing it, or is it a case of using NPS as a RADIUS accounting server and forwarding the info from there or from the Ruckus to Smoothwall?
  5. I've tested this update on two different installations and we are no longer seeing any crashes /lock ups. It was something that was very easy to replicate because it would happen so easily so it looks like the March update fixes the issue! Will report back if we run into any other problems with more testing. Thank you!
  6. Have you noticed anything in particular that causes it to crash/lock up? Is it the same Group Policies or do you believe it is something else? - - - Updated - - - I'll give this a go and report back if it improves the situation. Thanks.
  7. Is anybody experiencing problems using Classic Shell causing File Explorer to crash? I think I've narrowed it down to a few possible Group Policy objects but not sure where to go from there... At the moment, if I enable the policies: Admin Templates > Windows Components > File Explorer > Hide these specified drives from My Computer > Restrict C drive only Admin Templates > Windows Components > File Explorer > Prevent access to drives from My Computer > Restrict C drive only After approx. 1-2 minutes of using the system File Explorer crashes and hangs. If I revert these changes in GP and enable access then the user can log on and use it as normal... It only seems to happen when you either select 'This PC' from the start menu or click 'This PC' in a file explorer window. Has anyone had similar issues with Classic Shell installed? I've tried the latest version 4.2.5 and even 4.2.4 but still have the same problem. We have extensively disabled group policies to narrow the issue down to these two, however, this could well be a complete red herring... As various other users it works fine so its definitely a group policy issue or a settings conflict somewhere along the way...
  8. Thank you everyone once again for your input. I am certainly leaning towards the Smoothwall at the moment... How up to date is this attachment? Thanks!
  9. Thank you everyone for your input on this, it's much appreciated. There's certainly a lot to think about. I'm surprised there hasn't been any mention of Barracuda as I thought they might have been a strong contender. And Sophos was not on my list of contenders originally! Are there any other Bloxx users here that have already moved away to a different solution? If so, what did you go for? Also, for those of you that use Smoothwall, do you use it as a captive portal for BYOD traffic? I currently have a Ruckus wireless system that I was going to use as a captive portal, however, the Ruckus system (at least the system I have on the software version I have) is not able to push iOS devices from one SSID to another so as far as creating a provisioning/on-boarding portal goes, this failed miserably. I'm not sure if this is a Ruckus failing or a general iOS failing? I instead have separate BYOD networks that users connect to themselves, they then authenticate via RADIUS/NPS using their AD credentials... The Bloxx then filters based on policies assigned to the different subnets these wireless networks are on. I then have applications running on my DHCP and NPS servers to match MAC/IP addresses to NPS/AD credentials for reporting. Its a little cumbersome but does work... The only downside to the way I have it set up currently is that they are never prompted to install my CA certificate and so many complain they can't access certain sites/applications because SSL interception fails...
  10. Hi all, I'm currently a Bloxx customer and for obvious reasons looking for an alternative (and soon). I've had web demos of a number of products but would like to get peoples opinions on what you use now, what you have used in the past and what would you would buy if you had to renew right now. I use Bloxx for NTLM authenticated web filtering on the domain and transparent filtering on various BYOD networks plus I use the firewall features. So far I've looked at: Lightspeed (which currently does not have firewall features until May at the earliest) Smoothwall (which I currently have an evaluation unit for) Fortinet (web demo scheduled for next week) iBoss (the interface for which I wasn't very keen on) Barracuda (which supplies separate firewall and filtering appliances so is the most expensive yet possibly the most flexible) I'd really appreciate peoples thoughts and opinions as I an not sure which direction to head in! Thank you!!
  11. I've been running 'Everything' for a couple of days but no server hangs as yet so have been researching in other directions. After searching for every conceivable thread or article on the Internet related to this issue, clutching at straws begins and potentially fixes the problem! Came across a very old thread on the Internet whereby someone else had a similar issue with the Server service. After reading through the thread (which I think I had stumbled on before and dismissed as nonsense :-/ ) decided to give it a try. Their suggestion was to change the 'Log on as' account for the Server service from Local System account (the default), to a domain administrator account, accept the change and restart the service (which for me on one out of three systems crashed the o/s). Then change it back again to Local System Account. I have noticed that this invokes a key change. The Dependencies list for the 'Server Lanmanserver' service changes. It adds in Computer Browser, which as far as I am aware, is disabled and not running IF network discovery is switched off. Maybe someone else could confirm this? And or how their environment is configured by default? So, I changed the Computer Browser service startup type to Automatic and now when I restart the Server service, all dependencies restart and the Server service starts correctly as expected! Conclusion? A misconfiguration in the registry *somewhere* due to an update/upgrade/previous change that has caused the Log On as credentials strings to become corrupt in some way. Or a similar upgrade/update/previous change that has affected the dependencies of the Server service which in turn has affected its ability to restart/start after a certain number of shares/file share sessions are created.
  12. That's some good investigation work there! Thanks for that information, I will certainly look into some of these suggestions. Like you say, the issue I have only occurs on file servers that host multiple file shares and directories. All of which have varying characteristics. Using the techniques above I will need to wait until one of the servers in question crashes again. The annoying thing here is that I have no idea when that will be. It is not all that frequent, although there does seem to be an emerging pattern as it always seems to happen on a Thursday at around midday... I can force the server to crash simply by restarting the Server/Lanman service, but this doesn't really give me any indications other than that the problem still exists and will continue to happen as and when the faulting application/file/process occurs at some point in the future. Beyond this, I have checked all of the file shares, permissions, protected system files and nothing else is showing itself (yet) as a contributing factor. I'll hopefully be able to update this thread when I have more information!
  13. Odd that I should stumble on this thread after you have only just recently posted it. I am having a very similar problem that I am currently investigating. I have had one Hyper-V VM display the same behaviour in recent weeks, however, it is running Windows Server 2008 R2. I experience exactly the same problem as you, if I try to restart the server service it hangs in a stopping state. If I try and restart the server it crashes at 'Shutting Down'. I then have to force it off. Today, I now have two other servers that are displaying the same behaviour. One is a physical machine, the other is a VM hosted on a different Hyper-V host. As with the first, these do the same thing. There seems to be no correlation with any events and the event logs on all three servers are completely clear. There are no errors an no indications as to what is causing the problem. One system is an applications share server, the other two are domain controllers, print and file servers. I have force restarted one of the servers today and on restart I am able to restart the server service without any problem. It's not until a long period of uptime that the system them runs into problems. Searches have yielded little results due to the generic nature of 'server service', however, I've had a little more success with searches for the lanmanserver service, yet still have no solutions... I have run protected file system scans, trawled event logs and run various tests on the systems but there are no apparent reasons for the behaviour. On service restart I get the generic .net framework related 'Error 1053: The service did not respond to the start or control request in a timely fasion.' error which is little help. Could this be nic, network or switch related? Have you hit on anything as yet?
×
×
  • Create New...