nLinked
Members-
Posts
168 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by nLinked
-
Possible to have TMG and VPN side by side?
nLinked replied to nLinked's topic in Internet Related/Filtering/Firewall
Quick question, if I try to make a new Access Rule, then the properties for the rule don't show a Listener tab so I can't assign the newly created HTTPS listener to the rule. Would a Web Publishing Rule (which does have the Listener tab) be correct in this case? -
Possible to have TMG and VPN side by side?
nLinked replied to nLinked's topic in Internet Related/Filtering/Firewall
Thanks that sounds like exactly what we need. Will give it a go and update. We're on LGfL2 now but previously we had VPN working fine with PPTP and MSCHAP configured on TMG, but LGfL2 won't allow PPTP for security reasons, but they do offer an RDP Gateway. They said we can host our own RDP gateway on our own TMG via 443. -
Possible to have TMG and VPN side by side?
nLinked replied to nLinked's topic in Internet Related/Filtering/Firewall
Thanks both. Currently we have the normal HTTPS listener in TMG (443) which is used for accessing secure internal sites from outside. We have requested a new subdomain from our LA just for vpn purposes. Just to clarify, can we use the same HTTP web listener or do we have to make a new one in TMG? Our LA only allows RDP gateway over 443. -
When connecting from outside we are using a HTTPS address. I'm not sure about the tunnelling or how to check? But all servers have the wildcard cert installed too since before this error started happening. The only change that's happened so far is the expiry of a local cert which I believe was issued by the DC a long time ago to all workstations and servers (its some sort of internal, non-CA certificate). After deleting this, there was already another valid local one (also already installed on all machines) which really should have taken over. But we still get the error above. In Event Viewer though, I saw this today: "schannel The following fatal alert was received: 0" Googling a bit tells me it has lost the trust relationship to the DC and needs to be reset. The last post on this page has a command to reset the trust. Think this may be relevant and safe to continue with? Event ID: 36887 Source: Schannel, Error: The following fatal alert was received: 0.
-
2 days ago, we noticed we couldn't login to HTTPS addresses from outside to inside such as webmail or VLE. Whenever we logged in, we got this: We noticed a certificate had expired. It is a local certificate which appears on every workstation and server. It seems to be one that is issued by the domain controller. We removed this certificate off the domain controller and the TMG server, as well as critical servers like Exchange and SharePoint (VLE). There is another certificate already on these machines with a valid expiry and intended for "All Purposes". We have performed a gpupdate on the all servers but we still get the above error when logging into anything that passes through TMG. Any ideas what else it could be? Thanks. If we go to TMG Best Practise Analyser we see:
-
AQA E-Science - Unable to load JVM library - Windows 7
nLinked replied to J_Worth's topic in Educational Software
This post helped me. Although installing various Java VMs didn't help, simply placing MSVCR100.dll, MSVCR71.dll and msvcp71.dll into c:\windows\system32 and running regsvr32 msvcr71.dll for each file fixed it. Got the DLL's online randomly. -
We have TMG 2010 on Server 2008 R2. The TMG acts as our proxy server and has a 443 HTTPS listener installed. Is it still possible to use this same server to act as an RDP gateway (I believe this also uses port 443) to we can VPN to it from outside and let this server forward our RDP session to any internal machine? Is this something that is normally done or do we HAVE to have a separate server for VPN RDP purposes?
-
LGfL VPN on 172 range not working (RAv3)
nLinked replied to nLinked's topic in London Grid for Learning (LGfL)
Thanks, what we've done now is get LGfL to setup an RDP Gateway for us. They've bound port 3389 to our TMG public IP. They also gave us a .RDP file. This file connects us from a home computer to our internally hosted TMG server, at this point, our TMG server should accept our RDP connection on port 443. Can we do this on our existing TMG server which is currently used as our proxy server too? We need to let our TMG accept RDP connections from outside, but via port 443. -
WOW these are great! I've just tried Skeep VNC, I've been wanting a multi-viewer like this for some time, especially with AD support. I'll have to check out the other tools too! Thanks all!
-
[sims] Any way to use Nova-T4 after Summer 4 2012 update?
nLinked replied to nLinked's topic in MIS Systems
Just got the following response from Capita: "There are no current plans to remove Nova-T4 from the local SIMS .net folder" -
[sims] Any way to use Nova-T4 after Summer 4 2012 update?
nLinked replied to nLinked's topic in MIS Systems
Thanks, works great (for now)! -
Any way to use Nova-T4 after the Summer 4 2012 update? Obviously the Nova-T4 link has been removed...
-
We browse into \\COMPUTERNAME\C$ a lot. Is there any script that can pull a list of machines from AD so I can just double-click on them to browse? Or even simpler, an executable, when double-clicked, I type the PC name only into the empty box, and it launches \\COMPUTERNAME\C$ into an Explorer window as normal?
-
MS ForeFront TMG error "Routing (chaining) Failure"
nLinked replied to nLinked's topic in Internet Related/Filtering/Firewall
Thanks, but in Web Chaining I have only Default rule. The other one, the proxy one, we had already deleted. We even restarted after a few times. The default rule one has nothing in it regarding that proxy, or any other -
Looking for presentation software allowing YouTube embedding
nLinked replied to nLinked's topic in Office Software
This is a great short-term solution. Problem with this is it doesn't resume from the beginning when you go back to the slide containing it. It pauses where it was left. If this can be forced to resume that would be great! We have 2010 in some places and it's easier to embed the video, but it still won't autoplay. Haven't tried the above though with this method. Can't use sites like that due to copyright policy here. -
We have recently moved to our new ISP. On our MS Forefront Threat Management Gateway 2010 on Windows Server 2008 R2 Standard, we had a web chaining rule that was pointing to a proxy we used with our old ISP but don't any more. But with our new ISP, that proxy isn't needed so we removed the rule from MS TMG 2010. But even after restarting, the sever keeps looking for it and we get this error: Alert: Routing (chaining) Failure Description: The Firewall service detected that the upstream proxy server proxy.addressgoeshere.com is not available. If the upstream proxy server proxy.addressgoeshere.com becomes available, you may proceed as usual. If it does not become available, check the status of the upstream proxy server. Verify that the Firewall service is up and running on the upstream server. Verify that Forefront TMG Clients are enabled on the network where the downstream server resides. Check for the absence of events indicating that Forefront TMG Client listeners failed to start on the upstream servers. Why is it still looking for the old proxy? Where is it set?
-
LGfL VPN on 172 range not working (RAv3)
nLinked replied to nLinked's topic in London Grid for Learning (LGfL)
We would also have various staff and wouldn't want them to rdc into tmg first. I contacted Atomwide who said "The only way in which to do that would be configuring the NAT between are firewall and yours so that you have a one to one address that you can RDP to in the same way that you have configured the proxy server." Not sure what that means... -
Currently I'm using MS PowerPoint 2007 to embed YT videos with these steps. But it's not very smooth. When you reach the slide, you have to manually click play to play the video, not easy when the computer is at the back of the room and you are using a presenter device at the front. Anyone know alternative presentation software where YT videos can be embedded (not downloaded) easily and play automatically when reaching the slide?
-
Media server with upload, convert to FLV and stream?
nLinked replied to nLinked's topic in AV and Multimedia Related
Thanks for all the suggestions, going to give these a try. For Octopus, right at the end of setup it said I must sign up for Zencoder and have an Amazon cloud account. It wouldn't let me self-host and just get past that screen. I don't even want those accounts. Any way to bypass? -
RAv3 won't allow us to add 172 addresses as bookmarks. So I've added our TMG server's (our internal proxy) public facing 10. address as a bookmark into RAv3. How do I get TMG to forward VPN traffic to the correct internal machine? When I enter an IP address to connect to in RAv3, it says "Access to this resource has been denied". If I try my internal machine's hostname it says "Can not find server (hostname) or DNS error.
-
Anyone successfully linked ownCloud 4.0.2 to Active Directory
nLinked replied to nLinked's topic in Wired Networks
Would you know if there's a way I can use multiple security groups in the User List Filter box? I see you are using: (&(objectclass=person)(memberOf=CN=ownCloudAccess,CN=Users,DC=domain,DC=local)(!(userAccountControl: 1.2.840.113556.1.4.804:=2))) You're using a group called owncloudaccess. But I want to include a second group too. -
Anyone successfully linked ownCloud 4.0.2 to Active Directory
nLinked replied to nLinked's topic in Wired Networks
You're a star! After so much frustration your settings have worked for me. The main changes being your style of hostname (IP address), base group tree being exactly like you mentioned only with domain name changed. Thanks so much! -
Anyone successfully linked ownCloud 4.0.2 to Active Directory
nLinked replied to nLinked's topic in Wired Networks
Thanks, just tried but no joy. I just can't get it to work. Our LDAP is MS Active Directory. Other servers linking to it work fine, just not ownCloud. I now have ownCloud 4.0.4. If you use it with AD successfully and still have it would you mind screenshoting the LDAP settings pages for me please? I've tried countless combinations and it just won't link.
