Jump to content

slugshead

Members
  • Posts

    516
  • Joined

  • Last visited

Reputation

884 Excellent

About slugshead

Personal Information

  • Occupation
    Tecchy
  • Location
    South Wales

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. CRB have a separate product called ID store, which sites in the middle https://www.crbcunninghams.co.uk/idstore/ That pulls users from from AD using one of many methods. It monitors a folder for photographs and pulls them in too and attaches them to the user record. Idstore pushes users into their cashless system, pushes them into paxton net2, including photos. Permission groups from net2 sync back to idstore, I then pick an access level from the drop down, I can select multiple users to do this too. Our student services team also use Id store to set free school meals etc. It works well for us and I quite like it.
  2. I've had a few come down with some errors this week. Fixed it with... netsh winsock reset
  3. slugshead

    Lenovo

    They do, I went through it for a large order this summer just gone. It took a lot of hoops to jump through to get to them though. When I eventually got everything in place, they referred me to a local distributor who is their agreed partner and we carried on. There was someone from Lenovos edu team on each and every email chain and teams meeting. The discount I got at the end was disgusting. In a good way.
  4. Which server has your CA installed, check that's running (It might be on a DC if you've ever had anything RM). That will have a template certificate published that AOVPN needs, these get published to AD. You should have a group policy in place to auto renew that certificate on your devices. If that's not working, open certlm, go to the right store, right click, request new, pick from template, find the AOVPN one and next next next and you're done. I've recently setup AOVPN up from scratch, so it's all still quite fresh Verify your templates against this https://learn.microsoft.com/en-us/windows-server/remote/remote-access/tutorial-aovpn-deploy-create-certificates You can also verify the AOVPN profile, from powershell use - Get-VPNCnnection -AllUserConnection
  5. Last refresh went with AMD Epyc 9224's. Seriously impressed. Overkill for your scenario though.
  6. My DCs are all virtual, I used to run a 1U low spec bare metal server as a DC, just in case. Haven't done for a number of years and not had issue.
  7. WPAD https://kb.smoothwall.com/hc/en-us/articles/360002030230-Using-Automatic-Proxy-Discovery-with-the-Smoothwall-Filter If the users computer cannot see the proxy, they go direct.
  8. Keepass - unlock with a key file and a password. I do store a breakglass admin account on paper, in an envelope, that's been laminated, in a safe, in a locked room.
  9. https://www.currys.co.uk/products/corsair-4-in-1-gaming-bundle-2024-edition-10266645.html The most cost effective solution I could find. We do however on tournament night allow students to use their own peripherals. All mass storage is blocked so no concerns and we will not install proprietary software.
  10. Last summer we moved from AB tutor to impero ed pro. Managed to palm off the sales pitches for the cloud version. They've recently stated to a colleague of mine that development has not ended for edpro, just slowed down as they are pointing their devs at the cloud offerings instead.
  11. I'm fortunate enough to have an internet connection fast enough that a 2-5Gb update on 25 computers is barely noticeable. It's a different story though when Fortnite drop an 80Gb+ update. This has maxed out our internet a few times. Albeit, it's outside of lesson times so it's not the end of the world. E-Sports tournament nights though, there's plenty of time to get everything updated before the rounds start.
  12. https://www.jisc.ac.uk/guides/records-retention-management This is pretty comprehensive...
  13. We use the British e-sports associations list of games, that we enter the tournaments for. All free to play, students are free to create accounts with their school email addresses or log in with their own (They love to show off their in game skins). Got gaming rigs, i7, 3060Ti's, 8GB mem and 144hz 1080p monitors, nothing too overkill, but sufficient. They are standard domain joined computers, with their own OU, their own VLAN (ACLs in place to only allow what's needed between servers), same UAC level as the rest of the school, SCCM imaged etc, impero monitored like everything else. What's different? * They have their own AppLocker policies to allow the games * Different firewall/filtering rules applied on Smoothwall for their VLAN (If you don't want to use a dedicated VLAN, use an ip range). * They have their own group setup on our AV solution to allow the games and the anticheat software * They also have their own config from Impero to allow certain things Now the real challenge to overcome was updating and elevation. AdminByRequest worked wonders here, first 25 licenses are free. The approved game launchers are whitelisted and students are able to run as admin. Haven't had to go down to the room in about 4 months.
  14. They're way too late with this one. Only thing RM have been good for lately is getting good pricing on third party security products.
×
×
  • Create New...