smarties11
Members-
Posts
645 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by smarties11
-
Hi All, I installed Ruckus and SmoothWall here over the summer and set up a Guest network / VLAN for our sixth form and staff guests - open network with Ruckus Captive Portal and RADIUS accounting to Smoothwall. That works fine, but we've had a few moans from staff about the daily sign-in to the captive portal. So this morning, I've created a separate network for staff. I've created it as an 802.1X EAP network, with SmoothWall acting as the RADIUS server. Again, this works great. My question comes to groups - with the captive portal method, Ruckus picks up the group memberships from AD and I can use these on the ZoneDirector to control access to my WLANs on the roles screen. When using SmoothWall as the RADIUS server, it appears the groups aren't passed back - all users are assigned the 'default' role on the ZD. This isn't the end of the world for now, as I can specify in SmoothWall which groups I don't want to authenticate via RADIUS, and therefore I can block students from connecting to the new network that way. However, I would prefer to pass the group information back to Ruckus if possible and do the roles/WLAN assignments there as that gives me more granular control. Has anyone else who has 802.1X with Ruckus and SmoothWall set up been able to pass the group info back? Thanks!
-
Ruckus captive portal/Web authentication + iOS 10 - broken?
smarties11 replied to Paid_Peanuts's topic in Wireless Networks
We are also seeing the same issue, however it is not affecting all iOS 10 users - and those that it is, are intermittent! I've e-mailed our users and so far two have said they have had no issues since upgrading to iOS 10 and two have said they are getting the blank page. On an affected iPad, I have just tried to connect to our guest SSID 10 times - 9 of those times I got the blank page, and once I got the correct page. For now, I've told users to connect as normal, but when they get the blank page to tap 'cancel' and then 'use without internet'. This keeps them connected - they can browse to the ZD URL through Safari and then it works (I've suggested they save as a favourite). I've tried disabling Apple CNA through the ZD but all this does is stop the pop-up appearing at all. -
Hi, Just an update to say that SmoothWall found the solution. It's because the LSN router is the default gateway on the 10.24.208.0/20 subnet rather than the SmoothWall so there is no route back to the 172.16.0.0/20 subnet. For now, I've changed the default gateway just on the web servers we need access to and now the Zone Bridging works. Longer term I'll make SmoothWall the default gateway for all devices on the subnet (with the SmoothWall interface then having a default gateway of the LSN router). Just thought I'd update in case others have similar issues. Smarties
-
Hi All, I was wondering for those of you that have this set up, whether you could have a look at my setup below and find any obvious issues? We have our internal LAN for domain devices on subnet 10.24.208.0/20, gateway 10.24.208.1 (LSN router), VLAN 1 And then a BYOD VLAN on subnet 172.16.0.0/20, gateway 172.16.0.1 (smoothwall), VLAN 2 Internal LAN is smoothwall port 1 BYOD VLAN is smoothwall port 2 I have setup my core switch (HP 5820) as follows # interface GigabitEthernet1/0/26 port link-mode bridge description Smoothwall Port 1 (Internal) stp edged-port enable # interface GigabitEthernet1/0/27 port link-mode bridge description Smoothwall Port 2 (VLAN 2) port access vlan 2 stp edged-port enable I have setup the following Zone Bridging rule in SmoothWall Protocol: ALL Source interface: port 2 Source IP: 172.16.0.0/20 Destination interface: port 1 Destination IP: 10.24.208.0/20 Destination port: ALL Bi-directional: yes Enabled: yes Obviously I will reduce the IP ranges etc on this once it is working. I have RUCKUS set up to present a captive portal page, authenticated against AD and then with RADIUS accounting going to SmoothWall. This works a treat and my users can get internet access no problem. However, they can't access our internal webservers on 10.24.208.0/20 from 172.16.0.0/20, despite me having set up the above zone bridging rule. I have logged a case with SmoothWall but I wondered if anyone here had any advice to offer. Do I need to do anything else on my core switch? Surely I don't need VLAN/subnet routing in place on there when the SmoothWall can do this for me? Thanks, Smarties11
-
Just wanted to say a huge thank you for all your work on this. I stumbled across it yesterday whilst browsing Edugeek and have downloaded this morning and it looks great! We currently use Word (heavily crippled to disable proofing etc) however occasionally have issues where Word crashes on save and then the candidate loses 5 mins of work since the last AutoRecover. Going to suggest to our exams department that we trial this during our mocks later this year, with a view to implementing for future public exams. Thanks!
-
SOLUS3 install using existing SQL 2012 instance
smarties11 replied to smarties11's topic in MIS Systems
Thanks both! You were spot on - the 'compact' installer has only installed some dependencies and not an entire instance. Was able to point it at the existing full SQL 2012 instance no problems at all. They ought to update their installation instructions to explain this! Cheers Smarties -
SOLUS3 install using existing SQL 2012 instance
smarties11 replied to smarties11's topic in MIS Systems
Thanks! I suspect this will still install the compact edition but I could always uninstall that afterwards. As long as it gives me the option to choose the instance, I guess that's the main thing! Cheers - will give it a shot. -
Hi All, So I'm finally biting the bullet and installing SOLUS 3 to meet Capita's deadline of Summer 2016. I've dragged my feet up to now, as when I tried it a couple of years back it was terrible - so we've continued to use SOLUS2 up to now. We already have a full version SQL 2012 instance on our SIMS server and I had intended to also use this for our SOLUS DB. The installation manual for SOLUS doesn't appear to cover this as a scenario. When I run 'SOLUS3DeploymentServerDatabase.exe', the first part of the installation process, I am told that SQL Server Compact Edition is required before the DB itself can be installed. I can't 'uncheck' this option. It appears that the installation isn't detecting the existing full SQL 2012 instance. Has anyone else come across this? I have logged a case for Capita but thought I might get a faster response here. Seems crazy if the only supported config is for SOLUS3 to use a completely separate instance? Thanks Smarties
-
Just to report back - thankfully this is now resolved! I remembered I had a copy of the domain DRA private certificate saved on the network. I connected the hard drive of the machine in question to my own computer - imported the DRA private key - and then once I had given myself permissions to the offline files folder (\windows\csc) - I was able to decrypt and open the files. PHEW! I guess I could have just imported this private key into the users personal store and then removed once successfully synced but wanted to be in full control of the process. I can only assume that, in a situation where the client can't renew the EFS certificate due to not being connected to the network, and the certificate expires - the client then only encrypts using the DRA key? Hope this helps someone else in this situation!
-
Rolling the clock back / removing new certificate hasn't worked.
-
No, if I disconnect the network, as if I was 'at home' it still doesn't allow me to open the files. I was also just thinking about the clock. I think my next plan is to delete the new certificate from the personal store and turn back the system clock. If I can at least get access to those 30 files I can copy them off manually and then just do an offline file reset. Thinking logically, the system would have been unable to encrypt those files with the users EFS certificate, once it had expired. So the system must 'fall back' to a default certificate / encryption method? The files are there, they're obviously encrypted and I just need to work out how they were encrypted in order to unencrypt them.
-
Hi All, We use offline files here on Windows 7 so that our users can work on their documents at home and then sync when they are back in school. We have a particular user who has worked on around 30 documents over the holidays, and then when she has come in today she cannot sync the changes to the system - all modified files fail sync, and give the error 'access is denied' I suspected it may be an EFS issue; I've looked in our CA and can see that her Basic EFS certificate expired on 15/12/2015. A new certificate was issued today 04/01/2016. I've checked that both of these certificates exist in her personal store in Certificate Manager and they do. When I try to open any of the files modified since the old certificate expired, it says 'Access is Denied'. I can't even copy them to another location (I thought if I could get these on to another machine I could try installing the certificates and see if I could access this way). If I try and create a new file on her area, this also fails. So it seems that there is some sort of issue with her old certificate expiring - despite it having renewed successfully. Any ideas - this user will lose hours of work if I cannot solve - all help appreciated. Thanks, Smarties
-
Windows XP Starter Edition or MSI Wind U100 Recovery Disc
smarties11 replied to smarties11's topic in Windows
Thanks Martin for having a look! As Arthur says, it's XP Starter Edition I am looking for though not Windows 7 Starter. Appreciate you looking. I have already tried searching on Google and some of the torrent sites, without success. Would appreciate it if anyone has a recovery disc for this laptop or a Windows 7 Starter ISO. Thanks! -
Hi All, I have an old Netbook at home that has been sat in a cupboard for a few years unused. I had Windows 7 installed on it; but I want to return it to factory settings so I can sell it. I don't recall a recovery disc coming with it and stupidly I erased the recovery partition when I installed Windows 7 to free up the space, not forseeing this eventuality! So - I'm looking for either a recovery disc for an MSI Wind U100 - or, a Windows XP Starter Edition CD. If anyone has either of these and is able to rip to an ISO for me I would be most grateful! I have tried installing XP Home but as I expected it doesn't accept the Starter Edition serial number. Thanks!
-
If you want something a bit brighter, have a look at the NEC M311X, which has a throw ratio of 1:1.3-2.2. I fitted these to our classrooms in the summer of 2013, to replace our aging projectors. Really pleased with them, haven't had any complaints from teachers at all since fitting these. Before this we mainly had Epson EMP-S1's and Infocus IN26+ (terrible projectors!) We paid around £395 ex VAT for these, although we did buy 34 in total. I did the fitting myself which was a breeze; such a wide throw ratio on them that I didn't have to move any mounts. Hope this helps!
-
We don't publish staff e-mail addresses on our website (bar one or two) and many are also addressed to [real] pupils. This is what I found a bit bizarre! What was also very strange is that my e-mail address at work is my first name - but I go by a shortened version of it. The shortened version of it doesn't exist as an e-mail address here [and therefore can never have been scraped] yet wherever these e-mails originate from has tried my [email protected]?! Really weird......
-
Hi All, Has anyone else been receiving lots of these messages today? The subject line is always 'Test mesage ######A'. The hashes and A are random numbers followed by a random letter. Message is spelt incorrectly. Looking at exchange tracking logs, the majority of recipients are [email protected] - with a handful of correctly named recipients. The from address is always random. The body of the e-mail appears to be random snippets of text from Wikipedia articles. I've googled sentences and they all come back to Wikipedia. The behaviour is very consistent with a mass mailing worm. They are definitely originating from outside our LAN as I can see that in the tracking logs. I've spoken to our broadband/filtering provider (Mouchel) who are looking blocking these on their SPAM filters but I wondered if anyone else was receiving these? We've had 250 at the last count! Google only retrieves a couple of relevant hits (both also from today) Google New virus perhaps?
-
I've never used Veeam; but if this was Backup Exec, you would need to ensure that you had the Microsoft Exchange agent enabled and that you were doing GRT backups on exchange. With this setup, once BE has taken a snapshot of the exchange VM it then uses the backup exec agent to process the metadata for the exchange database, and then truncates the logs. If you look in your log folder and you have logs going back days, then this is the problem. Logs should be cleared down by the backup software after each backup.
-
Awesome, thanks Mark! Works great - appreciate your help on that. Hope the BBC feeds return in some shape or form - it's handy being able to switch to BBC1 or 2 for example when Wimbledon is on!
-
Hi, We've switched our Xibo display on this morning and are also getting an error now on the BBC News 24 live streams. Has anyone been able to work out a solution? I see they still work fine via the BBC News 24 website - I've looked at the underlying code but my coding skills are only basic! Would appreciate any help... Thanks!
-
Thanks Jona. That definitely makes sense - sadly none of our existing switches support 10GB SFP+ at present - so we'd be taking a bit of a punt from the outset on the first fibre.
-
Thanks Jona! Do you know roughly what distances you have had success with - and which you haven't? I know this will vary depending on the fibre spec but just as a rough idea? I've done some crude length calculations using google maps (and allowed for the vertical drops + a bit extra for good measure) and I think our 6 fibre runs are 40m, 45m, 50m, 50m, 60m and 93m.
-
Thanks for your input localzuk. Sounds like that is what we should do, in that case. Will have to keep my fingers crossed that the cable guys are able to use the existing ducting!
-
Thanks for the useful info localzuk. I guess this will be difficult for me to establish given that two of the fibres have no writing on them (will check the remote ends after school but the core ends have nothing on in the 2m or so that I can expose under trunking). I've worked out the price differential (replacing fibres vs more expensive LRM transceivers) to be about £1,200 - which isn't terrible given that phase 1 of this is probably going to cost us £20k. Just trying to make the best of what we have, and save some cash. Additionally two of our fibres feed external blocks and run in underground ducting. I can see where both enter their respective ducts but can't find where they resurface. So I'm conscious that there may be additional cost in exploring this - or even having to find alternatives such as a catenary wire.
-
To give some perspective; upgrading our existing fibres has been quoted at approx. £2,700. The additional cost for the LRM transceivers (12 required) over and above SR would be approx. £1,500. So the price differential is £1,200.
