Jump to content

smarties11

Members
  • Posts

    645
  • Joined

  • Last visited

Everything posted by smarties11

  1. Just to add; I'm not sure who your preferred vendor is when it comes to servers, but we engaged directly with Dell and they arranged for me a 2hr conversation with one of their top techies in Europe, who gave me an absolutely amazing overview and live demonstration of S2D. It really helped me to visualise, understand and feel secure with the technology. He even offered to give me VPN access to his test datacentre to have a play! We didn't go that far as were already happy enough with what we had seen.
  2. IMO shared storage via a traditional SAN is overkill and too complex for an edu environment. This is where we have come from, on a 3 node VMWare platform. It's also more expensive, the SAN solutions we were quoted were more expensive than S2D by some margin. Our new platform is a 2 node Hyper-V cluster with Storage Spaces Direct (S2D) as the storage layer. If you're not familiar with S2D, it's worth a look - it's essentially a vSAN/software defined storage - local storage from each server is pooled into a singled shared entity. In this scenario, you split your VM compute across the two hosts for performance/load balancing, and use the pooled storage for the VHDX storage. The storage is resilient across your nodes - so in a two node solution, it is mirrored, think software RAID 1. The storage network side of things in a two node solution is a direct RDMA connection between the two servers, in our case 2 x 25GB so 50GB bandwidth total. With more nodes, you require an RDMA switch. Failover and resiliency running the nodes as a Hyper-V cluster means that you can lose the entire node (or as many disks in ONE node as you like) and the other node will take over the compute for all your VMs and things continue to run seamlessly (so you need to spec accordingly in terms of RAM and cores). Additionally, we also have our S2D volumes set as nested mirror-accelerated parity - which means we can also tolerate one disk failure in the remaining node if one node is down. The beauty of S2D is caching. You can spec relatively lazy SATA 7,200rpm storage drives and then cache these with NVME. If you get your cache ratio's right, it will perform as well as an all flash SAN or S2D cluster in day to day operations. S2D is well worth a look. We've run it since October in production and it's awesome. The performance is fantastic, and much cheaper than continuing down the SAN route. I'm really happy with our decision and the solution we have now is far more resilient than what we had before. One thing to bear in mind is the cluster quorum. It requires a 'witness' to establish which node is the most up to date in the event of any issues. There are various options for this, we we use a file share on our backup NAS. Cluster and S2D setup is quite PowerShell heavy, especially for some of the finer options. For that reason we decided to buy in third party engineering for this, choosing a company who have done many of these setups before. It's the first time in my career I've used third party support for server config, always doing it myself, but it was worth it IMO. Just make sure you still understand all the basics so you can support it moving forward. If you're looking at backups at the same time, I'd highly recommend Altaro combined with NAS storage and cloud storage via Wasabi. I did a post on it here -> http://www.edugeek.net/forums/security/223075-backup-strategy.html -> saved us a fortune on our old setup and again more performant and more resilient.
  3. I'm running 2022 on both DCs, file servers and our Altaro backup server. No issues.
  4. How old are your kids? We've just bought the Samsung A7 Lite for ours, same one referenced in the post above - currently £119 at Argos, John Lewis etc as part of Black Friday. Usually £150. It's a great little tablet. It has an octa-core processor, 3GB RAM and 32GB storage. It's not lightening quick of course, but more than adequate for the kids, and hugely faster than their old Fire tablet from a couple of years back. Ours are aged 4 and 6, so they are playing things like Cbeebies playtime island, various colouring games, TT rockstars, Numbots etc and it has no trouble with those. They always used to complain about the speed of the old tablet, but I've not heard any moans yet! I'm using the free version of Kaspersky Safe Kids to block/allow apps and websites and set time limits.
  5. We have less than 1000 users and have been using the O365/M365 versions of Office for about 6 or 7 years now. First we used the original incarnation of Device Based Activation (which is now deprecated). Then we shifted to Shared Computer Licensing. There is no 5 device limit, this only applies if you don't use the Device Based / Shared Computer options available and get your users to sign in manually (as they would at home). We stored the Shared Computer license centrally on the network, to reduce the amount of activations against MS servers (they can apparently throttle these if they are excessive, we've never had any issues). Just customise your O365 installed using the customisation tool, to tell it to use shared computer licensing, and give it a path to save the license to if you go down the central option. For home users, when the central license path isn't available, it automatically reverts to local. EDIT: Just to add, the only minor issue we sometimes see is on a PC that hasn't re-activated within the relevant thresholds (i.e. if a PC has been off for a while) it doesn't re-activate instantly, it says that it is not licensed and editing is disabled. Rebooting the PC sorts it.
  6. No, it doesn't. SIMS exports CTF files which you manually upload to the LRS portal through a web browser. The email was sent in error to any Schools who used to use S2S, which has now been decommissioned, so the certificate isn't required.
  7. Your original post said 'offsite servers' which has made people assume you are part of a multi site setup. It sounds like you just need to add a DNS A record on your on-site DNS server. The 'host' field needs to be the name of the server and the 'IP address' needs to be the IP address you have been given by PSF.
  8. If you enable and configure offline files in a GPO that applies to your home laptops, then they will sync using sync center and show at home. That's what we do.
  9. Only required if you have systems / MIS that talks directly to LRS using their API. If you only access via a web browser, and upload / download your CTF files, it's not required.
  10. This indicates to me that DNS isn't set up correctly. Do you have conditional forwarders set up for the remote sites, pointing at their DNS servers? What happens if you ping / RDP using the FQDN i.e. servername.domain.com?
  11. Hi! Has anyone used the Storage Migration Service in Windows Admin Center? What I'm looking to do is use it to migrate one existing file server across to two new ones. When you create a new job, and specify a destination, you can only choose one destination. It does let me create a second job, and specify the same source server - so I could potentially create two jobs with the same source and different destinations - but I can't see if this is a supported config and whether I'm going to end up in a whole world of pain or not?! Obviously I'd make sure there was no overlap between the shares on the destinations. Can anyone shed any light on this? Thanks!
  12. Has anyone had any success getting Show|Ready working behind a proxy? I realise this thread is from 2013 but wondered if there was any updated information. Thanks!
  13. Achieving this with PaperCut is pretty staightforward (https://www.papercut.com/kb/Main/SSLWithKeystoreExplorer) - so the information is out there. Our internal domain is the same as our external, so for us we just use the wildcard certificate that we have from GlobalSign, same one we use to secure our website and external services. I use this on all our internal systems e.g. PaperCut, Ruckus Wi-Fi, Synology NAS etc. It should also be fairly easy to achieve with an AD CA, as with these the root certificate is automatically pushed to clients, so therefore they will automatically trust any certificates issued by it. However, it's a bit more upkeep - ensuring you renew your root certificates etc
  14. This is my understanding, yes. Any server identifying itself as the FQDN(s) you specify in those policies will be considered safe by your clients, anything else will require elevation. Hopefully Microsoft will make things clearer soon. There ought to be a more secure way to implement the above, e.g. by checking the SSL certificate on the print server is signed by your own / a trusted CA or something? But seems Microsoft have gone with the extreme fix on this one!
  15. The summary so far is, in order of best security.... 1. Get Type4 printer drivers for all your printers - these are user mode drivers and will work without any further changes after the August update. The reality is that this isn't possible for most. Even the HP Universal driver isn't available in Type4 2. Deploy print drivers to the machine via your preferred method. If the print driver is already on the machine, you won't be prompted to download it 3. Set the 'RestrictDriverInstallationToAdministrators' reg key to 0 AND set the 2 point and print policy GPOs to only allow your printer server (these are at Computer Config | Admin Templates | Printers - 'Point and Print Restrictions' and 'Package Point and print - Approved servers') In our environment I have opted for 3, because we already set those GPO settings to specify our printer server - so adding the reg key then doesn't leave us completely exposed, as all print servers except the one specified will still ask for elevation - plus this buys me a bit of time too - once things are quieter in September I will probably move to deploying out the drivers and then ultimately hopefully printer manufacturers will get their arses into gear and release Type 4 drivers.
  16. Ah poo. I hadn't realised this. Most of our print deployment is done based on PC name/OU, however we do deploy some based on user. I've e-mailed our supplier for a quote of the advanced enablement pack.
  17. Thanks all. Very surprised by this change, I'd imagine there's a high proportion of enterprise using point and print? I've put the 0 reg key in place for now, but I hate putting workarounds in place which are against advice. I already have PaperCut Print Deploy on my to-do list, looks like it just moved up higher!
  18. Hi All, We're seeing today issues printing, whereby printers all say "driver update needed" on clients. If they go ahead and print, it asks them if they trust the print server, and then they are prompted for admin credentials. If I provide these, printing continues no problem. We deploy all printers by user GPP. I have all the relevant point and print settings / restrictions set by GPO, and nothing has changed on this front. Two things have changed, yesterday - I have applied August windows updates to both servers and clients - I renewed our CA root certificate as it is due to expire soon I'm about to begin troubleshooting the above, but thought I'd ask here to see if anyone else was having the same issues? Thanks!
  19. Hi All, Tried to find similar threads but couldn't see anything. We potentially have an opportunity to have our office refurbished. It's a decent size, and there's myself and our Tech. I'm looking for ideas, what would be your absolute must haves? I'm thinking recommendations for toolkits, repair benches/stations, storage etc. Want to have enough 'bays' for 5 PC/laptop/tablet repairs on the go at the same time. Just at the brain storming stage and looking for some inspiration! Thanks
  20. Just to follow this up, I looked at it again today and you can simply add the group name under each product - then when you add a future user to the AD group, it syncs to Azure, then to Adobe, and because the group name is licensed the new user is too. I tried this the other day and the group name didn't appear, I've noticed today you have to type quite a lot of the group name in before it appears on the auto match. Hope this helps someone!
  21. Hi All, We've recently purchased Adobe CC named user licensing. I'm attempting to fully automate user provisioning. This is what I have so far... - Directories and domains set up in Adobe admin console, linked and sync with Azure - Groups created in local AD which I have added the relevant users to (e.g. Art students etc), have asked Salamander to manage these from SIMS - in Azure, I've added these groups into the Adobe enterprise application - Users appear in Adobe admin console automatically The last piece of the puzzle is that I'd like to then have the users automatically assigned to the relevant applications and profiles in the admin portal - but I can't see that this is possible in the Adobe documentation. Has anyone been able to achieve this? Thanks
  22. The AP reboot issues were apparently fixed in 10.4.1.0.214, but I've yet to test. Latest release is 10.4.1.0.238 EDIT: Have you checked in the ZD which AP these laptops are connecting to? We've randomly had a few computers recently connect to distant APs (even when there is one in the room!) resulting in similar issues
  23. Thanks for the detail. Will be way out of our budget though I suspect :-( Can I ask what size School you are and how many VMs you have?
  24. This looks interesting, and sounds like you came from a similar setup to what we have now. Would you mind sharing specs and costings of your solution? (by PM if you'd prefer) Thanks
  25. We only have port 80/443/53 open. All other ports are closed. These VPNs must be operating on port 80/443 as I can see the traffic via my SmoothWall.
×
×
  • Create New...