smarties11
Members-
Posts
644 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by smarties11
-
Hi All, We temporarily have our guest Wi-Fi open to all students (previously just sixth form). Looking at the daily reports I have set up in SmoothWall, I've noticed a sharp increase in traffic to IP hosts; and when you do a lookup to those hosts they link back to VPN companies such as M247. Does anyone have a strategy for this? SmoothWall has a category for 'web proxies' which we block however I have a list of 12 IPs just from yesterday that aren't in this category. I've started to add them manually so that they are blocked, but clearly there will be hundreds and thousands of these across the various VPN apps and services available. Is there a better way to filter these out? I'm not worried about bandwidth as we rate limit them anyway but more concerned about bypassing our filtering. Thanks!
-
Yes, this is exactly what I am after. I don't want to change any settings that lose or interfere with the domhier sync as I know this could lead to massive issues. I'll look into allsync and apply only to our offiste clients. Thank you for pointing me in the right direction! EDIT: Just to add that this worked perfectly. For anyone else, the GPO location is Computer Configuration > Administrative Templates > System > Windows Time Service > Time Providers and then enable the policy 'Configure Windows NTP Client'. Pop your preferred time server(s) in and change the type to 'AllSync' which still syncs via the domain hierarchy first, falling back to time server if not available.
-
Hi All, Our clients all update their time from our on-site DCs. We have a few people working from home at the moment, and as we don't use a VPN the DCs are not available for them to time sync. Consequently their time is now an hour behind, which obviously causes major issues with SSL. We've corrected manually for now, but I wondered if there is a way to specify (by group policy for example) a secondary time server when DCs are not available? I can't find anything online about this, I can see the time sync settings at Administrative Templates | System | Windows Time Service; but we don't configure anything here, the clients start syncing with our DCs when on the domain and I don't want to override this or create any issues with this. Thanks!
-
Teachers can download an attendance record from the three dots menu of the participants panel. We also give those members of staff responsible for attendance the "Teams communication support engineer" role in O365 admin which enables them to look at call history in Teams Admin Centre in order to verify attendance if there are any discrepancies. We were finding that when Teachers reported non-attendance and our attendance staff called home, parents and students were saying they were in attendance (when we knew they weren't), blaming it on technical reasons. Once I gave our attendance staff access to this and showed them how to use it and reassured them that this information is concrete and should not be challenged, this soon stopped!
-
Proxy exceptions and move to external hosting
smarties11 replied to smarties11's topic in Internet Related/Filtering/Firewall
Yep, good thinking - done, tested & working :-) Thank you! -
Hi, We use our external domain as our internal one too, and up to now have hosted our website internally. I'm now moving this to external hosting in order to air gap it from our network. So, up to now we have http://www.ourschool.co.uk pointing to our webserver internal IP on our internal DNS, and have *.ourschool.co.uk set as proxy exceptions so that this isn't proxied through our SmoothWall. On our external DNS, we have http://www.ourschool.co.uk pointing at an external IP which is NAT'd to our webserver. I've set up our external hosting and transferred our site to a test subdomain and it works great externally. Internally, I've set up a DNS record for the subdomain on our internal DNS pointing at the IP of our external hosting server. But of course this only works if I remove *.ourschool.co.uk from the proxy exceptions. What's the best thing to do in this scenario? We have a number of internal services so I don't want to list them individually as exceptions if I can help it. If I leave the wildcard exception in place, is there a way to tell SmoothWall that this is not internal and therefore to proxy the request externally?
-
Hi, Just to report back I went ahead and tested this anyway - nothing to lose - came back this morning to a successfully upgraded machine (1809 -> 20H2)! This was a using a custom WIM (the original vanilla WIM with unwanted appx apps removed and the unwanted operating system indexes removed - both removed on a mounted WIM using Microsoft tools). So perhaps it works if you manipulate the mounted WIM with Microsoft's command line tools but just not if you use a WIM you have captured yourself?
-
It used to be the case that if they weren't removed from the WIM, they would reappear after windows updates etc. That might have changed now though! Which script do you use to remove them out of interest?
-
Bummer. I thought this would be the case. I guess I'll just have to use the vanilla image then and remove the appx apps in a task sequence. Thanks for your feedback!
-
SchoolCloud Parents Evening & SmoothWall
smarties11 replied to smarties11's topic in Internet Related/Filtering/Firewall
Many thanks for your input Pete. I'll await confirmation from SchoolCloud over port 3478 or 10,000-60,000 and then get onto KCOM. -
I understand how I would achieve it, I'm looking to see if anyone has done this and whether it's successful (i.e. does it then break the upgrade process if you replace the vanilla WIM with a custom one). I can't find a definitive answer online from any official source so thought I'd ask here!
-
Thanks for your reply Chris. I know what steps to take, my question was; before I import the OS upgrade package; can I switch out the WIM file that comes with the vanilla image, with our our custom one that has already had the unwanted appx apps removed?
-
We're deploying out Win 10 20H2 ready for the 1809 end of support in May. Most machines will be reimaged, but we have some machines I'd prefer to upgrade. I've never done an OS upgrade task in SCCM, it looks like you use the original install media including setup.exe rather than a single WIM. My question is, in this scenario can I replace the install.wim file with our custom one still, which has had all of the rubbish appx removed and the other OS flavour indexes removed, or will this break the process? Is there a better way? I know I could remove the appx apps we don't want after the upgrade but I'd rather not introduce an extra step to manage. Thanks!
-
SchoolCloud Parents Evening & SmoothWall
smarties11 replied to smarties11's topic in Internet Related/Filtering/Firewall
Hi Pete, Thanks for this confirmation. Very frustrating when the message from SchoolCloud is that TCP only is OK, UDP for best quality. Out of interest, to get it working, did you request just port 3478 to be open on UDP? Or the full 10,000-60,000 plus 3478? Again, mixed messages from SchoolCloud. Docs say the full shebang, support are asking for 3478 only. If you did the full range, was this met with any challenge from KCOM/emPSN? It seems like a LOT of ports to open up over a LOT of IPs! I've looked up some of the IPs and they are all over the world! Twilio's docs suggest it's possible to force in their API that only a subset of data centres are used (rather than relying on latency tests) but I'm awaiting a response from SchoolCloud on this. It seems shoddy to me to open up IP ranges in China, Japan etc that will never be used unless our Teachers are in those countries... Thanks! -
Hi All, There is an existing thread on this in the SmoothWall Direct Support forum, however it won't let me reply to it. Has this forum closed? I wondered if any other SmoothWall users here have been able to get SchoolCloud Parents Evening system working using TCP only? Their guide at https://support.parentseveningsystem.co.uk/article/825-video-appointments-network-requirements states that UDP is required for best quality. Responses on the previous post quoting SchoolCloud state that TCP only is fine. I have whitelisted and disabled HTTPS inspection for twilio.com, parentseveningsystem.co.uk, schoolcloud.co.uk, pendo.io and bugsnag.com PLUS the almost 4,000 IP addresses listed in their guide. The Twilio tests all pass perfectly (except UDP of course), every single time. On a live parents evening (and a trial one I have created) the calls only connect properly around 50% of the time. The parents name appears in the window, but there is only a black screen where the video would be. Same on parents end, they see the teacher name but no video. Sometimes the video kicks in after a few seconds, sometimes after a few minutes, sometimes not at all. Those teachers working at home don't have this issue, just our on-site users. Thankfully not many of those at the moment! SchoolCloud are recommending we allow UDP as per their technical document (though they say their tests indicate TCP only works - not sure how in-depth these tests were) however this concerns me as it's a total of 50,001 UDP ports over almost 4,000 worldwide Amazon AWS IP addresses, and this seems a bit like building a motorway to ride a pushbike down to me. We are a Lincs School so firewalling is done upstream on the emPSN network at KCOM, so the request would need to go via them. Obviously if UDP is necessary then we'll have to evaluate the risk, however I just wondered whether other Schools have had success with TCP only as per the guide? Thanks!
-
Thanks to all who replied! I've got our supplier on it with a quote!
-
Just to add back to this thread that CAPITA have committed to fixing this issue in the Summer 2021 release. Updates are in KB0044887 on the support portal.
-
If you read back through this thread, there are a few options available 😊
-
Hi All, So we're running Adobe CS4 site wide at the moment, which we bought outright years ago. Technically it isn't Windows 10 compatible, but it works. We're rolling out the latest Windows 10 20H2 build soon, and although it works again on this build I'd like to investigate updating it, as we often have compatibility issues when users have newer versions at home. I've not touched Adobe licensing for years but I've heard of some eyewatering prices. What is the cheapest way to license this in education? The reality is we probably only have 200 users max who will actually use this, but if it's cheaper to license site wide then so be it. Thanks!
-
Yeah, that's exactly what we do currently, everything is in one policy that applies to our workstation root OU. This is the first time we've needed to block something site wide, but allow for certain computers. The program is running it in the user context, which is the issue.
-
We have an AppLocker group policy applied at the root of our workstations OU. Obviously all the sub-OUs below this inherit this policy, and this works great. In this policy we block, amongst other things, cmd.exe and netsh.exe. This has been the case for several years, however we're now deploying the SmoothWall Unified Client so that our student laptops are filtered via the SmoothWall Cloud Filter when at home. Blocking cmd and netsh breaks this and it fails to connect to the cloud service. If I remove the block rules for cmd and netsh it works great. Now I'm not all that happy about unblocking these executables; I appreciate that running under a limited account means that they shouldn't necessarily be a security risk - but my view is that they are a distraction to learning at an absolute minimum. However, that is an issue for SmoothWall to consider and address. My question relates to AppLocker inheritance; I'd at least like to only have these executables allowed on those devices where we deploy the unified client rather than site wide. As with most security software, in AppLocker a deny rule overrides an allow, no matter where it exists in the inheritance hierarchy, so I can't simply leave them blocked at the root and then allow in a sub-OU. The only way I can think around this is to split the policies at the root - one containing just the two block rules for cmd and netsh and then another with everything else. And then create an AD group containing the unified client workstations as members, and setting this group with deny permissions on the GPO. This is a bit clunky as it means I then have to maintain the AD group. Is there a better way that I might be missing? Thanks!
-
Black one only £14.99 Inc vat at amazon https://www.amazon.co.uk/StarTech-com-Gigabit-Ethernet-Network-Adapter-Black/dp/B0095EFXMC
-
Just to add that the StarTech USB31000SW (white) also comes in the USB31000S variety (black), which is cheaper
-
This is certainly possibly the case with your other devices, however I'm not so sure with the GEOs. They have confirmed to me in email that the GE114 doesn't support PXE boot, and they are awaiting a BIOS update from the motherboard manufacturer. The older GE109 revision works. I suspect there's something missing in terms of the range of devices supported. I've three or four different types of USB ethernet here that I've used loads of times to PXE boot various non-ethernet-equipped devices that won't work on the GE114! We have tried using a USB hub, all of the various BIOS options etc to no avail, except with the StarTech
