Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

cmpwat

Members
  • Posts

    71
  • Joined

  • Last visited

Everything posted by cmpwat

  1. and that's the info I was after! I have setup the guest wifi and the authentication ok, but its the pointing that's throwing me. If I want the wifi to only allow access to the interweb, where do I point it?
  2. Hi Zag, I noticed that you have a guest wireless setup using the Aurba APs..... Was wondering if you could give me some pointers on how to set it up? I am trying at the moment. I have the 105 APs with no physical controller. Wayne
  3. Issue has been resolved
  4. Sorry Rob, Sender is server room a, receiver is server room b. Looks like a leaky vlan and spanning tree causing the issue.
  5. --UPDATE-- By removing the management cable from Port 47 on the sender, we now have the switches talking???? Considering Port 47 is in the default Vlan why would this be the case? We have also tried with the port connected and spanning tree off on both the sender and receiver and this also works? Confused now thought that vlans were meant to be apart?
  6. Hi Rob 10.107.71.254 is the default gateway of the entire network. Spanning Tree is enabled on all switches and Jumbo Frames is on all ports on the vlans. Bridge Priority? I don't know what this is? Wayne
  7. Hi Dave Nope not a simple question at all! We have an ip of 192.168.130.230:255.255.255.0 on the sender and 192.168.130.231:255.255.255.0 on the receiver. I have attached the config of the switches below: Running configuration - Sender Switches ; J9147A Configuration Editor; Created on release #W.14.70 hostname "ProCurve 2910al-48G Switch" module 1 type J9147A module 2 type J9165A no stack ip default-gateway 10.107.71.254 vlan 1 name "DEFAULT_VLAN" untagged 47,A1 ip address 10.107.64.88 255.255.248.0 no untagged 1-46,48 exit vlan 10 name "iSCSI" untagged 1-30,48 ip address 192.168.130.231 255.255.255.0 tagged A1 jumbo exit vlan 50 name "vMotion" untagged 31-46 tagged A1 no ip address exit snmp-server community "public" unrestricted spanning-tree no autorun password manager Running configuration - Receiver Switches ; J9145A Configuration Editor; Created on release #W.14.49 hostname "SVS HP2910-24 iSCSI 2" module 1 type J9145A module 2 type J9165A ip default-gateway 10.107.71.254 vlan 1 name "DEFAULT_VLAN" untagged 23,A1 ip address 10.107.64.86 255.255.248.0 no untagged 1-22,24 exit vlan 10 name "iSCSI" untagged 1-22,24 ip address 192.168.130.230 255.255.255.0 tagged A1 jumbo exit snmp-server community "public" unrestricted snmp-server contact "Wayne Tuckwell" location "Science Prep" spanning-tree no autorun password manager Wayne
  8. Evening... now bear with me while I try and explain the problem! We have 2 HP ProCurve 2910al-48G switches (Sender for ease), connected via CX4 cable at the back. We are trying to connect the Sender switches to 2x HP ProCurve 2910al-24G switches (receiver) via a fibre cable. The fibre cable from the sender terminates in the comms rack. The receiver is connected to a fibre connection that terminates in the same comms rack. The 2 connections are connected with an ST to ST fibre patch cable. The idea is that we have one part of a SAN connected to the sender switches and one SAN on the receiver switches and create an iSCSI network over the fibre. I have created a vlan on the sender switches, vlan 10 and have ports 1-30 & 48 untagged. I have A1 (CX4) tagged and jumbo frames switched on. Port 48 has the SFP connected. This vlan is replicated to the second of the sender switches. I have also created a vlan on the receiver switches, again vlan 10 and have ports 1-22 & 24 untagged. I have A1 (CX4) tagged and jumbo frames switched on. Port 24 has the SFP connected. This vlan is also replicated to the second switch. It looks like the vlan is configured correctly but when we try and ping the SAN at the receiver end we get no reply. We have broken into the network at the comms cab with a PowerConnect 2824 and we can ping the SANs at both the sender and receiver ends but with the ST Patch connecting the 2 connections nothing seems to get through. The ST Patch cable is brand new (62.5/125). I have also tried another brand new patch cable (again 62.5/125) and nothing seems to be talking. Can anyone think of anything else we are missing here?
  9. The dumb terminals run windows 7 as a base, but the problem we had was when a student since in, it was pulling the full profile down, hence why they are not joined to the domain.
  10. Yes, a 12 year old may read it off the label but it won't work as: A) the APs are attached to the ceiling B) I put a strong pass phrase into the SSID c) there is no label on the APs So not sure what you meant by that comment. Thanks also for the insight into WPA2 as I will sleep easier knowing I have been corrected. My op was not for people to pick hole in my knowledge or my ability to explain properly, more to try and gain some help form other experts as to the best possible way of securing my WLAN. Having had experience of installing a WLAN with machine certificate on the server, PC and PKI smart card, I was merely asking for advise with regards to devices that have not been joined to the domain.
  11. The issue is that whilst the rest of the network is secure as I have had it tested, I do not want to have students connecting to the wireless network with phones and iPods. Will the netsh wlan work when the devices do not log on to the domain? I know it will work with ones that do, but the devices we use are standalone. Finally, I do not want to just use WPA2 as it is not very secure.
  12. Afternoon all I have run into a problem when a Y11 has managed to get hold of the WPA2 key for the Wireless Network (not my choice, I inhertited it!). This has meant that I am having to look at something more secure. So, I have install NPS on a W2K8r2 Server, with AD Certificate Services, created the access policy to use a certificate and AD Username and Password, tested on my laptop (connected to the domain) and iPad and both connected and are authenticated. Now comes the issue, we use laptops and netbooks as 'dumb' terminals to connect to out Xendesktop solution. These devices are not connected to the domain, just connect to the network. This means that the Wireless cards cannot authenticate to the certificate server as it is not trusted. The question is this, if I purchase a certificate from a trusted company (godaddy, symantec etc.) will this allow the devices to connect if i put the same cert in to NPS? or will i have issues with using AD usernames and passwords as the devices are not on the domain? Finally, does anyone else have any other ideas as to how to secure these devices to the wireless? I was thinking of using MAC Authentication as well as WPA2 but concerned about spoofing.
  13. Sorry... as I said, trying to get up to speed asap! All clients are set to use the 2 internal DNS servers. I have run the nslookup and get the following: We do have an external proxy and an internal web filter, but the clients are all set to bypass the proxy when going to and domain.name address.
  14. Hi psydii Thanks for you reply, I have added some responses below, but to be honest my knowledge of DNS is very flakey and have not had too much dealings with it in the past.
  15. Hi all. I have a bit of an issue with DNS, over the summer it decided to delete all its records (it might have had something to do with me, I couldn;t possible say either way!!!). Since then, it looks like all the Servers have a DNS record back in the DNS Sevrers however, when we try to go to a intranet site, like http://sv-app01, we get a DNS error where the address cannot be resolved? Any ideas on what I need to put into DNS? I have a static entry to the IP Address in the forward lookup zone and a entry in the reverse lookup zone..... but really at a loss now?
  16. j17sparky - your the second person to mention Daemon Tools..... it would make sence, then I could just have a monster NAS with the disks copied to for playing. Does Daemon run a video DVD in the same way for example?
  17. Whilst both answers are credible, they are not practical considering I have over 165 CDs in the existing server. Also with the number of mapped drives already in place, there are not enough letters in the alphabet!
  18. Hi all. We currently have an Avantis Open.CD in place that serve CDs and DVDs across the network. We are currently moving to Windows 7 and whilst Avantis do a Windows 7 Client, I have spoken to them and the Open.CD is about to go legacy. I was wondering if anyone could suggest another soloution, either hardware or software, for serving CDs and DVDs across the network? Cheers. Wayne
×
×
  • Create New...