-
Posts
2,258 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by wesleyw
-
Yes unfortunately so. What it asks is fine if the vpn server in on the internal domain not the dmz.
-
Hi, I was wondering if I could get any help at all on Always on VPN, I've been reading several articles/'blogs about the technology and deploying it. From what I can see it revolves around 2 servers a VPN server in your DMZ (between Perimeter firewall and internal firewall) and an NPS server on your Corp network. This is where I get stuck as all the articles talk about auto-enrolment of certificates for the NPS and VPN servers but the VPN Servers aren't part of the corp domain and as such cannot be auto enrolled. So I have some questions if anyone could answer them that would be great. The VPN Server in the DMZ needs two Network Interfaces one for the Public facing Perimeter and 1 Internally to talk with the NPS server? We already have DirectAccess working fine does Always on VPN use different Certificates (It doesn't look like it) if so can I just use these for the Clients (Windows 10 PCs)? If I just create a 2 year Certificate for the VPN server and manually update it when it needs to be will that suffice instead of having it on the internal domain? Does anyone have a in depth guide available that could talk me through some of gotchas are sure to come up and a step by step how to at all? Wes
-
Dell 5548 has 2 x 10gb links at about 1.5k but a decent amount (24) on a 8024f (also has 4 x 10gb copper) for around 7-8k just need to pop in sfp+ modules at £150 a piece good for future expansion.
-
Certainly be interestd what would you take for them?
-
Are the usb barcode readers still available?
-
Like the film with Yul Brynner cool
-
Tools installed version 6.5 dfs replication goes first then the other boxes freeze up Linux boxes inaffected
-
I have an issue currently where during normal hours our windows Vms crash but not our Linux boxes which are on the same hosts this seems to have started after we installed a number of kyocera printers with kx drivers
-
Certainly be interested in the 5520.
-
What would you want for them?
-
All from experience of migrating SIMS around 5 times at 2 different jobs lol
-
Check the connect.ini and sql.ini files on those workstations
-
Static IP addresses with BT Business Broadband
wesleyw replied to ithappy's topic in How do you do....it?
Fttc or ADSL I'd have a look at cisco asa with a cheap adsl card. Do you need anything else from the router? If you need decent firewall etc draytek or fortinet is a good option older fortinet boxes can be picked up cheap from ebay. -
Theres always ulteo as well french based cheap to buy and maintain its a good system as it'll run linux and windows apps easily.
-
After installing TMG, Client have no network
wesleyw replied to Fi011's topic in Internet Related/Filtering/Firewall
Yes thats correct as rhe ip address would be an exact address the name on the other hand needs to be translated to an ip address first. -
After installing TMG, Client have no network
wesleyw replied to Fi011's topic in Internet Related/Filtering/Firewall
The tmg was blocking dns traffic so although http and https were allowed there was no way for the clients to get dns info from outside. If you setup dns including dns forwarder info such as 8.8.8.8 on the dc then allow dns traffic for that server you can then point the clients to the internal dns and only allow http and https traffic for the clients. Everything should work then. -
Pretty much makes them easy to find.
-
Though it will depend on how much the teachers move around.
-
I'd look at vlanning per deoartment or building means an awful lot of vlans in some cases but it will seriously cut down broadcasting and of course it makes it a small list ;-)
-
https://social.technet.microsoft.com/Forums/office/en-US/74d2aaf9-1b07-4eae-92c7-00ac14b44d8b/error-1920-service-windows-font-cache-service-fontcache-failed-to-start?forum=officesetupdeploy i take it you've already used this as a basis?
-
I was thinking of just trying to use the domain admin not the local admin account on it possibly using the domai admin account for any service thats related just to see if that helps track what is happening. Id check through all the event logs as well
-
What account are you using within the service to start automatically? Try a domain admin account then if not try an enterprise admin account. Or just the builtin administrator account for the domain you have joined.
-
Hi, has anyone ever heard of this software at all and if possible has any info about it?
-
What security events would need to be captured to spot unauthorized access attempts being made to file shares and windows network devices? Wes
-
Having re-read my original thread I'm really looking for what would be the more sensible approach to logging security events in regards to intrusion detection on clients, member servers and domain controllers. What is the best level of granularity to audit so that a lot of useful information is stored but we cut down to the minimum of erroneous logs? What would be a sensible starting size for these security logs? Wes
