-
Posts
12,849 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Michael
-
Have a look here but unfortunately Azure is the most common solution. I guess alternatively you could use a Powershell script to check the Windows version/build.
-
The benefit is you don't need a WSUS server at all - devices communicate with Windows Update directly, but adhere to your set policies. I've had far less issues with WUfB than WSUS to be perfectly honest, plus it's one less VM per site to manage. I did look at making a WSUS server public facing, but there are big question marks over security, you'd need an SSL cert (potentially a small cost), plus you still have to manage that VM.
-
This is why for quite some time now I've implemented WUfB and using GPOs, specify that only updates published for more than 30 days can be installed. This is regardless of location; just anywhere with an internet connection and applies to workstations and servers. It also means you lot are my guinea pigs when it comes to new Microsoft patches
-
Maybe - the LAN port for viewing/recording locally and the modem for monitoring remotely? It looks like it has its own housing though, rather than just a PCI card to upgrade an existing system. Do we get a prize if we get it right?
-
Pass - some kind of network adapter or modem for a CCTV unit?
-
Inherited Network, How do I change the setup to meet our needs
Michael replied to JAB1a's topic in Wired Networks
Immediate thoughts that come to mind - - Were you given a hand-over sheet of any kind? - Before doing anything with phones, I'd engage the VOIP provider to better understand the configuration and likewise explain what you're trying to do. I'm somewhat perplexed why the phones all have static IPs for example. - Likewise same/similar to the above, I'd engage the ISP what you're trying to do For example it should be do-able to utilise the third port on the router, (communicating through the ISP) once you've gathered all the above info and then plan/consult the school when you're going to flatten the network. The priority immediately would be internet connectivity and phones, then everything else you can build on slowly. Hopefully nothing else is configured statically, other than servers and printers. I'd definitely say this is still the investigative/planning stage. -
I've not had any reports of schools I support using Bromcom. Immediate things that come to mind - - Which ISP/filtering? - What external DNS provider are you using? I normally use Google DNS. - What browser(s) are your users using? - Disable SSL inspection for cloudmis.bromcom.com - Create an exception so cloudmis.bromcom.com bypasses filtering - Unfortunately Bromcom have blocked pings on cloudmis.bromcom.com so whether there's another URL you can ping (you may have to PM them). - Separately another test you could try is over 4G, which of course bypasses your LAN altogether when you've identified the issue's there - Optionally create a local DNS zone/record, to speed up lookups to Bromcom - I'd also say there's a massive difference between slow down and being unable to resolve completely, which of course is a more serious problem - I think caching issues can be ruled out, otherwise it'd never work correctly, but clearly it does after x amount of minutes Apologies if you've already tried all or some of the above!
-
I think you're getting to the point of disconnecting non-essential/less desirable kit, just limit it to your core switches. Ideally disconnect them all, then perform the same test with your notebook. At least we know the Netgear ProSafe 5 cannot act as a rogue DHCP server. If it is the root cause, I'd say there are several solutions - - Replace with managed switches or (even better) - Install the additional network points required, so everything goes back to your core switches (which are most likely managed) I'm more inclined to think it's not a rogue DHCP server, as normally you'd see Class C IPs, such as 192.168.1.1, rather than a 169 address.
-
Do you have any unmanaged 5 port switches in classrooms, that shouldn't be anywhere near a large network? If yes, I'm just wondering if it's something along these lines or possibly even an STP issue. Many years ago this happened to me - an inherited network, unmanaged 5 port switches everywhere and one or more of these were bringing the network to a crawl; and yes, it can also block devices obtaining a DHCP lease.
-
I agree CAT5 can certainly break down, even if you had a small section (say 1m) exposed outside. I've seen all kinds of daft installations. Other possibilities are other contractors inadvertently damaging cable if it's not in conduit, or cables being painted to blend with walls etc...
-
I'm just skimming through this, but have all local switches now been rebooted, but the issue remains?
-
SPF, DKIM and DMARC walkthrough and tester
Michael replied to TechMonkey's topic in Enterprise Software
DMARC's enabled by default on O365 inbound email. It's more a question whether you want DMARC on your organisation's outbound email. SPF is also enabled as standard too. I created a guide (it was for Arbor), but describes how to enable DKIM (the first part). -
Promethean Activpanel HDMI Sound issues
Michael replied to Gkillie's topic in AV and Multimedia Related
In my experience - - Installing the latest drivers is always worth a shot - Native HDMI port/HDMI cable is the way to go, no converting - Despite the performing the above, I still get the occasional/rare user who needs to go into Control Panel > Sounds, to change the audio default. I think Windows Updates/driver updates certainly play a role. -
Scratch Online
-
What does RMUnify do that AAD Connect doesn't (which is also free)?
-
Personally I think 14 days is too long - I set all my scopes to 3 day leases. I'd also check what percentage of IPs you have free in your scope. Other aspects to check are reverse DNS - check all zones are configured correctly. Finally - when was the last time you updated/rebooted your switches? This can also clear out a whole load of issues.
-
Hi all, These are the steps I took (to help other Arbor schools in future) Sign into O365 using this URL - https://security.microsoft.com/dkimv2 Select your real email domain and select enabled. You'll be prompted to add two CNAME records (if not already enabled): Name: selector1._domainkey Value: selector1-school-sch-uk._domainkey.school.onmicrosoft.com Name: selector2._domainkey Value: selector2-school-sch-uk._domainkey.school.onmicrosoft.com Wait 5/10 minutes, then return back to https://security.microsoft.com/dkimv2 and select Enabled. Amend your SPF record as follows - O365 schools - v=spf1 include:spf.protection.outlook.com ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 -all G Suite schools - v=spf1 include:_spf.google.com ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 -all Hybrid schools (using both O365 and G Suite features) - v=spf1 include:spf.protection.outlook.com include:_spf.google.com ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 -all Contact Arbor support via their web chat facility, give them your school domain name and request the required CNAME records (you'll be given three) - Name: mbs._domainkey Value: MBS.domainkey.uxxxxxx.wlxxx.sendgrid.net Name: mbs2._domainkey Value: MBS2.domainkey.uxxxxxx.wlxxx.sendgrid.net Name: emxxxx Value: uxxxxxx.wxxxx.sendgrid.net
-
DHCP is easy enough to achieve on your gateway, most likely your filtering/firewall appliance. I still prefer Windows DHCP Server though as it's more granular. DNS there's a few options - Either point to say Google DNS if you're fully Azure, or alternatively specify internal DNS to your core, which then would go out to Google DNS.
-
There's an article about this here
-
Thanks - this appears to have done the trick - v=spf1 include:spf.protection.outlook.com ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 -all
-
The SPF record looks/tests fine, but it states the maximum number of lookups has exceeded 10.
-
This is just it - even with the SPF record amended and DMARC disabled, emails generated from Arbor were still going into Junk. I have enabled DKIM now, so just waiting on the CNAME record.
-
-
Thanks, that looks about right to me. I've asked for the school CNAME record, but been informed it'll take a few days
-
I've amended the SPF record, so it reads like this: v=spf1 include:spf.protection.outlook.com ip4:50.31.43.182 ip4:168.245.59.25 include:arbor-education.com -all I haven't done anything with DMARC, as in Microsoft's words, any inbound email is taken care of.
