Jump to content

TechMonkey

Members
  • Posts

    7,550
  • Joined

Everything posted by TechMonkey

  1. We use VeryPC D039 Android players. Downside is they aren't very manageable, setup is manual. Upside is not a lot of setup needed, just run and they are dirt cheap. Talking less than £150. Talk to them about what is available as they were silly cheap when we bought them but I think that was an offer.
  2. Just a note I learned yesterday, Clarion have a plugin that links to certain MIS (iSAMS being one) to allow number lookup. So when a call comes nominated staff will have the MIS record opened for the caller.
  3. Interestingly IDEX on Smoothwall seems to be having fun on our site. I've swapped domain Auth to higher priority to get us working.
  4. There is a system called EVOLVEvisits by Edufocus, that we seem to use successfully. I don't really have a hand in it, which potentially shows how easy it works.
  5. Are they all local network users or on cloud/Intune? Is there a difference between Wi-Fi and hard wire?
  6. We have set it up so that the boarding house pupils go on their own VLAN. This means we can relax the filtering on that VPN only with out them being able to mess around while in lessons. This does only work as teh boarding house is far enough from the school buildings so there is no bleeding of signal. This allows boarders not to be restricted if they have a free period, if they are ill and want to phone home or if they have a down day.
  7. To be fair, I'm surprised they haven't been snapped up before. Will be interesting to see how it develops now, especially under a company that, to my knowledge, is cloud first.
  8. Staff do need to be careful that they don't take notes in sensitive meetings and have them sync to their personal account. Our DSL started using one and I made sure he had put a PIN on it and asked him to be careful where his notes went. If I was to want to manage these, I would want to enforce PIN and be able to remote wipe at a minimum. Maybe domain lock where the notes could go to? Doesn't help for staff bringing in their personal devices though.
  9. If I understand your question correctly, and I remember rightly, you turn off the public access to the RDP servers and all access and negotiation is through Azure App Proxy.
  10. A +1 to SharePoint as a FAQ and helpsheet/guide respository. We are looking at Snipe-IT for asset management. Does the job, but a bit clunky in places. I spun up an Ubuntu server and got it all setup fairly easily. Alternatively, the cloud hosting is very cheap. If you are setting up a Linux server it gives you the option to setup an actual Wiki instance.
  11. Do you have all your email security set up correctly? SFP, DKIM, MTA-STS, etc? Can you get the headers of the message and run it through the MXToolbox header analyser? That may give you a better idea of what is going on. Are the emails definitely showing from Hotmail/Outlook or are they using vanity domains but really from Hotmail/Outlook accounts? We have lots of problems with parents setting up domains, either to use their own names or for their company, but not setting up the security and then blaming us for not receiving their emails.
  12. On my box the url is modules/snmp/cgi-bin/admin/snmp.cgi Thank you for the reminder we can add this to our monitoring system!
  13. Interesting, why would you force users to set a manual DNS? Surely, you'd set your own DNS to look at the Google DNS and then push your own DNS to users via DHCP. Yes, you need to allow your own DNS servers to access external DNS, but that is beyond the scope of the question, it is asking about BYOD firewall.
  14. I use it to draft some comms, just to get me going and have a basis to rewrite. I use it to generate some images for internal use, banners or presentations, so I don't have to worry about copywrite issues. I get (non-sensitive) documents distilled or concepts laid out. Not doing anything high level, just to save time and get me started on things.
  15. I wouldn't open UDP:53 as blocking it can stop a lot of malware and ransomware phoning home. This may have been superseded by DoT & DoH but belt and braces.
  16. We use the uplifted Exchange protection (I can never remember the license or name, probably Defender for Exchange or somesuch) and it seems to work pretty well. The only other one I have used was Vipre and that was very good.
  17. Am I misunderstanding or is the law there, it is up to us to enact it? So as long as we have done everything we should have done, DPIAs, risk assessments and the like, then we pass the breach on to ICO and they go after Class Charts for the breach if it is found they have not acted properly. How many schools have cancelled their subscription? How many are willing to cancel it if no answers are forthcoming? So, at that point we know Class Charts do not look after our data, we know they do not take responsibility for their own security or actions and we know they do not properly communicate with us as data controller when there is an issue, and we have continued with them, which makes the schools responsible and liable for them. We have all made a conscious decision to keep using them so we have made our selves liable for their actions.
  18. Depending on who "they" are, @Net-Ctrl do awesome work with CloudPath.
  19. We use CloudPath and don't get users to download or install anything and use DPSK with Smoothwall. The only thing needed to be installed is if you have want MitM certificate on the device, but this will be needed no matter what system is used. The only thing I can think of is something along the lines that you can't use Smoothwall as the auth server but you can account against it, to get Smoothwall authentication. Currently set up that users connect to a setting up SSID, authenticate against AzureAD, get given a code, then copy that and then paste it in to the general SSID. You can have it setup for visitors to get given a code, or email a nominated person to authorise. CloudPath can do a hell of a lot more than we are doing with it and I need to find time to play with it. Yell if you have any questions.
  20. Yep, I remember it being a bit of a palaver. As Andy_b says, wait till the DNS check is clear and it should all work.
  21. Funnily enough I got a tes survey come through so I let rip on why I couldn't recommend them. Funnily enough, even though I ticked the box, I haven't had any contact to get further feedback.
  22. I have had some very, very long conversations with people and companies about not white listing their domain just because they say it is safe. Lots of parents with custom domains, or using their own company emails, not understanding and getting fed up with me that no one else has the issue. Even talking to one parent's friend who runs a small ISP who argued that DKIM wasn't a guarantee or that secure. The funniest one was a department telling me that a small company they work with was always being quarantined so could we white list them as they didn't have the resources to sort DMARC. My response that they sound exactly like the kind company that shouldn't be white listed, didn't seem to go down well
  23. Yes. Been a while since I did it but you can set up a vanity URL for the repo. The settings page walks you through it, I think you have to put a file into DNS to allow it.
  24. Yes you can. I have a single github account with 2 different repos for two different domains.
  25. Github for MTA-STS was much easier than I thought it would be and we have multiple domains using the same github. Worked wonderfully and as we don't have access to our website file structure it was a great solution.
×
×
  • Create New...