Jump to content

TechMonkey

Members
  • Posts

    7,551
  • Joined

Everything posted by TechMonkey

  1. Me please! If you write anything else do you get disqualified?.... Damn it.
  2. Agree. Also I have found wireless, although more convenient to install, often lack features of the wired version. Paxton Net2 door looks can be locked down or remotely opened, but the wireless versions can't.
  3. Unfortunately that is confirmation bias though, the schools that have called in a security/network consultant probably know they need help and have issues. Also from your posts on here it seems you are aiming for complete lockdown, which is not practical in a school. The term "get on to their network" is a very broad term. Things like locking ports to MAC addresses or setting up systems where a new device has to have authorisation are a lovely ideal but less than practical and usually only implemented in Colleges and Universities. More practical observations or tips would be well and gratefully received but a combative attitude and swiping at others will never go down well here.
  4. Yeah this. There are very few workstations here that are purely used by only staff or students. The only places might be some offices but then something odd would happen like a pupil would need to do a test in an empty office. Personal devices though should be dumped into a completely seperated VLAN and shot straight out to the internet. We would be cutting our provision for staff or pupils dramatically if we marked stations as only for one set or the other. Yes we need to be secure but we have to remember we are not a military facility, the network needs to be useable. It is a fine line but being black and white won't serve the school well.
  5. Smoothwall have their Cloud Filter that syncs and interacts with your on site Smoothwall box, but the client is in the cloud. I'd speak to your account manager.
  6. I think that the confusion is, at least in my mind, "Smoothwall is either a time server or a time client" suggests that when Smoothwall is a time server it can not be a time client and pick the time up from elsewhere. I think it is the use of OR, making it sound like a one or the other, not both. I'm pretty sure the KB wording has been updated as it seems clearer on there now.
  7. Have you closed the firewall ports? Everything goes via Azure and the Proxy server so there shouldn't be a route to the RDP Gateway. Also I seem to recall having to change the binding for the gateway so it shouldn't respond to the old file.
  8. Is it completely ditched or just not visible to users? I mean there are still a lot of finance websites that use ActiveX plugins that need IE11.
  9. Depends on what is different. If it is just a graphical overhaul with things in the same place (which it is from the sounds of it) then it won't be much different from what most of us have been doing for ages. New version, wait a month to check no nasties and then rebuild using new version and because everything else is scripted or task based no major faff. If MS decide to go whacky with the start menu, ala Win8, then I will probably wait a while longer and do it over a summer so we can prep staff. We've already survived EOL for various versions of Win10, this sounds like just another one of those but with a different brand.
  10. Nothing in Event Viewer?
  11. We use PRTG free (up to 100 nodes) but we aren't monitoring every port, just that things are available and some extras. LibreNMS is meant to be very good.
  12. I wouldn't agree with you. The final line indicates to me that they expect you to use the Smoothwall box to provide the time internally and only the Smoothwall box to retrieve the time externally.
  13. In Server Manger on the Gateway go to Remote Desktop Services, then Servers and it will show you the relevant Event Viewer entries to RDP.
  14. Ha ha ha, yes. I went the short term pain for long term gain. Lots of whining but told them to get over it and pointed out how the machines slowed down when lots of them did it. Staff weren't bothering logging out as they knew it wouldn't stop someone else, but it was slowing the PCs right down. We were having to tell people to reboot the machine anyway so turned it off and told staff that if some one had abandoned a machine logged in you were allowed to just turn the PC off. Also laboured the point that if they stayed logged in they were stopping someone else getting on. Peer pressure did the rest.
  15. I got it working. I think I had this issue. Check the event logs, probably the Remote Desktop Services built in to the Server Manager will be most useful.
  16. Depending on what features you want Kefron AP seemed a good system and reasonably priced. We didn't go for it in the end only because we are migrating to a different finance system that has it built in.
  17. Depends on what you mean by terrible. Never had any issues with them. They also seem to work with the generic Papercut driver. The biggest issue we had was that due to having a central queue you had to have the most feature rich driver installed so all features were available. This confused some staff as they enabled some options that the copier they printed to didn't have so it ignored them. They thought this was unreasonable until I explained in very short words how a copier can't do something it doesn't have the capability of doing.
  18. No scope to turn off Switch Users? It really is a bodge and introduces more issues than it fixes.
  19. We have Sharp machines. We had a single RISO, but it was a previous generation model so it may be unfair me commenting on it. Sharp have been fine for us. We renewed the contract last time with them. We are starting to run into issues as the machines are old, but they are now coming up for 7 years old and we have a contract renewal impeding so we will refresh everything. Biggest issue we have is with paper quality and damp, but we are in an old building so it may be environmental rather than a Sharp issue. They were much cheaper by far for us so it was a no-brainer. Toners are auto ordered, a few consumables we have to manually order. Engineers are good and we have sometimes had same day response. The one difference in the tenders we got was a lot of suppliers were offering 4hr response, which Sharp didn't offer. But we have enough copiers that speedy response isn't a major issue, especially with the cost saving. We have integrated with Papercut and that all just works. RISO we got rid of in the end. The signing on system was clunky, having to have an external box that had interesting foibles like not being able to type some characters for passwords. I think this functionality is built in now. I can't remember all the issues but I seem to remember that the cost per print was much higher on black, I think. Staff loved the speed, but that was only available on black. Quality was alright, fine for exam papers and internal docs but not so great for sending things out. We did event programs on them a few times and they were ok.
  20. Is it definitely a block? I seem to recall Kindles had an issue with enterprise wifi so really wouldn't play nicely? Though it may be a HTTPS interception issue, rather than a blocking issue, as I know a lot of apps get picky about that. Do your logs not show anything?
  21. I would suggest going down to their offices and raising hell, but they have a moat so may raise the drawbridge... (this isn't a serious suggestion, I just always find it amusing that they have a moat and wonder if they have ever thought about cutting off the bridge to prevent customers getting to them when there are issues)
  22. In M365 you need to have a certain license so you can use Conditional Access. This also allows you to set it to only be used from home, rather than in school (though that depends on your position on MFA all the time or not) As we are local to the Skinners school that got hit I think staff were quite receptive, though most of them hadn't bothered to follow the instructions that had been sent and only realised once it was activated. We had already had management using it for about a month so they could at least say it wasn't much trouble and to just get on with it. We also set only on site activation of MFA to stop someone not setting it up and an attacker being able to setup MFA in their stead. As we are doing offsite only we have asked staff to setup on their own phones. Overall fewer issues than I thought but rather intense workload as a lot of staff can't read instructions.
  23. I'm sorry, in what world do people need it to made crystal clear the babies being born with antlers and feathers is anything but fantasy? To me a lot of those tweets read along the lines of "I'm gullible and don't like realising I am. Damn you Netflix" and I'm glad that one of them was self aware and admitted it. The discussion about a newspaper needing or allowing their paper to have a wrapper is a whole different discussion. Overall I thought the ad was fun.
  24. Jade at Haptic - 01536 316879
  25. So as my brain remembered it was DLP I went looking. In the M365 portal there is Compliance Admin Center, then go to Data Loss Prevention. You could see if there is a policy set up there and look at the activity explorer .
×
×
  • Create New...