-
Posts
254 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by link470
-
Very interesting! Ours are of course the standard Dell cloverleaf style. I'll see if I can track down a figure 8 style and see what happens. Anyone else have any suggestions?
- 2 replies
-
- flickering
- interference
-
(and 3 more)
Tagged with:
-
Hi everyone, I've got a Dell Vostro 1510 notebook PC here that I'm trying to use with an external 21.5" 16:9 Dell monitor. At least one other staff member is using the same hardware, as they all use a laptop/monitor combo, with their monitor set as the main display when plugged in [although the other staff member with the same hardware has the Nvidia graphics chipset instead of Intel in their 1510]. This laptop [intel graphics chipset] is having some issues though. The user was mentioning horizontal lines going across their external monitor, faintly, but definitely visible and distracting. They weren't solid, they were moving, like they were caused by interference. The laptop itself was having absolutely no issues on its built in display, but when plugged into the external monitor via the laptops VGA port, the external monitor would show the flickering lines. I did notice one interesting point. As soon as I unplug the power adapter from her laptop [a standard 90w Dell power adapter matching in volts/amps], the flickering on the external display stops. Instantly. If I plug the power adapter [or a 65w adapter] back in, the flickering resumes immediately. I doubt this is a driver configuration/version issue, and is probably hardware related, but I thought I'd run it by you guys to see if you have any tips to help get rid of this annoying issue, besides getting another laptop. Thanks!
- 2 replies
-
- flickering
- interference
-
(and 3 more)
Tagged with:
-
Barracuda? Is it still popular?
link470 replied to twin--turbo's topic in Internet Related/Filtering/Firewall
Yup. We actually just stopped using it recently though because the 310 model's interfaces are limited to 10Mbits, and we recently upgraded to a 100Mbit WAN connection, and we went through some massive network changes. So the 310 quickly became a bottleneck for internet performance. We're seeing how things go with students using the internet appropriately and if we have issues, a web filter may come into play again. That all being said, I'd definitely choose a Barracuda unit again. Customer support was fantastic in my experiences when I needed to call on them. I had great success with the 310, and the firmware for it kept getting better and better and making it a more powerful device. Not to mention perimeter antivirus/anti spyware, and the ability to strip ads from websites before they're delivered to the client are all great features. HTTPS filtering is another good one. Higher models don't have the 10Mbit limit either, so I'd go for a higher model. They're pricy, but well worth the money if it's a need in your school. [side note, that "mention" ability on the forums is apparently pretty effective ...] -
Hi everyone, I have a desktop computer of mine from 2004 that's been going strong, and this past Tuesday when I restarted the system after Microsoft Updates, I noticed one of my hard drives [not bootable, just held applications] wasn't listed in My Computer. I restarted my system to see if it was just temporary, and again, the drive didn't appear. My motherboard in here is a P4C800-E Deluxe, that has 4 SATA slots, 2 of which are SATA, and the other two are on a Promise Fasttrak 378 onboard RAID controller. I have a 36GB WD 10K Raptor on the first slot, a 74GB 10K Raptor on the second, and a 150GB 10K Raptor on one of the RAID slots, configured as a single drive stripe. It's been operating that way for a few years with absolutely no problem. When I rebooted and watched the boot process more carefully, I noticed the controller BIOS threw a "No arrays defined" error or something like that on boot, and when I tried to go into the RAID configuration utility when I saw that screen, I could see the 150GB drive there, as a single drive stripe, and the status was "functional", it just wasn't set as available. When trying to make the drive available and save the changes, I get an error saying "Error occurred when modifying array", and that the system needs to reboot. I then tried to run a sector scan/repair from the drive maintenance tool ViVARD from an Ultimate Boot CD on the 150GB drive, and I got a stream of "IDNF Can't found sector with current address" [yes, they said "found"] for every single sector that was scanned. After 2000 sectors or so, I restarted, and came here to make this post. Any ideas? The main thing I want to know is, is this the drive? Or is this the RAID controller/motherboard? If I take the drive out, and plug it in with an IDE/SATA to USB converter into another machine such as my MacBook Pro, the drive wouldn't mount and said it couldn't be initialized. But I still don't know if that's because the drive was a single stripe RAID and it has to be read by that controller in my system, or if the drive/drive board is actually failing. Any advice would be greatly appreciated! Thanks in advance.
-
Hi tannerozzy, welcome to the forums! Thanks for your reply. Good call on those settings, that Control Panel Access setting was indeed there! However, it didn't work for me. I think the control panel access feature must have been completely stripped from these printers which is really unfortunate given what a good setting it is to have. I noticed that there were 3 sections for control panel access, and when I hovered over the title of each one, I noticed that they were each for different printer models. I tried them all at once, then tried each one individually to see if that would work. None would apply to the p2055dn printers that I was trying to configure, each one gave me a warning that said the printer model didn't support that feature. So close!!
-
Thanks for your reply! I checked inside WJA for that option, and I could get as far as selecting the printer, choosing the Config tab, and expanding the Security options tree, and under that I only see: •Access Control List •Embedded Web Server Password •Encrypt all web communication •Encryption strength •Get community Name •PJL Password •Printer Firmware Update •Set Community Name •SNMP Version Access Control Can't find Control Panel Access. I could have sworn it was available in the printers web based configuration panel before, but I can't see it now. Starting to wonder if it was a firmware upgrade somewhere along the way that changed the setting. I can't imagine why anyone would remove it though, it's a really good setting for security and preventing tampering.
-
I'm currently looking for the exact same thing. We have the lots of HP p2055dn's and an HP cp2025dn [colour version], and I'm looking for a way to lock the local control panel. I know this has to be possible, as I somehow did it on the cp2025dn before it's firmware upgrade. I remember setting the option, and having the printer display "Menu Access Disabled" or something along those lines on the local printer LCD panel if I tried to access anything other than toner supplies to view toner levels. This was great. But now since all the printers have up to date firmware, I can't find where this option is for the life of me. I've talked to HP both on the phone and via chat support, but the support reps haven't been much help. One of them told me to use the HP Web JetAdmin [even though it requires 5.5GB to install and a local SQL server express install] and I haven't found the option to adjust these settings within that. The other person told me that setting an admin password should lock the control panel, but it most definitely does not. If anyone has found a way to do this, I'd really, really like to know. Thanks!
-
What jamesfed recommended there looks like it will work. The other option, if you can get a hold of two cheap PC's, is build yourself two pfSense firewall PC's and put one at each site. pfSense handles VPN connections very well, the best part though is that you can have a built in database of users right in the pfSense firewall if I remember correctly, which would eliminate the need for a Windows server. But, pfSense will also forward VPN login requests to a Windows Server for RRAS PPTP/L2TP authentication. This can be really handy if the company decides to get a Windows server at some point, which I think would be well worth the investment. Except if you wanted to really clean things up and add client machines to a domain, it could be quite the cost to get all of those "Home Premium" machines up to "Professional". This would be especially beneficial if you were rolling out TMG 2010, but that's even more money. The pfSense route is free [besides your time and finding a couple computers lying around with network cards], which is extremely attractive to a lot of small businesses. But you could easily pick up a couple of small business VPN routers too to save you the effort of building the systems. Either way, once you have the site to site VPN going, you can either do what you were thinking and set up a Linux box or something to use as a file server, or even a workstation running Windows if you like, and then sort out permissions accordingly. Users can map the drives manually, and the most they'll have to do is re-input their password once in awhile to the network share if the machines aren't on a domain. This is where having a server in general though can really help. I'd sell it to them with 3 points in mind. 1, authentication for keeping shares logged in and properly secured. 2, the ability to better control VPN connections and authenticate who's connected to your network from outside. 3, RAID, redundant storage of all of those files that will now be held on a server instead of each persons workstation. The last thing you want is for everyone to happily move their files to the new workstation "server", and then have the server hard drive fail. Hope that helps!
-
I haven't seen it mentioned here yet so I'll toss out what I use! I'm a huge fan of KoyoteSoft's Free HD Converter, and Free Video Converter. Their software is 100% free! I use Free HD Converter for transcoding those AVCHD files that come in .MTS and .M2TS formats off of modern HD consumer cameras that use a highly compressed HD codec for storing the video. Free HD Converter easily makes these something that almost any video editing platform can use. This is how I batch convert all my consumer HD footage and the digital media lab at the high school uses this so they can import their footage into Premiere Pro. I use Free Video Converter for everything else, and this is probably the one you'll want. If you import the videos that you want to convert and then click on one of the videos in the list, it will even tell you the resolution, audio bitrate, frame rate, and a few other useful pieces of info about the source up in the top right so you can correctly match the destination format options below and just change the format. Hope that helps!
-
Thanks SYNACK and Geoff, I fully understand what happened now and why it only triggered after adding the faster switch to the internal network. That makes perfect sense. Much appreciated and thank you both for your time and advice!
-
Good calls from both of you. The issue is now solved! I'd add a solved tag to the title but I can't edit past posts anymore. Just doing some thinking as to what may have caused it to go down suddenly after having worked for so long before and no configuration changes. I ended up removing the default gateway on the internal address, leaving only the IP/Subnet Mask/DNS1/DNS2, and the website from outside the router fired up instantly. So, why was this only an issue now? SYNACK, I think you may be onto something with the link speeds, although before, the external NIC was plugged into an 8 port 10/100 switch, and the internal was plugged into a 48 port 10/100 switch on the main rack. With the current setup, there's a 10/100/1000 switch as the backbone on the core internal network, and the internal NIC is now plugged into that, and the external is plugged into the rack mounted 24 port external switch, which is still 10/100 speed. So the only one that changed was the internal NIC is now on a gigabit switch. Does that make sense and could that be a valid reason that this happened?
-
Hello, thanks for your reply! That's right. On the internal NIC, the gateway address is the gateway of our firewall on the internal school network. On the external NIC, the gateway is the router. Each NIC only has one gateway defined. Despite that not being the recommended setup as servers only like one gateway, this setup has worked for ages. Why it's decided to quit now, I'm not quite sure. Since posting, I've also tried connecting to the external switch [a Dell PowerConnect 3324 managed switch] and reloading the default configuration, to make 100% sure that it was, in fact, a flat switch with no configuration. Absolutely no change. Still cannot access the website in question outside of the router. I've also dumped the ARP cache on the affected server.
-
Full subject: Urgent Help Needed: Can't ping or access website on a server behind a router unless second NIC is disabled I apologize for the extremely long post, but I'm posting this wherever I can to get help. None of our IT staff in the district can figure it out, and our ISP can't figure it out. If you could take 5 minutes to read this, any help would be greatly appreciated and I seriously thank you for your time in advance. --- Hey everyone, I've got a really odd and annoying issue that has just sprung up over the last few days. On the network, I've got a number of servers behind a Cisco router that is provided by our ISP and has a full class C external subnet assigned to it. I'm only using about 6 external addresses out of the more than 200 available. We have one main large network for the building that our users use, and that has a computer acting as a firewall. So the main internal network only uses 1 external IP address. The servers are all inside this corporate network with local IP addresses. I have several other devices in the building that require a dedicated external IP, and one of the servers has 2 NIC's, one NIC is internal [with a static internal IP address of course], 1 NIC is an external NIC with a static external IP address assigned to it. This is a critical server that is hosting a website application to the public. So my setup is that the internal port on the Cisco router plugs into a switch, and any device [including the external NIC on the mentioned server, and the main internal network for example] requiring an external IP address plugs into this. External IP's need to be assigned, as the Cisco router doesn't assign them. Stuck with me so far? Awesome, thank you! Now, this set up has worked great for around 4 years with absolutely no issues. Heck, we've even received a new router from our ISP [managed by the government, I don't have control over this unit] and things still continue to work. Here's where things get sketchy. I recently replaced a bunch of switches on our internal network on our patch panel/rack, and on this rack happens to be the router, and external switch. The external switch was an unmanaged 8 port switch, so I ended up replacing that with a rack mount 24 port switch to keep things clean. When I fired everything back up, our internal network came up, and had internet. The devices around the building that required an external IP and were patched directly into the external switch all came up, and are accessible from outside of the network. The only problem is with that one server with both an internal and external NIC. The website/services on that server hosted through the external NIC are unavailable from outside the router. Now, keep in mind that to me, the only thing that was changed between that external NIC and the Cisco router, was the switch. That's it. Even from inside of our main network, I can go to my desktop computer on the internal company network, pull up an internet browser, visit the publicly accessible [or so it should be] website, and it comes up. I watch the lights on the network equipment and follow the trace, and my computer is going to our gateway/firewall, out the external port to the switch, and straight through the switch into the external NIC on the server to pull the site. Perfect. But I can't view the website from outside of the router. I talked to someone from the ISP's support about it, and they were connected to the router and could ping inside to the server, but could not ping the server from outside the router. Gotta be a router issue on their side right? Wait. It gets weirder. After a couple hours of trying to figure out what was happening, I decided to try something. I brought down the Windows firewall on the affected server for both LAN and external NIC's, leaving the machine wide open as there is no hardware firewall between it and the switch>router, and I connected to the machine via RDC from the internal network, but typed in the external NIC's IP on the server to connect to [again, going out the firewall of our internal network, and through the switch to the server, never exiting the router], and of course, since the firewall was off, I was successful in connecting via RDC. But I then disabled the internal LAN adapter from my external IP session. My second RDC session that I had connected to using the main internal network adapter [the one I usually manage the server from at my desk] immediately cut out. Good so far. Low and behold, after disabling the LAN connection, the support representative could access the website from outside the router via the external NIC, and ping the server. I re-enabled the LAN connection on that server, and he couldn't access the website anymore. Thank you very much for reading this far, I really really appreciate your time. If you can offer any help as to why this is happening, that would be greatly appreciated, as I need to get this server up FAST. I don't want a bandaid fix, I need this server online the way it was. No changes were ever made over the last few days on the server, and everything was plugged in again properly after the switches were swapped out, and the support rep even removed all ACL's and firewall rules on the router to allow a 100% unrestricted straight pass through, and with the LAN connection on that affected server enabled, the external IP didn't serve the website outside the router. Keep in mind, when I accessed the website from inside our company network, even by specifying the external IP address in the web address bar to specify to only go via external [making sure I wasn't just using an internal path, despite that not even being available because of IIS configuration], it worked. The website came up. But would not serve outside of the router if the LAN port was enabled. Definitely one of the most confusing issues I've ever ran into, and the support people at Tier 1, Tier 2, and Tier 3 network operations support for the ISP were completely stumped. If you need any more information or clarification on anything I've described, please let me know. Thanks again!
-
I'd edit the original post and add [sOLVED] to the title, but the editing time is quite short for these forums. Anyway, I found the solution. Actually, I found the solution in another thread on Edugeek! I downloaded the Microsoft Fix It tool from the Microsoft article listed in the thread and deployed it. It worked! Staff can now use USB drives again. I'll definitely be running the Fix it tool on the image again before I re-sysprep it in the future.
-
Hey guys, Just updated all of our images over the summer, and noticed that on staff computers [iBM 8183-NUT's], YouTube doesn't play full screen without right clicking the video and unchecking "enable hardware acceleration". All of our other machines work fine, so it must be a compatibility issue with the video chipset in those IBM's [intel] and the latest version of Flash for whatever reason. Does anyone know of a way to change this centrally via GPO, or any other fixes? Thanks!
-
After updating our images over the summer and creating my usual default profile and sysprepping with /generalize the way I always have, I've noticed that some of the machines on our network [haven't tested all of our images/system types] are showing errors when viewing certain flash parts of website. The systems are Windows XP SP3 with IE8 fully updated. I first heard the issue from a user who was trying to load the website Brainpop and launch the science section. For whatever reason, the users report being unable to view the middle section of the website with all of the options. The website appears to be mostly in flash, and instead, they see a big box in the middle with a broken image symbol. But flash is definitely installed on those systems and is up to date as of this past summer with flash 10.3 [i believe that's the latest]. To test, I went to YouTube on the exact same computer, and YouTube launched no problem. So it seems to be only select flash items. Any advice from anyone here? Anyone ran into this issue before? I'm trying to avoid re-installing flash on every system and rebuilding the default profile on every system if possible. I know it's not a problem with the Brainpop website because I can access it find on my machine. Thanks!
-
Hey guys, So here's a really messed up issue that's just happened this school year startup. I've posted at the Microsoft Technet forums about this issue and still can't find what the route cause is. Here's the issue copy/pasted: I've been deploying new Windows XP SP3 images to our labs over the summer and everything has gone very well. However, one set of images, and I don't know if it has previously had a policy deployed to it for hardware restriction [machines are on a Windows Server 2003 domain], is asking to verify every single piece of hardware. I normally sysprep /generalize our machines, and then deploy them using Ghost. Every lab worked fine, booting up, asking what the computer name should be, and using the answer file to configure the rest. Boom. Done. The problem is the one image I'm deploying to another set of machines. After deploying the image, I started firing up machines to run through the mini-setup. The first unusual thing I noticed was that Windows was prompting for the Windows CD because it needed a file. None of my other images did this, and I thought I had created them the exact same. That's when I noticed the next issue. Upon inserting any USB keyboard/mouse I had lying around, it wouldn't accept them. The computer appeared frozen. But they weren't frozen, it was that I had to use the EXACT SAME keyboard and mouse that I had used while building the image. So for these 70 or so computers, I spent 2 days going around to each machine and plugging the exact same keyboard/mouse set into the machines...in the EXACT same port they were in when I was creating the image for this machine type. After mini-setup completed, the machines restarted, and upon first logon as a local administrator, I found that EVERY machine was popping up a hardware install verification box, like the one you see for "this hardware has not passed logo testing" when installing a driver...for every device. It prompted me to install the processor, the hard drive, cd-rom drive, ethernet [which I quickly burned a driver cd for to toss into each machine as it asked], several bus controllers, and last but not least, the keyboard and mouse that were actually plugged into that machine. I just had to click "allow" [i think it was allow...you'd think I'd remember by now] on each of those popups since I was already logged in as an administrator, and it just found the drivers on the local machine, except for ethernet, which the machine first prompts for a cd, and then takes the drivers from the local machine somewhere instead [go figure]. Staff can also no longer use their USB flash drives on these machines. They used to be able to insert a flash drive and have it just work, but now it's prompting for my Administrator password on all of these machines. Again, all labs and other computers in the building are unaffected, it's just these computers, and as far as I know, I don't have any policies in place for hardware restriction. The only thing I can think of is that there's a policy that once existed awhile back and the values still reside on the local group policy on this image. Anybody have any idea of which policy I should be looking for? I'd really really like to get this sorted out and would prefer to not redesign the image from scratch and re-deploy in the middle of a busy season. I'd much rather push out a fix. Thanks for your time in reading my post! ::EDIT:: I've already compared all 3 local policies [Audit Policy, User Rights Assignment, and Security Options] with a machine that works fine, as someone thought maybe the value in User Rights Assignment for "Load and unload all device drivers" was incorrect. But after comparing the 3 policies, EVERY single policy option was the exact same. No difference.
-
I'll give that a try! Thanks a lot. ::EDIT:: This method appears to work great. Thanks again!
-
Thanks for your reply localzuk, do you know how I can do this in Microsoft SQL 2005 Express Management Studio? I've never found a good way to schedule almost anything. If you have an example of a script and how I can schedule it, that would be greatly appreciated! Thanks again.
-
Useful tools for Technician? Just about to start my first job.
link470 replied to fredted40x's topic in Windows
First off, congratulations on the job! As mentioned by cpjitservices, Backtrack 5 is fantastic especially when doing security auditing. I also can't live without Ultimate Boot CD. Gotta have one of those on you at all times The actual item I came here to mention is a multitool. I've seen one mentioned already in this thread, but I'm just here to back up that statement. Aside from all things digital on a computer and all the downloads and software and bootable tools available, never underestimate the power of a multitool. I personally use the Leatherman Juice Cs4, and I absolutely love it. It comes with a leather case with a strong belt hook and I can't tell you how many times I reach for it during a day for many different reasons. When I don't have it with me, I definitely notice. The other thing I really like about it is it has the essentials without too many things you don't need, allowing it to be a LOT less bulky than a lot of tools I've seen. It's a really nice compact size and with a 25 year warranty [if I remember correctly], you can't go wrong. -
Hey guys, I'm using Microsoft SQL Server 2005 Express edition. As anyone here who manages these servers knows, it's not very easy to configure a backup from these servers as there's no Maintenance plans available [someone please correct me if I'm wrong, obviously]. But I'm wondering, would it be safe to backup these databases by simply backing up the %PROGRAMFILES%\Microsoft SQL Server\MSSQL.1 folder containing the Data folder [where it appears the databases are kept]? Since NTBackup uses shadow copies I don't think I'd need to stop the service. I can if neccessary via a script that runs just before the backup does, and then restart it afterwords with another script [or script a stop service>backup>start service all in one script]. But back to the main point Would this work? I've transferred databases from that folder before to another server and had it work perfectly fine. Thanks!
-
Hey guys, So, I have a ton of computers here that take PC2100 and PC2700 memory, and since our school district doesn't exactly have the highest budget, I'm looking to just upgrade the RAM from 512MB to 1GB in a lot of these machines to speed up login times and application launches. The question I have is...where still sells RAM for a decent price? I've been checking ebay recently. There's been a couple of good lots, but none close to the amount I need. I worked it out the best I could, and I need 186 sticks of PC2100 512MB, and 160 sticks of 512MB PC2700. The machines are Dell GX260's, HP Compaq D530's, and IBM MT-M 8183-NUT's. Any advice on a place to get the best deal for shipping to Canada would be greatly appreciated. Thanks!
-
Hey guys, First, some background. I've got a set of 5 laptops here [Acer Aspire 5552-3680] and they all have an interesting issue with wireless. We have about 12 access points around the school, all with the same WPA encryption key and SSID so they look like one large wireless network, and......this isn't the way I'd like but on a very very restricted budget, they're consumer routers with DHCP off and a network cable plugged in from a switch/network jack around the school to one of the 4 LAN jacks on the wireless routers. Since some routers are fairly close in proximity to others, what I've done is changed the channels on all of them between channels 1, 6, and 11, and separating the 1's farthest away from each other, 6's farthest away, and 11's farthest away. So for example, a channel 11 router might be in range of a channel 6 router, but not another channel 11 router. Believe it or not, it's worked fairly well. All laptops are on the domain and require authentication to use, there are no local accounts besides the Administrator account. Now the problem. These 5 laptops, for whatever reason, in certain areas of the school, won't log in. Domain not available. I log in locally using the Administrator account and I notice that the wireless adapter isn't connected, but can see the wireless network perfectly fine. If I try to connect [i'm using just the built-in Windows wireless manager], I notice the wireless adapter flip from Acquiring IP Address, to Not Connected. Back and forth fairly quickly [1 to 2 seconds between status change usually]. If I move the laptop down the hall about 10 to 15 meters and try reconnecting, boom, connected. Signal strength is good to excellent in both locations. I've noticed 3 particular places in the school that connectivity seems to be an issue, and I'm not sure if it's these particular laptops wireless adapters, or if it's something else. I notice the issue sometimes with my iPhone too. Is it the way I have the routers configured? Something else? It's been understandably frustrating for the staff that work with student services and lend a student a laptop to use during class only to find out that in some classrooms the domain connectivity isn't available because their laptop isn't connected, thus the student can't log into the laptop in the first place. What I'm wondering is if certain laptops and wireless adapters are getting confused at having multiple routers in range. But it should work, and has always worked for the majority of our computers here. Not sure what's up with these ones, and they're the newest. Any advice would be greatly appreciated! Thanks!
-
Hi everyone, I'm running a DHCP server on our Windows Server 2003 domain controller, and DNS is obviously hosted on the same box with a secondary domain controller on the network as well. Just recently, I noticed that the account that was entered in as a DNS update credentials account within DHCP Advanced tab properties was the same account as a domain administrator, which had escalated privileges. I wanted an account to be dedicated for just DHCP and DNS updating so I created a new account on our network and made that the account for DNS updates in the advanced tab of DHCP properties. This went ok, but I noticed that a heck of a lot of pens started appearing on the computer icons in DHCP. From what I know, this is caused by that DHCP entry waiting to update a record in DNS. I noticed that if I go over to DNS, right click on some of the entries, and choose properties and then choose the security tab, I can see the new account I created for DHCP/DNS updates listed as having write permissions, but not all of the records have this. What should be the next step for me to take? Should I delete all the A records for our network computers in the Forward Lookup Zone and wait for them to repopulate? Would that be bad news? Any advice would be greatly appreciated. I haven't actually noticed any problems yet, I changed the credentials used in the updates about a week ago, I haven't heard any panics from anywhere, I just remember that before, there were only pen icons above the few computers I had on the network with reservations in DHCP, no other computers. If you need more info, please just let me know. Thanks!
-
Hi Chris, Thanks so much for your help! I've implemented this change by adding just the *.lnk path and set it to unrestricted, and it works! No idea why this was just effecting one lab and none of the others. The part I find odd is it was exactly one lab of 10 computers, where all 10 computers were effected, and not a single other machine in the school was. Very strange. This fixed it though and has allowed me to deploy the policy now that it's working. No problems or complaints so far, which means things should be working and students should only be accessing what they're supposed to Thanks again!
