Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

superfletch

Members
  • Posts

    500
  • Joined

  • Last visited

Everything posted by superfletch

  1. Sorry Nick - I did mean you,
  2. @Bossman: "They are just full of excuses as to why they are so irresponsible when it comes to IT security." Sadly he's right - it is our job to fix this. --------------------- @Nick Ross: "If your students know staff passwords, then access to the MIS is far from your only concern, IMHO." True, but it is probably the biggest (or near biggest) concern. Afterall the MIS is where the schools most wothwhile, useable, and most sensitive data exists. Especially if they are a (wait for it...) "Power Teacher". -------------------- The whole "No - For other Reasons" connundrum: I totally agree with VikPaw: "Also, for whatever reason, due to lack of computers / laziness / speed, many of my users (especially admin/support/medical ..) share a logged in computer to use SIMS. For this reason, i could never have full trusted auto, and it is for this reason i have held back a full roll out." I myself feel that to troubleshoot issues non integrated logins help you. Sometimes a SIMS or FMS problem exists due to an issue with a Windows user profile. Non trusted logins helps you understand and resolve this issue when it occurs. --------------------- @dyoung5: "I'm trying to put a case for using SIMS trusted logins (integrated with active directory). Can you please vote and reply with any useful security information both for and against." I voted "no - for security reasons" I'd love to see integrated logins in action but I think it is too dangrous to use throughout a school as a whole. Example: Who cares if a random teacher with low, low access to MIS leaves their PC unguarded and the class gets in, they can't do anything or see that much (until they learn how to find a marksheet). However, if an SLT does the same then all of a sudden the class who get to look at the data can see (and edit) pretty much whatever they like. What I'd really like to see in a 2ndry is a decision whereby the office has integrated logins but not the teachers, (is/how easy is, this to implement)?? --------------------- @User3204: "expecially as SIMS made them all those stupid XKCDWVZXSJ type passwords." Surely you mean "secure" passwords?? --------------------- !!!Christ I sound like I work for Capita - scurries away with hand over back of head... My 2p
  3. superfletch

    Backups

    We got told this too (after we'd been told Off site was sensible)... times change I suppose, We responded with a FIPS 2 compliant solution on the tape (Symantec and a few other Backup Software will do this), basically encrypt the data that goes on the tape, CUL8R Audit...
  4. Hi Tony, I've had a good mess around with my own system manager groups in the past having reasonable success in some instances. However I wouldn't say I'm an expert in this area so if I'm talking crap here someone please put me straight!! Using the System Manager utility that allows you to define group permissions I'd suggest what you are asking for will be hard to achieve. Whilst the GUI provided in system manager allows you to set very granular permissions I don't think it will get you down as far as you want (ie - bulk update but just these particular G&T related tick boxes). One way or another you'll probably end up needing to give the teachers "a bit more than you want to" to achieve this. I think it would probably be possible by tampering with your SQL database using a third party tool of some description but obviously that would be a dreadful move as I'm sure support for modified DB's would be less forthcoming at your LA and CCS. Sorry mate I don't think you'll do it - I don't know if System Manager 7 might change this though?? SF
  5. It isn't free by any means but I consider Junior Library to be an excellent product, I work for several primary schools who run the software and find it easy to implement as well as having a sensibly laid out GUI for kids, librarians etc. Good support and easy to upgrade too. Don't know how the DB stands up to heavy access like a secondary might get through but for a primary I've found it great - thumbs up.
  6. If you're setting up anything new and whizzy which might take a lot of time (particularly multiple SQL Servers) don't forget that you're going to need to migrate from SQL 2005 to SQL 2008 at some point between October 2009 and October 2010. Just worth bearing in mind.
  7. Any info on those dates available yet? Cheers,
  8. I feel like I should know more about this conf', where, when, and how do we book? Is the whole conf' aimed at virtualisation tech or just the section you're doing? Cheers,
  9. You may already know this but it is possible in recent releases of Ubuntu to use the Windows WiFi drivers for your WiFi card. With your wired ethernet fully functioning, head to the repository download manager thinggy under System | Administration | Synaptic Package Manager - you'll probably need your root password. Search for the latest packages. Download: ndisgtk Once installed open and run it, System | Administration | Windows Wireless Drivers, choose your Wireless driver for windows (inf file) and you're pretty much done. Configure the WiFi settings for your network. Bob should turn out be your mothers brother.
  10. "I would advise him to contact County LA and ask for their advice on the matter but inform the HT first. :)" County LA - Thats us "Broken software is not a sufficiently good justification for disabling AV. Setting granular exceptions is a possibility. I assume the AV is picking up the SMS software as a spam mailer or similar infection and blocking or rate-limiting it?" Couldn't agree more - I'll find out what AV he's using - some of the interfaces aren't very good for setting exceptions.
  11. One of my colleagues (a network manager) has been told by his boss (HT) to switch off the AntiVirus on the schools MIS Server for at least an hour every day while some piece of software sends automated text messages to parents. Basically the software won't work without him doing this, the software company have recommended this is how he gets around it without suggesting anything else and they rather than him are getting the HT's support!! Now apart from the obvious risk of exposing the machine to a virus, malware, The BBC or anyone elses botnets, can people list the best reasons they can think of not to switch off the antivirus daily. This is a mission critical server housing sensitive data on a network full of secondary kids with an interface in some way to the telephone grid. I'm going to tell him to look at some other products but some ammo to throw at the HT might help.
  12. Most of this was written for Server 08 but is equally applicable to Server 03... Enabling workstations to run SIMS and FMS in a network environment... 1. TCP/IP and Named Pipes 2. Firewall access for SQL Server 3. Firewall access for Document Server How to enable TCP/IP and Named Pipes for SQL2005 Before amending please ensure that all users are out of SIMS .net On the Server 1. Click Start | All Programs | Microsoft SQL Server 2005 | Configuration Tools | SQL Server Surface Area Configuration 2. Click Surface Area Configuration for Services and Connections 3. Under the Database Engine for the correct instance click Remote Connections 4. Click Local and remote connections 5. Click Using both TCP/IP and named pipes 6. Click Apply 7. Click OK to the message 8. Click OK again 9. Click the X in red box to close the window To apply the changes made above Stop and start the SQL service: 1. Click on Start | Run 2. In the browse box type services.msc 3. Click on OK 4. When the Services screen starts 5. Click the Service relating to SQL server for SIMS “SQL Server (SIMS2005)” 6. Click Stop – this will stop the service 7. Click Start – this will start the service Firewall access for SQL Server: The firewall on Server needs opening to allow access to the SQL server Add the program: 1. Open the Windows Firewall dialog box 2. Click on the Exceptions tab 3. Click Add Program. 4. Click Browse and navigate to:- 5. D:\Program Files\Microsoft SQL Server\MSSQL.1 \MSSQL\Binn\Sqlservr.exe 6. Click OK Add the Port: 1. Click Add Port. 2. Add a TCP port 3. Name is SIMS SQL Server 4. Port number is 1433 (Unless it is set to a non default port). 5. Click OK 6. Click OK to close the Windows firewall program Firewall access for Document Server: To open a port for the DocStorage Server Windows firewall for TCP access 1. In the Windows Firewall dialog box, click the Exceptions tab, and then click Add Port. 2. In the Add a Port dialog box, in the Name text box, type DocStorage Server. 3. In the Port number text box, type the port number 8080. (Default for DocServer) 4. Verify that TCP is selected, and then click OK. Not required but useful info just in case. 5. To open the port to expose the SQL Server Browser service, click Add Port, type SQL Server Browser in the Name text box, type 1434 in the Port Number text box, select UDP, and then click OK.
  13. I don't like the fact that more than 1 person in school finds this behaviour familiar. Suggest to the users affected it might be viral - but it isn't their fault! Try reducing your DHCP Servers lease time to something really low (like an hour) while you remove uninfected machines from the domain. Keep a separate eye on any machines with static IP's to see if they act bizarrely. After this, staff/pupils should report any infected or bizarre machines (to the technician/co-ordinater). If they have a viral problem the best option might be just rebuilding by RM techiques or reimaging (standard image) the machine, as realistically the computer belongs to the school not the staff so as long as work is saved on the network it should not be a problem.. They can be rebuilt very easily.
  14. Hi folks, This is pretty much what I try to use where possible: "Redirected Start Menu in the mandatory profile with appropriate permissions." I'm happy with the concept of this but I seem to be getting it wrong: Where do you guys keep: Profile: Start Menu: Desktop: What are your AD Settings AS FAR AS where each thing should be? THANKS MF
  15. Hello there, I work for an LA and we support SIMS for all schools throughout our county - we also get involved with more general ICT (Network and Technical support) for schools (mostly primaries) that choose to buy into our service. I'm sure from your OP that you probably know most of this but here goes and I'll try to help - I expect a couple of people will post where I've gone wrong. Firstly - Most Secondary schools have a dedicated SIMS Server (it might run a couple of other non intensive tasks such as the nearby printers or image server). Second - In secondary schools most of the SIMS work is divvied up around the school, and as a rule each person knows how to use the bits of SIMS they need to very well. However they don't go any further than that - which is usually fine. Third - If you can, then follow mbrahams advice. Get someone else to manage SIMS outright (ie they are the SIMS manager)- if you want it work properly it needs to be something the headteacher leads on - getting everyone involved, and requires commitment particularly from its biggest users (eg Office and SEN). ---------TECH---------------------------- SIMS is composed of these main parts: The Database Server (Currently an SQL 2005 DB). The Document Server (Written totally in .net as I understand it) by default runs on port 8080 and in 99% of cases runs on the same server as the Database. The Shared folder (Mapped Drive) - usually on the same server. The Client Application. --------1-------- To install SIMS on a workstation - you need .net framework 2 + sp1 (minimum) installed. The user needs to be able to see the sims mapped drive (usually this is S:\) Then the following app' needs running with the correct options chosen from a settings menu (S:\SIMS\Setups\SIMSINST.exe). On connecting a new workstation you need to point it at the location of the simserver\instance and the databasename. OR you can point at a master ini file containing this information (Usually S:\Sims\connect.ini). --------2------- The SIMS Database has its own extensive security within the system manager module. (Log in and check out system manager investigating the Focus | User area) This area means that even if people can access the shared drive - unless they have a username and password for SIMS they can't access it. If they have a username and password - they can only access the bits they have been allowed to access. Permissions to the sims shared folder can also be controlled. ****V IMPORTANT - If people exist within the Personnel part of SIMS then they can be made users of the SIMS System easily - if they don't then a user can be added but it is better that people are on personnel wherever possible.**** --------3------- Subscribing to Capita's Supportnet was a good move - there is so much information on there about using SIMS and FMS. It helps me solve roughly half of the problems I am asked to help with. Click on | Web Support | Solution Search. --------4------- FMS is installed in a very similar way to SIMS (Instead of SIMSInst.exe you use a file called FMSApplicationSetup.exe - soon to change to FMSInst.exe I believe) All FMS Workstations need: SQL 2005 Native Client, http://www.microsoft.com/downloads/details.aspx?FamilyID=d09c1d60-a13c-4479-9b91-9e8b9d835cdc&DisplayLang=en .net framework 2 + sp 1 and to have to have a default printer. --------5------- The document Server is important because it deals with reports and any documents attached to students. Knowing where it is is equally important. By Default it gets installed at the SIMS Servers C:\ drive under "DocStorage" but most schools have modified this - to find exactly where your document server library is do the following: On your SIMS Server open a command prompt and go to the directory the document server lives in: Ususally - "correctdriveletter:\Program Files\SIMS\SIMS .net Document Server" From here run the command DMCONFIG This will tell you the protocol used to connect, the port the service runs on and the directory it resides in (the port must be available past your servers firewall). Your LA will usually do training but in our LA it is mostly for users rather that techs. Get someone from the LA to come out and do some one on one stuff with you so it meets your needs. SF
  16. Does it have more than one network card enabled or is there an alternate configuration set on the main network adapter?
  17. You probably tried it already but A Windows Server 2003-based computer may stop responding when it is resumed from standby and events 1030 and 1058 are logged in the application log of a domain controller looks very similar Look under the symptoms (description part) and it looks very similar to your issue...
  18. Any good? GPO Editor | Relevant OU user config admin templates start menu and taskbar prevent changes to taskbar and start menu settings
  19. I had the same problem as this with a Sony Vaio, eventually I took an image from another XP laptop and duplicated it across onto the Vaio installing device drivers afterwards - as RabbieBurns said already the Sony Website was very good indeed for the drivers (once I'd used the serial number to join club Sony Vaio). Like the OP - I wouldn't buy them again.
  20. By an icon that points at the server I expect they probably mean a RDP shortcut so that person can log on to the server remotely and carry out SOLUS upgrades? Connection failed reason 0 - either incorrect connect.ini (FMSConnect.ini in this case) or perhaps the servers firewall/antivirus is blocking the incoming connection to the SQL server. If that doesn't resolve then next question is: Is the machine definately on the domain or is it a workaround with some drive mappings and authentication jiggery pokery?
  21. I don't see any reason this shouldn't work - try it.
  22. Hi, My real name is Matt and I work for a Local Authority (Boo Hiss - yeah whatever) providing MIS support to all our schools and 'proper IT support' to a smaller number (5 years). Personally I'm involved with 7 schools on a regular basis as the IT Technician for them, these are mostly Vanilla setups which I prefer but also one CC3 and one Viglen, these total 10 Servers and approximately 250 PC's. Our team is something of a one stop shop for ICT questions and support for schools if we can help we do and if not we find the people who can. Main interests in ICT are: Client - Server troubleshooting, Scripting (crap at it mind), Group Policy Implementation, Remote Support solutions. Been using Edugeek a while now but don't post that frequently - had some fantastic help from other members it's a great resource - well done to all the admins and moderators.
  23. Gonna hazzard a total guess here, I've never used the version of McAfee your talking about but one version I have used has given me a number of problems with applications that send emails (which I'm guessing is what your OMA agent may be doing in one form or another). Try (If it exists) changing the exceptions setting in the firewall section of your McAfee. I often need to allow communication over port 25 (McAfee Identifies this as a port potentially used by malicious worms) in the problem version of McAfee to allow my applications to send notification emails. If it doesn't change the situation you can always switch it back on and then your down to the pain in the backsid job that is working out which setting is causing the problem.
  24. @contink - Good use of emoticons. I agree with the majority, Christmas should certainly be reserved until at least December. Sadly the powers that be dictate it must begin earlier every year. Just wanted to point out efficient use of emoticons really (afterall it does make a nice change).
×
×
  • Create New...