Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

teckedd

Members
  • Posts

    60
  • Joined

  • Last visited

Everything posted by teckedd

  1. Hi Stewie, It sounds like you are experiencing even more severe problems than we have seen. It would be very helpful if you created a support case with Microsoft and inform them you are experiencing a similar problem to case number: 110070944106368. I have been working with Kapil Thacker. If they are happy you have the same problem I would hope this would be enough of a business case. Thanks Edd
  2. Hi Synack, We are using the domain profile but the firewall starts in the public profile until the domain controller can be contacted, it then switches to the domain profile. Hence the DHCP problem occurs in the public profile. Thanks Edd
  3. Hi Stewie, Thanks for you post. What problem is this causing you? I know that sounds like a stupid question but this is the information MS are asking me for. The main problem I have seen is inconsistent application of GPOs. Thanks Edd
  4. Hi, Microsoft have found the location of the bug, but now require a business case to fix it! If you are experiencing this problem please send me a private message with your contact details on so I can try and get Microsoft to produce a hotfix. Thanks for your help, Edd
  5. Hi Simon, As this is with the debug team there is currently no number but if you say you are experiencing a similar problem to case number: 110070944106368 and I have been working with Kapil Thacker that should point them in the correct direction. Thanks Edd
  6. Hi Simon, This issue is currently with the debug team... progress is very slow and they have not given me an expected release date. The workaround is to disable the public profile (you don’t need to disable the whole firewall) or change the DhcpConnForceBroadcastFlag to 1. Setting the global broadcast flag works, but you need to delete the DhcpConnForceBroadcastFlag on each NIC, as the local one will override the global one! This would involve a script as each NIC is listed in the registry by its GUID. I personally did not want to do this as I believe increasing broadcasts is rarely a good thing and Microsoft firewall should work! I have requested the internal KB number and will post it when I get it. I hope finding this post saved you a lot of time Thanks Edd
  7. Glad you got it working. Thanks Edd
  8. Hi, We have just installed Junior Librarian system on a 2008 r2 server and Windows 7 clients without any problem. We used the latest version and 'edited' the RM CC3 MSI. Server You need to install the Server MSI on the server and move the Junior3 folder to a shared location that your clients have access to. You also need to map a drive to this folders. For example; if you have a shared folder called 'delivery' mapped to x: on the clients and you copied the junior3 folder into the delivery(x:) folder and the x: drive is accessible by all the users that will be using the system then this should be all you need to do to the server. (They need write access to this folder - you can check the exact permission on the CC3 installation instructions) Client You then need to edit the client MSI. You can do this with Microsoft Orca tool. Once you can open the MSI using Orca you need to search for p:\junior3 (this is from memory so I would need to check) and replace the text with the path you copied the junior3 folder to. In the example below that would be x:\junior3. Once you have edited the MSI you can then deploy the MSI in your normal way (e.g. group policy) and provide your uses with shortcuts. Hope this helps Edd
  9. Hi, To stop anyone else having the same 'fun' as me, I thought I would share my Windows 7 problem that has resulted in many hours spent testing different DHCP servers, routers, NICS and reviewing packet logs! This problem seems to occur if you have all of the following: Using a DHCP reply to forward DHCP requests (e.g. using VLANs and an IP helper on the router to forward DHCP requests) Windows 7 clients Windows Firewall Public Profile turned on (default configuration - all profiles) DhcpConnForceBroadcastFlag = 0 (Default for Windows 7) Symptoms NETLOGON event ID 5719 in system event log This computer was not able to set up a secure session with a domain controller in domain due to the following: There are currently no logon servers available to service the logon request. Group policies inconsistently applying on start-up Event ID 50024 logged in the Microsoft-Windows-DHCP Client Events/Operational event log (you need to enable this event log as its disabled by default) Ack Receive Timeout has happened in the Interface Id xx Background By default Windows 7 request for its DHCP reply's to be a uncast responses. If you are using a Windows DHCP server and your client is on the same broadcast domain (not accessing the DHCP server via a DHCP reply) the DHCP server receives the request but ignores the clients request for a uncast response, and reply's in a broadcast. In this situation everything works. The problem occurs when your client has to access the DHCP server via a DHCP relay, such as a router or switch and the DhcpConnForceBroadcastFlag registry key is still set to the default(0). In this situation, the client sends out a broadcasts requesting an IP address, the DHCP relay forwards the request to the DHCP server, the DHCP server sends the reply(ACK reply) to the relay and the DHCP relay sends a uncast reply to the client. If the Public profile is turned on in the Windows Firewall (on by default) then the ACK reply is dropped by the firewall and is never passed to the DHCPclient.dll Conclusion I passed my findings and research to Microsoft support and after more packet logs and deep Microsoft DHCP\Firewall traces, they have concluded it's a bug! they have now created an internal KB for this problem. This has now been passed to the developers and I am awaiting an acceptable workaround and Microsoft to release a patch. I will post the workaround and a link to the patch when I get more information from Microsoft. Hope this helps, Edd
  10. Hi Dan, We have one of the new stands and these should be what they are now shipping. They have improved the design problem but, if you use "excessive" force you can still remove the cover. Secondly if you plan to lock the computer cases with padlocks you need to use the largest ones that fit otherwise you can still "unlock" the stand and remove the cable cover with ease. Hope this helps, Edd
  11. Hi Carvjo, I am glad are finding Specops helpful. I think it's the best tool in my belt. If you need any thing just drop me a PM. Edd
  12. That price is about right. You should be able to offset the cost of it against the technician time saved. I plan to have Windows 7 installed on 600+ computers in 3 days over the summer, all I need to do is right click on an OU and select reinstall, then send a WOL packet to the computer to turn them on. They should install the Windows 7 image I created followed by all the applications deployed to that location. Then we will just need to visit any that might fail. What cost is did get quoted for Altiris, as I looked at this originally and it was more expensive. I just asked for a fresh price for Altiris OS and Application deployment and they want £17.63 per computer and you need an SQL server licence. Thanks Edd
  13. Hi I am using a batch script to install the required AD tools on staff computers. You need to download the x86fre_GRMRSAT_MSU.msu from Microsoft and place it in a location the computers have read access to. Then run the following commands once on each computer you want to install ADUaC on. My batch script look like this. Script Start - InstallADUaC.bat c:\Windows\System32\wusa.exe "\\...path to msu.....\x86fre_GRMRSAT_MSU.msu" /quiet /norestart dism /online /Enable-Feature /FeatureName:RemoteServerAdministrationTools dism /online /Enable-Feature /FeatureName:RemoteServerAdministrationTools-Roles dism /online /Enable-Feature /FeatureName:RemoteServerAdministrationTools-Roles-AD dism /online /Enable-Feature /FeatureName:RemoteServerAdministrationTools-Roles-AD-DS dism /online /Enable-Feature /FeatureName:RemoteServerAdministrationTools-Roles-AD-DS-SnapIns Script End I use a Specops Deploy to deploy applications. I use this to target what computers run the batch file and to make sure it only runs once. If you application deployment system does not support deploying/running batch file you could use a start-up script. You would just need to add some logic to make sure it only runs once. If you want more information about Specops Deploy I have talked about it in this post. http://www.edugeek.net/forums/o-s-deployment/53494-suggestions-new-deployment-software.html Thanks Edd
  14. Hi Stuart, I have just replied to another post about software deployment. Please look at http://www.edugeek.net/forums/o-s-deployment/53494-suggestions-new-deployment-software.html Hope this helps Edd
  15. We are now using Specops OS Deploy to install Windows 7 and its going very well. I have been talking to a couple of people who would like a demo of Specops OS and Application deployment. I work at a school located in Swindon and wanted to see if anyone else would be interested in attending a session about using Specops Deploy to install Windows and Deploy applications. Edd
  16. As mentioned previously, check you have enabled Integrated Authentication. Configuration -> Networks -> Networks(tab) -> Internal -> right click -> properties -> Web Proxy(tab) ->Authentication - check integrated You cannot use transparent proxy(just setting a default gateway) if you want to use rules requiring authentication. You need to set a proxy server in your Web Browser. Check your web browser is set to use ISA as the proxy server and on the correct port number( ISA default 8080). Check you rule is configured in the correct direction. Your source should be you internal network and the destination should be the URL set of the address you want to ban if you are trying to block out going requests. If you are still having problems use the Logging tab as it will tell you what rule is denying the request and if your user is authenticated. Monitoring -> Logging (tab) Hope this helps, Edd
  17. You should have a look at Specops Deploy It consists of two parts. Firstly, Application Deployment. This allows you to deploy both MSIs and legacy(exe/bat) files that can run silently. You can target your installation at 100s of different criteria, e.g. OUs/OS version/registry values/files/msi GUIDs... the list goes on! you can even target uses/groups/etc. The install of software can be scheduled into the future or done asap. The installation can occur during start-up or after the user has logged on! The system provides full feedback so you can see successful and failed installs(will details of the error the client experienced). The system uses a Client Side Extension to extend Microsoft's Group Policies so your software deployments are done within Group Policy's. Secondly, OS deployment. They have written a 'wapper' for WDS and MDT 2010 to make deployment much easier and quicker! You can right click on a computer or OU in AD and click reinstall and you then select the WDS image to install, it will then restart the computer and install the selected image. All very cool and make life so much easier. If you want to see it in action PM me. If you want the details of our account manager PM me and he should be able to sort out some discount. Edd
  18. I have received written confirmation from our account manager that this problem has now been fixed. They have produced an aftermarket 'fix' for customers who have the old affected units. So I have now placed my order... fingers crossed! Thanks Edd
  19. Dell has admitted it’s a design fault!! yay. After lots of "we will fix it", "we won’t fix it" finaly the product design has now been changed to resolve the problem. I am now waiting for another demo unit. Thank you to everyone to complained to Dell to get enough weight to get Dell to fix this. Thanks Edd
  20. craigw, Well I am glad it’s not just me! I have now got this escalated to manufacturing and am waiting for our account manager to update me, fingers crossed this will be fixed soon! Can you report this problem to Dell via your account manager to help build the case for this to be fixed? Thanks Edd
  21. Hi AngryTechnician Thanks for your reply. Our account manager has been absent for the last few weeks. Our stand in account manager insisted I had to go through the tech support. So I have been jumping through the hoops! Oh what fun Our account manager is now back so fingers crossed it will be resolved shortly. She has confirmed it should lock and is now looking into it being a manufacturing problem. If anyone has any of these units I would be interested if you have the same problem. Thanks Edd
  22. Thanks for your reply, however the design has changed from all the previous USFF chassis. The lock is now done on the stand not on the back of the cable cover. http://www.kingsdownschool.co.uk/edd/780/780.jpg Once locked, this catch should push a bar over the cable cover removal mechanism, but from what I can tell the measurements look all wrong. http://www.kingsdownschool.co.uk/edd/780/casefault.jpg Thanks Edd
  23. Please HELP! We have just received one of the Dell Optiplex 780 USFF computers and AIO stands. We are still able to remove the back cable cover after sliding the main lock on the back of the stand (just above the data socket) to the locked position. Dell tech support have sent me out another AIO stand and surprisingly it has the same problem! I believe it to be design/manufacturing problem but I am going round in circles with Dell! Does anyone else have one of these units they can check? Thanks, Edd
  24. Ok! it looks like I found the problem. It would appear the GPO that sets station permissions Windows 7 does not like! Once this policy has applied Windows 7 remains trashed, it would continue to not work even if the computer was removed from the domain. Anyway... I am now recreating the GPO to make it Windows 7 "friendly". Hopefully I will have the new network finished ready to put into priduction in the next couple of days. Thanks Edd
  25. I have a very strange problem! I have built a windows 2008 R2 domain I have added a Win 7 PC to it. When I log on to the PC with a domain admin account I can access “Devices and Printer”. When I logon using a normal domain user account, “Devices and Printer” does not load. I end up with a white box with the green progress bar, but no icons! I have tested as local user account and it does the same. I have no GPOs applying to the user. The only GPO that applies to the machine is the default domain policy. I have nothing configured in this GPO above the standard. I have read on the net and the only suggestion has been to enable the Bluetooth service. I have tried this but to no avail. This has also been tested on two different computers (one Dell and one HP). My Windows 7 PC is about to make a quick exit out the window! This is driving my up the wall, apart from this issue, I have a fully functional 2008R2/Windows 7 secured school domain If anyone can test this issue on their windows 7 network I would be interested to hear if you have the same issue. Thanks Edd Watton
×
×
  • Create New...