Jump to content

chazzy2501

Members
  • Posts

    4,011
  • Joined

  • Last visited

Everything posted by chazzy2501

  1. @MatthewL Ha! the document showed me that I was still using the non-ssl port. (changed to 587) That probably has more to do with it!
  2. Yes the printers have been scanning to email for almost 2 years with O365 (staff really like the feature). The new hack for the sharp printers has you put brackets around your email address. Not sure what the angled brackets do or how long the hack will work.
  3. some of the commenters have ended up like me..
  4. We've been having issues scanning to email recently from our Sharp Multifunction Printers "network timeout errors". I just happened to find the answer on youtube of all places. It seems that Office 365 changed their logins to only accept the latest TLS1.2 connections. Something to keep in mind if your having email issues with devices that are not updated frequently. I've had to call support for a firmware update of our printers.
  5. yay! I have the image, I'm just gonna continue using this flawed version for my master image (even edge isn't installed, didn't realize it'd be so naked)
  6. This is what I use with my guest network (vlan separate everything) https://www.opendns.com/setupguide/#familyshield
  7. I'd uncheck the power saving of the intel graphics (esp. refresh rate changes) I'd also raise the priority of PowerPoint to realtime to see if that helps.
  8. the answer was a blocking rule with a defined scope. (I didn't consider the scope working with the blocking rule) I blocked the outbound range (for the mstsc.exe) 1.1.1.1 to 212.219.242.145 and 212.219.242.147 to 255.255.255.255 this worked a treat. this was unfortunately a machine rule not a user rule so I can't use pupil PCs to hop on to a server now. (before I had a user rule stopping mstsc.exe)
  9. Yes, my issue is the other end. How would I limit my clients (for example) to only connect to your gateway and no other rdp provider.?
  10. I don't have ADFS or SCCM so it looks like I'm bundling office 2016 with windows 2019 LTSC.
  11. I think the Office 2019 new install process is a way for Microsoft to Punish Admins for not installing office365. Of course this is true for all prior versions of office as they've changed their deployment method every time just to waste our time. The old office install needed a script deployed as you couldn't use a straight msi anymore.
  12. ok, We now have Yeovil College students attending our school. They're required to access their work remotely via RDP using a proper RDP gateway. I'm not a big fan of this idea and I actively block the RDP client from even running for pupils. As I understand it the RDP client can use SSL to connect as well as a dynamic port for RDP. How can I create a firewall rule that would allow the client to only connect to a single ip address? (incoming I could do as I'd know the port and the range to limit) What I need is a block all, except... can windows firewall do that? can I do it by DNS instead of ip? the gateway is "workspace.yeovil.ac.uk" is that all I'd need to unblock? not the final computer "studentdesktop.yeovil.ac.uk" cheers
  13. umm how does ltsc differ from ltsb? looking to do a win10 deploy soon.
  14. or something simple like this powershell script on TechNet. https://gallery.technet.microsoft.com/scriptcenter/PowerShell-Hardware-f99336f6
  15. @sonofsanta This is exactly what I ran into and the solution I also implemented. Works most of the time isn't good enough. My script is a little more basic.
  16. Touch screens means buying the more expensive screens that are usually glossy (fingerprints and strip lights), i5s (boost tech, etc.) are a good choice, removable batteries is going to be tricky, older probooks and elitebooks had easy to replace keyboards as they were made to be field maintained. maybe a laptop that can use a docking station?
  17. omg sometimes I forget that Ubiquity have some alarming blind spots when it comes to enterprise networks. The refusal to acknowledge the need to use proxies in almost every enterprise environment. Changes in the way the product fundamentally works without notice. (see this firmware issue) Which I can't resolve. The rebranding of their devices to hide shortcomings (like the disappearing L3 ability of the XG product ((which changed from a core switch to an edge switch)) The failure to deliver on zero handoff for the uap-ac access points and their eventual abandonment. Which then leads, not just to no further updates but also the inability to configure them! You get what you pay for I guess. buy cheap buy twice.
  18. This is why I'm sticking to 8.1 for another year, I'm now waiting for the 2019 LTSB version of Windows 10 and Office 2019. EDIT: after 2 weeks (2 fing weeks) of testing 1703 this was my list of continuing issues:
  19. This obviously follows what I said earlier but I think some kind of education for users of email is that (I say again) no such thing as encrypted email... Encryption in spite of email, via email, through email. All require a solution to the dreaded authentication problem and usually bespoke software. I've also found that our photocopiers (that email) can do ePDFs they prompt for a password and send which is really slick for physical documents. (maybe obvious to some but again no special software to email encrypted PDFs straight from a printer) Sorry I rant but feel strongly about trying to accommodate users based on misinformed buzz words that over simplify. Next thing I'll hear is that xyz have done it and its great or the new £1300 iPhone can do it why not us? sorry going off topic..
  20. Well, the first thing I tell people is that there is no such thing as encrypted emails. An unhelpful term misused to confuse normies. Usually they want a safe way to move encrypted documents over email (rather that the whole body of the email) I discussed this with SLT and agreed that they can encrypt office documents easily (using password protection) and attach them to emails as usual. This would require no special training, plugins and other software. Just to phone the contact and tell them the password.
  21. I normally just use a single screw, jam it in a tight space or use the double sided foam tape (3m branded or Sellotape) I one case I screwed through the side vent to the SSD.
  22. its a shame that only the 48port unify switches have the sfp+ for 10Gbit. (and the xg) Remember that VLANs should never be used for security as it's trivial for a packet smith to hop across. The unifi APs do have a guest mode for the APs which will limit the clients ability to use the LAN. (pretty much gateway only)
  23. Thinking on this!!! I had a similar problem during my initial install! I also have an undesirable extended star topology as well. Set the root switches (the XG switches) to plain STP. Place all other switches to RSTP. (give them 5 minutes to settle)
  24. Spanning tree should be enabled on every port, and if possible (rapid) RSTP should be set for clients or they likely will time out looking for dhcp. RSTP is the default for every switch (on my XGs I've put it in STP mode as no clients connect, only switches)
  25. Use the OLD GPO method instead: (Machine policy with user settings for printer, also enable loopback GPO processing.) This has been better for me than GPP which has always been 99% (i.e. not 100%)
×
×
  • Create New...