ssiruuk2
Members-
Posts
271 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ssiruuk2
-
Matt, yes I am serious. I don't blame you if you can't be bothered to read this respone, its alot longer than I anticipated.. I'm not sure why your mentioning Outlook but in the real world teachers do walk away from machines without locking them. Its as simple as that. The whole "admin" machine thing doesn't stack up anymore I'm afraid. A teacher wants / needs to access the MIS where ever they log in; be it in their office, classroom or from home. Capitas current offering to protect your database easily when you have a lot of users is a joke. Of course you can say its a training issue but so is turning off the projector, lights and locking the door at the end of the day; a minority will still do it from time to time. It only takes one incident for this to really blow up in your face. I'll try and explain why we have issues with the software as it stands.. We have nearly 90 classrooms each with a teacher desktop at the front of the room, (lots of machine with Sims installed in areas easily accessible to students,though only staff can log into these computers) registration is taken from these machines with Sims, every lesson, every day. Teachers do get distracted, maybe they walk off down the corridor for 5 mins to collect print outs or whatever and don't/forget to lock it.. little Johnny walks up and fills his boots, modifies his record, deletes his negative behaviour marks etc - you name it. Can IT trace whats been done to the databse easily? No. Can IT force users to all change SQL`passwords if we feel a staff password has become common knowledge? No. Would AD trusted logs help us here? No. Could the above happen at your school? If not then please explain how you prevent it. Idle timeouts / auto locking fails in the classroom as many teachers want to display static content on whiteboards for very long periods of time..they dont want the machine locking half way through a lesson.. your left setting an idle timer so long that it renders it pointless. What is this "other good stuff" that I am clearly in the dark about? BTW, I have found out from Capita direct about System Manager 7 which is due for release next year. You'll be pleased to know that not one of the features I mention being useful are included nor are they on the roadmap at the moment. However, not all is lost. It will run directly in the Sims window and have a nice pretty colour scheme looking at the beta screen shots so thats good news for all! I am pointing out fairly obvious security issues that IT staff face in schools using their product. If they don't concern your school then I struggle to see how. Why must we still reset each SQL user manually in System Manager? why can't we force the login box to check the user actually knows the AD credentials for the account currently logged in when launching the software? Why is there no audit trail? (that alone is ridiculous - Serco Facility had this functionality in 1999) If you honestly believe your teachers NEVER act like the above in your school then fair play you must have some great people there.. or your deluded
-
AD Integration (as it stands) is far worse in my opinion than SQL logins. Teacher walks away and leaves a machine logged in .. student walks up .. double click on the Sims icon and he/she can fill their boots. Not good! I want to be able to either bulk reset SQL logins or prompt for the AD integrated login.. someone please prove me wrong but I dont think its posible at the moment.
-
An MIS where the "system manager" can bulk reset all users passwords in one go would be a good start... also force unique & high strength passwords. How about having an audit trail of all data changes to the database.. yes other MIS systems do manage this perfectly well.
-
If your using ESX/i then another recommendation for Veeam.
-
Setting up Cisco 1130 AG Wireless Access Points
ssiruuk2 replied to mac_shinobi's topic in Wireless Networks
We use these APs at work, do you still need help with this? PM me if you do and ill guide you through it. When you say mater and client are you talking about wds? -
Sorry for digging up an old thread, but just wanted to say a huge thanks to Terrorvis for uploading that NDIS driver. I have 60 new machines stacked up with this Atheros chipset that I couldn't Ghostcast until I saw this thread. Have spent hours scouring various sites trying to find one that would work.. Thanks again - really has got me out of a hole!
-
WiFi analyser is a free tool for Android smartphones that you can download from the market.. pretty useful if you have a phone of this type and can't get a laptop for some basic tests. Shows signal strength, channel, residential networks etc
-
Does anyone know if the Garageband 3 Jam packs work in the new version of Garageband (09?). I've tried googling but can't seem to find this anywhere Thanks
-
I just realised you are using a Small Business / Linksys AP rather than Cisco Aironet / IOS type. I was referring to the later in my post above thats all I have ever worked with; so what I was saying about the SSID screen and auth type doesn't quite apply
-
I have only ever setup Cisco APs with Windows Radius on Server 2003.. but ill try and give you a few pointers. I set it up using Protected EAP with IAS using a self signed certificate that you can install on clients manually or by gpo - google Microsoft PEAP with passwords for an integration guide, be aware its for 2003 though, but the pricinciples still all apply.. You will need to use EAP on your SSID setup screen in the Cisco web gui and select the previously configured Radius server to authenicate for EAP just below that (this is from memory cant you tell) On your NPS server you need to create a connection policy aswell as specifiy your radius client (you may have done this but you didn't mention it) for your AP(s) and select the appropirate authentication method (EAP/MsCHAPv2) to match your wireless setup - There are various ways to do this to be honest Im just saying how I set ours up
-
Sysaid do a free version of their helpdesk software.. you won't get ldap / email integration or any of the other bells and whistles but it is very good and worth looking at.
-
Even if you could put such a monitoring system in place it would prove a nightmare to try and nail down exactly when a specific change was made, and thats assuming you have a system recording screen activity for all staff at all times!?! With the advent of SLG / web based write access to Sims for teaching staff (theres absolutely no way are we giving that access to staff) I can see the need for an audit trail on the server of some kind being even more important! Sort it out Capita.
-
This is one of the many gripes I had with Sims when we moved from Facility / Serco years ago.. no audit trail. How Capita don't consider this a priority or a massive security problem I don't know, it cannot be anything from a technical standpoint surely as Serco have managed it just fine with their MIS running on SQL and that was nearly ten years ago when we were running it. I had to prove something simliar to the issue raised in this thread and in the end I restored a copy of the entire server to a VM and manually checked the data that we suspected had been tampered with.
-
I got mine for £3,500 (was a cancelled order) for the array and 5 300gb 15k SAS disks.
-
Just thought Id chip in as you mentioned the Dell Md3000i. We have virtualised about 20 machines onto our MD3000i across two disc groups one being made up of 15k SAS in Raid 10 and the other being large SATA discs in Raid 5. Im also using R710s using Vmware ESXi (licensed). Performance has been good considering it is an entry level SAN. Im running domain controllers, exchange, SQL / Sims, our VLE and a bunch of other servers for things like print services and some terminal servers from it.. Using Veeam for backup, have also heard good things about vranger but never used it. I would definately give the MD3000i the thumbs up if you are considering it Out of interest what did you get quoted for it with those discs?
-
Cant help with specific HP Procurve vlan config as I use Cisco switches, but have vlan'd our network so will let you how I have done it as Im sure the HP kit supports the same features. I created the vlans on the core switch by first making it a vtp server (vlan trunking protocol) and made all edge switches on the network vtp clients so they automatically learn of vlans from the core. Created a switched virtual interfaces (SVIs) with appropriate ip address for each vlan / subnet created on the core and enabled ip routing on that switch also. Tip - On Cisco kit you must use the "ip helper-address x.x.x.x" command for each vlan interface to point to your dhcp server- Im sure HP will have something similar. Next step was to ensure the servers and infrasturcture devices had appropriate gateway for the new subnets how to reach them; you might get away with just a default gateway on your network but I modified the server route tables manually due to the layout (in command prompt - route add -p x.x.x.x mask x.x.x.x x.x.x.x) so all subnets were reachable. Create new DHCP scopes on your DHCP server for each subnet / vlan with appropriate scope options with default gateway set to the SVI for that vlan. Finally, change the vlan config of the access ports on the edge switches for whatever vlan you want them to be in. We have vlans for each IT room, admin, printers, standard wireless users, guest wireless, servers, access points, switches etc. Hope thats useful?
-
Similar to above but we setup an ftp site in IIS and using NTFS permissions students can drag and drop work to a drop box for staff through Windows Explorer. Works a treat
-
WhatsUpGold does everything that you requested. SolarWinds Orion (v good but expensive) and Ip monitor (web based only, no sql backend) are also great monitoring applications and would recommend them also.
-
We use Userlock - really like it.. ontop of restricting the kids to 1 login; a while back we strongly suspected that a staff account had been compromised and via userlock had it set to email me as soon as this member of staff signed in anywhere.. needless to say the student was caught red handed whilst sat there looking at "applying personal settings" waiting for the staff desktop to appear But yes I do wonder why this isn't something that is just integrated into windows server / AD.
-
Regarding the certificate for https filtering - you need to deploy this across your network via a GPO so it ia a trusted root authority on your clients - it takes 2 minutes to setup and then however long to deploy as the clients are rebooted. No more certificate errors on your clients.. The chaps at Smoothwall will let you setup a second box for your wireless guests so you can use an alternative authentication method for those users. I too had issues with the pop up box on some machines
-
Your not using 64bit version of IE are you by any chance? Just a thought..!
