-
Posts
139 -
Joined
-
Last visited
Reputation
166 ExcellentAbout LytchettNM

Personal Information
-
Occupation
Network Manager
-
Location
Christchurch
-
Lytchett Minster School is looking for highly motivated colleagues, who are passionate about IT and who will relish the prospect of making a positive difference in the lives of young people. This post represents an exciting opportunity for a highly competent, pro-active and customer-focused technician to share in the work of this thriving department and to play a key role in delivering high-quality IT support to students and staff. This is a full-time, permanent contract. Set in a semi-rural location with an 18th Century family Manor House at its heart, Lytchett has one of the most beautiful and inspirational learning environments in the county with stunning extensive grounds and a number of modern extensions. The school is massively over-subscribed and highly regarded in the community. Parents know that Lytchett looks after its students, providing them with outstanding pastoral care and high-quality teaching. The school has a successful, thriving sixth form with over 340 students. Lytchett has not joined a multi-academy trust, and has no intention of doing so, because it values its independence as a secondary school which serves its local community and produces outstanding outcomes for its students. To find out more about the school, please refer to our 'What is it like to work at Lytchett?' document. WE RESERVE THE RIGHT TO CLOSE THIS ADVERT EARLY AND/OR TO APPOINT PRIOR TO THE CLOSING DATE. WE WOULD THEREFORE ENCOURAGE YOUR EARLY APPLICATION. Safeguarding Statement Lytchett Minster School is committed to safeguarding and promoting the welfare of children and young people and expects all staff and volunteers to share this commitment. Any offer of employment will be subject to receipt of a satisfactory DBS Enhanced Disclosure and acceptable references. Lytchett Minster School will conduct online searches of shortlisted candidates. This will be part of a safeguarding check, and the search will purely be based on whether an individual is suitable to work with children. All aspects of social media and internet searches will be conducted. As care must be taken to avoid unconscious bias and any risk of discrimination, a person who will not be on the appointment panel will conduct the searches and will only share information if and when findings are relevant and of concern. This post is exempt from the Rehabilitation of Offenders Act (ROA) 1974. The amendments to the ROA 1974 (Exceptions Order 1975, (2013 and 2020)) provide that when applying for certain jobs and activities, certain spent convictions and cautions are ‘protected’, so they do not need to be disclosed to employers, and if they are disclosed, employers cannot take them into account. The MOJ’s guidance on the Rehabilitation of Offenders Act 1974 and the Exceptions Order 1975, provides information about which convictions must be declared during job applications and related exceptions and further information about filtering offences can be found in the DBS filtering guide. IT Systems Technician.pdf
-
[23h2] Remote Desktop not working across subnet
LytchettNM replied to LytchettNM's topic in Windows 11
after chasing my tail for many months, I have finally got to the bottom of the issue and it was NOT an OS issues but it is now Resolved. It was our anti-virus product and contacting their support has resolved the problem plus they have report this to their backend as they do not believe it should have been an issue. -
[23h2] Remote Desktop not working across subnet
LytchettNM replied to LytchettNM's topic in Windows 11
Ok so an update and conclusion The issue is with the OS, come on Microsoft do some testing before blocking ports within the OS. As far as I understand Win 11 home now doesn’t allow RDP but it also seems the enterprise version also doesn’t? I went back to basics with a good old fashioned ping, with firewall disabled I couldn’t ping TCP port 3389 across our subnets but could within the same subnet what a massive waste of time🤬 And before someone says the issue is with our core network routing it works for Win 10. So in the end the resolution was to change the TCP port for Remote Desktop to not be 3389 and everything now works -
OK so we have migrated from windows 10 to windows 11 (bare metal install not in-place upgrade) 23H2 enterprise edition. Now we can’t remote to the client from another client on a different subnet and I’m pulling me hair out, we can Remote from client to client within the same subnet so GPO’s to enable Remote Desktop and firewall to allow are correct but log’s of the receiving firewall show deny! So what I have tried. The original GPO that worked with Win 10 allow RDP. Then tried a firewall rule to allow TCP 3389. Now I have tired firewall rule to allow all TCP ports from the subnet in the IT support office to all clients and still it won’t work! Can anyone suggest anything that I might not have thought of as I could do with some sleep 🤪 Thanks for any help.
-
If I was you at this point I would remove the edge switch (I know it a lot of hassle) take that switch to the core and plug in with a patch cable. If it works then problem is with the fibre run if does not well something to do with switch config or hardware but you will have an answer and can then plan you next step. Saying that do you have spanning tree enabled if so just unplugging everything on the edge except the fibre might bring the link back up.
-
Any radius Experts
-
Any advise on radius which is being used for wireless authentication please, what I would like to do is control how many devices a user can connect?
-
I have to say I’ve not taken a good look into at the capability’s of pfsence so assuming the software can provide all the protection you need just make sure the hardware is up to job.
-
I think I would be a little concerned about the amount of protection a pfsense box can provide.
-
In regards to routing I would not route you internal network via the ISP’s router as it’s connection you your core is likely to be 1GB at best, so get you core switches to do the main routing within the network as this is much more efficient.
-
If you are going to change the core switch at some point than just to throw a spanner in the works have you considered merging you distribution and core switches into a core stack using the fibre you already have to create a ring and then most of not all your current edge switches can plug directly into your core. I would setup you spare switching and just have a play it will help you understand. There will undoubtedly be things that you did not foresee when making a major network topology change like this so just give yourself time to understand/ fix and problems. I would do this work of during the summer holiday and book in some maintain time so there’s no pressure from staff that want to come in and use the system.
-
OK so if you already have VoIP then have you got QOS setup or are you relying on the bandwidth of the core link having enough overhead? There are many way to segregate off subnet’s but I went with simple, it can make is easier to trouble shot if there is a problem, I use the 10.0.x.x range so for example VLAN 10’s subnet is 10.0.10.x, VLAN 11- 10.0.11.x etc. I do not have distribution switches all of my edge switch have 2 x links (LACP) back to our core stack with 1 link to the first core switch and the other to second core switch this removing single point of failure as much as is possible and increases overall bandwidth availability. All servers connect to the core switch with and 2 x link same as the edge switching. For IP ranges I use x.x.x.x/24 for 90% of subnets with a DHCP scope offering the first 200 address which leave the rest of the subnet for anything that might need to be assigned with a reservation. If I need more address in an area i look to break up that area via something like the building, department or cabinet. Wi-Fi we have 4 SSID’s all assigned to their own subnet with a x.x.x.x/23 subnet for each. If I was you take a little time to make sure you are not going to overload a physical link to a single switch as the first things that will play up with be VoIP. 10 GB links we have around 75% of the edge switch’s connecting to the core with 2 x 10GB LACP link but this is well over the top bandwidth wise but I had a blinding deal when we were purchasing the edge switching and got the 10GB version of the edge switch for the same price of the 1GB so why not [emoji41] this did then highlight that some of our fibre runs were just over 350 meters which is why the whole campus has not been able to take advantage of the faster speeds yet. We also have central printing so all MFD’s connect to their own subnet which has an ACL so users can not print directly to the printing device which would allow them bypass our Papercut solution. Have you used VLAN’s yourself at all? Are you going to be doing all this yourself? Make sure you let staff know that the system will not be available for something like a whole week so you have time to resolve any problems that might come up. If you have some spare switching set it up and test so you know what to expect when it come to D-day.
-
Hi Ollie First thing I would ask is do you need VLAN’s (how many IP addressable devices not just computers do you have?) are your edge switches connected directly to your core switch or do you have distribution switches in place? How do you want to deal with things like printing, VoIP, CCTV etc will these be connected to their own subnet? Will devices from different subnet be connecting via the same edge switch? I see you are using a 24 port switch as you core switch so I little bit more of an overview as to where everything plug in would help understand your topology and where any bottle necks might be as you don’t want to be relaying on the buffering within you core switch. With regards to guest Wi-Fi do you host anything like say a website that a guests would need to access if not then I would go very simple ask you ISP to provide a secondary network without a route to your primary network and connect your guests to that, your ISP might even provide DHCP within that network so you don’t have to.
-
You could deploy from a laptop with enough resources for small numbers of computers but it would not perform as well as a server. You can recognise computers via MAC etc and then both WDS or WDS/MDT can deploy the operating system, but MDT is a lot more flexible than WDS on its own. I’ve used many deployment Methods but find IMPO using WDS/MDT and then spending a little time to understand what it can do, will in the long run save a lot of time. I now deploy over 800 machines (in around 2 days) every year and now that MDT is set up I believe it was worth the time spent.
-
If you have servers on each site then I would setup WDT/MDT this will allow you to deploy windows without USB sticks via network, and if you add an SQL database to the MDT side you can set the names of the computers automagically. Then moving forward all you need to do is add the new ISO image for the version of Windows you want to install then next time, or create a custom wim and then deploy that which could already have any software that’s required for that school.
