Jump to content

LytchettNM

Members
  • Posts

    139
  • Joined

  • Last visited

Everything posted by LytchettNM

  1. Lytchett Minster School is looking for highly motivated colleagues, who are passionate about IT and who will relish the prospect of making a positive difference in the lives of young people. This post represents an exciting opportunity for a highly competent, pro-active and customer-focused technician to share in the work of this thriving department and to play a key role in delivering high-quality IT support to students and staff. This is a full-time, permanent contract. Set in a semi-rural location with an 18th Century family Manor House at its heart, Lytchett has one of the most beautiful and inspirational learning environments in the county with stunning extensive grounds and a number of modern extensions. The school is massively over-subscribed and highly regarded in the community. Parents know that Lytchett looks after its students, providing them with outstanding pastoral care and high-quality teaching. The school has a successful, thriving sixth form with over 340 students. Lytchett has not joined a multi-academy trust, and has no intention of doing so, because it values its independence as a secondary school which serves its local community and produces outstanding outcomes for its students. To find out more about the school, please refer to our 'What is it like to work at Lytchett?' document. WE RESERVE THE RIGHT TO CLOSE THIS ADVERT EARLY AND/OR TO APPOINT PRIOR TO THE CLOSING DATE. WE WOULD THEREFORE ENCOURAGE YOUR EARLY APPLICATION. Safeguarding Statement Lytchett Minster School is committed to safeguarding and promoting the welfare of children and young people and expects all staff and volunteers to share this commitment. Any offer of employment will be subject to receipt of a satisfactory DBS Enhanced Disclosure and acceptable references. Lytchett Minster School will conduct online searches of shortlisted candidates. This will be part of a safeguarding check, and the search will purely be based on whether an individual is suitable to work with children. All aspects of social media and internet searches will be conducted. As care must be taken to avoid unconscious bias and any risk of discrimination, a person who will not be on the appointment panel will conduct the searches and will only share information if and when findings are relevant and of concern. This post is exempt from the Rehabilitation of Offenders Act (ROA) 1974. The amendments to the ROA 1974 (Exceptions Order 1975, (2013 and 2020)) provide that when applying for certain jobs and activities, certain spent convictions and cautions are ‘protected’, so they do not need to be disclosed to employers, and if they are disclosed, employers cannot take them into account. The MOJ’s guidance on the Rehabilitation of Offenders Act 1974 and the Exceptions Order 1975, provides information about which convictions must be declared during job applications and related exceptions and further information about filtering offences can be found in the DBS filtering guide. IT Systems Technician.pdf
  2. after chasing my tail for many months, I have finally got to the bottom of the issue and it was NOT an OS issues but it is now Resolved. It was our anti-virus product and contacting their support has resolved the problem plus they have report this to their backend as they do not believe it should have been an issue.
  3. Ok so an update and conclusion The issue is with the OS, come on Microsoft do some testing before blocking ports within the OS. As far as I understand Win 11 home now doesn’t allow RDP but it also seems the enterprise version also doesn’t? I went back to basics with a good old fashioned ping, with firewall disabled I couldn’t ping TCP port 3389 across our subnets but could within the same subnet what a massive waste of time🤬 And before someone says the issue is with our core network routing it works for Win 10. So in the end the resolution was to change the TCP port for Remote Desktop to not be 3389 and everything now works
  4. OK so we have migrated from windows 10 to windows 11 (bare metal install not in-place upgrade) 23H2 enterprise edition. Now we can’t remote to the client from another client on a different subnet and I’m pulling me hair out, we can Remote from client to client within the same subnet so GPO’s to enable Remote Desktop and firewall to allow are correct but log’s of the receiving firewall show deny! So what I have tried. The original GPO that worked with Win 10 allow RDP. Then tried a firewall rule to allow TCP 3389. Now I have tired firewall rule to allow all TCP ports from the subnet in the IT support office to all clients and still it won’t work! Can anyone suggest anything that I might not have thought of as I could do with some sleep 🤪 Thanks for any help.
  5. If I was you at this point I would remove the edge switch (I know it a lot of hassle) take that switch to the core and plug in with a patch cable. If it works then problem is with the fibre run if does not well something to do with switch config or hardware but you will have an answer and can then plan you next step. Saying that do you have spanning tree enabled if so just unplugging everything on the edge except the fibre might bring the link back up.
  6. Any radius Experts
  7. Any advise on radius which is being used for wireless authentication please, what I would like to do is control how many devices a user can connect?
  8. I have to say I’ve not taken a good look into at the capability’s of pfsence so assuming the software can provide all the protection you need just make sure the hardware is up to job.
  9. I think I would be a little concerned about the amount of protection a pfsense box can provide.
  10. In regards to routing I would not route you internal network via the ISP’s router as it’s connection you your core is likely to be 1GB at best, so get you core switches to do the main routing within the network as this is much more efficient.
  11. If you are going to change the core switch at some point than just to throw a spanner in the works have you considered merging you distribution and core switches into a core stack using the fibre you already have to create a ring and then most of not all your current edge switches can plug directly into your core. I would setup you spare switching and just have a play it will help you understand. There will undoubtedly be things that you did not foresee when making a major network topology change like this so just give yourself time to understand/ fix and problems. I would do this work of during the summer holiday and book in some maintain time so there’s no pressure from staff that want to come in and use the system.
  12. OK so if you already have VoIP then have you got QOS setup or are you relying on the bandwidth of the core link having enough overhead? There are many way to segregate off subnet’s but I went with simple, it can make is easier to trouble shot if there is a problem, I use the 10.0.x.x range so for example VLAN 10’s subnet is 10.0.10.x, VLAN 11- 10.0.11.x etc. I do not have distribution switches all of my edge switch have 2 x links (LACP) back to our core stack with 1 link to the first core switch and the other to second core switch this removing single point of failure as much as is possible and increases overall bandwidth availability. All servers connect to the core switch with and 2 x link same as the edge switching. For IP ranges I use x.x.x.x/24 for 90% of subnets with a DHCP scope offering the first 200 address which leave the rest of the subnet for anything that might need to be assigned with a reservation. If I need more address in an area i look to break up that area via something like the building, department or cabinet. Wi-Fi we have 4 SSID’s all assigned to their own subnet with a x.x.x.x/23 subnet for each. If I was you take a little time to make sure you are not going to overload a physical link to a single switch as the first things that will play up with be VoIP. 10 GB links we have around 75% of the edge switch’s connecting to the core with 2 x 10GB LACP link but this is well over the top bandwidth wise but I had a blinding deal when we were purchasing the edge switching and got the 10GB version of the edge switch for the same price of the 1GB so why not [emoji41] this did then highlight that some of our fibre runs were just over 350 meters which is why the whole campus has not been able to take advantage of the faster speeds yet. We also have central printing so all MFD’s connect to their own subnet which has an ACL so users can not print directly to the printing device which would allow them bypass our Papercut solution. Have you used VLAN’s yourself at all? Are you going to be doing all this yourself? Make sure you let staff know that the system will not be available for something like a whole week so you have time to resolve any problems that might come up. If you have some spare switching set it up and test so you know what to expect when it come to D-day.
  13. Hi Ollie First thing I would ask is do you need VLAN’s (how many IP addressable devices not just computers do you have?) are your edge switches connected directly to your core switch or do you have distribution switches in place? How do you want to deal with things like printing, VoIP, CCTV etc will these be connected to their own subnet? Will devices from different subnet be connecting via the same edge switch? I see you are using a 24 port switch as you core switch so I little bit more of an overview as to where everything plug in would help understand your topology and where any bottle necks might be as you don’t want to be relaying on the buffering within you core switch. With regards to guest Wi-Fi do you host anything like say a website that a guests would need to access if not then I would go very simple ask you ISP to provide a secondary network without a route to your primary network and connect your guests to that, your ISP might even provide DHCP within that network so you don’t have to.
  14. You could deploy from a laptop with enough resources for small numbers of computers but it would not perform as well as a server. You can recognise computers via MAC etc and then both WDS or WDS/MDT can deploy the operating system, but MDT is a lot more flexible than WDS on its own. I’ve used many deployment Methods but find IMPO using WDS/MDT and then spending a little time to understand what it can do, will in the long run save a lot of time. I now deploy over 800 machines (in around 2 days) every year and now that MDT is set up I believe it was worth the time spent.
  15. If you have servers on each site then I would setup WDT/MDT this will allow you to deploy windows without USB sticks via network, and if you add an SQL database to the MDT side you can set the names of the computers automagically. Then moving forward all you need to do is add the new ISO image for the version of Windows you want to install then next time, or create a custom wim and then deploy that which could already have any software that’s required for that school.
  16. Locations for us to.
  17. I went for a simple approach for our large network, all subnets are /24 and are in their own VLAN’s, the gateway for each subnet is x.x.x.254 and the first 200 IP’s are issued by DHCP. Things like servers, networking switches, printers, cctv, bms, etc have their own VLAN’s and are statically assign. A simple approach also allow for the design to grow as the network does, I would not remove the extra subnets you have.
  18. We are also a secondary with 1460 ish students + 200 ish staff but around 900+ computers and all the normal IP stuff printers, access points, cctv etc. We replaced our server side around 4 years ago and replaced our edge switches the last summer. As I’m sure you are aware every network / school is different so offering advise is limited. Please feel free to correct me if I’m a little off track with any assumption I’ve made. Assuming you have a flat network I would 100% recommend using VLANs and subnetting your school which will allow for access control and reduce broadcast traffic which will slow your network performance down, increasing the networks speed will not massively improve performance unless the IP space has an efficiently design. My background was in networking before becoming NM so I would recommend 2 x layer 3 switches stacked for the core, and then each edge switch connected directly back to the core switches with 2 GBICs so that’s 4 fibres per edge switch using a LAG, with the first GBIC of each edge switch connecting the first core switch and the second GBICs connection to the other. This is a very simple connection method but offers good resilience against a single device failure or human error like unplug the wrong cable. The way you end up going will very much depend if your going to do the work yourself as we did or use a third party. You need to have a plan before talking to suppliers as they will sell you the kit they get the best deals on, after all they need to make a profit to stay in business. Hope this helps. Darren
  19. It’s the port of the switch that is configured, so any port of a switch that supports the capability of VLAN traffic can be a trunk port. If you switch supports it you can also configure a LAG to bind 2 or more ports together so the the link is made up of more than 1 physical connection, the main advantage is that if 1 link fails the other link will take over without downtime plus when all are working you have higher bandwidth across that link.
  20. Yes i was thinking about server v1809 and was not aware of the Server 2019.
  21. We are still running a few servers on 2012r2 and slowly upgrading to 2016 i’ve not tried an in-place upgrade on a server if you do please let me know how it goes, not had any issue so far with clients on 1803/ 1809 and servers not. But are you aware that new version of server are core only?
  22. I have to same I love WDS/MDT I have ours setup so that each computer on the network is recognised by its MAC and this is used to name the computer, I then push the drivers to each computer based on its model so I’m not pushing all drivers to every computer. It has taken some time to get it right and I did each bit one at a time but it’s been worth it, I now build my images as a virtual machine with a pause in the task sequence so I can manually install any software I can deploy then capture that back to MDT ready to be deployed to each computers with zero touch, we re-image the whole site (around 1000 PC’s) every year.
  23. If I were you and assuming there’s a direct connection between the 2 networks, I would move all computer onto one domain and have a domain control at each site, I would probably subnet each site to reduce the broadcast. What type of connection do you have between the two networks?
  24. OK so if you don’t need / want internet access from this new network then make it very simple and static assign IP’s to these devices. If you go that way, the ports on the switch that you have plugged your AV kit into need to be reconfigured to not be on the default VLAN and just be untagged on the new VLAN you have created. If you think about it like the ports you assign to the new VLAN are like being plugged into a stand-alone switch. If you wanted to be able to access the internet and your main network then you would have to have the layer 3 switch setup to router traffic from the AV network to the main network, I’m not sure it worth the extra work to setup routing and ip helpers etc if you only need to control the desks from something like an iPad. Or of course you could just add the new AV kit to the main network and you all good to go.
×
×
  • Create New...