-
Posts
1,402 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ADMaster
-
One of the ages i created is tanted and another has pools of purifier May be useful for your thaum
-
This is the section I refer to that I had to remove my domain name from. See attached. However since I posted this it has gone out again. Some androids have the profile working and others don't. I've not been bothered to mess with it too much because these devices are mostly assigned to a single student. I have them just use their own credentials. Sorry I can't be of more help. Although we are talking of getting androids for the primary grades next year, so will be revisiting this then. Does the google play for education provide wifi configuration similar to the chromebooks?
-
@LiamH it will be good to see you back online, someone in my own time zone.
-
youtube schools subscription
ADMaster replied to Out_of_Sync's topic in Internet Related/Filtering/Firewall
Ah but when it worked it was great. I added their username to this list, then every video they wanted their students to see they just added to a playlist in their own account. It looks like I'll have to have them all come through me again though. -
youtube schools subscription
ADMaster replied to Out_of_Sync's topic in Internet Related/Filtering/Firewall
Yes I am a GAFE school as well. I am talking about adding them to the youtube for schools page to have full access, and approve videos for students. Here is a screen shot. -
youtube schools subscription
ADMaster replied to Out_of_Sync's topic in Internet Related/Filtering/Firewall
I have youtube for schools, but with the new forced linking to g+ I can't figure out how to add new staff as authorized users. The user is never found. @robjduk you say it works well, when is the last time you have added staff? Thanks, -
The server appears to be down.
-
It just kicked me off when I tried to open the chest. If your still online just stop the quarry for now, and I'll deal with it tomorrow. It won't allow me to sign back on. Thanks
-
It is still reporting offline for me.
-
Thanks for letting us know. I just got a java exception forcibly disconnected by the remote host.
-
Take a look at Admin Arsenal, PDQ inventory and PDQ deploy. Also I have heard good things about ninite pro but have not used it myself. cheers.
-
I solved the DHCP issue with this thread. https://social.technet.microsoft.com/Forums/windowsserver/en-US/8004c699-1a22-4f33-9fcd-7271bfcaf74e/dhcp-server-in-hyperv-forum?forum=winserverhyperv#page:2 I changed the subnet mask and then changed it back, strange.
-
Afternoon all, An update; After some more digging in the logs I found that my management point was reporting errors. I removed and re added the MP role to the server and that broke WDS, I reinstalled WDS again and all appears to be fine now, with imaging anyway. I’d still like to move the dhcp server to the 2012 r2 DC. I have gone into device manager and removed network adapters that are no longer present. I also tried setting the bindings with power shell but that failed too. Any suggestions? Thank you,
-
Good morning all, it has been a fun weekend. I lost a server over the weekend and got most of it restored to a VM. The second volume that contained WDS images didn’t restore. I don’t want to run WDS from a VM. I had plans to retire this server anyway, so the roles and services need migrated. The server that failed had AD DNS DHCP printing and WDS. I removed the WDS role and installed in on the SCCM server. Configured my ip helpers and all the clients can now pxe boot again. The boot images were still on the SCCM server so I added them to WDS and they boot, but do not connect to the management point. Prior to this change DHCP and WDS were on the same server, same subnet of course. Now WDS and DHCP are in different subnets this may be part of the problem, but should not be. I have the F8 option enabled on my boot images the winpe does get an IP address, but I have this line in the log Failed to get information for MP: http://SCCM.mydomain.example.com. 80004005. TSMBootstrap 12/15/2014 9:30:09 AM 852 (0x0354) I created a bootable iso and still get the 0x80004005 error while retrieving policy. This leads to me to think there is something more going on than just the WDS issue. From the win pe environment I can ping the sccm server by ip and name, so it is not dns. On another note, I would like to move my dhcp server to my 2012 r2 DC, I used the powershell cmd lets to export them import on the new server. However there are no bindings listed so it cannot hand out addresses. Thank you,
-
What are your server / client versions. introduced in win8 I think is the ability to activate via domain join. My Windows 7, Office 2010 are activated via KMS server. My windows 8.1 clients are activated via AD I'm not sure which method office 2013 uses. Windows and Office each require a client count of 25+ to activate via KMS. Servers require 5. Volume Activation Deployment Guide
-
Someone has done some thread necromancy. I as all the others, found it by searching for technical issues. I think it was Mimio, so that is education specific. Educational IT has its own unique challenges no matter the educational system.
-
I think the problem was with the cert used for peap. I now have Ruckus seamlessly failing over from ACS to NPS.
-
OK after some testing today it looks like ALL conditions must match. I tried adding in two mac addresses for the calling station ID and it failed where one worked and did what I wanted. I've replicated my entire ACS config to NPS and had clients authenticating to it today. My ruckus wireless has a place to configure a backup radius server. I configured it and shutdown the ACS. The NPS log was filled with event ID 18 invalid attribute. If I configure ruckus to authenticate against NPS directly it works but will not fail over to it. Any ideas on this? Also there are no students in today and very few staff so I'm not disrupting the entire network today.
-
Well, I use Cisco ACS so can't speak 100% for NPS. However I have set it up in a VM to check it out and this looks like the setting you need. Instead of using a user group just use a computer group. If you want to put all domain PC's in the same vlan to start just use the domain computers group. Otherwise you will need to create computer groups for the vlans you want them in. You can get a powershell script to create AD groups based on OU, this would give you computer groups to work with based on a structure you already have.
-
Hello all, I have been reading about the pros and cons of Cisco ACS vs Microsoft NPS, and have a question for those of you using NPS. Will NPS allow for end station filters based on mac address, not mac authentication bypass? A bit of background and my scenario. I currently have a Cisco ACS setup as my radius server, and it failed on Friday and I had to reload it from backup. This got me thinking what to replace it with when it completely dies and is unrecoverable. I have a number of policies for dynamic vlan assignment for staff / student etc. All of my windows PC’s authenticate as the machine and not the user, then put in a vlan with full network access. If a user authenticate they are placed in a guest vlan with limited access to the internal network, because it could be their own device for byod. Finally I have a few Macintosh computers that need to be in the trusted staff vlan but cannot authenticate as a domain machine. What I did to accomplish this was create an end station filter in ACS with the mac addresses of these machines. Then if the user is part of this group and has one of these mac addresses use this vlan. Cisco ACS calls them end station filters. I see a condition in NPS called calling station ID I have got mixed information on this from around the web. Also how are multiple conditions handled in NPS, ANDed ORed If calling station ID is the client MAC I want Group is Staff AND MAC is abc OR def etc Does NPS have a similar function or have I made this more complicated than it needs to be. If I get the time I will setup a test ssid and nps server. If I can replicate the functionality of ACS I’ll have a backup. Thank you,
-
Hello @mrbios I used to have only two ssids schoolname and guest. I have now added chrome for radius accounting to web filter. That's another story though. For devices such as the ipad I have created a generic AD account and push the credentials with meraki profile. You can use dynamic vlan assignment to have the staff / students / mobile devices all go to their own vlan with different settings. This will consolidate all the authenticating users into one ssid and then have a guest ssid. Here is an article on dynamic vlans with nps Wifi Nigel: Microsoft NPS as a RADIUS Server for WiFi Networks: Dynamic VLAN Assignment Cheers,
-
I have created a custom lock screen image for my windows 8.1 image, and built it into the image process. But all you need to do is replace the image file with your own. I mounted the install.wim and replaced it there, so all new builds have the custom screen. Here is what I have it my notes Will need to take ownership and give permissions for the following rename windows\web\screen\img100 to img100-1 copy in the replacement img100 Cheers
-
yeah edit was gone before I was a member, I'm just saying @Dos_Box will this be in the new platform once we move?
-
2 + hrs to download 15-20 min to install in a VM. I too have the default account and this is the standard not enterprise preview if that makes a difference. I also have to say I like the blue as the default background so much better than that bright yellow.
