etoipi
Members-
Posts
12 -
Joined
-
Last visited
Reputation
0 NeutralAbout etoipi

-
We're looking into upgrading our entire infrastructure over the next few years (we've got a three year plan to upgrade nearly every piece of hardware going), and I'm looking into licensing. Previously - we've licensed as we bought, but this time around we'd like to be a little bit quicker upgrading - we'll probably go for 7 / 2012R2 now, but want the flexibility to update Office / Windows more than the 2003 / XP we're on now. We're going to be scrapping everything over the next few years - starting this year with Servers. I've had a brief look on Microsofts Educational Website but just wanted some help with the licensing options. Ideally - we want some form of licensing solution that would cover us for our server infrastructure (we're possibly going virtualised), Client PCs, CALs, and Office. We'd like the ability to not really have to 'think' about licenses - just have a master image, that we can put onto a new computer when we get it and just know that we're covered. Same with Office. Our FTE count is low, as is our number of students / computers. Can anyone explain, slightly more simply than Microsofts website (which seems to like not actually linking to what it said it would!) what my options are and pros / cons of each? What has everyone found as the simplest to use? Cheers.
-
We have two servers running Windows Server 2003, one the standard version of Server 2003, and the second (our DC) Server 2003 R2 Standard. We're contemplating moving our server infrastructure to 2008 R2 / 2012 over the summer. Do I have to rebuy CALs for whichever server OS I change to, or can I just buy a license for the new server OS and we're done?
-
It's been decided that a variety of files, contained on a share on our Server 2003 R2 server should be set up for remote access, editing, and saving, where previously Server 2003 was just used to give a directory listing, where the files could be downloaded for local use. I'm not keen on using something like Dropbox, not least because at $15 / user / month it could work out quite expensive, and there would be a lot of junk left on all the teachers devices of rarely used documents! I'm slightly partial to using Google Docs, on the basis this can handle conflicts and two users editing the same file at the same time really rather well - and all the files remain in the cloud on the basis that you can't edit Google Docs not in a browser - with thinking being that anything on this share in MS Office is moved over to Google Docs, and then a shared folder is created in everyone's Google Drive (we're a Google Apps for Education user). This of course has the downside of time. What I was wandering is if there is something built into server that would allow for this two way sync whilst outside of the school network, not involving the use of FTP, and not requiring devices to be bound to Active Directory (although, of course, staff would use their Active Directory credentials to authenticate before viewing / uploading files). We would be open to a move toward Server 2008 R2 / Server 2012 if this would make life easier, as a) this is something on the cards and this could be the final tipping point and b) it would be a one of expense rather than Dropbox's monthly plan. How does anyone else achieve this? Am I missing an obvious solution?
-
Google Apps for Education is changing the way sign on works sometime in 2014 to make users include the domain, by forcing all users to use the 'new' Google accounts login process. This removes the nicely filled @Yourdomain.com in the username section when trying to login to a specific service. I don't like the idea of re-training all the users to login with their [email protected], especially when some applications around school will only let them login with their username, and not with @Yourdomain.com stuck on the end. In an effort to alleviate this, we're moving to a single sign on for all in-house web apps which interfaces with AD. We'd love to include this for Google Apps, too. I've been looking into some of the documentation available for Google Apps and was wandering if anyone has done / is doing anything similar? We've got a Server 2003 based domain. I've seen that AD FS can do SAML 2.0 stuff, but this only looks like later editions of AD FS which I'm not sure 03 will support. Ideally, if anyone has succeeded in doing this, we'd like to use our current in-house sign on process to just spit out the required SAML stuff to Google. Any tips, tricks, gotcha's for users who are doing something similar out there?
-
We're in the market for a new firewall and content filtering solution due to the fact that our content filtering license is coming up for renewal (and we're extremely unimpressed with the features) and the firewall being a complete pain in the behind to use. Currently both are done in the router - and this results in a absolutely hideous UI to manage the device, and doesn't fulfil our needs completely. What I'm contemplating doing is using a Linux box to do the firewall as I feel comfortable in a 'nix environment. I'm open to suggestions on both this, and the content filtering solution. From a content filtering / firewall point of view we'd like: Filtering by IP (ranges) Filtering by MAC address (for computers needing special policies applied) Ability to allow only recognised devices access to the outside world (by MAC address) Ability to log bandwidth use by device Ability to filter based on timeframes (boarders need a different policy in the evening, and at weekends) A decent reporting UI Ability to set our own HTML for a blocked page to gracefully help the users out Ability to blacklist / whitelist custom URLs, and place them in a specific category if needs must. We're not particularly bothered by things like AD integration (although at the right price would be nice). Ideally we're looking for something that's free to begin with to check it meets our needs, and ideally we'd like most of the cost to happen at the outset of this project. We wouldn't mind paying a one-off 'module' fee for some features we are after, nor a small fee every year but not a crazy renewal. So - as I'm probably not going to get a chance to use every combination of the firewall / filtering marketplace, are there any combinations that are good, or to be avoided? Any other things to lookout for, or products that look good but once used in anger have fallen below what was expected?
-
So I've done some investigation into the clients that exhibit this issue. They still have the three DNS servers as above (it will be changed in the very near future). It appears that: Running nslookup on the clients timeout, and do so even for things such as the DC Running nslookup once DNS server is set as static to only the DC also timeout Flush DNS results in same problems at the end. Registering the DNS (when static) doesn't help the timeouts. Pings to IPs do (even after a flush) lookup the domain, and get it right (even the VLE server). The errors ONLY occur on Wireless Clients (but only a subset thereof). Before I jump into the DC and change the DNS - are all of these errors likely to be because of the extra two DNS servers - or does this imply there's yet something else going on somewhere? I just don't want to start changing the DC without fully understanding what is currently happening on the clients!!
-
Cheers all. I shall have a look on Monday when I can sit down and have a play. We have been running ipconfig /flushdns After a flush, vle.schoolname.co.uk is resolved correctly (although not always persistent - mostly after a teacher takes a laptop home in the evening, and then have a DNS error in the morning - at the moment I'm just flushing the DNS when the problem arises).
-
They point to three, and search our naked domain. First is our internal DNS on the DC. The second two are the two DNS servers our ISP provides. I'm considering (in an unrelated event!) changing the second and third DNS to OpenDNS / Google Public DNS.
-
Under the schoolname.co.uk DNS zone (which is only used internally) I created a record to point vle.schoolname.co.uk to the IP of the server running the VLE stuff. Externally - the domain schoolname.co.uk has had an A record added pointing to an external IP of ours. The firewall then forwards HTTP traffic to this IP over port 80 to the server running VLE stuff. I believe that's what we're doing - we have DNS running internally, which is first for a lookup. I'm just worried that devices, such as laptops, could be caching the DNS for vle.schoolname.co.uk when devices are at home and as soon as they're on our network it uses the old, cached, route. That's the problem - they shouldn't be. As far as I'm concerned by adding an internal DNS record on our DC all internal clients connected to the network should be pointing to the internal IP, and not resolving externally at all. However, the internal clients are (incorrectly) resolving to the external IP, causing issues.
-
I'll have a go at doing that - as you say, should certainly help short term. The firewall was initially one of my thoughts. It doesn't do any DNS stuff switched on - it does however deal with some bizzare routings around the place (I've just inherited the system - and am getting out of the idea of this is what you do at school, this as what you do at home to just this is what you do).
-
We have a network running of a Windows server. The domain we use is in the format schoolname.co.uk. We also use this for our website - the DNS for this is handled externally by our web hosting provider. We've possibly been to clever for our own good - we've got a subdomain vle.schoolname.co.uk which, as far as our domain is concerned, has an A record pointing to one of our two external IPs for our broadband connection (i.e to get to in house servers). Our internal DNS on the Windows box also has a record for vle.schoolname.co.uk to tell all our internal clients the vle.schoolname.co.uk can use our Linux box running the VLE. All was fine when we began to this endeavour and clients began with clean DNS caches. However, now, internal clients are beginning to hit errors using vle.schoolname.co.uk. This is resolving to the external IP of the A record - and getting our internal clients absolutely nowhere. Is there anyway that I can get around this issue? We are not open to changing where our main website is hosted, nor really messing with the domain. We'd also ideally like the subdomain to be exactly the same for students and teachers when they are both in and out of school. BYOD is also in use - so devices will change where the domain needs to resolve itself.
