Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ranj

Members
  • Posts

    843
  • Joined

  • Last visited

Everything posted by ranj

  1. So what a journey I have had with my Netgear ReadyNAS duo v2 over the last year. I am now in a position to kick my ReadyNAS duo back after some disk corruption, NAS hanging issues. I am dubious however whether this is a good decision in the long run. So to summarise my NAS had been locking up, in the end, it was concluded that the disks that were in use were probably past their sell-by date and possibly contributing to the issues I had been seeing, the logs also seemed to prove this. So I have just recently purchased 2 x replacement Seagate iron wolf disks, currently, I have not used them in this NAS for 3 reasons 1) trying to get the data back from the X-RAID original disks was a mission but luckily managed to recover all the important data I needed and now have this on an external hard drive (see my previous posts as I detailed what I used, certainly a thumbs up from me!) and 2) my dilemma is do I purchase a new NAS replacement considering the current unit is over 8 years old and isn't being updated anymore? 3) My current requirement for a NAS has now changed, one of the main reasons is I want the ability to sync the data I currently have in the cloud (for argument sake we say this is in Microsoft OneDrive) but I want the ability to sync this to a local NAS drive and don't think there is a suitable solution for me to do this was the DuoV2 via the embedded tools or even using a 3rd party tool (where choice is rather limited). So if anyone has or has considered my situation based on their own requirements, what would you do? What would be the latest recommended NAS to choose from the current range based on this core requirement? My budget is undefined at the moment but I am thinking either a 2 bay NAS as a minimum but would probably prefer to have a bigger set (minimum 4) so I can also maximise the capacity of my disks, I probably start with the 2 2TB iron wolfs I have but then increase as I can afford to. Would I be able to start off with RAID1 and move to say to another RAID at a later date? I am currently looking at options, I probably consider another vendor if I did move (QNAP and Synology are the ones I like). I like QNAP as it seems that you got more for your buck and I prefer the interface however I do like the Synology and the ability to use hybrid RAID to grow disks with any size. Any tips, advice from fellow NAS users would be greatly appreciated. Thanks
  2. Hi Folks Just got a quick question. Just set up a multi-site direct access environment for a client (yes, DA over AOVPN), there’s a good reason for this! So the issue is getting DA clients to pick up SCCM policies and deployments when connected, there have been problems with this and I believe it’s around boundary setup. Does anyone have any experience with this? I am guessing I need to define a boundary for the DA subnet and issuing it an ipv6 prefix? Any help on this would be most appreciated. Thanks
  3. Thank you for your response, I thought a template was only needed if you wish to employ custom applications, third party, or line of business applications? Do I need to install and configure the UE-V template generator or can I just use the default mentioned in this article:https://www.systemcenterblog.co.uk/2017/11/windows-10-ue-v-deployment-guide.html Thanks
  4. Hi All I am trying to get UE-V working on Windows 10 1909 and Windows 2016 GPO. I have configured the storage location for the stored profile data and configured the GPOs. If I run get-UEVConfiguration and get-UEVstatus on client machines I can see that UEV is enabled and the settings defined in GPO are enabled on machines. I can see settings being written to the shared folder and this has the permissions as per Microsoft documentation. It's just that the two machines I am testing with, they dont seem to be getting the settings from the other machines, currently they both have independent settings configured and I dont know which settings are being configured to the network share. What am I doing wrong? Help! Thanks
  5. Thanks Steve Yes I suspect the issue is there as well. When I last checked I think they only have the 64bit image defined in DHCP options. I'll post back either way if this was the issue or not.
  6. Hi All I have ran into an issue with a customer last week and just wondering if anyone has any ideas. Customer currently deploys 64-bit Windows 10 using ConfigMgr through PXE boot configured through one of the DPs. All working well. The customer has a requirement to use 32-bit OS deployed also through PXE however I have noticed that when a UEFI 64-bit machine boots it only receives the x64 boot image. I have configured a specific task sequence to install 32-bit OS and have also specified the x86 boot image for that particular TS but my issue is when the machine reaches out to the PXE server it loading straight the x64 boot image. I have tried to adjust the settings on the client machine in UEFI such as turn off secure boot, choose legacy BIOS but have not been successful. Ideally, for the 32bit deployment the customer wants to leverage the task sequence steps that apply for 64-bit on the 32-bit machine such as BitLocker, would that be possible? Any advice on setup on the client machine and how to get the machine to boot the x86 boot image would be grateful. The machines in question are fairly recent Lenovo laptops which are configured with UEFI, 64-CPU architecture, secure boot and all the rest you expect of a newish laptop. Thanks
  7. Is this documented anywhere? pref from a Microsoft official source? I am struggling to find this....
  8. Hi All Wanted to bounce my thoughts with fellow members. I am about to embark on a mini project for a customer. It's for a small experiment and a new network and infrastructure environment will be created on-premises. Unfortunately for this piece of work cloud is not an option. So a Virtualisation environment, SAN, networking, firewalls will all be procured. I need to build MECM to help deploy a gold image to approx. 100 workstations, there are 2 variances of laptops I need to consider. As its an experiment it also not going to grow. I also need to ensure patching is configured for both clients and the small server estate being built. So my thoughts are to build a new VM with MECM 2006 with the SUP role for WSUS and then use the OSD techniques with TS to build the Windows 10 image using PXE. They will be building a SQL server to host a database for a third party application. My question is as its such a small environment should I put SQL on the same standalone server which will host the Primary site MECM server and SUP or it is doing a lot already and I should move the SQL stuff to a remote SQL rather than collocate? From reading the docs I understand some considerations need to be taken into account to host both WSUS and ConfigMgr DBs within SQL (difference instances?) but because the environment will be so small my personal preference would be to keep it on same box, easier for me to deploy and easier for the customer to manage. The security of the environment is high due to the nature of the customer. What would others recommend and what would your approach be? Many thanks
  9. To an Admin, Sorry I think have put this in the wrong forum, probably best if it can go under cloud services... Can this be done or do I need to repost and delete from here? Thanks
  10. You will require Intune and license which incorporate Intune. There are some policies within GPO to enable MDM registration, in your Azure AD connect you also need to sync your devices into the cloud to achieve Hybrid AD joined.
  11. Hi Folks Just wanted to get a consensus on what others do and would recommend in my scenario around updating Win32/MSI 3rd party apps in Intune. I am working with a customer who hasn't got the investment to make in a 3rd party patching solution such as patchmypc so I am working with the customer to look at the feasibility of updating apps manually using Intune which they already use. It's a standalone Intune without SCCM. The customer has a handful of apps which need updating and a lot of the apps are Line of business and a few from the major vendors such as Adobe, VLC, 7-zip etc. If the customer is already deploying the apps using MSI and wants to perform an update of an existing MSI already deployed, can the original MSI be updated just by going into the client app, and update the file from 'select file to update' and push the update out to clients. Would this process work? Would this conflict with the older app already installed? I guess its dependent on how the App is packaged and how the internal mechanism for updating works? Any help on this would be greatly appreciated. Thanks R
  12. Hi everyone Hoping someone has an answer to my question. My employer who is a Microsoft partner currently offers me a Visual Studio Enterprise Subscription – MPN account which gives me around $150 Azure credits every month. I also have my own Azure/0365 tenant which I use for testing purchases. I am doing a lot of work around my consulting work to do with Intune and Office 365, one of the areas I am looking at is Log Analytics and as some of you might be aware this needs to tie into a subscription. On my own Azure tenant (not MSDN) is there a way I can add in my MSDN Visual Studio Enterprise Subscription – MPN account as I would like to use the credits within there to create a log analytics workspace as I still have plenty of credits remaining every month as I only use it to store one Azure VM which is used with Hyper-V to create a nested VMs environment. I have tried to add a subscription however I dont see any option to add my company MSDN account. Is this possible? Has anyone tried this, if so how did you do it? Thank you R
  13. Thank you That's fine we do have a drain close by for the vent. I Thought there were options for a flue to be on a roof? I dont have a hot water tank. Just a combi setup.
  14. Hi fellow edugeekers Hoping someone can advise? I currently have an Ariston combi boiler which isnt working fully, having already spent a considerable amount of money trying to get it repaired it hasnt worked so am looking for a new combi boiler to be fitted when the weather gets a bit better. The current issues are lack of hot water, pressure build up on boiler and at the moment i am having to drain the system down periodically. In the last 6 months a replacement expression vessel has been installed as well as a replacement pressure relief valve. These two parts havent fixed the problem. The heating is working ok. The boiler has been on the premises over 15 years. The last person i had in said initially he didnt feel we needed a new boiler however having replaced a part which hasnt solved the problem he now thinks its not worth spending more money on it So at the moment my thinking is a new boiler. With a young family as well and when the Boiler last went down it was a very difficult period. As it does it went down at the worst possible time with the weather taking a turn for the worst. I am also looking to move the new boiler into the Garage, the gas feed into the house is very close to where the new boiler location as well as the current boiler location which is in the kitchen isnt too far from the garage so there shouldnt be a huge amount of work to redirect the pipework. There is a flat roof on the garage which should be suitable for the flue. The rationalle in moving is in the future we planning on doing an extension in the kitchen, in the current location it would need to be moved. As its going in the garage do i need to consider other factors? It does get cold in there. i would like insultation on the pipework to prevent any freezing. We also currently dont have a magna clean solution on current but would like this installed as part of any works. Is this essential? There are in total 10 radiators. All of the smaller kind but are double radiators. Majority are pretty old. Would say certainly over 25 years old but all are working fine. As part of the work's i been advised to flush of the existing system before new boiler is installed. Is this done anyway? In terms of boiler manufacturers i wish to stick with one of the more highly rated ones such as valliant or worcester bosch, both of these brands are constantly receiving high praise having spoken to many people and reading many articles and forums and decided i just going to take the hit and hopefully it pays off, also installing a suitable boiler to handle the pressure and demands. We plan to in the future install a downstairs toilet and basin as well as a shower which will be ran of the combi. Finally i am looking to replace the existing thermostat with a more inteligent wireless one which i can control from a mobile device. Does anyone advise on anything else i should consider when looking for a replacement, your thoughts are appreciated... Many thanks
  15. many thanks all. I agree with most of you. Sell existing one and just get myself a new one would be the safest bet.
  16. Hi All Just had a question on my personal home PC setup. I have a rather large custom built PC using an Antec case and space is becoming a bit of a premium in my house with the recent purchase of a large monitor. Rather than sell it I would like to use it but need to condense it down to a smaller case ideally Intel Nuc size. I am aware that a lot of the components I wouldnt be able to move to such a tiny case but I would like to reuse my Intel Core i3 4160 3.60GHz Socket 1150 processor as well as the memory and SSD drive I have already purchased. Is there a way I could do this? Does anyone have any suggestions on cases I could look at? Any help would be most appreciated. Thanks
  17. Hi fellow edugeekers We about to embark on an Office 365 rollout to the whole organisation and vastly improve our client estate. So I am looking for some suggestions on some challenges on how best we approach these. Apologises in advance for the technical list.... We have an existing tenant setup (****.onmicrosoft.com) in Azure but is based on our old organisation name. We want to create new tenant name to reflect the new organisation name. The name is yet to be decided. We have a few existing E1 (used) / E3 (not used and recently purchased) under existing tenant and want to understand once new tenant is created, how we would transfer licensing to new tenant. We also have EMS and dynamics 365 licenses setup in existing tenant. We prepared to keep these services in existing tenant and run them simultaneously if that will be the simpler approach. We currently use Azure AD Connect (formerly DirSync), this connects our on premise AD into Azure, it is setup with Filtering so only some OUs are sync to Azure. Our AD as it stands currently is setup with the old domain name. Due to incoming requirement for Office 365, our strategy is to create a new AD domain in the same Active Directory forest as we are also doing a Windows 10 deployment so we see this as the perfect opportunity to start with a new domain. It will be two way Domain trust so all resources in existing domain can be trusted in new domain and vice versa. It is our hope we can then create a second on premise Azure AD connect server using filtering to the new AD Domain and we’ll then move users/computers from the old to the new domain once we port users across to Windows 10. Looking at the Topology best practise guidance I believe this is supported as long as the user only appears in one tenant. Would there be a better way to set this up? Our preference is not to create a new AD forest and new domain as the administration and management of this would be far greater. We plan to use MFA on Office 365, however want to investigate the various avenue’s we can use as not all of our user base have a corporate phone so some will need to use personal phones for SMS or using an authenticator app. Does this need to be setup for all users or can it be switched off at the request of a user? On the back of this we want to investigate the possibility of users resetting their AD passwords through Office 365 so this task can be achieved anywhere on any device without the reliance of internal network. We currently have enabled password write back and password hash sync. We currently have an ADFS 3.0 setup with Web Application proxy and plan to use this to achieve SSO on the internal network for Office 365. We currently make use of the Application proxy feature in our existing tenant to make our internal SharePoint 2013 application available externally. Eventually we like to port over the configuration of this to the new tenant. Would this be possible? Going forward we probably want to make use of SharePoint online but are concerned about the considerations we need to take with regards to backup and recovery. We aware of the security abilities built into Office 365 such as classifications, DLP, data governance, threat management, E discovery. Can these tools be setup after deployment. Is there any requirement to set these up at the start? We currently use Intune and these are managed via EMS licenses in Office 365. The strategy is to move to using an alternative solution using Trend Micro mobile security solution and decommission Intune. Finally our plan is to do a phased approach to Office 365, starting off with One Drive and Share point Online and slowly introduce the new technologies as we become more familiar and iron out any deployment issues. As you can see I have lots of questions and having had a look and done some planning work I sort have an idea of what the options are but its always useful to get some other views on this hence my questions so appreciate any responses on all or some of the questions I have. Many Thanks
  18. Hi Fellow Techs I was wondering if I could get some support/advice from some SQL Guru's as I been having a problem with a legacy SQL server being backed up and have tried a number of steps however I not been able to get this issue resolved. This legacy server unfortunately runs 2005 ver 9.0.5069. So I have setup some SQL maintenance backup plans to schedule a full backup of a Database every night. What I have found is sometimes the backup works as expected but most of the time its just runs and takes days for the job to finish. When looking at the error logs I am seeing codes related to the following as well as one message which consistently comes up. Error: 3041, Severity: 16, State: 1. Error: 3023, Severity: 16, State: 2. Source spid20s Message Backup and file manipulation operations (such as ALTER DATABASE ADD FILE) on a database must be serialized. Reissue the statement after the current backup or file manipulation operation is completed. I attach the full recent log with this. SQL_Log.txt What I have tried: Created a maintenance task to check database integrity and rebuild the index, update the statistics. This job runs successfully once a week. Rebooted the server and SQL related services. Tried an alternative 3rd party backup software Redgate SQL Backup and have the same problem with the 3 party tool. It saying the database must be serialized. What exactly does this mean? Any help on this would be appreciated. Thanks
  19. Hi fellow Edugeekers! I have got a question to understand how you address this problem that we have started to see since increasing our patching levels. I am sure someone out there must have run into a similar problem to what we are facing. So historically we used to patch our most critical servers manually which we found was taking a long time and now with zero day attacks and ransom aware becoming more common a decision was made to ensure WSUS patches are applied in a reasonable time to our whole server/client estate. We do this using WSUS and other third party patching tools to install and reboot servers early on a Monday morning (between 2am - 5am). Since we have introduced this we have run into some problems. The main problem is when servers are rebooted automatically as part of the patching, if the application relies on a database and/or the application was rebooted before the database it doesnt always make a successful connection as well as if after a reboot the services don't start up correctly the application will fail for the end user and we sometimes need to manually start these up even though the services should automatically start following a reboot. We use VMware and use vApps to tie applications, database servers and other related back end servers but this is only good if it's part of a planned maintenance with the vsphere farm, it doesnt help when the reboots happen as part of patching/windows/application updates. I know there is an option for VM monitoring within VMware but unsure if this would help us in this situation and whether that could cause more issues. We need to somehow find a solution to ensure that we can control the order of certain high critical services are started up after a patching reboot otherwise we will need to go back to manually patching which is something we don't really want to do. Does anyone else have this issue, if so do you have any ideas of how we could address this? So far our best option for us to easily identify if services are down is to put our NOC in the DMZ and play with firewall rules to ensure this server can detect services which are down in the internal network or invest in a cloud NOC offering and perform monitoring this way. Any suggestions would be most appreciated. Many Thanks
  20. Hi Admins Any VMware Power Cli experts out there? I have got a question regarding a PowerShell script which was developed by one of our previous VM admins who was a bit of script guru who managed to create a script which we use as part of disaster recovery process. Unfortunately, my knowledge with PowerShell scripts is limited and I could do with some help. In summary we use this script as part of our DR recovery process to clone our volumes from our NetApp array using the NetApp flexclone method to bring our VMs online within minutes however the performance of that array is poor so we want to utilize another array which has higher performing disks. We use this PowerShell script to effectively interrogate a particular VM folder and it will literally process any VMs located on a particular storage which starts with the name 'snap' and if it identifies this, it will move to another storage array in a sequential order. As part of one of the variables defined we use $VM_LOCATION so the script knows which folder to look in to interrogate but ideally I need to amend this slightly so that it can interrogate sub folders within that main folder. I attach the script in txt format. Is this possible? Is anyone able to help me? I have tried to look for a variable which would meet this need but I cant seem to find one. Any help on this would be most appreciated. Many Thanks vMotion_Script.txt
  21. Hi Folks We currently use a Juniper SA4500 to publish Active Sync and OWA externally. This product is now due to be retired and I wanted to make use of the Windows 2012 feature Web Application Proxy (WAP) which replaced TMG as a way to publish these types of applications. Has anyone done this using WAP? I am looking to create a new active sync URL which is published via the WAP so our mobile devices can connect via that route and slowly remove the dependency from the SA4500. Just for further info, our WAP is in our DMZ and NOT domain joined and we also have an ADFS server which is on the internal domain. Any advice on anyone who has tackled this already using WAP/ADFS would be great. Thanks
  22. Hi We have an Exchange 2010 environment where for some users we have additional email alias set, however we have found these no longer work after making changes to the email policies within Exchange. our environment was upgraded from 2003 and before that Exchange 2000. We are in the process of changing our email domain name due to a brand change so had to make some changes to our email address policies to add in the new domain name, we did have to amend the existing email domain policy and I think by changing that it may have caused our email alias to stop working. the reply email which is set as default is working as expected e.g. [email protected]. Looking through the settings I think if I edit the email address policy and enable 'email address local part', could this fix that as I have noticed it is not enabled. If I was to enable this setting would it work for the original default email address whilst also work for email aliases? Any help on this would be most appreciated. Thanks
  23. Hi All We use Exchange 2010 on premise in our environment and have come across an issue where the format of the date in an auto response from Exchange in reply to a recurring meeting has 2 different date formats: Individual meetings are fine. I have had a look at the dates on our Exchange Database and Exchange mailbox, hub transport and the date format is all set to UK. The client settings are also correct. Has anyone seen this odd issue? Thanks
  24. Hi All We have a new requirement and I have asked to find a solution to something we want to implement and wanted to know if AD LDS would be the right way to do this. We have a web server in our DMZ and a new IIS based application is being built which our customers will use to authenticate with to login to the system. The IIS server will be configured to support federation using Google, facebook etc. However our internal users who are joined to our Active Directory domain will also need access. As the server is in the DMZ and isn't connected to our domain we need someway for the IIS application to support AD authentication as well for these users to login otherwise we will need to create separate logins which will be an administrative nightmare. The web server is Windows Server 2008 R2 and our AD is 2008 R2 with forest and domain functional levels set to WIndows 2008 R2. We also use ADFS 2012 R2 to allow internal applications (connected to the domain) through ADFS and web application proxy for external based access. My question is what options are available to us to address this new requirement? any advice on this would be most appreciated. Thanks
  25. Ok if that is the case I would certainly look at this KB article which came out from VMware as it looks like based on what you have told me you might be affected with this issue. https://kb.vmware.com/selfservice/viewdocument.do?cmd=displayKC&docType=kc&externalId=2129176 I only know as we had a similar issue and once we made the change on the VM our performance problems instantly went away. You can make the change per VM or at a host level or to completely resolve it upgrade your version of vSphere 6 to Update 2. If you make the change at VM level there will be a brief outage (approx 5 seconds to the network card), if you do at host level you login to each host via the CLI and to make the change active you just vmotion the servers affected to another host and that will trigger the change. All required info is in the KB article. I have done both methods in my environment so give me a shout if you want to ask something.
×
×
  • Create New...