Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

rob_f

Members
  • Posts

    240
  • Joined

  • Last visited

Everything posted by rob_f

  1. Yes, it's a "trick" you have to do when moving NG around on different hardware, due to the way that NG is setup using one NIC. We'll be modifying this behavior on an upcoming release to make things easier. If you move, say a VM, from one hardware spec to another (i.e. giving it a different virtual network card), or replace an existing network card with a new one, the best way to get it to "forget" the old cards is to login to the console and do: cd /settings/ethernet/nics ls look for settings- files that are 10 bytes in size and copy those other the larger files: cp settings-3 settings-2 cp settings-3 settings-1 so that all the settings- files are 10 bytes. then run "setup" from the console, go to networking and auto-detect cards. It'll then find the network card and you can set the network addressing from within setup. If in doubt, give support a call Thanks, Rob.
  2. Typically American, but might be something to warn the kiddies about, regardless of the youth detention cash-kickback element... http://www.nytimes.com/2009/02/13/us/13judge.html?_r=1&em
  3. rob_f

    SSH Problems

    Are you running SELinux? Type sestatus as root.
  4. rob_f

    SSH Problems

    Hmm looks good, how about: ls -al /etc/profile
  5. Yes, you're right (apart from the fact that I'm not Tom, but whilst he's on holiday I may as well be... ) however we've recently added a little ticky box on Services > Authentication > Settings > Advanced called "SAM Account Name" that should allow you to authenticate users that don't have the aforementioned username type. Check with support if you've any queries around this, as I haven't had chance to try it out myself. Having said that, make sure anyway that the user you are using to connect to AD on the auth settings page has both types of username.
  6. rob_f

    SSH Problems

    Heard about this occasionally on fedora, can you check the permissions of /etc - as root do: # ls -al / | grep etc You should see something like: drwxr-xr-x 73 root root 4096 2009-02-10 11:15 etc But if it's drwxr----- 73 root root 4096 2009-02-10 11:15 etc Then the perms have been screwed up
  7. Hey guys, sorry for the delay catching up to this. Best practice for handling AD groups with a smoothwall web filter is: - Create in AD separate groups for the separate policy groups you want in the SW, so an AD group Year7, Year8, Year9 etc. and put those in their own OU. - Set the group search root to be the OU above (ou=mygroups,dc=domain,dc=local for example) - Include the groups you want (Authentication > Include Groups) - Rename and map the groups to the smoothwall groups (Authentication > Groups) Handling of multiple group memberships isn't something that can be easily done, and it would make things too complicated to debug what user was getting which group anyway. Doing the above, and making sure each user is only in one group is the best way to do things. If you're trying to get NTLM Authentication rather than NTLM Identification working, and it's not, there are a couple of extra AD integration steps that need to be addressed. Basically, as NTLM Authentication checks the users' usernames and passwords with AD, the smoothwall itself needs to join the domain as a member server. Hence the user you specify on the System > Authentication > Settings page needs to be a domain admin, have a windows 2000 style user logon name ([email protected], top box of account tab) and password expiry turned off. Best to create a new user for the smoothwall rather than use Administrator or any other existing admin account. You also need to check that the smoothwall is using the AD DNS servers at the top of Networking > Interfaces and that AD DNS has a reverse lookup zone for the subnet in which the smoothwall and AD servers reside. Hope this is clear, still quite early in the day for this kind of thing Give me a shout if you need help, my number is below. Ta, Rob.
  8. Hey Macinator, not quite sure myself what this might be, but feel free to give support a call on 1 800 959 1261 (I gather you're in the US). Uninstalling and reinstalling the Guardian module on SG is somewhat strange, especially as it's a built-in module as standard, but if it worked for you..! Give them a call if you have any concerns or further questions. And thanks for the support kudos guys, I'll pass on the feedback Rob.
  9. Yes, it is unfortunate we have to let him have a holiday at some point Just a quick note from myself to PM/email me if you have something that needs my immediate attention, otherwise I'll try my best to watch the forums as often as I can. Other than that, support or your account managers on the usual number below will be delighted to help you Rob.
  10. Yeah, it's still the same user with the same GPOs and profile, they just happen to have admin rights on the local workstation. Just looked at the article I referenced and there might be a bit of an error. Rather than selecting the administrators group, enter builtin\administrators
  11. three posts at the same time with the same advice... great minds think alike eh!
  12. I'd consider instead making the users members of the local workstation administrators group rather than domain admins, if that's what you're doing. See Florian’s Blog How to use Restricted Groups? Part I for a quick howto on restricted groups. This way they have full (!) control of the local workstation, but won't be able to mess with active directory at all. I know the risks are low, but are never low enough to justify making standard users domain admins. If indeed that's what you're doing... i may have misread Ta, Rob.
  13. Was it csccmd you were using?
  14. Hi Simon, are the machines actually crashing or shutting down gracefully? If they are "proper" shutdowns, what happens if for instance you were to deny them shutdown rights in a GPO? That may give you a clue if it is a process running as the user or system that is initiating the shutdown. If you can catch the machine whilst its just started its mysterious shutdown, you may be able to glean information using pstools remotely such as pslist and psloggedon (to see if there's anything remotely interfering with it). Anyway, just a few thoughts.... although I have a lingering feeling of foul play going on here
  15. A HTTP 302 is a redirection, so it may be that the way in which your LEA does safesearch involves forcing the redirect, hence you will see it in your local logs. As a test now you can try disabling the SmoothWall safesearch, but if you can hold out I would recommend instead trying again tomorrow morning after our changes have been pushed through in tonight's blockies. Cheers, Rob.
  16. Chris, what were the steps taken to arrive at this? Was it simply going to the front page and typing in "blood sugar" for example? Is there anything else you have installed that may be trying to do safe search type things? safe=active doesn't look like us... is there perhaps an upstream proxy doing some meddling? We have a slight issue with safe search at the moment which will be fixed in tonight's blocklists. If you have only seen this issue today, I would see how it gets on tomorrow. Cheers, Rob.
  17. rob_f

    Slow menus

    If you've got a folder redirection on the start menu to a server, you'll always get some lag. As we weren't updating the start menu that often, there wasn't a need for it to be always checked on the server, so i wrote a script to do a sync of the menu on startup to local disk, then point the redirect at that. I found it did increase the startup script time, but that was resolved by putting a pointer file on the server with a version number in it. When you change the start menu on the server, increase the version. The script would then compare the local copy of the pointer and if the number is less than the server one, do a sync. Whilst doing these syncs you can also take the opportunity to use the script to do things like wallpapers - again faster to have them locally than refer to them on the server. I even made multiple resolution copies of the wallpapers and then had the script check the current screen res and download the relevant wallpaper to keep things looking nice Some food for thought hopefully, unfortunately I can't post the script as it's intellectual property of my previous employer. Boo.
  18. The proper way to do it would be to use JNI to interface with Windows Management Instrumentation (WMI). List currently running processes (Windows) - Real's Java How-to offers a way by capturing the stdout of tasklist.exe, a command-line variant of taskmgr. hth
  19. Probably not. 755 is: 7 readable / writable / executable by the Owner, 5 readable / executable by the Group, 5 readable / executable by Other web visitors. whereas 777 is: 7 readable / writable / executable by the Owner, 7 readable / writable / executable by the Group, 7 readable / writable / executable by Other web visitors. Been trying to find you a good explanation, maybe Perl Scripts Installation, FTP, File Permissions will help?
  20. MSSQL and MySQL will cohabit nicely. And you can quite happily have multiple MSSQL instances, which is fairly flawless unless you get an annoying bit of software which will *only* install to the default instance... of which I have come across a few. Grr.
  21. I thought timetables were part of Nova-T6? Which, if it is as it was 4 months ago, isn't part of the SQL database until you "commit" it. In which case a file-level backup of the timetable workstation and the fileserver would suffice. That is, of course, unless you are committing it to SQL.
  22. What is your LEA filtering product? How do you usually configure your browsers - proxy.pac, manual configuration, none: default gateway, etc.? It would seem rather odd for a filtering device to behave differently based on user agent. Do you have a firewall? And if so, do the safari requests exhibit noticeably different behavior in the logs to that of IE? Ta.
  23. Thanks ssiruuk2 & Edu_tech. karl - if you'd like to drop either myself or tom_newton a pm with your details, we can give you a call sometime if you fancy prices/a demo/bit of a chat Cheers, Rob.
  24. Do you have a trust relationship between the two domains? If so, what type is it?
  25. I would imagine that if the students own them (i.e. pay money for them) then they would expect to be able to install their own software. Hence why I have seen dual-boot in the past to allow this.
×
×
  • Create New...