Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Geoff

Edu Supporters
  • Posts

    13,543
  • Joined

Everything posted by Geoff

  1. Lets answer each question in turn. It depends on your equipment. If all your infrastructure supports 802.1X then no. If you have a mix of infrastructure that understands 802.1X or can be controlled via SNMP then no. Otherwise yes. If it's an 802.1X supported switch it will change the port VLAN tagging over as soon as the RADIUS auth is accepted by packetfence. If it's a SNMP switch it will be told to change its port VLAN tagging when packetfence writes out the config change via SNMP. This only matters in an 'inline' configuration. Which you only have to use if you have 'dumb' switches/APs. You basically put packetfence between your 'secure' network and everything else and route all traffic through it. It acts much like a firewall does on your Internet gateway but isolates clients by refusing them a DHCP lease/ARP poisioning/iptables rules. Indeed, in this case packetfence will control client access via the switch ports using 802.1X and/or SNMP commands. Indeed clients cannot even get a DHCP lease on the authorised vlan until packetfence has let them on.
  2. Yes I have deployed it in the past. I do not posses a working system at the moment as it isn't required (I just murder people if they BYOD instead). Ask away though, I can probably help.
  3. FQDN as AD domain and using hairpin NAT rather than split DNS. No issues at all.
  4. http://images2.wikia.nocookie.net/__cb20070623021846/indianajones/images/2/29/Staff_of_Ra.jpg
  5. If you are going to have this done make sure the DSL line takes a different route (ideally to another phone exchange via separate ducting) otherwise it can't really be considered a resilient backup. If, for example, a JCB collapses the ducting enough to take out your fibre, your copper will be out of action as well.
  6. Fail2ban can help you with this. Apache - Fail2ban
  7. It only stops the people who don't have the technical expertise to avoid said filtering. How good are the kids at your school at trying to get round your filters? How well do you think an ISP level filter will hold up in comparison. One major factor I can think of is that at least in a school there is central control over the clients (BYOD aside). Also on an related note, I see the VPN providers are doing really well these days for some reason..
  8. If my kids electrocute themselves in my house is it the suppliers fault?
  9. Install 64bit after 32bit and you'll be fine.
  10. If you are on a 64bit machine you need both 32bit and 64bit java installed, with all the enviroment variables and file associations pointing to the 64bit install.
  11. Are you mixing up 32bit and 64bit? I know IE10 likes to say it's 64bit but you really need 32bit java installed too.
  12. Geoff

    ingress invite

    Stumbled across an iOS port. No idea how well it works. https://github.com/alex-alex/iOS-Ingress
  13. I have some South African friends, they insist on BBQing (or Braai'ing as they call it) properly. So the coke thing was one of the things I picked up from them.
  14. One aspect of 'fully blown' QoS is traffic shaping. i.e. you restrict the bandwidth available to some traffic types so you can guarantee a certain level of service to others. This is above and beyond want most standard switches are capable of doing, as they only offer the ability to prioritise traffic. However in a LAN environment this generally isn't a concern (as opposed to a WAN/Internet gateway where it's always a foremost concern) because upgrading the capacity of your core links is (relatively) cheap. So as other have said as you should be looking at having a 10Gbit core if you are insisting on 1Gbit to the desktop. If you baulk at the costs of this, you might want to look at seeing where you actually need 1Gbit to the desktop and prioritising upgrades there first.
  15. LOAD THE PIG CANNONS!!!
  16. XILO Pro. Fast Broadband Internet Access - 8Mb, 16Mb and 24Mb Line Speeds - Static IP and Multiple IP addresses - Unmetered and Unlimited Packages - Bonding - Low Latency - LLU - Migration - MLPPP - Reverse DNS : XILO
  17. I know Skype messes with volume levels.
  18. Indeed, you can even soak pork in cola overnight if you want. Makes it very tender.
  19. Baste in cola. It's awesome, try it.
  20. Reinventing the wheel aren't we? OCS Inventory NG | Home
  21. Geoff

    ingress invite

    I have 5 invites if there is still interest.
  22. Geoff

    Warcraft

    1 - 60 got massively streamlined for Cataclysm. 60 to 85 are untouched.
  23. Geoff

    Warcraft

    Yes there was a lot of complaining about the amount of dailies people felt they were forced to do in Pandaria at launch. The issue has been largely addressed now. Rep grinds are no longer gated behind one another and there's only one faction for the last few patches quest hubs (Operation Shield Wall in 5.1 and the Kirin Tor Offensive in 5.3) that's relevant. You can ignore the dailies now if you want and there are several ways to get the same level of rewards if you have an irrational hatred of them. Most notably there are other ways to rep up (bonus rep from dungeons and scenarios). Valor points are massively easier to farm up too.
  24. Geoff

    Warcraft

    90% of the file size is due to the art work. Every expansion demands higher and higher resolution graphics. The launcher is intelligent enough to let you download the minimum graphics to run the game, then load the higher resolution graphics in the background as you play. So you can get going before you have all 22Gb. Also, I'm an officer in a guild on EU Quel'thalas alliance side and have plenty of SoR and RoF invites. So if anyone feels tempted and needs a home let me know.
  25. The linux driver for your Intel wifi card uses a binary firmware blob to operate. The bug causing the issue is within this binary firmware. Only intel can fix this properly. You can mitigate the situation by disabling the power saving features. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=594511 I would also strongly suggest you avoid hardware that doesn't have open specs where ever possible in future.
×
×
  • Create New...