-
Posts
13,543 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Geoff
-
Lets answer each question in turn. It depends on your equipment. If all your infrastructure supports 802.1X then no. If you have a mix of infrastructure that understands 802.1X or can be controlled via SNMP then no. Otherwise yes. If it's an 802.1X supported switch it will change the port VLAN tagging over as soon as the RADIUS auth is accepted by packetfence. If it's a SNMP switch it will be told to change its port VLAN tagging when packetfence writes out the config change via SNMP. This only matters in an 'inline' configuration. Which you only have to use if you have 'dumb' switches/APs. You basically put packetfence between your 'secure' network and everything else and route all traffic through it. It acts much like a firewall does on your Internet gateway but isolates clients by refusing them a DHCP lease/ARP poisioning/iptables rules. Indeed, in this case packetfence will control client access via the switch ports using 802.1X and/or SNMP commands. Indeed clients cannot even get a DHCP lease on the authorised vlan until packetfence has let them on.
- 23 replies
-
- 1
-
-
- boyd
- packetfence
-
(and 1 more)
Tagged with:
-
Yes I have deployed it in the past. I do not posses a working system at the moment as it isn't required (I just murder people if they BYOD instead). Ask away though, I can probably help.
- 23 replies
-
- boyd
- packetfence
-
(and 1 more)
Tagged with:
-
Can I create an Active Directory domain with external DNS name?
Geoff replied to link470's topic in Windows Server 2012
FQDN as AD domain and using hairpin NAT rather than split DNS. No issues at all.- 16 replies
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
http://images2.wikia.nocookie.net/__cb20070623021846/indianajones/images/2/29/Staff_of_Ra.jpg
-
If you are going to have this done make sure the DSL line takes a different route (ideally to another phone exchange via separate ducting) otherwise it can't really be considered a resilient backup. If, for example, a JCB collapses the ducting enough to take out your fibre, your copper will be out of action as well.
-
Ubuntu 12.04 LTS , GeoIP, IPTables & UFW
Geoff replied to CapnPugwash's topic in Internet Related/Filtering/Firewall
Fail2ban can help you with this. Apache - Fail2ban -
It only stops the people who don't have the technical expertise to avoid said filtering. How good are the kids at your school at trying to get round your filters? How well do you think an ISP level filter will hold up in comparison. One major factor I can think of is that at least in a school there is central control over the clients (BYOD aside). Also on an related note, I see the VPN providers are doing really well these days for some reason..
-
If my kids electrocute themselves in my house is it the suppliers fault?
-
Java 7 Update 25 Problems in Internet Explorer 10 on Windows 7
Geoff replied to AngryTech's topic in Educational Software
Install 64bit after 32bit and you'll be fine. -
Java 7 Update 25 Problems in Internet Explorer 10 on Windows 7
Geoff replied to AngryTech's topic in Educational Software
If you are on a 64bit machine you need both 32bit and 64bit java installed, with all the enviroment variables and file associations pointing to the 64bit install. -
Java 7 Update 25 Problems in Internet Explorer 10 on Windows 7
Geoff replied to AngryTech's topic in Educational Software
Are you mixing up 32bit and 64bit? I know IE10 likes to say it's 64bit but you really need 32bit java installed too. -
Stumbled across an iOS port. No idea how well it works. https://github.com/alex-alex/iOS-Ingress
-
I have some South African friends, they insist on BBQing (or Braai'ing as they call it) properly. So the coke thing was one of the things I picked up from them.
-
One aspect of 'fully blown' QoS is traffic shaping. i.e. you restrict the bandwidth available to some traffic types so you can guarantee a certain level of service to others. This is above and beyond want most standard switches are capable of doing, as they only offer the ability to prioritise traffic. However in a LAN environment this generally isn't a concern (as opposed to a WAN/Internet gateway where it's always a foremost concern) because upgrading the capacity of your core links is (relatively) cheap. So as other have said as you should be looking at having a 10Gbit core if you are insisting on 1Gbit to the desktop. If you baulk at the costs of this, you might want to look at seeing where you actually need 1Gbit to the desktop and prioritising upgrades there first.
-
LOAD THE PIG CANNONS!!!
-
I know Skype messes with volume levels.
-
Indeed, you can even soak pork in cola overnight if you want. Makes it very tender.
-
Baste in cola. It's awesome, try it.
-
Reinventing the wheel aren't we? OCS Inventory NG | Home
-
I have 5 invites if there is still interest.
-
1 - 60 got massively streamlined for Cataclysm. 60 to 85 are untouched.
-
Yes there was a lot of complaining about the amount of dailies people felt they were forced to do in Pandaria at launch. The issue has been largely addressed now. Rep grinds are no longer gated behind one another and there's only one faction for the last few patches quest hubs (Operation Shield Wall in 5.1 and the Kirin Tor Offensive in 5.3) that's relevant. You can ignore the dailies now if you want and there are several ways to get the same level of rewards if you have an irrational hatred of them. Most notably there are other ways to rep up (bonus rep from dungeons and scenarios). Valor points are massively easier to farm up too.
-
90% of the file size is due to the art work. Every expansion demands higher and higher resolution graphics. The launcher is intelligent enough to let you download the minimum graphics to run the game, then load the higher resolution graphics in the background as you play. So you can get going before you have all 22Gb. Also, I'm an officer in a guild on EU Quel'thalas alliance side and have plenty of SoR and RoF invites. So if anyone feels tempted and needs a home let me know.
-
The linux driver for your Intel wifi card uses a binary firmware blob to operate. The bug causing the issue is within this binary firmware. Only intel can fix this properly. You can mitigate the situation by disabling the power saving features. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=594511 I would also strongly suggest you avoid hardware that doesn't have open specs where ever possible in future.
