-
Posts
314 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rrrrr
-
Need help on SWF file downloading from School Website.
rrrrr replied to bcnate's topic in General Chat
A quick easy way that spings to mind, that should work in theory Open notepad Paste save swf (Make sure you enter the path to the swf in the above. You said you know this) Save as a .html file Open in browser Right click on link and select save target as Done -
"WiFi Sense" in Windows 10 - share WPA keys with friends...
rrrrr replied to pete's topic in Windows 10
We use radius auth as well as dynamic pre shared keys. When a user registers a device using their AD username and password they are created a dynamic pre shared key. This key will only work on one device and has an expiry date. This way, the psk cannot be shared and avoids the need for maintaining mac address tables -
Can you give more detail on "setup wireless"? Do you mean deploying the ssid to the devices? Are you planning byod? Do you have multiple ssids and vlans? Staff & student How far are you on the setup?
-
No Management IP Address on Core and Edge Switches
rrrrr replied to maxrebo's topic in How do you do....it?
Yeah console to the switch, manually change ip then make sure you save the config! -
No Management IP Address on Core and Edge Switches
rrrrr replied to maxrebo's topic in How do you do....it?
Are the switches vlaned? If so Have they remembered the vlan config still? It sounds like they have lost their running config where it was not saved, and either reverted to a previous config or gone back to factory defaults. If you can get into your core switch, you can do a cdp neighbors command that will tell you the ip addresses of all the managed switches connected to it. If it is a fully managed switch. You will need to do as cybernerd said and connect by console cable and reassign the switches ip to the management vlan. If its a web managed switch, you can try connecting to 192.168.2.10 (set your computers ip manually to same range first then plugging in directly) or it will be a factory reset job. By default, most switches dont get an ip address by dhcp, you would need to set this if you wanted to use this -
[windows mobile based] Best Windows Phone Out
rrrrr replied to newpersn's topic in Mobile Devices & Tablets
They have 2 new flagships out due this october that will be running wm10. They are called the 940 & 940xl. I would wait until then If you cannot wait its either the 930 or if you can find one on ebay, the 1520 is a good phone. No carriers sell the 1520 any more though -
In hyper-v, even if you disable time synchronisation on the integration services, the vm dc update source will just change from host to bios (which is same thing) if you try and set it to another source it wont change from this. I havent tried vmware as we are a hyper-v environment, but in davits comment, vmware recommend not using a virtualised ntp server as it caused him issues
-
It depends on if your dc is virtual or not. If your dc is physical then it can be set to update from an external source (utm or uk.pool,ntp.org) and be the reliable source for all your network clients using the command davit mentioned, If your dc is virtual, you need to split this command as i mentioned in my previous post, as a virtual dc will only update from the host server, you cannot set it to any other source. It will just revert back
-
migrating users homedrives to new file server
rrrrr replied to jslate1980's topic in Windows Server 2012
Backup and restore is the best and safest method of moving to new file server. I dont think robocopy has any file verification built in to prevent possible corruption (i know copying by cmd doesnt) I just wait for my out of ours dpm backup to take place, then restore with permissions to new location. Then select all users in ad and change home path to \\newserver\students\%username%\ and this is all automatically filled in. I have now put all home directorys on a dfs share so all i need to do in future is add and remove a dfs location. No changing home drive locations -
I have just done this on my network I had an issue caused by our DC's being virtual. The issue was "DC Was trusted time source on network" > "Physical host server updated time from DC" > "physical host updated DC time through integration services" > Loop this loop was causing a few seconds to get lost in the process, causing our clocks to get further and further out of sync as time went on. Below is a quick diagram of my setup now
-
Wlreless scans and intrusions can be mitigated by client isolation and ACL's. All our BYOD users can connect to is the DNS/DHCP servers on ports 67 & 53 and our UTM/Webfilter for internet traffic. Also, through device registration, their device is linked to their username for accountability. We also do rate limiting to stop bandwidth hogging. If you run your wireless without any ACL's / Isolation it would behave the same as if they were to plug their personal laptop into the Ethernet socket in a room. They could perform the same scans and attacks and the only accountability you would have is a time/place and ip address which wont help you pin it on a user unless their are witnesses/CCTV. This is why we use port security in any unsupervised areas, limiting each port to 1 mac address
-
All staff are given a staff device (surface pro 3) which are on their own ssid. These are fully encrypted with vpn access. We then have a byod ssid for staff and a seperate one for students. The staff one is generally used just for mobile phone internet access and is setup as mentioned before. The student one is also restricted with acls, rate limiting and web filtering. This is used by students with their own laptops. I have also implemented port security on our switches to stop students plugging in their laptops to ethernet ports. I have setup workfolders in server 2012r2 for students to access their work on byod. We dont do vdi
-
We use the byod functionality in the ruckus wireless system to isolate any byod traffic using acls from the rest of network so its purely for internet and for rate limiting. If its a computer we also supply sophos av to the staff member so they are protected. This is included in our agreement
-
[windows tablet] Surface Alternatives
rrrrr replied to karldenton's topic in Mobile Devices & Tablets
We have rolled out surface pro 3's to all staff. Very nice and fast. Looked at many alternatives but none had the build quality. Got 1 non pro surface 3, still nice device but pros are alot better -
Came in this morning and users were reporting "Access Denied Authentication Failed" messages. All was fine when I went home on Friday. Been speaking to Sophos tech support but getting nowhere fast and feel like I'm telling them more than they are telling me! My understanding is that the authentication is a chain of 3. Client Computer sends Kerberos key for users login credentials > UTM checks these against AD > AD server My 1st checks were between UTM and server 1, Restart UTM 2, Re-join UTM to domain under single sign-on tab (successful) 3, Goto Authentication servers, select DC's and do an "Authenticate example user" test (successful) 4, check the user is being filtered correctly in web protection>policy help desk (all correct) 5, flush authentication cache 6, One thing I did notice was our webfiltering authentication mode is set to transparent (no username or password box prompt) but our default authentication was set to none. I have since changed this to Active Directory SSO but still no luck. can anyone confirm what this should be as I hadn't changed it and it was set to none? ~ My Next checks were between Computer and UTM 1, Check proxy settings. (All correct and the authentication error would not appear if computer could not contact UTM, it would be page cannot be displayed) 2, check UTM logs for the machine 2015:08:24-11:32:35 proxy01-2 httpproxy[6376]: id="0003" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="HEAD" srcip="192.168.3.7" dstip="" user="" ad_domain="" statuscode="407" cached="0" profile="REF_HttProContaManagLan3 (AD auth Computers)" filteraction=" ()" size="0" request="0xe5742000" url="http://kzufjwvz/" referer="" error="" authtime="130" dnstime="0" cattime="0" avscantime="0" fullreqtime="200" device="0" auth="2" ua="Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" exceptions="" The user and domain parts are blank so the UTM is not receiving these from the machine. 3, restarted machine, no luck 4, run klist purge, no luck any ideas?
-
This is true for internal traffic if your using a switch as your default gateway but static routes may need to be added to your webfilter for internet traffic to be routed to correct vlan
-
We also use cisco aironets in the tag/untag config i mentioned in previous post. We are slowly replacing with ruckus
-
-
So the staff wireless will be the same ip range and vlan as the main network as well as the management interface of your ap's, and the guest wireless will be on a different vlan/ip range? If so on the switch port connected to the ap, untag the staff vlan (this should pass through to the default ssid) and then tag the guest vlan and link it to the guest ssid.
-
Also, its a bad idea to have a guest access with no isolation. If the guest wireless is not isolated from the rest of the network (acls etc) and only given bare minimum access (internet only) it could be used to attack your network with very little accountability
-
If your switch is layer 3, yes. Do you have a wireless controller? What vlan will the AP's management IP be on? You will need to create 2 ssid's and assign then to the vlans On the switch you wound untag on the management vlan and tag the ssid vlans
-
A 255.255.248.0 subnet is very large. if all your devices are on one vlan of that size it will probably cause a lot of network noise. (arp requests etc) I would split your network up into separate vlans for a number of reasons. Reduce network noice and possible network slowdown Help protect against malicious attacks (can implement ACL's) Protect againt packet storms, only 1 vlan will be affected. Servers should be on their own vlan, a separate vlan for management, and a separate one for printers (as they create alot of network noise)
-
What do you guys think is a good way to move forward for a small technical team of 2? We may not have an issue for a few months but sometimes when doing major development these become a lot more common. Also, when one major issue happens it can have a knock on effect that is not always apparent. this can mean dialing in and out over a few days. From your feedback, most of you either have; 1, a big enough team, or other branches to assist 2, Do as I am currently doing 3, wait till Monday I don't think its fair or would be accepted in industry to have one guy available / on call 24/7 and only given the odd hours overtime when action is needed thanks
-
I don't have keys, I call one of the site management team. they all live very local to the school so never been an issue.
-
Sorry, I left out he went off sick, not holiday
