Jump to content

rrrrr

Members
  • Posts

    314
  • Joined

  • Last visited

Everything posted by rrrrr

  1. Sophos utm is worth a look. We was a smoothwall customer for 3yrs and changed to sophos utm. Sophos utm can do everything smoothwall can do and much more. Went through a company called pcs-systems.com
  2. That is about right if i remove the 2x appliances 1x installation from my old quote. Sophos also supported 10gbps and full SSD storage which at the time smoothwall didnt
  3. For 3 years thats cheep. We payed around £11k for 3yrs/1200 students. That included a master and failover box. We scrapped smoothwall 2 yrs ago for sophos utm. Sophos is a more feature rich and stable solution and a similar price.
  4. I had a similar issue. I think by putting in fqdn of the server resolved it. Try for testing, mapping the same printer 3 times to a room and see what the result is. Do one by ip address e.g \\192.168.1.50\printer Do one by share name e.g \\printserver\printer And one more by fqdn e.g \\printerserver.domain.com\printer See what format is most successful. This is what i did and since changing it to fqdn it resolved issue
  5. Tring to get WOL working across vlans. WOL works fine on same vlan Across vlans it is blocked All switches are HP There are no ACL's between the 2 vlans. Can ping and connect to target PC's (when switched on) Have enabled "ip directed-broadcast" on core switch Any ideas?
  6. Do you know what the old range is? So I can identify what needs to be modified
  7. Do show running-config. This will display the whole config including all vlans and acls. Make sure you hash out any passwords that may be stored in clear txt before sharing
  8. Can you post your running config highlighting vlan mentioned?
  9. Just thought it was another line of defence as this thread is now mainly how to defend against it moving forward. What utm do you use? Would have thought this should have stopped it using blacklisted ip's and ids. Did you have live protection enabled on sophos av?
  10. Did noones utm pick this up? The utm should detect malicious activity and block communication to blacklisted ip addresses? If the virus cannot communicate with the control server it cannot create an encryption key and wont encrypt files By the looks of it, it has the below home servers hard coded into it. By blocking communication to these should stop encryption taking place, if you was to be infected. Also alerting you of infected computer
  11. If the virus is running from the appdata folder, i take it screen rules would only work if this has been redirected to a server location and not on the local machine?
  12. Macro virus in word? A software restriction policy wouldn't stop this
  13. We cant do this as students do VB programming for ICT
  14. Any schools gone down the route of completely blocking zip files over email? our local council has in replacement of 7zip files. I'm thinking of doing the same
  15. Can you give me an example of the GPO and script used? Do you know what the route to infection was? zip file over email? hyperlink in email? etc
  16. Depends on the strength of your technicians and if they can technically fill in the gaps while you find your feet. Also would look at doing some networking cert to compliment mcse (e.g ccna)
  17. Ive got surface pro 3 win10 and no issues, firmware/driver up to date? There were wifi issues when the pro 3 was first released, firmware update resolved it
  18. Should be just a case of removing the replication then reinstating it to the new server. Replication is only one way so you haven't got to worry about the old secondary server. Just to check, you do separate backups too? Hyper-v replication is good for a failover server but not data recovery
  19. We have hp solid states in our servers, came with them already installed. Server solid states would be tested for 24/7 operation and prob have a higher read/write before failure. We use the ssds in raid 10 for server os and to host any database servers (sims, exchange, vle, etc) we also have a standard hdd array for file servers, Very fast, sims backups of a 11gb database take under 20secs. Always get questioned what is our server spec by our sims support provider as they cant believe the speed and think it has not done it properly [emoji108]
  20. just a basic wol.exe of net. Run batch file wol.exe "Mac Address"
  21. Looking into this further, it appears to be an across VLAN issue. WOL works ok on the same vlan, but it does not work sending the magic packet across vlans. Anyone got this working?
  22. We have hp switches and mitel phones. Tag phone vlan and untag pc vlan, set vlan on phone and it passes through untagged pc vlan
  23. I have just recently done this with ruckus myself. Vlans dont make it secure on their own, you need to apply acls to the vlan to secure them. Splitting your network up into different vlans makes your network more efficient by reducing network noise. Also it helps contain any packet storms created by loops and makes the network better to manage. Acls are then applied to the vlans to control inter vlan traffic. It is important to isolate your byod users as you have limited control over what state their device is in (could be virus ridden) and the intent of the user. Just a point. I originally setup acls on my ruckus controllers ssids but for some unknown reason android and ios could not get an ip address when applied. Even if i applied an empty, total allow acl. I then moved the acl to the core switch and all was resolved
  24. This is something I keep revisiting and never managed to get working, has anyone got WOL working with an HP 8200 elite USDT? I have updated BIOS to latest version v02.28 Disabled "s5 maximum power savings" in BIOS Looked for Advanced > Device Options > S5 Wake on LAN. But this does not exist As we are running windows 7, there is no fast boot options (can cause issue on windows 8) Checked properties of NIC in Device manager and enabled any WOL related items. Any ideas?
  25. This is how i setup mine If you dont have a virtual dc, just do all the commands from the host and dc sections on your dc and instead of pointing at utm, point at internet
×
×
  • Create New...