Archipelego1
Members-
Posts
83 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Archipelego1
-
I've had a quick look through the past few months posts but couldn't find anyone who'd posted this question recently. We're looking to replace our ageing onprem phone system and are looking at both new hardware but also cloud based solutions. I just wondered if people could provide supplier recommendations and information on what solution they purchased.
-
Smoothwall Firewall and HTTPS
Archipelego1 replied to Archipelego1's topic in Internet Related/Filtering/Firewall
Thanks, did you use any tools to understand what application or service is creating the traffic? Some of the IP's just go to AWS etc, so knowing what's creating the traffic can be difficult. -
Smoothwall Firewall and HTTPS
Archipelego1 replied to Archipelego1's topic in Internet Related/Filtering/Firewall
Thanks for the replies. In answer to the questions, the affected PC's do have the Smoothwall SSL certs on them and we have auth exceptions for the websites used by Sophos. We're just in the process of setting up a Caching server, which should solve the issue with PC's trying to connect to Sophos directly. However, I don't understand why traffic over port 443 is going through the firewall and not the proxy (transparent or fixed) -
Good afternoon, I'm noticing on a couple of PC's, Sophos (Cloud) isn't updating and started to investigate why. Before summer, our firewall rules were restructured from allowing everything unless it was block, to blocking everything unless it was allowed. Checking our firewall logs, I'm seeing a lot of HTTPS requests getting blocked by our default firewall rule. These are going to numerous IP's for example 52.19.226.19 and 34.248.21.115. These are from different internal ports but are exiting over 443. Not being fully in the know with firewalls. Is there a reason why these request are not being sent over the proxy and are instead showing up as blocked in the firewall? I'm guessing that enabling 443 as a firewall rule isn't really a solution as could we be opening ourselves up for undesirable traffic leaving the network over 443. Thanks
-
To name a few : We have GPO's nested upon GPOs's, that configure things that are then over written with other GPO's. We have no override and block inheritance everywhere that have been used to get things working. Slow logons. IP address ranges incorrectly setup. Profiles that hard reference a server that no longer exists. Offline files that won't turn off and data is being written everywhere. Software that doesn't work if a particular server is turned off. Appdata local/roaming duplication issues. AD Sync errors.
-
Greetings all. Due to on going issues with a legacy Active Directory Domain that has been historically poorly maintained, we're seriously weighing up the advantages of starting afresh with a new Domain. With the current issues being experienced, we already have a requirement to rebuild every PC in school. We're also scheduled to install new PC's in the majority of classrooms. Given the PC work we'll be undertaking, migrating PC's to a new domain, via the rebuild, wouldn't be too much of an issue. The plan is between now and summer, we'd create a brand new Domain, DNS, GPO's etc, using another of our sites config as a reference. During the summer, we'd look to migrate data to a new file server and add some of the existing app servers to the new domain. The question is, does anyone have any experience of setting up and migrating to a new domain (we wont be using ADMT)? We use Frog, Papercut, Smoothwall, SIMS and all the usual extractors like Groupcall and Wonde etc. Did you migrate these servers or start them afresh and migrate data? Thanks in advance for any suggestions or feedback.
-
News regarding ICT4C/YHGfL?
Archipelego1 replied to enbiggen's topic in Yorkshire & Humberside Grid for Learning (YHGfL)
Dont let bandwidth issues sway your decisions. You can have a caching server installed locally, which will pull the updates down and then push to the clients. The cloud is more for management ... and devices such as laptops that never come into school. -
News regarding ICT4C/YHGfL?
Archipelego1 replied to enbiggen's topic in Yorkshire & Humberside Grid for Learning (YHGfL)
We've taken them up on the offer. Still waiting for a migration date though. Sophos advised us they're working through the list of schools have have requested this and will let us know when it is our turn. -
Tried this, for us, it works on Windows 7 but not on 10.
-
Is there any other way? I'd prefer not to standby the PC's, just lock the screen when not active. That way services and apps can still run in the background
-
I've done a search of the forums but haven't been able to find a definitive answer to the following : How can I enable to PC to lock after a certain amount of activity? On Windows 7, we have something similar to : https://community.spiceworks.com/topic/808517-lock-screen-using-group-policy-without-setting-a-screen-saver-server-2012 setup, which works fine. However this setting doesn't seem to be working on Windows 10. Is this to be expected, do you do this any differently? We have the latest release of 10.
-
News regarding ICT4C/YHGfL?
Archipelego1 replied to enbiggen's topic in Yorkshire & Humberside Grid for Learning (YHGfL)
Yep, we have our letter too. Spoken to Kirklees who have provided a bit more information. My advice would be contact the relevant person on the back of the letter, who can provide you with more information and options. -
Ended up speaking to Smoothwall. It turned out to be a specific problem with our setup where an orphaned IP address was stopping the VLAN interface being created. They managed to locate where this was and have it setup
-
Unfortunately, I'm not able to though. The help guide talks about setting up a parent interface, but nowhere does it tell you how to set this up
-
Hi there, If possible, I'd like to run two vlans over the same physical Smoothwall interface. I can see how I'm able to assign two IP addresses to the same Interface. However, is it possible to assign a VLAN to one of the ranges? Basically, the HP switch that the Smoothwall interface is connected to, would be configured as Tagged on one range and untagged on another. For example : I have IP address ranges of 10.140.0.0 and 10.150.0.0 and a Smoothwall interface, lets say Interface 1, configured with IP addresses of 10.140.0.1 and 10.150.0.1. Lets say that Smoothwall interface 1 is connected to HP switch port 12. HP switch port 12 is tagged on the 10.140 network (vlan1) and untagged on the 10.150 network (vlan2). As this is HP, any traffic travelling over switch port 12 that isn't already Vlan tagged, will be tagged on to vlan 2 (the 10.150 network) by the HP switch. I need Smoothwall to be able to send traffic over interface 1, through switch port 12, on vlan 1. The only way I can think this can be done, is for Smoothwall to tag traffic on the 10.140 (vlan1) network. That way, anything not tagged by Interface 1 will be tagged by the HP switch on to vlan2 Is there a way in Smoothwall that you can tag IP ranges on interfaces? I hope this makes sense
-
We've just implement FSRM filters. Anyone had FSRM screening save their bacon?
-
I have looked at the 2920 before. But the lack of native 10GB is a pain. Yes, I can add the expansions, but it's bumping up the cost quite a bit.
-
In terms of the Cisco's. I'm looking at the data sheets and the buffers seem to show 16 megabits, not 16 megabytes? found a couple of Redit posts that seem to confirm this. Looking at the spec sheet of the HP1950, they show the buffers in megabytes (MB)
-
Good afternoon, if you've read some of my previous posts, you'll be aware we're currently going through the process of speccing up and deploying a virtualisation solution of 3 hosts and shared storage. I'm currently working with suppliers to look at suitable switches to connect the hosts to the storage. We've currently been offered Cisco SG550 running at 10GB and a HP1950 running at 10GB. Although the suppliers are saying the switches should be good for the solution being proposed. I've read online that the Cisco SG550 isn't suitable due to the small buffer size, and HP themselves have said they don't recommend the 1950 for host to storage networking. Could I ask, what networking are people using to connect their hosts to the underlying storage. Thanks
-
The Mirfield Free Grammar & Sixth Form Multi- Academy Trust are recruiting for a Senior ICT Engineer to support the management and development of the ICT infrastructure. Reporting into the ICT Services Manager, this is a great opportunity for someone with experience in a similar role or someone who is ready to take the next step in their career. You will be an integral part of the ICT Team on site, providing day to day maintenance and support in the use of ICT facilities to teachers, support staff and students. As Senior ICT Technician you will also be required to contribute to the continual service improvement of the ICT support service and provide supervision and guidance to members of the ICT Team. We are looking for someone who has previous experience in server, desktop and software support. Knowledge of networking and virtualisation technologies would also be advantageous. You will have excellent communication skills, be approachable, adaptable and have the ability to work as part of a team. We welcome applicants from all sectors. If you are looking to take the next step in your ICT career or have previous experience of working in a similar role we would like to hear from you! To apply for this position please send your CV details to Alison Haldenby, Director of HR or, phone Alison to discuss this position in more detail. The Mirfield Free Grammar & Sixth Form - Job Vacancy: Senior ICT Engineer
-
Good afternoon all, we're currently looking to make a decisions on a new SAN for our VM environment. We have the following options : NetApp FAS2552 Dell Equallogic 4210X Dell Compellant 2020 All will have similar config in terms of 2 controllers and 24 drives. Price wise, the Equallogic is the cheapest, followed by the NetApp, then the Compellant. Each step up this ladder increases the price by a couple of thousand. I'm aware that Dell are looking to EOL the Equallogic range and with their recent aquisiion, may decide to do something with the Compellant range. My question is though, does anyone use the above SANs and have any feedback? We'll be running three hosts with initially 15 VM's (though this will change). Also, as a follow up, what RAID level are people using. I'm currently split between 50 and 6. Thanks
-
Virtualising SIMS (and other servers)
Archipelego1 replied to Archipelego1's topic in Thin Client and Virtual Machines
Lots of interesting comments and posts, thanks for the feedback and information so far....it's really helpful to see what peoples thoughts are. -
Hi all, we have a pair of Smoothwall S8's setup as a HA pair, one as master, one as slave. Physically looking at the boxes, is there anyway to tell which is the master and which is slave? Thanks
-
Good afternoon all, As some of you will know from previous posts, we're currently in the process of Virtualising our entire estate. As part of this project, I'll be planning in the migration of services from Physical hosts to VM's, which leads on to the questions ..... I'll create new DC's and add these to the domain, removing the old Physical DC's. However, what are peoples experiences with other services such as SIMS, file, app and print servers? Is it best to P2V them, or start from scratch? Thanks as always for your feedback and opinions
-
We're currently in the process of reviewing our network permission, with a view to undertake the reverse of what you're looking to do. All our staff areas are permissioned to give the user exclusive access to their folders. We have a real problems supporting the users on a day-to-day basis. We're unable to provide remote support on document issues due to no access. The user has restricted access to the desktop due to GP's, which make it hard for us to do anything while logged on as the user. We're looking to propose creation of a new security group which, along with the end user and system, will have permissions to access folders. Access to this group will be restricted and auditing placed on it. As a side note, if you think about it, as a domain admin you have the ability to reset someones password and thus gain access to their documents. Did someone famous once say, with great power comes great responsibility? If not, then they should have
