Arcolite
Members-
Posts
173 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Arcolite
-
[1703, cu] Windows 10 Creators Update (v1703) now available to download
Arcolite replied to Arthur's topic in Windows 10
It's not documented anywhere if it's changed to the point of breaking things. Only two changes to the answer file settings are documented - https://msdn.microsoft.com/en-us/windows/hardware/commercialize/customize/desktop/unattend/changed-answer-file-settings-for-windows-10-build-1703 -
[1703, cu] Windows 10 Creators Update (v1703) now available to download
Arcolite replied to Arthur's topic in Windows 10
Might be something I've done wrong, but has anyone noticed that their unattended.xml that was fully unattended in 1607 is now asking to confirm the installation language in 1703? The dialog has en-GB prefilled so it is using the file contents, just not auto skipping that prompt. Using the same xml with 1607 remains fully unattended. -
^^ This. I've seen it documented in many places that 32bit is the recommended path. 64bit is rarely advised. We've stuck with 32bit.
-
Putting some fat on! dumping Citrix VDI?!? maybe!
Arcolite replied to Griff's topic in Thin Client and Virtual Machines
We're looking to remove our Citrix environment this year. We can achieve everything we currently use Citrix XenDesktop for with GlobalProtect VPN on our Palo Alto. We've only used it for simplfied Remote Access and giving students a "break proof" programming environment. VPN solves one, and we can achieve the latter with either local Hyper-V Read-Only in Windows 10 or just through GPO and monitoring, saving ourselves a lot of money. -
Should I stay or should I go now - Smoothwall
Arcolite replied to Simcfc73's topic in Internet Related/Filtering/Firewall
You're right, Palo Alto, while being a beast of a Firewall, is pricey, although I'd argue it's worth the money. And you're right again, they know very little about Prevent. Thankfully, we had support from our Vendor who help us put in Prevent-Keyword monitoring - it's quite simple to put in place. -
Should I stay or should I go now - Smoothwall
Arcolite replied to Simcfc73's topic in Internet Related/Filtering/Firewall
We've recently removed our web filtering from a dedicated appliance to being handled purely by our Palo Alto Firewall. Best decision we've made - our internet speeds have increased dramatically. Our previous products (Bloxx and CensorNet, both Squid proxies) seemed to be a bottle neck. We did look at Smoothwall, but the quote was more than we had budgeted, especially when we're already paying for a URL subscription from Palo Alto. -
Securus Software Alternatives
Arcolite replied to bewlay51's topic in Internet Related/Filtering/Firewall
I think this covers it, it's part of the reporting server, under E-Safety - https://helpdesk.stone-ware.com/portal/kb/articles/report-server-version-8-overview "The eSafety section displays entries of Keystroke Alerts (Banned Words) that Teacher Consoles have received and the following details: – Date / Time – Username – Computer" -
Web Content Filtering Policy
Arcolite replied to DaveAB's topic in Internet Related/Filtering/Firewall
We tend to take the approach that filtering is never going to be 100%. You just have to ensure you've done everything you can to ensure that the risk is low (which it sounds like you have). Decent monitoring and reporting is just as important, if not more so, than efficient filtering because something getting through and not knowing about it is far worse. -
Securus Software Alternatives
Arcolite replied to bewlay51's topic in Internet Related/Filtering/Firewall
I don't know how good it it, but LanSchool 8.0 now has E-Safety. We plan to update over the summer. We also use Securus so LanSchool is just an additional layer. -
We're finding that the majority of our Unblock requested from Students these days are for resources within Blogs on WordPress, Blogger and others. In the past, we've always kept the "Personal Pages & Blogs" category blocked for Students on whatever Filtering products we've used. This was mainly due to the potential for inappropriate comments and content that can often be found. We would then just unblock each one as the requests come in, however this leads to quite a long white list to maintain. With an increasing number of of useful resources being hosted within this category I'm wondering if there's a better solution. How do you handle this category?
-
I'l be honest, we ditched our printer scripts years ago and instead switched to Group Policy Preferences. Had flawless printer deployment ever since and far easier to manage. The only suggestion I can think of would be to see if the "Always wait for the network at computer startup and logon" policy makes a difference. You may be hitting the problem where the network isn't quite ready to map the printer at the point of script execution - therefore fails the mapping.
-
Out of interest, have you considered AeroHive (controller-less). We've been using them for the last few years and can't fault it.
-
Mobile device & proxy with safeguarding
Arcolite replied to Sheridan's topic in How do you do....it?
We've just updated a few of our systems to tackle the very same problem. After exploring a few different options (such as Captive Portals), we opted to implement RADIUS 802.1x authentication. Students and Staff are prompted for their School Username and Password with accessing the SSID. No more PSK/PPSK to worry about. It's all tied to Active Directory via Windows NPS/RADIUS. Once a user has Authenticated, the RADIUS accounting information is sent to our Web Filter (CensorNet USS in our case, but Smoothwall does the same I believe). From that point on the Web Filter has User to IP mapping so all traffic from that device is mapped to the User rather than just an unknown IP. -
We're looking to migrate all our local user data to OneDrive. Initially we looked at mapping a drive via a PowerShell script but decided that for something we'll be relying on daily it would be wiser to purchase IAM Cloud, that way if anything goes wrong we have support. IAM Cloud is just a client that sit on each machine and maps to the drive letter(s) you tell it to. Works well and it's relatively inexpensive in the grand scheme of things.
-
What solution are you guys using for OS deployment these days?
Arcolite replied to localzuk's topic in O/S Deployment
I'm probably in the minority here, but we use the Dell KACE Appliances (now Quest). We use the Dell K2000 to install the Base OS plus Office, then the K1000 to install everything else after install via it's Agent. It's basically SCCM but without the configuration overhead. -
Same here. Students are denied access to the "Streaming & Downloadable Video" and "Streaming & Downloadable Video" Web Categories in CensorNet. Staff have Full Access. We have Planet eStream and push the teachers heavily to use that instead. Any resources that we are legally alowed to put on eStream are being added for Students to use.
-
We used to use ManageEngine SDP but the last few years we've been using a Dell KACE Management Appliance (now Quest KACE). Not only does it do our Helpdesk, but it also does Assets, Inventory and Application Deployment, Patching and Scripting via an Agent.
-
We're just in the process of setting up Captive Web Portal on our Palo Alto firewall. Everything is setup and working fine. On Windows devices, after a user has connected to the SSID they are redirected to the CWP as soon as they open a browser window. However on iOS devices, as soon as they connect to the SSID they get the iOS Auto-Login windows pop-up which is supposed to load the CWP. Instead however, it looks like it's trying to go to captive.apple.com, then presents an error message. I can make the error go away by allowing these requests through without CWP auth, however doing that stops the Auto-Login happening completely (because iOS can't see the CWP anymore!). iOS users have to manually open Safari (or Chrome) and browse to a website in order to Authenticate. Has anyone been able to get the Auto-Login working with Palo Alto CWP?
-
We're looking at implementing BYOD shortly but we're struggling to come to a consensus on the best approach. We have a few options are our disposal but can't decide which is the best option for the smoothest end user experience. LDAP Captive Portal on our Palo Alto Firewall with URL filtering polices on the Palo Alto appliance setup for the required user groups LDAP Captive Portal on via CensorNet USS Gateway. Our Domain Trust client machines use this as their proxy currently, but we're considering moving away from CensorNet and consolidating on just Palo Alto. Captive Portal on AeroHive with SSL Certs and instructions which redirects to Palo Alto Captive Portal for Authentication. Our ultimate goal is to have exactly the same visibility on BYOD Untrust clients as we do with our Domain Trust clients but in such a way where it's minimal effort for the user. Every route I've tried so far is fine for me, as a techy, but a complete minefield for Students and Staff. I've currently got LDAP Captive Portal (redirect, not transparent) semi-working in Palo, but the user experience isn't seemless. How have others dealt with this?
-
OneDrive for Business access via Office applications
Arcolite replied to Arcolite's topic in Cloud Services
I've managed to resolve this for my users. It appears to be related to the fairly recent change to the OneDrive app. Once you stop using OneDrive for Business and add your Business account to the standard OneDrive app you get the "OneDrive - SchoolName" option under Open and Save again. Solutions like IAM Cloud will be useful in the classroom where syncing isn't possible, however for Support Staff with dedicated desktops and Teaching Staff laptops we're trying to keep things vanilla Microsoft so that they learn to use the platform and adapt to change rather than be handheld through the process by masking the change. We have found in the past that our users never actually learn if we mask the change for them. We're learning organisations, that should mean Staff just as much as Students (I know, it's not always possible, but it's the aspiration we try to stick to). -
Information Systems Developer - Elstree - Closes 29/7/16
Arcolite replied to Arcolite's topic in Educational IT Jobs
I completely agree and I share the frustration. I wouldn't look at a advert without a salary either. I know how much I need to bring home to pay the bills. If a role wont cover that, regardless of how good the JD is and how much I'd love to work there, I simply wouldn't waste my time. I believe the range is £23-40k based on skills and experience, but as said, I'm not part of the interview panel or decisions. I'm part of the ICT Support team trying to cast the net wider to find a new colleague! -
Information Systems Developer - Elstree - Closes 29/7/16
Arcolite replied to Arcolite's topic in Educational IT Jobs
Bingo I know roughly what the upper level may be if the candidate is top notch, but I wouldn't want to post it and have that turn out to be misleading information when ultimately the SMT will be making the call on money. The only steerage I can give is that if my role is anything to go buy, the salary would indeed be competitive and the pension is very generous. -
Information Systems Developer - Elstree - Closes 29/7/16
Arcolite replied to Arcolite's topic in Educational IT Jobs
The only information I have is that the salary will be competitive and depends on experience. I agree it would be far more useful with that info. Part of the reason for adding the posting here is due to lack of applicants from press adverts and agencies. I'm not in HR or Management. Just trying to help my department fill a role using my channels as the normal channels appear to be lacking.
