Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

JRA

Members
  • Posts

    952
  • Joined

  • Last visited

Everything posted by JRA

  1. Hi everyone - yes easily Google-able but somehow I've spent an hour not getting there with it. Anyone feel like helping out? So, as I understand it the same .xml file that governs the start menu governs the taskbar too. I'd like my taskbar to have only file explorer on it (Cortana I'll bin with another policy.) Anyways, currently my start.xml file applies and we get no icons on the sidebar bit. Perfect: BUT if I add in what I think I should for the taskbar (and where I think I should add it) it all goes bonkers: Anyone fancy just pasting something in that works? Thanks ppl.
  2. This weekend (my fourth or fifth doing this I don't remember now) I'm getting errors where it can't see Sophos central so just refuses to install. This is out of the blue, it's just stopped working. I wrote the strongest email I possibly could to Sophos and will need them on-site Monday. This is atrocious garbage. If I put out a failure of an update this bad out into the world I should deservedly be fired on the spot. HOW can this be alright???? If I don't get an installer I can automate and removes/updates/installs perfectly and silently by Monday afternoon I am going to dial that ****ing support number every minute throughout the week until someone fixes this. I haven't been this angry at anything in so long. I hope Sophos read this. I want any way out of your useless software I can get and I want my weekends back.
  3. Hahaha - yeah you'd think I'd have already done that being an experienced network manager but I hadn't. So then I did. And then shortly after disabled the fast login optimisation experience wossname which was wrecking it and all is perfect with it. Thanks everyone!!!
  4. Thanks Davit and sure thing:
  5. Hi all, Think I'm not FAR off with my moving from profiles to mostly folder redirection for W10. Snag of the day today is this: Redirect the Desktop folder in Group Policy to \\fs1\profiles\Desktop. Now, fs1 is a Samba server, and the share [profiles] goes to %H/profile which, in real terms on the Samba server, is /home/staff/%username%/profile/Desktop. With me on that one? I'm not sure it 100% matters here what's occuring Samba-side, but just including that. In Windows, a staff user (all set up and been running a few years on W7) now logs on with nothing in the profile field in AD, and folder redirection is set to the attached. Now, users can log on and the desktop doesn't have the "old"/the W7 things they used to have on their desktop. It looks like this: BUT if I type that UNC path in as in the address bar there in explorer it's got what I'd expect to be on the desktop right now. However, if I click on the quick access link on the left to the Desktop I get what actually shows up on the desktop: ...Can anyone un-bugger my situation right here? ALSO also, is it possible to add in a number of desktop shortcuts for Word, PPT, Chrome, SIMS etc? Hopefully as per W7 the desktop could also be redirected to a share on netlogon for example with some links I can add to/remove. If not I can do that through GP Prefs I guess. Thanks anyone who looked and had a ponder.
  6. Thank you everyone for leaping into this and bailing me out. It was very much appreciated and I felt all desperate! In the end I did manage to get it working, and working the way I wanted too! Still have my guacamole and we're "getting on" together. Thanks everybody enormously.
  7. Ouch... :/
  8. Ooohhh... I'm going to set this up as you have and get a sandwich and see. Thanks MUCH for that!!
  9. I don't even seem to have tamper protection on at all. Lol, I'm happy for you though! Wish I'd had it go that way.
  10. Latest from Sophos is they want me to visit EVERY SINGLE PC ON THE NETWORK and boot it into safe mode, then disable tamper protection on it. Whiskey Tango Foxtrot??? Did anyone else have this much misery with it?
  11. Okay had a little discovery... It looks like the OLD Sophos is somehow reinstalling following the restart. Now the old server is back on (that started the batch file actually uninstalling it too) the uninstall happens, then reboot, then the old version reinstalls itself. Is there any capacity within Sophos itself to do this or am I pulling scripts apart? ...Might it even be worth renaming SAVXP on the old server to see?
  12. Hi - I have yes. Not heard back yet and I'll ring up tomorrow if I need. Bemoaning my bad luck atm. I need a tea... :/
  13. Thanks for that. Okay, I'm in over my head with Guacamole then and that'll need to go. I'll do a fairly vanilla link on the website, SSL cert on the RD server sort-of-thing and go down to the one server for everyone. I also discovered the registry key change to allow a remote desktop in the list of apps too, so hopefully I'm not MILES away. Thanks so much though. With no staff last 6 months AND Sophos being dreadful AND W10 still far off I really thought I'd have a bit of luck...
  14. Hi all - aside from the regular that's killing me, this is another awful one. Long and short is I've got no staff and no time. It's killed me on my W10 deployment and I need to overhaul the old 2008R2 RDP servers with Guacamole frontend to 2012 RDP. No problem, I thought, I can just in-place upgrade them to 2012 and keep the wolf from the door. How wrong I was... So, this is different. Very different. I'm tempted to just strip out Guacamole altogether unless I can figure this out. This might not be news to anyone else but it's changed massively since the last time I looked at anything to do with this! So, old RDP server Guacamole presented you with the choice of server. You logged in, got to a desktop. I would very much like to have that back again! How on earth do I go about doing that? If not, would YOU in my shows just strip out Guacamole, put a link (one for a staff server one for a student server) on the website and go virtual machine based rather than session based? Very grateful for any help at all. Thanks for reading.
  15. Lol, I'm happy for you but this is killing me. It's so bad I can't even log into a PC here as local admin and uninstall Sophos MANUALLY (objects saying update pending) and running the new exe regardless (either doubleclicking the new exe or running a batch file with the --quiet and the --proxy switches on) plain doesn't work or the exe itself fails to download updates. I've actually know very little to have been as awkward as this. Thanks Sophos...
  16. I wasn't, no. I can't seem to sign in with my SCA account to download that tool though. Heavens this is a CHORE... Thanks though everybody.
  17. Okay, long story short this was given to a tech here who went long-term sick and swore blind it was all getting sorted. Just discovered he did next to nothing on it. I have tried to just run the new installer, tried to reboot then do it, tried to remove the old one then reboot then install the new one. I've tried GP, WPKG, PDQDeploy and I have had absolutely no luck for days getting this STUPID THING to install the new Sophos on my clients. Does anyone have a bulletproof and foolproof way of sorting this out?? Thanks so much for anything.
  18. Ooh thanks massively for that! And congrats on it too! We'll use it happily, cheers.
  19. Hi all - as per title really. One of our data team wants it, looks kinda handy. Anyone else use it? Is it wonderful/awful? Thanks all.
  20. Thanks folks - that walkthrough page is especially good! Asking nervously here, when coping the extracted en-us folder and all the .admx files from the new folder to the original PolicyDefinitions folder in SYSVOL, do I want to overwrite the files already in there? I'm guessing I do of course, and have copied them out already... Someone just tell me that's what I need to do before I press the button??? Hahaha.
  21. Actually it turns out to be wronger even than I thought. I asked if it was SIMS itself this morning, and it turns out that they meant they can't open SIMS and it's in SIMS. Despite me asking that and being told it wasn't. The actual problem is no SIMS shortcut and they were talking about SIMS all along. I need a lie down. Thank you all so much.
  22. Lol, not dumb at all and I'm the NM here who's got no idea what my BM is on about, or what he should be double-clicking!
  23. Hi all - hopefully this isn't too horrid. Our business manager deleted the shortcuts to the SIMS Personnel module from his desktop and start menu and wanted them back. On thinking I knew or could find what that was and would be called and swiftly create a new one I came out scratching my head! ...Does anyone know what it's called and where it is?? Thanks muchly.
  24. ...Am I doing something bonkers here? Myself and another tech are baffled by this one. Trying to get some new W10 policies in and for the life of me I can't get it to work. Looking for Start Menu customisation (amongst other things) and admittedly it's been a few years since I've done it, but guh?? So, I download this: https://www.microsoft.com/en-us/download/details.aspx?id=58495 Install the .msi (which in the process gives you a location of the policies and admx/adml files it's going to install. In GP add template and browse there, and it can't find any policy definitions. Anyone see what I'm coming unstuck on? Thanks all.
  25. Hello all, title says it all really but I'll give the summary. Moving from KVM to HyperV and some of the older or odder Linux VMs (Varnish, chillispot, RT helpdesk) aren't moving over nicely. So, as their lives are limited (most of this will be replaced next year) I decided IN MY WISDOM to make a KVM guest in HyperV and just run those 3 VMs in a KVM standalone, itself a HyperV machine. They're "appliances" anyway and just sit there, so no biggie really. So, I set up a KVM head, all works fine and ran the powershell script that lets you run KVM that way, all fine. What I can't get however is my guests to see any networking. My setup for networking is all tagged packets on all VLANs go to the HyperV heads, which have a teamed NIC. This then appears as a virtual switch for HyperV and VLAN identifiers are used within each virtual machine, depending on the VLAN I want them in. Of course, this is ALSO what I want the KVM head to be doing, so I have three virtual NICs for it; one is for management of it and it's tagged in the servers VLAN and the other two are bonded (probably cack-handedly) with NO VLAN identifier, my thinking being it can then pass tagged packets to the VMs hosted within KVM and I can select the virtual NICs for them. If you're still with me, here's a config for one of the working, hardware KVM heads I'm replacing: # This filedescribes the network interfaces available on your system # and how toactivate them. For more information, see interfaces(5). source/etc/network/interfaces.d/* # The loopbacknetwork interface auto lo iface lo inetloopback # Primary IF auto eth0 iface eth0 inetstatic address 10.108.1.33 netmask255.255.255.0 network 10.108.1.0 broadcast10.108.1.255 gateway 10.108.1.1 dns-nameservers10.108.1.200 10.108.1.201 dns-searchmyplace.sch.uk #Oh boy, here we go.Trying for bonds for guests... auto enp0s10f0 iface enp0s10f0 inetmanual bond-master bond0 auto enp0s10f1 iface enp0s10f1 inetmanual bond-master bond0 #Bond to CORE auto bond0 iface bond0 inetmanual bond-mode 802.3ad bond-miimon 100 bond-lacp-rate 1 bond-slaves none #Think this one isjust for hotspot auto xenbr2101 iface xenbr2101 inetmanual bridge_portsbond0.2102 bridge_stp off bridge_fd 0 bridge_waitport off #Think this one isalso just for hotspot now auto xenbr2102 iface xenbr2102 inetmanual bridge_portsbond0.2102 bridge_stp off bridge_fd 0 bridge_waitport off #Regular serversVLAN auto xenbr10 iface xenbr10 inetmanual bridge_portsbond0.10 bridge_stp off bridge_fd 0 bridge_waitport off And here is the config from the new KVM in HyperV: # This filedescribes the network interfaces available on your system # and how toactivate them. For more information, see interfaces(5). source/etc/network/interfaces.d/* # The loopbacknetwork interface auto lo iface lo inetloopback # Primary IF auto eth0 iface eth0 inetstatic address 10.108.1.33 netmask255.255.255.0 network 10.108.1.0 broadcast10.108.1.255 gateway 10.108.1.1 dns-nameservers10.108.1.200 10.108.1.201 dns-searchmyplace.sch.uk #Oh boy, here we go.Trying for bonds for guests... auto enp0s10f0 iface enp0s10f0 inetmanual bond-master bond0 auto enp0s10f1 iface enp0s10f1 inetmanual bond-master bond0 #Bond to CORE auto bond0 iface bond0 inetmanual bond-mode 802.3ad bond-miimon 100 bond-lacp-rate 1 bond-slaves none #Think this one isjust for hotspot auto xenbr2101 iface xenbr2101 inetmanual bridge_portsbond0.2102 bridge_stp off bridge_fd 0 bridge_waitport off #Think this one isalso just for hotspot now auto xenbr2102 iface xenbr2102 inetmanual bridge_portsbond0.2102 bridge_stp off bridge_fd 0 bridge_waitport off #Regular serversVLAN auto xenbr10 iface xenbr10 inetmanual bridge_portsbond0.10 bridge_stp off bridge_fd 0 bridge_waitport off Can anyone see what I'm messing up here? Can ping the HyperV KVM head fine, but the VMs (although the options appear in virtual machine manager for KVM) don't get any network and can't ping anything. Thanks for any help! Feel like I'm dividing by zero a bit...
×
×
  • Create New...