KK20
Members-
Posts
969 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by KK20
-
LTSC 2019 supported till 2029 :-) https://docs.microsoft.com/en-us/lifecycle/products/windows-10-enterprise-ltsc-2019 For this reason alone I put 2019 on my digital signs and didnt upgrade them to 2021
-
It is also good to read up on how a client corrects its time. It doesnt just instantly change, it does it in increments. This is important if you have laptops with iffy batteries.
-
Indexing might be causing high spikes. Compression (users using compression) might also be causing grief.
- 4 replies
-
- hyperv
- server 2019
-
(and 2 more)
Tagged with:
-
Ive had a look at proxmox and ceph. It does seem to do what I want it to and im downsizing our server load to 3 nodes which is the minimum. Hardware will arrive in September for lab "test and soak" before I migrate the VMs across, the hardware is S2D certified as im still on the fence with regards to *S2D + full fat server + hyper-v cluster. Familiarity, im happy with windows clustering, S2D is new to me but the concept is similar. Im happy with powershell configuration (it was better to do this for stretch clustering anyway). Licensing is 3x EES DC licenses and covers cluster + S2D *starwind + full fat server + hyper-v. Starwind is new to me, I would be running the free version simply because the paid one is massively expensive even in education licensing. I would still need DC for the cluster due to VM count. *proxmox+ceph (with windows server guests). I have a good few months to play with the new hardware in lab configuration first. I would still need DC licensing for the VM count. Ive been playing with starwind in a set of VMs but have hit quite a few gotchas. No CHAP on the free version. Not a total game changer as I will be running in direct connect between the servers (40Gb interconnect between the 3 nodes) so wont need CHAP really, but if you are traversing switches (for whatever reason - perhaps you have a backup volume presented?) then you wont have CHAP! Caching + HA means a full resync of all data to unsync nodes, that should be fun with a pair of 8Tb volumes and pretty much puts your 3 node HA into a no redundancy until this completes. S2D flushes the sync cache then syncs delta changes, it does not full resync, so whilst again you are in a single node redundancy it isnt for nearly as long (minutes compared to hours/days possibly - I have yet to perform this on the real hardware). However, you can use hardware RAID for extra drive redundancy with starwind thus having a bit more resiliency for hardware failure, S2D can only run in HBA plus nested resiliency (mirror accelerated parity for example) is only available in 2 node configuration. Im yet to even start lab work on proxmox+ceph, this will be done on real hardware in the lab. Im not a fan of having a single VM perform all tasks hence DC licensing, it is cheap enough for schools to warrant such extravagance. Updating numerous VMs isnt an issue, they have been automated updating for years with scripts (always after the weekly archive backup!)
-
we dont have a 1gb connection and I wasnt keen on client machines collapsing the internet on patch tuesday. However, you can cache on a server https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/microsoft-connected-cache with the GPO living in windows components\delivery optimization -> cache server hostname I have a test ring running which seems to work.
-
SAN? I have never had a SAN go down totally, I have had a number of drives fail (in RAID configuration) and a management card die in an MD3220, but they are replicated so it was a simply yank out, put new one it - no downtime. Nodes? I had a hyper-v host R610 raid controller fail - the BBU went bad and took the RAID controller with it, magic smoke escaping and all. At the time we had a replicated hyper-v setup (local storage), not a cluster, and the replication failed when starting up - it had previously been fine when manually brought online for hypervisor updating plus a simulated fail had also worked. This ended up with around 8Tb of restoration which took a couple of days to get running. We had (and still have) a standalone physical DC so no rollbacks or AD sync issues. Since ive had the stretch cluster we had the UPS management card shutdown the cluster (power fault on one site) and one of the nodes did not wake up again, there was a motherboard fault (an R630, fans would simply spool to maximum, very noisy!). It should be noted that our "second site" nodes on the stretch cluster has no votes so cannot continue without manual intervention, this prevents split brain. The rest of the cluster came on just fine and no loss of service was seen (other than the time to reboot), this was all automatic and happened over a weekend. More recently we had a memory fault on an R740, we lost half of the memory, the poor thing carried on running, the cluster rebalanced automatically and the show carried on running, not a full fail though just not enough RAM to run the whole VM load - it would have been interesting on a single host system. Cluster Aware Updating works in 2019 (it didnt really work in 2016, it was always better to manually drain) so updating the hypervisors is a doddle.
-
It boils down to risk analysis I suppose. I wont do anything other than HA. Ive lived through a hyper-v failure plus restore to new hardware (after waiting for the new hardware) and do not wish to endure that ever again. I also only use VEEAM as it works and I have faith with it. With my stretch cluster a node failing or one of the SAN failing isnt an issue. The hardware is aging though and the system is overkill for a full replacement (it was previously incrementally updated) hence a 3 node HCI would be a better (resilient) option. I even HA our pfsense firewall as the hardware is cheap but we are resilient. Sourcing new hardware timely might be an issue and if you already have a cold server then why not HCI it? For us it is definitely worth it to have a VM down for only a minute but also not losing the delta of data since the last backup. My head would be on the block if I lost an hour of MIS data or academic reports etc "by choice" rather than necessity, I have continuous delta SQL backup to a NAS but only half daily backups of other stuff. Yes we use sharepoint and onedrive for a lot of things but quite a bit is still onsite due to cost effectiveness - our media is saved locally as it is unworkable to have our drama, art, music, DT and engineering have their gigantic files working via sharepoint and onedrive. Yes I have costed three lumps of iron onsite + local backup vs SaaS. Going OT though.
-
do you use proxmox for HCI? I had looked at alternatives to hyper-v clustering (licensing would be the same as the VMs would be windows servers) but looking at various options for HCI over 3 or 4 nodes. Other options were S2D, starwind+hyper-v cluster or carry on with the stretch cluster 4 node + 2 SANs. I will admit I hadnt heard of proxmox VE HCI (or ceph) so will have alook at that and their support pricing. Starwind was very expensive for a 4 node solution (yes 3 node is free with forum support) but I had a nightmare of a time with our testbed resyncing at inopportune moments (unless you disabled caching and take the performance hit) S2D was the fastest but also least flexible with hardware.
-
can you set a cache server for WUFB or do you only have the update peer to peer requests? Can you set a time for WUFB to start looking for updates or will they come down at any time? I am looking for WSUS replacement this summer so might start a test policy with a room or two on WUFB.
-
5 months on and we are doing "ok". There are a number of small nuances such as no ability to add a comment to the block or allow. For example "why was myairbridge.com allowed?" there is simply a mass of URLs that have been allowed. There are overall categories but not many. Our previous filter had a good 40 categories that you could allow/block before needing to resort to manual block/allow, securly has 14. The allow list is growing exponentially. You cannot filter BBC iplayer at all as the proxy is not located in the UK it seems, you need to add a blanket exception to iplayer. Im not sure how other streaming platforms fare as we dont use others. Performance can be hit and miss at peak times, we do get a slowdown from the securly proxy which is noticeable if you are allowed to remove the smartpac option. Not enough to cause an issue overall but certainly noticeable. Ability to use the smartpac on devices that are off premises is good and works, pupil (and staff) devices do work offsite nicely. Overall our first few months have been "ok" but there are improvements that could be made. Still, it was cheaper than the others and budget was a concern for us.
-
Technology hasnt really evolved. Short of the TPM, the last major innovation was the VTx support. I would argue that benchmarks are largely irrelevent, it depends what the benchmarks are doing vs what you want the PCs to do. Our standard desktops run office 365, the most worked PCs in the school run fusion360 and creative cloud suite. Our ancient core 2 duo will get from CTRL-ALT-DEL into a word document in under 2 minutes, they load browsers just fine, play youtube just fine and work well enough. cpubenchmark say that the e8400 benchmarks at 1165, our i5-4460 (majority of our fleet) benchmarks at 4841. So 4 times faster right? Nope. Put them side by side (such as in the library) and you are looking at maybe a 10 to 20 second difference in CTRL-ALT-DEL -> word document. The bottlenecks are elsewhere, network, internet, sharepoint, onedrive. Granted, first boot -> CTRL-ALT-DEL on a wednesday maybe 2 minutes on the i5 and 4 minutes on the core2 as we run updates at 5pm on Tuesdays so the first boot on a wed is always slow. Every other day not so much and WOL gets all my machines up and running in time anyway. The extra cores do help when running a lot of updates. My own PC at home is a 6600k (overclocked to 4GHz), this would be difficult to benchmark but stock would be 6320. This CPU is not supported for W11 but yet I can run elite dangerous in VR on my Rift (paired with a 1660TI). This CPU outperforms many CPUs that are on the W11 accepted list and is many generations behind. There are many CPUs on the W11 list that would be bottlenecked in VR. So, the core2duo is an ancient dog that runs too slowly? Well. MS support the celeron 4250U, an 8th gen laptop CPU that benchmarks at 1348. We have a couple of small laptops with those in them (I was shocked to find these supported so we DO have some machines that support W11!), the desktops are MUCH faster (even with SSDs across our whole fleet). How about a more modern supported common cheap laptop CPU? Celeron G5900T which benchmarks a whopping 2648. Now dont get me wrong, im not saying that the venerable e8400 should support W11, however there are ample other CPUs that not only COULD support W11 due to TPM and other requirements met, they are simply knocked off the list "because". What will we do? Pray for more money, we are a set of CofE schools afterall. I will probably lease the cheapest of the cheap I can find, PCs that ironically will perform worse than the fleet we already have. EDIT: I will admit I have not looked into the 11thgen+ threat detection tech in the new CPUs, that would be useful (if it works). I dont know if TDT is only featured in high end CPUs though which would preclude our upgrades anyway.
-
do you actually run that setup? Hats off if you do in a windows environment. When we were transitioning from 2008R2 to 2012R2 (when 2012R2 was the latest) I looked and tried moving to a linux server infrastructure for some core services and I wasnt very successful. First, the DC was a no go as GPO domain replication always seemed to be out of sync on our test bed subdomain, I had everything setup as per the paper, I didnt confuse ID, it *should* have worked but didnt. DNS worked, DHCP worked, CUPS just didnt, RADIUS and VPN I didnt try as we used SSTP at the time so it made sense to leave our setup alone for that. Hypervisor was a windows hyper-v (for the linux containers) only because I was familiar with the setup, I didnt try a linux hypervisor. Whilst I cannot replace MSSQL fully due to reporting services, I do have a very limited setup that did reduce the licensing costs to the bare minimum - cheaper than the online offering for our services that need it. The rest of our SQL is running on MariaDB VM. SIEM is ELK/ElasticAlert and runs nicely - this was one of the driving forces as I cannot afford the big boys and I needed it to be automated. PFSENSE is relatively turnkey. In all honesty, for the man-hours I would have spent keeping a "free" linux infrastructure up vs the 4xDC licenses I pay (I cannot remember the last time I needed to work on the infrastructure to fix an issue with File, DNS, DHCP, RADIUS services - the printer v3/v4 driver issue was the last I needed to "fix") means I would be out of pocket overall and I am confident in my knowledge, securing a linux environment would mean I should really get a specialist to get it running thus putting the cost way out of scope. Kudos if you did get it all working reliably, I certainly dont have that skillset to move to production!
-
Of course im delaying the inevitable. We still have a room of core2duo optiplexes. This isnt through lack of knowledge or care or belligerence on my part, it is because I am not given the money. Even rolling replacements are basically castoffs, generation 4's and 6's i5s. Will I have rolling replaced everything in 3 years? No, not unless I get a doubling of budget. Have I raised this with senior leadership and trustees? For at least the last 4 years I have warned of a rolling replacement issue, in the last 2 years I hit the doom and gloom button - all in my annual report and my appraisal, oh and in head of department. I just went through a new agreement renewal, I would have loved to move away from OVS licensing. However, almost none of our BIOS (and I use the word literally) support it without be going round to each PC and activating manually. Maybe 5% of our PCs have W10 keys embedded. That puts us on the back foot with everything else. If the money isnt there then it isnt there. So yes, I will be installing LTSC as I will have no choice (at least on what I have left). The alternative is a new job, and that is also on the cards. The optiplex 760's were purchased in 2009, so they are 13 years old now. With an SSD and 8gb RAM they run W10 and office 365 fast enough. Dont get me started on the 100+ 4:3 dell monitors from 2006, the plastics fail on these before the panels do. Not to worry, I stripped the broken ones for spares. Projectors? How about half a dozen benq PB2250? Im a dab hand at replacing the bulbs on these (the bulb, not module with reflector), the lens fail on these as the plastic goes cloudy (due to the non standard bulbs being a little brighter than the originals). Im used to being laughed at when I go to the AMNE meetings but we are where we are. I make do with the resources I am given and I make sure the pupils and staff can access everything they need for their work. My logon times are under a minute, we can print, everything is on the latest updates (for W10) and I run a pfsense stateful firewall with snort and PFblocker.
-
I have tried 3 times to sign up to chest. Not once have they gotten back to me, my emails have gone unanswered. I even check 365 logs to make sure 365 isnt eating them. Ive tried with our .sch.uk and our .co.uk without issue. We are a genuine secondary school! You say College so thats an education set of license. Im assuming that you will be running a cluster rather than a single host with no redundancy. Next look at how many VMs you want. 10VMs is around the breakpoint for std over dc. Each std license gives you 2 vms. DC gives you as many as you like. CALS depend on your desktop licensing model, you are better talking to someone (we use VeryPC, they were helpful running through scenarios and I got ZERO hard sell which wins in my book). It will depend on how you license your office, your OS as there are deals to be had with both. Or just purchase CALs. Linux doesnt consume a license if you are using std over DC by the way. With clustering you need to license as if you had one host then multiply that by total number of hosts - you cant say "i'll have 5 VMs on this clustered host but only 2 VMs on that clustered host" it would be 7VMs worth (4std licenses) multiplied by two hosts (so 8 std licenses total). With EES OVS you get the latest version and utilise downgrade rights so you would be purchasing 2022 licenses and downgrading to 2019. I must be one of the few people who have WSUS working without issues. I do keep the data clean on it though. I learnt what the AdamJ scripts did (before all the hoo haa) and created my own as part of the server update scripts.
-
Dont worry. LTSC 2019 has an end date of 2029. Office can install on LTSC and it has edge, that will do for the machines I cant get to run in W11....
-
Yeah, thats our thoughts. Although we do have a single room of i3-8 series that are on the approved list, none of our other pcs or laptops are on the approved list. Our technician installed W11 preview on a core2duo using an iso and a .dll delete workaround for giggles, seemed to work just the same as 10...
-
ironically enough, might be easier to promote another DC - let that replicate from the "backup DC", demote the NPS/DC - offline if necessary.
-
I have a frankenserver VM, it holds the BMS and is fairly locked down on its own VLAN. It started life as a physical 2008 machine and was P2V. I have inplace upgraded it all the way to 2022 over the years, it is a sort of joke system for us as it must have so much cruft in the registry but it has never had any issues. I did the same as I always did. Remove any profiles from the server that arent needed (in place upgrading updates all the profiles too so that might be an issue). Downloaded the ISO, ran setup, declined "updates during the installers", keep all the apps. Let it reboot. Reboot it again. Run updates. Job done. the only servers I *dont* in place upgrade are the physical hosts, VM SQL and VM exchange server. All the rest have been inplace upgraded. DCs get demoted first, upgraded then promoted. 2016->2022 is a supported upgrade so you should be ok. Others have said but assuming you are education volume licensing, you will already have a 2022 key in your MVLSC - in fact you are using downgrade rights to license your 2016 from 2022 right now. If you use KMS for your servers then you will need to request a new KMS server key as they dont tend to be given out naturally these days (we use MAK so not an issue). Our "playground" lab R610 has also been put on life support as there are no drivers in 2022 for the PERC card, that is a shame as we used that old beast as our testbed for many years. It goes without saying make sure you have a *TESTED* backup first.
-
2022 has edge installed so that is good enough for the non-core servers.
-
conditional access for Azure AD, have I got this right?
KK20 replied to KK20's topic in Cloud Services
Lockout is default of 10 with 60 seconds lockout. Attempts on one particular user is approximately 10 per minute in bursts, all from vietnam/far east area. Obviously with azure AD the first unsuccessful attempt after a lock is also a relock. Luckily this user is a fairly savvy 6th former so what I have done is given them a FIDO2 key and manually added MFA to them. That pretty much squashed the issue but there will be others. the irony of all this is our firewall used to geoblock so when we were fully onsite this was not such much of an issue... -
I had a similar issue some years ago. This was because when I created the initial 365 tenant, it did not initially get approved as an education tenant (so did not get my one million A1 licenses and 15Pb of sharepoint storage), MS support sorted this but what they did was change our onmicrosoft domain (not a problem as it was brand new at the time, we were never going to use our onmicrosoft domain for email or access etc). The old onmicrosoft domain somehow lingered in the background but wasnt listed anywhere. For us, this became an issue at agreement renewal and reactivation of our 365 licenses, it wasnt accepted because of the shadow onmicrosoft domain, I also needed two tickets to sort it out.
-
Is there a reason they have two mailboxes? When I was migrating I simply migrated or left onsite, we are all migrated now so only service accounts that need onsite mailboxes exist onsite. However, when I was migrating, I did make some mistakes initially and accidentally ended up with an onsite + offsite mailbox, this caused no end of issues with AD IDs for that user. I think in the end I removed the 365 license and mailbox, added a license only, migrated the mailbox but needed to do some AD cleaning for that user with spurious GUIDs remaining. https://docs.microsoft.com/en-us/exchange/troubleshoot/user-and-shared-mailboxes/mailbox-exists-exo-onpremises If the dataflow is going to 365 (our dataflow was to onsite for our duplicate mailbox users) then I would also suggest that the teams chats will go if you kill the 365 mailbox.
-
QNAP here and their integrated backup. the actual backup was a real pain to setup initially BUT the restore is much quicker and easier. I used QNAP as we had a big NAS with lots of ironwolf drives - this was one of our onsite backup repositories so repurposing to a sharepoint/onedrive/mail backup wasnt too onerous. We dont backup teams at the moment so that is at the mercy of MS and staff are aware.
-
I am so glad we arent the only ones with core2duos still on the network. we even have 20 of these remaining "Pentium® Dual-Core CPU E5200 @ 2.50GHz" till summer. In my defence with an SSD and 4Gb RAM they arent much slower than the i3 6 series for Outlook and Word use. We GPO'd QUIC from Day 1, originally I didnt like the sound of what it did and it seemed a good hunch as time went on.
