Jump to content

KK20

Members
  • Posts

    969
  • Joined

Everything posted by KK20

  1. the exact opposite for me. short of raising another ticket to ask for help the most information ive had was from Marc up above.
  2. Sounds good. I will get a wishlist of "this is what I have done, how do I now do this" to you later week. Ive pretty much gotten it working now with my test machine, it is just the guests I need to test when I get a chance. I have shelved this rollout for the time being (I have another month remaining on my current filter license) as other things have come up today.
  3. My first impressions of Securly has been quite poor. We are a new customer, purchased a couple of weeks ago. Got an onboarding form quite quickly, filled it out with as much technical information that I could. An email from Craig with my logon details and some onboarding information. Then, nothing. No calls, follow up emails, just a list of "this is what we might suggest as a way to setting things up". There is a widget in the bottom corner of the Securly screen with how to set the basics but it isnt intuitive - i.e. it tells me to do something but not why, the 40 minute youtube video shows a lot of information on a fully working system but nothing on how to get there - I would prefer to plan what I am going to do and why rather than just blindly follow a "click this, do that". Especially as it becomes harder to change things once you get started. However, im a network manager so I can dig through the screens and i'm a dab hand at google and reddit forums. First, I needed to find how securly actually works - that gives me an idea of how im going to lay things out. I managed to find this: https://www.securly.com/assets/images/DNSwhitepaper_final.pdf So at heart Securly has two DNS streams and a proxy that can be authenticated should you require. One DNS goes through the proxy, the other DNS blackholes unwanted sites. You need an SSL certificate installing for functionality (pure guests can get away without if they are happy to get an unsafe webpage error for redirected HTTPS bad sites - this is to be expected of course). There is a Securly chrome and edge extension available, I have no idea why I need this or what it does. Now I can get down to it. Set my firewall to allow client egress to securly IPs for DNS and proxy (we currently have an inline proxy with PAC so there is no direct egress for our clients). Import from azure AD went without a hitch, created a couple of test profiles (you cannot rename the profiles, make sure you choose a sensible name), map the profile to an azure group and all is good. My first test PC setup with smartPAC seemed to work but would only filter with the default group, it would not pick up on my "proper mapped group for my azure AD group membership". Teasingly there is a "you might be seeing this if you havent logged in" button in the corner of the block screen. I click this, it now seems to recognise me as a 365 logged in user now. At least this gives me something to google. Searched the get started https://support.securly.com/hc/en-us/sections/4405534891031-Get-Started for answers and found references to installing an extension (I wanted a fairly seamless approach, adding an extension was not mentioned by sales - in fact one of the selling points was that nothing needed to be added as the smartpac took care of things). No mention in the docs of why I need to add an extension or what it does. I decide not to install this. Then found another article that says I need to run an IIS server (not an existing one) to get 365 SSO (?) Sales DEFINITELY said nothing about that https://support.securly.com/hc/en-us/articles/115004747727-How-to-set-up-Office-365-Azure-AD-SSO-IIS-server- Im not going to run a random PS1 script with no breakdown or manual instructions on what it does on my IIS. The article also says I need to do this to get the groups setup from my AzureAD. Thats odd because I already did that by clicking on groups and accepting my azure AD permission. I decide not to do this. In the end I appeared to sort it by switching a global setting named "Force logins" but I suspect this will cause me issues later. so now my domain logged in client that uses chrome with 365 SSO for all our other 365 browser authenticated apps will now correctly filter according to the mapped azure group -> securly profile. Time to set up guests: Guest access is via guest DNS, not a problem as that is what I do for our current guest networks; we have two - one for staff BYOD and one for pupil/IOT BYOD. Staff use unifi vouchers to get on their network, pupils use a "known" SSID password. we are in the process of moving to packetfence for both. Separate VLANS, separate egress (pupil BYOD uses the backup internet line), separate filtered profiles. Now for the biggie, you cannot have more than one guest profile on Securly - I emailed support asking how to add a second "guest" profile as I did not seem to have the ability to do so on the Securly screen. Securly can identify ingress IP and can determine if a "guest" has used one of your particular public IP (so could in theory have multiple guest profiles for each of your public IPs) but will not let you create additional guest profiles to do so. Securly WILL let you create a custom IP profile that will trigger on ingress from a certain IP *but* requires that profile to be authenticated (as I have just clicked force logons to get round the issue above). There does not appear to be a way to ask for logons on certain profiles. sure I could ask staff that BYOD to use their school password but this will be useless for the visiting saleman doing a presentation or guests in assembly having a presentation - they will not have a school logon (and I am loathe to create "known password" logons, no matter how locked down they are!). The pupil BYOD is also used for IOT devices (photocopiers wanting to phone home, DAVIS weather stations, That drama projector that insists is needs internet access) that require the internet - those can live on the pupil heavily filtered vlan and be kept well away from anything else. That also means unauthenticated. Staff BYOD will allow more unrestricted youtube, social media etc. Pupils will have these tightened. I emailed support regarding the above and simply got a "no, you cannot do that, we support one guest profile". No work around, no pointers. I listed my thoughts on a potential solution as a reply to the support email and have just had a reply from Chris to say that my solution should work and is "pretty much how Securly works". Well why didnt you say that in the first place? Are we the only school to ever require a two tier guest filtered network? I have no idea on ways to whitelist the Securly certificate self help page from monitoring, which is available in SSL only ( securly.com/ssl ). In my old system the guest network would whitelist the certificate page from both authentication requirement and https bumping. Shortcomings in using: There is no way of re-categorising a certain site internally. There is a way of adding a site for "consideration" of re-categorising. So if you have 5 profiles and http://www.this_is_a_site_im_happy_to_allow.com happens to be a "real gambling site" but you are allowing it for a reason then you have to add this to all 5 profiles, you cannot do an internal re-categorisation. Obviously this IS a gambling site but might be allowed for "you" as an "educational gambling" site. We have had quite a few sites in the past that have been allowed (old flash gaming websites that ARE technically gaming websites but are allowed for various reasons) to be re-categorised "internally" as allowed. Im not saying the above is impossible but I have had to sort all of it out myself. In short, Securly seems to be capable as a product. Support have gotten back to me initially with no help but on pressing with a little more (due to my own googling and research not through any help of Securly) they have responded a little better. Onboarding though has been very bad, and since this is the "first contact" im already off to a negative.
  4. brilliant. deciphering SKUs can be ...interesting...
  5. In all my years of using hyper-v I have never had a corrupted VM. Never. Ive even made mistakes in the early days (I once restored a checkpointed DC, you learn about rollbacks the hard way). We have a machine on our network at the moment that started life as a physical 2003 poweredge 2800 - yes, I will let that sink in - it was P2V at 2008 then it has been in place upgraded all the way to 2019 at the moment! We have golden samples in VMs gen1 and gen2, we have linux machines, DB servers, web servers, student "web" server for A level ICT that are sandboxed, development test VMs. Infrastructure is a stretch VM cluster. Ive made mistakes on VMs and needed to restore (Veeam is awesome - the only failing being a slow restore), even windows backup and restore is good enough for a P2V! Production checkpoints are great for lab testing - I have even checkpointed an SQL server as a production checkpoint to see if it worked and it does flush the logs properly!
  6. For macs, look up "Apple school manager" and "MDM". This makes administering Macs a doddle. Think "GPO and a store that actually work together properly". If you dont have ASM, get it sorted, then use apple configurator to get your macs into ASM. This is the only annoying part really.
  7. SKU 2UJ-00012 DsktpEdu All Language LicSAPk OLV F 1Y Acdmc Ent Which CAL pack does this SKU include? I seem to remember the original documentation from Microsoft talking about STD core CALs(server+exchange basically) and Enterprise CALS (SCCM, forefront, lync and a few others I seem to remember). I know it has the "Ent" on the end but that doesn't always mean it is the enterprise pack, however if it is does anyone know the SKU for DsktpEdu with STD core CALS?
  8. As others have said. SKU 9EM-00293 is named WinSvrSTDCore ALNG LicSAPk OLV 16Lic F 1Y Acdmc AP CoreLic we have two of these on our license that is because I have a pair of R630 dual 4 core CPU servers. Each of my server has no VMs on them and they each have 2xCPU with a total of 8 cores (a physical DC and an "offline/offdomain" backup controller). So I need a full 16 core license per server hence me having 2x licenses. I also have 4x WinSvrDCCore ALNG LicSAPk OLV 16Lic F 1Y Acdmc AP CoreLic as I have 12 VMs on a stretched cluster. Each server has 2x8 core CPUs so a single license per server is adequate. It is a DC license so I can put as many VMs as I like (they are fairly lightweight ones so 16 cores is plenty for us). Ignore for the fact that you need DC for a stretch cluster (lets pretend). But if I wanted to run the cluster on STD licensing I would need the following: max VMs on a server = 11 - round up to 12 as each license covers you for 2x VMs per license. 2x8 CPU per server so a 16lic license is good enough. I would need 6x std licenses per server x4 for my cluster so 24 16lic licenses. Incidentally we also have a free licensed hyper-v server that only runs linux VMs, that has no "paid for" licensing as hyper-v server is free in this scenario of linux only VMs.
  9. Im guessing SKU "KW5-00360"? If so, no it doesnt. You will need "R18-03500" also.
  10. 2022 on our DCs and our CA server. Using the JAN edition. Still too early to see issues but none so far, we have had no issues with RDP.
  11. we went from 2016DC to 2019DC for our stretch cluster (4 nodes split over two buildings/2 sites). We did this last summer as I wasnt prepared to wait for 2022. I will wait for a while as 2019 had issues when it was first released (regarding clustering).
  12. deleted the users and let the federated update run nightly. After this ASM let me reset the passcode (it not longer said create). Problem solved.
  13. We use a dozen shared ipads (MDM is manageengine). There are few issues we have had so far, students and teachers that have these in the class have been using them for months without issue. However there are 5 members of staff who cannot log into the ipads as it asks them for a passcode. Normally in ASM if a user forgets their passcode I go to the user, go to "... more" and "reset shared ipad passcode", but for these 5 staff I dont get that option. The only option I get is "create shared ipad passcode". Normally when a user logged onto a shared ipad I got our ADFS prompt then the user is asked for an apple passcode, these go straight to passcode when they type their apple id (school email) in. Ideas? EDIT: I should have said, if you try and "create shared ipad passcode" for these staff, you get the completed with error "OPERATION_NOT_ALLOWED"
  14. 1000 users here. The physical DC has 8Gb RAM but the virtual one hovers around 3Gb dynamically assigned RAM (it can go up to 8). It only increases during updating.
  15. we have a bank of kit that is loaned out. However! This is often seen as a poverty marker when we first started and most kids will simply kept "forgetting" their phone rather than own up to not having one. There is a downward spiral after this. It is a known issue in our school but since about 20% now use the loan system it isn't as much of a stigma as was.
  16. OK this will be fun for you. Here are a couple of thoughts (I was asked to look into this a few years ago). * legality. You wont own the machine, they do. Whilst you can say "you must install this if you WANT to use our services" it will be very hard to get a sign off on "you must install this AND use our services". You will get pushback from parents. I (for one) would not let my kids have overreaching admin software installed on their devices by the school. On a school device sure, a home one? No. * accidental damage. Your insurance may not cover this. ~Who pays for the machines if they are damaged on school property? It is one things swapping a 4 year old dell inspiron with a refurb. It is another when little joey has his ipad pro knocked out of his hands on the stairs. *printing. This is fun for multi device on a network that needs to be authenticated but also open. I gave up on this aspect and told people to print from USB after logging into the printer. *Virus outbreak. Your WIFI network will need to be set up accordingly so that interdevice communication is blocked (this should be a given anyway). One spod brings that unpatched XP machine into the school laden with malware (on purpose or otherwise) and you are going to have fun. *Filtering. This depends on your system. Again, you are on shaky ground mandating that pupils install a root cert on their devices, it is one thing saying "you want to use our guest network? Install this cert if you do" against "you WILL install this". After that you are going to be down DNS filtering and block other DNS at the firewall etc. That wont stop DNS over 443 of course. Kids do know about this to get round crappy home filtering from ISP DNS (my kids learnt how to set private DNS on their phones to bypass adverts on their manga sites!) * Software. Not everyone will have or want to install office - even if it is free. Not only that but you will get all sorts of personal vs business onedrive issues and syncing. Newer versions of 365 are better at supporting simultaneous business and home but older office is a bit of a nightmare. Mandating software installation will be problematic. Software in DT? Music? IT lessons? *MDM, see the first point for mandating an MDM be added to a device. This is pretty much impossible with IOS as true MDM management (outside simple app changes) needs full ASM support and claiming the device. Otherwise you are locked out of a lot of settings. If you must have an MDM that supports windows, IOSthen ManageEngine and Intune do. Chromebooks are better using google own tools but again you need to claim the devices. All the above will need paid licensing of course, chromebooks will need an educational google license too. *Monitoring software. I assume you run some sort of classroom management. See the above points on legality when mandating a device owned by someone else needs software installing. *Admin rights. The home user will always have admin or root. Whatever you put on could well be bypassed. *Maintenance and spares. Speaks for itself, you run WSUS, you run GPOS, you run scripts to make things work. Dont expect this from a home device. *Licensing. A biggie, they are on your network and you have mandated that they should have a device. A very grey area of enforcement. They will be laden with ASK toolbars, DRIVERUPDATOR2021, Torrenting software, WAREZ AND GAMEZ. How are you going to check devices are licensed properly to be on your network? You have the burden of proving authentication on a device in school in a work environment and has been mandated. These are not "guests" in the true sense. If you are a private school then the only way around this is putting something on the bill, owning the device and you controlling it not them. State school? Dont bother.
  17. I was asked to look into an app that can simplify the minibus walkthroughs, so instead of going through the paper logbook before a journey the drivers will use an app instead. After a bit of web searching I found something called STRIDA. Has anyone used STRIDA? Before I sign up (and get bombarded by sales calls for minibus leasing) I was wondering if it is only for people who lease with Castle or free for anyone. The webchat was unresponsive and I dont fancy the spam if I sign up!
  18. gen 4 i5s mainly onsite here. I still have a dozen core2 duos in daily use. W11 is the least of my worries at the moment.
  19. Is it a laptop? Is the laptop docked? Does it work if NOT docked (i.e. all cables plugged in manually)? If so, is it a generation
  20. does this email need to be saved in a mailbox? If not, just create a mail enabled universal distribution group in AD.
  21. Cheers, that was going to be the approach I suggested. Adding "other" periods mid term is generally not a good idea in isams though..... Another IT admin has emailed me with "sign in app" who I had never heard of. They only use it as a standalone system though, no MIS integration.
  22. TechMonkey - do you have multiple "other" registration periods other than your AM/PM registration periods in isams? I.e. Early (say 8:00 open till 8:40) and AM (8:41 till 9:10) then PM (13:30 till 14:10) and "after school" (16:00 till 18:00)? My thinking is simply separate reg periods to split the groups. I was reading https://support.isams.com/hc/en-us/articles/224860288-Ad-Hoc-or-Activity-Registers reference adhoc registers (we dont use the activities module) so would be stuck with either multiple registration slots (clunky and prone to killing isams stats) or hijacking "one of the other groups" which im not familiar with (we dont use tutor groups as suggested in the web page)
  23. We currently use isams for registration, one AM and one PM, opens at 08:30, closes 09:15 opens again 13:30 closes 14:15 form tutors take the register, late pupils to either go to reception for them to update the codes accordingly. We are looking for something for our 6th formers, they are allowed onsite much earlier and dont have to go to after school clubs but can stay onsite studying. Currently they go to reception, sign in a book and sign out of a book both before and after school. Ideally they would have a self service sign in option for a "before registration club" or similar. Im looking to make this electronic. We dont have the activity module in isams. Ideally I would like to link the solution to isams for a single "press fire register here" but accept that it might be a two system due to isams limitations. Ideally the following: 08:00 pupil comes onsite, "signs in" self service 08:40 pupil goes to form room and is marked present by form tutor. 09:00 FIRE! the register printed off shows pupil was marked present by form tutor (but may also show they are in an "early arrive club" and signed in at 08:00) This solution could also be rolled out so staff "sign in" and "sign out" (some cleaners are in very early and very late, currently they manually sign in and out via a book) ideas?
  24. depends on your licensing of course. We use the "Desktop Education" approach with a "free" M365AppsforenterpriseOpen on top of our A1. This was cheaper for us previously. For our next renewal I am looking at a different 365 license so will lose our office LTSC. For that reason I binned the idea of upgrading 2019 to 2021 and went from 2019 to 365 desktop instead. A completely painless approach with almost identical XML. Some minor oddities when a person first used the new office (it still came up with the old splash screens and the version still thought it was the old version but new functionality was there such as "publish to stream" and subtitles in powerpoint!) Since we were going from an x86 to x64 this also meant I could easily search for markers in our migration script. As for differences, 2019 does not have co author capability whereas 2021 and 365 does. 365 has publishing options that are not available to 2021 such as powerpoint publish to stream etc. All versions can use 365 accounts, 365 NEEDS the 365 account or you get a big licensing error. This might be an issue if you are hybrid and use local service accounts - they wont be able to use office apps (maybe exam accounts in offline environments?). It might be one to consider if you have exam account requirements as these will need office 365 connectivity to license now. If you do go with 2021 you can request a KMS key from MS and add it easily enough.
  25. depends on your licensing of course. We use the "Desktop Education" approach with a "free" M365AppsforenterpriseOpen on top of our A1. This was cheaper for us previously. For our next renewal I am looking at a different 365 license so will lose our office LTSC. For that reason I binned the idea of upgrading 2019 to 2021 and went from 2019 to 365 desktop instead. A completely painless approach with almost identical XML. Some minor oddities when a person first used the new office (it still came up with the old splash screens and the version still thought it was the old version but new functionality was there such as "publish to stream" and subtitles in powerpoint!) Since we were going from an x86 to x64 this also meant I could easily search for markers in our migration script.
×
×
  • Create New...