Jump to content

KK20

Members
  • Posts

    969
  • Joined

Everything posted by KK20

  1. KK20

    RRAS query

    Well I gave up on RRAS doing the routing. I set up the RRAS box to simply VPN and disabled the ipv4 routing portion. I then added a virtual port onto our firewall and let the firewall do the routing (and ACL). All works now. I have no idea why RRAS wouldnt route between 2 NICs in this case.
  2. KK20

    RRAS query

    Minor error, the NAT from public IP should have been 10.1.1.140 (i.e. NIC#1 on RRAS box) silly fingers... NIC#2 guest LAN is an isolated LAN btw, no internet (as yet) though I could VLAN it to the firewall if necessary (i'd rather not though)
  3. KK20

    RRAS query

    I must have missed something, can someone cast their eye over this setup? We have a LAN on subnet 10.1.0.0/16 (GW 10.1.1.254) and a separate guest LAN on 10.11.0.0/16 Our RRAS server has 2 NICs- #1 10.1.1.140 (GW 10.1.1.254) and #2 10.11.0.140 (no GW) VPN has ipv4 set to pull its DHCP from the scope on NIC#2 pool (10.11.0.0) The firewall appliance takes a public IP and NATs it to 10.1.1.240 clients can VPN in and they get an address on 10.11.x.x correctly, the connection policy works fine - only people "allowed" can get on. They can see other PCs on the 10.11.0.0 subnet but nothing on the 10.1.0.0 subnet. I thought that perhaps the "GW" 10.1.1.254 might need a route to send 10.11.0.0/24 onto NIC#1 but that didnt work either. I thought RRAS would be able to route naturally since it has both the NICs. I must be missing a route somewhere, can anyone see where it is?
  4. We cant afford SCCM which is why im looking at this. Do you find any conflicts with installations running concurrently? Im thinking WSUS and AV possibly running at the same time as WPKG trying to fire off an install.
  5. I already use FOG to deploy our images. WSUS is great for patches but plugins to maintain software cost a fortune (and ive only really seen one company promoting this). I was looking at WPKG (WPKG | Open Source Software Deployment and Distribution) for software deployment and wondered if anyone used it? Any advice before I embark? Currently I simply use GPO to update and remove software - scripts mainly. I was wondering is WPKG is a better idea overall (from the point of view of people who used it vs GPOs)
  6. No issues for me. Our 2k12 "file server" (profiles and shared network drives) is fine. No issues on our exchange, WSUS or DC. I did have a very similar issue with out WSUS 2k8 server some time ago. This server would work if I used the IP address but not "servername" in the UNC. I cannot remember how I resolved it but I have a feeling it was either DFS (in that implementing DFS made it go away) or DNS related.
  7. We are a lot smaller - 5 servers. I took the opportunity at easter this year to virtualise onto 2 clustered r610s with bags'o'ram'n'CPUs ™ + MD3220 . I migrated 4 servers, exchange, sql, fileserver(profiles + shared drives), "other" (DC, WSUS, etc) from physical to virtual and left one on 2k8R2 as a physical DC (with FSMO roles). 2k12 went smoothly; spent easter setting up SAN and host + guests, then migrated fileserver and one DC. Over summer another week moved exchange and SQL. Since I still have the old hardware I am going to start them up again on a segregated network (still outside tombstone life so they should start up ok) and see what would actually happen if I inplace upgrade to 2k12 from 2k8R2. I have never done an inplace upgrade so it would be interesting to see what would happen. For backup we use both windows backup within the guests (for data recovery) using virtual drives and "backup assist" on the host for disaster recovery. A pair of mirrored openfiler boxes using consumer IDE drives stores our backups.
  8. you could use the same GPO to remove logoff and shortcut a powershell script containing: logoff;exit powershell to restart is restart-computer btw
  9. how is SSL webdav insecure? It is no more insecure than any other SSL. WebDAV without SSL is insecure as you would be sending your credentials in clear. The same can be said for FTP etc. I have a feeling windows wont connect to a non-SSL webdav server. This is the guide I used to set up webdav on our server. Staff loved this as it meant they could map a drive external to the school. Installing and Configuring WebDAV on IIS 7 : The Official Microsoft IIS Site whilst our webdav works on android phones (my own at least), windows clients and apple macbooks I have not tested 2 way webdav via apps on ipads (the web links work fine for read only access on ipads but there is no reason why they wouldnt - it is an extension of a normal HTTPS page afterall). We use webdav links a lot in our moodle VLE (mapped to shared drives within the school perimeter). I was never able to use the webdav moodle plugin, it simply never worked.
  10. Accidental shutdown is quite odd though. Even if you press start->shutdown you still need to type something into the "reason" box before the button activates. The worst culprit for accidental reboots is the "restart" option on windows updates. That is the only time one of our minions accidentally rebooted the exchange server during the middle of the day... If you make this change to the GPO can you still shutdown from the CTRL-ALT-DEL screen?
  11. I had assumed that W8 KMS would have a different count to W7 so I would need to KMS 25 W8 machines. After looking this up I was incorrect so I will KMS from the outset. Our KMS is 2K8R2 and I havent patched it for W8 yet (but have for office 2013). The laptops do have the stickers and I hadnt noticed the colur difference for home/pro. Thank you for pointing that out (the one I was going to build as a test is a home so if there are any issues with using my EES KMS for a "home" SLIC BIOS i'll report back. We do use a mixture of consumer and business on our network. Why? As part of our 5th form IGCSE they build a PC as part of their projects (the pupils have a budget and purchase the bits and build them - normal PC bits from SCAN). These PCs get added to the network along with the rest with the same image. I have not had any issues with W7 KMS though, if I start having with W8 KMS then great, that will cheer me up...
  12. New Toshiba laptops with W8 pre-installed. I had various types, some had home, some PRO. When they arrived I disregarded W8 as we have a perfectly functioning W7 image that everyone loves. W8 training would make my life hell so W7 it was. EES lets us downgrade a properly licensed PC (which they were) so away I went. Now I would like to trial messing about with W8(.1) and see how bad it would make my life. I picked the nearest spare laptop I could find which happened to be one of the toshibas that had W8 to begin with. However, I couldnt find a COA (none in the battery bay, under memory bay, none on PSU etc). This initially distressed me, no COA had me thinking of auditors dragging me away in shackles. However reading up on Activation 3 left me semi-safe in the knowledge that the BIOS tells W8 that it has a perfectly valid installation and key, im still not happy that a quick glance would appear to show an unlicensed laptop (albeit a small w8 sticker that would show me otherwise). That being said, how can I tell what VERSION or W8 this laptop will had? How can you extract the info? As far as EES goes personally I dont care as I can happily use W8pro if need be and use our VLK MAK. Im assuming that in any case I can use slmgr /ipk and /ato to manually add our EES VLK MAK as appropriate (until I get the client count then i'll /ipk our KMS key) or will the BIOS try to override this?
  13. What is the guest OS? Can you backup the guest from within and restore the guest to a new fresh VHD (or physical)?
  14. Im costing TS/RDP which will be for tablets/devices connecting to our network. Hardware aside im now looking at licenses. We have EES currently. The tablets/devices will be issued to the students with a number of extras in a pool as spares. How will this work with EES? Is the "per user" calulated on our FTE EES burden or on TS users? (since we will have extra devices "per user" seems more logical). There WILL be external access by the users (only users on our network) so im not sure if we need another external connector (I dont intend using our TS server as our existing web services server that has an external connector). On this thread here http://www.edugeek.net/forums/thin-client-virtual-machines/124216-terminal-server-rdp-server.html there was mention of 6VC-01518 WinRmtDsktpSrvcsCAL ALNG LicSAPk OLV E 1Y Acdmc Ent UsrCAL £3.06 each Is this suitable? Thank you
  15. whether you CAN and SHOULD snapshot a DC are different though. I suppose if you are only playing about (and have one DC) then snapshot away. If you do ever plan on VMing your DCs then it might be a good idea to have a physical one (with GC at least) just in case.
  16. I'll answer my own question for anyone else who was wondering. Loss of consistency with IDE-attached virtual hard disks when a Hyper-V host server experiences an unplanned restart This patch addresses the caching issue. It seems that because you cannot disable caching in hyper-v then AD could fall to pieces as previously a guest would get a spurious answer after requesting caching disabled (but in actual fact it had not). As long as this patch is installed (I suspect the DC would need to be promoted AFTER this patch) then all will be well - the host will actively refuse to disable caching for the guest, the guest will warn in event log and continue to save without caching (rather than blindly assuming that caching has been disabled).
  17. Just as an additional to what john has already said. Thats 2VMs and 2 CPUs per 2012 server (standard) license (enterprise is just gogogo for VMs). So if you have a 2012 standard licence that is currently supporting a host with 2 CPUs then it can have 2VMs (thats windows server VMs - you could have another dozen linux ones if you so wish). If you have an additional licensed 2012 server sat around then virtualise that one and transfer the license to your host - now you can have 4VMs and 4 CPUs on that 2012 server (magically transforming your single extra physical server server into 2 VMs). It does depend how many 2012 licenses you have purchased (you might have 2 licenses already but only 3 VMs so you are covered for another VM etc).
  18. Came across an interesting issue. I was helping someone migrate from P2V using the same method I did however they want to P2V one of their 2 DCs - I left both of mine P for the time being. After looking at best practice it seems the most foolproof was to bring online a temporary physical server, promote to DC, demote the "to be virtualised" then backup/restore before promoting again when running virtualised (then demote the temporary one when happy). Windows backup/restore has worked for all our servers when I P2Vd and it left us the possibility of bringing the old one back if something goes wrong. Looking at the best practice it seems that you should use a vSCSI disk for the AD directories to avoid caching anomalies on the IDE controller (there is a KB update that mitigates this for 2k8R2 and 2k12 but the best practice papers still say use IDE mounted disk not SCSI). However, how can you restore to a scsi host disk from windows restore? I couldnt get a driver to work that would allow the 2008 disk to see the SCSI disk does anyone know which driver to use? In this instance what would you do for a bare metal restore (from a regular windows server backup) in these cases? If you cant see a vSCSI disk in windows restore then that makes windows server backup is next to useless... Host is 2k12, guest is 2k8. Or are there people happily using a 2k8 (notR2) guest DC on 2k12 host? No caching issues?
  19. Our terms state 12 months notice for termination after 3rd anniversary so they have stuck to the terms.
  20. Just an update, the sonicwall is probably expensive for what it does but it works for me. A few VLAN issues that ive had to work around but overall it has worked perfectly. If I had to do it again then yes, pfsense will do the same (loaded up with NICs of course). I went for an NSA 2400 in the end. MS VPN using SSTP only as we only use windows devices. Stuff the ipads... (sonicwall wanted money for VPN clients, I dont think so.)
  21. I dont want this to turn into a tit-for-tat but scholarpack does not do what we want from an MIS point of view. I'll happily take it to PM if you wish as I dont want to derail the thread.
  22. 15k to move elsewhere (other than RM) doesnt grow on trees though.
  23. E1 customer (year 3 out of 5 on a contract). Telephoned E1 support to find out what is happening and if there is truth to the matter, person who is dealing with these queries will telephone me back. I found out by iSAMS contacting me! I will need to look through our T&C ref breach of contract as changing mid year is hardly ideal.
  24. basically extending a backbone to a different site (over some roads and across a patch of land that cant be dug up!). Cheaper than getting fibre WAN in by a long stretch. We wont be going many KMs but smaller rockets weren't good enough (I suppose I could have LAGd them)
  25. New toys. Cheaper than cabling over roads (and fields down to the pavilion)
×
×
  • Create New...