Jump to content

KK20

Members
  • Posts

    969
  • Joined

Everything posted by KK20

  1. if you like linux then squid and SARG would be a good idea. You can use an old crappy PC with 2 nics to do this easily.
  2. I had many many issues when I was changing over from IE7 to IE8 we use proxy.pac (FQDN config script) and wpad.dat in our DNS/DHCP. Automatic configuration failed randomly for some clients - no reason at all. I spent many days fault finding custom install folders in IE, DNS, DHCP. In the end I decided IE8 was crap, however, the proxy configuration script via FQDN always worked. so a few GPOs later and I was good to go. Check your GPOs, strip them down and have ONE that deals with IE configuration (per logon path that is, obviously one per forest would be unworkable for most people! but make sure each person only has one possible IE configuration GPO in their "path")
  3. My personal credit card is being used to purchase hosting and domain renewals (fasthosts). So far I have had no issues claiming back from the school. However I am deciding to move away from this idea. Does anyone know of a hosting company that will "invoice" instead (prefer UK)? What do other schools do? I would prefer to keep all renewals and hosting under one house for ease of admin. The hosting must be decent and not some "unlimited bandwidth for only £5 a month!" type affair that will bog down the moment a script it run. Ta.
  4. Are the users "ex 2003 outlook" users? We had a similar issue after I upgraded a few test PCs to outlook 2010. In the end I changed the MSP outlook install to "not upgrade existing profiles" which cured a very similar problem.
  5. wow. Has noone else come up against this? The only foolproof way of getting a clean 2010 for us (so far) is a complete uninstallation of 2003 before installing 2010. That and I replaced all the outlook 2003.lnk with "proper" ones on a startup script - then forcibly deleted all outlook 2003 .lnk from desktops and mydocs.
  6. We are rolling out office 2010 (replacing 2003). However, on a lot of staff machines there is a different MSP. This MSP installs 2010 but leaves 2003 in place - although groove and outlook 2003 have been set to remove (as they cannot coexist with the upgraded 2010 bits). however if a person double clicks an old outlook 2003 shortcut (which they copied off the start menu previouslyto say their desktop) this shortcut will kill the outlook 2010 installation - even though they arent power users or have admin rights to that machine. The only reliable fix I have found is a complete manual removal of 2010 and reinstall - simply double clicking an MSP isnt enough. Even then, that doesnt prevent someone double clicking their shortcut again. The original outlook 2003 shortcuts are "advertised shortcuts" and thus have installation pointers embedded. How in the name of 7 bells can I get old 2003 word & excel to live with 2010 without outlook 2010 being killed. My last resort is a manual search for .lnk on the profiles dir and order them/scan them for outlook 2003 links.
  7. If you have access to MVLS you can generally download XP install ISOs from there. Thats the ISO I used to use. We have moved over from XP to W7 in phases. The only downside is having two sets of profiles for everyone (mandatory so not an issue with profile migration between OS). Ref your original issue with desktops, if you DONT redirect desktops then the W7 profiles are .V2 profiles therefore different to the original ones - they DO NOT share between V2 and original. If you redirect desktops (which you should think about doing!) then I dont know - it works for us with mixed OS PCs (50% W7 after this summer, another 25% at christmas, remainder next summer). If the OS is 64 bit then you will need 64 bit drivers installing - on a 32 bit OS you can "push" the drivers from client to the server if necessary. Modern machines may well have no XP drivers available short of checking the website you may not be able to install XP on some machines.
  8. I have convinced the bean counter to give me another £300 for the venture and will be going down the hardware route. So far the vigor router has done exactly what I want it to do and it has "failed over" when the exchange had issues over the last weekend. So I have no reason to doubt a second one will do the same. It is a shame that TMG will only look at 2 WAN connections - it may be overkill but if I have 3 connections there is no reason why I cant failover onto all three if necessary (and just add the relevent MX weight in the DNS) Thank you for your replies though.
  9. openssh doesnt HAVE to listen on port 22. Indeed mine doesnt. Just change it to a port that IS open and forwarded on your network. Incidentally do you use FTP? FTP is far far more vulnerable than SSH, ask them can you have SFTP (which is SSH in a different coat) instead....
  10. I know that bit. Its the "backend" i'm working on. I am wondering what people have done at the backend to accept the second IP. Effectively they are both the same server but with different entry points. After more googling I havent found anyone who has used ISA to failover NICs reliably, so it looks like another vigor box when I can afford one.
  11. Description of the Wireless Client Update for Windows XP with Service Pack 2 Will this let you use the GPO on XP machines?
  12. sorry, I should have been clearer, it was directed more at beany (as you have a working solution). When I setup openSSH on server 2008 installing it wasnt enough, you need to configure it to your own domain etc. Hence me asking.
  13. 1) profiles are complex beasts. The teacher could have powered off during logging off. 2) you can set GPOs to delete locally stored profiles. install user hive cleanup then you can remotely delete without resorting to rebooting. Just store a "correct" profile somewhere and copy over busted ones.
  14. You cannot inplace upgrade 2003 -> 2010 so that rules a nice easy option out (plus you are using SBS so that wouldnt work anyway). You would install exchange 2003, patch, restore mailboxes from backups, install exchange 2010 then migrate mailboxes across. since you are using SBS then I would setup exchange 2003 on a different machine (just pressgang a desktop and put server on it!). Migration from 2003 -> 2010 is a breeze if you have "downtime" (which you have lots of!) In an emergecy you can setup a DC with the same details as your current domain (not on the network for obvious reasons) and install exchange 2003, export PSTs and reimport. Server 2008 can backup to a USB drive that can be restored to "hardware different" machines - that way you can do your backups and restoring on a "same domain" but isolated from the network thus not screwing up your new setup, I do not know if SBS can do the same.
  15. My priority would be securing a pay rise. Good luck!
  16. KK20

    Bad Caps

    It must be said that dell replaced GX270s and 280s well after their warranties expired. I found IBM to be shockingly poor when I first called them.
  17. Our connectivity is as follows; 1x SDSL connection and 2x ADSL connections. The SDSL is a 5 IP going directly to WAN side of ISA 2006. This is for our email, VPN, Web server and DNS server external requests. The ADSL connections go into a 3200 vigor 4xWAN router. The two ADSL are load balanced "UP" (WAN 1 & 2) and the SDSL on failover (WAN 3) if both the ADSL are down - the vigor pings "back" along each WAN to ensure connectivity to the internet rather than just ethernet link active. The 3200 is then the gateway for the clients (with filtering as a bridged proxy). however, I want to employ multiple MX records to ensure that if our SDSL connectivity goes down we wont lose out on our email. I am wondering what is the best idea, the cheapest would be to add another NIC and somehow configure ISA 2006 (I can install TMG if necessary) and connect this 3rd NIC to the DMZ of the vigor 3200. The more expensive would be to have another vigor box and "cross them over". I.e have a new vigor dual WAN box with WAN1 -> SDSL and WAN2 -> DMZ of the 3200 ADSL vigor then remove the SDSL from the WAN 3 of the 3200 to avoid a circular loop. I only plan on adding ONE of the ADSL external IP addresses to the MX record so that I can add a route for to the 3200 vigor for that ADSL line (although DMZ should take care of that anyway!) Bottom line. Can ISA failover a NIC based on connectivity (not simply ethernet link as the router would be live) such as ping. This will need to failover all external requests such as email, vpn etc and come back "live" once it has returned. Has anyone else done something similar? My guess is another vigor box so that all the rules in ISA simply send to its WAN side and the vigor decides which way that should go based on its own pings and routes. I would use the DMZ from the vigors in any case.
  18. Do you have any local policies that have been copied into default user? Local policies would still affect a domain admin if no GPOs override them. After you have logged out on the client, copy an ntuser.dat across from somewhere you know works (or from another admin)
  19. have you setup openssh to accept users for domain logins? Look at this guide here OpenSSH for Windows TBH I would look at ONE issue at a time. Get SSH working first *then* worry about RDP
  20. You will need to SSH over a port that is already open (i.e. already going to the server) then you can tunnel port 3389 on the client. It may not work if the firewall filters on protocol (thus blocking SSH). remote desktop gateway looks great but its 2k8R2 only ( Deploying Remote Desktop Gateway Step-by-Step Guide ) Can you get openSSH working at all?
  21. pull nib out, blob epoxy sparingly on sides, let it go tacky, push nib in. Worked on all of ours so far. @Sambob - Yeah, no PB2250 support though (small credit card size ones) the 5F.26J1K.071 doesnt work with the 2250 and the "wand" 2240 (though it some websites say they should - I was stung after ordering a pair) ones dont work either. Curse the previous guy who put those BenQ's in!
  22. Did you suspend VPNs? I suspect foul play or a severely corrupted AD database. If you have successfully logged in with an administrator account then either AD has turned very corrupt in which case it would be restore from backups anyway or someone has killed the account password. Obviously if you restore from backup you wont have an administrator account yet again (although the previous IT guy will have his account active again). Is anyones PERSONAL account a member of domain admins? Ntds.dit is the usual culprit of directory services errors. Since you havent reinstalled then the certificates on the server are still valid so if a backup exists then try copying that back over. TBH though you can either waste time cracking the admin account or start from scratch. I dont think you can reset the password in the same way as a normal windows machine as there isnt a local admin password on a DC. Domain controllers store their password in the AD directory - only after a DCPROMO demotion will you get a local admin password (having said that I have never used SBS therefore SBS could behave differently to a regular DC server) Not nice but you arent a miracle worker!
  23. BenQ remotes are like gold dust. PB2250 remotes (at reasonable prices) are near impossible to find. If anyone knows of a good "universal" remote that will work then i'd be grateful. I like the remote recoiler above - I'm tempted to put promethean pens on one (dont get me started on the nibs going missing. Epoxy is your friend)
  24. KK20

    Bad Caps

    Bit of a grave dig but it may help some people. We have some lenovos that started to behave oddly - maybe 6 months ago. Since they are well out of warranty (at least 2.5 years old) I did a bit of looking around. There are only a few caps (4) on the boards that had blown on ours so I simply bought some caps (1000uF 25v about £30 for a big bag of them from Farnell) and soldered them on. These were worth salvaging IMHO as they were all reasonable dual cores. The trick is to use pliers to PULL the old caps off. The old capacitor legs shear internally and you can solder onto those "stumps" thus avoiding messy SMT soldering - also some caps are most certainly multilayer soldered so you cannot simply desolder and remove. The most difficult one was inbetween the PCI slots. No issues at all since.
×
×
  • Create New...