Jump to content

KK20

Members
  • Posts

    969
  • Joined

Everything posted by KK20

  1. After looking at all the options I wont be virtualising. I will still be sticking with the 2 server (+1 firewall) approach. The cost will simply be too much for the small gain achieved as I would need a decent external storage unit of some description (almost the cost of a small server) and a decent core switch for the storage and server to sit on (although a direct link was a possibility in the short term via a dedicated card if iSCSI was to be used). I wasnt able to find any realworld data on raw access speeds for iSCSI as a principal for a virtualised environment but I suspect it is as fast as a bonded connection would allow + overhead.
  2. Thank you for taking your time to reply. Although it will blow the budget I will need a centralised storage. Because of our size a SAN will be overkill. We only have circa 1 tb of storage between both of our servers in its current guise so a small iSCSI would be best. The irony is, it will need numerous decent quality drives in there due to the flogging they would get being shared between 2VMs + failovers - as opposed to the RAID 5 76gb 15k SCSI living in the servers at the moment. what a can of worms I have opened
  3. One good idea you have all pointed me towards is snapshotting. I could snapshot the VMs to an iSCSI SATA box which would help recover the system (not necessarily data) in a failure. That at least is better than I have now. I would also gain the current physical PCs The idea of virtualising was my old training of keep exchange away from the DC wher you can. Since I have the money to replace 2 machines I was thinking about replacing with one bigger machine I dont think I can afford a SAN + required card on top of this. I wont have failover in any case - hardware failure (or mad RAID collapse) would kybosh the system - we simply arent a big enough school to afford redundancy. Although I would have the 2 poweredge 2800 servers that I will be retiring. -neilfisher- Your iSCSI NAS - what type of drives do you have in there and is it fast enough for you? Do you mind me asking what type (make) of NAS is it? I trust my openfiler RAID 10 (or is it 01, I cant remember now) SATA box with backups but I wouldnt trust it with live data (redirected documents so I dont think SATA or nearline SAS would cut it!) so a dedicated (for example Dell equallogic) box will be more appropriate (if I can shoehorn the money!) -anyone- how does hyperV handle snapshotting. Is this via the hypervisor or is each VM expected do snapshot itself? I am looking towards the bare metal hypervisor (free one) both VMS will have 2008 on there. I am not sure of the terminology but could I automatically replicate a virtualised setup from my NEW hyperV server to a cluster of 2 old servers? Or am I barking up the wrong tree. My thinking is to utilise the old 2 servers as a failover. This means that I *will* need a SAN/NAS iscsi arrangement rather than a new server full of drives. I still think that single box virtualisation is the way to go for me with perhaps the option of a clustered (but still woefully slow) backup. Lets see how my core switches can handle that traffic
  4. If we lose any hardware we are hosed (from an operational not backup sense) anyway as both servers are symbiant of each other due to the horrific infrastructure I inherited. DFS was not meant to be abused in the way it is..... Anyway I digress. I would be virtualising purely to move three big boxes down to one - space, power, heat. The more I look into it the more I think stick with extra boxes rather than a multicore with heaps of RAM.
  5. I've looked at some threads in here reference virtualisation but I have a few questions from the learned amongst you. We are a relatively small school, 200 PCs and 3 servers (1 firewall dedicated, 1 DC with IIS and SQL, 1 exchange) Ive been given enough cash to replace 2 of them but I was thinking about simply purchasing one and virtualising . Is it cost effective to simply virtualise into only 3 machines? The machines at the moment are all dual xeon (old 2.8's) so any quad core would blow them away even taking on the load of 2 + firewall. I dont plan on running a SAN as I will simply stuff SAS drives into the new box and RAID1 them. We have software assurance for the 2003->2008 (r2?) upgrade (and the SQL, exchange and ISA) and I think hyperV comes in 2008? I guess it would be a case of loading the 2008, virtualising it, keeping our 3 server licences and away I go? I know I will need new more expensive CALs over my 2003 ones. Has anyone virtualised on a small scale? Was it cost effective or should I simply buy 2 separate boxes (and leave the firewall box alone - its plenty powerful enough)?
  6. I would say that OpenDNS for schools is quite limited - unless you operate a pure whitelist operation (even so the free version will run out of domains quite quickly). Personally I would look at Dansguardian and squid. Its free, can get you going and if you arent as geeky or tech savvy as other people then there are commercial grade alternatives (such as smoothwall) There are cheap blocklists available for DG and it is fairly intuitive.
  7. I can recommend clonezilla but be careful if you have bad sectors on there, most duplicators bug out when the source has bad sectors.
  8. KK20

    ipsCA Global CA Root

    I suggest rolling out the root cert pack listed above.
  9. I am thinking about an SA but cannot make the numbers add up. We run 'select' at the moment. SQL, 4 servers (currently 2003 but moving to 2008), Exchange (2003 but 2007 once the server is x64 2008), ISA 2006 approx 220 desktops (all XP) with CALS for above, office 2003 pro (moving to 2010 as and when) with individually purchased copies of project for a handful of PCs. Now, as I see it it isnt beneficial for me to switch to SA unless I plan on moving all my XP machines to windows 7. I dont have SCCM so I can see this being a major PITA unless I see a major reason for doing so. I dont think I have the machine numbers to justify SCCM either which is a shame as I imagine it would make things easier for me. Looking at other peoples prices on here I would cost circa £6k whereas I only pay 5k at the moment. I do have the option of buyout which I may get a price on this year. 1k to rollout 220x windows 7 is a good idea but do I really want to go through that hassle. Natural desktop replacements will now be specified as windows 7 so im not convinced. Oh decisions decisions.
  10. you wont have an audit trail if the supply teacher does something silly. I'd say it is better for you to walk them through the registration rather than reset someone else password and give them their credentials.
  11. serif is a monkey for killing our profiles. Heavy users of drawplus (x2) seem to have the most profile corruption. Sometimes simply deleting the application data of a users profile fixes it (looking at the serif errors it seems to get into a recursive loop looking for something in the application data until the filepath exceeds the maximum) Dont assume that it is always ntuser.dat (as we use ntuser.man for our pupils) simply delete and copy as appropriate.
  12. software raid 5 does have its uses. The fact that it doesnt rely on a controller chip therefore can be swapped between OS following hardware failure does have its uses but im arguing a moot point as I agree with you wholeheartidly. Raid 5 sucks. Use Raid 1 (or 10/01). A cheap AMD board typically has 6 SATA ports on them nowadays so they can make mighty cheap backup boxes. Put that to the fact that modern SATA will hotswap (with a cheap hotswap 3 in 2 drive bay to you only need a 4x 5.25 slot case to fit 6 drives in). Anyway, I think im derailing so sorry!
  13. Dont forget your file system on the drive counts. You should be able to create plenty of iSCSI targets but only one machine will connect to each target (as intended). https://forums.openfiler.com/viewtopic.php?id=838 will give you more info.
  14. dont be too proud of this technical terror The damned problem now is that after killing blogging sites I now need to open some up for the A level Artwork. Damn! Thats ANOTHER group I need to create for DG. Dont get me started on i-GCSE ICT and their live practical exams.
  15. Be wary of freenas raid 5 if you decide to go down that route (not that I recommend raid 5 in these cheap drive times). A quick trip around the forums reveals many issues with freenas raid 5 (a breakaway from its parents openfiler raid 5)
  16. as an aside. Our buffalo NAS also died. I can heartily recommend openfiler as a replacement if you have a spare machine packed with drives.
  17. A quick wbinfo -t will tell you if the machine is still trusted and a wbinfo -g should pull a list of AD groups if it is. If these commands work then the machine is still part of your domain. I would consider removing the machine from AD then adding it again sans reference to the 2003 machine. That way you know it is part of the AD forest without the 2003 machine there (although technically it shouldnt matter). Dont forget to check your /etc/resolv.conf to see if the 2003 box is the only nameserver on there as you wont be able to resolve the names of the new boxes without the 2003 box in this case. Make sure there arent any fancy references in your HOSTS file pointing to hardcoded addresses on the old 2003 machine.
  18. An odd issue with DG webmin (Webmin Module Version 0.7.0beta1b). I can view/edit a groups filter list, click on the appropriate group and click on the relevent list file (such as /etc/dansguardian/lists/bannedsitelist) this will then allow me to add a site and save as appropriate. However. If I state a different file in the base configuration of a particular group - such as pointing "Exception site (domain) list" to say /etc/dansguardian/lists/pupilsexceptionsitelist then I cannot edit this file in webmin. I simply get "You are not authorized to change this file - you will be limited to only viewing this file Expected location: /etc/dansguardian/lists/pupilsexceptionsitelist" The lists work in DG - they act as exceptions just like I assumed they would but I would like to edit them in webmin rather than drop to putty. I initially thought permissions, so I did an ls -l on the "lists directory" but that didnt help: -rwxr-xr-x 1 root root 5285 2009-11-17 15:50 bannedsitelist (works and can be edited in webmin) -rwxr-xr-x 1 root root 1458 2010-01-13 14:48 pupilsexceptionsitelist (works as a filterlist but cannot be edited in webmin) I must be missing something but i'm darned if I know what. Any ideas?
  19. our exchange server (2003) is a dual 2.8 xeon with 2g ram on x86. Hardware raid card with 8 72g 15k drives. This setup is ancient by modern terms but runs perfectly fine for 500 users. It is also our print server running print manager plus (SQL on a different server) and our general shared resource drive too. Sure the cpu usage is 70% most of the time but everything works just fine (solarwinds is permanently in the yellow on CPU utilisation but it rarely hits red). 2g of RAM would make this a fine backup server (which is what it will become) I plan on upgrading to an 8g ram, quad core over the summer and putting x64/2008 and exchange 2007 on it. I'll see what "europc" have in stock rather than hunt for a certain spec.
  20. KK20

    ipsCA Global CA Root

    An update as sorts. The staff who use firefox are savvy enough to not care about the certificate after I explained to them. The staff who were having issues (all XP) were given the november certificate update pack from microsoft and told to install. None have returned with issues. One thing I have noticed is that it has thrown peoples mobiles out. My mobile refused to accept the new root CA so I needed to actually install the root cert before OMA and sync worked. The same thing for the blackberrys, they didnt seem to want to talk to our exchange server either so again I needed to import the root CA. This was only for our SMT (and me) though so not a major issue, however, if you use mobile devices around the school - be aware that you may have issues. Internally I distributed the cert pack via WSUS. I have no idea why I.E. was not picking up the certificates internally - I *suspect* that WSUS prevents this as squid or DG has not picked up any traffic (from one of my test machines) when I tried to access the seemingly untrusted root CA, hence me needing to keep up to date with the cert packs on WSUS. In any case, i'll stick with ipsCA for a while, simply because it works for what I want it too at the moment and since im moving our exchange server to x64 2008 and exchange 2007 over summer I would prefer a free wildcard certificate to a cheaper godaddy UCC cert.
  21. I paid on CC for godaddy then got the cash from petty cash (via our bursar of course). I was unable to use a PO with them after much communcation. I have been badgering our school to organise a paypal account - even if it needs to go through the bursars assistant to actually do the ordering. Ross- if you are still having issues, start a new thread and i'll help (save derailing this one). Feel free to hijack mine - as I sorted ours out (in a fashion) http://www.edugeek.net/forums/windows/47364-ipsca-global-ca-root.html
  22. The same as Tyiell here. I used to use a fortinet box which was as much use as a chocolate fireguard. Switched to dansguardian and squid and havent looked back. If I was allowed to spend money then I would have gone smoothwall but hey, being the only linux guy here it keeps me in a job. A good tip is to have a group in dansguardian that is super restricted (we operate a whitelist only group for unauthorised connections - great for guests). That way I can dump the miscreants into the restricted internet group giving them no freedom to do anything naughty. Echoing the same as everyone here - you need something that will have weighted scans or phrased scans not just blocklists.
  23. how are you blocking it? What software are you using? Can you "monitor" (VNC et al) someone going on facebook and watch what they do? Get a "stooge" to help Are they going directly onto facebook? Can you check the internet logs for a specific person at a time they were seen going on facebook?
  24. It all depends on how you do things. I would (personally for my situation) say that for flexibility I would go the 2 NIC route initially. I would put the DG box as follows: external router -> DG -> (ISA WAN connection) This will give you the advantage of having a filtered bridge forcing all traffic through your DG box. I assume that at the moment there is no filtering hence the clients can pass happily through your ISA server? That way you need to configure the DG box only and leave the ISA box alone. It also means that you dont need to change gateways - only add proxy rules (GPO, WPAD, proxy.PAC etc etc) and any clients that are simply added to the network will still need to go through the DG box. If you dont care about giving different levels of access then you could transparent proxy the box needing nothing configuring on the clients! Horses for courses though. I would say it is no harder to set up a 2NIC than a 1NIC box. My first 1NIC was soon ditched as it was too easy to bypass the DG box with pocket opera etc. Dont forget to get an extra CAL for your linux box
  25. KK20

    ipsCA Global CA Root

    seems odd, I had a random email almost immediately about "It was not possible to connect to a Whois Server". Then another email the next day asking me to agree to terms, shortly after the new certificate was included as an attachment.
×
×
  • Create New...