Jump to content

Bruce123

Members
  • Posts

    432
  • Joined

  • Last visited

Everything posted by Bruce123

  1. Thanks that explains it, we are running the latest IDEX agent on our DCs but our appliances are on Leeds-72. Does that mean we should make the registry change for compatibility with our Smoothwalls?
  2. Does anyone know what ports the IDEX agent uses? Smoothwall docs say 2948, but we are also seeing 2949 in our internal firewall logs. Thanks, Bruce.
  3. Hi all, We have a QNAP used as an iSCSI target and a user/customer is experiencing performance issues when using InDesign to load and save files (like 60 second delay when opening or saving or worse) But when we/they do a test transfer of a large ISO file (to and from) we're getting close to 1Gbit transfer rate (and the total sign of the InDesign file including images etc. isn't that big). So we're not sure what the root cause of the performance issue is or how to address it. Currently the link from the HyperV server to the QNAP is 1Gbit Ethernet cable (not going through switch) and we plan to replace this with 10Gbit. But having checked the utilisation of the port, it never seems to max out, so I'm not certain this is where the bottle neck is. The QNAP TS-EC1280U is fitted with 12x 8TB HDDs as RAID 6. I am wondering if the issue is with the QNAP itself and it just doesn't have the performance (IOPS, memory, CPU, effective seek speed) to meet their requirements (at least how it is currently configured RAID, HDDs etc). When the user saves locally or to a VM hosted on an HP SAN, they don't experience any issues (but we don't have the space on the SAN to store the files there - 7TB required). Any advice would be appreciated? Kind Regards, Bruce.
  4. Hi all, We're using VEEAM BR 11.01 to backup the VM(s) on a standalone not domain-joined HyperV host. Does anyone know if it's possible modify the IP of a standalone HyperV host without having to create a new backup job and start again (with it having to do a full backup - separate from the existing backups)? The HyperV host was added to VEEAM (under managed servers) using it's IP and this isn't modifiable from the GUI. There is some guidance on modifying the IP of a managed server using the VEEAM PowerShell, but this seems to only apply to VMWare (and when I tried using the same command for the HyperV host it refused). Re-doing the backup isn't feasible due to the time and storage required (7B of data). Any thoughts appreciated? Kind Regards, Bruce.
  5. I was going to update this thread anyway. The Issue was that I had clicked Update Firmware, but hadn't clicked on OK (on the Nodes tab) of config window (I must have waited and waited for the firmware to upgrade and given up and clicked Cancel). When I went through it again I clicked OK and a dialog box popped up to say the Net2 service would be stopped to allow the firmware upgrade to take place. After I clicked OK it actually initiated the firmware upgrade and rebooted the controllers. We also found that we needed to click Re-instate in Net2 to push out the config to the controllers (as per advise earlier in this thread - this can be found by in the main Net2 application, select Doors and click on Re-instate). So if you don't recall a dialog box asking if it's OK to stop thee Net2 service, then it's probably because you didn't click OK. I hope this advice is useful reaches you in time! Thanks, Bruce. PS You might have to start the Net2 service manually afterwards - right click on the triangle on the task bar.
  6. BUMP. After going from 4 to 6 the controllers are stuck on "update pending." Is there anything we can do to force the updates to apply (and controllers reboot)? I have already selected each node in the configuration utility and clicked Update firmware. Also, I notice that each node information it now shows 6. In Net2 itself all doors are shown with red crosses. I seem to recall an engineer saying Net2 tends to schedule the controller reboots out of hours (e.g. during the backup schedule) to minimize the interruption (not sure if during the reboot it leaves the lock open or closed). Thanks, Bruce.
  7. Thanks, I did come across this, not had the chance to read it yet though.... I'll start reviewing it today. If it turns out to be impractical due to the work/costs involved, then we may end up using PSK for a while. Thanks, Bruce.
  8. Hi, We have been issued with a ton of laptops which are currently AzureAD joined and managed with InTune. We want these laptops to be able to connect to our WiFi using 802.1x machine cert for authentication (rather than user 802.1x or PSK). All AD joined devices automatically have a unique cert pushed to them using Group Policy and certificate services CA, but the laptops are not AD joined. We know we can push certs out using InTune, which we are already doing for a Smoothwall Cert. But this requirement is different as for 802.1x (I assume) we need a unique cert for each device, and would ideally be issued from our on prem CA. Does anyone have any thoughts? Or could we potentially issue one cert for all of the laptops? This may be a security risk if the cert gets lifted from one of them. Any help is appreciated. Kind Regards, Bruce.
  9. Hi, We have been issued with a ton of laptops which are currently AzureAD joined and managed with InTune. We want these laptops to be able to connect to our WiFi using 802.1x machine cert for authentication (rather than user 802.1x or PSK). All AD joined devices automatically have a unique cert pushed to them using Group Policy and certificate services CA, but the laptops are not AD joined. We know we can push certs out using InTune, which we are already doing for a Smoothwall Cert. But this requirement is different as for 802.1x (I assume) we need a unique cert for each device, and would ideally be issued from our on prem CA. Does anyone have any thoughts? Or could we potentially issue one cert for all of the laptops? This may be a security risk if the cert gets lifted from one of them. Any help is appreciated. Kind Regards, Bruce.
  10. Does anyone have any experience of moving a school's Internet/filtering from being supplied by ICT4Leeds (formally Leeds City Council), to our own Smoothwall/Internet connection? Filtering is done using on on-prem Smoothwall appliance (managed by ICT4Leeds) and Internet is via a 100Bit broadband connection (VirginMedia). We understand that the on-prem Smoothwall appliance is setup as a child node which receives policies etc. from an off-prem parent appliance managed by ICT4Leeds. We also understand from a recent conversation with ICT4Leeds that the broadband connection isn't a simple a vanilla Internet connection but is actually a connection into their WAN and moving forward we wouldn't be able to utilise this as an Internet connection with our own Smoothwall. So I guess to move away we're looking at having to have a new broadband connection installed? There is, of course, the existing contractual agreement with ICT4Leeds that we would need to look at. Any advice is much appreciated. Kind Regards, Bruce.
  11. Hi, We a MAT with 3 academies and 2 RDS servers in a farm. We want staff to be able to run any of the 3 instances from the RDS server. We are aware of the changes that can be made to the connect.ini file to allow the user to select the instance from a drop-down menu after opening the SIMS client, but we could not get this working, the dropdown menu would not appear. So what we have done instead is share the SIMS.net folder on each SIMS server and create 3 shortcuts on the RDS server, each pointing to the pulsar.exe on each SIMS server. This seemed to work fine on testing, but the MIS managers have recently reported that the Exams and NovaT modules won't load. The error message is about incorrect connect.ini version. Does anyone have any thoughts on this or have a resolution? We could revisit the multi-instance setup, but one downside is that whenever an upgrade is due, we would have to ensure that all 3 SIMS instances are upgraded at the same time, otherwise the client will report "incompatible database". And at the moment, we stagger the upgrades. Kind Regards, Bruce.
  12. Hi all, I am just wondering what the expected behaviour should be if the outgoing interface of a static route goes down (or the next hop address is unreachable)? E.g. ip route 10.10.10.10 255.255.255.0 1.1.1.1 Where the local outgoing interface goes down or 1.1.1.1 won't respond to pings (which is an obvious consequence of the former), will this static route removed from the effective routing table (as confirmed by show ip route)? And is the behaviour consistent between vendors (e.g. HP / Cisco)? Kind Regards, Bruce.
  13. Can they not form an adjacency without advertising the ‘link’ network? I.e. As long as OSPF is enabled on the ports they will learn about each other using multicasts?
  14. Hi, I just have a quick question regarding OSPF and advertising networks, that I hope someone could assist with? There are 2x layer 3 switches (OSPF routers) connected together via a link (all in the same OSPF area including the link itself). Obviously, the link (IP) network exists on both layer 3 switches. Which layer 3 switch should advertise the network, one or the other or both? The backgroud to this is that under the proposal we have 3 switches; Switch1 has several IP Networks/VLANs defined (the core for the site) which are advertised into OSPF area 10. The link to Switch2 is using a network already defined on Switch1 (10.0.0.0/24) and is used for various hosts. Switch2 connects to Switch3 (at another site) as area 0. So, my question is, should the network 10.0.0.0/24 be advertised as area 10 by Switch1 or Switch2 or both? If Switch1, then it would leave Switch2 not advertising any networks at all (other than into area 0), leaving no actual management IP address for the switch. [switch2]---area 0---[switch3] |10.0.0.254 | | area 10 | |10.0.0.1 [switch1] I hope that makes sense? Thanks, Bruce.
  15. Hi, OK, I guess this one must come up quite often. But one of users have said said their team is working from home and can't afford mobile phones out of their budget. Can Skype or Teams be configured to support standard telephone numbers? Not sure if this is for receiving or making calls... We have cloud / SIP telephone system (Avaya), but I don't know if the numbers have to match these. Can MS supply spare DDIs as part of the agreement? Kind Regards, Bruce.
  16. Not on the Windows 2016 server I wouldn't have thought? When I installed RRAS I didn't tick NAT. The SM only has private address(es) [RFC1918] as we have public IP addresses on the Firewall [Watchguard] I'm just using the IP public at the moment. But when testing internally we used its internal IP. Not yet, but I don't know if SM is the issue. Certainly, outbound SM just passes through any non-web (80/443) traffic to the firewall, so I am hoping that inbound it will do the same. I am considering SSTP (whatever it's call VLAN over SSL) instead as it just uses 80/442, but want to try getting L2TP/IPSec working first... Thanks, Bruce.
  17. Hi, I'm trying to setup VPN on Windows 2016 to allow users to connect remotely (via VPN). I have installed RRAS role and configured it for L2TP/IPSec as per guidance online and a rule has been setup on the firewall to forward the traffic to the server (SNAT). On testing, it works internally (internal client Win10 and Win2012 R2), but we can't connect in remotely (from home). The firewall rule is identical to another rule we have to pass through L2TP/IPSec to another server (Mac), so by that logic the rule should be OK. Also, we have an inline Smoothwall proxy between the firewall and the rest of the network (the VPN server). Does anyone have any ideas what the issue could be? Kind Regards, Bruce.
  18. Thought that was probably the case, but wasn't 100% sure. Get-DistributionGroupMember -Identity "Distribution list" -ResultSize Unlimited | Set-MailboxRegionalConfiguration -Language 2057 -TimeZone "GMT Standard Time" -DateFormat "dd/MM/yyyy" -TimeFormat "hh:mm tt" Goes through all members of the list and modifies the attributes relating to Language/TimeZone/Date Format. I am only having to do this due to Office 365/Exchange defaulting new users to US. When I first ran it there are warnings about a xxx ms delay being inserted due to the load imposed on the server. Fine. But after running again this happened. And when I tried again the following day, from a different Internet connection. Like I said I've see this error before when attempting to make batch changes to users in online Exchange. Thanks, Bruce.
  19. I don't think I'm giving too much away pasting the full error (with name of host replaced with xyz): Microsoft.Exchange.Provisioning.ProvisioningBrokerException: Provisioning layer initialization failed: 'The domain controller 'xyz.eurprd06.prod.outlook.com' is not available for use at the moment. Please try again.' ---> Microsoft.Exchange.Data.Directory.ServerInMMException: The domain controller 'xyz.eurprd06.prod.outlook.com' is not available for use at the moment. Please try again.
  20. Hi all, I am trying to run a PowerShell script to modify an attribute for subset of users in Exchange online (Office 365). "The domain controller xxx is not available for use at the moment" (there is a load of other gumph in red text but this is the crux of the error). And the script stops at this point. I have also seen this happen before and seems to occur when a script takes a while/does a lot of processing in Azure (i.e. goes through a batch of users), but not always. It's quite frustrating because it stops me from making this change. Has anyone seen this before? Kind Regards, Bruce.
  21. I appreciate that Office 365 (user) accounts are Azure AD (user) accounts. But what I was asking about is Azure AD/Hybrid joining, and what this extra cost is that has been mentioned? Are there any issues with A1 in relation to Hybrid joined? Can computer objects be syncronised to AzureAD? Can replication happen in reverse (AzureAD > AD)? If not, does this matter? Thanks, Bruce.
  22. We have the A1 plan, are you inferring you can't do AzureAD joined/hybrid without a better license plan?
  23. Sorry, where does the cost come in?
  24. Hi all, Has anyone tried joining their laptops / PCs to AzureAD (or to both AzureAD and local AD - called Hybrid joined)? This will allow users to logon to the laptop using their Office 365 account (useful when off-site)? Thanks, Bruce.
  25. Typical unhelpful message from DPM. What type of backup is this; VM, file, Bare Metal Recover? Have you checked the event log on the target machine? These are often more revealing than those on DPM (as DPM heavily leaverages services / software on the target machine). Also, have you setup AV on the DPM server correctly (to exclude any points for replicas from being scanned/modified)? Thanks, Bruce.
×
×
  • Create New...