Jump to content

AngryTechnician

Members
  • Posts

    3,772
  • Joined

  • Last visited

Everything posted by AngryTechnician

  1. Theoretically yes, but they don't make it easy: How To Change Google Chrome’s Cache Location And Size
  2. Warning: if you use the above 'fix', it redirects ALL of Chrome's local profile data, including the cache. This means hundreds of extra MB per user being written to your redirected AppData or (worse) the roaming profile, depending on how you set it up. Consider how this will impact server space and performance before rolling it out to large numbers of users.
  3. OK, bringing together advice from a few different threads: - DO NOT just change your auth setting from NTLM to Kerberos. It will probably not work, and I will point and laugh at you. Set up a new auth policy on a different port number and test Kerberos with a range of users first. Then test it again. Only once you are satisfied it is working should you change the auth setting on the port that your workstations are configured to use by default. - The main prerequisite to using Kerberos as an auth method is for Smoothwall to be joined to your domain in Services » Authentication » Settings using the "Active Directory" type, instead of the "Active Directory (legacy method)" type. If you don't see the legacy method as an option, you need to run updates on your Smoothwall. - Once you change from the legacy type to the new type, all users must log off and back on before their Kerberos token will be recognised by Smoothwall. Any users who logged on to their workstations before you switched to the new type will fail to authenticate to Smoothwall. - Before you even get around to testing Kerberos on workstation, go to Services » Authentication » Control and run the configuration checks. Anything without a green tick next to it should be corrected first. Also, if you don't see a line with "Keytab created" and a green tick, Kerberos is not set up. - Any user-specific policies will need to be edited to reflect that the username will be reported as [email protected] instead of just user - The current Kerberos implementation on the Smoothwall does not correctly process usernames with spaces in. I believe this has been raised for a future patch, but for now, the only workaround at present is to rename user accounts so they have no space (luckily we only had 22 affected accounts). - Local users on the workstation (such as the local admin account) will not be able to authenticate at all using Kerberos, and will have to use different proxy settings if you need access. - Kerberos normally works better than NTLM (which is of course why I switched to it for use with Office 2013), but some software will still choke. Notably, Java works with NTLM but does not work with Kerberos. Until this is fixed (don't hold your breath), you will need to provide a separate NTLM port for Java to use. You can specify different proxy setting for Java using Java's deployment.config file.
  4. Arthur is correct. Output from Dell OptiPlex 960: Output from Lenovo ThinkPad X131e:
  5. I know I'm sounding like a broken record, but in case you haven't guessed, this will only work if the search is not encrypted. If the user is logged in, it will be encrypted, and this keyword filter will be rendered ineffective.
  6. Now that's just wishful thinking!
  7. I think the config.xml needs to be in the same folder as setup.exe (i.e. the root of the install files) even when using the MSI to deploy (which isn't supported after 2007, FYI).
  8. Just tried this out (purely in the name of research). Safe Search blocks 'boobs' in Spanish, while 'porn' was blocked by Smoothwall in both Spanish and French. Both Smoothwall and Safe Search did let through 'boobs' in French, but the results were still filtered and were relatively tame. I tried a few other terms in a variety of languages, and between Smoothwall and Safe Search they did a pretty good job of keeping things tame. Again, all of this can be bypassed if your filter is letting through encrypted search.
  9. Forcing Safe Search only works if your filter does HTTPS decryption. If the traffic remains encrypted, all the filter will see is the domain name, so it can't filter by anything after the / or do any content or request rewriting.
  10. Basically this is because Google has for some time enabled secure search (and only secure search) for any logged in user. If your filtering does not combat Google secure search, all of Google search is available. If you control your own DNS server, you may be able to combat this locally by adding your own DNS record to resolve www.google.co.uk to nosslsearch.google.com (substitute your local country suffix as appropriate, i.e. whichever one the geographic IP detection redirects you to). Google suggest using a CNAME record, but there are issues with this on Windows servers, so you may have to resort to an A record and make sure to update it when the IP chnages (not often, but does happen).
  11. Just wait a year or so, I'm sure within a couple of versions Microsoft will do away with the GUI entirely and everything will be done through PowerShell, same way they are going with Exchange and Windows Server.
  12. The top image is 1200px wide, and the CSS specifically sets the page width to 1200 too. Your screen resolution must be higher than you think it is!
  13. Your proxy server might have something like this built in. Positives: No long term benefit that I can think of. Pupils will just click OK without reading after the first few times (if they even read it the first time), just like everything else. Negatives: Might interfere with programs that need Internet access for some functionality.
  14. I can see why you'd like to avoid a full recable!
  15. I've used those couplers too in the past, only reason I didn't recommend them first is I suspect there are a lot of cables and the patch might be more manageable.
  16. We have it on a single machine at the moment. Unfortunately its not an MSI installer but building your own is relatively easy as all you need to do is copy the files from a working install to a new directory and add the file associations. It also needs manually activating on each machine. If I remember correctly this didn't work through a proxy, so I had to enter the details via a website and copy & paste a confirmation code. It's been a while since I did it so this may have changed/been fixed. Once installed it has been zero hassle whatsoever running under a limited user account. We've just had our licence confirmed, and here's an added bonus:
  17. Yes, pretty sure you'll need to install newer drivers. We bought a 680 last year and the version of the drivers we already had didn't support it.
  18. Primary (Prep) 510 250cm D x 220cm W x 280cm H No Conversion, previously one corner of open plan office 1 Standard and Pochin Enclosure Systems 800 x 1000 42U 17U servers, 6U patch, 2U cable management, 8U switches/routers, 9U UPS = 0U spare! Available: 4800W, drawn 2000W approx. Unknown Unknown Unknown
  19. Wire up 2 sets patch panels under the floor, one set to terminate the old cabling, and another set to terminate your new extensions. Then connect the two together with patch cables. It won't be pretty, but it should work and it will be relatively cheap. If you have (or can rent) a high-end cable tester it will be able to verify if the cabling is still up to standard with the extra patches.
  20. Good luck to anyone with Samsung machines - last time I called them because they shipped us 160 netbooks with no SLIC table at all, they claimed that they only support Vista Home Basic (the preinstalled OS) so refused to help us at all. I will certainly be talking to our Dell contacts about this before our next order.
  21. http://www.edugeek.net/forums/news/95516-leap-3d-motion-control-system-new-gesture-based-interface-computers.html
  22. We used to get those about once a week when we still had our RM Smartcache. I even circulated screenshots to staff titled "Why your computer doesn't have a virus", but people still routinely reported it until we switched to Smoothwall. Haven't had a single report since.
  23. Looks like somebody rang the BBC... was it you, @localzuk? BBC News - Heavy rain causes floods in Midlands and South West
  24. I believe the cheaper cert will suffice. Unless you have a non-standard setup, you only need to cover 2 domain names: the URL used internally by Outlook and internal webmail use, and the external URL you've given above.
  25. Not sure if it is possible, but it's not really advisable since the encryption key would be the same on all of them.
×
×
  • Create New...