Jump to content

Whistler

Members
  • Posts

    100
  • Joined

  • Last visited

Everything posted by Whistler

  1. Hi, we've inherited a POE switch from a closed business to one of the environments that I'm currently supporting (a charity). They have 4 Macs on their network and some Ubiquiti UniFi AP's for around the centre. We have this new switch which we installed and all the devices communicate on one network fine with, however the switch itself doesn't appear to be requesting an IP from DHCP. Doing a network scan doesn't find the switch either. The DHCP range is from 10.10.0.1-254, however the network scanner is scanning through the whole subnet which will take an age, and probably won't find it even then. It has a Serial port, however unsure about how to manage this considering they only have the new 12" MacBooks. Does anyone know how to reset this switch without having to telnet into it? First time dabbling with this sort of equipment, it should have a web GUI (referring to the users manual) however I can't find anything mentioning the default IP. If anyone could help, it'd be greatly appreciated!
  2. Hi, does anyone know if you can get these: 2x Dell PowerEdge R710 6GBPS SAS SATA H700 H200 Cables A/B 3.5" Backplane 3.5 | eBay any cheaper? We've recently upgraded to an H700, however my other tech ordered the wrong version (from eBay), so can't find any others for cheap. Would any 6GB/s to Mini SAS Work? If it would, could you provide a Link to one? Thanks,
  3. Hi, We have some servers we want to upgrade to Server 2016 We normally do a fresh install of OS' however are wanting to upgrade this time due to having to re-configure shares etc. Can we just pop the CD in and upgrade or do we have to do something special? Server holds WSUS, WDS, DFS and FS Resource Manager. Thanks, Whistler.
  4. Hi, Is it "safe" to disable the internet on our servers. We ideally don't want them to have any internet access for security. The only server we want is our WSUS Server/RD Gateway Server (which is in a DMZ) which would patch the other server with security updates. Is this standard practice? We can block the servers from the firewall (pfSense). Thank you.
  5. Hi, I don't have a spare router. Would any one do? Thx.
  6. Hi Kevin, I somewhat understand your thinking. I'm asking for opinions on how to move forward with this and what other people would do. Additionally, I'm interested as to how other people would do it, quite so given both the context and content of my question. I'm new to the industry so have little experience. I do know what a DMZ is used for, hence me asking if it'd be worth putting the Web Host onto it to separate it from the main network from a security standpoint. I've read it's not essential but I was asking from a security perspective from people who on here would know a lot more than me. Again, I'm asking for people's opinions which would encompass as to how other people would do it. Whistler.
  7. Hi everyone, I've been asking a few questions here recently, and about to ask another! Background is that I work with a small local IT support company and we've recently taken over a small business (5 employees). Their servers are running Server 2008 Standard (3x Servers). They have 1 domain controller with just AD, DHCP and DNS installed, the second is the "admin" server i.e home drives, sophos and printers etc go there along with terminal services (remoteapp). Last is a web host which hosts the "/tsweb" page and acts as the gateway and broker for the session connections. Currently, on their firewall they have port 443 and 3391 open which goes to the TS Gateway. The firewall is Sophos UTM and they have all networks allowed, apart from Korea, China and a few others (13 in total I think). My main concern is that this server isn't in the DMZ, however they get virtually no traffic and it only goes to the login page which required AD auth so how big of an issue is it leaving it out of the DMZ? The servers are virtual and Sophos runs inside of a VM on an HP DL380 G5. Their backups go to a NAS which is in another part of the office. I want to get this offsite eventually however works well for them currently. The AD side of things is done very well currently, with no scheduled tasks going via "Administrator" and about 25 security groups. I'm just after some general advice on how to protect the network better. They are looking to expand their main office and have some members of the public coming in whilst sitting in reception. They have UniFi for wireless and standard layer 2 switches with 2 vlans on (2 and 3) - 2 is the main network vlan and 3 is one that was going to be for the guest wireless but never configured. If you could give me some advice with going forward in regards to the overall setup that'd be great. We are going to upgrade to Server 2016 eventually however would like to get security sorted first. Anything applicable to small business security tips please post below! Thank you. Whistler
  8. Hi, I work in a small office and we are currently re-designing a portion of our network. We have acquired some IP security cameras and hope to integrate them into our network. Currently as a test I have put them on the main VLAN and they are working fine. However, I want to put them on their own separate network. We run an NVR in it's own VM from within Hyper-V, and I hope to put that on the same VLAN as the cameras. We only have Layer 2 Switches, so from my understanding we can't have "inter-communication" between VLANs without Layer 3? Ideally, I'd want to have the NVR and CCTV on the same VLAN, along with a "Management VM" whereby I could look back at the footage. Accessing it off the phone would be nice, but not essential. I'd create a new VLAN, tag the port on the switch and set the ID of the VLAN within Hyper-V, is that correct? Is there anyway I could access this from the main network? Cheers to any advice you could give. Whistler.
  9. Here is the error I'm receiving, it changes from Error 500 to the following. I personally think that me changing the page URL messed something up. Thoughts and advice appreciated!
  10. Hi, got a few questions with RDWeb and our domain name. Currently, we're hosting our domain name ourself with a dynamic IP, using NameCheap. Namecheap supports dynamic A records which gets updated when our IP address changes. This works fine. We're now looking to setup RDS (we tried previously, within the last week and eventually got it working on a test setup). I have bought an SSL cert for our domain and installed it on my Web Server. I have additionally installed the RD Gateway Role and RD Broker as the ports are already forwarded to the server (443 & 80). I installed the RD Web role, however IIS was complaining that it wasn't in the right directory to load the page (it installed in C:\Windows\Web etc), so I moved it to inetpub\wwwroot etc where the "RDWeb" folder now sits. However, since doing this and changing the physical path in IIS, I now only receive Error 500 Internal Server error, which doesn't help us! Our main SSL site is still loading fine, however I want /RDWeb to load, and it doesn't! Am I okay with having IIS, RDWeb & Gateway all on one box. We're a small business with not much web traffic, but was concerned regarding security. It's not in a DMZ or anything like that and is on our main network, so want to protect us as much as possible. Any help with getting this to work would be great. Thanks, Whistler.
  11. Another update, I've changed some DNS settings and it connects to the gateway fine (using myfirewall.co domain) , gives the security warning for the broker server, accepts cert but gives this error "The Gateway server could not reach the target server. Please make sure that the target hostname is correct." (OS X). Anything anyone suggests. I think we're nearly there, but not sure! Whistler.
  12. Doesn't mention anything to do with SSL in any logs that I can see. I have all of the certs, although self signed installed in Trusted Root. The only issue I can see is that for the gateway server it's still using the internal FQDN, rather than anything external which I think may be the problem. If you can give an explanation on what to do as easy as possible I'd appreciate it. Thanks for your help.
  13. UPDATE: I have got everything working internally, as I didn't have a certificate I needed. However, when accessing externally, I still tries to connect to the broker server and won't resolve as it's under our internal DNS. Any advice anyone can give would be great. Thanks.
  14. Hi, I've done as you said and migrated the Web role to the Gateway box, works fine. I'm able to connect to the box locally and access apps etc. However, when working remotely (or more specifically over a 4G connection - only thing we've got to test), I can sign into the portal fine, however it won't connect to any apps etc because it's using the internal DNS name "e.g rd-broker01.ad.contoso.com" How do I fix this? Thanks, Whistler.
  15. Hi, new setup for work we're trying to do, however have had some problems. We've installed a new 2012 R2 setup with Remote Desktop and RemoteApp, Web Access, Gateway etc on different servers. Works great internally and we can publish Apps and access Desktops. Our internal domain is along the lines of "ad.contoso.com". Our office has a dynamic IP and we are using the .myfirewall.co domain provided by Sophos as a DDNS host which refreshes every 4 minutes. We want to publish RD Gateway for users over port 433, we're not worried about certificate errors as we can fix this by deploying the certificate via Group Policy. However, we are confused regarding the setup and how to get it all working over the internet. We want all RemoteApps/Desktops to be accessible over SSL over the internet, however forwarding port 433 to the gateway does nothing, as it's not on the same server as the web role. We are confused at the setup also, as our AD FQDN is internal only and doesn't resolve in the public DNS records for obvious reasons?! What do I have to do to get this working? You can be general with instructions, or specific to Sophos XG if you know! First time we're doing a setup like this, however want this to work. Any ideas you've got, let me know! Thanks, Whistler.
  16. Bump. Anyone?
  17. Hi, As part of my home network project I am looking to setup Exchange at home using SBS 2011 on a separate AD domain which will host (ideally) all of the mailboxes for my domain. I own the rights for my domain name, and have it hosted with NameCheap. However, my IP at home is Dynamic and hosted with Virgin Media. I have heard about using Smart Hosts and various other ways of getting this to work with DDNS etc, but I haven't managed to get it to work. Is anyone able to help me with setting this up? My ideal goal is to have SBS running Exchange to host emails, with my own domain and for me to be able to send emails to other people (presumably via a Smart Host) with no fuss. I have all the ports SBS requires opened on the firewall, so it's not a port block error. Virgin Media doesn't block port 25 also, so no issue there. Hope you can help? Whistler.
  18. Thanks, I may have a look at this! Happy New Year! Whistler.
  19. Do you have a G7 or G8 Microserver? I prefer the G7 due to it having the extra drive physical capacity (i.e more physical drives) per unit than the G8 can support. I may look to get a G8 due to the improved processors however for the new build outside. I haven't really looked at Storage Spaces, however will look to do so at some point. I'll keep tabs on eBuyer! Thanks, Whistler.
  20. Thanks for the info. Looks like it'll be easier to run Cat 6. I may run two cables just because I can I guess, however will depend on how much cable I have left at such time. I'll take a look at the Hue range as you suggested. Whistler.
  21. I'm about to list it on eBay. Putting the price as £125 - I'll try my luck.
  22. Thanks to everyone for their replies. After replying to everyone, I seem I may have quoted multiple people into a single reply, sorry! I'm thinking of selling my ML350 now, and getting another Microserver. I lose the ability to do RAID 5 natively without a card, and I'm always hesitant to go with Software RAID. I want the solution to be as low power as possible, with after consulting all replies the G5 seems to be out of the question! I've always had a love-hate relationship with that machine, however it's more suited to eBay I think in hindsight. Anyone know what spec Microserver I ought to go for? At the minute, I've got an N54L, 6GB RAM, P410 RAID and 8x Drives in (mixture of 2.5 SSD and HDD). Would be replicating 3x VMs, with one additional VM hosted on that machine for a Windows 7 Workstation with Graphics Passthrough for a workstation. Thanks again everyone and again apologies if I've slightly messed up the replies! It's a great forum this is, kudos given to everyone who's contributed! Whistler.
  23. Looking to do this. Power Meter is about to be put on order for Server Cabinet. The Microserver idea looks pleasing as previously discussed. Something to replace the ML350 with I think. Whistler.
  24. A Power Meter's now on my "to do" list. Thanks for the recommendation. I, for reference was planning to use am ML350 so slightly better than the DLxxx series (I think?!) Whistler. - - - Updated - - - You think I'd be better off just selling the ML350 then? Any idea of what they're worth? (24GBs of RAM, 10x Gigabit Ethernet Ports (mixture of cards) and the obvious iLO (Advanced License)) Whistler.
  25. Similarly, wow - your electric is dead cheap compared to mine! My reply to Twin Turbo actually references your suggestion, I was thinking of going with LEDs for the rooms, with Phillips Hue being the choice however the cost looks quite expensive? The cloud is an option, however call me "old fashioned" but I think nothing beats local storage and having physical access to it. Whilst in the grand scheme of things most of our home networks are penetratable for the real experts in the field, it's something about physically having the drive which makes me happier about having it locally than in the cloud. Prices online for storage however are very competitive these days versus physical drives. I was considering Cat 5e, however the HDMI over Ethernet adapters I bought specifically mentioned Cat 6. However, checking the port status on my switch shows it only running at 100Mbps. I'd have to do some research, but I've found 50 metres of Cat 6, shielded etc for about £20, which for me seems quite reasonable? I second your thoughts on using the Ubiquiti link. I do like it, and would be easier to do than Fibre/Ethernet but was wondering as to weather it was capable of the throughput of all the data going between the two devices and at the rate of transfer. It's a few things to weight up, it'll probably happen Spring/Summer - but it pays to do planning beforehand. I'll be sure to post some photos if I get it done. I need to find a smallish Rack to use as I'm thinking of using the ML350 as a spare server if the R710 dies, and use a MicroServer down in the other building to just do backups and replicate my core servers). Thanks again for your suggestions and pointers, it's helped for me to consider a few things. Whistler.
×
×
  • Create New...