Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ICTNUT

Edu Supporters
  • Posts

    1,433
  • Joined

Everything posted by ICTNUT

  1. Yes i thought of that and on VLAn 2 that would be great, in fact i'll do that now however on VLAN 3 (students) I have a number of thin clients and these would effectivly stop working and that would be an issue....
  2. Hi All after getting my VLANs up and running with each core switch now having at least 4 redunudant links to it I now turn my attention to further locking down vlans. Now the subnets are working fine in that vlan 2 (Staff) cannot see vlan 3 (Students) and vice versa, this is good, you can however still launch mstsc (RDP) to the servers from either of these VLANS and there is a route through to the servers, there has to be ! Anyone know the best way of restricting this? Yes i kinow that you have tobe a member of the admins group to get access but if the username and password is compromised I am trying to reduce the attack window by only allowing mstsc access from within VLAN 1 only ie.e the server room, comms room, or my office. Thanks in advance
  3. All done, all sorted and all motoring Need to setup the firewall with sub interfaces for each VLAN and I forgot to add a static route on the second HP L3 switch which just so happens to be the one the firewall is linked to. Did the above and bingo
  4. I seconf what PEO says, we have the button on our student intranet and once clicked simply open the page with the form. if you email [email protected] they normally reply within 24 hours
  5. OK here we go. Thanks to all those that helped with the VLANs, easy once you get the HP terminology worked out. Any how I have now got the issue of no internet feed to each of the subnets with my setup being as follows: VLANs -> Proxy -> Firewall <- I get nothing of the internet in this setup VLANs -> Firewall <- I get nothing of this setup unless I change the Gateway on one DC to the IP of the Firewall and hey presto Internet (this is how I am posting at the moment.) Any ideas on how to get this sorted ideally as VLANs -> proxy -> Firewall Proxy is a bloxx TVT-500 box and firewall is a sonicwall pro 3060 firewall
  6. Many thanks for the pointers guys, here is where we are at, POsting at home at the moment as there is not internet at school. Proxy is a Bloxx box that handles all the filtering Firewall is a Sonicwall appliance. All DHCP Request are now being sent to the correct vlans with the correct IP schemes with VLAN seperation working a treat i.e CURRICULUM VLAN cannot access nor see the ADMIN (SIMS) VLAN. I think the internet side of things could be to do with routing but there are 2 other core switches in the way which still need to be configured properly so I will do this tomorrow after Ihave setup a dialup connection to the web Will let you all know how I get on and thanks again for the pointers
  7. I have got that in place I have just done a reboot of the HP Switch and did a release and renew on the pc in vlan 3 and hey presto an ip address from the correct range. But no internet Let me check my proxy filter..... runs off
  8. Yes I have:
  9. as requested:
  10. I think this is the case...! OK here is the situation so far. I have all six VLANs setup on both the switches and I know these work as the servers sit in VLAN 1 and any PC placed into any other VLAN fail to work. I am not getting DHCP from the server in VLAN 1 for a PC in VLAN 3 I have setup the dhcp helper on the HP switch as follows: RM77 Core SW1(vlan-1)# ip helper-address 192.168.0.3 and RM77 Core SW1(vlan-3)# ip helper-address 192.168.0.3 My question is should the ip helper address be different for VLAN 3 as the ip address given is in VLAN1?? Scopes on DHCP server have been setup, see attached image
  11. Ashok: IPs/Subnets have been worked out and i'll put these in place on the DHCP tomorrow DHCP-Helper Ihave worked out where this is on the procurve so no problems there. As far as the uplinks are concerned Would I need to ""tag" all vlans?? or just the core, and yes under Cisco "Just Trunk" !!!
  12. Hi Guys, I am in the process of testing VLAn setups and need some guideance. The first thing is HP terminology (gah!) hate it.... Secondly here is what I have a HP 2824 L3 Switch (Core) and a Netgear GSM 7248 L2 (Edge). Setup is as follows: Uplinks from 7248 to 2824 out on Port 48 and in on Port 24 respectively on the 7248 I have 4 PC's on port 1, 3, 5, 7 with 1 and 3 untagged on VLAN2, 5 untagged on VLAN 1, and 7 untagged on VLAN3 On the 2824 I have DC's, DHCP, File Server and Proxy all untagged on VLAN1 The problem: All the PC's can logon with out issue 1 - non of them can ping each other ( I would expect this for inter VLAN but thos on the same VLAN should be able to shouldn't they??) 2 - Shares are not mapping on any aprt from the PC in VLAN1 (Port 5) 3 - Non can access the internet apart from PC in VLAN 1 (Port 5) What am I missing, I am not used to HP stuff as I normally workwith Cisco but hey we have what we have Do I need to "tag" the uplinks in any way? My understanding is that each port need only be "untagged" if it is a member of only one VLAN which in most cases is the case? I would expect pinging to be restricted when trying to ping a pc in vlan 2 from vlan3. Any help would be great as I am STUCK.......
  13. ICTNUT

    OneLAN

    @Webman: You are correct it does not do HTTP Auth and you do not have shell access although if you really wanted to......! OneLan (v5.x.x) is based on Fedora and I think is pretty standard in it's setup. Depending on the VLE I am sure you could create public pages, we use moodle and can create these with no problems while keeping the courses restricted.
  14. ICTNUT

    OneLAN

    I have a OneLan box and currently deliver to 5 LCDs around the school without any issues(running version 5.2.2.) LCDs are linked over a seperate cat5e network running via a cat5e extender per screen. I do want version 6 but you have to buy that as verison 5 boxes don't support it.
  15. Hi All, If anyone out there uses the above swicth in a VLAN environment can you please tell me if the uplink ports need to be set as trunked or if this is done automatically by the switch. I have gone over the admin manual 3 times now and cannot find anything about trunking ports. Any help would be great.
  16. Hmmmm you have a point about VLAN 4 I may increase that to 1022 hosts also may look like overkill but as you say room for growth seeing as I have just added another 3 Thin AP's and plan to launch public wireless access.
  17. Hi All, I am in the process of setting out / planning the VLANs I am going to implement over the holidays. Could someone check that I have my IP schemes OK ? VLAN 1 (Management) IP Range: 192.168.48.0 - 192.168.51.255 Netmask: 255.255.252.0 CIDR: 192.168.48.0/22 Maximum Hosts: 1022 Network ID: 192.168.48.0 Broadcast ID: 192.168.51.255 VLAN 2 (Admin) IP Range 192.168.52.0 - 192.168.55.255 Netmask: 255.255.252.0 CIDR: 192.168.52.0/22 Maximum Hosts: 1022 Network ID: 192.168.52.0 Broadcast ID: 192.168.55.255 VLAN 3 (Curric) IP Range 192.168.56.0 - 192.168.59.255 Netmask: 255.255.252.0 CIDR: 192.168.56.0/22 Maximum Hosts: 1022 Network ID: 192.168.56.0 Broadcast ID: 192.168.59.255 VLAN 4 (Wireless) IP Range 192.168.60.0 - 192.168.60.255 Netmask: 255.255.255.0 CIDR: 192.168.60.0/24 Maximum Hosts: 254 Network ID: 192.168.60.0 Broadcast ID: 192.168.60.255 VLAN 5 (VoIP) IP Range 192.168.61.0 - 192.168.61.255 Netmask: 255.255.255.0 CIDR: 192.168.61.0/24 Maximum Hosts: 254 Network ID: 192.168.61.0 Broadcast ID: 192.168.61.255 VLAN 6 (Media) IP Range 192.168.62.0 - 192.168.62.255 Netmask: 255.255.255.0 CIDR: 192.168.62.0/24 Maximum Hosts: 254 Network ID: 192.168.62.0 Broadcast ID: 192.168.62.255 Many thanks
  18. Thanks to all for your input, I am speaking with the USB Company at the moment
  19. @Plexer: Using a bit of software called GateKeeper from Takeware pricey @ £3k but it does cover all types of mass stoarge devices including phones and mp3 players and such. @Kmount: Where did you find that price?
  20. I am putting in USB controls over the summer which will restrict students from brininging files that I don't want them to this will also "lock" the USB device to the student so they cannot share them. I have all the above ready to go but I also want to supply the students the USB sticks so we can provision them and we know they will work as there have been a high number of issues around cheap memory sticks not working or failing randomly. So my question is does anyone know of a good supplier that can provide the above 1000 sticks at a decent price and I would like branding but this again depends on price. I do plan to sell these to the students at no profit so the sticks will have to be competative so it remove the argument that they can get them cheaper from PC World (Blah!) or Currys (Blah! Blah!) Any ideas anyone ???
  21. @FN-Greatermanchester: Are you using the PHP network status tool or the one I have done?? If you are using my one then it would be a simple case of add the printer to the printers group and then add the print server to the servers group. If the print server is a windows box then you can monitor the print servers services also i.e. Print Spooler etc.
  22. What mysql client are you using to connect to the mysql database? You may need to tell the mysql client to ask for a password by using the -p command: You could also try and reset the root password: MySQL :: MySQL 5.0 Reference Manual :: 12.5.1.6 SET PASSWORD Syntax I quote from the above document: This was the exact problem I had.....
  23. I would assume that when you installed mySQL on the windows box you specified an admin password and did not leave it empty, if you did supply one then it could be the old password bug. I'll dig out my how too and post it up just incase.
×
×
  • Create New...