Jump to content

StephenPink

Members
  • Posts

    333
  • Joined

  • Last visited

Everything posted by StephenPink

  1. PM me and can chat pricing/supplier if it helps... I'm not sure I'd want to try and use CloudPath with another vendors APs. I've also been speaking to Unifi about their Endpoint app - as that can do one-click WiFi provisioning, but currently can't deploy certificates...
  2. R670s/T670s. Nah - for Visitors we use the Guest Portal in R1 instead, with voucher codes that are issued by IT/Reception. No SSL inspection on that network - Securly Guest DNS filtering only. Voucher codes so that it can't be used by students. Cheers
  3. Yeah you still need to install the root that signs the NPS cert for some Androids, tis annoying. Makes sense - am in the same boat. Will easypass also hand certificate distribution? That's the pain point (still)
  4. We've recently gone to the Ruckus CloudPath route due to this issue exactly. And still not perfect, but a smidge easier - Android is the worst, not helped by the amount of variation between manufacturer versions as well. The other route is enrol in an MDM... i can share instructions from pre-CloudPath if it helps? Again they were reasonably vague though to try to cover the majority of devices without taking into account the specific variations. Cheers
  5. GPO details below (not sure the scheduled task deletion actually worked, but the reg keys definitely had the desired effect) I will however also make clear - this is NOT a fix - these devices DO need to replaced due to age, but we are where we are unfortunately... Computer Configuration > Preferences > Windows Settings > Registry: - New > Registry Item: ○ General: § Action: Updated § Hive: HKEY_LOCAL_MACHINE § Key path: SYSTEM\CurrentControlSet\Control\SecureBoot § Value name: AvailableUpdates § Value type: REG_DWORD § Value data: 0 (Decimal) ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No - New > Registry Item: ○ General: § Action: Updated § Hive: HKEY_LOCAL_MACHINE § Key path: SYSTEM\CurrentControlSet\Control\SecureBoot § Value name: HighConfidenceOptOut § Value type: REG_DWORD § Value data: 1 (Decimal) ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No Computer Configuration > Preferences > Control Panel Settings > Scheduled Tasks: - New > Scheduled Task: ○ Task: § Action: Delete § Name: Secure-Boot-Update § Nothing else configured ○ Schedule: § N/A ○ Settings: § N/A ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No
  6. Just in case it helps anyone else - we had this on Win 10 and 11 machines - freezing ~10 minutes after boot, whether logged in or not - it was the Secure Boot certificate updates. Specifically, trying to update them on machines that couldn't take it.
  7. Recently gone through Procurement Services to get refurbished hardware; LOT 2 here: IT Hardware, ITAD & Associated Services The framework was quick and easy to use. Definitely easier than trying to get like for like quotes with refurbished kit - quick spec sheet, RFQ out and short turnaround - ended up awarding to BornGood and Tier1 - so far so good. Cheers
  8. Have found 2 genuine HP J9150A, the rest are all FS and were working in either a 5412zl or 8212zl Cheers
  9. Also generally recommend FS.com for everything - and the reprogramming side of things! More specifically though, I've been taking out a lot HP/Aruba switches and 10Gb SFPs so @Olliedawg if you confirm the exact part numbers you want I'll have a rummage and you're more than welcome to any I have? Cheers
  10. Makes sense! Yes absolutely a great reference - fills some gaps in the standards as well. Appreciate you finding and sharing.
  11. This is super interesting actually - how did you find this?? and thank you for sharing!
  12. Yep all seems fixed now. Only details that were shared to us was "It seems there was an update released overnight which was the cause of the issue. We are working on rolling that back ASAP to resolve the issue." Not the first update in recent times that's caused disruption unfortunately.
  13. Yes - we've got the same at several sites, and have a ticket with Securly. Seems to be related to an update yesterday - no details from them yet. Shame as recently there have been a number of disappointing incidents with Securly.
  14. Android devices are definitely a pain these days - more so if a 802.1x network! My notes regarding the "no internet" message are below; those URLs need to be excluded from filtering and ideally decryption too. HOWEVER be careful if you exclude the generic one, that as it contains google.com as if you the way it is excluded isn't specific to the exact URL, then there goes all your monitoring of Google searches... Below are the identified Connectivity Test URLs so far (these are required for devices to "think" they have internet access, regardless of if they actually do or don't have access to the rest of the internet) These URLs require adding to the "Custom allowed content" category, which means no filtering, and no decryption Android URLs Generic - google.com/generate_204 Huawei - connectivitycheck.platform.hicloud.com Huawei - connectivitycheck.cbg-app.huawei.com Oppo - connectivitycheck.gstatic.com Oppo - connectivitycheck.android.com Cheers
  15. Yep Shared iPad still not good enough. For the Junior school, we have 120 "Student iPad" accounts - 1 for each iPad. So they are setup as 1:1, and then the teachers have a record of student name to iPad for filtering/other issues. Then there's no password/code issues either as the teachers know the Managed Apple ID password if required (federated to the Entra account) and these are also still unique per account. No passcode on the iPads, managed layout via Jamf School etc too. Cheers
  16. We've been moving to Ruckus - so far so good. Previously an Aruba house, and as others say the Central costs are insane...
  17. SmartPAC We also have the DNS configured as well, as fallback
  18. I only have 1 Securly extension - I didn't think there were different ones for ChromeOS vs Chrome browser? Currently we are only deploying to Chromebooks though - when there were issues last year, it was removed from Chrome and has never been re-deployed. We have our Chrome devices in a separate OU so it only deployed there at the moment. Cheers
  19. I can log in fine from sites using Securly - so might be a you specific issue I'm afraid!
  20. Thanks both, good to know! I'll reach out to Redstor for futher info. Appreciate the response
  21. Question for those currently backing up Google - what are you using, and how does it handle Google Classroom? We have a lot of coursework that "lives" in Google Classroom, and so there is pressure from exam board regulations to ensure that all exam/courswork is backed up. The providers I've been looking at don't seem to specify Classroom, only Drive so not 100% if that would work. Cheers
  22. Oh yeah of course - I would also recommend a file share witness to help with that! Or think if you have a domain joined cluster there are other options for witness... Yeah sounds like a plan - and good luck! Ah sorry I was meaning the Workgroup Cluster specifically - otherwise Server 2025 seems fine. I did a mix of PowerShell and GUI and documented the lot - definitely safer in some ways to script it so definitely identical configs.
  23. Are you guys able to elaborate on the account charging/accounting/quotas? As I keep hearing conflicting things and am about to pull the trigger on one or the other. We currently only require a very basic account charging/quota setup - students start with X amount fo credit, and when it runs out they can't print anymore without topping up. (the top up side is managed separately, manually taking payment and updating balance via PaperCut admin) Will this work in Hive? Cheers
  24. Ouch and I thought I'd had full-on time! I would go nuke and restore - with all the updates/upgrades that have happened, and changes on some nodes but not others, feels far safer to start from a clean sheet. That way if anything goes wrong at that point, you know exactly where everything stands. For your S2D are you using mirror/parity/combination of? Now is probably the only opportunity to change this should you wish - my preference is 3 way mirror due to performance. VM-level restores are generally easy and trouble free. And at least with a clean cluster setup you can also spin up a new VM in advance to test to ensure if there is an issue, if its cluster or the restored VM. Also - 2025 Workgroup Cluster is a thing - having spent some time implementing it - not sure its 100% ready yet as has been quite tricky to get fully operational.
  25. Have you got any more information on this please? Am just setting up new 2025 NPS Servers, and enabling 802.1X EAP-TLS auth for the wired side for this site, and experiencing issues - but have done this plenty of times over the years in the past, so am sure I've got the config side right. I am seeing the exact same errors you mentioned.
×
×
  • Create New...