Teth
Members-
Posts
190 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Teth
-
I inherited a user group when I first started here who had a different mandatory profile which was basically windows millenium edition look and feel with a restricted subset of application shortcuts for a small group of the least technically able staff. Most of those have now retired and the rest had to upskill as you say when we got the C2K system because being a national managed system its their way or the highway with regards to UI. I have virtually nothing on my desktop these days I wouldn't dream of having an app shortcut there. However if you took quicklaunch off me I'd just have to retire from IT I've downloaded my windows 7 Beta today and will probably split my OS partition down a bit tonight at home and dual boot it to see what all the fuss is about.
-
This is a beta. It is the time to comment constructively on the new features as well as hunt for bugs. Change is inevitable and will always be so because the engineering mind is always looking for the tidy, more efficient and more convenient way to do anything. Some changes don't work out and get buried by history as dead ends. The Ribbon introduced in Office 2007 is clearly a step forward in UI design for microsoft and is making its way into the company's other products steadily. There are people in my school still insist on having a windows 9x start menu and a my computer icon on their desktop or a computer is unusable. Meanwhile there are others who feel a computer is broken if they can't right on the my computer shortcut on a 2 pane XP start menu and choose "Explore". I use a KDE4 Linux system, a Gnome 3 Linux system, a couple of command line only headless linux servers, several 2003R2 servers, an XP SP3 Desktop in work and a Vista machine at home. Not to mention a host of devices like playstations and smartphones etc. Everything has a UI that their respective designers thought was the best that could be done for that device. There is no doubt that some are more successful than others of course. When vista came out it was new and uncomfortable 2 years since the launch of Vista and the small programs menu really doesn't bother me anymore I just keep my program groups a bit tidier than I might have on XP or type the first 2 letters in the universal search if I'm being lazy. I also appreciate the cleaner screen layout with it rather than the infinite cascading of the windows 95 era programs menu. Otherwise its the same old 2 pane start menu as XP. The one poor decision in vista that I think will be gone for windows 7 is the network and sharing centre. That was a very poor UI design choice and I hope it is sorted. My point is what was good about Vista will stay. What was bad will go and there will be some new features for time and us users to judge. This isn't the time to be passing offhand damnations of it tho. Live with it for a few months and judge it on its merits instead of making a snap judgement like the users that we all have to support every day. Who complain about every carefully planned and tested update we make to our networks because its different.
-
I was previously in the host it yourself camp for e-mail especially with the stability and feature set now in Zimbra but this year after research into our proposed upgrade of e-mail I've switched camp. When you really start adding it up financially and with regard to security and accountability external hosting is looking very strong. The 2 big realisations for me were that its not as expansive as you think. When you get into it and start talking to hosts there are some really big discounts being offered for bulk clients especially schools. The break even point for self hosting is actually at much larger user numbers than what most of us have in UK schools. We're talking multiple thousands 3K users + Secondly with the current climate and emphasis on availability, privacy, accountability and security. Self hosting is risky. In terms of uptime its risky we have limited redundancy of equipment and connectivity compared to a colocation center hosted solution. My UPS system does around 20mins, Internet connectivity is redundant only in terms of ISP it all goes into the same cable to the same exchange. Likewise I have a spare PSU and hard drive for the mail server but if it blew a processor or a motherboard downtime could be 24-48 hours possibly much worse. For a small business 1 ADSL line a DC running sharepoint, e-mail, printers, webserver, antivirus is the norm and drop in replacement parts wont even have crossed their minds. Security wise I'm not confident I could harden a server windows or Linux to a level suitable for an outward facing system containing potentially very sensitive personal and financial information. I'm confident I could impliment good archival, tracking and accountability features but on what timescale? After weighing up the options my final report to our board will recommend a fully hosted external system for all staff and pupils to be offered for tender. Or a tired system with fully hosted mail for business critical staff e-mail and an internally hosted system for pupil e-mail with a SLA type policy document stating the limitations of that system in terms of security and privacy to pupils and parents. Rather topically Ars Technica has a nice piece on this today too. Gmail about one third as expensive as hosted e-mail
-
Dead right there. arp is ethernet technology while TCP/IP is a layer of abstraction above it. TCP/IP packets get sent down to the Ethernet layer which has no knowledge of the TCP/IP layer. Therefore as far as packets on your hardware network cards are concerned either card is a perfectly acceptable way into the device's TCP/IP stack where they then get routed to the correct address. Loadbalancing is what you need and the linux Kernel is great at and the instructions above should get you going. A machine can never successfully have 2 default gateways. You can specify 2 in Linux but only 1 will work. Default gateway is the default route to send a packet if you don't know the exact destination of that packet so there can be only 1. TCP/IP on LAN networks or internet follows a simple rule. It looks at the IP address, Splits it into Network address and Device address using the subnet mask and then asks itself the question. Do I know where that network is? If its does it send the packet out that interface to its intended recipient. If it doesn't it sends it to its defined default gateway which then makes the same choice. To use TCP/IP to send packets over particular interfaces requires a routing table and the interfaces have to be on different TCP/IP networks. The routing table can be an automatically generated one like the internet or in simpler LAN networks a static routing table manually configured.
-
I've done quite a bit of this over the last 3 years and can report both outcomes. The majority work just fine, however I have had machines from as early as second sysprep to as late as the 10th or 11th go tits up. Various interesting errors including complete refusal to be connected to any domain no matter what kind of setting reset attempts I made, blue screens etc. Interestingly a second syspreping of the original machine resulted in a good image on every occasion I can remember. So I would say keep a ghost of the machine pre sysprep and if it goes wrong go back to the ghost and re-sysprep.
-
I generally find you need to take the screenshot / video first because the first thing they do when you lock or message them is hit the power button
-
We give read access to all staff and specialist ICT and Media studies teachers have read and write access for administration of OCR exams which require a inf file to placed in the user's home directory before the exam software is started. It is clearly stated in our AUP for both staff and students that home folders are secure for the storage of school related data but that the content will be monitored by school staff and if requested would be surrendered to Law enforcement agencies. I don't like the law enforcement language its too American but that part wasn't my decision.
-
It may not be app data it saves that setting to. It my be hkey_current_user in the registry. You may need to write a simple registry script to run with user logons to add the entry to their registry. There are quite a few good examples of how to do it in the "how do you do it forum" I now use this for several apps we have in school inculding adobe products and the java runtime to control automatic update behaviour.
-
I think they are a known consumable. One of our 4200s had a transparency put through it which was of the non laser printer compatible variety and it melted round the fuser. I ordered a Maintenance kit its just a few pounds more than the fuser alone. It included new paper pickup rollers, rubber roller that is opposite the drum, Fuser and spare plastic gears including those for the fuser. They are quite simple to fit altho you do end up with alot of printer bits down a desk by the time you get to all tho shafts. Its a simple C clip and a flatted shaft when you get there. You just have to be methodical so you can put it all back together again.
-
Update. I eventually tracked this down to a fake version of jusched.exe the java VM but in C:\WINDOWS\ instead of Program Files\Java. Having terminated that process I'm no longer getting the file replication. For security tho since the autorun.exe on memory stick was never visible to the file system I think I'm going to rebuild my admin machine anyway.
-
I've gotten one of these now Got it on my admin machine when I found a lost memory stick in a computer room yesturday and was going to check for an owner. Neither AVG nor Kaspersky seem to be able to find it. I'm re-imaging that machine but that doesn't help the memory stick. It seems to put an autorun.exe in the recycler and run it from there but when I look in the folder there is nothing there... Anyone know of a removal tool for this one. [autorun] open=RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorun.exe icon=%SystemRoot%\system32\SHELL32.dll,4 action=Open folder to view files shell\open=Open shell\open\command=RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorun.exe shell\open\default=1
-
I have 80 redirected by IP chains into the proxy. I think the traffic that's missing the proxy is going straight through the default gateway. I don't have outgoing traffic firewalled. Maybe Its time to. I'd like to know why its seemingly random that it gets past the proxy tho because the proxy is obviously enforced. Firefox on USB isn't a problem because we have a software restriction policy in place to prevent execution from USB drives or Home directories.
-
We use a proxy server here for filtering as I'm sure the majority of you do. We use IE7 as the default browser for staff and students but in the last few days I have discovered pupils gaining access to sites that should be banned by the proxy for example manga comics on image shack style hosting sites. Bebo and some flash games. Having watched some of them do this it seems that they use the "no addons" shortcut to start ie which I include for when some sites we use cause IE to crash with an exception error. Running it with addons disabled fixes it. I know its a workaround and its on my list to figure out but there have been other priorities lately. What the pupils seem to do is start ie with no addons type a link get blocked, then close ie open it paste the link in and it will sometimes after 4-5 repeats load the page. If they try to browse on from that page it will again give them the blocked page. but they can copy the link and keep re-opening the browser till it lets them. Is this a bug in IE perhaps? I'm just not sure how this could be. Our proxy is set by group policy. 1 proxy with permissive filtering for staff and 1 with very restrictive filtering for pupils. Obviously any filtering bypass is a big problem for us I'm really not sure how to test for how this is going wrong tho.
-
Resurecting an old thread here because we're seriously giving consideration to google apps here for a few reasons. We're a Northern Ireland school which means we are under the C2K NI IT system for schools. It was a a centralised project to provide a total IT infrastructure for all schools primary and secondary level from MS to academic. Centrally managed with a central support contract. Its a project that was so ambitious it couldn't possibly succeed completely but they did a reasonable job to meet average educational needs but certain things are very weak. E-mail both student and staff goes through a "gatekeeper" a single member of staff who must approve or reject every piece of e-mail flagged by the filter which we have no control over the setting of and is hyper restrictive. Ok in a Primary school I guess but not ina secondary with over 100 staff and over 1200 pupils. Their VLE is terrible and if your teach a computing class don't expect to have your students to ever see any code they have written run. We have a large legacy network to counteract most of these points. However e-mail for students is becoming a real issue. Most of you would liekly consider us incredibly backward for not having student e-mail access on site already but du to the "gateway" feature it has been impossible. We have registered for google apps as an experiment for a select staff group and it has gone incredibly well. There is real momentum to continue rollign it out to more of the school. All staff and then 6th form for university applications etc to begin with. This however gives us a problem. We have no filtering beyond google's spam filtering and no archival of the mail for auditing / assigning blame in the event of manure hit a quickly spinning bladed device. After some google searching I've found a few ways of doing it. 1) put a mail gateway between google and the interne tfor incoming and outgoing mail. Seems solid to me but it would be a first dealing with mail in this way for me and I'm unsure I really want to be responsible for it. Comments / guides / experiences welcome. 2) Pay google. For $8 a year per user they will archive and allow you to filter incoming and outgoing mail. And allow mailbox inspection etc. thats quite a bill for 1350 users tho. 3) jury rig some kind of system using googles own filter language to forward all incoming mail to mail boxes to another google mailbox where it could be searched.... I'm going to be seareaching the relative cost and likelyhood of sucess of these options over the next 2 weeks before presenting to SMT. Any advice or experience would be welcome.
-
Serious Issue with unresponsive servers!
Teth replied to Zoom7000's topic in Windows Server 2000/2003
It will really come down to even logs but I'd pay special attention to DNS and AD replication service message. We had a similar issue a while ago because one of your DCs which is also the print server was running out of non-paged RAM due to a memory leak in a HP printer driver. When the system got low on non-paged RAM the DNS service was the first to fall over which in turn took down logins and eventually the whole network. -
Yea I redirect Desktop to home/Desktop same for favourites to home/favourites. Home folders are restricted by quota so everything stays sensible and speedy.
-
As I read this your talking about 2 OS's across 3 hardware platforms with even load spreading across it rather than 2 live environments and an idle backup. If that is the case then your going the wrong way at this. Yes it can be done but its expensive VERY VERY expensive and I can see no real world scenario outside of the Eve online server where this is necessary or even desirable. As posted above the bandwidth requirement to share tasks at a process level is just too intensive your talking infiniband technology with a custom written or heavily customised OS to make it work and even then unless your doing very compute heavy tasks on it its never going to pay back the investment. If redundancy a transparent failover is your goal then you want to VM your Individual servers in a standard Windows environment config ie. DC1, DC2, Print server, Fileserver, Exchange, Web, SIMS. You buy 2-4 powerful multiprocessor servers or a bladeserver pick a virtualisation environment such as hypervisor VMware or Xen and run your 7 virtual servers on that hardware from shared fault tolerant storage and in the event any of your physical servers crashes your users will because the VM management software will start the VMs that were running on the failed server on one of the healthy servers increasing load on them possibly leading to some slowdown for users but no loss of service. You could also cluster critical services using windows clustering technology across your Virtual servers so that in the event of one of them failing your services are also unafected. If you really need the raw processing power of multiple machines then your better staying away from virtualisation altogether. Even with the hardware support maturing as soon as you bring the word virtual into it you are not making the most efficient possible use of your hardware. You should look into compute clusters and render farm technology. Many of the universities have papers detailing the development of they're computation farms. From design documents for purposebuilt systems from IBM or for in house efforts built from off the shelf hardware such as beowulf clusters.
-
Yea Andi you will need to let it propagate but I don't think all year will be necessary. You want all you very active users to take their current app data with them in the move but I imagine if a user only logs in once a year they wont even notice if office resets to clean install. So theres no need to keep it forever.
-
assumeing from your post your using roaming profiles for each student then yes you could simply robocopy the app data folders back into the user profiles make sure permissions are correct and be sorted. There are some Major drawbacks tho. If your running CS2 or CS3 your profiles are going to get big and quickly. I do mean seriously big too. I went to Mandatory profiles this year for this specific reason a Profile that has used photoshop and Dreamweaver with the normal use of MS office and acrobat quickly becomes 15-25MB even with temp internet data etc being cleared by logo off script. People who use CS3 extensively and do alot of internet browsing rapidly aquire 50-100MB and greater profiles which chomps disc space and slows logons to a crawl. Its the one standout but unchampioned feature of vista I think that could really change the way we run windows systems. There are seperate Roaming and local sections of user profiles in Vista which woudl really help in these situations. I currently use Mandatory profiles which keeps them small because nothing gets saved back to the server. But the downside is a user cannot personalise their settings of any application or windows itself. All changes are forgotten when they log off. This is good in many ways but it makes the users completely dependent on the defaults you set when creating the mandatory profile. It took some tweaking but everyone seems to be happy now.
-
not really a very professional opinion I feel Matt. GUI is not and should not be taken as an indication of unprofessional, simplistic or inefficient. They would not be as pervasive across all forms of technology from academic research to consumer mobile phones if they were. Neither should command line be automatically assumed to be superior and more professional. There are a tonne of very bad command line environments out there. And situations where a command line is not even a realistic choice. You, me and most of the readership of edugeek may be most comfortable and most productive at the command line but our daily tasks suite its design focus. Quick access to specific known functions and task often performed in large similar batches. However score a command line environment of any kind for intuitive use. Can you sit down at say a french command line environment in which all commands even ls have been translated to french how fast would we get anything done. Yet sit down in front of completely translated french windows XP and there would be very little to stop you acheiving most user or admin tasks because the very layout of a GUI provides an intuitive indication of its function. Not a perfect analogy but passable I think. Ubuntu is trying to get Linux desktop user acceptance and that comes from something they can pick up and use with the knowledge they already have. Once you've got them working they will gradually pick up more advanced features and workflows that the new environment provides. This would never happen if day one starts a week of training to completely relearn their base skills. That is Ubuntu desktop's goal to quietly and almost subversively convert day to day users. They are I might add still along way off but they are building on the stable framework of Debain and making good progress. On the server side its still debain under the hood and by default there is no GUI slowing it down. There is however still their massive library of pre packaged software with mostly sensible default configurations to let people get into Linux at a pace they can deal with. Ubuntu is again at the server end going for a sensible middle ground. They provide a stable base on which to put whatever services you need in a way that is intuitive to anyone who already has advanced windows skills with the command line. Its all different but its also enough the same that there is a learning curve there and not a brick wall. The skills learnt are transferable so I think what they are doing is good for Linux and open source. Please don't dismiss them offhand. "Ubuntu is a gateway drug"
-
I think thats what incognito windows are for. They keep no history, password, cookie or other data after the window is closed. So far I'm quite impressed with the slimness of the UI less screen realestate wasted on bars and buttons is always good. Given the prevalence of web UIs for everything from servers to e-mail now their single tab single process concept with stronger faster code behind them can only be a good thing. The web has moved on so far from html now that I think something needed to be done. I don't think this is the be all and end all but its certainly an interesting glimpse of where we could / should be going. Using the youtube or google apps ajax interfaces in chrome is certainly a much better experience than IE7 or Firefox especially on low spec hardware. It wont be replacing my Firefox either personally or network wise for the foreseeable future but I'll keep it installed and updated and watch its progress. Network wise its going to need GPO control and enforcable proxying etc before it can even be considered on machines within the network. It currently seems to automatically bypass any proxy you set if the page its looking for is blocked
-
The author seems to have written the script with the intention that it might be put in a user logon or workstation logon script. The marker is to prevent the SID being regenerated every time the mahcine restarts. ie. If the mahcine already has the marker SID wont be regenerated the script will just finish without making changes.
-
Haha Gotta laugh or you'd cry. That does indeed do the trick.
-
Another couple of days have been spent rebuilding machines and while I've got my image itself perfected the deployment of it is still not right my machines are still not being named correctly and rejoining the domain. Everything I have read on edugeekers blogs, wiki's and technet makes sense and as far as I can tell I'm following it but I still continually get %MACHINE% in the computer name box instead of either its original machine name from AD or if its an unknown machine the machine name generated by the mask in the WDS properties. My understanding of this is as follows now. 1) Set up WDS for capture and deploy (Done) 2) Make an ideal XP image with driver repository on C: and sysprep it with minisetup enabled and Re-Seal. 3) Boot from PXE and capture the image to the server. 4) Specify a WDSClientUnattend.xml for the server which will pick the deply image and select the .WIM in the correct image group after partitioning the drive. The partitioning is working and the right image .wim is being pulled down so I'm pretty sure I'm right to here. 5) Place an sysprep.inf in the correct folder to automate the installation of the image. It gets placed on the boot drive once the .wim is extracted ready to control mini setup. It is placed in \\wdsserver\REMINST\Images\Imagegroup\imagefilename\$OEM$\$1\sysprep 6) Boot PC from PXE and it should arrive at a ctrl+alt+del to log on screen after 20mins ish connected to the domain and ready to go. 7)tear out hair because it doesn't. I will post my WDSClientUnattend.xml and my sysprep.inf bellow if anyone can point out anything I'd be very greatful because I'm stumped. WDS just doesn't seem to be replacing the %MACHINE% and %MACHINEDOMAIN% variables and I can't figure out why. Wether a machine is correctly prestaged or not its still %MACHINE% in the computer name box when it runs mini setup. I would expect either "RIS-PC##" or "ICT1-PC07". If I change %MACHINE% in the syprep.inf to * it correctly generates a random name based on our organisation. WDSClientUnattend.xml OnError account domain password OnError Dell 170L 3 ICTSuites dell170l3.wim 0 1 OnError 0 true 1 Primary 30000 2 Extended true 3 Logical true 1 1 NTFS WinXP C true 2 2 U Userdat NTFS sysrep.inf edited to remove the component and drivers blocks cos they are huge and Unrelated. [unattended] unattendedMode=FullUnattended OemSkipEula=Yes InstallFilesPath=C:\ ConfirmHardware=No DriverSigningPolicy=Ignore pempreinstall=yes updateInstalledDrivers=Yes [GuiUnattended] OEMSkipRegional=1 TimeZone=85 OemSkipWelcome=1 [userData] ProductKey=XXXXX-XXXXX-XXXXX-XXXXX-XXXXX FullName=" " OrgName="ORG" ComputerName=%MACHINE% [Display] BitsPerPel=32 Xresolution=1280 YResolution=1024 Vrefresh=60 [TapiLocation] CountryCode=44 Dialing=Tone AreaCode=028 [RegionalSettings] LanguageGroup=1 SystemLocale=00000809 UserLocale=00000809 InputLocale=0809:00000809 [setupMgr] DistFolder=C:\sysprep\i386 DistShare=windist [Networking] InstallDefaultComponents=Yes JoinDomain=%MACHINEDOMAIN% DoOldStyleDomainJoin=Yes [sysprepcleanup]
-
Ok moved from RIS to WDS this summer I had to make new images for all suites anyway so thought I'd run WDS in naitve mode and learn wim images while I was at it. Its all gone well partitioning works far better in windows PE than in XP setup etc. However I've hit a wall with machine nameing. With RIS when installing a machine that was already in AD it would name the machine the same as the existing record in AD as long as the GUID matched and it would stay in the correct OU. If it couldn't find a matching GUID it would generate a new name based on the auto generate rule and place it in a default OU set on the same page of server properties. I set up the equivalent Properties Page in WDS but whether the PC is known or unknown my images are copying over and extracting running mini setup for XP and just popping up and asking for a machine name every time. I'm guessing either WDS needs be told to write the machine name from AD into the image when it transferes it to the PC or soemthing needs added to the sysprep.inf to make it ask AD for its name but I can't find any mention of it no matter what I search for on Google. All the guides etc just gloss over this as if it wasn't an issue for them. I can't be the only person that doesn't want to have to type ina machine name every time. My Vista suite works fine of course. Its just the XP ones.
