Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

CrootUK

Members
  • Posts

    303
  • Joined

  • Last visited

Everything posted by CrootUK

  1. Whilst i’ve done this endless times on a traditional hyper-v cluster, not s2d so take this advice with a pinch of salt I’d personally do it via failover cluster manager; pause a node let all VMs drain which you can watch in vm/hyper-v view ensure the node is “paused” effectively then your running on how ever many nodes you have left. At that stage you should feel comfortable enough that a that remaining nodes can run the your environment. If you wanted to you could then power down the host and go as far as pulling the power out (imo not needed) Once ready power the node up and give it a few minutes, then run “get-storagejob” in powershell to check the storage sync is good (which does run even on paused nodes to my knowledge) then resume the node in the node view in failover cluster manager. If your using Windows Admin Center advice is similar but a little different. your powershell is fine, pro with GUI method is you get to see it doing stuff, vms moving, storage moving etc.
  2. I would like to see Tom talk about smoothwall roadmaps? I haven't seen a roadmap on your website. Something like this would be really cool and worth while. https://usehalo.com/haloitsm/roadmap/ Im a frequent checker of the release notes page, but I think a roadmap would really help your customers to know whats coming in the future, which all us nerds in IT love...
  3. Problem with this, is if we failed over too another circuit we would obviously have a different public ip, in smoothwall the ipsec we have currently since being on maiden with have had to specify the public ip of both ends in the settings for the tunnel to establish, I suppose we could just make lots of tunnels of each the possible public ips for each site but i’m not to keen on that idea it could get messy.
  4. Hi folks, Im curious what other trusts are doing on here when it comes to retaining routing/comms to other schools when having two different broadband circuits? is anyone doing this with smoothwall? does it work well? I know SD-WAN is the obvious solution, but we don't have anything capable of this currently. Thanks!
  5. Correct there will be nothing there. I have seen PXE boot not work without a TS being available. What you configure in MCM you wont see in WDS.
  6. I have worked with alot of these and I am yet to see one requiring or having the aux pci plugged in.
  7. I would add a windows wim file and build a basic TS and try again. PXE via mcm acts much differently to regular WDS.
  8. Top piece is correct, second piece just a default.bcd file. Have you updated your boot image in mcm with tickbox ticked to use from ADK? have you selected the correct bootimage on Task sequence properties.
  9. Have you installed ADK and WinPE addon? https://www.prajwaldesai.com/update-windows-adk-sccm-server/
  10. Eaton 5PX2200G2 [email protected]
  11. Fair enough. Lots of options if you have issues again though without breaking the bank.. Entra App Proxy for RDWebclient or your smoothwall can do VPN. Touch wood it doesn't happen again, do you have any support for the ASA? worth logging a ticket..
  12. New ASR rule now out that does this https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference#block-rebooting-machine-in-safe-mode
  13. Yep agreed, with budgets in schools though, if you’re already invested in a product that can do both, certainly makes sense to do so, if said product is capable of doing so well that is. If you were using say netsweeper then yeah separate firewall is your only option lol.
  14. Probably not useful sorry - with that ASA being eol and nearly eosl, is it not worth replacing? I see you previously talk about smoothwall, any reason your not using that as a firewall?
  15. Hi folks, For those that have centralised a Paxton server for their trust, how have you split up your individual schools within the system? Just door access groups or areas or something else? Many thanks!
  16. Support has been spot on for us in recent years. Really owt to send the team some chocolates tbh!
  17. What hardware are you running on? Are you using fiber or copper?
  18. if your DC is above 2008 R2 DES will be disabled by default anyway, even if the msDS-SupportedEncryptionTypes attribute on the computer object supports it. You can change this attribute on smoothwalls computer object to be 28 it should clear this warning and continue to work. (you can confirm this by running a diag on the directory in smoothwall)
  19. PaddyNewman mentioned that, glad its working, nice work.
  20. Transparent proxy is correct for BYOD, could you share some screenshots? as I am not convinced you need to change much at all. Like I mentioned before happy to do a team’s call if your a school worker not an MSP lol… if its of help, i’m not from smoothwall or an MSP myself but we do use smoothwall in our schools so familiar with them.
  21. We push our accounting to central radius servers, radius servers then to relevant smoothwall, very simple to setup and works well. (you do have to add nps servers in as authorised clients on the BYOD page on smoothwall) Like others say web proxy should be on core auth. I had UniFi previously working for this but just removed our last controller so don’t have config to compare sadly. The custom browser or browser extension isn’t needed for this, neither would be very feasible on a BYOD device tbh. Happy to have a team’s call if we can help! PM me.
  22. Meraki is possible with that budget, highly recommend https://www.redwaynetworks.com
  23. Its on the drop down of the below. Technical requirements before attempting a password re-set https://support.pearson.com/uk/s/article/Edexcel-Online-Forgotten-Passwords I am still discussing this with Pearson, again they've told me to add the DNS record into the firewall rules which we can't do as I have already explained to them multiple times.
×
×
  • Create New...