Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

CrootUK

Members
  • Posts

    303
  • Joined

  • Last visited

Everything posted by CrootUK

  1. enable CLI for the user account on the web console you can get on, then ssh on and reboot just the management console of the controller thats down then you wont need to pull the controller or have downtime. id recommend controller firmware asap tho, does require “Low I/O” on the SAN.. id check the notes on disk firmware too if you have any to see if its important… as they require NO I/O to upgrade. don’t forget to turn CLI off after, better safe than sorry.
  2. Yea if I recall it was some different login that worked no matter what and couldn’t be changed but could only be used when accessed via the micro usb.
  3. We have just been inplace upgrading all our servers across the trust from 2019 to 2022 everything and anything, with no real order unless its “clusters or services with multiple servers” we haven’t had any problems with 95% of them, have had 1 rds and 1 file server that failed to upgrade and were rebuilt. Hope all goes smoothly for you!
  4. Full power down is one option, we had this and resolved it live by plugging in the micro usb on back of san and puttying into it, you can then run “reboot mc” thats just the web interface, “sc” reboots the storage There is a guide for this if I find it il add it! The web interface dying is a bug in one of the firmware versions, latest one fixes it.
  5. For those 1 week into the holidays how are things going? many room moves I can imagine!
  6. Id personally virtualise sccm on this physical host you are building so it can easily be moved in future. Raid 10 x 8 disks, use 2 for hot spare. 1 virtual disk as many volumes as you wish, doesn’t really matter.
  7. Snap, neither do we. Majority of my longest standing tickets are awaiting on people to fix spf/dkim/dmarc on there domains. Some are quick, some are slow..
  8. Most common for BYOD/Guest networks is they sit in a different vlan, where its layer 3 interface is on a device that capable of ACLs or Firewall rules, depending on what access points you have some may also have “client isolation” where it does that on the AP itself. ontop of the the network separation they should usually be Web filtered with https inspection (this requires a cert installing on the devices usually straight forward with QR) now depending on your policies/contracts with isps etc https inspection may not be required but usually it is.. To my knowledge Lightspeed only offers dns filtering for unmanaged/byod devices (this maybe wrong dont quote me on it) which may be enough for your school, but you need to understand the pros and cons and ensure its communicated with Head/SLT/Safeguarding Leads I would advise looking at the DfE digital standards for this as it will point you in the correct direction and offer you backing when making these changes. https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/filtering-and-monitoring-standards-for-schools-and-colleges for us, all our schools the byod/guest networks are in a different vlan, with web filtering + https inspection and outbound/inter-vlans traffic blocked on firewall.
  9. Some mentioned in here /showthread.php?t=237983
  10. Thats not bad, are you using SBCs at every site? what hardware did you go for?
  11. Keen to also know an answer to this Q, looking to move our 7 onprem 3cx appliances to a single cloud one soon.
  12. Unless your a sparky too, I wouldn’t go near it, if the school burns down cause you opened something that says not serviceable you wont feel great! Replace it, perfect excuse too.. Eaton has some great ones..
  13. OneNote for documentation. For assets its all in our ITSM, we are doing computer startup scripts writing hardware specs etc to a sql db which also gets imported daily to our ITSM ITGlue is cool but expensive
  14. We found on our SNAT if we were restricting it to certain ports on smoothwall it caused audio (RTP) issues even though every port was in there, once changed to all ports it fixed it.
  15. This has been a repeated task for us, firms with incorrect spf config or missing completely along with dkim/dmarc… some big names too. We have been strict on following guidance no “allow listing” of any domains/email addresses.
  16. yep using this method for multiple schools, works OK guide is thorough enough to follow through.
  17. Also much smaller, we have 1x all through (2400+ kids) (1x senior, 3x techs) 1x secondary (1x senior, 3x techs) 4x primaries (supported by field team) 1x alternate provision (supported by field team) 1x primary customer (not trust) (supported by field team) 11 separate “premises” in total though, some schools have more than one site. Central Team IT Lead x1 Tech Manager x1 (infra, projects, escalation for all sites) Tech Engineers x2 (infra, projects, escalation for all sites) Field Team (supports primaries, alternative provision and customers) Senior Technician x1 Technician x1 14 staff total in IT. We fight not to support AV, but sometimes we have too, CCTV and Door Access sits with Facilities team, everything else “IT” is us, no MSP.
  18. Can confirm blocking calculator with applocker package app rules, works fine.. Do you have package app rules enabled on the properties tab of applocker config? Useful to also use to block all apps apart from microsoft signed ones for students due to the store not always instantly blocking and students trying their luck with VPN apps.
  19. Anyone found a cleaner way to do this?
  20. CrootUK

    Server Source

    correct
  21. we use a public/signed cert from comodo on our radius servers due to this, we just enter the cert domain in domain field and it just works.
  22. smoothwall onprem should probably have oauth for emailing now anyway… more secure and its the future[emoji106] unless they ditch emailing onprem..
  23. Had to log a ticket for two of our smoothwalls as they were only showing leeds-71, they got sorted today.
×
×
  • Create New...