Willott
Members-
Posts
787 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Willott
-
Smoothwall Express Subdomains
Willott replied to clarky2k3's topic in Internet Related/Filtering/Firewall
From the looks of it you'll be looking to do reverse proxying - I don't know whether smoothwall express has this feature. (I know that may not be of much help, but it may give you something to look for). If it doesn't then the easiest solution may be to get a second IP for external access to your mail. Edit: Looks like I should finish one job at a time, benaus has given a more full answer than me. Cheers Will -
Does the telephone system fall under your remit?
Willott replied to bandgeekmafia78's topic in Mobile Devices & Tablets
Just thought I better add - I used to work with Asterisk/Trixbox systems quite a lot before coming to this job and using it here, so I was happy to play/fiddle/kick it until it worked (and I understand what may be going wrong). There are a number of possible routes to go if you're unsure about setting it up yourself. The big names tend to be the big old school PBX supplier names, plus some of the network company names - this is where your budget may be useful! Asterisk and Trixbox both have commercial versions, and I think trixbox also has an appliance should that be the way you wanted to go. -
Does the telephone system fall under your remit?
Willott replied to bandgeekmafia78's topic in Mobile Devices & Tablets
Haven't dont redundant servers yet (but our physical servers running the VMs allow for physical failure), but may look at that in future. We've gone full VoIP, so the only hardline is a backup line in reception in case of total PBX/internet outage (using IAX2 trunks with hard line fail over). Line rental is about £60 a month for 20 inbound calls, and 4000 mins landline and 500 mins mobile outbound calls. So overall monthly costs should be less than line rental on 8 channels of ISDN30 (I believe about £120)! We're also looking at a SIP->GSM gateway with simplicity SIMs to add another outbound route for mobiles to reduce costs (and failover inbound route). Total cost thus far for hardware/software (factoring in partial cost of server) is probably under £4k - we did get a stonking good deal on our phones! Only issue we're having at present is some of our wifi phones, but that's most likely due to wifi coverage issues (being looking into - probably next year's budget). Cheers -
Does the telephone system fall under your remit?
Willott replied to bandgeekmafia78's topic in Mobile Devices & Tablets
Same as localzuk, built our own asterisk box (VM) and we're running over 50 extensions, and handling hundreds of calls (both internal and external) daily. Oh, and all for a lot less than you have in your budget! -
EMBC Filtering Inadequacies
Willott replied to Batman's topic in Internet Related/Filtering/Firewall
Some of the SSL proxy sites don't have a non-SSL version, so tend to be picked up less quickly by URL based filters - Smoothwall has (I believe the only) SSL MITM filtering, where SSL streams are opened by the smoothwall box, dynamic content filtering is done by the smoothwall box, and then passed to the client -it's a highly useful tool in the blocking of proxy sites! Cheers Will -
EMBC Filtering Inadequacies
Willott replied to Batman's topic in Internet Related/Filtering/Firewall
EMBC school - bought Smoothwall a couple of months back, haven't seen any incidents of proxy sites anywhere yet (and I put securus on looking for the word facebook and the only hits were links on sites). I was getting a little annoyed with the EMBC filtering, and the poor reporting and lack of dynamic content filtering, so went and found how good life is with Smoothwall. If you'd like to see it in action, let me know. Cheers -
Quick question for the Smoothwall guys - where does licensing stand on this, are you allowed as standard to have multiple instances running in active mode, or is it only active with passive for failover? If we're allowed multiple actives, I may bring up a second one with slightly different configuration for external parties. Cheers
-
Hi Daniel, I've spoken to Imran before, and he was also looking to get the kernel modified to allow for full xen support and better speed (it does seem to run fairly slowly in Xen currently), so when there's a beta, we'd be more than happy to test it for you! Amazon cloud sounds very interesting - would you be looking to load balance through RRDNS or some form of IP load balancing? Sounds like it may be a very good base for an ISP filtering solution! Cheers Will
-
Do you use mandatory profiles and do you have a .v2 version of the mandatory profile created (Vista and 7 use a different structure from XP)? It may be worth checking the machine event view to track down what is causing the user profile service to error out. Cheers Will
-
My random wondering from earlier was correct
-
It appears within your Smoothie, the area to dig through is /settings/ethernet/settings and /settings/ethernet/nics/settings-*. The nics/settings-* files seem to have MAC address assigned in there, so that may be somewhere to look.
-
Just had a quick look on our NG and there's no udev from what I can see... I'll see if there's anything obvious anywhere! Cheers
-
I used to have an issue on my old home file server whereby it would swap the network ports around on reboot (so my external IP would suddenly be on the internal card and vice versa). I can't remember fully, but I may have used udev to resolve - the dell article below seems to give some clues (page 3 has details about the udev line) - whether Smoothwall has udev or not I'm not sure (and I'm not sure how it may affect the machine). Can you specify mac address in the Xen machine config? Just a random wondering as to whether the mac address of the virtual nic is changing and causing issues. http://www.dell.com/downloads/global/power/ps1q07-20060392-Domsch.pdf
-
Remote access and Two Factor Authentication
Willott replied to gjames's topic in Internet Related/Filtering/Firewall
I have been thinking about this on 2 fronts - 1st for staff (with staff laptops) and secondly for students. For staff, I have VPN setup, with the first factor being machine specific (SSL Client Certificate unique to machine - if machine is compromised it can be revoked) and the second being user specific (domain username and password). For students (and staff without laptops), I'm thinking of having Squid setup in front of a Terminal Services Gateway, having authentication on the squid box which authenticates to a local database (1st factor - change password/pin in squid database if need be), then the user authenticating against the TS Gateway with domain credentials (and so showing them where they can logon to) - the second factor. This is only a theoretical idea of how I may do things here, it's most likely going to be the project for next year or the year after (along with a few more TSs so I can actually handle a large number of students being on - and hopefully a 100Mb net connection so we can handle a large number of students!). The 2 factor using mobile phones for single use pin looks interesting - may consider adding in something like that (that sends pin to predefined mobile number and links to a username in squid). Cheers Will -
OK, Are you trying to use the nagios web interface to see the status, or are you just looking to use nagios to send you alerts when there's a service issue? Regards
-
As it says, you have notification commands specified for a contact, and the commands are not defined. I would suggest removing the notification bits until you've got monitoring working, then add them back in, working through the config slowly. It may be worth grabbing a web gui for it if you're having difficulties with the config files. Grep for "notify-be-email" to find the file you're looking for. Cheers Will
-
Slightly off topic (well... quite a lot) - but I'm not aware of a quantity of a metric buttload - how does it compare to an imperial buttload? Back on topic - what difficulties were there (I guess this is where Rob could probably answer)?
-
Running Xenserver 5.0 update 3 and have it running successfully (though possibly a little slowly due to the kind of virtualisation used). I believe that there's someone at Smoothwall running a cluster of NGs on Xen (the hardcore kind, not the Citrix version), so it definitely runs. I didn't have any issues with networking - created a new machine with a single interface in Xenserver, ran install - configuring NIC. Job done (as far as I remember). Sorry I can't be more help! Maybe try reinstalling with a single NIC, then add a second once you have the first working (it's strange that they show as ethC and ethD tbh). @Tom: I'd be happy to test any Xen Kernel stuff if you need it - I believe for Xen support it's a kernel patch (I seem to remember Imran finding a link to something of use) - get on with it Possibly useful and interesting links: XenParavirtOps - Xen Wiki Also seems that on xen.org there are sources for kernels with Xen bits already in (would mean adding in necessary NG bits, but the Xen bit would be done!)
-
Another vote for service provider. If it's something to do with the service books, I think you can resend from your server. Cheers
-
What's telling you that the disk is full (you've said that explorer says there's only 7GB on there, so it shouldn't be that throwing the error)?
-
If it does it again... could it visit me instead... could do with another switch for my home lab, even if it's misbehaving, it'll mean I have a real problem to troubleshoot, rather than a made up one! Cheers
-
That still seems to me to suggest the apache DirectoryIndex being either changed or removed somewhere (it's the setting that choses what file to look for when you access /blog/). Other place to check is your apache error and access logs to see if there's anything there to give you a clue. Cheers Will
-
index.php set as a DirectoryIndex in apache config? Can you access the index.php file if you add that in the URL and does it display correctly? Cheers Will
-
I would look at using "opt out" instead of opt in. This way you don't need to disable anyone unless specifically requested. And to get round the "we didn't see any letter" issue, make sure it's published on your website, with a big sign somewhere saying that this is so. And, assuming you've got Parents' Evenings coming soon, put A3 copies of the letter on boards at the entrance.
