-
Posts
389 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PaddyNewman
-
@Koldov Whilst I know what HomeProtect is, I am not the guy that looks after it sadly. If you have emailed them and have got stuck feel free to try again/forward to me and I can pass to them no worries. I understand the balance, I deal with people well above me skill wise and also people that just want a fix and don't know what a patch lead is so we try to cater for the majority and in between. I'm fortunately able to poke various/most bits of our system, I'll probably be doing your HTTPS migration also, so all good. Support team are the first line you see so its key that you get what you intended to get by raising the case. It has been a bit troublesome to get people up to scratch when its pretty much isolated and everyone is at home, but still, we try to give 100%. I get how it is in your position though! If you IM me your case refs I can go take a look.
-
As @Face-Man points out, you can do that, it would save you requiring a VPN every time you wanted to do something. You can enable/disable file transfers per bookmark too which helps with moving files and means they don't have to run SIMS from home, just from their school based machine. If you had an RDGateway, we can sort that for you also. If you need anything configured or advise, don't hesitate to give us a buzz
-
Hello, If you need a hand, happy for you to give me on a call on the normal support line, I start around 9am. We can block SMB using your machines firewall or I can knock something up on your school firewall quite possibly. Let me know! If you do come through to support, just tell them I asked you to call. Paddy
-
Sophos Intercept X - LGfL licenses
PaddyNewman replied to cbsc's topic in London Grid for Learning (LGfL)
Thanks for the update, glad they were added. Sadly I think everyone is stretched right now and the majority or working from home, not just in AdEPT but also all other associated parties, whilst its not an excuse, it does make interaction a little harder. -
Sophos Intercept X - LGfL licenses
PaddyNewman replied to cbsc's topic in London Grid for Learning (LGfL)
Keeping an eye on this one. I've seen plenty of cases and I believe we have contacted Sophos and they are aiming to renew licences ASAP. Afraid I can't just turn around and ask someone as the majority are working from home, but I'll prompt for an update. @cbsc feel free to DM me a case reference and I'll look into it now for you. -
I will be there Thursday, obviously on our stand (Atomwide/AdEPT), so feel free to come say Hi! Your talk on Wednesday interests me, but sadly I'll be in the office!
-
^^ Pretty much that, also note if you have any MIPs on the firewall and mail relay page, some devices will have an alternative public IP.
-
Hi @xicor Do you mean you want it so you can only login from LGfL IPs, just your schools one or similar? Can't suggest anything regarding password spraying other than making sure passwords are not generic, can't tell you how many times over the years I've seen 'bursar' accounts with the password of bursar or 'schoolname' and thats going to be an easy catch. Thanks Paddy
-
Read-only view of DNS entries on Support site
PaddyNewman replied to gh5000's topic in London Grid for Learning (LGfL)
@DaveAshworth wasn't sure whether to thank the post or not... I have your case and will remove those for you! -
Read-only view of DNS entries on Support site
PaddyNewman replied to gh5000's topic in London Grid for Learning (LGfL)
@ghanel This should now be in place for you, on the support site under Service Desk > View DNS records. Can you take a look and let us know if that helps? -
Hi @xicor I can see my colleague has updated the IPs for you. Is this working now? If not let me know and I'll look further for you. Thanks Paddy
-
Hi xicor. As above, send me a PM with the reference and I'll take a look for you, I can't today as it's Saturday and I'm actually in the US on holiday, but I return Monday morning. I can also pass on to my colleague to assist if it's urgent Monday morning etc Assuming this is you going out to a remote NAS?
-
We aren't on 4.2 currently, but its definitely worth giving a try if we can licence it, thanks!
-
LAN DNS servers are provided down the VPN, problem being the computer is not always querying it down the VPN. A capture will show a query to the gateway for DNS and the record not found response. It 'should' go down the VPN but it isn't. The VPN works fine for most customers, but the only ones I've ever had issues with using AnyConnect and Split-DNS are users that have real world domains internally, every one I've had to troubleshoot has had external DNS resolving an internal request. To 'bodge fix' these, I usually just ask them to change their mapping batch to use an IP for home users, but in this instance I think its all group policy mappings rather than batches on logon. By all means I am happy to listen to any solutions
-
Hi there, Genuinely interested to hear what DNS changes could be made to make this work, for my own knowledge if anything else! Are you able to let me know what you would do in this situation as currently the school use their external domain internally and we use split-dns to tunnel this down the VPN. In this instance, it wasn't going down there and looking at public DNS. This would mean they would need to have private IPs in their public realm DNS and thats just not great.
-
Just a reply to this as I feel it was me that dealt with your support case. We use AnyConnect with split-DNS configured. You provide your domain name to us (which would be your real work domain, you haven't got a subdomain of that) which is then configured in the VPN; Example.. default-domain value school.borough.sch.uk Would then have a rule to allow both direct LGfLDomain and SpecifiedDomain through the VPN. split-dns value lgfl.org.uk school.borough.sch.uk When your machine from home connects and you ping PCNAME1, it'll try and append those. If it decides to query your outbound DNS rather than going down the tunnel, it'll hit public DNS, get no resolution and not work. This is what was happening in your instance. By all means, if we can get another case raised and we work together on it, we can narrow down what is happening. I'd suggest installing Wireshark, whilst it won't see into the VPN, it will see all other traffic, so you'll see a DNS request outbound to your local DNS. If that happens, the device isn't sending down the VPN. I'm happy to do this from home to replicate exactly what you have in place but I'll need some basic AD credentials to log in etc. if you want to go forward, ping me in a case and I'll assist as much as I can. Thanks Paddy - Atomwide.
-
Read-only view of DNS entries on Support site
PaddyNewman replied to gh5000's topic in London Grid for Learning (LGfL)
@minimoo again out of office so replies aren't so plush, but if there are ever issues like that, call in and ask for me, I aim (as do our service desk team) to do a first call fix, but obviously if you want something done and it doesn't break core rules, please feel free to ask for me. I'm not saying it will 100% get done there and then as we often need written confirmation but I'll aim to get it working within a very short time. @DavidYoung has unfortunately spent too long on the phone with me to the point my phone timed out, so I'm always down to assist! Firewalls should be replicated there, it's a manual process, I make the fw change, I update the page, sometimes this gets missed or someone doesn't 'lock' it so it's not visible but we routinely check these. But yes, there is human error on that side, I'm guilty of it also. -
Read-only view of DNS entries on Support site
PaddyNewman replied to gh5000's topic in London Grid for Learning (LGfL)
@DavidYoung afraid I'm out of the office today but a quick one with the SPF, we can't assume schools only send via MailProtect, some have their domain posting from web hosts for website mailers and other places, we would impact that mail... Essentially we can't assume. I know what you are saying though.. but it's above me politically I'm afraid! -
Read-only view of DNS entries on Support site
PaddyNewman replied to gh5000's topic in London Grid for Learning (LGfL)
@minimoo What happens when you pop your domain into - https://intodns.com a) Raise a case, I'll make it so it just redirects to the www if you want? b) Doesn't matter too much unless you know what you want? c) as above really. d) intodns doesn't complain about it, unless your domain differs to our lgflmail.org one. e) same as above. Feel free to raise a case for my attention and I'll use our redirector to just flip it to www if you want. I'll take a look at vinyldns, the problem I would expect is that we would need to embed with USO, it would require serious work and integration to get this working but its definitely worth a look, I can pass that on anyway for consideration. Thanks Paddy -
Read-only view of DNS entries on Support site
PaddyNewman replied to gh5000's topic in London Grid for Learning (LGfL)
Valid points @minimoo I'll be honest, being able to add TXT files for verification is a good idea from the verification side of things for Lets Encrypt and G Suite etc... but TXT also includes SPF and I've seen some REALLY dubious SPFs being passed over to us for addition, if they had added these themselves it would have had bad consequences. Such as being within LGfL StaffMail but adding a -all for the Google recommended SPF, or having multiple includes which exceeds the 10 lookup limit within a single one because they've omitted the first subdomain of the SPF lookup domain (I'm staring at one now) which cause a permanent error and fails SPF checking... sorry if I'm in the sucking eggs realm! Whilst I appreciate there are a fairly big group of technically capable users within our supported schools, we also do have to cater for ones that really don't understand the concept of DNS and try to assist or at least guide down the correct path. Few cases of bad requests, CNAME on the root domain, incorrect SPF etc are what we mostly see and we try to remedy these requests and advise the customers beforehand. I do think visible records would be helpful for the majority. I can't think of a logical way to let users manage their own DNS though without having their domain sent elsewhere as its an internal DNS system but I'll certainly feed this one back for you. Any other suggestions? Thanks Paddy -
Great news! Thanks for pointing that out.
-
@DavidYoung we've pushed out a change regarding validation. Can you cast your eye over, enter an incorrect IP and let me know how you find that. Thanks for the feedback regarding the UX. I've fed this to our teams also!
-
@DavidYoung @JohnJackson a fix is being looked at now, you do get empty reports (logically correct as it's per establishment) but as there is no prompt regarding the establishment it makes it problematic. I'll update you asap!
