Jump to content

dylanm

Members
  • Posts

    34
  • Joined

  • Last visited

Reputation

75 Excellent

About dylanm

Personal Information

  • Occupation
    Technical Support Engineer
  • Location
    London

Employer (optional)

  • Company Represented
    Joskos Solutions
  1. We set up 2x SSIDs (one for staff and one for students) with a 64-character WPA2/WPA3 pre-shared key. It's certainly not as secure as a radius solution but as long as you are able to lock that password down (eg. Applocker to block netsh for all users, not sharing the password with users, etc) it should do the job. The time it would take to crack a 64-character password from a de-authentication attack is effectively astronomical (as long as it's totally random with numbers, symbols etc). This is not the best way from a security preservative though - If you're able to, go with the radius/PKI solution! You can build a "cloud radius" like solution using software/solutions such as freeRadius and a Windows Server CA with the Intune Certificate Connector and a Windows NDES server. Microsoft has recently released a Microsoft Cloud PKI within Intune as a paid add-on so this could replace the Windows Server CA with the Intune Certificate Connector & NDES part. You're not going to be able to use a Windows RADIUS server though as it requires AD accounts for each device so solutions such as Aruba Clearpass/Cisco ISE/freeRadius would need to be used instead. Hope this helps!
  2. Yes - Usually have an OpenVPN client installed on the server/vm to set up the connection back to their data centre and then a funky bit of software to install the sims client. I haven't had that much experience with it but seems to be a very bouched-together solution...
  3. Hi, We currently have around 6 schools with individual SIMS Connected Third-Party Connectors in place at each of the schools. We are looking to decommission the servers at each of the schools however the third-party connectors are still running on these servers. We would like to consolidate all of these third-party connectors into one virtual machine/server that we can host centrally at the Trust. Does anyone know if this is supported? Thanks in advanced!
  4. Give this box a tick within Intune and it should enable the Proactive Remediation (if I remember correctly).
  5. Give this a try: https://github.com/dylanmccrimmon/IntuneProactiveRemediations/tree/main/Repository/DigitalLicense Download the two scripts and import them/create a proactive remediation within Intune.
  6. I'm sure it will be okay however would do testing first. Should be fine as your devices have come with the license already (you paid for the license when you bought your device) however I'm not the best when it comes to Microsoft licensing & the fine print so I would say to speak to your Microsoft licensing reseller/supplier (if you have one).
  7. So the way the A3 Win 10/11 licensing works is that it "upgrades" the device to either Education or Enterprise depending on the embedded device license. A few examples below + diagram: Scenario: The device comes with an embedded Windows 10 for Education Pro license and a user with an A3 license user logs in. Outcome: The device will upgrade itself to Windows 10 for Education. Scenario: The device comes with an embedded Windows 10 Pro license and a user with an A3 license user logs in. Outcome: The device will upgrade itself to Windows 10 for Enterprise. Scenario: The device comes with an embedded Windows 10 for Education license and a user with an A3 license user logs in. Outcome: The device will stay on Windows 10 for Education. Scenario: The device comes with an embedded Windows 10 Home license and a user with an A3 license user logs in. Outcome: The device will stay on Windows 10 Home. Scenario: The device doesn't come with an embedded license and a user with an A3 license user logs in. Outcome: The device will remain unactivated until activated with a product key. Note, if the device has come with an embedded license but Windows is showing as unactivated, the A3 license will not take effect. You will need to extract the embedded license key and then activate Windows. I have a proactive remediation (that you can import into Intune) that will do this for you, all it does is extract the key and activate Windows + report the status based on a 1 or 0 return value (IntuneProactiveRemediations/Repository/DigitalLicense/). Microsoft has further guidance on subscription activation here that goes into a bit more detail. Hope this helps!
  8. As foofihhterjim mentioned, it relies on the device having a product key in the TPM chip/main board. For the A3 license to work, you will also need to use/have Windows 10 Education Pro installed on the devices. The A3 license upgrades the OS to then use Windows 10 Education. Here is a good article on the A3 license: https://learn.microsoft.com/en-us/windows/deployment/windows-10-subscription-activation You can also push out a script/proactive remediation in Intune to check for the product key and then activate windows if one is installed.
  9. From the sounds of it, you have 4 cores (2 pairs). Using the light trick works nicely to see if there is a physical break in the fibre-optic cable. Side note, there is a great tool on Amazon for visually checking fiber cores: https://amzn.eu/d/4KSIBrv What you could do is check how many of the cores are broken. As long as you have a minimum of two cores working from either pair of fibres you can get away with taking a core from each fiber if that make sense? This will get you up and running on the fiber temporary. If you only have one core working out of the all of the cores then unfortunately, I think your out of luck. We have a awesome cabling team that does our fiber and cable installations that I can get you in touch with (they are based in Essex but are pretty much national). They can run you a new fibers or re-splice the cable (if it is possible). PM me if you want more details.
  10. There’s nothing stopping me now - I use port 443 on my vpn server to bypass the LGfL firewall and tunnel all my traffic. Works great to get round the filtering and port blocking issues that LGfL has. So by blocking all outbound ports on the LGfL network isn’t blocking the stuff you guys was trying to block in the first place... however I do understand why it's done but I think it is too aggressive. For example, LGfL blocks all Cisco Meraki ports even though it's one of LGfL's offerings... as well as educational software - SQUID, B Squared, Third Space Learning to name a few. Just wished that LGfL would keep up with these new technologies and not be a ISP that is restrictive to the point where we have to raise a ticket each time we want to use something new or allow software to work. Even if there was a button in the support site to allow the most common ports open, I would be happy. Apologies for the rant,
  11. Filtering? Do you mean web filtering?
  12. Sounds like you want to use the splash page login with sign-on. For that to work, you're going to need to open up some firewall ports (at your school) to enable Meraki's servers to communicate to your NPS server at your school. While you can do this and it will work, just be aware that there is no encryption or at least very poor encryption between Meraki and your NPS server - This RADIUS traffic/data travels across the internet and is not internal all internal... Meraki has a guide on how to set it up - See here
  13. See Attached - Our guest SSID uses sponsored login so the guest put's in their name & email address and then the email address of a member of staff at the school. An approval email gets sent to the member of staff at the school who approves access and job done. Just one thing to be careful of is that if students have a school email address that is using the same domain as the staff. You should block emails from Meraki for these students. This will stop students from being able to join their devices to the WiFi. Meraki - Guest Config.pdf
  14. No problem! - Happy to be able to help. We did use the slash page and the members of staff would have had to accept an agreement however it became very annoying for staff as they had to keep agreeing to it - there was no option for a “one off” splash page for each device and it had to have a frequency of days between each acceptance (from memory the maximum amount of days you could set was 90). Therefore we decided to just remove the splash page. There is also an option to have the authenticate users with active directory from the splash page instead of the usual 802.1X way in however we shyed away from this as there wasn’t any encryption (or at least very poor encryption) between Meraki’s servers and our NPS server meaning that all the RADIUS traffic would of been unencrypted / very poorly encrypted across the internet. We do we a splash page/splash page authentication for our guest network and I’m happy to send you the config for it if you want?
  15. I've attached the configs/screenshots for both Meraki and NPS. Just as a heads up - If you are running NPS on Windows server 2019 and above, you will need to run the below otherwise you will get some issues with NPS and the windows firewall 1. Run sc sidtype IAS unrestricted in terminal/cmd as an administrator on the NPS server. 2. Reboot the server. If you are using the config I have attached - All you gotta do is run copy it to your NPS server and the import it via PowerShell or the NPS interface. Then go in and change the following: 1. Change the IP address in the RADIUS clients to your schools IP range or IP range of the VLANs that the WAPS uses. 2. Change the shared secret to a random long string (you will need to add this to Cisco Meraki as well). 3. Change the windows group to a group in your active directory (I like creating a group just for BYOD and then adding the all staff group to that group; It give a little more control if students need to use it or if there was a guest account that isn't a staff member etc). 4. In the call station ID, enter the SSID name of your schools BYOD SSID after the : (for example our BYOD SSID is 'WBPS - BYOD' so the value should be '.*.:WBPS - BYOD'). 5. If you haven't already - register the NPS with active directory. Hope this helps you NPS.zip
×
×
  • Create New...