Showing posts with label General Troubleshooting. Show all posts
Showing posts with label General Troubleshooting. Show all posts

Thursday, 17 June 2010

SBS – Setting WSUS Synchronization Frequency

In our SBS 2008 Setup Guide V1.5.0 at step 22 we indicate some customizations to the WSUS setup.

  • 22: Make changes to the WSUS Setup:
    • WSUS Classifications: Enable all except Drivers.
    • WSUS Sync Schedule: Increase synchronization frequency schedule depending on what products are installed on the server.

If we have Forefront Server Security for Microsoft Exchange licensed on the SBS 2008 box, we would set a synchronization schedule of once per hour.

Now, since we use ExchangeDefender for our e-mail sanitation needs, we generally do not need to synchronize WSUS with such frequency as Forefront would not be installed.

However, we tend to set that frequency to at least 6 checks per day which equates to synchronizing every 4 hours.

Why?

In the above blog post, Damian examines an issue with a SVCHOST process causing a spike in the SBS server’s CPU.

After some troubleshooting by Damian, the problem turned out to be the Windows Update client and a series of Forefront updates.

Here is another WSUS update related issue that hit us:

So, when a problem fix is published by Microsoft to WSUS, it will not hit SBS until the next scheduled sync. The default is 1 sync per day (24 hours).

Our setting the WSUS sync schedule to every 4 hours is our attempt to mitigate any possible problems we may encounter.

WSUS Driver Classifications

As far as not allowing drivers to come down through WSUS, we do this for heterogeneous networks that still have Windows XP Professional installed on physical hardware.

For homogeneous Windows 7 networks, which are starting to be the norm, we enable the Drivers classification as the drivers delivered have been consistently stable in both the update process and in post update system stability.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 21 May 2010

Troubleshooting Flaky Systems Behaviours

Sometimes, we need to learn lessons the hard way.

I remember replacing the rear end on a 1500 series truck (mine) due to a major squealing sound that did not go away _after_ the change out. The problem turned out to be the hanger bearing. Lesson learned.

When it comes to computers, there is the workstation that behaves rather erratically over time. We would go through the regular troubleshooting steps looking in common problem areas such as software conflicts, memory issues, or physical problems on the hard drive’s platters.

Or, how about the printer that behaves fine for a number of days then stops responding or prints out funky characters instead of the page(s) sent to the printer.

The lesson being highlighted here has to do with starting with troubleshooting the small things first.

One of the small things that is common to both IT related problems listed above was that the interface cable turned out to be the culprit.

In the first example where the workstation was behaving flaky, the SATA cable connecting the hard drive to the motherboard turned out to be the problem.

For the printer, the USB cable connecting the printer to its workstation was the problem.

It is probably due to just how rare a cable turns out to be the culprit in a problematic setup that we overlook changing them out as part of our early troubleshooting steps. We usually go to some fairly great lengths to troubleshoot a problem before a cable even becomes a consideration.

So, sometimes, depending on the errant behaviour, it may be a good idea to actually _start_ by swapping out whatever interface cable or cables. We can then eliminate them right out of the box.

BTW, when it comes to USB cables and printers, watch the length of that USB cable relative to the cable’s diameter. If there is a need to run a cable longer than the standard 6’, then make sure that the extra length cable contains a heavier gauge core cable set to reduce the possibility of signal loss between the PC and the printer.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Saturday, 5 July 2008

SBS - Dragged email to my Mailbox - Philip Elder folder ... where did it go?!?

This was probably one of the more interesting predicaments that we needed to research today.

A user accidentally drags their email onto the Mailbox - User Name root in Outlook that is Exchange integrated.

There is no real way to get to that email using any Outlook folder hierarchy.

So, what do we do?

Well, if we are running Windows Vista, we can click the start button and type a few of the email's details to bring it up in the search results. From there, it is a matter of right clicking on the email in the search results and clicking on "Move to Folder" to place it back into a regular email folder.

If we are not running Windows Vista, and the Desktop Search feature does not find it on Windows XP, then we need to build an Advanced Find in Outlook. The neat thing about the Advanced Find is that we don't need to know any keywords. We need only click the Browse button and select the Mailbox - User Name folder along and not Search Subfolders. The search will happen quite quickly and we will be able to highlight them all and right click on them to move them to another folder.

This is the search result with a keyword:

Found Email in IPM_SUBTREE Folder

Note that they are found in a folder called the IPM_SUBTREE.

Ultimately, what lead us to the solution was having all email in Outlook read, right clicking on one and marking it as Unread, then dragging it over the Mailbox - User Name and letting go.

The Search Folder for Unread Mail showed one! Click on the Unread Mail Search Folder and voila: We have our missing email in the above IPM_SUBTREE folder. We realized after the fact that the Windows Vista method also reveals this folder ... if we have the Folder column enabled in the search results!

With that information in hand we were able to find Gilg's Weblog post: Finding lost mail in your top level Outlook/Exchange root that pointed us to creating the Advanced Find in Outlook. We restructured the find with no keywords and having it point only to the Mailbox root to discover any items there.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Tuesday, 1 April 2008

SBS Premium - ISA Client Firewall Icon

Sometimes it can be difficult to communicate just what the ISA Client Firewall Icon looks like when phone based troubleshooting with a client.

ISA Client Firewall Icon on the right

The icon to the left of the ISA icon is the Windows Vista Sync Center icon indicating that it is currently up to date and happy with the UT connected to the workstation.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Monday, 18 February 2008

Acer hard drive failure, flaky behaviour, and subsequent BSOD STOP framebuf 0x000000EA

Lately, one of our client's users was complaining about their laptop taking an inordinately long time to boot up.

To us, this usually indicates to us that there is a physical problem on the hard drive in the area where the OS has files written to. The extra time is the OS rereading the same sectors over and over again to get a proper read off of them.

So, we contacted Acer for a new hard drive. They sent one out immediately as this particular client always purchases the Acer Total Damage 3 Year warranty.

In the mean time, we took a ShadowProtect image of the existing OS and restored it to an identical replacement hard drive we keep around the shop for situations like this. Thus, we get the client's user back up and running in short order, and we place the incoming warranty drive on the shelf to be swapped back out when the user has some time to spare.

The hard drive swap did indeed work. The system now booted up in a reasonable amount of time, and seemed to be running all-around in a quicker manner.

So, out the door it went.

We then received a call from the user a few days later indicating that the system had blue screened again, and that their Kinston USB flash drive (DTSP) was no longer working with the laptop USB ports.

They were on-site and required an immediate replacement to get productive again. We brought in one of the older laptop spares they keep around for situations like this.

When we brought the system back to the shop, we figured that the preveious hard drive failure may have caused some spotty corruption in Windows XP, so we took the replacement warranty hard drive sent to us by Acer and ran the restore to factory default recovery DVD.

We had started the process at the end of the day, and this is what greeted us the following morning:

Windows XP Pro: STOP framebuf 0x000000EA

Ouch.

A force power down, and a power up again brought the system up into the Windows XP startup routine and subsequently the Acer setup routine once into the OS.

But, given the number of other flaky things the laptop was doing, along with the BSOD on recovering to factory default, this is a pretty clear indication that something has failed or is failing on the system main board.

A phone call into Acer, and we will be seeing a courier here to pick the unit up shortly.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Tuesday, 11 September 2007

System Builder Tips: Intel S3000AH "PCI Device" and "PCI Serial Port" Unknown in W2K3

There is an issue for the S3000AH Intel server boards with Windows Server 2003 or SBS 2003 installed.

From Intel's site:
Intel® Server Board S3000AH
Two Unknown Device Under Microsoft Windows* Device Manager

On Microsoft Windows*, after installing all the drivers (onboard LAN, video and chipset), Microsoft Windows* Device manager is showing two devices - "PCI Device" and "PCI Serial Port", each of which has a yellow question mark.

The devices "PCI Device" and "PCI Serial Port" are the components of Intel® Active Management Technology(iAMT). iAMT is not available without driver installed for these two devices. The .inf file for these devices are included in the LAN driver package (10.4 or later), rather than the Intel® Chipset Driver Package.

There are two ways to resolve the warning:

On LAN driver package 10.4 or earlier releases :

(1) Manually install the iamt.inf for the devices. Extract the LAN driver package, select the "PCI Device" in Microsoft Windows* Device Manager and direct Windows to find iamt.inf in the \platform\IntelAMT\Drivers\WS03XP2K (for IA32) or \platform\IntelAMT\Drivers\WS3XPX64 (for EM64T). This will install the iamt.inf. Do same steps for "PCI Serial Port" device.

or

(2) Run the setup utility provided for the LAN driver package in \apps\setup\SETUPBD. This will install the LAN drivers and the iamt.inf. Alternatively, you can install the LAN drivers, PROSET software and iamt.inf file from \apps\PROSETDX.

On LAN driver package 11.0 or later releases :

(1) Manually install the iamt.inf for the devices. Extract the LAN driver package, select the "PCI Device" in Windows* Device Manager and direct Windows to find iamt.inf in the \PLATFORM\IntelAMT\Drivers\Win32 (for IA32) or \PLATFORM\IntelAMT\Drivers\Winx64 (for EM64T). This will install the iamt.inf. Do same steps for "PCI Serial Port" device.

or

(2) Run the setup utility provided for the LAN driver package in \apps\setup\SETUPBD. This will install the LAN drivers and the iamt.inf. Alternatively, you can install the LAN drivers, PROSET software and iamt.inf file from \apps\PROSETDX.
Intel's Site: Intel® Server Board S3000AH - Two Unknown Device Under Microsoft Windows* Device Manager.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Wednesday, 20 June 2007

SBS 2K3 - Group Policy computer settings not applied

In the continuing saga of merging two FAT32 partitions on a set of TravelMate 8210 laptops we just delivered, we ran into a strange problem.

We have a set of GPOs set at the domain level for the various security needs of this particular firm.

We kept getting the following error when the policies from those GPOs were trying to be set:



Event ID 1202 - SceCli: Security policies were propagated with warning: 0x4b8: An extended error has occur ed.
Clicking on the link in the error brings up the Help & Support Center pointing to KB 324383: Troubleshooting SCECLI 1202 Events.

Scroll down to the 0x4b8 section and they ask you to change a registry setting to enable debug logging. Run a gpupdate /force instead of secedit BTW.

That didn't work for us, so, off to the next search that landed us on: KB 260715: Event ID 1000 and 1202 After Configuring Policies. Again, no help or at least the article couldn't help us, but it did bring up the following error when we went to check the local policy settings for the administrator:


Security Templates: The Group Policy security settings that apply to this machine could not be determined.
The error returned when trying to retrieve these settings from the local security policy database (%windir%\security\database\secedit.sdb) was: The parameter is incorrect.

All local security settings will be displayed, but no indication will be given as to whether or not a given security setting is defined by Group Policy.
Any local security setting modified through this User Interface may subsequently be overidden by domain-level policies.
Someone didn't have their spellcheck enabled on that last line - overridden! ;)

To check the local GP:
  1. Start-->Run
  2. gpedit.msc
  3. [Enter]
Therein we find the key! The local security database is somehow toast.

A quick search for the first line in the error error turned up the process we use to fix the database. Run the following command from the command line:

esentutl /p %windir%\security\database\secedit.sdb

And you will see the results will below:


Once that process finishes, run the following line from the same command line:

gpupdate /force

The system should ask to be rebooted once the domain GPOs have been processed. A successful SceCli should also now be in the App log.

Sure enough, once the system rebooted, all security policies were in place.

Buried about half way down (could have missed it) is the above command line fix: MCSE.MS: Re: Group Policy Security setting could not be determined.

Thanks to Doug Knox for sharing that fix!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

Wednesday, 6 June 2007

Outlook 2003 - The messaging interface has returned an unknown error

We have a client that was receiving the following error when trying to print a public calendar:

The messaging interface has returned an unknown error
Okay, a simple search turns up the following Microsoft KB articles, but they are not relevant: None of them applied.

Once, and only once did we get an error indicating permissions problems on the task list folder before the above mentioned error.

So, when printing the calendar view, we went to the Page Setup button, and disabled printing the tasks list.

It worked.

So far, we haven't been able to find out just where the permissions conflict is yet.

But, they are happy about being able to print out their calendar again.

Honourable mention to the following who provided the key to figuring out how to get things going again:

Experts-Exchange: The messaging interface has returned an unknown error.

MCSE.MS: The messaging interface has returned an unknown error.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

Saturday, 2 June 2007

Windows Vista - Network file copy to workstation performance issues

Just a quick note to let you know that there is a recognized performance issue in Windows Vista when copying files from a network source to the local workstation.

You may see a "Calculating Time Remaining" message indicating "0 minutes remaining" and get nowhere with the process.

If you are having issues with this, then there is a Knowledge Base article and a hotfix for you!

Microsoft KB931770: The copy process may stop responding when you try to copy files from a server on a network to a Windows Vista-based computer.

Give Product Support Services a call for the hotfix!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

Friday, 11 May 2007

System Builder Tip: When intalling Vista 32 or 64 bit on Intel D945G, D975XBX, DQ965GF boards with 4 GB+

You may encounter Windows Vista installation issues on systems being built with 4 GB or more RAM installed on the motherboard.

If installing the OS with a pair or more of 2 GB sticks of RAM, you may experience STOP errors.

Have a pair of 1 GB or even 512 MB sticks around for the install. Use that pair for the OS and post OS installation driver updates. When Vista has booted up into the installed and updated OS, shut down the system and swap out that pair for the 2 GB sticks.

Boot the system up, and Vista should recognize the 4 GB , 6 GB, or more RAM in the system.

Oh, and make sure your BIOS is the most recent before starting the install! Early board BIOS versions were also prone to killing Windows Vista installs.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

Tuesday, 3 April 2007

Office 2007 - Word stacks the letters on top of each other...

I am feeling a little bit on the cranky side right now.

I am trying to print to PDF a document that is due on my client's desk soon.

This is what is happening in Word:


This is what the PDF output looks like:


It looks like that whether generated for PDF, on the LJ 4600, or on the LJ 5Si.

Copy and paste the document into Notepad, then copy and paste the content back into a new document seems to cure it, though with all of the formatting stripped.

Must be a legacy Word codes issue with the template being used...it is our default letter template that has been around for a long time!

Ack! Things always seem to break when on a deadline! 8*O

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

Thursday, 29 March 2007

TroubleShooting: How to reset Internet Protocol (TCP/IP) in Windows XP & Vista

Occasionally there are seemingly unexplained reasons for no network communication on a system.

Sometimes the removal of a software firewall or some sort of OS update can be seen as responsible.

Either way, we may need to reset the TCP stack. XP follows, Vista is further below.

The following Microsoft KB 299357: How to reset Internet Protocol (TCP/IP) in Windows XP explains the ins and outs of the methodology.

Simply:

netsh int ip reset c:\resetlog.txt

The resetlog.txt will be made in the root of the drive where it can be scanned for any errors.

Generally, you are back in business!

Okay, in the case of the system I am working on now ... NOT. :D

Next step:

In the CMD window where I release the IP and try and renew it I am getting the following error: You receive an "An operation was attempted on something that is not a socket".

The following Microsoft KB 817517: You receive an "An operation was attempted on something that is not a socket" error message when you try to connect to a network contains further steps to take on, in this case, Windows XP:

Export and delete the corrupted registry subkeys

  1. Insert a floppy disk in the floppy disk drive of the computer whose registry entries you are exporting.
  2. Click Start, click Run, type regedit, and then click OK.
  3. Locate and then click the following registry subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock
  4. Do one of the following steps, depending on the operating system:
    • For Windows XP, on the File menu, click Export.
    • For Windows 2000, on the Registry menu, click Export.
  5. In the Save in box, click 3½ Floppy (A:), type a name for the file in the File name box, and then click Save.
  6. Right-click Winsock, and then click Delete. When you are prompted to confirm the deletion, click Yes.
  7. Repeat steps 3 through 6 for the following subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2
    Note Each .reg file that you save must have a different name.
  8. Right-click Winsock2, click Delete, and then click Yes.
  9. Quit Registry Editor.
Then on to the following for an XP based system:

Reinstall TCP/IP on a Windows XP-based computer

In Windows XP, the TCP/IP stack is a core component of the operating system. Therefore, you cannot remove TCP/IP in Windows XP.

  1. Install TCP/IP on top of itself. To do this, follow these steps:
    1. a. In Control Panel, double-click Network Connections, right-click Local Area Connection, and then click Properties.
    2. Click Install.
    3. Click Protocol, and then click Add.
    4. Click Have Disk.
    5. In the Copy manufacturer's files from box, type System_Drive_Letter:\windows\inf, and then click OK.
    6. In the list of available protocols, click Internet Protocol (TCP/IP), and then click OK.
  2. Restart your computer.

After the reboot, the system should come up and have network connectivity.

In our case, the problem has turned out to be the Panda Platinum Internet Security 2006.

As soon as I uninstalled the product, the system had network connectivity. Going to try and reinstall it to see if it breaks things again.

UPDATE 07-05-07: For Windows Vista: A lot of searches are ending up here looking for the ability to reset the TCP stack in Windows Vista.

The first place to start is to run the native Vista repair feature:

  1. Click Start
  2. Type "Network" in Start Search
  3. Click on Network and Sharing Center in the results
  4. Click on Diagnose and repair (bottom of left list)

  5. Run through the prompts to repair the connection.
If that doesn't fix the situation, then a manual reset of both Winsock and the TCP/IP stack would be in order.

  1. Winsock
    1. Click on Start
    2. Type CMD in Start Search
    3. Right click on the result and run as Administrator
    4. netsh winsock reset [Enter]
    5. exit [Enter]
    6. Restart the system

  2. TCP/IP protocol
    1. Bring up the command prompt authenticated as Administrator (steps 1-3 just above)
    2. netsh int ip reset [Enter]
    3. exit [Enter]
    4. Restart the system
On SBS Premium based networks, make sure that the proxy settings are correct in the browser and that IE is seen hitting ISA via the ISA live logging feature.

Make sure that the correct drivers are installed on the system, that the connectivity lights on the NIC and at the switch are lit and active.

Check your patch cables, especially for laptops.

If you need further Vista related troubleshooting tips: Gateway Support: Windows Vista - Troubleshooting Network Connections.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists