Showing posts with label SBS Monitoring. Show all posts
Showing posts with label SBS Monitoring. Show all posts

Wednesday, 8 December 2010

SBS 2003 – MSExchangeIS Error 9646 – Exceeded Maximum Objects

One of our SBS 2003 sites had the following in their morning report:

image

In the Event Logs we found:

image

Event Type:    Error
Event Source:    MSExchangeIS
Event Category:    General
Event ID:    9646
Date:        12/8/2010
Time:        9:46:25 AM
User:        N/A
Computer:   SBS
Description:
Mapi session "/o=DOMAIN/ou=first administrative group/cn=Recipients/cn=FirstLast" exceeded the maximum of 32 objects of type "session".

For more information, click http://www.microsoft.com/contentredirect.asp.

A quick search turned up:

The instructions were as follows:

  1. Click Start, click Run, type regedit in the Open box, and then click OK.
  2. Locate and then click the following registry subkey:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchangeIS\ParametersSystem

  3. If the Maximum Allowed Sessions Per User entry does not exist, do the following:
    1. On the Edit menu, point to New, and then click DWORD Value.
    2. Type Maximum Allowed Sessions Per User as the entry name, and then press ENTER.
  4. Right-click the Maximum Allowed Sessions Per User entry, and then click Modify.
  5. Click Decimal, type the value that you want to set in the Value data box, and then click OK.
  6. Exit Registry Editor.
  7. Click Start, click Run, type services.msc in the Open box, and then click OK.
  8. Click the MSExchange Information Store service, and then click Restart Service.

We configured the registry setting at 96. The default is 32.

Once we restarted the Information Store the user could connect to Exchange in their Outlook 2007.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Tuesday, 21 April 2009

So, just how stable is SBS 2008?

Here we are at day 86:

09-04-21 SBS 2008 at 86 Days

This particular client is just coming out of their peak season. We were not able to touch the server during business hours which for them were quite extended.

We will have a DRAC (Dell) remote management module installed on the server very soon so as to have out-of-band access to the box just in case there is any problems with updates.

We will also have the SBS OS DVD 1 in the optical drive so that we can recover the OS to the backup point we created just before running any updates.

With the DRAC, or its equivalent, we can do all of that from anywhere we have an Internet connection.

So, just how stable is SBS 2008?

In this case, the built-in SBS 2008 backup started showing a bit of strange behaviour as the server would bog down when it was initializing. We moved the backup to outside of their working hours and stepped up the Volume Shadow Copy frequency to compensate.

The server has been rock solid to date. We guesstimate that a reboot will be happening this coming weekend or the following one depending on the slow-down period for our client.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Tuesday, 24 March 2009

SBS 2008 – Terminal Services Gateway server is temporarily unavailable

Here is one of those cryptic error messages when connecting to an SBS server via RDP:

09-03-24 SBS 2008 - Gateway Temporarily Not Available

Remote Desktop Disconnected

This computer can’t connect to the remote computer because the Terminal Services Gateway server is temporarily unavailable. Try reconnecting later or contact your network administrator for assistance.

Now, since we are the network administrators, we now need to figure out just what is going on.

The first instinct is the Internet connection may be down. But, when we bring up the Remote Web Workplace (RWW), the site is there.

Try and log onto the RWW, and this is what we are greeted with:

09-03-24 SBS - RWW - Change Password Page

RWW: Password change needed

If we did not try and log onto RWW, the next logical step would have been to troubleshoot what was going on with the TS Gateway service in the logs.

Once into the server, the TS custom view in the Event Viewer had no errors whatsoever.

In our custom logon failure Event Viewer Custom View (SBS CodePlex) however, we found the following:

An account failed to log on.

Subject:
    Security ID:        NETWORK SERVICE
    Account Name:        SBS$
    Account Domain:        MySBSDomain
    Logon ID:        0x3e4

Logon Type:            3

Account For Which Logon Failed:
    Security ID:        NULL SID
    Account Name:        MyUserName
    Account Domain:       

Failure Information:
    Failure Reason:        The specified account's password has expired.
    Status:            0xc000006e
    Sub Status:        0xc0000071

A quick run through the logs produced the above. We made sure that all of the services were happy before accomplishing the folder recovery we needed to and then logged off.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Tuesday, 17 March 2009

SBS 2008 – New CodePlex URL and Backup Failure Filter Added

We just uploaded the XML to create a custom Event Viewer filter for failed backups onto the SBS CodePlex site. Once that XML has been set into a custom view in the Event Viewer we can attach a task to fire an e-mail off to us if the backup does indeed fail.

09-03-17 SBS 2008 CodePlex Site

SBS CodePlex 

Note that the previous URL to access the CodePlex site was:

The new URL is:

Have a look at the various SBS Console custom alerts as well as the custom Event Viewer filters that are to be found on the site.

The XML code on the site can be packaged up and become part of the SBS setup done for production SBS 2008 boxes by default.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Thursday, 5 March 2009

SBS 2008 – Failed Logon Custom Event Viewer Filter XML Updated to Include RDP Attempts

We updated the XML for the Custom Event Viewer filter to include failed logon attempts via RDP.

You can find the XML code along with instructions for creating the custom filter in the Event Viewer here: SBS CodePlex Custom Event Viewer Filter for Failed Logons.

Note that there are other XML files for Event Viewer custom filters along with the XML code to flag the failed logons in the SBS Console among other server events.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer

Wednesday, 4 March 2009

Just finished an SBS 2008 Setup Webinar for the folks in Johannesburg South Africa!

Greetings to the folks in Johannesburg!

It is 0400hrs (4AM), and Harry and I just wrapped up a Webinar running through a Small Business Server 2008 setup routine as well as a few of the post OS install configuration steps using our SBS 2008 Setup Checklist.

We also went through some of the key new features in Group Policy, Exchange, SharePoint, and Terminal Services among others.

We have another big day ahead of us today too … though it will be shorter so as to catch up on some rest. :)

Thank you to all of those that participated in today’s Webinar. And, thanks for the questions and keen interest in SBS 2008!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer

Wednesday, 25 February 2009

SBS 2008 – Get An E-mail On Failed Logon

One of the new features we inherit via Windows Server 2008 is the newly revamped Event Logs. We now have the ability to monitor pretty much anything happening on the server.

For those of us that manage SBS 2003 networks, we only knew when something was happening with a user account when we would receive an e-mail indicating that a user account had been locked out. No indication was given as to which account and when! We needed to filter through the Security log or the user would be calling for a reset of their account.

Now, we can actually have an e-mail happen from the SBS server that tells us that a failed logon attempt has happened, each time an attempt has made and in “real time” (depending on Outlook’s Send/Receive settings).

09-02-25 SBS 2008 - Failed Logon Attempt E-Mail

SBS 2008 E-Mail – Failed Logon Attempt

If there are hundreds of these e-mails filling the Server Monitoring folder for that client’s server, then obviously there is a priority problem that needs to be addressed right away!

The e-mail may be not too clear on the who or what, but we don’t have far to go to find those particulars out.

Log onto the SBS server and have a look at our Custom View in the Event logs and here is what we find:

09-02-25 SBS 2008 - Failed Logon Attempt - RWW

Event 4625: An account failed to log on - RWW.

And:

09-02-25 SBS 2008 - Failed Logon Attempt - Server

Event 4625: An account failed to log on – Server.

We get a lot more information on where the attempt was made from and to what service.

One of the benefits that comes with being made aware of failed logon attempts is getting to know when our client’s password refreshes are happening along with which users tend to miss their logons after that refresh.

The XML code for the above Custom View can be found on CodePlex: SBS Code Plex: Custom Filter for Failed Logon @ Server.

On the SBS 2008 server, install the above code into the Event Viewer from within the SBS Native Tools Management console:

  1. Right click on the Event Viewer and click on Create Custom View.
  2. Click on the XML tab.
  3. Click the Edit query manually radio button.
  4. Answer Yes to the warning.
  5. Copy the XML code out of the downloaded file.
  6. CTRL+V to paste it into the XML editor for the Create Custom View window.
  7. Click OK.
  8. Name the filter: SBS Failed Logons.
  9. You can choose a folder or create one to store your Custom Views.
  10. Click OK.
  11. Right click on the new filter and "Attach Task To This Custom View..." to have the event generate an e-mail.

Note that the XML code has been customized for the Event Viewer to pick up on both failed logon attempts via a server service and at the server console if the console was either free or locked. Thus, the code will not work for firing an event in the SBS Console under Other Alerts.

To get Event 4625 events to register in the SBS Console under Other Alerts, get the code SBS Code Plex: Alert for Logon Failure, and install it.

Just in case:

  1. Copy the LogonFailureAlert.XML file into the %programfiles%\Windows Small Business Server\Data\Monitoring\ExternalAlerts folder.
  2. Restart the Windows SBS Manager service in the SBS Native Tools Management console.
  3. Attempt a logon with bad credentials.
  4. SBS Manager cycles every 30 minutes, so the alert will show up at some point over the next 30 minutes. A force Refresh may make it show up.

We now have two ways to find out what is happening with logon attempts on the server. A quick visual glance via the SBS Console as well as via e-mail and the server’s Event logs.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer

Tuesday, 28 October 2008

SBS 2008 - Is my hardware not cutting it?

Further to the previous post: SBS 2008 - Reliability at a glance

How about how is the existing hardware handling the current load on the SBS OS?

System Performance

This has been one of the most difficult questions to answer from the client in the past. We needed to install third party monitoring tools to keep an eye on that box in order to provide a clear answer ... after a period of monitoring time.

That is no longer the case.

With the built-in Resource Overview and the ability to drill down to the smallest detail on the way the SBS OS is performing on the current hardware, we can find out very quickly whether the hardware is cutting it or not.

Under the four performance graphs are the four categories that can be clicked on to drill down to discover which processes are utilizing the hardware component the most.

Resource usage drill down

For those of us who have been working in this industry since way back, when we had to fight and struggle with third party tools to get any kind of information out of our systems, the new Reliability and Performance tools are a huge step ahead for us.

This particular SBS box configuration:

  • Intel Xeon 3070 Dual Core
  • Intel S3000AHLX Server Board with current BIOS
  • Dual on board Gigabit NICs are Teamed (one disabled when the wizards are required)
  • 8GB Kingston KVR667D2E5/2Gi DDR2 ECC (4 pieces)
  • Intel SRCSASRB PCI-E RAID Controller
  • 4x 320GB Seagate Enterprise Storage series in RAID 0+1 for redundancy and performance.
  • Intel SC5299DP series server chassis.

So far, with the Exchange being relatively quiet, the box has been running a consistent 4.5GB of RAM being used. Once we bring the e-mail volume up over the next couple of days or so we will see where things go with the Exchange Store.

SQL has been behaving itself as well, though it looks like we may end up needed to trim the memory levels allocated to each instance just as we needed to do for SBS 2003: SBS 2K3 RTM SP1 R2 Premium - Post install must do - Tame SQL Memory Usage.

More to come on our SBS 2008 lab setup ... and thanks for reading! :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Friday, 13 July 2007

SBS 2K3 - All Versions: Getting to know your servers...

We all get to know the temperaments of our client's servers as we monitor their reports on a daily basis.

We get to know which ones sit behind shoddy Internet connections as there are a number of POP3 Connector errors on a regular basis.

We can see security warnings, audit warnings and the like.

However, there are a couple of key ways we can further get to know our SBS boxes and their peculiarities.

One is to setup the Task Manager so that we can get a more thorough look at what is happening on the SBS box at a glance:


Keeping an eye on things as they are happening is a good way to get a deeper feel for how the various components of the server operate.

To do this:
  1. Open Task Manager
  2. Click View
  3. Select Columns
    Click the following (I forget which ones are there by default so excuse any duplication):
    1. PID
    2. CPU Usage
    3. CPU Time
    4. Memory Usage
      Memory Usage Delta
    5. Peak Memory Usage
    6. I/O Read bytes
    7. User Name
      Virtual Memory Size
    8. I/O Write Bytes
    9. I/O Other bytes
    10. Click OK
Once you are done clicking, it should look like the following:


Another "at a glance" tool is BGInfo by SysInternals.

Here is a shot of our TechNet Plus software SBS Premium based testbed/lab with the utility's image as a desktop background:


The above is one of the first things seen when logging on to the SBS box before the Server Management Console comes up.

An .ini file for BGInfo can be stored somewhere on the network and used to provide all of the servers on the network with the same settings. This provides a convenient way for us to see the same info on all of the servers.

SysInternal's Utilities Index.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.