This has been a pretty tough week already. And, Lenovo is definitely not contributing to the happiness factor right now. :(
Our one client is continuing to have nothing but grief with their Lenovo X61 tablet (previous blog post). After a number of on-site visits by the warranty contractor that included a number of motherboard and hard drive changes, Lenovo will not stand by their product and supply our client with a new unit.
They have lost untold hours of productivity across over a month now. Relatively, those costs have translated into the ability to have purchased a new unit several times over by now.
So, ultimately, what value have they received for the purchase of the extra on-site warranty and time extension? -$$$$.$$
We have another client where one of the managing partners has picked up a Trojan on their Lenovo laptop. The unit is around a year old now.
The security setup in the Lenovo software does not allow us to provide Remote Assistance, or even connect to the laptop via RDP. Now, there may be a setting in the security software setup to allow for these services, but it has not been found yet.
The partner has moved to an identical laptop where that machine's user is now on vacation.
Caveat: Once the Lenovo user has initiated and secured the laptop to their fingerprint, no one else can sign into that laptop. Again, this may be a software setting in the Lenovo security software, but we have not found it yet.
So, we need to change the vacationing user's password so that the partner can gain access to the network, then connect to their Outlook profile via OWA as a temporary measure. This means that we will be getting a phone call from the vacationing user as soon as they try and RWW or OWA into the system.
Tie these experiences into our recovery struggles on the Lenovo laptops here, and here, and we are definitely none too pleased with Lenovo's products and their (lack of) product support.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
SBS, SMB, SME, Hyper-V Failover Clusters, Technology, System Builder Tips, views from the I.T. Trenches, and more.
Tuesday, 12 August 2008
Terminal Server not showing up in Remote Web Workplace
This one is via the SBSC SBS Newsgroup: After setting up a new Terminal Server on the SBS2K3 network, the "Connect to my Application Server" link is not appearing in RWW.
Remotely edit the SBS and Terminal Server's registry and look for the keys:
We need to make sure that the Remote Registry service on the TS box is running, and that the firewall has the appropriate ports open to serve TS or the firewall is off altogether.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Remotely edit the SBS and Terminal Server's registry and look for the keys:
- On SBS:
- HKLM\Software\Microsoft\SmallBusinessServer\RemoteUserProtal\
KWLinks\AppTS=1 (wrapped on purpose) - On the TS:
- HKLM\System\CurrentControlSet\Control\Terminal Server\TSEnabled = 1
- HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat = 1
We need to make sure that the Remote Registry service on the TS box is running, and that the firewall has the appropriate ports open to serve TS or the firewall is off altogether.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Why we need at least one dedicated desktop for RWW
For our clients that have over 7-8 seats we tend to setup a dedicated box for a remote desktop via the Remote Web Workplace (RWW).
If our client has more laptops than desktops, we then look at the option of setting up a second box or a box with Server Core and Hyper-V to host 3 or more desktops depending on the client's size.
Why go through the extra expense of having dedicated remote desktops?
How many of our clients have a user at every PC workstation? We would be willing to bet that pretty much all of them do. Yes, we have the VPN. But, that only works well if a few connections are in use depending on the size of the ISP connection.
So, if a user needs to have access to a desktop within the organization, such as one of the managing partners of an accounting firm whose laptop was showing signs of dying ... while out of town, what do they do?
Here are a number or reasons why having at least one dedicated desktop for remote access is a good thing:
There are any number of really good reasons why this setup works to improve a client's efficiency. We need only be creative in discovering them as we develop an understanding of our client's business.
We always try to demonstrate the RDP via RWW tie in with the Companyweb SharePoint site facing both internally and the Internet via RWW, Outlook Anywhere, and Outlook Mobile Access to the managing partners. When we do, keeping the demonstration to about 30-45 minutes to prevent brain overload, we win the deal pretty much every time.
It pays to know the product ... it really pays to know all of the collaborative features SBS has to offer a firm ... as well as the many facets those features have:
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
If our client has more laptops than desktops, we then look at the option of setting up a second box or a box with Server Core and Hyper-V to host 3 or more desktops depending on the client's size.
Why go through the extra expense of having dedicated remote desktops?
How many of our clients have a user at every PC workstation? We would be willing to bet that pretty much all of them do. Yes, we have the VPN. But, that only works well if a few connections are in use depending on the size of the ISP connection.
So, if a user needs to have access to a desktop within the organization, such as one of the managing partners of an accounting firm whose laptop was showing signs of dying ... while out of town, what do they do?
Here are a number or reasons why having at least one dedicated desktop for remote access is a good thing:
- Laptop users have a desktop to work from while working off-site.
- Laptop users whose hard drives show signs of dying can transfer data back to the office and work remotely thus eliminating the possibility of loosing their work and their data.
- Client sensitive data can be accessed via RWW instead of kept on the local laptop reducing liability due to data exposure.
- BitLocker can help to reduce this exposure on laptops. But, Vista Ultimate or Software Assurance is required for access.
- TrueCrypt is another option, but can be awkward depending on the users capabilities.
- Clients can hire workers to work remotely. Less office space required saving leasing costs.
- This involves a little psychology as far as the paradigm shift from 9-5 thinking to goal setting and goal orientation for outbound workers.
- Scheduled flexibility time for workers to work in and out of the office.
- Summer and off peak times.
- Parents.
- Maternity and Paternity leave.
- Disability leave.
- A desktop for us to use as a logon point for managing the SBS network. We do not like to log directly into the SBS box via RWW or any other method if we can help it.
There are any number of really good reasons why this setup works to improve a client's efficiency. We need only be creative in discovering them as we develop an understanding of our client's business.
We always try to demonstrate the RDP via RWW tie in with the Companyweb SharePoint site facing both internally and the Internet via RWW, Outlook Anywhere, and Outlook Mobile Access to the managing partners. When we do, keeping the demonstration to about 30-45 minutes to prevent brain overload, we win the deal pretty much every time.
It pays to know the product ... it really pays to know all of the collaborative features SBS has to offer a firm ... as well as the many facets those features have:
- Firm productivity.
- Firm efficiency.
- Disaster recovery Scenarios.
- Data protection capabilities.
- Worker location flexibility.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Monday, 11 August 2008
Business Contact Manager - Recovery via *.mdf and *.ldf only
We have a relatively new client that has been going through what is turning out to be a month long odyssey of getting their Lenovo X61 tablet working again.
After an initial diagnosis that the hard drive was failing, they made a backup of their data and the Lenovo on-site people showed up and swapped out the drives.
Two hard drives and three motherboards later, we need to get their Business Contact Manager (BCM) data back online.
One slight gotcha though: The only data we have to work with is the original MSSmallBusiness.ldf and MSSmallBusiness.mdf files.
How did we realize that we were facing a gotcha? When we went to import the data via the database management in BCM it did not give us the option to import a *.mdf file.
After some searching about, we came up with the following Business Contact Manager Team Blog post: Restoring a BCM database from SQL .mdf and .ldf files (Windows Vista or XP).
Noting comments in the post about the environment variable used in the script were for Vista, we made sure to point them to the physical files using the full path.
No matter how many ways that script was modified to get it to work, we could not get those files to mount.
This left us in a bit of a pickle. How do we proceed?
Note the command line structure in the script itself. It contains osql commands. And, we SBSers all know where we need the osql commands (previous blog post on taming SQL's memory usage) don't we?
A quick search for sql 2005 sp_attach_db leads us to: MS KB 224071: How to move SQL Server databases to a new location by using Detach and Attach functions in SQL Server.
Since our BCM database is already detached, we need only attach it again.
But, before we try that, we remove BCM off the system altogether.
After making sure that BCM was fully removed from the system, we reinstalled it.
Run services.msc to verify that the MSSSQL (MSSMLBIZ) database instance is up. Do not run Outlook yet because the BCM will try and initialize a new database during its setup phase.
The databases would be located in: C:\Documents and Settings\%username%\LocalSettings\Application Data\Microsoft\Business Contact Manager\MSSmallBusiness.mdf.
We copied the recovered database and log files into the above location.
From there, we ran the following at the command line (assume Enter after each line):
Once we had a successful database and log file attach to the MSSMLBIZ instance and fired up Outlook, all of the BCM content was there.
We then imported the recovered PST file and our client was good to go.
UPDATE 2008-10-15: If you get an access denied error on the attach attempt then BCM is not installed properly. Run BCM, create a new set of dbs (generally MSSmallBusiness2), and then uninstall BCM, copy the original dbs into the directory, and attach again.
If you need help recovering your databases, please drop us a line: BCM Recovery.
UPDATE 2008-11-03: Added the hostname step to make sure you find the correct system name.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
After an initial diagnosis that the hard drive was failing, they made a backup of their data and the Lenovo on-site people showed up and swapped out the drives.
Two hard drives and three motherboards later, we need to get their Business Contact Manager (BCM) data back online.
One slight gotcha though: The only data we have to work with is the original MSSmallBusiness.ldf and MSSmallBusiness.mdf files.
How did we realize that we were facing a gotcha? When we went to import the data via the database management in BCM it did not give us the option to import a *.mdf file.
After some searching about, we came up with the following Business Contact Manager Team Blog post: Restoring a BCM database from SQL .mdf and .ldf files (Windows Vista or XP).
Noting comments in the post about the environment variable used in the script were for Vista, we made sure to point them to the physical files using the full path.
No matter how many ways that script was modified to get it to work, we could not get those files to mount.
This left us in a bit of a pickle. How do we proceed?
Note the command line structure in the script itself. It contains osql commands. And, we SBSers all know where we need the osql commands (previous blog post on taming SQL's memory usage) don't we?
A quick search for sql 2005 sp_attach_db leads us to: MS KB 224071: How to move SQL Server databases to a new location by using Detach and Attach functions in SQL Server.
Since our BCM database is already detached, we need only attach it again.
But, before we try that, we remove BCM off the system altogether.
After making sure that BCM was fully removed from the system, we reinstalled it.
Run services.msc to verify that the MSSSQL (MSSMLBIZ) database instance is up. Do not run Outlook yet because the BCM will try and initialize a new database during its setup phase.
The databases would be located in: C:\Documents and Settings\%username%\LocalSettings\Application Data\Microsoft\Business Contact Manager\MSSmallBusiness.mdf.
We copied the recovered database and log files into the above location.
From there, we ran the following at the command line (assume Enter after each line):
- hostname (system will reply with the name of your computer)
- osql -E -S MyComputer\MSSMLBIZ (assume MyComputer is your hostname)
- use master
- go
- sp_attach_db 'MSSmallBusiness','C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Business Contact Manager\MSSmallBusiness.mdf','C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Business Contact Manager\MSSmallBusiness.ldf'
- go
- quit
Once we had a successful database and log file attach to the MSSMLBIZ instance and fired up Outlook, all of the BCM content was there.
We then imported the recovered PST file and our client was good to go.
UPDATE 2008-10-15: If you get an access denied error on the attach attempt then BCM is not installed properly. Run BCM, create a new set of dbs (generally MSSmallBusiness2), and then uninstall BCM, copy the original dbs into the directory, and attach again.
If you need help recovering your databases, please drop us a line: BCM Recovery.
UPDATE 2008-11-03: Added the hostname step to make sure you find the correct system name.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Saturday, 9 August 2008
Calling MS Licensing for product keys - ARRRGGG!
*Choke*
This is utterly ridiculous. >8*
We are trying to get a Swing Migration off the ground with our client having purchased Open Value licensing for all of their licensing requirements.
None of the keys have shown up on the MVLS site yet, so we need to call into the toll free to obtain the required keys to get the CALs into the server as well as the install key code for Office 2007 so we can setup the GP distribution.
This is the sixth time calling into the licensing number that ends up terminating over seas.
Two of those calls were routed by the system to the wrong department and subsequently dropped.
One of them the person indicated they would email out and gave us a call reference number. That was yesterday, this is today, and we still did not have any keys.
Another call into the system and the person found the call reference number and our client's VL number.
After 20 minutes on hold, the call got dropped ... again.
The next call in, the person at the other end could not find any reference to the call reference number or our client's VL number! But, we did receive an email with a key code?!?
About 5 minutes later, we received another email with the previous 5 pack key code and a 20 pack key code!
After getting into the MVLS site, it turns out that the person had generated a 5 CAL and 20 CAL key. We needed 15 CALs which is three 5 pack keys. I guess they did find the agreement number after all.
This last call, the sixth one, the person seemed to grasp the problem: We ordered three 5 packs for a total of 15 add-on CALs. We somehow ended up with one 5 pack and one 20 pack for a total of 25 CALs.
So, as I now look at our client's MVLS portal, it looks as though the person may have not caught on at all. We now have six (6) 5 CAL packs and one (1) 20 CAL pack for a total of 50 add-on CALs!?!
*sigh*
Looks like we will need to get a hold of someone on this continent to sort things out.
What a huge waste of time. :(
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
This is utterly ridiculous. >8*
We are trying to get a Swing Migration off the ground with our client having purchased Open Value licensing for all of their licensing requirements.
None of the keys have shown up on the MVLS site yet, so we need to call into the toll free to obtain the required keys to get the CALs into the server as well as the install key code for Office 2007 so we can setup the GP distribution.
This is the sixth time calling into the licensing number that ends up terminating over seas.
Two of those calls were routed by the system to the wrong department and subsequently dropped.
One of them the person indicated they would email out and gave us a call reference number. That was yesterday, this is today, and we still did not have any keys.
Another call into the system and the person found the call reference number and our client's VL number.
After 20 minutes on hold, the call got dropped ... again.
The next call in, the person at the other end could not find any reference to the call reference number or our client's VL number! But, we did receive an email with a key code?!?
About 5 minutes later, we received another email with the previous 5 pack key code and a 20 pack key code!
After getting into the MVLS site, it turns out that the person had generated a 5 CAL and 20 CAL key. We needed 15 CALs which is three 5 pack keys. I guess they did find the agreement number after all.
This last call, the sixth one, the person seemed to grasp the problem: We ordered three 5 packs for a total of 15 add-on CALs. We somehow ended up with one 5 pack and one 20 pack for a total of 25 CALs.
So, as I now look at our client's MVLS portal, it looks as though the person may have not caught on at all. We now have six (6) 5 CAL packs and one (1) 20 CAL pack for a total of 50 add-on CALs!?!
*sigh*
Looks like we will need to get a hold of someone on this continent to sort things out.
What a huge waste of time. :(
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Labels:
Licensing,
Microsoft Licensing,
Open Value Licensing
The Cloud looks to be kewl ...
There have been some excellent posts on the forthcoming Coud initiatives by Microsoft and others:
Vlad's post is his initial reaction to the announcements, with his followup posted in David Overton's comments for the above post.
David Schrag does an awesome job of speaking to the business aspects and direction of an I.T firm. While not necessarily S+S focused, the article is great for a business owner to work on their own vision of their firm.
For us, the move to the Cloud for many products and services we have come to take for granted only seems natural.
We signed the SPLA because we perceive a need for providing Cloud based services to our smaller clients.
Our post on Terminal Services RemoteApps should really help to clarify where the Cloud will fit in. Cloud based service providers that utilize RemoteApps have a killer app in their hands. No need for dedicated TS desktops, just email an RDP or MSI file to the new user and away they go.
Perhaps something like AuthAnvil to provide some additional security for their services.
Our clients do not need a completely decked out server/client infrastructure to accomplish one's daily business needs anymore ... at least that is where things are going.
We do have a few clients with very specialized Line of Business Applications that may not fall into the need for the Cloud yet, but it won't be long before those LoB vendors may be offering Cloud based services.
What does this mean for us?
It means that we will still need to implement some soft of client/server setup. At this point, the robustness of that setup may take a number of steps back as the only real local services being served will be file, print, DNS, DHCP, and a few other oddball server services.
But, our management of those systems will definitely not be on par with what they are today.
So, that means that we need to take stock of how the vendors we work with are looking to implement their Cloud S+S and find a place to fit in.
For some, the changes may be sad or disheartening news ... for us, it presents a whole new series of challenges and adventures!
There will always be a way to provide products and services for a fee to earn a living for us and our employees. The way to discover them is to have a good ear with the vendors, other service providers, and your employees.
If we need to reinvent ourselves, then so be it.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
- David Overton: Why Microsoft Partners should embrace S+S and still deliver on premise solutions
- Vlad Mazek: Time to build your own bridge
- David Schrag: Information Technology Consultant, Contractor, or Vendor?
Vlad's post is his initial reaction to the announcements, with his followup posted in David Overton's comments for the above post.
David Schrag does an awesome job of speaking to the business aspects and direction of an I.T firm. While not necessarily S+S focused, the article is great for a business owner to work on their own vision of their firm.
For us, the move to the Cloud for many products and services we have come to take for granted only seems natural.
We signed the SPLA because we perceive a need for providing Cloud based services to our smaller clients.
Our post on Terminal Services RemoteApps should really help to clarify where the Cloud will fit in. Cloud based service providers that utilize RemoteApps have a killer app in their hands. No need for dedicated TS desktops, just email an RDP or MSI file to the new user and away they go.
Perhaps something like AuthAnvil to provide some additional security for their services.
Our clients do not need a completely decked out server/client infrastructure to accomplish one's daily business needs anymore ... at least that is where things are going.
We do have a few clients with very specialized Line of Business Applications that may not fall into the need for the Cloud yet, but it won't be long before those LoB vendors may be offering Cloud based services.
What does this mean for us?
It means that we will still need to implement some soft of client/server setup. At this point, the robustness of that setup may take a number of steps back as the only real local services being served will be file, print, DNS, DHCP, and a few other oddball server services.
But, our management of those systems will definitely not be on par with what they are today.
So, that means that we need to take stock of how the vendors we work with are looking to implement their Cloud S+S and find a place to fit in.
For some, the changes may be sad or disheartening news ... for us, it presents a whole new series of challenges and adventures!
There will always be a way to provide products and services for a fee to earn a living for us and our employees. The way to discover them is to have a good ear with the vendors, other service providers, and your employees.
If we need to reinvent ourselves, then so be it.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
SBS 2K3 - Change that product key
In some cases, we need to use our SPLA media's product key to get our base SBS 2K3 R2 Premium install in place.
Generally, it will take about 2-3 days post license transaction with Microsoft for the media to arrive at our client's site.
Obviously, it is our preference to have the correct key in place before activating the OS.
To change the product key if we have not activated the OS we do the following:
If the server was already activated, it should indicate that it is activated when running msoobe.exe /a after the above steps.
Link:
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Generally, it will take about 2-3 days post license transaction with Microsoft for the media to arrive at our client's site.
Obviously, it is our preference to have the correct key in place before activating the OS.
To change the product key if we have not activated the OS we do the following:
- Start --> Run --> %systemroot%\system32\oobe\msoobe.exe /a [Enter].
- Click on "Yes, I want to telephone a cust6omer service representative to activate Windows" NEXT.
- Click the "Change Product Key" button.
- Enter the new product key in the boxes.
- Click Update
- Click Remind me Later or close the activation window.
- Reboot.
- Double click on the activation icon in the tray.
- Activate.
- Start --> Run --> Regedit [Enter]
- Navigate to: HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\Current Version\WPAEvents
- Right click on OOBETimer and Modify.
- Change any one digit to deactivate Windows.
If the server was already activated, it should indicate that it is activated when running msoobe.exe /a after the above steps.
Link:
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Labels:
Activation,
SBS,
SBS 2003 All Editions,
System Builder Tips
SBS 08 - RWW + TS RemoteApp = Killer App for SBS and EBS
For us, one of the most anticipated features that we can implement for our clients is the publishing of Terminal Services Applications via the Remote Web Workplace in SBS and EBS.
To date, we have yet to find a definitive instruction set on getting that happening.
For now, it is important to begin reading some of the materials available to us on the Terminal Services TS RemoteApp technology (links to Word documents on Microsoft's site):
Anyone who can flesh out the above, please do so as it would be greatly appreciated by all of us! ;)
For now, we will keep plugging along to figure it out.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
To date, we have yet to find a definitive instruction set on getting that happening.
For now, it is important to begin reading some of the materials available to us on the Terminal Services TS RemoteApp technology (links to Word documents on Microsoft's site):
- Win2K8 TS Gateway Server Step-by-Step Guide
- Win2K8 TS Licensing Step-by-Step Guide
- Win2K8 TS RemoteApp Step-by-Step Guide
- Win2K8 Step-by-Step to Customizing TS Web Access by Using WSS (SharePoint)
- Charlie Russel: Windows Server 2008 RemoteApps is COOL
- Ask the Performance Team: WS2008: Terminal Services RemoteApps
- Export the apps as RDP files
- Save the RDP files to the path where RWW is hosted on the SBS server
- Add the RDP MIME type to IIS on the SBS server
- Add links to the RDP files using the wizard in the SBS console
Anyone who can flesh out the above, please do so as it would be greatly appreciated by all of us! ;)
For now, we will keep plugging along to figure it out.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Thursday, 7 August 2008
Virtualization - Server, Desktop, Performance, and the Future
We do a fair amount of client and internal virtualization setups.
For our clients, virtualization gives us a single system setup that can provide a number of desktop OS virtual machines for Group Policy managed Remote Web Workplace accessible desktops.
A little while back, our Edmonton Microsoft User Group (previous blog post) brought in Kai Axford to speak on various aspects of computer security with a focus on virtualization.
A number of really good points were made.
When it comes to virtual machine performance, the one thing Kai said that still stands out today: The more spindles (hard drives) the server has, the better the VM performance.
We have a number of low utilization setups where a simple RAID 1 volume configured in a 1U Xeon X3000 series Quad Core works really well.
For one of our clients, there is an employee expansion drive that goes beyond the limits of their current location. It is fortunate that they are at the end of their 2 year cycle for the implementation of new hardware and a refresh and re-purposing of their existing hardware as we have some flexibility for our solution proposal.
In their case, we spoke about utilizing the Remote Web Workplace (RWW) and dedicated desktops for people to work from home on (virtualized XP Pro or Vista Enterprise). We also spoke to some of the new RWW features that will be available in SBS 2008 such as Terminal Services Application publishing, so it was pretty easy to see the gears turning in the business owner's head as we went through the various remote access solutions we could implement today and next year.
Currently, they have a 1U Xeon 3000 series dedicated desktop that one of our primary technical contacts utilizes. So, it was not much of a step to develop that setup into a virtualized desktop solution for many more users.
For the hardware, we settled on the newer SR1550ALR 1U dual Intel Xeon 5000 Dual/Quad Core series chassis with the Intel SRCSASRB RAID controller that gives us the capability to run 8 2.5" SAS or SATA drives for our primary virtualization requirements. Since we are looking for capacity and performance, this configuration with the new 320GB 7200RPM Seagate Momentus SATA drives would make a good fit.
This setup will host a number of very active desktop OS VMs along with the possible addition of a server OS VM next summer. Out of the box we will install Windows Server 2008 full version with the Hyper-V role enabled.
This winter when SBS 2008 is released, we will initiate our client's Software Assurance benefits for their SBS 2003 R2 Premium Open Value Agreement to obtain the required media, keys, and updates to the Microsoft Volume Licensing Portal.
These Software Assurance Benefits will give us the flexibility to work with an additional inexpensive 1U for our client's ISA needs, or implement another VM running a server OS and ISA installed therein.
The Software Assurance Benefits will also enable us to look into implementing a cold backup setup for SBS disaster recovery purposes.
And finally, in this particular client setup, we will be able to utilize either the SR1550AL or the soon to be backup server to host a VM setup for the SBS 2008 migration process next summer.
We believe that our goal to provide a solution that will enable our client to expand their numbers today, and also provide the flexibility to implement upcoming technologies based on the new hardware being installed as well as the existing hardware being refreshed has been met. And, our client believes the same.
One other very important point: The new hardware and licensing setup will also give us some flexibility to implement solutions based on the upcoming Cloud solutions from Microsoft and others.
A couple of SBS migration related links:
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
For our clients, virtualization gives us a single system setup that can provide a number of desktop OS virtual machines for Group Policy managed Remote Web Workplace accessible desktops.
A little while back, our Edmonton Microsoft User Group (previous blog post) brought in Kai Axford to speak on various aspects of computer security with a focus on virtualization.
A number of really good points were made.
When it comes to virtual machine performance, the one thing Kai said that still stands out today: The more spindles (hard drives) the server has, the better the VM performance.
We have a number of low utilization setups where a simple RAID 1 volume configured in a 1U Xeon X3000 series Quad Core works really well.
For one of our clients, there is an employee expansion drive that goes beyond the limits of their current location. It is fortunate that they are at the end of their 2 year cycle for the implementation of new hardware and a refresh and re-purposing of their existing hardware as we have some flexibility for our solution proposal.
In their case, we spoke about utilizing the Remote Web Workplace (RWW) and dedicated desktops for people to work from home on (virtualized XP Pro or Vista Enterprise). We also spoke to some of the new RWW features that will be available in SBS 2008 such as Terminal Services Application publishing, so it was pretty easy to see the gears turning in the business owner's head as we went through the various remote access solutions we could implement today and next year.
Currently, they have a 1U Xeon 3000 series dedicated desktop that one of our primary technical contacts utilizes. So, it was not much of a step to develop that setup into a virtualized desktop solution for many more users.
For the hardware, we settled on the newer SR1550ALR 1U dual Intel Xeon 5000 Dual/Quad Core series chassis with the Intel SRCSASRB RAID controller that gives us the capability to run 8 2.5" SAS or SATA drives for our primary virtualization requirements. Since we are looking for capacity and performance, this configuration with the new 320GB 7200RPM Seagate Momentus SATA drives would make a good fit.
This setup will host a number of very active desktop OS VMs along with the possible addition of a server OS VM next summer. Out of the box we will install Windows Server 2008 full version with the Hyper-V role enabled.
This winter when SBS 2008 is released, we will initiate our client's Software Assurance benefits for their SBS 2003 R2 Premium Open Value Agreement to obtain the required media, keys, and updates to the Microsoft Volume Licensing Portal.
These Software Assurance Benefits will give us the flexibility to work with an additional inexpensive 1U for our client's ISA needs, or implement another VM running a server OS and ISA installed therein.
The Software Assurance Benefits will also enable us to look into implementing a cold backup setup for SBS disaster recovery purposes.
And finally, in this particular client setup, we will be able to utilize either the SR1550AL or the soon to be backup server to host a VM setup for the SBS 2008 migration process next summer.
We believe that our goal to provide a solution that will enable our client to expand their numbers today, and also provide the flexibility to implement upcoming technologies based on the new hardware being installed as well as the existing hardware being refreshed has been met. And, our client believes the same.
One other very important point: The new hardware and licensing setup will also give us some flexibility to implement solutions based on the upcoming Cloud solutions from Microsoft and others.
A couple of SBS migration related links:
- Migrating to Windows Small Business Server 2008 from Windows Small Business Server 2003
- Migrating to Windows Small Business Server 2008 from Windows Small Business Server 2008
- Windows Small Business Server 2008 Migration Help
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Server Core - Updates are available + How to manually update
Despite the fact that the Windows Server 2008 Server Core edition has an exceedingly small footprint does not mean that it will not require updates.
They may come fewer and further between, but Server Core will still need to be updated:
We look the Server Core Blog: Windows Update and More WMIC samples. Here we find the following command line to detect updates manually: Wuauclt /detectnow
However, we are not given any further indication as to how we must proceed to install those updates.
We search a little more, and our friend Sander Berkouwer on his blog The things that are better left unspoken gives us the process: (Manually) Updating Server Core .
The steps:
Our first Server Core setup to be updated is a 1U Xeon X3220 with 8GB of ECC RAM running a pair of Seagate ES series drives in a RAID 1 array. The updates took some time, around 30-45 minutes, to install during the reboot portion of the updates.
Once we had our Core box online and verified, we fired up our VMs with no issues.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
They may come fewer and further between, but Server Core will still need to be updated:
Finding out how exactly we get the updates onto the Server Core installation is another story.Windows Server 2008 Standard (Core Installation) - 13 updates required.
We look the Server Core Blog: Windows Update and More WMIC samples. Here we find the following command line to detect updates manually: Wuauclt /detectnow
However, we are not given any further indication as to how we must proceed to install those updates.
We search a little more, and our friend Sander Berkouwer on his blog The things that are better left unspoken gives us the process: (Manually) Updating Server Core .
The steps:
- Copy and paste the following script into NotePad on the Core installation:
Set updateSession = CreateObject("Microsoft.Update.Session")
Set updateSearcher = updateSession.CreateupdateSearcher()
WScript.Echo "Searching for updates..." & vbCRLF
Set searchResult = _
updateSearcher.Search("IsInstalled=0 and Type='Software'")
WScript.Echo "List of applicable items on the machine:"
For I = 0 To searchResult.Updates.Count-1
Set update = searchResult.Updates.Item(I)
WScript.Echo I + 1 & "> " & update.Title
Next
If searchResult.Updates.Count = 0 Then
WScript.Echo "There are no applicable updates."
WScript.Quit
End If
WScript.Echo vbCRLF & "Creating collection of updates to download:"
Set updatesToDownload = CreateObject("Microsoft.Update.UpdateColl")
For I = 0 to searchResult.Updates.Count-1
Set update = searchResult.Updates.Item(I)
WScript.Echo I + 1 & "> adding: " & update.Title
updatesToDownload.Add(update)
Next
WScript.Echo vbCRLF & "Downloading updates..."
Set downloader = updateSession.CreateUpdateDownloader()
downloader.Updates = updatesToDownload
downloader.Download()
WScript.Echo vbCRLF & "List of downloaded updates:"
For I = 0 To searchResult.Updates.Count-1
Set update = searchResult.Updates.Item(I)
If update.IsDownloaded Then
WScript.Echo I + 1 & "> " & update.Title
End If
Next
Set updatesToInstall = CreateObject("Microsoft.Update.UpdateColl")
WScript.Echo vbCRLF & _
"Creating collection of downloaded updates to install:"
For I = 0 To searchResult.Updates.Count-1
set update = searchResult.Updates.Item(I)
If update.IsDownloaded = true Then
WScript.Echo I + 1 & "> adding: " & update.Title
updatesToInstall.Add(update)
End If
Next
WScript.Echo vbCRLF & "Would you like to install updates now? (Y/N)"
strInput = WScript.StdIn.Readline
WScript.Echo
If (strInput = "N" or strInput = "n") Then
WScript.Quit
ElseIf (strInput = "Y" or strInput = "y") Then
WScript.Echo "Installing updates..."
Set installer = updateSession.CreateUpdateInstaller()
installer.Updates = updatesToInstall
Set installationResult = installer.Install()
'Output results of install
WScript.Echo "Installation Result: " & _
installationResult.ResultCode
WScript.Echo "Reboot Required: " & _
installationResult.RebootRequired & vbCRLF
WScript.Echo "Listing of updates installed " & _
"and individual installation results:"
For I = 0 to updatesToInstall.Count - 1
WScript.Echo I + 1 & "> " & _
updatesToInstall.Item(i).Title & _
": " & installationResult.GetUpdateResult(i).ResultCode
Next
End If - Save the file as WUA_SearchDownloadInstall.vbs in your preferred location.
- Navigate to the folder where the WUA_SearchDownloadInstall.vbs file is located.
- cscript WUA_SearchDownloadInstall.vbs [Enter]
- Answer Y to install the found updates.
- Once finished, note whether the Reboot Required: True flag is raised.
- If so: shutdown -r -t 15 [Enter]
- If there are VMs running on the system, you can shut them down via the Hyper-V manager before rebooting, or let Hyper-V take care of it for you.
- A snapshot of the VMs may be appropriate prior to updating and rebooting.
- Rerun the script once the server comes up again to verify that there are no further updates
Our first Server Core setup to be updated is a 1U Xeon X3220 with 8GB of ECC RAM running a pair of Seagate ES series drives in a RAID 1 array. The updates took some time, around 30-45 minutes, to install during the reboot portion of the updates.
Once we had our Core box online and verified, we fired up our VMs with no issues.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Wednesday, 6 August 2008
SBS - Windows Mobile 5 and a third party cert = stability
Since installing a third party SSL certificate on our SBS servers, our Windows Mobile 5 phones have demonstrated a markedly decreased need to be soft reset.
It was not uncommon to need to reset the units on an almost daily basis.
This side-effect of having the third party SSL certificate installed for Internet SBS access was an unexpected surprise ... and an additional selling point for going third party on our client's SBS installations.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
It was not uncommon to need to reset the units on an almost daily basis.
This side-effect of having the third party SSL certificate installed for Internet SBS access was an unexpected surprise ... and an additional selling point for going third party on our client's SBS installations.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Tuesday, 5 August 2008
When it rains ... it pours ... and a little SBS happiness!
What a week!
Last week, we had no less than five critical situations come up.
From array drive member failures to networks being completely down, we certainly ran the gauntlet.
Today was not different. Between catching up with the tail end of last week's issues, and a couple of new ones that cropped up, we were quite busy.
The best part of today was the afternoon training session with our existing nonprofit client that we installed an SBS network into last week.
They were very receptive to all of the features we ran through, writing things down as we went along.
One of the neatest things about the post SBS install training is watching the user's gears turning as they begin to realize just what they had received.
It was all fine and dandy to work with our contact and to some degree the Executive Director on the pre-install SBS setup. It was, however, another thing to be sitting there with the full-time employees working through the Remote Web Workplace, Outlook Anywhere and Exchange, Exchange enabled Outlook, and SharePoint among others ... the creative juices were flowing as were the, "Can we do this or that?" questions.
The biggest hits from this training session:
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Last week, we had no less than five critical situations come up.
From array drive member failures to networks being completely down, we certainly ran the gauntlet.
Today was not different. Between catching up with the tail end of last week's issues, and a couple of new ones that cropped up, we were quite busy.
The best part of today was the afternoon training session with our existing nonprofit client that we installed an SBS network into last week.
They were very receptive to all of the features we ran through, writing things down as we went along.
One of the neatest things about the post SBS install training is watching the user's gears turning as they begin to realize just what they had received.
It was all fine and dandy to work with our contact and to some degree the Executive Director on the pre-install SBS setup. It was, however, another thing to be sitting there with the full-time employees working through the Remote Web Workplace, Outlook Anywhere and Exchange, Exchange enabled Outlook, and SharePoint among others ... the creative juices were flowing as were the, "Can we do this or that?" questions.
The biggest hits from this training session:
- Remote Web Workplace for desktop access.
- Companyweb access facing internally and the Internet.
- Exchange enabled Outlook: Undelete
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Saturday, 2 August 2008
SBS 2K3 Premium - Configuring an SSL Wildcard Cert
Finding information on getting a third party SSL certificate installed on SBS Premium is a struggle.
In our case, we are looking to get away from the SBS self-issued certificate as much as possible. The amount of support related issues around that setup can be eliminated with the addition of a rather inexpensive investment in a third party certificate.
The process for setting up for the certificate is rather straight forward. The Official SBS Blog has a post on the initial part: How to Install a Public 3rd Party SSL Certificate on IIS on SBS 2003.
We create a dummy Web site in IIS, issued the certificate request from there, obtained the certificate from DigiCert, import it into the Intermediate Certification Authorities, and finally imported the certificate via the dummy site's certificate wizard. All of these steps are clearly outlined in the above blog post.
The blog author indicates that a further blog post is forthcoming on installing that certificate into ISA but none appear to be found.
The Configure Email and Internet Connection Wizard (CEICW) does have the ability to import a third party certificate, but it wants a *.cer file that does not seem to work from the many times we tried to get things configured that way.
So, that left us in a quandry: How do we get that certificate tied into ISA.
Having a little understanding as to how the CEICW configures both IIS and ISA together is a really important step to discovering how we need to get that certificate working.
With ISA installed on SBS, the configuration used to keep an end to end SSL tunnel between the user and IIS is called an SSL Bridge (MS TechNet Article).
When the browser requests https://rww.mydomain.com/remote and an SSL tunnel is established, ISA actually decrypts the tunnel to inspect the packets. ISA then re-encrypts the packets by establishing a subsequent SSL tunnel into the local IIS server.
When we look at the SBS ISA and IIS SSL setup from the user's perspective we see:
It is the Internet facing site that needs that certificate along with OWA, OMA, and direct SharePoint access.
The process is very simple:
An important note regarding SSL wildcard certificates: For Outlook 2003/2007 clients using Outlook Anywhere (RPC/HTTPS), the msstd:rww.mydomain.com setting in Outlook needs to be changed to: msstd:*mydomain.com in order to avoid this:
Managing our client's SSL certification needs is one small service addition we have made to our managed services portfolio.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
In our case, we are looking to get away from the SBS self-issued certificate as much as possible. The amount of support related issues around that setup can be eliminated with the addition of a rather inexpensive investment in a third party certificate.
The process for setting up for the certificate is rather straight forward. The Official SBS Blog has a post on the initial part: How to Install a Public 3rd Party SSL Certificate on IIS on SBS 2003.
We create a dummy Web site in IIS, issued the certificate request from there, obtained the certificate from DigiCert, import it into the Intermediate Certification Authorities, and finally imported the certificate via the dummy site's certificate wizard. All of these steps are clearly outlined in the above blog post.
The blog author indicates that a further blog post is forthcoming on installing that certificate into ISA but none appear to be found.
The Configure Email and Internet Connection Wizard (CEICW) does have the ability to import a third party certificate, but it wants a *.cer file that does not seem to work from the many times we tried to get things configured that way.
So, that left us in a quandry: How do we get that certificate tied into ISA.
Having a little understanding as to how the CEICW configures both IIS and ISA together is a really important step to discovering how we need to get that certificate working.
With ISA installed on SBS, the configuration used to keep an end to end SSL tunnel between the user and IIS is called an SSL Bridge (MS TechNet Article).
When the browser requests https://rww.mydomain.com/remote and an SSL tunnel is established, ISA actually decrypts the tunnel to inspect the packets. ISA then re-encrypts the packets by establishing a subsequent SSL tunnel into the local IIS server.
When we look at the SBS ISA and IIS SSL setup from the user's perspective we see:
- https://rww.mydomain.com/ ---> ISA ---> https://publishing.mysbsdomain.local/
- SBS Self Issued to https://rww.mydomain.com/
- This certificate faces the Internet only.
- SBS Issued https://publishing.mysbsdomain.local/
- This certificate is only on the local LAN.
It is the Internet facing site that needs that certificate along with OWA, OMA, and direct SharePoint access.
The process is very simple:
- On the SBS server open the ISA manager.
- Click on the Firewall Policy item.
- Double click on any SBS xxx Publishing Rule that uses the SBS Web Listener.
- Click the Listner tab.
- Click the Properties button beside "SBS Web Listener".
- Click the Preferences tab.
- Under SSL: Click the Select button.
- The new third party certificate should be one of the available ones, click on it.
- OK.
- Apply & OK.
- Double click on the SBS Windows SharePoint Services Web Publishing Rule.
- Listener tab.
- Properties button.
- Preferences tab.
- Select button
- Choose the correct certificate as above.
- OK.
- Apply & OK.
- Apply in ISA Manager.
An important note regarding SSL wildcard certificates: For Outlook 2003/2007 clients using Outlook Anywhere (RPC/HTTPS), the msstd:rww.mydomain.com setting in Outlook needs to be changed to: msstd:*mydomain.com in order to avoid this:
Microsoft Office OutlookSome helpful links:
There is a problem with the proxy server's security certificate. The name on the security certificate is invalid or does not match the name of the target site rww.mydomain.com.
Outlook is unable to connect to the proxy server. (Error Code 0)
- MS KB 923575: Error message when Outlook 2007 tries to connect to a server by using an RPC connection or an HTTPS connection: "There is a problem with the proxy server's security certificate"
- MS KB 831051: How to use the RPC Ping utility to troubleshoot connectivity issues with the Exchange over the Internet feature in Outlook 2007 and in Outlook 2003
- TechNet Forums: Outlook RPC/HTTPS setup with a wildcard
Managing our client's SSL certification needs is one small service addition we have made to our managed services portfolio.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Friday, 1 August 2008
DigiCert Gets our vote for wildcard SSL certificates
In our search for a wild card SSL certificate (previous blog post), we looked into a large number of SSL providers.
While all providers will provide us with a *.mydomain.com wildcard SSL certificate, only DigiCert gives us the option to tag the certificate with Subject Alternative Names.
What does that mean? That means that we can setup our certificate to look somewhat like this:
For those of our clients that have multiple SBS sites, or an SBS site with multiple branch offices, the wildcard SSL certificate will make things like Remote Web Workplace and other SSL secured Internet facing services simpler to access and manage.
Their price includes as many sites and servers needed. There is no price augmentation for additional sites, servers, or reissued certificate requests. The price is the price is the price! ;)
When we placed our order for a wildcard certificate, we heard back from DigiCert by phone within a couple of hours. Some questions needed to be answered to confirm our company's identity before the certificate release would happen.
Finally, their Web management interface is very straight forward to operate when requesting or managing our certificates.
For us SBSers, DigiCert is definitely a company to look at for your wildcard SSL needs.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
While all providers will provide us with a *.mydomain.com wildcard SSL certificate, only DigiCert gives us the option to tag the certificate with Subject Alternative Names.
What does that mean? That means that we can setup our certificate to look somewhat like this:
- *.mydomain.com
- mail.mydomain.com
- rww.mydomain.com
- oma.mydomain.com
- mydomain.com
For those of our clients that have multiple SBS sites, or an SBS site with multiple branch offices, the wildcard SSL certificate will make things like Remote Web Workplace and other SSL secured Internet facing services simpler to access and manage.
Their price includes as many sites and servers needed. There is no price augmentation for additional sites, servers, or reissued certificate requests. The price is the price is the price! ;)
When we placed our order for a wildcard certificate, we heard back from DigiCert by phone within a couple of hours. Some questions needed to be answered to confirm our company's identity before the certificate release would happen.
Finally, their Web management interface is very straight forward to operate when requesting or managing our certificates.
For us SBSers, DigiCert is definitely a company to look at for your wildcard SSL needs.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
SBS - .Local versus .com or others
We seem to see a fair amount of discussion around the .local top level domain (TLD) that we have been using in the SBS world for a while now.
Some links:
Qualification: That reason should never have existed in the first place.
Our client is a nonprofit. We have done sporadic support for them over the last three years or so as they have a very competent on-site person who can handle most anything. We were the ones she turned to when she ran into a wall.
Their budget came through for a new server. Working with them, and our support contact, it was decided that we would take on a more significant role in the supporting of their I.T. infrastructure to free up our contact to do other things.
Given the age of their Active Directory, and the need to restructure things accordingly, we elected to move the local desktops over the the new SBS domain, demote the existing server, and subsequently add it to the SBS domain as a member server only for the Line of Business app that ran on it.
While we took the time to look at the domain setup which was in place for a number of years prior to our contact coming on board with the organization, we never took too close of a look at it as we were dropping it all together.
The scenario:
Not taking a closer look initially was based on an assumption ... and we all know what happens when we do that right?!? ;)
Workstation #1 attempt to move to the new SBS setup:
Go back to the SBS box and open ISA's live query to see just what is going on and we see one IP address associated with the romancatholicparish.org (Note that the parish's name is the name of an RC Saint) and their Internet DNS servers in our SBS DNS Lookup Cache.
Huh?!?
First thought: Oh no, the DNS on this new SBS box has been poisoned or corrupted! But clarity soon ensued: Why in the chicken are we being redirected to an RC Parish and not some off the continent country infected Web site?
Just in case, the DNS patch was run on the SBS box and rebooted. We sometimes finish our patching after the SBS box has been installed on the network so WSUS picks up on the workstations in the new domain and if we are under the gun for timing as was the case here.
A deeper look into DNS pointed out to us just what was happening:
Once we discovered this, the resolution was quite simple: Remove the workstations for the workgroup.romancatholicparish.org domain, and then run the mysbs/connectcomputer wizard. Note that one of the first steps on the machine was to reset the local admin password to a known quantity.
That worked!
From this experience, it is pretty easy to see why Microsoft has decided to stick with the .local TLD. The DIY or "consultant" doesn't have to understand DNS to set things up.
For those who are working with the RCx of SBS 2008, that hand holding even goes so far as to integrate Internet DNS management into the wizards to make sure that things get setup properly.
Those of us who understand the ramifications of DNS setups, .local or .com, registering the .com and splitting the DNS, and the reasons why we choose one over the other, can make sure our client's configurations are setup correctly.
However, all it takes is one DIY, or "consultant" to hose an installation on the DNS setup alone as was the case here.
Our vote goes with .local. It is a necessary "evil" in the SMB sphere to take care of the DIY that may not want to grasp DNS concepts and the "consultant" that has not taken the time to learn them ... yet.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Some links:
- The Official SBS Blog: Geeky question of the day. . . Why .local for the default Windows SBS 2008 domain name extension?
- CanITPro Blog: Another .LOCAL post - SBS 2008, EBS 2008
- Susan Bradley: .Local Revisited
- Susan Bradley: And Another .Local
Qualification: That reason should never have existed in the first place.
Our client is a nonprofit. We have done sporadic support for them over the last three years or so as they have a very competent on-site person who can handle most anything. We were the ones she turned to when she ran into a wall.
Their budget came through for a new server. Working with them, and our support contact, it was decided that we would take on a more significant role in the supporting of their I.T. infrastructure to free up our contact to do other things.
Given the age of their Active Directory, and the need to restructure things accordingly, we elected to move the local desktops over the the new SBS domain, demote the existing server, and subsequently add it to the SBS domain as a member server only for the Line of Business app that ran on it.
While we took the time to look at the domain setup which was in place for a number of years prior to our contact coming on board with the organization, we never took too close of a look at it as we were dropping it all together.
The scenario:
- Existing Windows Server 2003 domain NetBIOS: Workgroup.?
- New SBS domain: NonProfit.local
Not taking a closer look initially was based on an assumption ... and we all know what happens when we do that right?!? ;)
Workstation #1 attempt to move to the new SBS setup:
- Log on as old domain admin.
- Reset local admin password.
- Open IE and point to: http://mysbs/connectcomputer
- IE opens: http://www.romancatholicparish.org/
Go back to the SBS box and open ISA's live query to see just what is going on and we see one IP address associated with the romancatholicparish.org (Note that the parish's name is the name of an RC Saint) and their Internet DNS servers in our SBS DNS Lookup Cache.
Huh?!?
First thought: Oh no, the DNS on this new SBS box has been poisoned or corrupted! But clarity soon ensued: Why in the chicken are we being redirected to an RC Parish and not some off the continent country infected Web site?
Just in case, the DNS patch was run on the SBS box and rebooted. We sometimes finish our patching after the SBS box has been installed on the network so WSUS picks up on the workstations in the new domain and if we are under the gun for timing as was the case here.
A deeper look into DNS pointed out to us just what was happening:
- Local W2K3 domain: workgroup.romancatholicparish.org
- WhoIs for above .org domain: Owned by an RC Parish in Kentucky!
Once we discovered this, the resolution was quite simple: Remove the workstations for the workgroup.romancatholicparish.org domain, and then run the mysbs/connectcomputer wizard. Note that one of the first steps on the machine was to reset the local admin password to a known quantity.
That worked!
From this experience, it is pretty easy to see why Microsoft has decided to stick with the .local TLD. The DIY or "consultant" doesn't have to understand DNS to set things up.
For those who are working with the RCx of SBS 2008, that hand holding even goes so far as to integrate Internet DNS management into the wizards to make sure that things get setup properly.
Those of us who understand the ramifications of DNS setups, .local or .com, registering the .com and splitting the DNS, and the reasons why we choose one over the other, can make sure our client's configurations are setup correctly.
However, all it takes is one DIY, or "consultant" to hose an installation on the DNS setup alone as was the case here.
Our vote goes with .local. It is a necessary "evil" in the SMB sphere to take care of the DIY that may not want to grasp DNS concepts and the "consultant" that has not taken the time to learn them ... yet.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Labels:
DIY,
SBS,
SBS 2003 All Editions,
SBS 2008 All Editions,
SBS Setup
Subscribe to:
Posts (Atom)