Jump to content

Jamo

Members
  • Posts

    1,449
  • Joined

  • Last visited

Everything posted by Jamo

  1. You have to make sure that both PCs have a user account with a password. As they are technically not part of a central group they have to authenticate with one of their own users to get the standard Windows sharing working. Also make sure that there are no firewall restrictions stopping the connections, in particular Symantec Norton 360 was a pain for leaving behind the firewall component during an uninstall meaning that pretty much all incoming ports were stuck to being blocked. Its worth just running the norton removal tool if any norton tool was ever installed anyway. Also make sure that File and Printer sharing is enabled
  2. Sophos is seeing this as malware btw
  3. Wel..... I have managed to edit the schema using ADSIedit and renamed the OIDs and CNs which are causing the issues. These changes replicated amongnst the DCs fine. The ADPrep /forestprep worked great and took around 5 minutes to run. I now though, seem to be getting replication errors which talk of a schema mismatch.... which to be honest is what I would expect as I am altering the schema using adprep! But I am confused about why the other DCs arent taking the schema from the schema master?? James
  4. Right I have got ADSIEdit loaded and have found the rogue entires in the schema. To be honest I would just like to blow them away and forget about them to see if that at least solves the first issue. Now I am being told I don't have permission as a schema admin to delete the values.... I have given the schema admin full control over the object and tried to delete and it says thatt he delete operation could not be perfomed? Apologies for the not particularly helpful error messages I am new to the ADSIEdit tool. (BTW I am performing all of this on the sandbox environment so its not going to break anything )
  5. I think we are using AD auth and samba as you suggested. Going to try to rip out the stuff now in the sandbox environment to see what happens! How exciting! This is a total legacy thing from the old old macs so its a little annoying that it has cropped up now! Typical really, I had said this morning that today might be a quick one!!
  6. In fact it has just finished uninstalling and unfortunately the OIDs are still present. It tells me to contact the product vendor... thanks microsoft...
  7. Quite likely, although it is the AD part of it which still exists in the domain. From my point of view I would either like to know if disabling would have any impact (we have Apples on the network atm, although we have a mac server to deal with them, they do log on using their normal domain credentials though? and would this even allow me to adprep the forest) or if there is a version which is compatible with the adprep command? It would be very much preferable that we didn't have to migrate all the users onto a new domain to facilitate the update to 2008R2 as it would be quite a lot to as us all to visit all 700 machines (including 300 laptops) to rejoin them to the new domain Thanks in advance James
  8. Hello all! I am having great fun today trying to run this one single command.... adprep /forestprep! My issue seems to lie with the services for unix (not sure which version or how to check to be honest) and its incompatability with the schema extensions on the new 2008r2 adprep program. FIX&#58 Error message when you try to prepare the Active Directory directory service for Windows Server 2003 R2&#58 &#34Attribute value for objects defined in Windows 2000 schema and extended schema do not match&#34 I have tried the hotfix applied in the above article (downloaded from MS) but it seems to only rename the OID's and then causes more errors when trying to run adprep! This is the message I got before "isSingleValued" attribute value for objects defined in Windows 2000 schema and extended schema do not match. This is the message/messages i get now! OID "1.3.6.1.1.1.1.0" defined for object CN=MSSFU2x-uidNumber,CN=Schema,CN=Confi guration,DC=compmed,DC=ucdavis,DC=edu conflicts with the schema extensions neede d for Windows Server 2008. [status/Consequence] Adprep will not extend your existing schema. [user Action] Contact the vendor of the application that extended the schema with the OID valu e "1.3.6.1.1.1.1.0" and resolve this inconsistency. Then run adprep again. Has anyone come across this and / or fixed it? It seems to be pretty deeply embedded in the AD now, (luckily this is all on a sandbox network so the production one is currently unaffected). I am not even sure if the SFU is still required, it was installed a long time ago by an outside agency for compatability with a version of OSx somewhere along the line hence the rather sketchy information on what version etc were installed :s Hope someone can help! James
  9. lol this is my plan! turn em on and see what happens to begin with!! Has anyone actually created a VM sandbox copy of a live environment beofre?
  10. Hi all! I am looking at replicating our current AD structure in a test sandbox environment. The network has all been created and the machines are currently restoring from backups to the new SAN area for testing. My question is...... Because I am restoring from backups taken at different times ie the first DC was backed up about 6 hours before the last, and the machines are being restored into an area where there is no communication with the live network (obviously ) does this mean that I will have to boot the first DC up and then the others in non-authoritive mode? Or will they boot back up and chat for a while and then be all ok? I have not done this before :s Hope someone can help!!
  11. Not sure if you have seen this thread? Joomla! • View topic - [Help] Strict Standards error after installing Any help?
  12. Upgraded PHP recently?
  13. I always thought with a VLK you could always downgrade w7 to XP provided you had the licences? Is that not the case?
  14. The box in disc management didn't ask you to initialise the disc did it? If so the boot sector is probably a little worse for wear! I would look on the backups first rather than try to recover the partition as you may spend a lot of time trying for no reward. The only recovery software I have used has been file level, I have not tried the partition level recovery software, I believe something along the lines of testdisk does support it though but wouldn't know what results you would get :s
  15. Group policy prefs? There is a shortcuts option which you can manage the start menu quite effectively without having to worry about the redirection
  16. Packet tracer is pretty much all you need for the CCNA, (hardware wise) although the real thing does get you the hands on experience which cannot be emulated in software. All the commands you require will be available in packet tracer, its surprisingly good. I did my course through the OU which atm is around 700 quid or something for 4 day schools etc, (have to pay for the exam at the end too) but its rather good. Basically following the Cisco netacad path.
  17. You will get better throughput with two, but in reality it is extremely unlikely that the devices would utilize the bandwidth effectively, it is better use of resources (ports) to just use one uplink (or create a portchannel aggregated link if you wanted to combine two ports into one trunk which would be a far better use of the links and would double the effective bandwidth available). I personally would just leave it as one trunk running between each device, if you haven't got devices which can stack then you won't get any redundancy from having multiple cables connected between the core and the individuals.
  18. You can trunk both VLANs up to the core on the same port, thats the idea of trunking, basically using one port to carry both VLANs traffic. If you were to do it like you suggested you should create both of the ports 23 and 24 as untagged in the particular vlans, IE port 24 untagged vlan1 and port 23 untagged vlan2. This basically makes them both access ports in their respective vlans. Are both 23 and 24 going directly to the core or are they passing through any other switches along the way?
  19. I have to ask, will it increase though? With this current government I wouldn't be surprised if we saw the use of technology in schools shrink considerably.
  20. One thing to note with MDT is that if you are running from within Windows then you cannot use the NewComputer deployment type. The same as when booting from PXE it defaults to NewComputer
  21. In HP terms, when a network packet gets transferred down the wire, in a VLANned setup the tagged packets are marked as beloging to a VLAN OTHER than what is known as the native vlan for that particular trunked port. You can have more than one vlan tagged on a port, meaning it will basically allow traffic destined to that VLAN to flow down that port. You can only have one VLAN untagged on a port at a time. If a port has only an untagged VLAN specified and no 'tagged' vlans then it becomes an access port and any device plugged into that port will be effectively on that VLAN. The trunk to the core basically requires all VLANs (apart from the native 'untagged' which you would normally leave as 1) to be tagged. Yup you will need to set ports 12-22 as untagged for VLAN 2, then the uplinks to the core on each switch along the way will require VLAN 2 tagged on the uplink port and vlan1 left as untagged. Hope that helps
  22. Do an aministrative install with /a on the exe /? will give you the options on the exe. Then you need to take the two MSIs and support files it creates and make a transform using Orca. The transform just makes the MSI think that it is running from the GUI and not to perform checks basically. Link looks like someone has made one on this MS blog. You can create your own by adding the properties passed to the MSI into the table using orca. You have two options for deployment then, either manually assign the MST transform using Orca and embed it into the MSI so you can just deploy the MSI, oooooor you can use an advanced install in group policy and just simply add the MST to the transforms tab with the msi. Hope that helps
  23. No the netgear should be left as a layer 2 switch with no ip addresses but the management ip. The ports on the netgear should be access ports in vlan 2 not tagged as tagged will turn the ports into a trunk and any access data will flow down the default vlan which will be 1 I would think on your setup. The layer 2 traffic will be transferred all the way to the main core interface at which point it will be routed between the VLANS and go into VLAN1 . If you start adding more layer 3 switches you will end up with a complicated network to debug when its all daisy chained like that
  24. The VLANS need to exist on all the switches in your daisy chain as otherwise the traffic will get dropped if it hits a switch without VLAN2. The fibre links need to be trunks (cisco talk) or have VLAN2 tagged on the uplink ports (HP talk) all the way up to the core, which needs to have both VLANS defined and ip routing enabled. You need to create a VLAN interface as VLAN2's default gateway as well as the VLAN itself on the layer 3 core switch. ie : On cisco: enable conf t vlan 2 name blahblah exit int vlan 2 ip address 192.168.2.1 255.255.255.0 exit Ensure that the Cisco has IP routing enabled (should have IP Routing listed in startup-config)
  25. With WSUS it will take aaaaaaages!! You can push out the dotNET 4 package as an MSI via gpo, in fact its what I am doing now!
×
×
  • Create New...