Jump to content

sacrej

Members
  • Posts

    120
  • Joined

  • Last visited

Everything posted by sacrej

  1. set to disabled in gpo, tried to change to unconfigured - no joy :/
  2. Oh those options, yes I have those - however they are all grayed out with the bottom option selected (Enforce NLA) not sure how to 'un-gray' them :/ I am logged in as a domain admin, local admin has the same issue.
  3. unfortunately this doesn't seem to be an option on R2 (that i can see)
  4. please read my previous posts as I have already provided this information. Enforce NLA - greyed out due to Negotiate selected making it 'optional'
  5. we are on 1.3 and just tried to get it working on win 7 to not much avail - it works for domain admins, on x64 and x32 but not regular users staff/students i'm actually trying to get it working in APP-V captured on a winxp machine, which works as above, the errors I get are: Error: JZ006: Caught IOException.java.net.SocketException: Create Now obviously SME DOES work on Win7 as i've had it running as a DA, so i'm thinking it must be a permissions issue The mapped network drive (L:) is correct and users have the correct permissions on it (it works on XP previously) We're using Sybase on a 2003 server, though I wasn't around when all of this was set up, its a matter of urgency that we get this sorted as soon as! well, they say its urgent anyway!
  6. does anyone know if there is a way to force disable NLA in 2008r2sp1, as I think that this would solve all of our issues. all the options under remote connections are greyed out and the options in TS dont seem to do anything either.
  7. also, 32bit versions of programs can only utilize a certain amount of memory 2-3gigs tops I think, for example Photoshop 64bit will utilize a lot more if given access to it. memory footprints are generally a bit larger for 64bit apps, so really 4 gig would be a minimum, I have six in my work machine, but my home has 4gig and I run stuff like cinema 4d x64 and photoshop x64 without any issues, although on big jobs and processes the more memory the better. for photo & video editing and anything requiring rendering (CAD, CG etc), in an ideal world I would give them minimum of 8gig plus x64... but that's wishful thinking. darn those budgets! on our 2gig curric machines we use x32 but for staff laptops we're thinking of rolling out x64.
  8. re-read my original post, but to add security layer - negotiate Encryption Level - Client Compatible Cert - (Domain CA provided) Enforce NLA - greyed out due to Negotiate selected making it 'optional'
  9. WYSE S10 with WTOS 5.3.0.09 machines pick up dhcp option to pick up WNOS.ini answer file from ftp server (this works) answer file tells them to run rdp connection to server 'studentRD; 172.16.45.103' this brings up an rdp connection on full screen normally, now we just get a short message saying "Connection "studentrd": connection failed. on the terminal event log I get loads of invalid statement:"random characters" after the 'Accessing system profile' event, may I reiterate that this event log is on the CLIENT the server doesnt really provide any information in the event log, before we removed the service pack it was showing some error messages specifically stating those machine names, but they seem to have disappeared now. i'm tempted to reinstall the service pack to see if they start showing up again
  10. They are thin terminals, there is no downloadable client, desktop machines connect fine. we uninstalled the service pack, but they still cant connect. it's the only thing we have changed on that server in a very long time! if I change the wnos.ini answer file to point to a different terminal server (2003) that works okay...but thats a staff rd server, the weird thing is that this all worked prior to the sp. gah
  11. we also use the GIMP instead of photoshop.
  12. we have office 2010 and libre office on our build (was my decision to slip it into our new win7 build at the last minute) not much usage but for the people that know what it is, i'm sure they're greatful. chosen over open office, due to the lack of oracle-ness
  13. If you're rebuilding existing machines, you could always run litetouch.vbs from scripts under deploymentshare$ (using MDT) we push it to all machines we want to image using abtutor, go round fill in the details and leave it to run, no more user interaction required, this is with a precaptured windows 7build. I want to try and get ZTI/UDI working using SCCM2007 but its pretty heavy work when there is only 2 of us and a whole school to support. :/ seriously though, using the vbs meant we could set them off at the end of the day and then just go home, before we would have to wait for them to finish and fill in the existing details, or go round and f12 at boot for pxe, this process bypasses PXE completely which is awesome, and I believe you can use it to capture/sysprep machines too. it adds the winPE boot image to the system bootloader so when the system restarts it comes up automatically.
  14. hey, we came from novell + Zenworks, migrated to 2003 + zenworks 6 years ago and then last year binned zenworks and moved to 2008r2, plus hyper-v/scvmm and App-v instead of zenworks. we also had deep freeze before and it sounds bad, but we didnt put AV on curric machines as it slowed them right down (old p4's, 256mb ram xp) we now have new workstations and win7 enterprise accross the board and have binned deep freeze as it was such a pain, also not patch management/SCCM friendly. we lock the machines right down via GPO and delete local profiles periodically and we have AV locally now. much better IMO.
  15. None of our clients have been able to connect since applying the SP, so we're going to have to return to roll back, what we've found is that it wont let us turn off Network level authentication, if anyone can suggest a way to work around this then I would be very appreciative. We no longer have a support contract and I couldnt say what firmware they are on, but they did work with R2 previously with security set to negotiate on the server.
  16. sacrej

    iSCSI bandwidth

    we have a dell md 3200i which has two controllers (8ports) these all go into a switch and then each server has 4 ports to this switch we have about 10 vm's running on SCVMM/Hyper-v and to be honest, bandwidth is NOT an issue. we are running 12 15k sas drives just make sure your adapters and switch are setup correctly (jumbo frames etc) we use MPIO, because....well....aggregation isnt an option (the san doesnt allow it) oh and we will be getting a second switch for multipathing at some point....just err...havent gotten around to it
  17. I`m not sure why the Intel adapters are showing 9014, they were definitely set as 9000 originally, as I was the one that configured them all, but I can't just try and change this on the fly though as its a live system with about 11 vm's running. The switch is set to support jumbo and flow control, that was manually set for all designated ports. There are the usual system tasks, but nothing that fits in with the times of the problems we are getting. If it helps, I can provide some kind of temporary remote access so you can have a look.. as I realise its quite a complicated problem to try and describe.
  18. one thing to add, only one server is generally dropping drives at the moment (named Hyperv-2) i.e. "Cluster Shared Volume 'Volume6' ('Cluster Disk 6') is no longer available on this node because of 'STATUS_CONNECTION_DISCONNECTED(c000020c)'. All I/O will temporarily be queued until a path to the volume is reestablished."
  19. roughly every 30minutes (give or take a few here and there) which is strange because on the client they are reporting the errors at slightly later times (about 5minutes later) - one server reports 2 errors every 30mins the other reports either 8 or 11 (alternates)
  20. well i'm not sure, in the SAN event log i'm getting 3 errors at 26minutes past and 3 errors at 56 minutes past every hour, 1 of these errors is for RAID controller 1 and 2 are for controller 0) the switch is this and yes, we are using the Microsoft connector, but it was setup via the Dell software. hope that helps
  21. Okay, due to the servers having 2 x 4 port nic's (intel and broadcom) we put two iscsi ports on the intel and 2 on the broadcom (Intel Gigabit ET Quad Port server adapter) and (Broadcom BCM5709C NetXtreme II) in the hope that if one card completely failed, then there would still be 2 ports serving ISCSI traffic on the server. the following settings are enabled on the Broadcom adapters: ethernet@wirespeed Flow Control Interrupt Moderation IPv4 Checksum Offload - tx/rx on IPv4 Large Send Offload - on Jumbo MTU - 9000 RSS queues - 8 priority and vlan- enabled Rcv Buffer - 750 Recieve side scaling - on duplex -auto TCP Connection offload - on Transmit buffer -1500 Intel Adapters Enable PME - disabled flow control - Rx/Tx Gigabit master slave mode - auto detect header data split - disabled interrupt moderation - enabled I moderation rate - Adaptive Ipv4 checksum offload - Rx/Tx jumbo packets - 9014bytes large send offload - on duplex - auto negotiation log link state event - on max rss cpu's - 8 preferred numa node- default priority and VLAN - enabled rcv buffer- 250 recieve side scaling - on RSS queues - 1 queue TCP checksum offload - rx/tx trasmit buffer - 512 UDP checksum offload - rx/tx Virtual Machine queues - disabled we use the Broadcom advanced control suite 3 as well, where 2 broadcom and one intel are bonded to make the primary LAN connection the failover link cable uses a intel socket which leaves 2 x intel and 2 x broadcom for the ISCSI. according to BACS3 the broacom adapters have the following offload capabilities: TOE,LSO,CO,RSS intel adapters show:LSO,CO,RSS and yes, all 4 nic's are showing traffic, although some more than others (reported on the SAN side too) also, all ISCSI cables are brand new 0.5m cat6. Thank you for your fast response.
  22. Morning all, Got a bit of an ongoing issue with or 2 hyper-v (scvmm) hosts connected to our dell md3200i san i'm getting thousands of error ID: 9, 39, 139 on both hyper-v servers, plus the SAN itself is kicking out disconnection errors everything seems to be functioning okay, but services (cluster drives) drop out briefly, usually out of hours thankfully.. both of our servers have 8 1gb/lan ports and the san has two controllers, so 2 x 4ports the configuration for each server is: 3ports aggregated to 3gbps on our main network subnet 172.16.*.* 1port connected to our other hyper-v server on the subnet 172.15.*.* 4 ports seperately connected to our SAN switch with different subnets for each port so.. server 1. 172.10.130.103 172.10.131.103 172.10.132.103 172.10.133.103 server 2. 172.10.130.104 172.10.131.104 172.10.132.104 172.10.133.104 SAN ports. 172.10.130.101 172.10.131.101 172.10.132.101 172.10.133.101 172.10.130.102 172.10.131.102 172.10.132.102 172.10.133.102 this should give us failover capacity if one controller goes down, or if a NIC fails. by the way, both Servers run server 2008R2 SP1 with failover clustering and the latest version of SCVMM. the san is reporting everything as ok, all adapters are IP4 with jumbo frames (9000) enabled. server adapters are a mix of broadcom and Intel...and they are Dell R610's if that helps. oh and the san switch is a D-link 24port gigabit managed switch (with jumbo enabled) and separate from the main network. if anyone has any suggestions I would be very appreciative, If you need any information please let me know. I just realised, this might be more suited to the virtualisation section, although...it is hardware.
  23. I agree, sounds like network drives. We had an issue where a member of staff would be working in word for example, would then click on Save As... and the little explorer browser would take an age to load, turned out in the end that we had decommissioned an old app server and his laptop still had mappings to a share on that server. as soon as we disconnected the offending drive all was okay.
  24. Got an issue on our desktops where they can't see any computers in network places, but can connect by typing the direct address in, eg \\IT-45\c$ The only machines we can see are the ones that haven't got the firewall client installed. in the Forefront logs I am getting many Netbios denied messages as it is saying my ip is spoofed. details from the log: a packet was dropped because forefront tmg determined that the source IP address is spoofed. source ip: 172.16.0.113:137 (internal) destination ip: 172.16.255.255:137 (internal) ------------------------------------------------------------- seems to have started happening since we deployed the client (we think) but this isnt the only protocol this happens with. if anyone has any idea as to what the issue is, I would be most thankful!
  25. Morning, just a quick query, and something thats stumped me for a while. prior to the summer we were using ISA 2004 and on client machines we were able to type in unfiltered.proxy.****.***.sch.uk in our browser settings and it allow us unblocked access to the web - handy for when we need to download installers etc, or if we have to investigate a website that a student has accessed via proxy sites - the problem is with the new FFTMG server, we can no longer do this - if we try it on the actual server it works - i'm guessing as it has the external DNS etc. it can see the addresses (ping etc) but from the clients we cannot ping, nor can we ping external DNS. on closer inspection of our internal DNS, we can see in the forwarders tab that the two external DNS's are there, but under server FQDN, it states 'unable to resolve' - i'm 90% sure that this is the issue, but I dont know how to solve it....does anyone have any ideas?
×
×
  • Create New...