ianh64
Members-
Posts
120 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ianh64
-
So no WSUS updates, mail server or edge firewall etc then?
-
[PRINTING] Shared Canon MFD needs everyone priv's to print
ianh64 replied to ianh64's topic in Windows Server 2008 R2
Just removing everyone otherwise the deny would take precedence over everything and lock everyone out. -
What I do at the moment is mount a share on the virtual machine and backup to that, which gives access to the USB drive from the VM. But as you suggest, creating a virtual hard disc on the USB drive (and I guess sharing to give access to the VM) may allow Windows backup to treat it as a dedicated disc may allow incremental backups to be performed without previous backups being overwritten. It may also allow me to create virtual drives on the same physical disc without having to dedicate 1.5TB storage to the single backup. WIll give this a try.
-
We have a Canon (IR3170Ci) multi function device that was installed by an excellent Ricoh engineer on our server yesterday to allow printing from our W7 clients. But we get insufficient privileges if we remove 'everyone' from the printer security, even though the user was allowed via another security group. The Ricoh engineer is stumped. Checked effective permissions for the user and it was as expected, but when trying to access the printer from the W7 machine, we were denied until we put 'everyone'=print back in the printer security. We got everything else working, including scanning and the additional driver features such on board custom forms but i'm not happy that we cannot prevent anyone printing to the printer unless we specifically exclude people or use the department code feature of the printer that forces anyone to enter a department code to print absolutely anything.
-
If I use a dedicated disk (ie a USB drive) for Windows Server backup, can it be used to store multiple backup sets or just the same backup? ie. Can it hold a one off full backup, but also handle nightly incremental backups of different discs? Seems like Windows backup options are limited if you don't use a dedicated disc. I was going to use different partitions/shares for different backup types, but Windows backup warns me that it will overwrite any previous backup if I use volume or share based backups. If I select to use a disk based backup, the implication is that it will reformat the whole drive including the partitions I was planning on using for the incremental backups. Extra question: If it can hold different backups, is there anyway of mounting the USB disc in a hyper-v virtual machine and performing a backup of the virtual machine? Hyper-V does not directly support USB devices so it would have to be accessed via the host. Problem is if I backup the virtual drive on the host, it takes ages as its about 200GB where as an incremental backup from the VM will have much less to backup.
-
Got as far as I wanted/needed to get so decided to jump and retrain in a different career. But got involved with my sons school and helping them with their IT and technical things is much more interesting even if it is mostly voluntary.
-
Im not going to mention the MIS company as I have criticised their practices on a public forum. Its possible that they are in a different sector than you are in so are not so widely known to you, but it is not one of the companies that you mention. My criticisms are not not meant to be a name and shame exercise, but a guide to what are reasonable expectations in this sector and at this price point. At the cost of the product, I personally think that my expectations are justified, but as I said, I was a very senior developer and technical consultant in the banking sector where getting things right and secure for the environment was a given and a strict process was followed, so my expectations are high. But I've also done media and broadcast sectors where things were a bit less stringent - just trying to gauge what to expect as its my first foray into the schools environment. I'm not saying that this is what we paid, as installation was bundled in with the total cost along with training days, but based on their, and other companies man day install costs of in excess of £700, I would expect a job better than I could do, not a cobbled together, well it doesn't work so give full access to everyone rather than track down the issue. To say they got the school by the short and curlies is an understatement, effectively saying that their old system is no longer supported and the only way of getting a supported product is to upgrade to new modern web package at twice the cost - then find its 40% sql/web based, 60% late 1990's technology such as dbase/delphi. Use of Exchange was a pre requisite by the school wanting to follow industry, it's cheap, relatively low ongoing costs (antispam/virus and smtp failover), and relatively easy to provide. Don't see the issue with giving them what they wanted even if 70% of the look and feel could be achieved with what they already have using Outlook, imap/unix server. But they wanted industry standard, which includes Outlook, owa, calenders, contact lists etc and better spam controls. Maybe there are other solutions, but Exchange just does what they expect it to and what they didn't realise they wanted until they used it such as shared mailboxes and active sync. I don't see any need for doing it any different. Plus its an extra tick box on my CV PS. Companies parent is a Microsoft Gold Partner. Obviously don't listen to what their parents recommend.
-
Neither.
-
Not everyone has mega bucks to implement best practice when the new server was forced on them by the need to upgrade their MIS system with the prior version being unsupported due to its age (it was quite ironic to find that their old unsupported system was based on same technology as the backend of their new system). We have got one physical server, its a one box solution, but its a small school and the spec is more than adequate for the school needs, except redundancy, although an extra few GB of RAM would be nice what with running a couple of VM's But the school knows the risks and don't have the funds to do anything about it so will take the hit if the servers (physical or virtual) goes offline for a few days whilst server and data are restored. I think the school have done exceptionally well with a server budget (hardware, install, licenses, backup, install) of about £3k which is a little more than the annual cost of the MIS upgrade forced on them and really should have taken last year and couldn't because we could not afford to buy the server needed to run it. The cost of server over 5 years is offset by losing the annual unix server contract that creaked everytime an email was received, hence the need to upgrade the email system too.
-
We have just had upgraded our MIS installation to a new Windows server platform and office machines. This was performed by the company responsibility for the MIS and will remain nameless as they are a big player in the education MIS sector. The server, policies and office network were designed and built by myself. So I am particularly protective of the environment as its in its infancy. I came from a long IT development background, much of it in international banking sector where security was paramount, and often to the point of being excessive and preventing you from doing your job without someone looking over your shoulder. Having seen the practices of the MIS company, I am wondering if I have become paranoid with security or whether it is too much to ask for a MIS company to treat the security and reliability of an establishments IT systems with a less cavalier attitude. Having found yesterday that they had told an end user to log into one of our servers and run a program from there, I started doing a bit of digging around to see what the result of this weeks install had left. It was a timely look as soon after I get a call asking for their trainer to know the admin password so they can 'fix' privileges on one of the office machines. The MIS system shared its server with Exchange. So it is quite a mission critical server. I was also led to believe that it was SQL based, but soon realised that it was a set of programs up to 15 years old with a bolt on web interface. The results of my brief investigation seem to result from the requirement of having legacy apps expecting free rein over a PC/Server. So I found many folders with 'all users' having full control privileges. I found a share on the servers, containing the schools accounts information having full control for everyone. The web site, appears to be internally unencrypted. So password will be passing in plain text from a forms based login. Not expecting any of our pupils to be using a sniffer, but for larger schools, it could be an issue. I'm having do so a https->http redirect on our external firewall to at least secure the site from external internet. Install a legacy app on a Windows 2008R2 server using software components dating back to 1997. This app was quickly removed by myself as it was installed without authorisation - they were told to install data on server and app on office machines. But instead install app on server too and when they can't get app on client to work, presumably as it didn't have required free reign over server, told the user to log into the server and run it from there. And today, the trainer asks for admin password so that they can give full control to all users on a office program files/mis app on PC C drive. I found that full control was not necessary and giving all mis users modify right to be sufficient. Residue of folders from the server installation left behind after install. About half a dozen folders being created at top drive level to contain the myriad of data files, backup files, program apps, third party software (eg Borland/Delphi dlls dating back to 1997 and 1998) left on server with default disk rights or everyone access. Expecting admin rights to be granted to office users so they can get around access issues with Borland/Delphi dll's expecting full access to machine. In the end this was achieved by a regedit fix which, in heindsight, has probably not been applied to the other machines requiring them to have 'full access' to their program files area. Am I being over protective or would you expect better of the latest, secure software being developed and installed by a leading educational MIS company?
-
[windows software] CALS - Device or User?
ianh64 replied to soveryapt's topic in Licensing Questions
This is quite a pertinent topic for us as we have just rolled out our first MS server in the school to host the office network. But over the summer, we have a new ICT suite coming online and upgrading to a school reporting system that will be rolled out to the teachers as well as the current office staff. Presently we decided on device CALs for the office suite, but the technicalities of licensing, a change in license supplier by Surrey County Council and, the direction of the school reports system shifting to the teachers working from home has recently led me to reassess our licensing options. Infact, it it one of my jobs today. We have available to us, two licensing models. 1. Perpetual licenses - Select Agreement 2. A subscription based license - Schools ProDesktop The perpetual licenses are available as Device CAL, User CAL or, something that I had not realised, a mix of both. We have approx 30 staff and 120 students, all of whom need to be licensed even though the younger pupils do nothing more than doodle on a group PC. So one of our options is to license all the student accessible PC's as device CAL's ie the ICT suite and some classroom PC's, then license all the staff with User CALs. This will bring our licensing requirements down to approx 60 units and allow staff to access the reporting system from home as they are user based CALs. The subscription based license is device based and one subscription is needed per desktop in the school. Servers are licensed separately either as a subscription based model, or a perpetual model. As it is a whole school agreement, its an all or nothing agreement so we cannot mix and match to different PC's - many of our PC's are legacy and will not run Office etc or benefit from software assurance which allows us to upgrade versions of the OS or applications. Even though this is device based, staff get work at home rights, which solves the problem of not being able to license a home PC with a school device CAL - putting it simply, you cannot license a device that you do not own, ie a home PC. Something I had not realised until reading this thread was that printers counted as device CALs. We have a networked photocopier with the server acting as print server. Thankfully we ordered a few spare CALs for the office so are covered until we need to make the decision about rolling out the rest of school. But does anyone know if a printer needs a device CAL if it is local to a PC but shared and deployed via group policy? -
Working in a test environment prior to deployment. 1 x Windows 7 client, 3 x Windows Server 2008R2 Servers (2 virtual), Exchange Server 2010/3, Forefront TMG 2010/SP1, Forefront Security for Exchange Server. I am trying to access the Exchange Web OWA website but I am having mixed results. Fore the purpose of this test, the everything is in AD domain xyz.school except Forefront (and edge transport) which is in a non AD workgroup. All dns is name.xyz.school so: office1.xyz.school - Windows 7 client - 192.168.3.101 griffin.xyz.school - Server 2008R2, AD DC and RRAS LAN routing - 192.168.3.1, 192.168.2.1 leo.xyz.school - Virtual 2008R2, Exchange Server and OWA on IIS - 192.168.2.21 eagle.xyz.school - Virtual 2008R2, Workgroup - Forefront TMG, Exchange EdgeServer, Forefront Security for Exchange Server - 192.168.2.11 On the Windows 7 client: https://leo/owa - works but gets certificate error - certificate is for LEO.abc.school. Cannot se any logs in Forefornt TMG https://leo.xyz.school/owa - times out. TMG indicates ssl tunnel is blocked by default rule. Everything looks fine in TMG. Domains setup, even excemption of domain from malware and ssl inspection. https://192.168.2.21/owa - times out. Again, ssl tunnel is blocked as above The SSL denied message is: Log type: Web Proxy (forward) Status: 12202 Forefront TMG denied the specified Uniform Resource Locator (URL) Source/Destination: Internal Request: leo.xyz.school:443 Protocol: SSL tunnel User: Anonymous On griffin AS server As above On eagle Forefront TMG No access via any method. Blocked by 'branchcache - advertise' rule!!! On leo Exchange server Seems to work as expected - seems because I have scripts blocked in IE so cannot use OWA otherwise access is not logged in tmg nor denied ---------------------------------------------- If this wasn't for the fact that this should work, I would probably setup an ssl tunnel allow rule. But I think there is an underlying problem. Especially when accessing from Windows 7 client via netbios name, it works. My guess is something to do with certificates, but I scratch my head over these. Prior to moving eagle (edge transport / forefront ) to a workgroup, it was part of the AD domain and it worked fine. Just decided fairly late in the day that, due to a change in ISP, it would be better to move edge transport out of AD domain. leo and eagle build largely from scratch - full reinstall of OS and rollback to earlier snapshot. Not sure if adding am exchange web client access rule in tmg will help since I had this in an earlier build and I was still having problems. But it has worked when eagle was part of the AD domain. Any suggestions please?
-
I didn't think it mattered but after doing a couple of re-installs over the weekend with mixed results, I got better results if I also deleted. OU : Users - delete the exchange specific users - discoverysearchmailbox, federatedemail and two systemmailboxes OU : Microsoft Exchange Security Groups - whole OU Jury is still out on what certificates need to be revoked if any.
-
A quick update. I found that previously email enabled users had a whole host of Exchange specific information as part of their profile so there was more to cleansing users than just removing the email address. IIRC, using adsl edit on each user, I simply set the exchange specific nodes to no configured on all but one of the values - the other could not be edited. On my test bed, this was only the administrators account so not much of a hardship.
-
Thanks to both of you. I took the opportunity to get more familiar with adsiedit and found things that I did not know existed, like the configuration container. So the original instructions from MS web page in regarding AD are helpful, but much has changed from 2003 version in other respects. There are some for 2007 too when I searched for the subject in the post. I initially tried to edit AD to move the mailboxes over and had some success, but was still getting a few errors. As I am in a test environment, I decided to remove Exchange from AD completely and roll back to earlier snapshots of my virtual machines and reinstall from scratch. As a result, I was also able to revert back to my earlier server name so no need to update all the documentation. A fresh install has just completed successfully, so I am able to move forward with this again. If anyone stumbles across this in the future, to completely remove exchange from a domain, use adsiedit to remove all the information from both the 'configuration/services/microsoft exchange' and 'microsoft exchange auto discovery' nodes plus two OU's from the 'default naming context' and a number of exchange users - discoverysearchmailbox, federatedemail and two systemmailboxes. I also removed email addresses from any users. Then reinstall. Easy when you know how!
-
Thanks for the link. I had already seen it an dismissed it as none of the information in it bears any resemblance to any of the options or structures in Server 2008R2 / Exchange 2010. Any more suggestions please? Its a fresh install of a new server with new name. The old server is non existent so there is nothing to remove from it, just active directory causing issues by repopulating mailboxes, defunct servers and I suspect, defunct corrupted certificates.
-
I'm running in a 2008R2 test environment and have been struggling with trying to create a fresh install of Exchange due to some configuration / authorisation issues. I have 3 test servers. One running AD GC, one running Exchange 2010 Typical install and one running Edge Transport and Forefront TMG / Exchange Server. The two exchange servers are virtual machines using Hyper-V. I have been using snapshots to roll back configurations to bare bone install but Exchange Server settings seems embedded in AD. Its the second time I have had this problem - last time I rebuilt the whole test network, but i'm not planning on that this time. I tried to do a reinstall of Exchange server on a fresh Windows install, same server name, but Exchange says that the its in a incomplete state and need to use setup /m:recoverserver (or whatever it is) but that fails due to a corruption issue with the certificates - the root cause of my transport errors in the first place that I am trying to solve. Q1: Can I delete exchange from AD and make a fresh start? There is some online documentation, but its all unsupported and for earlier versions of Windows and Exchange. So the instructions and structures mentioned are not the same. Thinking of changing the server name to something different, I got Exchange installed, but the old server, and mailboxes etc are still listed in Exchange. Q2: How can I delete this now defunct server and mailboxes from Exchange? Again, I have found instructions for earlier versions, but nothing matches the tools or structure in 2008R2 and Exchange 2010. As its a test environment, nothing is precious except my AD DS/GC server that I need to keep intact. Many thanks Ian
-
Thanks for assisting. I've gone and broken it big time now. As it was a test bed, I decided to delete all certificates that were not issued by the internal CA - Active Directory Certificate Services - Enterprise CA. The aim was to avoid kludging whatever certificate was not in the CA and get a proper one from the outset. Unfortunately, whilst the CA was active, auto enrollment was not so I think at some point, an important certificate got created but not with the correct CA. Anyhow, to cut a long story short, IIS on the Exchange Server is not working correctly when using ssl connections. Not sure what I broke, ie deleted, so not sure how to reinstate. Presumably I need to recreate one of the certificates that handles ssl? But not sure which of the many and many different templates handled this. I did roll back the Exchange Server machine using a hyper-v snapshot to a few days back and that did work do I know its the exchange server or the iis on same machine. But I don't want to revert permanently with this snapshot as its a few days out of date and I had made quite a few Exchange and SQL Server configuration changes in the interim. Any suggestion on tracking down this likely certificate issue with non functional iis/ssl. Many thanks
- 5 replies
-
- -2146893019
- 0x80090325
-
(and 3 more)
Tagged with:
-
Thanks. Ramesys finally got back to me and it seems Ramesys were no longer managing the licensing arrangement that we had previously used so had to get new supplier details from the County Council. New preferred supplier is Phoenix Software and they were very helpful, returning my call almost immediately then spending about 1/2 hour going through the intricacies of the different options.
-
Does anyone have a concise list of suppliers who can reliably provide licensing information and prices. Everything all seems a bit of a mine field so I need expert assistance. I tried Ramesys who we got our existing licenses with (via a third party reseller), but they obviously do not want our business as I have left multiple phone messages and emails over the last 5 days that have been unanswered. I need someone who can price a few urgent Forefront licenses then discuss the licensing of our next phase of rollout - currently chosen device CALs, but now that number and type of users have been more accurately assessed, and our access and product requirements are better understood, we are wondering if user CALs are going to be a better choice. Approx 45 PC's, 90 named users, 70 of whom are individual pupils, plus some generic classroom login's, for the nursery and lower (pre-school - year 3) years.
-
Thanks for the answers. Will take a look at personal folders. I looked at distribution groups - infact I am using one for group mailings. But, if I am not mistaken, distribution lists will only 'fan out' an email into different mailboxes which is not what we need. We need to have a single mailbox so that the sharing users can see if an email has been answered.
-
I am in the final stages of testing a migration of a primary schools Office suite from Navaho to Window Server 2008R2, Exchange 2010, Outlook 2007. At the moment, there is very little reliance on IT Security/auditing so there is significant use of shared role based accounts rather than individual logins - I am planning that this will change! As a result, a number of critical external email accounts are role based. For some, bursar, headmaster etc, there is a 1:1 mapping with a person, so its not too much of an issue to use the alias, but for for others, office, sports etc, are roles shared by a number of individuals. Even for individual roles, there will be some sharing of mailbox whilst individuals are for instance absent. I am looking for best practice on how to organise this. Ideally I would like each individual to have their own personal email address, and, based on roles (I have security groups set up for this), access to a role based email address. This would also apply to bursar and headmaster etc where the individual will have both a personal email address and their role. This is my first experience of exchange server. Got a big thick book and internet but nothing specific. Whilst I realise that mailboxes can be shared within Outlook, this is not an ideal solution since they need to be set-up within Outlook rather than managed centrally within exchange. I have done some reading and it has been suggested that room or resource based mailboxes may be suitable. I have set a test one of these up to cover office but have found a few issues: Only able to send email from users account, not room account; room shows up as a room in calendar - would like to disable this. In addition, being unable to test receipt of emails on my test network, I am not 100% sure whether a room or resource mailbox able to receive external emails or not. Many thanks Ian
-
Independent School : Nursery and Primary age 2 - 11 years. Approx 120 pupils in primary school requiring either group or individual (<70 in years 4,5,6) access. Approx 30 PC's, expanding to approx 40 over summer. Only admin staff heavily utilise IT. This is expected to change with new Windows system and more widespread use of DoubleFirst. 1 Windows 2008R2 AD DC server hosting 2 hyper-V virtual machines - Dell T410 dual quad processor, 8GB RAM, Raid 5 - SAS 15k drives ~ 850GB storage 1 Navaho Server currently hosting staff and pupil requirements, will become legacy during Summer with new 20 seat domain ICT suite replacing 10 seat Navaho/workgroup. Windows server hosting AD DC, Exchange Server, SQL Server/Double First, general infrastructure, routing and internet gateway/firewall. Ideally we could do with a bit more memory - host +2VM a bit tight on 8GB. Admin staff, Windows AD infrastructure - phase 1 (final testing, imminent rollout), Staff/Student roll-out phase 2, Contingency/redundancy is phase 3 - budget is limited so will see if any old kit can be redeployed.
-
Thankfully I won't have to worry about emails being exchanged between Navaho and exchange. After initial migration, Exchange will host office and Navaho the teaching staff and students which currently, do not need email communication with office staff. Teaching staff are only very occasional email users - soon to change with new system - only 2 teachers seem to have logged into their email this year, one in March! and the other is the ICT co-ordinator who will be getting an exchange email address in the first phase so will have exchange email access via owa.
-
I tracked down the test client incorrect status to what appeared to be a dns timing issue. The client only had one dns server (.2.x) configured, which was on a different subnet to the client lan (.3.x). I changed the primary dns server to be the one serving the client lan (.3.x) and kept the original dns server (.2.x) as alternate dns server. Its been running a few days now and, in test scenarios, always got the correct status. At the same time I also updated the DC NIC port on the server for this subnet to also have an alternate dns server (hosted on the DC). Since doing this, the DC has also given the correct internet connection status.
