-
Posts
1,891 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by tarquel
-
Just my two pence here, and pretty much echo'ing the others many, while I fully love and recommend SCCM, I dare say that it could be overkill depending on what you actually need. If you do want or need to do normal application deployment (after the OS is on the machine), OSD (Operating System Deployment in SCCM Terms ), machine inventory and reporting / Software Metering, etc etc.... then, providing the licensing cost isnt too much for you, go for it. If you think it might be a case of doing too much in one hit, but eventually you will want it, then possibly just set it up, but only use it for Application Deployment and some light reporting, and set up a seperate WDS/MDT server for OSD'ing. We kind of did this approach, with the exception that we used (and still do currently use) RIS for deploying XP, next came the set up of SCCM for some inventory / package deployment / natural progressing of things, and then started deploying Win7 via SCCM OSD around Oct of last year At the very least, it would seem to me that you'll likely need WDS WITH MDT in it for your needs (may as well, they are both free and MDT with WDS gives you much more scope than either one alone IMO), and it'll help you get in to how the OSD works in SCCM, while keeping SCCM fresh for when you're confident in doing that. Quite happy to have a chat about it in the evening if you want a IM'ing session - I'm heavily into it myself, along with some not-so-easy customised things within it - so always happy to chat about it PM me later on if you do want to chat about it
-
I dont quite know what: means exactly but bear in mind that if you did clone the partition from the old drive onto the newer drive, you could extend the partition in Windows 7, or do all sorts with a 3rd party tool. I would say thats the only real option here - trying to copy an installed Windows from one disk to another disk will pretty much always result in a waste of time (corrupt files that dont copy across at all, loss of file permissions, etc etc). The only real way that I personally know, is by cloning the partition from disk to disk (note, u dont have to clone a whole disk to another - all depends on the application ur using). Its been quite a long time since i've done any of this, so other than the "old" commercial PartitionMagic, I'm not up on what people use these days, but theres plenty out there - would have thought CloneZilla can do it. Cheers
-
Good find for those that need it.... im gonna stick that in a txt for some other automation plans. thankies.
-
Would have thought so Just like their are updates to the Sync Center / Offline Files components in SP1 to address certain "oddities" etc...
-
Microsoft sure are enjoying the egg on their faces these past couple of years on various things... shame we arent Maybe direction from Gates *IS* needed after all?
-
Sorry. A case of me not reading the content of the OP hehe my bad... accept my sincerest of apologies
-
A super quick google shows us this: How to Configure a Disclaimer: Exchange 2007 Help enjoy. In short: Yes you can using a Transport Rule
-
Good ol' stupid A/V scanning deciding whats best hehe
-
Exchange 2010 with Forefront Protection 2010 for Exchange queries
tarquel replied to tarquel's topic in Enterprise Software
Email is flowing into Exchange perfectly thanks Thats not the problem...- 5 replies
-
- exchange
- forefront protection
-
(and 1 more)
Tagged with:
-
Exchange 2010 with Forefront Protection 2010 for Exchange queries
tarquel replied to tarquel's topic in Enterprise Software
Cheers for the reply Usually when I do a thread on any forum , i do try and make it pretty detailed (tho sometimes the brain works faster than my ability to type, or vice versa), although usually its a wasted effort on the MS forums as it either usually ends up with a Mod or someone rewriting what I wrote, proposing it as the answer, and a mod closing it as answered lol Thankfully that doesnt happen here (we hope ), so thought it best to copy it to 'ere too The reason i wondered about the anti spam tab's in EMC is that, as an example, in the options in FPE, I have under "Antispam > Configure: Content Filter - SCL Thresholds and Actions" the following settings: Suspected spam: SCL 5 - 8 - Quarantine Certain Spam: SCL 9 - Reject but in the EMC under Org Configuration > Hub Transport > Anti-Spam: Content Filtering and on the Action Tab, I only have Reject ticked at SCP 8 and the others are unticked, which isnt the same as the FPE settings.... so it doesnt seem to be right (unless like you say, it wont sync the settings until i restart the settings, which, to be frank, is utter stupidness However, yes, I do see that under the "Enable content filtering" tickbox, it says "Note: The Microsoft Exchange Transport service must be restarted for changes to this setting to take effect" so rather than it meaning just that tickbox, it seems like it means the whole of that section. Thanks for the clarity there Microsoft lol Obviously, I'll have to wait until some point tonight to try that one. Hear ya about the logging.... ive got everything ticked under the logging but nothing mentioning the backscatter. Have found the Get-FseSpamAgentLog Powershell command so i'll have a play with that once things are working. Only the one domain really is on Exchange mainly, but yeah, i know what you mean and will look at that but it's not a prob at the mo Cheers- 5 replies
-
- exchange
- forefront protection
-
(and 1 more)
Tagged with:
-
Exactly my point with my 2nd and 3rd sentances. Had a query the other day, that the sender (and intended recipient) thought our system was blocking a email from a external contact due to file size, but as i discovered in the servername with the NDR message, the server name was a server name or filtering system that was part of their end, which was flagged up by them and sorted. So easy for that sort of mis-understanding to happen so if its only one person, its always worth getting some way of getting the full email bounce, or use a external webmail system that allows you to see the full headers, that they can send a test email to so u can see the full headers
-
Something i've been annoyed about since it came out hehe And yes, the reported workaround that Norphy mentions doesnt work for everyone (for whatever reason). EDIT: Must be blind, didnt even notice Mike's post above However, I did find the following thread: How-To: Install RSAT (Remote Server Administration Tools) on Win 7 Sp1 - MSFN Forum but I've yet to properly look at it to see if its the same, or whether this method is any better. Personally not too fussed now tbh, as April is tomorrow and I dare say they'll have it done pretty soon - given the amount of hate thats built up on every techie forum out there hehe, although its a bit annoying for some of our IT staff that have had new shiney Win7 SP1 SCCM deployed machines over the past few weeks Glad i noticed it before wiping my own with the clean SP1 build Not too sure if there'd be any aftermath from doing it too (probably not, but im not willing to risk it now - just in case). Cheers
-
hehe No probs. Do you ONLY have Exchange in the network or is there anything "upstream" at all? i.e. firewall or ISP blocking it. And does "anyone" literally mean anyone from external, or both internally and externally?
-
Hi all Don't suppose any of you good goooooooood people happen to use FPE [note, thats not a typo of FEP, its a diff product for those not aware ]? To save me re-writing the thread I started on the MS forums, i'm being lazy and just copying and pasting it 'ere. Any ideas (on where i'm being a dense fool) or any thoughts of those that have it set up and come across it or something similar would be most gratefully received Here's the URL to the MS Thread: Like other ppl, I have a few questions regarding FP 2010 for Exchange - the SCP -1 issue, integration, backscatter, and more ----- I seem to be going around and around, reading the same sites, and not actually getting the answers so time to post a thread I think. Firstly, here's the setup in order, from External to Internal: - Internet - Perimeter Firewall (Enterprise level firewall, that does scan email traffic initially) - Linux Mail Server - running Postfix - This has some older AV / Spam checks on it, and is the mail server that we were using prior to Exchange. It still exists as we are still in the migration period (although most of the users are migrated) and it handles entries for some other domains - mainly just aliases to the main AD domain (with Exchange). We have got this server set to deliver email to the Exchange HT server in the event that it cant deliver it to this server (not the best setup i know but its a working solution as we progress with the migration of the remaining users) - Exchange 2010 HT server (we DONT have a Exchange EDGE server at this time) - this is the only server I've configured with FPE at the moment (want to get this correct first before putting FPE on the MBX servers). For info, we have this setup as a seperate server to any of the other Exchange roles (all Exchange servers are Exchange 2010 SP1) The issues I've run in to at present: 1. No matter what I try, I cant seem to get any email coming into Exchange from External (to exchange) to be flagged as anything other than the following in the message headers: X-MS-Exchange-Organization-AuthSource: EXCHHTSERVER.domain X-MS-Exchange-Organization-AuthAs: Internal X-MS-Exchange-Organization-AuthMechanism: 10 X-MS-Exchange-Organization-Antispam-Report: MessageSecurityAntispamBypass X-MS-Exchange-Organization-SCL: -1 X-MS-Exchange-Organization-AVStamp-Mailbox: MSFTFF;1;0;0 0 0 I've tried: - populating the InternalSMTPServers in Exchange with the IP of the firewall - populating the InternalSMTPServers in Exchange with the IP of the firewall, and the linux mail server - leaving the InternalSMTPServers in Exchange empty - with the above combinations, I've also tried include these IP combinations (and leaving it empty) in the "IP addresses used to identify external addresses" option located in the FPE console > Policy Management > Global Settings > Advanced Options, but hasnt made a difference. Note: I've not restarted any services after making any of these changes and nothing specifies that you need to do that. I see in the Event Viewer that the configuration has been saved / changed when making these changes at each attempt, plus I cant just start randomly restarting the Exchange / FPE services continuously due to the organisation being very dependant on E-Mmail delivery (i'd have to do it late at night I wager). The Antimalware side of things and File Filtering works however, as I have entries for these, but nothing seems to work in getting this antispam feature working. This kind of leads me onto question 2.... 2. Do you have to enable or disable anything in Exchange itself in order for the anti spam of FPE to work? How does FPE integrate with Exch in this way? To explain a bit more, prior to trying FPE, I did attempt some while ago to set up the built in Anti Spam feature in Exchange but when trying to get it to install (using the script) it failed and I never got around to actually getting this resolved. Wondering whether this would have any bearing on it. After setting up FPE, I've noticed that when I use the Exchange Management Console on the HT server, it has Anti Spam tabs (fonud at Org Configuration > Hub Transport and Server Configuration > Hub Transport), whereas it doesnt show these when using the EMC on any of the other exchange servers. Is this down to FPE being installed? Does FPE actually install and turn on the native Exchange Anti Spam system and integrate into that, as these tabs and options within dont indicate FPE in any way, so I've no idea now whether they are meant to be used or not 3. Backscatter - I've enabled this and generated the key etc, but other than the Statistics in Server Security Views > Spam Details, I cant find any place showing logs of the messages that have been blocked. Is there some reason for this? The count seems quite high considering i only setup FPE last friday night and while I'm aware the first 24hrs to expect quite a number of them while it trains itself, the number seems to have increased steadily - it tells me 1227 messages have been blocked by the backscatter agent. It was about 400-500ish 24hrs later, but it still seems quite high considering we do have AV / spam / RBL checks in place in the firewall / linux mail server. 4. A side note but i've noticed a few things that I'd love to see in FPE in the future... does anyone know whether the FPE team welcome feedback (other than the surveys) where I could suggest to them some improvements? Any help on the above would be really welcome, as it seems like a really good comprehensive tool, and most of it is easy enough to work out, but seems to be lacking as far as helping you actually integrate it when you are using different scenario's to what is expected. Many thanks. Nath. ----------
- 5 replies
-
- exchange
- forefront protection
-
(and 1 more)
Tagged with:
-
What about your Receive connectors
-
Just to continue it a bit... What HP SAN model were you looking at? In fact, what EMC SAN model were you looking at? Were you planning on SLA maintainance on them too in any way? Prices of them would be cool to know too, tho feel free to PM them if you'd prefer not to openly discuss that. Dunno what prices you were getting for the EQL, and again, what model were you thinking of there (in a comparison)? I cant say i've seen alot of different manufacturers, but the EQL maintainance price for ours is exceptionally low compared to other. That, along with the speed and ease of use of them really sold them to us really. We had a live demo i.e. they brought one in to give us a demo, and I just couldnt believe that the GUI was Java. But again, like with most things, its down to personal opinion and experience i suppose. Also depends on how big ur site(s) are, what infrastructure you have, what you plan to store on it (i.e. solely for Exchange VM & storage or a bunch of stuff), etc etc.
-
yep, i did mean that, and I have Windows Live messenger with FB chat integrated [for those ppl who wow at the FB chat feature ;) hehe]. Its actually not quite Dell. They were bought by Dell a few years ago, but thankfully, seem to have been left to their own devices, and the GUI is the best java based gui ive ever seen....EMC's (old) Celera one was criminally bad for the maintainance (there was the kicker), along with a host of other problems that kept on resurfacing. That particular EMC product served a purpose / stepping stone at the time, but cant fault EQL really in a comparison. Easier to chat about it when i dont have a mountian of work (aka the evening. if ur about - just PM me on here if u have a diff form of IM account as I'm connected with most.....other than twitter )
-
EMC Celera? Cant say i'd recommend them over EQL tbh (we've had some older ones in the past, but dont really want to get into that publicly ) And yes, VMware vSphere 4.0 [4.1 soon] cluster with EQL SAN's clustered as one All storage - both VM's and iSCSI's are on the EQL SAN cluster Our migration is still ongoing (migration from non-exchange environment) I'll add you to messenger when i get home if u want to chat about it later on etc
-
Shared Calendars - Permissions Not Working!
tarquel replied to MyBrainHurts's topic in Enterprise Software
Dont see how that particular group setting would have any impact oni it as such (unless all ur users are Domain Admins )... but could be on the right lines, or it could well be some Exchange setting at play. Difficult for me to say for sure as not on Exch 2003 (running 2010 here) but would have thought that the AD integration isnt really far different between versions. None of our staff can alter each others calendars without requesting permission, even those in the groups u mention. Might be worth looking in AD Users and Computers console (on the Exchange server specifically or u might not see the relevent entries) - Advanced view - Security on the relevent OU, and see what grainial permissions those or the Domain Users group have on it regarding the Exchange related attributes. Obviously, use extreme caution with actually changing any of that, as u cud make it a whole lot worse Exchange 2010 is pretty good at reverting configuration weirdness like that, but I'm not so sure on how good Exch 2003 is with this. Regards -
We have it all (minus a UM server - not a requirement in Exch 2010 I believe but was in Exch 2007) virtualised and all stored using a EqualLogic SAN. I dare say with the RAID level, it would entirely depend on how good the storage system is in the first place. Our SAN(s) and LUN's on them are configured to RAID50 throughout, so I couldnt really tell you how good or not the performance is on a less RAID, but i dont notice any lagging in any sense with regardings to the MBX's at least on a related note, a DAG and "passive copies" for the win
-
Upgraded to Exchange 2010, we now have a problem!
tarquel replied to pritchardavid's topic in Enterprise Software
Like sukh says in points 1 -4 but given there are no storage groups in Exch 2010, you'll need to alter the email address policies to match the new database names and/or locations. No time to find examples at present, but can chat later on this evening most likely if you want a hand with this. -
I'm thinking could you use some 3rd party app out there to "grab" the window and force it to be where you are wanting?
-
Correct.... a newer version doesnt replace a previous version so you will indeed require the older versions (think most apps using .net framework are probably still using .net 2.0 or 3.x).
