Jump to content

azrael78

Members
  • Posts

    384
  • Joined

  • Last visited

Everything posted by azrael78

  1. We have it here, I'm sure there's no harm in trying to furnish you with a copy as you can't do squat without a VL key anyway. Besides nothing to (theoretically) stop you downloading it from the net... but let's not go into that. It's 2.14GB (Vista Business SP1 - Full OS + SP1). If you have your MS Licensing information, you can just download it from the MS site itself - it may be faster than trying to transfer it any other way. If not - let me know what methods you could use and we will see what we can do. Az
  2. azrael78

    4GB USB Pens

    The wonderful world of irony... I get my flash memory cards last night - all 3 work, they say 8GB and are 8GB (well 7.98) but that's all good. My card reader however (bought from EBay) for a couple of quid, is totally useless - it failed to work in 4 XP PCs and 1 Vista. It failed in as much as 'Windows doesn't recognise this device...'. The reseller says no drivers are needed, so I'm working on the basis that the reader itself is duff - so I've e-mailed the reseller and am waiting to hear back. For now I got a reader that works with my cards and can keep it until I get myself a new one or get a replacement... I won't lose sleep over it tho, it's a couple of quid but that doesn't mean I won't keep poking until I get an answer. Az
  3. Students: 50MB on one server and 300MB on the DT server. Staff: 300MB and DT staff have 800MB upwards on DT server. However these figures are slim and DO NOT permit any kind of video, audio or any such content to be stored. Manglement wanted it all nice and clear. Az
  4. In the GPMC - navigate to the OU where the policies are applied. Click that OU and then click 'Linked Group Policy Objects'. I believe that the higher the link order - the more precedence the policy is given, but I may be mistaken. Unfortunately I can't help you all that much more as the image you supplied is very small and it's tough to actually see it. Az
  5. azrael78

    4GB USB Pens

    DAMN - Wish I'd read this thread BEFORE ordering my 3x 8GB SD cards... from Hong Kong. They said around 5 business days but it's been longer so far - thankfully I don't NEED them urgently, but would be nice to have. Az
  6. azrael78

    Windows CA

    Funny you mention this - I've had to move a CA before now. All you need do is export the certs you want to keep from the old CA (not the root cert) - put a new CA on another server. Have the new CA make a new root cert - then via Group Policies it (by default) will import root CA's, I think there's a setting somewhere that tells it where to import the master CA from - but right now I can't find it. Be sure to decomission (remove) your old CA though once your new CA is working okay - or better still... just switch your old CA off (if you can). Hope this helps - thanks for kicking FastHosts into line Az
  7. Our kids don't get \\server\sharename when we connect their drives. They just get the letter - no paths, no nadda. For the most part - if they don't know the server names AND shares (as we turned off the browser service so they can't browse the domains) - then they can't just find this stuff out unless a member of staff unwittingly says something to them... hurrah. Az
  8. Same for us - I'd LIKE to upgrade, but I just can't justify the underlying reasons behind such a large upgrade (and with only 5 weeks too). 2K8 has a few things that would benefit us - the increased security, DFSR enhancements and RDC would be good - plus the additional GP updates too. Just don't know quite enough about it to upgrade 9 DCs in 5 weeks and hope everything works. Az
  9. This is what got me - sat here in my office I can almost 'taste' the MoviPrep - sounds strangely like what Lemsip tastes like. Az
  10. To me this makes sense also - the career information (as in job ads) could be public and the job advice should be registered only - as WITCH has pretty much stated above IMO Az
  11. Today we had a huge pile of fun regarding our 3 Forests (2003 R2), NTFRS and the SYSVOL area. Somehow - last night, the whole thing decide to 'kiss goodbye' to life in general and hang itself by the short rope. This morning I remoted in via VPN (or tried to) and discovered this heap of fun waiting for me. As I had no method to VPN in (as not only was SYSVOL non-existent, but no authentication worked at all either...) I had to wait until I got into the office. Suffice it to say that it's all working happily now, NTFRS is happy, SYSVOL is happy and all is right with the world again (despite the fact that certain members of staff can't follow instructions of "Please DO NOT call us to tell us things aren't working... we KNOW."). So... with todays' disaster behind me - I'm seriously considering moving our DCs to Server 2008. Now I feel the need to point out the following: 1) Servers are i386 - not x64 based. 2) Servers are DCs and GCs, host Group Policies and a whole host of other files. 3) Some DCs also host IIS based applications (this dates back to when we had very limited budget and not enough servers...). 4) Some DCs are using the File Quota and File Screening capabilities of 2003 R2. Now as far as I'm aware - they do little more than above, perhaps run a few additional 3rd party apps (Oliver+ for our Library - which is IIS based). For those of you who run 2008 servers either as member or DC servers, have you come across any little tips/tricks or stumbling blocks from moving to 2003 to 2008? We have 2 2008 servers, fresh builds - I noticed 3 issues. 1) Our remote access tool (Dameware) required a hugely later version to work with 2008 reliably. 2) In relation to #1 - We had to disable the whole UAC thing via local policies on the servers in order to get a decent level of access via DW to the servers. 3) We noticed that if we logged into the servers LOCALLY and the LOCAL account had the same password as a DOMAIN account - 'passthrough' didn't occur. (On 2003, if a local account and domain account had the same login name and password, you could simply login locally and use the local creds to get the domain-based access... local admin for example 'passes through' on 2003 to allow us to access network shares as a full domain admin IF our logins and passwords were the same. - On 2008, this doesn't seem to occur, is this normal behaviour?) (I know all about account security and such, sharing passwords between local/domain accounts and such is a huge no-no, we're trying to get away from all that style of thinking but manglement likes it nice and simple so my juniors don't have to remember lots and lots of passwords...) So... any advice/tips/tricks? On the surface - 2008 seems a different beast, but once you work out where the common options are and such, it just seems to work - just like 2003 R2. Az PS - For those curious/interested - NTFRS (among other things) had taken it upon themselves to wipe our SYSVOL structure and then hang itself. I fixed the issue by rebuiling SYSVOL and resetting NTFRS before restarting NTFRS and the NETLOGON services.
  12. I'm afraid I can't help here - don't even have Server 2008 around to try it on. If anyone comes up with anything positive (or otherwise) about NAP, I may be able to sell it as another reason why we want 2008 here as opposed to 2003. Az
  13. BUILTIN\Everyone - allows EVERYONE access to the resource, authenticated or otherwise I do believe. You should (in terms of security) use BUILTIN\Authenticated Users instead - as this then enforces them to have a valid domain or local account to be able to access the resource. Az
  14. We will shortly be doing this also. Running a delete profile script at PC shutdown (as our PCs get a reboot or 2 a day) - it won't delete Administrator, LocalService, NetworkService, Default User - but anything else is fair game to it. The good thing is it won't run on LFT's (as these have local cached roaming profiles) - but anything else (except Servers) is fair game for it. I'm almost looking forward to it in some kind of perverse way. Az
  15. Ah okay - thanks for that info though. We have Windows licensing all over the place here, so we'd probably end up using DFSR and Virtual Server - if we use virtualisation at all that is. Az
  16. I want to say 'yes it would' but I don't think I can in all honesty. While VSS can snapshot most things while running - to be quite honest I'd rather down the VM itself (if you can) rather than back it up while it's running. You can of course restore a running VM - but it may not be too happy when you try to reboot it. Best thing to do is to use NTBACKUP inside the VM itself (as you would a real server) or down the VMs and then use NTBACKUP. But it's all up to you - take a plain server VM - load something on it and then see if you can happily NTBACKUP it while it runs or no - that way you don't mess up anything that runs already and you get your answer with your own eyes too. But personally - I'd rather drop the VMs as a scheduled task and then back them up. Az
  17. We currently don't virtualise (but I plan to change this somewhat) - although I'd agree with the philosophy of 'backing up to' rather than 'storing on'. If your NAS fails - you lose the VMs (or their data) if you store it on the NAS, if you back it up TO the NAS, then if the NAS goes down - you only lose the backups for the VM. Az
  18. Manglement here isn't a fan of Linux et all - but if it saves £ then he may be swayed... do you have any additional information on Xen and DRBD? (I'm reasonably familiar with CentOS... what version did you use?) Also - why did you not use Server 2003 R2 and mirror using DFSR and Virtual Server? Any particular reason? Az
  19. Aha! I wondered how you could boot from USB... thanks Az
  20. I'd just like to add weight here by saying USBDLM... works wonders for pencil sticks. We use it here and it's made our USB drive-letter woes vanish real quickly. We are also going to implement SRP over summer as well, for us we permit anything EXCEPT where we specify (We have alot of apps, alot of servers and it's quicker for us to deny, than it is to whitelist). Our students home-folders are mapped to Y: - so we would just deny the drive letter - as opposed to any environment variables. Our USB sticks live on B: or F: or V: (in the event that B: is used, it moves to F: and in the event that F: is used... it moves to V:) so we can just deny those drives - it's highly unlikely that a student could get another drive letter for their USB, even if they plugged in 2 sticks. (Which they can't anyway here) So... for some apps a hash rule may be useful - but for us, I simply plan to use path rules to cover pretty much everything that isn't nailed down. We are also gonna put in some kind of executable monitor, so we can see what they are running and from where (just so we can see if we missed anything). HTH, Az
  21. No problem - if you find anything a little odd going on (which you shouldn't) - DFSR diagnostics (inside the DFS Management MMC) are invaluable for pointing out where a fault lies (in terms of servers) and how you might go about resolving it - but just don't rely on it too heavily as if DFSR is seriously bodged, then the diagnostics don't work either... hurrah! Plus... the old favourite... Event Viewer is your friend - even if it's wonderfully vague at times Suggest you run the diagnostics over each replication set at the end of each term (before half term starts - so you got some headway to restart things and such) - it should all keep reading as 'good/happy' or whatever other word they use to mean it works. We've rarely had any issues here Az
  22. Let me just add in my 2 pence here... We currently DON'T use DFSR (2003 R2) for staff DATA, but we do use it for Profiles. Aside from our initial configuration woes (when we didn't have R2) - it's been solid. It's a DFSR tree shared across 4 DCs - the updates are pretty much instant and we've rarely - if ever had huge problems or issues with DFSR. Something to think about though... if you are going to use it on student data and you plan to use file screening or quotas... be sure to set the DFSR root so that it's NOT inside the student folder. E.g. D:\Students\UserName - is where they live usually for example. If you wanted DFSR to succesfully replicate this (and not get throttled by your quotas or filescreens) you'd need to modify it to this: D:\DFS-Students\Students\UserName Point DFSR at the 'DFS-Students' folder, so that the DFSRPrivate folder is created outside of any quotas or filescreens and doesn't get hammered. You could of course simply exempt it from quotas and filescreens if you are using R2 or 2008 - but some quota apps don't easily allow exceptions - or don't work as expected. HTH, Az
  23. We've had this - no local policies set - yet internet explorer still pulled up our old old old old proxy. Have a look inside the registry of a dodgy PC. HKLM\Software\Microsoft\Internet Explorer\Main and HKCU\Software\Microsoft\Internet Explorer\Main Look at the entry called 'Start Page'. This is the homepage used. Check these remotely when a user is logged in (when the PC displays the right homepage) and then do this again when the PC displays the wrong homepage. I suspect you will find that ONE of those values will be reset to the HP page, in which case you may need to force-set the homepage somewhere on both the PC itself and the user just to be certain. Az
  24. This has already been said or thought I'm sure. Your DC's DNS should be pointed to itself and nothing else. Inside the DC DNS server - all local traffic should be handled by AD and DNS, external traffic should be set to forwarders. In your case, you should use your router as your forwarder. Using the cache thingy may end up causing unnecessary requests as the cache thingy will only query your upstream router anyway, so you'd be better off keeping the cache thingy for it's job (caching) rather than DNS forwarding also. So your client PCs should talk to the DC first - if it's internet, the DNS request (but not HTTP/HTTPS requests) should go to your external router (and not go via the cache thingy). Then your PCs simply use the cache thingy directly and any DNS requests it needs get handled by it directly. As for your homepage woes - I've had this before. Sometimes homepages would set, sometimes not. Set the GPO that sets your homepage and IE proxy information as Enforced - meaning no other GPOs can override it or disable it or mess with it. It may be worth logging the same user on 2 machines and checking to see what's different aside from the homepage... this assumes that the PCs with the issue are in the same OU as others and aren't hugely different in terms of software, Domain or Local GPOs. Az
  25. This smells of DNS not having proper NS records set or perhaps the DNS records for your FWD zone aren't correct here. As for doing a NSLOOKUP on (not FQDN) - you need to have DNS search suffixes configured inside of Group Policy to make that little gem work, however it's not 100% important right now as even if you put in the FQDN - you still get nothing. Let me throw you the entries we have here for one of our working zones. FWD Zone: (Same as Parent) Start of Authority (SOA) [###] dns.local, hostmaster.local (Same as Parent) Name Server (NS) dns.local dns Host (A) ##.##.##.## ### - Any number, usually relates to the number of updates the zone has had. ##.##.##.## - IP Replace 'dns.local' with the FQDN of your DNS server. Ensure that your DNS server has an A record in it's own zone. Once done, Clear the DNS cache and then go to a local PC and type NSLOOKUP This should then give you a positive lookup - I hope. HTH, Az
×
×
  • Create New...