PiqueABoo
Members-
Posts
2,184 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PiqueABoo
-
CC3 is mostly just a pre-configured Windows domain and you can set account policy the very same way you do in normal Windows e.g. in the Default Domain Policy. Off-hand the only policy thing I think you should avoid is GPMC, coz RM have AD and Sysvol permission mismatches that you definitely shouldn't let GPMC correct.
-
Pah.. it's Powershell (dotNet) scripting this week isn't it?
-
Well that worked.. why are you faffing about trying to make clunky things play nicely? Give them static addresses and put your favourite names in DNS yourself.
-
I think anything that provides a service to the network should have fixed address, so that's more or less everything but workstations. I'm not so interested in reservations coz I prefer to keep track of what's using what static IP in DNS where you can give them sensible names. If there are a lot of printer or switches or APs you can file them away neatly in their own zones.
-
Worse.. IE7 broke my 3yr olds Spooky Spoon song and anything else on CBeebies in full-screen mode, although that may well be an interaction with a ton of pre-installed tat that turns up on a Dell.
-
Do what Ben says i.e. zap the entire OS and start again. It's only worth spending time trying to clean machines where reinstallation would involve a huge amount of manual configuration. In practice various utilities will happily find/remove rootkits, but they'll be lucky to detect and remove changes someone might have made via that rootkit. Figuring out whether it has happened is not easy... even when you've been cunning enough to do things like routinely capture file integrity data for your system via a boot CD/floppy.
-
That's a bit I have a problem with. Unless adresses are scarce (which they don't need to be given rfc1918 & NAT) or you have an unusually unstable network, then why shouldn't it be much longer? What's wrong with making them long enough to comfortably survive the summer holidays? Short leases are obviously good for some untrusted subnet where visitors/students can connect laptops wirelessly or similar i.e. you don't want machines you might never see again squatting on a lease for the next three months. Short leases might be good if you're forever shifting machines into different subnets, but who amongst us does that? Yeah, but servers & services always try their very best to fail when no one is watching... a three day lease won't survive a bank holiday weekend (unless you're into wasting electricity occasionally starting up and shutting down machines in empty rooms).. and you've probably got more than 20% being started at the crack of dawn on the first day back by WOL... which won't keel over if there's an opportunity to humiliate you. You'll be lucky because "80/20" comes with the word "rule" glued to it (remember to do the same for any meme you want to dominate the planet). If you dig deep enough, there is or was an MS doc discussing the various pros & cons of the standby method and all the other approaches to DHCP discussed in this thread. Can't recall if that covers clustered DHCP, but that's another option.
-
Mmm.. that's what they all say.. ;b Is DHCP-20 on a different subnet from DHCP-80 and depending on (DHCP relay) latency to prevent leasing addresses until DHCP-80 dies? Are your leases long enough for DHCP-20 to have enough addresses during an outage (non pingable gateways could bite you here). If they're on the same subnet with a 50/50 split do you have at least twice the number of addresses you need and are you using superscopes? YMMV but a DHCP outage shouldn't affect too many machines. If those routers are pingable then Windows DHCP clients carry on with their existing lease until it expires, which in most sensibly configured cases should be quite a while. Laptops starting up for the first time after returning from foreign networks (e.g. home) are the main concern. Complexity isn't good for reliability either. I prefer one DHCP with a standyby i.e. a turned off DHCP on another box with the same configuration but with address conflict detection enabled. Yes that requires someone with half-a-clue to start the standby DHCP service, but the org is probably already screaming loudly for "someone" because of other stuff served from the dead DHCP box. How many people in education run DHCP-only boxes?
-
I honestly don't think it's worth doing that, just makes it more complex for very little and very debatable gain (in most common scenarios at least).
-
Get the system to yourself for an hour, switch the server off, switch the workstations on and if any of them hang then it's probably not the server.
-
It's no big deal, but I think a pingable gateway is better. If a Windows box with an unexpired lease starts up and can't find your DHCP server, it will ping the gateway. If it gets a reply it carries on using that lease, if it doesn't get a reply it uses APIPA. If it does go to APIPA it then checks for the DHCP every few mins so everything will recover shortly after you've fixed a DHCP outage, but users are much less likely to notice when your gateway is pingable. [This is useful for renumbering in a mostly DHCP environment] Edit/PS: I remember that Net Logon & DNS thing at startup, but haven't seen it for a while.. is it something that stopped happening with 2K3?
-
If you need to do that then your domain is (slightly) broken and you should fix it instead. There are a zillion ways to break things but: Look at a workstation System event log for w32time errors. If you find them (forget the event IDs, but they come in pairs) go to your PDC Emulator and check the SEL there to see if the time service is happy. I've seen a particular scenario (over and over and over again) where the PDC Emulator didn't supply time to the domain until it was configured with an external time source.
-
Seconded.. and don't forget DHCP or any boxes with static DNS server entries that might be pointing to the original DC.
-
12,000 users throwing around 1GB or more of data doesn't strike me as one of those d-i-y things. I'd want someone with relevant expertise worrying about bandwidth, backups, load balancing & redundancy (e.g. two copies of the data in different data centres).. oh and getting outages fixed in the middle of the night.
-
Intruiging.. would that be because they think they need the training[1] or does the person doing it have to be formally trained by RM so you don't break the support contract? It's not rocket-science. Best training is to just research and do it on a "lab bench" a couple of times (start with the manual methods, so you understand and have a better chance of fixing anything that goes wrong with Acronis|whatever).
-
..the VMWare Converter beta (not that I think the VMs are useful here). This is the successor to P2V & Importer, the "Starter Edition" does plenty and will be free. W2K=CC3=significant investment in existing AD. I don't see why de-CC3ing a domain would be that difficult. Building all your workstations into a new OU structure (with RIS or whatever) and sorting out your GPOs are the painful bits.
-
::reality check:: 1) Well it's not just a DNS xfer. If you want a comparison, it's closer to say moving Exchange to a different domain (which MS don't support). RM add custom properties etc. to AD, some of that stuff tells their apps where to find things and you'd need to know about all the ones pointing to the old box and be capable of modifying them to point elsewhere. 2) RM are probably not prepared to spend N hours at a cost of £X to clear up the mess people are likely to make playing with FSMOs (you may be perfect, but I see a lot of Windows networks that have been messed up by ambitious school techs). Simple economics. As a slight aside, what's the point of a MITM VM in the entirely native Windows scenario? Why not just build your new physical DC and xfer the roles directly?
-
+ I hope, the cost of properly testing everthing works afterwards, dns, dcdiag, netdiag, ntds and so on and so forth. I migrated a W2K FRS "by hand" a few months ago... backed up, set up a new hardware profile on the original in which I disabled all but basic h/w.. imaged it to new hardware with an old Ghost.. put new mass storage driver in place to boot it (via bartPE, but I strongly suspect an NT boot floppy with the right ntbootdd.sys would work).. installed other new h/w drivers, zapped original h/w profile & now redundant drivers... done. Spent a lot more time waiting for the imaging to happen than the rest put together. The only serious stability concern is whether the brand new h/w and drivers are buggy - it's the same concern whether you've migrated or installed a fresh OS. Edit: Forgot to mention, above scenario was to/from a multiprocessor system so I didn't need to worry about different HALs.
-
Uh huh.. and what did **zero admin** do for you around the turn of the century? .MS said every release of NT was utterly fabulous on all counts and I don't recall my relationship with it changing that much in the 13 years since v3.1. What usually happens is they make make feature X easier for the GUI-bound, but then there's some essential (hah!) new feature Y that takes up the time you just saved.
-
Don't know if this ever works.. I've given public folders addresses but have never cared about having them in the GAL. Best guess: Is there anything in the event logs to suggest RUS is broken? Have you tried kicking off RUS manually?
-
VPN showdown: IPSec vs SSL vs client-less SSL
PiqueABoo replied to ITWombat's topic in Wireless Networks
Mmm.. I had some involvement with the early "PPTP is Icky" uh.. campaign back when it was much, much worse. The 'Why not use PPTP?' comments on lack of two-factor authentication and sniffing have been true pretty much forever. However it's only "trivial" to break given a rubbish password.. and unlike ye olde LM Hash thing, you can't crack two or more passwords at the same time. IPSec (a good idea at the start) was murdered by a 10+ year committee design process, but when implemented wisely it's clearly more secure than PPTP. SSL tunnels (with mutual authentication i.e. server & client certs) are my favourite too. -
Ok.... but if you want reliability in that school, then the rule in my experience is: Less is more.
-
All sounds very complicated for a Primary School. I don't understand why DC-1 is between the LAN and the WAN.
-
Mmm.. using ARP to convert IP addresses to NIC vendors via MAC addresses can be useful. I rolled my own CL util for Windows, but IIRC one of the GUI arp spoofers does it (WinArpspoof?) and there are a couple for linux et al. Don't know whether it's got the latter, but if you don't already a nix box this is the kind of scenario where the Slackware-based "BackTrack" live CD should help. Edit: Changed "Auditor" to new name "BackTrack" (http://www.remote-exploit.org).
-
> if its a DC http://www.jms1.net/nt-unlock.shtml I thought that approach had been blocked with 2k3?
