Bruce123
Members-
Posts
432 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Bruce123
-
Well DPM won't backup VMWare hosted VMs. We thought it worthwhile paying for full Enterprise license for all our servers (all Windows apart from one Linux). Costs from memory: Standard ~£20 per year Enterprise ~£35 per year I am not sure but I think this may have been the cost of SCCM for each server (DPM included with it) One Enterprise license will allow you to backup all VMs hosted by the Hyper-V Server. Compare this to something like £1,200 for Hyper-V BackupExec agent (one off payment). But by backing up at the host level you don't get continuous backups (througout the day), for that you will need to backup at the Guest level (agent installed on the VM), but I think you would with BackupExec. I couldn't advise on whether it's worth moving from WMWare to Hyper-V (there are obviously more things to consider than cost). But it very cheap. If you buy Data Centre 2008 R2 (includes Hyper-V) then it automatically includes licensing for all your hosted Windows Server VMs, so this may actually work out cheaper overall than using the "free" VMWare ESXi. Thanks, Bruce.
-
I wasn't a fan of Windows 2008 and later Windows 2008 R2 backup. Not initially anyway, and I wouldn't have thought I would hear myself say this but now I really like WSB that comes with Windows 2008 R2. I know that having to backup a entire volume is a pain. But the following features make up for it..... The way it uses incremental backups and intelligently integrates them into a full backup. Backing up to UNC now possible (was an issue in 2008 WSB as I recall). Backup to local USB attached HDD Backup to standard VHD file These features make it quite powerful. Leave a USB HDD attached all week - let it do a full backup over the weekend then incrementals each evening. I have found it to be rock solid, fast and reliable. If you are concerned about having your backup device media "online" (and therefore suspectable to worms/hackers) then you can swap the drive once a week and use your normal Grandfather/Father/Son rotation for the USB drives. Backing up to .VHD means you can very easily mount the .VHD as a new drive using Storage Manager in 2008R2 or on your own Windows 7 PC (very good in simple cases of file deletion or in a real disaster recovery scenario - no need to get your backup tape and find a suitable backup drive and software). If you backup to a shared USB drive (located on another server at another site), then you can use it to do "continuous" offsite backups. Thanks, Bruce.
-
Afternoon all, Just query about how other people handle partitions when commissioning their new virtual servers. On most of our physical servers we have: C: RAID 1 (OS and applications) D: RAID 5 (Data) The logical drives map closely to the physical storage configuration and users get the performance benefit of having OS I/O and Data I/O on seperate arrays. However, the performance argument for retaining this convention on virtual servers is a weak (as they are stored on the same storage unit and won't see much, if any, peformance benefit). We have kept the convetion of C: and D: for our new virtual servers, mainly as a logical partition of OS from Data. But I do suspect that there are other specific technical reasons for wanting to maintain the seperation, but I can't actually think what they would be. I know, for example, that for a Bare Metal Recovery backup, WSBACKUP has to backup all folders on the System volume (and any volume containing system data), so keeping data away from the OS should reduce the amount of data that needs to be backed up. Having said that, what would be the point in doing a BMR backup within a VM when you can backup a VM at the host level, and therefore restore the entire VM without needing to use BMR. It got me wondering what other people are doing when creating partitions for their new virtual servers. Thanks, Bruce.
-
Afternoon Edugeeks, We have a Dell server PowerEdge 2950 purchased over 3 years ago, and one of the HDD drives has just failed in the RAID 5 array. It is a 300GB SAS 10K RPM drive. I spoke to Dell and they provided two options: A) Refurbished 300GB (£235 inc VAT) B) New 600GB 15K RPM (£358 inc VAT) (he said that they no longer sell the 300GB model of drive but the 600GB would work - the extra space would just just not be used) I did a quick search online and found new 300GB SAS 10K drive for a lot less, my question is should a non-Dell supplied drive (e.g. Seagate) work OK? (I would not go for the refurbished option so that would just leave the new drive at £358). Any advice appreciated. Thanks, Bruce.
-
We're expecting it to backup very fast to tape as we have D2D2T configuration.... Just need to get it working reliably on D2D first...
-
I have used the delprof.exe (presumably an older version) command in the shutdown script (with the switch to delete cached profiles only) on Windows XP PCs (placed it into the Shutdown Scripts part of a Group Policy object) and it worked fine, it cleared off loads of old cached copies of roaming profiles. Shutdown scripts are, I believe, run as the local System credential. That might not be much help to you but whatever account you use it needs to have permission to remove subfolders from the local profile store (e.g. c:\documents and settings\user1). I don't know whether you can add the domain account to be a member of the local group on the target computer? Off the top of my head, but isn't there a Backup Operator group? Bruce. Leeds, UK.
-
IF all you want is to backup shares then you're OK with Standard. Standard: Basically, backup of files/shares only, I think. With Enterprise you also get: Bare Metal Recovery/System State Exchange 2003--- Sharepoint SQL Server 2000--- Hyper V machines (i.e. backing them up at the host level) I think for most Educational users you're better off with the Enterprise (given the low cost). As to whether you will actually get DPM 2010 working reliably/properly... That's another matter entirely.
-
DPM 2010 - netgear readyNAS 2100 dynamic disk
Bruce123 replied to _techie_'s topic in Windows Server 2008 R2
Couple of things When you setup the RAID/iSCSI target on the NAS did it ask about formatting the disk with a Windows file system, as this should be left to DPM. The same goes on the DPM server, after setting up the iSCSI initiator you should need to use the Storage Manager to make the disk online only, if you did anything else such as initialise, partition or format it, you have done too much. Basically DPM expects a raw disk. The only thing I can think of is that you may have done too much prep to the disk, before letting DPM loose on it. Bruce. -
We are planning to implement DPM 2010 before September, and included in the project plan is to include longer term storage onto either tape or portable HDD. Main main concern about just D2NAS is if a hacker or worm hits your network, having the NAS offsite won't help. All it would take is for a worm to gain admin rights on your network, and it can potentially wipe all the HDDs on your servers, including the iSCSI devices linked to the DPM. There was a documented case where company backed up to an online NAS with no off-line backups, and this happened to them; the result? The company went under. I think it was an online-gaming company. I was at presentation by a well known and highly regarded (and rightly so) backup company; VEEAM (complete DR for VMWare hosted servers). I asked their reps the same question and it was as if it hadn't even ocurred to them. Their first response was that you can use RAID in the NAS (which wouldn't help) and then said you could always replicate the NAS to another NAS (again, wouldn't help), their third response was they you could replicate it into the cloud (might help if the provider does archive backups). I am sure they do have a solution, but this issue just seems to be off the radar generally. I was looking at either FireStreamer by a company called Cristalink.com (which allows DPM to archive to USB HDD) or an LTO5 tape drive. My main concern with Cristalink/FireStreamer is that it appears to be a company based around one product, which is mainly aimed at DPM 2010. Too many eggs on once basket So in the end we opted for a Quantum LTO5 Superloader 3 LTO5 with 8 slots (expandable to 16). With a max storage with compression of 48TB (3TB per tape). Placed the order last week It is worth nothing that during our research we discovered HP and other popular venders of backup hardware use the same drive LTO5 mechanism manufatured by Tandberg, so it probably isn't worth paying the premimum for an HP branded backup drive. We also ordered an SAS 6Gbit/s card and cable to link to the server to the tape drive. We plan to have the server, NASes and tape drive all together offsite, connected to the rest of the network with 100Mbit link. We concluded that you really can't base your tape drive/server in your main datacentre/server room as in the event of a fire all your DR infrastructure would be destroyed (even if the tapes are safe offsite it could take over 24 hours to get a new server/backup drive in place). Will try to keep people updated on how this project goes. Bruce. Leeds, UK.
-
You probably need to change the virtual web folders (if that's what they're called) so from the user's perspective they use https://xxx.xxx.xx/OWA for OWA and https://xxx.xxx.xx/Admin for Admin (i.e. the same domain name/IP). Look at the OWA publishing rule on ISA (assuming you use that) and IIS on the OWA server.
-
With DPM2010, can you not restore at the file level when backing up the Hyper-V host (and the VHDs)?
-
Evening all, We are hoping to move away from the older structure which we have used for many years of one share per user. e.g. H: -> \\server\studentid$ (located d:\shared\users\students\\) H: -> \\server\staffid$ (located d:\shared\users\staff\\) Where the security is set on the share level and NTFS permissions are everyone - full control. The user and domain admins are granted access at the share level. These are generated each day by an in-house developed system,which queries the MIS system for new enrolments. To one share for staff and one share for students as follows: \\server\student$\%username% \\server\staff$\%username% And where the permissions are set at NTFS level (presumably using Owner/Creator to set the user permissions automatically). I just wondered how many people are still using one share per user and how many are using the latter model? And also, what structure you are using? It's going to be quite a big job writing a script to move all accounts from the old setup to the proposed one. After that we plan to use a program like Dovestone ,which will automatically create them in this format. We have up to 7,000 accounts created in the academic year and these will be spread across 4 servers at the 4 College sites. I have a system which automatically moves home folders to the server at the site where they are most loging on at. Regards, Bruce. Leeds, UK.
-
We came to renew our annual license for all our MS Server/Desktop software and was surprised to learn that the cost had shot up by 60% over last year's. Apparently, this is due to a change to the requirements of the agreement that we were we have been subscribed to. In order to meet the new requirements there needs to be at least 1,000 staff employed at our FE College (which we don't have so the new quote is based on a different volume licnese agreement, which turns out to be a lot more expensive (for us anyway). Out of interest, has anyone else experinced this? Regards, Bruce. Leeds, UK.
-
We have planning to implement Data Protection Manager 2010 over the Summer. We have a dedicated server (Dell R200) and 4 Qnap NAS boxes (iSCSI). We are looking at backuping up around 28 servers (some/majority of these are virtual) My question is, what are the advantages/disadantages with installing the agent onto the Hyper-V host, over installing the agent onto all of the VMs and treating them as seperate machines? I don't want to do both as it's a waste of backup storage. Also, for long term stroage I am undecided between a Quantum 8 LTO5 auto tape changer connected with a 6Gbit SAS cable, or use Firestreamer to backup to locally attached USB HDDs. I really don't like tape as there are so many disadvantages, on the other hand I have concerns about using Firestreamer. The company seems to depend on this as their main product and the main use of this product seems to be for DPM2010. So there seems to be significant risk that the company could go under, leaving customers in the lurch, particularily in relation to archived backups and needing to restore data from them. All it would take is for MS to add backup to USB into their next version and Cristalink may go under. Am am particularily intestested to hear from anyone with any experience of implementing DPM 2010. Or did anyone get consultants into implement it (e.g. due to tight timescales/lack of expertise), or who have worked with them to implement it? For info: All the servers will be 2003/2008 and 2008 R2. We also have Exchange/ISA 2006 and several instances of SQL Server dating back to 2005 version, we no longer have Sharepoint to backup. Not that relevant but we have 4 sites connected at 100Mbit. Regards, Bruce. Leeds, UK.
-
By default, the autorecover files for MS Office apps are automatically saved into the <%USERPROFILE%>\Application Data\Microsoft\" (then Office or Word, I can't recall exactly). So if a user's computer crashes, the auto recover files get left in there, but since the location is shared with the other users, when the other users start the Office app they will get the option to recover these files, even though it wasn't there's to recover. Other than disabling autorecover feature, I don't think there is a lot you can do about it... Bruce.
-
Each user will need to have their own seperate application data redirected location. Re-directing the Desktop/Startmenu to a shared location is OK (but should be read-only to all the users)... redirecting application data to one shared location is a definite no no... the folder is used to store all sorts of personal information/app customisation relating to the particular user. To resolve this you could use GP to redirect Application data for this group of users to a new folder structure e.g. \\server\redirected$\%username%\application data. But it's a bit odd that using a mandatory profile results in slow logon times. With a brand new profile that has been converted to mandatory, the amount of data in the application data folder (and indead the whole profile) should be minimal (less than 2MB). With roaming profiles, reducing the size and number of files that build up in the application data folder(s) can really improve logon times (lots of tiny files is just as bad as several large files), so it can be worth investigating where all the files are and whether they are necessary. There is a GP setting that allows you to excluded certain folders from the roaming profile (deletes them from the server copy at logoff). We have excluded several key folders (which tend to hold a lot of unnecessary data) from all users profiles. From memory, these include "app data\GoogleEarth" and "app data\Sun" and a couple of others. On the broader subject of redirecting the application data folder, we have been trialing this for a number of years now (for some users). We found that it works well overall, but have come across a minority of problems and some applications don't work well with it (e.g. versions of Office prior to 2007 and I recently discovered an online testing system that didn't like it). Now that our network peformance issues have largely been resolved, we don't have any need for it, so we are planning to move anyone who still has their application data folder redirected, back to their roaming profiles. Regards, Bruce. Leeds, UK.
-
What do people have in-place in the event of the air conditioning unit in the server room failing? Our server room uses 3.2KW (so produces that amount of heat), so it won't take long for the temperature to increase very quickly resulting in melting of servers. We already have a rack mounted environmental monitoring unit, but it was never setup to trigger on any event, just provide a webbased interface to the sensor readings. The other option is to buy is a network/environmental monitoring card with a UPS we are purchasing. But how easy would it be to set it up so that the servers shutdown gracefully, should the temperature rise above a certain level? I have been looking at the Powerchute software, but I could not see any mention of temperature triggered shutdown. Our plan would be to keep the comms kit going as they only produce 1KW of heat. Regards, Bruce.
-
We are devising our UPS strategy and our plan is to split our UPSes to those protecting servers and those protecting our comms equipment. Those protecting the servers will be configuired to stay on for a while (say 50% remaining) and then start shutting down the servers if the power does not come back up by then. For the comms we plan for the UPSes to keep going for as long as they can and let themselves power off before the battery fully depletes. The idea for splitting them is for the telephones to keep working for as long as they can. Comms: Routers, Core Switches, the PBXes, ISDNs and any WAN/NTE devices. I don't really want to have the added complexity of having servers managing the UPSes for the comms (no serial cable to a server). But my concern is whether or not the UPSes will damaged by letting them run down, or whether they will automatically cut off before the battery runs flat, thus protecting the battery from damage. The UPSes protecting the comms equipment are all old APC SmartUPS 1400 (Model: SU1400 NET) with serial but no RJ45. Many Thanks, Bruce. Leeds, UK.
-
We are looking at purchasing some UPSes and saw APCs 2200VA at around that price, which seem more at the budget end of APCs range and I wondered if we would miss something really essential by going with these, rather than highest priced ones from APC. I am particularily intestered in how we could shutdown servers automatically after a certain amout of charge is left following a power cut? If they don't have a network card then presumably there is one cable which goes from the unit to a server and then does this server run software which can then be used to shutdown the other servers? Is this software free? And is it flexible enough to say "Initiate shutdown when UPS has 10 mins of charge left"? Also, I assume that a unmanaged UPS (i.e. with no software or cable) won't let itself fully dischage and damage the Lead Acid battery? UPS seems to be a whole field of it's own (which I have have neve really tocuhed before)! We discovered load of old (dud) APC Smart-UPS 1400VA units (which are probably around 10 years old) which we determined just needed new batteries. So we plan purchase new batteries for these and perhaps use them for comms side, rather than servers (mainly because I am unsure of the auto shutdown), they have a serial connection, but not USB or Cat5. Totally agree with your about floor standing verses rack mount. Any advice/help much appreciated. Bruce. Many Thanks, Bruce.
-
The consensus seems to be that Disc to Disc to Cloud (D2D2C) is the ideal solution. I would say second to this is Disc to Disc to USB drive. D2D2T is good too, but backup tapes aren't ideal these days. Thanks, Bruce.
-
We map home drives using the path in the account and redirect My Documents to H:\system\my documents (the subfolder is irrelevant), and the drive always maps quickly enough. How did you direct My Documents to network drive in GPE? When I last tried it it wouldn't let me specify a network drive, only UNC (but that was Windows 2000 GPM so I don't know if this has changed with 2003/2008), So I had to create a customer ADM template for this purpose. Regarding the Shell folders in the registry; there are two keys which relate to folder redirection; UserShellFolders and ShellFolders. I think it's the latter that is read once when you first logon and contains env variables; these are then expanded and written values in ShellFolder. In fact with true polices there is another key under "policies". I am not sure that changing the registry in Default User on each machine would help but even if it does, you'd need to give all your users a new profile? If this is the route you go down and you use roaming profiles, you don't need to change default user on each PC, just save a a copy to a folder called "Default User" to the netlogon share on your DCs and new users will pick it up from there (you may need to tweak it slightly to flag it as a roaming profile first). The ADM template I use actually changes the UserShellFolder directly (unlike a policy), so this could be why it works for us. I can send you a copy if you want. In fact with this, it may not matter if H drive is mapped and it still redirects, only allowing users to use My Documents when H drive becomes available. Thanks, Bruce.
-
Deploy printer using group policy - won't work
Bruce123 replied to KevWCFE's topic in Windows Server 2008
I know this has been expressed already, but I would personally forget about using pushprinterconnections.exe and use the Group Policy Preferences section in 2008/R2 to deploy your printers, instead. This is probably best done on using User preferences but targetted to computers (and linked to a OU contain computers). You do need Client Side Extensions on your XP machines for this to work (approval in WSUS). It is (by a long way IMHO) Microsoft's most elegant method yet for printer deployment and also gives you a lot of control/flexibilty of what printers are mapped/unmapped and setting defaults etc. Thanks, Bruce. -
We are also behind schedule. Apparently, some controllers (but not WFS709TP) will also identify attempts to access a website via a proxy addresses and redirect you to it's own portal (and presumably allow you to connect its web portal via it's own built-in proxy). But other problems exist; WPAD via DHCP is apparrently not supported by Chrome and Firefox (due to legitimate security concerns). But DNS is OK, maybe the answer is to do it via DNS and place the DNS being behind the portal, so your webbrowser only sees it once you're authenticated. If you're worried about security (i.e. wireless clients seeing your internal DNS records) you could setup a dedicated DNS server which is just used by these wireless clients, and the IP of this DNS server could be handed to it via DHCP for the VLAN used by these devices. The DNS server would just provide the WPAD info and be set with forwarders for external address resolution. Another option entirely is to forget about trying to push out the proxy address and just give the wireless clients full layer 3 (NAT) routing out to the Internet. But, would your web filtering continue to work via layer 3? I've not tried this with our ISA/Third party plugin and how is ISA's user authentication handled at this level? Finally, forget about using Netgear's own Captive Portal and use something else. More questions than solutions. Bruce.
-
Raising the functional level of the domain from 2000 to 2003
Bruce123 replied to Bruce123's topic in Windows Server 2000/2003
That was painless!
