Bruce123
Members-
Posts
432 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Bruce123
-
Raising the functional level of the domain from 2000 to 2003
Bruce123 replied to Bruce123's topic in Windows Server 2000/2003
Forest then Domain.... Here goes.... fingers X-ed!! Bruce. -
Raising the functional level of the domain from 2000 to 2003
Bruce123 replied to Bruce123's topic in Windows Server 2000/2003
With the Full OFSTED inspection now a distant memory, I plan to raise the Functional Level of our Forest then Domain from 2000 to 2003. Hopefully I will have time to do this this afternoon (after doing a full backup of a DC with the FSMO roles). Would there be any problems with do this while people are still logged on? MS don't provide any info on this in the guidance article, or maybe they just assume that no users will logged on or logging on as the process takes place? But as it is half term week, there aren't many users on (just a few staff). We will then progress with the DPM 2010 project. I will provide an update on here as some people have expressed an interest in how it goes. We have 4x NASes for the continuous backup storage and DPM will be installed onto a Dell R200 server dedicated to DPM. We plan to purchase a Quantum auto changer (8 slots) LTO-5 1.5TB Tape drive for the long term (offline) backups (either full backup each day or just Fridays, yet to be decided). I have my doubts about depending on Firestreamer (VTL software) to portable USB as I am concerned what would happen if the company behind Firestreamer goes under. Thanks, Bruce. Leeds, UK. -
Networking between two buildings - issues!
Bruce123 replied to smurfomatic's topic in Wireless Networks
I would forget the wired option and use fibre or WiFi instead. We have a wireless bridge connecting our main site to a small office across the road (12 PCs, 10 VoIP phones, switch, printer and a 802.11g wireless access point for wireless laptops). The wireless link has been in since Summer 2008 and had only gone down twice; once when a thief snuck into the main building and stole a printer (unplugging the wifi bridge in the process) and again following a powercut where one of the bridges didn't come up properly. As long as the wireless link is 5Ghz, rather than 2.4Ghz you should not have many problems with wireless. We even have VoIP over the same link without any problems. The link consists of 2x ProSafe Netgear WNDAP330 802.11g/n setup in bridging mode (with encryption). However, I am very interested in the wireless bridging kit referred to earlier, and the potential speed benefits. Bruce. -
We have loads of these (over 150 anyway). Purchased a batch in 2007, then again in 2008 (to go with our OptiPlex 755s) and I have't seen this problem. However, there has been a problem where the user will report the monitor is dead (won't turn on); when we check we find it to be the case. But if we unplug the power cable and put it back in (or swap the power to the PC to the power to the monitors) it sometimes fixes it. Bruce.
-
OK, I just had a thought. Is it something to do with not having the Vista/2008 Group Policy templates/schemas properly installed? The folder that you're having an issue with is Documents, which is a new "shell folder" introduced with Vista (and 2008 server). I appreciate you said that the Downloads Folder Redirection does work, so maybe I am on the wrong track with this. I have to confess that I've not looked very much at Folder Redirection options specifically for Vista/Windows, is there any option to "apply once" (and not again)? As an aside, we use the same redirection Policy for our (few) Windows 7 PCs as we originally setup for our XP machines and it seem to work (although we do still need to do something about Videos and Downloads at some point). Bruce.
-
Queries... What happens when you check the target for Documents when logged onto Windows 7? Is the path as though there is no redirection set (c:\users\user\documents....). You mention using loopback processing to target different folder redirection policies for XP than Windows 7. I have found that loopback processing can cause some unexpected results. I would disable that setting (it is a computer setting) temporarily for the Windows 7 PC (explicitly "disable" in a GPO above it), then try logging on with an account that you are sure the Win7 folder redirection policy applies. At least you can then eliminate this. The other thought has already been tried (deleting the local profile from the machine). Try re-creating the Win7 folder redir GPO entirely and start again. Also, I have found that folder redirection can take two logons to "take affect". Bruce.
-
Interesting to read the backupexec and speed issues with multiple shares. Problems we've had in the past: Years ago, we had a fileserver keel over twice (and it had to be reinstalled twice as a result) and we couldn't work out why until we determined that it was caused by the large number of shares on the server (there were several 1,000). On Windows, the information about the shares is stored in the HKLM registry hive and Win2K had a 16MB limit on the size of the file containing this local hive (system.dat?), if size creeps above this limit the server will crash and won't boot (with a message about the system.dat file being missing or corrupt). It makes creating, deleting, moving and securing accounts more cumersome. E.g. I have a script which automatically moves homes students' home drives to the server closest to where there have been logging on (we have multiple sites and the script is scheduled to run once per week using logon logs to determine where they have been logging on the most). It has to remotely create a share when it moves the files and remotely remove the share from the source server. The program has to set the share permissions, rather than it happening automatically as with NTFS. What about the history? I assume that the one-share-per-user method dates back to Novell servers (from the 90s) and was retained on MS networks until a never version of Windows introduced the network drive deep mapping feature (\\server\share$\folder). Of course, the server would have needed NTFS to secure files.
-
We have this issue to deal with, and being an FE College many (probably the majority) of learners are on a short courses, say 4 weeks or even 1 day (rather than the full 34 weeks). The student account generation program (which is run once per day) needs to look at the end date of the course and use that when creating the accounts (set them to expire then or soon after) & either the creation program itself or another needs to disable the accounts for any learner who have been "early leavered" (left the course early). Bruce.
-
Raising the functional level of the domain from 2000 to 2003
Bruce123 replied to Bruce123's topic in Windows Server 2000/2003
Thanks for all of the feedback over the last few days; we will certainly take it into consideration. Yes we are still on Exchange 2003, and we have one linux box (SugarCRM). I hadn't considered the need to raise the Forest level as there is just the one domain in the Forest, but I guess this needs doing first? I will update this thread on how we get on with DPM2010, I have seen the same feedback. Either it's brilliant and "just works" or rushhish and "could never get it to work and gave up". I am hoping were's in the former, as we have invested a lot of time and money (on the hardware and software). Re Firestreamer, that was the plan, but we are considering a use a tape drive (once per week), rather than firestreamer, since this is natively supported by DPM2010. I really don't know how people afford the likes of BackExec... Thanks, Bruce. -
Regarding cost, don't you have a MS agreement that allows you to install the latest version of office (at no extra cost)? Or do you have one license per PC? I only ask because I imagine that most schools have the former. In any case I would say upgrading is your best option, because you'll only have to do it eventually anyway. All new PCs/laptops typically come with a trial version of Office 2010 and many parents will have pruchased the £90- version of Office 2007/2010. Some younger kids may have even never seen 2003. There is of course a compatibility pack from MS for Office 2003 which allows it to open .docx files, but I guess you're using that already. Thanks, Bruce.
-
Raising the functional level of the domain from 2000 to 2003
Bruce123 replied to Bruce123's topic in Windows Server 2000/2003
Thanks everyone for the advice, I think just to be careful we'll wait until OFSTED have been, the momet the step out of the door.... I am keen to get DPM 2010 setup. -
Thank you, I tried following the instructions inside this case study. We already have a functioning WiFi network across 3 sites, so I just focused on the Captive Portal section. I managed to setup the Captive Portal linked to AD usernames/passwords. The problems I came up against was; When/how to push the proxy address out to the browser? If I set it manually before the portal then it won't connect to the portal as it is trying to connect to a proxy server, which is cannot see until after authentication. If I leave the proxy info blank (no proxy) I can get authenticated against the portal and gain access to the network, but to access the Internet I then have to enter the proxy info (server : port) into the browser. If I do this I can gain access to the Internet, but only have entering by logon details again (to authenticate myself to the proxy server). If I did push out the proxy info via DHCP WDAP (which is what was planning), then it would presumably not allow access to the portal. Catch 22? Also, in the doc it says that network account must have "allow reversable encryption" ticked, which sounds a less secure than now allowing it. By default none of ours have it ticked. So would I have to run a script to change them all? And modify network accounts generation program. The other problem is setting up ISA 2006 for this, as the moment we have the IP range(s) used by the guest wifi added as a seperate "network" in ISA config and also have a proxy rule which applies to the network, to allow web access, but I am unsure what type of authentication should be used. Basic, Integrated, forms...? The final problem is how to restrict client laptops to connect only to the proxy server address and not allow connections to anything else on the network (presumably this can be done on the routers using a rule)? I have come to the conclusion that setting up a Open Access WiFi network is far from simple because it involves knowledge of so many different network technologies (ADS, VLANs, ISA 2006, Authentication, RADIUS, DHCP, WPAD, IOS... the list goes on and on...) If any has any experince of this I would be pleased to hear from you. Many Thanks, Bruce.
-
I neglected to mention that we are an FE College, and tend to get enrolments throughout the year (maybe around 6,000 in an academic year, but only around 30% of these ever logon). I am not very up on this, but I imagine that many Schools use CC3 or CC4 linked into SIMS?
-
I just wondered how people create student account and how users home drives are structured on your network? We have historically created one share$ per user (for both staff and learners) and have the home drive (H: ) mapped directly to it. Permissions are set on the share level and the NTFS permissions are set to everyone full-control. The folder stucture is D:\shared\users\students\a..z \ useriD " " " " "\staff\a..z\ userID And these are stored on 4 fileservers (as we have 4 geographically dispersed sites connected together with WAN links). The servers are old Xenon based (P3 tech I think) Viglen servers which were purchased on 2003. After RAID they each have about 150Gb of storage on D:. We are looking to replace these servers and move existing staff/learners (and update the staff/student account genertion programs). We see this as a possible opportunity to change the way we stucture the H drive (use NTFS permissions and deep mapping of H drives to higher level share for staff and one for students). Both the student and staff account generation programs were developed "in house" using VB. The student account generation program connects to our MIS system an pulls off a list of enrolments, and generates the accounts from there. My questions is: A) What system do people use (one share per user or deep mapping)? B) What system do they use to autogenerate their student accounts? Any other advice? Thanks, Bruce.
-
Has anyone had any experience of raising the functional level of the domain? I plan to raise the functional level of our domain from 2000 native to 2003. I have done some research and it appears as it only affects the way DCs communicate with each other (and the internal ADS database of the DCs) and not how member servers/clients communicate with the DCs, so it should not cause many or any issues. All the DCs are 2008, but I thought that a smaller step (to 2003) might be preferable. As a precurser, I've checked the event logs on the DCs for any errors, ran a tool to verify replication, deleted a lot of old GPOs and old network accounts, and done a full backup of a DC (to get a snapshot of ADS) The main reason for raising that another project that I am working on (Data Protection Manager 2010) requires the level to be 2003 (or more). We have OFSTED coming in a couple of weeks, so I think we will gave to defer raising the level until after the inspection, just in case. Thanks, Bruce. Leeds, UK.
-
Thank you for your ideas everyone. I've done a little more research myself as well. It appears that the method that I described was first introduced in Windows 2003 and is still available in Windows 2008 and R2, but has one serious limitation in my view. Although it allows you to map a printer on a PC or user basis, it won't allow you to set it as the default. With the prelifera of printers and MS image writers that can build up, I consider being able to set a printer as the default as essential. Using the the Group Policy "Preferences" (which were introduced in 2008) looks like a really powerful and simple solution. It allows you to push out a printer(s) on a per user or per PC basis within a GPO. Not only that, but it also allows you to set one as a default AND even seems to allow you to remove all existing printers (before mapping a printer and making it the default). One downside is that the Group Policy Preferences apply only to Vista/Win7 machines but won't apply to XP machines, but there is an update available which allows them to work in XP, which I have now set WSUS to push out to all PCs. Thank you Tumbleweed for suggesting this solution. Thanks for the other suggestion, but we are really looking at moving away from scripting to map printers. The only method that meets our requirements seems to be the Group Policy Preferences. One potential problem I do see with it is this; In my experience, mapping for a user seems to work better from a technical point of view than creating a printer on the machine itself (e.g. automatic driver download from server, centralised settings picked up on the clients, one centralised print queue), but in a classroom environment you usually want to map on a per PC(s) basis, rather than per user(s). Enabling loopback processing will get around this (thanks again TW ), but when I have enabled this in the past it has sometimes caused unexpected problems (i.e. logon scripts running twice). I think this may have been because we linked logon scripts to the domain and this caused the logon script to filter down down two paths (to both the computer object and the user object) resulting in the User section of the GPO (including the scripts) to apply twice. I guess that the answer to this would be to move any global logon scripts (e.g. any set in the Default Domain Policy) from a GPO linked to the domain, to the College Users OU? Althoigh, I am still unsure how LBP would affect logon scripts that are linked to AD Sites. Other than that niggle, the use of Preferences in Group Policy to deploy printers on a per IT Room OU basis looks like the ideal solution. But why did it take MS so long to come up with good way to deploy printers to computers in a domain? Thanks, Bruce. Leeds / Doncaster.
-
Network Administrator Permissions vs Local Admin
Bruce123 replied to jj99's topic in Windows Server 2000/2003
I would *suspect* a Group Policy setting is to blame (possibly a "local security" policy setting). And since it effects all of your 2008 servers it must be set in a GPO (that presumably is applied to the domain), rather than locally on each 2008 non-DC server. There is a seperate default GPO policy which applies to DCs (Default Domain Controllers Policy). Running a RSOP might assist here, and compare this with running the tool on your 2003 servers. I would also run the local security policy editor to see if there is anything obviously wrong there. I would also delete all your locally stored profiles on these servers for the jpc\administrator account. Thanks, Bruce. -
We've got various startup and logon scripts, and usually if a share that one of the scripts tries to write/read to isn't available (e.g. in the start-up script), we'd get the the familiar 10 minute wait at start-up. But it would usually get stuck on "Running Start-up Scripts...", which helps us to identify the cause of the problem. On updates causing unexpected problems, we applied loads of updates this week. Some of them was to our Windows 2003 server hosting ISA2006. Immediately following the updates being applied, the server stopped proving Internet access (HTTP proxy). But I wasn't too concerned as it still needed a reboot, but it wouldn't work even following two reboots (and it got stuck for 10 minutes on "applying computer settings..." as described, which I know can often be caused by a DNS issue). Searching through the forums, we tracked down the source of the problem; the post suggested removing the DNS address of the external DNS resolver from both Internal and External network connection settings. This resolved it, but this original configuration was as recommended in an trustworthy consultant's article on isaserver.org. Now our ISA server cannot resolve external names directly with external DNS resolver, instead it has to refer to an internal DNS server which then forwards the request to the external DNS resolver via our ISA server. A bit convoluted, but there you go... Thanks, Bruce.
-
I know that this has already been dealt with, but I would hazard a guess that the permissions of one or more of the files/folders associated with the GPO had somehow become corrupted or lost. The files for any GPO are located here by default: \\dc_server\sysvol\domain name\policies\{GUID of GPO}\ Or it could simply be the permissions listed within Group Policy Management for this GPO don't grant you rights to Edit the GPO, as already suggested by Glennda. Thanks, Bruce. Leeds, UK.
-
redirecting Application data to a mapped drive
Bruce123 replied to craigg's topic in Windows Server 2008 R2
Don't you mean the other way around? That the policy is applying *before* the drive is mapped? We use Adobe Reader on WinXP and redirect app data to a subfolder of a network drive, but the network drive in question is the user's home drive, so maps pretty quickly (before the policy applies). Thanks, Bruce. -
I'd love to exclude the Cookies folder from the roaming profile of all users; purely because the sheer number of tiny files that accumulate can have a huge (negative) impact on logon times. We've experimented with Folder Redirection for Cookies, but it doesn't work perfectly, something to do with the .dat file being locked. We just need to determine whether Moodle works properly without Cookies. We're already a excluding several folders; My Documents, Desktop, and various in app data\ e.g. Google. Bruce.
-
Data Protection Manager 2010 features/limitations
Bruce123 replied to Bruce123's topic in Windows Server 2008 R2
Am I right in thinking that DPM2010 has two forms of backup; Continuous to a permanent online device (e.g. NAS) and (Full) Backup to tape drive (but not USB HDD)? And is firestreamer's function to allow you to use the latter backup type but to USB HDD (presumably by tricking DPM 2010 into thinking it's a tape)? This would sound ideal, and I notice that our QNAP 509's have external SATA ports for this. For info: we actually 4 QNAP 509+ and 15 1TB SATA drives. 3 of the NASes will be setup with 3 HDDs and the 4th will be setup with 5 HDDs. All RAID 5. This would give us around 2TB of storage on 3 of them and 4TB on the 4th. Thanks, Bruce. -
How do your users access the Internet?
Bruce123 replied to Bruce123's topic in Internet Related/Filtering/Firewall
John - We also have this problem with Secure Assess, but I think it might be the auto updater part of the software that crashes when assumes it has admin rights to apply any updates, when it doesn't. I doesn't look very good though if/when the candidates see it! Bruce. -
How do your users access the Internet?
Bruce123 replied to Bruce123's topic in Internet Related/Filtering/Firewall
I was going to day "good luck", but then noticed you posted this yesterday, so i hope that it went ok. In the half-baked email apology that we recived from AAT, they referred to an reconfiguration of their server scheduled for the evening of the Friday 16th of December. But in the end our Exams dept. had to reschedule all of our remaining AAT exams to January, hopefully they'll go smoothly this time (one group of 14 who paid £100s each for the course is having to re-sit for a third time, some having taken time of work to take the exam) We had considered that not hosting our own server was the best option for this exam, as there is less for us to look after/maintain. However, this does depend on their AAT/Secure Assess server being high availability and reliable (and our Internet connection as well). We have 4 other online testing systems going at the moment; for 2 of them we have internal servers for, and the other 2 (including AAT) just connect externally. I think that online exams (whether hosted internally or externally) are the way forward, the providers just need to make sure their systems are tested and work reliably at all times. Thanks, Bruce. Leeds, UK.
