Jump to content

Bruce123

Members
  • Posts

    432
  • Joined

  • Last visited

Everything posted by Bruce123

  1. The error looks like a folder/file/mounted volume permission issue. Do you do D2D as well (iSCSI or local?). But if the restore is purely from tape I'd have thought that all it would need to do is read from the DPMDB and read the data from the tape and write it to the destination folder. Mind you some of the ways DPM works is peculiar (and the help isn't much use half the time). It does hi light the need to regularly backup the DB, as without it all D2D backups are worthless and any restore from tape will require a full catalogue, which could take hours. I scheduled a backup of the DB once a day to a USB drive attached to a server at a remote site. There is a simple command to backup the DPMDB. I would test other restores if I were you to try to determine if the issue relates to a particular tape/protected server/type of source (files/sql etc.) Also, if not done so already I would run/schedlue a full consistency check on all protected servers. As, with way DPM works an error could have crept into one of the snapshots and this could have been incorporated into all subsequent restore points (on disk and then on tape). All protected sources might look green but the only time you'll find out there is a problem is when you try to restore data. There are a couple of horror stories online about it (relating to SQL server backups not restoring on DPM2010). I understand that it is easier to schedule forced full consistency checks on 2012. I hope you work out where the problem lies and can resolve it. Thanks, Bruce.
  2. I just purchased the Moto G, it's an OK phone, if a little boring...
  3. Has anyone seen the new Motorola Moto G smartphone? It's getting fantastic reviews and is available for only £130 SIM free (for the 8GB version). I'm tempted to get one myself just as a spare (not sure I can really justify that though.. Thanks, Bruce.
  4. Amazon, Facebook, Google give Cisco's switches the COLD shoulder Essentially Amazon and a number of other companies have formed an alliance to make their an open networking operating system for switches and they are buying hardware from cheap manufacturers to build their own switches and routers. It's difficult to know how the giants of the switch/router world (e.g. Cisco/Juniper/Brocade) can respond to this assault. It's their own fault really for charging such a high mark-up for their devices and for so long. And while the rest of the world is moving more towards open software (and at least in the server market, to lower profit margins). Thanks, Bruce.
  5. Hi, I have been asked to look into using SCCM as a tool for monitoring the health and status of the servers. I have looked into it briefly a couple of years ago but have never actually implemented, so it's not something I know a lot about. The network is quite large, with around 200 servers and 5,500 desktops PCs (and a growing number of BYOD wireless devices). We'll be getting in a partner company to do the lower level monitoring of the network (i.e. up to the Transport layer), for things like, bottlenecks, Routing, QoS, STP issues. But we need something to report on the higher layers (to enable us to be more proactive about any issues that arise). For example, I would want it to report on issues like; servers low on HDD space, High Disk IO, High Network IO, Event logs categorized as Error/something else, DHCP servers running low on available IPs, DNS issues, or if a DC is not functioning correctly. And summarise issues is a readable format and have method to alert us of more serious issues. And also, to be able to pull reports from it e.g. In relation to bringing together of event logs "which DC was used to authenticate x user on y date"? We already have some basic monitoring software that just tells us if a server it up or down. So I suppose I am asking two questions really: 1) What would be the benefits to us (and our customers) of implementing SCCM in an Educational environment (not just for server monitoring)? It seems that for a lot of what it offers there are already solutions (e.g. WSUS, WDS). Is it straightforward to implement? 2) Can SCCM be used to monitor the servers (as above)? If not, can anyone recommend any software? All our servers are all Windows Servers (up to 2012) and we use VMware 5.x (with VSphere) for virtualisation. The hardware from a variety of manufactures but tends to be IBM/HP/Netapp. Any advise appreciated. Many Thanks, Bruce.
  6. Hopefully they're just trying it on. I can't see it being any where near that when it gets officially announced in a few hours.... I notice the LG2 has speaker grills on the bottom, like the iPhone 5, so I'm expecting good sound output on the Nexus 5. I tried out the LG2 and I really like it. It has two LED indicators on the front. It's a shame the buttons are on the side on the Nexus 5. I like the buttons on the back, a rare bit of innovation not seen these days. Thanks Bruce. Sent from my Nexus S
  7. Another reason to wait a 'few' more days.... Halloween?
  8. Let's hope they manufacture enough of them to satisfy (the initial) demand this time. I agree that the white looks good. A couple of things that concern me, it has LCD rather than AMOLED, how visible is this in sunlight? And does it have a missed call/battery charged indicator? (cannot use the main screen as the LCD back-light would drain the battery) How good is the speaker output (for music etc.) as I can't see a sound grill on the back? I am still disappointed that the Motorola Moto X won't be released in the UK, apparently they have something better in mind for the UK, but when...
  9. That was my thoughts exactly, and running low disc IO servers in snapshot mode makes more sense (rather than on high IO servers) as the snapshot file won't get too big. Bruce.
  10. We have a member of staff who keepings getting the high contrast mode appearing on his roaming profile, for no apparent reason. I have spent ages trying to resolve this and I've come to an almost dead end. So I thought I would throw it out to everyone on these forums in the hope that someone may have seen this issue before or have an idea of the cause. The PCs were WDS-imaged to Win7 in the Summer. The member of staff had a stroke last year and was then made redundant and he returned in a new role this September. Rather than create a new account, we re-enabled his old network account. However, he can't be picking up cached copies of profiles from PCs as they were (nearly) all imaged before he started back. He logs onto different PCs and also connects from home into our 2008 R2 RDP farm. It looks like that the High Contract mode starts when he logs on at work after connecting to the RDP farm the previous day from his own laptop from home (although it's not consistent). I have tried deleting his roaming profile from the server (and simultaneously any cached copy from the PC he uses and the 2 servers in the RDP farm). But it shortly reappears, so it's not a long term fix. The last thing I tried was to disable his account and create a new account with a different username (thinking that he may somehow be picking up a cached copy from somewhere or that there is something setup on the network previously that pushes out the High Contract setting). It was a bit of a hassle and his mailbox took around 48 hours to appear as Disconnected, to reconnect it to the new account, in the meantime he was without email. This looks like it had resolved it, but then after a few days the problem returned. The only thing I can think of is that the laptop is somehow telling the RDP session to go into high contract mode. Is this possible? Like Ease of Access redirection? He did mention that he used the Dolphin pen for a while (after he had the stroke), but doesn't use it anymore and said he has never used it on the laptop. I have asked the member of staff to bring in the laptop today so I am going to take a look. The High Contract mode can be enabled in Win 7 by pressing LEFT-SHIFT & LEFT ALT & PRNT-SCREEN. But he says that he isn't pressing this. And even if he is accidently, the default is for a pop-up box to ask for confirmation. Due to the stroke the member of staff finds the High Contract mode very difficult and simply cannot use the display like that (causes a headache etc.) so I am very keen to get this one sorted. Any ideas appreciated. Many Thanks, Bruce.
  11. The obvious/simple solution is often the right one... But I image they'd prefer the carrot to the stick.. less questions asked. IT Bod with the Ferrari in the car park might raise a few eyebrows though.
  12. I think GCHQ thinks the DPA doesn't apply to them (or it actually doesn't apply to them - I know there is an exception in the Act for prevention and detection of crime). Similar for NSA and the USA DPA act I imagine.
  13. I don't know about 2012 or dedup, but have plenty of experience of 2010. If I were you I would schedule a full consistency check on all your protected sources as soon as possible, as it sounds like one or more of your replicas are corrupt.
  14. Recent leaks from the NSA talk about them having made a "breakthrough in 2010", making "vast amounts of data newly exploitable". Journalists assume it relates to cracking SSL (e.g. HTTPS), but does anyone care to speculate on exactly what that the breakthrough was? The online press seem reluctant to speculate. My guess is that they have got hold of one or more of the 'master' secret key(s) used by the main root certification authorities (i.e. a secret key used to sign the certs for the intermediary authorities who then provide/sign certs for companies like Google etc.). My browser has around 25 of these root certificates installed (from the likes of VeriSign etc.) This will enable them to produce fake certificates, but this by itself won't let them eavesdrop on traffic 'passively'. They would have to initiate an 'active' Man in the Middle Attack for each SSL session, whereby the session is decrypted-> recorded/analysed -> re-encrypted using a fake certificate, on-the-fly. Which I guess is feasible, but perhaps a little processor intensive for millions of sessions (e.g. when passing through a major Internet hub). Or have they cracked SSL in a more fundamental way? If they have not then re-issuing of the root certs would render this breakthrough obsolete. If they did obtain the master secret keys from the root CAs (rather than breaking SSL), how did they do this? By hacking into their systems? By brute force on the public keys available in the root certs (would take too long surely)? Or have they discovered an efficient way to factorise primes (as in fundamentally breaking RSA/SSL)? Some kind of leap forward in quantum computing? No harm in speculating.. Thanks, Bruce.
  15. Interesting... It was caused by Duplicate SIDs rather than duplicate GUIDs. It could have been caused by be the way the Windows image was sys-prep'ed before uploading to the WDS server. There is a tick box on sys-prep window "Don't re-generate security identifiers". I wonder if this ticked by accident? Anyway, good luck with it, you're half way there now you have identified the cause. Thanks, Bruce.
  16. Just to add one last thing to this thread... (Columbo....) I have seen this happen before, and it's one of the strangest things, and I never did manage to track it down. I even wondered if a 'hacker' had managed gain the rights to delete computer objects and was randomly deleting the odd object. Though in our cases there number of occurrences was few and far between..
  17. I could be barking up the wrong tree with the duplicate GUIDs, it's just an idea... Also, the Security Event log on DC2 may give more details about the deletion of the computer object event (but only if the appropriate local security policy setting is enabled). Thanks, Bruce.
  18. I did wonder about the affect of bringing the old PCs back onto the network, but as you simply moved the HDD from the broken PC into the newly commissioned old hardware, I would have expected the GUID of the computers to remain the same.... Computer GUIDs are supposed to be randomly generated, but I noticed that when deploying WinXP PCs it was simply picking up the MAC address of the NIC and using that as the GUID (prefixing it with zeros). So one way you can end up with computer objects with duplicate GUIDs is if they were joined to the network with the same network card (or cards with the same MAC address). One issue to watch out for when removing and re-joining PCs from the domain, if there are objects with duplicate GUIDs then I am guessing that when you remove the PC from the domain, all of the computers objects with the same GUID would be deleted too.. Thanks, Bruce.
  19. A couple of ideas: There is an ADS Clean-up wizard somewhere in Windows that when run will delete any computer objects that have not been used for 90 days. Maybe there is a way to automate this process and this is what is causing it? Under the bonnet, all computer objects (like user objects) have a password and this is automatically changed for each PC by the DC every 30 days (but only when the PC is turned on). If any computer is left turned off for extended periods, the computer object never gets modified and the wizard I mentioned would use the modified date to determine that the computer has not been used and therefore probably doesn't exist. This of course would only be an issue if the computer has not been be used for ages. Another avenue of investigation would be examine the modified date of the objects in the Deleted Objects Container(*), it might not be particularly useful in the above scenario but it might give you the precise date/time when the objects were deleted. Another avenue would be to enable auditing of modifying of computer objects events on the DCs (in local security policy settings), so you can get some info on precisely when they were deleted and by what user/security principle, and maybe a reason. One final avenue would be to check the GUID of the your computer objects to ensure they all have unique GUID numbers, I imagine that having computer objects with duplicate GUIDs could cause all sorts of weird behaviour. (*) When was the Deleted Objects container introduced into ADS, I have not seen it before? I am aware of the Object Recycle bin, but I was under impressions this was for domains running at 2008 R2 Functional Level only. Thanks, Bruce.
  20. We have had a number of Netgear switches/devices including their wireless solution (which worked very well). All OK, the only problem we had was with the Netgear GS724T switch. Experienced connectivity issues including when trying to configured it via the web interface (it kept dropping the connection). I am not certain what the cause was, I am fairly sure it wasn't caused by an external issue, but in the end we just swapped it out. If you can go afford it go for HP/Cisco, otherwise Netgear are OK. I hope that this helps. Regards, Bruce.
  21. I noticed that there is also RAID controller card drivers available, would these need to be installed as well? Many Thanks, Bruce.
  22. Thanks for your advise everyone. I did a search on HP's website and found the software/updates for this server: here And listed at the bottom is: RECOMMENDED * HP ESXi Offline Bundle for VMware ESXi 5.x (American, International) Is this the software I need to allow vSphere to see the failed HDD events on the ESX hosts? Is it simply a matter of physically shutting down the host server and booting into some kind of ESX admin mode and installing this software from a memory stick? Thanks, Bruce.
  23. Hi sorry for the delay, I was on annual leave yesterday. The hardware is ML350 G5 (~5 years old) Running ESX 5.0 Thanks. Bruce.
  24. Is this correct? Local GPO policies don't apply on W7 PCs when joined to a domain? Are you referring to computer or user settings or both? What about the old order of policy application rule? LSDO; Local, Site, Domain, OU. I have never actually tried modifying the local GPO on Windows 7. Bruce.
  25. I would concur with FN-GB. The most likely cause is a computer (needn't even be a server) that has been infected (somehow) and the account that is logged on has domain admin rights, Conficker is picking up the rights of the account and is using the those rights to spread unhindered to all c$ and admin$ shares it finds on the network. If not dealt with it could infect all PCs and servers on your network causing a cascade affect.. any servers that are currently left logged in with a domain admin account, being used to infect PCs and servers in the same way. In reality, AV software is limited in what can do in defense as the the worm will have had to have placed itself on to the server (via an admin share) before the active scanning picks it up and tries to remove it. The MS update doesn't prevent the worm spreading in this way, it just patches the RPC buffer overrun bug, which is one of the other main method that it uses to spread. One useful tip is running the Malicious Software Removal tool in your shutdown script using the quickscan option. It has a specific understanding of the worm and how to remove it. One other thing I would check is whether the AV is picking up a actual infection or an infected file. Sent using my Google Nexus S
×
×
  • Create New...