2009-07-12

Forward different port to internal service on SonicalWall firewall

Scenario:
You want to use other ports other than 3389 for remote desktop.
The plan is to use wan ip xx.xx.xxx.xxx:4000-xxxx for the other remote desktop users.

Solution one:
You could just forward 4000-xxxx to the windows servers and change the listening port for RDP: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TerminalServer\WinStations\RDP-Tcp
Edit PortNumber, change it to decimal and specify the new port number.
Reboot the server

Solution two:
1. Create an Address Object allowing a WAN IP to access the Firewall.
a. Network > Address Object > Click Add button.
b. Name: WAN IP Access
c:Zone Assignment: Host
d. Type : Wan
e. IP Address: Whatever your External IP Address is.
f. Click OK
What you’ve done here is create a way for you to access this firewall from outside the network.

2. Next, create your custom port.
a. Go to Firewall > Services, put a bullet for Custom Services this will make it easier to see.
b. Scroll down to the Services area and click on the Add button.
c. From here is where you:
i. Name the port that you are opening and assign what port to be open.
ii. Protocol: for Remote Desktop is TCP (6)
iii. Port Range: For me I wanted my Remote Desktop users to start Using 9000. So the port Range is 9000-9000.
iv. And Sub Type I left alone. Then click OK .

3. To keep things organized we added Services to a Services Group
a. Click Add Group ex. Remote Desktop; for us since we had more than Remote Desktop users we called it External Ports.
b. Then select your newly created Service from the left column and put it on the right by highlighting and then using the arrow button.
c. Then click OK

4. Next we went to Network > Address Object; place a bullet in Custom Address Objects.
a. Click the Add Button
b. Name: Username PC
c. Zone Assignment: LAN
d. Type: Host
e. IP Address: Enter local IP address of computer or machine ex. 192.168.1.100
f. Click OK

5. Now, below Address Objects select NAT Policies ; place a bullet in Custom Policies.
This is what binds the Outside IP address to the local IP address using your custom port.
a. Original Source: Any (any request from the outside coming to the firewall)
b. Translated: Original (keep the request the same, say if you want to enter through port 3389)
c. Original Destination: Public IP Address (WAN IP/ External IP)
d. Translates: Username PC (Custom Address Objects)
e. Original Service: created Port 9000
f. Translated: Remotes Desktop
g. Interface Inbound: Any
h. Interface Outbound: Any
i. Click ok.

Reference reading:
http://www.sonicwall.com/downloads/C...Forwarding.pdf , Standard is pages 2 to the top of 3.
Above steps enhanced which started on page 3-7.

2009-07-09

Remote Server Administration Tools for Vista

Remote Server Administration Tools (RSAT) for Windows Vista allows administrators to use their Vista machines to manage their Windows 2000, Windows Server 2003, and Windows Server 2008 infrastructure.

1. Downloads:
Microsoft Remote Server Administration Tools for Windows Vista for x86-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyID=9ff6e897-23ce-4a36-b7fc-d52065de9960&DisplayLang=en

Microsoft Remote Server Administration Tools for Windows Vista for x64-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyID=d647a60b-63fd-4ac5-9243-bd3c497d2bc5&DisplayLang=en


2. Installation and configuration:
After you install this, open Control Panel -> "start Programs and Features"->"Turn Windows Features on or off" -> scroll down to the Remote Server Administration Tools ->turn on the the features you needed, or just simplely turn on all features.

3. To fix missing tab issue of "AD users and computers":
Specifically, in Active Directory Users and Computers (DSA.MSC) when you looked at the properties of a user, you do not see:

Terminal Services Profile
Environment
Sessions
Remote Control

This is a known issue and has now been fixed by MS KB960890: "Some tabs are not available in the properties of a user account in the Active Directory Users and Computers MMC snap-in after you install Remote Server Administration Tools (RSAT) on a computer that is running Windows Vista"
http://support.microsoft.com/default.aspx?scid=kb;EN-US;960890

4. Reference reading:
A guide to install and setup
http://www.trainsignaltraining.com/windows-vista-rsat/2008-04-03/

RSAT and ADUC: Getting the Terminal Services Tabs to Appear in AD Users and Computers
http://blogs.technet.com/askds/archive/2008/03/31/rsat-and-aduc-getting-the-terminal-services-tabs-to-appear-in-ad-users-and-computers.aspx

RSAT (Remote Server Administration Tools): what's included and what's NOT!!
http://trycatch.be/blogs/roggenk/archive/2008/04/08/rsat-remote-server-administration-tools-what-s-included-and-what-s-not.aspx

2009-06-30

Installing .net framework v1.1 on Vista

Installing .net framework v1.1 on Vista

http://www.mydigitallife.info/2007/12/27/install-microsoft-net-framework-11-on-windows-vista-fix-regsvcsexe-fails-error/

2009-06-23

Best Practice importing drivers in SCCM

Best Practice importing drivers in SCCM

What would be the required best practice steps on how to import new drivers in System Center Configuration Manager (SCCM), when building a new hardware model.
Kenny Buntinx introduced a good series of articles discussing on this issue.

SCCM 2007 : Best Practice importing drivers (Part 1) , creating a driver Package.
http://scug.be/blogs/sccm/archive/2009/02/27/sccm-2007-best-practice-importing-drivers-part-1-creating-a-driver-package.aspx

SCCM 2007 : Best Practice importing drivers (Part 2) , importing a driver into the SCCM Database.
http://scug.be/blogs/sccm/archive/2009/03/03/sccm-2007-best-practice-importing-drivers-part-2-importing-a-driver-into-the-sccm-database.aspx

SCCM 2007 : Best Practice importing drivers (Part 3) , Creating your search folders in SCCM.
http://scug.be/blogs/sccm/archive/2009/03/06/sccm-2007-best-practice-importing-drivers-part-3-creating-your-search-folders-in-sccm.aspx

SCCM 2007 : Best Practice importing drivers (Part 4) , adding drivers to your SCCM Driver Package.
http://scug.be/blogs/sccm/archive/2009/03/12/sccm-2007-best-practice-importing-drivers-part-4-adding-drivers-to-your-sccm-driver-package.aspx

SCCM 2007, WinXP deployment sound card problem

SCCM 2007 : Solution for audio issue when building your Windows XP SP3 Reference image
By Kenny Buntinx
http://scug.be/blogs/sccm/archive/2008/12/05/sccm-2007-solution-for-audio-issue-when-building-your-windows-xp-sp3-reference-image.aspx

When you deploy a Windows XP SP3 reference image, and you use the Task Sequence to add certain soundcard drivers you might face the problem that your soundcard drivers are installed but at the end there is no sound.

Apparently if you do not log in without a user on your XP SP3 windows can't detect a part of the soundcard device.

A possible solution is installing the sound device manually and using the application drivermax (http://www.innovative-sol.com/drivermax/) to capture the necessary drivers.

Import these drivers as a driver package in SCCM and deploy it with your task sequence.

Guidelines to build a greadt virtual machine

Building a great Virtual Machine
By Kim Oppalfens
http://scug.be/blogs/sccm/archive/2008/03/20/building-a-great-virtual-machine.aspx

Domain Name and Passwords should be keyboard agnostic (ie: be the same on azerty/querty )

  • Domain Example: Contoso.net
  • Password Example: Topsecret

The lab layout should be set as the background image, like in the screenshot

The lab should contain the lab credentials set with bginfo

The saved parameters file and the windows background should be saved to a folder called c:\bginfo

Create login script with saved bginfo parameters file to run as login script.

The machine should allow you to shutdown/ restart from the ctrl-alt-del box

The welcome page should be disabled

System restore should be disabled

The shutdown event tracker should be disabled

password complexity should be disabled

Changing the computer account password should be disabled.

Screensaver should be disabled

Showing icons on the desktop should be disabled (you didn't spend all this time on building backgrounds to have them cluttered with icons)

All passwords should be configured to not expire

Vm's should be running on the latest service pack

Your last login should be with the user that the people will need in the lab so that it is prefilled when pressing ctrl-alt-del

the c:\drive should contain a folder called buildguide and an rtf file with the steps taken to create the vm, this way you can see what preparative action has been taken to make the labs work.

So I created my lab environment in visio and saved the different visio's as bmp's

And set a lot of the above options using a gpo, I backupped the gpo and saved it. The gpo can be found here:http://scug.be/files/folders/sccm/default.aspx

And you could obviously import it back on any domain controller using gpmc.

SCCM2007 OSD : Customising your Task Sequence for Building a Client OS on your VMWare Workstation 6.0 or later
By Kenny Buntinx

This article provides detailed steps on how to build a reference image of your physical workstations onto your VMware Workstation so that people could play around

http://scug.be/blogs/sccm/archive/2009/04/20/sccm2007-osd-customising-your-task-sequence-for-building-a-client-os-on-your-vmware-workstation-6-0-or-later.aspx#1002

Deploying a Windows XP SP3 "Gold image" with SCCM 2007

Deploying a Windows XP SP3 "Gold image" with SCCM 2007

By Kenny Buntinx

http://scug.be/blogs/sccm/archive/2008/07/01/deploying-a-windows-xp-sp3-quot-gold-image-quot-with-sccm-2007.aspx

This post and subsequent posts will be a step by step on how to build a base XP SP3 image in SCCM. I will be outlining not necessarily pointing out every click. Hopefully others will find this helpful. This assumes an understanding of SCCM and uses what is referred to as a “Thin Image Strategy”.

1.Create a network access account, it only need be a domain user and its password should not expire. Add the account to the Computer Client Agent in the Client node under Site Settings

2. Import XP SP3 as an operating system Install Package.

3. Add a Distribution point to your new XP SP3 package created in step 1

4. Create the XP SP3 sysprep package in SCCM

4.1 The Deploy.cab included on the CD was not updated properly for XP SP3 so you must download a new version here.

4.2 Create a package that points at the extracted CAB file for its source

4.3 You do not need to create any programs for the package the build task sequence takes care of this

4.4 Add the package to a DP that can be used during your build

5. Create a package for the Config Mgr Client

5.1 Specify always obtain file from source directory

5.2 Usually here I create a share at \\SCCMSERVER\Souce$\SCCMClient.

5.3 Update the ccmsetup command line properties accordingly. Extensive information about command line properties on TechNet here.

5.4 Add the package to a DP that can be used during your build

6. Create a “Build and capture a reference operating system image” task sequence

6.1 Name the task sequence something appropriate like “Build & Capture Windows XP SP3 Gold 6.2 Image”

6.3 Select the x86 boot image

6.4 Select the Operating System Package you created in step 1

6.5 Enter a product key

6.6 Set the local admin password to any password

6.7 Join a workgroup

6.8 Select the Config Mgr client you created in step 4

6.9 Don’t add any software to the base image

6.10 Set your image properties

6.11 Select a location to save the image and make sure you include the full path including the .wim extension

6.12 Enter an account with rights to write to the share

6.13 Finish up

7. Change the task sequence to use “Quick Format”

7.1 Right Click on the Task Sequence and choose Edit

7.2 Select the “Partition Disk 0″ step

7.3 Choose properties on the Default (Primary) partition and check the “Quick Format” option

8. Create a collection to which you will advertise the task sequence; I usually use "customer" Base Builds

9. Advertise the task sequence to the collection you created in step 7 as optional

9.1 Right click Task sequence and choose advertise, follow the wizard

9.2 Make sure you select the check box “Make this task sequence available to boot media and PXE”

9.3 If you are in test and your boundaries are not defined make sure you select “When no local distribution points are available, use remote distribution point”

9.4 Make sure you completed step 1

10. Ensure that you have the network and mass storage drivers to boot the device on the boot image and in the driver store (If you have to do this in the future you must update the PXE and standard DPs)

11. Add the appropriate boot images (x86 / x64) to the PXE and standard DPs

12. Allow the client to boot from PXE

12.1 If this client previously had an SCCM agent on it you just need to add the client to the collection you created in step 6

12.2 If this is a new client and SCCM is pre-R2 add the client manually

12.2.1 Add the client by right clicking the Computer Associations node under OSD and choosing “Import Computer Information”

12.2.2 Enter the Name of the computer

12.2.3 Enter the MAC and or SMBIOS GUID

12.2.4 Add the computer to the collection you created in step 7

13. Boot the device up to PXE and choose your task sequence. In less than an hour you should have the start of a great XP Image

SCCM OSD Deployment with static IP address

SCCM OSD Deployment with static IP address

Scenario:
Deploy a new system via SCCM OSD, there is no DHCP in the LAN, hence have to setup static IP on the workstation.
But the problem is, the static IP lost after reboot the workstation.

Solution:

When there is no DHCP, the manually typed IP settings will gone after reboot if you don't fill the data again, becasue TS variables are just created as OS environment variables.

To resolve this, you can add 'Apply Network settings' step in task sequence
http://technet.microsoft.com/en-us/library/bb633293.aspx

Then write a custom script using the SMS.TSEnvironment COM object to set the TS variables to get this done.

Reference:
Apply Network Settings Task Sequence Action Variables
http://technet.microsoft.com/en-us/library/dd252744.aspx.

How to Use Task Sequence Variables in a Running Configuration Manager Task Sequence
http://msdn.microsoft.com/en-us/library/cc145669.aspx

SCCM: OSD Task Sequence fails to join the PC to the domain during system build

ConfigMgr 2007: OSD Task Sequence fails to join the PC to the domain during Windows setup
http://blogs.technet.com/smsandmom/archive/2008/12/01/configmgr-2007-osd-task-sequence-fails-to-join-the-pc-to-the-domain-during-windows-setup.aspx

Issue: When running a SCCM 2007 OSD Task Sequence deployment to a PC, the PC will be successfully download the image, however when it runs through Windows Setup, the PC will eventually fail to join the domain and the Task Sequence will fail. Inspecting the "Apply Network Settings" task in the Task Sequence shows that all settings and accounts being used in the task are correct.

Looking at the SMSTS.log, the following error message will be repeat throughout the log:

Sending StatusMessage
Formatted header:
1dc5ca47-2e4e-42ef-9c32-231959eb878emp:[http]MP_StatusManagerdirect:OSD336002008-11-03T21:10:05ZhttpStatusReceiverSync

CLibSMSMessageWinHttpTransport::Send: URL: :80 CCM_POST /ccm_system/request
Error. Received 0x80072ee7 from WinHttpSendRequest.
unknown host (gethostbyname failed)
hr, HRESULT=80072ee7 (e:\nts_sms_fre\sms\framework\osdmessaging\libsmsmessaging.cpp,7714)
sending with winhttp failed; 80072ee7
Will retry in 5 second(s)
Retrying...
CLibSMSMessageWinHttpTransport::Send: URL: :80 CCM_POST /ccm_system/request
Error. Received 0x80072ee7 from WinHttpSendRequest.
unknown host (gethostbyname failed)
hr, HRESULT=80072ee7 (e:\nts_sms_fre\sms\framework\osdmessaging\libsmsmessaging.cpp,7714)
sending with winhttp failed; 80072ee7
Will retry in 10 second(s)
Retrying...
CLibSMSMessageWinHttpTransport::Send: URL: :80 CCM_POST /ccm_system/request
Error. Received 0x80072ee7 from WinHttpSendRequest.
unknown host (gethostbyname failed)
hr, HRESULT=80072ee7 (e:\nts_sms_fre\sms\framework\osdmessaging\libsmsmessaging.cpp,7714)
sending with winhttp failed; 80072ee7
Will retry in 22 second(s)
Retrying...
CLibSMSMessageWinHttpTransport::Send: URL: :80 CCM_POST /ccm_system/request
Error. Received 0x80072ee7 from WinHttpSendRequest.
unknown host (gethostbyname failed)
hr, HRESULT=80072ee7 (e:\nts_sms_fre\sms\framework\osdmessaging\libsmsmessaging.cpp,7714)
sending with winhttp failed; 80072ee7
Will retry in 45 second(s)
Retrying...
CLibSMSMessageWinHttpTransport::Send: URL: :80 CCM_POST /ccm_system/request
Error. Received 0x80072ee7 from WinHttpSendRequest.
unknown host (gethostbyname failed)
hr, HRESULT=80072ee7 (e:\nts_sms_fre\sms\framework\osdmessaging\libsmsmessaging.cpp,7714)
sending with winhttp failed; 80072ee7
End of retries
Send (pReply, nReplySize), HRESULT=80072ee7 (e:\nts_sms_fre\sms\framework\osdmessaging\libsmsmessaging.cpp,2052)
failed to send the request
DoRequest (sReply, false), HRESULT=80072ee7 (e:\nts_sms_fre\sms\framework\osdmessaging\libsmsmessaging.cpp,3835)
Failed to send status message (80072ee7)
smStatusMessage.Send(), HRESULT=80072ee7 (e:\nts_sms_fre\sms\client\tasksequence\executionengine\utility.cxx,529)


Cause: This is caused by a missing NIC driver in the Windows installation. Either the NIC driver was missing or not available during the driver injection (Apply Device Drivers, Auto Apply Drivers, or Apply Driver Package tasks) of the Task Sequence and driver installation portion of Windows Setup. Because of this reason, the PC has no network connectivity, cannot join the domain, and the Task Sequence eventually fails. However, a NIC driver was present as part of the WinPE Boot Image, which allowed the deployment to get far along enough in the deployment process where it dropped the image down on the PC.

Resolution: To correct the problem follow the steps below:

1) Make sure that the appropriate NIC drivers for the model PC, Windows OS version, and architecture have been imported into the Operating System Deployment --> Drivers node in the SCCM 2007 Admin console.

2) Make sure that the imported NIC drivers from step 1 have been added to a Driver Package under the Operating System Deployment --> Driver Packages node in the SCCM 2007 Admin console.

3) Make sure that the Driver Package from step 2 has been copied to distribution points (DPs) that are accessible to the PC during the OSD Task Sequence deployment.

4) If using the "Apply Driver Package" task in the Task Sequence, make sure that Driver Package that contains the NIC driver is selected in the "Apply Driver Package" task next to the field "Driver Package". If filtering Driver Package by model using WMI queries under the Options tab of the "Apply Driver Package" task, ensure that the WMI query is correct and you choose the correct model PC.

Enable portfast on CISCO switch to fix SCCM error 0x80072ee7

ConfigMgr 2007: Task Sequence may fail to run with error code 0x80072ee7
http://blogs.technet.com/smsandmom/archive/2008/12/09/configmgr-2007-task-sequence-may-fail-to-run-with-error-code-0x80072ee7.aspx

If you're PXE booting machines and they're throwing 0x80072ee7 errors along with getting APIPA addresses then you might try turning on portfast if you're using a Cisco Spanning Tree Protocol (STP) enabled switch to see if that helps:


Issue: When attempting to PXE Boot and install an OS Image with SCCM 2007, the Task Sequence may error out and reboot the machine. The SMSTS.LOG files may show error code 0x80072ee7 that points to a name resolution and/or networking issue. Additionally, you may notice that WINPE boots and gets an IP address from the DHCP server initially, however, once it gets to the Graphical User Interface portion of WINPE and try and run the Task Sequence it reverts to an Automatic Private IP Address (APIPA) of 169.354.x.x.

Note: If you use Task Sequence Boot Media and manually configure a static IP address and subnet mask, etc. then the Task Sequence runs as expected.

Cause: This can occur if portfast is not enabled on your SPT enable Cisco switch. If portfast is not enabled then the port using STP may remain in blocking mode long enough to prevent the client computer from communicating over the network.

Resolution: To resolve this issue you can turn on "spanning tree portfast enable" on the Cisco switch. For more information on this feature contact your switch manufacturer or see the following article on Cisco.com's website:

http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a00800f0804.shtml

2009-06-17

TechNet Virtual Labs: Windows System Administration Scripting

TechNet Virtual Labs: Windows System Administration Scripting http://technet.microsoft.com/en-au/virtuallabs/bb512930.aspx

Step into the Windows Scripting Virtual Labs for Free

It's simple: no complex setup or installation is required to try out Windows System Administration Scripting running in the full-featured TechNet Virtual Lab. You get a downloadable manual and a 90-minute block of time for each module. You can sign up for additional 90-minute blocks any time.

Virtual labs
TechNet Virtual Lab: Using Microsoft Windows PowerShell for Administration and Customization of Microsoft Windows SharePoint Services 3.0
TechNet Virtual Lab: Writing Scripts with Windows Powershell
TechNet Virtual Lab: Using PowerShell in Windows Server 2008 Beta 3
TechNet Virtual Lab: Introduction to Windows PowerShell
TechNet Virtual Lab: System Administration Scripting
TechNet Virtual Lab: Active Directory Scripting
VBScript tools for windows
http://www.computerperformance.co.uk/ezine/tools.htm

Contents of Guy's VBScript Tool Kit
ADSI - Check LDAP properties
Cacls - Set permissions
Connections web site
CDVDE - Bulk import / export accounts
CMDHere
LDIFDE - Bulk import / export accounts
Link Checker
NetSh - Network Shell
OH (Open Handles)
RoboCopy
Scriptomatic
StringConverter.exe - LDIFDE Password generator
TaskKill
Tasklist
WBEMTEST
Windiff - Compares two files
WinExit.scr
WSH client for Windows 9x and NT 4.0
VBScript tools for windows
http://www.computerperformance.co.uk/ezine/tools.htm

Contents of Guy's VBScript Tool Kit
ADSI - Check LDAP properties
Cacls - Set permissions
Connections web site
CDVDE - Bulk import / export accounts
CMDHere
LDIFDE - Bulk import / export accounts
Link Checker
NetSh - Network Shell
OH (Open Handles)
RoboCopy
Scriptomatic
StringConverter.exe - LDIFDE Password generator
TaskKill
Tasklist
WBEMTEST
Windiff - Compares two files
WinExit.scr
WSH client for Windows 9x and NT 4.0

ADSI Scriptomatic

ADSI Scriptomatic

What is the ADSI Scriptomatic?
The ADSI Scriptomatic -- as we keep trying to tell you -- is designed to help you write ADSI scripts; that is, scripts that can be used to manage Active Directory. As if that isn’t enough (and we learned the hard way that things are never enough), the ADSI Scriptomatic also teaches you an important point about ADSI scripting: like WMI, there are consistent patterns to ADSI scripts. For example, the ADSI Scriptomatic will help you write a script to delete a user account. It will also help you write scripts for deleting groups and organizational units. And if you take a close look at the scripts for deleting different objects, you’ll see something very interesting: theyre practical identical! What is this, some kind of a rip-off?

Well, it might be. But the reason the scripts look so similar is because ADSI uses a consistent approach for deleting objects, regardless of the type of object being deleted. What does that mean? Well, if you take the time to study the scripts created by the ADSI Scriptomatic (and if you read the ADSI chapter from the Windows 2000 Scripting Guide), you’ll understand how you can delete pretty much anything from Active Directory. For example, we wanted to keep the ADSI Scriptomatic relatively simple; as a result, weve limited the objects you can work with. The ADSI Scriptomatic will write a script that deletes a user account, but it won’t write a script that deletes a published printer. But, hey, so what? After you understand the pattern, you can write your own script for deleting published printers. (OK, OK, well consider creating the DeletePublishedPrintersOmatic. But don’t hold your breath.)

Find for details from here:
http://technet.microsoft.com/en-us/scriptcenter/dd939958.aspx

Download ADSI Scriptomatic
http://www.microsoft.com/downloads/details.aspx?FamilyID=39044e17-2490-487d-9a92-ce5dcd311228&DisplayLang=en

Take Advantage of Scriptomatic 2.0 to Maximize Your WMI Scripting Efforts

Scriptomatic 2.0 resources

Take Advantage of Scriptomatic 2.0 to Maximize Your WMI Scripting Efforts
http://windowsitpro.com/article/articleid/44360/take-advantage-of-scriptomatic-20-to-maximize-your-wmi-scripting-efforts.html

The simplest and most obvious use for Scriptomatic is reading and displaying a class's properties and their values. When Scriptomatic 2.0 loads, it defaults to the root\CIMV2 namespace, then loads the classes in that namespace. You select a WMI class, such as Win32_ComputerSystem, to generate a script.

After Scriptomatic 2.0 generates the code, you can immediately run the script or save it to a file so that you can use it to create more complex code. If you run the script, you can output the results as command output in the command-shell window, as a text file for viewing in Notepad or another editor, as an HTML or XML file for viewing in a browser such as Microsoft Internet Explorer (IE), or as a comma-separated value (CSV) file for viewing in Microsoft Excel or another spreadsheet program.

Scriptomatic 2.0 alone won't give you a complete picture, which is why you need several WMI-specific tools and references in your toolkit. Here's a list of essential WMI tools and documentation that you can use to expand on the information Scriptomatic 2.0 provides:

Using Contrast as an Effective Learning Tool

Scriptomatic 2.0 lets you select other WMI namespaces besides the common root\CIMV2 namespace. CIMV2 is the only namespace available in version 1.0. In version 2.0, you can gain insight on whether a namespace (i.e., provider) is available on other platforms. For example, the root\MicrosoftIISv2 provider is available on Windows 2003 computers running Microsoft IIS 6.0. In contrast, this namespace isn't available on computers running Windows XP and IIS 5.1 because the MicrosoftIISv2 provider is available only on IIS 6.0.

Download Scriptomatic 2.0:

http://www.microsoft.com/downloads/details.aspx?FamilyID=09dfc342-648b-4119-b7eb-783b0f7d1178&displaylang=en

VB Scripts generated by Scriptmatic, ready for use.

VB Scripts generated by Scriptmatic, ready for use.

http://www.thescriptlibrary.com/Default.asp?Action=Browse&Level=Category1&ScriptLanguage=VBScript&Category1=Scriptomatic

VBScript > aspnet(14)
VBScript > CCM\invagt(7)
VBScript > CCM\Policy\Machine(40)
VBScript > CIMV2(495)
VBScript > CIMV2\Applications\Exchange(5)
VBScript > CIMV2\Applications\MicrosoftIE(10)
VBScript > CIMV2\Dell(50)
VBScript > CIMV2\SMS(2)
VBScript > DEFAULT(2)
VBScript > directory\LDAP(3)
VBScript > IntelNCS(38)
VBScript > Microsoft\SqlServer\ComputerManagement(15)
VBScript > MicrosoftActiveDirectory(7)
VBScript > MicrosoftDNS(37)
VBScript > MicrosoftExchangeV2(3)
VBScript > MicrosoftIISv2(337)
VBScript > MicrosoftNLB(20)
VBScript > MOM(14)
VBScript > MSAPPS11(121)
VBScript > perfmon(1)
VBScript > Policy(2)
VBScript > RSOP(2)
VBScript > ServiceModel(80)
VBScript > subscription(1)
VBScript > WMI(378)

2009-06-13

Everything About Labels in Blogger.

http://www.blogdoctor.me/2007/06/everything-about-labels-in-blogger.html

Ubuntu自动启动程序

Ubuntu自动启动程序

首先,linux随机启动的服务程序都在/etc/init.d这个文件夹里,里面的文件全部都是脚本文件(脚本程序简单的说就是把要运行的程序写到一个文件里让系统能够按顺序执行,类似windows下的autorun.dat文件),另外在/etc这个文件夹里还有诸如名为rc1.d, rc2.d一直到rc6.d的文件夹,这些都是linux不同的runlevel,我们一般进入的X windows多用户的运行级别是第5级,也就是rc5.d,在这个文件夹下的脚本文件就是运行第5级时要随机启动的服务程序。需要注意的是,在每个rc (1-6).d文件夹下的文件其实都是/etc/init.d文件夹下的文件的一个软连接(类似windows中的快捷方式),也就是说,在 /etc/init.d文件夹下是全部的服务程序,而每个rc(1-6).d只链接它自己启动需要的相应的服务程序!
要启动scim(某一程序),我们首先要知道scim程序在哪里,用locate命令可以找到,scim在/usr/bin/scim这里,其中usr表 示是属于用户的,bin在linux里表示可以执行的程序。这样,我就可以编写一个脚本程序,把它放到/etc/init.d里,然后在rc5.d里做一个相应的软链接就可以了。
这个脚本其实很简单,就两行:
#!/bin/bash
/usr/bin/scim
第一行是声明用什么终端运行这个脚本,第二行就是要运行的命令。
还需要注意的一点是,在rc5.d里,每个链接的名字都是以S或者K开头的,S开头的表示是系统启动是要随机启动的,K开头的是不随机启动的。这样,你就可以知道,如果我要哪个服务随机启动,就把它名字第一个字母K改成S就可以了,当然,把S改成K后,这个服务就不能随机启动了。因此,我这个链接还要起名为SXXX,这样系统才能让它随机启动。

在RH下,rc.local是默认启动的最后一个脚本文件,所以,

如果你想要随机启动,还有一种方法就是在rc.local的尾部加入/usr/bin/scim,这样就可以了。

Apcupsd a daemon for controlling APC UPSes

http://www.apcupsd.com/

Apcupsd can be used for power mangement and controlling most of APC's UPS models on Unix and Windows machines. Apcupsd works with most of APC's Smart-UPS models as well as most simple signalling models such a Back-UPS, and BackUPS-Office. During a power failure, apcupsd will inform the users about the power failure and that a shutdown may occur. If power is not restored, a system shutdown will follow when the battery is exhausted, a timeout (seconds) expires, or runtime expires based on internal APC calculations determined by power consumption rates.


Apcupsd安装使用笔记
http://www.chinaunix.net/jh/5/611485.html

基于Apcupsd的UPS配置使用总结(局域网/内外网共享)
http://allo.ave7.net/config_apcupsd

Problems accessing file shares on Windows Server 2008 64-bit running Symantec Endpoint Protection

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008100113145148?Open&seg=ent

Network resources on Win2008 serve cannot be accessed after installed SEP 11.0.
This article is the solution.

BTW, don't install Network component if you don't need.

Installing Windows XP on 6710b / SATA Native Mode Issues

It's known that, when install XP on HP 6710b, you must turn off SATA native mode from BIOS first otherwise HDD cannot be detected.

The below is a discussion on how to install WinXP while SATA native mode turned on.
http://forums11.itrc.hp.com/service/forums/questionanswer.do?admit=109447626+1244880500516+28353475&threadId=1175405

Suggestion from Matthew Neale:
There's an easy fix for getting around the f6 prompt and supplying a floppy disk...

download Nlite http://www.softpedia.com/progDownload/nLite-Download-12443.html

Install Nlite on a pc, run the program, it will prompt for a win xp source disk, then will prompt you to pick a location u want to save it to, the next screen is where we work our magic, have your sata drivers on hand and select integrate -> drivers and the make bootabe cd option... click next, it will prompt you to select the drivers you want to inject into the windows installation cd...

follow the prompts and burn your cd...

you now have a windows xp installation cd with sata support for your 6710b

Verified by Cheryl G.:
Hi Matthew
Yes,Nlite is the best! I found Nlite since this post and recommend it all the time now with the driver and guide below.
------------------
Intel SATA driver.
Download and run it,make a floppy OR cancel floppy creation.The files will be extracted to C:\Swsetup\sp37005 to use with Nlite.

Enabling SATA Native Mode after XP Install
http://tinyurl.com/ytpkpp

You can use Nlite to integrate the drivers into a new XP install cd.Nlite will even burn the new XP cd.
Very easy ,just follow the guide below closely.
http://www.howtogeek.com/howto/windows/resolving-setup-did-not-find-any-hard-disk-drives-during-windows-xp-installation/

Nlite dl:
http://www.nliteos.com

mikenchi reported an issue with this method
Hi all:
One word of warning. I used nLite and it does cause problems in some cases. If you remove an OS component, then need it later, you cannot add it, and sometimes need to do an OS repair with an original XP cd. Also, it is not compatible with Sysprep. (The author of nLite even acknowledges this) After you sysprep a machine, and apply the image to a new machine, after the first reboot it will pause asking you where are a number of files.

2009-05-25

Change Volume Licensing product key for windows 2003 server or R2

At some point you may want to change the product key of your windows 2003 server OEM version with a VLK key.

This can be done with two major steps:
1. Determine the channel that your copy of Windows Server 2003 was obtained through
http://support.microsoft.com/kb/889713/en-us
2. Change the Volume Licensing product key


Part 1. Determine the channel that your copy of Windows Server 2003 was obtained through

About Product IDs
All Windows Server 2003 products require the end user to type a Product Key during installation. A unique Product ID (PID) is generated when you run the Windows Server 2003 Setup program. After the Product Key is validated in the Setup program, the Setup program builds the 20-digit PID. The PID is assigned to the computer.
A PID contains the following information:
The first five characters of the PID indicate the Microsoft Product Code (MPC).
The three characters after the MPC indicate the channel ID.

To find your current PID:
Right-click My Computer, and then click Properties.
On the General tab, the PID appears in the Registered to box.

Some MPC codes for Windows Server 2003
Standard Edition 32 bit retail, 69712-000
Standard Edition 32 bit volume licensing, 69712-640
Standard Edition R2, 32 bit volume licensing, 69712-650
Standard Edition 32 bit OEM, 69712-OEM
Enterprise Edition 32 bit retail, 69713-000
Enterprise Edition 32 bit volume licensing, 69713-640
Enterprise Edition R2, 32 bit volume licensing, 69713-650
Enterprise Edition 32 bit OEM, 69713-OEM

More MPC codes please refer to MS KB:
http://support.microsoft.com/kb/889713/en-us


Part 2: change Volume Licensing product key for windows 2003
From part 1 you know what you currently have, then you can change it to the correct VL Key.

KB article 328874 explains how to do it for XP, the good news is, same method works for any version of 2003. So check this out:
http://support.microsoft.com/kb/328874

Here are the steps:

Deactivate Windows

Click Start, and then click Run.
In the Open box, type regedit, and then click OK.
In the navigation pane, locate and then click the following registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\Current Version\WPAEvents
In the topic pane, right-click OOBETimer, and then click Modify.
Change at least one digit of this value to deactivate Windows.

Reactivate Windows and add new product key

Click Start, and then click Run.
In the Open box, type the following command, and then click OK.
%systemroot%\system32\oobe\msoobe.exe /a
Click Yes, I want to telephone a customer service representative to activate Windows, and then click Next.
Click Change Product key.
Type the new product key in the New key boxes, and then click Update.If you are returned to the previous window, click Remind me later, and then restart the computer.
Repeat steps 1 and 2 to verify that Windows is activated. You receive the following message:
Windows is already activated. Click OK to exit.
Click OK.

2009-05-24

Setup network from Microsoft Virtual server 2005 R2

Setup network from Microsoft Virtual server 2005 R2

You can configure NAT on the host machine to share your local network with guest virtual machines so that they can be access Internet.With network address translation (NAT), you can configure one or more virtual machines to share the host operating system's Internet connection, as shown in the following table.
1.Install Microsoft Loopback Adapter on the host operating system
2.Enable Internet Connection Sharing on the physical network adapter that is connected to the Internet. Configure ICS so that the physical network adapter shares the connection with Microsoft Loopback Adapter.
3.Create a virtual network and configure it to use Microsoft Loopback Adapter
4.Connect one or more virtual machines to the virtual network that is configured to use Microsoft Loopback Adapter

DHCP server must be in the reserved IP list.An example:1. Host pc setting:Physical NIC: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NICIP: 192.168.10.6subnet: 255.255.255.0Gateway: 192.168.10.1 DNS: 192.168.10.1
MS Loopback adapter is installed on the host pc. ICS is enabled on physical NIC and shares the connection with the loopback adapter.Loopback adapter IP: 192.168.0.1 (leave "default gateway" blank)
2. Guest virtual pc settingVirtual network setting:Start IP: 192.168.0.20End IP: 192.168.0.200DHCP server: 192.168.0.2Default gateway: 192.168.0.1
Note:a. You must leave 16 address as system reserved.For example, if your virtual network is 192.168.0.0, then the first available DHCP IP is 192.168.0.17.b. The virtual DHCP server's IP address must within the reserved IP range.

2009-05-23

IE7.0 compatibility issue with IE8.0

Problem:
When use Virtual server admin web console, got error:
Message: 'document.getElementById(...)' is null or not an object
Reason:
IE8 seems to have some trouble to work normally with the js controls of Virtual Server 2005, but you can easily make it work by choosing IE8 to work in IE7 compatibility mode.

Just aside to the url you should have a button that seems like a "broken sheet of paper". Click on that and you will be in IE7 compatibility mode, and everything will work fine with Virtual Server.







A nice music blog

http://wuhuiyu1983.blogbus.com/

2009-05-20

ConfigMgr 2007: The Preload Package Tool (PreloadPkgOnSite.exe) Explained

ConfigMgr 2007: The Preload Package Tool (PreloadPkgOnSite.exe) Explained

http://blogs.technet.com/configurationmgr/archive/2009/05/07/configmgr-2007-the-preload-package-tool-preloadpkgonsite-exe-explained.aspx

How do we refresh a package located on a Branch Distribution Point?

http://blogs.technet.com/carlossantiago/archive/2008/05/16/how-do-we-refresh-a-package-located-on-a-branch-distribution-point.aspx

The short answer is, we can't. That does not mean that we don't have a way to update that package on the Branch Distribution Point (BDP), it just means that we can't refresh them. In SCCM refreshing vs. updating a package has different meanings. When we run the Manage Distribution Points Wizard and select the option to refresh a package on distribution points, we are asking the Distribution Manager service to use the existing compressed version of the package and extract it to the specified distribution points. This is true unless we used the always obtain files from source option on the package properties. When we select the option to update a package, we are asking Distribution Manager to get the files from the source directory, create a new compressed version of the package, possibly send the compressed version to child sites, and then extract the new version to the distribution points. If you are wondering when should we use a refresh vs. an update think about the following scenarios:
Scenario #1
There is a central site in your headquarters office (NY) with primary child sites on remote offices. Software packages are created on the central site. There is a slow WAN connection between the central site and the child sites. One of the child sites is in Dallas and has distribution points in Dallas, Austin, and Houston. There is a hard drive failure on the Houston distribution point and a new hard drive is installed. There is no backup of the hard drive that was replaced since it only contained SCCM packages.

Scenario #2
There is a central site in your headquarters office (NY) with primary child sites on remote offices. Software packages are created on the central site. There is a slow WAN connection between the central site and the child sites. One of the child sites is in Dallas and has distribution points in Dallas, Austin, and Houston. The signature files for the antivirus application used by the company got updated. We updated the package source files and now need to get those files to the distribution points.
In Scenario #1, we could use the refresh package on the Houston distribution point option. The central site server will send an instruction to distribution manager on the Dallas site to extract the local compressed version of the package to the Houston distribution point. This will save time and traffic across the WAN link. In Scenario #2, we need to get new files for a package to the distribution points. In that case we need a new version of the compressed package to be sent over the WAN to the child sites. Distribution Manager on the Dallas child site will get the new compressed package and will then extract it to its local distribution point and the the ones in Austin and Houston.
The above is a very simplified explanation of what happens behind the scenes and I am not going to get in the details of delta replication. That is because this blog is about BDPs, so lets get back on track. If we run the Manage Distribution Points Wizard the first thing we are going to find out if we try to refresh a package on a BDP is that they are not listed in the Wizard. There is no refresh option for the BDPs because distribution manager does not handle packages on BDPs. The BDP role is a client side role. The BDP gets machine policies that tell the client what packages to download and share. Let say that in scenarios #1 and #2 the Houston distribution point is a BDP. In that case the refresh will not work obviously because it is not an option in the admin console. On scenario #1, to get the packages back on the Houston BDP we would have to use update option. On scenario #2, we would also get the new signature files to the Houston BDP by selecting to update the package on the distribution points.

SCCm package distribution

When you refresh package data on a Microsoft System Center Configuration Manager 2007 distribution point, the package is copied from the compressed version on the site server but not updated from the original source.

Refreshing the package does not increment the package version.

Updating the distribution point will copy files from the source folder, thus incrementing the package version

2009-02-12

New group policies for DNS in Windows Server 2003

New group policies for DNS in Windows Server 2003

http://support.microsoft.com/default.aspx?scid=kb;en-us;294785

Windows Server 2003 resolves the problem of centralized DNS management by introducing group policies to configure DNS clients. For example, the following parameters are available in Windows Server 2003:
Enable or disable dynamic registration of the DNS records by a clientConfigure DNS suffix search list of the clientsDevolution of the primary DNS suffix in a name resolution processDNS suffix search list
These group policies are at the following location:
Computer Configuration/Administrative Templates/Network/DNS Client Group policy always supersedes the local configuration as well as the DHCP configuration. The only exception to this rule is if the REG_DWORD value DoNotUseGroupPolicyForDisableDynamicUpdate is enabled under the following registry key to disable dynamic DNS registration: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\ParametersIf this value exists and it is set to 0x1, then services do not use a group policy value; instead they use locally configured values. If DoNotUseGroupPolicyForDisableDynamicUpdate does not exist or is set to 0x0, services must use the value that is specified by the group policy.
Policy DescriptionsThis section describes the settings' functions, the registry key which is modified on the client, and the valid values for the policy and the registry key. These values are stored on the client is the following registry key: HKEY_LOCAL_MACHINE\Software\Polices\Microsoft\Windows NT\DNSClientPrimary DNS SuffixThis setting specifies the primary DNS suffix for all affected computers. The primary DNS suffix is used in DNS name registration and DNS name resolution. This setting specifies a primary DNS suffix for a group of computers, and prevents users, including administrators, from changing it.
If this setting is disabled or not configured, each computer uses its local primary DNS suffix that is usually the DNS name of the Active Directory domain that it is joined to. However, administrators can use the System tool in Control Panel to change the primary DNS suffix of a computer.
To use this setting, type the entire primary DNS suffix that you want to assign in the text box that is provided (for example, microsoft.com). This setting does not disable the DNS Suffix and NetBIOS Computer Name dialog box that administrators use to change the primary DNS suffix of a computer. However, if an administrator enters a suffix, that suffix is ignored while this setting is enabled.
IMPORTANT: For the changes to this setting to be applied, you must restart Windows Server on all computers that are affected by the setting.
TIP: To change the primary DNS suffix of a computer without setting a policy, click System in Control Panel, click the Network Identification tab, click Properties, click More, and then type a suffix in the Primary DNS suffix of this computer box.

what is the difference between Difference between "Primary DNS Suffix" and "Connection specific DNS Suffix"??

http://www.experts-exchange.com/Networking/Misc/Q_21729492.html

Question:
what is the difference between Difference between "Primary DNS Suffix" and "Connection specific DNS Suffix"??

This information is presented whenever i perform a "ipconfig -all", such as:

C:\>ipconfig -all

Windows 2000 IP Configuration

Host Name . . . . . . . . . . . . : webserver
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : scaa.org

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : scaa.org
Description . . . . . . . . . . . : Realtek RTL8139(A) PCI Fast Ethernet
Adapter
Physical Address. . . . . . . . . : 00-30-1B-3E-4E-19
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 10.0.1.50
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.0.1.1
DHCP Server . . . . . . . . . . . : 10.0.1.10
DNS Servers . . . . . . . . . . . : 10.0.1.10
64.80.125.114
Primary WINS Server . . . . . . . : 10.0.1.10


Answer 1:
You assign the Primary DNS Suffix and your DHCP device assigns Connection specific DNS Suffix

Answer 2:
True, but not complete.

Primary DNS Suffix is set for the entire computer and will be used on any network adaptor on which no Connection-specific DNS Suffix has been defined.

The Connection-specific DNS Suffix allows us to overide the Primary for a specific network adaptor so that when your computer registers itself with the DNS server it's presently using, it will register with a well-formed fully qualified domain name (FQDN). The thing that MS calls DNS suffix is really just everything to the right of the first dot in a FQDN.

Imagine your company-supplied laptop computer has FQDN "joe.boston.corpX.com" and it's part of an Active Directory domain at the office. It's Primary suffix is "boston.corpX.com" and it's name is "joe." When you boot it up at the office, it will DHCPDISCOVER an IP address and the AD DC's DHCP server will respond, then your computer will register itself with the DNS server on that AD DC using it's FQDN.

If you use a VPN Client on the road, though, so you can connect to your company's network from the hotel broadband service. It may be smarter (or neccessary) to have your computer register itself as joe.remote.corpX.com with the RAS server in your network. That's where the Connection-specific DNS Suffix comes in. When you installed that VPN Client Software (or your IT team did), it created another network adaptor and the Connection-specific DNS suffix on that one is ... yep, remote.corpX.com and all is well.

In general use, we don't use it. On systems with only one network adapator, just leave it blank. Unless someone in a higher paygrade that knows why you should change it tells you to, that is... :-)

2009-01-28

How to open Control Panel Items from Command Line in Vista

How To Make Shortcuts to Control Panel Pages in Vista
http://www.dailygeeks.com/howto/how-to-make-shortcuts-to-control-panel-pages-in-vista/

How to open Control Panel Items from Command Line in Vista
http://www.nibbleguru.com/problem/5074-how-open-control-panel-items-command-line-vista

New Vista Syntax for Opening Control Panel Items from the Command-line
http://www.howtogeek.com/howto/windows-vista/new-vista-syntax-for-opening-control-panel-items-from-the-command-line/


Accessibility Options, access.cpl

Add/Remove Programs, appwiz.cpl

Add Hardware Wizard, hdwwiz.cpl

Automatic Updates, wuaucpl.cpl

Bluetooth Properties, bthprops.cpl

Display Properties, desk.cpl

Firewall Properties, firewall.cpl

Game Controllers, joy.cpl

Internet Options, inetcpl.cpl

iSCSI Initiator, iscsicpl.cpl

Java Control Panel, jpicpl32.cpl (java install folder\javacpl.exe)

Licensing Mode, liccpa.cpl

Mouse Properties, main.cpl

Network Connections, ncpa.cpl

Network Setup Wizard, netsetup.cpl

ODBC Properties, odbccp32.cpl

Power Options, powercfg.cpl

Regional and Language Options, intl.cpl

Sound and Audio Devices, mmsys.cpl

Stored Passwords, keymgr.cpl

System Properties, sysdm.cpl

Telephone and Modem Properties, telephon.cpl

Time and Date Settings, timedate.cpl

User Accounts, nusrmgr.cpl

Windows Security Center, wscui.cpl

Wireless Link, irprops.cpl

2009-01-27

借助路由器,实现iAMT的本地管理

借助路由器,实现iAMT的本地管理


我们在开发支持Intel主动管理技术的控制台时,访问管理引擎(ME)提供的Web Service接口有两种方式,一种是通过网络访问,另外一种是本机直接访问。但是本机访问有比较多的限制,大部分iAMT功能接口对本地应用程序来说是不可用的,比如CircuitBreak,AgentPresence,SecurityAdministration等等。那么在没有两台机器的情况下,如何实现在iAMT机器的主机操作系统上就能对iAMT所有特性进行操作呢?
经过笔者的一些简单实验,我们只需要一台普通的路由器就能做得到。比如,一般的ADSL接入设备,无线路由器,或者自己用Linux搭建的网关都行。大概的原理是这样的:给iAMT和Host OS配置不同网段的IP地址,都将网关指向路由器;然后在路由器上设定所需的路由;在Host OS上的应用程序访问iAMT IP地址时,网络包首先被发送到默认网关,也就是路由器,然后路由器根据自身的路由表将网络包路由到iAMT,iAMT的返回结果同样也是先发送到路由器,然后由路由器再将网络包路由回Host OS。如下图所示。

在上图中,我们将一台Intel Core 2 vPro机器(内建iAMT功能)的主机操作系统IP地址配置为192.168.2.10,网关指向192.168.1.1,由于这里网关和主机地址不在同一个网段,只能手动配置静态IP了;将底层的iAMT的IP地址配置为192.168.1.10,网关指向192.168.1.1。
这里的路由器兼做网关(我们使用的普通路由器都是这么用的),LAN口配置的IP地址是192.168.1.1;为了使得路由器能够将iAMT返回的数据包回送给Host OS,我们需要在路由表里面增加一项: Destination:192.168.2.0 Netmask: 255.255.255.0 Gateway: 0.0.0.0 (如果是Windows做路由器, 这里就是192.168.1.1)
另外,如果路由器支持LAN接口配置多个IP地址,那只需要为路由器LAN口再配置一个IP地址:192.168.2.1,上面那条路由就能自动加入到路由表;这时候,Host OS的网关可以设置为192.168.2.1。这样,我们就可以在Host OS上通过直接访问底层iAMT的IP来访问iAMT的功能了。比如,通过IE打开:http://192.168.1.10:16992,就可以见到我们熟悉的iAMT WEBUI的登陆界面了。
我在一台LinkSys的无线路由器,和一台Windows 2003 Server的网关上测试过,上述的方法都可以成功。如果你有兴趣,欢迎一起交流探讨。

Out of Band Management简介

http://blogs.technet.com/msdchina/archive/2009/01/08/out-of-band-management-sccm-2007-.aspx

Out of Band Management简介 —— SCCM 2007 Out of Band Management专题系列之一
Out of Band Management正在逐步成为IT管理的主流技术,本专题系列计划就SCCM 2007中Out of Band Management feature做一些介绍和探讨,来帮助读者了解并使用SCCM 2007中的Out of Band Management技术,系列将包括简介,使用,调错等专题文章。

Out of Band Management简介
Out of Band Management是指带外管理技术,是一种不依赖于操作系统就可对目标机器进行管理的技术,目前Intel的AMT(Active Management Technology)和DASH标准(Desktop and mobile Architecture for System Hardware)都提供了Out of Band Management的支持。 在SCCM 2007 SP1,我们将AMT技术整合到SCCM产品之中,此模块被称为Out of Band Management feature。上海研发团队主导了这部分功能的所有设计,开发工作。
SCCM Out of Band Management结合了AMT在硬件层面的强大功能,并依托了SCCM平台中强有力的企业机器管理模式,为企业提供了灵活、便捷、强大的远程唤醒、远程技术支持、资产管理、、灾难恢复等功能。


Overview of Out of Band Management
Topic last updated—May 2008
http://technet.microsoft.com/en-us/library/cc161963.aspx
Out of band management in Configuration Manager 2007 SP1 provides powerful management control for computers that have the Intel vPro chip set and Intel Active Management Technology (Intel AMT) firmware versions 3.2.1 or later.

Out of band management allows an administrator to connect to a computer's management controller when the computer is turned off, in sleep or hibernate modes, or otherwise unresponsive through the operating system. By way of contrast, in-band management is the classic approach used by Configuration Manager and its predecessors whereby an agent runs in the full operating system on the managed computer and the management controller accomplishes tasks by communicating with the management agent.
Out of band management supplements in-band management. While in-band management supports a wider range of operations because its environment is the full operating system, in-band management might not be functional if the operating system is not present or is not operational. In these situations, the supplementary capabilities of out of band management allow administrators to manage these computers without requiring local access to the computer.

2009-01-22

Content location request for apps package failed. (Code 0x80040102)

Got error during SCCM deployment:
Content location request for apps package failed. (Code 0x80040102)

Information from Microsoft about this code:
Error code 0x80040102: No content location returned for the given package
solution:
Check the server side to make sure the package is distributed to at least one distribution point. Also check whether advertisement allows the task sequence to fall back to remote distribution point when there is no local distribution point

Troubleshooting Operating System Deployment Using Custom Error Codes
http://technet.microsoft.com/en-us/library/bb735886.aspx

Custom Error Codes for Configuration Manager 2007
http://technet.microsoft.com/en-us/library/bb632794.aspx

This fixed my problem:
Configuration manager->site database->computer management->software distribution -> advertisements -> right click on the advertisement you want to edit and choose properties -> "distribution points" Tab -> tick "when no local distribution points is available, use a remote distribution point" and "when no protected distribution point is available, use an unprotected distribution point.
Save and restart the build again.

2009-01-09

Ports used by Configuration Manager

Ports used by Configuration Manager
http://technet.microsoft.com/en-us/library/bb632618.aspx
Client to MP: 80 mixed mode, 443 for native mode
Client to SUP: 80/8530 or 443/8531
Client to DP: 80/443 and 445 (SMB)
Client to SLP: 80



You should also take into account that workstations may (and should) have Windows Firewall enabled.

Firewall Settings for Configuration Manager Clients
http://technet.microsoft.com/en-us/library/bb694088.aspx

Also clients need to be installed first. If you plan to use Client Push, I believe ports for RPC and Kerberos should be opened. Or you can use logon scripts.

However the ports used depend on the features that you plan to use in your infrastructure. Best option in my opinion is to try to implement Native Mode. Then all the communication with the clients will use 443 (SSL).

As a matter of fact I am struggling to configure it myself right now :-)

More info here:

Choose between Native Mode and Mixed Mode
http://technet.microsoft.com/en-us/library/bb632431.aspx

2008-12-31

SMS2003部署及troubleshooting

http://struggle.blog.51cto.com/333093/79354
详解SMS2003部署Windows 2003

http://www.winsvr.org/info/info.php?sessid=&infoid=32&page=1
SMS 2003安装配置系列之一:SMS 2003主站点安装指南



http://www.ixpub.net/archiver/tid-658413.html
解读SMS2003日志文件

http://www.microsoft.com/technet/sms/2003/library/techfaq/tfaq03.mspx#EWEAC
Clients Frequently Asked Questions


http://www.ixpub.net/thread-658378-1-7.html
如何解决在 Systems Management Server 2003 高级客户端推送安装问题


http://www.microsoft.com/technet/scriptcenter/guide/sas_roa_overview.mspx?mfr=true
Microsoft Windows 2000 Scripting Guide


http://technet.microsoft.com/en-us/library/cc179974%28TechNet.10%29.aspx
Scripting in SMS


http://support.microsoft.com/kb/883620
You cannot install Advanced Client when your Systems Management Server 2003 does not use Active Directory or when the schema for Active Directory has not been extended


http://support.microsoft.com/kb/925282
How to troubleshoot Advanced Client Push Installation issues in Systems Management Server 2003

http://www.tek-tips.com/viewthread.cfm?qid=1151166&page=1
解决sms客户端无法安装的问题,如何检查DC之间的复制是否成功。


http://technet.microsoft.com/en-us/library/cc181833%28TechNet.10%29.aspx
technet resource: Systems Management Server 2003

Force SCCM client to check advertisements

System ManagementCustomize SMS Using Local Policies
http://technet.microsoft.com/en-us/magazine/2006.09.customizesms.aspx

Force Task Sequence Execution without Advertisement
http://social.technet.microsoft.com/Forums/en-US/configmgrsdk/thread/298b32f6-746c-473a-b7ce-6bb51cfe1270/

Force SCCM Client to Check for New Advertisements
http://social.technet.microsoft.com/Forums/en-US/configmgrswdist/thread/a1066dfb-a71e-4e52-b7b7-c225ea0935a4/

Control SCCM client actions by scripting

The Advanced Client, is scriptable. You can use the CPApplet locally on the client or you can use WMI to do things remotely. On thing you'll often need is the triggering of an action. There are loads of samples in this forum meanwhile how to do it. Here is an overview of the actions available and their respective ScheduledMessageIDs which you will need to trigger them remotely.
(From http://www.myitforum.com/articles/8/view.asp?id=6757)
Hardware Inventory Cycle
CPApplet Name: Hardware Inventory Collection Cycle
ScheduledMessageID: {00000000-0000-0000-0000-00000001}

Software Inventory Cycle
CPApplet Name: Software Inventory Collection Cycle
ScheduledMessageID: {00000000-0000-0000-0000-00000002}

Discovery Data Collection Cycle
CPApplet Name: Discovery Data Collection Cycle
ScheduledMessageID: {00000000-0000-0000-0000-00000003}

File Collection Cycle
CPApplet Name: Standard File Collection Cycle
ScheduledMessageID: {00000000-0000-0000-0000-00000010}

ID MIF Collection Cycle
CPApplet Name: Standard File Collection Cycle
ScheduledMessageID: {00000000-0000-0000-0000-00000011}

Machine Policy Retrieval & Evaluation Cycle
CPApplet Name: Request & Evaluate Machine Policy
ScheduledMessageID: {00000000-0000-0000-0000-00000021} RequestAssignments Resource Type=’Machine’
ScheduledMessageID: {00000000-0000-0000-0000-00000022} Evaluate Policy Resource Type=’Machine’
The Machine Policy Retrieval & Evaluation Cycle consists of these two actions! There are two more Scheduled Messages in this context with no corresponding Client Actions.
ScheduledMessageID: {00000000-0000-0000-0000-00000040} CleanupPolicy Resource Type=’Machine’
ScheduledMessageID: {00000000-0000-0000-0000-00000042} ValidateAssignments Resource Type=’Machine’

User Policy Retrieval & Evaluation Cycle
CPApplet Name: Request & Evaluate User Policy
ScheduledMessageID: {00000000-0000-0000-0000-00000026} RequestAssignments Resource Type=’User’
ScheduledMessageID: {00000000-0000-0000-0000-00000027} Evaluate Policy Resource Type=’User’
The User Policy Retrieval & Evaluation Cycle consists of these two actions! There are two more Scheduled Messages in this context.
ScheduledMessageID: {00000000-0000-0000-0000-00000041} CleanupPolicy Resource Type=’User’
ScheduledMessageID: {00000000-0000-0000-0000-00000043} ValidateAssignments Resource Type=’User’

Software Metering Usage Report Cycle
CPApplet Name: Software Metering Usage Report Cycle
ScheduledMessageID: {00000000-0000-0000-0000-00000031}

Windows Installer Source List Update Cycle
CPApplet Name: MSI Product Source Update Cycle
ScheduledMessageID: {00000000-0000-0000-0000-00000032}

There are a few Scheduled Messages that do not correspond to Client Actions that can be triggered via the GUI.

Refresh default MP
ScheduledMessageID: {00000000-0000-0000-0000-00000023} LSRefreshDefaultMPTask

Refresh Location
ScheduledMessageID: {00000000-0000-0000-0000-00000024} LSRefreshLocationsTask

Timeout Location Service Requests
ScheduledMessageID: {00000000-0000-0000-0000-00000025} LSTimeOutRequestsTask

Manage Certificates
ScheduledMessageID: {00000000-0000-0000-0000-00000051} CertMaintenance

Force SCCM clients to check for new program advertisements

Q: How can I force my SCCM clients to check for new program advertisements?
A: Program advertisements occur as part of the Machine Policy Retrieval & Evaluation cycle action in the SCCM Client.
To force a client to find new programs that are available ahead of the regular discovery phase, perform these steps:
1. Start the Systems Management Control Panel applet (Start, Settings, Control Panel, Configuration Manager).
2. Click the Actions tab.
3. Select "Machine Policy Retrieval & Evaluation Cycle" and click Initiate Action.
4. Close the Systems Management Control Panel applet. Within a few minutes, the new-program advertisements should be visible. Alternatively, you can use the Policy Spy Tool to force a Machine policy retrieval. You can download the Policy Spy Tool at http://www.microsoft.com/smserver/downloads/2003/tools/toolkit.asp.




Q: When you distribute sw to user collections what triggers the installation?
A: It is the "User policy retrieval and evaluation cycle" that triggers the installationThe interval of "User policy retrieval and evaluation cycle" is defined in the Computer Client Agent properties on the SCCM server:
(http://technet.microsoft.com/en-us/library/bb693764.aspx)
SCCM console -> site management-> site name XXXX -> site settings -> client agents -> right click

By default it’s 60 minutes.

2008-12-22

BDD 2007 - Troubleshooting Database issues

BDD 2007 - Troubleshooting Database issues

(Original from Ben Hunter's blog, check more details from this link:
http://blogs.technet.com/benhunter/archive/2007/07/10/bdd-2007-troubleshooting-database-issues.aspx)

Common issues
The following section details common issues and recommended configurations for each.
Database Rules - Ensure that the appropriate database rules have been created. Database rules are specified using the deployment point rules tab. Configuration database rules can be created manually or using the Configure DB Wizard in the Deployment Workbench.
A typical database section should look similar to the following:
[CSettings]
SQLServer=SERVERNAME
Database=BDDAdminDB
Netlib=DBNMPNTW
SQLShare=logs
Table=ComputerSettings
Parameters=MacAddress
ParameterCondition=OR
The critical components of the database section are:
SQLServer - must specify the SQL server that hosts the BDD configuration database. SQLShare – must be a valid share on the SQL server and the user account (UserID as specified in the rules) must have access rights to that share. If SMS OSD Feature Pack is used for deployment then the SMS Advanced Client installation account will require access rights rather than the user account. Netlib – there are many issues with using TCP/IP sockets based connections so ONLY USE NAMED PIPES (DBNMPNTW).Database connectivity issues – There are a number of issues that can stop the client connecting to the SQL server, these are detailed below:
Ensure that Named Pipes is enabled for remote connectivity on the SQL server, this is not enabled by default. Has the surface area been configured to enable Named Pipes? When using SQL 2005 it is important to ensure that the “Surface area” is configured in such a way that remote connectivity to Named Pipes is allowed. If you have issues accessing the database from the workbench then ensure that you are using Named Pipes. The Deployment Workbench always uses Named Pipes to connect to the database.Security - has the deployment account got the appropriate database rights? The account used will need read rights to the BDD admin database. The account can vary depending on the deployment type:
ZTI – The SMS advanced client installation account. LTI – The user account specified in the rules (bootstrap.ini).SQL instances – If you are connecting to a database instance then this instance must be specified. This value is specified using the Instance field in the deployment workbench

Troubleshooting methods
During the troubleshooting process it is critical that you can easily test the database rules. The following instructions detail how to manually test the database connectivity. The rules specified in the deployment point can be tested without running through the entire BDD build process. Rules are processed using a script called ZTIGather.wsf, this script can be run separately from the other BDD scripts allowing easy testing. The steps below detail the process required to perform manual rule testing. To properly reflect the deployment environment it is important to perform these tests from a client device:
1. Create a folder on the client device and copy the following files from the deployment point to this folder:
ZTIGather.wsf ZTIGather.xml ZTIUtility.vbs CustomSettings.ini 2. Delete C:\MININT directory if it already exists. This folder can also be located at X:\MININT if the C drive is not available.
NOTE: BDD stores configuration and progress information in the MININT folder, if this folder is not removed between tests then the results will be invalid.
3. From the command prompt navigate to the newly created folder and execute the rule processing script using the following command:
"cscript.exe ZTIGather.wsf /debug:true"
The script will then be processed and the results outputted to the command prompt and a log file ( .\MININT\SMSOSD\OSDLOGS\ZTIGather.log)

List of Log Files in Configuration Manager 2007

http://technet.microsoft.com/en-us/library/bb892800.aspx

List of Log Files in Configuration Manager 2007

All the client and site server components in Microsoft System Center Configuration Manager 2007 record process information in individual log files. You can use the information in the client and site server log files to help you troubleshoot issues that might occur in your Configuration Manager 2007 hierarchy.
By default, client and server component logging is turned on in Configuration Manager 2007.
Client Log FilesThe Configuration Manager 2007 client logs are located in one of the following locations:
On computers that serve as management points, the client logs are located in the SMS_CCM\Logs folder.
On all other computers, the client log files are located in the %Windir%\System32\CCM\Logs folder or the %Windir%\SysWOW64\CCM\Logs.

Site Server Log FilesMost Configuration Manager 2007 site server log files are located in the \LOGS folder. Because Configuration Manager 2007 relies heavily on Microsoft Internet Information Services (IIS), you can review the IIS log file for additional errors that relate to client access to the IIS server. The IIS log file is located in the %Windir%\System32\logfiles\W3SVC1 folder on the IIS server.

Management Point Log FilesIf management points are installed in the site hierarchy, management point log files are stored in the SMS_CCM\LOGS folder on the management point computer.

Network Access Protection Log FilesBy default, client log files related to Network Access Protection are found in %windir%\CCM\Logs. For client computers that are also management points, the log files are found in %ProgramFiles%\SMS_CCM\Logs.
The System Health Validator point log files are located in %systemdrive%\SMSSHV\SMS_SHV\Logs.
Desired Configuration Management Log FilesBy default, the Configuration Manager 2007 client computer log files are found in %windir%\System32\CCM\Logs or in %windir%\SysWOW64\CCM\Logs. For client computers that are also management points, the client log files are located in the SMS_CCM\Logs folder. The following table lists and describes these log files.

Wake On LAN Log FilesThe Configuration Manager 2007 site server log files related to Wake On LAN are located in the folder \Logs on the site server.
Software Updates Site Server Log FilesThe Configuration Manager 2007 site server log files are found, by default, in \Logs.
WSUS Server Log FilesBy default, the log files for WSUS running on the software update point site system role are found in %ProgramFiles%\Update Services\LogFiles.
Software Updates Client Computer Log FilesBy default, the Configuration Manager 2007 client computer log files are found in %windir%\CCM\Logs.
Windows Update Agent Log FileBy default, the Windows Update Agent log file is found on the Configuration Manager Client computer in %windir%.
Out of Band Service Point Log FilesThe Configuration Manager 2007 SP1 log files listed in the following table are located in the folder \Logs on the site system server selected to host the out of band service point role.
Out of Band Management Console Log FilesThe Configuration Manager 2007 SP1 log file listed in the following table is located in the folder \AdminUI\AdminUILog on any computer that runs the out of band management console from the Configuration Manager console.

Out of Band Client Computer Log FilesThe Configuration Manager 2007 SP1 log file listed in the following table is located in the folder %windir%\System32\CCM\Logs on workstation computers that are running the Configuration Manager 2007 SP1 client and that are managed out of band.

Troubleshooting Tips for SCCM deployment

http://blogs.technet.com/inside_osd/archive/2007/12/13/troubleshooting-tips.aspx
Inside ConfigMgr 07 Operating System Deployment
Contributed by Brett Flegg

Troubleshooting Tips
The follow is a collection of tips that may be helpful when troubleshooting issues with ConfigMgr 07 Operating System Deployment.

Error Codes
There is no definitive list of error codes that can be returned in a task sequence, because most of the error codes originate from calls to other Windows API functions. The error lookup functionality provided by trace32.exe is a good place to start when trying to figure out what a specific error code means (in trace32.exe, go to Tools / Error Lookup...).

Enable the Debug Shell on your boot image
Boot images have an option to enable a command shell while running in Windows PE. This is turned off by default for security reasons (since it would allow an end user to open a command shell during the re-imaging process) but can be enabled on the “Windows PE” property page.
Open the boot image’s properties dialogOn the Windows PE tab check the “Enable command support (testing only)” optionUpdate the boot image on the distribution pointsRebuild any media that uses the boot image (e.g. capture media, boot media, or stand-alone media)When a task sequence is running in Windows PE you can open a command shell by pressing F8. As long as the command-shell is open the task sequence will not reboot the machine. This will give you a chance to verify network connectivity, diagnose driver issues, and view/copy the log files (see Client Log Files section below).

Client Log Files
All actions in a task sequence log to the smsts.log file. This file is moved around during different stages of an operating system deployment so that it does not interfere with the imaging process.
While in Windows PE the log file is stored in the windows temp directory on the RAM-disk (typically x:\windows\temp\smstslog)While in a full operating system that has a ConfigMgr client installed the log file is located in the smstslog subdirectory under the client logging path (typically %windir%\system32\ccm\logs\smstslog)While in the full operating system that does not have a ConfigMgr client installed the log file is located in the Windows temp directory (typically %windir%\temp\smstslog)When the task sequence completes, the log file is “finalized” to one of the following locations depending on the state of the machine:
If the task sequence finishes in Windows PE the log file is copied to an SMSTSLog directory on the largest available partition.If the task sequence finishes in the full operating system and a ConfigMgr client is installed then the log is copied to the client logging path (typically %windir%\system32\ccm\logs)If the task sequence finishes in the full operating system and there is no ConfigMgr client installed then the log is copied to the Windows temp directory.

Task Sequence Reports
When running, task sequences send status messages back to the server for each step in the task sequence. Included in these status messages are the last 1024 characters of stdout/stderr text from the action. Many times, this information can be used to remotely diagnose a task sequence issue (especially useful if an error has occurred in Windows PE and the debug shell was not enabled). The “History - Specific task sequence advertisements run on a specific computer” report provides a list of these status messages for a specific advertisement and computer and can be opened from the Reports node in the ConfigMgr console.

2008-12-09

Create a shortcut using the runas command

A command prompt with administrative credentials:
runas /user: ComputerName\administrator cmd

Computer Management with administrative credentials: runas /user:ComputerName\administrator "mmc %windir%\system32\compmgmt.msc"

Active Directory Users and Computers with domain administrative credentials: runas /user:DomainName\administrator "mmc %windir%\system32\dsa.msc"

Active Directory Users and Computers in another forest: runas /netonly /user:DomainName\UserName"mmc %windir%\system32\dsa.msc"

2008-11-26

how to check if your mail server on the spam black list

http://spamlinks.net/filter-dnsbl-lookup.htm#general-sites


http://www.emailtools.co.uk/tips/blacklists.htm


Check email black list tool
http://www.emailtools.co.uk/tools/blacklistcheck.htm
http://openrbl.org/query?i=xxx.xxx.xx.xxx
http://dnsbl.njabl.org/cgi-bin/lookup.cgi?query=xxx.xxx.xxx.xxx
http://www.junkemailfilter.com
http://www.mxtoolbox.com/blacklists.aspx


Check exchange server smtp log:
http://www.msexchange.org/tutorials/Logging_the_SMTP_Service.html

Stop Spam From the Inside by Locking Down SMTP:
http://technet.microsoft.com/en-au/magazine/cc161029.aspx

2008-11-24

troubleshooting computer browser problem

You are experience one of the following errors:
1. Got error when run netdiag on a DC:
DC list test . . . . . . . . . . . : Failed
Failed to enumerate DCs by using the browser. [ERROR_NO_BROWSER_SERVERS_
FOUND]

2. Got "conflict" netbios info when run "nbtstat -n

3. Got error when run "browstat status":
Status for domain LGSYDNEY on transport \Device\NetBT_Tcpip_{6F7C3E8B-4519-4BA6-
AF4B-B4BB15621181}
Browsing is NOT active on domain. Status : 6118
Master browser name is held by: SSFILE01
Master browser is running build 3790
Status for domain LGSYDNEY on transport \Device\NetBT_Tcpip_{1DB6AA0C-F123-4B47-
9B57-E2DC1530C31C}
Browsing is NOT active on domain. Status : 6118
Master name cannot be determined from GetAdapterStatus.

4. Error from the event log:
Event Type: Error
Event Source: Server
Event ID: 2505
Description:
The server could not bind to the transport \Device\NetBT_Tcpip_{E57CCD50-5575-4191-B19A-4D1C8083D98A} because another computer on the network has the same name. The server could not start.

5. Event Type: Warning
Event Source: MRxSmb
Event ID: 3033
Description:
The redirector was unable to register the address for transport NetBT_Tcpip_{E57CCD50-5575-4191-B19A-4D1C8083D98A} for the following reason: You were not connected because a duplicate name exists on the network. Go to System in Control Panel to change the computer name and try again. . Transport has been taken offline.

This problem typically caused by RAS running on a domain controller with DNS and WINS running it.
http://support.microsoft.com/kb/292822

Other reference articles:
http://support.microsoft.com/kb/135404
http://support.microsoft.com/default.aspx?scid=kb;en-us;818092

2008-11-05

Troubleshooting Kerberos Authentication problems – Name resolution issues

Troubleshooting Kerberos Authentication problems – Name resolution issues

http://blogs.technet.com/askds/archive/2008/05/14/troubleshooting-kerberos-authentication-problems-name-resolution-issues.aspx

PPTP VPN tracing

Problem: user cannot connect to the PPTP VPN server. Error message showing in system log of the VPN server:
"The user hasconnected and failed to authenticate on port VPN3-127. The line has beendisconnected."
Troubleshooting:
To enable RAS tracing on the VPN server: run " netsh ras set tr * en"
It will create a new folder: c:\windows\tracing
Then check the iassam log file from %windir%\tracing folder

To disable RAS tracing : netsh ras set tr * di