<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8266630769448616975</id><updated>2024-11-01T03:32:11.097-07:00</updated><category term="IIS 7"/><category term="DHCP"/><category term="FTP"/><category term="Fine Grained Password Policy"/><category term="Hyper-V"/><category term="IPSec"/><category term="IPv6"/><category term="RODC"/><category term="Routing"/><category term="SMTP"/><category term="SSL"/><category term="TS Network Load Balancing"/><category term="Terminal Service"/><category term="Windows Deployment Services"/><category term="gpresult"/><category term="loopback processing"/><title type='text'>Windows Networking</title><subtitle type='html'>Windows Server 2008</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-2358892515390121090</id><published>2010-03-15T06:37:00.000-07:00</published><updated>2010-03-15T06:37:19.668-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IPSec"/><title type='text'>IPSec</title><content type='html'>&lt;strong&gt;What is IPSec&lt;/strong&gt;&lt;br /&gt;
- IPSec is used to secure data sent between two computers&lt;br /&gt;
- IPSec not only keeps the data confidential through encyrption, but also ensures the authenticity of the data through mutual authentication.&lt;br /&gt;
- IPSec is a standard tht can be used between different platforms.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;IPSec Protocols&lt;/strong&gt;&lt;br /&gt;
- IPSec primarily uses two protocols&lt;br /&gt;
&amp;nbsp;&amp;nbsp; * Encapsulating Security Paiload (ESP)&lt;br /&gt;
&amp;nbsp;&amp;nbsp; * Authentication Header (AH)&lt;br /&gt;
- ESP is used for encryption for the payload&lt;br /&gt;
- AH is used for authentication of sending (and recieving) computer.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Tunnel Mode vs Transport Mode&lt;/strong&gt;&lt;br /&gt;
Tunnel Mode is used to secure data travelling between two gateways. Typicall this would be used if the gateways were connected via an unsecure network. This mode is very seldom used.&lt;br /&gt;
&lt;br /&gt;
Transport Mode is used to secure data between computers within a network. This is the default mode and is used most often.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Authentication Methods&lt;/strong&gt;&lt;br /&gt;
IPSec supports three authentication methods:&lt;br /&gt;
- Kerberos - used in AD environment&lt;br /&gt;
- Certificates - used when AD is not available or when stronger security is needed&lt;br /&gt;
- Preshared Key - should only be used in test environments.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Configuring IPSec in Server 2008&lt;/strong&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;Open Group Policy management editor&lt;br /&gt;
Windows settings &amp;gt; IP Security Policy &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-wkL__peRzNDDkyQKO-NMwVuyKnzXk2HNboVvOR7cC_78akgYZDf9QLUWIZr9-99Dc062_SEIuh4YpIdsBr30vaEcoEDkO-D6v7a5fi24U2vgoSBSnTXaylLDY-L84q23hyphenhypheniKE3SHkkV8/s1600-h/2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-wkL__peRzNDDkyQKO-NMwVuyKnzXk2HNboVvOR7cC_78akgYZDf9QLUWIZr9-99Dc062_SEIuh4YpIdsBr30vaEcoEDkO-D6v7a5fi24U2vgoSBSnTXaylLDY-L84q23hyphenhypheniKE3SHkkV8/s320/2.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;The 3 policy is not assigned.&lt;br /&gt;
&lt;span style=&quot;color: yellow;&quot;&gt;Client (Respond Only)&lt;/span&gt; means the clients are not going to initiate IPSec communication, because they typically dont have secure data to worry about.&lt;br /&gt;
If there is a server set with IPSec, Clients will communicate via IPSec&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: yellow;&quot;&gt;Server (Request Security)&lt;/span&gt; In this case any computer that has assigned this policy when it communicates with any other machine, it will make a request, hey i would like to communicate securely via ipsec and if other party is capable of communicating, then they will have secure communication. If other party is not capable of communicating via ipsec, then the server says, its ok, then we will communicate unsecurely anyway.&lt;br /&gt;
&lt;br /&gt;
If we have old windows 98 machineswhich doesnt support then we can implement IPSec policy&lt;br /&gt;
&lt;br /&gt;
Secure Server (Require Security). This means the server says, are you going to communicate with me? then its going to be IPSec or else cannot communicate. &lt;br /&gt;
&lt;br /&gt;
The way how to assign policy is, right click and assign, you can have one assigned at a time. &lt;br /&gt;
&lt;br /&gt;
How to Create New Policy&lt;br /&gt;
Right Click IPSec, Create New Policy&lt;br /&gt;
We create new Policy name Secure DNS Lookup, where anyone who is going to use DNS lookup thought this server they have to use this policy&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgz3Aq_Y0jKoLjAi1OZZu9EobtKlAyj29wOm8xoeeivc6zguWhHixfrXmudjuLFm8y4aHA-J1G1To3zo8Z7OoyxQ_nRAF2YhD4tnYGFQsOb6KR-o1A4Jv9FvDyUPY00flCAUUfscIckA3O/s1600-h/3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgz3Aq_Y0jKoLjAi1OZZu9EobtKlAyj29wOm8xoeeivc6zguWhHixfrXmudjuLFm8y4aHA-J1G1To3zo8Z7OoyxQ_nRAF2YhD4tnYGFQsOb6KR-o1A4Jv9FvDyUPY00flCAUUfscIckA3O/s320/3.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
Activate Default response rule means do you want to create a rule within this policy that is just a default response to any other IPSec requests. In other words for some reason you are trying to communicate with another computer, that has IPSec configured, maybe slightly different than this computer, do you want to ahead with that request by&amp;nbsp;default &amp;nbsp;and communicate securely? or you want to make it, its only done explicitly that you create a rule on this policy. Typically we would set it yes, so that if anyone have configured ipsec it will communicate securely&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4oSB1RohSquKP4NLPKu79AiFNbOOcA4IGVDyd8P7zGIDy-QyOFZdWvroQzW5bAYjEeoJanq-ucBMslQv-p43e1vR7CYXMzqhyQThqEtLR883a8Abcl6FlFU83vwJaEcEFI48aQP-eAbzl/s1600-h/4.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4oSB1RohSquKP4NLPKu79AiFNbOOcA4IGVDyd8P7zGIDy-QyOFZdWvroQzW5bAYjEeoJanq-ucBMslQv-p43e1vR7CYXMzqhyQThqEtLR883a8Abcl6FlFU83vwJaEcEFI48aQP-eAbzl/s320/4.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Authentication Method select Kerberos v5 because we dont have CA and finish the IPSec create policy wizard.&lt;br /&gt;
&lt;br /&gt;
Eventhough we have named the policy as Secure DNS lookup, we havent secured anything yet&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8JInoxWc3yEnXDJPK3QHhJgKSMUZN-vcZD6-IjEQSEasyuA3jtt4wYpMDZDBpldo0Cdivbgw8btWe-kLKSjCJ4sUBatLOyu9d8r0IJMXs-tlh3_dnjE9lW0qhqZY8m_5EZP45786zmNOO/s1600-h/5.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8JInoxWc3yEnXDJPK3QHhJgKSMUZN-vcZD6-IjEQSEasyuA3jtt4wYpMDZDBpldo0Cdivbgw8btWe-kLKSjCJ4sUBatLOyu9d8r0IJMXs-tlh3_dnjE9lW0qhqZY8m_5EZP45786zmNOO/s320/5.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
We have created the policy, now we need to create a rule, click Add and you get IPSec Rule wizard.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOoi8Ta6sd3YXeJ8Xw85eJKfsfvb2U8_QVIiXPoOegX8HFJk0f5D7-bd5sNH5kp0ItKb9I0YV-5ux-vRYiaNNCLVEApnM7a0el25-vYAlZK9qH7nP-RdrQhDpAKcjluclQ0uKrdc3rGVAV/s1600-h/6.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOoi8Ta6sd3YXeJ8Xw85eJKfsfvb2U8_QVIiXPoOegX8HFJk0f5D7-bd5sNH5kp0ItKb9I0YV-5ux-vRYiaNNCLVEApnM7a0el25-vYAlZK9qH7nP-RdrQhDpAKcjluclQ0uKrdc3rGVAV/s320/6.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
This rule does not specify tunnel&lt;br /&gt;
If you want tunelling, enter the ip address the computer on other side, select network type, &lt;br /&gt;
Add IP Filter List, &lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj97DRVhdT6oIBHMUcI_AWc8GA4cMiuOg-MLl4S4XzOO4I33YVRq65pI7ObE7Nc6Ainv39rWWlgSRkmEQnHGH6znZJXbu1TH5vnnUiT9oNms4JtegBWMeZltsFMKuTQ4xqt2Kmk8nGSyrr2/s1600-h/7.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj97DRVhdT6oIBHMUcI_AWc8GA4cMiuOg-MLl4S4XzOO4I33YVRq65pI7ObE7Nc6Ainv39rWWlgSRkmEQnHGH6znZJXbu1TH5vnnUiT9oNms4JtegBWMeZltsFMKuTQ4xqt2Kmk8nGSyrr2/s320/7.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Now click add to add specific filter&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGEStQaA5v8oKaHF1Idv4IOUTjlc040cApJI7PkmlkmOnikHyH-xGSDztr214DkGWvaLbJpOBacTHK4U37ZnUsIyCBgpS_RazplhOq577BRZ8rzL-pVIN-iOFvuP0TbNYhm3F_ED5wu6SU/s1600-h/8.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGEStQaA5v8oKaHF1Idv4IOUTjlc040cApJI7PkmlkmOnikHyH-xGSDztr214DkGWvaLbJpOBacTHK4U37ZnUsIyCBgpS_RazplhOq577BRZ8rzL-pVIN-iOFvuP0TbNYhm3F_ED5wu6SU/s320/8.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;if you are worried about specific type of traffic then tick&amp;nbsp; Mirrored Match packets with exact opposite source and destination address, click Next, Select &lt;br /&gt;
Source Adress =&amp;nbsp;Any &lt;br /&gt;
Destination = DNS Servers &lt;br /&gt;
Select Protocol = TCP &lt;br /&gt;
Port = 53&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYqQOLyjChM_HD-09znnbIsJU8RKflyXvgj0Ga5IOxJ1Pc5HCtcot7ac4m7r2S0cuWfUO0H9i3vTSIZTZnDRApsD96y5n7GgiSF7oJzkCFCv-GeIYYABI8FyDwiJrwVqIIn0BikOyS6pro/s1600-h/9.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYqQOLyjChM_HD-09znnbIsJU8RKflyXvgj0Ga5IOxJ1Pc5HCtcot7ac4m7r2S0cuWfUO0H9i3vTSIZTZnDRApsD96y5n7GgiSF7oJzkCFCv-GeIYYABI8FyDwiJrwVqIIn0BikOyS6pro/s320/9.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIhh2pZEUplTrXoT4NfFr6EtOY1-PqbdSO89bcj37ILos4NeR_Ub44QcCaNHA9G4Sc-JGSY1Dh7QGkO66meOjTMKoIhviHxYhFQo6YuWi4vMLp2Zm-6GH-ph8p1geffQMD0D3N3o7EimhF/s1600-h/10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIhh2pZEUplTrXoT4NfFr6EtOY1-PqbdSO89bcj37ILos4NeR_Ub44QcCaNHA9G4Sc-JGSY1Dh7QGkO66meOjTMKoIhviHxYhFQo6YuWi4vMLp2Zm-6GH-ph8p1geffQMD0D3N3o7EimhF/s320/10.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Filter Action&lt;br /&gt;
Permit = Non IPSec&lt;br /&gt;
Request Security = If no IPSec still the traffic will go ahead&lt;br /&gt;
Require Security = if no IPSec no traffic&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjY4IHV1aYWThhvEnsPurddtl43WXHlyE7P3958QR6Wjwj1E1ZKqmYcYyZPRAUkagJzmYVitJ0R26B1TXCLHcKIvKJXmaX-H2Y-dpF9CJrLUtJ8rCQF8W4IpzLqGtOzaoxqIQs30exV4nqT/s1600-h/11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjY4IHV1aYWThhvEnsPurddtl43WXHlyE7P3958QR6Wjwj1E1ZKqmYcYyZPRAUkagJzmYVitJ0R26B1TXCLHcKIvKJXmaX-H2Y-dpF9CJrLUtJ8rCQF8W4IpzLqGtOzaoxqIQs30exV4nqT/s320/11.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Select Authentication method as Kerberos, Finish</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/2358892515390121090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/ipsec.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/2358892515390121090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/2358892515390121090'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/ipsec.html' title='IPSec'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-wkL__peRzNDDkyQKO-NMwVuyKnzXk2HNboVvOR7cC_78akgYZDf9QLUWIZr9-99Dc062_SEIuh4YpIdsBr30vaEcoEDkO-D6v7a5fi24U2vgoSBSnTXaylLDY-L84q23hyphenhypheniKE3SHkkV8/s72-c/2.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-6808457637659061890</id><published>2010-03-15T03:35:00.000-07:00</published><updated>2010-03-15T03:35:43.858-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Routing"/><title type='text'>Setting up Routing</title><content type='html'>To Add routing, go to Server Roles Click Network Policy and Access Services&lt;br /&gt;
in Role Services click Routing and Remote Access Services&lt;br /&gt;
&lt;br /&gt;
To open go to Administrative Tools, Routing and Remote Access&lt;br /&gt;
Now right click server name, and Click Configure and Enable Routing and Remote Access&lt;br /&gt;
In the Wizard click Custom Configuration&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_nxaDanlj8pBYAsJXGoslUt_zshSFqNsUK66ExLnugSGPeyWSMJ2ab4lif6A554v41IJbxEFXkYmfxm9kdbGjT7xoy_RqNfrDB4jmaxAbX5HDBWDM2M-kXvP5Wt3YJwEGqM7EP3hAjOuV/s1600-h/15.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_nxaDanlj8pBYAsJXGoslUt_zshSFqNsUK66ExLnugSGPeyWSMJ2ab4lif6A554v41IJbxEFXkYmfxm9kdbGjT7xoy_RqNfrDB4jmaxAbX5HDBWDM2M-kXvP5Wt3YJwEGqM7EP3hAjOuV/s320/15.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;in Select Services tick LAN routing and click finish then start service&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmdEojiVSChT9W6bfMFZAg1hQAuY0fBhDjEH2gvR9-Pd5FlgJ6PFPAOKzmmYeQHtRHy67Ijy47ApGbbAboxh252VyQsaLjEMNx_gER7n6ypBppbDXrU4zJL-fkH-cTkO9UfTQlDqeaUtHp/s1600-h/8.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmdEojiVSChT9W6bfMFZAg1hQAuY0fBhDjEH2gvR9-Pd5FlgJ6PFPAOKzmmYeQHtRHy67Ijy47ApGbbAboxh252VyQsaLjEMNx_gER7n6ypBppbDXrU4zJL-fkH-cTkO9UfTQlDqeaUtHp/s320/8.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;now go IPv4, and in general section you will see 2 network interface with&amp;nbsp;2 ip ranges&lt;br /&gt;
now this server is fully confiugred routing enabled. the 2 networks 192.168.11 and 192.168.10 will be able to talk each other.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNsq-IIyPmembzSGvpcI-6duCsESJFT5lCIyfRwh0EI0GB_GmBwRB9z8fAgD4fQVSh8NLkniRsKci4iprnTAmvcQmKHaJBzn-ao5rNYnFtWWut3W5chWtY7gMn8rLlmOz4R5mYmvUoJyA9/s1600-h/9.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNsq-IIyPmembzSGvpcI-6duCsESJFT5lCIyfRwh0EI0GB_GmBwRB9z8fAgD4fQVSh8NLkniRsKci4iprnTAmvcQmKHaJBzn-ao5rNYnFtWWut3W5chWtY7gMn8rLlmOz4R5mYmvUoJyA9/s320/9.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;On-Link means directly connected, dont have to go through another router.&lt;br /&gt;
&lt;br /&gt;
Metric is needed if there are more than one way to get into a single destination, metric will help the router to determine which way to try first, whichever destination have lower value will try first. &lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: lime;&quot;&gt;route add 192.168.15.0 mask 255.255.255.0 192.168.15.100&lt;/span&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhWmswHV8U6sWNKZe8issZeBND-zlHz14y65wr0b-nTR48ALIwvU0uXC5hQVyGDnPkQxYn35op6dQBieOS0ugck2g6BaUZJQRZ-zqKj2WvdALg01LTURRmZxvF9sm00-vQBnLhaIrQEaPt3/s1600-h/9.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhWmswHV8U6sWNKZe8issZeBND-zlHz14y65wr0b-nTR48ALIwvU0uXC5hQVyGDnPkQxYn35op6dQBieOS0ugck2g6BaUZJQRZ-zqKj2WvdALg01LTURRmZxvF9sm00-vQBnLhaIrQEaPt3/s320/9.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;now check the routing table, this time instead of On-link it says 192.168.15.100 because im not connected to 192.168.15 network. so its going to send it to another router or another gateway which has ip address of 192.168.15.100 and the system will determine which interface its goin out, in this case its going out with 192.168.10.100 interface and the reason why is because &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgj3fmkvOuidS6foe1bn8MDKvKKeXladMhgIczeFVwmvNy0GMyKN-3F-XcLW4_mvILMrPs3bWYHHG6RyA78aqPc4UT3BEa2MiImJ02JbhmGL1cdntJjz_ezaW1_BQclQC96foQ9WkPeNf3I/s1600-h/10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgj3fmkvOuidS6foe1bn8MDKvKKeXladMhgIczeFVwmvNy0GMyKN-3F-XcLW4_mvILMrPs3bWYHHG6RyA78aqPc4UT3BEa2MiImJ02JbhmGL1cdntJjz_ezaW1_BQclQC96foQ9WkPeNf3I/s320/10.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;the 10 network has a default gateway, and the 11 network does not. and what that means is if i get an ip address that i dont know where it is suppose to go, then i will send it to my default gateway. &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGEIDFhyWfDfD62YxyBweR3yXnMDbrlphDyeOUYMk1I7lzzkythyphenhyphenKTsi6CUHR_9qVancQVYUegEqmHfaqby_9gbLDgQ9DnBrwiVYYzeoUyc4CnufWn2QOyYWehWTNEGILqJhJM-wL1PYI2/s1600-h/11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGEIDFhyWfDfD62YxyBweR3yXnMDbrlphDyeOUYMk1I7lzzkythyphenhyphenKTsi6CUHR_9qVancQVYUegEqmHfaqby_9gbLDgQ9DnBrwiVYYzeoUyc4CnufWn2QOyYWehWTNEGILqJhJM-wL1PYI2/s320/11.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;when adding static route from GUI we have the capablity to manually select which network interface that we want to send the packet out.&lt;br /&gt;
&lt;br /&gt;
when adding static route in GUI the route doesnt show in IP routing table and in route print. This is the reason why it is not user friendly to add the route in GUI.&lt;br /&gt;
&lt;br /&gt;
To delete a route&lt;br /&gt;
route delete 192.168.15.0&lt;br /&gt;
&lt;br /&gt;
Inbound and Outbound filters&lt;br /&gt;
in IPv4, right click general and go properties&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLJu1ZrDuQDuebiG8pDIGzFintEqwdJIJlKvhdCWgIZAie2sZbf7CYFotAxgfOSpPh1EA-icqM1RBrGsdD7bAD4I4sVBDs82-kHH3kH7N5cZW9mZlzvPDtJixaEgbJcRfH0KdhqIT-ogVj/s1600-h/12.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLJu1ZrDuQDuebiG8pDIGzFintEqwdJIJlKvhdCWgIZAie2sZbf7CYFotAxgfOSpPh1EA-icqM1RBrGsdD7bAD4I4sVBDs82-kHH3kH7N5cZW9mZlzvPDtJixaEgbJcRfH0KdhqIT-ogVj/s320/12.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
what you can do with this filters is we can control what traffic can come into the router and can go out of this router.&lt;br /&gt;
&lt;br /&gt;
Click Inbound filter, click New&lt;br /&gt;
i want to say if anyone coming in from 192.168.15.0 255.255.255.0&lt;br /&gt;
or by specific ip address 192.168.15.243/255.255.255.255 (put 255 in all 4 places, that means one computer) &lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBeSMboFMwONcti9uyDO6Oj_PK5m5nah436PSbcDS0lB8E-CgM-xzQfAXHOkBgcpVldY9urGvsnp_eVMDXWrpfXtxH12uWOHcF5NzQzUYhozEcMEOMbrSSxkTzL2arElEyKGcY3f8wPHep/s1600-h/13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBeSMboFMwONcti9uyDO6Oj_PK5m5nah436PSbcDS0lB8E-CgM-xzQfAXHOkBgcpVldY9urGvsnp_eVMDXWrpfXtxH12uWOHcF5NzQzUYhozEcMEOMbrSSxkTzL2arElEyKGcY3f8wPHep/s320/13.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;now if 192.168.15.243 try to go through this router, it wont because we have filter to recieve all traffics except 192.168.15.243&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUWqeXDQsyG6pup56SSla_gpPMftIyL65tXqKmnUhZgkepA6b_de7Y3Vimx78wsHGvXY_O4CbgdpegIycUh8k1bvWpBAxE_2Xr8rN4eAMovmNLNNQAaKedhf92gCEuP0akX2jODvk31cIs/s1600-h/14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUWqeXDQsyG6pup56SSla_gpPMftIyL65tXqKmnUhZgkepA6b_de7Y3Vimx78wsHGvXY_O4CbgdpegIycUh8k1bvWpBAxE_2Xr8rN4eAMovmNLNNQAaKedhf92gCEuP0akX2jODvk31cIs/s320/14.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;now we are saying if 192.168.15.243 came in and was looking for any computer in 192.168.16.0 network then we are not going to allow it. &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Static vs Dynamic Routing&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;em&gt;Static Routing&lt;/em&gt;&lt;/strong&gt; - All routers have their routing table configured and updated manually&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;em&gt;Dynamic Routing&lt;/em&gt;&lt;/strong&gt; - Routers communicate with each other to share their routing information with each other.</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/6808457637659061890/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/setting-up-routing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/6808457637659061890'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/6808457637659061890'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/setting-up-routing.html' title='Setting up Routing'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_nxaDanlj8pBYAsJXGoslUt_zshSFqNsUK66ExLnugSGPeyWSMJ2ab4lif6A554v41IJbxEFXkYmfxm9kdbGjT7xoy_RqNfrDB4jmaxAbX5HDBWDM2M-kXvP5Wt3YJwEGqM7EP3hAjOuV/s72-c/15.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-5406293837223522230</id><published>2010-03-15T00:54:00.000-07:00</published><updated>2010-03-15T00:54:01.343-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DHCP"/><title type='text'>Managing DHCP</title><content type='html'>Open DHCP console&lt;br /&gt;
Right click DHCP server name, and click Add/Remove Bindings and it will open a window showing all the&lt;br /&gt;
network connections or networks that this server is connected to. This gives us the opportunity to let the server know which networks we want to provide DHCP services to. &lt;br /&gt;
In this following example the dhcp server is set to service to 192.168.10 network&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSjxspOnBNz9VqxF1pxKCVHt2Y5tc8U_HL7Ny4krmbm4xloYcZNphoC8qvhSBbj3M-kFk_9FU_BKMB2skOdERWClf-G0Sa7Ffj9n5mGinJFcpnCZ0MJpxRaoWi2E2rUAfZ2hS9peWjh8Qg/s1600-h/1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSjxspOnBNz9VqxF1pxKCVHt2Y5tc8U_HL7Ny4krmbm4xloYcZNphoC8qvhSBbj3M-kFk_9FU_BKMB2skOdERWClf-G0Sa7Ffj9n5mGinJFcpnCZ0MJpxRaoWi2E2rUAfZ2hS9peWjh8Qg/s320/1.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
to locate where the dhcp database is stored, right click and go properties&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiomV6XM9HpnjWe0MtxeuPf7-klZzuOvCHGqe_IA0Dn8b74W-nXQZ81c3TTOgMTIrQW3QY7GMlw-bOQLniSMdYaIIOIJim1U5c83sUTUwgt_GazWHBj3pZAcAOWMAr56iQPrwf8Sa3nHjMz/s1600-h/2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiomV6XM9HpnjWe0MtxeuPf7-klZzuOvCHGqe_IA0Dn8b74W-nXQZ81c3TTOgMTIrQW3QY7GMlw-bOQLniSMdYaIIOIJim1U5c83sUTUwgt_GazWHBj3pZAcAOWMAr56iQPrwf8Sa3nHjMz/s320/2.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
open the database path&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG-GgovEPykJoxj4XxqhlWA2_MFojiYQ0j3osWs27RVp6DZDtNq-uhQIvyn0mOa_JeQN8Lh5U9E779G576i8zKnOCc1FMIfi7c5jtwJQqkphCfhdeLhKabRUNK9xHUp9UWmGZt2qw7AzB6/s1600-h/3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG-GgovEPykJoxj4XxqhlWA2_MFojiYQ0j3osWs27RVp6DZDtNq-uhQIvyn0mOa_JeQN8Lh5U9E779G576i8zKnOCc1FMIfi7c5jtwJQqkphCfhdeLhKabRUNK9xHUp9UWmGZt2qw7AzB6/s320/3.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;dhcp.mdb file is the actualy dhcp database file&lt;br /&gt;
and the highlighted are dhcp logs and the rest of the files are supporting files to the database.&lt;br /&gt;
&lt;br /&gt;
open backup and new folder, you would see another dhcp.mdb file which is the back up file.&lt;br /&gt;
&lt;br /&gt;
DHCP server automatically backs itself up once in a hour, it essentially resorts itself it occurs a failure.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpVH9_yucDtE29SRzknpPMGmpSxQh5AEXVirlHgxY0xC-i1FNzkDCNhq_1WD7hKH4jIRexjQ335_aitrW1lyNF29R6Awyx44x5pmY256iYRHZneLqChzAjt9TU-IA7W30wjdP94O23mWLY/s1600-h/4.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpVH9_yucDtE29SRzknpPMGmpSxQh5AEXVirlHgxY0xC-i1FNzkDCNhq_1WD7hKH4jIRexjQ335_aitrW1lyNF29R6Awyx44x5pmY256iYRHZneLqChzAjt9TU-IA7W30wjdP94O23mWLY/s320/4.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style=&quot;color: cyan;&quot;&gt;Nacks &lt;/span&gt;= Negetive Acknowledgement which is where dhcp server refuses requests made by a client &lt;br /&gt;
&lt;span style=&quot;color: cyan;&quot;&gt;Declines&lt;/span&gt; = Client specifically refusing a offer from a dhcp server&lt;br /&gt;
&lt;span style=&quot;color: cyan;&quot;&gt;Release&lt;/span&gt; = a client has requested dhcp server that i want to release this ip addresses, i want to release this lease back to you&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjUBGDlWgX8dWDL6nijhJToJkqsWfn1SlTmDovEbbL32N5XeMpM_GcwJQ9few8wzq8_oYBVv_e-jCoae_nZmWZDLpmtakz65Ov6DoDD35Qtmkwbbmmzd-veSNQ8NDBgZNNXiMuTEYURfWWv/s1600-h/5.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjUBGDlWgX8dWDL6nijhJToJkqsWfn1SlTmDovEbbL32N5XeMpM_GcwJQ9few8wzq8_oYBVv_e-jCoae_nZmWZDLpmtakz65Ov6DoDD35Qtmkwbbmmzd-veSNQ8NDBgZNNXiMuTEYURfWWv/s320/5.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Conflict detection attempts, the default 0 means that there is no conflict detection on dhcp server. if you set it to 1, what dhcp server will do is, everytime when its going to handout an ip address first thing its going to do is ping to the ip address to see if it gets a response. if it does get a ip address then it will move to a different ip address to give out to the client. if it did not get response that means that ip address is not in use. disadvantage of this is it will delay the handout of an ip address. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/5406293837223522230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/managing-dhcp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/5406293837223522230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/5406293837223522230'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/managing-dhcp.html' title='Managing DHCP'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSjxspOnBNz9VqxF1pxKCVHt2Y5tc8U_HL7Ny4krmbm4xloYcZNphoC8qvhSBbj3M-kFk_9FU_BKMB2skOdERWClf-G0Sa7Ffj9n5mGinJFcpnCZ0MJpxRaoWi2E2rUAfZ2hS9peWjh8Qg/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-1490066510412929583</id><published>2010-03-14T09:10:00.000-07:00</published><updated>2010-03-14T09:10:43.976-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IPv6"/><title type='text'>Fundamentals of IPv6</title><content type='html'>Disadvantages of IPv4&lt;br /&gt;
- Not enough Addresses&lt;br /&gt;
- Cluttered the Internet Routing Tables&lt;br /&gt;
- Difficult to Configure&lt;br /&gt;
- Security was Optional (ipsec is optional)&lt;br /&gt;
&lt;br /&gt;
IPv6 Solutions&lt;br /&gt;
- Plenty of Addresses (3.4 x 10 Power 38)&lt;br /&gt;
- Simplified the Internet Routing Tables&lt;br /&gt;
- Easy and Automated Configuration &lt;br /&gt;
- Security is Required (ipsec is required, not optional)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmZUvtBmOY6FadM2KcxH7Gsy4IAhlVj63G1uVUB2wcUe32B6OC_sCyd0WY-1KKsHAOesTXw-S6n67jVpLw1sFqnMTvwqPqKuIH3mi_10P9rBiaigwunlVsbfb9Oxm-Qti8a2iyl76H6By5/s1600-h/5.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmZUvtBmOY6FadM2KcxH7Gsy4IAhlVj63G1uVUB2wcUe32B6OC_sCyd0WY-1KKsHAOesTXw-S6n67jVpLw1sFqnMTvwqPqKuIH3mi_10P9rBiaigwunlVsbfb9Oxm-Qti8a2iyl76H6By5/s320/5.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
in IPv6 all addresses are 128 bits long&lt;br /&gt;
128 bits is too long to look at, so what we are going to do is we will take 128 bit and devide them into 16 bit chunks, then take those 16 bit chunks and convert them into hexadecimal number which gives a ip address which looks like FE80:0000:00000:0000000:05EE:00FF:0238:47B1, and here we end up with 8 hexadecimal numbers seperated by colons&lt;br /&gt;
&lt;br /&gt;
we can further simplify this by supressing the leading zeros&lt;br /&gt;
&amp;nbsp;for example in real world, 0049 you would simply say it as 49, this concept is true with hexadecimal numbering as well.&lt;br /&gt;
Example : FE80:0000:00000:0000000:&lt;span style=&quot;color: red;&quot;&gt;0&lt;/span&gt;5EE:&lt;span style=&quot;color: red;&quot;&gt;00&lt;/span&gt;FF:&lt;span style=&quot;color: red;&quot;&gt;0&lt;/span&gt;238:47B1&lt;br /&gt;
and endup with FE80:0:0:0:5EE:FF:238:47B1&lt;br /&gt;
&lt;br /&gt;
Further compress by expressing a single congiguous set of 0 blocks into &quot;::&quot;&lt;br /&gt;
&lt;br /&gt;
FE80:&lt;span style=&quot;color: red;&quot;&gt;0:0:0&lt;/span&gt;:5EE:FF:238:47B1&lt;br /&gt;
&lt;br /&gt;
Here we have 3 zeros, what we can do is we can take that and turn that into double colon :: to represent those zeros and we endup with &lt;strong&gt;&lt;span style=&quot;color: blue;&quot;&gt;FE80::5EE:FF:238:47B1&lt;/span&gt;&lt;/strong&gt; which is our final ip address version 6&lt;br /&gt;
&lt;br /&gt;
this is still difficult to understand, ipv6 is not designed for an average person to understand, ipv6 is designed with simpicity and the only people who needs to understands are network administrators.&lt;br /&gt;
&lt;br /&gt;
In ipv6 there are 3 different types of addresses&lt;br /&gt;
*&amp;nbsp;Unicast (one to one)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- Global Address&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Link-Local Addresses&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Unique Local Addresses&lt;br /&gt;
* Multicast (one to many)&lt;br /&gt;
* Anycast (one to one of many)&lt;br /&gt;
&lt;br /&gt;
Global addresses are address which are set to be available on the internet, these will be recorganize by internet routers. &lt;br /&gt;
&lt;br /&gt;
Link-Local address will always start with &lt;span style=&quot;color: #38761d;&quot;&gt;&lt;strong&gt;FE80&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;
Unique Local Address will always start either &lt;span style=&quot;color: #6aa84f;&quot;&gt;FC&lt;/span&gt; or&lt;span style=&quot;color: #6aa84f;&quot;&gt; FD&lt;/span&gt;, if you see address start with FC or FD its a local address and is not valid on the internet.</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/1490066510412929583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/fundamentals-of-ipv6.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/1490066510412929583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/1490066510412929583'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/fundamentals-of-ipv6.html' title='Fundamentals of IPv6'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmZUvtBmOY6FadM2KcxH7Gsy4IAhlVj63G1uVUB2wcUe32B6OC_sCyd0WY-1KKsHAOesTXw-S6n67jVpLw1sFqnMTvwqPqKuIH3mi_10P9rBiaigwunlVsbfb9Oxm-Qti8a2iyl76H6By5/s72-c/5.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-5265474279061094385</id><published>2010-03-14T07:37:00.000-07:00</published><updated>2010-03-14T07:49:05.749-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="SSL"/><title type='text'>Implementing SSL for IIS 7</title><content type='html'>Secure Socket Layer (SS) allows you to encrypt data sent back and forth from servers to clients.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_0ChBAreG3ESSJn5ekGPGRT5QYL8lCOKFJwvZthLdOy1wJqowbQextdDocsMGUKJN5sw0ytPyIx-4nLeK5Xb3gpeGDP2ZEs7AnT0RdZ9LhrgBDda7Nix_n-_UOefwj2jr4cIWj1k4Z6C7/s1600-h/1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_0ChBAreG3ESSJn5ekGPGRT5QYL8lCOKFJwvZthLdOy1wJqowbQextdDocsMGUKJN5sw0ytPyIx-4nLeK5Xb3gpeGDP2ZEs7AnT0RdZ9LhrgBDda7Nix_n-_UOefwj2jr4cIWj1k4Z6C7/s320/1.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;What this does is encrypt data send back and forth from servers to clients.&lt;br /&gt;
SSL uses port 443&lt;br /&gt;
Data being sent back and forth between the server and client is encrypted using certificates.&lt;br /&gt;
Using SSL does require more processing overhead for encryption and decryption, and may reduce the apprearance of the speed of the server.&lt;br /&gt;
&lt;br /&gt;
To implement SSL, first we need a SSL Certificate&lt;br /&gt;
You can &lt;br /&gt;
- Buy one from third party&lt;br /&gt;
- Use a self-signed certificate from server&lt;br /&gt;
- User a certificate generated from server 2008 / server 2003 certificate authority&lt;br /&gt;
- Use the sharepoint certificate that was generated during sharepoint configuration.&lt;br /&gt;
&lt;br /&gt;
Then we need to install the certificate&lt;br /&gt;
After that we need to set a binding for the sharepoint site so that it can use HTTPS and port 443&lt;br /&gt;
Then instruct the users to access the sharepoint -80 site using https:// instead of http://&lt;br /&gt;
&lt;br /&gt;
To create SSL certificate, go to IIS Manager / Server Certificates&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijy-vTWxwP8A2QxZO-53WhnqLaNQVi_mUhRi_UKaFn8Ki5h_u3eTJpxE03xXSKleDAzRYO76n-KKvttA4V182Ajaxg4NcxbsMT93sMyi_0I9_Y4sIHKXC-gy6G4Vb77DVCyRIcErsS7KQ1/s1600-h/2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijy-vTWxwP8A2QxZO-53WhnqLaNQVi_mUhRi_UKaFn8Ki5h_u3eTJpxE03xXSKleDAzRYO76n-KKvttA4V182Ajaxg4NcxbsMT93sMyi_0I9_Y4sIHKXC-gy6G4Vb77DVCyRIcErsS7KQ1/s320/2.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
To enable SSL on SharePoint and select Edit Binding&lt;br /&gt;
Click Add https, Port 443, and select SSL from the drop down box&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiB-PfJ0NDy09uTXkg2ZTezPSv53nSBYPy9Y_FJBMoEEbdT7mo7HgdDLaAWa_yOmn-9w8udwRo11x6l4Zf-LbYWuvjUnnRKXJO_bAZhRd_C9f47uFaT6tarDs2_AjPE30ZDB5o0ZWK8t5-j/s1600-h/3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiB-PfJ0NDy09uTXkg2ZTezPSv53nSBYPy9Y_FJBMoEEbdT7mo7HgdDLaAWa_yOmn-9w8udwRo11x6l4Zf-LbYWuvjUnnRKXJO_bAZhRd_C9f47uFaT6tarDs2_AjPE30ZDB5o0ZWK8t5-j/s320/3.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Create Internal URLs&lt;br /&gt;
Go to Central Administration / Opertions / Alternate Access Mappings / Add Internal URLs&lt;br /&gt;
in Alternate Access Mapping Collection Select SharePoint - 80&lt;br /&gt;
URL, put &lt;a href=&quot;https://web1-globo/&quot;&gt;https://web1-globo/&lt;/a&gt;&lt;br /&gt;
Zone select Intranet&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJ4y-UnKQ9LxJPI7EA2UBHFsdnvghi4LO2qkVLsLD70EL95eXbrdOWgEJlCfm2yMJ_8R1Ydr0_vmYAm694qumCn5zUdhJffiGjYHJLI9CPrrp3xTbhyphenhyphenej9YRZvLqKcGpGxsI5AK7vHUtGD/s1600-h/4.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJ4y-UnKQ9LxJPI7EA2UBHFsdnvghi4LO2qkVLsLD70EL95eXbrdOWgEJlCfm2yMJ_8R1Ydr0_vmYAm694qumCn5zUdhJffiGjYHJLI9CPrrp3xTbhyphenhyphenej9YRZvLqKcGpGxsI5AK7vHUtGD/s320/4.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/5265474279061094385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/implementing-ssl-for-iis-7.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/5265474279061094385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/5265474279061094385'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/implementing-ssl-for-iis-7.html' title='Implementing SSL for IIS 7'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_0ChBAreG3ESSJn5ekGPGRT5QYL8lCOKFJwvZthLdOy1wJqowbQextdDocsMGUKJN5sw0ytPyIx-4nLeK5Xb3gpeGDP2ZEs7AnT0RdZ9LhrgBDda7Nix_n-_UOefwj2jr4cIWj1k4Z6C7/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-172090231021151903</id><published>2010-03-14T05:14:00.000-07:00</published><updated>2010-03-14T05:20:05.073-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="FTP"/><category scheme="http://www.blogger.com/atom/ns#" term="IIS 7"/><category scheme="http://www.blogger.com/atom/ns#" term="SMTP"/><title type='text'>Install IIS 7 FTP SMTP</title><content type='html'>Controlling Access to a Web Site with IIS 7 manager and FTP Tools&lt;br /&gt;
&lt;br /&gt;
Scenario&lt;br /&gt;
Globomantics hired a developer to customize sharepoint. We have already created sharepoint site, now we need to allow management access to that site to the developer.&lt;br /&gt;
&lt;br /&gt;
So what do we need to do?&lt;br /&gt;
&lt;br /&gt;
1. You&#39;ll enable remote Management in IIS 7 and IIS Manager Credentials&lt;br /&gt;
2. You&#39;ll create an IIS Manager User account for our developer&lt;br /&gt;
3. You&#39;ll then provide specific access for the sharepoint site to your developer&#39;s account&lt;br /&gt;
4. Last, we&#39;ll provide FTP access for our developer for easy access to the file folders for the site.&lt;br /&gt;
&lt;br /&gt;
To create user account, goto IIS Manager&lt;br /&gt;
Enable Remote connections&lt;br /&gt;
User Windows credentials or IIS Manager credentials, click apply&lt;br /&gt;
&lt;br /&gt;
Now you will notice management service is stopped, click start to start management service&lt;br /&gt;
&lt;br /&gt;
Go back to IIS Manager&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3LtgpULFWH7vozm8sEQmJYsN_E8zDRQyRy-BQxvdc7rW6TRx09u20dYUmLhraRo6Jahy7v63deeC1QSXFRdpi0s7gpbHI7f_0GUyNc63NaGizlFadsxtxSGxSFcknqzMjL8jXfe0Mgs33/s1600-h/1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3LtgpULFWH7vozm8sEQmJYsN_E8zDRQyRy-BQxvdc7rW6TRx09u20dYUmLhraRo6Jahy7v63deeC1QSXFRdpi0s7gpbHI7f_0GUyNc63NaGizlFadsxtxSGxSFcknqzMjL8jXfe0Mgs33/s320/1.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;double click IIS Manager Users, add user&lt;br /&gt;
&lt;br /&gt;
Now go to Sites / Sharepoint - 80&lt;br /&gt;
go to IIS Manager Permissions, we are going to allow persmission for our developer to access only this particular website&lt;br /&gt;
click allow users, select IIS Manager and select user&lt;br /&gt;
&lt;br /&gt;
so far what we have done is, &lt;br /&gt;
we have enabled remote management&lt;br /&gt;
we have created IIS user account for developer&lt;br /&gt;
and also we have given access to developer only for sharepoint site.&lt;br /&gt;
&lt;br /&gt;
If you want to allow developer to Sharepoint central administration page, &lt;br /&gt;
go IIS Manager permissions and add user&lt;br /&gt;
&lt;br /&gt;
Now we need to add IIS Manager client to vista and connect to sharepoint server&lt;br /&gt;
&lt;br /&gt;
Before we install IIS Manager client, go control panel from vista client&lt;br /&gt;
program and features, Turn on windows features, and turn on IIS Management Console&lt;br /&gt;
&lt;br /&gt;
now go to iis.net/downloads&lt;br /&gt;
and dowlnoad IIS 7.0 Manager for Remote Administration&lt;br /&gt;
Now in programs open IIS Manager in client machine&lt;br /&gt;
&lt;br /&gt;
We have enable the developer to connect only to sharepoint site. there for click connect to a site&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinjn6mIEVEIt2ZFx08GRPJA6beUIFJrzMELZHXYoxGsct1MAHqJPPSxfYmaOVVQGoeIInzGO8edwWTstYNa_Io8JWRual-n18N9fvgerXsu5_k66UlH7OEcAiP-iYyDss3Ksfj70VAPRhA/s1600-h/2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinjn6mIEVEIt2ZFx08GRPJA6beUIFJrzMELZHXYoxGsct1MAHqJPPSxfYmaOVVQGoeIInzGO8edwWTstYNa_Io8JWRual-n18N9fvgerXsu5_k66UlH7OEcAiP-iYyDss3Ksfj70VAPRhA/s320/2.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7DvhdpP7Me_jO-zCIrF-qUeQfwh495lP1scCJ0YocyVm9oB2BWNbBoWmYSrB0FG4EmZktfubPMMsOcKUr7IVw64rXq8b7EMoVWeVAthG_X3EWAXefyOE6tnq9dBj4bBuAv_vXy9MdFi8z/s1600-h/3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7DvhdpP7Me_jO-zCIrF-qUeQfwh495lP1scCJ0YocyVm9oB2BWNbBoWmYSrB0FG4EmZktfubPMMsOcKUr7IVw64rXq8b7EMoVWeVAthG_X3EWAXefyOE6tnq9dBj4bBuAv_vXy9MdFi8z/s320/3.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;Go next and put sharepoint developer username and password&lt;br /&gt;
Click Install Certificate and then connect&lt;br /&gt;
&lt;br /&gt;
Setup FTP&lt;br /&gt;
FTP is a role service, optional part of IIS&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPIWgOr1lqaeJ_sbt76DZG3e-xnsBLXn0VMEr10hNapV49NC-2g0QuCovtTLd1F0RPRjoBN-8nvxUMVxdzR7KXgJuXFiGsr-59I6GzH-40MOnYJR0NIZoIBKiEfvfEcJmkldp-fo6HHVsQ/s1600-h/4.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPIWgOr1lqaeJ_sbt76DZG3e-xnsBLXn0VMEr10hNapV49NC-2g0QuCovtTLd1F0RPRjoBN-8nvxUMVxdzR7KXgJuXFiGsr-59I6GzH-40MOnYJR0NIZoIBKiEfvfEcJmkldp-fo6HHVsQ/s320/4.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;You&#39;ll need to neable FTP for IIS, but you&#39;ll also need to restrict FTP access only for your&lt;br /&gt;
web developer as well. we will need to allow where he can put stuff, so that he cannot put files whereever he wants.&lt;br /&gt;
&lt;br /&gt;
FTP Management Console provides infrastructure to manage an FTP site. IIS 7 uses IIS 6 managment console for FTP server management.&lt;br /&gt;
&lt;br /&gt;
No go to Administrative Tools, IIS 6.0 Manager&lt;br /&gt;
Go to Default FTP Site and start&lt;br /&gt;
Right click Default FTP Site / Properties&lt;br /&gt;
First change the name to SharePointFTP&lt;br /&gt;
&lt;br /&gt;
Go to Security Accounts Tab&lt;br /&gt;
Turn Off anonymous connections. this means a user needs to have a very specific access to acces this FTP server&lt;br /&gt;
&lt;br /&gt;
Go to Home Directory Tab, we can allow which folders that developer can access to.&lt;br /&gt;
&lt;br /&gt;
Browse folder, and you will see wss is the folder created when installing sharepoint&lt;br /&gt;
folder 80 is default sharepoint site, and 14453 is administration site.&lt;br /&gt;
we will give developer to access wss folder&lt;br /&gt;
we will need to give read access as well as write access&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiOi7rnLoKwVuojTZfBA-8qfhreLK7y9ZC2kc4pZtjhLqr4h0GUcgMtNey_uPEcFZxO6yvCilxrfRxDuc4KlZcX4jWKuVzB662J3TthwgbZC0RX4aZoxyGEN0Ipr1Mq19AEanHh5k_pnKs/s1600-h/5.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiOi7rnLoKwVuojTZfBA-8qfhreLK7y9ZC2kc4pZtjhLqr4h0GUcgMtNey_uPEcFZxO6yvCilxrfRxDuc4KlZcX4jWKuVzB662J3TthwgbZC0RX4aZoxyGEN0Ipr1Mq19AEanHh5k_pnKs/s320/5.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Go to Directory Security Tab&lt;br /&gt;
We can give access based upon IP address&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ4QcgEJ_gs_nK2Lr3Z_yOZ9ntD_0NifuoltjzComa40GF4UFpdoBSOU7m4TGg9CowTcc3ETgZaWM6ImsSWH4J_FoBDdBxNxNcsmrmOrpx4fWj55YQyX83hWmsv5ErE91T1mudt1FDNc4A/s1600-h/6.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ4QcgEJ_gs_nK2Lr3Z_yOZ9ntD_0NifuoltjzComa40GF4UFpdoBSOU7m4TGg9CowTcc3ETgZaWM6ImsSWH4J_FoBDdBxNxNcsmrmOrpx4fWj55YQyX83hWmsv5ErE91T1mudt1FDNc4A/s320/6.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Except 192.168.5.128 all computers are denied access to ftp site.&lt;br /&gt;
&lt;br /&gt;
Now we need give permissions to web developer to sharepoint site&lt;br /&gt;
right click SharePointFTP / permissions and add web developer&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7IKmQ_z7pcMuu3Z0-s9S_i2sIKrLoN9oH_8pjjSMtelGDtmmQhf16Fl7CedR82MthYS0fDdqE8rzbGLpfw53Tmb3ZUx1-xxjm5aZlEEtIPgSR-nyxLgjt_octo7IAQ4yofKBCod2yu1jX/s1600-h/7.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7IKmQ_z7pcMuu3Z0-s9S_i2sIKrLoN9oH_8pjjSMtelGDtmmQhf16Fl7CedR82MthYS0fDdqE8rzbGLpfw53Tmb3ZUx1-xxjm5aZlEEtIPgSR-nyxLgjt_octo7IAQ4yofKBCod2yu1jX/s320/7.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Now we need to test FTP&lt;br /&gt;
&lt;br /&gt;
In client PC use command line ftp&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgALHvtsg_KBghsPM7BHOI0q9kO_pdZjaueuehkiC26vF-arTUqbRpCtfWhlzqHDDaELzxauV60ijz7SAFxwLH_iC4qgZVqi7o7_NB5yknqEkWYDWoHGFzG1S4Kt9t-I2zwD9d78CfXm9RC/s1600-h/8.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgALHvtsg_KBghsPM7BHOI0q9kO_pdZjaueuehkiC26vF-arTUqbRpCtfWhlzqHDDaELzxauV60ijz7SAFxwLH_iC4qgZVqi7o7_NB5yknqEkWYDWoHGFzG1S4Kt9t-I2zwD9d78CfXm9RC/s320/8.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;We can login using web developer user account, but we cannot login annonymously&lt;br /&gt;
&lt;br /&gt;
We can use secure FTP by installing FTP for IIS 7&lt;br /&gt;
To do that we need to uninstall old FTP&lt;br /&gt;
Download and install Microsoft FTP Publishing Service for IIS 7&lt;br /&gt;
&lt;br /&gt;
Configure SMTP&lt;br /&gt;
Developer requests SMTP be installed and configured on sharepoint on the webserver for email alerts delivdered to users.&lt;br /&gt;
SMTP server is a feature that needs to be installed on the web server then also configured seperately on sharepoint site.&lt;br /&gt;
&lt;br /&gt;
To install SMTP go to&lt;br /&gt;
Server Manager / Features / Add Features / Tick SMTP Server and Add Required Features&lt;br /&gt;
Click Next and Install&lt;br /&gt;
&lt;br /&gt;
Open IIS Manager 6, ane expand you will see SMTP Virtual Server&lt;br /&gt;
&lt;br /&gt;
Now check with IIS that SMTP is available&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGd1i_oDFZrQQXt-T7RYFY_Q7SLcNS_YyLklku_la8l4LNcBi9UpWFCwqv3JYMmdfcgksUvSBOXdRrmUP9lu9oQwsVnGsIyMWausGBvj9aL5g8jhDYh43t7s98zUtrAf_NC2HwtonALSrs/s1600-h/9.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGd1i_oDFZrQQXt-T7RYFY_Q7SLcNS_YyLklku_la8l4LNcBi9UpWFCwqv3JYMmdfcgksUvSBOXdRrmUP9lu9oQwsVnGsIyMWausGBvj9aL5g8jhDYh43t7s98zUtrAf_NC2HwtonALSrs/s320/9.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Now check SMTP settings in sharepoint&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijqIoPkSiCg8XdGU4ioHYXJDps-pk3_1u-z5X7ASaeOzJ6SEW99yzk3yr5QQ6Ar7tb0tWwRvxziDuZ4Fxui6_pYcDDqtKiW_PfZipSrJYMdjZE4nBPng8h4IZV6bCJsL6FukuJH5vCVDjb/s1600-h/10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijqIoPkSiCg8XdGU4ioHYXJDps-pk3_1u-z5X7ASaeOzJ6SEW99yzk3yr5QQ6Ar7tb0tWwRvxziDuZ4Fxui6_pYcDDqtKiW_PfZipSrJYMdjZE4nBPng8h4IZV6bCJsL6FukuJH5vCVDjb/s320/10.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/172090231021151903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/install-iis-7-ftp-smtp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/172090231021151903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/172090231021151903'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/install-iis-7-ftp-smtp.html' title='Install IIS 7 FTP SMTP'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3LtgpULFWH7vozm8sEQmJYsN_E8zDRQyRy-BQxvdc7rW6TRx09u20dYUmLhraRo6Jahy7v63deeC1QSXFRdpi0s7gpbHI7f_0GUyNc63NaGizlFadsxtxSGxSFcknqzMjL8jXfe0Mgs33/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-8514649548086729969</id><published>2010-03-13T06:58:00.000-08:00</published><updated>2010-03-13T06:58:42.396-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IIS 7"/><title type='text'>Install IIS 7 and SharePoint</title><content type='html'>In this tutorial we will look at two different flavours of website capabilities in windows server 2008&lt;br /&gt;
application server vs web server and which one you should select.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJ5-yEwMOGNIS-NFeltpAtcj08G0Ruzje6aRtdLVfknVqrGhRZauZUYk1r8tai2PC7f90tcPEr0anfk17QuZ4bqZxl20CO0TJAzPi7kRUydCYdvcgkteNdUXOnK_rOg2MShdm2Zn9UTxY4/s1600-h/1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJ5-yEwMOGNIS-NFeltpAtcj08G0Ruzje6aRtdLVfknVqrGhRZauZUYk1r8tai2PC7f90tcPEr0anfk17QuZ4bqZxl20CO0TJAzPi7kRUydCYdvcgkteNdUXOnK_rOg2MShdm2Zn9UTxY4/s320/1.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Here our goal for globomantic project we need to install share point service&lt;br /&gt;
&lt;br /&gt;
We need to setup web server setup to pre for our sharepoint services. There&#39;s two web-type server roles available, Web Server and Application Server. Which one should we choose?&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOswqgNPclenJorFVSS9d9aYceA6tYSnTpK9vpZh7uHMV8UBJd9jP6RtnwTJAr60jVwZfJHorSTV_JzQupMgtEs26jlL4bS4zd70RpDuH9BdLvdUapLmGWLVQuFugRhYDmLm50k6qrtxni/s1600-h/2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOswqgNPclenJorFVSS9d9aYceA6tYSnTpK9vpZh7uHMV8UBJd9jP6RtnwTJAr60jVwZfJHorSTV_JzQupMgtEs26jlL4bS4zd70RpDuH9BdLvdUapLmGWLVQuFugRhYDmLm50k6qrtxni/s320/2.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
For sharepoint and other high level web apps/distributed apps:&lt;br /&gt;
The Application Server Role is requied for SharePoint Services Installation.&lt;br /&gt;
&lt;br /&gt;
The Web Server Role is good if you have is a basic web site or maybe an ASP or PHP content managment system that requires a database on the back end.&lt;br /&gt;
&lt;br /&gt;
This Application Server more for heavy duty internal use&lt;br /&gt;
&lt;br /&gt;
Think Web Server for External Sites.&lt;br /&gt;
&lt;br /&gt;
Go to server WEB1, and add Application Server Role&lt;br /&gt;
In Role services select Web Server IIS, go next&lt;br /&gt;
In Web Server Role, keep as it is and go next and then press install&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTUBzy5ICpZsdt7shY3uFPtYleS9PAzCqZCne_wlXpfeQmiZHwB6FfNY3tngpH24LuoefmJd_h4yZe9CPBnh8eYvCtaM038JSxhxaVuTQgCJt_LD3G2_Db59_9Xk8N4Tvcr83m_w9wvJec/s1600-h/3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTUBzy5ICpZsdt7shY3uFPtYleS9PAzCqZCne_wlXpfeQmiZHwB6FfNY3tngpH24LuoefmJd_h4yZe9CPBnh8eYvCtaM038JSxhxaVuTQgCJt_LD3G2_Db59_9Xk8N4Tvcr83m_w9wvJec/s320/3.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Go to Web Server (IIS) and start Web Management Service &amp;amp; ASP.NET State Service&lt;br /&gt;
&lt;br /&gt;
Now we have successfully installed web server and the application server.&lt;br /&gt;
&lt;br /&gt;
Go to IIS Manager, and Sites, and Default Website&lt;br /&gt;
If you want to add files to the website, go Actions Expore and copy files to wwwroot folder&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;Now our server is ready to install sharepoint server&lt;br /&gt;
&lt;br /&gt;
Once we got sharepoint services installed, we will create new sharepoint site for Globomantics &lt;br /&gt;
Operations Staff&lt;br /&gt;
&lt;br /&gt;
Download sharepoint from microsoft site and install with basic installation to WEB1 server&lt;br /&gt;
&lt;br /&gt;
Once you finish the setup, go to &lt;a href=&quot;http://web1-globo/&quot;&gt;http://web1-globo/&lt;/a&gt;&lt;br /&gt;
to access sharepoint site&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEI3MtiSHYT-K2Tcd1TUqEl-BBTJHAME5r7Vqaekj0ubVdNGlOkFxZM9ZlfneyCZ0e8ljpCPPH3JOv6TFxUVkBYLV3o5U8dbBaNMEOTrfw7KKwxjGwLNBZCMqs_UV-RCIG8ijalJ1DDyiO/s1600-h/5.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEI3MtiSHYT-K2Tcd1TUqEl-BBTJHAME5r7Vqaekj0ubVdNGlOkFxZM9ZlfneyCZ0e8ljpCPPH3JOv6TFxUVkBYLV3o5U8dbBaNMEOTrfw7KKwxjGwLNBZCMqs_UV-RCIG8ijalJ1DDyiO/s320/5.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
Now lets create a site for globomantics&lt;br /&gt;
go site actions and create / Web Pages / Sites and Workspaces put site name and then create&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxYfEK0rg91TI8kV0pOZ0KpTBTT3YgzdrRvXyu3CavcNBH_GC-ZHehdQzg4PonhDZtSFQMbiXiT1asg7uva8ArhmsEHp2r8HAn3bcPTEhGEWglpp6mX63HrBdSArK9UVfWs3QIwOaWIXFA/s1600-h/6.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxYfEK0rg91TI8kV0pOZ0KpTBTT3YgzdrRvXyu3CavcNBH_GC-ZHehdQzg4PonhDZtSFQMbiXiT1asg7uva8ArhmsEHp2r8HAn3bcPTEhGEWglpp6mX63HrBdSArK9UVfWs3QIwOaWIXFA/s320/6.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Now you can go to sharepoint site &lt;a href=&quot;http://web1-globo/&quot;&gt;http://web1-globo/&lt;/a&gt;&lt;br /&gt;
Site Actions / Site Settings to get into administration interface&lt;br /&gt;
Go to people and groups and you can add users who can have access to sharepoint</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/8514649548086729969/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/install-iis-7-and-sharepoint.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/8514649548086729969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/8514649548086729969'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/install-iis-7-and-sharepoint.html' title='Install IIS 7 and SharePoint'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJ5-yEwMOGNIS-NFeltpAtcj08G0Ruzje6aRtdLVfknVqrGhRZauZUYk1r8tai2PC7f90tcPEr0anfk17QuZ4bqZxl20CO0TJAzPi7kRUydCYdvcgkteNdUXOnK_rOg2MShdm2Zn9UTxY4/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-3905178094115552674</id><published>2010-03-13T02:50:00.000-08:00</published><updated>2010-03-13T02:50:13.328-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="TS Network Load Balancing"/><title type='text'>TS Network Load Balancing</title><content type='html'>Scenario &lt;br /&gt;
Tom is concerned that Terminal Service machine might fail in the most critical of times. He is admant that you do whatever you need to so that he and the other staffs have access to the office-based report writing software as close to 100% of the time. Here is our options:&lt;br /&gt;
&lt;br /&gt;
1. &lt;span style=&quot;color: yellow;&quot;&gt;Network Load Balancing&lt;/span&gt;--Distributes work load to different machines to alleviate stress on the machines and provide scalability. Based for web-based stuff.&lt;br /&gt;
&lt;br /&gt;
2. &lt;span style=&quot;color: yellow;&quot;&gt;Failover Clustering&lt;/span&gt;-Multiple machines acting like one machine for high availability in case one machine fails. Best for Fault Tolerance (in case one machine blows up) and for database servers.&lt;br /&gt;
&lt;br /&gt;
3. &lt;span style=&quot;color: yellow;&quot;&gt;Terminal Service Load Balancing&lt;/span&gt; - Requires at least two machines with TS configuration. Load balancing just redirects TS requests to the servers that&#39;s less busy.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxlWlSB0npr18-IH8kYmmYXq0mjl-Lz7jFv6Bq2cqBP2JKb-8AjsjX29aTEaR3Duy5tZqH4QfGN4Zm4ZlLeQhjwW_bZFX3il3-6N5upS3_CQ0kQkTv2vksINb-a5ciheh_T4RoRbZEFz3T/s1600-h/1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxlWlSB0npr18-IH8kYmmYXq0mjl-Lz7jFv6Bq2cqBP2JKb-8AjsjX29aTEaR3Duy5tZqH4QfGN4Zm4ZlLeQhjwW_bZFX3il3-6N5upS3_CQ0kQkTv2vksINb-a5ciheh_T4RoRbZEFz3T/s320/1.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
In the above image, all 3 servers have TS running on them, and as request come in from client whichever server is least busy gets that particular request.&lt;br /&gt;
&lt;br /&gt;
Round Robin DNS basically circulates the requests to different servers.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7JolcB-aOfzcr-VNu25R7gnZLquPCj3V4VlxyIn13Xt-8JSLaE0lmgyTQlWkk_N5zAhvaIJszBsrWXPfKUEsIp1WaLYwaCJ2aBWJ3A_th_UCBLJNieLzfnC7D03BL15Vw1rbE615f1ivE/s1600-h/2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7JolcB-aOfzcr-VNu25R7gnZLquPCj3V4VlxyIn13Xt-8JSLaE0lmgyTQlWkk_N5zAhvaIJszBsrWXPfKUEsIp1WaLYwaCJ2aBWJ3A_th_UCBLJNieLzfnC7D03BL15Vw1rbE615f1ivE/s320/2.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
In clustering all three machines act like one machine. If one machine goes down, the others keep going to provide services.&lt;br /&gt;
&lt;br /&gt;
If one machine goes down, not that of a big deal because we have 2 other machines operating as fail over clusters. The other 2 machines pick up the slack and it takes off where the other machine left off.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Since we already have a TS machine built, we&#39;ll use our Deployment Service Machine to capture an image of it and then deploy it on another virtual machine.&lt;br /&gt;
&lt;br /&gt;
1. First we need to create a Capture Image so we can grap whats on TS1&lt;br /&gt;
2. Then we need to run the utility called sysprep on TS1 so we can use the OS and all its fun features we&#39;ve installed as a clean image.&lt;br /&gt;
3. Then we capture the image by rebooting the machine and using the Capture image we created to boot up with .&lt;br /&gt;
4. After the capture is complete we can deploy using deployment service as normal. We are going to make a duplicate machine of TS1 using deployment service.&lt;br /&gt;
After we have a duplicate machine then we will use Terminal Service Load Balancing through TS session broker to create a highly available solution.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First create Capture image, so we can grab the stuff from TS1 and save it as image and create a dublicate machine. &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;span style=&quot;color: lime;&quot;&gt;Create Capture Image&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;
Go to WDS server, go to Boot Images to create capture image&lt;br /&gt;
&lt;br /&gt;
Our capture image needs to match architecture of the OS that we are going to capture.&lt;br /&gt;
If your network card is not PXE enabled, then use create discover boot image&lt;br /&gt;
Once you create boot image for 32bit, you can use it forever&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIM9pfApVj2n33HKwm9Q0lGS0rkuz2S23IZ6ogNBk6JmnjvGINjjwWn7V43VqH__8ULqPQPsqihnBCGfF-32zDeg9-XAsrFEqqiUpN4LvZA847sNl-RONz2XQb4MnTQmTHGSnLiAtOi-nA/s1600-h/3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIM9pfApVj2n33HKwm9Q0lGS0rkuz2S23IZ6ogNBk6JmnjvGINjjwWn7V43VqH__8ULqPQPsqihnBCGfF-32zDeg9-XAsrFEqqiUpN4LvZA847sNl-RONz2XQb4MnTQmTHGSnLiAtOi-nA/s320/3.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Once boot image is created, rightclick and select Add Boot Image.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYa9m9UxLDeirfIr18FRtDEW-Qb527gNjBnefX6VjJG2mEKqNj51jQypqMaTuhddviJ0p-WAkI2huzEFt-LVBk-LIpUfqja5hxApzrh8E_08KVuHOFlC0DcGcbzvso1KoPDdlsZXqnla4T/s1600-h/4.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYa9m9UxLDeirfIr18FRtDEW-Qb527gNjBnefX6VjJG2mEKqNj51jQypqMaTuhddviJ0p-WAkI2huzEFt-LVBk-LIpUfqja5hxApzrh8E_08KVuHOFlC0DcGcbzvso1KoPDdlsZXqnla4T/s320/4.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Now the image is ready to boot up a machine using network boot sequence &lt;br /&gt;
We need to boot TS1 server using new image &lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: lime;&quot;&gt;&lt;strong&gt;Sysprep&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;
now go to TS1 server, open sysprep&lt;br /&gt;
select OOBE&lt;br /&gt;
Tick Generalize&lt;br /&gt;
select Reboot&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;span style=&quot;color: lime;&quot;&gt;Capture image of TS1&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;
now it will take sometime to strip out the name of the machine, UID. but it will keep all the softwares u installed, keep joined to the domain.&lt;br /&gt;
&lt;br /&gt;
Now when server roots, it will prompt to press F12 from keyboard for network boot.&lt;br /&gt;
Press F12&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjB2e9pQhX90XFU6ijizMT6O7q69j22ek1U7Z5-0ndwkHo7py0ju2Y1oGVNixLuZsjYaSvcKPISLI3eM5iIHifSFG_GAW5Zdi87EC_BKth4AnijcPjgLut_fy2S8dbhlpYGfFSV4_FDw8Yh/s1600-h/5.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjB2e9pQhX90XFU6ijizMT6O7q69j22ek1U7Z5-0ndwkHo7py0ju2Y1oGVNixLuZsjYaSvcKPISLI3eM5iIHifSFG_GAW5Zdi87EC_BKth4AnijcPjgLut_fy2S8dbhlpYGfFSV4_FDw8Yh/s320/5.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Now you should see 3 network boot images, select the new boot image name grabIT&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1mjwU09LmcLkOPrlcmh-OQVDLLgg5NfPj73uUEyahJ7BJoR50EppPua8MEizfHXu_TGK7AdlA2saxxAnLE4RltAAo4RwJCqiTkESDhfybmC4BelI5XtscI_60hEkidzRfiZfR1qd7ne2_/s1600-h/6.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1mjwU09LmcLkOPrlcmh-OQVDLLgg5NfPj73uUEyahJ7BJoR50EppPua8MEizfHXu_TGK7AdlA2saxxAnLE4RltAAo4RwJCqiTkESDhfybmC4BelI5XtscI_60hEkidzRfiZfR1qd7ne2_/s320/6.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Now select which drive to capture, type image name, &lt;br /&gt;
&lt;br /&gt;
Go Next&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgM_a5lLdFWc7QDmx0ZmBsf-SyG7KnbemC-JpTfbSxLCwMdOPZLRdO1bdF33J9Z01qqzDtiEK7trcwcIb2OEAjJbWRZl0DJsZzdmbmepTfBBjyNF5DXKD8ca8dNFCdO_x4Qhnuo2k-9v1f_/s1600-h/7.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgM_a5lLdFWc7QDmx0ZmBsf-SyG7KnbemC-JpTfbSxLCwMdOPZLRdO1bdF33J9Z01qqzDtiEK7trcwcIb2OEAjJbWRZl0DJsZzdmbmepTfBBjyNF5DXKD8ca8dNFCdO_x4Qhnuo2k-9v1f_/s320/7.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Select a where to save the new image&lt;br /&gt;
You can browse TS1 C drive, TS1 will capture a image of TS1 and save it on its C drive itself.&lt;br /&gt;
Tick upload images to WDS Server&lt;br /&gt;
Enter WDS Server name, and connect&lt;br /&gt;
then select image group name&lt;br /&gt;
Now press Finish, and it will take sometime to finish creating image.&lt;br /&gt;
&lt;br /&gt;
Now go to WDS Server, go to the image group and see if the new image is there.&lt;br /&gt;
If its not there, right click and add the image.&lt;br /&gt;
&lt;br /&gt;
Now we can use the new image to deply another server.&lt;br /&gt;
&lt;br /&gt;
When you reboot TS1 it will boot with setup windows, this is not what we want, we want the server to boot up with previous settings. &lt;br /&gt;
&lt;br /&gt;
To do that go to Hyper-V Manager, Screenshots, select After video, right click and apply&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFQqk1KRxehvzqD0JqsijUhyqOre_ZOL8oCWtZakbuy9WdcPFf2VVtAn9aXPBtsxjomvU4aZV2fEH3n1RrccUmtjX7meyPtj9gPdOWjUauLCHSoLerEQIlCrkMSr0l6WyfnlCOj9fgkYz4/s1600-h/9.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFQqk1KRxehvzqD0JqsijUhyqOre_ZOL8oCWtZakbuy9WdcPFf2VVtAn9aXPBtsxjomvU4aZV2fEH3n1RrccUmtjX7meyPtj9gPdOWjUauLCHSoLerEQIlCrkMSr0l6WyfnlCOj9fgkYz4/s320/9.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;What it is going to do is, revert back to original state before we took snapshot&lt;br /&gt;
Hit Apply&lt;br /&gt;
&lt;br /&gt;
Now setup new server, and boot from network&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMNXGsHh1lBAWfpMW0HUIm5lSfEGPhEFBrIxoBuuwZiJbUY2x7QCKrQMcOn8O6i5IepkoJS7Dx9B4y1Lha0Jq7Sz7e-3olAH2eLqtEIvGM034RMOhI9N5IN6yMwajzw1djGvqV2c_RVA0F/s1600-h/8.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMNXGsHh1lBAWfpMW0HUIm5lSfEGPhEFBrIxoBuuwZiJbUY2x7QCKrQMcOn8O6i5IepkoJS7Dx9B4y1Lha0Jq7Sz7e-3olAH2eLqtEIvGM034RMOhI9N5IN6yMwajzw1djGvqV2c_RVA0F/s320/8.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Select boot image x64&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgo8WEZaMb60L2nY9_-nkPtGciAugoeYH2mvzYmmhX-HlUO47jMb_sym15smgQrUpZGN1_IcMN9zbUP3I3bsvh9bGeszYkUIjxMwyn_2QdZWXgg4BabwZBL-c-jX1JU_cGMJGsSnowZ4XKz/s1600-h/10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgo8WEZaMb60L2nY9_-nkPtGciAugoeYH2mvzYmmhX-HlUO47jMb_sym15smgQrUpZGN1_IcMN9zbUP3I3bsvh9bGeszYkUIjxMwyn_2QdZWXgg4BabwZBL-c-jX1JU_cGMJGsSnowZ4XKz/s320/10.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
select the appropriate image.&lt;br /&gt;
now proceed with normal windows setup&lt;br /&gt;
&lt;br /&gt;
now check the new machine if all softwares and settings are same as TS1&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;span style=&quot;color: lime;&quot;&gt;Setup TS Session Broker&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;
Now we need to setup TS Session Broker, in order to manage the load balancing so that when one machine is busy the other machine will pick up.&lt;br /&gt;
&lt;br /&gt;
one thing to remind is the TS Session broker must be a memeber of the domain.&lt;br /&gt;
&lt;br /&gt;
To add TS Session Broker, go to Terminal Service and add role&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZnQcIIrQwqkpRH7WXrN5g4LFZJ3kNlhxggUoAwcxtR0tfD_x99RcqT-JHFe6_eM1PwMVKsb0rmQQLvoEn6Wx-KyS33Ayi-CoYC9ROHfWSBxB5v23ch3onp9vxcsCMranoOlJ98HWnd1B5/s1600-h/11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZnQcIIrQwqkpRH7WXrN5g4LFZJ3kNlhxggUoAwcxtR0tfD_x99RcqT-JHFe6_eM1PwMVKsb0rmQQLvoEn6Wx-KyS33Ayi-CoYC9ROHfWSBxB5v23ch3onp9vxcsCMranoOlJ98HWnd1B5/s320/11.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
Check list for TS Session Broker &lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjR6yQ88PcuZrJKnVVQTVuc7XmOHSmblIxv3QuSzlhWu0dPxJze2GC7pcfxSJ_XcrcSI5KHdUNLcSbs32TDeN33T56WVN12Yw93R9lEOcxq2-fqVvN_rjqctalvHLg24dGpAlcL3RfexNX6/s1600-h/12.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjR6yQ88PcuZrJKnVVQTVuc7XmOHSmblIxv3QuSzlhWu0dPxJze2GC7pcfxSJ_XcrcSI5KHdUNLcSbs32TDeN33T56WVN12Yw93R9lEOcxq2-fqVvN_rjqctalvHLg24dGpAlcL3RfexNX6/s320/12.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
add TS1 and TS2 to to Session Directory Computers Local Group&lt;br /&gt;
To do that go to computer management, local users and groups, double click session directory computers and select object type as Computers, and add TS1 and TS2&lt;br /&gt;
&lt;br /&gt;
Now we need to Configure Terminal Server to join a firm in TS Session Broker.&lt;br /&gt;
&lt;br /&gt;
Go to Server Manager, Terminal Service, Terminal Serivice Configuration&lt;br /&gt;
and you would see down below Member of firm TS Session broker = No&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-rY4KsFYtOYwjdDZYKZMBRady8jY3ykUlVFcQR5foMQZDnZRltSrobLcFt1eJImRLzmL9-mpYcnPpZocWm4tz9wgEUyAm4kWsJlo2loNcz70G1nfOy9-Cgmxh0p4r4eMzviQrgy6pT7Tg/s1600-h/13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-rY4KsFYtOYwjdDZYKZMBRady8jY3ykUlVFcQR5foMQZDnZRltSrobLcFt1eJImRLzmL9-mpYcnPpZocWm4tz9wgEUyAm4kWsJlo2loNcz70G1nfOy9-Cgmxh0p4r4eMzviQrgy6pT7Tg/s320/13.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Member of firm in TS Session Broker, doesnt look like a link, double click it &lt;br /&gt;
Go to TS Session Broker Tab, &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb3Ol4HHUvRv3zoq_eLDGVnOoE6g0tMqgKsSFQKqoGqs3noM2YP-mX_LANHu48PaUeBXX1L_oagOaogDBs82te0qkJTUOw9aSkUhyphenhyphen_najXtOAy72USDcjd7hffTnbQMbeV_S7Ad0iOR3v7/s1600-h/14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb3Ol4HHUvRv3zoq_eLDGVnOoE6g0tMqgKsSFQKqoGqs3noM2YP-mX_LANHu48PaUeBXX1L_oagOaogDBs82te0qkJTUOw9aSkUhyphenhyphen_najXtOAy72USDcjd7hffTnbQMbeV_S7Ad0iOR3v7/s320/14.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Enter TS Session Broker Server name&lt;br /&gt;
Enter Firm Name&lt;br /&gt;
Tick Participate Session Broker Load Balancing&lt;br /&gt;
Tick Use IP address redirection&lt;br /&gt;
Select IP to be used for reconnection, this would help to reconnect disconnected sessions.&lt;br /&gt;
&lt;br /&gt;
Now do the samething to TS2&lt;br /&gt;
&lt;br /&gt;
in TS2, TS Session Broker Server Name, we need to put TS1, and use same firm name.&lt;br /&gt;
&lt;br /&gt;
Now we need to configure DNS for TS Session Broker Load Balancing&lt;br /&gt;
&lt;br /&gt;
To do that go to DNS and create AAA records, we need to mention TS server firm name, NOT the server name. instead of TS1 or TS2 we need to mention firm name.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLqnoJIvKjn0OPgb1WhzL_yZaC1ocgq7iJIsbReglg0gmgPJ5_2s0wGF1tCaYs9G1EoQjRrMPD4Tp7fQ9PbyEWmb_k2UcjDP74Q06O3FyDx785l2GGMRyU37xb71UFkgUdhg_-t6sy01HG/s1600-h/15.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLqnoJIvKjn0OPgb1WhzL_yZaC1ocgq7iJIsbReglg0gmgPJ5_2s0wGF1tCaYs9G1EoQjRrMPD4Tp7fQ9PbyEWmb_k2UcjDP74Q06O3FyDx785l2GGMRyU37xb71UFkgUdhg_-t6sy01HG/s320/15.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;The farm name is the virtual name that clients will use to connect to the terminal server farm.&lt;br /&gt;
now we have same record point to 2 ip address.&lt;br /&gt;
&lt;br /&gt;
Note : By default DNS Round Robin is enabled when using DNS on windows 2008 based domain controller. The enable round robin tab is available in advance tab of DNS server properties.&lt;br /&gt;
&lt;br /&gt;
now to test this from a client PC go to&lt;br /&gt;
http:\\globotsfarm.globomantics.com\TS</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/3905178094115552674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/ts-network-load-balancing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/3905178094115552674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/3905178094115552674'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/ts-network-load-balancing.html' title='TS Network Load Balancing'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxlWlSB0npr18-IH8kYmmYXq0mjl-Lz7jFv6Bq2cqBP2JKb-8AjsjX29aTEaR3Duy5tZqH4QfGN4Zm4ZlLeQhjwW_bZFX3il3-6N5upS3_CQ0kQkTv2vksINb-a5ciheh_T4RoRbZEFz3T/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-852637265334359006</id><published>2010-03-11T07:17:00.000-08:00</published><updated>2010-03-11T07:17:01.143-08:00</updated><title type='text'>Installing Remote Apps</title><content type='html'>After installing MS Office to TS Server&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Go to Terminal Service, TS RemoteApp Manager&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMQP0qFzaHrx4IxE-ZfKlLX0BH9Kz3vFMiTyuvyFpTaR_r31F2-NitoSc_DW2DBDt4kK0vNaWoPw1jKmHcxwjEuUF9AQKUpmzN12wLc0sxvuyev-RIdbqxDyb8vqeGtTbXSxSJrZrJ2nze/s1600-h/ts.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMQP0qFzaHrx4IxE-ZfKlLX0BH9Kz3vFMiTyuvyFpTaR_r31F2-NitoSc_DW2DBDt4kK0vNaWoPw1jKmHcxwjEuUF9AQKUpmzN12wLc0sxvuyev-RIdbqxDyb8vqeGtTbXSxSJrZrJ2nze/s320/ts.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
Click Add RemoteApp Programs&lt;br /&gt;
&lt;br /&gt;
Select the applications that you want to be available&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTFGdIBUqHoQ4Uznsxw_5fCOCUDSpAIboOM7qHxNwHERTGxUoz3ovDOaA1pZN_fjLYGK3iulaAPVO2CxKKduLRpRLwpLqivP02mK8ST394GigrdKYt9UO0Wybat09iR0Nh4-NmSNZng5zc/s1600-h/remoteapp.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTFGdIBUqHoQ4Uznsxw_5fCOCUDSpAIboOM7qHxNwHERTGxUoz3ovDOaA1pZN_fjLYGK3iulaAPVO2CxKKduLRpRLwpLqivP02mK8ST394GigrdKYt9UO0Wybat09iR0Nh4-NmSNZng5zc/s320/remoteapp.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Click Properties, Tick the program available through TS Web Access&lt;br /&gt;
&lt;br /&gt;
Now you need to add users to TS Web Access Computer Group&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb5WMYAeQzpnLTrj9_5n5kPWowgHJn-kcBc6LCq5_XexBjGSei9TBNsPwYxdCpF6mOoXLvclwk1EpKNx9zHntbynIGK2-eOSJ5pA-6bpzReVzM05CpGWvMqWhyphenhyphenSVz2kxpOehbWFsku0mqI/s1600-h/tsgroup.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb5WMYAeQzpnLTrj9_5n5kPWowgHJn-kcBc6LCq5_XexBjGSei9TBNsPwYxdCpF6mOoXLvclwk1EpKNx9zHntbynIGK2-eOSJ5pA-6bpzReVzM05CpGWvMqWhyphenhyphenSVz2kxpOehbWFsku0mqI/s320/tsgroup.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Now go to IIS Manager &lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3u639bhUgI8xZO63j911xbZzbs1eDkk2_68mthbCMeZGwRhbBpdf1ME1Y1YtG_TNyEMP4jQQLKi0VcYS6DXZqtg-j5uMDu-48DooSJzHsmLB84pA__GTY-YDVzL3VybRBNc5_YwvNE1Zn/s1600-h/iis.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3u639bhUgI8xZO63j911xbZzbs1eDkk2_68mthbCMeZGwRhbBpdf1ME1Y1YtG_TNyEMP4jQQLKi0VcYS6DXZqtg-j5uMDu-48DooSJzHsmLB84pA__GTY-YDVzL3VybRBNc5_YwvNE1Zn/s320/iis.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Click TS then click Browse &lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
When you install TS and when you include Web Access in there, it creates a website on localhost for remote access. &lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
Distributing Applications to users using Group Policy &lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
go to TS TS RemoteApp Manager and select the application &lt;br /&gt;
and then create a RDP file or create a windows installer package &lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
TS Gateway &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiENX6I4KFXfqGP3TVdN8bvWa9CR2qu-DIXFz_KajfEXf_vyUYLBqXk8Rp8USdF9LVkYL3zwL3u6rQ2Yn8hsOsZqHt8HiUJertnDcD09kSoNCpmT-S5ypRcgF-KY-za32CjKeaIcdaoFrQL/s1600-h/tsgate.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiENX6I4KFXfqGP3TVdN8bvWa9CR2qu-DIXFz_KajfEXf_vyUYLBqXk8Rp8USdF9LVkYL3zwL3u6rQ2Yn8hsOsZqHt8HiUJertnDcD09kSoNCpmT-S5ypRcgF-KY-za32CjKeaIcdaoFrQL/s320/tsgate.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;TS Gateway Manager &lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieK-YT-fBayJc37-VVZa-pAyplxAjw7Wb_gqdC0VdE7M9Z9mNFNR6Ycb_fmCQRWS7lWfcMSoY8LlzIIRbtSelRdgV5J1glaUvC_FBXmA4RkYpNnL_1_FGu_RFK7yXyoSA6f9QiVyXguvxR/s1600-h/tsgm.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieK-YT-fBayJc37-VVZa-pAyplxAjw7Wb_gqdC0VdE7M9Z9mNFNR6Ycb_fmCQRWS7lWfcMSoY8LlzIIRbtSelRdgV5J1glaUvC_FBXmA4RkYpNnL_1_FGu_RFK7yXyoSA6f9QiVyXguvxR/s320/tsgm.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp; &lt;br /&gt;
add which computers can connect to TS Gateway &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-xDcpprOChB-jObc1bNup2TXvJCXSIKrCHJQb-azZNPCb5ixBCRidFt7ryzryoBerM4FOS8i_hqrQr-oD_HwqtNXBYUE-PYeO2gdw5tYdHgCMTd5tZjG8j53QfYp-HdDROzRUp7p1JXv8/s1600-h/tscomp.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-xDcpprOChB-jObc1bNup2TXvJCXSIKrCHJQb-azZNPCb5ixBCRidFt7ryzryoBerM4FOS8i_hqrQr-oD_HwqtNXBYUE-PYeO2gdw5tYdHgCMTd5tZjG8j53QfYp-HdDROzRUp7p1JXv8/s320/tscomp.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp; &lt;br /&gt;
TS Gateway settings &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2D1IcFyXZOIaq1xXswXQiJpNCSI9hx7W-fniLOAzfaYtC3I0KH9kW47IcosoeSLdtKe5Qa5blN7oPO6F0YvXY7ShTKiFTTPDd29m8ij_eRuUGV05J7kosNR50b6BOTj6bq1dBv9NQtsqb/s1600-h/tsgateway.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2D1IcFyXZOIaq1xXswXQiJpNCSI9hx7W-fniLOAzfaYtC3I0KH9kW47IcosoeSLdtKe5Qa5blN7oPO6F0YvXY7ShTKiFTTPDd29m8ij_eRuUGV05J7kosNR50b6BOTj6bq1dBv9NQtsqb/s320/tsgateway.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Go settings and enter TS gateway server name to connect</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/852637265334359006/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/installing-remote-apps.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/852637265334359006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/852637265334359006'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/installing-remote-apps.html' title='Installing Remote Apps'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMQP0qFzaHrx4IxE-ZfKlLX0BH9Kz3vFMiTyuvyFpTaR_r31F2-NitoSc_DW2DBDt4kK0vNaWoPw1jKmHcxwjEuUF9AQKUpmzN12wLc0sxvuyev-RIdbqxDyb8vqeGtTbXSxSJrZrJ2nze/s72-c/ts.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-1133735644959412471</id><published>2010-03-11T06:14:00.000-08:00</published><updated>2010-03-11T06:14:28.333-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Terminal Service"/><title type='text'>Terminal Service</title><content type='html'>What makes up Terminal Services?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
1. The &lt;span style=&quot;color: lime;&quot;&gt;Terminal Services Server Role&lt;/span&gt; - The foundation of using TS&lt;br /&gt;
&lt;br /&gt;
2. &lt;span style=&quot;color: lime;&quot;&gt;TS Remote App&lt;/span&gt; - A Role services installed with the terminal services server role, it allows you to make applications available on the server available for use by client machines via a short cut through TS Web Access.&lt;br /&gt;
&lt;br /&gt;
3. &lt;span style=&quot;color: lime;&quot;&gt;TS Licensing&lt;/span&gt; - TS requires more licenses, and the TS licensing Role Service allow you to more easily manage TS licenses.&lt;br /&gt;
&lt;br /&gt;
4. &lt;span style=&quot;color: lime;&quot;&gt;TS Session Broker&lt;/span&gt; - Install this role services only when you want to have multiple TS servers operating in a &quot;farm&quot; for highly available applications. TS session broker allows clients to reconnect to disconnected sessions.&lt;br /&gt;
&lt;br /&gt;
5. &lt;span style=&quot;color: lime;&quot;&gt;TS Web Access&lt;/span&gt; - This role service allows users to access TS Remote Apps through a web page.&lt;br /&gt;
&lt;br /&gt;
6. &lt;span style=&quot;color: lime;&quot;&gt;TS Gateway&lt;/span&gt; - A role service to provide terminal services to users outside of your network.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpAuoMqBRuGzCtnABhs3nCgbGNxBeSOlqewO1Uk4tQQX9x1FNQ5Fx3AxjcgCRYVQsiGPSpfoGbYge8UUi6WaaCwrO8ToGIu9J5BepZ8VfkVayWLN_GmhYMoq6oM-lN-DyDT6cR1sbJQ7Zk/s1600-h/ts.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpAuoMqBRuGzCtnABhs3nCgbGNxBeSOlqewO1Uk4tQQX9x1FNQ5Fx3AxjcgCRYVQsiGPSpfoGbYge8UUi6WaaCwrO8ToGIu9J5BepZ8VfkVayWLN_GmhYMoq6oM-lN-DyDT6cR1sbJQ7Zk/s320/ts.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Configuring TS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
1. Install TS services on your requirement.&lt;br /&gt;
2. Select Authentication Method&lt;br /&gt;
3. Select Licensing Mode&lt;br /&gt;
4. Select Users Group&lt;br /&gt;
5. Choose a Server Authentication Certificate for SSL Encryption&lt;br /&gt;
6. Create Authorization Policies for TS Gateway&lt;br /&gt;
7. Select User Groups that can connect through TS Gateway&lt;br /&gt;
8. Create a TS CAP for TS Gateway&lt;br /&gt;
9. Create TS RAP for TS Gateway</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/1133735644959412471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/terminal-service.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/1133735644959412471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/1133735644959412471'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/terminal-service.html' title='Terminal Service'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpAuoMqBRuGzCtnABhs3nCgbGNxBeSOlqewO1Uk4tQQX9x1FNQ5Fx3AxjcgCRYVQsiGPSpfoGbYge8UUi6WaaCwrO8ToGIu9J5BepZ8VfkVayWLN_GmhYMoq6oM-lN-DyDT6cR1sbJQ7Zk/s72-c/ts.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-6756496684902206896</id><published>2010-03-11T00:27:00.000-08:00</published><updated>2010-03-11T00:27:10.399-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="RODC"/><title type='text'>Building RODC</title><content type='html'>Building a Read-Only Domain Controller&lt;br /&gt;
&lt;br /&gt;
- An RODC allows users that the administrator allows to log into a particular location.&lt;br /&gt;
- The RODC downloads only the User account information that it needs - it does not upload anything to the writeable (or Full) domain controllers.&lt;br /&gt;
- You dont need to have a Global Catalog on the RODC - you can use Universal Group Caching to cut down on replication traffic.&lt;br /&gt;
- Better yet, you can use the Server Core Installation to provide 2 important advantages.&lt;br /&gt;
&lt;br /&gt;
1. You dont need a high end computer&lt;br /&gt;
2. You can administrate teh server core function using MMC&#39;s&lt;br /&gt;
RODC is good for remote locations which they dont have much physical security in this example, remote location name is &quot;Dallas&quot; in NY-DC1 create OU for Dallas, and inside Dallas OU, create DallasUsers and DallasComputers&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3mEravWNFLeVUQXDykxLFdM5aOKzDx2Tg3kgb7NikmNgJFYRgQZ6E6h2FI-M68b7rdsd6CJ4JNFy9SbaE6oMy6K2Z-PRExL8fVJiB02pWeG31xamSPBW27UW8ZP09xymQCK6_MyYrjY-p/s1600-h/dallas+users.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3mEravWNFLeVUQXDykxLFdM5aOKzDx2Tg3kgb7NikmNgJFYRgQZ6E6h2FI-M68b7rdsd6CJ4JNFy9SbaE6oMy6K2Z-PRExL8fVJiB02pWeG31xamSPBW27UW8ZP09xymQCK6_MyYrjY-p/s320/dallas+users.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Now go to AD Sites and Services&lt;br /&gt;
Right click Sites, and Create Newsite name Dallas&lt;br /&gt;
Note: To create Sites you need Enterprise Administrator rights.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZb5in05A8MS6tJiG-XzV18R_qG1dyvR5zwQ2O3dCWYncjG1FYRG70kWCxrF646ubBV9oAD9LOGAbTy_uWl97qxKo1LCjobXWTcUIef3CfrVvLY9bxur2F6HzK11bTaNpG_df3BvxpfzxA/s1600-h/newsite.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZb5in05A8MS6tJiG-XzV18R_qG1dyvR5zwQ2O3dCWYncjG1FYRG70kWCxrF646ubBV9oAD9LOGAbTy_uWl97qxKo1LCjobXWTcUIef3CfrVvLY9bxur2F6HzK11bTaNpG_df3BvxpfzxA/s320/newsite.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Now we have our site created, now we need to add in our Read Only Domain Controller&lt;br /&gt;
We do need to wait for our domain controllers to talk each other, for replication etc.&lt;br /&gt;
&lt;br /&gt;
In this tutorial first i setup a server core installation and make it as a RODC&lt;br /&gt;
&lt;br /&gt;
Step 1. Setup server core installation&lt;br /&gt;
After finishing server core instllation, join to NY-DC1 and login using NY-DC1 administrator priviledge&lt;br /&gt;
download and install CoreConfigurator2.msi&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTExdf5TYOD-9SMoBClkEK5ZQTrcq9FeAONmZNERhvXJ-87Rl_c5Zp2c2iRunJOuLmtvHMKBhEa2eGan4jSQqBz8_gRHtkAQ1evYv-Er2hKq5_NjGnq-FpU3RYIXQdUoFs_w5KLyxTSTBM/s1600-h/servercore.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTExdf5TYOD-9SMoBClkEK5ZQTrcq9FeAONmZNERhvXJ-87Rl_c5Zp2c2iRunJOuLmtvHMKBhEa2eGan4jSQqBz8_gRHtkAQ1evYv-Er2hKq5_NjGnq-FpU3RYIXQdUoFs_w5KLyxTSTBM/s320/servercore.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
After installing run the core configurator script, CoreConfigurator.exe&lt;br /&gt;
Using CoreConfiguration, setup IP address and join to NY-DC1&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgwjAQBwjhjbWaFJrBpIUPR4xBc4zBsank_jvapFahUAwBZlyJTtqkFUdJe69MOMl7IJgBJYhVww_ctdo3_7owlrI7FS1x5XDlvp1ehe_wQMzkZvFKGF7uMPGozOcM1geyZ3pJnkkpMI2K/s1600-h/configurator.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgwjAQBwjhjbWaFJrBpIUPR4xBc4zBsank_jvapFahUAwBZlyJTtqkFUdJe69MOMl7IJgBJYhVww_ctdo3_7owlrI7FS1x5XDlvp1ehe_wQMzkZvFKGF7uMPGozOcM1geyZ3pJnkkpMI2K/s320/configurator.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Now run DCPROMO&lt;br /&gt;
Select Add a domain controller to an existing domain&lt;br /&gt;
&lt;br /&gt;
Type Domain DNS Name NY-DC1&lt;br /&gt;
Tick Install and Configure DNS&lt;br /&gt;
Untick Configure Global Catalog&lt;br /&gt;
Tick Make the server as RODC&lt;br /&gt;
&lt;br /&gt;
Select AD Site, Dallas&lt;br /&gt;
Save answer file&lt;br /&gt;
&lt;br /&gt;
Run the DCPROMO&lt;br /&gt;
&lt;br /&gt;
Now go to NY-DC1 and connect to Dallas RODC using MMC to manage remotely in DC1, open mmc&lt;br /&gt;
&lt;br /&gt;
add Snap-ins&lt;br /&gt;
add DNS, AD users and computers, Sites and Services, &lt;br /&gt;
Add Computer Management, in Another Computer type name of RODC&lt;br /&gt;
&lt;br /&gt;
Now in MMC, go to Active Directory Users and Computers, expand it&lt;br /&gt;
right click name of domain controller, and click Change Domain Controller and Select RODC, Click OK&lt;br /&gt;
&lt;br /&gt;
Now you will get a message, The selected Domain Contorller is Read only....etc&lt;br /&gt;
&lt;br /&gt;
Now you can save the mmc as RODC to desktop&lt;br /&gt;
&lt;br /&gt;
Now go to NY-DC1, AD Domain Services / Domain Controllers&lt;br /&gt;
Right click RODC/Properties/Password Replication Policy &lt;br /&gt;
&lt;br /&gt;
Now you will see NY-DC1/Users which means any user in NY-DC1 can get in to RODC&lt;br /&gt;
&lt;br /&gt;
Remove it, if you really want to decide who can login and who cannot login to RODC&lt;br /&gt;
&lt;br /&gt;
Now we need to add user, click Add&lt;br /&gt;
Select Allow passwords for the account to replicate to this RODC&lt;br /&gt;
Make sure you APPLY, after adding users&lt;br /&gt;
&lt;br /&gt;
In NY-DC1, go to Dallas OU, Go to DallasUsers and right click a user &lt;br /&gt;
(Before that make sure go view and advance features is on) right click user, and go password replication, and you can see which users can login to this domain controller&lt;br /&gt;
&lt;br /&gt;
Any other user cannot login unless they have global catalog or universal group caching, if that is present, users can use user principle name (email style login) &lt;br /&gt;
&lt;br /&gt;
if that is not present, only the users that is added to the list in RODC/Password Replication Policy will be able to login&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now go to Advanced button, click Prepopulate Passwords, Enter user name so what here we are doin is prepopulating passwords for user&lt;br /&gt;
&lt;br /&gt;
NY-DC1 will be sending password for the use to RODC</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/6756496684902206896/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/building-rodc.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/6756496684902206896'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/6756496684902206896'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/building-rodc.html' title='Building RODC'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3mEravWNFLeVUQXDykxLFdM5aOKzDx2Tg3kgb7NikmNgJFYRgQZ6E6h2FI-M68b7rdsd6CJ4JNFy9SbaE6oMy6K2Z-PRExL8fVJiB02pWeG31xamSPBW27UW8ZP09xymQCK6_MyYrjY-p/s72-c/dallas+users.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-3737194257008751584</id><published>2010-03-07T05:23:00.000-08:00</published><updated>2010-03-11T00:15:26.634-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Fine Grained Password Policy"/><title type='text'>Fine Grained Password Policy</title><content type='html'>&lt;span style=&quot;color: #999999;&quot;&gt;A Feature in server 2008 that allows an override of the Domain Password Policy Requirement&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;Password&lt;/span&gt; Setting Objects (PSO)&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Normally you have only one password policy settings in your entire domain, but by creating PSO you can specify multiple password policies for individual users or for groups that users are part of.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Your domain functional level must be at server 2008 level (all your domain controllers must be server 2008)&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;We&#39;ll need to go into ADSI edit to create password policy objects, and link them to the user account or group they&#39;ll apply to.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;STEPS&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;1. Open ADSI edit, go to system and you will find password settings container, double click&amp;nbsp; and open it.&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjo6wO5eI5BGkc-qMvOmAKJk22KrEhhBqisFkn4M3_SoKJxMSoL-IyUk_cT5QvrUPqA333qfAiGDUV7_hhzDXsndnPGoF7nzN9srZDve3MkNmOvdCxbCt7zWXtm-ytZ_c_aOslUmkcd0Xhr/s1600-h/adsi.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjo6wO5eI5BGkc-qMvOmAKJk22KrEhhBqisFkn4M3_SoKJxMSoL-IyUk_cT5QvrUPqA333qfAiGDUV7_hhzDXsndnPGoF7nzN9srZDve3MkNmOvdCxbCt7zWXtm-ytZ_c_aOslUmkcd0Xhr/s320/adsi.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;2. Create new PSO, right click, new, object&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;3. Select a class msDS-PasswordSettings&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;4. Common-Name Value : ExecutivesPasswordPolicy&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;5. Password Settings Precedence password settings precedence basically determines if the user is part of&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;different groups that have multiple PSO applied to them. example user1 is in 2 groups, and each of these 2 groups has different password settings applied so the highest value, the value in the Password Settings Precedenec will win.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;example Value 1&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;6. Password Reversible encryption status for user accounts, Value FALSE&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;7. Password History Length for user accounts, Value 5&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;8. Password complexity status for user accounts, Value FALSE&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;9. Minimum Password Length for user accounts, Value 4&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;10. Minimum Password Age for user accounts, Value 1:00:00:00&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;days:hrs:min:sec&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;11. Maximum password age for user accounts, Value 90:00:00:00&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;12. Lockout threshold for lockout of user accounts, Value 20&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;13. Observation Window for lockout of user accounts, Value 0:00:20:00&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;This means, if user1 try all 20 attempts in 20 minutes then he will get locked out&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;14. Lockout duration for locked out user accounts, Value 0:01:00:05&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Value is 1hr 5 sec&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;15. Link this PSO to appropriate group, to do this click More Attributes&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;16. In Select property to view, select msDS-PSOAppliesTo&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;17. In Edit Attribute type distinguishName for the object that we are linking to, click add&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;You can add additional users, or groups if you want to. This is the only people that we want this particular PSO to be applied to.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Click Finished&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Note: Syntax DN stands for Distinguish name&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;HOW TO FIND DISTINGUISH NAME&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Open server manager&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Go to Roles Section&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Expand Active Directory Domain Services&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Expand your domain&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Expand OU&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Go to view manu, and turn on advanced features&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;now right click users group and go properties&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Click Attribute Editor in Attribute Editor search fo&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh46IjSt6itEX-044bX0ro3rmJ1WzdnOYaUXrtAiQPI3aLX4lkTy7wMTjhkta78g-4hSXZ4QQ6X2jp1WqX3-AdqnT7cnZFD7Z0i-QACLTygN0oIy2F8bwlvRaXxZeciYFyqyeYk33JwpuMr/s1600-h/distinguishname.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh46IjSt6itEX-044bX0ro3rmJ1WzdnOYaUXrtAiQPI3aLX4lkTy7wMTjhkta78g-4hSXZ4QQ6X2jp1WqX3-AdqnT7cnZFD7Z0i-QACLTygN0oIy2F8bwlvRaXxZeciYFyqyeYk33JwpuMr/s320/distinguishname.png&quot; vt=&quot;true&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;color: #999999;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #999999;&quot;&gt;Note: PSO can be applied to users and groups, NOT OU&#39;sr distinguishedName&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/3737194257008751584/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/fine-grained-password-policy.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/3737194257008751584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/3737194257008751584'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/fine-grained-password-policy.html' title='Fine Grained Password Policy'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjo6wO5eI5BGkc-qMvOmAKJk22KrEhhBqisFkn4M3_SoKJxMSoL-IyUk_cT5QvrUPqA333qfAiGDUV7_hhzDXsndnPGoF7nzN9srZDve3MkNmOvdCxbCt7zWXtm-ytZ_c_aOslUmkcd0Xhr/s72-c/adsi.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-1012488997835781941</id><published>2010-03-06T19:22:00.000-08:00</published><updated>2010-03-06T19:22:22.011-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="loopback processing"/><title type='text'>Group Policy Loopback Processing</title><content type='html'>loopback processing works at computer level&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
if computerlockdown policy has loopback processing, it takes one of 2 things&lt;br /&gt;
&lt;br /&gt;
it take either all of my settings will add to desktoplockdown settings, or all of my settings will replace desktoplockdown&lt;br /&gt;
&lt;br /&gt;
so whoever has loopback processing wins&lt;br /&gt;
&lt;br /&gt;
group policy that has loopback processing is generally computer side group policy&lt;br /&gt;
&lt;br /&gt;
group policy works at the computer level of the group policy object side&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Example&lt;br /&gt;
&lt;br /&gt;
For example user1 has desktoplockdown policy&lt;br /&gt;
user1 log into PC1, desktoplockdown policy will apply to him&lt;br /&gt;
if PC1 is in a OU that has computerlockdown policy applied or linked to it&lt;br /&gt;
When user1 login to PC1, there is 2 things that can happen&lt;br /&gt;
PC1 has loopback processing, if loopback processing says replace, then desktoplock down has no say what user1 can or cant do&lt;br /&gt;
at that point user1 is subjected to computerlockdown policy</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/1012488997835781941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/group-policy-loopback-processing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/1012488997835781941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/1012488997835781941'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/group-policy-loopback-processing.html' title='Group Policy Loopback Processing'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-4308100643565361727</id><published>2010-03-04T05:06:00.000-08:00</published><updated>2010-03-04T05:06:39.861-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Windows Deployment Services"/><title type='text'>Windows Deployment Services WDS</title><content type='html'>An image can take on a hard drive, stored on a server and then deploy via broadcast to several &lt;br /&gt;
machines all at once.&lt;br /&gt;
&lt;br /&gt;
Steps&lt;br /&gt;
1. Join the machine to the domain&lt;br /&gt;
2. Install the WDS role&lt;br /&gt;
3. Add images from windows 2008 install disk (and vista, if you are deploying clients)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - You&#39;ll need to add these two images from the source folder&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * The boot.wim&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * The install.wim&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Also, if you are planning on deploying 32-bit and 64-bit editions, you&#39;ll need to grab the WIM files&lt;br /&gt;
from both the 32-bit and 64-bit disks&lt;br /&gt;
&lt;br /&gt;
Note: To install windows operating system from a windows deployment services server, either the client computer must be PXE-enabled, or you must use the windows server 2008 version of windows preinstllation environment (windows PE)&lt;br /&gt;
&lt;br /&gt;
PXE means the pc should be able to boot from its network card&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;WDS Role Services&lt;/strong&gt;&lt;br /&gt;
&amp;nbsp;1. Deployment Server, which provides full functionality of windows deployment service, with this one we can create and customize images&lt;br /&gt;
2. Transport server is used if you want to transmit data using multicasting&lt;br /&gt;
&lt;br /&gt;
To configure WDS, click Action and use Configuration wizard &lt;br /&gt;
&lt;br /&gt;
Install images folder contains available operating systems that you want to install&lt;br /&gt;
Boot image only allows the machine to bootup to install the server&lt;br /&gt;
&lt;br /&gt;
NOTE: There is a boot image available in vista disc, DO NOT USE IT. Do not use vista install.vim file.&lt;br /&gt;
Because when you use vista isntall.vim file you can deploy only one machine at a time.&lt;br /&gt;
&lt;br /&gt;
We can install vista using server 2008 install.vim file. For example if you want to install 10 vista clients at the&lt;br /&gt;
same time, you cannot do from vista install.vim, but from server 2008 install.vim you can do.&lt;br /&gt;
&lt;br /&gt;
Now i need to install server 2008 into 3 machines at the sametime&lt;br /&gt;
Create 3 virtual machines, and select deploy using network based server&lt;br /&gt;
&lt;br /&gt;
Now go Server Manager, Windows Deployment, Multicasting&lt;br /&gt;
Rightclick, Create Muticast Transmission&lt;br /&gt;
Select which operating system to install&lt;br /&gt;
&lt;br /&gt;
now reboot the clients i am going to install server 2008&lt;br /&gt;
&lt;br /&gt;
Unattended installation&lt;br /&gt;
right click image group and select unattended installation file</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/4308100643565361727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/windows-deployment-services-wds.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/4308100643565361727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/4308100643565361727'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/windows-deployment-services-wds.html' title='Windows Deployment Services WDS'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-1719875951543665073</id><published>2010-03-03T23:22:00.000-08:00</published><updated>2010-03-03T23:22:53.732-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hyper-V"/><title type='text'>Hyper-V</title><content type='html'>Hyper-V A server role in windows server 2008 enterprise edition that allows you to run multiple operating systems in virtual machines in a single machine.&lt;br /&gt;
&lt;br /&gt;
Virtual Machine - A software based instance of an operating system that uses shared physical hardware&lt;br /&gt;
&lt;br /&gt;
VHD - Virtual Hard Disk - A file that lives in physical HDD that acts like physical HDD on a virtual machine.</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/1719875951543665073/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/hyper-v.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/1719875951543665073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/1719875951543665073'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/03/hyper-v.html' title='Hyper-V'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8266630769448616975.post-2209930034637175524</id><published>2010-02-23T05:12:00.001-08:00</published><updated>2010-02-23T05:12:35.542-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="gpresult"/><title type='text'>gpresult</title><content type='html'>gpresult is a command line utility for active directory that will display the effects of group policy on a local or remote machine. You can use it to create reports on GPOs affecting users and computers. It’s available for Server 2000, 2003, 2008, Microsoft, windows xp, vista, and 7. (Requires opening ports on firewall.) The group policy results reports will save as either HTML or XML documents showing the applied GPOs and which GPOs affect which settings in group policy. It’s a toll that can be used in a workgroup or domain (active directory)&lt;br /&gt;
&lt;br /&gt;
commands used…&lt;br /&gt;
gpresult /R&lt;br /&gt;
&lt;br /&gt;
gpresult /H Test.html&lt;br /&gt;
&lt;br /&gt;
gpresult /S DESKTOP101 /USER my\gandrews /H Test.html</content><link rel='replies' type='application/atom+xml' href='http://windowsnetworkingtutorials.blogspot.com/feeds/2209930034637175524/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/02/gpresult.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/2209930034637175524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8266630769448616975/posts/default/2209930034637175524'/><link rel='alternate' type='text/html' href='http://windowsnetworkingtutorials.blogspot.com/2010/02/gpresult.html' title='gpresult'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>