2010/03/13
2010/03/12
2009/11/30
2009/11/26
SBS 2003 push mail 解決方法
Posted using ShareThis
for HTC 及 iPhone
2009/10/23
Exchange Server 2007: Setting Message Size Limits
Do individual size limits bypass the Organization size limit?
Setting higher message size limits on an Exchange recipient bypasses the maximum message sizes in the Exchange Organization configuration, albeit only for internal messages, not for messages sent to or received from unauthenticated sources.
2009/10/21
2009/04/27
Improving TS Gateway availability using NLB
here
Recommendations about NLB parameters for TS Gateway farm scenario:
Cluster operation mode (multicast / unicast): If the gateway servers have multiple network adapters, use unicast cluster operation mode. It is a requirement that the TS Gateway farm can communicate between gateway servers. So if you have only a single NIC on gateway servers, then multicast should be used to enable communication between gateway servers in the cluster.
IP Affinity: In most cases, especially when clients originate from many different locations on the internet, like their homes, set the IP affinity to Single. There is one scenario where the IP affinity must be set to None: if many of the TS Gateway clients are behind NAT devices causing all connections to end up with the same IP and hence the same TS Gateway server, then IP affinity set to Single on NLB will load one server more than another (for example, all remote workers in a branch behind a NAT with a single external IP). In this scenario IP affinity should be set to None.
It is recommended to configure TS Gateway for a farm scenario, no matter what affinity is used. This allows users to connect in the situation where the 2 SSL connections (RPC_IN_DATA, RPC_OUT_DATA channels) originate from different client IP addresses. For example, suppose a client is trying to connect from within an organization having two proxies to the Internet (or a proxy having two Internet IP addresses) which are used randomly. In this scenario, If TS Gateway farm is not configured then the connection might fail for any NLB IP Affinity setting because SSL connections (RPC_IN_DATA, RPC_OUT_DATA) from the client may go to different TS Gateway servers.
2009/04/16
2009/04/09
exchange 2003 owa 開啟 pdf
Description of the KnownContentTypes registry entry for Outlook Web Access in Exchange Server 2003 Service Pack 1
2009/04/07
2009/03/31
2009/03/28
upgrade from Windows Server 2000 to Windows 2003 Server
2009/03/26
2009/03/20
cisco asa 5505 設定
Step 1 Locate an RJ-45 to RJ-45 Ethernet cable.
Step 2 Connect one end of the Ethernet cable to an Ethernet port (ports 0 through 7), as shown in Figure 4-2. (Typically Ethernet port 0 is used to connect to an Internet router.)
===
Step 1 Make sure that the speed of the PC interface to be connected to one of the ASA 5505 inside ports is set to autonegotiate. This setting provides the best performance.
By default, the ASA 5505 automatically negotiates the inside interface speed. If autonegotiate is not an option for the PC interface, set the speed to either 10 or 100 Mbps half duplex. Do not set the interface to full duplex; this causes a duplex mismatch that significantly impacts the total throughput capabilities of the interface.
Step 2 Configure the PC to use DHCP (to receive an IP address automatically from the ASA 5505), which enables the PC to communicate with the ASA 5505 and the Internet as well as to run ASDM for configuration and management tasks.
Alternatively, you can assign a static IP address to your PC by selecting an address in the 192.168.1.0 subnet. (Valid addresses are 192.168.1.2 through 192.168.1.254, with a mask of 255.255.255.0 and default route of 192.168.1.1.)
When you connect other devices to any of the inside ports, make sure that they do not have the same IP address.
Note The MGMT interface of the adaptive security appliance is assigned 192.168.1.1 by default, so this address is unavailable.
Step 3 Use an Ethernet cable to connect the PC to a switched inside port on the rear panel of the ASA 5505 (one of the ports numbered 1 through 7).
Step 4 Check the LINK LED to verify that the PC has basic connectivity to the ASA 5505.
When connectivity is established, the LINK LED on the front panel of the ASA 5505 lights up solid green.
2009/03/18
Session Directory and Load Balancing Using Terminal Server
Summary
Terminal Server Session Directory is a feature that allows users to easily and automatically reconnect to a disconnected session in a load balanced Terminal Server farm. The session directory keeps a list of sessions indexed by user name and server name. This enables a user, after disconnecting a session, to reconnect to the correct terminal server where the disconnected session resides to resume working in that session. This reconnection will work even if the user connects from a different client computer.
This white paper discusses how to plan and deploy a load balanced terminal server farm using session directory, and how the session directory operates in a load balanced environment.
Included in This Document•
Session Directory Overview
•
Load Balanced Configurations
•
Session Directory
•
Summary
•
Appendix
以 Windows 負載平衡服務使用終端機伺服器 243523
您可以使用 WLBS (或 Windows 2000 中的 NLB) 在一組「終端機伺服器」中 散佈眾多的「終端機伺服器」用戶端。下列清單包含設定 WLBS 或 NLB 的 指導方針。 將使用者資訊、系統資訊和一般資料儲存在一個位置上,例如 SQL 伺服器內, 這樣每個「終端機伺服器」便能服務網路上的所有使用者。我們建議您使用 Microsoft Cluster Services (MSCS) 共用資料。
WLBS/NLB 要靠用戶端的 IP 位址 (如果您使用「無相似性」,則為連接埠編號) 來 判斷哪一個「終端機伺服器」為用戶端提供服務。如果您將 WLBS/NLB 設定為使用「相似性」, 則只要您不變更「終端機伺服器」叢集,用戶端所用的 IP 位址會由相同的「終端機伺服器」 提供。
在工作階段中,當「終端機伺服器」用戶端從「終端機伺服器」中斷連線時, 「終端機伺服器」會將該用戶端的工作階段標示為「中斷連線」。您在該 工作階段內所用的用戶端程序和虛擬記憶體空間,仍會保留在伺服器上, 只要「中斷連線」的工作階段狀態沒有結束,這些資訊便會對應至使用者的 「工作階段識別碼」。如果您將用戶端電腦重新連線到「終端機伺服器」而該 工作階段仍處於「中斷連線」狀態的話,可以用該工作階段狀態資訊繼續 使用在中斷連線之前所用的相同程序和程式。
「終端機伺服器」不支援將記憶體內的工作階段狀態複製到其他的「終端機伺服器」 或與其他的「終端機伺服器」共用這些資訊。如果您在工作階段時從「WLBS/NLB 終端機伺服器」 叢集成員之一的「終端機伺服器」中斷連線,而在重新連接到該「終端機伺服器」之前,用戶端 的 IP 位址變更了,這時候,連線的要求可能會由叢集中,不同的「終端機伺服器」提供服務。 如果發生這種現象,記憶體內的工作階段便會繼續使用原始伺服器上的資訊。您需要在新的 「終端機伺服器」上啟動新的工作階段。
如果您需要中斷連線的用戶端連線到相同的「終端機伺服器」,才能回復「中斷連線」工作階段, 用戶端的電腦需要使用靜態的 IP 位址,而 WLBS/NLB 必須設定為使用「單一相似性」。 請注意,透過您的 ISP、從 LAN 上的 DHCP 伺服器所取得的 IP 位址可能會變更,如同漫遊使用者的 IP 位址。如果固定 IP 不是必要條件,則您可以在從「終端機伺服器」叢集要求服務時,使用 用戶端電腦上的不同 IP 位址,且可將 WLBS/NLB 設定成不使用「相似性」。
2009/03/10
NLB 單點及多點
今天設定單點不通,ping 不到168.95.1.1 , 改成多點就OK.
文件說:預設用單點即可.
A Windows NLB cluster can be configured in either unicast or multicast mode, where unicast is the default mode.
Unicast Mode
With the WNLB cluster configured in unicast mode, the MAC address of each server’s network adapter will be changed to a virtual cluster MAC address, which is the MAC address that will be used by all servers in the Windows NLB cluster. When unicast mode is enabled, clients can only connect to the servers using the cluster MAC address.
Multicast mode
With the Windows NLB cluster configured in multicast mode, a multicast MAC address is added to the cluster adapter of each server in the cluster. Note that I write “is added”, as each server will retain their original MAC addresses.
A Windows NLB cluster, no matter what mode it is configured in, works with just a single network adapter installed in each server, but it is recommended to install a second network adapter in each server, in order to achieve optimal performance, and to separate ordinary and cluster related network traffic.
So what mode should I use for my Exchange 2007 Client Access solution and how many network adapters should I install in each Client Access server? Well, best practice recommendations are to install two network adapters and use unicast mode, so that the host and cluster network traffic are each separated in their own respective network adapter2009/03/09
本機升級win 2003 to win 2008
In-Place Upgrade from Windows Server 2003 Domain Controller to Windows Server 2008
2009/03/02
NLB相關的文件
Deployment Options for Hub Transport Servers
NLB Fundamentals
Hub transport and CAS combined role & Network load balancing
Checklist: Enabling and configuring Network Load Balancing
How To Set Up TCP/IP for Network Load Balancing in Windows Server 2003
How-To: Configure Network Load Balancing (NLB) with Two Network Adapters
如何設定網路負載平衡參數在 Windows Server 2003 中
2008/02/03
2008/01/20
2008/01/15
2008/01/13
2008/01/04
Repair Install For Vista - Vista Forums
http://www.vistax64.com/tutorials/88236-repair-install-vista.html
2008/01/03
2008/01/02
Microsoft Virtual Server support policy
http://support.microsoft.com/kb/897613/
2007/12/31
Exchange Server 2007 SP1 的新功能
http://technet.microsoft.com/zh-tw/library/bb676323.aspx
2007/12/26
如何藉由使用 ISA Server 封鎖 MSN Messenger 傳輸及 Live Windows Messenger 傳輸"
KB:925120
Exchange 2007 SP1 BuildtoBuild Upgrade 錯誤
http://blog.5dmail.net/user1/1/20071251222.html
2007/12/20
Description of the support process for issues that are related to the "Outlook is retrieving data" message in Outlook 2002 and Outlook 2003
2007/12/17
Description of System Center Essentials 2007 post-release hotfix rollup
The Microsoft System Center Essentials 2007 post-release hotfix rollup is available.
2007/12/16
2007/12/10
2007/12/07
以管理為優先的Windows Server 2003 R2(上)
Microsoft Services for NFS的前身是Services for UNIX 3.5,但更新後的Microsoft Services for NFS還具有下列新功能:
•x64 位元的支援:Microsoft Services for NFS可安裝在Windows Server 2003 R2的所有版本上,包括x64位元版本。
•更新的Microsoft Services for NFS Administration,這是MMC嵌入式管理單元,讓管理者能以圖形介面工具管理NFS。
•更穩定的可靠性
•支援特殊的UNIX裝置(mknod)
Microsoft Services for NFS允許UNIX用戶端存取Windows Server 2003 R2上的資源。企業或組織內若有UNIX檔案伺服器和UNIX用戶端,而且UNIX用戶端可存取UNIX檔案伺服器裡的檔案資源,若要充分利用Windows Server 2003 R2的功能(例如共用資料夾的陰影複製),可以將UNIX檔案伺服器上的資源,移至Windows Server 2003 R2伺服器,然後設定Microsoft Services for NFS,以啟用執行NFS軟體的UNIX用戶端存取權,如此一來,所有UNIX用戶端都不需要進行任何變更,就可以透過NFS通訊協定存取移至Windows Server 2003 R2伺服器的檔案資源。
此外,Microsoft Services for NFS也可以讓Windows Server 2003 R2伺服器存取UNIX檔案伺服器上的資源。例如混用Windows與UNIX的環境,可能會有資源(例如檔案)存放在UNIX檔案伺服器,若UNIX檔案伺服器也使用NFS,就可以使用Microsoft Services for NFS讓Windows Server 2003 R2伺服器存取UNIX伺服器上的資源。
XADM: Notifying Exchange and Outlook Clients of Password Expiration
2007/12/06
VOIP
FXO(Foreign eXchange Office)與FXS(Foreign eXchange Station)他們是一對。比如家裏面用的電話,是用一個線,把你家電話和郵電局的交換機連在一起。交換機上面的那個介面就是FXS,你家電話上的那個口就是FXO。FXS要提供電流,FXO就像一個開關,負責線路的閉合(拿起話機)和打開(掛上話機)這些都是電信上面的知識,VOIP常見的介面類型(和交換機連接)。過去沒有規範的時候, FXS也叫AL FXO叫做AT。FXO是接PBX或者PSTN的,FXS是接電話機的。如果一個閘道上有FXO口和FXS口的,那接FXS口的電話可以打通FXO口所連的網路。
FXO與FXS應用架構圖。
FXS--可接一般話機、傳真機、PBX 外線,提供 Dial-Tone 跟 Voltage
FXO--可接局端來的電話線、PBX 內線,送出 DTMF 完成撥號動作
傳統電話交換機 PBX 與 VGW (Voice Gateway) 的串接
PBX(交換機) 為一般企業中使用的語音交換機,為了讓多人可同時並方便使用 VOIP 語音服務,VGW 與 PBX 的串接方式就顯得格外重要。此外,市面上 PBX 型號形形色色,PBX 所發送的訊號亦是非常複雜,無法以單一設定串接所有 PBX。
2007/11/28
2007/11/26
2007/11/25
OpsMgr, SCE And MOM Blog : System Center Essentials post RTM Hotfix Rollup released to the Web
Does the hotfix rollup apply to you?
If you already have Essentials installed this hotfix rollup does not apply to you.
If you already have Essentials installed and you experience the symptoms referred to in KB936339 or KB937467 please refer to those KB articles on how to obtain the hotfixes separately so that you can apply them in your environment.
ReSearch This! - Rod Trent at myITforum.com
ReSearch This! is a common repository for sharing your knowledge on how to resolve alerts for Operations Manager 2007, System Center Essentials and Microsoft Operations Manager 2005. It provides a method to search the SystemCenterForum community repository for alert resolutions and to submit information to share how you have resolved alerts in your environment.
I like to think of this as shared “company knowledge” for the community at large.
These management packs are available for download at:
http://systemcenterforum.org/wp-content/uploads/ReSearchThisOpsMgr.zip (Operations Manager 2007 and SCE)
2007/11/23
CE 500 smartport
Smartport Roles
The Smartports are preconfigured switch ports that provide preset Cisco recommended network enhancements, Quality of Service (QoS) and security. Catalyst Express 500 series switches have a number of Smartport roles. Each port role is just a configuration template. With these templates, users can consistently and reliably configure essential security, availably, and QoS features with minimal effort and expertise. Smartport roles simplify the configuration of critical features.
The port roles are based on the type of devices to be connected to the switch ports. For example, the Desktop port role is specifically for the switch ports that are connected to desktop or laptop PCs.
| Smartport Role | Description |
|---|---|
| Desktop | Apply this role to ports that are connected to desktop devices, such as desktop PCs, workstations, notebook PCs, and other client-based hosts.
|
| Switch | Apply this role to ports that are connected to other switches.
|
| Router | Apply this role to ports that are connected to WAN devices that connect to the Internet, such as routers and Layer 3 switches with routing service capabilities, firewalls, or VPN Concentrators.
|
| IP Phone+Desktop | Apply this role to ports that are connected to IP phones. A desktop device, such as a PC, can be connected to the IP phone. Both the IP phone and connected PC have access to the network and the Internet through the switch port. This role prioritizes voice traffic over data traffic to ensure clear voice reception on the IP phones.
|
| Access Point | Apply this role on switch ports that connect to non-Power over Ethernet (PoE) and PoE-capable wireless access points (APs). Connected to the AP are mobile devices, such as wireless laptop PCs.
Note: Functionality of Cisco Wireless Bridges are more similar to that of a switch. So, Cisco recommends the Switch smartport role for Wireless Bridges. |
| Server | Apply this role to ports that are connected to servers that provide network services, such as Exchange servers, collaborative servers, terminal servers, file servers, Dynamic Host Configuration Protocol (DHCP) servers, IP private branch exchange (PBX) servers, and so on. This role is for Gigabit or non-Gigabit ports, based on the server type to be connected.
This role prioritizes server traffic as trusted, critical, business, or standard, based on the function of the server.
|
| Printer | Apply this role on switch ports that connect to a printer, such as a network printer or an external print server. This role prevents printer traffic from affecting voice and critical data traffic.
|
| Guest | Apply this role to ports that are connected to desktop devices and to APs to provide guest wireless access.
|
| Other | Apply this role on switch ports if you do not want to assign a specialized role on the port. This role can be used on connections to guest or visitor devices, printers, desktops, servers, and IP phones. It allows for flexible connectivity of non-specified devices.
|
| Diagnostic | Customers can connect diagnostics devices to monitor traffic on other switches (can be configured using Cisco Network Assistant only). |
2007/11/15
2007/11/13
2007/11/11
2007/11/07
Cisco - Understanding Service Access Point Access Control Lists
Filtering NetBIOS
NetBIOS traffic uses SAP values 0xF0 (for commands) and 0xF1 (for responses). Typically, network administrators use these SAP values to filter this protocol. The access list entry shown below permits NetBIOS traffic and denies everything else (remember the implicit deny all at the end of each ACL):
access-list 200 permit 0xF0F0 0x0101
Using the same procedure shown in the previous section, you can determine that the above ACL permits SAPs 0xF0 and 0xF1.
On the contrary, if the requirement is to block NetBIOS and allow the rest of the traffic, use the following ACL:
access-list 200 deny 0xF0F0 0x0101
access-list 200 permit 0x0000 0xFFFF
IBM - 4690 OS and communication with S/390 using SNA via WAN with routers to provide 3270 sessions
Problem
I want to know the specific configuration to communicate to a 4690 OS store controller with IBM® Mainframe S/390® using SNA via WAN where routers are included, to provide 3270 sessions. How can we filter the messages from the POS system to permit only IP and SNA (3270 emulation) messages to be sent and received between locations? We do not want NetBIOS messages to exit from the store.
Two solutions to the IP and SNA WAN need are listed below. This LAN-WAN support is provided by the routers, and the only 4690 tuning required would be to review 4690 SNA timers for WAN delay implications. Search the Knowledgebase for "4690 OS Logical File Names" for information regarding LAN/SNA timers.1) Route IP and bridge SNA
Setting up a router to route IP and bridge SNA is feasible and is a normal capability of routers. It is recommended that other non-routable protocols be prevented from traversing the WAN, so filters might have to be put in place to Deny RPL, NetBIOS and TCC frames. If you are using SAP filters, the associated SAPs are:
0xF0 for NetBIOS Flows
0xE8 for TCC flows
0xF8 and 0xFC for RPL flowsConsult your router vendor documentation about how to set up this environment.2) Route IP and use Encapsulation Technique for SNA
Many router vendors provide an encapsulation technique to pass SNA data over the IP network. In IBM router products (2210, 2212, and 2216) two strategies are available:
Data Link Switch
Enterprise Extender Consult your router documentation for details about encapsulation techniques.
Cisco - DLSw+ SAP/MAC Filtering Techniques
Contents
IntroductionNetwork DiagramDLSw+ SAP Filtering Techniques
Configuring LSAP Output Access Lists at Remote OfficesConfiguring dlsw icannotreach saps at Central RouterConfiguring dlsw icanreach saps at Central RouterDLSw+ MAC Filtering Techniques
Configuring dlsw icanreach mac-address at Central RouterConfiguring dlsw icanreach mac-exclusive at Central RouterConfiguring dlsw mac-address at Remote RoutersConfiguring dlsw icanreach mac-exclusive remote at Central RouterRelated Information
System Center Essentials 2007 支援的 Microsoft SQL Server 版本
部署環境需求
以下清單說明 System Center Essentials 2007 支援的 Microsoft SQL Server 版本。
- SQL Server 2005 Express Edition SP1 或更新版本 (限 32 位元)
- SQL Server 2005 Workgroup Edition SP1 或更新版本 (限 32 位元)
- SQL Server 2005 Standard Edition SP1 或更新版本 (32 位元及 64 位元)
- SQL Server 2005 Enterprise Edition SP1 或更新版本 (32 位元及 64 位元)
2007/11/05
2007/11/02
2007/10/30
Exchange 2003 queues 很多信
In Exchange Server 2003 or in Exchange 2000 Server, the Exchange Server queues are filled with many non-delivery reports from the postmaster account because of a reverse non-delivery report attack
Link完修IBM刀鋒
1.報修IBM刀鋒網路不通,工程師到場發現網路模組無法設定,報修
2.網路模組無法設定:透過MM-I/O Module - bay 1 - start web session - 進入nortel module 無法config.
處理:
1.原廠on-site,覺得NORTEL模組OK,恢復工廠值
2.nortel module INT1-14為內部port / EXT1-6為外部module
3.EXT1-4設定trunk與cisco switch連接
4.INT1-4及EXT5-6設定為VLAN 2 連接d-link switch 為DMZ
5.nortel trunk 設定複製另一台刀鋒設定檔(dump),再利用telnet 方式下指令完成設定
6.不會用nortel web UI建立VLAN,改用telnet 建立VLAN2
7.nortel web UI switch port 修改 INT1-4 VID:2
8.EXT5-6 enable tag and 改為VLAN2
9.指令語法:/c/port ..../c - dump or /c/l2/vlan
10.nortel特性:現有的config must apply and save
11.config save之後成為active block ,原來的config會變成backup block






