2010/05/05
2010/05/04
2010/05/03
Windows server 2008 R2 dcpromo 一直無法成功
期間遇到幾個失敗
1.FSMO:domain naming and schema master miss, use seize 取回OK
2.adprep32 /forestprep 一半失敗,AD架構要開啟允許修改
3.prepare OK之後,開始 dcpromo , but 一直無法成功 結果在 kb 找到答案:KB 2000939
troubleshoot public folder replicate is stop between ad site. - Windows Live
公用資料夾的問題終於處理ok
原因是Public folder 的 proxyaddress衝突
利用adsiedit錯開即可。
Windows Server 2008 R2: Windows Storage Server 2008
Microsoft Windows Storage Server 2008 is built upon an optimized release of the reliable and flexible file services of Windows Server 2008 for better file serving performance. Microsoft then adds advanced storage technologies such as file de-duplication and an iSCSI software target for unified file- and block-based storage and packages it for delivery within storage appliances. Similarly, Microsoft partners then offer specialized hardware and introduce additional software components to create WSS08-based appliances. Windows-powered storage appliances give customers new storage capabilities, simplified deployment and easier management while assuring seamless synergy in their Windows infrastructure in a cost-effective and high-performance platform, and is delivered through our OEM Partners.
Exchange 2003 - Planning Roadmap for Upgrade and Coexistence: Exchange 2010 Help
First, you upgrade all Internet-facing Active Directory sites by doing
the following:
- Upgrade existing Exchange 2003 servers to Exchange 2003 SP2.
- Deploy Exchange 2010 servers in this order:
- Client Access
- Hub Transport
- Unified Messaging
- Mailbox
- Client Access
- Configure the Exchange 2003 front-end server and the Exchange 2010 Client Access server
- Configure the Exchange 2010 Hub Transport servers (s)
- Configure the Unified Messaging server(s)
- Move mailboxes from Exchange 2003 to Exchange 2010
Then, you upgrade all internal Active Directory sites in the same manner.
2010/05/02
2010/04/30
2010/04/29
exchange 2000 public folder 複寫 in sync and local Modified
since changes were last sent.
Local Modified indicates that there have been changes made to local public folder replicas that have not yet been sent. So if you see the local modified for Exchange 2003 server there is no need to worry, if it is for 2000 it means that there are changes yet to be replicated.
As far as best way to know if replication completed, I rely on looking at the size and number of items in the local public folder store for each PF and compare both source and target store (This is not feasible in large environments and you might need to export the list and compare using excel).
thanks,
2010/04/27
Public Folder Replication Troubleshooting – Part 1: Troubleshooting the Replication of New Changes
New-DatabaseAvailabilityGroup: Exchange 2010 Help
you must add the Exchange Trusted Subsystem universal security group to the local Administrators group on the witness server prior to creating the DAG
Moving public folder replicas from Exchange 2000 to Exchange 2007
2010/04/26
2010/04/22
2010/04/21
Mailbox Database 失敗
經過時間: 00:00:09
Mailbox Database 0203679921
失敗
錯誤:
xxxxx.com.tw 上的 Active Directory 作業失敗。此錯誤無法重試。其他資訊: 存取權限不足,無法執行操作。。
Active Directory 回應: 00002098: SecErr: DSID-03150A45, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
使用者的存取權限不足。
已嘗試的 Exchange 管理命令介面命令:
move-DatabasePath -Identity 'Mailbox Database 0203679921' -EdbFilePath 'E:\EXCHDB\Mailbox Database 0203679921\Mailbox Database 0203679921.edb' -LogFolderPath 'E:\EXCHDB\Mailbox Database 0203679921'
經過時間: 00:00:09
exchange 2010 管理權限
移出自Exchange Organization Administrators
得到的結果
將user加入 Exchange Organization Administrators
得到的結果
CAS / hw loadbalancer configuration
Ok got It working.
Setting static ports made it easy to configure the loadbalancer.
Any reasons why it's dynamic in the default exchange 2010 configuration ?
And to share the configuration (foundry serveriron) :
==========
server real exchangenode01
port 25
port 80
port http healthck exchangenode01
port 443
port 135
port 55000
port 55001
server real exchangenode02
port 25
port 80
port http healthck exchangenode02
port 443
port 135
port 55000
port 55001
server virtual exchange
sym-priority 50
dyn-sym-pri-factor 30
advertise-vip-route
vip-route-subnet-mask-length 32
port smtp
port http sticky
port ssl sticky
port 135 sticky
port 55000 sticky
port 55001 sticky
track-group http ssl 135 55000 55001
bind smtp exchangenode01 smtp exchangenode02 smtp
bind http exchangenode01 http exchangenode02 http
bind ssl exchangenode01 ssl exchangenode02 ssl
bind 135 exchangenode01 135 exchangenode02 135
bind 55000 exchangenode01 55000 exchangenode02 55000
bind 55001 exchangenode01 55001 exchangenode02 55001
==========
How to Upgrade Default Address Lists from LDAP Filters to OPATH Filters: Exchange 2007 Help
- 已使用 Google 工具列寄出"
A public folder rule with more than six recipients does not replicate
Exchange 2000 PF 無法與exchange 2007複寫.
2010/04/20
Windows Server 2008 :: AD RMS 安裝 - I'm small, so share nothing...- 點部落
AD RMS 安裝時會用到兩個帳戶,一是 ADRMSADMIN 即安裝帳戶,會授予 Domain Enterprise Admin 與 SQL Server SystemAdmin,如果是安裝在新的伺服器上,則 ADRMSADMIN 要賦予本機 Administrators 群組權限來安裝;另一為 ADRMSSRVC 服務帳戶,此帳戶是 Domain user 即可,但如果是在 DC 上做安裝,小弟至少給它 Account Operator 才能進行安裝。
最後,AD RMS 會建立三個資料庫用來儲存 AD RMS 資訊,這裡可以選擇使用 Windows 內建或者另外安裝 SQL Server 資料庫。
2010/04/19
gigabit ethernet 測試
10/100 : 7000-8000 KB/sec
gigabit : 24000-25000 KB/sec
約提昇 3 倍速度!!!
2010/04/09
Hyper-V 實體硬碟
今天測試將實體硬碟在虛擬機器卸離之後,再到Host來進行連線,仍可以看見硬碟裡面的資料。
2010/03/25
ocs 參考資料
http://blogs.technet.com/ucedsg/archive/2009/01/20/what-do-i-need-to-prepare-for-to-deploy-ocs-r2.aspx
What do I need to prepare for to deploy OCS R2?
With R2 on the horizon (Feb. 3rd), I figured you should know about some of the things to prepare for deploying R2.Run the OCS Best Practice Analyzer
If you have OCS 2007 today, you should run the OCS BPA to get a snapshot of your OCS environment. Fix any issues identified prior to rolling out R2 to help ensure a smoother transition to R2.
Do you have any 64-bit domain controllers?
If the answer is yes, you will have an easier time with OCS R2 prep work as well as with any Exchange 2007 installation.
If the answer is no, you may consider installing a 64-bit DC/GC since you can consolidate more DCs and the ratios of DC/GCs for things like Exchange improve (1 DC:8 cores of Exchange mailbox vs 1:4 with 32-bit DCs).
The OCS R2 Prep wizard only preps 64-bit Domain controllers so if you have 32-bit DCs you will need to run the command line LDIFDE tool to modify the schema from the command line.
Sample LDIFDE run on a 32-bit DC:
ldifde –i –v –k –s DC1 –f schema.ldf –c DC=X “DC=contoso,DC=com” –b Administrator password
What flavors of Active Directory work with OCS R2?
· All global catalog servers in the forest where you deploy Office Communications Server run Windows Server 2003 with SP1, Windows Server 2003 R2, or Windows Server 2008.
· All domains in which you deploy Office Communications Server are raised to a domain functional level of Windows Server 2003 or Windows Server 2008. You cannot deploy Office Communications Server 2007 R2 in a Microsoft Windows 2000 mixed, Windows 2000 native, or Windows 2003 interim domain.
· The forest in which you deploy Office Communications Server is raised to a forest functional level of Windows Server 2003 or Windows Server 2008. You cannot deploy Office Communications Server 2007 R2 in a Windows 2000 mixed, Windows 2000 native, or Windows 2003 interim forest.
Prep the Schema
R2 requires an AD schema extension so you, or someone with rights, will need schema administrator rights to deploy R2. Obviously, this is something that needs to be planned, approved, etc.
Run the R2 schema prep off hours as any schema modification forces a full global catalog replication (e.g. a 1GB DIT file means 1GB of AD data replicated across all GCs in your environment).
Prep the Forest
You also need to Forest prep to create the global settings and universal groups specific to OCS R2. This requires Enterprise admin rights to perform.
Prep the Domain
Finally, for each domain where you will host OCS users you will need to prepare the AD domain to configure OCS rights, etc. This requires domain admin rights to perform.
What else?
You should certainly be thinking about consolidated Edge and Front End architectures for most roles in addition to other functionality you may have to plan for such as Group Chat server, audio conferencing, response groups, etc.
Note: Some of this information was taken from the upcoming OCS R2 Deployment whitepaper.
In my next blog, I will talk about how to get from OCS RTM to OCS R2.
Published Tuesday, January 20, 2009 11:06 PM by markga Filed under: OCS, R2, deployment, schema
OCS 2007 R2 Schema prepare
If you need to extend the Active Directory schema on a domain controller running a 32-bit operating system, or if you need to run the schema preparation step on a domain controller that is not the schema master, you can use the Ldifde.exe tool to import the schema file. The Ldifde.exe tool comes with most versions of the Windows operating system.
http://technet.microsoft.com/en-us/library/dd441329%28office.13%29.aspx
同事問我如何在child domain prepare exchange server schema
我原來以為這個是for exchange的,結果不是,真是年紀大了
這個是給OCS 2007r2用的,上次在客戶那裡遇到的問題也是這個OCS2007 prepare.
2010/03/23
2010/03/15
SBS 2003維修
2010/03/13
蓬蓽生輝 不是 蓬壁生輝
╳ 蓬壁生輝
「蓽」是指以荊竹樹枝之類所編成的籬笆或遮擋物;「壁」是牆壁的意思。「
蓬蓽」形容簡陋的房屋,也用來謙稱自己的住宅。「蓬蓽生輝」形容貴客來訪
或接受別人題贈的詩畫而使主人感到增光不少,所以當用「蓽」而非「壁」。
exmerge 權限問題
administrator 不一定有權限
建議新增一組安全性群組
KB
如果沒有 "安全性" 頁籤
請照以下方式
1. 啟動 「 登錄編輯程式 」 (Regedt32.exe)。
2. 在登錄中找到下列機碼:
HKEY_CURRENT_USER\Software\Microsoft\Exchange\ExAdmin
3. 在 [編輯] 功能表上按一下 [新增值],並再新增下列登錄值:
數值名稱: ShowSecurityPage
資料類型: REG_DWORD
值: 1
4. 結束 「 登錄編輯程式 」。
2010/03/12
2009/11/30
2009/11/26
SBS 2003 push mail 解決方法
Posted using ShareThis
for HTC 及 iPhone
2009/10/23
Exchange Server 2007: Setting Message Size Limits
Do individual size limits bypass the Organization size limit?
Setting higher message size limits on an Exchange recipient bypasses the maximum message sizes in the Exchange Organization configuration, albeit only for internal messages, not for messages sent to or received from unauthenticated sources.
2009/10/21
2009/04/27
Improving TS Gateway availability using NLB
here
Recommendations about NLB parameters for TS Gateway farm scenario:
Cluster operation mode (multicast / unicast): If the gateway servers have multiple network adapters, use unicast cluster operation mode. It is a requirement that the TS Gateway farm can communicate between gateway servers. So if you have only a single NIC on gateway servers, then multicast should be used to enable communication between gateway servers in the cluster.
IP Affinity: In most cases, especially when clients originate from many different locations on the internet, like their homes, set the IP affinity to Single. There is one scenario where the IP affinity must be set to None: if many of the TS Gateway clients are behind NAT devices causing all connections to end up with the same IP and hence the same TS Gateway server, then IP affinity set to Single on NLB will load one server more than another (for example, all remote workers in a branch behind a NAT with a single external IP). In this scenario IP affinity should be set to None.
It is recommended to configure TS Gateway for a farm scenario, no matter what affinity is used. This allows users to connect in the situation where the 2 SSL connections (RPC_IN_DATA, RPC_OUT_DATA channels) originate from different client IP addresses. For example, suppose a client is trying to connect from within an organization having two proxies to the Internet (or a proxy having two Internet IP addresses) which are used randomly. In this scenario, If TS Gateway farm is not configured then the connection might fail for any NLB IP Affinity setting because SSL connections (RPC_IN_DATA, RPC_OUT_DATA) from the client may go to different TS Gateway servers.
2009/04/16
2009/04/09
exchange 2003 owa 開啟 pdf
Description of the KnownContentTypes registry entry for Outlook Web Access in Exchange Server 2003 Service Pack 1
2009/04/07
2009/03/31
2009/03/28
upgrade from Windows Server 2000 to Windows 2003 Server
2009/03/26
2009/03/20
cisco asa 5505 設定
Step 1 Locate an RJ-45 to RJ-45 Ethernet cable.
Step 2 Connect one end of the Ethernet cable to an Ethernet port (ports 0 through 7), as shown in Figure 4-2. (Typically Ethernet port 0 is used to connect to an Internet router.)
===
Step 1 Make sure that the speed of the PC interface to be connected to one of the ASA 5505 inside ports is set to autonegotiate. This setting provides the best performance.
By default, the ASA 5505 automatically negotiates the inside interface speed. If autonegotiate is not an option for the PC interface, set the speed to either 10 or 100 Mbps half duplex. Do not set the interface to full duplex; this causes a duplex mismatch that significantly impacts the total throughput capabilities of the interface.
Step 2 Configure the PC to use DHCP (to receive an IP address automatically from the ASA 5505), which enables the PC to communicate with the ASA 5505 and the Internet as well as to run ASDM for configuration and management tasks.
Alternatively, you can assign a static IP address to your PC by selecting an address in the 192.168.1.0 subnet. (Valid addresses are 192.168.1.2 through 192.168.1.254, with a mask of 255.255.255.0 and default route of 192.168.1.1.)
When you connect other devices to any of the inside ports, make sure that they do not have the same IP address.
Note The MGMT interface of the adaptive security appliance is assigned 192.168.1.1 by default, so this address is unavailable.
Step 3 Use an Ethernet cable to connect the PC to a switched inside port on the rear panel of the ASA 5505 (one of the ports numbered 1 through 7).
Step 4 Check the LINK LED to verify that the PC has basic connectivity to the ASA 5505.
When connectivity is established, the LINK LED on the front panel of the ASA 5505 lights up solid green.
2009/03/18
Session Directory and Load Balancing Using Terminal Server
Summary
Terminal Server Session Directory is a feature that allows users to easily and automatically reconnect to a disconnected session in a load balanced Terminal Server farm. The session directory keeps a list of sessions indexed by user name and server name. This enables a user, after disconnecting a session, to reconnect to the correct terminal server where the disconnected session resides to resume working in that session. This reconnection will work even if the user connects from a different client computer.
This white paper discusses how to plan and deploy a load balanced terminal server farm using session directory, and how the session directory operates in a load balanced environment.
Included in This Document•
Session Directory Overview
•
Load Balanced Configurations
•
Session Directory
•
Summary
•
Appendix
以 Windows 負載平衡服務使用終端機伺服器 243523
您可以使用 WLBS (或 Windows 2000 中的 NLB) 在一組「終端機伺服器」中 散佈眾多的「終端機伺服器」用戶端。下列清單包含設定 WLBS 或 NLB 的 指導方針。 將使用者資訊、系統資訊和一般資料儲存在一個位置上,例如 SQL 伺服器內, 這樣每個「終端機伺服器」便能服務網路上的所有使用者。我們建議您使用 Microsoft Cluster Services (MSCS) 共用資料。
WLBS/NLB 要靠用戶端的 IP 位址 (如果您使用「無相似性」,則為連接埠編號) 來 判斷哪一個「終端機伺服器」為用戶端提供服務。如果您將 WLBS/NLB 設定為使用「相似性」, 則只要您不變更「終端機伺服器」叢集,用戶端所用的 IP 位址會由相同的「終端機伺服器」 提供。
在工作階段中,當「終端機伺服器」用戶端從「終端機伺服器」中斷連線時, 「終端機伺服器」會將該用戶端的工作階段標示為「中斷連線」。您在該 工作階段內所用的用戶端程序和虛擬記憶體空間,仍會保留在伺服器上, 只要「中斷連線」的工作階段狀態沒有結束,這些資訊便會對應至使用者的 「工作階段識別碼」。如果您將用戶端電腦重新連線到「終端機伺服器」而該 工作階段仍處於「中斷連線」狀態的話,可以用該工作階段狀態資訊繼續 使用在中斷連線之前所用的相同程序和程式。
「終端機伺服器」不支援將記憶體內的工作階段狀態複製到其他的「終端機伺服器」 或與其他的「終端機伺服器」共用這些資訊。如果您在工作階段時從「WLBS/NLB 終端機伺服器」 叢集成員之一的「終端機伺服器」中斷連線,而在重新連接到該「終端機伺服器」之前,用戶端 的 IP 位址變更了,這時候,連線的要求可能會由叢集中,不同的「終端機伺服器」提供服務。 如果發生這種現象,記憶體內的工作階段便會繼續使用原始伺服器上的資訊。您需要在新的 「終端機伺服器」上啟動新的工作階段。
如果您需要中斷連線的用戶端連線到相同的「終端機伺服器」,才能回復「中斷連線」工作階段, 用戶端的電腦需要使用靜態的 IP 位址,而 WLBS/NLB 必須設定為使用「單一相似性」。 請注意,透過您的 ISP、從 LAN 上的 DHCP 伺服器所取得的 IP 位址可能會變更,如同漫遊使用者的 IP 位址。如果固定 IP 不是必要條件,則您可以在從「終端機伺服器」叢集要求服務時,使用 用戶端電腦上的不同 IP 位址,且可將 WLBS/NLB 設定成不使用「相似性」。
2009/03/10
NLB 單點及多點
今天設定單點不通,ping 不到168.95.1.1 , 改成多點就OK.
文件說:預設用單點即可.
A Windows NLB cluster can be configured in either unicast or multicast mode, where unicast is the default mode.
Unicast Mode
With the WNLB cluster configured in unicast mode, the MAC address of each server’s network adapter will be changed to a virtual cluster MAC address, which is the MAC address that will be used by all servers in the Windows NLB cluster. When unicast mode is enabled, clients can only connect to the servers using the cluster MAC address.
Multicast mode
With the Windows NLB cluster configured in multicast mode, a multicast MAC address is added to the cluster adapter of each server in the cluster. Note that I write “is added”, as each server will retain their original MAC addresses.
A Windows NLB cluster, no matter what mode it is configured in, works with just a single network adapter installed in each server, but it is recommended to install a second network adapter in each server, in order to achieve optimal performance, and to separate ordinary and cluster related network traffic.
So what mode should I use for my Exchange 2007 Client Access solution and how many network adapters should I install in each Client Access server? Well, best practice recommendations are to install two network adapters and use unicast mode, so that the host and cluster network traffic are each separated in their own respective network adapter2009/03/09
本機升級win 2003 to win 2008
In-Place Upgrade from Windows Server 2003 Domain Controller to Windows Server 2008
2009/03/02
NLB相關的文件
Deployment Options for Hub Transport Servers
NLB Fundamentals
Hub transport and CAS combined role & Network load balancing
Checklist: Enabling and configuring Network Load Balancing
How To Set Up TCP/IP for Network Load Balancing in Windows Server 2003
How-To: Configure Network Load Balancing (NLB) with Two Network Adapters
如何設定網路負載平衡參數在 Windows Server 2003 中




