Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Methanar
Sep 26, 2013

by the sex ghost
Stupid question here. I have GPO in bpinske.local to disable cmd and I want to to set a GPO to enable it for only a specific group (named IT support inside of the BC OU). What is the proper way of doing this?

Adbot
ADBOT LOVES YOU

Methanar
Sep 26, 2013

by the sex ghost

socialsecurity posted:

So our Group Policy Objects no longer save changes, like the permissions are all fine and there are no errors you just change something and it just reverts back it's crazy. I can even make new ones just fine just never change the old ones Google has been low on anything seems like a rare situation.

I know nothing but is there some bad replication going on?

Methanar
Sep 26, 2013

by the sex ghost
Does anyone know of a good checklist to go through when replacing a DC from 2003 to with a new one with 2012 R2.

I've read over http://blogs.technet.com/b/canitpro...erver-2012.aspx but this feels like way too little.

Methanar
Sep 26, 2013

by the sex ghost
I definitely didn't like having to track down Java 6 to make my old as gently caress Cisco ASDM work.

Methanar
Sep 26, 2013

by the sex ghost

Internet Explorer posted:

working IT for IBM, Cisco, or the government. It's a mark against, not a mark in your favor

Why?

Methanar
Sep 26, 2013

by the sex ghost

Tab8715 posted:

Has anyone ever seen a Windows Network Adapter simultaneously show two IP Addresses in ipconfig /all?

It's the standard Virtual Adapter that comes with Hyper-V, I've tried resetting/rebooting the adapter but there's one always second address. My next approach is to just blow away the machine and re-build but this has left me perplexed and I've never seen anything like it.

Are they both dhcp? Do they both work?

Methanar
Sep 26, 2013

by the sex ghost
I just made my first powershell script and I'm very proud of myself. I needed to change all references to \\oldserver\ to \\newserver\ in all files in a directory.

I can just hold onto this script basically forever now and just change the filepath, oldtext, newtext variables whenever I need to.

Methanar
Sep 26, 2013

by the sex ghost
Has anyone ever used nvgre to set up a VPN between Azure and somewhere?

How did it work and what documentation did you use?

Methanar
Sep 26, 2013

by the sex ghost

Orcs and Ostriches posted:

Another important thing I forgot to mention - only the office has an ISP connection, so each site's WAN link carries much more traffic than just this. I'd have to be wary of any sort of extra replication traffic using those connections as I'd want to minimize what's going through them during the day.

What?

How do you do site-site VPNs without an ISP connection.

Methanar
Sep 26, 2013

by the sex ghost

NevergirlsOFFICIAL posted:

Hey guys can you walk me through DNS like I'm a complete moron which I am. Here's the problem:

I have two DNS servers, DNS1 and DNS2. User has DNS1 as the primary DNS server, DNS2 as the second.

When DNS1 is turned off, the user cannot access the Internet or get any DNS. They can put in 8.8.8.8 as DNS server manually and then Internet (but not internal) DNS works.

Why would this be. Why wouldn't the second DNS server work. Does it have to do with which DNS server that second DNS server has listed as the primary?

Make sure it's actually active and replicating.

Methanar
Sep 26, 2013

by the sex ghost
Just for fun I've installed myself the 2012 r2 sccm suite because I wanted to try and do stuff with it.

What are some neat little projects I could try with this behemoth?

Methanar
Sep 26, 2013

by the sex ghost

BaseballPCHiker posted:

You could try to not get liver failure while using it.

Serious answer, I think the knowledge that transfers over the most to other IT areas would be playing with ADRs, and making software packages. You could try creating a package and deploying it to some test computers and then setup updates to deploy as well to those computers.

Just a tip starting out get the CMTrace tool. I think it's a separate download for some reason from Microsoft as part of a developers kit.

I already regret my decision to try and use this.

Methanar
Sep 26, 2013

by the sex ghost

BaseballPCHiker posted:

It is without a doubt the most touchy, unstable, infuriating piece of software that I've ever worked with. I can't tell you how many times I just wanted to give up working with it. Inevitably some tiny tiny detail will trip up a whole package or deployment. Or the one thing that should' have been simple to do ends up taking days of work to just get started. Part of my problem with it was that it has to be a persons full time job and I was split managing our SCCM environment while doing other things.

Don't let me discourage you completely. If you can get imaging setup properly through SCCM you will have already made a tremendous first step towards learning the product.



I banged my head on this cannot connect to application server bit for like 2 hours. I don't even know what I did to fix it. For the 4th time I went over the logs, saw that everything was (still) correct, tried the catalog again out of frustration and it starts working.

It would have been nice if at some point technet, SCCM itself, etc would have mentioned that this requires like 8 IIS dependencies instead of letting me go forward with basically nothing.

Methanar fucked around with this message at 18:49 on Oct 22, 2015

Methanar
Sep 26, 2013

by the sex ghost
SCCM 2012 R2 SP1 CU1

what the gently caress kind of naming convention is this

Methanar
Sep 26, 2013

by the sex ghost


oh come on all of your shits in there.



I didn't even change anything. I don't think it was a waiting thing either this time. I removed all my images, tasks, deployments, etc and redid it from scratch exactly the same, and now it suddenly works.

Methanar fucked around with this message at 02:20 on Nov 2, 2015

Methanar
Sep 26, 2013

by the sex ghost
I spent my morning watching a bunch of documentaries about government surveillance and all the evil things microsoft has ever done.

So when I started playing with SCOM and saw this option I thought it was funny.

Methanar
Sep 26, 2013

by the sex ghost

Sacred Cow posted:


Also wouldn't you want to uninstall 2010 first then install 2013?

Having the sccm check that the installation of 2013 was successful before removing 2010 is probably a good idea to cover your rear end.

At least if the deployment fails halfway through, the users have the old version of office instead of no office.

Methanar
Sep 26, 2013

by the sex ghost
Installing sccm/scom/scvmm sucks so much

Methanar
Sep 26, 2013

by the sex ghost
SQL needs a specific collation :argh:

BaseballPCHiker posted:

Are you installing the newest version? SCCM 2012 R2 CU4 Rev 5 Alpha LE?

Good luck, the install is a pain. I remember just trying to get a handle on the hardware requirements was a pain.

I can't tell if that's a real version or not. But no, I am doing sccm 2016 technical preview 4 right now.

http://www.microsoft.com/en-us/evalcenter/evaluate-system-center-2012-r2-configuration-manager-and-endpoint-protection

Methanar
Sep 26, 2013

by the sex ghost
NLB and failover are mutually exclusive.

Methanar fucked around with this message at 20:23 on Dec 11, 2015

Methanar
Sep 26, 2013

by the sex ghost

Walked posted:

I think you're referring to on a single host.

I want to have VMs running NLB on top of a Hyper-V failover cluster.

Oh a hyperV failover, I misread your question.

I'd imagine you can then, one is a VM level redundancy and one is a host level. But I'm not 100% sure and google doesn't show much either.

Methanar
Sep 26, 2013

by the sex ghost

Walked posted:

Yeah; same - I'm just wondering it is against any best practices to do so due to the MAC spoofing that NLB does; but I dont think it'll cause any issues really. Probably put this one into a lab environment first - failover cluster some NUCs to test I guess :v:

I asked one of my mentors your original question and he had an interesting response

quote:

The two technologies will not run concurrently on the same install as they are intended for different purposes, thus what could be done:



- Run a NLB cluster inside of a Hyper-V host (containers starting with Windows Server 2016 will also do that)

- Run a failover cluster inside of Hyper-V but place the nodes of that cluster on different hosts (again this will be easier with Server 2016)

- Lastly the architecture overall

o Assume you have web site that sells stuff and wants to be up always

§ Build a NLB cluster for the front-end (web site and all)

§ Redirect all 443 traffic to one host in the NLB

§ Redirect any DB traffic and payment from that node to a SQL DB that his hosted on a failover cluster

· Of course the same would apply to Exchange for example for the appropriate rolesJ.

o What is not addressed in the above is session state, server side cookies, and client side cookies


Remote Desktop Services for example would behave the same way: The front-end broker is hosted on NLB and the desktops on a failover cluster. Front-end/back-end AFS same thing. The only thing Hyper-V adds in here is that you do that with virtual machines. From an architecture perspective this becomes interesting as you will have to place some of the nodes on different hosts and create appropriate virtual switches that map to different physical adapters and/or virtual networks.



Hope this helps.


Respectfully

Methanar
Sep 26, 2013

by the sex ghost
That annoyed me a lot yesterday.

I instinctively clicked on NEW REPLIES like 40 times even though I knew it was going to happen.

Methanar
Sep 26, 2013

by the sex ghost

Something Awful

Methanar fucked around with this message at 07:44 on Feb 2, 2016

Methanar
Sep 26, 2013

by the sex ghost
Microsoft has a half-rear end step by step guide for building a LAN ADCA, pushing it to clients and installing it into IIS.

It might be helpful.

https://technet.microsoft.com/en-us/library/gg314532(v=ws.10).aspx

Methanar
Sep 26, 2013

by the sex ghost
Does anyone have any cool ideas or good resources for things I can try and do in Office 365's sharepoint? I've never used it before and my impression is that it's just a big scary CMS, is that about right?

Methanar
Sep 26, 2013

by the sex ghost

Thanks Ants posted:

You should avoid using SharePoint where at all possible

I heard bad things about skype for business too but after how easy it was for me to set up office 365 for it I feel inspired.

I'm sure it's not that bad

:kiddo:

Methanar
Sep 26, 2013

by the sex ghost

Zero VGS posted:

The PCs are in a weird purgatory where "This PC -> Properties" has a blank domain, and Workgroup: WORKGROUP. But if you go to Windows 10 "PC Settings -> System -> About", it says Organization: ourOrganization with a "Disconnect from organization" button. That's how Windows 10 Cloud Join works.

Glad my misery is so entertaining, you bastard!

Is there any reason you haven't looked into OpenLDAP or similar for your kerberos/RADIUS needs?

Methanar
Sep 26, 2013

by the sex ghost
Maybe run a dcdiag to see if there are any outstanding issues beforehand.

Methanar
Sep 26, 2013

by the sex ghost
HP's Device Manager is so good and easy to use. I remotely captured a gold image and then deployed it to 5 devices like nothing. The only thing I really noticed was missing was multicast for pushing the images. Why did I ever put myself through SCCM for imaging.

Is it normal for thin clients with an embedded version of Windows to come with Windows Update locked down stock from the OEM? I thought it was weird at first but I guess it makes sense with the write filter preventing anything from ever changing anyway. I called HP about it and the guy told me HP strongly recommends to leave WU off and if you allow Windows Updates to Windows 8 Embedded it stops being an embedded version and somehow becomes a full OS, I've never heard of anything like that before and I know we have Embedded POS editions with WU and nothing weird happening. Is W8E special regarding this or was the guy just full of poo poo.

Methanar
Sep 26, 2013

by the sex ghost

Weedle posted:

I use a domain administrator account called simply "Administrator." Apparently Windows 10 thinks this is the built-in administrator account and won't let me run apps when logged in. Is there a way to lift this restriction? I tried Googling but only found stuff about enabling the built-in admin account.

Are you specifying the account is a domain admin like domain\administrator

Methanar
Sep 26, 2013

by the sex ghost

Zero VGS posted:

I don't drink :-/

You can always settle for some nice iced tea, I guess.

Methanar
Sep 26, 2013

by the sex ghost

22 Eargesplitten posted:

I'm running a Robocopy, and I'm getting some files saying they can't be copied because they are being used by other processes. I was wanting to do multiple copies from the same source at the same time, am I not able to do that with robocopy?

Wrap the statements in powershell with a sleep 5 between the robocopies.

Methanar
Sep 26, 2013

by the sex ghost

Wrath of the Bitch King posted:

SCOM and SCCM definitely aren't packaged together as far as licensing goes unless you have a "gently caress you, have all the products" EA.

SCOM is in a higher licensing tier. Same for SCOR.

My understanding was that every tier of System Center licensing gave you every product under the family. SCCM, SCOM, SCVMM, Orchestrator, etc. The difference between the tiers was how you were allowed to spread the applications around. Basic tier you're limited to two, higher tiers allow more.

It even includes the SQL licenses to run mssql for everything.

Methanar
Sep 26, 2013

by the sex ghost

SeaborneClink posted:

I've been stuck on this for a while, hoping someone else has the critical missing piece of information.

Setting up L2TP/IPSec VPN on a 2008R2 host. The host is behind the FW (ASA5505), I've configured UDP 500, 1701, 4500 as well as gre, esp & ah to pass through the firewall successfully. I can authenticate using Windows Creds, as well as receive a valid IP address from the DHCP pool.

When looking at ipconfig I get the address 10.102.131.x, a subnet mask of 255.255.255.255 and a default gateway that is just empty. It does however pick up the correct DNS servers, from both the local site and the remote one.

From the client I can't ping the RRAS server, or any other computer, from the RRAS server I can't ping the client.

Do I have to add static routing to RRAS? What did I miss?

The VPN subnet should be something not in your primary LAN network, it should also be an actual pool and not a /32. Have the default gateway be the VPN server which has a route to your real lan.

Methanar
Sep 26, 2013

by the sex ghost
In this brave new Windows as a Service world, how is Microsoft going to be getting their money where they traditionally have by releasing a new OS. They can't be banking on Office 365 alone.

Methanar
Sep 26, 2013

by the sex ghost
Yes, but is there/going to be a Windows 10 Enterprise subscription or are they going to charge for the right to a use a LTSB branch.

Do we know yet?

Methanar
Sep 26, 2013

by the sex ghost

Toshimo posted:

We do that now, but with FTEs, not interns. I was hoping for ideas on a way to script something I could leave running as a scheduled task for a day that would log-on/log-off every 10 minutes.

[A]sk me how much fun it is with the laptops where the full-disk encryption kicks in and you have to run down to the lab every time it reboots, get past the FDE, login, logout, and then fridge back to your desk despairing in the knowledge that you'll be back to do it again in an hour.

No because I would never do that. Fix SCCM.

Methanar
Sep 26, 2013

by the sex ghost

Toshimo posted:

I mean, yeah, sure, but if I don't fix this, it's not like they are going to do anything to me, so I just thought I'd make my life a little easier, but ultimately, if the answer is "gently caress it", that's on the agency.


I love you, bro, but this is kinda harsh coming from someone whose IT resume includes "Cleaned chicken coops in Sub-Zero conditions". Sometimes :20bux: is :20bux:.

I'll have you know there were no chickens involved.

Adbot
ADBOT LOVES YOU

Methanar
Sep 26, 2013

by the sex ghost
What exactly are the rules surrounding Essentials?

Could you just make it a RODC with no FSMO and forget about it? It would be pretty dumb, even in an entry level product, to prevent you from say giving Microsoft twice as much money so you could have a pair of DCs.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply