silentfury-s4provm or physical
silentfury-s4prothere's a registry enrty for vm's
silentfury-s4prohyper-v or vmware
sine0small question, some staff have 2 inboxes in outlook exchange and share another email address, this needs to be removed, would this account have been physically added or done at the group admin level
_root_I was wondering how could I run a SIP server on windows server.
linerrorany requirements?
linerrorthere's about a dozen foss solutions and 3 dozen paid ones...
_root_free ones is always better :d
_root_linerror, just a software that gives my a SIP server .
linerror_root_, would be a good start if you have no requirements other than free and runs on windows
Dus10Skype for Business
Dus10it is SIP-based
Dus10you can drop a SIP-trunk onto it
Dus10everything works on my desktop
Dus10Now... my desktop is a Core i7 with 24GB of RAM
linerrordid you have to jump through the same hoops as 2012 r2?
Dus10it also has 1GbE and a wireless adapter... and a nice AMD Radeon with 8GB of RAM
linerroror did you not use e2?
Dus10what hoops?
Dus10I installed it
Dus10I installed my drivers
Dus10all was well
Dus10I did use Windows Server 2012 R2 as my desktop for some time on my old system
linerrorr2 has things like Audio disabled at the service level by default
kuaharaI love that they're centralizing many of the popular device drivers with Windows Update, but I wish the Windows Update button when adding a new device would just populate Mfr/Model only, then only download the driver you need after you've select the device you're installing
Dus10and I have previously used Windows Server 2008 R2 and 2003 R2
Dus10linerror: that isn't a big deal at all
kuaharainstead of spending 20+ minutes downloading drivers for every model device a mfr makes
Dus10just enable it
Dus10if that is a hoop, then you are safe
Dus10A server doesn't often need sound... so I don't see that being a big deal
Dus10you enable it for VDI solutions...
Dus10and things like this
Dus10it works fine
linerrornot a big deal, no, but the hassle of things i have to deal with, no sound, disable dep and sehop, missing dlls... things like driver packages and applications seeing an odd windows version and puking
Dus10if you can't be bothered to enable a service, how do you work up the nerve to install an OS to begin with?
linerrorevery -- asus -- utility -- failing to install without a greybeard
kuaharathe discomfort of never seeing your OS in the list of supported OS's for desktop software you're paying for
linerrorthe joy of having to manipulate logs to keep paid support from rejecting you...
_root_ACTION says there is no good and easy software to run a SIP server on windows o_O
TLoFPbewbs: could it be because it is a dynamic disk?
bewbshonestly i don't know. i'm at about the edge of my knowledge on this subject
TLoFPbewbs: also what OS is the host?
bewbsserver 2012
TLoFPI have the same issue different setup
TLoFPhow do you copy from disk to VM btw? via network drive?
TLoFPand what does your performance counter tell you about the disk usage?
bewbssmb share
bewbslooking at resource monitor it shows disk queue length at 5 for the T: volume
TLoFPI am guessing that SMB share is installed on the Host?
bewbswhile D: is 0.05
bewbsT: is pretty busy though
TLoFPT is your SSD array?
TLoFPand what is D:
CptLuxxfloppy raid
TLoFPso you copy from D to T?
TLoFPand T has your VHDX?
TLoFPhow many other VMs have their vhdx on T?
bewbsit's all vhdx
bewbsi copy from D: or T: to vm and it's all about 30-50MB/sec
TLoFPthe raid of ssds is for a single VM?
bewbsthere are ~20 vm's with vhdx's on T:
TLoFPcan you shut them down?
TLoFPlook at their disk usage with performance monitor
TLoFPone or many of them are likely hogging the disk
bewbsthat's what i was looking at. T: is showing disk queue length of 5, while others were < 1
bewbsthe biggest hittes are the sql servers to t:
bewbsbut i have 300 applciation servers utilizing the sql servers
bewbsnot large data, just lots of small ones
TLoFPlook at the "Hyper-V Virtual IDE Controller"
TLoFPthen see which one of your VMs is going insane on the IO
bewbsunder what
bewbsi'm in perf mon
TLoFPthis is where others might help more. I plot "normalized" throuhgput
TLoFPnow add counter
bewbsi'm not seeing where to do that
TriptichI'm having a rough time migrating our kms server from 2003 to 2012.. the new server doesn't seem to be compatible with Win7 kms keys, our Win8 kms keys work fine.... anyone been down this road before?
TLoFPif you right click then you see "add counter"
TLoFPthen on the left side under "avialable counters"
TLoFPyou actually want to look for "Hyper-V Virtual Storage Devices"
TLoFPexpand that
TLoFPselect Normalized THroughput
TLoFPthen select all of the vhdx that you have
bewbsright click what, i'm not getting anything like that under performance monitor
TLoFPand hit add
TLoFPright click your graph in perf mon
bewbsi can add/hide columns
bewbsnothign happens when ir ight click the graph
TLoFPimg of what your look at pls
TLoFPI think I know what you are looking at
TLoFPthats resource monitor
TLoFPnot perf mon
bewbsah got it
bewbsthat only lists vhd's hosted locally
bewbsadding the other servers
bewbsi have error, flush, read bytes, read count, write bytes, write count
TLoFPbetween read and write counts you can probably find the problem
bewbslooks like sql is doing the brunt of it
TLoFPmy guess is that it is an IO issue
TLoFPso if you pause that vm, probably your throughput will go up
bewbsnot mb
bewbsthe read/write count is 150,220,797/sec
bewbssorry write count
bewbsread count is 89mil/sec
bewbsi'm not even sure i'm reading this right
bewbssql does more htan every other server combined
bewbsmaybe sql should get it's own ssd
bewbsi should note that not within the vm, i get screaming fast speeds between hdd's
bewbsD: and T:
bewbssolid 200MB/sec between D: and T: and D: and E:
ZewWhat are people using for end device A/V?
CptLuxxme trendmicro
TheRabbitTrend, but it doesn't matter
ZewI found trend was slow on the ball
Zewfrom the latest attempts of attchements in emails I generally find Sophos is the main one picking them up on VirusTotal
ZewI know its a bad file, used Trend A/V to scan, returns clean
Zewput in VirusTotal shows its not clean by other AV vendors
Zewso yes, slow
CptLuxxif thats your test okay
ZewHow do you test agaisn't multiple AVs?
Zewplease provide an alternative method
CptLuxxi read some test like av test#
CptLuxxand well
CptLuxxevery av sucks and its snakeoil
CptLuxxbut hey.. some people want it
Zewhence VT is a good option
Zewits not an agent
Zewbut you can check against multiple AV vendors
Zewam I the only one who uses VirusTotal?
qbrixnever heard of it
qbrixoh weird, apparently I have visited their site
qbrixI guess we do use it!
qbrixnot my team specifically
tang^I am only familiar from the user standpoint. I have a test account that's had to get it's expiry moved a few times now.
dopiwanInterestingly enough I dont see an Expired attribute or any relevant booleans but technet plebs saying "Expired" seems to be a thing
tang^oh, I can't log in. hey, IT, is this expired? yes? can you give me two more weeks please??
BobFranklyget-aduser dopiwan -properties * #look at the first 2
sepecktang^: please submit a security ticket to enable the test account fo the new date.
sepecktang^: we're seriously hard cases on this :) For this very reason. This nickle and dime crap. Then when they try and blame us fo rwhatever, we have a documentation trail
tang^sepeck: I'm glad I don't work at a company with that kind of request structure
tang^sepeck: but fair enough
CptLuxxi wish i would work at a company with that kind of structure
tang^I just have to point one of our nerf guns at IT and fire to get their attention
sepeckwe have several hundred devs who fail at planning and communications but seem all about pointing fingers
tang^and, probably, a return volley
sepeckalso,l Security team is responsible for accounts, so not IT :) which helps.
dopiwanBobFrankly: Correct, again Technet nerds saying there's an "Expired" attribute but doesnt seem to exist
sepeckAccountExpirationDate and accountExpires
sepeckI see it. first two items
dopiwanso what actually happens when an account hits it's ExpirationDate ?
sepeckgranted,t he number is AccountExpires seems to need some decoding
dopiwanwhat nmechanism prevents logon
sepeckyou can no longer log on with it
dopiwandoes it get DIsabled?
HarlockCptLuxx would you know why, in a shadowprotect backup job that has been running fine for months, "sbcrypt" would no longer ask for the encryption password?
CptLuxxhow you mean?
CptLuxxwhen you create the job.. you enter the encryptin password and done
CptLuxxit nevre asks you for it
Harlockin the log you see it
Harlocksbcrypt asking for the password
Harlockin a normal running job
CptLuxxah hm
CptLuxxdont know
CptLuxxi never check the logs :x
Harlockeven when jobs fail?
pun844Is there a tool that would show whether or not a PC is fully up to date when you've got a WSUS server in place? I am just trying to confirm that my WSUS server isn't missing critical security updates
t0fu|workyeah, check for updates from MS update
t0fu|workif it shows up to date before, then you check ms update and it pulls a bunch of criticals you can cross check wsus
Toaster_Strudelcompdoc: 365
Toaster_Strudelpun844: used to be one..
Toaster_Strudelcalled MBSA
Toaster_Strudelwill check security patches
pun844AWESOME, this is exactly what i was hoping to find thanks - ill give it a shot
pun844Ah, its not for windows 10 ? :(
Toaster_Strudelyou could probably make a script fairly quickly with QFE
Toaster_StrudelI'd imagine that still applies to windows 10
Digzwindows 10's update system has changed, so it may not apply... but I don't know :)
Toaster_Strudelif they got rid of QFE I'll be pissed
Toaster_Strudelwe haven't made the full switch yet
Toaster_Strudeldoesn't say it doesn't work
Minnebohow fast does DFS sync?
Toaster_Strudelbut I wouldn't expect documentation to be updated on
Minneboor how fast should it sync
Toaster_StrudelDFS sucks
MinneboI know :p
Toaster_Strudelunless you are running ALL windows file servers
Toaster_Strudelit depends on sites and services
Minnebojust two servers (used it for migration)
Toaster_Strudelit shouldn't have to sync many times. How ofted does sites and services change?
Minnebowanted to make sure all files are copied so I made a folder in the old server
Minnebowaiting like 15 min, and folder didnt show yet on the new one O_o
Toaster_Strudeloh, that is a different question
Toaster_Strudelthat will depend on a number of factors
Toaster_Strudelbut it sounds like something isn't working correctly
MinneboThe DFS Replication service stopped replication on volume E:. This failure can occur because the disk is full, the disk is failing, or a quota limit has been reached. This can also occur if the DFS Replication service encountered errors while attempting to stage files for a replicated folder on this volume.
Minnebobut the E is not full :(
Toaster_Strudelcheck the server logs
Toaster_Strudelcheck the service
CptLuxxThis failure can occur because the disk is full, the disk is failing, or a quota limit has been reached
CptLuxxfailing.. quota or something other
Minneboits a vmdk, 50GB free... never use quoata's :(
Toaster_Strudelkeep checking them off the list
Toaster_Strudelwhat else?
Toaster_Strudelyou may find dfsutil.exe helpful
Toaster_Strudelmaybe not for this specific falure, but worth mentioning
MinneboSERVER_EstablishSession Failed to establish a replicated folder session. connId:{FC377100-92BA-47A1-9067-4210C7DFF04D} csId:{8B404C99-B21A-4DE6-A918-FFB4965CD42D} Error:
Minnebo+ [Error:9028(0x2344) UpstreamTransport::EstablishSession upstreamtransport.cpp:808 11676 C The content set was not found]
Minnebogetting further!
Stryykercheck event viewer for any other issues detected near then
ZewWoooooo! My buddies Web Application is Live! WooooHoooo!
CptLuxxlets hack it Zew
JedicusMy web dev is using a mac to get to an IIS7.5 web server using SMB. I think it's something the mac is doing, or perhaps in concert with IIS, but he keeps locking files and folders and then can't rename, delete, etc. I used handle.exe and the only processes that have handles to the files/folders are w3wp.exe and system-pid4. What would make IIS or system lock files it's serving? This is a big web site, so I can't really
Jedicusbe stopping the worker process.
ZewCptLuxx: Probably had a better chance at hacking the PWM implementation when it was live
Minnebocan't I just make a copy job to copy the missing files
Minneboused dfs for a migration anyway
Zewthe amount of attacks my IPS picked up on, was disturbing
Minnebobut I don't want to overwrite stuff
CptLuxxi see
ZewJedicus: using impersonation auth?
ZewAlso I'd blame the fact their using a mac :P
jcottonTheRabbit: there's LTSC
TheRabbitI know
TheRabbitat least they are committing to LTSC
Minnebowhat is the command for robocopy?
TheRabbit.\Robocopy /?
Minneboto copy only files that are not in target or where the target is older?
Minnebojust want to be sure >_< didnt use it before, its 5TB of data, can't f it up ;p
furmelademake a test run before?
furmeladeand read the documentation?
Minnebojust say
MinneboI don't know either
khelpwso for those of you who were present for my stupid failover cluster testing questions yesterday I figured out the missing piece to the puzzle. The storage server cannot be a part of the cluster.
Minnebokhelpw, google
khelpwdespite the storage from that storage server being applied as a cluster disk.
Minnebomake a testrun
khelpwthis was the test run...I did google...
khelpwbut this is a stupid setup to begin with, it's basically HA between 2 instances of MS SQL across a couple of VMs on the same host, my difficulty came from the fact that I was trying to keep it entirely contained on that host without using a NAS or other external shared storage device.
sauli just created an AD account on one DC
saulbut i cannot find it in the list of users on a client machine
sauli cant see it on my other domain controller actually
sauldo DCs take some time to synchronize ?
khelpwYeah it can take a couple minutes, saul
furmeladeyou can force a replication tho
furmeladeeither via AD sites and services or repadmin
sauli'll wait a bit i guess then
saulwell i see why it's not replicating, i tried to replicate through ad sites and i get an error
saul"The naming context is in the processof being removed or is not replicade from the specified server."
sauli imagine it wont replicate on its own if it doesnt work manually
khelpwYep, safe bet.
saulso now i have an actual problem
saullol "Wait."
saulor "Make originating changes in the right places"
saulhow specific lol
saulshould it matter if the DCs are on different 24 bit subnets ??
xnomarofcourse it does
sauli had no idea
saulthey can reach other though, there's a route between them
xnomarcan't replicate to something you can't contact
saulof course but they are reachable to each other
saulmy cisco switch handles routing between the subnets
sauli find it hard to believe you're not allowed to have DCs across more than a single subnet heh
kidn3yserrr, there is nothing wrong with having DCs on different subnets as long as they are reachable
kidn3ysain lab uplinks for MPLS purposes terminate on a metro cluster on bvi's, over which I run more cross connects to points to link in hardware, and on top of that, I still managed to run another cross connect terminating in a PW-HE
sauli went ahead and added the new DC's subnet to the list of 'subnets' in AD sites and services
kidn3yssaul: is this at the same physical location?
saulthe old DC is a physical box, the "new" one is a VM, they're feet apart, just on different subnets
kidn3ysshould be fine as long as their is reachability
sauli took over a really old setup that uses win2k3 as their main DC
sauli segmented the network and added a win2012R2 machine, but im using the 2003 functional level because of the old DC
kidn3yswe typically do two dcs per site for redundancy, and each on a separate subnet to limit the affect of individual failure domains
saulthat's kind of what im trying to do kidn3ys
HEROnymoushaving all yer DCs on a single subnet would be nuts
saulbut these guys are not talking to each other apparentlyl
HEROnymoussaul, is it because 2003? :/
saulHEROnymous: i dont see why, you can add new DCs and keep the 'functional level' at 2003
saulor whatever it's called
kidn3yswas the new DC built on that subnet?
saulyes kidn3ys
sauland joined the domain no problem as a domain controller
HEROnymousI dunno, I mean in theory, but I've never tried any leap that large (assuming you're doing 2012r2 or 2016 now)
saulit has the users and OUs and everything, i just noticed the issue when i added a user on the 2012r2 box and it never showed up in the 2003 machine
saulor on any client machines, for that matter
kidn3ysYou might also consider checking out the firewall rules if windows firewall is enabled, I've found a lot of the rules only allow traffic from the local subnet that the server resides on
saulkidn3ys: good call
kidn3yssaul: and you said you tried to manually replicate via sites and services?
saulthey can ping each other but that's not enough
saulkidn3ys: indeed
saulkidn3ys: that's where i get the error i mentioned
HEROnymousyou may also have acls/rules on your layer3 gateway for packets traversing different networks, too
kidn3ysand that fails?
saulHEROnymous: good call as well but im sure it's full access
sauli will check firewalls though
sauli detest the 2003 DC, not for being old but for being in Spanish
saulfinding things is really hard because it's all translated
saulok the firewall isnt active
HEROnymousso many jokes... but far too racist to share...
saulkidn3ys: from 2012r2 to 2003
kidn3ysso you created the user on the 2012 box?
saulkidn3ys: if i go into sites/services on the 2003 machine, and enter the 2012 machine and go to "ntds settings" i dont even see the new 2012r2 machine lited
saulkidn3ys: right
saulcreated user on 2012r2, cant find it anywhere else on the domain
kidn3ysdoes the 2012 box show up in AD on the 2003 box?
saulkidn3ys: yep
saulit's under "domain contollers" in 'users and computers' app
sauli tried to replicate, on the 2012r2 machine, from 2003 to 2012r2 and i get a different error
saul"RPC server is unavailable"
saul"condition may be caused by a DNS lookup problem"
kidn3yssaul: have you tried replicating from the 2003 box first?
kidn3ysand then back the other direction?
sepeck2003 is EoL you WILL have problems. However, check that they are both can communicate on the same version of SMB
sepeckthere are sites that will answer how.
saulkidn3ys: i get different errors
kidn3yswhat errors?
kidn3ys2003 still holds all the FSMO roles, right?
saulsepeck: for what it's worth, this is all going to be legacy very soon
TLoFPso... is it possible to run a VPN on a desktop you are connected to remotely?
sepeckwell, it's legacy now. Just not where you work
TLoFPor will the VPN by necessity destroy your connection to the remote desktop?
kidn3ysTLoFP: depends on the type of VPN. if it's a split tunnel, more than likely
sepeckTLoFP: depends on the VPN and options in the VPN, but yes, most defautl settings will nuke your other connecctions by default
CptLuxxyou want split tunneling TLoFP
TLoFPyea. I am afraid my work probably didn't implement that one right
TLoFPnow I have to go home and hope the VPN works on my VM
TLoFPbut what about the Hyper-V itself, will it be able to connect to the VM once the VPN is launched?
saulthis ancient AD crap is there to support an even more ancient ERP software. once we migrate i'm going to enjoy scrapping all of it
sauli'll just create a new forest/domain using 2012r2 and it'll be peachy as can be
saulall servers in english!
saul(i'm in latin america, but sysadmins and engineers who cant handle english can gtfo)
Alagargood evening all
Alagaris any good free windows patch management like wsus ?
diabillicspiceworks do patching?
CptLuxxcomodo one
AlagarCptLuxx: thank you,
AlagarCptLuxx: compare than wsus, Comodo one is good ?
VaevictusAlagar: what's wrong with wsus?
AlagarVaevictus: Thank iam sorry, iam new to wsus, so just iam asking, could you please help me to get one good online learning link for wsus ?
AlagarVaevictus: Also could you please recoment one good free patch management
Vaevictuswsus is free patch management, and what most of us use.
Vaevictusi don't have good learning tools for it, and don't have any other recommendations
Vaevictusinstall it, approve all the patches, done.
CptLuxxread the topic
BobFranklyalagar: microsoft virtual academy is the usual "learning" resource we point to around here. Not sure if they have classes specific to WSUS in there
CptLuxxthere are some links to read.. and mva
BobFranklyif there's nothing specific to "wsus" on MVA, then it's likely a subtopic of their Windows Server classes
