SBS to Router VPN - something blocking TFTP?
Hi all,
Previously posted [initially under VPN from Draytek Vigor 2900...] but
things have moved on a little since then. Current situation is this:
SBS2K - dual NIC set-up with ISA 'sitting in the middle' - 2nd NIC
connecting to Broadband [cable modem]
Remote office connecting via Draytek Vigor 2900Gi
For testing purposes, this is how we have things set-up currently:
LAN - 172.16.0.x
IP-enabled phone system - 172.16.0.50 [*not* a Windows-based system as many
are - Avaya IP Office]
SBS internal NIC - 172.16.0.1
ISA
SBS external NIC - 192.168.42.2 - acting as VPN Server [RRAS/ISA configured
and working]
Broadband Router - 192.168.42.10 - PPTP [1723] pass-through to 192.168.42.2
enabled and working
Vigor External Fixed IP - 192.168.42.50 - gateway of 192.168.42.10
Vigor Internal Fixed IP - 192.168.90.1 - acting as DHCP Server
Laptop - 192.168.90.2 - assigned by Vigor - gateway of 192.168.90.1
IP hardphone - 192.168.90.170 - fixed IP address - gateway of 192.168.90.1
Try as we could, we could *not* manage to initiate a stable VPN connection
from the Vigor to the SBS box - we kept coming up against 'could not
successfully negotiate any network protocols' in the Event Logs on the SBS
box. We were attempting to connect using PPTP and had configured the Server
to the lowest possible level [i.e. not requiring encryption etc and allowing
PAP, etc...]
Therefore, we changed tack a little and can bring up a stable VPN connection
from the SBS box to the Vigor, with the corresponding static routes
configured both ends. We can thereafter do the following:
From the SBS Server, ping anything on the 192.168.90.x range successfully
From the laptop at the Vigor end, ping anything on the 172.16.0.x range
successfully
At this stage we thought we had it cracked. However...
It appears that TFTP traffic [at least] is being blocked or otherhow
prevented from being fully 'transported' between the LANs. On running a
trace of the phone system engineering software, we can see that a request
from the laptop at the Vigor end is received by the system at 172.16.0.50
but that it cannot appear to transmit the requested data back to the
192.168.90.x side successfully, failing with an 'unreachable net' error.
Likewise, from any of the SBS LAN clients, we cannot ping anything on the
192.168.90.x range - in fact, although we can ping the likes of our ISP's
domain from any of the SBS LAN clients, we cannot ping anything on the
192.168.42.x side either.
Anyone got any ideas? I cannot help but think that we're now missing
something simple at the SBS side that is the root of this and that resolving
it cannot be far away. It is somewhat crucial that we get full connectivity
working as we're testing with this in-house set-up the potential for a
client to implement a remote IP phone in a similar set-up [if we can get
this working in our test-bed set-up above, we *should* be able to replicate
it across the Internet - in theory!]
Thanks in advance,
David Tag: spam post deleted Tag: 161513
OWA, SSL & HTML formatted e-mails
I have successfully set up OWA using SSL (as per Chad A Gross excellent
guide), and generally it works fine.
However, an internal e-mail in HTML format (using Outlook) cannot be read
using OWA - a 404 page not found is generated, with suggestions to open the
mail.domain.com home page etc.
But if an HTML format e-mail is received from an external source, that can
be read OK.
Is there a setting I have missed? I have port 80 inbound specifically
blocked in ISA with a packet filter. My suspicions are that this is why the
problem occurs.
TIA Tag: spam post deleted Tag: 161510
Internet conn with Win 98 workstation on SBS2003
I have a site with a Windows 98 machine (yes I know and I
have told them to replace this machine) running on a SBS
2003 Standard network. I cannot access the Internet
through the Lan. It runs the SBS login script okay, it is
slow to load a mapped drive, but it cannot access the
Internet. Other machines (Win XP Pro) access the Internet
ok. The network has a DSL connection using a modem/router
and demand-dial.
Any help would be appreciated.
Thanks Tag: spam post deleted Tag: 161503
Windows update problem
Hello,
A friend of mine has a small business network and decided to do an
update to her server running W2k. She has 5 workstations on the network and
one of them will not connect to the server after the update was done. The
system with the problems is a PIII system running windows 98.
Any suggestions would be greatly appreciated.
Thank you,
Chris Tag: spam post deleted Tag: 161496
SBS2000 UPGRADE TO WIN2K3 ENTERPRISE
I have a SBS2000 domain and I want to upgrade to Windows 2003 Enterprise.
Can I do it by doing the following:
a. Add new Windows 2000 Server to the domain.
b. Promote the Server from step "a" to new Windows 2000 Domain
Controller (With DNS) in the same domain.
c. Install Exchange 2000 on the new Windows 2000 Domain
ontroller - you may need to add the Exchange 2000 to the same
Exchange organization.
d. Move users mailboxes from old Exchange 2000 to the new Exchange
server.
e. Move Public Folders from old Exchange 2000 to the new Exchange
server.
f. Move GC+ FSMO functions from the original domain controller to
the new domain controller .
g. Remove the original Exchange server from the original Exchange
organization.
h. Demote the original domain controller to be a member server.
i. Remove the member server (step "h") from the domain.
PLEASE HELP, I'M ABOUT TO MIGRATE TO START THIS MIGRATION. Tag: spam post deleted Tag: 161495
Block Port 1433 on windows 2000 server
Hi
I have a question regarding the SQL Server(SQL Server 7) port 1433.
Some body is trying to hack into our Windows 2000 server through port
1433. Is there a way i can close this port? I tried using a tool
called Ipsecpol.exe ( Internet Protocol Security Policies Tool). But
when we run netstat, it still looks like they are able to connect to
the server using port 1433. Has anyone come across this problem? I
would appreciate it very much if somebody could send in any
suggestions regarding this.
Thanks,
Ann Tag: spam post deleted Tag: 161492
Modem Sharing GONE from SBS2003
As I understand it, modem sharing has been deleted from SBS2003. That is the
only thing stopping me from upgrading.
Does anyone have a suggestion for a modem sharing product? I see PCMICRO's
DialOutServer might fit the bill. Comments? Suggestions? Tag: spam post deleted Tag: 161490
IPSec policy storage failed to open...
I have a group policy defined on our Win2K terminal Server. This policy was
configured on our Windows 2000 Small Business Server using an MMC group
policy snapin.
When I double click the Group Policy I want to manage for our terminal
server (called True2 Policy) and then try to open the security settings
(Console root\True2 Policy\Computer configuration\Windows Settings\Security
settings), I get the following error...
'The IPSec policy storage failed to open"
Does anyone have any ideas what to look for to fix this? Nothing shows up in
event viewer so I have no clue where to look. Also the IPSec Policy Agent
service is running...
Any help would be appreciated...
Thanks,
Brad Tag: spam post deleted Tag: 161489
SBS 2000 Maintenance
Does anyone have a list of suggested tasks for routine
monthly maintenance in a SBS 2000 environment?
Appreciate any advice. Tag: spam post deleted Tag: 161475
account lockout policy issues...
We have a Windows 2000 Small Business Server and a member Windows 2000
server we are running terminal services in admin mode on.
For some reason, we are getting account lockout issues. There is no account
lockout "domain security policy" configured on the SBS server nor is there
an account lockout configured under "domain controller security policy".
Also there also isn't an account lockout "local" policy configured on the
Win2K Terminal Server. So, to the best of my knowledge, there isn't ANY
account lockout policy configured anywhere, yet we are getting a lockout
after 3 invalid atempts which is way too low of a value and is causing
issues.
We do have a Group Policy(GP) configured on the terminal server OU
(organization unit) listed under "active directory users and groups" and a
GP defined on the lighlevel domain (ourdomain.local) but NEITHER of these
have account lockout configured!
So, my question is, where the heck is the account lockout coming from? Could
there be a registry setting that did not get changed?
Thanks,
Brad Tag: spam post deleted Tag: 161468
Terminal Services Burning Questions!!
Hi all
I am currently trying to implement TS and I have a couple
of questions that I am unable to find the answers to!
Question 1
All our clients are XP so I know we don't need any TS
licences but do I still need to install a Licensing
Server?
Question 2
I want to run Office 2003 on the TS and have succesfully
installed it and used it on a clients session. Do I need
to purchase any additional licences for Office 2003?
Question 3
Users are going to be remotely acccessing TS via a VPN.
Is there anything I need to do in relation to that?
thanks for any assitance you can provide
Mark Tag: spam post deleted Tag: 161467
HELP UPDATE KB832880 wont install
HI all
I'm having real problem with the companyweb part of SBS W2k3
I've tried installing the update which claims to fix the problems with it
but windows update cannot install kb832880
I've also run Windows SBS 2003 setup and uninstalled and installed
"Intranet" again and again but this problem will not resolve.
Why wouldn't it install from the SBS setupdisk in the first place??
Please help, I cannot get the helpdesk or vacation calender to work without
this installed properly.
TIA
Rob Tag: spam post deleted Tag: 161464
HELP UPDATE KB832880 wont install
HI all
I'm having real problem with the companyweb part of SBS W2k3
I've tried installing the update which claims to fix the problems with it
but windows update cannot install kb832880
I've also run Windows SBS 2003 setup and uninstalled and installed
"Intranet" again and again but this problem will not resolve.
Why wouldn't it install from the SBS setupdisk in the first place??
Please help, I cannot get the helpdesk or vacation calender to work without
this installed properly.
TIA
Rob Tag: spam post deleted Tag: 161462
Upgrade from SBS2K to SBS 2003
I just upgraded from SBS 2000 to SBS 2003 and while the
process seemed to go
all right I now have a problem with RWW and companyweb.
The installation was done with an uncorrected disk 3 for
SharePoint on
Saturday but today I got a corrected disk 3 and executed
the procedures
detailed in KB 829114. This KB has worked for me in a
previous installation
(but that was not an upgrade.)
Now I am getting 4 errors in the event logs.
Event Source: W3SVC-WP
Event ID: 2214
Desc: The HTTP Filter DLL c:\intepub\sbsflt\sbsflt.dll
failed to load. The
data is the error.
Data: 05 00 00 00
Event Source: W3SVC-WP
Event ID: 2268
Desc: Could not load all ISAPI filters for
site/service. Therefore startup
aborted.
Event Source: W3SVC-WP
Event ID: 2214
Desc: The HTTP Filter DLL c:\intepub\sbsflt\shrptflt.dll
failed to load.
The data is the error.
Data: 05 00 00 00
Event Source: W3SVC-WP
Event ID: 2268
Desc: Could not load all ISAPI filters for
site/service. Therefore startup
aborted.
I looked at the version numbers of both DLL and they are
5.2.2651.0.....does
anyone have any ideas??
Terry Barr Tag: spam post deleted Tag: 161450
HELP! ICW fails and fails to make SMTP connector
Hi
We have changed broadband service provider. I reran ICW
to make the changes to the DNS forwarders, but forgot to
make any changes to the SMTP delivery address (which of
course is different) for Exhcange.
Now things are working OK (interent, internal email,
external emails coming in) but cannot send emails to
external recipients.
Every time I run ICW after trying to apply the new SMTP
delivery address I get an error and it fails. (I do have
acces to ICW There is not smtp connector in Exchange.
HELP
Thanks
Anon Tag: spam post deleted Tag: 161447
HELP! Need Expert in Seattle area
I need the help of a Small Biz 2000 expert in the Seattle area. I have a
failed server that is limping along (hard drive errors, OS file corruption)
and unable to operate for any length of time without freezing. Help!
Marc Gordon Tag: spam post deleted Tag: 161439
LAN to LAN VPN
Hi there,
I have a client with 2 offices. They have a SBS2K server
at head office with 20 clients mainly running XP Pro. The
SBS runs Exchange and ISA with 2 nics. The Branch office
has a W2K server with about 5 clients on W2K Pro or XP
Pro. The W2K server just has 1 nic.
At each Site there is a Vigor ADSL Router with ISDN backup
(not setup). I have enabled a IPSEC VPN between the two
routers (I have also tried using PPTP which made a tunnel
fine but did not solve the following problem). I can ping
between a laptop plugged into the routers and I can ping
from HQ to the server at the branch office but I cannot
ping the server at HQ. I have adjusted some settings in
ISA and can now ping the internal router address at HQ
192.168.1.1 but the server lies at 192.168.0.2 and cannot
be seen.
However I have bypassed the ISA server and changed the
router address to 192.168.0.1 (then re-ran ICW) and
physically linked it to the switch and thus same subnet.
I then setup a static route in Routing and Remote Access
from the HQ server to the router and network addresses at
branch office and this pinged ok. However the internet
access at HQ was then disabled and I don't know if that
is the answer to the problem rather just it proves that
somewhere in ISA Server the route is blocked. I have
enabled IP Routing in ISA server for packet filtering but
to no avail.
I am really at a loss as how to talk through ISA server.
I have setup the branch office network address
192.168.2.0 up in the LAT on ISA Server but still no good.
Is it easier to bypass ISA in the end? Does ISA require
another ISA Server at the branch office? Would it be
simpler to network 2 ISA Server's? I can VPN in using a
windows VPN client and RDP to the server using the
server's external IP address on the internet.
Does this all make sense? Any ideas?
Many thanks Sam. Tag: spam post deleted Tag: 161438
Demand-Dial Routing through VPN (PPTP)
We have an existing SBS server connected to internet with ADSL Router (on a
second NIC) and static address.
I'm trying to setup a new server (Windows Server 2003 ) that will connect to
the internet through a DSL router (ISDN router for the moment) with a static
address. This new server will connect to the existing server with
Demand-Dial Routing through VPN (PPTP).
Using "Connecting a Remote Office to a Small Business Server 2000 Network"
white paper I managed to connect the two servers but the connection fails
when it's initiated by the remote office server with the following message:
"An error occured during connection of the interface. No more connections
can be made to this remote computer at this time because there are already
as many connections as the computer can accept ".
When the connection is initiated by the SBS server it works fine. What could
be the cause of this?
The SBS server was recently upgraded (migration) from 2000 to 2003 premium
but the white paper whould still apply... correct?
Thank you,
Nikos Tag: spam post deleted Tag: 161437
<< I have a question?>>
A fellow MVP who runs usergroups said that his community just doesn't
find value in newsgroups. That you have to filter out a lot of
gunk,etc. Just got me to thinking about the time a couple of years back
that Jeff Middleton asked "How can we do better?" in the Newsgroups. We
haven't done that in a long time...
So.... without further ado....I'm asking
"How can we [all] do better?"
Suggestions? Recommendations? Things that can be done better?
Recommendations to take back to Microsoft?
Remember, that it's my belief that all of us out here that have the BTDT
credentials are higher than any other credential holder, MVP tag line,
you name it.
[BTDT = been there, done that]
--
http://www.sbslinks.com/really.htm Tag: spam post deleted Tag: 161432
<<< SBS News of the Week 7/11/2004>>>
Kevin's song of the week
news://msnews.microsoft.com/O3d95boZEHA.2944@TK2MSFTNGP11.phx.gbl
---------------
This week is patch week - look our for Tuesday's Security bulletins
-----------------
David Barnes posted to my blog this list of patch install steps... So
what do you do to install SBS ?
http://msmvps.com/bradley/archive/2004/07/10/9904.aspx#FeedBack
------------------
Exchange
843363 - List of bugs that are fixed in Exchange Server 2003 Service
Pack 1:
http://support.microsoft.com/?kbid=843363
841995 - The Always-up-to-date Notifications feature may not work with
mobile devices in Exchange Server 2003 SP1:
http://support.microsoft.com/?kbid=841995
867628 - Monitoring programs report that the Store.exe process consumes
additional memory after you install Exchange Server 2003 SP1:
http://support.microsoft.com/?kbid=867628
867626 - New error correcting code is included in Exchange Server 2003 SP1:
http://support.microsoft.com/?kbid=867626
Small Business Server
840685 - An event ID 1000 error message is logged to the application
event log when you restart Windows Small Business Server 2003:
http://support.microsoft.com/?kbid=840685
827601 - Cannot send external mail when your smart host server is
different from the ISP server where your e-mail is stored in Windows
Small Business Server 2003:
http://support.microsoft.com/?kbid=827601
838429 - The "My Company's Internal Web Site" link on the default Web
site Welcome page does not work when you connect to the site over the
Internet in Windows SBS 2003:
http://support.microsoft.com/?kbid=838429
838431 - You receive an error message when you try to join your computer
to a Windows Small Business Server 2003 domain:
http://support.microsoft.com/?kbid=838431
842612 - You receive a "403 Forbidden" message when you try to connect
to a Web site that is on Small Business Server 2003:
http://support.microsoft.com/?kbid=842612
836413 - You receive an "unexpected error occurred" error message when
you try to access resources on a Windows-based network from your
Macintosh computer:
http://support.microsoft.com/?kbid=836413
837365 - You cannot expand the public folders list in Exchange System
Manager on a Windows Small Business Server 2003-based computer:
http://support.microsoft.com/?kbid=837365
--------------------
SBS once again talked about at the WWPC
--------------------
CRN | Ringing Up Partner Profits:
http://www.crn.com/sections/coverstory/coverstory.jhtml?articleId=22104657
-------------------
Ballmers memo to the troops
http://www.fortune.com/fortune/print/0,15935,661919,00.html
--------------------
CRN | Microsoft Rethinks Customer Segmentation:
http://www.crn.com/sections/breakingnews/breakingnews.jhtml?articleId=22104737
---------------------
Okay so how soon before a bobble head shows up on Ebay?
MICROSOFT Tries To Buddy Up To ISVs
Information Week - USA
... To entice its employees to participate in the program, Microsoft is
handing out bobble-head dolls of senior VP Eric Rudder, the executive
in charge of the ...
<http://www.informationweek.com/story/showArticle.jhtml?articleID=22104671>
In other news
- - - - - - - - - -
Feds drag feet on cybersecurity, officials say
Business and government representatives teamed up
in March to recommend steps to reduce the nation's
vulnerability to cyberattacks. But they say they
have yet to receive a response from the U.S.
Department of Homeland Security, and wonder what
is causing the delay. "There has been a 'pregnant
pause' waiting for a response," says Rick White,
CEO of TechNet, a technology industry trade group
and co-sponsor of a December 2003 summit to develop
an action plan.
http://computerworld.com/securitytopics/security/story/0,10801,94391,00.html
- - - - - - - - - -
Security hole found in Mozilla browser
update Developers at the open-source Mozilla
Foundation have confirmed that the latest version
of their Web browsers have a security flaw that
could allows attackers to run existing programs
on the Windows XP operating system. The flaw,
known as the "shell" exploit, was publicized
Wednesday on a security mailing list, along with
a link to a fix for the problem. Updated versions
of the affected software programs, which include
the Mozilla, Firefox and Thunderbird browsers,
have been released.
http://news.com.com/Security+hole+found+in+Mozilla+browser/2100-1002_3-5262676.html
- - - - - - - - - -
Cybsecurity research underfunded, executives say
The National Science Foundation can only fund a
subset of the research proposals it receives on
ways to better IT system security, an NSF official
said at a House technology subcommittee hearing.
?There are good ideas in the cybersecurity area
that we?re simply not able to fund,? Peter Freeman,
assistant director of NSF?s computer and information
science and engineering directorate, said at
yesterday?s hearing.
http://www.gcn.com/vol1_no1/daily-updates/26526-1.html
- - - - - - - - - -
Web app vulnerabilities on the rise
Nine out of 10 web applications remain vulnerable
to attack even after developers think they have
been 'fixed', security experts have claimed.
A study by security firm Imperva on the vulnerability
of public and private web applications found that,
despite periodic penetration testing and subsequent
fixes, flaws reappeared over time.
http://www.vnunet.com/news/1156498
- - - - - - - - - -
Fujitsu technique hides data in images
Fujitsu has developed a method of embedding data
invisibly within printed pictures. The procedure,
commonly known as steganography, will allow
numerical information to be hidden within a color
image and accessed via a camera. Steganograghy
involves altering an image in a way that cannot
be perceived by the human eye, but which can
be detected electronically. Fujitsu's technique
can apparently hide a 12-digit number in a
1-centimeter square.
http://zdnet.com.com/2100-1103_2-5260241.html
- - - - - - - - - -
Investigating digital images
What's real and what's phony? "Seeing is no longer
believing. Actually, what you see is largely irrelevant,"
says Dartmouth Professor Hany Farid. He is referring
to the digital images that appear everywhere: in
newspapers, on Web sites, in advertising, and in
business materials, for example. Farid and Dartmouth
graduate student Alin Popescu have developed a
mathematical technique to tell the difference between
a "real" image and one that's been fiddled with.
http://www.dartmouth.edu/~news/releases/2004/07/01.html
- - - - - - - - - -
Spam can hurt in more ways than one
Small businesses that depend heavily on the Web and
e-mail to market products are increasingly caught in
a spam squeeze. Hackers and spammers hijack their PCs
and then Internet providers wrongly shut down the
victims' e-mail.
http://www.usatoday.com/tech/news/2004-07-07-spam_x.htm
- - - - - - - - - -
E-voting security: getting it right
As we noted in our previous story - E-voting security:
looking good on paper? - the much-celebrated voter
verifiable paper trail is useless as a security measure
for Direct Recording Electronic (DRE) election systems,
and actually introduces far more problems than it solves.
http://www.theregister.co.uk/2004/07/08/getting_e-voting_security_right/
Wash. state announces safeguards for electronic voting
http://www.usatoday.com/tech/news/techpolicy/2004-07-08-wash-evote_x.htm
- - - - - - - - - -
Security spending rises, as do risks
IT security spending across the world is rising, but
so are virus and malicious code attacks. The findings
from the Global Information Security Survey, conducted
by vnunet.com's sister magazine Computing and its
international sister publications, shows businesses
are not following best practice security advice,
but are increasing security budgets to cope with
growing threats.
http://www.vnunet.com/news/1156507
- - - - - - - - - -
Service Pack Deux?
Microsoft should make SP2 available to all users
and backport the changes to older operating systems,
or they risk putting profits ahead of security yet
again. As some of you may have guessed by now, one
of my side interests when I'm not sitting in front
of a computer is the study of history.
http://www.securityfocus.com/columnists/254
- - - - - - - - - -
Scotland Yard and the case of the rent-a-zombies
Vast networks of home computers are being rented
out without their owners' knowledge to spammers,
fraudsters and digital saboteurs, security experts
said on Wednesday. The terminals have been infected
by a computer virus, turning them into "zombies"--
slaves to the commands of a malicious and unseen
controller. Connect them all up, and the result
is a powerful network of zombie PCs that security
experts call a "botnet."
http://zdnet.com.com/2100-1105_2-5260154.html
- - - - - - - - - -
Everyone saw this right?
ISP's have the right to read your mail
You've Got Mail (and Court Says Others Can Read It)
When everything is working right, an e-mail message
appears to zip instantaneously from the sender to
the recipient's inbox. But in reality, most messages
make several momentary stops as they are processed
by various computers en route to their destination.
Those short stops may make no difference to the
users, but they make an enormous difference to the
privacy that e-mail is accorded under federal law.
http://www.nytimes.com/2004/07/06/technology/06net.html
- - - - - - - - - -
- - - - - - - - - -
Great Britain: A new law on cybercrime is being elaborated
The threats facing Britain's Internet-enabled
companies and consumers are so great that new
laws are needed to fight the problem, and fix
the mistakes made by the government in its
previous attempts to combat spam. That was
the message from the Communications Management
Association (CMA) on Monday, as it kicked off
a debate into Broadband Britain at the
Enterprise Networks show.
http://www.crime-research.org/news/07.07.2004/474/
- - - - - - - - - -
Old-school worm loves Windows applications
The latest Lovgate worm variant can destroy access
to hundreds of Windows applications as it spreads.
The latest variant of the Lovgate worm scans PCs
for executable files and then renames them,
a tactic used by viruses from a much older
generation, according to antivirus companies.
http://news.zdnet.co.uk/internet/security/0,39020375,39159870,00.htm
- - - - - - - - - -
Password-stealing Trojan cut off at source
A malicious program that tried to steal banking
passwords has been stopped, says Symantec.
An attempt to pinch user information from banking
sites using a malicious pop-up program has been
nipped in the bud, says Symantec. Last week,
security experts uncovered a Trojan horse --
dubbed PWSteal.Refest by the security software
maker -- which installs itself through a pop-up
advertisement when users logged onto the Web
sites of any one of nearly 50 targeted banks.
http://news.zdnet.co.uk/internet/security/0,39020375,39159780,00.htm
- - - - - - - - - -
Lax data security seen at many Japanese companies
A Japanese government report published yesterday
says at least 40% of companies surveyed are taking
no special measures to ensure the privacy and
security of personal data stored on computers.
Results of the survey were included in the
government's annual White Paper on Information
and Communications in Japan, which was published
by the Ministry of Public Management, Home Affairs,
Posts and Telecommunications (MPHPT). It comes
after several incidents in the last year in which
personal information on customers, sometimes
numbering into the millions of people, has
beenleaked or stolen from Japanese companies.
http://computerworld.com/securitytopics/security/story/0,10801,94368,00.html
- - - - - - - - - -
36 percent of software worldwide pirated, trade group says
O&O Software, with only 28 employees, has built
a $3 million-a-year business developing award-
winning utilities for personal computers. How
much bigger it might be without the plague of
software piracy is impossible to say, but it's
clear sales are being lost.
http://www.siliconvalley.com/mld/siliconvalley/news/editorial/9097724.htm
Software piracy losses double
http://zdnet.com.com/2100-1104_2-5259395.html
http://www.cnn.com/2004/TECH/biztech/07/07/software.piracy.reut/index.html
http://www.newsfactor.com/story.xhtml?story_title=Software-Piracy-Soars&story_id=25750
UK firms 'forget' to pay £1bn for software
http://news.zdnet.co.uk/business/legal/0,39020651,39159797,00.htm
http://www.vnunet.com/news/1156500
Software pirates cost $9.7bn in Europe - BSA
http://www.theregister.co.uk/2004/07/07/bsa_software_piracy_study/
- - - - - - - - - -
Two more from NIST
Two new publications from the National Institute
of Standards and Technology provide technical help
for government agencies and businesses that are
required to protect information systems. One
publication offers a starting point for organizations
to understand basic information security principles.
The other gives technical tips for setting up
electronic authentication using guidelines issued
by Office of Management and Budget officials.
http://www.fcw.com/fcw/articles/2004/0705/web-nist-07-07-04.asp
- - - - - - - - - -
PC: Hey, your mobile's being stolen!
Researchers at Leeds University are developing
technology that will allow Bluetooth devices to
keep tabs on - and potentially protect - each other.
Bluetooth, the short-range personal area networking
technology, may have found a new application as
a guard dog for notebooks and smartphones.
http://news.zdnet.co.uk/hardware/emergingtech/0,39020357,39159785,00.htm
- - - - - - - - - -
Another day, another IE flaw...
Yet another vulnerability has been unearthed
in Microsoft's Internet Explorer - the company
is working on a 'series of updates', it says.
A computer science researcher has highlighted
the shortcomings of Microsoft's latest patch
for its Internet Explorer browser by identifying
another way that online vandals could run
malicious programs on a Web surfer's computer.
http://news.zdnet.co.uk/0,39020330,39159868,00.htm
Microsoft, biometrics firm to tackle homeland security
http://zdnet.com.com/2100-1105_2-5259889.html
- - - - - - - - - -
Multi-Layer Intrusion Detection Systems
A business critical system has been breached
by attackers. Responding to the event, you grab
your gear and head down to where the system is.
En route a red faced executive seemingly about
to explode brushes past you in a hurry, suddenly
turning around upon realization that you are the
specialist responding to the very incident which
has him on the brink. Already knowing the words
about to come out of his mouth, the man begins
to spout, "We need this system back up immediately!!
http://www.securityfocus.com/infocus/1788
- - - - - - - - - -
Attention, Shoppers:
You Can Now Speed Straight Through Checkout Lines!
Radio-frequency chips are retail nirvana. They're
the end of privacy. They're the mark of the beast.
Inside the tag-and-track supermarket of the future.
I'm in a supermarket called the Extra Future Store
in Rheinberg, Germany, 40 kilometers north of
Düsseldorf, jonesing for a bit of Philadelphia
cream cheese. I feed my request into the touchscreen
console on my shopping cart, and up pops a map
showing the optimal path to the dairy section.
I steer over and grab a box - regular in name
but far smarter than the average cream cheese.
The package carries a computer chip that talks
to a 2-millimeter-thin pad lining the shelf
under the box. When I pick up the cheese,
sensors in the pad notify the store's
database that the box has been removed.
http://www.wired.com/wired/archive/12.07/shoppers.html
--
http://www.sbslinks.com/really.htm Tag: spam post deleted Tag: 161431
Back-up
am endeavouring to complete a new back-up with no
success. I am backing up to a 4mm DDS tape which was not
formatted at insertion but was formatted by the Server on
request. It has no media on it at the present time so this
is like an initial back-up.
I feel that I am following all the Instructions and have
read all the information in "Help" about Back-ups but
at the end I receive this message:-
"There is no media with this selected type.
Add Unused media or click cancel to select another type.
It may take up to 60 Seconds for Removable Storage to
recognise new media."
Initially I was receiving a message which read "add 4mm
DDS media to the free storage pool or to Media
Pool "\Remote Storage|4 mm DDS" but I appear to have got
over that problem.
I am obviously missing some point!!!
Peter.
. Tag: spam post deleted Tag: 161430
Back-ups
I am endeavouring to complete a new back-up with no
success. I am backing up to a 4mm DDS tape which was not
formatted at insertion but was formatted by the Server on
request. It has no media on it at the present time so this
is like an initial back-up.
I feel that I am following all the Instructions and have
read all the information in "Help" about Back-ups but
at the end I receive this message:-
"There is no media with this selected type.
Add Unused media or click cancel to select another type.
It may take up to 60 Seconds for Removable Storage to
recognise new media."
Initially I was receiving a message which read "add 4mm
DDS media to the free storage pool or to Media
Pool "\Remote Storage|4 mm DDS" but I appear to have got
over that problem.
I am obviously missing some point!!!
Peter. Tag: spam post deleted Tag: 161428
Exchange mail server problem
I am having a problem with exchange 2000 on sbs and i need some help.
I set up sbs2k and it all seems to be working fine except for exchange. I
host a mail server so i am not popping with exchange.The problem i am having
is i can send mail but can't recieve on any of my addresses not even the
postmaster can recieve external mail. Internal works fine. It is not ISA as
i stopped the service and tested mail and still nothing, Any suggestions.
Thanks Tag: spam post deleted Tag: 161427
Small Business
I'm planning to open ecommerce business and hopefully grow.
What operating systems + servers using .NET technology?
thanks Tag: spam post deleted Tag: 161422
Moving SBS2000 to New Hardware
Hi
I would appreciate some assistance on the best way to moving an existing SBS
2000 server to new hardware.
The client has approx 30 PCs, one SBS 2000 server and two Windows 2000
Servers
If possible we do not want to change the domain name, ideally switch off old
server, install and switch on new server with no changes to existing W2K
servers or
clients.
SBS2000 server is mainly used for Exchange and as its a Pentium III 650
needs
an upgrade! Tag: spam post deleted Tag: 161409
OT, Dedicated hosting
hi, i think this should not be posted in this newsgroup, but i might get the
answers i need.. so sorry about it :)
my company is running a website that is on one of the many shared hosting
companies on the net
but now they are thinking of getting dedicated hosting
my questions here, if they get dedicated hosting, what is the procedure to
run a website that is secured from the bad boys outthere
the items that will be running on this server is,
IIS, MSSQL
my narrow mind says
renaming the administrator account, and long password,
patched and uptodate IIS, MSSQL
what else do they have to do?
Thanks Tag: spam post deleted Tag: 161406
How to transfer/import client's Outlook *.pst file to SBS 2000 Exchange.....
Hello all,
My client is currently running Windows 2000 Professional workstations
with Office 2000 Professional on a Windows NT 4.0 server. They each (6 in
all) have a great deal of information in their Outlook folders as well as
rules.
Here's my question; is there an easy way to transfer each of their
Outlook *.pst folders (including their rules) to the SBS 2000 server's
Exchange? Can anyone provide me with some links that have worked for them?
TIA
John Vighetto Tag: spam post deleted Tag: 161405
Song of the Week - July 10, 2004
This is a multi-part message in MIME format.
------=_NextPart_000_0099_01C46665.7901FD00
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Earlier this week I hads the need to go back and do some old DOS shell =
programming -- now that's what I call real programming! ;-) I also had =
to dig back into the archives to remember some old tweaks for Windows =
98. With all of that, my three sisters and I are coming together for a =
family reunion, of sorts, this week. So, with looking back so much, I =
knew the perfect song for the situation.
So, boys and girls, get your hands a 'clappin and your toes a 'tappin as =
we joing with Bob Seeger ...
Old Time Rock 'n Roll
(aka Old Time Software Code)
Just take those old data files off the shelf=20
I'll sit and load them all by myself=20
Today's servers ain't got the same soul=20
I like that old time Software Code
Don't try to take me to a Linux
You'll never even let me try to finish=20
In ten minutes I'll be late for the door=20
I like that old time Software Code
Still like that old time Software Code=20
That kind of coding that soothes the soul=20
I reminisce about the days of old=20
With that old time Software Code
Won't go to learn how to us some Java scripts
I'd rather hear some DOS or funky old bits
There's only one sure way to get me to go=20
Start using old time Software Code
Call me a relic, call me what you will=20
Say I'm old-fashioned, say I'm over the hill=20
Today's coding ain't got the same soul=20
I like that old time Software Code
Still like old time Software Code
That kind of coding just soothes the soul=20
I reminisce about the days of old=20
With that old time Software Code
--=20
Kevin Weilbacher [SBS-MVP]
"The days pass by so quickly now, the nights are seldom long"
------=_NextPart_000_0099_01C46665.7901FD00
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2800.1400" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff background=3D"">
<DIV><FONT face=3DArial size=3D2>Earlier this week I hads the need to go =
back and do=20
some old DOS shell programming -- now that's what I call real =
programming! ;-) I=20
also had to dig back into the archives to remember some old tweaks for =
Windows=20
98. With all of that, my three sisters and I are coming together for a =
family=20
reunion, of sorts, this week. So, with looking back so much, I knew the =
perfect=20
song for the situation.<BR><BR>So, boys and girls, get your hands a =
'clappin and=20
your toes a 'tappin as we joing with Bob Seeger ...<BR></FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Old Time Rock 'n Roll</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>(aka Old Time Software =
Code)</FONT></DIV>
<DIV><FONT face=3DArial size=3D2><BR>Just take those old data files off =
the shelf=20
<BR>I'll sit and load them all by myself <BR>Today's =
servers ain't got=20
the same soul <BR>I like that old time Software Code<BR><BR>Don't try to =
take me=20
to a Linux<BR>You'll never even let me try to finish <BR>In ten minutes =
I'll be=20
late for the door <BR>I like that old time Software Code<BR><BR>Still =
like that=20
old time Software Code <BR>That kind of coding that soothes =
the soul=20
<BR>I reminisce about the days of old <BR>With that old time Software=20
Code<BR><BR>Won't go to learn how to us some Java scripts<BR>I'd rather =
hear=20
some DOS or funky old bits<BR>There's only one sure way to get me to go=20
<BR>Start using old time Software Code<BR><BR>Call me a relic, call =
me what=20
you will <BR>Say I'm old-fashioned, say I'm over the hill <BR>Today's =
coding=20
ain't got the same soul <BR>I like that old time Software =
Code<BR><BR>Still like=20
old time Software Code<BR>That kind of coding just soothes the soul =
<BR>I=20
reminisce about the days of old <BR>With that old time Software =
Code<BR><BR>--=20
<BR>Kevin Weilbacher [SBS-MVP]<BR>"The days pass by so quickly now, the =
nights=20
are seldom long"</FONT></DIV></BODY></HTML>
------=_NextPart_000_0099_01C46665.7901FD00-- Tag: spam post deleted Tag: 161401
Hi to all you folks
As the subject says, firt I wanna to send greeting to all of the
participiants of this group.
We are the firm situated in Dubrovnik, Croatia which has recently purchased
a Windows 2003
SMB Server Premium edition (Academic Release).
We moved from our email pop account to excange and establish local domain.
Could you people help me with this stuffs:
1) How can I register a SMB with MS to get a tech support.?
2) How can I install ISA firewall clients on the machines?
3) How can I encrease manage security log setting for each workstation in
domain?
4) How can I manage synchronization setting (eg. some of our laptop
workstations are for some
reason going in offline mode?)
MS software are well documented, and there are lot of stuff on groups, net
but I want to
hear what are the best practice to manage first two or three basics steps to
configure SMB to work
correctly (e.g. http://companyweb are not working-> says bad request)
Also I must point that I (as possible administrator of SMB 2003) did not
installed it, it has be done
by the company who sold us a Fujitsu-Siemens server, and they have not
finished all the work.
Thanky you in advance.. Tag: spam post deleted Tag: 161398
SBS2003 wont start - recovery help please
Hi everyone
I have a system running Windows SBS2003.. its on a RAID5 array which had
some failures and caused some system corruptions as a result.
I have repaired the array but SBS2003 wont start.
Basically it was saying that it is missing system32\config\system - so I
went into the recovery console and copied the system.sav file to system..
unfortunately the system.sav file is from when it was first installed.
There is no Emergency Repair Disk or Automated Recovery Disk available.
There are tape backups of SYSTEM STATE available.
I have confirmed the data is still okay on the array?
Whats the best way to recover this system? Would putting in a temporary
drive, doing a SBS2003 install on that temp drive, then restoring system
state from tape, and then copying the necessary files back to the original
sbs2003 installation fix this? Tag: spam post deleted Tag: 161395
VPN from Draytek Vigor 2900 - remote client can't ping local LAN
Hi all,
Hopefully we're missing something simple and someone can point us in the
right direction.
Central Office:
SBS2000 - set-up as noted below:
Cable Modem
Broadband Router - passthrough for PPTP VPN enabled [int - 192.168.42.10]
External NIC on SBS [192.168.42.2]
ISA 2000
Internal NIC on SBS [172.16.0.1]
LAN [172.16.0.x]
Remote Office:
ADSL
Broadband Router - Draytek Vigor 2900Gi [int - 192.168.45.150]
PC - fixed IP - 192.168.45.160
As those who are familiar with the Vigor range will know, the Draytek kit
can initiate a VPN call [it can also act as a VPN Server if required]. We
can initiate a full-time VPN connection from the Vigor to our SBS box across
the Internet no problem but the remote PC cannot ping anything on the LAN IP
range.
This is kinda critical from a testing perspective as the crux of this is to
eventually implement an IP hardphone within the Remote office, connecting to
the VoIP-enabled telephone system on the LAN at the Central office.
We're sure this has to be a fairly basic routing issue and that we should be
able to add a route somehow to 'force' the VPN traffic back to the remote
LAN. Problem is we can't for the life of us work out what to do!
Anyone got any pointers?
Cheers,
David Tag: spam post deleted Tag: 161382
Remote Desktop
Does anyone know of a good remote desktop client than can do the following:
What we are looking for is something where someone on out WAN can goto a
webpage, and request a chat. From there they can tell us what their problem
is, and then if needed, we can take control of there system from the
inthernet through Port 80. If anyone can point me in the rigth direction on
this, I would appreciate it!
Keith
MMS IT Department
ksylvester@funddrive.com Tag: spam post deleted Tag: 161376
Site Bandwidth Managemnt
Hello All,
We have an SBS2k that has four satellites connected via VPN as well as RAS
users. The satellite offices are connected via router to our SBS VPN with
each site using a different class C private subnet. My question, are there
settings on SBS that I need to adjust so that the system can determine that
if a traffic has to go to a satellite site subnet, that it will adjust
accordingly? I've read about replication on AD and Exchange and using sites
to control traffic, but since we're using SBS, we don't have multiple
servers. I'm just trying to figure out if we need to make adjustments to
the SBS to make it process traffic more efficiently.
Second part of my question is: should the subnets from the satellite offices
be included in the LAT of ISA?
Thank you all for your comments.
Reggie Dones Tag: spam post deleted Tag: 161374
account lockout issues...
I have a couple of question regarding the account lockout policy.
1) I had originally set a local policy on our Win2K terminal server such
that 3 invalid logon attempts would cause an account lockout.
Later on, I had applied a domain wide policy (on our SBS 2000 server) that
set it to 5 invalid attempts.
I assumed the domain policy would override any local policy but it doesn't
seem to. If a user logs on 3 times with an incorrect password, it will still
lock them out!
Also becuase we have been having problems with users being locked out, I
decided to completely eliminate the lock out. So , I disabled account
lockouts in both the domain policy on the SBS 200 server and the local
policy on the win2K terminal server.
I am still getting accounts locking out after 3 invalid attempts.
What gives? Can anyone help me?
2) Also, maybe I need a lesson on what can cause a lockout...
We have a user who brings in his home laptop to copy drawings off our server
so he can work from home.
I configured his laptop so that he has the same drive mappings he has on his
work machine. Two drive mappings point to shares on our win2K server that is
part of our domain. The other mapping points to a share that is on an older
NT 4 server - which is NOT part of the domain.
When he logs onto his laptop, he is logging on locally - not as part of the
domain. (It's winxp home edition).
When I set up his shares, I configured the appropriate domain\username and
password so it would connect. For the NT 4 share which is part of a
workgroup (not in our domain) I configured his username and password
excluding the domain.
The problem is, as soon as he logs on and double clicks one of his mapped
drives, it asks for his password and when he enters that, it says it has
locked him out!!!
Why would the account be locking out when I have specified the
domain/username and passwords to use for the drive mappings? There is only
two drive mappings that use his domain username/password. If the lockout was
set to 3 invalid attempts, why is it locking out when there are only two
mappings ???
I am obviously missing something here...
Thanks
Brad Tag: spam post deleted Tag: 161370
VPN client dials in and the office network neighbourhood goes blank
Hi,
We have an SBS2000 server setup, running file, print, exchange, ISA and VPN.
We have 1 user who works half his time from home and uses VPN to log into
the office network for email download from exchange and file browsing hte
network. This works files for the client and office users, except for one
small problem. When the user VPN's in to the office, the network
neighbourhood here does not show any local computers. They are still
accessible just not visible.
Can anyone help point me in hte right direction.
The SBS2000 box does DHCP. All clients are XPPro or 2k. Network using TCP/IP
only.
One other thing, the remote user's laptop is not on the domain.. His
username and password are the same on the domain + laptop so his login works
fine. Tag: spam post deleted Tag: 161362
Peachtree on workstation in SBS Network
Does anyone know which ports have to be opened on ISA in SBS server to allow
Peachtree to successfully download updates?
Tony R Tag: spam post deleted Tag: 161354
Badwidth Monitoring
Hello,
I know this is not exactly an SBS question, but since I run SBS2k on my
server I thought I'd ask it here:
I want to monitor my WAN connection for uptime & throughput. We have a
cable modem & I suspect the line is fishy but everytime the cableman comes,
he finds no problems. Anyone have any ideas as to how I can generate hourly
bandwidth availability reports?
Thanks,
Shaq Tag: spam post deleted Tag: 161351
Company folder in SBS2003
Have they removed the Company Shared folder in the 2003
version of SBS??? If so WHY???
I installed SBS2003 on a test server and noticed no
Company Shared Folder. Have I done something wrong??? I
can't find it anywhere!
- Bobby Tag: spam post deleted Tag: 161348
Using Ghost
Hi all
I have succumbed to the fact that my C drive is going to
run out of space sooner or later and I need to move it to
a new drive.
My current setup is 3 x 36gb scsi disks
1st disk 8gb C drive system files and 28gb D drive
program files and exchange logs
2nd disk 33.91gb user data
3rd disk 33.91gb exchange info store
I want to move the 1st disk to a new 36gb disk so I can
expand the C drive to 20gb? so I need to ghost the C
drive and move it. I would also like to keep the D drive
on the 1st disk with the remaining space so I would
probably need to ghost that too.
How would I do this? Would I have to stop any services
while I ghost the original drive? Do I then swap the
disks and image the new disk?
So many questions from a nervous IT bod!
Any help would be greatly appreciated
thanks
Mark Tag: spam post deleted Tag: 161347
Terminal Services Manager
Hi
I am using terminal services to connect clients remotely. When they disconnect it still shows the processes that they are using. When they log in again it allows them to connect but creates a different connection. Therefore on the screen in the terminal services manager appears a user name saying connected and the same username saying disconnected (from the previous log out). So I have to right click on the user name saying disconnected and click 'Reset'. Then the processes and their name disappears. Do I always have to reset their last log out?
Sean Tag: spam post deleted Tag: 161345
SBS 2003 setup stops responding
Hy
my setup procedure allways spots to respond during setup from first CD
on 34% of "Installing Devices". Mouse is frozzen, HDD activity is high.
Server is Asus cp1700-s5.
What could be problem?
Thx
Igor Tag: spam post deleted Tag: 161342
SBS 2003 and Mac OS9.2
We have been asked to set up a new network using SBS2003 with 9 PC's and 1
Apple Mac running OS9.2. We know absolutely sod all about Macs! Can anyone
give us some detailed info on how to connect and configure the Mac or point
us somewhere where we can get that kind of information.
Many thanks
Peter Tag: spam post deleted Tag: 161336
Outbound Mail
Hi everyone,
I just installed a 2003 small business server - including running the internet & email wizard - but I cannot send mail for some reason.
I've tried using both DNS and a smarthost to route mail. I've tried my comcast email server (my ISP) and the mail server where I have email accounts because they host a website for me. Nothing seems to get mail out.
Initially, I found files in the BadMail folder. I deleted those and tinkered with the SMTP connector some more. I'm not getting anything in the BadMail folder, but mail apparently is going nowhere.
I see the message quickly leave the Outbox and I don't get any undeliverable messages. Where is the mail going? Where can I look for it? Any help would be appreciatied.
Frank Tag: spam post deleted Tag: 161329
Default Group Memberships
A new staff member at one of our sites has just rang me to enquire whether
she really should be able to open anyone's mailbox! Apparently all she has
to do in Outlook (2002) is go to Open/Other users folder, put in the name,
and voila! she can see their mailbox!
Now why should this be? No-one has given permission to anyone else, so I'm
assuming wrong/modified Group relationships. So just what are the default
group memberships for ordinary and power users?
TIA
Norm Hughes Tag: spam post deleted Tag: 161325
VPN problem
Hello Guys i have SBS 2000 when i try to dial into the server with a VPN connection it gives me the error 721 ( from xp computer saying the remote computer is not responding) but i can use remote desktop to get into the server any one got
any ideas how to trouble shoot??? thanks Tag: spam post deleted Tag: 161322
SBS 2000 Exchange upgradable to exchange 2003 ?
Is it possible to upgrade the exchange component of SBS 2000 to Exchange
2003 ?
I do not want to upgrade to SBS 03 due to user limits,has anyone tried this
and/or know if it is even possible.
Eventually All of the components (ISA, SQL, Exchange) will be upgraded.
Kevin D. Tag: spam post deleted Tag: 161312
New SBS2003 premium install problem
First of all, I realise this isn't the correct group for 2003 queries. So
far, my ISP hasn't added the new one to the list.
I am setting up a new IBM Dual CPU server. It's running on a RAID5
configuration with 2.5GB RAM.
I have got past the windows setup bit, and it's allowed me to log on to
windows and started the next phase of the install.
When the next phase starts, its asks me for the telephone, address details
etc. I click next and after about 5 minutes it fails with the following
message:
An error occurred while installing Internet Information Services
Anyone got any ideas, this is a major disaster for me as I am trying to
install this at the weekend :o(
Thanks in advance
Robbie Niblock Tag: spam post deleted Tag: 161301
Partition Magic
Hi
Will Partition magic let me resize my C drive on the
server? I want to extend it as it is only 8 gb
any thoughts??
thanks
Mark Tag: spam post deleted Tag: 161292
Security question on DNS zone transfers
In DNS settings for Forwarders, should zone transfers be allowed "to any
server" or be limted to named servers only?
If the latter, which other servers should be listed?
Situation: SBS2000, two NICs, and using a dynamic DNS service (DNS2GO) to
host Exchange e-mail and (gulp) web site.
Any assistance much appreciated. Tag: spam post deleted Tag: 161289