Anti-virus firewall is blocking remote desktop.

Friday, October 30th, 2015

Company acquisitions bring new challenges to environments. Such was the case with two servers which are used to test McAfee with the companies product. These servers were moved from a public area to a hardened site. They used to walk up and login when needed but now they could only use remote desktop. They reported the servers were down.

The McAfee fire was setup with a basic configuration and blocked ICMP and but did not block remote desktop.

Ping was enabled and on further review port 3389 needed to be enabled for TCP.

What type of windows licesense do I have?

Saturday, September 5th, 2015

Any reasonable sized Windows development shop will find itself using both Volume Licensed and MSDN software. Due to the nature of the MSDN licensing; sometimes you have to verify the licenses. The question asked is “How do you tell the difference?”

In my particular instance, a simple command will give you information to make the distinction.

slmgr /dli

(use CTRL + C to copy output from the resulting window)

---------------------------
Windows Script Host
---------------------------
Name: Windows(R), Enterprise edition
Description: Windows(R) Operating System, VOLUME_KMS_W10 channel
Partial Product Key: *snip*
License Status: Licensed
*snip*

If you notice where it displayed “channel” you will see the word “VOLUME”

This particular install uses a volume license.

The following was taken from a test server:

---------------------------
Windows Script Host
---------------------------
Name: Windows Server(R), ServerStandard edition
Description: Windows Operating System - Windows Server(R), VOLUME_KMSCLIENT channel
Partial Product Key: *snip*
License Status: Licensed
Volume activation expiration: 249240 minute(s) (173 day(s))

Key Management Service client information
 Client Machine ID (CMID): *snip*
 KMS machine name from DNS: *snip*
 KMS machine extended PID: *snip*
 Activation interval: 120 minutes
 Renewal interval: 10080 minutes
 KMS host caching is enabled

Another volume license.

In time I will update this with output from an OEM, Retail, and MSDN.

What is the iLO4 default password?

Saturday, September 5th, 2015

Sometimes new server setups are missing the iLO configuration. A failed OS install is usually what discovers this problem and the question of the default password is asked.

For ilo4, you have to look at the toe tag on the server. The password does not have any similarity to the serial number as with previous versions of iLO.

No remote server administration toolkit for Windows 10?

Friday, August 7th, 2015

RSAT is one of those “must haves” for server management and scripting.  It just makes work easier.

I early tested Windows 10 and there was a great deal of complaining when the preview release of RSAT stopped working.  I even expressed concern over this and promptly reserved a survey about what I thought of the new look.  They probably just “rolled their eyes” when I responded with I don’t care about “eye candy” when RSAT doesn’t work.

Microsoft’s response was it would be a couple weeks after RTM.  Sounds hopeful but they tend to align RSAT with the server release.

Will this be the case or does a couple of weeks in Microsoft speak mean next year?

Rather annoying and it does give thought to downgrading back to Windows 8.

-edit-

RSAT was released with the preview of 2016. Things are right in the Powershell universe again.

Flagging duplicates in excel

Monday, July 20th, 2015

Excel is a useful tool in matters such as listing systems which need migration to new domains. Problem is duplication of records.  Rather then sorting and reviewing each entry; why not flag each duplicate found?

  • To do so:
    1. Select the range of cells you wish to test. …
    2. On Excel’s Home tab, choose Conditional Formatting, Highlight Cells Rules, and then Duplicate Values.
    3. Click OK within the Duplicate Values dialog box to identify the duplicate values.
    4. Duplicate values in the list will now be identified.
  • Identifying Duplicate Values in an Excel List | AccountingWEB

    m.accountingweb.com/article/identifying-duplicate-values-excel…/221103

Restarting the automounter on Redhat

Saturday, June 20th, 2015

I had a messed up automounter and wanted to restart it. Sometimes I just draw a blank for the command. It could be that I am focused mainly on Windows these days and I simply forget the command. Who knows?

It’s simple really,

service autofs restart

If I needed to start it:

service autofs start

To get a simple status:

service autofs status

Now that I have written this; it should remain.

Importing Powershell Active directory module into windows 2008

Wednesday, June 17th, 2015

I am “crash and burn” testing windows 10. Painful but a good way to get the feel of it. One painful loss was the Active Directory module for Powershell. You have to have Remote Server Administration Tools (RSAT) and they stopped working for Win 10. There was a special release for the January version of Win10 but it died with the May version and Microsoft reported they will fix it with the general release.

What to do?

I thought about using one of my test VMs running Windows 2008. It had RSAT but when I tried to import the Active Directory module into Powershell; I received an error saying it did not exist.

I found there were a extra other steps needed to be done:

1) Import-Module ServerManager

2) Add-WindowsFeature RSAT-AD-Powershell

After that, I was able to import the active directory module.

-edit- 07/23/15

There was a recent update to windows 10 and it nuked RSAT.  Microsoft will basically fix it after the OS is released.  *sighs*

Windows 10 Preview won’t activate!

Friday, June 5th, 2015

I am early testing windows 10.  Overall I am liking the OS but it has it quirks and issues. My biggest issue involved the Juniper Pulse client no longer functioning.

I recently upgraded to release 100130 and found the pulse client not working and the OS required activation.

The product key had changed and the new one would not take. The error basically said the wrong product key is in play?

I tried many things and nothing worked. Then, I remembered I was testing the Enterprise version.

A quick check of the site and sure enough there was a different product key.  I used it and the OS activated.

The pulse client decided to be a pain again. It would take the token and then sit forever with a message about securing the tunnel.

I installed the latest build of but the problem remained.  I removed and installed the client and this time it was able to connect!

Terabit speed for SDN?

Friday, May 29th, 2015

The US government has asked for terabit speed over optical for SDN.  Just a little feeling of “whoa” especially since I remember thinking a  1200 baud modem was the epitome of networking speed.  Amazing times in computing…..

Cygwin sshd multiple user access.

Monday, May 4th, 2015

Some of our development groups like to use SSH.  Especially, if they have a Linux background and were tossed into the windows world.

The basic configuration does work.  However, it’s for the main user running the sshd.

The documentation will tell you to have the user run ssh-config-user.  However, it’s not enough as you will be tormented by messages of /bin/bash not allowed and the connection dropping right after password entry.

Certain authority rights have to be established for the main account to allow other users to access the box.  Try the following:

  • editrights -l -u <local or domain/user>
  • editrights -a SeAssignPrimaryTokenPrivilege -u <local or domain/user>
  • editrights -a SeCreateTokenPrivilege -u <local or domain/user>
  • editrights -a SeTcbPrivilege -u <local or domain/user>
  • editrights -a SeServiceLogonRight -u <local or domain/user>
  • editrights -l -u <local or domain/user>

Restart you cygwin service and you should be able to ssh from any box.