<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>microsoftNOW &#187; Windows Server 2003</title>
	<atom:link href="http://www.microsoftnow.com/tag/windows-server-2003/feed" rel="self" type="application/rss+xml" />
	<link>http://www.microsoftnow.com</link>
	<description></description>
	<lastBuildDate>Wed, 18 Jan 2012 05:17:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.2</generator>
		<item>
		<title>Using Windows File Servers with Macintosh clients</title>
		<link>http://www.microsoftnow.com/2009/05/using-windows-file-servers-with.html</link>
		<comments>http://www.microsoftnow.com/2009/05/using-windows-file-servers-with.html#comments</comments>
		<pubDate>Sun, 03 May 2009 15:11:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[File servers]]></category>
		<category><![CDATA[Macintosh]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2009/05/using-windows-file-servers-with-macintosh-clients.html</guid>
		<description><![CDATA[This article used to exist on www.shijaz.com before it was taken down in May 2009. This article gives helpful hints on how to successfully interoperate Windows Server with Mac clients. Areas covered are: Accessing Windows File Server from Macintosh Using Windows DHCP Server with Macintosh clients Using Windows DNS with Macintosh clients Additional tips for [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2009%252F05%252Fusing-windows-file-servers-with.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Using%20Windows%20File%20Servers%20with%20Macintosh%20clients%22%20%7D);"></div>
<table border="1" cellspacing="0" cellpadding="2" width="500">
<tbody>
<tr>
<td valign="top" width="500">
<p align="left"><em>This article used to exist on </em><a href="http://www.shijaz.com"><em>www.shijaz.com</em></a><em> before it was <a href="http://www.microsoftnow.com/2009/05/changes-to-web-site.html" target="_blank">taken down</a> in May 2009. </em></p>
</td>
</tr>
</tbody>
</table>
<p align="left">This article gives helpful hints on how to successfully interoperate Windows Server with Mac clients. Areas covered are:</p>
<ul>
<li>Accessing Windows File Server from Macintosh</li>
<li>Using Windows DHCP Server with Macintosh clients</li>
<li>Using Windows DNS with Macintosh clients</li>
<li>Additional tips for Macintosh (How to Ping, NSLOOKUP, etc)</li>
</ul>
<p><b>Background</b></p>
<p>Many organizations such mainly media and advertising agencies have a mixed environment containing Windows and Macintosh machines. This article explains some of common tasks required when operating Macintosh clients in a Windows Server environment.</p>
<p><b>Making Windows file shares accessible to Macintosh users</b></p>
<p><b>Step 1. </b><b>Configure the Windows file server</b></p>
<ol>
<li>Create the folder on the file server</li>
</ol>
<ol start="start">
<li>Right-click <b>My Computer</b>, choose <b>Manage</b>.</li>
</ol>
<ol start="start">
<li>On the left pane, expand <b>System Tools</b> &gt; <b>Shared Folders</b></li>
</ol>
<ol start="start">
<li>Right Click <b>Shared Folders</b> choose <b>Configure File Server for Macintosh</b>.</li>
</ol>
<ol start="start">
<li>On the <b>Configuration </b>tab, under <b>Security</b>, select “<b>Apple ClearText or Microsoft”</b> under <b>Authentication.       <br /><a href="http://lh5.ggpht.com/_lSGuEfogrPw/SyzssX5PPjI/AAAAAAAABtY/qZJ_7WIlCGA/s1600-h/image%5B4%5D.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/_lSGuEfogrPw/SyzstxclU9I/AAAAAAAABtc/-S9plzUBMQE/image_thumb%5B6%5D.png?imgmax=800" width="412" height="457" /></a> </b></li>
</ol>
<ol start="start">
<li>If you would like to allow Macs to save the password, put a check mark next to <b>Allow workstations to save password.</b></li>
</ol>
<ol start="start">
<li>You can also specify a logon message for connected Mac users if required.</li>
</ol>
<ol start="start">
<li>On the left pane, expand <b>System Tools</b> &gt; <b>Shared Folders</b> &gt; <b>Shares</b></li>
</ol>
<ol start="start">
<li>Right Click on <b>Shares</b> and choose <b>New </b><b>&gt; Share</b>.</li>
</ol>
<ol start="start">
<li>Click Next on the welcome screen.     </p>
<p><a href="http://lh5.ggpht.com/_lSGuEfogrPw/SyzsvIp8moI/AAAAAAAABtg/0hp7s-S5YW8/s1600-h/image%5B8%5D.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/_lSGuEfogrPw/SyzsxO54ogI/AAAAAAAABtk/BOMkfM_-LqI/image_thumb%5B8%5D.png?imgmax=800" width="515" height="398" /></a> </li>
</ol>
<ol start="start">
<li>Put a check mark next to <b>Apple Macintosh users</b>. Click Next.</li>
</ol>
<ol start="start">
<li>On the next screen, choose <b>Use custom share and folder permissions</b> and click <b>Customize</b>.      </p>
<p><a href="http://lh5.ggpht.com/_lSGuEfogrPw/SyzsyiSSuAI/AAAAAAAABto/AVZeMZqyeDs/s1600-h/image%5B12%5D.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/_lSGuEfogrPw/Syzs0PXvnrI/AAAAAAAABts/VyXS9kINWiU/image_thumb%5B10%5D.png?imgmax=800" width="512" height="396" /></a> </li>
</ol>
<ol start="start">
<li>Click on the security tab and add users whom you want to give access.</li>
</ol>
<ol start="start">
<li>For read-only access Allow only <b>Read &amp; Execute, List folder contents, Read</b> privileges. For full access, click <b>Modify</b> and <b>Write</b> also.      </p>
<p><a href="http://lh4.ggpht.com/_lSGuEfogrPw/Syzs1LJfoII/AAAAAAAABtw/AWpslsPXOPg/s1600-h/image%5B16%5D.png"><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/_lSGuEfogrPw/Syzs22GfwPI/AAAAAAAABt0/yH3y8dXsKrA/image_thumb%5B12%5D.png?imgmax=800" width="377" height="455" /></a> </li>
</ol>
<ol start="start">
<li>Click <b>Next</b> and then click <b>Close</b>.      </p>
<p><a href="http://lh4.ggpht.com/_lSGuEfogrPw/Syzs7s0V9hI/AAAAAAAABt4/WmmVvitUmdw/s1600-h/image%5B20%5D.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/_lSGuEfogrPw/SyztA2WGh7I/AAAAAAAABt8/DXotl2-29qQ/image_thumb%5B14%5D.png?imgmax=800" width="588" height="420" /></a> </li>
</ol>
<p>16. In <b>Computer Management</b>, see that a new <b>MACINTOSH</b> share for your folder has been created. Right click the <b>MACINTOSH</b> share for your folder and select <b>Properties</b>.</p>
<p>17. Under <b>SFM Volume Security</b>, Remove the check mark next to <b>This Volume is read-only</b>.    </p>
<p><a href="http://lh5.ggpht.com/_lSGuEfogrPw/SyztCbMDMXI/AAAAAAAABuA/FNnJ0MH9-ZA/s1600-h/image%5B24%5D.png"><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/_lSGuEfogrPw/SyztDncgLTI/AAAAAAAABuE/cBLpkMojPcQ/image_thumb%5B16%5D.png?imgmax=800" width="412" height="457" /></a> </p>
<ol start="start">
<li>Click <b>OK</b>.</li>
</ol>
<p><b>Step 2. </b><b>Configure the Macintosh client</b></p>
<ol>
<li>Goto <b>Apple </b><b>&gt; Chooser</b></li>
</ol>
<ol start="start">
<li>Click <b>AppleShare</b>. Click <b>Server IP Address</b>.</li>
</ol>
<ol start="start">
<li>Enter IP address of file server<b>.</b></li>
</ol>
<ol start="start">
<li>Click <b>Connect</b>.</li>
</ol>
<ol start="start">
<li>Choose <b>Registered user</b> and enter domain username and password. Click <b>Connect</b>.</li>
</ol>
<ol start="start">
<li>Select the folder that you shared on the file server and click <b>Connect</b>. You can also save the password to keychain before clicking connect.</li>
</ol>
<ol start="start">
<li>The icon for the shared location will appear on the desktop.</li>
</ol>
<p><b></b></p>
<p><b>Enabling Macintosh clients to use Windows DHCP (Mac OS X)</b></p>
<p><b></b></p>
<ol>
<li>Go to <b>Apple </b><b>&gt; Control Panel &gt; TCP/IP</b></li>
</ol>
<ol start="start">
<li>Select obtain IP addresses through <b>DHCP</b></li>
</ol>
<ol start="start">
<li>Close the window. Click <b>Save</b> when prompted.</li>
</ol>
<p><b>Enabling Macintosh clients to use Windows DHCP (Mac OS 10.x/TIGER)</b></p>
<ol>
<li>Go to <b>Apple </b><b>&gt; Control Panel &gt; Networks</b></li>
</ol>
<ol start="start">
<li>Select the Network interface connected to the LAN</li>
</ol>
<ol start="start">
<li>Select <b>TCP/IP</b>.</li>
</ol>
<ol start="start">
<li>Choose <b>DHCP.</b></li>
</ol>
<p><b>Enabling Macintosh clients to use Windows DNS</b></p>
<ol>
<li>Go to <b>Apple </b><b>&gt; Control Panel &gt; TCP/IP (</b>for Mac OS 10.x, choose <b>Networks &gt;</b> <b>TCP/IP</b>)</li>
</ol>
<ol start="start">
<li>Under<b> Name Servers</b>, specify your DNS Server IP address.</li>
</ol>
<ol start="start">
<li>You can also specify your domain name suffix under <b>Search Domains</b>.</li>
</ol>
<ol start="start">
<li>On your Windows DNS Server, allow <b>both secure &amp; non-secure</b> updates.</li>
</ol>
<p><b></b></p>
<p><b>Additional Tips</b></p>
<p><b></b></p>
<ul>
<li>For Mac OS 10.x, you can use “<b>ping”</b> command (without quotes) from the <b>Terminal</b>. (Go &gt; Applications &gt; Terminal) <b></b></li>
</ul>
<p><b></b></p>
<ul>
<li>For Mac OS 10.x, you can use the “<b>dig</b>” (without quotes) to see the name servers that are being used. In the last four lines of the output, you will see the IP address of the primary DNS server mentioned on a line starting with the word <b>SERVER</b></li>
</ul>
<p><b></b></p>
<p>SERVER:192.168.2.10#53</p>
<p><b></b></p>
<ul>
<li>For Mac OS 9.x, you can do a ping, NSLOOKUP, etc by using a free tool called OT Tools, available for download from <a href="http://mac.softpedia.com/get/Math-Scientific/OTTool.shtml">http://mac.softpedia.com/get/Math-Scientific/OTTool.shtml</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2009/05/using-windows-file-servers-with.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to enable Remote Desktop remotely</title>
		<link>http://www.microsoftnow.com/2009/05/how-to-enable-remote-desktop-remotely.html</link>
		<comments>http://www.microsoftnow.com/2009/05/how-to-enable-remote-desktop-remotely.html#comments</comments>
		<pubDate>Sun, 03 May 2009 14:54:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[RDP]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Windows Vista]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2009/05/how-to-enable-remote-desktop-remotely.html</guid>
		<description><![CDATA[This article used to exist on www.shijaz.com before it was taken down in May 2009. Originally published in January 2008. This article explains how you can enable Remote Desktop on a server that you do not have physical access to. You&#8217;ve built new servers, updated them with the latest service pack, and even run Windows [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2009%252F05%252Fhow-to-enable-remote-desktop-remotely.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22How%20to%20enable%20Remote%20Desktop%20remotely%22%20%7D);"></div>
<table border="1" cellspacing="0" cellpadding="2" width="500">
<tbody>
<tr>
<td valign="top" width="500">
<p align="left"><em>This article used to exist on </em><a href="http://www.shijaz.com"><em>www.shijaz.com</em></a><em> before it was <a href="http://www.microsoftnow.com/2009/05/changes-to-web-site.html" target="_blank">taken down</a> in May 2009. Originally published in January 2008.</em></p>
</td>
</tr>
</tbody>
</table>
<p>This article explains how you can enable Remote Desktop on a server that you do not have physical access to.</p>
<p align="left">You&#8217;ve built new servers, updated them with the latest service pack, and even run Windows Update. Proud of the good job you done, you move upstairs to the comfort of your office to do the rest of the installation, away from the freezing server room. And then you suddenly realize that you did not enable Remote Desktop connections on your new server. Aw, now you need to go back all the way to your data center to enable RDP. The situation is even worse if you pre-configured the server without enabling RDP and shipped it to your branch location in Timbuktu!</p>
<p align="left">Well, here&#8217;s the good news. You can actually enable remote desktop remotely. All you need to do is open up the registry of that server remotely, and make some changes and then initiate a remote restart of the server. Well, that&#8217;s the only downside &#8211; you normally don&#8217;t need a restart if you enable it physically.   <br />1. On your Windows workstation, open Registry Editor (<b>Start</b> &#8211;&gt; <b>Run</b> &#8211;&gt; <b>Regedit.exe</b> &#8211;&gt; <b>OK</b>)<b>     <br /></b>2. On the File menu, choose <b>Connect Network Registry</b>.</p>
<p align="left"><a href="http://lh5.ggpht.com/_lSGuEfogrPw/SyzqU8WdA_I/AAAAAAAABtI/WmF2kXiBe7A/s1600-h/Regedit1%5B5%5D.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="Regedit1" border="0" alt="Regedit1" src="http://lh3.ggpht.com/_lSGuEfogrPw/SyzqXeaxRJI/AAAAAAAABtM/gnFfLGYChFM/Regedit1_thumb%5B3%5D.jpg?imgmax=800" width="554" height="335" /></a>    <br />3. Select the name of the computer that you want to enable RDP on. Make sure the logged in user has administrator rights on the remote server.</p>
<p align="left"><a href="http://lh6.ggpht.com/_lSGuEfogrPw/SyzqZZS4DQI/AAAAAAAABtQ/EfGhVPRpj94/s1600-h/enable1%5B3%5D.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="enable1" border="0" alt="enable1" src="http://lh3.ggpht.com/_lSGuEfogrPw/SyzqbI82hJI/AAAAAAAABtU/byC1LXelirQ/enable1_thumb%5B1%5D.jpg?imgmax=800" width="476" height="260" /></a> </p>
<p align="left">&#160;</p>
<p align="left">4. On the remote computer, Navigate to the key <b>HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server</b>. Find a value named <b>fDenyTSConnection</b> and change it to <b>0</b> (zero).</p>
<p align="left">5. Restart the remote computer by typing the following command in the Command prompt of your workstation.</p>
<p align="left">shutdown -m \\myserver -r</p>
<p align="left">where &#8216;myserver&#8217; is the name of your server.</p>
<p align="left">6. Wait for the server to restart and connect to it using Remote Desktop Connection (MSTSC) from your Windows PC.</p>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2009/05/how-to-enable-remote-desktop-remotely.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Server service not starting: &quot;Access Denied&quot;</title>
		<link>http://www.microsoftnow.com/2008/11/server-service-not-starting-denied.html</link>
		<comments>http://www.microsoftnow.com/2008/11/server-service-not-starting-denied.html#comments</comments>
		<pubDate>Tue, 25 Nov 2008 06:15:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2008/11/server-service-not-starting-access-denied.html</guid>
		<description><![CDATA[Recently, I noticed that many of the computers running Windows Server 2003 SP2 had the Server service in the stopped state. When I tried to manually start the service I got an Access Denied error. A restart of the server didn&#8217;t help. The Server service is critical because file sharing depends on it. If the [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2008%252F11%252Fserver-service-not-starting-denied.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Server%20service%20not%20starting%3A%20%26quot%3BAccess%20Denied%26quot%3B%22%20%7D);"></div>
<p>Recently, I noticed that many of the computers running Windows Server 2003 SP2 had the <strong>Server </strong>service in the <strong>stopped</strong> state. When I tried to manually start the service I got an <strong>Access Denied</strong> error. A restart of the server didn&#8217;t help.</p>
<p>The Server service is critical because file sharing depends on it. If the service is stopped, shared folders and administrative shares on the server cannot be accessed. This is especially critical on file servers, and on domain controllers for replication/access to SYSVOL folder for group policies.</p>
<p>The problem got resolved when I installed all the latest updates from Microsoft Update and restarted the machine. This is a security vulnerability listed in the <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">security bulletin MS08-067</a> released by Microsoft this Sunday.</p>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2008/11/server-service-not-starting-denied.html/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Unlocking files that are in use</title>
		<link>http://www.microsoftnow.com/2008/10/unlocking-files-that-are-in-use.html</link>
		<comments>http://www.microsoftnow.com/2008/10/unlocking-files-that-are-in-use.html#comments</comments>
		<pubDate>Wed, 22 Oct 2008 18:20:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[File servers]]></category>
		<category><![CDATA[SysInternals]]></category>
		<category><![CDATA[tips]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Windows Vista]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2008/10/unlocking-files-that-are-in-use.html</guid>
		<description><![CDATA[Sometimes you cannot delete or rename a file that is currently in use. You might receive an access violation error, or simply a message telling you that your action could not be completed because the file is open in another program. You may have already come across the Unlocker freeware tool that lets you &#34;unlock&#34; [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2008%252F10%252Funlocking-files-that-are-in-use.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Unlocking%20files%20that%20are%20in%20use%22%20%7D);"></div>
<p>Sometimes you cannot delete or rename a file that is currently in use. You might receive an access violation error, or simply a message telling you that your action could not be completed because the file is open in another program.</p>
<p><a href="http://lh6.ggpht.com/shijaz.a/SP9uBsygZ8I/AAAAAAAAA3o/ithdm4279Gs/s1600-h/image%5B6%5D.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="280" alt="image" src="http://lh6.ggpht.com/shijaz.a/SP9uFgU0CsI/AAAAAAAAA3s/hRLIauTmEuo/image_thumb%5B2%5D.png?imgmax=800" width="500" border="0" /></a> </p>
<p>You may have already come across the Unlocker freeware tool that lets you &quot;unlock&quot; files that are in use by some application.</p>
<p>Here is another way (let&#8217;s call it the &#8216;techie&#8217; way) to unlock files that are in use. It makes use of the <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx">Process Explorer tool from Windows SysInternals</a>. </p>
<ul>
<li>Download the Process Explorer tool. Execute <strong>procexp.exe</strong></li>
<li>Choose <strong>Find </strong>&gt; <strong>Find Handle or DLL </strong>option</li>
</ul>
<p><a href="http://lh3.ggpht.com/shijaz.a/SP9uTchWhII/AAAAAAAAA3w/RtO7fP4VYBA/s1600-h/image%5B12%5D.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="419" alt="image" src="http://lh6.ggpht.com/shijaz.a/SP9uer8wvGI/AAAAAAAAA30/cNhru_1_Kz0/image_thumb%5B6%5D.png?imgmax=800" width="504" border="0" /></a></p>
<ul>
<li> Type the name of the file you want to unlock and hit <strong>Search</strong>.</li>
</ul>
<p><a href="http://lh5.ggpht.com/shijaz.a/SP9uhtTjSAI/AAAAAAAAA34/QNtxCzNiUko/s1600-h/image%5B22%5D.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="274" alt="image" src="http://lh5.ggpht.com/shijaz.a/SP9umDXJlLI/AAAAAAAAA38/x4VuwiBRDJo/image_thumb%5B10%5D.png?imgmax=800" width="512" border="0" /></a> </p>
<ul>
<li>The process EXE locking the file and the path to the file are listed. Double click on the result.</li>
</ul>
<p><a href="http://lh6.ggpht.com/shijaz.a/SP9uyxv7TxI/AAAAAAAAA4E/F17boDaDoec/s1600-h/image%5B28%5D.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="437" alt="image" src="http://lh5.ggpht.com/shijaz.a/SP9u9Qgo_oI/AAAAAAAAA4I/0ERFHju-IaE/image_thumb%5B14%5D.png?imgmax=800" width="554" border="0" /></a></p>
<ul>
<li>The file handle will be highlighted. Right-click on it and choose <strong>Close Handle</strong>. </li>
</ul>
<p>Your file is now unlocked and can now be deleted, moved or renamed.</p>
<p>A little disclaimer here, closing handles might cause data inconsistency, loss and/or other undesirable effects. Make sure you understand what you&#8217;re doing before you do it.</p>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2008/10/unlocking-files-that-are-in-use.html/feed</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
		<item>
		<title>Slow Remote Desktop on Dell PowerEdge 2950 running Windows Server 2003 R2 x64</title>
		<link>http://www.microsoftnow.com/2008/05/slow-remote-desktop-on-dell-poweredge.html</link>
		<comments>http://www.microsoftnow.com/2008/05/slow-remote-desktop-on-dell-poweredge.html#comments</comments>
		<pubDate>Thu, 15 May 2008 10:30:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Dell]]></category>
		<category><![CDATA[PowerEdge]]></category>
		<category><![CDATA[RDP]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2008/05/slow-remote-desktop-on-dell-poweredge-2950-running-windows-server-2003-r2-x64.html</guid>
		<description><![CDATA[I&#8217;ve seen this problem when I prepare Dell PowerEdge 2950 servers using the Dell OpenManage Server Assistant 5.3 to install Windows Server 2003 R2 x64 with Service Pack 2. Once the OS installation is complete, if you enable Remote Desktop and connect from a Windows Vista machine using RDP, the RDP session/screen refresh is kind [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2008%252F05%252Fslow-remote-desktop-on-dell-poweredge.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Slow%20Remote%20Desktop%20on%20Dell%20PowerEdge%202950%20running%20Windows%20Server%202003%20R2%20x64%22%20%7D);"></div>
<p><a href="http://2.bp.blogspot.com/_lSGuEfogrPw/SCwV2YSm8VI/AAAAAAAAAtQ/PcdVjk7HanI/s1600-h/2950.jpg"><img id="BLOGGER_PHOTO_ID_5200555693683700050" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_lSGuEfogrPw/SCwV2YSm8VI/AAAAAAAAAtQ/PcdVjk7HanI/s400/2950.jpg" border="0" /></a>
<div>
<div>I&#8217;ve seen this problem when I prepare Dell PowerEdge 2950 servers using the Dell OpenManage Server Assistant 5.3 to install Windows Server 2003 R2 x64 with Service Pack 2.</p>
<p>Once the OS installation is complete, if you enable Remote Desktop and connect from a Windows Vista machine using RDP, the RDP session/screen refresh is kind of slow. This only happens with x64 edition of Windows Server 2003.</p>
<p>The problem seems to disappear when I install all the latest updates from Microsoft Update/Windows Update so I guess the issue is addressed in one of the fixes.</p></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2008/05/slow-remote-desktop-on-dell-poweredge.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Crash-proofing the Enterprise Root CA</title>
		<link>http://www.microsoftnow.com/2008/04/crash-proofing-enterprise-root-ca.html</link>
		<comments>http://www.microsoftnow.com/2008/04/crash-proofing-enterprise-root-ca.html#comments</comments>
		<pubDate>Tue, 08 Apr 2008 04:24:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[backup and recovery]]></category>
		<category><![CDATA[certificate]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2008/04/crash-proofing-the-enterprise-root-ca.html</guid>
		<description><![CDATA[Your enterprise root CA is an important piece of your enterprise network. Especially if you issue a lot of certificates for a wide variety of purposes to your users. A root CA also needs to be highly secured, both physically and over the network, because it contains the private key. A downtime on the root [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2008%252F04%252Fcrash-proofing-enterprise-root-ca.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Crash-proofing%20the%20Enterprise%20Root%20CA%22%20%7D);"></div>
<p><a href="http://1.bp.blogspot.com/_lSGuEfogrPw/R_r9hUUPyJI/AAAAAAAAAmE/hYRkgBAecE8/s1600-h/icon-ssl_certificate-64x64.png"><img style="FLOAT: right; MARGIN: 0px 0px 10px 10px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5186736669701687442" border="0" alt="" src="http://1.bp.blogspot.com/_lSGuEfogrPw/R_r9hUUPyJI/AAAAAAAAAmE/hYRkgBAecE8/s400/icon-ssl_certificate-64x64.png" /></a>Your enterprise root CA is an important piece of your enterprise network. Especially if you issue a lot of certificates for a wide variety of purposes to your users.
<div></div>
<p>
<div>A root CA also needs to be highly secured, both physically and over the network, because it contains the private key. A downtime on the root CA is seldom noticed because there is minimal need for using the server &#8211; except while issuing or renewing certificates. In fact, the Microsoft best practice is to power down your root CA when not in use.</div>
<p>
<div></div>
<div>Now, what to do if your enterprise root CA crashes? Information about the enterprise root CA is written on the Active directory, in the registry of the Windows Server hosting the CA, and most important of all, the private key is also stored on this machine.</div>
<p>
<div></div>
<div>Quite obviously, In the event of a total failure, a backup is required. Taking a backup of the root CA is often neglected. Believe me, it takes virtually no time to take a backup and it&#8217;s the only way to restore your CA with all private keys intact.</div>
<p>
<div></div>
<div><a href="http://support.microsoft.com/kb/298138">Microsoft KB Article 298138</a> explains how you can backup your CA and move it to separate hardware. The procedure is also applicable if the hardware running your root CA crashes totally and you want to set up the same CA on a new server hardware.</div>
<p>
<div></div>
<div>In this post, I will explain how you can automate a backup of the CA. Restoration can be done as per the article mentioned above. Write a script &#8220;backupCA.bat&#8221; with the following code:</div>
<div></div>
<p>
<div><strong>certutil -backup D:\backup</strong></div>
<div><strong>certutil -backupkey D:\backup</strong></div>
<div><strong>certutil -backupdb D:\backup</strong></div>
<div><strong>reg export HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration D:\backup\regbackup.reg</strong></div>
<p>
<div><strong></strong></div>
<div>Make sure the D:\backup folder is picked up by your centralized tape backup solution. Be extra careful with the tape because this contains the private key of your CA. Your organization should have the handling of tapes included in the security policy.</div>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2008/04/crash-proofing-enterprise-root-ca.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Articles on enabling Remote Desktop</title>
		<link>http://www.microsoftnow.com/2008/02/articles-on-enabling-remote-desktop.html</link>
		<comments>http://www.microsoftnow.com/2008/02/articles-on-enabling-remote-desktop.html#comments</comments>
		<pubDate>Sun, 17 Feb 2008 09:38:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[article]]></category>
		<category><![CDATA[RDP]]></category>
		<category><![CDATA[Server Core]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Server 2008]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2008/02/articles-on-enabling-remote-desktop.html</guid>
		<description><![CDATA[It&#8217;s been some time since I&#8217;ve written new articles on shijaz.com I have added two new articles on Remote Desktop: How to enable Remote Desktop &#8220;remotely&#8221;Discusses how to enable Remote Desktop on a machine that you do not have physical access to. Needs administrator privileges (of course!) How to enable Remote Desktop on Windows Server [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2008%252F02%252Farticles-on-enabling-remote-desktop.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Articles%20on%20enabling%20Remote%20Desktop%22%20%7D);"></div>
<p>It&#8217;s been some time since I&#8217;ve written new articles on <a href="http://www.shijaz.com/">shijaz.com</a> <img src='http://www.microsoftnow.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I have added two new articles on Remote Desktop:
<ul>
<li><a href="http://www.shijaz.com/windows/enable_RDP_remotely.htm">How to enable Remote Desktop &#8220;remotely&#8221;</a><br />Discusses how to enable Remote Desktop on a machine that you do not have physical access to. Needs administrator privileges (of course!)</li>
<li><a href="http://www.shijaz.com/windows/enable_RDP_WS08SC.htm">How to enable Remote Desktop on Windows Server 2008 Server Core</a><br />Discusses how to enable Remote Desktop on Windows Server 2008 Server Core, the installation mode in which there is no GUI!</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2008/02/articles-on-enabling-remote-desktop.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&quot;Setup failed to install ADAM in replica mode&quot;</title>
		<link>http://www.microsoftnow.com/2008/02/setup-failed-to-install-adam-in-replica.html</link>
		<comments>http://www.microsoftnow.com/2008/02/setup-failed-to-install-adam-in-replica.html#comments</comments>
		<pubDate>Tue, 05 Feb 2008 05:14:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ADAM]]></category>
		<category><![CDATA[css]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[ISA server]]></category>
		<category><![CDATA[tips]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2008/02/setup-failed-to-install-adam-in-replica-mode.html</guid>
		<description><![CDATA[If you have already have ISA Server 2006 Enterprise Edition installed and you are trying to installing ISA Server on another server and configuring it as a replica of the Configuration store, you may get the following error on Windows Server 2003 R2: &#8220;Setup failed to install ADAM in replica mode.&#8221; Setup then exits and [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2008%252F02%252Fsetup-failed-to-install-adam-in-replica.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22%26quot%3BSetup%20failed%20to%20install%20ADAM%20in%20replica%20mode%26quot%3B%22%20%7D);"></div>
<p>If you have already have ISA Server 2006 Enterprise Edition installed and you are trying to installing ISA Server on another server and configuring it as a replica of the Configuration store, you may get the following error on Windows Server 2003 R2:</p>
<p>
<div align="center"><strong>&#8220;Setup failed to install ADAM in replica mode.&#8221;</strong></div>
<p>Setup then exits and you are unable to complete the installation. This usually happens if there was a previous failed installation from the machine that you&#8217;re trying to join to the array. You will need to cleanup the values related to the server you&#8217;re installing from the ADAM installed on your first configuration store, which stores config information for the array.</p>
<p>A simple solution to this is to ensure that both nodes are running Windows Server 2003 R2 and then edit the ADAM to remove the orphaned server on which installation is failing:
<ol>
<li>Open \Windows\ADAM\ADAM-ADSIEDIT.msc on the existing ISA Config Storage server.</li>
<li>Navigate to CN=Configuration, CN=Sites, CN=Default-First-Site-Name,CN=Servers.</li>
<li>Delete the server on which you have the installation problem.</li>
</ol>
<p>Re-run the installation, it should succeed now.</p>
<p><a href="http://3.bp.blogspot.com/_lSGuEfogrPw/R6gYHMugVqI/AAAAAAAAAdw/sM7NQ_fzKpY/s1600-h/adam_isa.jpg"><img id="BLOGGER_PHOTO_ID_5163403484734707362" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_lSGuEfogrPw/R6gYHMugVqI/AAAAAAAAAdw/sM7NQ_fzKpY/s400/adam_isa.jpg" border="0" /></a></p>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2008/02/setup-failed-to-install-adam-in-replica.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The day the Exchange cluster died</title>
		<link>http://www.microsoftnow.com/2007/09/day-exchange-cluster-died.html</link>
		<comments>http://www.microsoftnow.com/2007/09/day-exchange-cluster-died.html#comments</comments>
		<pubDate>Mon, 24 Sep 2007 05:48:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[Exchange 2003]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[memory]]></category>
		<category><![CDATA[Service Pack]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2007/09/the-day-the-exchange-cluster-died.html</guid>
		<description><![CDATA[I installed Windows Server 2003 Service Pack 2 on a client&#8217;s Exchange Server 2003 cluster on Thursday night (Yeah, I hear you &#8211; what a way to spend a weekend!). Everything went well, installation completed, rebooted and everything was happy and kicking. &#8230;until on Friday morning when the Exchange HTTP Virtual Server Instance failed. Since [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2007%252F09%252Fday-exchange-cluster-died.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22The%20day%20the%20Exchange%20cluster%20died%22%20%7D);"></div>
<p>I installed Windows Server 2003 Service Pack 2 on a client&#8217;s Exchange Server 2003 cluster on Thursday night (Yeah, I hear you &#8211; what a way to spend a weekend!). Everything went well, installation completed, rebooted and everything was happy and kicking.</p>
<p>&#8230;until on Friday morning when the Exchange HTTP Virtual Server Instance failed. Since this resource was configured to &#8216;affect the group&#8217;, the failure forced a failover of the whole Exchange cluster group to the passive node.</p>
<p>Within no time, Exchange HTTP Virtual Server Instance failed again, this time on the passive node! Someone press the Panic button!! The initial understanding of the situation was clear &#8211; Installation of Windows Server 2003 Service Pack 2 brought the mighty Exchange cluster to its knees.</p>
<p>I rebooted both nodes and normal operation ensued. But after a couple of hours it happened again. In the event logs, I could see things like:</p>
<p>
<blockquote>Event Type: <strong>Warning</strong><br />Event Source: <strong>MSExchangeIS Mailbox Store</strong><br />Event Category: <strong>General </strong><br />Event ID: <strong>1115</strong><br />Description:<br /><strong>Error 0xfffffbbe returned from closing database table, called from function JTAB_BASE::EcCloseTable on table DeletedFolders. For more information, click </strong><a href="http://www.microsoft.com/contentredirect.asp"><strong>http://www.microsoft.com/contentredirect.asp</strong></a><strong>.<br /></strong><br />Event Type: <strong>Error </strong><br />Event Source: <strong>MSExchangeCluster<br /></strong>Event Category: <strong>Services<br /></strong>Event ID: <strong>1005</strong><br />Description: <strong>Exchange HTTP Virtual Server Instance 100 (servername): The IsAlive check for this resource failed. For more information, click </strong><a href="http://www.microsoft.com/contentredirect.asp"><strong>http://www.microsoft.com/contentredirect.asp</strong></a><strong>.</strong></p>
<p>Event Type: <strong>Error</strong><br />Event Source: <strong>Srv</strong><br />Event Category: <strong>None </strong><br />Event ID: <strong>2019 </strong><br />Description: <strong>The server was unable to allocate from the system nonpaged pool because the pool was empty. For more information, see Help and Support Center at </strong><a href="http://go.microsoft.com/fwlink/events.asp"><strong>http://go.microsoft.com/fwlink/events.asp</strong></a><strong>.<br /></strong></p></blockquote>
<p>I couldn&#8217;t find much on these errors on the Internet, and this is the reason for this post. Here&#8217;s what the problem is.</p>
<p>My client is running Windows Server 2003 on a 32 bit server. 32-bit versions of Windows, as we all know, support a maximum of 4 GB RAM. By default, Windows slices the total memory right down the middle: 2 GB is reserved for the OS and 2 GB for the applications. Out of the 2 GB reserved for the OS, 256 MB is reserved for non-paged pool memory.</p>
<p>My client is using the /3GB switch, which forces Windows to limit itself to 1 GB RAM and let the applications use 3 GB. But this causes the non-paged pool memory reservation to be reduced to 128MB instead of 256MB.</p>
<p>Now, 128 MB is a tight little space. IIS uses non paged pool memory for processing requests. On Windows Server 2003 and Windows Vista, IIS stops processing requests once the available non-paged pool memory goes <a href="http://support.microsoft.com/kb/933844">below 20 MB</a>. Event 2019 is evidence for that.</p>
<p>Of course you know, Exchange relies heavily on IIS. So that explains why the Exchange HTTP Virtual Server resource went down! But wait &#8211; what&#8217;s hogging up the non-paged pool memory? And how do we fix this?</p>
<p>That&#8217;s when Microsoft sent in their Poolmon utility, that grabs information on whats in there. The culprit? &#8211; Broadcom&#8217;s NetXtreme II network card driver! It was incompatible with scalable networking features bundled with Windows Server 2003 SP2 (and the Windows Scalable Networking Pack) and caused a memory leak! I disabled the TCP Chimney with the following command:</p>
<p>Netsh int ip set chimney DISABLED</p>
<p>I also disabled the registry key <strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableTCPA</strong> registry value setting by it to zero on both nodes and other steps mentioned in <a href="http://support.microsoft.com/kb/936594">KB936594</a>. That was all it took to solve the problem!</p>
<p>See my earlier related post: <a href="http://blog.shijaz.com/2007/08/delayed-logins-change-password-feature.html">Delayed Logins: Change Password feature in ISA 2006</a></p>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2007/09/day-exchange-cluster-died.html/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Frequently Asked Questions on Windows NLB</title>
		<link>http://www.microsoftnow.com/2007/09/frequently-asked-questions-on-windows.html</link>
		<comments>http://www.microsoftnow.com/2007/09/frequently-asked-questions-on-windows.html#comments</comments>
		<pubDate>Sat, 08 Sep 2007 08:11:00 +0000</pubDate>
		<dc:creator>Shijaz Abdulla</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[load balancing]]></category>
		<category><![CDATA[NLB]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false">http://microsoftnow.com/2007/09/frequently-asked-questions-on-windows-nlb.html</guid>
		<description><![CDATA[Q. What is Network Load Balancing?NLB is a distributed algorithm used to load balance network traffic across a number of hosts. Q. What is a Cluster?A cluster is a group of independent computers that work together to run a common set of applications and provide the image of a single system to the client and [...]]]></description>
			<content:encoded><![CDATA[<div class='wb_fb_top'><div style="float:right;"></div></div>
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.microsoftnow.com%252F2007%252F09%252Ffrequently-asked-questions-on-windows.html%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Frequently%20Asked%20Questions%20on%20Windows%20NLB%22%20%7D);"></div>
<p><strong>Q. What is Network Load Balancing?</strong><br />NLB is a distributed algorithm used to load balance network traffic across a number of hosts.</p>
<p><strong>Q. What is a Cluster?<br /></strong>A cluster is a group of independent computers that work together to run a common set of applications and provide the image of a single system to the client and application.</p>
<p><strong>Q. What are the differences between NLB Clusters and Server Clusters?<br /></strong>Server Cluster is a collection of servers that together provide a single, highly available platform for hosting applications.</p>
<p>NLB Clusters dynamically distribute the flow of incoming TCP and UDP traffic among the cluster nodes according to a set of traffic-handling rules. NLB usually functions at the network level and have little to do with the actual application. There is no shared disk requirement.</p>
<p><strong>Q. Can I Use NLB and Server Clusters on the same set of servers? </strong><br />No. NLB and Server Clusters CANNOT be used on the same set of servers.</p>
<p><strong>Q. How large can my NLB cluster be? </strong><br />A single NLB cluster supports up to 32 hosts.</p>
<p><strong>Q. Are there any performance concerns as my cluster grows?<br /></strong>Yes. NLB performance begins to decrease from the linear as the cluster grows beyond 20-25 nodes.</p>
<p><strong>Q. How can I get around the 32-node limit on NLB?<br /></strong>NLB can be used to scale beyond 32 machines by using Round Robin DNS between multiple NLB Clusters.</p>
<p>For example, if virtual IP 1 (VIP1) has 32-nodes behind it, and VIP2 has another 32 nodes behind it, you can load balance between VIP1 and VIP2 using Round Robin DNS, hence having 64 nodes in NLB. The same analogy can be scaled to very large number of nodes. (Although I don&#8217;t see a reason why you would need so many nodes operating in tandem).</p>
<p><strong>Q. How Does NLB Detect a Server Failure? </strong><br />NLB Cluster host emits &#8220;heartbeats&#8221; to the other hosts in the cluster. If a host fails and stops emitting heartbeats, then after a default time period of 5 seconds, the remaining hosts in the cluster undergo a process called <strong>convergence</strong> to remove the failed host from the cluster and have new client connection requests mapped to remaining hosts in the cluster.</p>
<p><strong>Q. How long does it take for a failed Server to be removed from the cluster?<br /></strong>5 seconds are required to detect a failed host it is default time.<br />2 to 3 seconds to remove the failed host and redistribute its load to the alive hosts.</p>
<p><strong>Q. Do the heartbeat packets consume a lot of bandwidth? </strong><br />No. Heartbeat packets are emitted every second by each host and consume less than 1,500 bytes</p>
<p><strong>Q. Is NLB a kernel component?<br /></strong>Yes. NLB has a Windows kernel component called WLBS.SYS. (WLBS = Windows Load Balancing Services)</p>
<p><strong>Q. What are the benefits of NLB over simple Round Robin Domain Name Service (RRDNS)?<br /></strong>In Windows NLB, automatic recovery occurs within 5 seconds<br />The load balancing is more even in the case of Windows NLB, when compared to Round Robin DNS.</p>
<p><strong>Q. How Does NLB Cluster Convergence Work?<br /></strong>Convergence involves computing a new cluster membership list and recalculating the statistical mapping of client requests to the cluster hosts. There are two instances in which cluster traffic has to be remapped due to a change in cluster membership:<br />1. when a host Leaves the Cluster, and<br />2. when a host Joins the Cluster.</p>
<p><strong>Q. Can NLB Balance Load Based on CPU/Memory Usage?<br /></strong>No. NLB does not respond to changes in the server load such as CPU usage or MEMORY utilization or the HEALTH of an APPLICATION. NLB has nothing to do with the application itself. It merely balances evenly the network traffic among a number of nodes based on some port rules. If your NLB nodes are of different hardware configurations, you may face problems when requests are sent to the slower node, because NLB has no way of finding out which node is slow, it just evenly distributes traffic. period.</p>
<p><strong>Q. Will I get more even Load Balancing if most clients connect to the NLB Cluster through a proxy?<br /></strong>If the cluster is configured in No Affinity mode, NLB will use both the Source IP Address and the Source Port to achieve the load balancing, and so load will be distributed amongst all of the hosts.</p>
<p><strong>Q. What is the basic difference between Multicast and Unicast Modes of operation?<br /><em>Unicast:</em></strong><br />There is no inter-host communication possible between the hosts configured in Unicast mode with 1 NIC.<br /><strong><em>Multicast:</em></strong><br />Allows inter-host communication between the hosts configured in Multicast mode with 1 NIC.</p>
<p><strong>Q. How do I Reduce Switch Flooding Caused by Network Load Balancing?<br /></strong>Hosts can be homed to their own LAN or Virtual LAN. It will work for both Unicast or Multicast modes.</p>
<p><strong>Q. Does NLB require two Network Cards per host?<br /></strong>No.</p>
<p><strong>Q. How do I configure layer 2 switches to work with Windows NLB? </strong><br />Make sure that the switch does not associate the cluster MAC address with a particular switch port!</p>
<p><strong>Q. How Do I Configure Layer 3 Switches to work with Windows NLB?<br /></strong>Layer 3 switches need to be specially configured to work with NLB. A VLAN must be established for the hosts in the cluster, and this VLAN must be configured to operate in Layer 2 mode.</p>
<p><strong>Q. How Do I Remove the Switch as a Single Point-of-Failure?<br /></strong>Create a subnet that spans two switches and connect half of the NLB cluster nodes to each switch. In this case, if one switch fails, you only lose half of your nodes from participating in the NLB. Alternatively, you can have other failover arrangements on your core switch.</p>
<p><strong>Q. I Have two Network Adapters on each server in my NLB Cluster. How do I ensure that all outbound traffic goes through non-load-balanced network adapters? </strong><br />Simply set the metric on the cluster NIC to a higher value than the non-cluster NIC.</p>
<p><strong>Q. Can I Have Part of the Cluster Operate in Multicast Mode and the Other in Unicast Mode?<br /></strong>No. The entire cluster MUST be in one operational mode.</p>
<p><strong>Q. Does NLB Support Multiple Virtual IP Addresses?<br /></strong>Yes. NLB supports multiple, virtual IP addresses.</p>
<p><strong>Q. Is it possible to specify different port rules for different virtual IP addresses </strong><strong>(VIPs) on the same set of hosts? </strong><br />Windows Server 2003 supports specifying different port rules for different virtual IPs. However, this is not supported on Windows 2000 NLB.</p>
<p><strong>Q. Is it possible to mix Windows NT 4.0 WLBS, Windows 2000 WLBS and Windows Server 2003 in the same cluster? </strong><br />Yes. Mixing is supported.</p>
<p><strong>Q. Is it possible to Bind NLB to multiple interfaces?<br /></strong>Yes. This is supported in Windows Server 2003 only.</p>
<p><strong>Q. Can I have two NLB clusters on the same subnet?<br /></strong>Yes. In a switched environment.</p>
<p><strong>Q. We Need to span a cluster, where nodes are distributed across buildings. Can we use NLB to load-balance them?<br /></strong>Yes. As long as the hosts are part of the same subnet.</p>
<p><strong>Q. How can I keep a record of NLB Manager activities?<br /></strong>Configure Network Load Balancing Manager to log each event.</p>
<p><strong>Q. Can I manage an NLB Cluster remotely using WLBS.EXE?<br /></strong>Yes, but this is generally not recommended.</p>
<p><strong>Q. How do I deal with Denial of Service (DOS) attacks on my NLB Cluster?<br /></strong>NLB utilizes the TCP/IP Denial of Service attack protection.</p>
<p><strong>Q. How Do I secure my NLB Cluster? </strong><br />NLB assumes that the<br />
 LAN to which it is homed is trusted. There are no security features to configure on the NLB itself. Administrators should secure the network itself using firewalls, intrusion prevention systems, etc.</p>
<p><strong>Q. How do I configure my cluster to handle load non-uniformly? </strong><br />To configure a host to handle more or less than an equal share of the load, edit the port rule to clear the “Equal” load weight check box and enter a load weight number between 1 and 100.</p>
<p><strong>Q. How Does Single Affinity Mode Differ From No Affinity Mode? Which One Should I Use to Load Balance My Application?</strong><br /><strong><em>Single Affinity mode:</em></strong><br />NLB load balances traffic based <u>only</u> on the <u>Source IP Address</u> of the incoming connection. Single Affinity mode ensures that all TCP connections originating from the same client (IP Address) are sent to the same host in the cluster.</p>
<p><strong><em>No Affinity mode:</em></strong><br />NLB load balances traffic is based on <u>Source IP Address</u> and <u>Source Port</u> of the incoming connection request. In No Affinity mode, multiple connections from the same client may be handled by different hosts in the cluster as long as these connections have different source ports.</p>
<p><strong>Q. If my clients use SSL to connect to my web servers, can I still use NLB to load balance these web servers?<br /></strong>Yes, for efficiency reasons configure the port rule in Single Affinity mode.</p>
<p><strong>Q. I have multiple web servers on my NLB. How do I make sure that the website content is exactly the same on all nodes so that all users get the same version of the page?</strong><br />NLB has nothing to do with your application/web site. It merely distributes requests evenly between the nodes. The synchronization/replication of content/data evenly between the two nodes has to be done manually or by using another solution.</p>
<p><strong>Q. Can I use NLB to load balance my database server?<br /></strong>No, for database servers like Microsoft SQL Server, use Server Clusters/Microsoft Cluster Service instead. You can, however, use NLB on your front end application web servers and have them connect to the Server Cluster on your database servers. See image below.</p>
<p><a href="http://3.bp.blogspot.com/_lSGuEfogrPw/RuJljvdkP8I/AAAAAAAAASA/_WAGnKJT1oE/s1600-h/NLBvsMSCSCluster.gif"><img id="BLOGGER_PHOTO_ID_5107756592101867458" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_lSGuEfogrPw/RuJljvdkP8I/AAAAAAAAASA/_WAGnKJT1oE/s400/NLBvsMSCSCluster.gif" border="0" /></a><br /><strong>Q. Can NLB be used for Load Balancing Terminal Server Clusters?<br /></strong>Yes.</p>
<p><strong>Q. While Load Balancing Terminal Server Clusters, how can I ensure that a disconnected user always re-connects to the same terminal server node? </strong><br />WLBS/NLB relies on the client&#8217;s IP address to determine which Terminal Server services a client. If you configure WLBS/NLB to use Affinity, the IP address used by the client is serviced by the same Terminal Server as long as you do not change the Terminal Server cluster.</p>
<p>If you need disconnected clients to connect to the same Terminal Server to recover from a &#8216;disconnected&#8217; session, the client computers need to use static IP addresses and WLBS/NLB must be configured to use Single Affinity. Note that IP addresses obtained from DHCP servers on the LAN or through your ISP may change, as well as roaming users&#8217; IP addresses. See <a href="http://support.microsoft.com/kb/243523">KB243523</a>.</p>
<p><strong>Q. Does NLB Support WINS Resolution?<br /></strong>No. WINS names should not be automatically registered for the IP addresses configured on the NLB interface. The IP can be mapped statically in WINS.</p>
<p><strong>Q. Can I Use L2TP/IPSec on a NLB Cluster? </strong><br />Yes, in Windows Server 2003 NLB supports both PPTP and L2TP VPN sessions.</p>
<p><strong>Q. Can I Use Kerberos with Applications Load-Balanced by NLB?<br /></strong>Yes.</p>
<p><strong>Q. Can I Use NLB with Host Header Names?<br /></strong>Yes.</p>
<p><strong>Q. Can I Load-Balance NetBIOS Traffic? </strong><br />Yes, it is possible, though not recommended for File and Print Services.</p>
<p>See also: <em><a href="http://www.shijaz.com/windows/web_nlb.htm">How to use Windows NLB to load balance web servers</a></em></p>

]]></content:encoded>
			<wfw:commentRss>http://www.microsoftnow.com/2007/09/frequently-asked-questions-on-windows.html/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
	</channel>
</rss>

