• Main
  • Blog
  • Who We Are
    • Jeremy Anderson
    • Amy Babinchak
    • Philip Elder
    • Cliff Galiher
    • Chris Matthews
    • Eriq Neale
    • Edwin Sarmiento
    • David Shackelford
  • HelpDesk
  • FAQ
  • Datto
  • SMBKitchen Project
    • SMBKitchen Crew

Archive for EBS 2008

Jul
23

EBS Migration SKUs

by steve

Are you a Volume License customer, looking to migrate out of EBS per Microsoft's offer? Here are the part numbers you'll need to order the new media. Microsoft says to order from your original reseller. If you have EBS Premium, your SQL media will already work, so they have not included that SKU.

Windows Server Standard 2008  P73-03830

Windows Server Standard 2008R  P73-04819

Exchange Standard 2007   312-03748

System Center Essentials 2007  UCH-01603 System Center Essentials 2010  UCH-02057

Categories : Uncategorized
Jun
30

How do you move out of EBS now that it is retired?

by steve

Details on how to move out of Essential Business Server are now live at http://www.microsoft.com/ebs/en/us/default.aspx. Well, really it is here at http://www.microsoft.com/ebs/en/us/offers.aspx. You have until December 31, 2010 to do the change over if you are going to.

Categories : Uncategorized
Mar
29

How to create (or recreate) an Edge Subscription in Exchange 2007

by steve

The following directions are for EBS 2008, but will work for any 2-server Exchange 2007 deployment:

Security (Edge) Server
1. From Exchange Management Shell, enter the following command:
a. New-EdgeSubscription -FileName "c:\windows\temp\EdgeSubscriptionInfo.xml"
2. Copy “c:\windows\temp\EdgeSubscriptoinInfo.xml” to the Messaging server


Messaging Server
1. Open the Exchange Management Console.
a. Expand Organization Configuration
b. Select Hub Transport
c. In the result pane, click the Edge Subscriptions tab.
2. In the action pane, click New Edge Subscription. The New Edge Subscription Wizard starts.
3. On the New Edge Subscription page, in the Active Directory Site: drop-down list, select an Active Directory site.
4. On the New Edge Subscription page, click Browse. Locate the Edge Subscription file to import. Select the file, and then click Open.
5. On the New Edge Subscription page, click New.
6. On the Completion page, click Finish.
7. Open elevated Exchange Management Shell instance and run the command:
a. start-edgesynchronization (or restart the Microsoft EdgeSync service in the Services console.)

Categories : Uncategorized
Mar
5

Elvis has left the building (EBS retired)

by steve

Microsoft today announced the discontinuation of Windows Essential Business Server. Catch the full story at the EBS Official Blog. Thank you to all who have made EBS a great adventure over the past four years.

Steve

Categories : Uncategorized
Dec
17

BPOS Sync Tool does not migrate passwords

by steve

Had this question come up today, so thought I'd drop a quick post on it. The Directory Synchronization tool used with Microsoft's Online Services does a one-way sync from your Active Directory up to the BPOS servers, and does not migrate passwords. You have to do those manually, and if you change a password in your local AD, it must be updated manually on the BPOS side.

See the Microsoft Online Services "About Directory Synchronization" page for the official wording on it.

Categories : SBS 2003, SBS 2008, Steve
Dec
9

"Failed to create Edge Subscription" error in your SBS to EBS migration?

by steve

Great blog post by Steve Knutson on his "Failed to create Edge Subscription" error in his Essential Business Server 2008 migration from Small Business Server 2003. We've seen this error in EBS installed into virtualized environments, but the timing issue with SBS and EBS was a new twist on the same error. Thanks for the screen shot and the log content too!

Categories : Steve
Nov
6

Mark's Rules for Successful Replacement Mode – MR4SRM. RM = replacment mode

by steve

Second in the Mark Stanfill EBS 2008 tweet series (check out his TMG series here), we have Mark's latest on Rules for Successful Replacement Mode. As before, I'll be updating this post with new tweets as Mark sends them out. Be sure to check back for updates.

#EBS08 New Series - Mark's Rules for Successful Replacement Mode - MR4SRM. RM = replacment mode.

#EBS08 MR4SRM Rule #1 - Make a complete server backup first. No exceptions.

#EBS08 MR4SRM Export config to XML using http://bit.ly/2jlxkE. Pay special attention to all IP addresses . Make sure they're corrrect.

#EBS08 MR4SRM You need 2 functional EBS servers for Replacement Mode. If not, restore one server from backup.

#EBS08 MR4SRM Always back up CALs on Mgmt server before RM.

#EBS08 MR4SRM Mgmt server needs CALs reinstalled or restore post RM.

#EBS08 MR4SRM Mgmt Server RM will pull down all WSUS data again - many GB. Export & import - http://bit.ly/4DUxtN. Backup data drive

#EBS08 MR4SRM All servers are going to need patching. Expect many reboots, considerable time.

#EBS08 MR4SRM Security & Msg can pull updates from WSUS rather than MU. Deselect optional updates during RM. Critical updates come from MU

#EBS08 MR4SRM Make sure AD is healthy before RM. Always run IT Health Scanner first - http://bit.ly/Od1uH

#EBS08 MR4SRM Never, ever delete computer accounts or run metadata cleanup before RM. http://bit.ly/Cwsrr

#EBS08 MR4SRM All DCs need to be online and contactable before RM.

#EBS08 MR4SRM Make sure IIS is healthy, started, listening on port 808 for /remoting directory on all servers before RM.

#EBS08 MR4SRM Run "dnscmd /config /enableglobalqueryblocklist 0" for wpad autodiscovery - http://bit.ly/3NceQm

#EBS08 MR4SRM Management Server restore - repair all SCE clients underAdministration node.

#EBS08 MR4SRM RM on Messaging obviously does not restore mailboxes & PFs. Make backups first - online, offline, PSTs. Belt and suspenders.

#EBS08 MR4SRM To get Security Server to report back to SCE after RM - "net stop fweng /y", repair SCE client, restart services

#EBS08 MR4SRM Remove UM (if present) from Exchange before RM of Messaging Server to avoid setup failure.

Categories : Steve
Oct
8

Mark's rules for TMG Firewall client (MRFTFC)

by steve

Mark Stanfill has started a great series, via his Twitter account, covering EBS rules for TMG. So good that I thought it a great idea to include them here. I'll add to this post as he adds additional rules. Following are the first sets, plus a bonus precursor:

#EBS08 New series: Mark's rules for TMG Firewall client (MRFTFC)

#EBS08 Never use 'route add' on TMG. Use the TMG getting started wizard instead. Look for startup scripts that do route adds,exclude admin

#EBS08 MRFTFC #1 - You probably don't need th FWC. 99% of apps can get by with SNAT and web proxy

#EBS08 MRFTFC #2 - Install from Management Server (not Security): C:\Program Files\Windows Essential Business Server\bin\ISA\client

#EBS08 MRFTFC #3 You only need the FWC if you have an APP that needs it or if you want to track access by user rather than by IP.

#EBS08 MRFTFC #4 Down-level FWC from ISA 2004/6 still works, but you should update it if you use it.

New #EBS08 TMG rule 1 - never, ever use "route add" - you will corrupt the IP stack

New #EBS08 TMG rule 2 - add routes via the getting started wizard only - TMG Console -> Forefront TMG -> Tasks

New #EBS08 TMG rule 3 - Only use TMG Console to configure VPN, never RRAS Mgmt console

New #EBS08 TMG rule 4 - Never, ever,ever, ever disable IPv6 on Security Server - you will never fix anything, but you will break RRAS

New #EBS08 TMG rule 5 - Networks under TMG Console\Networking\Networks must have an interface on TMG server itself or we'll drop traffic

New #EBS08 TMG rule 6 - deploy firewall client via gpo from MGMT server: c:\progra~1\window~3\bin\isa\client --- Exclude Servers from GPO

-Additional markstan comment: It depends on the app and the environment. Use FWC if you need user auditing, don't want to use default gateway, or know that you will have a lot of custom protocols. Undefined protocols = block for SNAT, access for FWC.
New #EBS08 TMG rule 7 - for WMI to work you must disable Enforce Strict RPC Compliance on all applicable access policies and system policies
#EBS08 TMG-if you are publishing TS 2 another server, TS 2 TMG will fail. Set the winstations regkey to 3390 on TMG,reboot cr8 access policy. Set the winstations regkey to 3390 on TMG,reboot create access policy for internal to localhost
 
#EBS08 TMG - Want to query RBLs 4 SMTP? Create an access rule for DNS (not dns server) from localhost to external. Not there by default.
#EBS08 TMG rule - TMG requires IPv6. Never disable via registry or uncheck from ncpa.cpl. This will lead to routing issues and application crashes. I've seen random blue screens, but never been able to repro.
#EBS08 TMG tip - you can copy rules via ctrl-c/ctrl-v, modify settings (like port #) to save time.
#EBS08 TMG tip - getting started wizard (for adding static routes) must be ran on Security Server itself (can't do from mgmt)
#EBS08 TMG TIP - slow web page load/dns name resolution - use the script from http://bit.ly/4tuT6u
#EBS08 TMG TIP 3 updates that need additional work on Security Server - http://bit.ly/3kD7na http://bit.ly/1IeVCM and http://bit.ly/2NypqT
#EBS08 TMG Tip - TMG comes with a 1yr AV subscription. TMG Console\Update Center\Highlight 'Malware Inspection'\Configure License details
#EBS08 TMG TIP - renew licensing for TMG - http://bit.ly/aCRtl To renew, contact your Microsoft Partner or Small Business Specialist.
#EBS08 TMG -Networking\Networks\Internal\Web Browser-'Directly access computers specified in the addresses tab' needs to be checked
#EBS08 TMG TIP - quick TMG backup - EBSAdmin console\Security tab\highlight Network firewall\Save network firewall settings
#EBS08 TMG TIP - Native TMG backup- right-click forefront TMG (servername) in TMG Console -> Export (Back Up)... - choose the defaults.
#EBS08 TMG : Reset TMG to day1 (all ebs services published) in Admin Console\Security\Network firewall\restore default network firewall set
#EBS08 TMG - TMG has a 1 GB limit on http downloads by default
#EBS08 TMG - tmg download limts = TMG Console\Web Access Policy\Configure Malware Inspection\Inspection Settings
#EBS08 TMG - Email a daily network usage report - TMG Console\Monitoring\Reporting\Create Recurring Report Job
#EBS08 - To run IT Health Scanner w/ TMG - create allow all access rule as rule #1, disable strict rpc checking there & on system policy\AD
  - blog post: http://bit.ly/2nwQh3 - How to run the IT Environment Health Scanner in an EBS Environment
#EBS08 - Update to blog post - http://bit.ly/3oWBYO - Preparation Wizard/IT Environment Health Scanner fail with DNS WMI Provider error
Not labeled TMG by Mark, but worth having in this list:
#EBS08 browser access from security server itself - you must manually configure proxy, port 8080, set exclusion for local domain
#EBS08 - security server unable to get updates? Check the proxy exclusions list first.
#EBS08 MRFTFC - Address ranges, subnets, and computer set objects should not contain the TMG server’s IPs (rare exceptions).
#EBS08 MRFTFC - OWA HTTP 500/error 12217 = disable normalization on the OWA publishing rule
#EBS08 MRFTFC OWA "Could not connect to a directory server" error = disable link translation on OWA publishing rule. http://bit.ly/OXr0X
#EBS08 MRFTFC Slow or failed FTP behind TMG? Create the reg key in http://bit.ly/2kPttl and restart server. (many other potential causes)
#EBS08 MRFTFC Postback errors uploading to or configuring SharePoint? Add /WebResource.axd* to the SharePoint publishing rule's path.
#EBS08 MRFTFC to repair or uninstall/reinstall SCE Agent on Sec Server, "net stop fweng /y", install or repair, then "net start fwsrv"
Categories : Steve
Sep
26

Need to tame TMG in EBS 2008? Here's your ticket!

by steve

After having a few weeks of close and personal time with TMG at one of our EBS sites, I had a chance to deploy and use this at another and it is awesome. If you run into a blocking issue that you need to deal with ASAP, you can drop down the overall level of TMG with the click of a button and alleviate your pain while you work on a new rule to drop into TMG to fix the original challenge. Or drop down the firewalling in TMG altogether and allow yourself the option of using a hardware firewall.

Categories : Steve
Sep
21

SBS/EBS 2008 Remote Web Workplace not working for you?

by steve

Having trouble getting to your SBS or EBS 2008 Remote Web Workplace (RWW) from your remote computer? Check to make sure you have the certificate package installed on your client computer.

SBS Links to learn more:

http://technet.microsoft.com/en-us/library/dd353115(WS.10).aspx
http://blogs.technet.com/sbs/archive/2008/09/30/how-do-i-distribute-the-sbs-2008-self-signed-ssl-certificate-to-my-users.aspx
http://blogs.technet.com/sbs/archive/2008/10/03/receiving-certificate-errors-when-connecting-to-clients-servers-with-ts-gateway-or-remote-web-workplace-on-sbs-2008.aspx

EBS Links to learn more at:

http://technet.microsoft.com/en-us/library/cc463553(WS.10).aspx
http://technet.microsoft.com/en-us/library/cc463480(WS.10).aspx

Categories : SBS 2008, Steve

Search

Support

Third Tier provides advanced support services to IT Professionals. Learn about what we do at http://www.thirdtier.net or click on the support icon below to chat with one of our support representatives.

Live Chat Software by Kayako
Third Tier
Copyright © 2013 All Rights Reserved
iThemes Builder by iThemes
Powered by WordPress