<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Geek in Disguise</title>
	<atom:link href="http://thegid.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://thegid.wordpress.com</link>
	<description></description>
	<lastBuildDate>Fri, 31 May 2013 11:28:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='thegid.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/a63294f888218f27f54bf0f8f809ddd8?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>The Geek in Disguise</title>
		<link>http://thegid.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://thegid.wordpress.com/osd.xml" title="The Geek in Disguise" />
	<atom:link rel='hub' href='http://thegid.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Installing the Lync 2010 Monitoring Role</title>
		<link>http://thegid.wordpress.com/2013/05/31/installing-the-lync-2010-monitoring-role/</link>
		<comments>http://thegid.wordpress.com/2013/05/31/installing-the-lync-2010-monitoring-role/#comments</comments>
		<pubDate>Fri, 31 May 2013 11:24:43 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Lync]]></category>
		<category><![CDATA[Lync 2010]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=71</guid>
		<description><![CDATA[Quick and dirty post.. sorry. When installing the Lync monitoring role, if you receive an error like the following: Running script: C:\Windows\system32\cscript.exe //Nologo "C:\Program Files\Common Files\Microsoft Lync Server 2010\DbSetup\RtcCdrDbSetup.wsf" /dbexists /sqlserver:thegid-lync.thegid.local\MONITORING /serveracct:thegid\RTCComponentUniversalServices /logsize:1024 /verbose --------------- Installed SQL Server 2005 Backward Compatibility version is 8.05.2312 Connecting to SQL Server on thegid-lync.thegid.local\MONITORING Error connecting ( name: Error [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=71&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Quick and dirty post.. sorry.</p>
<p>When installing the <strong>Lync monitoring role</strong>, if you receive an error like the following:</p>
<pre style="padding-left:30px;">Running script: C:\Windows\system32\cscript.exe //Nologo "C:\Program Files\Common Files\Microsoft Lync Server 2010\DbSetup\RtcCdrDbSetup.wsf" /dbexists /sqlserver:thegid-lync.thegid.local\MONITORING /serveracct:thegid\RTCComponentUniversalServices /logsize:1024 /verbose
 ---------------
 Installed SQL Server 2005 Backward Compatibility version is 8.05.2312
 Connecting to SQL Server on thegid-lync.thegid.local\MONITORING
 Error connecting (
 name: Error
 description:
 number: -2147221504
 message:
 )
 Attempting to start SQL Server and connect...
 Error starting SQL Server on thegid-lync.thegid.local\MONITORING
 Error (
 name: Error
 description:
 number: -2147023840
 message:
 )
 Ensure that thegid-lync.thegid.local\MONITORING is a valid SQL instance.
 ---------------
 Exit code: ERROR_START_SQLSERVICE (-1)
 When running /dbexists, non-zero exit codes are not necessarily errors
 ---------------</pre>
<pre style="padding-left:30px;">Running script: C:\Windows\system32\cscript.exe //Nologo "C:\Program Files\Common Files\Microsoft Lync Server 2010\DbSetup\RtcCdrDbSetup.wsf" /sqlserver:thegid-lync.thegid.local\MONITORING /serveracct:thegid\RTCComponentUniversalServices;"RTC Component Local Group" /dbpath:C:\CsData\MonitoringStore\MONITORING\dbpath /logpath:C:\CsData\MonitoringStore\MONITORING\logpath /logsize:1024 /verbose
 ---------------
 Installed SQL Server 2005 Backward Compatibility version is 8.05.2312
 Connecting to SQL Server on thegid-lync.thegid.local\MONITORING
 Error connecting (
 name: Error
 description:
 number: -2147221504
 message:
 )
 Attempting to start SQL Server and connect...
 Error starting SQL Server on thegid-lync.thegid.local\MONITORING
 Error (
 name: Error
 description:
 number: -2147023840
 message:
 )
 Ensure that thegid-lync.thegid.local\MONITORING is a valid SQL instance.
 ---------------
 Exit code: ERROR_START_SQLSERVICE (-1)
 ---------------</pre>
<p>Open <strong>SQL Server Configuration Manager &gt; SQL Server Network Configuration &gt; Protocols for &lt;SQL instance&gt;</strong> and ensure that <strong>TCP/IP is enabled</strong>. Restart the SQL instance after enabling it.</p>
<p>Also if you have issues running the &#8220;<strong>Deploy Monitoring Server Reports</strong>&#8221; open <strong>Reporting Services Configuration Manager &gt; Web Service URL</strong> and ensure that you are able to browse to the <strong>Report Server Web Service URL</strong>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/71/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=71&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2013/05/31/installing-the-lync-2010-monitoring-role/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>
	</item>
		<item>
		<title>Cannot insert duplicate key row in object &#8216;dboAgents&#8217; with unique index &#8216;IX_Agents_UserSid&#8217;</title>
		<link>http://thegid.wordpress.com/2013/03/22/cannot-insert-duplicate-key-row-in-object-dboagents-with-unique-index-ix_agents_usersid/</link>
		<comments>http://thegid.wordpress.com/2013/03/22/cannot-insert-duplicate-key-row-in-object-dboagents-with-unique-index-ix_agents_usersid/#comments</comments>
		<pubDate>Fri, 22 Mar 2013 14:49:58 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Cannot insert duplicate key row in object ‘dboAgents’ with unique index ‘IX_Agents_UserSid’]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=75</guid>
		<description><![CDATA[Lync server 2010 admin? Read on&#8230; If you need to move a user from one Response Group to another you may well encounter the following error message&#8230;. &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; Don&#8217;t worry, just check the event viewer on the Lync server for the following event: &#160; &#160; &#160; &#160; &#160; &#160; &#160; [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=75&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://thegid.files.wordpress.com/2012/02/capture.jpg"><img class="size-medium wp-image-66 alignright" alt="Capture" src="http://thegid.files.wordpress.com/2012/02/capture.jpg?w=300&#038;h=134" width="300" height="134" /></a></p>
<p>Lync server 2010 admin? Read on&#8230;</p>
<p>If you need to move a user from one <strong>Response Group</strong> to another you may well encounter the following error message&#8230;.</p>
<p><a href="http://thegid.files.wordpress.com/2013/03/lync-2010-response-group2.jpg"><img class="size-full wp-image-79 alignleft" alt="lync 2010 response group" src="http://thegid.files.wordpress.com/2013/03/lync-2010-response-group2.jpg?w=786&#038;h=238" width="786" height="238" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Don&#8217;t worry, just check the event viewer on the Lync server for the following event:</p>
<p><a href="http://thegid.files.wordpress.com/2013/03/lync-server-event.jpg"><img class="size-large wp-image-77 alignleft" alt="lync server event" src="http://thegid.files.wordpress.com/2013/03/lync-server-event.jpg?w=1024&#038;h=368" width="1024" height="368" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Once you see that event you can add the user to the other response group.</p>
<p>That&#8217;s it.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/75/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=75&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2013/03/22/cannot-insert-duplicate-key-row-in-object-dboagents-with-unique-index-ix_agents_usersid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2012/02/capture.jpg?w=300" medium="image">
			<media:title type="html">Capture</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2013/03/lync-2010-response-group2.jpg" medium="image">
			<media:title type="html">lync 2010 response group</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2013/03/lync-server-event.jpg?w=1024" medium="image">
			<media:title type="html">lync server event</media:title>
		</media:content>
	</item>
		<item>
		<title>Office 365 directory synchronisation failing for a couple of users (permission-issue)</title>
		<link>http://thegid.wordpress.com/2013/03/20/office-365-directory-synchronisation-failing-for-a-couple-of-users-permission-issue/</link>
		<comments>http://thegid.wordpress.com/2013/03/20/office-365-directory-synchronisation-failing-for-a-couple-of-users-permission-issue/#comments</comments>
		<pubDate>Wed, 20 Mar 2013 15:24:47 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Server Installations]]></category>
		<category><![CDATA[directory synchronization]]></category>
		<category><![CDATA[Office 365]]></category>
		<category><![CDATA[permission-issue]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=72</guid>
		<description><![CDATA[When I deployed directory synchronisation for our Office 365 (Exchange online) migration I noticed that a couple of users did not sync.  The synchronisation service manager shows the users failing synchronisation. Here&#8217;s what it looks like. It&#8217;s the same for both users. There&#8217;s 1 warning and 2 errors in the event viewer which I&#8217;ve pasted [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=72&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>When I deployed directory synchronisation for our Office 365 (Exchange online) migration I noticed that a couple of users did not sync. <b><br />
</b></p>
<p>The synchronisation service manager shows the users failing synchronisation. Here&#8217;s what it looks like. It&#8217;s the same for both users.</p>
<p><a href="http://community.office365.com/cfs-file.ashx/__key/communityserver-components-userfiles/00-00-19-06-29-Attached+Files/3386.dirsync.jpg"><img alt=" " src="http://community.office365.com/resized-image.ashx/__size/550x0/__key/communityserver-components-userfiles/00-00-19-06-29-Attached+Files/3386.dirsync.jpg" /></a></p>
<p>There&#8217;s 1 warning and 2 errors in the event viewer which I&#8217;ve pasted below.</p>
<p>Can anyone shed some light on this please?</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p><em>Log Name:      Application<br />
Source:        FIMSynchronizationService<br />
Event ID:      6100<br />
Task Category: Management Agent Run Profile<br />
Level:         Warning<br />
Keywords:      Classic<br />
User:          N/A<br />
Description:<br />
The management agent &#8220;SourceAD&#8221; step execution completed on run profile &#8220;Export&#8221; with errors.</p>
<p>Additional Information<br />
Discovery Errors       : &#8220;0&#8243;<br />
Synchronization Errors : &#8220;0&#8243;<br />
Metaverse Retry Errors : &#8220;0&#8243;<br />
Export Errors          : &#8220;2&#8243;<br />
Warnings               : &#8220;0&#8243;<br />
User Action<br />
View the management agent run history for details.<br />
</em></p>
<p><em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</em></p>
<p><em>Log Name:      Application<br />
Source:        Directory Synchronization<br />
Event ID:      0<br />
Task Category: None<br />
Level:         Error<br />
Keywords:      Classic<br />
User:          N/A<br />
Description:<br />
The Management Agent &#8216;System.Management.PropertyData&#8217; reported  errors on execution.</em></p>
<p><em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</em></p>
<p><em>Log Name:      Application<br />
Source:        Directory Synchronization<br />
Event ID:      0<br />
Task Category: None<br />
Level:         Error<br />
Keywords:      Classic<br />
User:          N/A<br />
Description:<br />
Executing export run profile on source MA failed for System.Management.PropertyData. Failed to export objects:<br />
dn=&#8221;CN=&lt;User1&gt;,OU=&lt;OU&gt;,DC=&lt;domain&gt;,DC=local&#8221;,error-type=permission-issue,error-code=8344,<br />
dn=&#8221;CN=&lt;User2&gt;,OU=&lt;OU&gt;,DC=&lt;domain&gt;,DC=local&#8221;,error-type=permission-issue,error-code=8344,</em><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p><strong>Here&#8217;s the fix in my case:</strong></p>
<p>Open Active directory Users and Computers, enable the Advanced features in the View settings and open up the user object that can&#8217;t sync. Go to the security tab and then into advanced, check to make sure the box is checked to inherit permissions.</p>
<p>Before you do that you might want to check what permissions are currently assigned and what they will be assigned after inherit permissions is enabled. After all there might be permissions that you do not wish the particular user to have.</p>
<p>That&#8217;s all for now.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/72/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=72&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2013/03/20/office-365-directory-synchronisation-failing-for-a-couple-of-users-permission-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>

		<media:content url="http://community.office365.com/resized-image.ashx/__size/550x0/__key/communityserver-components-userfiles/00-00-19-06-29-Attached+Files/3386.dirsync.jpg" medium="image">
			<media:title type="html"> </media:title>
		</media:content>
	</item>
		<item>
		<title>Exchange 2010 Outlook Web App and Lync Server 2010 Integration</title>
		<link>http://thegid.wordpress.com/2012/02/24/exchange-2010-outlook-web-app-and-lync-server-2010-integration/</link>
		<comments>http://thegid.wordpress.com/2012/02/24/exchange-2010-outlook-web-app-and-lync-server-2010-integration/#comments</comments>
		<pubDate>Fri, 24 Feb 2012 16:30:04 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Lync]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=69</guid>
		<description><![CDATA[ Quick and dirty guide to get Lync working in Exchange 2010 Web App 1. Download and install the following components On Exchange 2010 CAS Unified Communications Managed API 2.0, Core Runtime (64-bit) Note: If any other Unified Communications Managed API are installed uninstall before installing Microsoft Office Communications Server 2007 R2 Web Service Provider Note: [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=69&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h1> Quick and dirty guide to get Lync working in Exchange 2010 Web App</h1>
<h2>1. Download and install the following components</h2>
<h3 style="padding-left:30px;">On Exchange 2010 CAS</h3>
<ul>
<li><a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;id=4705" target="_blank">Unified Communications Managed API 2.0, Core Runtime (64-bit)</a></li>
</ul>
<p style="padding-left:30px;">Note: If any other Unified Communications Managed API are installed uninstall before installing</p>
<ul>
<li><a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;id=2310" target="_blank">Microsoft Office Communications Server 2007 R2 Web Service Provider</a></li>
</ul>
<p style="padding-left:30px;">Note: The installer has a limited GUI which does not confirm that the software was installed</p>
<ul>
<li><a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;id=797" target="_blank">OCS 2007 R2 Web Service Provider Hotfix KB 981256</a></li>
</ul>
<p style="padding-left:30px;">Note: The installer has a limited GUI which does not confirm that the software was installed</p>
<h2>2. Check (and note) Exchange Certificate Thummbprint</h2>
<h3 style="padding-left:30px;">On Exchange 2010 CAS</h3>
<ul>
<li>Run the following command in the Exchange Management Shell and note the thumbprint and subject on the certificate you are using</li>
</ul>
<p style="padding-left:30px;"><em># get-ExchangeCertificate | fl</em></p>
<h2>3. Set Lync server used by Exchange for IM</h2>
<h3 style="padding-left:30px;">On Exchange 2010 CAS</h3>
<ul>
<li>Run the following command in the Exchange Management Shell</li>
</ul>
<p style="padding-left:30px;"># Get-OwaVirtualDirectory | Set-OwaVirtualDirectory -InstantMessagingServerName &lt;Lync server (or pool) FQDN&gt; -InstantMessagingCertificateThumbprint &lt;thumbprint from previous step&gt; -InstantMessagingEnabled $true -InstantMessagingType 1</p>
<ul>
<li>Open an eleveated command prompt and run &#8220;iisreset /noforce&#8221; to apply the changes to OWA</li>
</ul>
<h2>4. Finally tell Lync about OWA</h2>
<h3 style="padding-left:30px;">On Lync 2010 Server</h3>
<ul>
<li>Run the following command in Lync Server Management Shell:</li>
</ul>
<p style="padding-left:30px;"><em># Get-CsSite (make a note of the siteID)</em></p>
<p style="padding-left:30px;"># New-CsTrustedApplicationPool -Identity &lt;SN of Exchange certificate from step 2&gt; -Registrar &lt;Lync server (or pool) FQDN&gt; -Site &lt;siteId from previous step&gt; -RequiresReplication $false</p>
<p style="padding-left:30px;"># New-CsTrustedApplication -ApplicationId OutlookWebApp -TrustedApplicationPoolFqdn &lt;SN of Exchange certificate from step 2&gt;  -Port 9999</p>
<p style="padding-left:30px;"># Enable-CsTopology</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/69/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=69&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2012/02/24/exchange-2010-outlook-web-app-and-lync-server-2010-integration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>
	</item>
		<item>
		<title>Lync Mobile Notifications</title>
		<link>http://thegid.wordpress.com/2012/02/24/lync-mobile-notifications/</link>
		<comments>http://thegid.wordpress.com/2012/02/24/lync-mobile-notifications/#comments</comments>
		<pubDate>Fri, 24 Feb 2012 15:46:09 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Lync]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=65</guid>
		<description><![CDATA[Just a quick post this time on Lync Mobile client notifications. Lync mobile app notifications on iOS and Windows Phone 7 devices will only work if you have dynamic federation. The reason for this is because the app needs to be running to be able to receive notification and iOS and Win Phone 7 do not allow [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=65&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><img src="http://lync.microsoft.com/en-us/FeatureMatrixPictures/MOBILE-win-ON.png" alt="" /><img src="http://lync.microsoft.com/en-us/FeatureMatrixPictures/MOBILE-ipad-ON.png" alt="" /><img src="http://lync.microsoft.com/en-us/FeatureMatrixPictures/MOBILE-iphone-ON.png" alt="" /><img src="http://lync.microsoft.com/en-us/FeatureMatrixPictures/MOBILE-android-ON.png" alt="" /><a href="http://thegid.files.wordpress.com/2012/02/capture.jpg"><img title="Capture" src="http://thegid.files.wordpress.com/2012/02/capture.jpg?w=300&#038;h=134" alt="" width="300" height="134" /></a></p>
<p>Just a quick post this time on Lync Mobile client notifications.</p>
<h2><strong><span style="color:#ff0000;">Lync mobile app notifications on iOS and Windows Phone 7 devices will only work if you have dynamic federation.</span></strong></h2>
<p>The reason for this is because the app needs to be running to be able to receive notification and iOS and Win Phone 7 do not allow the app to run in the background to receive notifications. For other devices it just works.</p>
<p>Here&#8217;s what synamic federation is as explained by <a href="http://ocsguy.com/about/" target="_blank">Lync Guy</a> (@ <a href="http://ocsguy.com/2011/04/20/a-few-words-on-federation/"><br />
http://ocsguy.com/2011/04/20/a-few-words-on-federation/<br />
</a>)</p>
<p><strong>Dynamic federation</strong> is a method where a partner company’s edge server is discovered by looking up an SRV record (_sipfederationtls._tcp.domain.com).  Dynamic federation is perfect for an environment where users may need to add contacts from other companies quickly and without administrative intervention.  The firewall will have to allow inbound connections to the access edge server on port 5061 from any potential partners, but for most companies who use open federation, they allow traffic from everywhere on this port to prevent needing administrative assistance.</p>
<p>So with the above in mind, if the company who hosts your external DNS does not support SRV records then you will not have dynamic federation or notification on your mobile clients who run iOS or Windows Phone 7.</p>
<p>Lync Mobile App Downloads <a href="http://lync.microsoft.com/en-us/what-is-lync/Pages/what-is-lync.aspx?Title=mobile-apps&amp;tabID=4&amp;itemID=4" target="_blank">link</a> (probably easier to just go to your respective app store on your device)</p>
<p><span style="font-size:medium;"><span style="line-height:normal;"><br />
</span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/65/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=65&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2012/02/24/lync-mobile-notifications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>

		<media:content url="http://lync.microsoft.com/en-us/FeatureMatrixPictures/MOBILE-win-ON.png" medium="image" />

		<media:content url="http://lync.microsoft.com/en-us/FeatureMatrixPictures/MOBILE-ipad-ON.png" medium="image" />

		<media:content url="http://lync.microsoft.com/en-us/FeatureMatrixPictures/MOBILE-iphone-ON.png" medium="image" />

		<media:content url="http://lync.microsoft.com/en-us/FeatureMatrixPictures/MOBILE-android-ON.png" medium="image" />

		<media:content url="http://thegid.files.wordpress.com/2012/02/capture.jpg?w=300" medium="image">
			<media:title type="html">Capture</media:title>
		</media:content>
	</item>
		<item>
		<title>Aruba &#8211; Load Balancing / ARM</title>
		<link>http://thegid.wordpress.com/2011/09/12/aruba-load-balancing-arm/</link>
		<comments>http://thegid.wordpress.com/2011/09/12/aruba-load-balancing-arm/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 16:08:34 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=51</guid>
		<description><![CDATA[Here are some helpful wireless settings that are particularly useful in deployments where there are dense amounts of clients logging in at the same time. When lots of clients are connected at the same time e.g. in a school, the AP does not immediately start to load balance them as it waits 30 seconds to [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=51&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Here are some helpful wireless settings that are particularly useful in deployments where there are dense amounts of clients logging in at the same time.<a href="http://www.arubanetworks.com/products/arubaos/adaptive-radio-management/"><img class="alignright size-full wp-image-62" title="aruba_networks" src="http://thegid.files.wordpress.com/2011/09/aruba_networks-1.png?w=130&#038;h=130" alt="" width="130" height="130" /></a></p>
<p>When lots of clients are connected at the same time e.g. in a school, the AP does not immediately start to load balance them as it waits 30 seconds to evaluate each time. The setting is Spectrum Load Balancing Update Interval. Set this at a low level such as 2 seconds and the hand off should be really fast.</p>
<h4>This setting is in RF Management &gt; Radio Profile</h4>
<div><a href="http://akagoose.files.wordpress.com/2011/09/evernote-20110616-191958.jpg"><img title="radio profile" src="http://akagoose.files.wordpress.com/2011/09/evernote-20110616-191958.jpg?w=1024&#038;h=344" alt="" width="1024" height="344" /></a></div>
<p>Secondly, a problem in some places is that by default ARM is client aware and will not change channel if a client is connected. If there&#8217;s a device that is always connected this can cause channel issues with APs interfering with each other as they were not allowed to change. I would recommend changing this setting unless you&#8217;re using VoIP over your wireless.</p>
<h4>This setting is in the ARM profile:</h4>
<p><a href="http://akagoose.files.wordpress.com/2011/09/arm1.jpg"><img title="ARM" src="http://akagoose.files.wordpress.com/2011/09/arm1.jpg?w=1024&#038;h=351" alt="" width="1024" height="351" /></a></p>
<p>Here&#8217;s a link to the <a href="http://www.arubanetworks.com/pdf/solutions/TB_ARM.pdf" target="_blank">Aruba ARM Collateral</a>. It&#8217;s good stuff.</p>
<p>&nbsp;</p>
<div></div>
<div></div>
<div></div>
<div></div>
<div></div>
<div></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/51/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=51&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2011/09/12/aruba-load-balancing-arm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2011/09/aruba_networks-1.png" medium="image">
			<media:title type="html">aruba_networks</media:title>
		</media:content>

		<media:content url="http://akagoose.files.wordpress.com/2011/09/evernote-20110616-191958.jpg?w=1024" medium="image">
			<media:title type="html">radio profile</media:title>
		</media:content>

		<media:content url="http://akagoose.files.wordpress.com/2011/09/arm1.jpg?w=1024" medium="image">
			<media:title type="html">ARM</media:title>
		</media:content>
	</item>
		<item>
		<title>Cisco WLC, Single SSID, 2 User Groups in Different VLANs</title>
		<link>http://thegid.wordpress.com/2011/05/24/cisco-wlc-single-ssid-2-user-groups-in-different-vlans/</link>
		<comments>http://thegid.wordpress.com/2011/05/24/cisco-wlc-single-ssid-2-user-groups-in-different-vlans/#comments</comments>
		<pubDate>Tue, 24 May 2011 20:20:29 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Server Installations]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=37</guid>
		<description><![CDATA[Here&#8217;s the scenario: The customer wanted to provide wireless network access to 2 different groups of users, say sales and technical. The sales and technical user groups have their network privileges restricted by use of VLANs and the customer envisioned have 2 SSIDs, one per user VLAN. Wireless authentication was going to be via a pre-shared [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=37&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><img class="alignright" title="Cisco" src="http://admintell.napco.com/ee/images/uploads/gadgetell/cisco640.png" alt="" width="384" height="190" /></p>
<h2>Here&#8217;s the scenario:</h2>
<p>The customer wanted to provide wireless network access to 2 different groups of users, say sales and technical. The sales and technical user groups have their network privileges restricted by use of VLANs and the customer envisioned have 2 SSIDs, one per user VLAN. Wireless authentication was going to be via a pre-shared key (not my idea!!!).</p>
<h2>Here&#8217;s the hardware:</h2>
<p>2 x Cisco 5508 Wireless LAN Controller (Active &amp; Backup)<br />
130 x Cisco 3500 APs<br />
5 x Cisco 3750 Switches (Core)<img class="alignright size-medium wp-image-39" title="Cisco 5508" src="http://thegid.files.wordpress.com/2011/05/cisco-5508.jpg?w=300&#038;h=56" alt="" width="300" height="56" /> 24 x Cisco 3650 Switches (Access)<br />
2 x HP DL380 G7 (Server 2008 R2)</p>
<p>I work for an <a title="Aruba Networks" href="http://www.arubanetworks.com" target="_blank">Aruba Networks</a> partner and know that there&#8217;s a more elegant solution to what the customer is asking to do when using an Aruba wireless controller but wasn&#8217;t aware of a way to do this with a Cisco Wireless LAN Controller.</p>
<p><img class="alignright size-medium wp-image-41" title="Cisco 3750" src="http://thegid.files.wordpress.com/2011/05/cisco-3750.jpg?w=300&#038;h=121" alt="" width="300" height="121" /></p>
<h2>Solution:</h2>
<p>I installed the Certificate Services role on one server and then installed Network Policy Server role on the other.<br />
Created 1 SSID on the Cisco WLC and put it in a guest VLAN which only has Internet access. Configured the SSID to use 802.1x authentication and pointed it at the NPS server and enabled <strong>Allow AAA Override</strong>. <span style="color:#ff0000;">This override setting is key!</span> It allows you to send back RADIUS attributes from NPS which will specify which VLAN users will be put into upon authentication.</p>
<p>Next NPS was configured with 3 Network Policies. One for sales users, one for technical users and one for domain computers.</p>
<p><img class="alignright size-medium wp-image-42" title="Cisco 3560" src="http://thegid.files.wordpress.com/2011/05/cisco-3560.jpg?w=300&#038;h=35" alt="" width="300" height="35" /></p>
<p><strong>Now here&#8217;s the good bit:</strong></p>
<p>By configuring the following 3 <strong>RADIUS standard attribute types</strong> in each Network Policy, NPS tells the Cisco WLC that users authenticated should be placed in a VLAN specified in the &#8220;Tunnel-Pvt-Group-ID&#8221; RADIUS attributes.</p>
<p><img class="alignright size-medium wp-image-40" title="HP" src="http://thegid.files.wordpress.com/2011/05/hp.jpg?w=300&#038;h=180" alt="" width="300" height="180" /></p>
<p>Here are the 3 attributes:</p>
<p>[64] <strong>Tunnel-Type</strong> (Set this to VLAN)<br />
[65] <strong>Tunnel-Medium-Type</strong> (set this to 802)<br />
[81] <strong>Tunnel-Pvt-Group-ID</strong> (Set this to the VLAN ID you wish to put the user in)</p>
<p>Next a wireless group policy was configured with the SSID, Encryption, Authentication and single sign on settings and applied to domain computers.</p>
<p>Note: The domain computers NPS Network Policy is essential so that machines can login before the user attempts to authenticate and therefore computer group policy applies and users can authenticate against the domain.</p>
<p><img class="alignright size-medium wp-image-38" title="HP DL380 G7" src="http://thegid.files.wordpress.com/2011/05/hp-dl380-g7.jpg?w=300&#038;h=55" alt="" width="300" height="55" /></p>
<h2>Sources:</h2>
<p><a href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008076317c.shtml" target="_blank">Dynamic VLAN Assignment with RADIUS Server and Wireless LAN Controller Configuration Example<br />
</a><a href="http://technet.microsoft.com/en-us/library/dd197472(WS.10).aspx" target="_blank">NPS RADIUS Attributes</p>
<p></a>Note: This post is mostly for my benefit so I don&#8217;t forget! The links above go into more detail on the topic.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/37/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=37&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2011/05/24/cisco-wlc-single-ssid-2-user-groups-in-different-vlans/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>

		<media:content url="http://admintell.napco.com/ee/images/uploads/gadgetell/cisco640.png" medium="image">
			<media:title type="html">Cisco</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2011/05/cisco-5508.jpg?w=300" medium="image">
			<media:title type="html">Cisco 5508</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2011/05/cisco-3750.jpg?w=300" medium="image">
			<media:title type="html">Cisco 3750</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2011/05/cisco-3560.jpg?w=300" medium="image">
			<media:title type="html">Cisco 3560</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2011/05/hp.jpg?w=300" medium="image">
			<media:title type="html">HP</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2011/05/hp-dl380-g7.jpg?w=300" medium="image">
			<media:title type="html">HP DL380 G7</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Lync Response Group UK Holiday Set</title>
		<link>http://thegid.wordpress.com/2011/03/24/microsoft-lync-response-group-uk-holiday-set/</link>
		<comments>http://thegid.wordpress.com/2011/03/24/microsoft-lync-response-group-uk-holiday-set/#comments</comments>
		<pubDate>Thu, 24 Mar 2011 14:59:29 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Lync]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=27</guid>
		<description><![CDATA[I&#8217;ve recently migrated our existing Microsoft Office Communication Server (OCS) 2007 R2 to Microsoft Lync Server 2010. I used to like OCS a lot and my first impressions of Lync are, well I love it! I&#8217;ve set up enterprise voice on Lync and have configured it to route calls through a Trixbox (Asterisk-based software PBX) virtual [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=27&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I&#8217;ve recently migrated our existing Microsoft Office Communication Server (OCS) 2007 R2 to <a title="Lync Server 2010" href="http://lync.microsoft.com/en-us/Pages/default.aspx" target="_blank">Microsoft Lync Server 2010</a>. I used to like OCS a lot and my first impressions of Lync are, well I love it!</p>
<p><a href="http://thegid.files.wordpress.com/2011/03/lync-server-2010.jpg"><img title="lync-server-2010" src="http://thegid.files.wordpress.com/2011/03/lync-server-2010.jpg?w=614&#038;h=181" alt="" width="614" height="181" /></a></p>
<p>I&#8217;ve set up enterprise voice on Lync and have configured it to route calls through a <a title="Trixbox" href="http://fonality.com/trixbox/" target="_blank">Trixbox</a> (Asterisk-based software PBX) virtual machine.</p>
<p><a href="http://fonality.com/trixbox/" target="_blank"><img class="aligncenter size-medium wp-image-31" title="trixbox2" src="http://thegid.files.wordpress.com/2011/03/trixbox2.jpg?w=300&#038;h=97" alt="" width="300" height="97" /></a></p>
<p>Speaking of virtual machines, the Lync (standard edition) front end server and the Lync edge server are Hyper-V virtual machines.</p>
<p>I&#8217;ll move onto the purpose of this post now&#8230;</p>
<p>Whilst setting up the Lync Response Groups I noticed that the standard holiday lists are empty by default and must be entered via the Lync Server Management Shell (powershell).</p>
<p>You&#8217;ll need to use <strong>New-CsRgsHoliday</strong> command to create the holidays then add them to a &#8220;Holiday Set&#8221; using the <strong>New-CsRgsHolidaySet</strong> command. <a title="Define Response Group Business Hours and Holidays" href="http://technet.microsoft.com/en-us/library/gg398605.aspx" target="_blank">Here&#8217;s the TechNet page</a> details this.</p>
<p>To save you some time here are the commands to create all the UK public holidays for 2011 and input them into a holiday set called &#8220;2011 Holidays&#8221;. (updated due to John&#8217;s comment below)</p>
<pre><span style="color:#000080;">$a = New-CsRgsHoliday -Name "New Year's Day" -StartDate "1/1/2011" -EndDate "1/3/2011" </span><span style="color:#000080;">$b = New-CsRgsHoliday -Name "Good Friday" -StartDate "22/4/2011" -EndDate "23/4/2011" </span><span style="color:#000080;">$c = New-CsRgsHoliday -Name "Easter Monday" -StartDate "25/4/2011" -EndDate "26/4/2011" $d = New-CsRgsHoliday -Name "Royal Wedding Bank Holiday" -StartDate "29/4/2011" -EndDate "30/4/2011" $e = New-CsRgsHoliday -Name "Early May Bank Holiday" -StartDate "2/5/2011" -EndDate "3/5/2011" $f = New-CsRgsHoliday -Name "Spring Bank Holiday" -StartDate "30/5/2011" -EndDate "31/5/2011" $g = New-CsRgsHoliday -Name "Summer Bank Holiday" -StartDate "29/8/2011" -EndDate "30/8/2011" $h = New-CsRgsHoliday -Name "Boxing Day" -StartDate "26/12/2011" -EndDate "27/12/2011" $i = New-CsRgsHoliday -Name "Christmas Day Holiday" -StartDate "27/12/2011" -EndDate "28/12/2011" New-CsRgsHolidaySet -Parent "applicationserver:&lt;your lync mediation server name&gt;" -name "2011 Holidays" -holidaylist ($a, $b, $c, $d, $e, $f, $g, $h, $i)</span></pre>
<p>Just modify the last line and replace &lt;your lync mediation server name&gt; with the FQDN of your Lync server.</p>
<p>Here&#8217;s the same for 2012:</p>
<pre><span style="color:#000080;">$a = New-CsRgsHoliday -Name "New Year's Day 2012" -StartDate "2/1/2012" -EndDate "3/2/2012"</span>
<span style="color:#000080;">$b = New-CsRgsHoliday -Name "Good Friday 2012" -StartDate "6/4/2012" -EndDate "7/4/2012"</span>
<span style="color:#000080;">$c = New-CsRgsHoliday -Name "Easter Monday 2012" -StartDate "9/4/2012" -EndDate "10/4/2012"</span>
<span style="color:#000080;">$d = New-CsRgsHoliday -Name "Early May Bank Holiday 2012" -StartDate "7/5/2012" -EndDate "8/5/2012"</span>
<span style="color:#000080;">$e = New-CsRgsHoliday -Name "Spring Bank Holiday 2012" -StartDate "4/6/2012" -EndDate "5/6/2012"</span>
<span style="color:#000080;">$f = New-CsRgsHoliday -Name "Diamond Jubilee Holiday 2012" -StartDate "5/6/2012" -EndDate "6/6/2012"</span>
<span style="color:#000080;">$g = New-CsRgsHoliday -Name "Summer Bank Holiday 2012" -StartDate "27/8/2012" -EndDate "28/8/2012"</span>
<span style="color:#000080;">$h = New-CsRgsHoliday -Name "Christmas Day 2012" -StartDate "25/12/2012" -EndDate "26/12/2012"</span>
<span style="color:#000080;">$i = New-CsRgsHoliday -Name "Boxing Day 2012" -StartDate "26/12/2012" -EndDate "27/12/2012"</span>
<span style="color:#000080;">New-CsRgsHolidaySet -Parent "applicationserver:&lt;your lync server name&gt;" -name "2012 Holidays" -holidaylist ($a, $b, $c, $d, $e, $f, $g, $h, $i)</span></pre>
<p>Just copy the whole lot into the Lync Server Management Shell and Bob&#8217;s your uncle. Now when you create a hunt or interactive response group you can choose the enable 2011 and 2012 Holidays.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=27&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2011/03/24/microsoft-lync-response-group-uk-holiday-set/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2011/03/lync-server-2010.jpg?w=1024" medium="image">
			<media:title type="html">lync-server-2010</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2011/03/trixbox2.jpg?w=300" medium="image">
			<media:title type="html">trixbox2</media:title>
		</media:content>
	</item>
		<item>
		<title>Windows XP SP3, 802.1x, Server 2008 &amp; mandatory profiles</title>
		<link>http://thegid.wordpress.com/2010/08/25/windows-xp-sp3-802-1x-server-2008-mandatory-profiles/</link>
		<comments>http://thegid.wordpress.com/2010/08/25/windows-xp-sp3-802-1x-server-2008-mandatory-profiles/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 21:22:10 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Wireless]]></category>
		<category><![CDATA[802.1x]]></category>
		<category><![CDATA[mandatory profile]]></category>
		<category><![CDATA[PEAP]]></category>
		<category><![CDATA[windows server 2008]]></category>
		<category><![CDATA[windows xp sp3]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=22</guid>
		<description><![CDATA[I&#8217;ve been working deploying Aruba wireless solutions for some time now and as no 2 clients network infrastructure are the same it offers some challenges and it keeps me on my toes.  Pretty much all of the installations that I do use 802.1x authentication for their corporate SSID and most of the clients use Windows server [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=22&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I&#8217;ve been working deploying <strong>Aruba</strong> wireless solutions for some time now and as no 2 clients network infrastructure a<a href="http://thegid.files.wordpress.com/2010/08/aruba2.jpg"><img class="alignright size-medium wp-image-23" title="aruba" src="http://thegid.files.wordpress.com/2010/08/aruba2.jpg?w=300&#038;h=117" alt="" width="300" height="117" /></a>re the same it offers some challenges and it keeps me on my toes. </p>
<p>Pretty much all of the installations that I do use <strong>802.1x authentication</strong> for their corporate SSID and most of the clients use Windows server 2003 &amp; Windows XP SP3.  The deployment of the wireless solution is usually pretty smooth as it&#8217;s all tried and tested.</p>
<p>Recently I&#8217;ve come across an issue with a deployment where the users struggle to authenticate.  The machines authenticated but once the user logged in they couldn&#8217;t authenticate.</p>
<p>The main difference in the deployment was the IAS server which was <strong>Windows server 2008 </strong>(so it&#8217;s NPS rather than IAS) but the client OS was <strong>Windows XP SP3</strong> which is still pretty normal to see.</p>
<p style="text-align:center;"><a href="http://thegid.files.wordpress.com/2010/08/untitled.jpg"><img class="size-full wp-image-24     aligncenter" title="Untitled" src="http://thegid.files.wordpress.com/2010/08/untitled.jpg?w=648&#038;h=136" alt="" width="648" height="136" /></a></p>
<p> </p>
<p>I double checked the configuration of NPS and it was all fine. The administrator could connect to the wireless and any new users I created could also connect.</p>
<p>I checked the existing user account and noticed that they all used the same <strong>mandatory profile</strong> which is stored on the server.  A bit of investigation via the power of the mighty google and a few minutes later I found a Microsoft KB titled &#8220;<strong>A Windows XP Service Pack 3-based client computer cannot use the IEEE 802.1x authentication when you use PEAP with PEAP-MSCHAPv2 in a domain</strong>&#8220;.</p>
<p>Looking at the title this seemed promising and while reading the KB (see below) this is exactly the configuration and what&#8217;s occuring.</p>
<ul>
<li><em>You configure a Windows Server 2008-based computer as the Network Policy Server (NPS). </em></li>
<li><em>You enable IEEE 802.1x authentication in the network. </em></li>
<li><em>You use Protected Extensible Authentication Protocol (PEAP) with Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP-MSCHAPv2) in the network.</em></li>
</ul>
<p><em>In this scenario, when a Windows XP Service Pack 3 (SP3)-based client computer tries to join the network by using the IEEE 802.1x authentication, the IEEE 802.1x authentication fails.</p>
<p><strong>Notes</strong></em></p>
<p><em> </em></p>
<ul>
<li><em>This problem occurs when you use a user account that uses a mandatory user profile. </em></li>
<li><em>This problem does not occur when you use a user account that uses a roaming user profile.</em></li>
</ul>
<p>You&#8217;ll need to call Microsoft to get hold of the hotfix and make sure you don&#8217;t believe them if they say &#8220;This hotfix is included in XP SP3&#8243; because it isn&#8217;t. They tried to fob be off with that.</p>
<p>The hotfix also comes with a disclaimer&#8230;</p>
<p><em>WARNING: This fix is not publicly available through the Microsoft website as it has not gone through full Microsoft regression testing.  If you would like confirmation that this fix is designed to address your specific problem, or if you would like to confirm whether there are any special compatibility or installation issues associated with this fix, you are encouraged to speak to a Support Professional in Product Support Services.</em></p>
<p>It worked just fine on my clients machines though which made me and them happy.</p>
<p>Here&#8217;s the link to the KB. <a href="http://support.microsoft.com/kb/969111"><br />
http://support.microsoft.com/kb/969111<br />
</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=22&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2010/08/25/windows-xp-sp3-802-1x-server-2008-mandatory-profiles/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2010/08/aruba2.jpg?w=300" medium="image">
			<media:title type="html">aruba</media:title>
		</media:content>

		<media:content url="http://thegid.files.wordpress.com/2010/08/untitled.jpg" medium="image">
			<media:title type="html">Untitled</media:title>
		</media:content>
	</item>
		<item>
		<title>Forgotten Password Woes</title>
		<link>http://thegid.wordpress.com/2010/04/12/forgotten-password-woes/</link>
		<comments>http://thegid.wordpress.com/2010/04/12/forgotten-password-woes/#comments</comments>
		<pubDate>Mon, 12 Apr 2010 14:36:35 +0000</pubDate>
		<dc:creator>James Whitehead</dc:creator>
				<category><![CDATA[Support]]></category>
		<category><![CDATA[CA ARCServe]]></category>
		<category><![CDATA[Forgotten passwords]]></category>
		<category><![CDATA[McAfee ePolicy Orchestrator]]></category>

		<guid isPermaLink="false">http://thegid.wordpress.com/?p=16</guid>
		<description><![CDATA[There&#8217;s nothing worse that urgently needing access to an application but being refused access due to forgotten password! I know, I know this should always to documented but sometimes you will gain ownership of an issue where the password is not known or just forgotten. Disclaimer: I know there are many things worse really but [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=16&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>There&#8217;s nothing worse that urgently needing access to an application but being refused access due to forgotten password! I know, I know this should always to documented but sometimes you will gain ownership of an issue where the password is not known or just forgotten.</p>
<p><em>Disclaimer: I know there are many things worse really but it&#8217;s pretty annoying nonetheless</em><em> </em></p>
<p>Here are a couple of ways to reset passwords which you may otherwise find difficult to reset. I&#8217;ll try to update this from time to time with more applications.</p>
<p><strong><br />
CA ARCServe</strong><strong> </strong></p>
<ol>
<li>Open a command prompt on the server where you want to change/reset the caroot password.</li>
<li>In the command prompt browse to the drive where you have ARCServe installed (e.g. C:\Program Files\CA\&#8230;)</li>
<li>Once in the ARCServe folder type in the following: <em>cstop</em></li>
<li>This will stop the ARCServe services that are running.</li>
<li>When all services are stopped open the Windows Explorer and browse to the folder:</li>
</ol>
<p>C:\Program Files\CA\BrightStor ARCserve Backup\Data\Discovery</p>
<p>Here you will find a folder that has the name of your server.</p>
<ol>
<li>Rename this folder. (Don&#8217;t delete it as you can always change the name back if there are issues)</li>
<li>Back in the command prompt type in the following: cstart</li>
<li>This will start the ARCServe services that were stopped in item 4.</li>
<li>Still in the command prompt type in the following: Authsetup/p &#8220;password&#8221; where “password” is what you want the new password to be.</li>
<li>Close the command prompt and try to open ARCServe with the new password.</li>
</ol>
<p><strong>McAfee ePolicy Orchestrator 4.x</strong><strong></strong></p>
<ol>
<li>Login to your SQL server where your ePolicy Orchestrator DB is located.</li>
<li>Execute the following query to create a user called epoadmin with a password of epoadmin.</li>
</ol>
<p>INSERT INTO [dbo].[OrionUsers]<br />
(Name, AuthURI, Admin, Disabled, Visible, Interactive, Removable, Editable)<br />
VALUES (&#8216;epoadmin&#8217;,'auth:pwd?pwd=7LTSeirrzM8EjqttaozV4cSiPGQWi8w3&#8242;,1,0,1,1,1,1)</p>
<p><strong> </strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thegid.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thegid.wordpress.com/16/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thegid.wordpress.com&#038;blog=12864479&#038;post=16&#038;subd=thegid&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thegid.wordpress.com/2010/04/12/forgotten-password-woes/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/9a681b257488a1a0aa7942f055e3cc9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Goose</media:title>
		</media:content>
	</item>
	</channel>
</rss>
