Tuesday, June 19, 2012

Two Printers to One Print Server Port


A while back, the idea of duplex printing for our computer labs was thrown around. Once approved we had to come up with an easy way to implement this while still giving the student an option to print simplex. To make things easier, we have a print manager software called Papercut. There is a duplex feature to turn on duplex printing for the specified printer, however, from there on - duplex is strictly enforced, even if a student turned off duplex in their favorite program. This presented a challenge as most of our labs only contain one physical printer. So, to get around that challenge, we setup a "new printer" using an existing port on the print server. Essentially this is like having two virtual printers to one physical printer.

So as you can see, I have printer 1C05-1 with Duplex enforced (on Papercut side). To add a "Simplex" printer, using the same port click on "Add a printer." 



Next, click on "Add a local printer"


Choose the same port, in this case "1C05P1" which is the dns name in which printer 1C05-1 is assigned


Once the printer is added, you now have two virtual printers, using the same port. So essentially, a student can now choose the "1C05-1-Simplex" printer to print 1-sided print jobs, while leaving 1C05-1 as the default, duplex virtual printer. Keep in mind, this is still one - physical printer.


On the server, if you go to Print Server Properties, you can see two (virtual) printers are assigned to the one port.



Tuesday, April 17, 2012

Setting up MS System Center Configuration Manager 2012 in a Test Lab Environment

To keep all of the System Center stuff separate from our network and production, I decided to set up an ESXi lab to do some testing first. Some settings that I list below could be different from your network or situation and may not necessarily apply to best practices. Active Directory is heavily involved with System Center and in some cases, extending the AD Schema can be one of the most important steps. For this test, SCCM and MS SQL will be on the same server.

Test Hardware:
 Lenovo 3269, Intel i5 processor, 16GB's ram, two ssd's

Prep (a couple hours):
  • Install ESXi hypervisor
  • Get vSphere setup, create two datastores, setup two vSwitches - 1 for management (public ip), 1 - for vm's (private ip's)
  • Setup one Domain Controller VM (Server 2008 R2)
  • Setup one System Center VM (Server 2008 R2)
  • Setup four Win7 VM's (clients)

System Center Configuration Manager 2012 Prep Install:

In AD, create some users and place them in a special OU
  • sql.sa (for sql server agent account, domain user recommended)
  • sccm.install (for client push installs, software installs, needs to be local admin on all client computers)
  • sccm.admin (used if you don't want to deal with multiple Windows user profiles on SystemCenter server, however not necessary)

Install MS SQL 2008 R2
**Go with the defaults unless specified below
 SQL Server Agent: payneb\sql.sa or Choose SYSTEM
 SQL Server Analysis Services: choose SYSTEM account
Database Engine Configuration 
  (o) Windows Authentication Mode
  Remove your user account from Administrators, add payneb\sql.sa (add domain admins group if desired)
Analysis Services Configuration
  Add payneb\sql.sa  (add domain admins group if desired)

Install MS SQL 2008 R2 SP1
 http://www.microsoft.com/download/en/details.aspx?id=26727

Install CU4 for SQL
 http://support.microsoft.com/kb/2633146

*Only needed if separate servers
Create 2 InBound Firewall Rules on SystemCenter
 Name: “SQL Server Port 1433” TCP, port 1433
 Name: “SQL Broker Service”, TCP, port 4022

Add SystemCenter computer object to local admin group on System Center server

Add sql.sa and sccm.admin users to local administrators group on System Center server

Create the System Management container in AD
  • In ADSI Edit, click on the + and scroll down to CN=System > Right Click on CN=System and choose New, Object
  • Choose Container from the options, click Next and enter System Management as the value
Delegate Permission to the System Management Container
  • Open Active Directory Users and Computers. Click on view, select Advanced Features.
  • Select the System Management Container, and right click it, choose All Tasks and Delegate Control.
  • Click Add. Type in your SCCM server name and click on Check Names. Choose Create a Custom Task to Delegate, click next, make sure This folder, existing objects in this folder and creation of new objects in this folder is selected., click next, select the 3 permissions General, Property-Specific and Creation-deletion of specific child objects are selected then place a check mark in FULL CONTROL
Failure to do the above will mean that the System Management Container in AD will NOT POPULATE with ConfigMgr site info needed by the Clients and you will see many errors in your site status warning you of same.

Extend the Active Directory schema for Configuration Manager
  • Browse to the System Center 2012 iso and copy \Bin\x64\Extadsch.exe to AD server
  • In AD, open up a command prompt, run Extadsch.exe
  • After ran, log file is located on C:\

Add .NET 3.5.1 and WCF Activation and IIS roles on System Center server
    Add Features, Select .NET Framework 3.5.1, also select WCF Activation and when prompted answer Add Required Role Services
    Check these IIS Components
        Common HTTP Features
        Static Content
        Default Document
        Directory Browsing
        HTTP Errors
        HTTP Redirection

        Application Development
        ASP.NET
        .NET Extensibility
        ASP
        ISAPI Extensions
        ISAPI Filters
     
        Health and Diagnostics
        HTTP logging
        Logging tools
        Request Monitor
        Tracing
        
        Security
        Basic Authentication
        Windows Authentication
        URL Authorization
        Request Filtering
        IP and Domain Restrictions

        Performance
        Static Content Compression

        Management Tools
        IIS Management Console
        IIS Management Scripts and Tools
        Management Service
        IIS 6 Management Compatibilty
        IIS 6 Metabase Compatibility
        IIS 6 WMI Compatibility
        IIS 6 Scripting Tools
        IIS 6 Management Console


Install .NET 4 Full
 http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=17718

Add BITS and Remote Differential Compression
  • Add Features, place a selection mark in BITS and Remote Differential Compression (RDC).

Install System Center Configuration Manager 2012

    (o) Install a Configuration Manager primary site
        Download files when prompted. If it fails, try again
    Site and Installation Settings
        Site Code: P01 (Primary 01)
        Site Name: SCCM 2012
        Installation Folder: Data drive (E:)
    Primary Site Install
        (o) install the Primary site as a stand-alone site
    Database Information
        Leave Database Information as defaults
        Instance name - leave blank
    FQDN of server for SMS Provider, leave as default
    Communication Settings
        (o) Configure the communication method on each site system role
    Site System Roles
        [x] Install a management point, stay with default FQDN
        [x] Install a distribution point, stay with default FQDN
    Prerequisite checks
        Ignore SQL memory limit and WSUS warnings
    You can use the CMTrace tool and watch the log - C:\ConfigMgrSetup.log

Monday, January 30, 2012

Remotely Remove a User From the Local Administrators Group

Here's an easy way to remotely remove a user from the local administrators group using Psexec

What you'll need:

  • psexec
  • Elevated privileges 
  • Allow inbound remote administration on pc you are reaching

Pull up the command prompt. It may be good to double check what users are in the Administrators group first.
C:\>  psexec \\2E01-Computer net localgroup Administrators
Now that you know the user you want to remove, insert the command below
C:\>  psexec \\2E01-Computer net localgroup administrators User /delete
That's it.



Friday, September 23, 2011

Modify BAUD speed on Cisco Switch and Router

I have a rack of switches and routers that I connect through from a terminal server. I noticed how slow and laggy the switches and routers would be after entering a command. The current baud speed is set at 9600. I wanted to change this to 115200.

************************************************************
SET BAUD/CONSOLE SPEED TO 115200 ON CISCO 2600 ROUTERS
************************************************************

http://www.cisco.com/en/US/products/hw/routers/ps133/products_tech_note09186a008022493f.shtml
Router> ena
Router# conf t
Router(config)# config-register 0x3922
Router(config)# end
Router# reload
Put "n"  you dont need to save configuration

Immediatly press CRTL + Break keys

It should put you in Rommon mode
rommon 1 > confreg 0x3922
rommon 1 > reset
Router or switch should reboot, thats it.

************************************************************
SET BAUD/CONSOLE SPEED TO 115200 ON CISCO 3750 SWITCHES
************************************************************

http://www.cisco.com/en/US/products/hw/switches/ps628/products_tech_note09186a0080169696.shtml

Hold MODE button down while powering on
SWITCH: set BAUD 115200
Unplug switch and plug power back in

****************************************************************
FIX UP  TELNET SPEED TO 115200 ON CISCO 2600 TERMINAL SERVER
****************************************************************
Router> ena
Router# conf t
Router(config)# line 33 64
Router(config-line)# speed 115200


Wednesday, June 8, 2011

Finding Out a Machines Uptime

This post sort of goes along with the previous "Remotely Rebooting Machines" post.

The title says all - being curious, I wanted to find out everyone's machine uptime. In other words, how long has the computer been powered on?

You need:
-psexec
-elevated privileges to access remote machines
-grep - if you want to filter out what you dont need from the command, add ".../bin" directory to your environment variables

If you run "systeminfo" from the command prompt on your machine, this is the output that we are looking for from remote machines. Also, we just need this line from the output: "System Boot Time: 6/8/2011, 7:07:01 AM" The other junk can be handy for other "curiousness'" but for this instance, Im not interested.

Create a .cmd file, paste in this command (all one line):
for /f "tokens=*" %%c in (machines.txt) do psexec \\%%c systeminfo | grep "System Boot Time:"
Create a separate text file named machines.txt in the same directory. Put all your computer names in the text file, each on a separate line. Ok, open the command prompt, adjust your screen buffer, run the .cmd file.  If you have hundreds of computers, this will take a LONG time to run.

I believe there is a way to output the results in a local text file, but I could never get it to work since I have a pipe grep at the end, however I could be doing something wrong.

Monday, June 6, 2011

Remotely Rebooting Machines

I noticed there are some machines on the network that haven't been rebooted for quite some time. As time moves along, new gpo's are created, software is updated, etc. Nonetheless, every month or two, all machines should be rebooted to pick up what has changed.

Create a .cmd file with this command in it:
for /f "tokens=*" %%c in (machines.txt) do shutdown /r /f /m \\%%c
You also need to create a txt file in the same directory that includes the machines you want rebooted. Make sure you do not include \\ in front of the computer name. If you prefer leaving \\, then revise the command above.

/r - Indicates to reboot the machine
/f - Force running applications to close without forewarning users
/m - Specify the remote computer in \\

Run your .cmd file in the command prompt window so you can see which machines errored out. You may need to adjust your screen buffer size if you have alot of machines.
C:\Reboot\RebootMachines.cmd
Note - There may be computers that are shutdown or in Sleep mode, this command will error out if it cannot contact the machine, however, it will proceed to the next machine after about 15 seconds. Keep a list of what computers errored out and visit them individually.
2E01: The entered computer name is not valid or remote shutdown is not supported on the target computer.
Also, if you dont have the proper permissions to do so, this will fail.

Thursday, June 2, 2011

Malware/Viruses in the Workplace

Now that our campus is dominantly running Windows 7, I've seen MAJOR improvement on malware/virus infections on campus machines. When we were running XP, I typically cleaned about a machine or two a day. Mostly using ComboFix, Malwarebytes, and/or Microsoft FEP 2010. If those scanners didn't clean the infected machine, I'd resort to a reformat/rebuild of the OS. My time was consistently being pulled away from projects, server maintenance, etc. Thanks Windows 7!

We still have a handful of machines out there running Windows XP. My new motif (which has been quite some time now) that I've learned is that "most of the time" it's easier to just grab a different hard drive, image it, move over the files. This process is usually quicker than cleaning the infected machine and taking a chance of it not being cleaned after spending time on it. Or even the chance of lingering infections that will come back to haunt. This is something that I've learned over my desktop support years.

For on the spot imaging, we use Acronis True Image. I can image a hard drive typically in about 4 minutes, boot it up, let Win7 find the drivers and am ready to go.