Posts

Showing posts from February, 2014

is there any authentication between wsus srv & wsus clients by default?

hi friend in win2008 r2, there authentication between wsus srv & wsus clients default?  mean if deploy wsus srv in domain, default service clients (workgroup clients & domain joined clients ?) if so, how can deploy authentication it? mean wsus srv service domain joined client. what downstream wsus servers? domain joined upstream wsus srv default service downstream wsus srv? if how can deploy authentication here ? thank in advance  in terms of server client communications, design anonymous , there's no mechanism far i'm aware configure client machines authenticate the wsus server. if want prevent unauthorised machines connecting wsus server updates need use other mechanisms that, instance firewall restrictions. i've seen comments on here suggesting add authentication in iis, break wsus functionality , doesn't work. in terms of server server communications, yes can secure that. see http://technet.microsoft.com/library/dd939849(ws.10).aspx full

WinXP Pro SP3: Some policies missing in Group Policy Editor

Image
i want enforce password-protected screensaver on users. there should related policies in [user configuration --> administrative templates --> control panel --> display] but shown in screenshot below (sorry it's in chinese), there many folders missing under [user configuration (使用者設定) --> administrative templates (系統管理範本)]. 1 left [windows component (windows元件)] as shown in screenshot, haven't applied filter. why? my windows version winxp pro version 2002 sp3 it has joined domain, related?     hello, looks deafult .adm files missing. on administrative templates level rightclick , choose add/remvoe templates. should containby default conf/inetres/system/wmplayer , wuau. best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. Windows Server  > 

Replacing a file server using a CNAME record - an SPN issue?

we have old file server (2008 r2) used data exchange between several devices. devices connect usual file share. need use file server exchanging data and retire old server permanently. however, changing paths inside devices major problem. prefer leave them intact. in addition, devices critical, , have roll should goes wrong. idea we've developed shutting down old server, delete record primary dns zone , replace cname record pointing new server. did before while retiring old file server, , went smoothly. however, time method doesn't work. if create cname record , try access shared folder using it, error "windows cannot access path". in same time, if create cname record name didn't exist before, can access new server using it. i suspect has an existing spn in ad points old server (host/old-server-name). possibly can create new 1 using setspn command. however, happen old spn if it? deleted or overwritten? if remove new cname record, spn recreated when

How do I prevent IIS 8 from starting up when my computer starts

i using apache server writing web sites. have turn off iis every day before can start apache server. there should way of preventing case in earlier versions, cannot find it. windows 7 professional 64 bit. can help? hwalker1 try disabling service. might ask them here if can't uninstall it. http://forums.iis.net/ http://answers.microsoft.com/en-us/windows/forum/windows_7       regards, dave patrick .... microsoft certified professional microsoft mvp [windows] Windows Server  >  Server Manager

2012 R2 standard Replica DC cant connect to the main DC to be promoted

hi everyone, i have strange issue adding additional dc replica/backup, dc might need hardware maintenance , not sure how long out of order.  both servers 2012 r2 standard, , when installed 1 trying add replica, had evaluation. have not been able it, converted full retail standard version key, , tried promote it, didnt work. keeps saying there communication.  the servers added domain, can ping main dc, can nslookup, cant open connection using ldp port 398. dns added advanced settings of ipv4, ipv6 disabled, saw in other posts try, firewall not blocking because tried , without firewall. server has static ip, has dns role installed (also suggested other post), keep getting same error when trying promote 1 dc. event viewer time time gives netlogon error of not being able contact dc. communication there, can see it, blocking being recognized when run dcpromo wizard. hi  you should check port accessibility , dns config,run "ipconfig /all" on both , can check ports

WSUS ISSUE

hi everyone, i have 1 upstream & 1 downstream server, my problem that win server 2k8 r2  not taking update wsus.over all clients win7,windows 2k3 server,   ram prakash sharma hi, so understand question, servers 2008 r2 installed don´t gets updates. first, please have in wsus optons. choose "products , classifications" , make sure, win server 2008 r2 choosen. synchronize wsus again , check, updates approved. kind regards, m.hivner Windows Server  >  WSUS

Server 2012 Domain Controller Policy Problem

on domain, when promote server(win server 2012) dc, of gpos stop applying. can see settings before promotion, , after promotion settings show undefined. in particular account , password policy settings vanish. dc fsmo roles applying policy correctly. if demote server policy starts applying correctly again. have servers in right ous, , i've got policy scope set correctly, , can't see differences between 1 server correct, , others not. thoughts? after prompting dc, existing user account converted ad built-in account. try run gpupdate /force again after promption , see if helps. Windows Server  >  Windows Server General Forum

Windows 7 and WSUS scheduled install times

hi group, it appears our windows 7 enterprise clients (both 32 , 64 bit) ignoring gpo settings scheduled install day and scheduled install time . clients getting updates okay not on gpo prescribed schedule. i've confirmed windows update settings (found via control panel) in fact show correct schedule. any idea why is? wsus 3.2.7600.226 windows server 2008 windows 7 enterprise 32 , 64 thanks, please post entries windowsupdate.log showing actual update installation event. note: wuapp not reliable source actual configuration settings. configuration settings stored in registry @ hklm\software\policies\microsoft\windows\windowsupdate , should directly inspected. configuration settings logged in windowsupdate.log @ service startup , can reviewed in logfile searching backwards end of logfile first occurrence of "service start". lawrence garvin, m.s., mcitp:ea, mcdba, mcsa principal/cto, onsite technology solutions, houston, texas microsoft mvp - softw

Dead WSUS Server

hi, unfortunately our wsus server has died. round building new 1 in short term remove it's configuration clients. 2 days ago reset group policy object settings "not configured". now when visit ms update site updates can downloaded fail install errors 0x8024200e , 0x80070005. thanks help david resetting policy option not configured not revert registry-based policy setting policy. to revert such policy, must configure , apply opposite setting. so, in case of wsus policy, critical policy enable/disable use of wsus "specify microsoft intranet update service location" policy. you'll need disable policy, , apply policy. set usewuserver=dword:0x1 value dword:0x0, removing configuration option imposes use of wsus. lawrence garvin, m.s., mcitp:ea, mcdba principal/cto, onsite technology solutions, houston, texas microsoft mvp - software distribution (2005-2009) Windows Server

TFS 2010 - AD 2012 R2

can tfs 2010 environment run on ad 2012 r2 functional level? all tfs 2010 articles written before came out it's hard find information - assuming it's supported since it's not old. hi, >>can tfs 2010 environment run on ad 2012 r2 functional level? based on research , understanding, tfs 2010 should supported on ad 2012r2 functional level. regarding active directory requirements team foundation server, following article can referred more information. active directory requirements team foundation server https://msdn.microsoft.com/en-us/library/dd578631.aspx in addition, tfs questions, in order better help, it's recommended ask advice in following forum. team foundation server-general https://social.msdn.microsoft.com/forums/vstudio/en-us/home?forum=tfsgeneral best regards, frank shen   please remember mark replies answers if , unmark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.

PowerShell - Remove-CMContentDistribution

hi, i try remove app, packages os etc. remote dps , using remove-cmcontentdistribution. using try , catch method, catch appending on testing if 1 of packages missing write package names in-line - example package not @ site or had error removing: adobe flash player 22.0.0.209 test test1 i have tried -append text file , csv. here script - $packages = get-content "c:\scratch\psin\packages.txt" $distrbutionname = "servername.com" foreach($package in $packages) {   try {      remove-cmcontentdistribution -distributionpointname $distrbutionname -applicationname $packages -verbose -force }    catch {       "package not @ site or had error removing: $packages" | out-file "c:\scratch\psout\removepackage.txt" -append        } } if  format , design code more , better able see mistakes: $packages = get-content c:\scratch\psin\packages.txt $splat = @{ distributionpointname = 'servername.com' erroraction

Shared Volume IO is paused

we're seeing foll scom alerts csv disk during or after backup job run vm on disk using netbackup. of vm's on disk fail , have manually brought online, , backup job fails. disk gets stuck in redirected access vss state not cleared, gets online after deleting shadow copy using diskshadow. we're running 12 node w2008r2 cluster on hp dl 380 g7 proliant svrs, using hp eva 8400 san w2008 server mode enabled support prs. also, using latest hp mpio dsm v4.0.2 2 paths storage , latest firmware , drivers hp fc2242sr hba (a8003a).   n/ws using hp nic teaming vm network, csv/hb/lm 1 teamed nic , backup n/w , single nic hb, host mgmt. metric set manually lowest metric csv/hb/lm teamed nic, second lowest hb nic. cluster shared volume 'disk_name' ('disk_name) no longer available on node because of 'status_wait_0(0)'. i/o temporarily queued until path volume reestablished   cluster shared volume 'disk_name' ('disk_name') no longer available

Logon Scrip not working via GPOs

dear i need over-right saplogon.ini file script this scripting file upload gpo. @echo off set source="\\10.1.125.2\software_drive\saplogon.ini" have read access set destiny="c:\windows\" xcopy   %source% %destiny% /y   user not have wright access c drive. need copy above .ini file windows folder clients pc in mix environment , dc in 2008 os version, domain , forest functional level 2003 native microsoft technet forum bandara make startup - rather logon script. make sure computer accounts have read permissions \\10.1.125.2\software_drive\saplogon.ini hth marcin Windows Server  >  Directory Services

RDWEB Access SSO issue with ISA 2006 RADIUS OTP authentication

i have windows 2008 r2 based remote desktop services environment with a) 2 load-balanced servers hosting both rd gateway , web access servers role b) 2 clustered rd connections broker servers functioning dedicated farm redirectors c) 3 rd session host servers in farm.  a public certificate godaddy used digitally sign applications.  internally when users access rd web access page, prompted once authentication ( user@domain.com ), , when click on published applications after providing credentials @ rdweb access page, no longer prompted credentials.  in essence single signon works internally. if users try access rdweb access page internet through isa using radius otp, single signon doesn't work.  the users prompted credentials 3 times @ locations below 1) isa logon page 2) rdweb access page 3) when clicking published application the way single signon works if connect windows 7 laptop directly internal network, access rdweb access page, , use same laptop access pa

2008 R2 VM cannot browse the web

i have 2012 server 2008 r2 vm running on it.  i staged @ home , fine.  i changed ip's static , moved client site.  once there reason can no longer browse web within vm.  i gat "cannot display page" errors. tracert site goes way through cannot site ip or name. the host can still browse web fine. any ideas appreciated. jim -jim hi, please check following configuration correct. you have create vswitch type external , attach physical nic. confirm child vm nic has attached external vswitch. confirm child vm obtain correct tcp/ip configuration dhcp. confirm edge firewall or system firewall not block child vm internet link. hope helps. alex lv Windows Server  >  Hyper-V

msa1500 , windows 2008r2, scsi, can't initialize disks

hello, have problem with msa1500, working before reboot on weekends . now, in windows disk manager see disks them "not initialized" . when i'm trying initialize error message "invalid function". in diskpat can see 1 c disk diskpart> list disk disk ### status size free dyn gpt -------- ------------- ------- ------- --- --- disk 0 online 136 gb 6144 kb diskpart> rescan did not help.  san policy  : online all give me advices ? in advance. how these disks connected server? regards satish Windows Server  >  File Services and Storage

AD

hola nuevamente aqui, cada dia peor. ayer, con problemas dns, desinstale, sin pensar, que habia sido creado junto ad. lo volvi crear, solo, el dns. el problema ahora es que exchange no levanta, por no encontrar ad. corri dcdiag microsoft windows [version 6.1.7601] copyright (c) 2009 microsoft corporation.  rights reserved. c:\users\administrator>dcdiag directory server diagnosis performing initial setup:    trying find home server...    home server = dcname    * identified ad forest.    done gathering initial info. doing initial required tests    testing server: default-first-site-name\dcname       starting test: connectivity          host b9444ded-6444-4f4c-63d1-ff805806b668._msdcs.domain.local          not resolved ip address. check dns server, dhcp,          server name, etc.          got error while checking ldap , rpc connectivity. please check your          firewall settings.          ......................... dcname failed test conn

Users in the BUILDIN/administrators security group

Image
i reviewing build-in security group administrators , notice lot of entries seems external can please explain these entries , can remove group. the problem facing called sid translation failure can due several issues. 1 of reason might user deleted not cleaned in groups. how ever can translate sid names user friendly name , troubleshoot if users exists. using tools psgetsid http://technet.microsoft.com/en-gb/sysinternals/bb897417.aspx i encourage read well  sid translation failures http://blogs.technet.com/b/askds/archive/2011/07/28/troubleshooting-sid-translation-failures-from-the-obvious-to-the-not-so-obvious.aspx http://www.arabitpro.com Windows Server  >  Windows Server General Forum

Server 2008 cluster disk

disk validation cluster setup failing because of mirrored set of local drives.   once break mirror validation passes , i’m able build cluster, add disk resources etc.   once local mirrors have been recreated i’m not longer able add disk resources.   in technet forms there confirmation ms engineer there hotfix coming out issue.   my question is: fix out yet, if so, how it.   thank you. where confirmation?   can provide thread link? Windows Server  >  High Availability (Clustering)

HOW TO MAKE BACKUP SERVER OR SYNCHNONIZATION BACKUP SERVER ?

dear friends, i have windows ad window 2003 server   and db window server 2003. db server using oracle   documentation, company details server. need make additional   server machine backup server , should work automatically every day. could please help   me how make backup server or synchnonization backup server. do have good   suggestion problem than you suresh     suresh you can use dfs if files backing not locked process; go windows backup (scheduled backup), , backup on second server specified. adrian costea - mcp, mcts, mcsa 2003, mcitp: windows 7 my blog: www.vkernel.ro/blog Windows Server  >  Setup Deployment

Unattented install on HP Gen9 fail in BFS

hi, i'm trying automate installation of windows 2012r2 , 2008r2 uefi, , bios. use winpe 4.1 disk boot server. - works on vmware uefi mode vm 40 gb vmdk disk. - on hp gen 9 in uefi or bios mode, server setup unable install system because says can't find suitable partition. use 64 gb lun on san through virtual connect. on both, disk partitions created windows setup according unattended.xml file.   partition 1    recovery           350 mb   partition 2    system             100 mb   partition 3    reserved           128 mb   partition 4    primary             64 gb : hp gen 9, , 39 gb vm using virtual disk. for hp gen 9, setupact.log says : summary - ccp check passed; able calculate space reqs; able find install location; location type meets installation reqs; size of location not small; location free space enough; location free space not meet recommendation and then, there strange message : info       [0x0606cc] ibs    getsystemdiskntpath: una

How to create CSR for user certificate using certmgr.msc?

hi, i trying to run test by importing ad user certificate sap client user can login sap ad account. currently, not running ad cs pki infrastructure. therefore, i need manaully create csr and have third party tool issue certificate @ time testing. learned other member use certmgr.msc generate csr. however,  when launched certmgr.msc windows 8 client , goes \personal\advanced operations\create custom requests....\proceed without enrollment policy\pkcs#10\ next. kind of stuck here.... what kind of information is required create csr for user certificate his/her existing ad user account?  as far knew the upn , full dn under subject tab required else needed generate csr existing ad user account?  thanks. mugen there no standard certificate contents users in ad - depends on application validates certificate. in case of 'native windows logon' against ad user principle name matter, example. as said other thread have seen sap white paper how create certificates sap log

Error While installing Application patch

hi i getting below error while updating application patch .net or ms office the upgrade path cannot installed windows installer service because program upgraded missing or upgrade path may update different version of program . my server os windows server 2003 r2, enterprise edition sp2 please let know steps resolve this. hi, here wsus forum. issue seems out of scope of forum.we focus more on wsus server operation , deployment.for individual update failure issue,i suggest ask in 03 os forum or specific application(.net,office) forum. regards, clarence please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.

IE8 msi not installing on some machines(upgrade from IE6).....

Image
hi, i have deployed ie8 customized msi 500 machines, worked except on 30 (approx.) machines. computers picked gpo whatever reason did not install. i created new ie8 customized .msi, machines picks gpo not install.  is there reason .msi not install second time if fails first? there no reason why wont install, racking brains bit. nothing in event viewer helps me.  os – windows xp sp3 dc – 2008 r2 dc any more info needed, let me know.  cheers hi, thanks posting. since customized ie8 msi file works of clients, issue caused 30 individual workstation. although mentioned os , memory requirement in ie8 installation requirement website, still remember updates need install before install ie8. manually install msi , install updates follow installation tips or find error log during installation. you may refer article check , fix ie 8 installation problems: how solve internet explorer 8 installation problems http://support.microsoft.com/kb/949220 for more informati

Sites & Services

hi, i using following subnet on network: ip:     192.168.3.0 mask: 255.255.255.0 gw:   192.168.3.254 i creted subnet in sites , services; 192.168.3.0/24 , assigned site called sitea. my problem when go active directory , @ properties for a computer which is picking dhcp address in sites range (192.168.3.x), don't show site under general tab?  doing wrong here?  how site show here? if soneone kindly awesome, d. hi,   as far know, site information not show in general tab of properties on client workstation object. the site information determined net logon service when workstation starts , stored in dynamicsitename registry entry.   dynamicsitename http://technet.microsoft.com/en-us/library/cc960209.aspx   regarding issue cannot install exchange management tools on workstations, please upload exact error message further research. in addition, please check if there netlogon 5807 event logged in domain controller. if so, please refer following kb article resolve issue:   you

Need Help with Microsoft interview

i have 1st interview microsoft , pfe active directory , exchange, interviewed ms country manager in country i've been told on phone. will technical interview or personal please want job dream :))) abeer omar, mcp,mcsa,mcse,mcts.mcitp you might want check http://www.sellsbrothers.com/interview  if looking general guidelines on way such interviews might conducted - or @ least way few years back. however, forum deals specific technical, ad-related questions... hth marcin Windows Server  >  Directory Services

Property Fields and Restricted Editing [Word 2010]

i've reviewed other 'similar' questions , not address issue. have document property [form] fields tie in database. if leave document unlocked there possibility user delete these fields. avoid have done following: 1) on developers tab selected 'restrict editing' 2) restrict editing chose 2. allow type of editing in document > no changes (read only) 3) proceeded select areas of document edited "everyone". includes selecting property [form] field. 4) when i'm done, save , start enforcing protection. when appears lose functionality of property [form] field , 'place holder' becomes text entry. any or insight appreciated. regards ~ karyn assuming using content controls (with blue surrounds , labels)  a. if select entire control (by clicking on tag, example) before checking "everyone" box, user able delete control. in case, stop controls being deleted, have select properties of each 1 , check "content control c

script for Get-ExchangeCertificate

hello all.. i want create script check certificate exchange.. i need know when expire... the idea create script , link nagios. step nagios can myself, compose script need help, so, lets try help. im using command date of certificate: get-exchangecertificate | { $_.services -like "*imap*" } | select notafter the result is: notafter -------- 19/11/2014 08:45:13 but i need receive date, below: 19/11/2014 how can it? im using command date of day: get-date -uformat "%d/%m/%y" the result need, date: 19/11/2012 after, need compare date of day date of certificate. want receive message if 30 days remaining expire. i appreciate me thanks diego $cert = get-exchangecertificate | {$_.services -like "*imap*" } $date = $cert.notafter if($date.subtract((get-date)).days -le 30) { "critical - certificate expire in " + $date.tostring("dd\/mm\/yyyy") } else { "ok - certificate expire in " + $da

WSUS Reports

hello,       client wants take overall report wsus console daily.i want automate it.can same details from wmi classes? thanks in advance gowthaman j my client wants take overall report wsus console daily. there isn't "overall report" wsus console. there update reports, , computer reports -- kinda looking @ moon earth or outer space, never seeing other side. i want automate it. automating reporting in wsus requires using public_views , writing .net code , using task scheduler. can same details wmi classes? no. wsus not wmi-enabled application. having said of that, there third-party application allow implement automated reporting clients wsus server. see solarwinds patch manager . (note: indicated in sig, employed solarwinds.) lawrence garvin, m.s., mcitp:ea, mcdba, mcsa solarwinds head geek microsoft mvp - software distribution (2005-2012) mvp profile: http://mvp.support.microsoft.com/profile/lawrence.garvin

Windows Deployment Services on Novell Networks

i working on novell network , looking @ implementing mdt2008 , windows deployment services. understanding of wds functions on active directory domain. possible use wdt in novell environment? hi, your computing environment must meet following technical requirements install windows deployment services:   ·          active directory. windows deployment services server must either member of active directory domain or domain controller active directory domain. active directory domain , forest versions irrelevant; domain , forest configurations support windows deployment services.   ·          dhcp. must have working dynamic host configuration protocol (dhcp) server active scope on network because windows deployment services uses pxe, relies on dhcp ip addressing.   ·          dns. must have working dynamic name services (dns) server on network run windows deployment services.   ·          an ntfs partition. server running windows deployment services requires ntfs file system volu

2012r2 dual parity virtual disk capacity incorrect

i have 2012r2 storage server 12x 6tb hdd. drives shows 5.46 tb capacity expected. unexpected creating array in powershell. setup 12 drives single dual parity space. using command new-virtualdisk -storagepoolfriendlyname 72tb -friendlyname hdd_parity -usemaximumsize -resiliencysettingname parity -provisioningtype fixed -physicaldiskredundancy 2 i reported capacity of 48.88 tb. using n-2 x 5.46 tb should see 54.6 tb 48.88 / 9 = 5.43 tb or n-3. specifying columns manually @ 12 gives same results, columns 11 drops capacity 1 more drive , on. if switch routes , use new-virtualdisk -storagepoolfriendlyname 72tb -friendlyname hdd_parity -usemaximumsize -resiliencysettingname parity -provisioningtype fixed -physicaldiskredundancy 1 -numberofcolumns 6 which if not mistaken 2x 6 drive single parity arrays striped or spanned? 54.57 tb aligns n-1 x 2 or 5.46 tb x 10. so missing drive dual parity virtual drive? it's not reported hot spare , rather not throw away capacity of thi

NPS and NAP

server 2012 standard the roles installed on server are: ad cs ad ds dhcp dns file , storage services iis nap print services i trying setup 802.1x wireless. when go through wizard.  i select peap under type. specify user groups.  i click add.  i search group want add.  i click okay.  after couple of seconds of computer thinking following error appears.  "windows cannot process object name "teacher group" because of following error:  the specified domain either not exist or not contacted.   which shouldn't happen since on domain server making these changes.  i have checked to confirm if there issue in dns or dhcp.  i can't find issue.  if nslookup server name comes correct ip address , domain.  i able find using ip address.  (the server has static ip.)   what causing issue?  how rectify this? hi, sorry delay. have registered nps server in ad?if case,please register first , test again. ref:register nps server in active direc

Changing domain users desktop wallpaper periodically

hi  i know can set wallpaper users gpedit>  administrative templates> desktop.  but there way automatically each day or week ? tanx i know can set wallpaper users gpedit>  administrative templates> desktop.  but there way automatically each day or week ? depending on os version of client computers, there may several ways; a) use windows theme, desktop background=slideshow b) use adm template setting, configure folder+filename, , use other process (maybe startup script) copy down new file same filename. c) use bing desktop, or similar application don (please take moment "vote helpful" and/or "mark answer", applicable. helps community, keeps forums tidy, , recognises useful contributions. thanks!) Windows Server  >  Group Policy

Windows 2008 R2 PKI with Windows XP 802.1X

hello, i planning upgrade our domain controllers, windows 2003, windows 2008 r2. have mixed environment of wireless windows 7 , xp clients use certificate services connect our secure wireless network. use wpa2, aes, , peap. i have test environment 1 windows 2003 offline root ca, 1 widows 2003 issuing subca (also dc, dhcp, dns, , ias server), , windows 2008 issuing subca (also dc, dhcp, dns, , nap server). environment setup secure wireless network using wpa2, aes, , peap. windows 7 machine not have problem getting on network either widows 2003 subca or windows 2008 subca servers. however, windows xp machine can connect widnows 2003 subca, but not 2008 subca. from research looks windows xp clients have problem new 2008 cryptography next generation (cng). my plan upgrade windows 2003 dcs 2008. there way windows xp client work w/ 2008 r2 subca?   thank help! hello, i went ahead , removed roles server, reinstalled, , worked. able xp machine connect windows 2008 nps.

Grupo Restringido - Administradores locales

buenas noches, por favor orientenme respecto este tema; estoy por implementar uan politica de grupos restringidos, en la cual voy restringir la pertenencia al grupo de administradores locales solo los administradores del dominio y grupo de helpdesk, pero tengo una incognita, al hacer esto el usuario administrador (el que viene por defecto) del equipo local va dejar de pertenecer al grupo administradores del equipo local? entonces si algun momento ese equipo pierde conectividad o tiene alguna falla por la cual no es posible conectarse al dominio, y nunca en ese equipo se ha logueado uno de los usuarios del grupo administradores que voy agregar, como haria para poder hacer algunas modificaciones con derechos administrativos sobre el equipo si esta fuera de la red?? ya que solo agregue como miembros del grupo administradores los administradores del dominio y grupo de helpdesk, en este caso que se podria hacer?? gracias. orlandop según está documentado, el administrador local no será sac

confused about VPN server in windows 2008. need help

through rras setup both nat , vpn server on windows 2008. using virtualbox, created 2 bridged network adapters. during nat server setup, asked interface public interface , choose 1 connects internet ip of 192.168.1.43 , private interface 192.168.4.2. i asked give own assigned range vpn clients. not sure about. ip range should assign? ip range of 1.43 subnet public interface or 4.2 subnet private interface? also when create vpn connection on client side, interface's ip address should connect to?   192.168.1.43 or 192.168.4.2? and on client computer, should assign specific ip address , default gateway or dns in nic adapter before connecting vpn server or not?   thanks i asked give own assigned range vpn clients. not sure about. ip range should assign? ip range of 1.43 subnet public interface or 4.2 subnet private interface? give range private interface. also when create vpn connection on client side, interface's ip address should connect to?   192.168.1.43