Showing posts with label server. Show all posts
Showing posts with label server. Show all posts

Monday, November 24, 2014

IT on the cheap: Dealing with resource attacks


In a perfect world the Internet would be free, nobody would want to steal your stuff and bad people would be too stupid to do any harm.

Alas, we don't live in such a blissful Utopia and have to deal with the seedy underbelly of a connected world.  As such if you're the guy managing servers and networks you have to be concerned about security.

It doesn't matter how deftly you can crank out pages of powershell commands if your network is under attack.  Worse, if you don't have the budget for the latest IDS (Intrusion Detection System) you're going to have to do some of the heavy lifting.

Thankfully, it's not that hard and while not the ideal scenario you can improve security even if your tools come from Ebay and Best Buy sales.

So take a look at the video below while I walk you through some basic security procedures and deal with an ongoing attack.





Tuesday, March 26, 2013

PC upgrade or replacement (nostalgia version)

The following is from my old website.  It's a little humorous in light of where technology is now and product cycles are much shorter.  Even though the article is 5 years old a lot of it is still relevant.

Enjoy a bit of geek nostalgia!



March 2008


The question of upgrade or replacement.

Could it be the software?

Often times I’ll be working on a project at a client’s site and will be asked to look at a pc that just doesn’t seem to be working as well as it used to.  In almost every case the primary complaint is poor performance with reliability issues running a close second.

When I spend some time with the afflicted “patient” I often find the performance issue has less to do with the hardware and more to do with an errant application or overdue maintenance tasks. 
In many cases the offending pc can be restored to acceptable performance by performing simple maintenance tasks such as defragmenting the hard disk, applying operating system and application updates and removing unused applications that load a portion of themselves into memory but are never used. 

Many Internet security suites are guilty of this behavior.  Perhaps you bought the security suite to protect you from spyware and virus infection but ended up getting extra pop-up blockers and search toolbars that you either didn’t need or didn’t use.  They’re installed and enabled by default and will use memory and slow performance.  This will be more evident on pc’s with less powerful processors and smaller amounts of RAM.
At this point you may be asking, “What does this have to do with upgrading or replacing my pc?”  The answer is that software issues can often appear as a hardware problem.  Often just addressing maintenance and software issues can return a pc to better than new performance.  This is especially true if there are applications present from the original pc manufacturers configuration.  This is a common practice and these applications can eat up system resources unnecessarily.

I recently had just such an issue with a brand new pc preloaded with extra applications that would never be used in a business setting.  One of these was a proprietary encryption program that the client neither wanted nor needed;  even worse, this application used 25% of the processor’s resources! 
The net effect was to make a brand new pc act like one with a serious hardware issue.  Removal of the extraneous applications greatly improved system performance.

It’s not the software…

Ok, so we’ve gone through the pc, got rid of all the extra software clutter, updated all your programs, defragmented your hard drive and tweaked settings in the operating system.  “Great! Now we’ve done all that and it’s still too slow!”

Now comes the question of whether a business pc should be upgraded or just replaced.

The criteria for making this decision should include the age of the pc and your current and future usage. 
The short answer is that if the pc is over 3 years old it’s best to replace it rather than attempt an upgrade.  The lifecycle for computer hardware is still very short and often parts availability for an older pc can be limited.  These parts can be quite expensive especially when the hardware was based on a platform that was only available for a short period of time such as INTEL 850 chipset based pc’s using the RAMBUS memory platform.  Once the industry moves on to the next hardware platform, the previous platform will be abandoned rather quickly by parts manufacturers.  

I recently had a client with an ailing 2 year old pc.  It had performed satisfactorily until recently when it began to exhibit reliability and response issues.  Finally this pc completely failed and would no longer boot.  Fortunately I was able to obtain compatible hardware to repair this pc but had this problem occurred 6 months later the outcome would have been much different.  In that case I would have advised replacement as the availability and cost of parts as well as the downtime caused by limited parts supply would have been more cost effective.  This pc was, in effect, on the cusp of the repair/replace trigger.

In a business setting it’s not uncommon to see a three to five year replacement cycle for desktop pc’s with shorter cycles for larger firms.  Most manufacturers offer one year warranties with longer terms available at an additional cost.  Rarely do these warranties extend past 3 years.  The reason for this has to do with the rate of technology change and the cost to the manufacturer maintain a service inventory on platforms that become relatively obsolete within one year’s time.  The computer industry has very thin profit margins and a business model based on having just enough inventories to process active orders.  The major players don’t want to maintain a large cache of inventory that they can’t immediately liquidate. 

Businesses know that after the warranty expires on a pc; the cost of repairing hardware issues can exceed the costs associated with replacement.  It’s more than simple hardware costs; it’s the cost of lost productivity from the end user as the problem is addressed as well as the cost of labor to deal with the hardware issue.  It’s far more cost effective to replace rather than repair or upgrade a pc in this case.

What works for a larger business doesn’t always work for a smaller one, however.  A larger business will usually have the capital to absorb the initial costs of hardware purchases over shorter periods of time.  Many times a larger business’s assets are depreciated over shorter periods of time than those of a smaller business.  Computer hardware tends to lose its value quickly and thus quickly erases any depreciation benefit past one year.  Couple this with potential costs mentioned earlier in this article and it’s easy to see the reason for the turnover.

What's different about a small business pc??

A smaller business may not have the luxury of short turnover periods and may choose to depreciate the cost of a new pc over a longer period of time.  In this case the best path is to buy as much pc as you can reasonably afford.  That means a better processor such as the Intel or AMD Dual or Quad core based processors ( Leave Single c
ore an
Semprons out of the mix as their presence in a configuration  indicates a low-end system), at least 2GB of RAM and a Hard disk at least 250GB (preferably 500GB or more) in size. 

For newer pc’s that will eventually run Windows Vista or Windows 7 a good mid level graphics card such as the current Nvidia GTX 250 or ATI 5650 is mandatory.  While thought of as mainstream gaming cards, these cards actually handle Microsoft Vista and Windows 7'’s 3D graphics capability much more effectively than any integrated graphics options.  Vista makes use of the 3D capabilities of these cards and can offload much of the image processing duties from the system processor.  While not the only Operating system option available it’s likely that any new pc in the near future will come pre-installed with Vista and applications expecting to make use of it’s more graphics intensive interface.

The advantage of buying as much pc as you can afford is of course having a faster pc and a longer depreciation period.  What you also gain is a bit more “future proofing” allowing the possibility of upgrades in the future as your needs change.  Changing the video card, adding memory and even processor upgrades are much more likely with the higher end configurations.  Manufacturer’s higher end pc offerings often use more robust system level components that are unavailable in lower end models.  This can help extend the useful life of the pc and may be offered with a longer warranty term.  The rule of diminishing returns still applies however and eventually any upgrade potential will evaporate.  

For a small business that time will likely occur in the 4th or 5th year due either to major hardware failure or requirements of a critical business application that the hardware cannot meet.
I should mention that there is such a thing as “too much of a good thing” when it comes to buying a pc for business.  Generally speaking, a well-equipped business pc should not exceed 1200.00 base price.  Extra network adapters, High End video cards, special paint jobs and the like do nothing for the business user.  On the opposite end of the spectrum a pc offered for 399.99 is likely to have insufficient RAM, a low-end processor and video system and offer disappointing overall  performance. 

As an example; I own three pc’s not counting my laptop. Two are used exclusively for my business and one is reserved for Saturday night recreation driving a virtual Ferrari ENZO around Hawaii J
The cost to build the gaming pc is within a few dollars of what it is going to cost me to replace my two production pc’s.  That’s because my business machines do not require the level of hardware of my recreational pc.  In fact the gaming pc would be overkill for anything but gaming and an inefficient use of resources.  That doesn’t mean I plan to have inferior hardware in my production rigs, quite the contrary.  My production pc’s are purpose built for the jobs I need them to perform.  Luckily those purposes don’t require the hardware expense of a dedicated gaming pc.

What about laptops?


For the most part many of the above rules apply but the time periods are much shorter.  Laptops are not designed to be long term and their design severely limits upgrade potential as well as longevity.  For business use most laptops are outmoded within 2 years with the only upgrade path available being RAM, Hard Drive and wireless adapters.  Some models do have modular video cards but these are generally reserved for the high end enthusiast market with little value for the business user.  Again, buy as much as you can afford but realize that after a few years items such as batteries, power supplies, keyboards and LCD displays will often fail.  Replacement can be costly and often more than the cost of a replacement laptop with the added frustration of poor parts availability and user downtime.

Final Word

The choice of upgrade or replacement of a business pc is governed primarily by practical factors.  Time is always a factor no matter what size the business.  Generally a pc that is over 3 years old that is no longer performing adequately for the applications installed should be replaced.  Often, the cost of upgrade will likely exceed the value of the pc and bring little or no improvement.  While many pc’s will function reliably after the 3 year mark; their viability will decrease as software places increased demands on hardware and replacement parts become scarce.
Your best option for upgrade of a brand name pc is at the point of purchase when the pc is new.  Often, hardware upgrades can be more economical when the system is initially configured than after delivery.

In troubling economic times it more important than ever to get as much as you can out of all of your business assets.  As with any purchase, the best value isn’t always the cheapest option.  I hope I’ve been of some assistance.  Feel free to contact us if you’d like assistance with this or any other IT need.


        

Wednesday, January 23, 2013

Is it a Role or a Feature?




I had an interesting experience today.  Without boring you with the details let's just say I'm no richer for the experience save for providing the catalyst for the following instructional tidbit.  The catalyst in this case was a question posed to me.  I was asked what the difference was between a Role and a Feature when configuring a Windows server.

Now most of you who have any experience at all in Windows Administration may not necessarily be comfortable with the concepts of Server Roles and Features.  It's been a slow but steady evolution from an abstract label to a shortcut in Server Manager. 

Since Windows 2000's introduction of Active Directory, the concept of a server role took on new meaning.  Instead of being limited to just designating a server as a Primary or Backup Domain controller now we had multiple roles that made the old labels moot.

Yeah, I'm talking about the most confusing collection of server "Roles" ever introduced to the Windows Universe, the FSMO or Flexible Single Master Operation.  5 labels that have confused Windows Administrators for a decade. 


I mean, the PDC emulator is fairly intuitive, for example.  We know what that's for right?  Well only partially because that role handles a lot more than just  Primary Domain Controller services for Windows NT (non AD) networks.  It also provides Time synchronization, Group Policy replication, and account lockout and password change services for an entire windows domain.  If the server that holds this role fails you're going to have a very bad day until you move it to another server.

Relative ID master?  All that does is keep all the names on your network unique.  It's function is to keep combining computer or user object Identifiers (SIDS) with a pool of unique Identifiers managed by this role (RID)  Combining the two values ensures that no two objects on an AD network are alike even if everything else about them is the same.  The RID master can't allow its pool of RIDS to go empty or it won't have anything to combine with the new SIDS that come from a new user or computer account.  Yeah, that's real obvious.


How about the Infrastructure Master?  It's a role and its function is... uhh...Oh yeah, it makes sure that if someone from one domain gets rights to something in another domain their specific information is recognized properly.  How come such a serious sounding name for such a tiny function that's so rarely used?  Whatever..

Those three roles are considered the "Domain" roles in Active Directory networks.  That means they only affect the immediate domain they serve.  There are two other roles that are considered Forest or Enterprise level roles.  That means they live at the top of your AD network above all the domains (assuming there's more than 1) that branch off of the "trunk" of your "forest". 

In case all this talk of Directories and Forests is confusing try a different metaphor.  Think of AD in the context of a Phone Book instead of a forest.  You usually have one Phone book for a town and it contains all the names and numbers of the people with phones.  Those names and numbers can be thought of as domains.

Now say your aunt Bessie changes her phone number.  The phone book is going to need to be updated to reflect the change or she'll be very lonely because nobody will be able to call her anymore.  That would be sad for Aunt Bessie and nobody wants that!

If the phone company decides to change the area code for your town then all the people listed in the phone book have to tell their out of state relatives what the new area code is or they won't be able to call them anymore.  Changing the area code, by the way, would be considered an enterprise event to the people listed in the phone book.  So would changing the name of the town by the way. 

It's the concept of changing names within an organization that leads us to the first of the two "Forest" or "Enterprise" level roles in Active Directory.  Coincidentally, it's called the Domain Naming Master and the simplest way to explain its role is to refer back to our theoretical phone book. 

Remember when Aunt Bessie changed her number?  Well she's a spry old gal and decided to get hitched up to a nice older gent.  That meant her last name changed.  To make sure everyone can find the happy newlyweds we'll need to get the phone book entry updated.  To accomplish that, she had to call the phone company and ask them to change it.  The phone company is responsible for changing Bessie's name in the phone book and they are the only ones that could do it.  If the phone company is closed nothing changes just as no domain names throughout the enterprise can change if the Domain Naming Master goes offline.

The second and final enterprise FSMO role is easier to understand since its name is a little more descriptive than the others.  It's the Schema Master and if you have any experience with databases its function will be instantly recognizable.  If you remember that all the information in Active Directory is stored in a database then you know that something has to control the way its organized.  That's the function of the Schema Master along with copying (replicating) any changes that occur to the Schema to the rest of the Enterprise. 
Going back to the phone book example, the Schema Master would be the guy who decides how the phone book is going to be organized.  Will it be sorted by name or phone number? How much information will each listing contain?  These questions are all answered by the guy printing the phone book.  He is the Schema Master.

Ok maybe not so dramatic but the Schema Master is an important Role.  Without it Active Directory couldn't exist.

I've actually went a bit deeper into FSMO roles than I planned but it's important information.  It's also important to know how Microsoft tends to overload their terminology.

In the previous discussion I've laid out what Microsoft defines as a "Role" in the context of functions that support Active Directory.  There's another definition of a server role, however, that has nothing to do with supporting Windows but rather defines services for users. 

You may have noticed that I haven't said much about "Features" to this point.  That has everything to do with Microsoft's overloaded terminology again.  In the context of an FSMO role a feature is nothing more than a facility for management of a given role.

In the context of a Server Role, however, features become very important.  A Server Role in Windows 2000 and later is designated set of services that support user activities.  Examples are File and Print services, Application Server and DNS Server roles.  Each of these roles is task based defining a set of services to be offered to users by the server. 

Server Roles can be viewed more as containers than mechanisms.  They are comprised of programs and services tailored to the support of the role.  Features are usually the programs and services that provide the functionality of the role.  Think of it as the option list on a new car.

A new car has one role, to provide transportation.  It's price, however, is dependent on the number of features it has.  A base model won't have as many amenities but will still satisfy the core requirement to provide transportation.  Many times you can specify additional equipment to tailor its function to better match your needs.  This affords additional functionality or "Features" without affecting the core requirement of providing transportation.

It's really that simple.  Roles define a task and features support it. 

That's about enough, I really don't want to write the word "Role" anymore..
:-)

Tuesday, October 16, 2012

Monday, October 15, 2012

Hangin' with Server 2012

I've done a couple of introductory videos just so you can see what it's like to get around in Server 2012.  That means learning to use the interface, basic administration, adding roles and basic AD setup.  If you've managed a 2008R2 deployment 80% is the same but there are a few differences to take note of.  Check it out below.

Enjoy!

Part 1



Part 2




Thursday, March 8, 2012

Windows Server 8, Microsoft's Attempt at a New Server Paradigm

Article first published as Windows Server 8, Microsoft's Attempt at a New Server Paradigm on Technorati.


Server operating system releases rarely garner much excitement outside of IT circles.  They are the necessary evil coordinating all or our messaging, file handling and online services vital for networked world.  Even if you don't spend your days in a cube for a living and prefer to store your files in the cloud there is a server somewhere making it all possible.

As such they tend to not be very sexy.  In the case of Microsoft, most server operating systems appear on the surface at least to be a stripped down purpose built version of their desktop counterparts.   At their core they are with some important differences..  The primary differentiation is that they've been optimized for better storage, memory handling and security.

Which leads us to the latest offering from Microsoft, Windows Server 8. 

Windows Server 8 Beta was released to the public on March 1st, 2012, one day after the Windows 8 consumer preview.  Hardware requirements are as follows:

Processor - Minimum: 1.4 GHz 64bit processor

Memory - Minimum: 512 MB RAM

Available Disk Space - Minimum: 32 GB

Optical Drive DVD-ROM drive

Display and Peripherals - Super VGA (800 x 600) or higher-resolution monitor

 Keyboard

 Microsoft Mouse or other compatible pointing device



Upgrade paths from Server 2008 R2 are supported with other versions of  Server 2008 allowed for the Beta release.  Microsoft makes available a 64Bit ISO and a VHD (Virtual Hard Disk) file as the installation media options.   The VHD option assumes at least Server 2003 and Microsoft Virtual server 2005 (Hyper-V).  VMWARE test installations would likely be better served by mounting the ISO as the install medium for a new VM.

As with all Beta installs, Server 8 should only be deployed in a test environment as there is no installation roll-back functionality.

There are two installation options, Server core which offers little more than a powershell window and a GUI version which adds a system manager applet similar (if not a bit gaudy) to the Server 2008 system manager.  In my use the Server Manager is functional but counterintuitive due to the haphazard  organization of the applets.  As an aside it's not very attractive either, looking much like one of those bad Powerpoint slides we've all had to suffer in a sales meeting.


Microsoft has stated that they want to move away from GUI administration tools on the actual server and instead manage server resources remotely.  That would explain the prominence of powershell and the GUI as a now secondary option for installation.

Microsoft has also touted is Hyper-V version 3.0 as a real challenger to the virtualization space currently dominated by VMWARE.  The new virtualization framework touts better support for more physical CPUs, larger storage volumes and larger RAM sizes.  Improvements in SAN performance are also claimed utilizing ODX (offloaded data transfer) which basically sends commands to the SAN directly instead of attempting to read and write data as though the storage were local.  Hyper V virtual machines are also said to support up to four virtual Fiber channel Host Bus Adapters.

Improvements to Hyper-V may be of most interest to IT departments with complex Hyper-V deployments who will appreciate support built into the management GUI.   Hyper -V also supports a new feature called  Hyper-V Replica which can be thought of as a kind of VM failover mechanism utilizing two Hyper-V VM's that are constantly kept updated. 

Improvements in Microsoft's Web Server, IIS and Remote Desktop services (Terminal Services) are also included with this latest release but what may be most striking has little to do with the dry technical stuff.  Server 8, like it's desktop cousin, has inherited the Metro Tile interface.

You'd be hard pressed to tell the difference between Microsoft Server desktops at a glance from Windows 2000 on.  Aside from tweaks to the start button they generally don't include the flash of their desktop counterparts and as such are fairly plain.

Not so with Server 8.  The Metro Tile interface has replaced the Start button/menu and includes tiles to manage the basic functions of the server.  Additional administrative tiles are available by enabling the option giving you access to most of the familiar tools any Windows admin would recognize. 

At first blush this seems like a pointless addition and more than one IT peer has balked at it especially in light of Microsoft's desire to move away from graphical interfaces.  Take a moment to consider the minimalist strategy Microsoft is now promoting, however and it makes sense. 

The desktop in Windows 8 is little more than a convenience primarily existing for backward compatibility for applications that require it.  Desktop  based applications can create a tile in Metro but will launch on the desktop instead of directly from Metro.

With the Metro tiles, senior administrators now have more control over the level of administration they allow to junior staff.  With virtually all aspects of the operating system controllable via Group policy it's not inconceivable to lock junior IT staff into only those functions they need to have with no opportunity to circumvent their limited access. 

Microsoft has not yet set a release date for Server 8 but it's likely that it will be within a few months of the desktop OS release.  Does that mean that Server 8 will replace current installations overnight?  That's unlikely considering that many companies are only now moving to Server 2008 R2 as legacy applications catch up to embrace 64 bit platforms.  In my own experience, there's generally a 2 year lag before a new server operating system starts to gain significant market share over its predecessors.  The most likely driver will be the improved virtualization for companies looking to move from VMWARE and improved resource and access management functionality.

Time will tell if Server 8 is embraced as many IT organizations chose to ignore the last Microsoft server  release,  For many IT organizations Server 2008 offered no real advantage over Server 2003 other than better 64 bit hardware support.  Many organizations also choose to skip versions which may translate into better adoption of the new server OS for IT organizations still using Server 2003.