Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
vty
Nov 8, 2007

oh dott, oh dott!
Anyone dealt with rolling out SCCM/SCVMM to a pretty old and stable 2k3/2k8 forest? I'm curious if any issues tend to arise when dumping it into a rolling environment. (Yes, yes, I should be testing)

Adbot
ADBOT LOVES YOU

vty
Nov 8, 2007

oh dott, oh dott!
I'm very interested in the Kase review also, if you don't mind.

vty
Nov 8, 2007

oh dott, oh dott!
I ran away screaming from the SCCM install. The pain of configuring it wasn't worth it in a small (300 cloned computer) environment.

I'd definitely go with it if I had user groups with various PC images, things of that nature.

vty
Nov 8, 2007

oh dott, oh dott!

Wicaeed posted:

Isn't that what File Screens are for in the first place? Prevent users from saving .wav .mp3 .flac .mp4 files, voila!

I thought file screens would be an absolute god send until I rolled them out and realized that they aren't (IIRC) user based ACLs at all, but are instead folder\share based. Meaning the CEO has the exact same limit to \importantcrap\ as the janitor who uploads all of his Itunes mp3s.

I wound up never using it to do anything but report because it became a headache.

vty
Nov 8, 2007

oh dott, oh dott!

Wicaeed posted:

So what is going to be the best way for me to remove 3 network printers from about 30-40 user accounts?

We are in the process of commissioning a new print server, and are rolling out the new printers via Desktop Authority. We want to make it so that any old printers hosted on our old print server are removed from the users computers, but I haven't found any way to do this in Desktop Authority (yet).

Suggestions?

Depends on how it was added;

Via share;

@Rundll32.exe printui.dll,PrintUIEntry /dn /q /n"\\server\printersharename"

Via printer name;

@Cscript.exe //nologo //b "%windir%\system32\Prnmngr.vbs" -d -p "\\server\printer name"

vty
Nov 8, 2007

oh dott, oh dott!
What are you folk using for network management in 2013? I'm sure SCCM will be pretty common, but what else, has anybody recently compared PRTG, OpManager, Orion, and whatever else I've left off?

Not too interested in a roll my own wheel scenario (mrtg, nagios, zabbix, etc) as we've got a budget specifically for this.

vty
Nov 8, 2007

oh dott, oh dott!

dotalchemy posted:

You'll need to be a lot more specific with what your scope and requirements.

What are you trying to implement? What functionality or features do you require? What problems are you trying to fix? I'm assuming by saying Network Management and then immediately listing SCCM as being common that you actually mean Windows client management? Or do you want monitoring, as you list Orion, or network entity management?

Figure out the scope and the functional requirements (or at least state them), then start looking at pieces of software.

I'm asking what people are using to monitor their environments- performance degradation, server/network outages, latency, etc. I derped out and got SCOM mixed up with SCCM.

Essentially I'm comparing Orion, ManageEngine, PRTG all of which take a pretty incredible amount of time to configure- would like to know if anyone has compared the recent versions of these and other products I'm missing in their environments.

I don't need something that actually manages deployment or updates, or anything of that sort. I code Puppet stuff when that's necessary. Just need a damned good monitoring tool.

vty
Nov 8, 2007

oh dott, oh dott!

Docjowles posted:

We use Nagios, collectd (check_mk on Windows hosts) and Graphite. Given that your preferred solutions still "take a pretty incredible amount of time to configure" I'm curious why you dismiss free and ubiquitous tools like Nagios out of hand. Yeah it will take time to configure and get it right, but so will basically anything. I'm not aware of a silver bullet autodiscover tool that actually works well enough to save time, though I'd be glad to learn about it!

Especially if you're already using Puppet, which has tight integration with Nagios out of the box. Having hosts automatically register themselves with Nagios when they come up and delete themselves when you kill it off again is pretty rad.

Edit: Zabbix is more all-in-one, but last I used it the UI was an abomination and it was a LOT of work to configure, more so than Nagios.

I've deployed plenty of Nagios/mrtg/cacti, etc setups (I design datacenters/webhosts/SAAS infrastructures). I've really never been impressed, and I have a great budget so it's not worth the effort to spend a month getting everything going. When I say the other NPMs "take a pretty incredible amount of time to configure" I don't mean even 1/100th of the amount of time to configure Puppet/nagios/etc. It's more of a matter of grouping service/application priorities, things of that nature. I spend most of my time coding manual procedures when I deploy the usual nagios/puppet/chef stuff.

Anyhow, this conversation is better off in a non-Windows thread, so I'll take it to the IT thread.

vty fucked around with this message at 16:54 on May 8, 2013

vty
Nov 8, 2007

oh dott, oh dott!
I need a sanity check.

I've got a forest with multiple domains. Two of which have a one way trust (prod1, prod2).

We've recently been deprecating the prod2 and moving everything to prod1.

The method to the madness was;

1. Remove all servers from prod2 by switching them to a workgroup
2. Rejoin all servers to prod1
3. Test logins, walk away, sip tea

What I'm experiencing now is that the servers were never fully removed from prod2 (still in ADUC), this is causing (and this is whats confusing me the most)-

1. Kerberos errors (eventid 4, kerberos) which is basically a duplicate entry error
2. The servers can't access prod1s sysvol now (due to said kerberos error)

So I'm sure I just need to remove them from PROD2 completely, although I may need to remove them from prod2 and prod1 and then rejoin them again to prod1.

What I'm not understanding is this- the servers were in separate domains?! Why would duplicate server entries with different ending suffixes (server01.prod1.com, server01.prod2.com) matter? Apparently whatever is currently going on I CANNOT have any objects between the two domains that have the exact same hostname- and that is baffling me.

Adbot
ADBOT LOVES YOU

vty
Nov 8, 2007

oh dott, oh dott!

Bob Morales posted:

What's the recommended book for Windows server? Something that covers AD and GPO and bonus points for getting into WSUS and other stuff. I've been away for two years and am not really sure what all has improved or changed since Server 2003.

Typically the "Inside Out" books if you don't want to bore yourself with an entire MCP/MCITP course.

http://www.amazon.com/Windows-Server-2012-Inside-Out/dp/0735666318/ref=sr_1_1?s=books&ie=UTF8&qid=1371828037&sr=1-1&keywords=windows+server

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply