Quantcast
Channel: Small Business Server forum
Viewing all 8539 articles
Browse latest View live

SBS 2011 and external mail addresses with the same domain name

$
0
0

We have a SBS 2011. POP3 is used for mail connection and a smarthost for SMTP. We now have several external users with no internal AD account, however they should receive emails sent toalias@mycompany.com (internally & externally).

Emails sent from external addresses is not the problem, simply no POP3 connector account for such users in Exchange and they setup their mail client with the relevant POP3 credentials. However, what about users within the AD Domain, who want to send emails to their external colleagues? How do we setup Exchange to look internally for the user, and if not found send onto the SMTP smarthost without send a NDR. We thought about creating contact records for all these external users.

Thanks for your help with this one.

Regards, Oliver


Migrate Windows Small Business Server 2011 Standard from Windows Server 2003 Standard?

$
0
0

Hi everyone,

Is it possible to migrate SBS 2011 in a Server 2003 environment? Will I have to decommission existing domain controllers or will SBS 2011 coincide with existing DC's?

Thanks for the help, Rick 

Multiple security audit failures a second

$
0
0

A client's SBS 2011 machine is experiencing multiple audit failures a second and we believe it is diminishing the performance of the machine. We can't seem to find the source or how to remedy the issue. It its happening way too fast to be a human trying to login. 

Keywords Date and Time Source Event ID Task Category
Audit Success 6/18/2014 1:50:32 PM Microsoft-Windows-Security-Auditing 4905 Audit Policy Change "An attempt was made to unregister a security event source.

Subject
Security ID: SYSTEM
Account Name: SBS$
Account Domain: <ommited from forum post>
Logon ID: 0x3e7

Process:
Process ID: 0x10d4
Process Name: C:\Program Files\Windows Server\Bin\SharedServiceHost.exe

Event Source:
Source Name: ServiceModel 4.0.0.0
Event Source ID: 0x262070f0"
Audit Success 6/18/2014 1:50:32 PM Microsoft-Windows-Security-Auditing 4904 Audit Policy Change "An attempt was made to register a security event source.

Subject :
Security ID: SYSTEM
Account Name: SBS$
Account Domain: < ommited from forum post >
Logon ID: 0x3e7

Process:
Process ID: 0x10d4
Process Name: C:\Program Files\Windows Server\Bin\SharedServiceHost.exe

Event Source:
Source Name: ServiceModel 4.0.0.0
Event Source ID: 0x262070f0"
Audit Failure 6/18/2014 1:50:32 PM Microsoft-Windows-Security-Auditing 4625 Logon "An account failed to log on.

Subject:
Security ID: SYSTEM
Account Name: SBS$
Account Domain: <ommited from forum post>
Logon ID: 0x3e7

Logon Type: 3

Account For Which Logon Failed:
Security ID: NULL SID
Account Name:
Account Domain:

Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc0000064

Process Information:
Caller Process ID: 0x24c
Caller Process Name: C:\Windows\System32\lsass.exe

Network Information:
Workstation Name: SBS
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Schannel
Authentication Package: Kerberos
Transited Services: -
Package Name (NTLM only): -
Key Length:0

Subject
Security ID:SYSTEM
Account Name:SBS$
Account Domain:<ommited from forum post>
Logon ID:0x3e7

Process:
Process ID:0x131c
Process Name:C:\Program Files\Windows Server\Bin\SharedServiceHost.exe

Event Source:
Source Name:ServiceModel 4.0.0.0
Event Source ID:0x26206ef4"
Audit Success6/18/2014 1:50:32 PMMicrosoft-Windows-Security-Auditing4904Audit Policy Change"An attempt was made to register a security event source.

Subject :
Security ID:SYSTEM
Account Name:SBS$
Account Domain:<ommited from forum post>
Logon ID:0x3e7

Process:
Process ID:0x131c
Process Name:C:\Program Files\Windows Server\Bin\SharedServiceHost.exe

Event Source:
Source Name:ServiceModel 4.0.0.0
Event Source ID:0x26206ef4"
Audit Failure6/18/2014 1:50:32 PMMicrosoft-Windows-Security-Auditing4625Logon"An account failed to log on.

Subject:
Security ID:SYSTEM
Account Name:SBS$
Account Domain:<ommited from forum post>
Logon ID:0x3e7

Logon Type:3

Account For Which Logon Failed:
Security ID:NULL SID
Account Name:
Account Domain:

Failure Information:
Failure Reason:Unknown user name or bad password.
Status:0xc000006d
Sub Status:0xc0000064

Process Information:
Caller Process ID:0x24c
Caller Process Name:C:\Windows\System32\lsass.exe

Network Information:
Workstation Name:SBS
Source Network Address:-
Source Port:-

Detailed Authentication Information:
Logon Process:Schannel
Authentication Package:Kerberos
Transited Services:-
Package Name (NTLM only):-
Key Length:0


Jerry T




Recovering SBS 2011 on a failing Raid 5 system

$
0
0
I have a single server with SBS 2011 that was never backed up - don't ask I am not the onsite IT guy. It has a RAID 5 config., however, two drives (RAID 5 H700 Dell SAS controller)have now been marked as pending failure. Dell says I must delete RAID array, replace the drives, rebuild raid array then reload operating system. They said I could not just Back up the server (it is still running and there are no issues - that I know of) because the restore on the new array will still be corrupt. Can I restore or do I need to rebuild from scratch? Can I back up Active Directory and restore? Can I backup Exchange 2010 and restore? or do I need to just install operating sys and re configure everything? any help on restoring backup or tricks to restore config after reinstalling operating system would be greatly appreciated. It may mean the difference in customer running on Monday with email and user access and not. Help!!!

Where in Group Policy (or anywhere else) is the Port for outgoing email (SMTP Server) defined?

$
0
0

SBS2003, SP1. 

When I open the firewall applet in the control panel, and open the settings for the WAN connector, the box for the Internet Mail Server (SMTP) is checked.  I try to edit the settings and the Port is greyed, the value is 25, and I cannot change it.  Various help pages suggest that I can't edit the port number because it is controlled by some group policy.  However, I have been through the group policy manager and cannot find anywhere that a port number is set.  The question becomes Where is the port number set for the Internet Mail Server (SMTP)?  Is it a Registry Key?

I have achieved outgoing email by adding a Port exception with the needed port number.  I also put in a custom scope, but another help file said that wasn't particularly useful, because the bad guys could just spoof the IP address.  I would be nice if I could just specify that it is a one way, outgoing, exception.  Is there a later MS firewall, that does this, and that can be downloaded (and used on SBS2003, SP1) ?

Bare metal restore after losing a backup drive.

$
0
0

I am currently backing up my SBS2011 server using the backup program that comes with SBS2011.

I originally used 4 Seagate usb drives to perform the backups and rotated once a month. I then decided that if I lost the current backup drive at the end of the month I would lose too much information. I added 4 more Seagate usb drives and now I rotate between the drives every week.

I noticed that when I used one of the new drives for the first time the backup completed very quickly. Since it only backups what is new or has changed this would seem correct. However, it leads me to believe that if I lose the first drive that I used to back up the server which contains all files I will not be able to perform a bare metal restore (complete image restore) of the SBS 2011 server if I had a catastrophic failure.

Am I correct and if so, what do I need to do in order to be able to perform a bare metal restore when I lose the first drive or any one of the 8 drives that are being used as a backup device?

Thanks

sbs2003 does not redirect external users to correct website on a member server

$
0
0

I have both an SBS2003 server with MOSS2007, and on a second server box, I've installed an additional domain controller (Server 2008 R2) w/ DNS, IIS7, and SharePoint Server 2010.

Internally, I can visit http://MOSS2007 (example) orhttp://SPS2010 (example) from any device on the network and it takes me to the correct website on the first or second box, respectively.  I can also visithttp://MOSS2007.domain.com (example) orhttp://SPS2010.domain.com (example) with no problems.

Externally, I can visit http://SBS2003.domain.com (example) and get the "welcome to small business server" webpage.  I can also visithttp://MOSS2007.domain.com (example) and visit the first server box with no problems.  However, visitinghttp://SPS2010.domain.com (example) simply shows the "welcome to small business server" webpage.

I can't figure out why SPS2010.domain.com won't display properly to external users outside the network.

Any help would be greatly appreciated.

 

Remote Desktop timing out often.

$
0
0
We are running server 2008 R2 Standard.  Just recently, after logging in to remote desktop it times out every couple of minutes.  It's worked fine for months.  It will lock screen then come back after about 30 seconds. 

SBS 2011 Configured Manually Instead of Using Wizards, Some Things not Working.

$
0
0

Has anybody had any experience remediating an SBS 2011 Standard server that has been manually configured instead of using the wizards?  

I've inherited a 3-year-old SBS 2011 Standard installation that is behaving like a Domain Controller, file, and Exchange server, but has been left with a lot of the roles like Remote Web Access and Sharepoint, just barely functional if at all.  Now that the client knows that these features are available, naturally, I have been tasked with getting them going.

My hope is that I'll be able to go in and manually reproduce/repair the configurations that the wizards normally would do, so that I will eventually have an SBS box that behaves like an SBS box; such as adding machines/users through the Console application, quick and easy cert updates, etc.

My concern with just running or re-running the configuration wizards is that things like the internal domain name (which does not match the external domain name) will simply break and I'll loose a lot of data and/or security associations.

Any links to step-by-step checklists, "gotcha's" and their workarounds, or "DO NOT PUSH THE GIANT RED BUTTON!"-like warnings, would be extremely helpful.  

Thanks!

migration mode

$
0
0

is migration mode only for other sbs editions?

will it work going from server 2003 standard to sbs 2011?

Outlook login screen pops up

$
0
0

Hi, I have SBS 2011 and recently I manually changed certificate to UCC certificate. My impression is that from then most of the laptops that are not in the domain have similar issue.When outlook is opened, log in screen keeps popping up. The connection state is connected to the microsoft exchange even if you press cancel. Domain joined pc doesn't have this issue.

Can you please advice. The certificate I installed was not generated by SBS, but by Lync edge server. So I imported certificate to personal store, I did binding in IIS and exchange to use this certificate. I can connect to OWA, use ActiveSync, RWW... I can see that newly imported certificate is used. 

Migration of SBS 2008 to new harware

$
0
0

Hi all,

We have a SBS 2008 + exchange 2007 running on a MSI  mobo for 5 users, this works fine, only the capacitors are degrading and we need to move over ASAP.

We followed the described steps and restarted the migration from backup 8 times now..  last attempt was with answerfile in attended mode, this made us get through, but!!  in SBS console we get "terminal services not installed" and all manual attempts fail, also "cannot install exchange server 2007" even it appears its installed (but not correct ?), beside several solutions on the internet, the Microsoft proposed solution is to call Microsoft product support.  Also we cannot configure domain name, even internet is connected...  and we are only on page 22 of the 61 page book for migration :-)

is there anyone with similar problems and got exchange and the other setup working, with the move of mailboxes?

is there another way to get around this, as its only for 5 users?

thanks in advance

Walter

SBS 2008 Server Backup Issues

$
0
0

Starting in April my Windows Server Backup jobs have been failing with the error message "The request could not be performed because of an I/O device error."

I am backing up to a NAS target using ISCSI with the Windows Server Backup tool. SBS 2008 fully updated on a VMWare ESXi host.

I have a NAS which is sharing an ISCSI drive to Windows Server. This has worked for over 3 years without issue. The backup fails at 91% complete

The event viewer output is available here. http://pastebin.com/25aQYxk4

vssadmin list writers lists no errors and chkdsk completes successfully. I have tried expanding and shrinking the volume per Technet support.

Event logs report "backup started at 3:00AM failed with the following error code ' 2147943517'".

Any ideas?

Surface tablet that does not support RWW

$
0
0

One of our clients said “Surface tablet that does not support RWW and does not allow ActiveX”. My Windows 8 Pro works fine, but I don't have Surface to test it. Can someone confirm that? If yes, what’s the resolution?


Bob Lin, MVP, MCSE & CNE Networking, Internet, Routing, VPN Troubleshooting on

http://www.ChicagoTech.net

How to Setup Windows, Network, VPN & Remote Access on

http://www.howtonetworking.com

Remote Web Workspace Certificate Error

$
0
0

We have been running SBS 2008 for five years or so and RWW has been working without problems.  We've recently had a problem where the remote websites are showing a certificate which is not present on our SBS installation.  

If logging on internally then the certificates are correctly assigned to remote.mywebsite.com but when trying to log on externally the certificates show as being from debian_lenny nothin g to do with our site.

I've tried generating new certificates and check the correct bindings are present in IIS and terminal services.  Any idea how I clear these rogue certificates?


connect to network drive with SBS2008

$
0
0

Hi,

i have the following problem on my small bussines server 2008.
I have a network drive that i use to store my backup. since a week ago my sbs2008 won't map the drive anymore.
I can ping my drive with no problem and if i use a windows 7 on the same network i can see my network drive.
To map my drive i do start - run - \\ip-adress of the network drive. So on other computers in the network i can see the folders on my network drive but not on my SBS2008. I've tried restart the workstation sevice with no luck. also restarted the network drive with no luck.
I think the problem came up when i removed my network teaming on the server because of a problem with a network interface.
So now i use one network interface with static ip on. Maybe this is why the problem occurs.

i also tried to put the ip adress of the drive into my dns setting on the NIC but also with no luck.
Does anyone also had this problem or anyone can help me?

Thanks in advance.

SBS 2011 suddenly has failing ADUC/Exchange seemingly related to LDAP

$
0
0

Within the last week definitely, not sure the exact day, our SBS 2011 started behaving badly (it has been in continuous operation for almost 3 years).  I only noticed the issue when I had to add a user to a group. I logged into the SBS, with a Domain Admin Account, to make the change. I could not connect to the ADUC MMC nor could I use the Server Console (which sucks and fails constantly BTW). Consequently, Exchange is also having issues, although almost all of the Exchange functionality still works (albeit sporadically), except for backend management.  Basically the error states that the server is not operational when it is.

So, I rebooted the server, now on my third try.  The Event Log is not showing anything in particular, but maybe I'm not digging far enough.  When I try to run a DCDIAG (a full test from the DC I normally run it), I get the error 81 message.  When I do a DCDIAG check to make sure it can connect and see the folder shares, it can.  I looked in DNS and everything appears OK.  ADSI Edit runs fine, my secondary DC runs fine.  The Firewall is allowing the required ports (both the Win Firewall, which is off, and the Trend Firewall, which is on)  I meant to check on the replication status on our secondary DC, but failed to do that, but will update when I get that info.

Services are all running, and even when I select to connect to a different DC, the failing DC does show up in the list as Online and is selectable.  Once selected, ADUC fails again.  Best Practices analyzers fail because it cannot connect to the DC.

No changes have been made to the infrastructure for over a year except for deploying TFS about 6 months ago.  The server is regularly updated every 2 weeks and reboot.  The only other 3rd party updates that may have happened on my last update day would be the Backup Exec Agent, but I don't think that would have caused this (but maybe).

Any ideas would be greatly appreciated, this is a head scratcher for me.  Everything indicates that things should be operating within normal parameters. 

OWA worked fine for 18 months. How comes it doesn't now without a public DNS A record and HTTPS port forwarding on my firewall?

$
0
0

So here's a puzzler...I understand why you SHOULD need an A record for remote.yourdomain.com in your public DNS; and I understand why you should port forward HTTPS/443 through your firewall, so that folks can reach https://remote.yourdomain.com/owa, but how comes we haven't needed either (SBS2011 server came online 18 months ago) until someone inadvertently moved us from our regular DNS provider to a new one a couple of days back?

I moved us back to our regular provider again within the hour, but ever since OWA refuses to work (except internally) without both the DNS pointer and port forwarding in place.

I don't mind that we need to have both these things in place, it's just that I'm at a loss to understand why we haven't need them all along. In fact, I remember being somewhat surprised that OWA worked as it did, but put it down to the folks at Microsoft being very clever indeed! Any ideas?

Under SBS 2011 Can Windows 8.1 block group policy

$
0
0

All users in our office run a login batch fike  when logging on to our SBS 2011 domain. We just purchased a new Windows 8.1 pc. The batch file creates mapped drives for the user. Is there any reason why since the user switched to the new 8.1 and is not having the drives mapped?

I am assuming that our group policy to run the batch file attaches to the user mapped drives not specific to the PC OS.

Thanks,

Terry

Migration from SBS2003 to 2012 Server Essentials *SAME HARDWARE* (with a member server already installed)

$
0
0

Hello,

My client has the following set up.

HP ML350 G5 running SBS 2003 R2 std and one 2003 SVR as a member server.

Exchange 2003 has been obliterated (we have moved mail to Office 365).

Client wants to install 2012 Server essentials on the HP server over the SBS installation.  ( I have warned him several times that I am not convinced it will work, but he is insistent that we try!)

My theory is this:

1. DCpromo the member server to a DC, GC and transfer FSMO roles.

2. At this point migrate the domain as per: http://blogs.technet.com/b/sbs/archive/2012/08/24/migrating-to-windows-server-2012-essentials.aspx and install 2012 SE in migration mode on the sbs 2003 server (upgrading BIOS etc), preparing the newly promoted 2003 server as though it is the SBS 2003 server.

Has anyone tried this? Are there any obvious pitfalls that I am not seeing?

Thanks

Ben Schneider


Viewing all 8539 articles
Browse latest View live




Latest Images