<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>BFTech Impressions</title>
	<atom:link href="http://blog.bruteforcetech.com/index.php/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.bruteforcetech.com</link>
	<description>Here you will find nuggets of information about various technologies that I am working with and learning about.</description>
	<pubDate>Wed, 10 Mar 2010 18:11:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Possible workaround when your ESXi server runs out of space on the datastore</title>
		<link>http://blog.bruteforcetech.com/index.php/archives/489</link>
		<comments>http://blog.bruteforcetech.com/index.php/archives/489#comments</comments>
		<pubDate>Wed, 10 Mar 2010 18:11:15 +0000</pubDate>
		<dc:creator>Paul Sterley</dc:creator>
		
		<category><![CDATA[Backup and Restore]]></category>

		<category><![CDATA[ESXi]]></category>

		<category><![CDATA[Hardware]]></category>

		<category><![CDATA[Hyper-V]]></category>

		<category><![CDATA[datastore]]></category>

		<category><![CDATA[disk space]]></category>

		<guid isPermaLink="false">http://blog.bruteforcetech.com/?p=489</guid>
		<description><![CDATA[Scenario:
You have a virtual machine running on ESXi, and either the disk is thin-provisioned, or you have one or more snapshots. The datastore runs out of space, and the VM goes down. You are unable to boot the VM because there is not enough free space on the datastore.
When you allocate memory to a VM [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Scenario:</strong><br />
You have a virtual machine running on ESXi, and either the disk is thin-provisioned, or you have one or more snapshots. The datastore runs out of space, and the VM goes down. You are unable to boot the VM because there is not enough free space on the datastore.</p>
<p>When you allocate memory to a VM and boot it, ESXi creates a &#8220;swapfile&#8221; on the datastore using an amount of space equivalent to the amount of RAM you allocated. By default, ESXi is configure to place this swapfile in the same folder (on the same datastore) as the VM.</p>
<p>Thus although the datastore might have 3.75 GB free, when you attempt to boot the server that you have allocated 8 GB of RAM to, it will not boot.</p>
<p> </p>
<p><strong>Solution:</strong><br />
If you have more than one datastore available, you can go into the vSphere Client, configuration tab, and configure the virtual machine swapfile location. Place the swapfiles on the second datastore.</p>
<p>If you don&#8217;t have more than one datastore, perhaps you can add one. If you have a NAS device that supports NFS, you can use that. If the onboard SATA controller on your server is supported by ESXi, you can add a cheap SATA disk to use for your swapfile location (and a good backup location) while you sort this issue out.</p>
<p>Once you have done this, you can boot the server, and run a backup from within the OS .</p>
<p>Once you have a full backup, you can delete the VM to free up space. If you ran out of room due to snapshots, you can create a new VM and start restoring your backup right away. If you ran out of room due to a thin provisioned disk that exceeded the datastore size, you will obviously need to make your datastore larger before proceeding with the restore.</p>
<p><strong></strong></p>
<p><strong>Other ways you can recover from this situation:</strong><br />
1. Add disks to the server and extend the datastore to use them, so the datastore gets larger.</p>
<p>2. Move one or more of the VMDK files to the second datastore and edit your VM configuration to use the disk(s) in the new location.</p>
<p><strong></strong></p>
<p><strong>How you can prevent this situation:</strong><br />
1. When allocating space, ensure that if you are using thin provisioning, if the disk grows to its full potential size, it will still fit on the datastore. If you want to use some of teh available space while your VMDK files are still small, go right ahead - but make sure you can either delete or move the less important machines on short notice - and monitor your disk usage!</p>
<p>2. leave plenty of extra room. Put more physical space in the server than you&#8217;re ever likely to need. Disks are cheap.</p>
<p> </p>
<p>P.S. I am sure that this same concept, or parts of it, can be applied to Hyper-V virtual hosts. However, I am not familair enough with Hyper-V to give specifics.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.bruteforcetech.com/index.php/archives/489/feed</wfw:commentRss>
		</item>
		<item>
		<title>Updated: Configure PPTP on a Watchguard Firebox Using RADIUS Authentication and Windows 2008</title>
		<link>http://blog.bruteforcetech.com/index.php/archives/470</link>
		<comments>http://blog.bruteforcetech.com/index.php/archives/470#comments</comments>
		<pubDate>Sun, 17 Jan 2010 22:43:37 +0000</pubDate>
		<dc:creator>Paul Sterley</dc:creator>
		
		<category><![CDATA[Firewall Configuration]]></category>

		<category><![CDATA[In the Windows Box]]></category>

		<category><![CDATA[Windows Server]]></category>

		<category><![CDATA[Firebox]]></category>

		<category><![CDATA[Fireware]]></category>

		<category><![CDATA[Network Policy Server]]></category>

		<category><![CDATA[PPTP]]></category>

		<category><![CDATA[RADIUS]]></category>

		<category><![CDATA[Watchguard]]></category>

		<guid isPermaLink="false">http://blog.bruteforcetech.com/?p=470</guid>
		<description><![CDATA[This article covers the steps to configure a Watchguard Firebox to pass authentication traffic for PPTP VPN connections to a RADIUS server running on Windows Server. The first part of the document covers Fireware 10.2 and Windows 2008. Legacy technologies can be found at the bottom of the article.
Usage Scenario: You wish to have the Firebox terminate [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">This article covers the steps to configure a Watchguard Firebox to pass authentication traffic for PPTP VPN connections to a RADIUS server running on Windows Server. The first part of the document covers Fireware 10.2 and Windows 2008. Legacy technologies can be found at the bottom of the article.</span></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;">Usage Scenario:</strong> You wish to have the Firebox terminate the VPN connection, but still pass the authentication through to your Active Directory server instead of using static Firebox user accounts.</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;"><span style="line-height: 115%; font-size: 9pt;">Note:</span></em></strong><span style="line-height: 115%; font-size: 9pt;"> Fireware has Active Directory and LDAP authentication methods, but these cannot be used for PPTP VPN authentication as of version 10.2.12. These can be used with MUVPN, which requires IPSEC Client software to be loaded on the connecting workstation.</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Calibri; font-size: small;"><strong>Benefits of having the firewall terminate a PPTP VPN:</strong></span></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;"><span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"><span style="mso-list: Ignore;"><span style="font-size: small;">·</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">It is not necessary to have more than one IP address on the Firebox’s external interface.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;"><span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"><span style="mso-list: Ignore;"><span style="font-size: small;">·</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">It is not necessary to set up 1:1 NAT, which would put your server on a different outgoing IP address from the rest of the network (this is a good thing from a “keep it simple” perspective).</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;"><span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"><span style="mso-list: Ignore;"><span style="font-size: small;">·</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">You can reboot the server without dropping your VPN connection – you cannot authenticate while it is rebooting, but if you are already connected, you will stay connected.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;"><span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"><span style="mso-list: Ignore;"><span style="font-size: small;">·</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">PPTP tunnels terminated by the Firebox are generally faster and more reliable than when terminated by a Windows server.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;"><span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"><span style="mso-list: Ignore;"><span style="font-size: small;">·</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">It is not necessary to load any software on the connecting workstation; it’s built into Windows.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in;"><span style="font-family: Calibri; font-size: small;"> </span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt; mso-add-space: auto;"><strong style="mso-bidi-font-weight: normal;"><span style="line-height: 115%; font-size: 13pt;"><span style="font-family: Calibri;">Configure the Firewall:</span></span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt; mso-add-space: auto;"><strong style="mso-bidi-font-weight: normal;"></strong> </p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><strong><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">1.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Open the Policy Manager.</span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><strong><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">2.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Configure RADIUS Authentication:</span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">a.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Click Setup -&gt; Authentication -&gt; Authentication Servers.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">b.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Click the RADIUS tab.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">c.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Check to enable the RADIUS server.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">d.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Type the IP address of the Windows 2008 server and set the port to 1812.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">e.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Type a “secret” and confirm it. Take note of this in your network documentation, as you will need it later to configure Windows 2008, and possibly even later still, when you change things on the network. Try to use a secure secret here.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">f.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Click OK to close the Authentication Servers dialog.</span> </p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><strong><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">3.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Create the PPTP VPN Policy:</span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">a.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Click VPN -&gt; Mobile VPN -&gt; PPTP.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">b.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Check the box to Activate Mobile VPN with PPTP.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">c.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Check the box to use RADIUS authentication.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">d.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Require 128-bit Encryption (I think this is optional, but why would you?).</span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">e.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Add an IP address pool.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note</em></strong>: It would be a very good idea to create a DHCP exclusion matching this IP address pool, both to avoid IP conflicts due to DHCP, and to remind you that you have assigned these addresses when you go looking for an available static IP address later. If you have an IP address spreadsheet (hopefully you do), add it there as well. Documentation is key to an organized network.</span></span></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">f.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Click OK.</span> </p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">4.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">Create an Access Rule to allow VPN traffic:</span></span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">a.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Click Edit -&gt; Add Policy.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">b.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Expand Packet Filters and double-click the “Any” filter.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">c.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Change the name to “Any-RUVPN” (or something else that is descriptive to you).</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">d.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Remove “Any-Trusted” from the “From” area.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">e.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Click Add-&gt; Add User, select type “PPTP” and “Group”, double-click PPTP-Users, and click OK.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">f.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Click Add-&gt; Add other -&gt; Network IP, add your internal network subnet, and click OK -&gt; OK.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">g.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Remove “Any-External” from the “To” area.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">h.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Click Add-&gt; Add other -&gt; Network IP, add your internal network subnet, and click OK -&gt; OK.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">i.</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">Click Add-&gt; Add User, select type “PPTP” and “Group”, double-click PPTP-Users, and click OK.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt; mso-add-space: auto;"><span style="font-size: small;"><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> We have just created a bi-directional rule that allow traffic both directions over the PPTP VPN. Your rule should have “PPTP-Users” and your internal subnet in both the “From” and the “To” areas.</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">j.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Click OK to close the policy properties dialog.</span><span style="font-family: Calibri; font-size: small;"> </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">5.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">(Important!) Configure DNS on the Firebox:</span></span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">a.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Click Network -&gt; Configuration and go to the WINS/DNS tab.</span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 1in; mso-add-space: auto; mso-list: l0 level2 lfo1;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">b.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Enter the DNS servers for your network.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> The DNS settings are important for your VPN client to obtain the DNS server automatically from the firewall when the VPN connects. Unfortunately, as of Fireware 10.2, the DNS suffix is not passed to the VPN client, so you will need to include that in the VPN connection’s advanced properties on the workstation.</span></span></p>
<p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">6.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">Upload your config to your firewall.</span></span></strong> </p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong style="mso-bidi-font-weight: normal;"><span style="line-height: 115%; font-size: 13pt;"><span style="font-family: Calibri;">Configure Windows 2008:</span></span></strong></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">1.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">Prerequisites:</span></span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">a.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Network Policy and Access Services</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">b.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Windows Firewall disabled or configured to allow RADIUS traffic on port 1812.</span> </p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">2.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">Ensure that NPS is installed and started.</span></span></strong> </p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">3.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">Create a Security Group:</span></span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">a.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Create a security Group on your AD domain controller with a name that is descriptive to you (VPNUsers, for example) and populate it with users who will have VPN access.</span> </p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">4.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">Open the Server Manager.</span></span></strong> </p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">5.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">Tell Windows about the RADIUS Client:</span></span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">a.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Expand Roles -&gt; Network Policy and Access Services -&gt; NPS (Local) -&gt; RADIUS Clients and Servers, and select RADIUS Clients.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">b.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Right-Click RADIUS Clients and select New RADIUS Client.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">c.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Check the box to enable the RADIUS Client.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">d.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Type a friendly name (Firebox) for the RADIUS Client.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">e.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Add the IP address of the Firebox.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">f.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Select RADIUS Standard from the Vendor Name list.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">g.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Choose the “Manual” radio button.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">h.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Type and confirm the “secret” you entered into the Firebox config in the “Configure the Firebox” section.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">i.</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">Make sure both checkboxes at the bottom o the dialog are unchecked and click OK.</span> </p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">6.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">Configure a RADIUS Authentication Policy:</span></span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">a.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Expand Roles -&gt; Network Policy and Access Services -&gt; NPS (Local) -&gt; Policies -&gt; Network Policies.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">b.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Right-Click Network Policies and select New.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">c.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Type a Policy name that will be descriptive to you (RUVPN Connections, for example).</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">d.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Leave the “Type of network access server” set to “Unspecified” and click Next.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">e.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Click the Add button and double-click “Windows Groups” in the Conditions list.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">f.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Click the Add Groups button and type or search for the VPN users group you created earlier.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">g.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Click OK -&gt; OK, which should bring you back to the Specify Conditions dialog.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">h.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Click the Next button to get to the Specify Access Permission dialog.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">i.</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">Leave “Access granted” selected and click Next.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">j.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Ensure that MS-CHAP-v2 and MS-CHAP are selected, and click Next.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">k.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Click Next again without configuring any constraints.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">l.</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="font-family: Calibri; font-size: small;">In the left Windows pane, select Standard under RADIUS Attributes.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">m.</span><span style="font: 7pt &quot;Times New Roman&quot;;">    </span></span></span><span style="font-family: Calibri; font-size: small;">Remove any existing attributes and click Add.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">n.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Double-click Filter-ID.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">o.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Click the Add button.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">p.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Type “PPTP-Users” (case sensitive) into the “String” field and click OK.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">q.</span><span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: Calibri; font-size: small;">Click OK and Close to get back to the Configure Settings dialog.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">r.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Select Encryption under Routing and Remote Access, and uncheck “No Encryption”.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">s.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Click Next -&gt; Finish.</span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 1in; mso-add-space: auto; mso-list: l2 level2 lfo2;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">t.</span><span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span><span style="font-family: Calibri; font-size: small;">Right-click you new policy and select “Move Up” repeatedly until it is first in the list.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong style="mso-bidi-font-weight: normal;"><span style="line-height: 115%; font-size: 10pt;"><span style="font-family: Calibri;">Test your configuration:</span></span></strong></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l3 level1 lfo4;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">1.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Set up a workstation outside the firewall with PPTP VPN.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l3 level1 lfo4;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">2.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Connect to the VPN with a user who exists in the VPN users group you created in AD.</span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l3 level1 lfo4;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;"><span style="font-family: Calibri; font-size: small;">3.</span><span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span><span style="font-family: Calibri; font-size: small;">Once the VPN is running, test access to network resources.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> It is possible to be connected to the VPN, but still have no resource access if you did not configure the access policy properly, so be sure to test this.</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;"><strong>Update:</strong></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;">If you have an older Firebox running WSM 7.x, and wish to use PPTP terminated by the firewall, with RADIUS authenticated by a Windows 2008 server, use these instructions for the firewall side:</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;"><strong><em>Note:</em></strong> You will need to adjust the policy in NPS on the Windows 2008 server to use “pptp_users” instead of “PPTP-Users”. This changed between WSM and Fireware.</span></span></p>
<p> </p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 10pt;">Configure a legacy Firebox (WSM 7.x) for Remote User PPTP:</span></strong></p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">1.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Open Policy Manager and select Setup -&gt; Firewall Authentication.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">2.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Select the radio button for RADIUS Server -&gt; OK -&gt; OK.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">3.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Enter the IP address of the Windows 2000 server running IAS.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">4.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Change the Port number to 1812 and enter your shared secret -&gt; OK</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">5.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Click Network -&gt; Remote User -&gt; PPTP tab.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">6.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Check the checkboxes for Activate Remote User and Use Radius Authentication.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">7.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Click the Add button, select Host IP Address and enter the first IP address you allocated for use by the Firebox -&gt; OK.</p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">8.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Repeat this until all of your allocated IP addresses have been entered.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> You can copy/paste into the IP address field.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> You may wish to enable logging here if you have any difficulty getting this to work.</p>
<p class="MsoListParagraph" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">9.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Click OK.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 10pt;">Configure a legacy Firebox Access Rule for RUVPN:</span></strong></p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">1.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Add a service to allow traffic from VPN Users:</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-list: l0 level2 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">a.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Click Edit -&gt; Add Service. Expand Packet Filters and select &#8220;Any&#8221;.</p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-list: l0 level2 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">b.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span>Click the Add button. Change the name to &#8220;Any-RUVPN&#8221;.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> If you change this name, I recommend against using spaces.</p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-list: l0 level2 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">c.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>On the Incoming tab, select &#8220;Enabled and Allowed&#8221; from the selection list.</p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-list: l0 level2 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">d.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span>Click the Add button in the &#8220;From&#8221; area and add the &#8220;pptp_users&#8221; group.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> If the &#8220;pptp_users&#8221; group is not available to be selected here, you can click &#8220;Add other&#8221;, drop down and select &#8220;Radius User or Group&#8221; and type pptp_users in. I had to do this with a Firebox. Once I had uploaded the config and firmware to the firebox, then pulled down a fresh config file from the firebox, the pptp_users that I had typed in became the special Firebox group and took on the icon with the two head with a red thing behind them, indicating that it recognized the special group. Your mileage may vary.</p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-list: l0 level2 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">e.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span>Click the Add button in the &#8220;To&#8221; area and add &#8220;Trusted&#8221;.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-list: l0 level2 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">f.<span style="font: 7pt &quot;Times New Roman&quot;;">        </span></span></span>Go to the Outgoing tab.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-list: l0 level2 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">g.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Add &#8220;Trusted&#8221; to the &#8220;From&#8221; area and &#8220;pptp_users&#8221; to the &#8220;To&#8221; area.</p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 1in; mso-list: l0 level2 lfo2; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">h.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span>Finish the rule and upload the configuration to the Firebox.</p>
<p class="MsoNormal" style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt"> </p>
<p class="MsoNormal" style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt"> </p>
<p class="MsoNormal" style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt"> </p>
<p class="MsoNormal" style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt"><strong>If you have a Windows 2003 server and wish to use IAS for RADIUS authentication for a Watchguard Firebox, here are the steps:</strong></p>
<p class="MsoNormal" style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt"><strong></strong></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 10pt;">Install and Configure IAS on Windows 2003:</span></strong></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 10pt;"> </span></strong></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> You must either <a title="Disable SMB Signing" href="http://www.google.com/search?hl=en&amp;source=hp&amp;q=disable+smb+signing&amp;aq=f&amp;oq=&amp;aqi=g10" target="_blank">disable SMB Signing</a> or use Firebox Software version 7.30-B2938 or later!</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 10t;"> </span></strong></p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">1.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>In Add/Remove programs -&gt; Windows Components -&gt; Networking Services, check &#8220;Internet Authentication Service&#8221; and finish the wizard.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">2.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Open the Services applet and stop, then restart the IAS service. Refresh the screen and ensure that the service continues to show “running” status. Some applications (the Symantec antivirus management console, for example) interfere with IAS by using port 1812. If this is the case you will need to configure IAS on a different server.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">3.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Open Administrative Tools -&gt; Internet Authentication Service and select Radius Clients in the left pane.</p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">4.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Click Action -&gt; New Radius Client. Enter &#8220;Firebox&#8221; for the friendly name.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> If you change this name, I recommend against using spaces or non-alpha characters.</p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">5.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Enter the Trusted IP address of the Firebox for the Client Address and click Next.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">6.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Verify that RADIUS Standard is the selected protocol.</p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">7.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Enter and confirm a &#8220;shared secret&#8221; of your choice.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> I recommend Uppercase, Lowercase, and Numbers - but not non-alpha characters.</p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">8.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Verify that RADIUS Standard is the selected Client-Vendor.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">9.<span style="font: 7pt &quot;Times New Roman&quot;;">       </span></span></span>Verify that the box for &#8220;Request must contain the Message Authenticator attribute&#8221; is NOT checked, and click Finish.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">10.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Select Remote Access Policies and click Action -&gt; New Remote Access Policy.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">11.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Select the option for &#8220;Set up a custom policy&#8221;.</p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">12.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Enter VPNUsers for the friendly name of the policy.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> If you change this name, I recommend against using spaces or non-alpha characters.</p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">13.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Click Next -&gt; Add -&gt; select Windows-Groups -&gt; Add -&gt; Add -&gt; select your VPNUsers group -&gt; OK -&gt; OK -&gt; Next.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">14.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Select the radio button for &#8220;Grant remote access permission&#8221; -&gt; Next.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">15.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Click the Edit Profile button -&gt; Authentication tab.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">16.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Verify that the checkboxes for &#8220;Microsoft Encrypted Authentication version 2 (MS-CHAP v2)&#8221; and MS-CHAP are checked.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">17.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Go to the Encryption Tab and clear the check box next to &#8220;No Encryption&#8221;.</p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">18.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Click the Advanced tab and remove &#8220;Framed-Protocol&#8221; and &#8220;Service-Type&#8221;.</p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">19.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Click Add -&gt; Filter-Id -&gt; Add -&gt; verify that &#8220;string&#8221; is selected and type &#8220;pptp_users&#8221; into the attribute field.</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> For Fireware Pro 8.2 the string must be set to &#8220;PPTP-Users&#8221; (case sensitive).</p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">Note:</em></strong> Other documentation may suggest that you type something else here, like your group name. DON&#8217;T. The Firebox wants to see &#8220;pptp_users&#8221; or &#8220;PPTP-Users&#8221; in this attribute, just as it is typed here - lowercase, underscore or hyphen and all.</p>
<p class="MsoListParagraph" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: Ignore;">20.<span style="font: 7pt &quot;Times New Roman&quot;;">   </span></span></span>Click whatever combination of OK, Next, and/or Finish is required to complete the config. If it prompts you to view help topics, say no.</p>
<p class="MsoNormal" style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt"> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.bruteforcetech.com/index.php/archives/470/feed</wfw:commentRss>
		</item>
		<item>
		<title>Quickbooks 6000, 83 Error - Usually the Quickbooks Database Server Manager</title>
		<link>http://blog.bruteforcetech.com/index.php/archives/460</link>
		<comments>http://blog.bruteforcetech.com/index.php/archives/460#comments</comments>
		<pubDate>Fri, 18 Dec 2009 08:49:39 +0000</pubDate>
		<dc:creator>Paul Sterley</dc:creator>
		
		<category><![CDATA[LOB Software]]></category>

		<category><![CDATA[Not in the Windows Box]]></category>

		<category><![CDATA[Windows Server]]></category>

		<category><![CDATA[Workstation OS]]></category>

		<category><![CDATA[Quickbooks]]></category>

		<guid isPermaLink="false">http://blog.bruteforcetech.com/?p=460</guid>
		<description><![CDATA[The following are some tips and tricks I have picked up when troubleshooting access to Quickbooks files on a server - particularly when they are set up for multi-user access, and the Quickbooks Database Server Manager is installed. QDSM is there to act as a proxy server, intercepting file requests for QBW files and ensuring [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">The following are some tips and tricks I have picked up when troubleshooting access to Quickbooks files on a server - particularly when they are set up for multi-user access, and the Quickbooks Database Server Manager is installed. QDSM is there to act as a proxy server, intercepting file requests for QBW files and ensuring that no conflicts arise when more than one user opens the file at the same time.</span></p>
<p><span style="color: #800000;">The error message that you get when you try to open the Quickbooks file goes like this:</span><br />
<span style="color: #800000;"><strong>Error -6000, -83: &#8220;An error occurred when QuickBooks tried to access the company file&#8221;.</strong></span><br />
<span style="color: #800000;">Of course, there are many, MANY hits when searching this error, and most of them are unhelpful. The knowledge base article on the Intuit website is also fairly limited.</span></p>
<p><span style="color: #008000;"><strong>Here is my experience with that error and the things that cause it:</strong></span></p>
<p><span style="color: #000080;"><strong><span style="color: #800000;">1. There are multiple instances of the Quickbooks Database Server Manager running.</span></strong></span></p>
<p><span style="color: #000080;">Check this by opening the Services applet and looking for services called &#8220;QuickbooksDB17, QuickbooksDB19, QuickbooksDB20, etc.&#8221; You only need ONE of these. If there are more than one, remove all except the newest one. Multiple instances means you can have conflicts, because they are both trying to serve the same files.</span></p>
<p><span style="color: #000080;"><span style="color: #800000;"></span></span> </p>
<p><span style="color: #000080;"><strong><span style="color: #800000;">3. The .ND file contains outdated or inaccurate information.</span></strong></span></p>
<p><span style="color: #000080;">When the QDSM finds a QBW file, it creates a small text file with the .ND extension matching the QBW&#8217;s filename. This file contains information about the server hosting the file, the IP address, whether it is available for multi-user access, and which database engine is serving the file to the users. When this information becomes stale, the solution is to delete the .ND file, and tell the QDSM to run a Scan of the folder the QBW files are in to recreate the .ND files. Deleting and recreating these is especially recommended if you have just cleaned up multiple instances of the QDSM service.</span></p>
<p><span style="color: #800000;"><strong>4. The NTFS permissions are wrong.</strong></span></p>
<p><span style="color: #000080;">Yes, the Intuit article mentions this, but they are talking about the user&#8217;s access to the files. That&#8217;s important, and you should check it, but it&#8217;s not what I am referring to here. What I am talking about is the permissions for the QDSM user account. When you install the QDSM, it creates a user account with the same name as the service it creates. When it scans and finds QBW files in a folder, it assigns itself NTFS permissions to that folder so it can do its job. When you have uninstalled and reinstalled the QDSM a few times, or perhaps done a server migration, this user account can become disassociated with the QDSM service and things don&#8217;t work right anymore. Maybe the old server was a DC, and the new one is not. In that case the old account is an Active Directory user account, and the new one is a local account. they have the same name but the passwords are different, so Access is Denied.</span></p>
<p><span style="color: #000080;"><strong>The best thing to do when you suspect you might have this problem is:</strong></span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">a. Remove the Quickbooks account from the NTFS folder permissions anywhere that it has put itself.<br />
b. Uninstall the QDSM.<br />
c. Delete the user account from both AD and the local SAM, wherever you find it.<br />
d. Reinstall the QDSM.<br />
e. Scan the folders where the Quickbooks files are, and let the QDSM reassign NTFS permissions.</span></p>
<p><span style="color: #000080;"><strong>If you&#8217;re seeing the 6000, 83 error, and you go through the above steps, there&#8217;s a very good chance one of them will sort it out for you.</strong></span></p>
<p><span style="color: #000080;"><strong>Good Luck!</strong></span></p>
<p><span style="color: #000080;"><span style="color: #800000;"><strong>2. One or more of the workstations have the QDSM installed and are hosting multi-user access.</strong></span></span></p>
<p><span style="color: #000080;">A lot of users don&#8217;t understand the components of the multi-user Quickbooks system, and will install all options and turn everything on. Either they assume more is better, or they don&#8217;t know which parts to say &#8220;No&#8221; to, despite Intuit&#8217;s best effort to try making this easier to figure out. If a user has hosting turned on, and they open a shared file on a server, there will be a conflict with the QDSM running on the server, and other users may have trouble opening this file. Go into the Quickbooks program on each workstation and check for multi-user hosting. In a network with a central file server, no user should be hosting. In a peer to peer network, it&#8217;s best to pick a workstation that will do all of the hosting and turn it off for everyone else.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.bruteforcetech.com/index.php/archives/460/feed</wfw:commentRss>
		</item>
		<item>
		<title>Product Review: R1Soft&#8217;s CDP Server</title>
		<link>http://blog.bruteforcetech.com/index.php/archives/454</link>
		<comments>http://blog.bruteforcetech.com/index.php/archives/454#comments</comments>
		<pubDate>Tue, 08 Dec 2009 19:24:37 +0000</pubDate>
		<dc:creator>Paul Sterley</dc:creator>
		
		<category><![CDATA[Backup and Restore]]></category>

		<category><![CDATA[CDP]]></category>

		<category><![CDATA[Local Backup]]></category>

		<category><![CDATA[R1Soft]]></category>

		<guid isPermaLink="false">http://blog.bruteforcetech.com/?p=454</guid>
		<description><![CDATA[I recently evaluated the Windows version of the R1Soft CDP Server 2.0 product. What follows is a basic write-up of the points and features that seemed relevant and important to me. Your needs may be different. For a full description of the product, click here.
For their full documentation set, click here.
Summary: 
In my opinion this [...]]]></description>
			<content:encoded><![CDATA[<p>I recently evaluated the Windows version of the R1Soft CDP Server 2.0 product. What follows is a basic write-up of the points and features that seemed relevant and important to me. Your needs may be different. For a full description of the product, <a title="R1Soft CDP Server 2.0 for Windows Product Page" href=" http://www.r1soft.com/windows-cdp/cdp-server-20/" target="_blank">click here</a>.</p>
<p>For their full documentation set, <a title="R1Soft CDP Server 2.0 for Windows Documentation Set" href="http://wiki.r1soft.com/display/R1D/Home" target="_blank">click here</a>.</p>
<p><strong>Summary: </strong></p>
<p><span style="color: #000080;">In my opinion this is a great product for local backup to disk.</span> <span style="color: #800000;">However, it has no good provisions for rotation of storage devices and offsite backup for disaster recovery. They did give it a go with the Archive module, but I feel that they fell short of the mark with this.</span></p>
<p><span style="color: #800000;"> The only way to get a good offsite backup with full capabilities is to stop the CDP service, back up the CDP Server including its databases, system state, etc. to portable media, and take that offsite. In a disaster, you’ll spend some time recovering your recovery server first.</span></p>
<p><strong><span style="color: #000080;"> Overview:</span></strong></p>
<p><span style="color: #000080;">·         The product is installed on a server that is not one of those that you will be backing up.</span></p>
<p><span style="color: #000080;">·         A disk is defined for the storage container. This disk cannot be rotated with other disks and taken offsite. It must remain present.</span></p>
<p><span style="color: #000080;">·         Agents are installed on server that you wish to back up.</span></p>
<p><span style="color: #000080;">·         Backups are scheduled.</span></p>
<p><span style="color: #000080;">·         E-mail notifications can be scheduled, which include a summary of the history screen.</span></p>
<p><span style="color: #000080;">·         Individual file/folder restore is done via the CDP server console and is pretty easy.</span></p>
<p><span style="color: #000080;">·         Bare Metal restore is accomplished by booting a server from CD and controlling it from the CDP Server console. There are other methods as well, but this is the most straightforward.</span></p>
<p><span style="color: #000080;">·         Archives to Zip files can be scheduled via the console, as long as you are not using encryption. The target for these can be FTP, SFTP, or CIFS.</span></p>
<p> </p>
<p>During my evaluation of the product, there were several points that I could not find information about in their documentation, so I submitted technical support incidents. I just got the answers back from them. I can&#8217;t say I&#8217;m happy about any of them.</p>
<p><span style="color: #800000;">1.       When you “Archive” information from the data storage container, which allows you to send it off to an FTP server or something, you can no longer use the R1Soft graphical interface to work with that archive. From that point it becomes a Zip file that you can manually open up and copy data out of. So we could not use an Archive to do a bare-metal restore, for example.</span></p>
<p><span style="color: #800000;">2.       If you choose to “encrypt” (password protect) your storage, then you cannot schedule an Archive job. The software does not store the encryption password. Archives can then only be manually done.</span></p>
<p><span style="color: #800000;">3.       It is not possible to rotate data storage media. R1Soft writes to a disk as a container to store the data. It makes a database there, and it wants the same database to be available at all times. So the only way to get an offsite backup of the data container as an intact, whole backup that you can use the GUI to restore from is to stop the R1Soft services, back up the entire CDP Server to removable media, and take that offsite. That means restoring from one of these will involve first recovering the R1Soft server from that backup.</span></p>
<p><span style="color: #800000;">4.       The current version of CDP Server (2) involves one central server with agents installed on other servers to back them up. The pricing is excellent. However, version 3, which is due out in 2010, changes this model. Each server will have its own copy of the software and will back up to standalone databases that can be copied around. This will improve the offsite storage capability. The “Enterprise” edition will still have the capability to have a central server with agents for the backup targets. It is unknown at this time what the pricing will be like for either option.</span></p>
<p><strong>Conclusion:</strong></p>
<p><span style="color: #000080;">Within its limits, the R1Soft CDP Server 2.0 product performs well and provides a very cost effective (at this time) local backup solution for companies with multiple servers.</span></p>
<p><span style="color: #800080;">However, the lack of off-site disaster recovery functionality makes this a product that I am unlikely to recommend to customers, unless I have some other independent option for offsite disaster recovery.</span></p>
<p><span style="color: #800000;">Further, the fact that the architecture (and pricing) will change significantly in the next version, due out within a year, gives me pause. I am hesitant to roll out a backup system based on this architecture and pricing, with the probability that in less than a year, I will either have to change the backup model completely, or pay significantly more for the “enterprise” edition that will include the backup model that is being offered at such a good price now.</span></p>
<p><span style="color: #800080;">During my evaluation, when I found something that was not intuitive, or an interface that seemed a little clunky, I reminded myself of the great pricing and the benefits of needing only a lightweight agent installed on each server. Finding out that within a year I will either have to abandon the benefits of the agent or pay a higher cost for an “Enterprise” level product puts those rough edges and minor defects in an entirely different light.<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.bruteforcetech.com/index.php/archives/454/feed</wfw:commentRss>
		</item>
		<item>
		<title>Updated: Recover from a USN Rollback WITHOUT Demoting and Promoting your DC</title>
		<link>http://blog.bruteforcetech.com/index.php/archives/438</link>
		<comments>http://blog.bruteforcetech.com/index.php/archives/438#comments</comments>
		<pubDate>Wed, 28 Oct 2009 07:16:06 +0000</pubDate>
		<dc:creator>Paul Sterley</dc:creator>
		
		<category><![CDATA[Backup and Restore]]></category>

		<category><![CDATA[ESXi]]></category>

		<category><![CDATA[IIS]]></category>

		<category><![CDATA[In the Windows Box]]></category>

		<category><![CDATA[Virtualization]]></category>

		<category><![CDATA[Windows Server]]></category>

		<category><![CDATA[Active Directory]]></category>

		<category><![CDATA[Restore]]></category>

		<category><![CDATA[Snapshot]]></category>

		<category><![CDATA[System State]]></category>

		<guid isPermaLink="false">http://blog.bruteforcetech.com/?p=438</guid>
		<description><![CDATA[What&#8217;s a USN Rollback? That&#8217;s when you&#8217;ve restored an Active Directory DC in a multiple DC environment using a method that is not Active-Directory Aware. Examples include Ghost images, VMware or Hyper-V snapshots, or other imaging or volume-level restore methods.
Why is that a problem? A very good detailed explanation is available here, but the basic [...]]]></description>
			<content:encoded><![CDATA[<p><strong>What&#8217;s a USN Rollback?</strong> That&#8217;s when you&#8217;ve restored an Active Directory DC in a multiple DC environment using a method that is not Active-Directory Aware. Examples include Ghost images, VMware or Hyper-V snapshots, or other imaging or volume-level restore methods.</p>
<p><strong>Why is that a problem?</strong> <a title="USN Rollback Explained" href="http://elssblog.blogspot.com/2006/06/usn-rollback.html" target="_blank">A very good detailed explanation is available here</a>, but the basic idea is that AD keeps track of which servers it has replicated with and when, and if a DC is rolled back in a way that is not compatible with the record-keeping, the affected DC will disabled inbound and outbound replication, and refuse to replicate with the other DCs.</p>
<p><a title="Recovering from a USN Rollback" href="http://elssblog.blogspot.com/2006/06/recovering-from-usn-rollback.html" target="_blank">Here&#8217;s a related article</a> by the same author as the above post, which led me to my solution this evening. My article expands on the second option provided, but goes into the mechanics of it, and the associated difficulties.</p>
<p>According to <a title="Dectect and Recover from USN Rollback" href="http://support.microsoft.com/kb/875495" target="_blank">Microsoft&#8217;s Knowledge Base article on the subject</a>, recovering from this situation entails forcibly demoting the DC, cleaning up the AD, and then (optionally) promoting it again. If the DC in question has no other roles, or just a couple of basic ones such as a print server, this might be the best way to go, if you&#8217;re familiar with such things as <a title="Using NTDSUtil to Seize FSMO Roles" href="http://support.microsoft.com/kb/255504" target="_blank">seizing FSMO roles </a>and performing <a title="AD Metadata Cleanup" href="http://support.microsoft.com/kb/216498" target="_blank">metadata cleanup in Active Directory after an unsuccessful DC demotion</a>.</p>
<p><em>** Update: Read on for more details about how this all works, but make sure you check the update at the bottom of the article for the easier method I successfully tested!</em></p>
<p>However, if you&#8217;re not familiar with these things, or you have other applications on the server which might be affected (IIS, in particular, is very sensitive to the permissions changes associated with DC promotion), this might create a very large amount of havoc on your server.</p>
<p><strong>Your saving grace</strong>, if you have one, is a System State backup from before the USN rollback occurred. If you don&#8217;t have a backup of JUST the System State, perhaps you can restore an entire image to another server, boot it, and create one.</p>
<p>If you have or can create one of these, your solution becomes much simpler. You just need to boot your server in Directory Services Restore Mode, <a title="Restore Active Directory from Backup" href="http://technet.microsoft.com/en-us/library/cc758435(WS.10).aspx" target="_blank">restore the System State</a>, <strong><em>DO NOT</em></strong> mark any part of your restore as authoritative, and reboot.</p>
<p>After the reboot, you might need to remove the flags AD has set, which have disabled inbound and outbound replications. <a title="REPADMIN Syntax" href="http://technet.microsoft.com/en-us/library/cc736571(WS.10).aspx" target="_blank">The commands for this</a> are:<br />
<span style="line-height: 115%; font-family: &quot;Courier New&quot;; font-size: 10pt;"><br />
repadmin /options [YourServerName] -disable_inbound_repl<br />
repadmin /options [YourServerName] -disable_outbound_repl<br />
</span><br />
<em>Note: This looks like you are disabling replication, but what you are actually doing is putting a minus sign (-) before the disable option, which enables it. I know, it&#8217;s counter-intuitive, but trust me on this one - or </em><a title="REPADMIN Syntax" href="http://technet.microsoft.com/en-us/library/cc736571(WS.10).aspx" target="_blank"><em>go check the syntax yourself</em></a><em>.</em></p>
<p>Of course, you need the Support Tools installed to get the repadmin utility. Once you run those commands, your server will start replicating again, and the more up-to-date DC(s) will override the old, out of date information your USN Rollback victim was holding onto.</p>
<p><strong>There are some extra difficulties associated with the above plan:</strong><br />
1. If you have to restore a server image to create that System State backup, and you restore to different hardware, things could get a little messy. Is it messier than demoting, seizing FSMO roles, performing metadata cleanup, promoting, and cleaning up the fallout from your installed apps? You&#8217;ll have to decide on that one.</p>
<p>2. This requires you having an extra server (or two, if you want to restore more than one DC to create a stable lab environment from which to back up the System State) laying around. Do you have those resources available?</p>
<p>I was facing this issue today, and all of the above became MUCH simpler for me when I realized I could use the <a title="Doyenz" href="http://www.doyenz.com" target="_blank">Doyenz</a> Test Lab to sort all of this out. I did NOT have a System State backup from before the USN Rollback, but I HAVE been running backups into the Doyenz system since before the problem began.</p>
<p><strong>Here is what I did:<br />
1. Created a backup of the System State</strong></p>
<p style="padding-left: 30px;">a. Restored a copy of the affected server in the <a title="Doyenz" href="http://www.doyenz.com" target="_blank">Doyenz</a> Test Lab. I specifically restored from the date BEFORE the USN Rollback happened. It was easy to find this by looking at the date of the last successful replication with repadmin on the affected server.<br />
b. Performed a System State backup using NTBackup (you can do this with WBAdmin on Windows 2008).<br />
c. Zipped the backup file and sent to an FTP server.<br />
d. Shut down the restored server.</p>
<p><strong>2. Performed a test run to make sure this was going to work, without affecting the live servers.</strong></p>
<p style="PADDING-LEFT: 30px">a. Using the <a title="Doyenz Portal" href="https://app.doyenz.com" target="_blank">Doyenz Portal</a>, I select last night&#8217;s backup and restored it for both servers.<br />
b. I booted the primary DC (the one with the FSMO roles) first.<br />
c. Attached the second (USN Rollback victim) server to the first one in the Lab, and booted it.<br />
d. Pulled the System State backup down from the FTP site onto the affected server.<br />
e. Rebooted the affected server into Directory Services Restore Mode.<br />
f. Restored the System State on the affected server.<br />
g. Rebooted the affected into Normal Mode.<br />
h. Used the repadmin commands to remove the replication blocks.<br />
i. Forced replication using AD Sites and Services.</p>
<p><strong>3. Verified successful replication.</strong></p>
<p style="padding-left: 30px;">a. Created a user account on one DC in the Test Lab, forced replication, and checked for the account on the other DC.<br />
b. Deleted the user account on the other DC, and checked it on the first DC.</p>
<p><strong>4. Tested the touchy sensitive web applications that are running on the affected server.</strong></p>
<p><strong>5. Shut down the servers in the test lab.</strong></p>
<p><strong>After this successful test, I notified the users of pending late-night downtime, and repeated the above steps, this time on the live, production server and with great confidence of the outcome.</strong> Sure enough, I restored the AD replication functionality of the server with minimal downtime, without crossing my fingers, holding my breath, and hoping against hope that it would work and not trash the server.</p>
<p>What is more, since the production server is a virtual server, and I have VPN access to the virtual host, I was able to perform the entire operation from my home office, 30 miles away. I didn&#8217;t swap any tapes, set up any lab hardware, or drive to the server site late at night. I did the whole thing in comfortable clothes with a 2-liter bottle of Ruby Red Squirt, Winamp playing &#8220;Save Me&#8221; by Queen, and my devoted cat purring on my lap.</p>
<p>What could be better than that?</p>
<p><em><span style="color: #003300;">Update: It was very handy to be able to do the above scenario, but what is even handier is that I was able to find a significantly simpler method. So much simpler, I wonder why it did not occur to me sooner, and why Microsoft doesn&#8217;t have this listed in their KB article.</span></em></p>
<p><em><span style="color: #003300;">I set this problem up in a lab scenario again, and this time rather than do a complicated restore of an earlier version of the machine, I simply:</span></em></p>
<ul>
<li><em><span style="color: #003300;">Performed a System State backup of the machine (in its broken, non-replicating condition).</span></em></li>
<li><em><span style="color: #003300;">Booted it into Directory Services Restore Mode.</span></em></li>
<li><em><span style="color: #003300;">Restored the System State backup, carefully NOT selecting the option to make it authoritative.</span></em></li>
<li><em><span style="color: #003300;">Rebooted, and ran the above repadmin commands to re-enable replication.</span></em></li>
</ul>
<p><em><span style="color: #003300;">After that, I was able to trigger another replication, and it worked just fine.</span></em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.bruteforcetech.com/index.php/archives/438/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
