달력

1

« 2025/1 »

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
2008. 12. 15. 23:50

Forefront Client Security(FCS) 배포 - 클라이언트 Security2008. 12. 15. 23:50

FCS 클라이언트의 사전 요구 사항

1. Task Scheduler 서비스 확인
시작 유형 : 자동
로그온 : Local System, '서비스와 데스크탑 상호 작용 허용' 체크

2. 윈도우즈 인스톨러 3.1 설치 (XP SP2)
http://go.microsoft.com/fwlink/?LinkID=62933

3. Forefront Client Security Filter Manager QFE (XP SP2)
http://support.microsoft.com/KB/914882

4. Windows update agent 2.0(엔진/패턴 업데이트를 위해 필요)
- Windows update 사이트에서 한 번이라도 업데이트를 받았다면 설치되어 있음

32비트(X86 기반) 컴퓨터용 Windows Update Agent 독립 실행형 설치 관리자
http://download.windowsupdate.com/v6/windowsupdate/redist/standalone/WindowsUpdateAgent20-x86.exe

x64 기반 컴퓨터용 Windows Update Agent 독립 실행형 설치 관리자
http://download.windowsupdate.com/v6/windowsupdate/redist/standalone/WindowsUpdateAgent20-x64.exe

5. 기존에 설치되어 있는 백신 제거


AD 환경, WORKGROUP 환경 모두 클라이언트의 업데이트 소스를 WSUS(Distribution Server) 변경
'자동 업데이트 구성' -> 사용, '자동 업데이트로 바로 설치' -> 사용



AD 환경의 클라이언트

1. FCS 클라이언트 설치
ClientSetup.exe /CG <MOM Management group> /MS <Collection Server FQDN>

2. MOM 서버에서 Agent를 설치한 클라이언트 승인 (1시간 후 자동으로 승인됨)

3. 관리 서버의 정책 설정 후 배포
그룹 정책을 이용한 배포 (OU, 보안 그룹)
- 클라이언트 컴퓨터 계정이 OU에 있는 경우 재부팅 불필요
- 클라이언트 컴퓨터 계정이 보안 그룹에 속하는 경우 재부팅해야 적용됨

Fcslocalpolicytool을 이용한 정책 배포
- 관리 서버의 정책 설정 후 '파일 추가'를 통해 REG 파일 생성 후 다음 명령을 이용하여 적용
fcslocalpolicytool.exe /f /i <policy.reg>


WORKGROUP 환경의 클라이언트

1. MOM 관리자 콘솔 실행 -> 관리 -> 전역 설정 -> 보안 -> '상호 인증 필요' 체크 해제

2. MOM Agent 설치
MOMAGENT.MSI CONFIG_GROUP=<MOM Management group> MANAGEMENT_SERVER=<Collection Server FQDN> REQUIRE_AUTH_COMMN=0

3. FCS 클라이언트 설치
CLIENTSETUP.EXE /NOMOM

4. MOM 서버에서 Agent를 설치한 클라이언트 승인 (1시간 후 자동으로 승인됨)

:
Posted by 커널64
2008. 12. 11. 18:45

Windows Server 2003 R2의 DFS-R에 대한 FAQ Etc.2008. 12. 11. 18:45

http://technet.microsoft.com/en-us/library/cc773238.aspx

Interoperability
Can DFS Replication communicate with FRS?
Can DFS Replication replace FRS for SYSVOL replication on Windows Server 2003 R2?
Can I upgrade from FRS to DFS Replication without losing configuration settings?
Can I use DFS Replication in a mixed Windows/UNIX environment?
Can I use Volume Shadow Copy Service with DFS Replication?
Do file system policies impact DFS Replication?
Does DFS Replication replicate mailboxes hosted on Microsoft Exchange Server?
Does DFS Replication support file screens created by File Server Resource Manager?
Is DFS Replication cluster aware?
Is DFS Replication compatible with RIS and WDS?
Is it possible to use DFS Replication with Offline Files?
What antivirus applications are compatible with DFS Replication?
What are the benefits of using DFS Replication instead of Windows SharePoint Services?

Limitations and requirements
Can DFS Replication replicate between branch offices without a VPN connection?
Can DFS Replication replicate files encrypted with the Encrypting File System?
Can DFS Replication replicate Outlook .PST files?
Can I use DFS Replication in a workgroup?
Can more than one folder be replicated on a single server?
Does DFS Replication require DFS Namespaces?
Does DFS Replication require time synchronization between servers?
Does DFS Replication support replicating an entire volume?
Does DFS Replication support RPC over HTTP?
Does DFS Replication work across wireless networks?
Does DFS Replication work on FAT volumes?
Does DFS Replication work with sparse files?
Do I need to log in as administrator to replicate files?
Is DFS Replication suitable for replicating roaming profiles?
Is there a file character limit or limit to the folder depth?
Must members of a replication group reside in the same domain?
What are the supported limits of DFS Replication?
When shouldn't I use DFS Replication?
Why is a schema update required for DFS Replication?

Monitoring and management tools
Can I automate the health report to receive warnings?
Can I use Microsoft Operations Manager to monitor DFS Replication?
Does DFS Replication support remote management?
Do Ultrasound and Sonar work with DFS Replication?
Is there a way to know the state of replication?

Performance
Does DFS Replication support dial-up connections?
Does DFS Replication perform bandwidth sensing?
Does DFS Replication throttle bandwidth per schedule, per server, or per connection?
Does DFS Replication use Active Directory Domain Services to calculate site links and connection costs?
How does DFS Replication avoid saturating a connection?
How does DFS Replication performance compare with FRS?
How frequently does DFS Replication replicate data?
How much of my server's system resources will DFS Replication consume?
What happens if a WAN link fails during replication?
Remote Differential Compression details
Are changes compressed before being replicated?
Can an administrator turn off RDC or change the threshold?
Does RDC work on all file types?
How does RDC work on a compressed file?
Is cross-file RDC enabled when upgrading to Windows Server 2003 Enterprise Edition?
Is RDC true block-level replication?
What happens if I rename a file?
What is cross-file RDC?
What is RDC?
When is a RDC used for replication?

Replication details
Can I change the path for a replicated folder after it is created?
Can I configure which file attributes are replicated?
Can I control which member is replicated?
Can I seed a replication group member with data prior to the initial replication?
Does DFS Replication overcome common File Replication Service issues?
Does DFS Replication replicate files in chronological order?
Does DFS Replication replicate files that are being used by another application?
Does DFS Replication replicate NTFS file permission, alternate data streams, hard links, and reparse points?
Does DFS Replication replicate timestamp changes if no other changes are made to the file?
Does DFS Replication replicate updated permissions on a file or folder?
Does DFS Replication support merging text files in the event of a conflict?
Does DFS Replication use encryption when transmitting data?
Is it possible to disable the use of encrypted RPC by DFSR?
How do I force replication or polling?
Is it possible to configure a quiet time between replications for files that change frequently?
Is it possible to configure one-way replication with DFS Replication?
Is there a way to force a complete replication of all files including unchanged files?
What happens if the primary member suffers a database loss during initial replication?
What happens if the replication schedule closes while a file is being replicated?
What happens when two users simultaneously update the same file on different servers?

Staging

Does DFS Replication prevent other applications from accessing a file during staging?
Is it possible to change the location of the staging folder with the DFS Management Tool?
When are files staged?
What happens if a file is changed after it is staged but before it is completely transmitted to the remote site?

:
Posted by 커널64
2008. 12. 9. 18:40

윈도우 2000/2003/XP Sysprep 파일 Etc.2008. 12. 9. 18:40

Windows 2000 Sysprep



Windows XP/2003 Sysprep


:
Posted by 커널64
2008. 12. 9. 15:50

SCCM Agent의 지원 운영체제 SystemCenter2008. 12. 9. 15:50

운영체제

x86

x64

ia64

Windows 2000 Professional SP4

O

   
Windows XP Professional (SP2/SP3)

O

O

 
Windows XP Tablet PC SP2

O

   
Windows Embedded Standard 2009

O

   
Windows Embedded for Point of Service (WEPOS)

O

   
Windows Embedded POSReady 2009

O

   
Windows Fundamentals for Legacy PCs (WinFLP)

O

   
Windows Vista Business Edition (RTM/SP1)

O

O

 
Windows Vista Enterprise Edition (RTM/SP1)

O

O

 
Windows Vista Ultimate Edition (RTM/SP1)

O

O

 
Windows 2000 Server SP4

O

   
Windows 2000 Advanced Server SP4

O

   
Windows 2000 Datacenter SP4

O

   
Windows Server 2003 Web Edition (SP1/SP2)

O

   
Windows Server 2003 Standard Edition (SP1/SP2)

O

O

 
Windows Server 2003 Enterprise Edition (SP1/SP2)

O

O

O

Windows Server 2003 Datacenter Edition (SP1/SP2)

O

O

O

Windows Server 2003 R2 Standard Edition

O

O

 
Windows Server 2003 R2 Enterprise Edition

O

O

 
Windows Server 2003 R2 Datacenter Edition

O

O

 
Windows Server 2008 Standard Edition

O

O

 
Windows Server 2008 Enterprise Edition

O

O

 
Windows Server 2008 Datacenter Edition

O

O

 
Windows Server 2008 for Itanium-Based Systems    

O

:
Posted by 커널64
2008. 12. 9. 13:13

IIS 웹사이트의 식별자 변경 Etc.2008. 12. 9. 13:13

SCCM의 MP(Management Point)의 경우 기본적으로 IIS://LocalHost/W3SVC/1 위치에 웹사이트를 생성하기 때문에 기본웹사이트를 지우고 재생성했다면 식별자가 변경되어 MP 설치 작업이 실패하게 된다.
이런 경우 다음 명령을 이용해 기본 웹 사이트의 식별자를 변경해야 할 수도 있다.

CSCRIPT %SYSTEMDRIVE%\Inetpub\AdminScripts\adsutil.vbs STOP_SERVER W3SVC/old_identifier_number

CSCRIPT %SYSTEMDRIVE%\Inetpub\AdminScripts\adsutil.vbs MOVE W3SVC/old_identifier_number W3SVC/new_identifier_number

CSCRIPT %SYSTEMDRIVE%\Inetpub\AdminScripts\adsutil.vbs START_SERVER W3SVC/new_identifier_number
:
Posted by 커널64

SCVMM 2008 설치 후 Hyper-V 호스트를 등록하면 Need Attention 경고와 함께 Upgrade available로 나타나는 경우 해당 Hyper-V 호스트에 다음 업데이트를 적용하면 해결된다.

KB956589 - KO EN
KB956774 - KO EN



Hyper-V RTM
KB950050 - KO
KB950050 - EN

:
Posted by 커널64

Transfer Files... 과정 중에 Critical 오류가 발생하며 아래 파일 복사 오류가 발생한다.
무슨 이유인지 모르겠으나... Evaluation Version에는 있으나 MSDN 버전의 ISO 이미지에는 없다.

<Source Directory>\SMSSETUP\ADMINUI\XMLSTORAGE\FORMS에 붙혀 넣고 재설치한다.


PS)원인을 알았다... 해당 파일 경로가 너무 길어(256bit 초과) 뒷 부분이 잘려서 나타난 증상이었다. 이런.....;;;;
:
Posted by 커널64

지원되는 운영 체제

P2V 변환을 수행하려면 원본 컴퓨터에 다음의 지원되는 운영 체제 중 하나가 있어야 합니다.

  • Windows Server 2008(32비트)
  • Windows Server 2008(64비트)
  • Windows Server 2003(32비트) SP1 이상
  • Windows Server 2003(64비트) SP1 이상
  • Windows 2000 Server SP4 이상(오프라인 P2V만 해당)
  • Windows 2000 Advanced Server SP4 이상(오프라인 P2V만 해당)
  • Windows XP Professional(32비트) SP2 이상
  • Windows XP Professional(64비트) SP2 이상
  • Windows Vista 서비스 팩 1(32비트)
  • Windows Vista SP1 이상(64비트)



Online P2V 과정

1. VMM은 원본 컴퓨터의 하드웨어 및 소프트웨어 설정을 가져오기 위해 원본 컴퓨터에 VMM Agent를 설치한다.
변환이 완료되면 Agent는 제거된다.

2. VMM은 다음과 같은 방법을 통해 원본 컴퓨터의 하드웨어와 소프트웨어 설정을 가져온다.
VMM Agent는 하드웨어, 소프트웨어, 서비스, 핫픽스, 볼륨(파일 시스템, 볼륨 타입, 섹터) 정보들을 수집한다.
그 다음 VMM Agent는 이 정보들을 XML 파일의 형태로 VMM 데이터베이스로 내보낸다.
VMM은 원본 컴퓨터의 OS 및 구성에 대해 가상화가 가능한지를 판단하고 가상화가 가능하다고 판단되면 VMM은 필요한 패치 정보를 확인하고 다운로드한다.

3. 이미징 과정
VSS에 의해 각 NTFS 볼륨이 캡춰된다. 만약 대상 VHD 파일이 동적 확장으로 설정되어 있다면 데이터 부분만 캡춰하고 빈공간은 캡춰하지 않는다.
캡춰된 데이터는 원본 컴퓨터에서 BITS를 실행 중인 VMM 호스트로 전송된다.
각각의 물리적인 볼륨은 별도의 VHD 파일들로 변환된다.

4. 수정 과정
VMM은 가상 하드 디스크와 가상 머신의 생성을 준비한다.

5. 가상 머신 생성 과정
VMM은 가상 머신을 생성하고 하드 디스크와 네트워크 어뎁터, CD-ROM, 메모리를 구성한다.


Offline P2V 과정
Offline P2V는 VSS를 지원하지 않는 윈도우 2000 서버의 변환에 사용되는 옵션이다. Online P2V와 달리 만약 원본 컴퓨터에 Windows PE가 지원하지 않는 드라이버가 있다면 해당 드라이버를 제공해야만 한다.

1. VMM Agent 설치. VMM은 원본 컴퓨터에 VMM Agent를 설치한다.

2. VMM Agent는 원본 컴퓨터에 Windows PE를 설치하고 부트 레코드를 변경한다. 이 과정을 통해 원본 컴퓨터는 기본 운영체제가 아닌 Windows PE로 부팅하게 된다.

3. VMM은 물리적인 디스크의 데이터를 전송한다. 이 과정에서 VSS에서와 같은 스냅샷은 존재하지 않는다.

4. 남은 과정은 Online P2V의 수정 과정, 가상 머신 생성과정과 동일하게 진행된다.

:
Posted by 커널64
2008. 12. 8. 20:47

Hyper-V RTM의 지원 운영체제 Virtualization2008. 12. 8. 20:47

Supported Server Operating Systems

Microsoft Windows Server 2008 x64 (VMs configured with 1, 2 or 4 virtual processors)
Windows Server 2008 Standard
Windows Server 2008 Enterprise
Windows Server 2008 Datacenter
Windows HPC Server 2008
Windows Web Server 2008
Windows Server 2008 Standard without Hyper-V
Windows Server 2008 Enterprise without Hyper-V
Windows Server 2008 Datacenter without Hyper-V

Microsoft Windows Server 2008 x86 (VMs configured with 1, 2 or 4 virtual processors)
Windows Server 2008 Standard (x86 Edition)
Windows Server 2008 Enterprise (x86 Edition)
Windows Server 2008 Datacenter (x86 Edition)
Windows Web Server 2008 (x86 Edition)
Windows Server 2008 Standard without Hyper-V (x86 Edition)
Windows Server 2008 Enterprise without Hyper-V (x86 Edition)
Windows Server 2008 Datacenter without Hyper-V (x86 Edition)

Microsoft Windows Server 2003 x86 (VMs configured with 1 or 2 virtual processors)
Windows Server 2003 R2 Standard x86 Edition with Service Pack 2
Wndows Server 2003 R2 Enterprise x86 Edition with Service Pack 2
Windows Server 2003 R2 Datacenter x86 Edition with Service Pack 2
Windows Server 2003 Standard x86 Edition with Service Pack 2
Windows Server 2003 Enterprise x86 Edition with Service Pack 2
Windows Server 2003 Datacenter x86 Edition with Service Pack 2
Windows Server 2003 Web Edition with Service Pack 2

Microsoft Windows Server 2003 x64 (VMs configured with 1 or 2 virtual processors)
Windows Server 2003 R2 Standard x64 Edition with Service Pack 2
Windows Server 2003 R2 Enterprise x64 Edition with Service Pack 2
Windows Server 2003 R2 Datacenter x64 Edition with Service Pack 2
Windows Server 2003 Standard x64 Edition with Service Pack 2
Windows Server 2003 Enterprise x64 Edition with Service Pack 2
Windows Server 2003 Datacenter x64 Edition with Service Pack 2

Microsoft Windows 2000 Server (VMs configured with 1 virtual processor)
Windows 2000 Server with Service Pack 4
Windows 2000 Advanced Server with Service Pack 4

Linux Distributions (VMs configured with 1 virtual processor)
Suse Linux Enterprise Server 10 with Service Pack 2 x86 Edition
Suse Linux Enterprise Server 10 with Service Pack 2 x64 Edition
Suse Linux Enterprise Server 10 with Service Pack 1 x86 Edition
Suse Linux Enterprise Server 10 with Service Pack 1 x64 Edition


Supported Client Operating Systems

Microsoft Windows Vista x86
(VMs configured with 1 or 2 virtual processors)
Windows Vista Business x86 with Service Pack 1
Windows Vista Enterprise x86 with Service Pack 1
Windows Vista Ultimate x86 with Service Pack 1

Microsoft Windows Vista x64 (VMs configured with 1 or 2 virtual processors)
Windows Vista Business x64 with Service Pack 1
Windows Vista Enterprise x64 with Service Pack 1
Windows Vista Ultimate x64 with Service Pack 1

Windows XP Professional x86 with SP3 (VMs configured with 1 or 2 virtual processors)

Windows XP Professional x86 with SP2 (VMs configured with 1 virtual processor)

Microsoft Windows XP Professional x64 with SP2 (VMs configured with 1 or 2 virtual processors)

:
Posted by 커널64
2008. 12. 8. 20:35

SCVMM 2008의 P2V Issue 해결 SystemCenter2008. 12. 8. 20:35

http://technet.microsoft.com/en-us/library/bb740927.aspx

Convert physical server fails with error 407: "The agent operation with server <computer name> was not successful."

Convert physical server fails with error 410: “Agent installation failed on <computer name>.”

Convert physical server fails with error 554: "Access is denied.
Permissions have not been granted to access the registry key
HKEY_LOCAL_Machine\vmmsystem\ControlSet001\ENUM\PCI\VEN_1011&DEV_009&SUBSYS_21140A00&REV_20."

Convert physical server fails with error 1206: "A Virtual Disk Service (VDS) error occurred on server <host name>."

Convert physical server fails with error 2940: "VMM is unable to complete the requested file transfer. The connection to the BITS server <server name> could not be established."

Convert physical server fails with error 3133: "Virtual Machine Manager could not connect to source computer <computer name> after it restarted into Windows PE."

Convert physical server fails with error 3134:" An internal agent error has occurred on <computer name>."

Convert physical server fails with error 3136: "An error occurred executing <file name>; on <server name>."

Convert physical server fails with error 3210: "Boot and\or System volume C was not selected or is not found on source machine <server name>. Selected machine <server name> cannot be virtualized. Verify that the boot and system volumes are selected for migration and the boot.ini file is present on the active volume of the boot drive. Then try the operation again."

:
Posted by 커널64