Thursday, August 8, 2019

untagged - netstat tips and tricks

In the same vein as the "Useful Command-line" questions (for Windows, Linux, and Mac)
, I think it would be handy to have "useful ways to use utility x" questions. Man pages tell you what parameters do, but not necessarily why you would use them, what the result means, what useful things the command does that you'd never know without extensive experimentation, or how to get the answer you really want.




I'd like to know about netstat. It would appear that I should be able to figure which processes are using bandwidth, and, indeed, how fast the system is using bandwidth. It also looks useful for detecting unwanted connections (likely virii), and it gives all sorts of routing information (that I only had to play with when trying to make a Sharp Zaurus PDA use TCP/IP over USB.) In other words, it sounds like a gold mine, and I was hoping some of you would share nuggets of information you've found.



Please include the version of netstat and your OS in your reply. It would be nice to see some sample output and know what it means. I've marked this question as community wiki, and I hope you'll do the same in your answers, so that other people, knowing a different OS, can put down a near equivalent command if they know, in the same answer, and then we can vote on which answers are the most useful.

Wednesday, August 7, 2019

email - Is This Feasible - Running MailWash on a dedicated machine to pre-check




Is This Feasible - Running MailWash on a dedicated machine to pre-check 80-100 email accounts before end-users check with Outlook?



We have some major SPAM issues at my company with some users receiving over 1000 SPAM messages per day. Our mail is web-based and managed by a local ISP that does not offer any SPAM filtering at all. All user are required to check their mail with Outlook 2003/2007.



What are some of the issues that I might face if I run MailWAsh on a dedicated machine to precheck everyones mail numerous times per day. If you arent familiar with MailWash, thats exactly what it does, although it is meant to run locally on each machine. It prechecks mail, weeds out SPAM, and leaves legimate mail. When the user send/receives in Outlook, they hopefully receive only the legit mail left on the server.


Answer



Yes. It's pretty much the same way that I have my family's postfix/linux mail server set; due to some bad filtering when I first started, mailscanner/clamav simply flags the message as spam and gives it a meta heading with a spam score. When the user's client accesses it, a rule in the client filters the spam into the trash bin automatically where the user can retrieve it if they think it was a false positive.



Now, a better solution would be to switch to a host that at least scans your incoming mail, or if you have control over your DNS zone, then you could always just route your mail through a server that you have set up with mailscanner or similar, strip/quarantine the mail, and THEN roue to the Exchange server.


dell perc - Cable for SFF-8087 to SAS drives

I have a bunch of 3.5" SAS hard drives that I removed from one of my raid enclosures that has a backplane and want to reuse those drives with a Perc H700 controller in a PC that is a full tower system so it doesn't have a backplane in it. But want to reuse the drives there. Any recommendations for a cable that would go from SFF-8087 to 4 SAS connectors with power? I thought the breakout cables I had were what I needed but they were just 8087 to SATA connectors.



Thanks.



JR

Tuesday, August 6, 2019

windows server 2008 r2 - Group Policy installation failed error %%1274



OK, I have a really tough one I've already spent all morning on.



PC is a Win7 64 with SP1 and all MS Patches
Usual error everyone is familiar with:

The assignment of application Adobe Reader X MUI from policy Software Install failed. The error was : %%1274



Failed to apply changes to software installation settings. The installation of software deployed through Group Policy for this user has been delayed until the next logon because the changes must be applied before the user logon. The error was : %%1274




  1. gpupdate /force /boot

  2. Done: Always wait for the network at computer startup and logon = Enabled

  3. Done: Startup policy processing wait time = 30, 120

  4. Done: Updated network card drivers

  5. Done: Deleted HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Group Policy


  6. Done: GPO permissions check: Authenticated Users have Read access

  7. Done: Share permissions check: Everyone has Full access

  8. Done: Folder permissions check: Authenticated Users have Read and
    Execute permissions

  9. Done: File Permissions check: Inherited

  10. Done: PSExec -i -s cmd.exe to make sure I have access to the network
    files

  11. Done: PSExec -i -s cmd.exe + re-run explorer.exe and manually start
    the MSIs works fine (they install)

  12. Done: I've had instances where a network share with a space in it

    didn't work, so I've added a Share name without a space but the
    installer still fails on that package (and all the others).



I've seen this happen with some WiFi cards, but this computer is using Ethernet.



Is there a way of seeing the MSIExec logs to see exactly what transpired?



As an aside, while all the old Group Policy settings have applied, some IE10 settings I added recently are also refusing to apply.


Answer




Oh dear. It took me the whole day, but I found this Windows 7 SP1 bug:
http://support.microsoft.com/kb/2459530



DHCP doesn't get an address on first request because the Windows Boot Firewall rejects the DHCP answer before the Windows Firewall has loaded and replaced it, and allows DHCP answers. In the mean time GP fails to process in that gap.



Ended up it is affecting all GP deployment on this domain (small domain).



MS, I want a refund for my time.


Monday, August 5, 2019

Cassandra: when to add capacity?



How does one know when it's time to add capacity to a cassandra cluster? Error msgs? Performance? Some other tell-tale sign?



Since capacity planning with Cassandra is a (seemingly) black art knowing where to start and when to grow could be somewhat problematic.



Answer



Without knowing anything about your workload, I'd start looking at:




  • IO queue length

  • CPU load

  • Amount of data read vs written

  • GC behavior

  • Compaction stats




When any of these start to get "high" (definition depends on your hardware) then it's time to revisit your application, or scale up.


Sunday, August 4, 2019

windows - Dynamic DNS Registration over VPN?



In our Windows AD domain, we have 2 DCs that also act as our DNS servers which allow the client computers to update their A records. We have a lot of outside salespeople, so some of our laptops have to go off-site for long periods of time and connect in through our (full tunnel) SSL VPN, using a Fortinet VPN client. DNS over the VPN tunnel works fine, VPN clients are able to resolve local hostnames perfectly.




The problem is that the clients connecting in over the VPN do not update the DNS records with their SSLVPN Adapter IP address. In fact, they don't update the DNS server at all. From my research, I've determined that clients are supposed to send an update to the DNS server "when a change occurs," but that doesn't seem to happen when the SSL VPN adapter connects and gets an IP address.



I have thought about deploying PowerShell scripts to all of the computers that employ the DNSCMD command when it detects that the SSL VPN adapter has an IP address, but that solution is far from ideal, feels overly complicated and very messy. I am hoping there is a simpler solution to this that I have not been able to dig up.


Answer



In the SSLVPN adapter, in TCP/IP properties, DNS, make sure Register this connection's addresses in DNS actually checked.



Often on a VPN connection it isn't...


zfs - Acquiring new servers to run ESXi and SAN/NAS



Here is our goal:



Setup new servers to turn our entire physical computer network into 3 physical groups, which are:





  • Server 1 - NAS - Openfiler/NexentaStor CE/FreeNAS/(Other Suggestions)







  • Server 2 - ESXi Server with the following VM's:



    • VM1 - AD/DNS/DHCP - Windows SBS 2008

    • VM2 - SQL Server 2008 r2 / Database Tier - Windows Server 2008 R2

    • VM3 - Sharepoint 2010 / Applicaton Server Tier - Windows Server 2008 R2

    • VM4 - IIS / Web Front End Tier - Windows Server 2008 R2

    • VM5 - Windows Multipoint Server 2011 - Supporting 10 Clients / Some with 2D Cad









  • 10 Clients - Atrust M220 WMS Zero Clients



Question:



For servers 1 & 2, I would like to know what configuration ensures maximum performance?



Configuration means:





  • Hot Swap Hard Disk Options


    • iSCSI targets

    • Regular volumes

    • 7500 SAS disks

    • 10/15K SAS disks

    • VM's on iSCSI target on NAS machine

    • VM's on DAS


    • RAID 0/1/5/10

    • No RAID and ZFS file system


  • Memory Configurations


    • 2/4/8/16/32 Gb DDR3 Memory


  • CPU Configuration



    • Xeon / Opteron

    • 2/4/8 Cores

    • 1/2 Physical CPU's


  • OS


    • For NAS server, Openfiler OR NexentaStor CE OR FreeNAS OR some other free option




Answer



It's quite a bit to digest. This is a solution that could work, and I am a proponent of ZFS-based solutions, but I'd initially ask why you wish to have a storage server with only one VM host. Granted, you could expand to multiple hosts over time... But looking at your setup plan, I'd almost recommend a large standalone server with robust local storage. The NAS wouldn't buy you anything with one VM host.



Think something like a current-model HP ProLiant DL380 with 8 or more disks (RAID 1+0, please), running ESXi with plenty of RAM to handle your setups without oversubscribing. Two 6-core CPUs should round it out.


linux - How to SSH to ec2 instance in VPC private subnet via NAT server

I have created a VPC in aws with a public subnet and a private subnet. The private subnet does not have direct access to external network. S...