Wednesday, December 30, 2009

Optimizing GPO Performance

Want to speed up the computer startup and user login process? Sometimes, it can be terribly slow to wait while login on or waiting for the server to boot up, especially when the client CSE are loading whatever GPO settings applied to them. Usually, we create single-purpose GPOs targeting at either computer setting or user setting only. If that's the case, you can disable either setting on the GPMC (Group Policy Management Console) to speed up the process.

Tuesday, December 29, 2009

Command to change Computer Time Zone

I was searching for the GPO setting to change the multiple computer time zone and I found none - not even in Administrative Template settings that supposed to set system registry.

I searched the Internet and found this "hidden command" - tzutil.

tzutil /g (To know current time zone)
tzutil /l (To get a list of all available time zones)
tzutil /s time_zone_ID (To change time zone)

To set to SG time: tzutil /s "Singapore Standard Time". Deploy it on startup script. It works on Win7 and W2K8 computers.

Monday, December 7, 2009

Windows System Resource Manager

Windows System Resource Manager (WSRM) can be used in 2 modes. Firstly, it allows application profiling, which helps identify the amount of resources (e.g. CPU, memory etc) that the applications consume.

Secondly, it can also operate in manage mode. WSRM uses its allocation policies to control how many resources applications can use on a server. If applications exceed the allocation, WSRM can be stop the applications from executing and make sure other applications can continue to operate. However, WSRM will not enforce the resource policies until the processor usage exceeds 70 percent.

WSRM can be assigned to manage 3 objects, namely processes, users and IIS application pools. WSRM is available for download for Windows 2003 and is available as a feature to be added in Windows 2008.

Thursday, November 26, 2009

VRF aware Site-to-Site IPSec

Cisco introduced new configuration guidelines for VRF aware IPSec. I spent a day worth and finally got it working. The understanding of Front Door VRF (FVRF) and and Inside VRF (IVRF) is key. Each IPsec tunnel is associated with two VRF domains. The outer encapsulated packet belongs to one VRF domain, which Cisco called it FVRF. The inner & encrypted IP packet belongs to another domain called the IVRF.

Part 1 is the base configuration without any IPSec. I'm using Loopback interface to simulate internal trusted network address (e.g. LAN). GRE tunnel is setup to bridge 2 separate LANs. In part 2, IPSec profile is applied to encrypt GRE tunnel (a.k.a GRE over IPSec).

Part 1 - Base Configuration
hostname Router1
ip vrf FVRF
rd 0:0
!
ip vrf IVRF
rd 1:1
!
interface Loopback0 # internal address
ip vrf forwarding IVRF
ip address 192.168.255.1 255.255.255.255
!
interface Tunnel0
ip vrf forwarding IVRF
ip add 192.168.1.1 255.255.255.252
tunnel source Serial1/0
tunnel destination 192.168.1.2
tunnel vrf FVRF
!
interface Serial1/0
ip vrf forwarding FVRF
ip address 192.168.1.1 255.255.255.252
!
ip route vrf IVRF 192.168.255.2 255.255.255.255 Tunnel0

----
hostname Router2
ip vrf FVRF
rd 0:0
!
ip vrf IVRF
rd 1:1
!
interface Loopback0
ip vrf forwarding IVRF
ip address 192.168.255.2 255.255.255.255
!
interface Tunnel0
ip vrf forwarding IVRF
ip add 192.168.1.2 255.255.255.252
tunnel source Serial1/0
tunnel destination 192.168.1.1
tunnel vrf FVRF
!
interface Serial1/0
ip vrf forwarding FVRF
ip address 192.168.1.2 255.255.255.252
!
ip route vrf IVRF 192.168.255.1 255.255.255.255 Tunnel0

Part 2 - IPSec related crypto configuration
Router1
crypto keyring vpnKey vrf FVRF
pre-shared-key add 192.168.1.2 key vpnkey
no crypto xauth s1/0 #exempt extended authentication for physical interface
!
crypto isakmp policy 1
authentication pre-share
!
crypto isakmp profile isaPro
vrf FVRF
keyring vpnKey
match identity add 192.168.1.2 255.255.255.255 FVRF
!
crypto ipsec transform-set myset esp-des esp-md5-hmac
!
crypto ipsec profile ipsecPro
set transform myset
set isakmp-profile isaPro
!
int Tunnel0
tunnel mode ipsec ipv4 #apply IPSec to protect GRE tunnel
tunnel protection ipsec profile ipsecPro
!
-------

Router2
crypto keyring vpnKey vrf FVRF
pre-shared-key add 192.168.1.1 key vpnkey
!

no crypto xauth s1/0
!
crypto isakmp policy 1
authentication pre-share
!
crypto isakmp profile isaPro
vrf FVRF
keyring vpnKey
match identity add 192.168.1.1 255.255.255.255 FVRF
!
crypto ipsec transform-set myset esp-des esp-md5-hmac
!
crypto ipsec profile ipsecPro
set transform myset
set isakmp-profile isaPro
!
int Tunnel0
tunnel mode ipsec ipv4
tunnel protection ipsec profile ipsecPro



Verification
Router1#ping vrf IVRF 192.168.255.2 source lo0

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.255.2, timeout is 2 seconds:
Packet sent with a source address of 192.168.255.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 372/429/512 ms

Router1#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id slot status
192.168.1.1 192.168.1.2 QM_IDLE 1001 0 ACTIVE

IPv6 Crypto ISAKMP SA

Router1#sh crypto session
Crypto session current status

Interface: Tunnel0
Profile: isaPro
Session status: UP-ACTIVE
Peer: 192.168.1.2 port 500
IKE SA: local 192.168.1.1/500 remote 192.168.1.2/500 Active
IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0
Active SAs: 2, origin: crypto map

Thursday, November 5, 2009

SID reset on Win7 image

If you want a quick SID reset on a Win7 clone, the official way is to use sysprep on "c:\Windows\System32\sysprep\sysprep.exe" and select "Generalize". Remember to perform this task before joining the machine to domain.

For corporate Windows 7 deployment, Microsoft provides a free toolkit called Microsoft Deployment Toolkit (MDT) 2010, which is specifically designed for imaging & deploying Windows 7 machines.

Friday, October 30, 2009

OU Delegation

Imagine your infrastructure now contains several OUs of computers and users and you want to delegate them to different admin groups, including the rights to set their own group policies. How do you do this?

Launch "Active Directory Users and Computer". Right click on the OUs that you want to delegate and select "Delegate Control". Select the delegated groups and tasks. For full delegation, select "Create a custom task to delegate" and select all permissions subsequently as follows:



To assign the rights to create Group Policy, launch "Group Policy Management Console" and click on "Group Policy Objects". Click "Delegation" tab on right plane and add the delegated groups as follows:

Friday, October 23, 2009

Native VHD mount in W2K8 R2

Another new feature in W2K8 R2 - you can now create and mount Virtual Hard Disk (VHD). Go to Server Manager -> Storage. Expand into Disk Management, mouse over to More Actions. Create & mount VHD just like what you do for a new physical hard disk.


What about turning on Bitlocker to encrypt virtual volume? Add "Bitlocker" feature on the Server Manager. After reboot, go to control panel -> Bitlocker Drive Encryption. Hey, the VHD is ready for you to encrypt (See picture below). Next, instead of storing the key on the TPM, we will enrol a smart card to encrypt this virtual volume. We will update again when we are ready.