<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Matt</title>
	<atom:link href="http://www.ffoutpost.net/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ffoutpost.net</link>
	<description>Random Tech Journal</description>
	<lastBuildDate>Thu, 10 Dec 2009 01:51:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Openfiler Kernel 2.6.29.6-0.13.smp.gcc3.4.x86_64</title>
		<link>http://www.ffoutpost.net/2009/12/10/openfiler-kernel-2-6-29-6-0-13-smp-gcc3-4-x86_64</link>
		<comments>http://www.ffoutpost.net/2009/12/10/openfiler-kernel-2-6-29-6-0-13-smp-gcc3-4-x86_64#comments</comments>
		<pubDate>Thu, 10 Dec 2009 01:51:13 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Openfiler]]></category>
		<category><![CDATA[ethernet]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=391</guid>
		<description><![CDATA[With the latest version of the Openfiler Kernel Linux &#60;hostname&#62; 2.6.29.6-0.13.smp.gcc3.4.x86_64 #1 SMP Fri Nov 20 15:47:20 GMT 2009 x86_64 x86_64 x86_64 GNU/Linux  the network udev rules get rewritten for some reason.  So be sure to have some way to physically access the machine if for some reason you are not able to remote into [...]]]></description>
			<content:encoded><![CDATA[<p>With the latest version of the Openfiler Kernel Linux &lt;hostname&gt; 2.6.29.6-0.13.smp.gcc3.4.x86_64 #1 SMP Fri Nov 20 15:47:20 GMT 2009 x86_64 x86_64 x86_64 GNU/Linux  the network udev rules get rewritten for some reason.  So be sure to have some way to physically access the machine if for some reason you are not able to remote into it after rebooting the server.  I noticed this as I currently have a server with multiple ports that would respond to some machines but not all.  Digging around I found that the network ports had gotten remapped.  So to fix this take note of which port is assigned before you upgrade.  After you upgrade the system, be sure to edit the udev rules for the network ports located in:</p>
<p>/etc/udev/rules.d/70-persistent-net.rules</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/12/10/openfiler-kernel-2-6-29-6-0-13-smp-gcc3-4-x86_64/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exchange 2010RC to 2010RTM Upgrade</title>
		<link>http://www.ffoutpost.net/2009/12/10/exchange-2010rc-to-2010rtm-upgrade</link>
		<comments>http://www.ffoutpost.net/2009/12/10/exchange-2010rc-to-2010rtm-upgrade#comments</comments>
		<pubDate>Thu, 10 Dec 2009 01:24:41 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[exchange 2010]]></category>
		<category><![CDATA[upgrade]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=379</guid>
		<description><![CDATA[As Microsoft published prior to the Exchange 2010 RTM release, that people who installed the RC would be able to upgrade to the RTM with their currently running system.   I tested this out recently with my test system, and it was as simple as they said.  I&#8217;ll post some screen shots below, but it is [...]]]></description>
			<content:encoded><![CDATA[<p>As Microsoft published prior to the Exchange 2010 RTM release, that people who installed the RC would be able to upgrade to the RTM with their currently running system.   I tested this out recently with my test system, and it was as simple as they said.  I&#8217;ll post some screen shots below, but it is pretty much as simple as double click and go.  As a side note though, you should make sure to have all of the EMC and EMS closed.  Best to close everything running on the desktop if possible I suppose.  Then just run the setup.exe.  If you are going to install this off of a network, it would probably be better to place the files as close as you could to the server you are upgrading.</p>
<div id="attachment_380" class="wp-caption aligncenter" style="width: 677px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up1.png"><img class="size-full wp-image-380" title="exchange2010up1" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up1.png" alt="Select the language option that you want to upgrade." width="667" height="500" /></a>
<p class="wp-caption-text">Select the language option that you want to upgrade.</p>
</div>
<div id="attachment_381" class="wp-caption aligncenter" style="width: 677px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up2.png"><img class="size-full wp-image-381" title="exchange2010up2" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up2.png" alt="Previously I installed from the DVD so I only updated the DVD languages." width="667" height="500" /></a>
<p class="wp-caption-text">Previously I installed from the DVD so I only updated the DVD languages. Then press the Install Microsoft Exchange Server Upgrade to start the upgrade process.</p>
</div>
<div id="attachment_382" class="wp-caption aligncenter" style="width: 648px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up3.png"><img class="size-full wp-image-382" title="exchange2010up3" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up3.png" alt="Press Next to get started." width="638" height="555" /></a>
<p class="wp-caption-text">Press Next to get started.</p>
</div>
<div id="attachment_384" class="wp-caption aligncenter" style="width: 650px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up4.png"><img class="size-full wp-image-384" title="exchange2010up4" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up4.png" alt="The system will then do some readiness checks." width="640" height="556" /></a>
<p class="wp-caption-text">The system will then do some readiness checks.</p>
</div>
<div id="attachment_385" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up4a.png"><img class="size-medium wp-image-385" title="exchange2010up4a" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up4a-300x262.png" alt="If not, you will get an error like this." width="300" height="262" /></a>
<p class="wp-caption-text">If not, you will get an error like this.</p>
</div>
<div id="attachment_386" class="wp-caption aligncenter" style="width: 648px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up5.png"><img class="size-full wp-image-386" title="exchange2010up5" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up5.png" alt="Press the Upgrade button once all the checks have passed." width="638" height="557" /></a>
<p class="wp-caption-text">Press the Upgrade button once all the checks have passed.</p>
</div>
<div id="attachment_387" class="wp-caption aligncenter" style="width: 647px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up6.png"><img class="size-full wp-image-387" title="exchange2010up6" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up6.png" alt="Exchange will then go off upgrading the system automatically." width="637" height="556" /></a>
<p class="wp-caption-text">Exchange will then go off upgrading the system automatically.</p>
</div>
<div id="attachment_388" class="wp-caption aligncenter" style="width: 646px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up7.png"><img class="size-full wp-image-388" title="exchange2010up7" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/exchange2010up7.png" alt="The upgrade process is done." width="636" height="843" /></a>
<p class="wp-caption-text">The upgrade process is done.</p>
</div>
<p>It&#8217;s pretty straight forward.  I have my test environment broken up, so in this upgrade I only updated the Mailbox role which took about 8 minutes.  Your times will vary depending on how your servers are configured.  For a fairly basic setup, it was simple painless and straight forward.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/12/10/exchange-2010rc-to-2010rtm-upgrade/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Install VMware tools for Gentoo</title>
		<link>http://www.ffoutpost.net/2009/12/10/install-vmware-tools-for-gentoo</link>
		<comments>http://www.ffoutpost.net/2009/12/10/install-vmware-tools-for-gentoo#comments</comments>
		<pubDate>Thu, 10 Dec 2009 00:30:32 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Gentoo]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[vmware tools]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=181</guid>
		<description><![CDATA[Just as a note to myself and whomeever it may help.  Whenever you update your kernel in Gentoo you also need to make sure that you upgrade the vmware tools as well.  After recompiling and booting with the new kernel run the following command to update the vmware services.
emerge -v app-emulation/open-vm-tools
As an update to this, [...]]]></description>
			<content:encoded><![CDATA[<p>Just as a note to myself and whomeever it may help.  Whenever you update your kernel in Gentoo you also need to make sure that you upgrade the vmware tools as well.  After recompiling and booting with the new kernel run the following command to update the vmware services.</p>
<pre class="brush: bash">emerge -v app-emulation/open-vm-tools</pre>
<p>As an update to this, I had some problems getting this working since the last few updates (As of December 10th, 2009).  Have found a way to get it to work again though.</p>
<p>Emerge the additional modules that are needed with:</p>
<pre class="brush: bash">emerge -v app-emulation/vmware-modules</pre>
<p>Then rename (or delete) the *.la files in the following directory:</p>
<pre class="brush: bash">cd /etc/vmware-tools/plugins/common
ls -l *.la
-rwxr-xr-x 1 root root 1093 Dec  9 11:17 libhgfsServer.la
-rwxr-xr-x 1 root root 1108 Dec  9 11:17 libvix.la</pre>
<p>This last part I found is a bug for right now so hopefully it should be addressed in the future.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/12/10/install-vmware-tools-for-gentoo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware Last Resort System Recovery</title>
		<link>http://www.ffoutpost.net/2009/12/04/vmware-last-resort-system-recovery</link>
		<comments>http://www.ffoutpost.net/2009/12/04/vmware-last-resort-system-recovery#comments</comments>
		<pubDate>Fri, 04 Dec 2009 08:31:30 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[failed start]]></category>
		<category><![CDATA[Server]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=362</guid>
		<description><![CDATA[This might not be the best way to go about restoring your system.  But for me my iSCSI disk decided to do something crazy and after restarting it, my servers were not able to start up again.  Basically I had to re-add the host system to my VMware servers for it to start again, as [...]]]></description>
			<content:encoded><![CDATA[<p>This might not be the best way to go about restoring your system.  But for me my iSCSI disk decided to do something crazy and after restarting it, my servers were not able to start up again.  Basically I had to re-add the host system to my VMware servers for it to start again, as I was getting a configuration error.</p>
<ol>
<li>First remove the troubled server from your servers list.  Becareful to <em><strong>Remove from Inventory</strong></em> and not <em>Delete from disk</em>.</li>
<li>SSH into your VMware server and go to the /vmfs/volumes directory and then into the path where your troubled VMDK is residing.</li>
<li>I like to have the directory name the same as my machine name, so I move the directory to a different name before readding the system otherwise /vmfs/volumes/&lt;storename&gt;/domainad readded will become /vmfs/volumes/&lt;storename&gt;/domainad_1 or something weird like that.</li>
<li>Start by adding a new virtual machine and select custom.<a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate1.png"><img class="aligncenter size-medium wp-image-363" title="vmrecreate1" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate1-300x225.png" alt="vmrecreate1" width="300" height="225" /></a></li>
<li>Type in the machine name.  Again I like to keep things clean so I use the previous system name.
<div id="attachment_364" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate2.png"><img class="size-medium wp-image-364" title="vmrecreate2" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate2-300x225.png" alt="machinename" width="300" height="225" /></a>
<p class="wp-caption-text">machinename</p>
</div>
</li>
<li>Select the datastore where the problem system resides.
<div id="attachment_365" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate3.png"><img class="size-medium wp-image-365" title="vmrecreate3" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate3-300x225.png" alt="Select datastore where troubled system is." width="300" height="225" /></a>
<p class="wp-caption-text">Select datastore where troubled system is.</p>
</div>
</li>
<li>From here on you need to make sure that you select the same settings as you had before otherwise the system will not start up.
<div id="attachment_366" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate4.png"><img class="size-medium wp-image-366" title="vmrecreate4" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate4-300x225.png" alt="Machine Version Type" width="300" height="225" /></a>
<p class="wp-caption-text">Machine Version Type</p>
</div>
<div id="attachment_367" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate5.png"><img class="size-medium wp-image-367" title="vmrecreate5" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate5-300x225.png" alt="OS Type" width="300" height="225" /></a>
<p class="wp-caption-text">OS Type</p>
</div>
<div id="attachment_368" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate6.png"><img class="size-medium wp-image-368" title="vmrecreate6" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate6-300x225.png" alt="CPU Count" width="300" height="225" /></a>
<p class="wp-caption-text">CPU Count</p>
</div>
<div id="attachment_369" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate7.png"><img class="size-medium wp-image-369" title="vmrecreate7" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate7-300x225.png" alt="Memory Amount" width="300" height="225" /></a>
<p class="wp-caption-text">Memory Amount</p>
</div>
<div id="attachment_370" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate8.png"><img class="size-medium wp-image-370" title="vmrecreate8" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate8-300x225.png" alt="NIC Card" width="300" height="225" /></a>
<p class="wp-caption-text">NIC Card</p>
</div>
<p>Selecting the disk type is <em>really important</em>.  I picked the wrong one initially and the OS would crash as soon as it started loading what I assume was the disk drivers.</p>
<div id="attachment_371" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate9.png"><img class="size-medium wp-image-371" title="vmrecreate9" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate9-300x225.png" alt="Disk Controller Type" width="300" height="225" /></a>
<p class="wp-caption-text">Disk Controller Type</p>
</div>
</li>
<li>From here it is important that you select the <strong><em>Use an existing virtual disk</em></strong> option to restore your system back to working order.
<div id="attachment_372" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate10.png"><img class="size-medium wp-image-372" title="vmrecreate10" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate10-300x225.png" alt="Use an exisiting virtual disk" width="300" height="225" /></a>
<p class="wp-caption-text">Use an exisiting virtual disk</p>
</div>
<div id="attachment_373" class="wp-caption aligncenter" style="width: 490px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate11.png"><img class="size-full wp-image-373" title="vmrecreate11" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/vmrecreate11.png" alt="Select the original VMDK from the datastore" width="480" height="337" /></a>
<p class="wp-caption-text">Select the original VMDK from the datastore</p>
</div>
</li>
<li>Complete the configuration and go back to the terminal window.  Again in keeping everything clean, you need to move the VMDK that you just reconfigured to the proper directory.  Otherwise you will have a system taking up two directories.</li>
<li>From the old directory, you only need to move the &lt;servername&gt;.vmdk and the &lt;servername-(type)&gt;.vmdk to the newly created directory.</li>
<li>After moving the virtual disks over, edit the <em><strong>&lt;servername&gt;.vmx</strong></em> file and change the (depending on disk count) scsi0:0.fileName from the <em>oldpath</em> to the <em>newpath</em>.</li>
<li>Save the changes and exit out of the terminal.</li>
<li>With luck, you can start up your server again and should have no problems getting it to start.</li>
</ol>
<p>I initially got the idea from the VMware KB article located <a href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;cmd=displayKC&amp;externalId=1006232">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/12/04/vmware-last-resort-system-recovery/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to &#8220;undelete&#8221; Outlook Mail</title>
		<link>http://www.ffoutpost.net/2009/12/04/how-to-undelete-outlook-mail</link>
		<comments>http://www.ffoutpost.net/2009/12/04/how-to-undelete-outlook-mail#comments</comments>
		<pubDate>Fri, 04 Dec 2009 07:37:46 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office 2010]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[outlook]]></category>
		<category><![CDATA[undelete]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=359</guid>
		<description><![CDATA[There is a way via installing an additional Microsoft plugin to undelete hard deleted mail (ie. Shift + Del) from Outlook.
It can be found in the Microsoft KB246153 article.  It is fairly straight forward, even a little too much as after installing it I couldn&#8217;t tell if it installed correctly.  After you run it, start [...]]]></description>
			<content:encoded><![CDATA[<p>There is a way via installing an additional Microsoft plugin to undelete hard deleted mail (ie. Shift + Del) from Outlook.</p>
<p>It can be found in the Microsoft <a href="http://support.microsoft.com/kb/246153">KB246153</a> article.  It is fairly straight forward, even a little too much as after installing it I couldn&#8217;t tell if it installed correctly.  After you run it, start or restart outlook and then to start using it, all you need to do is right click on the folder and run the &#8220;Deleted Items Recovery&#8221; either from right clicking or going to <strong>Tools</strong> &gt; <strong>Deleted Items Recovery</strong>.<br />
Should you need to be trying to recover mails that were hard deleted you might heave a chance to get them back here before the server wipes them permanently.  It also save the hassle if having to go to archive or backup to try and retrieve the missing file.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/12/04/how-to-undelete-outlook-mail/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec Endpoint Protection Manager Server Change</title>
		<link>http://www.ffoutpost.net/2009/12/04/symantec-endpoint-protection-manager-server-change</link>
		<comments>http://www.ffoutpost.net/2009/12/04/symantec-endpoint-protection-manager-server-change#comments</comments>
		<pubDate>Fri, 04 Dec 2009 07:30:06 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Endpoint Protection]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[endpoint protection manager]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=354</guid>
		<description><![CDATA[&#8230;is a huge pain.  When it works, it works.  But more often than not for some reason I have a problem with the server going wrong doing something which more often than not involves me having to reinstall the server.  Because of this all the clients loose their connectivity.  Even better there is no real [...]]]></description>
			<content:encoded><![CDATA[<p>&#8230;is a huge pain.  When it works, it works.  But more often than not for some reason I have a problem with the server going wrong doing something which more often than not involves me having to reinstall the server.  Because of this all the clients loose their connectivity.  Even better there is no real &#8220;simple&#8221; solution to this.</p>
<p>Probably the best thing to do, as per Symantec&#8217;s website is to backup all the pertinent information.  Which can be found <a href="http://service1.symantec.com/support/ent-security.nsf/docid/2008081906512748?Open&amp;seg=ent">here</a>.  However, sometimes this isn&#8217;t even enough.  One thing to do first after trying to reinstall the system, is to change the <strong>DomainID</strong>.  Do this by:</p>
<ol>
<li>Opening the Symantec Endpoint Protection Manager Console</li>
<li>Click on <strong>Admin</strong></li>
<li>Click on <strong>Add Domain</strong></li>
<li>Enter the domain name (use default2 or something and rename to default when deleting the new &#8220;old&#8221; default)</li>
<li>Company and contact list are optional.</li>
<li><em>Most important </em>enter the previous Domain ID that you were using before reinstalling the SEPM services.</li>
</ol>
<div id="attachment_355" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/sepm1.png"><img class="size-medium wp-image-355" title="sepm1" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/sepm1-300x217.png" alt="Symantec Endpoint Manager" width="300" height="217" /></a>
<p class="wp-caption-text">Symantec Endpoint Manager</p>
</div>
<p>Hopefully if all goes well, then you should see all your clients in the <strong>Clients</strong> area and everything should return back to normal.</p>
<p>However, for me that wasn&#8217;t the case.  For some reason my database became corrupt and wouldn&#8217;t let me revert back to the old ID.  So I had to install a new database with the previous <strong>DomainID</strong>.  But my clients would not join after doing this.  Of course as its a new database and everything is empty, only the <strong>DomainID</strong> was the same.   Which means you need to replace the <strong><em>sylink.xml</em></strong> file on <em>every</em> computer that was connecting to the managing server.  The appropriate sylink.xml file can be found in the following directory:</p>
<p>x64 machine &#8211; C:\Program Files (x86)\Symantec\sepm\data\outbox\agent</p>
<p>x86 machine &#8211; C:\Program Files\Symantec\sepm\data\outbox\agent</p>
<p>There will be directories with a long string of numbers and random letters.  You need to go into each one and view the <strong><em>Profile.xml</em></strong> and the very top of the file will be the &lt;GroupInfo Description=&#8221;&lt;yournamehere&gt;&#8221;&#8230;&gt;  After finding the appropriate folder/group that you want to reset to the clients, use the <strong><em>sylink.xml</em></strong> file in this directory to replace on that computer.  If you are in the same room, you can go to each computer, load an <em>Admistrator</em> level command prompt and go to the directory:</p>
<p>%PROGRAMFILESDIR%\Symantec\Symantec Endpoint Protection</p>
<p>To replace the sylink.xml  However, if the SEP client is running you cannot just copy the file here.  You will get an access violation error telling you that the file is in use.</p>
<div id="attachment_356" class="wp-caption aligncenter" style="width: 476px"><img class="size-full wp-image-356" title="sepm2" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/12/sepm2.png" alt="Sylink.xml Copy Error" width="466" height="412" />
<p class="wp-caption-text">Sylink.xml Copy Error</p>
</div>
<p>To successfully change the file, At the command prompt where SEP resides run:</p>
<p>smc -stop</p>
<p>copy over the sylink.xml file</p>
<p>smc -reload</p>
<p>smc -start</p>
<p>Almost immediately, you should see the green dot appear that the client is connected again to the server.  Problem solved.</p>
<p>However, doing this for more than a hand few of machines is less than ideal.  You can use the Symantec &#8220;<a href="http://www.symantec.com/connect/downloads/sylinkreplacer-tool-connecting-sep-clients-sepm">Syslink</a> Replacer&#8221; to do this remotely.  (This is a support tool from them, so actually the the link has no file you need to ask Symantec as it might get taken down.)  There is a PDF description also included with this.  So, I won&#8217;t go to much into the basics on how to use it.  But it does what you just did above automatically and remotely.  What I can say, is that you need to make sure that you have all the proper <a href="http://www.symantec.com/connect/forums/sylinkreplacerexe-and-vista-clients">remote ports open</a> (Port TCP139&amp;445). Also, the &#8220;Remote Registry Service&#8221; also needs to be initiated as well for this tool to work properly.  Otherwise the client will fail and the <strong>sylink.xml</strong> file will not be replaced.  By default, it starts automatically in XP, but in Vista and Win7 it does not.  I am sure there are lots of ways to do this, but for this time I just started the service remotely by using <a href="http://www.scriptingpod.com/rcf-gadget.asp">RCF+ windows gadget</a>.  A small desktop gadget for Vista/Win7 that will let you do lots of things from your desktop over your AD network.</p>
<p>Hope this might help anyone who has ever had a SEPM go south on them.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/12/04/symantec-endpoint-protection-manager-server-change/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec Endpoint Protection Communication Ports</title>
		<link>http://www.ffoutpost.net/2009/11/20/symantec-endpoint-protection-communication-ports</link>
		<comments>http://www.ffoutpost.net/2009/11/20/symantec-endpoint-protection-communication-ports#comments</comments>
		<pubDate>Fri, 20 Nov 2009 02:29:43 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Endpoint Protection]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[port]]></category>
		<category><![CDATA[ports]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=352</guid>
		<description><![CDATA[When setting up the firewalls on the servers for use with Symantec Endpoint Protection, it was a bit hard to find the ports that were needed from the Symantec Website.  So, I just copied them here for easy reference.








Port Number
Port Type
Initiated by
Listening Process
Description


80, 8014
TCP
SEP Clients
svchost.exe (IIS)
Communication between the SEPM manager and SEP clients and Enforcers. [...]]]></description>
			<content:encoded><![CDATA[<p>When setting up the firewalls on the servers for use with Symantec Endpoint Protection, it was a bit hard to find the ports that were needed from the Symantec Website.  So, I just copied them here for easy reference.</p>
<table border="0" cellspacing="0">
<tbody>
<tr valign="top">
<td width="90"></td>
<td width="770">
<table border="1" width="100%">
<tbody>
<tr valign="top">
<td width="6%" valign="middle"><strong><span style="font-size: x-small;">Port Number</span></strong></td>
<td width="5%" valign="middle"><strong><span style="font-size: x-small;">Port Type</span></strong></td>
<td width="12%" valign="middle"><strong><span style="font-size: x-small;">Initiated by</span></strong></td>
<td width="8%"><strong><span style="font-size: x-small;">Listening Process</span></strong></td>
<td width="70%" valign="middle"><strong><span style="font-size: x-small;">Description</span></strong></td>
</tr>
<tr valign="top">
<td width="6%" valign="middle"><span style="font-size: x-small;">80, 8014</span></td>
<td width="5%" valign="middle"><span style="font-size: x-small;">TCP</span></td>
<td width="12%" valign="middle"><span style="font-size: x-small;">SEP Clients</span></td>
<td width="8%"><span style="font-size: x-small;">svchost.exe (IIS)</span></td>
<td width="70%" valign="middle"><span style="font-size: x-small;">Communication between the SEPM manager and SEP clients and Enforcers. (8014 in MR3 and later builds, 80 in older).</span></td>
</tr>
<tr valign="top">
<td width="6%" valign="middle"><span style="font-size: x-small;">443</span></td>
<td width="5%" valign="middle"><span style="font-size: x-small;">TCP</span></td>
<td width="12%" valign="middle"><span style="font-size: x-small;">SEP Clients</span></td>
<td width="8%"><span style="font-size: x-small;">svchost.exe (IIS)</span></td>
<td width="70%" valign="middle"><span style="font-size: x-small;">Optional secured HTTPS communication between a SEPM manager and SEP clients and Enforcers.</span></td>
</tr>
<tr valign="top">
<td width="6%" valign="middle"><span style="font-size: x-small;">1433</span></td>
<td width="5%" valign="middle"><span style="font-size: x-small;">TCP</span></td>
<td width="12%" valign="middle"><span style="font-size: x-small;">SEPM manager</span></td>
<td width="8%"><span style="font-size: x-small;">sqlservr.exe</span></td>
<td width="70%" valign="middle"><span style="font-size: x-small;">Communication between a SEPM manager and a Microsoft SQL Database Server if they reside on separate computers.</span></td>
</tr>
<tr valign="top">
<td width="6%" valign="middle"><span style="font-size: x-small;">1812</span></td>
<td width="5%" valign="middle"><span style="font-size: x-small;">UDP</span></td>
<td width="12%" valign="middle"><span style="font-size: x-small;">Enforcer</span></td>
<td width="8%"><span style="font-size: x-small;">w3wp.exe</span></td>
<td width="70%" valign="middle"><span style="font-size: x-small;">RADIUS communication between a SEPM manager and Enforcers for authenticating unique ID information with the Enforcer.</span></td>
</tr>
<tr valign="top">
<td width="6%" valign="middle"><span style="font-size: x-small;">2638</span></td>
<td width="5%" valign="middle"><span style="font-size: x-small;">TCP</span></td>
<td width="12%" valign="middle"><span style="font-size: x-small;">SEPM manager</span></td>
<td width="8%"><span style="font-size: x-small;">dbsrv9.exe</span></td>
<td width="70%" valign="middle"><span style="font-size: x-small;">Communication between the Embedded Database and the SEPM manager.</span></td>
</tr>
<tr valign="top">
<td width="6%" valign="middle"><span style="font-size: x-small;">8443</span></td>
<td width="5%" valign="middle"><span style="font-size: x-small;">TCP</span></td>
<td width="12%" valign="middle"><span style="font-size: x-small;">Remote Java or web console</span></td>
<td width="8%"><span style="font-size: x-small;">SemSvc.exe</span></td>
<td width="70%" valign="middle"><span style="font-size: x-small;">HTTPS communication between a remote management console and the SEPM manager. All login information and administrative communication takes place using this secure port.</span></td>
</tr>
<tr valign="top">
<td width="6%" valign="middle"><span style="font-size: x-small;">9090</span></td>
<td width="5%" valign="middle"><span style="font-size: x-small;">TCP</span></td>
<td width="12%" valign="middle"><span style="font-size: x-small;">Remote web console</span></td>
<td width="8%"><span style="font-size: x-small;">SemSvc.exe</span></td>
<td width="70%" valign="middle"><span style="font-size: x-small;">Initial HTTP communication between a remote management console and the SEPM manager (to display the login screen only).</span></td>
</tr>
<tr valign="top">
<td width="6%"><span style="font-size: x-small;">8005</span></td>
<td width="5%"><span style="font-size: x-small;">TCP</span></td>
<td width="12%"><span style="font-size: x-small;">SEPM manager</span></td>
<td width="8%"><span style="font-size: x-small;">SemSvc.exe</span></td>
<td width="70%"><span style="font-size: x-small;">The SEPM manager listens on the Tomcat default port.</span></td>
</tr>
<tr valign="top">
<td width="6%" valign="middle"><span style="font-size: x-small;">39999</span></td>
<td width="5%" valign="middle"><span style="font-size: x-small;">UDP</span></td>
<td width="12%" valign="middle"><span style="font-size: x-small;">Enforcer</span></td>
<td width="8%"><img src="http://service1.symantec.com/icons/ecblank.gif" border="0" alt="" width="1" height="1" /></td>
<td width="70%" valign="middle"><span style="font-size: x-small;">Communication between the SEP Clients and the Enforcer. This is used to authenticate Clients by the Enforcer.</span></td>
</tr>
<tr valign="top">
<td width="6%"><span style="font-size: x-small;">2967</span></td>
<td width="5%"><span style="font-size: x-small;">TCP</span></td>
<td width="12%"><span style="font-size: x-small;">SEP Clients</span></td>
<td width="8%"><span style="font-size: x-small;">Smc.exe</span></td>
<td width="70%"><span style="font-size: x-small;">The Group Update Provider (GUP) proxy functionality of SEP client listens on this port.</span></td>
</tr>
</tbody>
</table>
<p>The Symantec Endpoint Protection Manager (SEPM) use two web servers: Internet Information Services (IIS) and Tomcat. IIS uses port 80 (or 8014) and 443 &#8211; Tomcat uses port 9090 and 8443. The communication between IIS and Tomcat uses the HTTP protocol. IIS uses port 9090 to talk to Tomcat, Tomcat uses port 80 to talk to IIS.<strong><br />
</strong><br />
<strong>Client-Server Communication:</strong><br />
For IIS SEP uses HTTP or HTTPS between the clients or Enforcers and the server. For the client server communication it uses port 80 (or 8014) and 443 by default. In addition, the Enforcers use RADIUS to communicate in real-time with the manager console for clients authentication. This is done on UDP port 1812.<strong><br />
</strong><br />
<strong>Remote Console:</strong><br />
9090 is used by the remote console to download .jar files and display the help pages.<br />
8443 is used by the remote console to communicate with SEPM and the Replication Partners to replicate data.<strong><br />
</strong><br />
<strong>Client-Enforcer Authentication:</strong><br />
The clients communicate with the Enforcer using a proprietary communication protocol. This communication uses a challenge-response to authenticate the clients. The default port for this is UDP 39,999.</td>
</tr>
</tbody>
</table>
<p>You can find the original link <a href="http://service1.symantec.com/SUPPORT/ent-security.nsf/2326c6a13572aeb788257363002b62aa/edda0cd89141a6788025734e004b6a02?OpenDocument">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/11/20/symantec-endpoint-protection-communication-ports/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A (kind of) Mac Tablet</title>
		<link>http://www.ffoutpost.net/2009/11/19/a-kind-of-mac-tablet</link>
		<comments>http://www.ffoutpost.net/2009/11/19/a-kind-of-mac-tablet#comments</comments>
		<pubDate>Thu, 19 Nov 2009 06:07:42 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Macintosh]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[tablet]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=349</guid>
		<description><![CDATA[Well as with all the news and buzz about highly sought after Mac Tablet, I found something that is kind of like it.  I say kind of very loosely as it seems nice.  I can&#8217;t say much since I&#8217;ve never tried it.  But I do like the concept.  It is by a company called Axiotron.  [...]]]></description>
			<content:encoded><![CDATA[<p>Well as with all the news and buzz about highly sought after Mac Tablet, I found something that is kind of like it.  I say kind of very loosely as it seems nice.  I can&#8217;t say much since I&#8217;ve never tried it.  But I do like the concept.  It is by a company called <a href="http://www.axiotron.com/index.php?id=overview">Axiotron</a>.  If you can&#8217;t wait for the official one from Apple.  I guess this is a pretty close 2nd runner up.  Overall the value added functions like a built in camera and GPS are pretty nice.  It&#8217;s also got a CD/DVD drive as well.  I thought it looked pretty neat.  Here is a picture of it:</p>
<div id="attachment_350" class="wp-caption aligncenter" style="width: 246px"><img class="size-full wp-image-350" title="axiotron-modbook" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/axiotron-modbook.jpg" alt="Axiotron Modbook" width="236" height="313" />
<p class="wp-caption-text">Axiotron Modbook</p>
</div>
<p>You can read more on their <a href="http://www.axiotron.com/index.php?id=compare">comparison</a> page.  I thought this would be something neat to get until I looked a bit closer.  As Apple really doesn&#8217;t like people selling Mac clones, at all, I wondered how this works.  Basically you&#8217;re modding your current MacBook that you have/buy modified.  Hence the name ModBook.  So, I suppose Apple doesn&#8217;t mind as you already bought their hardware.  I thought it was quite interesting as well, until I saw that it was just a modified MacBook.  The fact that it&#8217;s almost ~3cm (~1in+) tall and that it weights 2.4kg (5.3lbs) is a bit of a downer though.  I wanted to try out something like this.  It seems a bit too thick and heavy to carry around to wield easily for a tablet PC.   Still would like to give out a test though.</p>
<p>But the best part is, among from what i said earlier is that you can buy it now.  No need to wait.  You can see the distributor page on their website as well to order one online.  How about that?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/11/19/a-kind-of-mac-tablet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exchange 2010 and Office 2010 Beta</title>
		<link>http://www.ffoutpost.net/2009/11/18/exchange-2010-and-office-2010-beta</link>
		<comments>http://www.ffoutpost.net/2009/11/18/exchange-2010-and-office-2010-beta#comments</comments>
		<pubDate>Wed, 18 Nov 2009 09:05:42 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office 2010]]></category>
		<category><![CDATA[exchange 2010]]></category>
		<category><![CDATA[office 2010 beta]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=344</guid>
		<description><![CDATA[Wow how great!  All the new software for 2010 from Microsoft is finally coming out.
Exchange 2010 went RTM about a month back and now it is finally out for download and use.

Also at the same time, it seems that Microsoft also took this chance to release their beta of upcoming Office 2010 as well.

Take a [...]]]></description>
			<content:encoded><![CDATA[<p>Wow how great!  All the new software for 2010 from Microsoft is finally coming out.</p>
<p>Exchange 2010 went RTM about a month back and now it is finally out for download and use.</p>
<p><img class="aligncenter size-full wp-image-346" title="exchange2010try" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/exchange2010try.jpg" alt="exchange2010try" width="394" height="204" /></p>
<p>Also at the same time, it seems that Microsoft also took this chance to release their beta of upcoming Office 2010 as well.</p>
<p><img class="aligncenter size-medium wp-image-345" title="office2010professionalbeta" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/office2010professionalbeta-300x44.png" alt="office2010professionalbeta" width="300" height="44" /></p>
<p>Take a look at the <a href="http://technet.microsoft.com">Microsoft TechNet site </a>for more information and a free trial download.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/11/18/exchange-2010-and-office-2010-beta/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Server Time Services</title>
		<link>http://www.ffoutpost.net/2009/11/18/windows-server-time-services</link>
		<comments>http://www.ffoutpost.net/2009/11/18/windows-server-time-services#comments</comments>
		<pubDate>Wed, 18 Nov 2009 08:50:32 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Windows Server 2008 R2]]></category>
		<category><![CDATA[authoritative]]></category>
		<category><![CDATA[ntp]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ffoutpost.net/?p=327</guid>
		<description><![CDATA[One thing that I think no one cares a great deal about is if their clock is off by a minute or two.  Unfortunately, when running computers they do.  Even a slight variation in the time can mean a difference from your computers talking to each other to rejecting each other due to security policy [...]]]></description>
			<content:encoded><![CDATA[<p>One thing that I think no one cares a great deal about is if their clock is off by a minute or two.  Unfortunately, when running computers they do.  Even a slight variation in the time can mean a difference from your computers talking to each other to rejecting each other due to security policy violations.  In this case because there is a clock skew.  So just wanted to write on how to setup an authoritative time server in your Windows AD environment.  AD is pretty picky about the time and its the easiest place to setup the authoritative time server for your domain, as all your domain joined PCs will sync pretty quickly if the AD server makes a time shift.  This will work on any version of Windows Server Domain Controllers (2000/2003/2008) that I know of.  You can even do it on XP, Vista, Win7, but on the desktop there is an extra tab to modify the time server source directly.  Also when you join a computer to a domain it will pull the time from the domain controller.</p>
<h3 id="tocHeadRef">Configuring the Windows Time service to use an external time source</h3>
<p><script type="text/javascript">// < ![CDATA[
                loadTOCNode(2, 'summary');
// ]]&gt;</script> To configure an internal time server to synchronize with an external time source, follow these steps:</p>
<ol>
<li>Change the server type to NTP. To do this, follow these steps:
<ol>
<li>Click <strong>Start</strong>, click <strong>Run</strong>, type <span>regedit</span>, and then click <strong>OK</strong>.</li>
<li>Locate and then click  the following registry subkey:
<div><strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\Type</p>
<div id="attachment_328" class="wp-caption aligncenter" style="width: 310px"></strong><strong><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp1.png"><img class="size-medium wp-image-328" title="ntp1" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp1-300x212.png" alt="Change type to NTP" width="300" height="212" /></a></strong>
<p class="wp-caption-text">Change type to NTP</p>
</div>
</div>
</li>
<li> In the right pane, right-click <strong>Type</strong>, and then click <strong>Modify</strong>.</li>
<li> In <strong>Edit Value</strong>, type <span>NTP</span> in the <strong>Value data</strong> box, and then click <strong>OK</strong>.</li>
<li>Your modified value should look as such:
<div id="attachment_329" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp1a.png"><img class="size-medium wp-image-329" title="ntp1a" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp1a-300x212.png" alt="Changed to NTP Type" width="300" height="212" /></a>
<p class="wp-caption-text">Changed to NTP Type</p>
</div>
</li>
</ol>
</li>
<li>Set AnnounceFlags to 5. To do this, follow these steps:
<ol>
<li>Locate and then click  the following registry subkey:
<div><strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\AnnounceFlags</p>
<div id="attachment_330" class="wp-caption aligncenter" style="width: 310px"></strong><strong><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp2.png"><img class="size-medium wp-image-330" title="ntp2" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp2-300x212.png" alt="Change the AnnounceFlags Value" width="300" height="212" /></a></strong>
<p class="wp-caption-text">Change the AnnounceFlags Value</p>
</div>
</div>
</li>
<li> In the right pane, right-click <strong>AnnounceFlags</strong>, and then click <strong>Modify</strong>.</li>
<li> In <strong>Edit DWORD Value</strong>, type <span>5</span> in the <strong>Value data</strong> box, and then click <strong>OK</strong>.</li>
<li>The modified value should look as such:
<div id="attachment_331" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp2a.png"><img class="size-medium wp-image-331" title="ntp2a" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp2a-300x212.png" alt="Changed AnnouncedFlags Value" width="300" height="212" /></a>
<p class="wp-caption-text">Changed AnnouncedFlags Value</p>
</div>
</li>
</ol>
</li>
<li>Enable NTPServer. To do this, follow these steps:
<ol>
<li>Locate and then click  the following registry subkey:
<div><strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer</p>
<div id="attachment_332" class="wp-caption aligncenter" style="width: 310px"></strong><strong><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp3.png"><img class="size-medium wp-image-332" title="ntp3" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp3-300x212.png" alt="Enable the NTP Server" width="300" height="212" /></a></strong>
<p class="wp-caption-text">Enable the NTP Server</p>
</div>
</div>
</li>
<li> In the right pane, right-click <strong>Enabled</strong>, and then click <strong>Modify</strong>.</li>
<li> In <strong>Edit DWORD Value</strong>, type <span>1</span> in the <strong>Value data</strong> box, and then click <strong>OK</strong>.</li>
<li>Your changed value should look as such:
<div id="attachment_333" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp3a.png"><img class="size-medium wp-image-333" title="ntp3a" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp3a-300x212.png" alt="Enabled NTP Server" width="300" height="212" /></a>
<p class="wp-caption-text">Enabled NTP Server</p>
</div>
</li>
</ol>
</li>
<li>Specify the time sources. To do this, follow these steps:
<ol>
<li>Locate and then click  the following registry subkey:
<div><strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters</strong></div>
</li>
<li> In the right pane, right-click <strong>NtpServer</strong>, and then click <strong>Modify</strong>.</li>
<li> In <strong>Edit Value</strong>, type <var>Peers</var> in the <strong>Value data</strong> box, and then click <strong>OK</strong>.
<div id="attachment_334" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp4.png"><img class="size-medium wp-image-334" title="ntp4" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp4-300x212.png" alt="Modifying the NTP Servers List" width="300" height="212" /></a>
<p class="wp-caption-text">Modifying the NTP Servers List</p>
</div>
<p><strong>Note </strong><var>Peers</var> is a placeholder for a space-delimited list of peers from which your computer obtains time stamps. Each DNS name that is listed must be unique. You must append <span>,0&#215;1</span> to the end of each DNS name.   If you do not append <span>,0&#215;1</span> to the end of each DNS name, the changes made in step 5 will not take effect.  You can add additional NTP servers with a single character &#8220;space&#8221; between the &#8216;,0&#215;1&#8242; and the next server.  Look at my screenshot below for a visual explanation.  I recommend setting three as this is usually the standard for NTP.  You can go to the NTP Pool website <a href="http://support.ntp.org/bin/view/Servers/NTPPoolServers">here</a> to find what servers work best for you.  Closer to you is always better.  In my case, I used the Japan pool.</p>
<div id="attachment_335" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp4a.png"><img class="size-medium wp-image-335" title="ntp4a" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp4a-300x212.png" alt="Modified NTP Server Source List" width="300" height="212" /></a>
<p class="wp-caption-text">Modified NTP Server Source List</p>
</div>
</li>
</ol>
</li>
<li>Select the poll interval. To do this, follow these steps:
<ol>
<li>Locate and then click  the following registry subkey:
<div><strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient\SpecialPollInterval</strong></div>
</li>
<li> In the right pane, right-click <strong>SpecialPollInterval</strong>, and then click <strong>Modify</strong>.</li>
<li> In <strong>Edit DWORD Value</strong>, type <var>TimeInSeconds</var> in the <strong>Value data</strong> box, and then click <strong>OK</strong>.
<div id="attachment_336" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp5.png"><img class="size-medium wp-image-336" title="ntp5" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp5-300x212.png" alt="Change the default polling period" width="300" height="212" /></a>
<p class="wp-caption-text">Change the default polling period</p>
</div>
<p><strong>Note </strong><var>TimeInSeconds</var> is a placeholder for the number of seconds that you want between each poll. A recommended value is 900 Decimal. This value configures the Time Server to poll every 15 minutes.  This will tell your domain controller to communicate with the NTP pool servers that you just set to make sure that it is within the correct time boundaries.</p>
<div id="attachment_337" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp5a.png"><img class="size-medium wp-image-337" title="ntp5a" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp5a-300x212.png" alt="Modified Poll Interval Time" width="300" height="212" /></a>
<p class="wp-caption-text">Modified Poll Interval Time</p>
</div>
</li>
</ol>
</li>
<li>Configure the time correction settings.    To do this, follow these steps:
<ol>
<li>Locate and then click  the following registry subkey:
<div><strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\MaxPosPhaseCorrection</strong></div>
</li>
<li> In the right pane, right-click <strong>MaxPosPhaseCorrection</strong>, and then click <strong>Modify</strong>.</li>
<li>In <strong>Edit DWORD Value</strong>, click to select <strong>Decimal</strong> in the <strong>Base</strong> box.</li>
<li> In <strong>Edit DWORD Value</strong>, type <var>TimeInSeconds</var> in the <strong>Value data</strong> box, and then click <strong>OK</strong>.
<p><strong>Note </strong><var>TimeInSeconds</var> is a placeholder for a reasonable value, such as 1 hour (3600) or 30 minutes (1800). The value that you select will depend upon the poll interval, network condition, and external time source.</li>
<li>Locate and then click the following registry subkey: <strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\MaxNegPhaseCorrection </strong></li>
<li>In the right pane, right-click <strong>MaxNegPhaseCorrection</strong>, and then click <strong>Modify</strong>.</li>
<li>In <strong>Edit DWORD Value</strong>, click to select <strong>Decimal</strong> in the <strong>Base</strong> box.</li>
<li> In <strong>Edit DWORD Value</strong>, type <var>TimeInSeconds</var> in the <strong>Value data</strong> box, and then click <strong>OK</strong>.
<div id="attachment_338" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp6.png"><img class="size-medium wp-image-338" title="ntp6" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp6-300x212.png" alt="Modify the Correction Time" width="300" height="212" /></a>
<p class="wp-caption-text">Modify the Correction Time</p>
</div>
<p><strong>Note </strong><var>TimeInSeconds</var> is a placeholder for a reasonable value, I usually use double what I set the poll interval to.  In this case 30 minutes or 1800 seconds. The value that you select will depend upon the poll interval, network condition, and external time source.</p>
<div id="attachment_339" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp6a.png"><img class="size-medium wp-image-339" title="ntp6a" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp6a-300x212.png" alt="Modified Phase Correction Time" width="300" height="212" /></a>
<p class="wp-caption-text">Modified Phase Correction Time</p>
</div>
</li>
</ol>
</li>
<li>Quit the registry editor.</li>
<li>At the command prompt, type the following command to restart the Windows Time service, and then press ENTER:
<div><span>net stop w32time &amp;&amp; net start w32time</p>
<div id="attachment_340" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp7.png"><img class="size-medium wp-image-340" title="ntp7" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp7-300x225.png" alt="Restart the Time Services" width="300" height="225" /></a>
<p class="wp-caption-text">Restart the Time Services</p>
</div>
<p></span></div>
</li>
<li><span>The time then almost immediately updated to the correct time as you can see in the next two pictures of the corrected time and also in the event log (eventvwr.msc)
<div id="attachment_341" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp7a.png"><img class="size-medium wp-image-341" title="ntp7a" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp7a-300x225.png" alt="Updated to correct time" width="300" height="225" /></a>
<p class="wp-caption-text">Updated to correct time</p>
</div>
<div id="attachment_342" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp8.png"><img class="size-medium wp-image-342" title="ntp8" src="http://www.ffoutpost.net/wordpress/wp-content/uploads/2009/11/ntp8-300x225.png" alt="Event Log of Time Services" width="300" height="225" /></a>
<p class="wp-caption-text">Event Log of Time Services</p>
</div>
<p></span></li>
</ol>
<p>I hope that this helps anyone who is trying to setup an authoritative time server in their Windows Domain network.  It&#8217;s not really hard.  Just make sure if you are changing multiple machines that the time you are modifying isn&#8217;t terribly huge.  (ie. half a day or something.)  If you change one AD machine and the clock jumps forward or back half a day (probably due to a time zone setting) the other servers will loose trust between the other machines.  Authentication processes will stop working and whatever else is based on those servers trusting each other.  A snowball of problems so just might want to keep that in mind.</p>
<p><span>This process was taken from the Microsoft article source <a href="http://support.microsoft.com/kb/816042">KB816042.</a><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ffoutpost.net/2009/11/18/windows-server-time-services/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
