2020年12月10日 星期四

[微軟ADDS] Win XP 無法加入 Windows Server 2019 AD 網域問題

[Lab 筆記]

Lab: Win XP Join Windows Server 2019 AD Domain Fail. 


[Lab 環境]

DC OS: Windows Server 2019 Forest / Domain Function Level: windows server 2008 

Client OS: Windows XP SP3 ( 無額外 Windows Update )

 

預設狀況下,Win XP 無法加入 Windows Server 2019 AD 網域。

主要原因為 smb v1 支援 與  legacy Kerberos encryption 

 

故 Windows Server 2019 需調整 2 項設定

1. Windows Server 2019 安裝 SMBv1 ( Client and Server 都有安裝 ) 

可透過 Powrshell Get-SmbServerConfiguration 檢查 EnableSMB1Protocol  : True 

( 如果未安裝 SMBv1 Join AD Domain 錯誤訊息: "指定的網路名稱無法使用"


2. Windows Server 2019 透過 Default Domain Controller 設定 允許 

legacy Kerberos encryption types ,勾選 XP 支援類型。

GPO 設定路徑: 

Windows Settings - Security Settings - Local Policies - Security Options - 

Network security: Configure encryption types allowed for Kerberos

( 注意,並非全部勾選,AES128..., 256... 不支援 XP ) 

參考: https://docs.microsoft.com/zh-tw/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos 


額外參考連結

大部分 Google 的資料,都是在討論 smb v1 與 RC4 encryption  

https://docs.microsoft.com/zh-tw/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos

https://social.technet.microsoft.com/Forums/windowsserver/en-US/29bf5c6c-f854-4308-b9b3-7c688ddfb923/windows-xp-got-error-joining-domain-on-windows-server-2019?forum=ws2019


延伸閱讀

1. GPO 套用順序 

https://docs.microsoft.com/en-us/previous-versions/windows/desktop/policy/group-policy-hierarchy 

套用結果可透過 gsop.msc 檢查


2. 發現 windows 10 無法存取 DC 上的 SYSVOL 與 NETLOGON 分享

http://woshub.com/cant-access-domain-sysvol-netlogon-folders/ 


2018年7月23日 星期一

[Hyper-V] Hyper-V 2016 Deploy an Active Directory-Detached Cluster 注意事項

Windows Server 2012 參考資料

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn265970(v=ws.11)

Windows Server 2016 參考資料
https://docs.microsoft.com/zh-tw/windows-server/failover-clustering/create-failover-cluster






重點標示

This deployment method still requires that the failover cluster nodes are joined to an Active Directory domain.




















2017年10月5日 星期四

2017年4月27日 星期四

[Virtual SAN] 關於 Virtual SAN 6.5 iSCSI Target 注意事項

參考 使用 Virtual SAN iSCSI 目標服務 需注意的事。

相關設定與注意事項,可參考官方文件。

https://pubs.vmware.com/vsphere-65/index.jsp#com.vmware.vsphere.virtualsan.doc/GUID-13ADF2FC-9664-448B-A9F3-31059E8FC80E.html


2017年4月26日 星期三

[VMware] vCSA 6.5 透過 Web Console 進行更新

vCenter Server Appliance (後面簡稱 vCSA) Web Console 功能,
在 vSphere 6.5 回歸。也簡化了 vCSA 的更新作業。


[瀏覽器] 瀏覽器重新設定

測試環境的管理,需透過 Web GUI,
但是一個測試後,常常忘記自己調整了那些設定,
到下一個測試環境,又發生異常問題,

這時候不需要重新安裝瀏覽器,就算重新安裝,也可能讀取舊的環境設定檔,
試試將瀏覽器重新設定,也許可以解決。


2017年4月12日 星期三

[閒聊] NewSID 退休

你知道 Windows SID 變更工具 NewSID 退休了嗎?

[HP Storage] HP P2000 空間 Mapping 方式說明

HP P2000空間Mapping,

[HP Storage] HP P2000 清除 Log

狀況: 印象中 HP P2000 當設備問題事件處完成,
但仍顯示相關錯誤事件,如何清除。


[HP Storage] HP P2000 儲存 Log 報修用

如何蒐集 HP P2000 Storage Log 供報修使用。

[HP Storage] 查看 HP P2000 設備序號

如何查看 HP P2000 設備序號

[Paloalto] 名詞解釋: DNS Sinkholing

原文與出處

DNS Sinkholing
The DNS sinkhole action that you can enable in Anti-Spyware profiles enables the firewall to forge a response to a DNS query for a known malicious domain, causing the malicious domain name to resolve to an IP address that you define. This feature can be used to identify infected hosts on the protected network using DNS traffic in situations where the firewall cannot see the infected client's DNS query (that is, the firewall cannot see the originator of the DNS query). In a typical deployment where the firewall is north of the local DNS server, the threat log will identify the local DNS resolver as the source of the traffic rather than the actual infected host. Sinkholing malware DNS queries solves this visibility problem by forging responses to the client host queries directed at malicious domains, so that clients attempting to connect to malicious domains (for command-and- control, for example) will instead attempt to connect to a sinkhole IP address that you define. Infected hosts can then be easily identified in the traffic logs because any hosts that attempt to connect to the sinkhole IP address are most likely infected with malware.
DNS Sinkhole Workflow
The following illustration shows an example of how to identify client hosts that are attempting to communicate with known malicious domains:


來自 <https://www.paloaltonetworks.com/documentation/60/pan-os/newfeaturesguide/content-inspection-features/dns-sinkholing>

2017年4月6日 星期四

[HP Switch] IRF Config 範例

關於 HP IRF 分兩篇說明,
第一篇是一些概念釐清。
第二篇(本篇)是網路案例說明。


[HP Switch] IRF Config 概念

關於 HP IRF 分兩篇說明,
第一篇(本篇)是一些概念釐清。
第二篇是網路案例說明。

[HP Switch] 1910.1920 啟用進階指令


HP 1910, 1920 預設只有簡單指令操作,
以下說明,開啟進階指令操作:

[HP Switch] Tracert HP Switch 顯示 * 問題

檢測網路時,會使用 tracert 指令, 
但是在環境中有 HP L2 L3 Switch 時,追蹤資訊,總是顯示 *
較難判斷 * 是哪個設備

2017年3月31日 星期五

[案例分享] Storage LUN Resize. ESXi 觸發 APD 與 PDL

儲存空間線上擴充,這類的案件,
這幾年下來直接與間接執行的間數手指+腳趾也不夠數,
就在今年Q1,兩間執行線上擴充,Storage 完成 LUN Resize,
但 ESXi 對應的 Datastore 卻呈現非作用中 inactive。
存放在此空間 運行的 VM 當然也受到影響,而無法正常運作。

問題發生期間,嘗試手動掛載 執行 Datastore Rescan All ,仍無法恢復空間掛載狀態,
最後只好將 ESXi 主機 Reboot,Reboot 後 空間才恢復掛載,
在重開機之前,蒐集了 Storage Log 與 ESXi Log,以利後續 Open Support Case 釐清原因。



2017年3月30日 星期四

[Email] 郵件系統的網路備援

網路的備援,分為 Inbound 與 Outbound。
目前市面上支援多 WAN 介面的防火牆,大多支援 Outbound Loading Balancing
但要支援 Inbound Loading Balancing 則需要特殊的設備才能達成。
但一般企業最常使用的郵件服務,若要達成網路備援效果,

可以怎麼做?


[微軟ADDS] Win XP 無法加入 Windows Server 2019 AD 網域問題

[Lab 筆記] Lab: Win XP Join Windows Server 2019 AD Domain Fail.  [Lab 環境] DC OS: Windows Server 2019 Forest / Domain Function Level: windows s...