Monday, October 31, 2016

Windows 2003 SAN Migration from one storage to another.

Good day!

Welcome back!!! and Happy Diwali to all!!!

Recently we had a request to migration SAN from existing storage to a new Storage.As the SAN was pretty old SAN level migration didn't work and we manually had to do xcopy.

If anyone thinks this is pretty easy well to be frank nope, lot of risk involved with no support from MS and also remember drive details are in registry in the form of Signature, so if you change drive letter like we do in Windows 2008 and expect Cluster disk to come online it will fail.

Prerequisites before you start:

1.Take Full Back of both the Nodes
2.Take Registry backup on both the Nodes
3.Take System state backup for both the Nodes.
Note: if anyone things taking system state backup can we restore a Windows 2003, well absolutely and we have done it 2 times successful.
4. Make sure you have the password for Cluster Service account it is set under.Usually 2003 cluster are always set under Service accounts.
5. Make sure you have 2003 resource toolkit is installed and navigate to make sure you can see Clusterrecovery.exe under C:\program files\Windows Resource Kits\Tools.

Steps to perform:

Note: All these steps should be performed by login in on the Node with Cluster Service Account.
If your security doesn't allow to login using the Service Account then make sure you have ID which is part of Local Administrative group before you proceed.

1. Request storage team to assign Luns to both nodes
2. On confirmation that you can see the disk on all Nodes,Shutdown the passive node
3. Format the disk on the active node and assign a drive letter
4. Go to Cluster Admin, right click and add a disk resource and give some dummy name and select the defaults and click and select the new Formatted drive letter and finish it.
5. Bring the disk online and then power on the passive node online
6.Try failing over the disk to another node to make sure you can see the disk on the other node as well.
7. Make sure you do some read/write operations on the disk on the node which is active and confirm that the same can be seen on the other Node.
8. After confirmation disk looks good then perform the xopy from Source to destination disk and after completion make sure all the contents and folders are the same as Source disk.

Command we used:

xcopy Source_drive: destination_drive: /e/v/c/h/k/o/y

9. Now navigate to the clusterrecovery.exe and run it.It will ask you to connect to Cluster, in-case you have stopped the cluster make sure its running and online.After connecting when click next you will see a window asking if you want to replace a disk,Click next and in the final window you need to select Source disk and destination disk what you want to replace it with and Click Finish.
10.What this tool will do is update registry signature of the new disk.
11. Now if you open cluster admin, you will see that new Disk is renamed with the drive letter the old disk had and the old disk is commented as lost.
12. Right click the lost disk in clusteradmin and delete it.
13. Go to disk management and remove the drive letter Q to old disk and change the new Disk to Q.If you get a warning saying reboot is needed to take effect just say ok and be patient it will take sometime and then will show Q assigned to new SAN disk.
14.Verify in Cluster, try failing over to see if Q works fine and both nodes.
15. Last just reboot both the nodes and finally node fail over testing
16. We did 2 Clusters and above steps worked both the time.

The disk we performed had Shared drive, no issue reported after disk replacement and even shares showed up just fine.
Quorum was replaced that worked with no issues.
On google some reported disk signatures issues and had to do some registry fix etc was so not sure under what scenarios, but the steps above is what i have followed and was successful to migrate close to 6 drives.

Hopefully this will help someone, until next one you all have good day!!!!!!!!!!!!

Friday, October 14, 2016

Roaming Profiles, Terminal Server Profiles and Profile Versions

Good day All,

Welcome back, it been some time i did my last posting.. quite busy these days with so many things going on..

We are in the process of rolling out Folder Redirection for our Citrix users so during the process i had lot of confusions on Roaming profile and Terminal Server profile which loads when and why there are different version etc....

So i did some homework and thought to share the same so it may help someone else too..

Please the the screenshot below not sure how many of them understood



Let me tell you i didn't understand fully either and started to try different combinations to really understand this chart.

Before i post the result, the question why would you care??? well if you one of those users you need to implement Citrix UPM or Roaming Profiles Or if you introducing Windows 2012 R2 or Windows 2016 Citrix App Servers then yes you should have this knowledge because if no proper care taken you will hear lot of Profile corruption and also document missing in Profile issues.

How do we avoid it, well you should look at introducing folder redirection , that way Users My documents, desktop etc move along with User on any version of Windows they log in


Roaming Profile set for a User when logs on Windows 7:

A user when logs to a Windows 7 desktop/laptop gets a V2 profile created.

Roaming Profile set for a User when logs  on Windows 10:

A user when logs to a Windows 10 desktop/laptop gets a V5 profile created.


Roaming Profile V2 user logs to Windows 10 desktop/laptop:

A V2 Roaming Profile user when logs to a Windows 10 desktop/laptop then a new V5 profile will be created


Roaming Profile V5 user logs to Windows 7 desktop/laptop:

A V5 Roaming Profile user when logs to a Windows 7 desktop/laptop then a new V2 profile will be created



Roaming profile user on Windows 7 and launching Citrix\RDP on 2008\2012:


A V2 roaming profile user when launches Citrix or RDP on Windows 2008\2012 then same V2 profile will be loaded when no hotfix and registry changes are done.

A V2 roaming profile user when launches Citrix or RDP on Windows 2012 R2 then  V4 profile will be created if hotfix installed and registry changes are done.


Roaming profile user on Windows 10 and launching Citrix\RDP on 2008\2012:

Roaming Profile user on Windows 10 will have a V5 profile, so when he launches Citrix or RDP on Windows 2008\2012 then V2 profile will be created and loaded when no hotfix and registry changes are done.

A V5 roaming profile user when launches Citrix or RDP on Windows 2012 R2 then  V4 profile will be created and loaded if hotfix installed and registry changes are done.


Roaming Profile with TS Profile:

A V2 roaming Profile user if TS profile is attached then when launching Citrix or RDP on Windows 2008 then a new V2 TS profile will be created and loaded

A V2 roaming Profile user if TS profile is attached then when launching Citrix or RDP on Windows 2012 then a new V4 TS profile will be created if hotfix is installed and registry change are done.

A V5 roaming Profile user if TS Profile is attached then when launching Citrix or RDP on Windows 2008 then a new V2 profile will be created and loaded

A V5 roaming Profile user if TS profile is attached then when launching Citrix or RDP on Windows 2012 then a new V4 TS profile will be created and loaded if hotfix is installed and registry change are done.


Only TS Profile :

A new User with TS profile configured logs to a Citrix or RDP on Windows 2008 , then V2 profile will be created

A new User with TS profile configured logs to a Citrix or RDP on Windows 2012 , then V4 profile will be created if hotfix is installed and registry change is done ,if not it will search for any exsisting V2 profile to load or Will create a new V2 profile and will load.


Hotfix links:

Windows 8/Server 2012 (KB 2887239)
Windows 8.1/Server 2012 R2 (KB 2887595)

Registry Changes:

  1. Locate and then tap or click the following registry subkey: 
    HKEY_LOCAL_MACHINE\System\CurrentControlset\Services\ProfSvc\Parameters
  2. On the Edit menu, point to New, and then tap or click DWORD Value.
  3. Type UseProfilePathExtensionVersion
  4. Press and hold or right-click UseProfilePathExtensionVersion, and then tap or click Modify.
  5. In the Value data box, type 1, and then tap or click OK.
  6. Exit Registry Editor
Last Step: Make sure to reboot the Server. If anyone has question on which Server you going to do? well all the Server where you will RDP or Citrix App will be published .

I wanted to end with a example let say we have a new User, Roaming Profile has been set and the requirement is he will log to Windows 7 laptop, Windows 10 laptop and also will launch Citrix Application on Windows 2008, Windows 2012 how many profile will get created????? if hotfix and registry change is done on Windows 2012

If anyone say 3 then yup you got the concept right.. let me elaborate..

When User logs to Windows 7 he will get a V2 profile.
When the same User logs to Windows 10 he will get a V5 Profile
Same user When launch Citrix App on Windows 2008 then already created V2 profile will load.
Same user When launch Citrix App on Windows 2012 then new V4 profile will be created and loaded.

Hopefully this help some, until next one you all have a good day!!!!!!!!!!!!!!!!!!!!!!!!


Tuesday, September 20, 2016

Convert to .PFX certificate for Windows if you receive Server certificate (.crt) and Private key(.key)

Good day All,

Welcome back!!! We had a request to apply SSL for a website during the conversation it was suppose to be applied at F5 Load Balancer so the LB team took care of generating the certificate.

Little later client requirement changed and it was decided that SSL should be applied at Windows Web server and not on Load balancer and it should just redirect the traffic to web server.

So the LB team sent me the Certificate file which is .crt and a very confidential file is the .key file which has the private key for the certificate was sent only to authorized people.

Now i had to find a way to merge both so that i can generate a web server certificate with Privatekey embed.

Follow the below steps:

1.Got to following link https://slproweb.com/products/Win32OpenSSL.html and download either 32 bit or 64 depending on the OS



2. Its simple next,next installer and then you will see a folder called C:\OpenSSL-Win64 depending on which version you installed

3. Copy the .cert and .key file to following location C:\OpenSSL-Win64\bin

4.Open a Command Prompt with Administrative rights and change path to C:\OpenSSL-Win64\bin and run command as below in screen shot



Format of Certificate should be pkcs12
Dummy name to export the certificate as PFX
Private key path
Server certificate path
Friendly name
When you hit enter it will ask you set a password, remember that password or make a note if it..
After verifying then you will see that there is a file with .pfx extension generated as below



5. Now open certificate.MMC and import the .pfx and note during the import it will ask for the password you set during Step 4.



Enable the checkbox which says this key as exportable , in case for future use you want to export the certificate from certificate.mmc store.

6. Now open the certificate under personnel store and you will see now that the Server certificate has private key.





Let's assume you want to do vice versa that is you have .PFX certificate and you want to extract Private key(.key) for say Load balancer either F5 or Netscaller then you will have to follow the below steps


Import password is the password for the pfx
Enter Pem pass phrase is just a some password you will have to give

Note: the reason we have to do rsa temp key to private key is that it's observer without rsa command some spaces are in the key which when added to load balancer will through error.



The steps above helped and hopefully this will help someone too!!!!
Until next one all have great day!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Sunday, September 18, 2016

SSL on 2 Node Storefront 3.6 Load Balancing Servers

Good day All,

Welcome back!!!

We got a request to apply SSL to Storefront Servers recently even for internal users and also add 1 more Server for Load balancing .The current Setup we had was 1 Node Storefront Server with 2.x version running on it

Below are the steps we followed to fulfill the request

Step 1. We add a new Storefront Server with same 2.x version and added the Server to Load balancer. The steps are pretty straight forward..

a.Installed Storefront on the new node
b.Go to primary node, Click Add Server under Server Group in Citrix Storefront MMC and it will show a Authorization code as below



















c. Login to new Secondary Storefront Server and click join to Storefront farm in welcome screen when you open Citrix Storefront MMC and then type in the Primary Node Server name and Authorization code , OLA the Server is added to Load Balancer
c. Requested a new Virtual IP(VIP) from F5 Load Balancer team and it was configured to Load Balance traffic on port 80 between both Storefront Servers.
d. Last step was to update the DNS record as it was earlier 1 node and it was pointing to the Primary Storefront Server IP. So we changed the DNS record to point to F5 Load Balancer VIP


Step 2: We wanted to upgrade the Storefront Servers from 2.x to 3.6 before we apply SSL. If you have a huge user base and can't afford to have users downtime for very long time then you probably will have to make sure you involve Load Balancer team during the upgrade process

a. Request Load Balancing team to remove Primary Server from Load Balancing.
b. Download the Setup and run the upgrade, simple straight forward upgrade.
c.After testing upgrade , add the upgraded Server to Load Balancing and remove the old Server from it
d.Upgrade the Secondary node
e.Request Load Balancing team add the other Server

As we had required downtime we didn't involve Load Balancer team and Servers was upgraded 1 Node at a time.

Step 3: Final step was to apply SSL on both the Storefront Servers.
As our requirement was to apply SSL for internal users we wanted to have the SSL traffic get terminated at Storefront Servers and not at F5 Load Balancer. Also we wanted if any users types in url then it should get auto redirected to 443 traffic and send to Storefront Servers.

a. A certificate was requested .Generating certificate etc are pretty straight forward process and there are so many articles out there so will not be covering it.
b.Requested the F5 Load Balancer team to reconfigure the Virtual IP(VIP) so that HTTP to HTTPS redirection works and HTTPS traffic is sent to both Storefront Servers.
c. Certificate as uploaded to Certificate.MMC store and also root and Intermediate Certificate was added to both Storefront Servers.
c.On both Citrix Storefront Servers under IIS, new binding was added for 443 as below under Default website and under the tab which says SSL Certificate , the certificate we processed earlier was pointed and applied.
























d.Same steps as above needs to be done on the other node as well.
e. last Step was under Primary  Citrix Storefront Server MMC, right click Server Group and click change Base URL and change the record from HTTP to HTTPS
f. During the testing we started to see the below error when we browsed the URL.



















Troubleshooting Steps performed:

1. We know that before we applied SSL storefront was working fine so to identify if this error is on both nodes or 1 single node , so i went ahead and shutdown Secondary Server.
2. When tested, Storefront was working fine and we able to browse the Apps.
3. So this time i powered off Primary and brought online Secondary, now we Started to see the same error. Now i know the issue is with Secondary node. As we had load balancer sending traffic to both SF Servers so we seeing the above error when we hinting the Secondary node.
4. To fix the issue i brought the primary node online and went to Server group and started to check around.
5. Anyone any guess? what would be the fix? well guess what when i checked the Last Synchronization time it was showing couple of days ago, so clicked under Actions to propagate changes to all the other Nodes, and ola the issued got fixed.



To make sure we do a through testing , following things was tested

1. Primary Node was shutdown and Secondary Node was tested with Node IP, Load Balancer IP and HTTPS and application was tested.
2. Vise versa was tested
3. Last step was both Servers was brought online and tested both Servers with IP, VIP IP,HTTPS.

So this is how we completed this request, hopefully this helps someone...........

Until next one you all have great day!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Tuesday, August 23, 2016

RDP-TCP recreation on Windows 2012/R2

Good day All,

Welcome back!!!

Recently on a Windows 2012 R2 domain controller unable to RDP. We tried almost everything and eventually rebooted it still we had the same issue unable to RDP Server and using the  KVM we able to see everything was healthy.
So decided that we should try deleting RDP-TCP connection and see if this helps.
Well i remember in old Windows 2008 days you go into Remote desktop Session Host configuration (tsconfig.msc) and delete it and recreate it .. simple right well that is gone in Windows 2012,R2 .. as MS moved to a improved version of RDSH they incorporated all this to GPO Settings

Windows 2008:













Windows 2012:



















After searching for a while there is absolutely no way we could recreate the RDP-TCP using gui so came across this excellent article which talks about how to re-create it by deleting and recreating the registry Key and it worked like a charm and we able to RDP back.

Note: If any one would like to thank , then follow the link and convey it, i take no credit for this one.

Recreate the default RDP Listener

How to recreate the RDP listener.
  1. Export the following registry key:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp
  2. Delete the following registry key:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp
  3. Copy and paste the below text into notepad, and save the file as RDP-Tcp.reg. Additionally, if the operating system is 2012 R2, another file will be required with the contents of the second box.

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp]
    "fInheritMaxIdleTime"=dword:00000001
    "fPromptForPassword"=dword:00000000
    "fResetBroken"=dword:00000000
    "PdClass"=dword:00000002
    "LoadableProtocol_Object"="{5828227c-20cf-4408-b73f-73ab70b8849f}"
    "UserAuthentication"=dword:00000001
    "fDisableCam"=dword:00000000
    "fInheritAutoLogon"=dword:00000001
    "InteractiveDelay"=dword:00000032
    "Domain"=""
    "fInheritReconnectSame"=dword:00000001
    "SelectTransport"=dword:00000000
    "MinEncryptionLevel"=dword:00000002
    "fInheritShadow"=dword:00000001
    "WFProfilePath"=""
    "fReconnectSame"=dword:00000000
    "PdDLL"="tdtcp"
    "PortNumber"=dword:00000d3d
    "PdFlag1"=dword:00000000
    "WdName"="Microsoft RDP 8.0"
    "fInheritMaxSessionTime"=dword:00000001
    "WdFlag"=dword:00000036
    "SelectNetworkDetect"=dword:00000000
    "fLogonDisabled"=dword:00000000
    "MaxDisconnectionTime"=dword:00000000
    "Callback"=dword:00000000
    "PdDLL1"="tssecsrv"
    "NWLogonServer"=""
    "MaxIdleTime"=dword:00000000
    "fDisableEncryption"=dword:00000001
    "fInheritCallback"=dword:00000000
    "fDisableCcm"=dword:00000000
    "ColorDepth"=dword:00000003
    "PdName"="tcp"
    "fEnableWinStation"=dword:00000001
    "OutBufLength"=dword:00000212
    "PdFlag"=dword:0000004e
    "CallbackNumber"=""
    "CdClass"=dword:00000000
    "Shadow"=dword:00000001
    "fDisableCdm"=dword:00000000
    "PdName1"="tssecsrv"
    "fInheritSecurity"=dword:00000000
    "CdDLL"=""
    "LanAdapter"=dword:00000000
    "fInheritResetBroken"=dword:00000001
    "CfgDll"="RDPCFGEX.DLL"
    "InitialProgram"=""
    "fDisableClip"=dword:00000000
    "InputBufferLength"=dword:00000800
    "fAllowSecProtocolNegotiation"=dword:00000001
    "fDisableAudioCapture"=dword:00000000
    "Password"=""
    "CdName"=""
    "fDisableLPT"=dword:00000000
    "CdFlag"=dword:00000000
    "PdClass1"=dword:0000000b
    "fAutoClientLpts"=dword:00000001
    "fAutoClientDrives"=dword:00000001
    "fInheritCallbackNumber"=dword:00000001
    "OutBufCount"=dword:00000006
    "fInheritMaxDisconnectionTime"=dword:00000001
    "MaxInstanceCount"=dword:ffffffff
    "KeyboardLayout"=dword:00000000
    "fDisableExe"=dword:00000000
    "AudioEnumeratorDll"="rdpendp.dll"
    "Username"=""
    "KeepAliveTimeout"=dword:00000000
    "fUseDefaultGina"=dword:00000000
    "fHomeDirectoryMapRoot"=dword:00000000
    "fInheritColorDepth"=dword:00000000
    "fForceClientLptDef"=dword:00000001
    "WorkDirectory"=""
    "SecurityLayer"=dword:00000001
    "DrawGdiplusSupportLevel"=dword:00000001
    "WdPrefix"="RDP"
    "fInheritAutoClient"=dword:00000001
    "fDisableCpm"=dword:00000000
    "Comment"=""
    "OutBufDelay"=dword:00000064
    "fInheritInitialProgram"=dword:00000001
    "MaxConnectionTime"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\VideoRemotingWindowNames]
    "AGFullScreenWinClass"="*"
    "MacromediaFlashPlayerActiveX"="*"
    "EVRVideoHandler"="*"
    "MicrosoftSilverlight"="*"
    "ShockwaveFlashFullScreen"="*"

    Additional 2012 R2 values:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp]
    "UserAuthenticationBackup"=dword:00000000
    "MaxMonitors"=dword:00000004
    "MaxXResolution"=dword:00000a00
    "MaxYResolution"=dword:00000640
  4. Double-click the RDP-Tcp.reg file and click Yes at the prompt.

So later after sometime started to poke around to see if there is any other way rather than deleting and creating the registry setting , well none in Windows 2012.

Well then i went back to Windows 2008 Server opened tsconfig.msc and tried to connect to a Windows 2012 R2 Server and see if it connects and sure enough i was able to connect and it showed the RDP-TCP settings and tried deleting and recreating it and it worked like a charm.

















































































































In Windows 2016 TP4 i don't see any option to delete it from MMC, tested it from Windows 2008, was able to connect and recreate the Listener as well..

Windows 2016 TP4:











                                                                                                                                                               

Let's hope final release of Windows 2016 probably this option comes back which i highly doubt it .
As long as Windows 2008 around it works ,if not we have to work with registry, no much choice :)

Hopefully this helps someone, until next one you all have a great day ahead!!!!!!!!!!!!!!!!!!!!!

Monday, August 8, 2016

SSL Offloading Where to do it? in Citrix Storefront 7.6

Good day All,

Welcome back!!!

We are trying to setup SSL for our new Citrix 7.6 farm and we had a  question from our Network guy asking how is password been sent when user types the user name and password on the Citrix URL.
Well  Citrix support was called they kept saying it was clear text so to double confirm it i setup a lab and installed Netmon on the Storefront server.

My Source IP was 192.168.1.5 and my destination Storefront IP was 192.168.1.72 and by delivery controller was 192.168.1.73.

So opened the URL , typed it username and password before i hit enter logged on to the Store front Server and installed the Netmon and started the capture.

Logged into client machine 192.168.1.5 and at Citrix URL login screen hit entered and i was logged in to Citrix and my published app showed up.So i quickly jumped to my storefront and stopped the Netmon.

Microsoft Netmon  is very simple and powerful tool , all you have to do is Click All Traffic you will see it beautifully segregates traffic between 2 hosts..
















Well i high-lighted in yellow, now you know my username and password for my Citrix login.

So i was curious and wanted to check how is password been sent from Storefront to Delivery Controller and my delivery controller IP was 192.168.1.73 and for every one knowledge its is been set at port 80 for communication


















if you see the screen shot Storefront is sending a xml query to delivery controller on port 80 and good thing is password is not been sent as clear text but its been de-crypted .
Well there are tools out there which can help in de-crypting so at least it not clear-text.

So the big question becomes how far we should go to encrypt the traffic?????

1. It depends on how the client is connecting? if external then SSL is a must on for Citrix URL
2.If all Client communication is internal probably we can get away with no SSL
3.Is SSL needed between storefront and delivery controller, it would depend on company to company how far we need to go and how secured you want.. understand there will always be over head associated to it.
4.Most of the companies i have seen is they offload SSL on load balancer either on F5 or Net scalar to avoid over head on the Storefront, that means traffic from Client to F5 or Net Scalar will be 443 and from there it will be port 80 to Storefront.


So testing,testing and more testing how secure and how how fast you need the apps to users will determine how much secure you need it.


before i conclude i added SSL for storefront so now see the communication from user desktop to Storefront.. its all been encrypted on port 443 and Secure..



















Let me know how secure you have implemented in your environment , so until next one you all have good day!!!!!!!!!!!!!!!!!!!!


Wednesday, July 6, 2016

Windows Performance Analysis pdf for a grab!!!!

Good day All,

Welcome back!!!
 I came across this link i see ebook of Client Huffman Windows Performance Analysis is up for a grab

As of this posting this link is available

http://www.rccsonline.com/library/backend/books/Syngress%20Publishing%20Windows%20Performance%20Analysis%20Field%20Guide%20(2015).pdf

 Don't miss to download a copy, it is must read if you are a Windows Admin :)

 Untill next one all have a good day!!!!!