<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Geniesis's Weblog</title>
	<atom:link href="http://geniesis.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://geniesis.wordpress.com</link>
	<description>Design</description>
	<lastBuildDate>Wed, 27 Jul 2011 06:58:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='geniesis.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Geniesis's Weblog</title>
		<link>http://geniesis.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://geniesis.wordpress.com/osd.xml" title="Geniesis&#039;s Weblog" />
	<atom:link rel='hub' href='http://geniesis.wordpress.com/?pushpress=hub'/>
		<item>
		<title>ESX 4.x dvSwitch with Private VLANs to Cisco</title>
		<link>http://geniesis.wordpress.com/2011/07/04/esx4-x-dvswtich-pvlan-cisco/</link>
		<comments>http://geniesis.wordpress.com/2011/07/04/esx4-x-dvswtich-pvlan-cisco/#comments</comments>
		<pubDate>Sun, 03 Jul 2011 14:30:09 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=262</guid>
		<description><![CDATA[With the new dvSwitch capabilities in ESX 4.x, one feature that has been introduced is Private VLANs. Private VLANs give you the ability to isolate network devices/nodes that are within the same Layer 2 domain. Check out http://kb.vmware.com/kb/1010691 for VMware&#8217;s description of Private VLANs. Cisco also has an article for configuring Private VLANs on Catalyst switches. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=262&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>With the new dvSwitch capabilities in ESX 4.x, one feature that has been introduced is Private VLANs. Private VLANs give you the ability to isolate network devices/nodes that are within the same Layer 2 domain.</p>
<p>Check out<a title="Vmware KB1010691" href="http://kb.vmware.com/kb/1010691" target="_blank"> http://kb.vmware.com/kb/1010691</a> for VMware&#8217;s description of Private VLANs.</p>
<p>Cisco also has an article for<a href="http://www.cisco.com/en/US/tech/tk389/tk814/technologies_configuration_example09186a008017acad.shtml" target="_blank"> configuring Private VLANs on Catalyst switches</a>.</p>
<p>Essentially, you are able to create Private VLANs on a Cisco switch and trunk it to the ESX server.</p>
<p>On the ESX server you can create a dvSwitch with the private VLAN assignments as required.</p>
<p><a href="http://geniesis.files.wordpress.com/2011/07/selection_002.png"><img class="alignnone size-medium wp-image-263" title="dvSwitch Private VLAN Settings" src="http://geniesis.files.wordpress.com/2011/07/selection_002.png?w=300&#038;h=229" alt="" width="300" height="229" /></a></p>
<p>As shown above, I have created a single primary VLAN with ID 3 and associated with it Secondary VLAN ID 300.</p>
<p>PVLAN 300 is an isolated VLAN. This means that guests inside PVLAN 300 will not be able communicate with each other. They will only be able to communicate with guests in the promiscuous vlan.</p>
<p>Once this is done, you will need to create a new port group which has the vlan settings set to Private vlan and in the drop down list, select the appropriate PVLAN.</p>
<p><a href="http://geniesis.files.wordpress.com/2011/07/selection_001.png"><img class="alignnone size-medium wp-image-264" title="dvSwitch Port Group Setup" src="http://geniesis.files.wordpress.com/2011/07/selection_001.png?w=300&#038;h=119" alt="" width="300" height="119" /></a></p>
<p>You can see two port groups have been created. Servers in the DMZ-WebServers port group will only be able to communicated with servers in the DMZ port group.</p>
<p>As for the Cisco configuration, it is relatively simple.</p>
<p>Creation of the PVLANs can be found in the Cisco documentation as linked earlier in this post.</p>
<p>To integrate with VMware, the switch ports associated with the ESX host must be trunked and allow all the appropriate VLANs including the PVLANs you have created.</p>
<p><a href="http://geniesis.files.wordpress.com/2011/07/selection_003.png"><img class="alignnone size-medium wp-image-265" title="Cisco Private VLANs" src="http://geniesis.files.wordpress.com/2011/07/selection_003.png?w=300&#038;h=57" alt="" width="300" height="57" /></a></p>
<p>&nbsp;</p>
<p>You will find that VMware virtual machines will not be able to communicate with other machines in the PVLAN except for hosts in the promiscuous vlan. Also note that the PVLAN settings are still honoured when entering the Cisco switch. This means you can have a combination of ESX PVLAN isolated/community hosts as well as physical PVLAN hosts and still have isolation between all machines.</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/262/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=262&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2011/07/04/esx4-x-dvswtich-pvlan-cisco/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>

		<media:content url="http://geniesis.files.wordpress.com/2011/07/selection_002.png?w=300" medium="image">
			<media:title type="html">dvSwitch Private VLAN Settings</media:title>
		</media:content>

		<media:content url="http://geniesis.files.wordpress.com/2011/07/selection_001.png?w=300" medium="image">
			<media:title type="html">dvSwitch Port Group Setup</media:title>
		</media:content>

		<media:content url="http://geniesis.files.wordpress.com/2011/07/selection_003.png?w=300" medium="image">
			<media:title type="html">Cisco Private VLANs</media:title>
		</media:content>
	</item>
		<item>
		<title>Policy route Management traffic</title>
		<link>http://geniesis.wordpress.com/2010/12/31/policy-route-management-traffic/</link>
		<comments>http://geniesis.wordpress.com/2010/12/31/policy-route-management-traffic/#comments</comments>
		<pubDate>Fri, 31 Dec 2010 06:48:24 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Cisco]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=257</guid>
		<description><![CDATA[The other day I ran into the issue of a firewall being in the way of management traffic for a switch. In this particular network design, there was a secondary path that bypassed the firewall. This secondary link is used by a route-map on ingress to route traffic requiring ultra low latency and jitter. As [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=257&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The other day I ran into the issue of a firewall being in the way of management traffic for a switch. In this particular network design, there was a secondary path that bypassed the firewall. This secondary link is used by a route-map on ingress to route traffic requiring ultra low latency and jitter.</p>
<p>As a result, I ended up pushing management traffic for the switch on the other side of the firewall through this secondary link as well. Since management traffic is sourced from the switch itself, a normal policy-map to an interface would not work. Hence, the following solution was found.</p>
<blockquote><p>interface LoopBack0</p>
<p>ip address 1.1.1.1 255.255.255.0</p>
<p>!</p>
<p>ip access-list extended MANAGEMENT_TRAFFIC</p>
<p>permit ip any host 1.1.1.1</p>
<p>permit ip host 1.1.1.1 any</p>
<p>!</p>
<p>route-map MANAGEMENT_POLICY 10</p>
<p>match ip address MANAGEMENT_TRAFFIC</p>
<p>set ip next-hop 2.2.2.2</p></blockquote>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/257/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=257&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2010/12/31/policy-route-management-traffic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
		<item>
		<title>Exchange Stub Mailboxes</title>
		<link>http://geniesis.wordpress.com/2010/07/11/exchange-stub-mailboxes/</link>
		<comments>http://geniesis.wordpress.com/2010/07/11/exchange-stub-mailboxes/#comments</comments>
		<pubDate>Sat, 10 Jul 2010 14:47:05 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=254</guid>
		<description><![CDATA[During an Exchange 2003 to Exchange 2010 migration I came across a situation whereby the mailbox move caused a stub mailbox to be left in the Exchange 2003 mailbox store. That is, a 0 Item mailbox of a very small size (few bytes). Running the &#8220;Get-MoveRequestStatistics&#8217; command, it reported a &#8220;CompletedWithWarning&#8221; status. The event logs [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=254&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>During an Exchange 2003 to Exchange 2010 migration I came across a situation whereby the mailbox move caused a stub mailbox to be left in the Exchange 2003 mailbox store. That is, a 0 Item mailbox of a very small size (few bytes).</p>
<p>Running the &#8220;Get-MoveRequestStatistics&#8217; command, it reported a &#8220;CompletedWithWarning&#8221; status. The event logs showed that the move completed successfully but was unable to delete the mailbox on the source server. This is how I ended up with a stub mailbox.</p>
<p>I then tried to delete the mailbox on the Exchange 2003 store. This was a VERY BIG MISTAKE. It proceeded to delete the Exchange details for the user in AD. This meant that even the Exchange 2010 server deleted the mailbox as well. I was however able to get it back by reconnecting the mailbox use the cli command &#8216;Connect-Mailbox&#8217; on the Exchange 2010 server. Note that the deleted mailbox never came up on the &#8220;Disconnected Mailbox&#8221; section of the GUI.</p>
<p>This still left me with a stub mailbox on the Exchange 2010 server albeit with a red &#8216;X&#8217; on the mailbox. Attempting to purge the mailbox gave a &#8220;&#8230; have been reconnected with an exisitng user&#8230;&#8221; error message.</p>
<p>The solution to getting rid of the stub mailbox ended up being setting the retention policy for deleted mailboxes to 0 days. That is in setting mailbox store-&gt;properties-&gt;limit-&gt;Keep deleted mailbox to 0 days.</p>
<p>Then running the &#8220;Cleanup Agent&#8221; allowed the system to delete the stub mailbox.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/254/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/254/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/254/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/254/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/254/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/254/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/254/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/254/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/254/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/254/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/254/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/254/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/254/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/254/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=254&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2010/07/11/exchange-stub-mailboxes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
		<item>
		<title>Cannot save attachment error in Outlook XP/2003/2007</title>
		<link>http://geniesis.wordpress.com/2010/06/30/cannot-save-attachment-error-in-outlook-xp20032007/</link>
		<comments>http://geniesis.wordpress.com/2010/06/30/cannot-save-attachment-error-in-outlook-xp20032007/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 05:17:33 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=250</guid>
		<description><![CDATA[The other day I came across an error with Outlook complaining that it couldn&#8217;t open an attachment. It appears that when opening or saving an Outlook attachment it will save the file to it&#8217;s secure temporary location first. The issue with this is that if you have many attachments with the same filename, you may [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=250&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The other day I came across an error with Outlook complaining that it couldn&#8217;t open an attachment.</p>
<p>It appears that when opening or saving an Outlook attachment it will save the file to it&#8217;s secure temporary location first. The issue with this is that if you have many attachments with the same filename, you may run into an issue whereby Outlook runs out of alternative filenames.</p>
<p>When Outlook saves the attachment to the temp location it uses the attachment name. However if the filename already exists it appends (#) where # is an incremental number starting at 1. It appears that when outlook reaches &#8220;filename (99)&#8221; it isn&#8217;t programmed to allow three digit numbers and hence fails to save the file.</p>
<p>The solution to this is to clear the temporary folder. You can work out where this folder is by looking at the registry location: &#8220;HKEY_CURRENT_USER\Software\Microsoft\Office\###\Outlook\Security\OutlookSecureTempFolder&#8221; where ### is the Microsoft Office version. 11.0 for Outlook 2003.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/250/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/250/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/250/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/250/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/250/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/250/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/250/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/250/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/250/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/250/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/250/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/250/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/250/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/250/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=250&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2010/06/30/cannot-save-attachment-error-in-outlook-xp20032007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
		<item>
		<title>BES and SBS2003 MSDE SQL</title>
		<link>http://geniesis.wordpress.com/2010/02/23/bes-and-sbs2003-msde-sql/</link>
		<comments>http://geniesis.wordpress.com/2010/02/23/bes-and-sbs2003-msde-sql/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 04:11:17 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Blackberry Enterprise]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=246</guid>
		<description><![CDATA[If your going to run BES on SBS2003 then you will need to check what version of MSDE SBS is using. You can do this by looking in c:\program files\Microsoft SQL Server\&#60;instance&#62; If your using MSDE2000, then use the following steps: Manually install an MSDE instance for the BlackBerry Enterprise Server by completing the following [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=246&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If your going to run BES on SBS2003 then you will need to check what version of MSDE SBS is using.</p>
<p>You can do this by looking in c:\program files\Microsoft SQL Server\&lt;instance&gt;</p>
<p>If your using MSDE2000, then use the following steps:</p>
<ol>
<li>Manually install an MSDE instance for the BlackBerry Enterprise Server by completing the following steps:
<ol>
<li>Go to the <a href="http://support.microsoft.com/" target="_blank">Microsoft Support Center</a> and download MSDE 2000 Release A. Make sure to read the MSDE2000RelA release notes.</li>
<li>Double-click the downloaded file to extract the MSDE Release A installation files.</li>
<li>Locate the directory to which the files were extracted. The default directory is C:\<em>MSDERelA</em>.</li>
<li>Open a command prompt window and change directory to the folder identified in step 3.</li>
<li>Type <strong>setup sapwd=&lt;<em>password</em>&gt; instancename=BlackBerry</strong>, where <strong>&lt;<em>password</em>&gt;</strong> is the strong password you want to specify for the <strong>sa </strong>account.</li>
</ol>
</li>
<li>Run the BlackBerry Enterprise Server software installation program.</li>
<li>When prompted, restart the BlackBerry Enterprise Server.</li>
<li>When prompted to specify BlackBerry Configuration Database information, type the configuration settings listed in the table below.<br />
<table>
<tbody>
<tr>
<td>BlackBerry Configuration Database details</td>
<td>Configuration setting</td>
</tr>
<tr>
<td>Database location</td>
<td><strong>Local</strong></td>
</tr>
<tr>
<td>Database information</td>
<td><strong>&lt;<em>server_name</em>&gt;\BlackBerry</strong></p>
<p>where <strong>&lt;<em>server_name</em>&gt;</strong> represents the NetBIOS name of the computer in which the MSDE instance was installed.</td>
</tr>
<tr>
<td>Database name</td>
<td><strong>BESMgmt</strong></td>
</tr>
<tr>
<td>Data Directory</td>
<td><strong>C:\Program Files\Microsoft SQL Server\MSSQL$BlackBerry\Data</strong></td>
</tr>
<tr>
<td>Backup Directory</td>
<td><strong>C:\Program Files\Microsoft SQL Server\MSSQL$BlackBerry\Backup</strong></td>
</tr>
<tr>
<td>Database authentication</td>
<td><strong>Windows (Trusted)</strong></td>
</tr>
</tbody>
</table>
</li>
<li>Continue the installation and start the BlackBerry Enterprise Server services when prompted.</li>
</ol>
<p>If your using MSDE 2005</p>
<p>1) Download the software to C:\Downloads<br />
2) Open a command prompt and go to C:\Downloads<br />
3) Run this command C:\Downloads\SQLEXPR32.exe -X<br />
4) A prompt will open asking you where to Extract the program (C:\MSDE2005)<br />
5) From the SAME command prompt browse to C:\MSDE2005<br />
6) Run this command setup INSTANCENAME=&#8221;blackberry&#8221; SAPWD=&#8221;password&#8221; (this is a copy/paste from a blackberry support e-mail from 2005)<br />
7) *VERY IMPORTANT* When it opens the installer for MSDE 2005 UNCHECK the Hide Advanced Options. Continue clicking next in the install until it comes to the point where it asks about Authentication. Selected MIXED MODE and enter &#8220;password&#8221; as the password.<br />
 <img src='http://s0.wp.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> When it comes time in the install you will see SERVERNAME you add \blackberry to make it SERVERNAME\blackberry</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/246/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=246&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2010/02/23/bes-and-sbs2003-msde-sql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
		<item>
		<title>BES on SBS 2003</title>
		<link>http://geniesis.wordpress.com/2010/02/23/bes-on-sbs-2003/</link>
		<comments>http://geniesis.wordpress.com/2010/02/23/bes-on-sbs-2003/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 03:12:42 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Blackberry Enterprise]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=239</guid>
		<description><![CDATA[It seems more and more people insist on putting Blackberry Enterprise Server or Blackberry Professional on the same server as SBS 2003. This really isn&#8217;t the best way to install BES, but it is doable. Here is a brief summary of the steps you need to take. (Thanks goes to GaryCutri &#8211; source:http://www.blackberryforums.com.au/forums/microsoft-exchange/281-bes-sbs-2003-a.html). Ensure the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=239&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It seems more and more people insist on putting Blackberry Enterprise Server or Blackberry Professional on the same server as SBS 2003. This really isn&#8217;t the best way to install BES, but it is doable.</p>
<p>Here is a brief summary of the steps you need to take.</p>
<p>(Thanks goes to GaryCutri &#8211; source:http://www.blackberryforums.com.au/forums/microsoft-exchange/281-bes-sbs-2003-a.html).</p>
<ol>
<li>Ensure the port 3101 TCP is open on the firewall (Outbound ONLY).</li>
<li>Create a new user called BESadmin and ensure you create a mailbox. Ensure this user is ONLY a member of &#8220;Domain users&#8221;</li>
<li>Make BESadmin a local Administrator of the server. This is done in AD via the &#8220;Built-in&#8221; Administrators group</li>
<li>Go to Admin Tools on open &#8220;Domain Controller Security Policy&#8221; and expand the &#8220;Local Policies&#8221; and &#8220;User Right Assignment&#8221;. You need to add BESadmin to &#8220;Log on Locally&#8221; and &#8220;log on as Service&#8221;.</li>
<li>Open Exchange System Manager and right mouse click on &#8220;DOMIANNAME (Exchange)&#8221; and select Delegate Control. Follow the steps and add BESadmin as an Exchange View Only Administrator.</li>
<li>In Exchange manager expand the servers folder and right mouse click on your server and select properties. On the properties windows select BESadmin and add the permissions &#8220;Administer Information Store, Receive As, Send As&#8221;</li>
<li>Open Active Directory and from the View menu select &#8220;Advanced Features&#8221;. Then go to each user that will be added to the BES and open their properties, go to the security tab and add the user BESadmin and add the security permission &#8220;Send As&#8221;. (This will overcome some MS patches that prevent BES sending emails)</li>
<li>Log on as BESadmin and install the BES software, normally you just install &#8220;BlackBerry Enterprise Server&#8221; as most sites don&#8217;t use the MDS services (MDS is a much heavier install). Follow the prompts of the install and the server will be required to restart half way through the install. Restart the server and log back on as BESadmin and the install will continue. (Make sure the Connect Test works and the SRP ID etc is validated during the install)</li>
<li>After the install is finished open BlackBerry Manager, an error will appear about MAPI client which you can just hit OK. The MAPI setting windows will appear so just add the server name back in and select &#8220;Check Name&#8221;, if it resolves just hit OK and the manager will start.</li>
<li>Within Blackberry Manager click on Blackberry Domain in the left column and then the users SERVERS tab in the center section, select your server within this tab and view the properties below. Ensure that &#8220;SRP Status:&#8221; is Connected (This can take a few minutes the first time so refresh the screen a few times). Once your status is connected you can start adding users.</li>
<li>Within Blackberry Manager click on you server name in the left column and then the users TAB in the centre section, just add a user and the click on that user. You will see all the users’ properties and a drop down menu called &#8220;Service Access” and select “Set Activation Password” and set a password of “a” for example.</li>
<li>Turn on you BlackBerry device and ensure Wireless is enabled. Go into “Options/Settings” and “Time &amp; Date” and set the correct zone and time etc. Then from the home screen go to enterprise activation and enter the users email address and enter the password that was set in step 11. Press the track wheel and select Activate. Within a minute you should get data returned which indicates the process is functioning correct.</li>
</ol>
<p><strong>Extra</strong></p>
<p><strong>Note:</strong></p>
<ul>
<li> Sites running SBS 2003 premium will need to change the BES &#8220;Web Server Listen Port&#8221; from 8080 to another available port (e.g. 8090 or 9090) as soon as it is installed. This port needs to be changed as the BES Web Server will be listening on the same port as ISA. To change this setting open Blackberry Manager, select MDS and then &#8220;edit Properties&#8221; and change the &#8220;Web Server Listen Port&#8221; to the desired port number.</li>
<li>Also ensure you review the IT Policy in BlackBerry Manager. This can be found in BlackBerry Domain &gt; Global TAB &gt; Edit properties. It is recommended that in the IT Policy you go into “Device Only Items” and set “Enable WAP config” to FALSE, this will force user to use the free browser (It uses the internet connection of your BES server). It is also highly recommended that you configure a password policy prior to rolling out any handhelds.</li>
<li>If you are unable to activate devices wirelessly you can test your connectivity to Blackberry buy running the following app from the command prompt: C:\Program Files\Research In Motion BlackBerry Enterprise Server\Utility\BBSrpTest.exe. This will send a signal to BB and wait for a response, it this fails check your firewall settings (open and/or direct port 3101 TCP to you BES server)</li>
<li>If you have Domain Admins using BlackBerry devices you may have to run the following script if you are unable to send email for those users devices: dsacls &#8220;cn=adminsdholder,cn=system,dc=domainname,dc=c om &#8221; /G &#8220;DOMAINNAME\BESadmin:CA;Send As&#8221;</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/239/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=239&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2010/02/23/bes-on-sbs-2003/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
		<item>
		<title>PFDAVAdmin error</title>
		<link>http://geniesis.wordpress.com/2010/02/03/pfdavadmin-error/</link>
		<comments>http://geniesis.wordpress.com/2010/02/03/pfdavadmin-error/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 02:16:26 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=236</guid>
		<description><![CDATA[You may run across this error when using it on servers. Esepcially Exchange 07 servers. Could not expand https://FQDNServer/ExAdmin/Admin/HOME.LOCAL/public%20folders/:Name cannot begin with the &#8217;0&#8242; character. hexadecimal value 0&#215;30. Line 1. position 409. It appears that this error is due to a .NET version problem. The tool requires the .NET 1.1 framework which on Exchange 07 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=236&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>You may run across this error when using it on servers. Esepcially Exchange 07 servers.</p>
<blockquote><address>Could not expand https://FQDNServer/ExAdmin/Admin/HOME.LOCAL/public%20folders/:Name cannot begin with the &#8217;0&#8242; character. hexadecimal value 0&#215;30. Line 1. position 409.</address>
</blockquote>
<p>It appears that this error is due to a .NET version problem. The tool requires the .NET 1.1 framework which on Exchange 07 servers probably wouldn&#8217;t be installed since Exchange 07 uses .NET 2.0.</p>
<p>It is also advised that you DO NOT install .NET 1.1 on a working Exchange 07 server since the .NET 1.1 installation will reset crucial config settings and break Exchange.</p>
<p>If you however install .NET1.1 before installing Exchange, then you should be fine there. Hence, its best to run the tool on a workstation that has .NET1.1 installed.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/236/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=236&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2010/02/03/pfdavadmin-error/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
		<item>
		<title>Undeleting Exchange Emails</title>
		<link>http://geniesis.wordpress.com/2010/01/11/undeleting-exchange-emails/</link>
		<comments>http://geniesis.wordpress.com/2010/01/11/undeleting-exchange-emails/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 04:05:57 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/2010/01/11/undeleting-exchange-emails/</guid>
		<description><![CDATA[If a user deleted a folder or item from a public folder or mailbox, and also deleted it from their deleted items folder as well, then not all is lost. Using the MS tool PFDAVAdmin, @ http://www.microsoft.com/downloads/details.aspx?FamilyId=635BE792-D8AD-49E3-ADA4-E2422C0AB424&#38;displaylang=en Allows you to recover any email that has been deleted.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=235&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If a user deleted a folder or item from a public folder or mailbox, and also deleted it from their deleted items folder as well, then not all is lost.</p>
<p>Using the MS tool PFDAVAdmin, @ http://www.microsoft.com/downloads/details.aspx?FamilyId=635BE792-D8AD-49E3-ADA4-E2422C0AB424&amp;displaylang=en</p>
<p>Allows you to recover any email that has been deleted.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/235/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/235/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/235/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/235/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/235/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/235/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/235/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/235/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/235/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/235/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/235/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/235/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/235/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/235/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=235&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2010/01/11/undeleting-exchange-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
		<item>
		<title>Domain Controller Replication Fails with Access Denied</title>
		<link>http://geniesis.wordpress.com/2009/12/04/domain-controller-replication-fails-with-access-denied/</link>
		<comments>http://geniesis.wordpress.com/2009/12/04/domain-controller-replication-fails-with-access-denied/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 14:17:36 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=230</guid>
		<description><![CDATA[Working on a multi-site AD setup, a DC was shutdown for a few months. When the server came backup, it appeared the computer account credentials had expired. Normally a netdom resetpwd /server:Replication_Partner_Server_Name userd:domainname\administrator_id /passwordd:* would fix the issue, however in this case it didn&#8217;t. Because the DC was reporting an access denied error, running DCpromo [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=230&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Working on a multi-site AD setup, a DC was shutdown for a few months. When the server came backup, it appeared the computer account credentials had expired.</p>
<p style="text-align:left;">Normally a <em>netdom resetpwd /server:<var>Replication_Partner_Server_Name</var> userd:<var>domainname</var>\<var>administrator_id</var></em> /passwordd:* would fix the issue, however in this case it didn&#8217;t.</p>
<p>Because the DC was reporting an access denied error, running DCpromo to Unpromo the DC didn&#8217;t work either. It failed with an Access Denied error as well.</p>
<p>The solution came to be that disabling KDC (net stop kdc), then running DCpromo and Unpromo the broken DC would then work. After a reboot, a DCpromo could be run again to make it a DC again.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/230/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=230&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2009/12/04/domain-controller-replication-fails-with-access-denied/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
		<item>
		<title>ASA VPN Server config template</title>
		<link>http://geniesis.wordpress.com/2009/11/20/asa-vpn-server-config-template/</link>
		<comments>http://geniesis.wordpress.com/2009/11/20/asa-vpn-server-config-template/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 04:21:05 +0000</pubDate>
		<dc:creator>geniesis</dc:creator>
				<category><![CDATA[ASA]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Crypto]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://geniesis.wordpress.com/?p=226</guid>
		<description><![CDATA[I keep forgetting the config required for setting up an ASA VPN server, so here it is for reference: This is an ASA config with Radius authentication. aaa-server RADIUS protocol radius aaa-server RADIUS (inside) host &#60;HOST&#62; key &#60;KEY&#62; access-list VPN_splitTunnelAcl standard permit &#60;NETWORK&#62; &#60;SUBNET&#62; ip local pool VPN-IP-POOL &#60;FROM_IP&#62;-&#60;TO_IP&#62; mask 255.255.255.0 access-list nonat extended permit [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=226&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I keep forgetting the config required for setting up an ASA VPN server, so here it is for reference:</p>
<p>This is an ASA config with Radius authentication.</p>
<blockquote><p>aaa-server RADIUS protocol radius<br />
aaa-server RADIUS (inside) host &lt;HOST&gt;<br />
key &lt;KEY&gt;</p>
<p>access-list VPN_splitTunnelAcl standard permit &lt;NETWORK&gt; &lt;SUBNET&gt;<br />
ip local pool VPN-IP-POOL &lt;FROM_IP&gt;-&lt;TO_IP&gt; mask 255.255.255.0</p>
<p>access-list nonat extended permit ip any &lt;NETWORK&gt; &lt;SUBNET&gt;<br />
nat (inside) 0 access-list nonat</p>
<p>group-policy &lt;GROUP&gt; internal<br />
group-policy &lt;GROUP&gt; attributes<br />
dns-server value &lt;DNS_IP&gt;<br />
vpn-tunnel-protocol IPSec webvpn<br />
ipsec-udp enable<br />
split-tunnel-policy tunnelspecified<br />
split-tunnel-network-list value VPN_splitTunnelAcl<br />
default-domain value &lt;DNS_SUFFIX&gt;<br />
webvpn<br />
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac<br />
crypto ipsec security-association lifetime seconds 28800<br />
crypto ipsec security-association lifetime kilobytes 4608000<br />
crypto dynamic-map outside_dyn_map 10 set transform-set ESP-3DES-SHA<br />
crypto dynamic-map outside_dyn_map 10 set security-association lifetime seconds 28800<br />
crypto dynamic-map outside_dyn_map 10 set security-association lifetime kilobytes 4608000<br />
crypto dynamic-map outside_dyn_map 10 set reverse-route<br />
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map<br />
crypto map outside_map interface outside<br />
isakmp enable outside<br />
isakmp policy 10 authentication pre-share<br />
isakmp policy 10 encryption 3des<br />
isakmp policy 10 hash sha<br />
isakmp policy 10 group 2<br />
isakmp policy 10 lifetime 1000<br />
isakmp nat-traversal  20</p>
<p>tunnel-group &lt;TUNNEL&gt; type ipsec-ra<br />
tunnel-group &lt;TUNNEL&gt; ipsec-attributes<br />
pre-shared-key &lt;PRESHAREKEY&gt;<br />
isakmp keepalive threshold 10 retry 2<br />
tunnel-group &lt;TUNNEL&gt; general-attributes<br />
address-pool VPN-IP-POOL<br />
authentication-server-group RADIUS<br />
default-group-policy &lt;GROUP&gt;</p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/geniesis.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/geniesis.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/geniesis.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/geniesis.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/geniesis.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/geniesis.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/geniesis.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/geniesis.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/geniesis.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/geniesis.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/geniesis.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/geniesis.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/geniesis.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/geniesis.wordpress.com/226/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=geniesis.wordpress.com&amp;blog=4268058&amp;post=226&amp;subd=geniesis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://geniesis.wordpress.com/2009/11/20/asa-vpn-server-config-template/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c76a2811ee38d8a22d7a47606b03979?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">geniesis</media:title>
		</media:content>
	</item>
	</channel>
</rss>
