<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Oliver Hansen &#187; Technology</title>
	<atom:link href="http://blog.oliverhansen.com/index.php/category/technology/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.oliverhansen.com</link>
	<description>A techie&#39;s not-so-technical weblog</description>
	<lastBuildDate>Sun, 27 Nov 2011 23:37:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>

	<item>

		<title>Interesting History of Mathmaticians</title>

		<link>http://blog.oliverhansen.com/index.php/2011/09/11/interesting-history-of-mathmaticians/</link>

		<comments>http://blog.oliverhansen.com/index.php/2011/09/11/interesting-history-of-mathmaticians/#comments</comments>

		<pubDate>Sun, 11 Sep 2011 23:19:32 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Videos]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=775</guid>


		<description><![CDATA[<p>I found this series quite interesting. I&#8217;m not very confident in my own mathmatical abilities but it&#8217;s interesting to me to ponder these larger ideas.</p>
<p></p>
Possibly Related Posts:Interesting VideoInteresting Idea In Free Culture &#8212; CCTV For FilmmakingThe Trolley ProblemPowered by Contextual Related Posts]]></description>

	
		<content:encoded><![CDATA[<p>I found this series quite interesting. I&#8217;m not very confident in my own mathmatical abilities but it&#8217;s interesting to me to ponder these larger ideas.</p>
<p><embed src="http://www.youtube.com/v/Cw-zNRNcF90?version=3" type="application/x-shockwave-flash" width="500" height="400"></embed></p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2007/05/13/intersting-video/" rel="bookmark" class="crp_title">Interesting Video</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/10/01/interesting-idea-in-free-culture-cctv-for-filmmaking/" rel="bookmark" class="crp_title">Interesting Idea In Free Culture &#8212; CCTV For Filmmaking</a></li><li><a href="http://blog.oliverhansen.com/index.php/2008/07/29/the-trolley-problem/" rel="bookmark" class="crp_title">The Trolley Problem</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2011/09/11/interesting-history-of-mathmaticians/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>Install pfSense on Symantec 5420 Security Gateway</title>

		<link>http://blog.oliverhansen.com/index.php/2009/11/18/install-pfsense-on-symantec-5420-security-gateway/</link>

		<comments>http://blog.oliverhansen.com/index.php/2009/11/18/install-pfsense-on-symantec-5420-security-gateway/#comments</comments>

		<pubDate>Wed, 18 Nov 2009 21:32:31 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[5420]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[pfsense]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[unix]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=567</guid>


		<description><![CDATA[<p>I need to give credit to this post in the pfSense forums which showed that this was possible. This box is pretty nice in that the processor is a Celeron 2.0GHz and it has 6 onboard Intel 10/100 NICs which are preferred by far over the usual Realtek NICs found in embedded devices. It was [...]]]></description>

	
		<content:encoded><![CDATA[<p>I need to give credit to <a href="http://forum.pfsense.org/index.php/topic,17843.0.html">this post in the pfSense forums</a> which showed that this was possible. This box is pretty nice in that the processor is a Celeron 2.0GHz and it has 6 onboard Intel 10/100 NICs which are preferred by far over the usual Realtek NICs found in embedded devices. It was just by chance that I saw the post the other day even though it had been posted a while back. My company had two of these donated a while back but we weren&#8217;t using them because we had no real need to muck with the licensing when the hardware was discontinued. Have a look at what you can find these <a href="http://www.google.com/products?oe=UTF-8&#038;sourceid=navclient&#038;gfns=1&#038;q=Symantec+5420+Security+Gateway&#038;um=1&#038;ie=UTF-8&#038;ei=L2YES4ajB5DSsgOC3YGXBg&#038;sa=X&#038;oi=product_result_group&#038;ct=title&#038;resnum=4&#038;ved=0CCEQrQQwAw">Symantec 5420 Security Gateway</a> for these days. The author of the post gave a few tips but no real instructions so after I got it working I thought I would put together a step-by-step guide.</p>
<p>First, what you will need:</p>
<ul>
<li>A knowledge of how to install pfSense &#8211; This guide assumes you have installed pfSense before. If you have not, look at the <a href="http://doc.pfsense.org/index.php/InstallationGuide">detailed instructions on the pfSense wiki</a>.</li>
<li>1 Symantec 5420 Security Gateway &#8211; these can be found secondhand since they are discontinued</li>
<li>1 IDE HDD (Hard Drive)</li>
<li>1 computer that can boot from CD &#8211; you will not need this after the install is finished</li>
<li>1 computer with a serial port and a serial cable &#8211; this can be the same computer that you boot with but must have an OS</li>
</ul>
<p><span id="more-567"></span></p>
<ol>
<li>Burn a copy of the <a href="http://www.pfsense.org/index.php?option=com_content&#038;task=view&#038;id=58&#038;Itemid=46">latest stable version of pfSense</a> &#8211; I chose 1.2.3-RC3 which I have used and is quite stable.</li>
<li>Open the case of the Symantec 5420 and remove the HDD and the CF-to-IDE adapter. Put them both aside in case you want to revert to the Symantec system at some point.</li>
<li>Take a HDD that can be erased and put it in your PC &#8211; remove all other HDDs  from the computer so you don&#8217;t overwrite the wrong one and set this one to Master.</li>
<li>Boot the pfSense CD and choose &#8220;Easy Install&#8221; which will give you the kernel option we need at the end.</li>
<li>After the files are copied to the hard disk, choose &#8220;Embedded Kernel&#8221; from the custom kernel choices &#8211; this will give us output to the serial port since the Symantec 5420 does not have a monitor output or keyboard inputs.</li>
<li>When the install finishes, choose reboot and wait for the computer to shut down. Before it boots again, turn the computer off and remove the HDD.</li>
<li>Install the HDD into the Symantec 5420 and ensure the jumper is set to Master.</li>
<li>Plug in your serial cable from your running PC and the Symantec 5420 serial port and begin a serial connection with <a href="http://www.google.com/url?q=http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html&#038;ei=zSADS-aiO4_ssQOLlNS4BA&#038;sa=X&#038;oi=smap&#038;resnum=1&#038;ct=result&#038;cd=1&#038;ved=0CAsQqwMoAA&#038;usg=AFQjCNGhgiMXTL2-wtEDMQRdxsND7APsmw">PuTTY</a> or another client program and connect using 9600 8-N-1 settings.</li>
<li>Turn on the Symantec 5420 and see the boot screen come up on your terminal window after about 15 seconds. <strong>Important: Make sure to choose boot option 2: ACPI Disabled</strong>. If it does not boot, go back and check your steps. Ensure you chose the Embedded kernel during install.</li>
<li>When the system boots, it should recognize all the hardware and then prompt you to set up the interfaces just like a normal pfSense installation.</li>
<li>This step seems to only happen if the drive was not Master in the computer it was installed in. If it doesn&#8217;t boot the first time and you get a &#8220;mountroot>&#8221; prompt it is because the name of the drive was different in the machine you installed pfSense on. As the prompt will tell you, type &#8220;?&#8221; to see a list of the possible valid partitions. You want to replace the first part (drive name) with what you see in the currently installed and possible drive partitions. If you got the message &#8220;Trying to mount root from <strong>ufs:/dev/ad2s1a</strong>&#8221; but your valid drives all start with <strong>ad0</strong>, then type &#8220;<strong>ufs: ad0s1a</strong>&#8220;. Once the computer has booted you will need to take one more step to avoid this in future boots. You will need to edit the file <strong>/etc/fstab</strong> and change the drive reference (ad0 in the example) to be correct. You can edit this file through the web interface in pfSense or using <strong>vi </strong>or <strong>ee </strong>from the shell command prompt. Note: this tip was taken straight from the <a href="http://blog.pfsense.org/?p=509">official pfSense book</a> which I recommend buying if you are using pfSense frequently.</li>
<li>Next, to make sure it boots with ACPI disabled by default you will need to make another edit. <strong>/boot/device.hints</strong> is the file. Add a line at the bottom that says <strong>hint.acpi.0.disabled=&#8221;1&#8243;</strong>. Now when the system is booted, boot with ACPI disabled will be default.<br />
<br /><em>*Note that this has been reported to be unnecessary for others. I had no luck with ACPI enabled the first time I tried but that could have been related to something else. </em></li>
</ol>
<p>Currently I do not know of a way to get the LCD screen functioning. There is an LCDproc package for pfSense but the driver is unknown. Hopefully this will change soon. Thanks as well to <a href="http://gnuler.blogspot.com/">Gnuler</a> (page in spanish &#8211; <a href="http://translate.google.com/translate?js=y&#038;prev=_t&#038;hl=en&#038;ie=UTF-8&#038;u=http%3A%2F%2Fgnuler.blogspot.com%2F2008%2F08%2Freciclando-un-appliance.html&#038;sl=es&#038;tl=en&#038;history_state0=">link to english</a>) who seems to be the first record of someone trying out Linux on this box.<br />

<a href='http://blog.oliverhansen.com/index.php/2009/11/18/install-pfsense-on-symantec-5420-security-gateway/imag0007/' title='Opening Case'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2009/11/IMAG0007-150x150.jpg" class="attachment-thumbnail" alt="Opening Case" title="Opening Case" /></a>
<a href='http://blog.oliverhansen.com/index.php/2009/11/18/install-pfsense-on-symantec-5420-security-gateway/imag0010/' title='Remove Hard Drive'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2009/11/IMAG0010-150x150.jpg" class="attachment-thumbnail" alt="Remove Hard Drive" title="Remove Hard Drive" /></a>
<a href='http://blog.oliverhansen.com/index.php/2009/11/18/install-pfsense-on-symantec-5420-security-gateway/imag0011/' title='Remove Hard Drive Bracket'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2009/11/IMAG0011-150x150.jpg" class="attachment-thumbnail" alt="Remove Hard Drive Bracket" title="Remove Hard Drive Bracket" /></a>
<a href='http://blog.oliverhansen.com/index.php/2009/11/18/install-pfsense-on-symantec-5420-security-gateway/photo/' title='Kernel Choice'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2009/11/photo-150x150.jpg" class="attachment-thumbnail" alt="Kernel Choice" title="Kernel Choice" /></a>
</p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2007/10/01/what-device-is-my-serial-port-in-freebsd/" rel="bookmark" class="crp_title">What Device Is My Serial Port In FreeBSD?</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/08/05/recovering-my-freebsd-nas-server-from-a-hard-drive-failure/" rel="bookmark" class="crp_title">Recovering My FreeBSD <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Network Attached Storage' );"><acronym class="uttAcronym">NAS</acronym></span> Server From A Hard Drive Failure</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/09/27/updating-my-freebsd-installation-automatically/" rel="bookmark" class="crp_title">Updating My FreeBSD Installation &#8212; Automatically</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2009/11/18/install-pfsense-on-symantec-5420-security-gateway/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>How to Restore a Deleted Computer Account in Active Directory</title>

		<link>http://blog.oliverhansen.com/index.php/2009/08/09/how-to-restore-a-deleted-computer-account-in-active-directory/</link>

		<comments>http://blog.oliverhansen.com/index.php/2009/08/09/how-to-restore-a-deleted-computer-account-in-active-directory/#comments</comments>

		<pubDate>Mon, 10 Aug 2009 03:24:51 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[computer account]]></category>
		<category><![CDATA[restore]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=436</guid>


		<description><![CDATA[<p>I read this a while back and it is quite helpful to know beforehand. We had an instance of this at work a while ago where an OU of computers was accidentally deleted. You can recover the computer accounts easily enough but when they don&#8217;t recover with their machine password it still doesn&#8217;t help. This [...]]]></description>

	
		<content:encoded><![CDATA[<p>I read this a while back and it is quite helpful to know <strong>beforehand</strong>. We had an instance of this at work a while ago where an OU of computers was accidentally deleted. You can recover the computer accounts easily enough but when they don&#8217;t recover with their machine password it still doesn&#8217;t help. This walk-through shows you how to set it up so the machine password is saved when the account is tomb-stoned and then restoring is a breeze. If there is a next time, we&#8217;ll be ready! </p>
<p><a href="http://edmckinzie.spaces.live.com/blog/cns!687C72A5909E4230!232.entry">http://edmckinzie.spaces.live.com/blog/cns!687C72A5909E4230!232.entry</a></p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2009/03/26/apple-ad-login-error-the-home-folder-for-the-user-account-is-located-on-afp-or-smb-server/" rel="bookmark" class="crp_title">Apple &#8211; AD Login Error: The home folder for the user account is located on AFP or SMB server</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/06/29/get-rid-of-all-the-annoying-things-about-windows-live-messenger/" rel="bookmark" class="crp_title">Get Rid of All The Annoying Things About Windows Live Messenger</a></li><li><a href="http://blog.oliverhansen.com/index.php/2009/05/04/adobe-acrobat-crashes-on-os-x-with-network-account/" rel="bookmark" class="crp_title">Adobe Acrobat Crashes on OS X With Network Account</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2009/08/09/how-to-restore-a-deleted-computer-account-in-active-directory/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>Adobe Acrobat Crashes on OS X With Network Account</title>

		<link>http://blog.oliverhansen.com/index.php/2009/05/04/adobe-acrobat-crashes-on-os-x-with-network-account/</link>

		<comments>http://blog.oliverhansen.com/index.php/2009/05/04/adobe-acrobat-crashes-on-os-x-with-network-account/#comments</comments>

		<pubDate>Tue, 05 May 2009 05:30:41 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[acrobat]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[crash]]></category>
		<category><![CDATA[network]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=430</guid>


		<description><![CDATA[<p>I had another network account issue with our Apple at work. Got that one solved and then we finally got the software from Adobe for CS4 after a couple hours on the phone convincing them that they had already said we would get it before they changed their mind. Well, that&#8217;s a whole other story [...]]]></description>

	
		<content:encoded><![CDATA[<p>I had another network account issue with our <a href="http://blog.oliverhansen.com/index.php/2009/03/26/apple-ad-login-error-the-home-folder-for-the-user-account-is-located-on-afp-or-smb-server/">Apple at work</a>. Got that one solved and then we finally got the software from Adobe for CS4 after a couple hours on the phone convincing them that they had already said we would get it before they changed their mind. Well, that&#8217;s a whole other story I don&#8217;t have time for.</p>
<p>This problem lies in the fact that <a href="http://www.adobe.com/products/acrobat/">Acrobat</a> for some reason has a problem reading or writing to a file on a network share. Since the user&#8217;s home drive is connected to the network share, Acrobat will crash every time they try to open a file. Log in with a local user account and everything works great. After figuring out where the problem lay, I found a posting on the <a href="http://forums.adobe.com/message/1150921#1150921">Adobe Forums about this exact issue</a>.<br />
<span id="more-430"></span></p>
<p>What I found there was the following:</p>
<blockquote><p>
1. Log in as a Network User<br />
2. Go to /Users/Shared/<br />
3. If you are on an Intel based Mac create a folder in /Users/Shared/ named 9.0_x86 if you are on a Mac that is a G5/G4 create a folder named 9.0_ppc</p>
<p>At this point you should have created either<br />
/Users/Shared/9.0_x86/<br />
/Users/Shared/9.0_ppc/</p>
<p>4. Go to ~/Library/Application Support/Adobe/Acrobat/ and trash the 9.0_x86 or 9.0_ppc folder contained within<br />
5. Go to Applications/Utilities/ and open Terminal<br />
6. Enter one of the following into the Terminal<br />
If you are on an Intel based Mac enter<br />
ln -s /Users/Shared/9.0_x86 ~/Library/Application\ Support/Adobe/Acrobat/<strong>9.0_x86</strong><br />
If you are on a G5/G4 Mac enter<br />
ln -s /Users/Shared/9.0_ppc ~/Library/Application\ Support/Adobe/Acrobat<strong>/9.0_ppc</strong><br />
7. Open up Acrobat 9 and it should work!
</p></blockquote>
<p>*bold is my edit*</p>
<p>I found for the link command (ln) I had to actually specify the <strong>9.0</strong> folder. You are basically telling the computer to go to a local directory when it tries to find the user&#8217;s files in the home directory which is on the network. I also had to chmod the <strong>/Users/Shared/9.0_ppc</strong> to 777 because I created the folder with an admin user and the normal user didn&#8217;t have rights to make changes. After doing this, it all worked!</p>
<p>As of this posting, it appears the problem still exists and has not been fixed by Adobe even though it has been a known issue for 7 months now.</p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2009/03/26/apple-ad-login-error-the-home-folder-for-the-user-account-is-located-on-afp-or-smb-server/" rel="bookmark" class="crp_title">Apple &#8211; AD Login Error: The home folder for the user account is located on AFP or SMB server</a></li><li><a href="http://blog.oliverhansen.com/index.php/2009/01/27/using-ias-radius-for-client-vpn-authentication-to-cisco-pix/" rel="bookmark" class="crp_title">Using <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span> (<span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span>) For Client VPN Authentication To Cisco PIX</a></li><li><a href="http://blog.oliverhansen.com/index.php/2008/11/17/replace-first-domain-controller-in-forest/" rel="bookmark" class="crp_title">Replace First Domain Controller in Forest</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2009/05/04/adobe-acrobat-crashes-on-os-x-with-network-account/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>Apple &#8211; AD Login Error: The home folder for the user account is located on AFP or SMB server</title>

		<link>http://blog.oliverhansen.com/index.php/2009/03/26/apple-ad-login-error-the-home-folder-for-the-user-account-is-located-on-afp-or-smb-server/</link>

		<comments>http://blog.oliverhansen.com/index.php/2009/03/26/apple-ad-login-error-the-home-folder-for-the-user-account-is-located-on-afp-or-smb-server/#comments</comments>

		<pubDate>Fri, 27 Mar 2009 03:13:14 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Technology]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[home]]></category>
		<category><![CDATA[os x]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=426</guid>


		<description><![CDATA[<p>I&#8217;ve been trying to get our web and print design specialist at work set up with an Apple that was donated to us. It&#8217;s not a bad machine but one of the older ones running the Power PC hardware. It&#8217;s also running OS X version 10.4.11. Apples are completely new to me so it&#8217;s been [...]]]></description>

	
		<content:encoded><![CDATA[<p>I&#8217;ve been trying to get our web and print design specialist at work set up with an Apple that was donated to us. It&#8217;s not a bad machine but one of the older ones running the Power PC hardware. It&#8217;s also running OS X version 10.4.11. Apples are completely new to me so it&#8217;s been a challenge. I figured out how to get it to be part of our <span class="ubernym uttJustLink" onmouseover="domTT_activate(this, event, 'content', 'Microsoft Directory Service' );">Active Directory</span> domain a while ago so I thought all would be fine but there have been quite a few problems getting it to work smoothly.</p>
<p>One of the issues is logging on to the computer when home drives are assigned through the <span class="ubernym uttJustLink" onmouseover="domTT_activate(this, event, 'content', 'Microsoft Directory Service' );">Active Directory</span> profile. As a Domain Admin, when I would sign in I would get the message </p>
<blockquote><p>The home folder for the user account is located on an AFP or SMB server</p></blockquote>
<p>and it would not log me in. Upon trying again immediately, it would log me in and my home drive would be mapped just fine! I thought it was annoying but we could deal with it at first but when I had the user try to log in with an account that was not an admin they repeatedly got the error and were not able to log on at all.<br />
<span id="more-426"></span></p>
<p>A bit of searching led me to an <a href="http://discussions.apple.com/message.jspa?messageID=5141262#5141262">Apple Discussion Forum</a> where I saw that an edit of one file <em>/etc/hostconfig</em> would help. The change is</p>
<p> <code>AUTOMOUNT=-NO-</code> </p>
<p>changing from the YES that is currently in the file. I&#8217;m not clear on the exact cause of this but it is definitely a bug. Well, now it works so that part is down. More issues later.</p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2009/05/04/adobe-acrobat-crashes-on-os-x-with-network-account/" rel="bookmark" class="crp_title">Adobe Acrobat Crashes on OS X With Network Account</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/10/28/cron-is-different-in-freebsd-and-linux/" rel="bookmark" class="crp_title">Cron is Different in FreeBSD and Linux</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/03/01/my-network-attached-storage-part-2/" rel="bookmark" class="crp_title">My Network Attached Storage Solution &#8211; Part 2</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2009/03/26/apple-ad-login-error-the-home-folder-for-the-user-account-is-located-on-afp-or-smb-server/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>Routing and Remote Access Changes From Automatic to Disabled</title>

		<link>http://blog.oliverhansen.com/index.php/2009/03/22/routing-and-remote-access-changes-from-automatic-to-disabled/</link>

		<comments>http://blog.oliverhansen.com/index.php/2009/03/22/routing-and-remote-access-changes-from-automatic-to-disabled/#comments</comments>

		<pubDate>Mon, 23 Mar 2009 02:39:24 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[isa server 2006]]></category>
		<category><![CDATA[routing]]></category>
		<category><![CDATA[service]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[windows]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=427</guid>


		<description><![CDATA[<p>I&#8217;ve been working on setting up an ISA Server 2006 to be a VPN connection for employees. I had it working and then the next day it wouldn&#8217;t work. I looked and saw that the Routing and Remote Access service had been not only stopped but disabled. I would turn it back on and then [...]]]></description>

	
		<content:encoded><![CDATA[<p>I&#8217;ve been working on setting up an ISA Server 2006 to be a VPN connection for employees. I had it working and then the next day it wouldn&#8217;t work. I looked and saw that the Routing and Remote Access service had been not only stopped but disabled. I would turn it back on and then a few hours later it would be disabled. It was really frustrating me. We had used the server for another purpose previously and not reinstalled the OS so I even did that. No luck. The problem kept coming back.</p>
<p>The link below led me to think of Group Policy and I did an <em>rsop.msc</em> on the server to find it <strong>was</strong> the workstation policy affecting the server. Created a new OU outside the range of the policy which should have been done a long time ago anyways and the problem has been resolved. No more services getting disabled.</p>
<p>My Hint: <a href="http://www.tech-archive.net/Archive/Windows/microsoft.public.windows.server.general/2007-05/msg00216.html">http://www.tech-archive.net/Archive/Windows/microsoft.public.windows.server.general/2007-05/msg00216.html</a></p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2009/01/27/using-ias-radius-for-client-vpn-authentication-to-cisco-pix/" rel="bookmark" class="crp_title">Using <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span> (<span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span>) For Client VPN Authentication To Cisco PIX</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/01/21/took-290-and-passed/" rel="bookmark" class="crp_title">Took 290 and passed</a></li><li><a href="http://blog.oliverhansen.com/index.php/2009/03/02/add-new-exchange-2003-server-to-existing-organization/" rel="bookmark" class="crp_title">Add New Exchange 2003 Server To Existing Organization</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2009/03/22/routing-and-remote-access-changes-from-automatic-to-disabled/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>Add New Exchange 2003 Server To Existing Organization</title>

		<link>http://blog.oliverhansen.com/index.php/2009/03/02/add-new-exchange-2003-server-to-existing-organization/</link>

		<comments>http://blog.oliverhansen.com/index.php/2009/03/02/add-new-exchange-2003-server-to-existing-organization/#comments</comments>

		<pubDate>Tue, 03 Mar 2009 05:10:04 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Technology]]></category>
		<category><![CDATA[exchange 2003]]></category>
		<category><![CDATA[existing server]]></category>
		<category><![CDATA[microsoft exchange]]></category>
		<category><![CDATA[server]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=415</guid>


		<description><![CDATA[<p>These are the steps I followed to set up a new exchange server which will eventually replace the original exchange server.</p>
<p>Before installation, decide on the best partitioning strategy available with the given hardware. Raid 1 (Mirroring) should be the minimum for redundancy purposes.  Raid 5 is generally not the best because of the additional [...]]]></description>

	
		<content:encoded><![CDATA[<p>These are the steps I followed to set up a new exchange server which will eventually replace the original exchange server.</p>
<p>Before installation, decide on the best partitioning strategy available with the given hardware. <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'A collection of disk drives that employ two or more drives in combination for fault tolerance and performance. (&lt;a href=&quot;http://www.acnc.com/raid.html&quot;&gt;link&lt;/a&gt;)','caption', 'Redundant Array of Independant Disks' );"><acronym class="uttAcronym">Raid</acronym></span> 1 (Mirroring) should be the minimum for redundancy purposes.  <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'A collection of disk drives that employ two or more drives in combination for fault tolerance and performance. (&lt;a href=&quot;http://www.acnc.com/raid.html&quot;&gt;link&lt;/a&gt;)','caption', 'Redundant Array of Independant Disks' );"><acronym class="uttAcronym">Raid</acronym></span> 5 is generally not the best because of the additional work of calculating parity. Consider these options:<br />
<span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'A collection of disk drives that employ two or more drives in combination for fault tolerance and performance. (&lt;a href=&quot;http://www.acnc.com/raid.html&quot;&gt;link&lt;/a&gt;)','caption', 'Redundant Array of Independant Disks' );"><acronym class="uttAcronym">RAID</acronym></span> 1       =  System volume, operating system, Exchange Server binaries</p>
<p><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'A collection of disk drives that employ two or more drives in combination for fault tolerance and performance. (&lt;a href=&quot;http://www.acnc.com/raid.html&quot;&gt;link&lt;/a&gt;)','caption', 'Redundant Array of Independant Disks' );"><acronym class="uttAcronym">RAID</acronym></span> 1       =  Pagefile</p>
<p><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'A collection of disk drives that employ two or more drives in combination for fault tolerance and performance. (&lt;a href=&quot;http://www.acnc.com/raid.html&quot;&gt;link&lt;/a&gt;)','caption', 'Redundant Array of Independant Disks' );"><acronym class="uttAcronym">RAID</acronym></span> 0+1     =  SMTP and MTA queues</p>
<p><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'A collection of disk drives that employ two or more drives in combination for fault tolerance and performance. (&lt;a href=&quot;http://www.acnc.com/raid.html&quot;&gt;link&lt;/a&gt;)','caption', 'Redundant Array of Independant Disks' );"><acronym class="uttAcronym">RAID</acronym></span> 1       =  Log files from one Exchange Server storage group</p>
<p><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'A collection of disk drives that employ two or more drives in combination for fault tolerance and performance. (&lt;a href=&quot;http://www.acnc.com/raid.html&quot;&gt;link&lt;/a&gt;)','caption', 'Redundant Array of Independant Disks' );"><acronym class="uttAcronym">RAID</acronym></span> 0+1     =  Exchange Server databases from storage group<br />
<span id="more-415"></span></p>
<p>If drives are scarce, attempt to at least keep the Log files, DBs, and Pagefile on separate partitions.</p>
<p>Use DISKPART to create the partition that will hold the DB:<br />
<strong>CREATE PARTITION PRIMARY ALIGN=64</strong><br />
See <a href="http://technet.microsoft.com/en-us/library/aa995867(EXCHG.65).aspx">http://technet.microsoft.com/en-us/library/aa995867(EXCHG.65).aspx</a></p>
<p>Install the current sever OS, Service Packs, and updates used by the organization (i.e. Server 2003, SP2)</p>
<p>Set Paging file to the same size as the amount of RAM installed (i.e. 2046 for 2GB RAM)</p>
<p>Add the following to the <em>boot.ini</em> file: <strong>/3GB /USERVA=3030 /BASEVIDEO</strong><br />
See <a href="http://technet.microsoft.com/en-us/library/aa996130.aspx">http://technet.microsoft.com/en-us/library/aa996130.aspx</a> for 3GB and USERVA=3030<br />
See <a href="http://support.microsoft.com/?kbid=815372">http://support.microsoft.com/?kbid=815372</a> for BASEVIDEO</p>
<p>Change video driver to Standard VGA Graphics Adapter (uses less memory)</p>
<p>Under <em>Add/Remove Programs -> Windows Components -> Application Server -> IIS</em>: Add <strong>ASP.NET, NNTP, SMTP, and World Wide Web Services</strong>.</p>
<p>Use <strong>Exdeploy.exe</strong> to guide you through the installation of Exchange<br />
See <a href="http://www.microsoft.com/downloads/details.aspx?familyid=271e51fd-fe7d-42ad-b621-45f974ed34c0&#038;displaylang=en">http://www.microsoft.com/downloads/details.aspx?familyid=271e51fd-fe7d-42ad-b621-45f974ed34c0&#038;displaylang=en</a></p>
<p>You may need <strong>Windows Support Tools</strong> and <strong>Windows Resource Kit Tools</strong> to run some of the tests. <strong>Do not skip this step.</strong></p>
<p>Move the Exchange database and log files to their separate partitions. Note the information on folder permissions.<br />
<a href="http://support.microsoft.com/kb/821915">http://support.microsoft.com/kb/821915</a></p>
<p>When installing Antivirus, there are some folders, files and processes that need to be excluded.</p>
<ul>
<li>Use wildcard for the folder Exchsrvr as it exists in several places. <strong>*\exchsrvr\*</strong></li>
<li>Same for inetsrv. <strong>*\inetsrv\*</strong></li>
<li>All files of type <strong>.CHK</strong></li>
<li>Folder <strong>c:\Windows\IIS Temporary Compressed Files\</strong></li>
<li>Processes: <strong>Cdb.exe Cidaemon.exe Store.exe Emsmta.exe Mad.exe Mssearch.exe Inetinfo.exe W3wp.exe</strong></li>
</ul>
<p><a href="http://support.microsoft.com/kb/823166">http://support.microsoft.com/kb/823166</a></p>
<p>Install Microsoft Update (not Windows Update) to recieve updates for Exchange as well as Windows.</p>
<p>Install and run <em>Microsoft Exchange Server Jetstress</em> to test the performance of the system before putting it into production.<br />
If there are problems running Jetstress you may have to copy a few files to the Jetstress installation directory. First run &#8220;<strong>unlodctr ESE</strong>&#8221; from the command prompt. The program will tell you which files but <em>do not copy the from the CD</em>. Copy them from the currently installed exchange directory because it has the most updated files from the service packs. <strong>\Program Files\Exchsrvr\bin\</strong><br />
See <a href="http://support.microsoft.com/kb/555554">http://support.microsoft.com/kb/555554</a></p>
<p>Replicate Public Folders<br />
From <a href="http://support.microsoft.com/kb/822895">http://support.microsoft.com/kb/822895</a><br />
Find <strong>PFMigrate.wsf</strong> in <em>Support\ExDeploy</em><br />
Run <strong>Cscript pfMigrate.wsf /S:oldsrv /T:newsrv /A /SF /N:100 /F:c:\PF01.log </strong>where <em>oldsrv </em>is the old server with public folders, <em>newsrv</em> is the new server you want to replicate to, <em>100</em> is the number of folders you want to move (max), <em>c:\PF01.log</em> is where you want the log of the transaction to be placed.</p>
<p>Change the server that is responsible for creating the offline address list.<br />
From <a href="http://support.microsoft.com/kb/822931">http://support.microsoft.com/kb/822931</a><br />
Start <em>Exchange System Manager</em>, expand <em>Recipients</em>, and then click the <em>Offline Address Lists</em> container.<br />
In the right pane, right-click <em>Default Offline Address List</em>, and then click<em> Properties</em>.<br />
In the <em>Default Offline Address List</em> Properties dialog box, the server that is going to be removed from the administrative group will be in the Offline address list server list.<br />
Click Browse, and then type the name of the server that the replica of the <em>Offline Address Book</em> was added to in the &#8220;Rehome the Offline Address Book folder&#8221; section.<br />
Click OK.</p>
<p>Check that the performance and configurations have all been reviewed and applied if necessary &#8211; Exchange Performance Configurations</p>
<p>Run <strong>Exchange Best Practices Analyzer Tool</strong> (from any workstation) and check any of the configurations it recommends.</p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2008/11/17/replace-first-domain-controller-in-forest/" rel="bookmark" class="crp_title">Replace First Domain Controller in Forest</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/01/21/took-290-and-passed/" rel="bookmark" class="crp_title">Took 290 and passed</a></li><li><a href="http://blog.oliverhansen.com/index.php/2009/03/22/routing-and-remote-access-changes-from-automatic-to-disabled/" rel="bookmark" class="crp_title">Routing and Remote Access Changes From Automatic to Disabled</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2009/03/02/add-new-exchange-2003-server-to-existing-organization/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>Using IAS (RADIUS) For Client VPN Authentication To Cisco PIX</title>

		<link>http://blog.oliverhansen.com/index.php/2009/01/27/using-ias-radius-for-client-vpn-authentication-to-cisco-pix/</link>

		<comments>http://blog.oliverhansen.com/index.php/2009/01/27/using-ias-radius-for-client-vpn-authentication-to-cisco-pix/#comments</comments>

		<pubDate>Wed, 28 Jan 2009 02:32:32 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ias]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[radius]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=407</guid>


		<description><![CDATA[<p>I just had an opportunity to set this up again. The domain controller we had that was the RADIUS server crashed over the weekend so this is one of many things I had to get going again. Yes, our backup strategy needs some attention. So anyways, it did give me an opportunity to re-learn how [...]]]></description>

	
		<content:encoded><![CDATA[<p>I just had an opportunity to set this up again. The domain controller we had that was the <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> server crashed over the weekend so this is one of many things I had to get going again. Yes, our backup strategy needs some attention. So anyways, it did give me an opportunity to re-learn how to get this going. The purpose of using <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> for the VPN connections is to allow VPN access for the employees we want to have it and let them use their credentials already stored in <span class="ubernym uttJustLink" onmouseover="domTT_activate(this, event, 'content', 'Microsoft Directory Service' );">Active Directory</span>. The less user-names and passwords for employees to remember, the better.</p>
<p>The first thing is that the PIX Firewall (with VPN) was already set up when I got here so I won&#8217;t get into that configuration. It used to be configured with local accounts for each person who needed VPN and they had a static password. This was a bit cumbersome and insecure as the password never changed. I had used <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> to set up the same sort of thing for wireless authentication so I decided to see if I could get it working for the VPN. It took a little doing but I got it.<br />
<span id="more-407"></span></p>
<p>On Windows Server 2003, you need to install <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span> (Internet Authentication Service). Go to <em>Add/Remove Programs</em> (appwiz.cpl) and then select <em>Add/Remove Windows Components</em> on the left side. Select <strong>Networking Services</strong> then <strong>Details</strong>, then put a check next to <strong>Internet Authentication Service</strong>. Select <strong>OK</strong> and <strong>Next</strong> and it will be installed. You will find the program under <em>Administrative Tools</em> in the Start Menu.</p>
<p>Once you open <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span>, you will need to right click <em>Internet Authentication Service (Local)</em> and select <em>Register Server in <span class="ubernym uttJustLink" onmouseover="domTT_activate(this, event, 'content', 'Microsoft Directory Service' );">Active Directory</span></em>. This will add the computer to a security group in <span class="ubernym uttJustLink" onmouseover="domTT_activate(this, event, 'content', 'Microsoft Directory Service' );">Active Directory</span> and register the service. Next, right click on <em><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> Clients</em> and select <em>New <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">Radius</acronym></span> Client</em>. Here, you will put in the info about your PIX device. Now, even though there is an option in Client-Vendor for Cisco, we will leave it at the default value of <em><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> Standard</em>. Here, you also choose a shared secret. I strongly recommend using a very long string of numbers, letters and symbols. You will only need to enter this here and in the PIX one time and then you can forget about it so don&#8217;t worry about making it something easy to remember. One final important note on this step is to leave the box <strong>unchecked</strong> for <em>Message Authenticator attribute</em>.</p>
<p>Next go to the <em>Remote Access Policies</em> window. Right click and select <em>New Remote Access Policy</em>. Now, I&#8217;m going to suggest you do it a little differently than I did originally but it will save you making a few changes later. Instead of using the wizard, select <em>Set up a custom policy</em>. You can name it something like &#8220;Allow VPN Access&#8221;. Now, in policy conditions select <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Network Attached Storage' );"><acronym class="uttAcronym">NAS</acronym></span>-IP-Address and then enter the IP address of your PIX. The second attribute we&#8217;ll select is <em>Windows-Groups</em>. You will need to have created a group in <span class="ubernym uttJustLink" onmouseover="domTT_activate(this, event, 'content', 'Microsoft Directory Service' );">Active Directory</span> first before you can select it so create one called &#8220;VPN Access&#8221; or something similar. This is the security group you&#8217;ll place all users who you want to have access. If a user that does not have access tries to use it when they are not in the group it will fail. After you have added the group, click next and you will be finished. Note the order of the policies &#8212; the server will attempt to match each rule starting with the first and if it matches the default rule that denies connections first then it won&#8217;t even evaluate yours.</p>
<p>Now that you have your rule in place, open it up for more details. Click on the Advanced tab then Add. Here, you want to add <em>Ignore-User-Dialin-Properties</em> and set it to <strong>True</strong>. This tells <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span> to ignore the properties of each user in their profile which gives them dial-in privileges. I assume this was a previous way of configuring remote access that is not used much anymore. Having users in the security group you created earlier controls the permission of users connecting. Next, go to the Encryption tab and select every encryption but the <em>no encryption</em> box. Then on to Authentication and choose only Unencrypted authentication (PAP, SPAP). Now, this last one with no encryption &#8212; I tried very hard to see if there was another way because I don&#8217;t want any credentials floating around in plain text but I didn&#8217;t see a way. I&#8217;m no security expert but when I analyzed some traffic establishing the connection, it looks like the pre-shared key we set up before encrypts the authentication so it is in plain text but only inside of an already encrypted tunnel so it should be safe. Feel free to correct me because I&#8217;m still learning about VPNs. After that setting you should be done with the <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span> setup.</p>
<p>Now for the PIX. For this I used the PDM interface. I know the true Cisco experts will prefer the command line and I do for switches usually but for the VPN I&#8217;m sticking with the PDM interface for now. Once you are logged in, go to <em>Configuration</em>. Once there, select the <em>System Properties</em> tab and then navigate to the <em>AAA</em> category. Under <em>AAA Server Groups</em> you will see <strong><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> </strong>among others. The only thing I set was <strong>Dead Time</strong> to 0. If you have more than one <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> server you may want to set this to 10 minutes or so because it is the time it will consider a server dead if it can&#8217;t contact it and then it will use another server during this time period. On to <em>AAA Servers</em>. Click<em> Add</em> and select <em><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span></em> for the group, <em>inside</em> for the interface, the <em>IP address</em> and also your <em>key</em> that you created back in <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span>. Make sure you are <strong>applying</strong> these settings as you go. Next, we move to the <em>VPN</em> tab and select the <em>IKE</em> category. Find the <em>XAuth/Mode Config</em> and edit the <em>outside</em> interface. Here you&#8217;ll select <strong><span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span></strong> for <em>server group</em> and if you want you can check the box to use <strong>LOCAL</strong> accounts when the <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> fails. If for some reason your <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> server goes down, you could connect using a local account (such as administrator). This would mostly benefit the admins who know the password as other users wouldn&#8217;t know what to type. However, if you have a weak password I suppose it could be a security risk. After you have that set you can apply then save the changes to the PIX.</p>
<p>There is always troubleshooting of course. In the PIX, you can click the Monitoring icon and then view the PDM Log. This should show you when a <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Remote Authentication Dial In User Service' );"><acronym class="uttAcronym">RADIUS</acronym></span> lookup is attempted or if it is not then what is. In <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span> you&#8217;ll want to look under your normal event logs in the System setting. You will see <span class="ubernym uttAbbreviation" onmouseover="domTT_activate(this, event, 'content', 'Internet Authentication Service' );"><abbr class="uttAbbreviation">IAS</abbr></span> as Source and you can see what policy is matched. If your policy is not being matched then you need to find out why. It does give you good information such as the IPs, user-name, the authentication and encryption being used. If any of those do not match you may see it is being matched against another <em>Policy-Name</em> and that will give you some clues.</p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2008/11/17/replace-first-domain-controller-in-forest/" rel="bookmark" class="crp_title">Replace First Domain Controller in Forest</a></li><li><a href="http://blog.oliverhansen.com/index.php/2009/03/22/routing-and-remote-access-changes-from-automatic-to-disabled/" rel="bookmark" class="crp_title">Routing and Remote Access Changes From Automatic to Disabled</a></li><li><a href="http://blog.oliverhansen.com/index.php/2009/03/02/add-new-exchange-2003-server-to-existing-organization/" rel="bookmark" class="crp_title">Add New Exchange 2003 Server To Existing Organization</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2009/01/27/using-ias-radius-for-client-vpn-authentication-to-cisco-pix/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>Move Supreme Commander: Forged Alliance Menu To Left Side</title>

		<link>http://blog.oliverhansen.com/index.php/2009/01/24/move-supreme-commander-forged-alliance-menu-to-left-side/</link>

		<comments>http://blog.oliverhansen.com/index.php/2009/01/24/move-supreme-commander-forged-alliance-menu-to-left-side/#comments</comments>

		<pubDate>Sun, 25 Jan 2009 05:20:18 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Recreation]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[forged alliance]]></category>
		<category><![CDATA[menu]]></category>
		<category><![CDATA[rts]]></category>
		<category><![CDATA[supreme commander]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=405</guid>


		<description><![CDATA[<p>Finally!!!!! I found the method to move the in-game menu to the left and back to the bottom of the screen in Supreme Commander: Forged Alliance. I had done this accidentally and had no idea how it happened. I searched and searched online and didn&#8217;t find anything so I just had to make due for [...]]]></description>

	
		<content:encoded><![CDATA[<p>Finally!!!!! I found the method to move the in-game menu to the left and back to the bottom of the screen in Supreme Commander: Forged Alliance. I had done this accidentally and had no idea how it happened. I searched and searched online and didn&#8217;t find anything so I just had to make due for a few months til I finally decided to search again today. I found an obscure reference to it on <a href="http://www.fragland.net/reviews/Supreme-Commander-Forged-Alliance/1141/">this page talking about the game</a> in general. I couldn&#8217;t even find how to do this in the manual.</p>
<p><strong>How to do it:</strong> While in the game, press <em>Alt + Up Arrow</em> to switch the menu between the bottom of the screen (default) and left of the screen.</p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2007/12/15/getting-video-to-play-after-installing-compiz-fusion/" rel="bookmark" class="crp_title">Getting Video To Play After Installing Compiz Fusion</a></li><li><a href="http://blog.oliverhansen.com/index.php/2008/12/10/reply-on-top-of-message-in-thunderbird-20018-linux/" rel="bookmark" class="crp_title">Reply On Top Of Message In Thunderbird 2.0.0.18 Linux</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/08/05/recovering-my-freebsd-nas-server-from-a-hard-drive-failure/" rel="bookmark" class="crp_title">Recovering My FreeBSD <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Network Attached Storage' );"><acronym class="uttAcronym">NAS</acronym></span> Server From A Hard Drive Failure</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2009/01/24/move-supreme-commander-forged-alliance-menu-to-left-side/feed/</wfw:commentRss>


	
	</item>

	
	<item>

		<title>Moving and Organizing My Home Server Closet</title>

		<link>http://blog.oliverhansen.com/index.php/2008/12/20/moving-and-organizing-my-home-server-closet/</link>

		<comments>http://blog.oliverhansen.com/index.php/2008/12/20/moving-and-organizing-my-home-server-closet/#comments</comments>

		<pubDate>Sat, 20 Dec 2008 22:45:29 +0000</pubDate>

		<dc:creator>Oliver</dc:creator>

				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[closet]]></category>
		<category><![CDATA[desk]]></category>
		<category><![CDATA[home]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[organize]]></category>



		<guid isPermaLink="false">http://blog.oliverhansen.com/?p=344</guid>


		<description><![CDATA[<p>I actually did this back in August but I didn&#8217;t get around to uploading the photos til today so here it is!</p>
<p>Some wise person suggested that since I had a free room that I move my servers to the closet in that room instead of keeping them in my own closet. I&#8217;ve gotten used to [...]]]></description>

	
		<content:encoded><![CDATA[<p><strong>I actually did this back in August but I didn&#8217;t get around to uploading the photos til today so here it is!</strong></p>
<p>Some wise person suggested that since I had a free room that I move <a href="http://blog.oliverhansen.com/index.php/2007/03/27/my-network-attached-storage-solution-part-25-update/">my servers</a> to the closet in that room instead of keeping them in my own closet. I&#8217;ve gotten used to closing the door to the walk-in closet each night to lessen the noise of the fans but having them in another room would be even better! I decided if I was going to do this that I should do it a little better than last time. I now have three servers: One acting as my router and running <a href="http://www.ipcop.org/">IPCop</a>, a second running a <a href="http://www.lighttpd.net/">web server</a> for local development and testing, and a third running <a href="http://www.samba.org/">Samba</a> and acting as my main file server. It started as just one and grew to more.</p>
<p>Instead of taking up more floor space, I decided to stop by the local thrift store and find some sort of small desk. I found a pretty beat up rolling desk and paid $10 for it. One wheel fell off while I was rolling it out to the car but oh well. haha. Anyways, it fit in the closet and had two levels for my computers to sit on.</p>
<p>I had some zip ties and cable running hardware from when I planned to re-run my grandma&#8217;s phone line a while back so I used those to run the cable along the wall instead of the gaff tape I used previously. I couldn&#8217;t mount the switch on the wall but I did put it up above on the top shelf of the closet. I used zip ties as cable management to run the permanent cables up to the switch. As I get more or have temporary cables I won&#8217;t worry about the neatness so much but at least the existing cables are managed nicely. It&#8217;s not perfect by any standards but I think it&#8217;s a step up and not bad for an amateur with a couple hours. </p>
<p>Photos below:<br />
<span id="more-344"></span><br />

<a href='http://blog.oliverhansen.com/index.php/2008/12/20/moving-and-organizing-my-home-server-closet/p1040128/' title='Power To UPS'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2008/12/p1040128-150x150.jpg" class="attachment-thumbnail" alt="Power To UPS" title="Power To UPS" /></a>
<a href='http://blog.oliverhansen.com/index.php/2008/12/20/moving-and-organizing-my-home-server-closet/p1040129/' title='Poor Man&#039;s UPS (aka none)'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2008/12/p1040129-150x150.jpg" class="attachment-thumbnail" alt="Poor Man&#039;s UPS (aka none)" title="Poor Man&#039;s UPS (aka none)" /></a>
<a href='http://blog.oliverhansen.com/index.php/2008/12/20/moving-and-organizing-my-home-server-closet/p1040130/' title='Gigabit Switch and Fan'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2008/12/p1040130-150x150.jpg" class="attachment-thumbnail" alt="Gigabit Switch and Fan" title="Gigabit Switch and Fan" /></a>
<a href='http://blog.oliverhansen.com/index.php/2008/12/20/moving-and-organizing-my-home-server-closet/p1040131/' title='Power and Cable Modem'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2008/12/p1040131-150x150.jpg" class="attachment-thumbnail" alt="Power and Cable Modem" title="Power and Cable Modem" /></a>
<a href='http://blog.oliverhansen.com/index.php/2008/12/20/moving-and-organizing-my-home-server-closet/p1040132/' title='File Server and UPS'><img width="150" height="150" src="http://blog.oliverhansen.com/wp-content/uploads/2008/12/p1040132-150x150.jpg" class="attachment-thumbnail" alt="File Server and UPS" title="File Server and UPS" /></a>
</p>
<div id="crp_related"><h2>Possibly Related Posts:</h2><ul><li><a href="http://blog.oliverhansen.com/index.php/2007/09/27/updating-my-freebsd-installation-automatically/" rel="bookmark" class="crp_title">Updating My FreeBSD Installation &#8212; Automatically</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/08/05/recovering-my-freebsd-nas-server-from-a-hard-drive-failure/" rel="bookmark" class="crp_title">Recovering My FreeBSD <span class="ubernym uttAcronym" onmouseover="domTT_activate(this, event, 'content', 'Network Attached Storage' );"><acronym class="uttAcronym">NAS</acronym></span> Server From A Hard Drive Failure</a></li><li><a href="http://blog.oliverhansen.com/index.php/2007/03/27/my-network-attached-storage-solution-part-25-update/" rel="bookmark" class="crp_title">My Network Attached Storage Solution &#8211; Part 2.5 &#8211; Update</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div>]]></content:encoded>

	

		<wfw:commentRss>http://blog.oliverhansen.com/index.php/2008/12/20/moving-and-organizing-my-home-server-closet/feed/</wfw:commentRss>


	
	</item>

	
</channel>

</rss>
