<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Windows sbs 2008</title>
	<atom:link href="http://techstogo.ca/index.php/category/windows-sbs-2008/feed/" rel="self" type="application/rss+xml" />
	<link>http://techstogo.ca</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 12:24:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Configure Exchange to only accept mail from the hosted anti-spam service</title>
		<link>http://techstogo.ca/windows-sbs-2008/configure-exchange-to-only-accept-mail-from-the-hosted-anti-spam-service/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/configure-exchange-to-only-accept-mail-from-the-hosted-anti-spam-service/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 14:51:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=511</guid>
		<description><![CDATA[Configure Exchange to only accept mail from the hosted anti-spam service: Under Server Configuration, select Hub Transport, move to the Receive Connectors tab. Double click on Windows SBS Internet Receive YourServerName. Move to the Network tab. In the receive mail from servers with these IP addresses, add the IP address ranges of the hosted anti-spam [...]]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 3] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><p>Configure Exchange to only accept mail from the hosted anti-spam service: Under Server Configuration, select Hub Transport, move to the Receive Connectors tab. Double click on Windows SBS Internet Receive YourServerName. Move to the Network tab. In the receive mail from servers with these IP addresses, add the IP address ranges of the hosted anti-spam solution servers. </p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 4] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/configure-exchange-to-only-accept-mail-from-the-hosted-anti-spam-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Configure Smarthost for Outbound Filtering by hosted anti-spam</title>
		<link>http://techstogo.ca/windows-sbs-2008/configure-smarthost-for-outbound-filtering-by-hosted-anti-spam/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/configure-smarthost-for-outbound-filtering-by-hosted-anti-spam/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 14:50:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=509</guid>
		<description><![CDATA[Configure Smarthost for Outbound Filtering by hosted anti-spam: Under Organization Configuration, select Hub Transport, move to the Send Connectors tab. Double click the connector and move to the Network tab. Select the Route mail through the following smarthosts and enter the friendly name of the service. ex: outbound.exchangedefender.com]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 7] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><p>Configure Smarthost for Outbound Filtering by hosted anti-spam: Under Organization Configuration, select Hub Transport, move to the Send Connectors tab. Double click the connector and move to the Network tab. Select the Route mail through the following smarthosts and enter the friendly name of the service. ex: outbound.exchangedefender.com</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 8] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/configure-smarthost-for-outbound-filtering-by-hosted-anti-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disable Exchange 2007 Anti-Spam</title>
		<link>http://techstogo.ca/windows-sbs-2008/disable-exchange-2007-anti-spam/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/disable-exchange-2007-anti-spam/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 14:48:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=507</guid>
		<description><![CDATA[Disable Exchange Anti-Spam: Launch the Exchange Management Console. Expand Organization Configuration. Choose Hub Transport. Move to the Anti-Spam tab. Highlight each item except recipient filtering and choose Disable. Recipient filter is left enable to prevent reverse NDR attacks.]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 11] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><p>Disable Exchange Anti-Spam: Launch the Exchange Management Console. Expand Organization Configuration. Choose Hub Transport. Move to the Anti-Spam tab. Highlight each item except recipient filtering and choose Disable. Recipient filter is left enable to prevent reverse NDR attacks.</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 12] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/disable-exchange-2007-anti-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to configure Active Directory FTP User Isolation Mode (IIS 6.0) on SBS 2008</title>
		<link>http://techstogo.ca/windows-sbs-2008/how-to-configure-active-directory-ftp-user-isolation-mode-iis-6-0-on-sbs-2008/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/how-to-configure-active-directory-ftp-user-isolation-mode-iis-6-0-on-sbs-2008/#comments</comments>
		<pubDate>Thu, 23 Sep 2010 19:33:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=490</guid>
		<description><![CDATA[FTP is an older protocol which has been replaced with better methods of hosting files. FTP is also unsecure and your username/passwords are sent in clear text which poses a major security risk. For a list of better methods in lieu of FTP please consider using a secure SharePoint site, a secured website, or Secure [...]]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 16] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><h5><strong>FTP is an older protocol which has been replaced with better methods of hosting files. FTP is also unsecure and your username/passwords are sent in clear text which poses a major security risk. For a list of better methods in lieu of FTP please consider using a secure SharePoint site, a secured website, or Secure FTP to host and share files. However, if you have no choice but to use FTP and need to isolate Users continue reading.</strong></h5>
<p>IIS 6.0 introduced a new feature for companies hosting an FTP site on their server to isolate users so they are “locked” in to their home directory and cannot browse the root of the FTP server. There are two ways of accomplishing this goal with user isolation, one method is to isolate users by creating a folder structure which has their username and another method is using Active Directory attributes to isolate the user(s). Here are the steps for configuring AD Isolation mode.</p>
<p>1. Install the FTP Service from add/remove windows components.</p>
<p>2. Open IISManager</p>
<p>3. Delete the Default FTP Site as it does not get created in isolation mode by default</p>
<p>4. Create a New FTP Site by right clicking FTP Sites and going to new FTP Site</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image001%5B1%5D.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image001%5B1%5D_thumb.jpg" border="0" alt="clip_image001[1]" width="654" height="462" /></a></p>
<p>5. This will launch the FTP Site Creation Wizard, Click Next</p>
<p>6. Enter a Description for Your FTP Site</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image002%5B1%5D.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image002%5B1%5D_thumb.jpg" border="0" alt="clip_image002[1]" width="485" height="373" /></a></p>
<p>7. Set the IP address and Port to use for your FTP Site</p>
<p>*note if you have ISA 2000/2004 installed on this server do not select All Unassigned, select the internal IP address only.</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image003%5B1%5D.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image003%5B1%5D_thumb.jpg" border="0" alt="clip_image003[1]" width="479" height="372" /></a></p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 17] -->
<div class="ezAdsense adsense adsense-midtext" style="float:left;margin:12px; "></div><p>8. Next screen will be the FTP User Isolation options, Select Isolate users using Active Directory</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image004%5B1%5D.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image004%5B1%5D_thumb.jpg" border="0" alt="clip_image004[1]" width="481" height="372" /></a></p>
<p>9. Next you will need to select a User that has Access to Active Directory, any domain admin account will suffice. Click Next and re-enter password to Confirm</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image005%5B1%5D.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image005%5B1%5D_thumb.jpg" border="0" alt="clip_image005[1]" width="482" height="373" /></a></p>
<p>10. Select the required Permissions and click Next and then Click Finish</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image006_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image006_thumb.jpg" border="0" alt="clip_image006" width="473" height="368" /></a></p>
<p>11. The IIS portion is now finished and now on to AD.</p>
<p>12. There are 2 schema attributes in AD that reside in the User Class that will allow us to define the users home directory for FTP. They are msIIS-FTPRoot which defines the root of the FTP server and msIIS-FTPDir which defines the users Home Directory. The problem here is that there is no GUI interface to define these attributes so for the purpose of this demonstration I will use ADSIEDIT from Support tools to modify these attributes, however you can also run the below script to do it as well.</p>
<p><strong>Iisftp.vbs /SetADProp </strong><em>UserName</em><strong> FTPRoot </strong><em>Server</em><strong>\</strong><em>Share</em></p>
<p><strong>Iisftp.vbs /SetADProp </strong><em>UserName</em><strong> FTPDir </strong><em>Directory</em></p>
<p>13. Load Up Adsiedit and drill down to the user account you want to isolate and go to the properties of that account and modify the 2 attributes mentioned above</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image007_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ActiveDirectoryFTPUserIsolationModeIIS.0_109AD/clip_image007_thumb.jpg" border="0" alt="clip_image007" width="399" height="450" /></a></p>
<p>14. Now whenever that user connects to your FTP server the user will be isolated to the Home Directory that was defined in Active Directory.</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 18] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/how-to-configure-active-directory-ftp-user-isolation-mode-iis-6-0-on-sbs-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Common Remote Web Workplace (RWW) Connect to a Computer Issues in SBS 2008</title>
		<link>http://techstogo.ca/windows-sbs-2008/common-remote-web-workplace-rww-connect-to-a-computer-issues-in-sbs-2008/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/common-remote-web-workplace-rww-connect-to-a-computer-issues-in-sbs-2008/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 23:31:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=487</guid>
		<description><![CDATA[The connect to a computer feature in SBS 2008 is one of the most popular features of RWW. The connect to a computer feature in SBS 2008 utilizes TS-Gateway behind the scenes, however, when there is a misconfiguration or a problem, RWW may only provide partial information to help isolate the root issue. This post [...]]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 22] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><p>The connect to a computer feature in SBS 2008 is one of the most popular features of RWW. The connect to a computer feature in SBS 2008 utilizes TS-Gateway behind the scenes, however, when there is a misconfiguration or a problem, RWW may only provide partial information to help isolate the root issue. This post will discuss most of the known issues, how to identify them and steps to resolve them.</p>
<p>What we will cover:</p>
<ol>
<li>Receiving Certificate Errors When Connecting to Clients/Servers with TS Gateway or Remote Web Workplace on SBS 2008</li>
<li>VBScript Error: 50331676</li>
<li>Connection Authorization Policies and Resource Authorization Policies.</li>
<li>Authentication Failures</li>
<li>Client Machine Requirements</li>
<li>Internal DNS Considerations</li>
<li>External DNS Considerations</li>
<li>TS Gateway Service Known Issues</li>
</ol>
<h4>1.  Receiving Certificate Errors When Connecting to Clients/Servers with TS Gateway or Remote Web Workplace on SBS 2008</h4>
<p>For certificate related errors, please review the issues discussed in this article: <a href="http://blogs.technet.com/sbs/archive/2008/10/03/receiving-certificate-errors-when-connecting-to-clients-servers-with-ts-gateway-or-remote-web-workplace-on-sbs-2008.aspx">http://blogs.technet.com/sbs/archive/2008/10/03/receiving-certificate-errors-when-connecting-to-clients-servers-with-ts-gateway-or-remote-web-workplace-on-sbs-2008.aspx</a></p>
<h4><strong>2.  VBScript Error: 50331676</strong></h4>
<p>When you try to connect to a server or machine you get the following error:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image002_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image002_thumb.jpg" border="0" alt="clip_image002" width="464" height="163" /></a></p>
<p>You must have a certificate installed in TS Gateway Manager. This is handled by the “<a href="http://blogs.technet.com/sbs/archive/2008/10/15/introducing-the-internet-address-management-wizard-part-1-of-3.aspx">Set up your Internet Address Wizard</a>” or the “<a href="http://blogs.technet.com/sbs/archive/2008/09/20/introducing-the-add-a-trusted-certificate-wizard-in-sbs-2008.aspx">Add a Trusted Certificate Wizard</a>” in the SBS 2008 Console. To verify you have a certificate installed for TS Gateway do the following:</p>
<ol>
<li>Open TS Gateway Manager from Administrative Tools &#8212; Terminal Services</li>
<li>Select <strong>Properties</strong> on the Server Object, and choose the <strong>SSL Certificate</strong> tab from within properties. You should see a screen similar to the one below stating which certificate TS Gateway is using.
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image003_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image003_thumb.jpg" border="0" alt="clip_image003" width="504" height="570" /></a></li>
</ol>
<p>As stated beofre, you should not see this problem If you have completed the Internet Address Management Wizard, if for any reason no certificate is selected, make sure you click on Browse Certificates and select the proper certificate, for example “remote.contoso.com”.</p>
<h4>3.  Connection Authorization Policies and Resource Authorization Policies.</h4>
<p>You must pass the connection authorization policy to make a connection, and the resource authorization policy for the machine you are trying to connect to. This error may also display the VBSCRIPT error 50331676.</p>
<p>We have seen a few cases where the connection authorization policy was modified manually to<strong> only</strong> allow domain computers to make connections. This means that any machine outside the domain (e.g. their home machine) would not be able to connect. This is shown below. To access this policy:</p>
<ol>
<li>Open TS Gateway Manager from Administrative Tools – Terminal Services</li>
<li>Expand your computer object</li>
<li>Expand <strong>Policies</strong></li>
<li>Select <strong>Connection Authorization Policies</strong></li>
<li>Right-Click on the <strong>General Connection Authorization</strong> policy on the right hand side and choose <strong>properties</strong></li>
<li>Make sure the <strong>Client computer group membership</strong> is blank if you want non-domain joined machines to be able to use the RWW Connect To Computer feature.</li>
</ol>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image004_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image004_thumb.jpg" border="0" alt="clip_image004" width="463" height="566" /></a></p>
<h4>4.  Authentication Failures</h4>
<p>You must have Windows Authentication enabled on the IIS /RPC virtual directory under the SBS Web Applications web site. If it is missing, you will see a looping prompt for authentication when you try to connect.</p>
<p>Since both Outlook Anywhere and TS Gateway share this Virtual Directory modifying authentication settings in Exchange for Outlook-Anywhere within the Exchange Management Console can disable Windows Auth. To make sure Windows-Auth is enabled in Exchange Management Shell (Run as admin) perform the following command:</p>
<blockquote><p><strong>Get-OutlookAnywhere</strong></p>
<p>(Ignore the warning)</p></blockquote>
<p>Check the value for the <strong>IISAuthenticationMethods</strong> Parameter.</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 23] -->
<div class="ezAdsense adsense adsense-midtext" style="float:left;margin:12px; "></div><p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image006_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image006_thumb.jpg" border="0" alt="clip_image006" width="628" height="385" /></a></p>
<p>You can also check in IIS Manager under the RPC virtual directory, authentication.</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image008_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/CommonRemoteWebWorkplaceRWWConnecttoaCom_E081/clip_image008_thumb.jpg" border="0" alt="clip_image008" width="628" height="332" /></a></p>
<p>Changing the authentication here may only help for a few minutes as Exchange will reset the settings again. You need to complete the proper Exchange configuration steps to resolve this.</p>
<p>If the output of the Exchange Management Shell shows that you are missing NTLM, you need to reset the Exchange setting for outlook anywhere from the Exchange Management Shell (run as admin) perform the following command (ignore the warning):</p>
<blockquote><p><strong>Get-OutlookAnywhere | Set-OutlookAnywhere –IISAuthenticationMethods: Basic, ntlm</strong></p></blockquote>
<p>After you make this change, the settings in IIS will not immediately change, it might take up to 15 minutes for this change to happen. You can safely make the change in IIS, under the authentication for RPC to enable Windows Authentication and Basic Authentication and they should remain set as expected.</p>
<p>If you still cannot authenticate to the TS gateway prompt, the following resources discuss some known issues:</p>
<ul>
<li><a href="http://blogs.technet.com/sbs/archive/2009/02/20/the-network-policy-server-service-ias-fails-to-start-or-be-installed.aspx">http://blogs.technet.com/sbs/archive/2009/02/20/the-network-policy-server-service-ias-fails-to-start-or-be-installed.aspx</a></li>
<li><a href="http://blogs.technet.com/sbs/archive/2009/05/18/bits-ias-vss-and-rras-may-stop-responding-on-sbs-2008-with-a-particular-nic-driver.aspx">http://blogs.technet.com/sbs/archive/2009/05/18/bits-ias-vss-and-rras-may-stop-responding-on-sbs-2008-with-a-particular-nic-driver.aspx</a></li>
</ul>
<h4>5.  Client Machine Requirements</h4>
<p>The client machine you are trying to connect to must have RDP enabled and listening on the default port of 3389. You must also verify that any firewalls present on the workstation are allowing the traffic inbound on TCP/3389.  Additionally, the client machine you are making the connection from must allow the ActiveX Control to run.  The easiest way to ensure that ActiveX will be enabled is by adding your remote web workplace site to your list of trusted sites in Internet Explorer.</p>
<h4>6.  Internal DNS Considerations</h4>
<p>You might connect to an unexpected machine when trying to connect to the remote machine.  If this happens you should verify that the DNS records for the clients on the SBS 2008 server hosting RWW are correct.  To do this open the DNS Management console from Start, Administrative Tools, DNS.  Expand the forward lookup zones, and your local active directory zone.  Verify that the host (A) records for the clients are correct.</p>
<h4>7.  External DNS Considerations</h4>
<p>The hostname section of the PTR record for the remote client machine’s public IP address cannot match the NetBIOS hostname of the SBS 2008 server. If these names match the RWW will not use TS proxy and the connection will fail or connect to an unexpected target.</p>
<p>The only fix is the change the PTR record for the client pc&#8217;s external IP address.</p>
<p><strong>Example:</strong> Suppose you are using a Windows Vista machine on the Internet. The public IP for this client is 65.53.x.x. The PTR record for this IP is <strong>server01.</strong>contoso.com. If the SBS 2008 server this machine is trying to connect to has a NetBIOS hostname of <strong>Server01</strong>, the connection will fail. Ideally your PTR record should match your MX record and your MX record should not be the NetBIOS hostname of your server.</p>
<p><strong>Note:</strong> This is a very RARE issue.</p>
<h4>8.  TS Gateway Service known issues</h4>
<p>TS Gateway Service Not Started After Restart in IIS Manager.</p>
<p>This issue is discussed on this post: <a href="http://blogs.technet.com/sbs/archive/2009/04/20/ts-gateway-service-not-started-after-restart-in-iis-manager.aspx">http://blogs.technet.com/sbs/archive/2009/04/20/ts-gateway-service-not-started-after-restart-in-iis-manager.aspx</a></p>
<p>The Terminal Services Gateway service is not running, Contact your network administrator to resolve this issue.This error can happen due to a number of different issues other than the TS Gateway service not running or the role service not being installed.</p>
<ul>
<li>If IPv6 has been unproperly unbound from the network interface you might get an error that states that the TS Gateway service is not installed.  Check the following link for issues related to improperly disabling IPv6: <a href="http://blogs.technet.com/sbs/archive/2008/10/24/issues-after-disabling-ipv6-on-your-nic-on-sbs-2008.aspx">http://blogs.technet.com/sbs/archive/2008/10/24/issues-after-disabling-ipv6-on-your-nic-on-sbs-2008.aspx</a></li>
<li>If Client certificates has been set to Accept or Require under the SSL setttings on the Rpc virtual directory. This must be set to Ignore.</li>
<li>In general, this error will happen when we cannot properly access the /RPC virtual directory or its settings have been changed from default.</li>
</ul>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 24] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/common-remote-web-workplace-rww-connect-to-a-computer-issues-in-sbs-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Receiving Certificate Errors When Connecting to Clients/Servers with TS Gateway or Remote Web Workplace on SBS 2008</title>
		<link>http://techstogo.ca/windows-sbs-2008/receiving-certificate-errors-when-connecting-to-clientsservers-with-ts-gateway-or-remote-web-workplace-on-sbs-2008/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/receiving-certificate-errors-when-connecting-to-clientsservers-with-ts-gateway-or-remote-web-workplace-on-sbs-2008/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 23:29:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=485</guid>
		<description><![CDATA[Remote Desktop Disconnected You may receive the following errors when attempting to access a client machine through the Remote Web Workplace (RWW) or the TS Gateway: [To connect to Remote Web Workplace, you must install the proper certificate. Contact the person who provides technical support for your network.] Likewise, connections to TS Gateway will fail [...]]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 28] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><h4>Remote Desktop Disconnected</h4>
<p>You may receive the following errors when attempting to access a client machine through the Remote Web Workplace (RWW) or the TS Gateway:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image001_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image001_thumb.jpg" border="0" alt="clip_image001" width="490" height="176" /></a></p>
<p><em>[To connect to Remote Web Workplace, you must install the proper certificate. Contact the person who provides technical support for your network.]</em></p>
<p>Likewise, connections to TS Gateway will fail as well. You will receive the following error:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image003_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image003_thumb.jpg" border="0" alt="clip_image003" width="628" height="128" /></a></p>
<p><em>[This computer can't connect to the remote computer because the certificate authority that generated the Terminal Services Gateway server's certificate is not valid.  Contact your network administrator for assistance.]</em></p>
<p>To determine whether you trust the certificate or not, browse to RWW from Internet Explorer. If it’s not trusted, you will receive the following error in IE:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image005_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image005_thumb.jpg" border="0" alt="clip_image005" width="628" height="320" /></a></p>
<p>Also, check for the certificate status to the right of the URL field:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image006_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image006_thumb.jpg" border="0" alt="clip_image006" width="288" height="328" /></a></p>
<h4>Certificate Creation</h4>
<p>When you complete the Internet Address Management Wizard for the first time, a certificate installation package is created for distribution to non domain-joined client machines and mobile devices. Details regarding this package can be found here:</p>
<p><a href="http://blogs.technet.com/sbs/archive/2008/09/30/how-do-i-distribute-the-sbs-2008-self-signed-ssl-certificate-to-my-users.aspx">http://blogs.technet.com/sbs/archive/2008/09/30/how-do-i-distribute-the-sbs-2008-self-signed-ssl-certificate-to-my-users.aspx</a></p>
<p><strong>NOTE: This package is not for installation on the SBS 2008 server</strong></p>
<p>Connections to TS Gateway or Terminal Services through RWW will fail if either the certificate is not trusted, or the name on the certificate does not match the name of the server that you are connecting to.</p>
<h4>Certificate Not Trusted</h4>
<p>If you are receiving these errors, you need to install the root CA certificate from the SBS server by using the certificate installation package as described in:</p>
<p><a href="http://blogs.technet.com/sbs/archive/2008/09/30/how-do-i-distribute-the-sbs-2008-self-signed-ssl-certificate-to-my-users.aspx">http://blogs.technet.com/sbs/archive/2008/09/30/how-do-i-distribute-the-sbs-2008-self-signed-ssl-certificate-to-my-users.aspx</a></p>
<p>Once the certificate is installed, you can view it in IE by going to <strong>Tools &gt; Internet Options &gt; Content &gt; Certificates. </strong>You will also stop receiving certificate errors once to connect to RWW.</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 29] -->
<div class="ezAdsense adsense adsense-midtext" style="float:left;margin:12px; "></div><p><strong><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image008_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image008_thumb.jpg" border="0" alt="clip_image008" width="523" height="483" /></a></strong></p>
<h4>Certificate Name Does Not Match</h4>
<p>Connections will also fail if you connect to TS Gateway or RWW using a different address than that on the certificate. In this case, you will receive the following error when you connect.</p>
<p>For <strong>RWW</strong>, you will receive these errors in IE:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image010_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image010_thumb.jpg" border="0" alt="clip_image010" width="628" height="276" /></a></p>
<p>If you check the certificate status to the right of the URL field, you’ll see this:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image012_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image012_thumb.jpg" border="0" alt="clip_image012" width="288" height="316" /></a></p>
<p>For <strong>TS Gateway</strong>, you will receive the following:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image014_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image014_thumb.jpg" border="0" alt="clip_image014" width="628" height="129" /></a></p>
<p>In either case, click on <strong>View certificates</strong> to show the <strong>Issued to </strong>name on the certificate. This is the name that you need to put into IE or the RDP client:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/00c4000.tmp_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/00c4000.tmp_thumb.jpg" border="0" alt="00c4000.tmp" width="423" height="524" /></a></p>
<p>In the case of the above certificate, I would type <a href="https://remote.contoso.com/remote">https://remote.contoso.com/remote</a> to connect to RWW. For TS Gateway, I would connect in the following manner:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image018_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/clip_image018_thumb.jpg" border="0" alt="clip_image018" width="472" height="317" /></a></p>
<h4>Certificate Has Expired</h4>
<p>This issue can also occur if the SSL certificate has expired.  SBS 2008 self-signed leaf certificates are valid for 2 years and the root cert is valid for 5.  If your self-signed certificate has expired run the &#8220;Fix My Network&#8221; wizard from the Connectivity tab.  This wizard will automatically issue a new matching cert.  If you are using a trusted (purchased) certificate you will need to contact the cert issuer for a new cert and import it using the &#8220;Add a trusted certificate&#8221; wizard.</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/hdcFB23.tmp_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/ReceivingCertificateErrorsWhenConnecting_DC81/hdcFB23.tmp_thumb.jpg" border="0" alt="hdcFB23.tmp" width="425" height="526" /></a></p>
<h4>Wrong Version of Remote Desktop Connection</h4>
<p>RWW and TS Gateway require that the connecting client have Remote Desktop Connection 6.1 or greater installed.   RDP 6.1 is included with XP SP 3, Windows 2008, and Vista SP 1. RDP 6.1 is available as a separate <a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;952155">download</a> for XP SP 2 (requires a reboot).</p>
<p><a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;952155"></a></p>
<p>You can tell the version of the RDP client by looking at the version of C:\windows\system32\mstsc.exe</p>
<ul>
<li>6.0.6001.18000 is RDP 6.1</li>
<li>6.0.6000.16386 is RDP 6.0</li>
</ul>
<p><strong>NOTE:</strong> After installing SP3 for XP you may see the following error <em>&#8220;Remote Desktop Web Connection ActiveX control is not installed. A connection cannot be made without a working installed version of the control.&#8221;</em>  If you receive this error please review <a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;951607">KB951607</a> for information on enabling the IE-add on to support RWW.</p>
<h4>In Summary:</h4>
<ol>
<li>For TS Gateway or RWW to function properly, you cannot receive any certificate errors when you connect.</li>
<li>Your client machine must trust the Root CA certificate.  Install the certificate installation package on the client accomplish this. (This package is created by running the Internet Address Management Wizard.)</li>
<li>You must connect to TS Gateway or RWW using the address listed on the <strong>Issued to</strong> field on the certificate.</li>
<li>The certificate must NOT be expired.</li>
<li>You must be running <strong>Remote Desktop Connection 6.1</strong> on the client making the connection.  (<a title="http://support.microsoft.com/kb/951616" href="http://support.microsoft.com/kb/951616">http://support.microsoft.com/kb/951616</a>)</li>
</ol>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 30] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/receiving-certificate-errors-when-connecting-to-clientsservers-with-ts-gateway-or-remote-web-workplace-on-sbs-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SBS 2008: Introduction to Remote Web Workplace</title>
		<link>http://techstogo.ca/windows-sbs-2008/sbs-2008-introduction-to-remote-web-workplace/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/sbs-2008-introduction-to-remote-web-workplace/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 23:24:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=483</guid>
		<description><![CDATA[Just as it was in SBS 2003, Remote Web Workplace (RWW) is an integral component in the SBS feature set for 2008. Its purpose is to provide a secure centralized web portal for employees and administrators to access network resources. Users can perform the following actions when logged in: Check their E-mail. Access the Internal [...]]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 34] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><p>Just as it was in SBS 2003, Remote Web Workplace (RWW) is an integral component in the SBS feature set for 2008. Its purpose is to provide a secure centralized web portal for employees and administrators to access network resources. Users can perform the following actions when logged in:</p>
<ol>
<li>Check their E-mail.</li>
<li>Access the Internal Web Site (CompanyWeb).</li>
<li>Connect to a computer through RDP (only network admins can connect to the SBS server)</li>
<li>Change their domain password</li>
<li>Access help and configuration information for RWW</li>
<li>Access customized corporate links (more information available at: <a href="http://technet.microsoft.com/en-us/library/cc527586.aspx">http://technet.microsoft.com/en-us/library/cc527586.aspx</a>)</li>
</ol>
<p>RWW is installed on the server during SBS Setup, but is not fully configured for Internet access until you complete the “Internet Address Management Wizard” (IAMW). <strong>Note:</strong> If you are using a 3<sup>rd</sup> party SSL certificate, you must complete the “Add A Trusted Certificate Wizard” also. It is installed as the <em>remote</em> virtual directory under the SBS Web Applications site, which accepts SSL connections on port 443. By default, the IAMW will add the prefix “remote” to your chosen domain name to distinguish the SBS 2008 in your web presence as the remote user portal. In this case, if you chose <em>contoso.com</em> as your domain name, you would access RWW using <em>“https://remote.contoso.com”.</em></p>
<p>For full access to the RWW feature set from the Internet, you must ensure the following:</p>
<ol>
<li>TCP 443 and TCP 987 (For SharePoint) are open on your Internet firewall.</li>
<li>Clients are running Internet Explorer 6.0 SP2 or higher</li>
<li>The RDP 6.1 client or higher is installed on the client machine</li>
<li>The client must trust the SSL certificate that is installed on the SBS Web Applications site</li>
<li>The client must connect using the URL that matches the common name on the certificate.</li>
</ol>
<h4>Features</h4>
<p>From a centralized location, users can launch OWA, connect to an authorized computer, launch CompanyWeb, change their password, and access the built-in corporate links (help for RWW and Outlook Anywhere) or customized links (these links are shared with the Vista Desktop Gadget).</p>
<p><em><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image002_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image002_thumb.jpg" border="0" alt="clip_image002" width="628" height="222" /></a></em></p>
<p>Administrators and users are presented with the same features upon login to the homepage, with the following exceptions:</p>
<ol>
<li>Users are not offered the “Connect to Server” option. Only network administrators can connect to the SBS server.</li>
<li>Users are not presented with the “Administration” links</li>
</ol>
<h4>SBS Console Integration</h4>
<p>From the SBS 2008 console, you can perform a variety of management tasks for the website itself. You can access this under “Shared Folders and Web Sites”. The various tasks you can perform include:</p>
<ol>
<li>Enabling or disabling the website</li>
<li>Browse the website (opens in IE using https)</li>
<li>Add or remove users permissions to login to RWW</li>
<li>Enable or disable RWW homepage links (OWA, Connect to Computer, Internal Website, Change Password, Connect to Server, Help, and Remote Web Workplace Link List)</li>
<li>Manage Organizational and Administrative links that are displayed upon user login. Here you can enable/disable them, change permissions (who can see them), remove them or add new ones, or change their titles</li>
</ol>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image004_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image004_thumb.jpg" border="0" alt="clip_image004" width="628" height="205" /></a></p>
<h4>Login Requirements</h4>
<p>As it did in SBS 2003, RWW uses forms based authentication, which stores the encrypted credentials from the user’s initial login as a cookie in the web browser. This cookie is used to authenticate further connections to restricted resources inside RWW, such as OWA and CompanyWeb. Only members of the Windows SBS Remote Web Workplace Users security group are allowed to login to RWW. To modify membership for this group, use the SBS 2008 Console:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image006_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image006_thumb.jpg" border="0" alt="clip_image006" width="469" height="607" /></a></p>
<p>User Account Properties for RWW Login Rights</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image008_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image008_thumb.jpg" border="0" alt="clip_image008" width="505" height="528" /></a></p>
<h4>Launching OWA and CompanyWeb</h4>
<p>When OWA and CompanyWeb are launched in RWW, your browser is connected to either <strong>https://<em>remote.domain.com</em>/owa</strong> or <strong>https://<em>remote.domain.com</em>:987</strong> respectively; where <em>remote.domain.com</em> is the domain name that you have configured in the IAMW<em>.</em> By default, they open in their own restricted Window with no address or navigation bar, preventing you from navigating to a different site in the same window. You can override this (only in IE 7) on the client machine by opening <strong>Tools &gt; Internet Options &gt; General &gt; Tabs &gt; Settings </strong>and allowing pop-ups to be opened in a new tab:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image010_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image010_thumb.jpg" border="0" alt="clip_image010" width="367" height="100" /></a></p>
<h4>Connect to a computer</h4>
<p>When a user clicks “Connect to a computer”, they are presented with a list of computers in which they are authorized to connect to and set as their default. Once they choose a default computer, they will no longer be presented with a list and will connect automatically to their chosen machine. <strong>Note: If the user is authorized to only a single machine, a list is not shown and instead will be directly connected to their authorized machine. </strong>This is meant to give the Administrator greater control over what machines their users can connect to. This information is defined both on the user account and computer account properties from the SBS 2008 console:</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 35] -->
<div class="ezAdsense adsense adsense-midtext" style="float:left;margin:12px; "></div><p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image012_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image012_thumb.jpg" border="0" alt="clip_image012" width="502" height="552" /></a></p>
<p>Computer account properties:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image014_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image014_thumb.jpg" border="0" alt="clip_image014" width="502" height="553" /></a></p>
<p>Once “Can log on remotely to this computer” is checked, the next group policy refresh will add the user account to the “Remote Desktop Users” local group on the machine. <strong>Note: Administrators automatically have the right to remotely connect to any machine in the domain.</strong></p>
<p>If you have installed Terminal servers in your domain, you can run into a problem where they will not show up in the list of computers to connect to for standard users. To override this behavior to display all computers in the domain, perform the following:</p>
<ol>
<li>To open the Registry Editor, click Start, click Run, type regedit in the text box, and then press ENTER.</li>
<li>Browse to HKEY_LOCAL_MACHINE\Software\Microsoft\SmallBusinessServer.</li>
<li>Right-click SmallBusinessServer, click New, and then click Key.</li>
<li>Name the key BusinessProductivity.</li>
<li>Right-click BusinessProductivity, click New, and then click DWORD (32-bit) Value.</li>
<li>Name the new value ShowAllComputers.</li>
<li>Right-click ShowAllComputers, type 1 in the Value data text box, and then click OK.</li>
</ol>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image016_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image016_thumb.jpg" border="0" alt="clip_image016" width="628" height="264" /></a></p>
<h4>TSGateway Integration</h4>
<p>RWW in SBS 2008 leverages the TSGateway service that is running on the SBS server to perform the remote desktop connection to the chosen machine. Like RWW, TSGateway is fully enabled when the IAMW is completed (“Add a Trusted Certificate” must also be completed if you are using a 3<sup>rd</sup> party SSL certificate). This allows remote desktop connections to your domain-joined machines through port 443. This is different from RWW in SBS 2003, where you had to open port 4125 through your firewall.</p>
<p>The following screenshot shows what an RDP connection to TSGateway looks like. We can see that the “Gateway server” field is populated with the URL of the server, which is resolvable both externally and internally in DNS. The “Remote computer” field is populated with the internal machine name of the computer that we are connecting to:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image018_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image018_thumb.jpg" border="0" alt="clip_image018" width="461" height="400" /></a></p>
<p>You can, in fact, configure the RDP 6.1 client or higher to connect directly through TSGateway without having to first login to RWW. The only difference between this and connecting through RWW is that RWW does this for you automatically. Click on “Options” &gt; select the “Advanced” tab &gt; and click on “Settings” under “Connect from Anywhere” to display the TSGateway configuration settings:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image020_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image020_thumb.jpg" border="0" alt="clip_image020" width="415" height="477" /></a></p>
<p>Enter in the URL for the SBS 2008 server (which you configured during the IAMW)</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image022_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image022_thumb.jpg" border="0" alt="clip_image022" width="416" height="466" /></a></p>
<p>Finally, on the “General” tab, enter the internal machine name of the computer you wish to connect to:</p>
<p><a href="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image024_2.jpg"><img src="http://blogs.technet.com/blogfiles/sbs/WindowsLiveWriter/SBS2008IntroductiontoRemoteWebWorkplace_C5F6/clip_image024_thumb.jpg" border="0" alt="clip_image024" width="414" height="469" /></a></p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 36] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/sbs-2008-introduction-to-remote-web-workplace/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Install a GoDaddy Standard SSL Certificate on SBS 2008</title>
		<link>http://techstogo.ca/windows-sbs-2008/how-to-install-a-godaddy-standard-ssl-certificate-on-sbs-2008/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/how-to-install-a-godaddy-standard-ssl-certificate-on-sbs-2008/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 20:27:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=476</guid>
		<description><![CDATA[Many providers offer inexpensive SSL certificates for domain-only validation.  GoDaddy seems to be a popular choice given just how inexpensive the certificates are.  GoDaddy’s inexpensive cert is called Standard SSL certificate. Before we dive in, let’s recap the certificate story in Windows Small Business Server 2008. There are two &#8220;types” of certificates and four “states” [...]]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 39] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><p>Many providers offer inexpensive SSL certificates for domain-only validation.  GoDaddy seems to be a popular choice given just how inexpensive the certificates are.  GoDaddy’s inexpensive cert is called <a href="https://www.godaddy.com/gdshop/ssl/ssl.asp" target="_blank">Standard SSL certificate</a>.</p>
<p>Before we dive in, let’s recap the certificate story in <a href="http://www.microsoft.com/sbs08" target="_blank">Windows Small Business Server 2008</a>. There are two &#8220;types” of certificates and four “states” your certificate can be in.  Those are defined on TechNet in the <a href="http://technet.microsoft.com/en-us/library/dd353115.aspx" target="_blank">Managing Certificates</a> section of the SBS documentation.  The two types are “Self-Issued” or “Trusted”, and by default, SBS 2008 ships using a <a href="http://sbs.seandaniel.com/2008/07/understanding-self-issued-certificates.html" target="_blank">self-issued certificate infrastructure</a>, which is used to authenticate the server to the client, and encrypt the traffic between the remote client and the server. The obvious downside here is there is extra work with the <a href="http://sbs.seandaniel.com/2008/07/windows-sbs-2008-certificate-installer.html" target="_blank">certificate installer package</a> on your remote/non-domain joined clients, and Windows Mobile devices.  At some point there are enough of these to warrant the low cost to upgrade to a 3rd party Trusted certificate.  With a 3rd party trusted certificate, the client computers and mobile devices already trust the root of the 3rd party certificate, as these are maintained by <a href="http://update.microsoft.com/" target="_blank">Microsoft Update</a> (and various other solutions for non-Microsoft based clients/devices).</p>
<p>As you probably read when you learned about the <a href="http://sbs.seandaniel.com/2008/08/how-new-sbs-2008-internet-address.html" target="_blank">Internet Address Management Wizard</a>, we have a number of domain name providers, <a href="http://www.enomcentral.com/" target="_blank">eNomCentral</a>, <a href="http://www.godaddy.com/" target="_blank">GoDaddy</a>, and <a href="http://www.rconnection.com/" target="_blank">Register.com</a>.  All three of these providers are very well equipped to sell you and facilitate installing a trusted certificate for your small business network, so feel free to shop around! </p>
<p>I’ll be going through the steps for GoDaddy today as they are the only provider that requires intermediate certificates, which is a bit more challenging.  The process is the same for all the providers, except for eNomCentral and Register.com, you can skip the intermediate certificate steps, and naturally the UI would be different.  On a final note, I have not had luck with the GoDaddy certificate and Windows Mobile 5 <em><span style="color: #800000;">(Update Below)</span></em>, if you have Windows Mobile 5 devices, you may want to consider one of the other partners, but the best thing to do here is open the certificate store on your WM5 device and validate the root cert for the provider you’re going with is available in the certificate store.</p>
<p>provide detailed steps, specific for SBS 2008:</p>
<ol>
<li>In your <strong>Windows SBS Console </strong>on the server, navigate to the <strong>Network</strong> tab and the <strong>Connectivity</strong> sub-tab and launch the <strong>Add a Trusted Certificate</strong> connectivity task</li>
<li>Click <strong>Next</strong> on the welcome screen and choose <strong>I want to buy a certificate from a certificate provider</strong> and click <strong>Next</strong>.</li>
<li>Verify this information is correct.  This information will be encoded in the request to the certificate provider, and cannot be changed without buying a new certificate.  Additionally for some certificate requests this information could be used to contact you to validate the ownership of the domain name.  Then click <strong>Next</strong>.</li>
<li>Once you get to the screen below, you are now going to deal with only the certificate provider, with the encoded certificate request shown in the gray box.  Since most providers have you paste this into a web browser, you should click the <strong>Copy</strong> button to place this into your clipboard. <a href="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnNiDd71I/AAAAAAAACNw/2vBKzICls-A/s1600-h/image%5B8%5D.png"><img title="image" src="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnOFyLoBI/AAAAAAAACN0/D5t63bK-lOU/image_thumb%5B4%5D.png?imgmax=800" border="0" alt="image" width="404" height="335" /></a>
<ol>
<li><span style="color: #ff0000;"><strong>IMPORTANT</strong>: It’s important not to click back or next-back on this page, as it will re-generate a new encoded string, which will not match the request you make to your cert provider.</span></li>
</ol>
</li>
<li>Once the encoded string is copied safely (I paste it into Notepad so I don’t loose it during the process) Let’s close the Trusted Certificate wizard for now to get it out of the way and prevent errors now that we have that encoded text in the clipboard (and hopefully in Notepad).  Let’s click <strong>Next</strong> and then select <strong>My certificate provider needs more time to process the request</strong>, and click <strong>Next</strong> again, the wizard will show a warning that it could not import the certificate into Remote Web Workplace.
<ol>
<li>You will also notice after you click <strong>Finish</strong>, that the console now shows <strong><em>Request Submitted</em></strong> and you have an option to <em>Remove this Certificate</em>, which we don’t want to do unless we want to go back to the beginning.</li>
</ol>
</li>
<li>At this point, go to your providers website and follow the instructions for purchasing a certificate.  The provider will most likely ask you to purchase the certificate before they collect the certificate information (encoded text above) from you. Notes:
<ol>
<li>The provider may try to sell you other services, feel free to browse, but the server doesn’t require additional services</li>
<li>The server does not require a wildcard certificate, port numbers (such as 987) are used to save you the cost of purchasing a wildcard certificate</li>
<li>You should get a confirmation email with instructions on how to install the certificate.  My particular email has this section in it, stating to log into the website to obtain my cert: <a href="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnOmmJzKI/AAAAAAAACN4/pw4ryX2BQyQ/s1600-h/image%5B16%5D.png"><img title="image" src="http://lh4.ggpht.com/_TOcS-U2k2tU/SZNnPX9fltI/AAAAAAAACN8/ptsQosh4DRM/image_thumb%5B10%5D.png?imgmax=800" border="0" alt="image" width="304" height="346" /></a></li>
</ol>
</li>
<li>Once I log into my account, It’s abundantly clear that I have a certificate set up waiting for me: <a href="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnPm1NM6I/AAAAAAAACOA/GJX_X6QJ1qM/s1600-h/image%5B20%5D.png"><img title="image" src="http://lh4.ggpht.com/_TOcS-U2k2tU/SZNnQLgIeZI/AAAAAAAACOE/f11TzdY6HvM/image_thumb%5B12%5D.png?imgmax=800" border="0" alt="image" width="304" height="109" /></a></li>
<li>I log in to my account using the ID and choose to use your certificate credit <a href="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnQSSCB6I/AAAAAAAACOI/8DUgtjFXTTI/s1600-h/image%5B24%5D.png"><img title="image" src="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnQmYRIPI/AAAAAAAACOM/QC-Zqxib-aI/image_thumb%5B14%5D.png?imgmax=800" border="0" alt="image" width="304" height="159" /></a></li>
<li>Next you will want to go to the Manage Certificate Control Panel: <a href="http://lh5.ggpht.com/_TOcS-U2k2tU/SZNnQwgitvI/AAAAAAAACOQ/51-hlKDE900/s1600-h/image%5B29%5D.png"><img title="image" src="http://lh4.ggpht.com/_TOcS-U2k2tU/SZNnRA6gIzI/AAAAAAAACOU/yJ-LG3zLSwY/image_thumb%5B17%5D.png?imgmax=800" border="0" alt="image" width="454" height="97" /></a></li>
<li>In the control panel, select your certificate credit and click <strong>Request Certificate <a href="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnRceWKWI/AAAAAAAACOY/sH3Q-syKdxI/s1600-h/image%5B33%5D.png"><img title="image" src="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnRhMx4GI/AAAAAAAACOc/jLFetpvfJPI/image_thumb%5B19%5D.png?imgmax=800" border="0" alt="image" width="304" height="169" /></a> </strong></li>
<li>Now you are prompted to insert the CSR, or Certificate Signing Request, which is all of the information you copied out of the trusted certificate wizard (and put into Notepad right?)
<ol>
<li><span style="color: #ff0000;">IMPORTANT</span>: Make sure you select the server software to be <strong>Microsoft IIS</strong>.</li>
<li>Note: the actual domain name you are requesting for is encoded in the string from within the Trusted Certificate wizard</li>
</ol>
</li>
<li>Validate the information in the cert is correct, once you confirm it, it’ll cost more money to do this over again, and then click <strong>Confirm</strong>.</li>
<li>Once you confirm, an email gets sent to the email account on file for that domain name, once you get that email, there is a verification link inside that email that needs to be clicked.  Click it and approve the request, some more email will come into that account you just checked.  One to tell you that it was approved, and one to give you the link to go and get the encoded text.
<ol>
<li>One thing to note here is there are two things to download, the signed certificate itself, and the intermediate certificates which must also be installed on the website.</li>
</ol>
</li>
<li>Validate the install type is IIS and click <strong>Continue</strong>, then proceed to the <strong>Download Signed Certificate</strong> link and save the certificate to the desktop of the server.</li>
<li>Then click the <strong>IIS Installation Instructions </strong>link to open up the installation instructions.  It’s important to use these instructions for installing the <em>Intermediate Certificate Bundle</em>.  You can follow the <em>Installing the SSL certificate</em> steps as well, but it will change the flow through the Trusted Certificate wizard shown later in this instruction set.
<ol>
<li>So follow the steps from GoDaddy.com, but I’m going to paste and modify them for SBS 2008 here for you as well… <em>These are of course subject to change without notification</em>!!!
<ol>
<li>Select <strong>Run</strong> from the start menu; then type <strong>mmc</strong> to start the Microsoft Management Console (MMC). Agree to the UAC prompt</li>
<li>In the Management Console, select <strong>File</strong>; then &#8220;Add/Remove Snap In.&#8221;</li>
<li>In the Add Standalone Snap-in dialog, choose <strong>Certificates</strong>; then click the <strong>Add</strong> button.</li>
<li>Choose <strong>Computer Account</strong>; then click <strong>Next</strong> and <strong>Finish</strong>.</li>
<li>Close the Add Standalone Snap-in dialog and click <strong>OK</strong> on the <strong>Add/Remove Snap-in</strong> dialog to return to the main MMC window.</li>
<li>If necessary, click the <strong>+</strong> icon to expand the <strong>Certificates</strong> folder so that the Intermediate Certification Authorities folder is visible.</li>
<li>Right-click on <strong>Intermediate Certification Authorities</strong> and choose <strong>All Tasks</strong>; then click <strong>Import</strong>.</li>
<li>Follow the wizard prompts to complete the installation procedure.</li>
<li>Click <strong>Browse</strong> to locate the certificate file (gd_iis_intermediates.p7b). You’ll have to change the file filter at the bottom right to <em>PKCS #7 Certificates</em>.</li>
<li>Choose <strong>Place all certificates in the following store</strong>; then use the <strong>Browse</strong> function to locate <strong>Intermediate Certification Authorities</strong>. Click <strong>Next</strong>.</li>
<li>Click <strong>Finish</strong>.</li>
</ol>
</li>
</ol>
</li>
<li>Once this is imported, we can go back to the Trusted Certificate wizard in the product
<ol>
<li>Click <strong>Add a Trusted Certificate</strong> in the console to re-launch the wizard if you closed it (as recommended above), and click <strong>Next</strong> on the welcome page.</li>
<li>Click <strong>I have a certificate from my certificate provider</strong> and click <strong>Next</strong>.</li>
<li>Since GoDaddy provided me with a file, I’m going to browse to the file (alternatively if the provider gave back encoded text, that could be pasted into the wizard too) that matches my domain name, in this case, remote.seandaniel.net. and clicking <strong>Next</strong>. <a href="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnSMrruqI/AAAAAAAACOg/lWDTB9Xsn30/s1600-h/image%5B38%5D.png"><img title="image" src="http://lh5.ggpht.com/_TOcS-U2k2tU/SZNnSY90z-I/AAAAAAAACOk/QaPYrY1AjT0/image_thumb%5B22%5D.png?imgmax=800" border="0" alt="image" width="404" height="327" /></a></li>
<li>We’re finally done, click <strong>Finished</strong>!  Now remote clients will get the benefit of a trusted certificate, and the console reports <em>Trusted</em> as the certificate type.</li>
</ol>
</li>
</ol>
<p>It’s important to use the Trusted Certificate wizard for the last step, to ensure that the certificate is bound to the correct IIS website, as well as TSGateway for remote desktop access.  If you followed all the steps from GoDaddy to install the certificate, simply run the Trusted Certificate wizard and choose <strong>I want to replace the existing certificate with a new one</strong>, and you’ll get shown the trusted certificate and the self-issued certificate for your domain name, just choose the appropriate one based on the type and the expiration date:</p>
<p><a href="http://lh5.ggpht.com/_TOcS-U2k2tU/SZNnTAshtcI/AAAAAAAACOo/QAmQGYfQrbc/s1600-h/image%5B43%5D.png"><img title="image" src="http://lh3.ggpht.com/_TOcS-U2k2tU/SZNnTm4Ni0I/AAAAAAAACOs/Fh9d9Qry8Ic/image_thumb%5B25%5D.png?imgmax=800" border="0" alt="image" width="454" height="367" /></a></p>
<p>On a final note, renewing your certificate after the year, just click that <strong>Add a Trusted Certificate</strong> link in the console but this time through choose <strong>I want to renew my current trusted certificate with the same provider</strong>, and follow the instructions!</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 40] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/how-to-install-a-godaddy-standard-ssl-certificate-on-sbs-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Restoring Active Directory in servers</title>
		<link>http://techstogo.ca/windows-sbs-2008/restoring-active-directory-in-servers/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/restoring-active-directory-in-servers/#comments</comments>
		<pubDate>Thu, 20 May 2010 16:04:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SBS 2008]]></category>
		<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=462</guid>
		<description><![CDATA[On Windows Server 2003 or Windows 2000 domain controllers the Active Directory can be backed up while the domain controller is online. You can restore these backups only when the domain controller is booted into Directory Services Restore mode by using the F8 key when the server is starting.]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 43] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><p>On Windows Server 2003 or  Windows 2000 domain controllers the Active Directory can be backed up while the  domain controller is online. You can restore these backups only when the domain  controller is booted into Directory Services Restore mode by using the  <strong>F8 key</strong> when the server is starting.</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 44] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/restoring-active-directory-in-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can I backup the system state while the Active Directory is online?</title>
		<link>http://techstogo.ca/windows-sbs-2008/can-i-backup-the-system-state-while-the-active-directory-is-online/</link>
		<comments>http://techstogo.ca/windows-sbs-2008/can-i-backup-the-system-state-while-the-active-directory-is-online/#comments</comments>
		<pubDate>Thu, 20 May 2010 16:03:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows sbs 2008]]></category>

		<guid isPermaLink="false">http://techstogo.ca/?p=460</guid>
		<description><![CDATA[Yes &#8211; On Windows Server 2003 or Windows 2000 domain controllers the Active Directory can be backed up while the domain controller is online.? You can restore these backups only when the domain controller is booted into Directory Services Restore mode by using the F8 key when the server is starting.]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.79 -->
<!-- Post[count: 47] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "></div><p>Yes &#8211; On Windows Server 2003 or Windows 2000 domain controllers the Active  Directory can be backed up while the domain controller is online.?</p>
<p>You can restore these  backups only when the domain controller is booted into Directory Services  Restore mode by using the F8 key when the server is starting.</p>
<!-- Easy AdSense V2.79 -->
<!-- Post[count: 48] -->
<div class="ezAdsense adsense adsense-leadout" style="float:left;margin:12px; "><a href="http://www.ibackup.com/p=5145945646"><img src="http://www.techstogo.ca/Ibackup_banner.jpg" alt=Online width="468" height="131" border="0" align="left" title="Online Backup" Backup></a></div>]]></content:encoded>
			<wfw:commentRss>http://techstogo.ca/windows-sbs-2008/can-i-backup-the-system-state-while-the-active-directory-is-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

