09 December 2013

Backup Exec Backup-to-Disk Best Practices

Requirements for creating a backup-to-disk folder:

Backup-to-disk folder can be created in any of the following locations: 
  • NTFS partitions (local or remote) and External USB Hard Drives.
    • The backup-to-disk folder must exist on an NTFS partition for backup jobs in which the Granular Recovery Technology(GRT) option is selected. This option is available for Microsoft Exchange databases and storage groups, Microsoft Active Directory, Microsoft Hyper-V machines, VMware Virtual Machines, and Microsoft SharePoint content database and Team database.
  • Distributed File System (DFS) shares. 
  • FAT/FAT32 partitions(local or remote). 
  • Veritas Volume Manager partitions. 
  • RAID drives with any configuration. 
  • NFS volumes.
  • Network Attached Storage (NAS) devices.
    • If a NAS device is emulating a Windows operating system, contact the NAS manufacturer for assistance before creating backup-to-disk folders on the NAS device. Symantec does not certify NAS devices. If the operating system is a proprietary operating system and not a true Windows operating system, Symantec cannot properly troubleshoot the device.

Recommendations for the "Backup to Disk" feature:

Minimizing Fragmentation:
  • Avoid hosting multiple backup-to-disk folders on the same volume.
  • Minimize the number of concurrent backup operations. Allow only one operation for maximum control.
  • Maintain at least 30 percent free space, and avoid allowing the disk to become completely full.
  • Avoid hosting other applications on the same volume.
  • To prevent fragmentation a regular defragment operation should be performed on all backup-to-disk volumes.
  • Maintain 10% or less total volume fragmentation.
  • Perform a CHKDSK on the volume.
Performance:
  • Do not allocate the maximum size of the backup-to-disk files when performing a GRT enabled backup.
  • All backup-to-disk locations should be excluded from antivirus/antispyware scans.
  • Destination drives that are setup with RAID 5 can show degraded performance. RAID 10 has been shown to significantly improve overall performance. In some cases, RAID 10 offers faster data reads and writes than RAID 5 because it does not need to manage parity.
  • Use high RPM drives in all backup-to-disk volumes for best performance.
  • Maximize the available memory. The amount of available memory will impact backup speed. Insufficient memory, improper page file settings, and a lack of available free hard disk space will cause excessive paging and slow performance.
  • Do not use Microsoft Windows compression or encryption on the volumes hosting the backup-to-disk folder.
  • Experiment with the options for buffered reads and buffered writes. Enabling these options may increase backup performance depending on the underlying disk structure implemented.

Guidelines:
  • All Backup to Disk jobs should be overwrite operations.
  • Calculate disk space requirements before assigning a disk space threshold.
  • Create a separate backup-to-disk folder specifically for all GRT enabled backup jobs. Note: Backup Exec 2012 enforces one disk storage device per Windows volume, as such this will need multiple volumes
  • Erase media from the Backup Exec console do not use Windows Explorer to delete Backup Exec data, unless it has already been properly removed from the application. For more information on deleting media properly please review the related articles section.
  • The size of Backup to disk files should not be set larger than 4GB.  This is the default size for backup-to-disk files in all current Backup Exec releases.  The larger the file size the more data is exposed when that file is corrupted.
  • USB/eSATA drives are not removable media, and should not be used as such.
   
Note:- For more information please refer to the Administrator’s guide and/or Hardware Compatibility List(HCL) pertaining to the Backup Exec version being used.

References:
http://www.symantec.com/business/support/index?page=content&id=TECH164267

19 November 2013

Folder Redirection Failing

After setting up Folder Redirection in a Windows 2003 domain and logging onto a Windows 2008 R2 server we get the following error:
The following error occurred: "Failed to build the list of known sub folders".
Error details: "The system cannot find the file specified.

Apparently, the Folder Descriptions are messed up. To fix this, we ran the following registry file.
Run the following registry file:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}][-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}][-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag]

References:
http://www.edugeek.net/forums/windows-7/111616-folder-redirection-has-stopped-working.html
http://social.technet.microsoft.com/Forums/windowsserver/en-US/ab158713-5501-4959-9a60-06b4331e844f/gpo-folder-redirection-does-not-work-anymore-502



13 November 2013

09 October 2013

Pop-out Replies and Forwards by Default in Outlook 2013

To set email replies and forwards to pop-out, or open in a new window, instead of using the in-line editor, select the following option:
File-> Options-> Mail-> Replies and Forwards-> Open replies and forwards in a new window

01 October 2013

Enable Remote Management in Windows 7

As I've completely ripped off this most excellent post...just in case it is ever taken down, I'll put the reference at the top:
http://skatterbrainz.blogspot.co.nz/2009/08/enabling-windows-7-remote-management.html

I hope to customise this to my personal style at a later date:
I’ve been searching for a comprehensive article/blog-post/kb, etc on this for a while but have only been able to find pieces of the overall solution I was looking for.  The challenge?
Enable remote management capabilities on Windows 7 clients within an Active Directory domain environment using Group Policy.
Which capabilities?
  1. Be able to PING clients
  2. Be able to connect to clients via Remote Desktop
  3. Be able to connect to clients via Computer Management
  4. Be able to connect to clients through Event Viewer, RegEdit, etc.
You may notice that my “solution” doesnt’ involve a great deal of security options.  That’s because I’m pretty comfortable with the boundary security on my network environment, which will not be described herein.  Suffice it to say that I am only interested in being able to enable and use these capabilities.  If you need increased security, you can configure additional options via Group Policy settings to suit your needs.
Computer Configuration \ Policies \ Administrative Templates
Network \ Network Connections \ Windows Firewall \ Domain Profile
  • Allow ICMP Exceptions:
    • ENABLED - Allow inbound echo request
  • Allow Inbound remote administration:
    • ENABLED: Enter asterisk (*) in IPv4 address box
  • Allow inbound Remote Desktop:
    • ENABLED: Enter asterisk (*) in IPv4 address box
Windows Components \ Remote Desktop Services \ Remote Desktop Session Host \ Connections:
  • Allow users to connect remotely using Remote Desktop services
    • ENABLED
Windows Components \ Windows Remote Management (WinRM) \ WinRM Service:
  • Allow automatic configuration of listeners
    • ENABLED: Enter asterisk (*) in IPv4 address box
If you need a nudge in the right direction for how to add these settings:
  1. Open Group Policy Management (aka “GPMC”)
  2. Expand Forest: <name> / Domains / <your-domain> / Group Policy Objects
  3. Right-click and select “New”
  4. Enter a name for the GPO (e.g. “Remote Management”) and click OK
  5. Right-click on the new GPO and select “Edit”
  6. Follow the guideline above to locate and enable the settings
  7. Right-click on the very top of the tree-view panel on the name of the GPO and select “Properties”
  8. Check the box “Disable User Configuration settings”
  9. Click “Yes” to accept the warning.
  10. Close the Group Policy Management Editor
  11. Right-click on the desired computer OU in the GPMC and select “Link an existing GPO” and select your new GPO.
  12. That’s it.
You can then either wait for the regular GPO refresh cycle to run (about 90 minutes on average, sometimes less) or go to a client and open a CMD console (remember to right-click and choose “Run as Administrator”) and at the command prompt, enter “GPUPDATE /FORCE” and press Enter.  You should be able to connect to that client from another client on your domain immediately after that.  If you still cannot, double-check your GPO settings and double-check where you linked the GPO (which OU) related to the computer account within AD.  You can (and should) use GPRESULT on the remote client to diagnose GPO issues.
Thank you Skatterbrainz.

References:
http://skatterbrainz.blogspot.co.nz/2009/08/enabling-windows-7-remote-management.html

27 September 2013

Symantec Endpoint Protection Manager Logs Are Huge

Recently a server's OS drive filled up very quickly before I realised that I had not turned on log truncation in Symantec Endpoint Protection Manager (SEPM). As soon as I performed a truncation and set SEPM to do it every four hours, all was well with the server.

To do this complete the following:

  1. Log in to the SEP Manager.
  2. Click Admin and select Servers.
  3. Select the localhost under Servers.
  4. Under Tasks, Select Edit Database Properties.
  5. In the General tab under Database Maintenance Tasks.
  6. Select the checkboxes next to Truncate the database transaction logs and Rebuild Indexes.
  7. Click OK to apply the changes.



References:
http://www.symantec.com/connect/forums/symantec-endpoint-protection-db-log-problem