Various kind of wireless network technology, computer technology, information technology, Ethernet security,isp,network security,wireless internet,wifi internet,wireless network,wi-fi network and various type of Tips and tricks are Known from this site.

Domain Name System (DNS) Tutorial



Contents

   1. Domain Name System (DNS)
   2. DNS Components
         2.1 DNS Servers
         2.2 DNS Data Base
         2.3 DNS Client
   3. Prerequisite Steps
         3.1 Static IP Address
         3.2 Steps to Assign Static IP to Server
         3.3 Steps to verify your static IP
   4. Domain Namespace
   5. Zone Types
         5.1 Primary and secondary zones
         5.2 Stub zones
         5.3 Active directory integrated zone
   6. Benefits
         6.1 Multi master replication
         6.2 Stream line data replication
         6.3 Secure dynamic updates
         6.4 Backward compatible to secondary zones
   7. Forward and Reverse look up
   8. Dynamic updates
   9. DNS Records
         9.1 A [Host]:
         9.2 PTR [Pointer]:
         9.3 SOA [Start of Authority]:
         9.4 SRV [Service Locator]:
         9.5 NS [Name Server]:
         9.6 MX [Mail Exchanger]:
         9.7 CNAME [Alias]:
  10.  Zone Transfers:
         10.1 AXFR [Full Transfer]:
         10.2 IXFR [Incremental Transfers]:

Domain Name System (DNS)

DNS stands for Domain Name System, which is basically an internet service to translate (convert) the domain names in to IP addresses as domain names are alphabetic and easy to remember then IP addresses. A distributed database is used to implement and store this name and address information for all public hosts on the internet.

DNS Components

DNS Servers

Responsible for answering queries (Request to translate name and IP addresses).DNS server change domain names to IP addresses and locating the hosting server.

DNS Data Base

Contain information about name and IP addresses where DNS server goes to and looks for the required information (or answer to the request).

DNS Client

It sends the requests to the DNS server and communicates with DNS server for translation of host name to IP address.

Prerequisite Steps:

Static IP Address

Make sure that the server where you want to install DNS is configured with static IP. Whenever you are installing a network service on a server and you have to provide the service to clients you need static IP as you should not be a moving target.

Steps to Assign Static IP to Server

    * Open start menu and Go to Network and sharing center
    * On the left side of the window click on Manage Network Connections
    * Right Click on the given connection and Disable it
    * Now Right click and go to properties of the connection
    * Click on Internet Protocol Version 4(TCP/IP4) and then click the properties
    * Select Radio Button “Use the following IP address” and write the appropriate static IP address in the given text area
    * Now right Click and Enable the Connection

Steps to verify your static IP

    * Go to start menu, and open up Command Prompt as Administrator
    * In the Command Prompt window Type ipconfig  /all
    * Notice the line “DHCP Enabled. No” which means it has static IP configuration

Domain Namespace

Domain Name space is higher archival naming convention used by DNS to locate given host name in the given domain relative to domain tree. It based on levels that are

    * Root- Domain
    * Top- Level Domain
    * Second- Level Domain
    * Sub –Domain

Zone Types

Zones come in a two different types.
Primary and secondary zones

Primary and secondary are standard zone types. This is how DNS used to work. It still can work same way but it is not common any more.

    * Primary
          o Master
          o Read/write
          o Primary is the master read write copy of the zone. Whatever server is hosting the primary zone will have the master read/write copy of the zone data base coy of the hard drive.
    * Secondary
          o Read only
          o A DNS server hosting a secondary zone has a read only copy of the database. So no changes can be made. It has the full database it can respond to client requests and it is used for the exact purpose but updates cannot be made.
    * Stub
          o Only contains information about other DNS servers.
          o A stub zone only contains information about other DNS servers. It does not have a full database.
    * Active Directory Integrated
          o DNS database is stored as an active directory object.
          o Active directory integrated zones take the place of all primary and secondary. Now the DNS database is stored as an active directory object eliminating that master read/write copy having a single master. Now we can use the multi master topology that active directory provide for us.

Stub zones

    * DNS allows for delegations.
    * A delegation is where another DNS server has been delegated the authority over a sub-domain.
    * Before stub zones, all delegations had to be managed manually.
    * A stub zone allows for the automatic propagation of delegation to DNS servers.

Active directory integrated zone

Active directory integrated zone has many benefits.

Benefits

    *  Multi master replication
    *  Stream line data replication
          o Now we have DNS and active directory databases together and replicate them altogether as one.

    *  Secure dynamic updates
          o Dynamic updates can now be secure to have only clients that have been authorized by the active directory database can update the DNS server, which stop somebody generically out of the internet for updating your DNS server.
*    Backward compatible to secondary zones
          o In active directory integrated zone will act as a primary zone. If you have older DNS server or UNIX bind DNS server which you want to keep functioning but it does not have the mechanism to support active directory integration. Simply make old DNS server in to a secondary zone DNS server pointing to one of the active directory integrated DNS servers as its primary and everything will work just fine.

Forward and Reverse look up

    * Forward look up
          o Name to IP address
          o Widely used
    * Reverse Look up
          o IP address to name
          o Not always needed
          o Usually used to meet the needs of a particular application (very often for validation purposes)

]Dynamic updates

    * Before dynamic updates all DNS information was manually entered.
    * Now records can be dynamically added (or updated) from the client.
    * Updates can be secured with active directory integrated zones. (Authorized users)
    * Dynamic updates can be integrated with other network services. (I.e. DHCP).
          o DHCP inform DNS to make a record that an IP address has been given.

DNS Records

The record can be added to the zone files we create. With the help of standard DNS query the DNS Resolver class resolves the domain names.As a result of the DNS query there is a DNS response that contains the DNS record for that query. And this DNS record contains the information depending upon the type of DNS resource record. There are many DNS record of different types but some of the records are commonly used. These are following:

A [Host]:

The A record or Host record resolves the Host name in to IP addresses and it is a typical Forward Lookup Record.  And A Record maps an IPv4 address to a hostname.

PTR [Pointer]:

The PTR or Pointer Record resolves the IP addresses to a Host name and it is exactly opposite to the A or Host Record and also called a Reverse Lookup Record

SOA [Start of Authority]:

This is the first record in any zone file and it is most authoritative for the zone.It gives the foundation and the starting point for the zone database. The SOA Record is added automatically created when we add a zone.

SRV [Service Locator]:

SRV Service Locator Records are used to represent a certain service that a computer is may be offering. They are typically use in conjunction with active directory.Active Directory requires DNS in order for its clients to locate the presence of domain controllers. When a user attempts to login for instance the client machine go out to its DNS Server to find the domain controller for the particular domain. It is the SRV Resource Record that resolves the query and directs it towards the domain controller services for that particular domain. The A record works in correspondence with the SRV Record to resolve the hostname in to IP addresses.

NS [Name Server]:

The Name Server or NS Record identifies the DNS Servers that are authoritative in each zone. And it specifies a name server for the particular domain that allows the DNS lookups within the different zones in the domain.

MX [Mail Exchanger]:

The MX or Mail Exchanger Record is used to help email give from one point to another suppose when you want to send an email to some body at sbk.edu.pk there are the DNS server over the internet that have MX or Mail Exchanger Record which point to our Email server. The Mail Exchanger Record specifies a mail exchange server for the particular domain that allows the mails to deliver to that particular mail server in the domain.

CNAME [Alias]:

The CNameor Canonical Name or simply refers to Alias some times. The CNAME Record resolves the Alias to a host name. For example when you go to www.microsoft .com then now the Microsoft might have the web server named webserv1.microsoft.com.when any body types www.microsoft .com the CNAME Record has been actually created where www.microsoft.com is directed to webserver1.microsoft.com.

Zone Transfers:

Zone transfers are only used with the Standard zones that are Primary and Secondary Zones. They cannot use with Active Directory Integrated zone. Replication takes place in active directory integrated zone as part of active directory replication. When we use standard zones Primary or Secondary we use Zone Transfers for this replication. There are two different types of zone transfers

AXFR [Full Transfer]:

AXFR means transfer the entire database. Older version of DNS has to do it every time there is an update. AXFR is really only used when we first create a secondary zone to get the entire database to come over or for the recovery of database.

IXFR [Incremental Transfers]:

IXFR is used to for the incremental transfers and most commonly used now days. IXFR is used to save our bandwidth so that when changes made only that changes must be added to the secondary.

Note: The DNS Zone Transfers can be a Security risk as there are number of issues surrounding zone transfers for example a hacker might be able to create the DNS Server and can tell your primary database that it is the secondary database through all the data here. Zone transfers are less secured then the Active Directory Integration.

[Read More...]


Active Directory Domain Services (ADDS) Tutorial



Contents

1 Directory:

2 Active Directory:

3 Active Directory Domain Services (ADDS):

4 Rules and Features in Active Directory Domain Services:

5 Benefits of Active Directory Domain Services:

6 Important Terms, Tools and Concepts in AD DS:

    6.1 FQDN (Fully Qualified domain Name):
    6.2 Active Directory Users and Computers:
    6.3 User:
    6.4 OU (Organizational Unit):
    6.5 Group Policy Object (GPO):

7 Benefits of using GPO

8 Roaming Profile

9 The Issues with Roaming Profile:

10 Network Drive (Z drive)

11 Advantages Network Drive:

12 Home Directory/ Home Folder:

13 Assigning Home Folder:

ACTIVE DIRECTORY DOMAIN SERVICES (ADDS)

Active directory was introduces on 1990’s and implemented in Windows 2000 Server with its release in 2000. Windows Server 2003 and Windows Server 2008 used Active Directory with its expansions during time. Window 2000 Server, Windows Server 2003 and Windows Server 2008 use Active Directory domain Services as a base for distributed networks (distributed computing network system).

Directory:

The listing of objects in the comprehensive way general data base of information or repository is known as directory.

Active Directory:

Active directory provides a way to store and avail information related to the network objects to other users, administrator and applications. The objects organized inform of organizational units (OUs), domain, sites, trees and forests. Active directory with the standard protocols is accessible by third party directory services because it can easily exchange and use the information effectively.
Active Directory in Windows Server 2008 R2 with the expand functionalities provide centralized administration to its users and application objects. The management of related identities are provided for the network of organization by Active Directory.

Active Directory Domain Services (ADDS):

The Active directory domain Services stores information and use stored data in the computer network. It has hierarchal structure for network objects. Objects include in the network are users, resources, computer accounts, security policies and applications. The user account in the Active directory can stores names, email address and password which are the example of particular information stores in the directory. Active Directory Domain Services make the server domain controller and it is integrated with Domain Name system (DNS).The data is protected from unauthorized use and access of objects by any unauthorized access. The integration of AD DS with operating system and other applications has different capabilities like shared resource management. AD DS provides easier access of data for the users and administrator.

Rules and Features in Active Directory Domain Services:

The following features are included in Active Directory domain Services
  • Access control to resources and authenticated logon for the users for the security integration in AD DS
  • Central management and organization by administrator with single network logon
  • The specific formats and limits for the objects and their related attributes
  • The use of global catalogue by the users and administrator for information about the objects
  • Index mechanism provide query system for the easy access of network objects and their attributes
  • Centralized management of network with the security
  • Comprehensive use of network object and properties with protected management

Benefits of Active Directory Domain Services:

Active Directory Domain Services is very secure with the comprehensive solution for the span network in multiple locations.
  • Ease of administration with centralized secure management
  • Comprehensive management with the increasing number of objects (users, computers and roles)
  • Provide single view of the users with proper management
  • Single network with different mechanisms of security
  • Automation for the administration tasks like managing and adding users and groups or other works related to different objects

Important Terms, Tools and Concepts in AD DS:

FQDN (Fully Qualified domain Name):
The FQDN is specified for the host, internet or specific computer. It is the complete name with two parts host name and domain name and also top level domain. Like project.sbk.com is FQDN where project is host name, “sbk” is second level domain and com is top level domain. FQDN has specific location in the hierarchy of Domain Name System (DNS).
Active Directory Users and Computers:
The active Directory Users and Computers is tool and a console snaps in introduced by Microsoft for the management purposes. You can create user and computer accounts; set their security policies an2d you can also apply group policies.
User:
User is the person who can use any specific computer in the given environment with the specified policies. You can log on the computer by the Active Directory user account. The Active Directory account identifies the user and establish authentication so that the user can use the resources within the domain.
OU (Organizational Unit):
Organizational Unit let you organize the users in one container that can hold all user and computer accounts that have common needs so that can be easily managed and supported by the administrator. The example is an OU Students that is for all the common users. The domain can contain the collection of different OUs with the same policies like security (password policy) that is basically same for every user in the OU. The organizational unit administrator is responsible for user and computer account maintenance in the OU.
Group Policy Object (GPO):
Group policy object is the tool which provides centralized configuration and management for the operating system and let you set rules on user and computer accounts in the Active Directory as the system administrator. It is used in the small businesses and organizations very commonly. Group policy object will store the configured setting of Active Directory. The management and configuration of software, desktop and network environments can be done by GPO. The Group Policy is the feature in Windows Server 2008’s Server Manager you need to install so that you could use and manage multiple accounts. Group Policy management console let you easily use different policies for the group policy objects.

Benefits of using GPO

There are some uses of Group Policy Objects
  • You can block as the administrator the devices for specific users
  • The improved security implementations for devices and users using firewall and IPsec
  • Categorized management of resources makes it possible to easily deploy and manage the resources
  • You can manage multiple groups, logs and event in the GPO

Roaming Profile

The roaming profile let you store and access the shared documents and desktop setting on the same network with the customize settings seamlessly. The roaming profile stores your customized data on the server; you can get access of your profile data in the same way as you saved last time even using the other computers on the network so roaming profile makes it possible by just joining the domain regardless of location. Administrator can control and designate the roaming profile to the domain administrator group and other groups and accounts.

The Issues with Roaming Profile:

The roaming profile bandwidth problems can appear inform of time consuming logging in and logging off from the account. The transformation and use of higher bytes of data is not possible with it and it can create problems for the different accounts of the users log in at the same time.

Network Drive (Z drive)

Network drive is the shared space on the hard disk for different users in the network. It is a central location for the users provided on the server also known as remote drive. The data from here is accessible by the authorized users of the domain. Mapping the network drive can be the time saver to access data files and folders from remote computer (Server). The path of drive is specified for each user in the network so the users can easily access their required data.

Advantages Network Drive:

Network drive has the following benefits:
  • A user do not need to follow and remember a large path to access the data, you just need to open ‘‘My Computer’’ and the access allocated drive by the administrator
  • You do not need to shift and transfer data after each modification, your data is save at your network drive
  • In case of any problem in the client computer data is accessible in the centralized domain controller or server

Home Directory/ Home Folder:

Home directory is used for the user so that they can save securely their data and could easily access the data. The users can have their unique and individual home directory to save and use data. The UNC (Universal Naming Convention) path is used and you can access your home drive from any directory. The users can save the images, music, videos and text document in the home drive. In command line activities it is called home directory and in graphical user interface it is known as home folder. The user profile is used as the default home folder for the user accounts. It has following benefits:
  • Provide backup of important data on the server central to separate users by the administrator
  • Central collection of files makes the management easier for the administrator
  • Secure data by providing separating system data and user’s data, and providing recovery to data
  • The large files can be store easily
  • The user can access the data from any connected computer in the network

Assigning Home Folder:

You can assign home folder to the domain users easily by the following the instructions.
  • Home folder path should be specified
  • The shared permissions should permit the user to access the home folder
  • Assign the home folder to the domain user

[Read More...]


What is Hidden Camera ? How to find it?



Now a days Hidden Cameras can be used for fun or serious business purpose. Hidden Cameras are hide in plants, radios, books, smoke detectors, desk plants, house plants, tissue boxes, DVD cases, air filter equipment, eye glasses, lava lamps, it looks like little hole, no bigger than this "o," somewhere on the side facing the room.

surveillance systems at gainable prices for every person. When you need for prevention of losses in your business or the privacy of your Family and valuables at home, purchase one of hidden spy cameras today.
[Read More...]


Installation and Configuration of DNS on Windows Server 2008



Installation and Configuration of DNS

  • Go to the Start Menu and select Server Manager

    SERVER 2008 ADDS (80)[1]

  • The Server Manager Console will be open select Add Roles from Right pane

    SERVER 2008 ADDS[1]

  • The Add Roles Wizard will be open click Next

    SERVER 2008 ADDS (1)[1]

  • Select The DNS Server Role from the Roles list and click Next

    DNS INSTALLATION AND CONFIGURATION (3)

  • Read the introduction to DNS Server and Click Next

    DNS INSTALLATION AND CONFIGURATION (4)

  • Review the Confirm Installation Selection and click Install

    DNS INSTALLATION AND CONFIGURATION (5)

  • Check the Installation Progress

    DNS INSTALLATION AND CONFIGURATION (6)

  • When the installation is succeeded click close to exit the installation wizard.

    DNS INSTALLATION AND CONFIGURATION (7)

Configuration of DNS Zones

  • Click on the Start menu select Administrative Tools and choose DNS to open DNS Manager Console

    DNS ZONES CONFIGURATION

  • The DNS Manager Console will be open, now expand your computer name

    DNS ZONES CONFIGURATION (1)

  • Right Click on Forward Look up Zones and select New Zone from the list

    DNS ZONES CONFIGURATION (2)

  • On the New Zone Wizard click Next to continue

    DNS ZONES CONFIGURATION (3)

  • Choose Primary Zone for creating the primary forward look up zone and click the check box for storing the zone in Active Directory and click Next.

    DNS ZONES CONFIGURATION (4)

  • Select To all DNS servers in this domain: project.cs.com (your domain name) and click Next

    DNS ZONES CONFIGURATION (5)

  • Give appropriate Zone Name and click Next

    DNS ZONES CONFIGURATION (6)

  • Select the radio button to Allow Secure Dynamic Updates and click Next

    DNS ZONES CONFIGURATION (7)

  • Review the Settings you specified and click Finish

    DNS ZONES CONFIGURATION (8)

  • The newly created zone (sbk_zone) is displayed under the forward look up zones

    DNS ZONES CONFIGURATION (9)

Thank you…………

[Read More...]


How to Join Windows 8 to Windows 2012 Domain Server



1. Log on to the Windows 8 client computer you want to join to the domain.
2. Make sure you have set static IP and you have the DNS IP address that's pointing to the server.
3. Type domain in the metro UI. Open up the Settings Search and Join a Domain.
4. Select Change, Select the Domain radio button, and type in the domain name.
5. For this tutorial, Im using Domain.local and Press OK.
6. You will be prompted to enter Domain Admin Credentials to join computers to the domain. I will be using my Domain Admin account.
7. If there were no problems with your credentials, follow the prompts to reboot.
8. Once rebooted, Log into the local computer.
9. You can see this by looking at the current username CLIENT-PC\LOCAL-USER.
10. Press the left arrow to switch users. Select Other User.
11. You need to log in using Server2012\Local Username
12. At this point, you are on the domain.

[Read More...]


How to Install Active Directory on Windows Server 2008 Tutorial



  • First Open Server Manager by clicking the icon in the Quick Launch toolbar, or from the Start > Administrative Tools > Server Manager.
  • Wait till it finishes loading, then click on Roles > Add Roles link.
  • In the Before you begin window, click Next.
  1. In the Server Roles window, click on check box to select Active Directory Domain Services, and then click Next.
  2. In the Active Directory Domain Services window read the provided information if you want to, and then click Next.
  3. In the Confirm Installation Selections, read the provided information if you want to, and then click Next.
  4. Wait till the process completes.
  5. When it ends, click Close.
  6. Going back to Server Manager, click on the Active Directory Domain Services link, and note that there’s no information linked to it, because the DCPROMO command has not been run yet.
  7. Go to Start > Run then type DCPROMO then enter the Run command, or click on the DCPROMO link from Server Manager > Roles > Active Directory Domain Services.
  8. Depending upon the question if AD-DS was previously installed or not, the Active Directory Domain Services Installation Wizard will appear immediately or after a short while. Click Next.
  9. In the Operating System Compatibility window, read the provided information and click Next.
  10. In the Choosing Deployment Configuration window, click on “Create a new domain in a new forest” and click Next.
  11. Enter an appropriate name for the new domain. Make sure you pick the right domain name, as renaming domains is a task you will not wish to perform on a daily basis. Click Next.
  12. Pick a full domain name such as “mydomain.local” or “mydomain.com”.
  13. The wizard will perform checks to see if the domain name is not already in use on the local network.
  14. Pick the right forest function level. Windows 2000 mode is the default, and it allows the addition of Windows 2000, Windows Server 2003 and Windows Server 2008 Domain Controllers to the forest you’re creating.
  15. Pick the right domain function level. Windows 2000 Native mode is the default, and it allows the addition of Windows 2000, Windows Server 2003 and Windows Server 2008 Domain Controllers to the domain you’re creating.
  16. Note: If you select “Windows Server 2008″ for the forest function level, you will Not be prompted to pick a domain function level.
  17. The wizard will perform checks to see if DNS is properly configured on the local network. In this case, no DNS server has been configured, therefore, the wizard will offer to automatically install DNS on this server.
  18. Note: The first DCs must also be a Global Catalog. Also, the first DCs in a forest cannot be a Read Only Domain controller.
  19. It’s most likely that you’ll get a warning telling you that the server has one or more dynamic IP Addresses. Running IPCONFIG /all will show that this is not the case, because as you can clearly saw, I gave the server a static IP Address. So, this come from IPv6. I did not manually configure the IPv6 Address, hence the warning. In a network where IPv6 is not used, you can safely ignore this warning.by clicking on Yes,the Computer will use a dynamic assigned IP address (Not recommended)
  20. You’ll probably get a warning about DNS delegation. Since no DNS has been configured yet, you can ignore the message and click Yes.
  21. Next, if you want change the paths for the AD database, log files and SYSVOL folder. For large deployments, carefully plan your DC configuration to get the maximum performance.or leave it as default When satisfied, click Next.
  22. Enter the password for the Active Directory Recovery Mode. This password must be kept confidential, and because it stays constant while regular domain user passwords expire (based upon the password policy configured for the domain, the default is 42 days), it does not. This password should be complex and at least 8 characters long (with capital latter, small latter and number combination). I strongly suggest that you do NOT use the regular administrator’s password, and that you write it down and securely store it. Click Next.
  23. In the Summary window review your selections, and if required, save them to an unattend answer file. When satisfied, click Next.
  24. The wizard will begin creating the Active Directory domain, and when finished, you will need to press Finish and reboot your computer.
          Reboot and you will have AD installed on your Win 2008 Server.
[Read More...]


How to Install DHCP on Windows Server 2008 Tutorial



To do Install DHCP, you will need a Windows Server 2008 system already installed and configured with a static IP address and Active directory. You will need to know your network’s IP address range, the range of IP addresses you will want to hand out to your PC clients, your DNS server IP addresses, and your default gateway. Additionally, you will want to have a plan for all subnets involved, what scopes you will want to define, and what exclusions you will want to create.

1. Click on Start then Click on Server Manager, click Roles from the Left  then Click on Add Roles.
2. When the Add Roles Wizard comes up, you can click Next on that screen.
Note: have a static IP address assigned on your server, and a Strong Password.
3. Select the DHCP Server Role, and click Next.
Note: Plan the IP network information, scope information, and DNS information. If you only want to install DHCP server with no configured scopes or settings, you can just click Next.
4.Select the network Connection Bindings by selecting the Network connection that is going to assign IP addresses to your clients then click on Next.
5. Validate Your DNS Settings. to make sure everything is fine.
6. Type the address of the WINS server if you are using one. if not then leave it as default and click next
7. Click on add, to add a DHCP scope.
8. Now Name yous Scope, Type the starting IP range and the ending IP address, subnet mask and default gateway which is optional.
9. Make sure activate the Scope is check. Click OK then Click Next.
10. Then no need to Configure DHCPv6 so click Disable and click next.
11. leave the authorization default and click next. Unless you are a user.
12. Confirm the Installation and click install, and that is it you are Done!
[Read More...]


How to Set up VPN Server on Windows Server 2012



Set up a VPN Server on Windows Server 2012. This tutorial shows you how to install a VPN Server on Windows Server 2012, that's Setting up the firewall and Client computer for a successful connection to the server.

Set up a VPN Server on Windows Server 2012:

1. Open the Server Manager and select Add rolls and features.
2. In “Select installation type” window check Role based or feature based installation. Next.
3. Select the local server in the Select destination server window. Next.
4. Now Select Remote access Role, and click on Add features button. Next.
5. No more features so Im clicking Next in the “Select features” window.
6. Next in the Remote Access window.
7. Select Direct Access and VPN (RAS) under Role Services Window.Next.
8. Leave everything default in the Select role services Window. Next.
9. Click Install in the Confirm Installation selection Window. Then close once it finish the installation.
10. You will now see a Remote access on the left pain, Click on it.
11. Now click on More link, under SERVERS.
12. Click on the Open Getting Started Wizard to complete the VPN configuration.
13. Select Deploy VPN Only
14. This opens the MMC for Routing and Remote Access
15. Right click the server and select Configure and Enable Routing and Remote Access
16. This launches the Setup Wizard
17. Since their is only one network interface you will need to choose Custom Configuration. Next
18. Check VPN Access. Next
19. Finish the Wizard.
20. You will need to enable users to Dial-in On a standalone server (default) this can be done in the Computer Management MMC,
if you are in a domain environment you can do this in the User properties of Active Directory.

Define a Static Address ‘pool’

Since you don’t have a DHCP Server in our VPS Environment you have to add a static address pool.
1. Right click on the Remote Access server and select Properties
2. Select the IPv4 tab and select Static address pool

Firewall Settings

Now that your VPN installation is complete you will need to modify your Windows Firewall to allow the VPN traffic You will need to open the following ports.
  1. For PPTP: 1723 TCP and Protocol 47 GRE (also known as PPTP Pass-through
  2. For L2TP over IPSEC: 1701 TCP and 500 UDP
  3. For SSTP: 443 TCP
Windows Firewall
  1. Launch Windows Firewall
  2. Click Allow a program of feature through Windows Firewall
  3. Check Routing and Remote Desktop
  4. Click OK

 Configure the Client Computer

1. Click Start button –> Control Panel -> Network and Internet -> Network and Share Center –> Click “Set up a new connection or network” under the “Change your networking settings”.
2.Select ” Connect to a workplace” and click Next.
3. Use my internet connection (VPN) –> Type the IP address and destination name in the box –>
4. Check ‘Don’t connect now; just set it up so I can connect later’ and click Next
5. Now we need to Configure the VPN Connection so right click Properties.
6. Select the Security Tab. in the Data encription drop down Select “Optional encryption (Connect even with no encryption)” Also Check Allow these protocols and place a check on Microsoft CHAP version 2 Click OK.
7. Now Enter your VPN username and password to Connect to the VPN server.
[Read More...]


How to Set Up Remote Desktop Services on Windows Server 2012



Simple tutorial on How to Set Up Remote Desktop Services on Windows Server 2012.


1. Click on Add Rolls Features from the Server Manager.
1. From the Dashboard click on “Add roles and features”.  You will be presented with the “Before you begin screen.  Click Next.
2. In the “Installation Type” screen Select “Role-base or feature-based installation”. Click Next.
3. Select a destination server.  This is a new feature of Windows 2012 where you have the ability to deploy roles and features to remote servers and even offline virtual hard disks.
4. In our case, we are selecting the current server from the server pool.Click Next.
5. Select the “Remote Desktop Services” Click Next.
6. Select Remote Desktop Session Host from the Select Roll Services window.
7. You will then be prompted to add features that are required for Remote Desktop Session Host. Click on Add Features. Click Next.
8. Check mark Restart the destination server if require.Click Install.
9. Once the server restart is ready for remote access.
[Read More...]


How to install Active Directory 2012 Domain on Windows Server 2012 Tutorial



First we need to change the computer name.  Windows provides a default name in the form of WIN <random characters>
1. To do it Go to Server Manager > Dashboard screen, click on Local Server and then click on the computer name hyperlink. This will take you to the all familiar System Properties
2. Click Change, enter a Computer Name and then click OK.
3. You will be prompted to restart your computer to apply the changes.  Click Ok and then Click on restart now.
4. After your computer has restarted, we will be presented with the Server Manager Screen.  Now we are ready to configure this server as an Active Directory Controller.
Second Assign a Static IP
1. To do so, from the Server Manager > Dashboard screen, click on Local Server and then click on the Ethernet IP hyperlink.
2. Right click on the Ethernet adapter > Click on Properties from the context menu.
4. In the Ethernet properties select the Internet Protocol version then click on Properties to assign an static IP.
Note: You can use the Gateway IP address as your Primary DNS, Once you install Active Directory and DNS it will change to point to itself.
Third Make sure you have set the proper time and timezone on the server before (AD DS)
Adding the Active Directory Domain Services Role
1. From the Dashboard click on “Add roles and features”.  You will be presented with the “Before you begin screen.  Click Next. 
2. In the “Installation Type” screen Select “Role-base or feature-based installation”. Click Next
3. Select a destination server.  This is a new feature of Windows 2012 where you have the ability to deploy roles and features to remote servers and even offline virtual hard disks.
4. In our case, we are selecting the current server from the server pool.Click Next
5. Select the “Active Directory Domain Services”
6. You will then be prompted to add features that are required for Active Directory Domain Services. Click on Add Features, Click Next
7. If you want to add additional features, you can do so from the next screen, otherwise click Next
8. You will now be presented with the Active Directory Domain Services (AD DS) screen outlining some information about AD DS and its requirements. Click next
9. You now provided with a summary of installation selections, The installation will now begin
10. Upon completion you will see an installation succeeded message. Click Close.
11. Back in Server Manager, you will notice that AD DS has been added to the left navigation tree. 
12. Click on it and then click on More… on the right navigation pane where it states that Configuration is required for Active Directory Domain Services.
13. In the All Servers Task Details Window, you will click on Promote this server to a domain controller under Action.
14. The Deployment Configuration screen appears and we will select “Add a new forest” as this is the first domain controller.
15. Enter your Root domain name and then click Next.
16. The following screen will then appear in which you will enter and select your Domain Controller Options.
17. You will then get a warning in which you can ignore for now. Click Next
18. The NetBIOS domain name will then be inputted automatically.  In the event of a conflict, it will suggest an alternative by appending the original name with a 0. Click Next
19. Confirm or change the locations of your database folder, log folder and SYSVOL folder. Click Next
20. Review your selections and then Click Next.
21. If all of the prerequisites checks have passed successfully, you will be able to click on Install to proceed. Click Install
22. The installation will now proceed and you will see the progress being displayed.
23. The computer will most likely restart on its own to complete the installation so don’t be alarmed if it does.
Upon restart, you should be able to login using your domain credentials for the user administrator.
 
[Read More...]


How to Install Windows Server 2012 step by step video tutorial



How to Install Windows Server 2012 this is a step by step video tutorial. Even though the steps haven’t really changed dramatically compared to windows server 2008, the interface has! especially with the new metro look.  So let’s begin Installing Windows Server 2012



How to Install Windows Server 2012 Steps Bellow.
1. The first step is to Boot up from the CD or ISO image and select your language settings.
2. Select your Language and input options and then click on Next.
3. Click Install Now
4. Select the operating system you want to install.  I selected Windows Server 2012 Release Candidate Server with a GUI.  The other option is server core which was first introduced in Windows 2008 and is a minimal install with no GUI but provides remote management through Windows PowerShell and other tools. Click Next
5. Accept the License terms. Click Next
6. We are performing a new installation of Windows Server, so click on Custom.
7. Partition your drives and then click Next.
8. The Installation of Windows then proceeds.
9. The installation will eventually re-start your Windows Server where it will go through the final stages of preparing the environment for first time use.
10. You will eventually be prompted to enter a password for the built-in Administrator account. Click Finish
11. You will now be presented with the new Windows Login Screen, which is a fair change to what we have been accustomed to with previous releases of Windows Server.
[Read More...]


E-mail client Mail Server Settings



Hotmail Settings:

As other web based email services, Hotmail is using the HTTP protocol for connecting you to your mailbox. If you want to send and receive Hotmail emails using an email client software, then your software must support Hotmail HTTP access for your email account. Some email clients, such as Outlook Express or Microsoft Outlook, offer builtin support for Hotmail accounts, so you only have to select HTTP when you are asked to select your email account type and select Hotmail as the HTTP Mail Service Provider.
Mail Server Settings for Hotmail using the Microsoft Outlook Connector
If you are using Microsoft Outlook & the Outlook Connector, you can define your Hotmail account just like any regular POP3 email account:

Hotmail Incoming Mail Server (POP3) - pop3.live.com (logon using Secure Password Authentification - SPA, mail server port: 995)

Hotmail Outgoing Mail Server (SMTP) - smtp.live.com (TLS enabled, port 587)

· Yahoo! Mail Settings
Yahoo Mail offers standard POP3 access for receiving emails incoming through your Yahoo mailbox, by using your favorite email client software. To setup your email client for working with your Yahoo account, you need to select the POP3 protocol and use the following mail server settings:

Yahoo Incoming Mail Server (POP3) - pop.mail.yahoo.com (SSL enabled, port 465)

Yahoo Outgoing Mail Server (SMTP) - smtp.mail.yahoo.com (SSL enabled, port 995)

POP Yahoo! Mail Plus email server settings

Yahoo Plus Incoming Mail Server (POP3) - plus.pop.mail.yahoo.com (SSL enabled, port 995)

Yahoo Plus Outgoing Mail Server (SMTP) - plus.smtp.mail.yahoo.com (SSL enabled, port 465, use authentication)

· Google GMail Settings
The Google GMail service offers email client access for retrieving and sending emails through your Gmail account. However, for security reasons, GMail uses POP3 over an SSL connection, so make sure your email client supports encrypted SSL connections.

Google Gmail Incoming Mail Server (POP3) - pop.gmail.com (SSL enabled, port 995)

Outgoing Mail Server - use the SMTP mail server address provided by your local ISP or smtp.gmail.com (TLS enabled, port 587)

Google Gmail Outgoing Mail Server (SMTP): smtp.gmail.com

The Gmail SMTP server requires authentication (use the same settings as for the incoming mail server)

The Google Gmail SMTP Server requires an encrypted connection (SSL) on port 465.

· MSN Mail Settings
The MSN email service allows you to use the MSN POP3 and SMTP servers to access your MSN mailbox.

MSN Incoming Mail Server (POP3) - pop3.email.msn.com (port 110, using Secure Password Authentication - SPA)

MSN Outgoing Mail Server - smtp.email.msn.com (select "My outgoing server requires authentication")

· Lycos Mail Settings
The Lycos Mail Plus service allows you to use POP3 and SMTP servers for accessing your Lycos mailbox.

Lycos Mail Incoming Mail Server (POP3) - pop.mail.lycos.com (port 110)

Outgoing Mail Server - smtp.mail.lycos.com or use your local ISP SMTP mail server

· AOL Mail Settings
The AOL email service is a web based system, designed for managing your AOL mailbox via HTTP IMAP access. Unlike Hotmail, you can use any email client to access your AOL mailbox, as long as it supports the IMAP protocol.

AOL Incoming Mail Server (IMAP) - imap.aol.com (port 143)

AOL Outgoing Mail Server - smtp.aol.com or use your local ISP SMTP mail server

· Mail.com Mail Settings
The Mail.com email service allows you to use POP3 and SMTP servers for accessing your Mail.com mailbox.

Mail.com Mail Incoming Mail Server (POP3) - pop1.mail.com (port 110)

Outgoing Mail Server - use your local ISP SMTP mail server

· Netscape Internet Service Mail Settings
The Netscape e-mail system is web-based, which means you can access their e-mail from any Internet connection. Netscape Internet Service also supports AOL® Communicator, Microsoft® Outlook, Microsoft® Outlook Express, and other POP3 e-mail software. The outgoing mail server needs SSL support, so make sure your email client software supports SSL connections over the SMTP protocol.

Netscape Internet Service Incoming Mail Server (POP3) - pop.3.isp.netscape.com (port 110)

Netscape Internet Service Outgoing Mail Server - smtp.isp.netscape.com (port 25, using a secure SSL connection)

· Tiscali Mail Settings
The Tiscali email service allows you to use POP3 and SMTP servers for accessing your Tiscali mailbox.

Tiscali Incoming Mail Server (POP3) - pop.tiscali.com (port 110)

Outgoing Mail Server - use your local ISP SMTP mail server

· Freeserve Mail Settings
The Freeserve email service allows you to use POP3 and SMTP servers for accessing your Freeserve mailbox.

Freeserve Incoming Mail Server (POP3) - pop.freeserve.com (port 110)

Outgoing Mail Server - use your local ISP SMTP mail server

· Supanet Mail Settings
The Supanet email service allows you to use POP3 and SMTP servers for accessing your Supanet mailbox.

Supanet Incoming Mail Server (POP3) - pop.supanet.com (port 110)

Outgoing Mail Server - use your local ISP SMTP mail server

[Read More...]


How to Configure Outlook Express email client



Configuring your email client: Microsoft Office Outlook Express

Method 1: Microsoft Office Outlook 2010

1. Start Outlook.

2. On the File menu, click Info and click Account Settings.

3. Select Account Settings from the list.

4. On the E-mail tab, click New and Select Email Account, and then click Next

5. Click to select the Manually configure server settings or additional server types check box, and then click Next.

6. Click Internet E-Mail, and then click Next.

7. In the Server Information section, select IMAP for Account Type.

8. In the Your Name box, enter your name exactly as you want it to appear to recipients.

9. In the E-mail Address box, type your e-mail address.

10. In the User Name box, type your account name.

11. In the Password box, type your password.

12. In the Incoming mail server box, type the name of your IMAP4 server.

13. In the Outgoing mail server (SMTP) box, type the name of your SMTP server.

Note IMAP4 is a retrieval protocol. You must have SMTP to send your messages.

14. Click Next after you have completed entering this configuration information, and then click Finish.

Method 2: Microsoft Office Outlook 2007

1. Start Outlook.

2. On the Tools menu, click Account Settings.

3. Click New.

4. Click Microsoft Exchange, POP3, IMAP, or HTTP, and then click Next.

5. In the Auto Account Setup dialog box, click to select the Manually configure server settings or additional server types check box, and then click Next.

6. Click Internet E-Mail, and then click Next.

7. In the Server Information section, select IMAP for Account Type.

8. In the Your Name box, enter your name exactly as you want it to appear to recipients.

9. In the E-mail Address box, type your e-mail address.

10. In the User Name box, type your account name.

11. In the Password box, type your password.

12. In the Incoming mail server box, type the name of your IMAP4 server.

13. In the Outgoing mail server (SMTP) box, type the name of your SMTP server.

Note IMAP4 is a retrieval protocol. You must have SMTP to send your messages.

14. Click Next after you have completed entering this configuration information, and then click Finish.

Method 3: Microsoft Office Outlook 2003 and earlier versions of Outlook

1. Start Outlook.

2. On the Tools menu, click E-mail Accounts.

3. Under E-mail Accounts, click Add a new e-mail account, and then click Next.

4. Click IMAP as the type of account that you are creating, and then click Next.

5. In the Your Name box, enter your name exactly as you would like it to appear to recipients.

6. In the E-mail Address box, type your e-mail address.

7. In the User Name box, type your account name.

8. In the Password box, type your password.

9. In the Incoming mail server (IMAP) box, type the name of your IMAP4 server.

10. In the Outgoing mail server (SMTP) box, type the name of your SMTP server.NOTE: IMAP4 is a retrieval protocol. You need SMTP to send your messages.

11. Click Next after you have completed entering this configuration information, and then click Finish.

[Read More...]


How to Configure your email client Eudora 7.0



Now Eudora is popular e-mail client program available for Microsoft Windows. Configuring Eudora 7 for Windows to use your new E-mail account. If you should be problem in

“ Could not connect to "pop.gmail.com"

Cause: connection timed out (10060) ”

Then try this procedure, it 100% work for you.

Configuring your email client Eudora 7.0

  1. Open Eudora.
  2. Click the 'Tools' menu, and select 'Options.'

clip_image001

  1. Click 'Getting Started' under 'Category'
    • Enter your full name in the 'Real name' field.
    • Enter your full webmail address (sample@yourdomain.com) in the 'Email address:' field.
    • Enter 'pop.mailserver.com' Like Gmail (pop.gmail.com) in the 'Mail Server (Incoming):' field.
    • Enter your Login “User Name” in User Name field.
    • Click 'Allow authentication' below 'SMTP Server.'
    • Enter 'smtp.mailserver.com’ Like Gmail (smtp.gmail.com) in the 'SMTP (Outgoing) Server:' field.
clip_image003

 

  1. Click 'Checking Mail' under 'Category:.'
    • Set 'Secure Sockets when Receiving' to 'Required, Alternate port'

clip_image002[1]

  1. Click 'Incoming Mail' under 'Category'
    • Optional: If you want to use both Eudora and webmail to check your mail, check the box for "Leave mail on server".
    • Select 'Passwords' for 'Authentication Style.'

clip_image004

  1. Click 'Sending Mail' under 'Category:.'
    • Check the box next to 'Allow authentication.'
    • Set 'Secure Sockets when Sending' to 'Never,' and click 'OK.'
    • Check the box next to "Use submission port (587)" (Check your firewall settings if necessary to enable that port.).

clip_image005

  1. Click 'OK,'
  2. Now go personalities option then “Dominant option”.

clip_image007

  1. Right click on Dominant then click properties.

clip_image009

  1. set 'Secure Sockets when Receiving' to 'Required, Alternate port', And check all check box

clip_image010

  1. et 'Secure Sockets when Receiving' to 'Required, Alternate port'

clip_image011

12. Click ok.

13. Now verify your settings by clicking 'File,' and then 'Check Mail.'

[Read More...]


what is a computer firewall and how does it work



What is Computer firewall:

A wall between the source and the user that blocks a certain type of traffic from reaching its destination is firewall. The firewall protects systems from unauthorized access while maintaining communications with the legitimate ones. A device or a combination of devices configured to allow and reject transmissions in a network on the bases of well-defines rules works as firewall.

A majority of personal computers have built-in firewalls to defend the operating system from illegitimate efforts of transmitting or accessing data. Firewalls do have the capability to perform the routing functions where a number of routers are capacitated to act like firewall filters.

Network traffic has three features: a source, a protocol (typically UDP, TCP or ICMP) and a destination. The UDP and TCP protocols have a source (mostly random) as well as a destination port (a well-known number) for example the destination port of DNS is 53 and the destination port for HTTP is 80. The ICMP protocol carries an ICMP message type; the most common of them are Echo Reply and Echo Request. A firewall protection allows network security administrator to pick which ports and protocols or message types would have access and which would be blocked. Read below to find out how firewall works

How the Firewall Works?

The prime security feature of a firewall is its inbound restriction. A typical firewall configuration abandons all inbound traffic to internal IP addresses. A DMZ network should carry the server that accepts the incoming connections or traffic. Latest firewalls allow in the responses to outbound tariff; the firewalls of computers that are connected to web server via internet would automatically accept responses from the web server that would in turn return to the computer.

Inbound Confinement Example: A “ping” command transmits ICMP Echo Request message and as a response receives ICMP Echo Reply message. For blocking the ICMP Echo Request messages to reach its destination, one has to configure a firewall that would result in failed ping commands. For blocking ICMP Echo Reply messages a firewall could be assembled between the source and the destination to fail all ping commands. A potential attacker is allowed by ping to map the network; for preventing the use of ping command for mapping network disable the inbound Echo Request messages.

The outbound traffic is denied in some network security administrators. The feature forbids users from accessing unapproved protocols while limiting their access to only approved protocols; such restrictions involve avoiding users from online chat or sending outbound emails especially in work places. Such limitations are sensitive to work-around the time and effort of the user necessary to approach a particular protocol via indirect ways thus very few users spent time in figuring out a way. The outbound confinement most of the time works as per design.

Outbound Confinement Example: SMTP protocol that responds to TCP port 25 is used for emails. Blocking the outbound TCP port 25 in your network would disable the users from sending outbound emails except from enabled email servers. An effective work-around the confinement policy is the configuration of mail server to respond to an additional port along with port 25 by an intelligent user.

What are the Types of Firewall?
On the foundation of communication’s situation, its interception and the state firewalls could be classified.

  • The Network Layer Firewall also known as packet filters (in BSD operating systems’ context) works on the low level of the TCP/IP protocol heap which means that none could cross the firewall unless the packets resemble the established rules. Usually default rules are applied but the administrator has authority to modify rules. The Packet Filters have two sub-types. A firewall could make use of a number of packet attributes for filtering traffic such as source port, IP address, destination port or IP address, destination service like FTP or WWW. The process of filtering could be based on protocols of the source such as net block, TTL values and other properties.
    • Stateful Firewalls manages the context of ongoing sessions and process speed packet by the help of state information. In case a packet does not resemble an existing connection then the evaluation would be based on the rules of new connections where the resemblance with the connection on the bases of comparison with the state table of firewall would enable the packet to cross the firewall without any further processing.
    • Faster filters and less memory requirement makes Stateless Firewalls a better option. These firewalls are fundamental for the filtering of stateless network protocols due to no concept of session in their set ups. The firewalls are not clever enough to figure out the extent of communication between the hosts.

 

  • The Application Layer Firewall functions on the application level of TCP/IP stack such as all telnet or FTP traffic and tap all packets whether travelling from or to an application. They drop other packets without recognition of the sender. These filters are helpful in restricting outbound traffic from approaching the confined machine.

 

  • The process ID of data packets is examined by the application firewall against a local process’ ruleset implied in data transmission. The rendered ruleset defines the extent to which filtering would be done. In this firewall the ruleset for standard services such as sharing services is very complex. Along with other processes there might occur some possible associations but these ruleset for process has fixed efficiency; it could not defend against modifications that are caused by exploitations such as the exploits of memory corruption.

 

  • These limitations in the application firewall have triggered the association of a new generation of application named MAC (Mandatory Access Control) or sandboxing in these firewalls in order to secure sensitive services. APPArmor is an example of next generation application firewall that is included in some distributions of Linux.

 

  • A Proxy Server could be configured to act as a firewall by responding to input packets such as connection requests. The server could serve as an application that runs on software of a machine made for this purpose or on a hardware dedicated to the task thus breaking into the path of other packets so they could not access their destination.
    It would be extremely tough for an external network to temper with an internal system that is synchronized with a proxy server. If the application proxy is accurately configured and intact then the misuse by an external network would not inevitably lead to some security breach exploitation. A system that is in the reach of public might be hacked by intruders who would employee the system as a proxy for their illegitimate motives; in such cases proxy would present that machine as it is to the internal computers. For passing packets to a specific target, hijackers could make use of IP Spoofing.

 

  • The function of NAT (Network Address Translation) is often installed in firewalls that give private or personalized address range as given in RFC 1918 to the hosts that are secured behind a firewall. The initiative is taken to protect or camouflage the hosts from potential threats.

 

  • The routable addresses of IPv4, assigned to individuals or organizations to reduce the number along with cost of acquiring such public addresses for every other computer in the building, were the reason behind the designing of a function like NAT. Against network reconnaissance the best defense is to hide the address of protected devices.
[Read More...]


what is spam in computer networking? How spam works?



What is Spam?

When we use different types of technologies related to the field of computer networking, we should know about the different types of advantages and disadvantages of the technologies. As we know that there are lot of advancements in the computer networking field but still these technologies has a security issue in there working. However, one of the major disadvantages of the computer networking is that they can easily affected by different types of methods from different source without the permission of the users. One of them is Spamming. Read further below about what is spam.

An other important types of such infection that can affect the system badly is the Spam. It is the types of messages or the email that can infect your personal computer and decode all the important information related to your computer called as spam. It is that types of system that can infect the PC with the help of different types advertising messages or email downloaded from the net that are unwanted and stored in the email box with out the permission of the user.

How spam Works?
Spam is the type of the unwanted or infected messages that infect the personal computer and slows down the working of the computer. Spam works in number of ways some important that is used by the spammers to spread the spam in enter networks and also in your systems are as follows.

When we move on to the network with the help of different networking devices, there are lot of advertisements present on the internet the can provide some good offers to the customers such as some sale purchase offer or some kind of games etc. But in these advertisements spammers use different techniques to store the infected messages in it and when we click to open the ad, the email works and decode the information and the working of the system become very slow and it can also hijack the personal information of your system. Commonly it is present in the inbox of the users and when the user clicks to read the mail it can infect the whole system with the help of different types of software that can be stored by the spammers in it. And can cause the harm to your operating system at the large extent.

Basically spammers designed the system to spread the different type of emails in the form of spam and then distribute those spam to that site that contains the protection software such as antivirus. And when the users download the protection software, these spam can also downloaded to your system and affect the whole system. Some common types of spam are present almost on every mail site. But the major sources that take part in spreading the spam are the spy wares or ad wares. With the help of such spam the email recommend the site to the user where such kind of dangerous software are present and can be downloaded easily when the user open the site.

Methods Used by Spammers:

Spammers used different ways to get the email address to spread the spam into the mail boxes of different types of users. Some times they can purchase the CD of the email address directly from the company and do there work of spreading the spam easily. Another method that is used by the spammers to search the email addresses is that they designed such system that can search the email address on the internet with the help of @ such sign.


Protection from Spam:

Some protective software and different ways are also adopted to reduce the distribution of spam in the mail boxes. Te easy and the common method to avoid the spam is to use only those email sites that can provided with the spam filters.

[Read More...]


Related Posts Plugin for WordPress, Blogger...
 

Subscribe And Get Free E-Mail Updates:

Return to top of page Copyright © 2012