<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>LaslowNET &#187; Networking</title>
	<atom:link href="http://laslow.net/category/networking/feed/" rel="self" type="application/rss+xml" />
	<link>http://laslow.net</link>
	<description></description>
	<lastBuildDate>Sat, 04 Feb 2012 03:06:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>On Labeling</title>
		<link>http://laslow.net/2011/09/21/on-labeling/</link>
		<comments>http://laslow.net/2011/09/21/on-labeling/#comments</comments>
		<pubDate>Wed, 21 Sep 2011 19:01:37 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA["It's a Feature"]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Makes Sense]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[What?]]></category>

		<guid isPermaLink="false">http://laslow.net/?p=1301</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<div id="attachment_1302" class="wp-caption aligncenter" style="width: 235px"><a href="http://laslow.net/wp-content/uploads/2011/09/11-1.jpg"><img class="size-medium wp-image-1302" title="Plug" src="http://laslow.net/wp-content/uploads/2011/09/11-1-225x300.jpg" alt="Plug" width="225" height="300" /></a><p class="wp-caption-text">What is this? I don&#39;t even...</p></div>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2011/09/21/on-labeling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPv6 over an IPv4 Tunnel on a Dlink DIR-825 Rev. B</title>
		<link>http://laslow.net/2011/06/27/ipv6-over-an-ipv4-tunnel-on-a-dlink-dir-825-rev-b/</link>
		<comments>http://laslow.net/2011/06/27/ipv6-over-an-ipv4-tunnel-on-a-dlink-dir-825-rev-b/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 04:52:53 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA[howto]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[IPv6]]></category>

		<guid isPermaLink="false">http://laslow.net/?p=1254</guid>
		<description><![CDATA[Although I missed World IPv6 Day, I was bored the other night and decided to finally setup an IPv6 tunnel. To do this, I registered a free account with Hurricane Electric&#8217;s Tunnel Broker. The process was a breeze and in no time I had a regular tunnel created. From there, it was all up to [...]]]></description>
			<content:encoded><![CDATA[<p>Although I missed <a href="http://en.wikipedia.org/wiki/World_IPv6_Day" target="_blank">World IPv6 Day</a>, I was bored the other night and decided to finally setup an IPv6 tunnel. To do this, I registered a free account with <a href="http://www.he.net/" target="_blank">Hurricane Electric&#8217;s</a> <a href="http://tunnelbroker.com/" target="_blank">Tunnel Broker</a>. The process was a breeze and in no time I had a regular tunnel created. From there, it was all up to the Dlink router.</p>
<p>A few notes:</p>
<ol>
<li>Make sure you have the latest firmware for your DIR-825 Rev. B. At the time of writing, it&#8217;s version 2.05(NA).</li>
<li>You will need to enable &#8220;WAN Ping Respond&#8221; &#8211; this can be found under <strong>Advanced</strong> -&gt; <strong>Advanced Network</strong>. You can safely disable this after you finish complete the process and your tunnel is working. This is needed so that Tunnel Broker (TB, from here on out) can confirm your public-facing IP address and link it to your tunnel.</li>
</ol>
<p>So, that out of the way, once Tunnel Broker has confirmed your tunnel is available, login to your router and do the following:</p>
<ol>
<li>Under the main <strong>Setup</strong> tab, click <strong>IPv6</strong>.</li>
<li>Click the <strong>Manual IPv6 Internet Connection Setup</strong> button. <em>Do not</em> use the wizard.</li>
<li>For the <strong>IPv6 CONNECTION TYPE</strong>, choose <strong>IPv6 in IPv4 Tunnel</strong>.</li>
<li>In the <strong>Remote IPv4 Address</strong> box, enter the <strong>Server IPv4 Address</strong> provided by TB.</li>
<li>In the <strong>Remote IPv6 Address</strong> box, enter the <strong>Server IPv6 Address</strong> provided by TB.</li>
<li>The <strong>Local IPv6 Address</strong> is the <strong>Client IPv6 Address</strong> from TB.</li>
<li>Under the <strong>IPv6 DNS SETTINGS</strong> heading, choose <strong>Use the following IPv6 DNS servers</strong> and enter the <strong>Anycasted IPv6 Caching Nameserver</strong> provided by TB in the <strong>Primary IPv6 DNS Server</strong> box (TB did not provide me with a secondary DNS address).</li>
<li>Finally, uncheck <strong>Enable DHCP-PD</strong> under the <strong>LAN IPv6 ADDRESS SETTINGS</strong> heading.</li>
<li>Leave the settings under the <strong>ADDRESS AUTOCONFIGURATION SETTINGS</strong> heading as their defaults.</li>
<li>Click the <strong>Save Settings</strong> button at the top of the page and let the router do it&#8217;s thing. It will take some time to &#8216;measure the internet connection&#8217; &#8211; this is normal.</li>
</ol>
<p>You&#8217;re almost done. At this point, if you go to the <strong>Status </strong>tab and choose <strong>IPv6</strong> from the options down the left side of the page, you should see the TB information you entered, and <strong>Network Status</strong> should say <strong>Connected</strong>.</p>
<p>The rest of the work depends on your operating system. I use Windows 7 on my main PC, which natively supports IPv6 (as does OS X and most *nix distros). As IPv6 is enabled by default, I simply had to open an <strong>Elevated Command Prompt</strong> and type:</p>
<blockquote><p>ipconfig /release</p>
<p>ipconfig /renew</p></blockquote>
<p>After it finished thinking, ipconfig spat out the new network configuration which included the correct IPv4 and IPv6 addresses. I opened Firefox and browsed to <a href="http://ipv6.google.com" target="_blank">http://ipv6.google.com</a> &#8211; success! Everything works! You can also confirm that IPv6 is working by using the <strong>nslookup</strong> tool from a command prompt like so:</p>
<blockquote><p>C:\Users\Laslow&gt;nslookup<br />
Default Server:  ordns.he.net<br />
Address:  2001:470:20::2</p>
<p>&gt; xbox.com<br />
Server:  ordns.he.net<br />
Address:  2001:470:20::2</p>
<p>Non-authoritative answer:<br />
Name:    xbox.com<br />
Addresses:  2a01:111:f009::3b03<br />
65.55.42.140</p>
<p>&gt;</p></blockquote>
<p>As you can see, the IPv6 nameserver came back with an IPv6 AAAA record (2a01:111:f009::3b03) and an IPv4 A record (65.55.42.140) for <a href="http://xbox.com" target="_blank">xbox.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2011/06/27/ipv6-over-an-ipv4-tunnel-on-a-dlink-dir-825-rev-b/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Shaw Cable Pulls a Rogers; Hijacks NX Records</title>
		<link>http://laslow.net/2011/05/01/shaw-cable-pulls-a-rogers-hijacks-nx-records/</link>
		<comments>http://laslow.net/2011/05/01/shaw-cable-pulls-a-rogers-hijacks-nx-records/#comments</comments>
		<pubDate>Mon, 02 May 2011 05:31:41 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA["It's a Feature"]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Bullshit]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Hijacking]]></category>
		<category><![CDATA[Shaw]]></category>

		<guid isPermaLink="false">http://laslow.net/?p=1213</guid>
		<description><![CDATA[The last time I wrote about NX Domains, it was because I noticed that Rogers wireless was hijacking them on my phone. Now, it appears that Shaw Cable is doing the same. I use OpenDNS, so I&#8217;m used to search pages coming up when I mistype URLs, however that is something I&#8217;d opt&#8217;ed in to. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://laslow.net/wp-content/uploads/2011/05/Shaw.png"><img class="alignright size-full wp-image-1219" title="Shaw Cable" src="https://laslow.net/wp-content/uploads/2011/05/Shaw.png" alt="Shaw Cable" width="154" height="70" /></a>The last time I wrote about <a href="http://en.wikipedia.org/wiki/DNS_hijacking" target="_blank">NX Domains</a>, it was because I noticed that <a href="http://laslow.net/2010/06/07/rogers-wireless-hijacks-wildcard-dns-records/" target="_blank">Rogers wireless was hijacking them on my phone</a>. Now, it appears that <a href="http://www.shaw.ca" target="_blank">Shaw Cable</a> is doing the same.</p>
<p>I use <a href="http://www.opendns.com/" target="_blank">OpenDNS</a>, so I&#8217;m used to search pages coming up when I mistype URLs, however that is something I&#8217;d opt&#8217;ed in to. You can imagine my surprise when, after mistyping a URL, I was directed to this instead:</p>
<blockquote><p><a href="http://assist.shaw.ca/shawcaassist/dnsassist/main/?domain=www.example.com">http://assist.shaw.ca/shawcaassist/dnsassist/main/?domain=www.example.com</a></p></blockquote>
<p>(original URL redacted).</p>
<p>It appears that, even if you aren&#8217;t using Shaw&#8217;s DNS servers they are still checking your DNS requests and, in the case of NX domains (at least &#8211; they could technically do this for any traffic), hijacking the result and forwarding your browser to their page instead.</p>
<p>I&#8217;ve sent a barrage of messages to Shaw&#8217;s PR team on Twitter, but haven&#8217;t had a response yet. I&#8217;ll update this article when (or if) they reply.</p>
<p>For the time being, though, it appears you can opt-out of the &#8216;service&#8217; using this page: <a href="http://nxr.shaw.ca/optout/">http://nxr.shaw.ca/optout/</a></p>
<p><strong>Update:</strong> I&#8217;ve had a reply from Shaw saying &#8220;We do not modify any DNS traffic going to our customers from other sources&#8221;. They&#8217;re currently looking in to the issue apparently, so another update will be in order when I hear back.</p>
<p><strong>Additional Update: </strong>I received a reply from Shaw asking me to do some further troubleshooting, all of which would have been useless (eg, using the &#8216;dig&#8217; and &#8216;nslookup&#8217; commands to confirm my DNS settings and what the NX response was), however as I opted out of the &#8216;service&#8217; I can&#8217;t actually complete the steps as everything is working correctly. Additionally, there doesn&#8217;t appear to be a way to opt back in to the &#8216;service&#8217;, so that&#8217;s also a bust. I guess I won&#8217;t be getting an answer as to what happened. Also, <a href="http://www.reddit.com/r/canada/comments/hanhe/shaw_cable_hijacks_mistyped_domain_names/" target="_blank">I was linked on Reddit Canada</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2011/05/01/shaw-cable-pulls-a-rogers-hijacks-nx-records/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>ADMT: What I Learned</title>
		<link>http://laslow.net/2011/03/29/admt-what-i-learned/</link>
		<comments>http://laslow.net/2011/03/29/admt-what-i-learned/#comments</comments>
		<pubDate>Tue, 29 Mar 2011 16:22:46 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA[howto]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[ADMT]]></category>
		<category><![CDATA[Server 2003]]></category>
		<category><![CDATA[Server 2008]]></category>

		<guid isPermaLink="false">http://www.laslow.net/?p=1176</guid>
		<description><![CDATA[Years ago, long before I started working at my current job, management launched a new contract in a office building just across the street. At the time, wireless network connections were still in their infancy and not to be trusted, so the new office was set up with a pair of servers, a nice new [...]]]></description>
			<content:encoded><![CDATA[<p>Years ago, long before I started working at my current job, management launched a new contract in a office building just across the street. At the time, wireless network connections were still in their infancy and <em>not to be trusted</em>, so the new office was set up with a pair of servers, a nice new Active Directory Forest and Domain (DomainB), and a VPN to access resources on the primary network, DomainA.</p>
<p>Fast forward to three years ago, just before I was hired. The then-sysadmin was getting flak for the VPN being slow, so he installed a pair of wireless routers on the roofs of the buildings and linked the two networks. However, instead of getting rid of DomainB, he simply left it in place.</p>
<p>Fast forward to now. Due to cost issues, the contact in the remote office was physically moved to our main building. As such, their network equipment and servers came with them, which created cramped quarters <a href="http://www.laslow.net/2009/04/08/short-some-days-are-better-than-others/" target="_blank">in an already cramped space</a>. As such, I set about doing what should have been done years ago &#8211; migrating users from DomainB to DomainA.</p>
<p>There was a group of client computers that needed to go through a round of updates anyways, so those were simply re-imaged and joined to a separate, restricted network (DomainC) used for our clients only (this had been another pet peeve of mine &#8211; due to costs, the clients in that office were put on the same network and although they had their permissions restricted, it was still a concern in my mind). The main problem, though, was the staff workstations. Not only were they setup on DomainB, put PrimaryDC.DomainB was also an Exchange 2003 server, and TertiaryDC.DomainA was our primary mail server running Exchange 2007. The first step was to manually export the mail for the twelve staff members and create their DomainA accounts, and then get them setup on the DomainA Exchange server. Once that was up and running, the Exchange 2003 install was shutdown. Although it took a while to manually transfer the mail by exporting to .PST files and then importing it again, it was the cleanest way to do the move (and also encouraged users to clean out their mailboxes).</p>
<p>The last step was to actually get the users logging in to DomainA rather than DomainB. That&#8217;s where ADMT (Active Directory Migration Tool) comes in.</p>
<p>ADMT comes in a few &#8216;current&#8217; versions. 3.0 if the server it&#8217;s running on is Server 2003, 3.1 if it&#8217;s Server 2008, and 3.2 if it&#8217;s Server 2008 R2. The source domain (B) was running on Server 2003 boxes, but the target domain (A) was running mostly on Server 2008 boxes, so I installed ADMT 3.1 on one of those.</p>
<p>After getting it installed and playing around with it on a test VM, I learned a few things that helped me get all of the staff workstations migrated with minimal issues:</p>
<ul>
<li>Setup a Two-Way Trust between the domains first, but be aware that if users are already authenticating on both domains by using store credentials, that may break unless you also setup permissions for users of both domains on effected shares.</li>
<li>Double-check your DNS configuration. If both domains have separate Forward Lookup Zones (which they probably do), make sure that the DNS servers in both domains are setup to perform Zone Transfers between each other, and then check to make sure that all A and PTR records are actually correct and current.</li>
<li>Make sure that the user you are logged in to on the server running ADMT is in the Domain Admins group on the target domain, and the Administrators group in primary DC on the source domain.</li>
<li>Change the DNS servers that the computers to be migrated are using to the servers on the target domain. This is important, or after the computer migrations are complete you may run in to issues when logging in (for me, Active Directory decided to continually lock out user accounts of migrated users because of a missing A record in the source domain&#8217;s DNS zone).</li>
<li>If you have any local firewall software running on the workstations that are to be migrated, either temporarily disable it or add exceptions for the Netlogon Service, File and Printer Sharing, and Windows Management Instrumentation (although the last may not strictly be needed &#8211; it was hit-or-miss for me).</li>
<li>Run the following command on the workstations that you&#8217;re migrating: <strong>net localgroup &#8220;Administrators&#8221; &#8220;DomainAdomain admins&#8221;</strong> /ADD (changing DomainA to your target domain). This is important, as local admin rights are needed for the computer migration steps.</li>
<li>If users from your source domain are using resources on your target domain and using stored credentials to authenticate, delete those stored usernames/passwords from the workstation (in most cases, open Control Panel, then User Accounts, and click &#8216;Manage Network Passwords&#8217; on left). Then, once you have migrated the user accounts, give those accounts permission to access the required resources.</li>
<li>During the migration, if you are trying to migrate a computer account and you continually receive an error like <strong>ERR2:7666 Unable to access server service on the machine &#8216;computer.domain&#8217;.  Make sure netlogon and workstation services are running and you can authenticate yourself to the machine.  hr=0&#215;80070005. Access is denied.</strong>, and you&#8217;ve run the command above on the machine to give Domain Admins from the target domain local admin rights, you may need to remove the computer from the source domain, rejoin it to the source domain to re-establish the trust relationship, and then try the migration again.</li>
<li>After the migrations are done, make sure to go back to the DNS servers on your target domain and verify that the migrated computers&#8217; PTR records reflect the new domain suffix (eg, changed from &#8216;workstation1.domainB.&#8217; to &#8216;workstation1.domainA.&#8217; (and leave the trailing . in, or you&#8217;ll have trouble!).</li>
</ul>
<p>And that&#8217;s it! ADMT worked like a charm, and after using it to migrate and merge user accounts, and then migrate the computer accounts, everyone was off DomainB with out the hassle of needing to manually join DomainA and reconfigure the user accounts. By performing both the user account and computer account migrations, once the process was done users just had to login to their computers using &#8216;DomainAUsername&#8217; instead of &#8216;DomainBUsername&#8217; and everything was left exactly like it had been, right down to the desktop wallpaper.</p>
<p>And now I&#8217;m free to decommission two old servers.</p>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2011/03/29/admt-what-i-learned/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Folder Redirection to Mapped Network Drives: Fracking Stupid</title>
		<link>http://laslow.net/2011/03/08/folder-redirection-to-mapped-network-drives-fracking-stupid/</link>
		<comments>http://laslow.net/2011/03/08/folder-redirection-to-mapped-network-drives-fracking-stupid/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 02:10:51 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA["It's a Feature"]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[Makes Sense]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Stupidity]]></category>
		<category><![CDATA[Windows Server]]></category>

		<guid isPermaLink="false">http://www.laslow.net/?p=1140</guid>
		<description><![CDATA[While updating a set of public computers to have private file shares (making use the Home Directory account property in AD to automagically map the drive), I ran in to an issue with folder redirection. I wanted to redirect all of the standard personal folders (Documents, Pictures, Music, et al&#8230;) to the same share, so [...]]]></description>
			<content:encoded><![CDATA[<p>While updating a set of public computers to have private file shares (making use the Home Directory account property in AD to automagically map the drive), I ran in to an issue with folder redirection. I wanted to redirect all of the standard personal folders (Documents, Pictures, Music, et al&#8230;) to the same share, so I setup folder redirection in a Group Policy Object to point those folders to the users home drive (for this example, we&#8217;ll say drive Z: was mapped to \serversharefolder).</p>
<p>I gave the user full rights to the share, and assigned it Owner status as well (all through the Security tab, as standard), and then configured the GPO as appropriate. After rebooting the client computer, however, I checked the Documents folder only to find that it was still pointing at the default location. A quick peek in to Event Viewer revealed the following error:</p>
<blockquote><p>Failed to apply policy and redirect folder &#8220;Documents&#8221; to &#8220;\serversharefolder&#8221;.</p>
<p>Redirection options=0&#215;80009211.</p>
<p>The following error occurred: &#8220;Can not create folder &#8220;\serversharefolder&#8221;".</p>
<p>Error details: &#8220;Access is denied.&#8221;.</p></blockquote>
<p>Which was very strange indeed, as a brief check confirmed that yes, the domain user did in fact have full access to both the folder and the share.</p>
<p>Then, something I saw (and stupidly, ignored) when setting up the GPO came back to me. I fired up the GPO editor and and browsed back to the Documents folder redirection section (User ConfigurationPoliciesWindows SettingsFolder Redirection). After double-clicking the Documents option, and then switching to the Settings tab (shown below), I noticed the top two boxes (&#8220;Grant User Exclusive Rights to Documents&#8221; and &#8220;Move the Contents of Documents to the New Location&#8221;) were selected by default. Given that this was an &#8216;Access Denied&#8217; error, I figured one of these two settings must be at fault, so I unchecked them.</p>
<p><a href="http://www.laslow.net/wp-content/uploads/2011/03/folder_redirection_stupidity.png"><img class="aligncenter size-medium wp-image-1142" title="Folder Redirection Stupidity" src="http://www.laslow.net/wp-content/uploads/2011/03/folder_redirection_stupidity-300x212.png" alt="Folder Redirection Stupidity" width="300" height="212" /></a>After rebooting the client computer, the Documents folder redirected to the Home Drive as expected.</p>
<p>Here&#8217;s where it gets stupid, though. On the &#8216;Target&#8217; tab in the Documents properties window (visible in the screenshot above), if you have the &#8216;Target folder location&#8217; set to &#8216;Redirect to the users home directory&#8217;, it explicitly adds a note that says &#8220;This settings ignores the value of the &#8216;Grant User Exclusive Rights to Documents&#8217;  option on the settings page.</p>
<p>Apparently not, Microsoft. Apparently not.</p>
<p><strong>TL;DR Version: If Folder Redirections aren&#8217;t applying correctly, Event Viewer is showing &#8216;Access Denied&#8217; messages, and you&#8217;re using Home Folders specified in the user account, disable &#8216;Grant User Exclusive Rights to Documents&#8217;  option on the settings page of the GPO. </strong></p>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2011/03/08/folder-redirection-to-mapped-network-drives-fracking-stupid/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Server 2008 R2 and Windows 7 Client SMB2 Share Refresh Issue</title>
		<link>http://laslow.net/2011/01/31/server-2008-r2-and-windows-7-client-smb2-share-refresh-issue/</link>
		<comments>http://laslow.net/2011/01/31/server-2008-r2-and-windows-7-client-smb2-share-refresh-issue/#comments</comments>
		<pubDate>Mon, 31 Jan 2011 17:58:50 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Server 2008 R2]]></category>
		<category><![CDATA[SMB2]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.laslow.net/?p=1125</guid>
		<description><![CDATA[That&#8217;s one heck of a long post title, but it at least describes the issue. Here&#8217;s the setup: 1x Windows Server 2008 R2 with Hyper-V/AD/File Server roles, and two shared folders. Server has dual onboard NICs, one with full access to the client network below, the other to a separate network to allow the server to be [...]]]></description>
			<content:encoded><![CDATA[<p>That&#8217;s one heck of a long post title, but it at least describes the issue. Here&#8217;s the setup:</p>
<ul>
<li>1x Windows Server 2008 R2 with Hyper-V/AD/File Server roles, and two shared folders. Server has dual onboard NICs, one with full access to the client network below, the other to a separate network to allow the server to be managed remotely (no gateway configured on this NIC).</li>
<li>18x Windows 7 x86 clients</li>
<li>Standard network setup (read: no VLANs, bridging, etc&#8230;. Just one network switch).</li>
</ul>
<p>The previous server used by these clients worked perfectly. However, upon replacing the server with the one above, my users began noticing an odd issue. If they copy one or more files/folders to a share that is visible to all of the computers, the file(s) don&#8217;t immediately show up on <em>all</em> of the computers &#8211; usually 3/4 of the computers will see the file(s). On the 1/4 that don&#8217;t, users either have to wait ~10 minutes before the files will appear, or they can reboot to force a refresh. Simply pressing F5, or right-clicking in the shared folder and choosing &#8216;Refresh&#8217; doesn&#8217;t work &#8211; only waiting or rebooting does.</p>
<p>In terms of a solution, I&#8217;ve seen a number of suggestions, but none seem to work. The server has dual-onboard Broadcom Gigabit NICs, and a number of forum posts have suggested disabling Checksum Offload and Large Send Offload, but this made no difference. Neither did disabling IPv6 on the client and server side. Disabling firewalls on the client and server side made no difference, nor did <a href="http://www.vistaheads.com/forums/microsoft-public-windows-vista-file-management/176210-windows-explorer-doesnt-refresh-folder-shares.html" target="_blank">this post suggesting a few registry settings to change</a>.</p>
<p>What did fix the issue, though, was <a href="http://www.petri.co.il/how-to-disable-smb-2-on-windows-vista-or-server-2008.htm" target="_blank">disabling SMB2</a>. Once all of the clients were connecting using the old SMB protocol the issue disappeared. I have no idea why SMB2 is an issue as I haven&#8217;t take the time to troubleshoot further with SMB2-specific settings, however this at least has things running normally.</p>
<p><strong>TL;DR Version:</strong> If you have clients connecting to a Windows Server 2008 R2 box and the contents of file shares aren&#8217;t refreshing immediately or until reboot, disable SMB2 on the server.</p>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2011/01/31/server-2008-r2-and-windows-7-client-smb2-share-refresh-issue/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>IPTABLES Logging on a VPS</title>
		<link>http://laslow.net/2010/10/11/iptables-logging-on-a-vps/</link>
		<comments>http://laslow.net/2010/10/11/iptables-logging-on-a-vps/#comments</comments>
		<pubDate>Tue, 12 Oct 2010 04:19:21 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA[howto]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[VPS]]></category>

		<guid isPermaLink="false">http://www.laslow.net/?p=1036</guid>
		<description><![CDATA[When you manage a *nix-based server, there are a few general guidelines that most admins follow; Doing things like setting a strong root password, changing SSHD to a non-standard port, and setting up logging are usually firsts. However, if you&#8217;re on a VPS, you may run in to a few issues (note that these instructions [...]]]></description>
			<content:encoded><![CDATA[<p>When you manage a *nix-based server, there are a few general guidelines that most admins follow; Doing things like setting a strong root password, changing SSHD to a non-standard port, and setting up logging are usually firsts. However, if you&#8217;re on a VPS, you may run in to a few issues (note that these instructions are for CentOS 5.x and may vary depending on your distro).</p>
<p>For example, when I was setting my the nice new VPS that I&#8217;m running this site from I attempted to enable IPTABLES logging to monitor attempts to get to the standard SSH port (22), and the port that I actually use for SSH (I won&#8217;t post the real one, but for the example I&#8217;ll use port 1234) with the following lines in &#8220;/etc/sysconfig/iptables&#8221;:</p>
<blockquote>
<pre id="_mcePaste"><em>&lt;Snip other rules&gt;</em></pre>
<pre>-A INPUT -m state --state NEW -p tcp -m tcp --dport 1234 -j LOG -m limit --limit 20/m --log-level warn --log-prefix "SSH Attempt on port 1234: "
-A INPUT -p tcp -m tcp --dport 1234 -j ACCEPT</pre>
<pre><em>&lt;Snip even more rules&gt;</em></pre>
<div>
<div>
<pre>-A INPUT -p tcp -m tcp --dport 22 -j LOG -m limit --limit 20/m --log-level warn --log-prefix "Dropped SSH on port 22: "</pre>
<pre>-A INPUT -j DROP</pre>
</div>
</div>
</blockquote>
<div>Note that you need to add the <em>LOG</em> lines<em> </em><strong>before</strong> the <em>ACCEPT</em> and <em>DROP</em> lines.  Only 20 lines will be logged per minute to prevent file sizes from going nuts in case of an attack.</div>
<div>After restarting IPTABLES with <em>service iptables restart</em>, I made a few access attempts and checked /var/log/messages &#8212; no log lines appeared, though. Then I realized I was missing something.</div>
<div>In &#8220;/etc/syslog.conf&#8221; I had to add the following to the end:</div>
<blockquote>
<div>kern.=warn   /var/log/firewall</div>
</blockquote>
<div>I opted to log to <em>firewall</em> instead of <em>messages</em> simply to keep the file clean.</div>
<div>I restarted SYSLOG with <em>service syslog restart</em>, made a few more attempts, and still nothing was appearing in &#8220;/var/log/firewall&#8221; or &#8220;/var/log/messages&#8221;. However, typing <em>dmesg</em> showed the relevant lines:</div>
<blockquote>
<div>SSH Attempt on port 1234: IN=venet0 OUT= MAC= SRC=10.0.0.1 DST=10.0.0.2 LEN=48 TOS=0&#215;00 PREC=0&#215;00 TTL=116 ID=28979 DF PROTO=TCP SPT=35291 DPT=1234 WINDOW=8192 RES=0&#215;00 SYN URGP=0</div>
</blockquote>
<div>So I knew that SYSLOG was working, however it wasn&#8217;t going all the way. Then I decided to see if KLOGD was running:</div>
<blockquote>
<div>[root@vps ~]# ps aux|grep klogd</div>
<div>root     13632  0.0  0.1   7188   788 pts/0    S+   00:07   0:00 grep klogd</div>
</blockquote>
<div>So that means that KLOGD isn&#8217;t running, which is the cause of the problem! I checked &#8220;/etc/rc.d/init.d/syslog&#8221; and found that the KLOGD lines were commented out, as such:</div>
<blockquote>
<div><em>&lt;snip&gt;</em></div>
<div><em> </em>passed klogd skipped #daemon klogd $KLOGD_OPTIONS</div>
<div><em>&lt;snip&gt;</em></div>
<div><em> </em>passed klogd skipped #killproc klogd</div>
</blockquote>
<div>In the &#8220;start()&#8221; and &#8220;stop()&#8221; areas respectively. I simply removed the &#8220;<em>passed klogd skipped #</em>&#8221; parts, saved and ran <em>service syslog restart</em> and presto, KLOGD was up and running:</div>
<blockquote>
<div>
<div>[root@vps ~]# ps aux|grep klogd</div>
<div>root      7542  0.0  0.0   3808   424 ?        Ss   Oct11   0:00 klogd -x</div>
<div>root     15402  0.0  0.1   7188   788 pts/0    S+   00:13   0:00 grep klogd</div>
</div>
</blockquote>
<div>I made a few more connection attempts and verified that now everything was working correctly:</div>
<blockquote>
<div>
<div>[root@vps ~]# cat /var/log/firewall</div>
<div>Oct 11 23:47:06 vps kernel: SSH Attempt on port 1234: IN=venet0 OUT= MAC= SRC=10.0.0.1 DST=10.0.0.2 LEN=48 TOS=0&#215;00 PREC=0&#215;00 TTL=116 ID=28979 DF PROTO=TCP SPT=35291 DPT=1234 WINDOW=8192 RES=0&#215;00 SYN URGP=0</div>
<div>Oct 12 00:13:03 vps kernel: Dropped SSH on port 22: IN=venet0 OUT= MAC= SRC=110.77.129.166 DST=10.0.0.2 LEN=60 TOS=0&#215;00 PREC=0&#215;00 TTL=45 ID=59383 DF PROTO=TCP SPT=33846 DPT=22 WINDOW=5840 RES=0&#215;00 SYN URGP=0</div>
</div>
</blockquote>
<div>Done and done! IPTABLES now properly logs to &#8220;/var/log/firewall&#8221; when someone attempts to hit port 22 or 1234.</div>
<blockquote>
<div><strong>TL;DR Version: If you want IPTABLES logging enabled on your VPS, follow the normal steps to enable IPTABLES logging and then make sure KLOGD is enabled in  &#8221;/etc/rc.d/init.d/syslog&#8221;.</strong></div>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2010/10/11/iptables-logging-on-a-vps/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Updated x4: The Non-Existent State of IPv6 in Canada</title>
		<link>http://laslow.net/2010/07/25/the-non-existent-state-of-ipv6-in-canada/</link>
		<comments>http://laslow.net/2010/07/25/the-non-existent-state-of-ipv6-in-canada/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 02:49:54 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Shaw Cable]]></category>
		<category><![CDATA[Telus]]></category>

		<guid isPermaLink="false">http://www.laslow.net/?p=962</guid>
		<description><![CDATA[Further Update (06/27/2011): If you have a Dlink DIR-825 router, I just published an article on getting a free Tunnel Broker IPv6 tunnel account working. Check it out! If you have a router that is cable of an IPv6 over IPv4 tunnel, or just want to use a single computer, check out Tunnel Broker from [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Further Update (06/27/2011): </strong>If you have a Dlink DIR-825 router, I just published an article on getting <a href="https://laslow.net/2011/06/27/ipv6-over-an-ipv4-tunnel-on-a-dlink-dir-825-rev-b/" target="_blank">a free Tunnel Broker IPv6 tunnel account working</a>. Check it out! If you have a router that is cable of an IPv6 over IPv4 tunnel, or just want to use a single computer, check out <a href="http://tunnelbroker.com/" target="_blank">Tunnel Broker</a> from <a href="http://he.net/" target="_blank">Hurricane Electric</a>.</p>
<p>Over the last few days I&#8217;ve been attempting to gather information on <a href="http://en.wikipedia.org/wiki/IPv6" target="_blank">IPv6</a> in Canada, and so far the news is grim. Why am I looking in to it? Well, there have been <a href="http://blogs.computerworld.com/15966/as_ipv4_addresses_run_out_fears_of_ip_cybersquatting_increase" target="_blank">a number</a> of <a href="http://tech.slashdot.org/story/10/04/24/1743244/What-Happens-When-IPv4-Address-Space-Is-Gone" target="_blank">articles posted lately</a> about the impending <a href="http://en.wikipedia.org/wiki/IPv4_address_exhaustion" target="_blank">end of available IPv4 addresses</a> and the <a href="https://wiki.bc.net/atl-conf/display/BCNETPUBLIC/2009/05/27/IPv6+Deployment+-+BCNET,+Canada+and+the+World" target="_blank">sorry state of IPv6 addoption</a>, and I wanted to check in on my local ISPs and see if any of them are preparing for this. The short answer? No.</p>
<p>My region has two primary ISPs &#8211; <a href="http://www.telus.com" target="_blank">Telus</a> and <a href="http://www.shaw.ca" target="_blank">Shaw Cable</a>. I did a quick Google search to see if either had made any announcements about IPv6 readiness, and I ended up with no relevant results. In fact, a search of &#8220;IPv6&#8243; on the domain shaw.ca only returns results on user hosted pages. Searching Google for &#8220;IPv6 Telus&#8221; only comes up with one close match &#8211; <a href="ttps://wiki.bc.net/atl-conf/download/attachments/23760004/2009+11+IPv6+Intro+-+GHolan.pdf?version=1&amp;modificationDate=1257733161000" target="_blank">this PDF document that&#8217;s basically a beginners guide to IPv6</a>.</p>
<p>So, I opened a ticket with my ISP (Shaw), and tweeted at their customer care guys. I also tweeted at Telus&#8217; customer care. Here&#8217;s what I got back.</p>
<p><a href="http://twitter.com/TELUSsupport/status/19527637693" target="_blank">Telus tweeted back pretty quickly</a>:</p>
<blockquote><p>@<a rel="nofollow" href="http://twitter.com/laslow" target="_blank">laslow</a> We don&#8217;t have any news on implementation of IPv6. It would make sense that everyone will switch eventually. -Trevor @<a rel="nofollow" href="http://laslow.net/TELUSSupport" target="_blank">TELUSSupport</a></p></blockquote>
<p><a href="http://twitter.com/laslow/status/19527968573" target="_blank">I replied</a>, and they came back with this:</p>
<blockquote><p>@<a rel="nofollow" href="http://twitter.com/laslow" target="_blank">laslow</a> We&#8217;ll try and help where we can but no real info on this. Hope your day goes well!</p></blockquote>
<p>Well, that was rather uninformative.</p>
<p>Sean from Shaw Customer Care <a href="http://twitter.com/Shaw_Sean/status/19509552145" target="_blank">also replied rather quickly on Twitter</a>:</p>
<blockquote><p>@<a rel="nofollow" href="/laslow">laslow</a> hey man, no word on IPv6 yet, hopefully sometime in the near future though.</p></blockquote>
<p>Shortly after, I received the following reply to the ticket that I opened with Shaw:</p>
<blockquote><p>Hello [Laslow],</p>
<p>This is [Agent], thank you for your e-mail.</p>
<p>At this time there is no set date that IPv6 will start to be used. As soon as address’s have ran out with IPv4 then everything would be switched over to the IPv6. Kind of like how in B.C. not including the lower mainland we have been using the area code 250 for years. There are no longer numbers available with the 250 area code so they moved to 778 area codes. It will be similar to this when IPv6 is released, sorry we have no further information for you at this time on this.</p></blockquote>
<p>So in short, Shaw&#8217;s plans are to wait until they&#8217;ve run out addresses, and then worry about what to do next. I don&#8217;t know about you, but I&#8217;m <em>definitely</em> feeling more confident that Shaw will be able to connect me to IPv6-only services in the next, you know, ten years or so.</p>
<p>Honestly, though, there are a number of ISPs in the states that already have public IPv6 tests available (<a href="http://www.comcast6.net/" target="_blank">Comcast</a>, for example) &#8211; why is Canada so far behind?</p>
<p>If anyone reading this works for Telus or Shaw and has more information on their progress towards IPv6, please leave a comment or send me a tweet &#8211; It would be nice to know if there are at least <em>plans</em> in place rather than just a sense of &#8220;we&#8217;ll cross that bridge when we get there&#8221;.</p>
<p><strong>Updated (11/29/2010):</strong></p>
<p>I contacted <a href="https://twitter.com/#!/laslow/status/9423905143918592" target="_blank">Shaw</a>, <a href="https://twitter.com/#!/laslow/status/9424035322527744" target="_blank">Telus</a>, and <a href="https://twitter.com/#!/laslow/status/9424539758895104" target="_blank">Rogers</a> via twitter again and received the following responses (still waiting to hear from Shaw):</p>
<blockquote><p>@<a rel="nofollow" href="http://twitter.com/laslow" target="_blank">laslow</a> At this time we do not have any information/news &#8211; Ryan with @<a rel="nofollow" href="http://twitter.com/TELUSSupport" target="_blank">TELUSSupport</a> (<a href="https://twitter.com/#!/TELUSsupport/status/9424625486274560" target="_blank">Direct link to tweet</a>)</p></blockquote>
<p><a rel="nofollow" href="http://twitter.com/TELUSSupport"></a>And:</p>
<blockquote><p>@<a rel="nofollow" href="http://twitter.com/laslow" target="_blank">laslow</a> Hi Laslow. I have no info &#8211; but can ask around tomorrow. I&#8217;ll get back to you if I get an update. (via @<a title="Elise Ondet" href="https://twitter.com/#!/RogersElise" target="_blank">RogersElise</a> - <a href="https://twitter.com/#!/RogersElise/status/9431775495323648" target="_blank">Direct link to tweet</a>)</p></blockquote>
<p>I&#8217;ll post any additional information I receive as I get it.</p>
<p><strong>Updated (11/30/2010</strong>):</p>
<p>Shaw responded this morning with the following (still no additional information back from Rogers):</p>
<blockquote><p>@<a rel="nofollow" href="http://twitter.com/laslow" target="_blank">laslow</a> yes, it&#8217;s in the pipeline, however, no confirmed release dates yet. (via @<a href="https://twitter.com/#!/Shaw_Sean" target="_blank">Shaw_Sean</a> &#8211; <a href="https://twitter.com/#!/Shaw_Sean/status/9677165478027264" target="_blank">Direct link to tweet</a>)</p></blockquote>
<p>So we have at least one ISP that will willing to publicly state that they have plans to deploy IPv6. Still, solid details would be welcome.</p>
<p><strong>Updated (02/01/2011):</strong></p>
<p>You can check to see if your ISP has IPv6 Prefixes using <a href="http://bgp.he.net" target="_blank">this site</a>. If they do (I can confirm Shaw and Telus do, haven&#8217;t checked others yet), it shows that they have IPv6 connectivity with the rest of the world. If not&#8230;well, it might be time to panic. <a href="https://twitter.com/#!/laslow/status/32569816229347328" target="_blank">I bugged Shaw again via Twitter about IPv6</a>, and got <a href="https://twitter.com/#!/Shaw_Sean/status/32593611908456448" target="_blank">this response</a>:</p>
<blockquote><p>@<a rel="nofollow" href="http://twitter.com/laslow" target="_blank">laslow</a> I honestly have no idea, but I&#8217;ll make sure you&#8217;re the first to know should I hear something.</p></blockquote>
<p>So, I&#8217;ll update again when I hear more.</p>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2010/07/25/the-non-existent-state-of-ipv6-in-canada/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Windows Cannot Connect to the Printer: 0x0000007e/0&#215;00000006</title>
		<link>http://laslow.net/2010/05/27/windows-cannot-connect-to-the-printer-0x0000007e0x00000006/</link>
		<comments>http://laslow.net/2010/05/27/windows-cannot-connect-to-the-printer-0x0000007e0x00000006/#comments</comments>
		<pubDate>Thu, 27 May 2010 18:46:13 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA["It's a Feature"]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Printers]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.laslow.net/?p=774</guid>
		<description><![CDATA[Note: Make sure to read over the comments on this post &#8211; there is some excellent advice there as well. Windows 7 has been very good to me so far, but this morning I was literally pounding my desk in frustration over a printer issue. I just received two brand-new Dell Optiplex 780&#8242;s and was in the [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_778" class="wp-caption alignright" style="width: 160px"><a href="http://www.laslow.net/wp-content/uploads/2010/05/hp4015n.jpg"><img class="size-medium wp-image-778 " title="HP P4015dn" src="http://www.laslow.net/wp-content/uploads/2010/05/hp4015n-300x300.jpg" alt="An HP P4015dn - This morning, the bane of my existence" width="150" height="150" /></a><p class="wp-caption-text">An HP P4015dn - This morning, the bane of my existence</p></div>
<p><span style="color: #ff0000;">Note: Make sure to read over the comments on this post &#8211; there is some excellent advice there as well.</span></p>
<p>Windows 7 has been very good to me so far, but this morning I was literally pounding my desk in frustration over a printer issue. I just received two brand-new Dell Optiplex 780&#8242;s and was in the process of configuring the printers on them when I happened across this little message:</p>
<blockquote><p><em>Windows Cannot Connect to the Printer: 0x0000007e</em></p></blockquote>
<p>Now here&#8217;s the situation. The computers are running Windows 7 Professional x64. The printer (an HP P4015dn) is connected to a Windows XP x86 machine and shared normally. Of all of our printers, this is the only one directly shared with a computer due to a wiring issue I have yet to correct (although now I&#8217;m going to make an effort to fix it). I have several other computers running XP and Vista (x86 and x64) that already print this computer without issue, so I was rather stumped. Then I realized I had attempted to install the Vista x64 Postscript drivers instead of the Windows 7 ones.</p>
<p>Unfortunately, Windows 7 no longer provides a dedicated &#8216;Printers&#8217; control panel, and the &#8216;Devices and Printers&#8217; one doesn&#8217;t have a Server Properties option to let you manage installed drivers. So, I stopped the <em>print spooler</em> service and manually deleted the drivers from <em>C:\Windows\System32\spool\Drivers</em>. When I tried to re-add the printer, though, I got this message:</p>
<blockquote><p><em>Windows Cannot Connect to the Printer: 0&#215;00000006</em></p></blockquote>
<p>Hmm. Google wasn&#8217;t much help, so I went to an old standby &#8211; I mannually added the network printer by choosing to create a local port (silly, I know). Here&#8217;s how to get this working:</p>
<ol>
<li>In the <em>Devices and Printers</em> control panel, choose <em>Add a Printer</em>.</li>
<li>In the new window, click <em>Add a local printer</em>.</li>
<li>On the following screen, select <em>Create a new port</em>, and then choose <em>Local Port</em> from the drop-down list and click <em>Next.</em></li>
<li>When asked to enter a <em>Port Name</em>, use the full path to the printer. For example, if your printer share is called <em>Dave</em> and is a computer with the name <em>PrintSrv1</em>, you would enter <em>\PrintSrv1Dave</em> as the <em>Port Name</em>. If you receive an error saying <em>The network path was not found</em>, check the computer name and share name, then try again.</li>
<li>You should be asked to install a driver. Manually download the correct driver (in this case, the <em>HP Universal PostScript</em> driver worked for my <em>HP P4015dn</em>) from the manufacturer&#8217;s website and extract it to a folder on your computer. Then click the <em>Have Disk&#8230;</em> button in the <em>Add Printer</em> wizard and point it to that folder, then click <em>OK </em>and <em>Next</em>.</li>
<li>Wait for it to install the driver.</li>
</ol>
<p>At this point, the printer should be installed and functional. Print a test page to make sure everything worked alright, and then do a little dance (as long as no one is looking)!</p>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2010/05/27/windows-cannot-connect-to-the-printer-0x0000007e0x00000006/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Updated: Office Apps Stuck on Downloading Files from Network Shares</title>
		<link>http://laslow.net/2010/05/19/office-apps-stuck-on-downloading-files-from-network-shares/</link>
		<comments>http://laslow.net/2010/05/19/office-apps-stuck-on-downloading-files-from-network-shares/#comments</comments>
		<pubDate>Wed, 19 May 2010 19:19:32 +0000</pubDate>
		<dc:creator>Laslow</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Office 2007]]></category>
		<category><![CDATA[Office 2010]]></category>

		<guid isPermaLink="false">http://www.laslow.net/?p=708</guid>
		<description><![CDATA[For a while now I was having problems opening Word and Excel (2007 and 2010) documents on my work computer. Most of the time everything would work, but every now-and-again I&#8217;d go to open something and Word or Excel would report that it was &#8220;Downloading &#60;filename&#62;&#8221;, and simply get stuck. Although I could click the [...]]]></description>
			<content:encoded><![CDATA[<p>For a while now I was having problems opening Word and Excel (2007 and 2010) documents on my work computer. Most of the time everything would work, but every now-and-again I&#8217;d go to open something and Word or Excel would report that it was &#8220;Downloading &lt;filename&gt;&#8221;, and simply get stuck. Although I could click the little &#8216;X&#8217; to cancel and close the window, the process for either Word or Excel would stay active, and any attempts to kill it would fail. In the end, I&#8217;d have to hard power off the computer to get it to shutdown, and then do a cold boot.</p>
<div id="attachment_731" class="wp-caption aligncenter" style="width: 387px"><a href="http://www.laslow.net/wp-content/uploads/2010/05/downloading.png"><img class="size-full wp-image-731" title="Downloading...." src="http://www.laslow.net/wp-content/uploads/2010/05/downloading.png" alt="'Downloading' an Excel Workbook" width="377" height="46" /></a><p class="wp-caption-text">Oh, &#39;Downloading&#39; message, how I hate thee.</p></div>
<p>I wasn&#8217;t really bothered by it until a few of my users started reporting the same problem. I had a look in to it, and after a lot of fiddling, came across two Microsoft Knowledge Base articles that eventually led me to a solution.</p>
<blockquote><p><a href="http://support.microsoft.com/kb/833041" target="_blank">An Office program is slow or may appear to stop responding (hang) when you open a file from a network location</a></p>
<p><a href="http://support.microsoft.com/kb/313937" target="_blank">The program stops responding when you try to open or to save a file in an Office 2002 program, in an Office 2003 program and in an Office 2007 program</a></p></blockquote>
<p>By adding the registry value from the first KB article linked above (EnableShellDataCaching), and by removing the Group Policy object that was creating a persistent drive mapping and replacing it with a login script (below) to map the drive, I haven&#8217;t had any further reports of the problem.</p>
<blockquote><p>REM Login Script &#8211; Paste these lines in to a batch file, and add that .bat file to a GPO</p>
<div id="_mcePaste">net use z: /delete</div>
<div id="_mcePaste">net use z: \10.0.0.100share</div>
</blockquote>
<div>Note the use of the IP Address, rather than the Fully Qualified Domain Name (FQDN) &#8211; this was essential to getting things working in the end.</div>
]]></content:encoded>
			<wfw:commentRss>http://laslow.net/2010/05/19/office-apps-stuck-on-downloading-files-from-network-shares/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

