• No results found

Syngress Mission Critical! Windows 2000 Server Administr pdf

N/A
N/A
Protected

Academic year: 2020

Share "Syngress Mission Critical! Windows 2000 Server Administr pdf"

Copied!
753
0
0

Loading.... (view fulltext now)

Full text

(1)

FREE Monthly

Technology Updates

One-year Vendor

Product Upgrade

Protection Plan

FREE Membership to

Access.Globalknowledge

If it’s a

high-risk, high-impact,

must-not-fail situation,

it’s MISSION CRITICAL!

Robin Walshaw, MCSE

Technical Editor:

D. Lynn White, MCPS, MCSE, MCT, MCP+I

”This book is perfect for administrators who

need an advanced Windows 2000 reference.

I will turn to it again and again.“

–Eric Livingston,

(2)

With over 1,500,000 copies of our MCSE, MCSD, CompTIA, and Cisco

study guides in print, we have come to know many of you personally. By

listening, we've learned what you like and dislike about typical computer

books. The most requested item has been for a web-based service that

keeps you current on the topic of the book and related technologies. In

response, we have created

[email protected]

, a service that

includes the following features:

A one-year warranty against content obsolescence that occurs as

the result of vendor product upgrades. We will provide regular web

updates for affected chapters.

Monthly mailings that respond to customer FAQs and provide

detailed explanations of the most difficult topics, written by content

experts exclusively for

[email protected]

.

Regularly updated links to sites that our editors have determined

offer valuable additional information on key topics.

Access to “Ask the Author”™ customer query forms that allow

readers to post questions to be addressed by our authors and

editors.

Once you've purchased this book, browse to

www.syngress.com/solutions

.

To register, you will need to have the book handy to verify your purchase.

Thank you for giving us the opportunity to serve you.

(3)
(4)

M I S S I O N C R I T I C A L !

(5)

Syngress Publishing, Inc., the author(s), and any person or firm involved in the writing, editing, or production (collectively “Makers”) of this book (“the Work”) do not guarantee or warrant the results to be obtained from the Work.

There is no guarantee of any kind, expressed or implied, regarding the Work or its contents. The Work is sold AS IS and WITHOUT WARRANTY. You may have other legal rights, which vary from state to state.

In no event will Makers be liable to you for damages, including any loss of profits, lost savings, or other inci-dental or consequential damages arising out from the Work or its contents. Because some states do not allow the exclusion or limitation of liability for consequential or incidental damages, the above limitation may not apply to you.

You should always use reasonable case, including backup and other appropriate precautions, when working with computers, networks, data, and files.

Syngress Media® and Syngress® are registered trademarks of Syngress Media, Inc. “Career Advancement Through Skill Enhancement™,” “Ask the Author™,” “Ask the Author UPDATE™,” and “Mission Critical™” are trademarks of Syngress Publishing, Inc. Brands and product names mentioned in this book are trademarks or service marks of their respective companies.

KEY SERIAL NUMBER 001 9TATW2ADSE 002 NF4TRA7TC4 003 CDE3C28FV7 004 DC5C8NVT4N 005 Z745QQE2BR 006 PF62RT652H 007 DTP252ZX44 008 NT3F743RTG 009 6532M977LS 010 SMWR8P554N

PUBLISHED BY

Syngress Publishing, Inc. 800 Hingham Street Rockland, MA 02370

Mission Critical Windows 2000 Server Administration

Copyright © 2000 by Syngress Publishing, Inc. All rights reserved. Printed in the United States of America. Except as permitted under the Copyright Act of 1976, no part of this publication may be reproduced or dis-tributed in any form or by any means, or stored in a database or retrieval system, without the prior written per-mission of the publisher, with the exception that the program listings may be entered, stored, and executed in a computer system, but they may not be reproduced for publication.

Printed in the United States of America

1 2 3 4 5 6 7 8 9 0

ISBN: 1-928994-16-4

Copy edit by: Beth Roberts Proofreading by: Fred Lanigan

Technical edit by: D. Lynn White Page Layout and Art by: Reuben Kantor Index by: Robert Saigh and Shannon Tozier

Co-Publisher: Richard Kristof

(6)

v

Acknowledgments

We would like to acknowledge the following people for their kindness and sup-port in making this book possible.

Richard Kristof, Duncan Anderson, Jennifer Gould, Robert Woodruff, Kevin Murray, Dale Leatherwood, Rhonda Harmon, and Robert Sanregret of Global Knowledge, for their generous access to the IT industry’s best courses, instructors and training facilities.

Ralph Troupe and the team at Callisma for their invaluable insight into the challenges of designing, deploying and supporting world-class enterprise net-works.

Karen Cross, Kim Wylie, Harry Kirchner, John Hays, Bill Richter, Kevin Votel, Brittin Clark, Sarah Schaffer, Ellen Lafferty and Sarah MacLachlan of

Publishers Group West for sharing their incredible marketing experience and expertise.

Mary Ging, Caroline Hird, and Simon Beale of Harcourt International for making certain that our vision remains worldwide in scope.

Annabel Dent, Anneka Baeten, Clare MacKenzie, and Laurie Giles of Harcourt Australia for all their help.

David Buckland, Wendi Wong, David Loh, Marie Chieng, Lucy Chong, Leslie Lim, Audrey Gan, and Joseph Chan of Transquest Publishers for the enthu-siasm with which they receive our books.

Kwon Sung June at Acorn Publishing for his support.

Ethan Atkin at Cranbury International for his help in expanding the Syngress program.

Special thanks to the professionals at Osborne with whom we are proud to publish the best-selling Global Knowledge Certification Press series.

(7)

vi

From Global Knowledge

At Global Knowledge we strive to support the multiplicity of learning styles required by our students to achieve success as technical professionals. As the world's largest IT training company, Global Knowledge is uniquely positioned to offer these books. The expertise gained each year from pro-viding instructor-led training to hundreds of thousands of students world-wide has been captured in book form to enhance your learning experience. We hope that the quality of these books demonstrates our commitment to your lifelong learning success. Whether you choose to learn through the written word, computer based training, Web delivery, or instructor-led training, Global Knowledge is committed to providing you with the very best in each of these categories. For those of you who know Global Knowledge, or those of you who have just found us for the first time, our goal is to be your lifelong competency partner.

Thank your for the opportunity to serve you. We look forward to serving your needs again in the future.

Warmest regards,

Duncan Anderson

(8)

vii

About the Author

Robin Walshaw(B.Sc Computer Science, MCSE, DPPM) is an independent consultant who delivers strategic Windows 2000 solutions to large corpora-tions around the globe. Born in England, Robin spent the majority of his ear-lier years in Scotland and South Africa. One of the first MCSEs in Africa, he enjoys being at the forefront of new developments in network and operating system architecture.

With a flair for developing strategic IT solutions for diverse clients, he has worked in the world of computers in eight countries, and has traveled to over thirty countries in the last ten years. A veteran of numerous global pro-jects, Robin has honed his skills across of a wide variety of platforms and technologies.

Though an industrious computer professional by day, by ‘night’ Robin is an experienced mountain guide. Robin is a keen sportsman and has man-aged to balance work with a passion for climbing the world’s highest moun-tains, culminating in an attempt on the North Ridge of Mount Everest.

(9)

viii

Contributors

Melissa Craft(CCNA, MCSE, Network+, CNE-3, CNE-4, CNE-5, CNE-GW, MCNE, Citrix) is a Director of e-Business Offering Development for MicroAge. MicroAge is a global systems integrator headquartered in Tempe, Arizona. MicroAge provides IT design, project management and support for distributed computing systems. Melissa develops enterprise-wide technology solutions and methodologies for client organizations. These technology solutions touch every part of a system’s lifecycle—from network design, testing and implementation to operational management and strategic planning. Melissa holds a bachelor’s degree from the University of Michigan and is a member of the IEEE, the Society of Women Engineers and American MENSA, Ltd. Melissa currently resides in Phoenix, Arizona with her family, Dan, Justine and Taylor, and her two dogs, Marmaduke and Pooka.

Debra Littlejohn Shinder (MCSE, MCP+I, MCT) is an Instructor in the AATP program at Eastfield College, Dallas County Community College District, where she has taught since 1992. She is Webmaster for the cities of Seagoville and Sunnyvale, Texas, as well as the family Web site at www.shinder.net. She and her husband, Dr. Thomas W. Shinder, provide consulting and technical support services to Dallas area organizations. She is also the proud mom of a daughter, Kristen, who is currently serving in the U.S. Navy in Italy, and a son, Kris, who is a high school chess champion. Deb has been a writer for most her life, and has published numerous articles in both technical and non-technical fields. She can be contacted at [email protected].

(10)

ix

Technical Editor

D. Lynn White(MCPS, MCSE, MCT, MCP+I) is President of Independent Network Consultants, Inc. Lynn has more than 14 years experience in net-working and programming. She has been a system manager in the mainframe environment as well as a software developer for a process control company. She is a technical author, editor, trainer, and consultant in networking and computer-related technologies. Lynn has been delivering mainframe,

(11)
(12)

Contents

xi

Chapter 1: Introduction to Windows 2000 Server

1

Introduction 2 What’s New in Windows 2000 Server? 3 The Key to Unlocking Your Network: Active Directory 5 Why Should I Use the Active Directory? 6 Change and Configuration Management 7

Group Policies 10

Windows 2000 Security 11

Why the Change? 12

Differences in Windows 2000 Server Security 12 Windows 2000 Network Services 13 Managing and Supporting Windows 2000 Server 14 Integrated Directory Services 15 Comprehensive Management Solutions 15 Comprehensive File, Print, and Web Services 17 What’s Not New in Windows 2000 Server? 20

Core Architecture 21

Application Support 21

User Interface 21

Client Support 22

Windows 2000 Challenges 22

Summary 24 FAQs 25

Chapter 2: Active Directory—The Heart of

Windows 2000 Server

27

Introduction 28 Mission-Critical Active Directory Concepts 29

Where Active Directory Fits in the Overall Windows

2000 Architecture 30

Active Directory Concepts 30

What’s in a Name? 30

(13)

Developing a Naming Strategy 40 Active Directory’s Integration with DNS 41 How Active Directory Uses DNS 43

Forest Plan 45

Domain and DNS Strategy 48

Organizational Units (OUs) 49

Site Topology 52

Naming Conventions 53

Defining DNS Names 53

Defining DNS Zones 55

Naming Conventions for Active Directory 55

Virtual Containers 56

Designing Active Directory Domains 56

Forest Plan 58

Domain Plan Including DNS Strategy 58

Organizational Unit Strategy 60

Organizational Unit Structure 60

OU Objects in the Active Directory 60

Group Policy and OUs 60

Delegating Administration 61

Site Topology 62

Summary 63 FAQs 64

Chapter 3: Migrating to Windows 2000 Server

67

Introduction 68

Server Migration Strategies 69

Primary Domain Controllers (PDCs) 76 Changes Required when Upgrading a

Domain Controller 78

Backup Domain Controllers (BDCs) 79

Member Servers 81

Promoting Member Servers with DCPROMO 81 Upgrading with the Windows 2000 Setup Wizard 82 Installing Active Directory Services 84

Interim Mixed Domains 87

Mixed Mode 88

Native Mode 88

Migrating Components 90

Using Organizational Units (OUs) to Create a

Hierarchical Structure 91

User Accounts 92

(14)

Nested Groups 94

Global Groups 95

Delegating Administrative Authority 95 Insert into the Replication Topology 96 Migrating from Novell Directory Services 97 Upgrade Clients to Windows 2000 Professional 98 Summary 100 FAQs 102

Chapter 4: Implementing Domains, Trees

and Forests

103

Introduction 104

Implementing a Domain 104

Installing the First Domain in Active Directory 105

Active Directory Wizard 106

Integrating DNS into the Active Directory 110

Configuring DNS 111

Active Directory Integrated Zones 112

About Zones 112

Service Resource Record Registration 114

Creating Organizational Units 114

Managing Objects in Active Directory 115

Managing User Accounts 116

Managing Groups 117

Managing Computers 119

Managing Shares 120

Managing Printers 121

Common Object Management 122

Nesting Groups 122

Role-Based Administration 123

Microsoft Management Console 123

Administrative Roles 123

Delegating Administration 124

Object-Based Access Control 126

Building Trees and Forests 127

Forest Characteristics 128

Common Schema 128

Common Configuration 128

Global Catalog 128

Contiguous Namespace 129

Trust Relationships 129

Planning a Forest Structure 134

The Domain Tree Structure 137

(15)

Sizing the Active Directory Store 139

Managing the Forest 142

Summary 145 FAQs 147

Chapter 5: Planning and Implementing Active

Directory Sites

149

Introduction 150 The Function of Sites in Active Directory 150 Default-First-Site-Name 153 Replicated Active Directory Components 153

Domain Partitions 153

Global Catalog 154

Schema and Configuration Containers 155

Modifying the Schema 155

Configuring Site Replication Components 166

Creating Site Objects 166

Creating Connection Objects 167

Creating Site Links 167

Creating Site Link Bridges 168

Replication Protocols 169

Replication in Active Directory 170

Replication Topology 171

Planning a Site Structure 174

Placing Domain Controllers 177

Where to Place Global Catalog Servers 177 Implementing a Site Structure in Active Directory 178

Replication Utilities 183

Replication Monitor (REPLMON) 183

Replication Administrator (REPADMIN) 183 DSASTAT 183 Understanding Time Synchronization in Active Directory 184 Summary 185 FAQs 187

Chapter 6: Advanced Active Directory

189

Introduction 190 Interfacing with Active Directory 190 ADSI 190 RPC 192

Windows Sockets 192

(16)

Microsoft’s Metadirectory 195

VIA Architecture 199

Implementing a Disaster Recovery Plan 200 Modeling Sites with Disaster Recovery in Mind 201 The Active Directory Database File Structure 204 Backup 205 Creating an Emergency Repair Disk 206 Recovering a Failed Domain Controller 208 Authoritative Restore of Deleted Objects 208

Startup Options 209

The Recovery Console 210

For Experts 211

PDC Emulation and Native Mode 211

How Active Directory Prevents Unnecessary

Replication 212 How an LDAP Query Accesses Active Directory 213

Renaming Domains 214

Add a Server to Two Different Sites Simultaneously 214

Removing Phantom Objects 215

Phantom Domains 215

Transferring FSMO Roles 216

Troubleshooting Tips 219

Avoiding Errors When Migrating a Domain 220 Remote Procedure Call (RPC) Errors 220 Summary 221 FAQs 222

Chapter 7: Configuring IntelliMirror

223

Introduction 224

What Is IntelliMirror? 224

Configuring Group Policies 226

How Group Policies Are Applied 229

Refresh Interval 230

Blocking and Enforcing 230

Group Policy Information Storage 231

Administrative Templates 232

Registry.pol 233

Group Policy Settings 233

Computer Configuration 235

User Configuration 235

(17)

Link a Group Policy Object to a Container 241 Keeping Groups from Growing Over Time 242 Delegating Control of Group Policy 243

Troubleshooting Group Policies 245

Policy Does Not Execute 245

Policy Executes in the Wrong Way 246

Logging On Takes a Long Time 246

Security 247

Groups 247

Group Strategy 249

Viewing Security Features in Active Directory

Users and Computers 250

Domain Security Console 250

Account Policies 250

Local Policies 254

Event Log 254

Restricted Groups 255

System Services 255

Registry 255

File System 255

Public Key Policies 256

IP Security Policies on Active Directory 256

Security Templates 256

Object Protection 256

Access Control Lists (ACLs) 256

Access Control Entries (ACEs) 257

Security Descriptor 258

Security Identifier (SID) 259

Summary 260 FAQs 261

Chapter 8: Managing Settings, Software, and User

Data with IntelliMirror

263

Introduction 264 Deploying Software with Group Policies 264

Assigning Software 265

User Assignments 265

Computer Assignments 266

Publishing Software 266

Enhancements within Add/Remove Programs 266

Packaging an Application 268

Windows Installer 269

Creating a Package 272

(18)

ZAP Files 273

Customizing a Package 273

Creating Distribution Points 274

Targeting Software and Using the Software

MMC Snap-In 274

Using the Software Policy MMC Snap-In 275 Using Group Policy to Assign or Publish

an Application 276

Managing Software with Group Policies 277

Upgrading Software 278

Upgrading Windows 2000 279

Removing Software 280

Redeploying Software 281

Software Installation Options 281

Group Policy Settings 283

Application Deployment Walkthrough 285

Deployment Methods 287

Managing User and Computer Settings 287

Using Administrative Templates 288

Assigning Registry-Based Policies 290 Creating Custom Administrative Templates 293 Adding Administrative Templates 299

Using Scripts 300

Assigning Script Policies to Users and Computers 301

Folder Redirection 303

Summary 305 FAQs 306

Chapter 9: Managing Users and Groups

309

Introduction 310

Setting Up User Accounts 310

Defining an Acceptable Use Policy 310 Requirements for New User Accounts 312

Default User Account Settings 313

Logon Mechanics 313

Creating User Accounts 314

Setting Account Policies 315

Account Policy Configuration 315

Modifying Properties for User Accounts 317

Managing User Accounts 319

Deleting User Accounts 319

Resetting Passwords 319

Disabling an Account 320

(19)

Other Active Directory Users and Computers

Functions 320

Moving User Accounts 320

Mapping a Certificate to a User 321 Using Groups to Organize User Accounts 323

Group Types 323

Security Groups 323

Distribution Lists 324

Group Scope 324

Local 324

Domain Local 325

Global 325 Universal 325

Implementing Groups 326

Creating a Group 328

Assigning Users to a Group 328

Adding Users through Group Settings 328

Configuring Group Settings 328

Managing Groups 329

Changing a Group’s Scope 330

Deleting Groups 330

Implementing Local Groups 331

Preparing to Create Local Groups 331

Creating a Local Group 331

Implementing Built-in Groups 332

Built-In Group Behavior 332

Groups—Best Practices 335

Administering User Accounts 336

User Profiles Overview 337

Types of User Profiles 337

Contents of a User Profile 338

Settings Saved in a User Profile 339

Local User Profiles 340

Roaming User Profiles 340

Creating Individualized Roaming User Profiles 341

Mandatory Profiles 341

Setting Up a Roaming User Profile 342 Assigning Customized Roaming Profiles 343

Creating Home Directories 343

Home Directories and My Documents 343

Creating Home Directories 344

Advanced Techniques 345

(20)

Creating New Active Directory Users in Bulk 346 Importing Users from Novell Directory Services (NDS) 348 Summary 348 FAQs 349

Chapter 10: Managing File and Print Resources

351

Introduction 352

Windows 2000 Data Storage 352

Understanding Disk Types 352

Basic Disks 353

Dynamic Disks 354

Configuring Disks 355

Understanding Windows 2000 File Systems 357 CDFS 358 UDF 358 FAT 358 NTFS 359

Configuring File Systems 364

Configuration Options for Windows 2000 Storage 365

Logical Disk Manager 366

Removable Storage Manager 366

Remote Storage Server 367

Distributed File System 367

File Replication Service 368

Indexing Service 369

Backup Utility 369

Defragmentation Utility 369

Administering NTFS Resources 370

How NTFS Permissions Are Applied 370

Access Control Lists 371

Combining NTFS Permissions 371

Permission Inheritance 372

NTFS Folder Permissions 372

NTFS File Permissions 372

Managing NTFS Permissions 373

Special Access Permissions 375

Using Special Access Permissions 375

Changing NTFS Permissions 378

Copying and Moving Files and Folders 378

Copying Files 378

Moving Files 379

Administering Shared Resources 380

Securing Network Resources 380

(21)

Creating Shared Folders 381

Administrative Shares 381

Creating a Shared Folder 383

Assigning Permissions to a Shared Folder 383

Managing Shared Folders 384

Administering Printers 385

Planning the Print Environment 386

Local, Remote, and Network Printers 386

Creating the Print Environment 386

Installing a Local Printer 386

Installing a Network Printer 387

Installing a Printer from Another Server 388

Loading Printer Drivers 388

Managing Printer Permissions 389

Security/Sharing Permissions 389

Printer Ownership 390

Managing Printers 390

Creating a Printer Pool 390

Specifying Printer Priorities 391

Redirecting a Printer 391

Removing Printer Drivers 391

Managing Documents in a Print Queue 392 Setting Priority, Notification, and Printing Time 392 Administering Printers by Using a Web Browser 393 Summary 394 FAQs 396

Chapter 11: Inside Windows 2000 TCP/IP

397

Introduction 398

A TCP/IP Primer 398

IP Address Classes and Subnets 398

Subnets and Routing 399

The OSI Model 400

Seven Layers of the Networking World 401

The TCP/IP Protocol Suite 403

TCP/IP Core Protocols 404

TCP 404 UDP 405 IP 405 ARP 408 ICMP 408 IGMP 408

TCP/IP Applications 408

(22)

Windows 2000 TCP/IP Stack Enhancements 410

NetBT and WINS 410

DHCP 412 DNS 412 SNMP 412

Using TCP/IP Utilities 412

ARP 412 Hostname 413 Ipconfig 413 Nbtstat 414 Netstat 415 Nslookup 415 Ping 416 Route 417 Tracert 417 Pathping 418 Netdiag 419 SNMP 421

How Does SNMP Work? 421

Installing the Agent 422

Using Windows 2000 Monitoring Tools 425

Basic Monitoring Guidelines 425

Performance Logs and Alerts 426

Counters 427

Log File Format 427

Alerts 427

Network Monitor 428

Filtering 428

Security Issues 429

Using Network Monitor 429

Capture Window Panes 430

Buffers 430

Collecting Data 430

Filtered Captures 433

Summary 437 FAQs 439

Chapter 12: Managing Windows 2000 DHCP Server

441

Introduction 442

DHCP Overview 442

(23)

DHCPACKNOWLEDGMENT (DHCPACK) 444 DHCP Negative Acknowledgment (DHCPNACK) 444

Integration of DHCP with DNS 445

What Are Leases? 447

Leasing Strategy 447

Operating without a DHCP Server 448

Automatic Client Configuration 448

Manual IP Addresses 450

Design of a DHCP Configuration 450

Placement of Servers 450

Using DHCP Routers or DHCP Relay Agents 451

RRAS Integration 452

Configuring a DHCP Server 452

DHCP Scopes 453

Configuring Leases 453

DHCP Options 453

Server Options 454

Scope Options 455

Client Options 456

DHCP Options Order of Precedence 456

BOOTP/DCHP Relay Agent 457

Vendor-Specific Options 457

User Class Options 458

BOOTP Tables 459

Similarities between DHCP and BOOTP 459 Differences between DHCP and BOOTP 460 Superscopes 460

Managing DHCP Servers 461

Enhanced Monitoring and Statistical Reporting for

DHCP Servers 461

Authorizing DHCP Servers 461

How Rogue DHCP Servers Are Detected 462

Authorizing a DHCP Server 463

Deploying DHCP 464

Best Practices 465

Optimizing Lease Management Practices 466

Lengthening Lease Duration 466

Shortening Lease Duration 466

Determining the Number of DHCP Servers to Use 467

Fault-Tolerant Planning 467

Router Support Required 468

DHCP Walkthroughs 468

Installing a DHCP Server 468

(24)

Troubleshooting DHCP 471

The DHCP Database 472

Multiple Clients Fail to Obtain IP Addresses 472

Duplicate Addresses 473

Summary 473 FAQs 474

Chapter 13: Managing Windows 2000 DNS Server

477

Introduction 478

Understanding DNS 478

Domain Namespace 479

Domain Naming Conventions 480

Host and Domain Names 480

Host Names 481

Fully Qualified Domain Names 481

Zones 482

Using Zones 482

Reverse Lookup Zones 483

Zone Transfer 484

Methods of Zone Transfer 485

The Retry Interval 485

Compatibility of DNS Server Versions 485

Incremental Zone Transfers 485

DDNS Dynamic Updates 486

Understanding Name Resolution 487

Recursive Queries 487

Iterative Queries 487

Looking Up an Address from a Name 488 Looking Up a Name from an Address 489 Active Directory and DNS Integration 490

Using Active Directory to Replicate and

Synchronize DNS 491

RFC 2137 Secure DNS Updates 491

Changing Zone Types 491

Integration with DHCP 492

Registration of Server in DNS Using the SRV Record 493

Installing DNS Server Service 494

DNS Server Roles and Security Topology 494

Primary DNS Server 494

Secondary DNS Server 496

Caching-Only Servers 496

(25)

Configuring DNS Services 503

Creating Forward Lookup Zones 503

Creating Reverse Lookup Zones 507

Record Types 508

Manually Adding Records 510

Configuring the DNS Client 511

Manually 511

Using DHCP 512

DNS Walkthroughs 513

Installation of a DNS Server 513

Creating a Forward Lookup Zone 514

Creating a Reverse Lookup Zone 514

Testing the DNS Server 516

Summary 517 FAQs 518

Chapter 14: Managing Windows 2000 WINS Server

521

Introduction 522

WINS Functional Description 522

NetBIOS Name Resolution 523

B-Node 524 P-Node 524 M-Node 524 H-Node 525

What Does WINS Do? 526

Broadcasting vs. WINS 527

LMHosts vs. WINS 528

NetBIOS Name Registration Request 528

Name Renewal 529

NetBIOS Name Release 531

NetBIOS Name Query Request 532

WINS Configuration 532

Configuring Static Entries 532

Connecting WINS Servers through Replication 535 Designing a Network of Multiple WINS Servers 538

Backing Up WINS Databases 540

New Features in Windows 2000 WINS 541

Persistent Connections 541

Manual Tombstoning 542

Improved Management Tools 544

Higher Performance 546

Enhanced Filtering and Record Searching 547 Dynamic Record Deletion and Multiselect 548

(26)

Burst Handling 549

Dynamic Reregistration 551

WINS Walkthrough 551

Installing and Configuring a WINS Server 551 Configuring Replication Partners 554 Summary 557 FAQs 559

Chapter 15: Windows 2000 Security Services

561

Introduction 562 Windows 2000 Security Infrastructure 562

Authentication Protocols 563

NTLM and LM 564

Kerberos 565 Private/Public Key Pairs and Certificates 566

Encryption Technologies 567

Security Configuration Tool Set 567 Secure Authentication Using Kerberos 567

Basic Concepts 567

Key Distribution Center 568

Session Tickets 569

Ticket-Granting Tickets 570

Services Provided by the Key Distribution Center 570 Tickets 572

Kerberos and Windows 2000 573

Key Distribution Center 573

Kerberos Policy 574

Contents of a Microsoft Kerberos Ticket 576

Delegation of Authentication 576

Preauthentication 576

Security Support Providers 577

Credentials Cache 578

DNS Name Resolution 578

UDP and TCP Ports 578

Using the Security Configuration Tool Set 579 Security Configuration Tool Set Overview 579 Security Configuration and Analysis Snap-In 579 Security Configuration and Analysis Database 581 Security Configuration and Analysis Areas 581 Security Configuration Tool Set User Interfaces 582

Configuring Security 585

Account Policies 585

Local Policies and Event Log 586

(27)

Restricted Groups 586

Registry Security 587

File System Security 587

System Services Security 588

Analyzing Security 588

Group Policy Integration 589

Security Configuration in Group Policy Objects 589

Additional Security Policies 589

Using the Tools 589

Using the Security Configuration and

Analysis Snap-In 590

Using Security Settings Extension to

Group Policy Editor 591

Encrypted File System 591

How EFS Works 591

User Operations 592

File Encryption 593

Decrypting a File 594

Cipher Utility 594

Directory Encryption 595

Recovery Operations 595

Summary 596 FAQs 597

Chapter 16: Securing TCP/IP Connections

599

Introduction 600

Secure Sockets Layer 600

Overview of SSL 600

How a Secure SSL Channel Is Established 601 Symmetric and Asymmetric Encryption 602

Symmetric Encryption 603

Asymmetric Encryption 603

Hash Algorithms 604

Digital Certificates 605

Certificate Authorities 606

SSL Implementation 606

Secure Communications over Virtual Private Networks 609

Tunneling Basics 609

VPN Definitions and Terminology 609

How Tunneling Works 610

IP Addressing 610

Security Issues Pertaining to VPNs 610

Encapsulation 610

(28)

Data Security 611 Windows 2000 Security Options 611

Common VPN Implementations 614

Remote User Access Over the Internet 614 Connecting Networks Over the Internet 615 Tunneling Protocols and the Basic Tunneling

Requirements 616 Windows 2000 Tunneling Protocols 617 Point to Point Tunneling Protocol (PPTP) 617 Layer 2 Tunneling Protocol (L2TP) 618

Using PPTP with Windows 2000 618

How to Configure a PPTP Device 618

Using L2TP with Windows 2000 619

How to Configure L2TP 619

How L2TP Security Differs from PPTP 619 Interoperability with Non-Microsoft VPN Clients 621

IPSec for Windows 2000 621

Overview of IPSec Cryptographic Services 622

Message Integrity 622

Message Authentication 623

Confidentiality 624

IPSec Security Services 624

Authentication Header (AH) 624

Encapsulating Security Payload (ESP) 625 Security Associations and IPSec Key Management

Procedures 626

IPSec Key Management 627

Deploying IPSec 628

Building Security Policies with Customized

IPSec Consoles 628

Building an IPSec MMC Console 629

Flexible Security Policies 629

Rules 631

Flexible Negotiation Policies 634

Filters 635

Creating a Security Policy 635

Making the Rule 636

Summary 642 FAQs 643

Chapter 17: Connecting Windows 2000 Server

645

(29)

What Do You Need to Use ICS? 646

ICS and TCP/IP 647

How APIPA Works 647

ICS Address Autoconfiguration and the

DHCP Allocator 648

Private Network Addresses vs. Public Addresses 648 Using Internet Connection Sharing 649 Using ICS with a VPN Connection 649

On-Demand Dialing 649

Configuring Applications and Services 649

ISP Static IP Addressing 650

What Happens When You Enable ICS? 650 Network Address Translation (NAT) 651

How NAT Differs from ICS 651

What Is NAT? 651

Setting Up the NAT Computer 652

Multiple Public Addresses 656

Setting Up the NAT Client Computers 656

A NAT Example 656

Accessing Other Computers’ Printers and

Network Drives 658

Accessing Other Computers’ Resources

over the Internet 659

Protecting Your Computer from Unauthorized

Access 659 Comparison of ICS, NAT, and Windows Routing 660 A Windows 2000 Routed Connection 660

Performance Considerations 660

Security 661 How Do NAT and ICS Protect My Network? 661 Security Issues with Routed Connections 662

Comparison of Features 662

Establishing VPNs over the Internet 662

PPTP and L2TP 662

VPN Solutions 664

Client/Server VPN 664

Creating a VPN Router 665

Connecting a VPN Client 667

Tunneling Non-TCP/IP Protocols 669

Dial-Up Access 669

Configuring RAS 670

Security Concerns 671

Secure the Telephone Number 671

(30)

Authentication and Encryption 672

Caller ID and Callback 672

Outsourcing Dial-Up Access 673

RADIUS 673 Summary 674 FAQs 675

(31)
(32)

Just a few short years ago, no one could have foreseen the huge impact that the personal computer would have on the working lives of so many people. Idling on the desk of millions of office workers around the world is a tireless instrument that extends and facilitates our ability to deliver work. Today, the personal computer and the operating systems that run it are as ubiquitous as the car, with which it shares several pow-erful characteristics.

The modern car comes with a surfeit of features—sleek lines, aggressive low-cut features, and a powerful engine—all intended to tempt the buyer. But, it is the road that the car travels along that makes it truly productive. Without the road, the modern car would be sleek, beautiful, and useless. Windows 2000 Professional and most other modern personal operating systems are armed with the same sleek lines, powerful engines, and aggressive features as the modern car. To guide operating systems such as Windows 2000 Professional down the road of increased productivity, flexibility, and reliability, a robust and mission-critical server operating system infrastructure is required—an operating system infrastructure like Windows 2000 Server.

A significant portion of the design objectives for the Windows 2000 development team was to ensure that Windows 2000 Server was the most efficient, scalable, and reliable Microsoft operating system for the enterprise. Complex decision-making issues that arose during the design of Windows 2000 Server were handled with ruthless efficiency. If a choice arose between compatibility and stability, it was ruled as no competition—stability won every time. That has left us with an

oper-Introduction

(33)

ating system that has gone through one of the most rigorous testing cycles in operating system history. Compound this with the involve-ment of some of the best minds in the computing business, and you have a network operating system that can only be described as a winner.

What does Windows 2000 Server signify to information tech-nology professionals? It means an exciting opportunity to learn new skills, provide better services, and enhance productivity (and to use cool-sounding words like ADSI and Kerberos). Windows 2000 Server ushers in a bevy of features that leverage best-of-breed technology sets. This is not technology for technology’s sake, but a technical architecture geared toward providing an infrastructure based on delivery.

Even on first appearances, it is obvious that Windows 2000 Server is a vastly complex operating system. With functionality liter-ally bursting from the seams, it creates the dual opportunity for success and failure. The correctly prepared professional who under-stands the nature and complexities of Windows 2000 Server can provide an outstanding infrastructure based on its reliable, exten-sible, and flexible feature set. Those unprepared for managing and working with a product as far-reaching and complex as Windows 2000 Server should prepare for a good deal of confusion and reac-tive problem solving.

Windows 2000 Server is the next-generation operating system from Microsoft that not only replaces, but also revolutionizes the network operating system product space that Windows NT 4 Server occupied. With adequate preparation, appreciable benefits can be realized by all information technology professionals, from the Dilbert-style network manager, to the technical developer who sits in a lotus position chanting C++ mantras. But, more importantly, your clients—the users—will be able to reap the rewards that go hand in hand with Windows 2000 Server.

Mission-Critical Windows—A Contradiction

in Terms?

Rightly or wrongly, Microsoft has been soundly chastised on more than one occasion for supplying server-based operating systems that fail ungracefully under pressure. Mention Windows and

(34)

choke on their coffee. In the last 10 years, mainframes and several flavors of UNIX have been the first choice for providing mission-crit-ical services, and for very good reasons. The message chanted by hardware and software vendors alike was, “Don’t use Microsoft for anything that just can’t go down”—a statement that most times I would have agreed with. Windows 2000 Server has changed all of that.

The Windows 2000 product group represents the largest and most technically advanced body of work undertaken by the most successful software company in the world. It is considered by many to be the single most important milestone in the evolutionary devel-opment of the Windows family. By providing a computing platform that offers stability, high productivity, and compatibility, Microsoft is extending its software presence even further into the server space.

The deluge of complaints that Microsoft has received (not to mention the battering suffered at the hands of the press) regarding its server-based operating systems has ensured that the Windows 2000 core services are built around a reliable and scalable architec-ture. Don’t get me wrong, blue screens of death are not a thing of the past, nor have required reboots been relegated to the dust pile of Windows anachronisms. What has changed is the refocus on sta-bility and on user requirements.

I am not alone in wanting 99.999% uptime, scalable directory services, and a secure computing platform. Windows NT went some way to addressing all of those concerns, but not nearly far enough. Mission critical means different things to different organizations—to supermarkets, point-of-sale systems are mission critical; to e-busi-nesses, Web farms are mission critical. The common thread that runs through these disparate businesses is the requirement to provide a stable, supporting infrastructure that technologically enables mission-critical business services—a requirement to which Windows 2000 Server provides an almost unbeatable solution. That’s the good news. The bad news is that you need more than a superficial level of understanding of your network operating system, you need to get your hands dirty with the real technical nuts and bolts.

(35)

Who Should Read This Book?

If you work with Windows 2000 Server, or are planning to, then this book will be of use to you. It is not meant to be light bedtime

reading, but an exploration of the more technical issues of Windows 2000 Server. I recommend that you gain some familiarity with Windows 2000 Server concepts before reading this book (though it is not entirely necessary, since most chapters have introductory material), and that you understand general networking and oper-ating system concepts. Don’t let that scare you though—you don’t need a degree in Quantum Physics, or need to own a personalized pocket protector to derive value from this book. What you do need is a will to get involved with the most exciting development in oper-ating systems in the new millennium.

Windows 2000 Server is not a lightweight operating system. As users have become more demanding, there has been an associated increase in the complexity of the supporting technical infrastruc-ture. But even among scary-sounding Windows 2000 Server

acronyms like FSMO, SDOU, and LDAP, you will find concepts such as ease of use, security, and decreased support overhead. These are certainly concepts that most people can identify with, and if you do, then you wantto understand the contents of this book.

How This Book Is Organized

When I was initially putting together the outline for this book, I realized that it would be impossible to cover all the technology sets in as great a detail as I would have liked—not unless I was prepared to have a book published that no one was physically able to pick up! As a result, certain features of Windows 2000 Server have received greater coverage than others. Core Windows 2000 Server features like Active Directory, IntelliMirror, network services, and security rightfully receive the lion’s share of the coverage.

(36)

Windows 2000 Serverwill take on the appearance of a truly useful book—in other words dog-eared and discolored, with a fair amount of pencil work in the margins!

Acknowledgments

There are a number of people I must thank; some of them provided invaluable help in writing this book, while others taught me many of the things worth knowing in life. Thanks go to Sonia Barrett, for teaching me to laugh, to smile, and to appreciate real music. To Ray Walshaw, for gifting me with confidence and teaching me the

courage of my convictions. Martin Walshaw—big brothers just don’t come any better. Costas Kellas, for starting me down the road. The lads from the valley—Uruman Gwuafi, Alex Harris, David Ker, Sean Disney—thanks for teaching me that no mountain is too high—liter-ally. Andrew Williams and Syngress, for being all the things a good publisher should be. D. Lynn White, for a great job of technical editing this back breaker.

(37)
(38)

Introduction to

Windows 2000

Server

Solutions in this chapter:

What’s New in Windows 2000 Server?

What’s Not New in Windows 2000 Server?

Windows 2000 Challenges

Chapter 1

(39)

Introduction

Significant changes in the way that computers are used in the workplace have heralded an increased focus on issues such as security, manage-ability, scalmanage-ability, and reliability. The use of information technology has ushered in an era characterized by high availability, high productivity, and increased support levels. Unfortunately, the burden of responsibility rests squarely on the shoulders of the IT professional to ensure that the infras-tructure meets the requirements of the modern demanding user.

It is no great secret, or surprise, that legacy technologies are beginning to creak under the strain of ever-increasing user requirements, stability initiatives, and management drives to lower the cost of ownership. A new technology set was needed to provide services that existing operating sys-tems could not. Microsoft itself was guilty of a lack of technical delivery with glaring omissions in the Windows NT 4 technical strategy that

included the lack of a perceived stable mission-critical server platform and the absence of a cohesive infrastructure to manage configuration changes.

With a vision of providing an operating system for the future, Microsoft began development on its most ambitious project to date: Windows 2000. The aims of the design team, though simple in theory, proved to be much more difficult to achieve in reality. They had to provide scalable answers to the deficiencies in Windows NT 4, and satisfy design objectives that

included:

■ Increasing reliability, availability, and scalability

■ Reducing costs through simplified management

■ Providing a powerful and robust Internet and application server

Much has been said about the complexity and size of this new brain-child. The modern-day software malady of ever-increasing size and com-plexity has certainly directly affected Windows 2000 Server, but not necessarily in the manner that many people perceive.

(40)

Whether you plan to deploy it or are already using it, a lasting first impression of Windows 2000 Server is the vast array of integrated function-ality. Casual inspection reveals a hauntingly familiar interface—is it just Windows NT 4 with a slick version of the Windows 98 GUI? Actually, nothing could be further from the truth. By probing a little deeper it soon becomes apparent that Windows 2000 Server combines an evolutionary upgrade path with a revolutionary feature set.

This chapter touches on the powerful features of Windows 2000 Server, and its effect on the organization and Administrators. Windows 2000 Server presents a radical change from its predecessor, and knowledge of its myriad of features is required to leverage its true power.

What’s New in Windows 2000 Server?

When confronted by the sea of features and changes that accompany Windows 2000 Server, it is easy to understand the need to address some of the new features in detail, while touching on others in no more than a cur-sory fashion. Microsoft supplies a “feature highlight” that includes almost 80 major features—enough to make the eyes water!

Microsoft, to its credit, has learned that it is not possible to satisfy the diverse set of server requirements with a “one package fits all” strategy. To allow Windows 2000 Server to scale from the small business right into the multinational corporate server farm, it has been divided into a family of server operating systems (Table 1.1).

Each of the various flavors supports the much-touted Active Directory, which is probably the most critical element of the Windows 2000 Server family. Active Directory simplifies management, extends interoperability with applications and devices, and improves security.

The entry-level and most commonly used edition is Windows 2000 Server Standard Edition. The nomenclature for Windows 2000 Advanced Server hearkens back to the early days of Windows NT, when the name Advanced Server made its debut. Aside from its nostalgic name, Advanced Server maps most closely to Windows NT Server Enterprise Edition. It con-tains all the features and benefits of Windows 2000 Standard Edition, but includes support for larger deployments. The inclusion of support for net-work load balancing, clustering, and a more scalable memory and CPU architecture makes Advanced Server an excellent candidate for large SQL Server databases, for high-end Web servers, and for meeting the demands of high-end, critical file and application services.

Windows 2000 DataCenter is Microsoft’s top-of-the-line model. In addi-tion to having all the features of the Standard Ediaddi-tion and Advanced Server, DataCenter supports more processors and larger amounts of

(41)

deployments with the most demanding needs, such as high-end clustering, data warehousing, and Internet Service Providers (ISPs).

As usual, Microsoft has published a minimum hardware specification for the Windows 2000 Server family (Table 1.2)—and also, as usual, you can totally disregard them. I would be sorely taxed to think of anything as mind-numbingly boring as watching Windows 2000 Server run on a

Pentium 133MHz. So this said, the recommendations should be read

care-Table 1.1

Windows 2000 Server Family

Description Features

Windows Designed to be a ■ During upgrade four-way SMP

2000 powerful support. Fresh install supports Server multipurpose server. two-way SMP.

Ideal for workgroup ■ Supports 4GB of memory.

and departmental ■ Active Directory.

servers. ■ Kerberos security.

■ Enhanced Internet and Web

services.

Windows Designed for ■ All Windows 2000 Server features.

2000 intensive enterprise ■ Up to eight-way SMP support.

Advanced applications. Provides ■ Supports up to 8GB of memory.

Server further availability ■ 32-node network load balancing.

and scalability ■ Two-node clustering.

enhancements.

Windows Designed for massive ■ All Windows 2000 Advanced

2000 enterprise solutions Server features.

DataCenter providing maximum ■ Up to 32-way SMP support.

levels of scalability ■ Supports up to 64GB of memory.

and availability. ■ Four-node clustering.

Table 1.2

Minimum Hardware Requirements for Windows 2000

Microsoft published minimum requirements for Windows 2000 Server and Windows 2000 Advanced Server

■ 133MHz or higher Pentium-compatible CPU ■ 256MB RAM (128MB minimum supported)

(42)

fully, and then thrown away. Hardware specifications are very much

dependant on the type and volume of usage, but to provide a decent level of performance for the base operating system (but without leaving too much room for applications), I would recommend at a minimum a Pentium II 500MHz, 256MB of RAM, and a 100MB network interface card (NIC). The same rule that applies to luck also applies to RAM in the context of Windows 2000 Server: There is no such thing as too much of it!

The Key to Unlocking Your Network: Active Directory

The success or failure of a Windows 2000-enabled network will, in the majority of cases, hinge on the implementation of Microsoft’s directory ser-vice, Active Directory. It is a fundamental change that affects the Windows operating system and Windows networking from top to bottom, and pro-vides a structure for other applications to integrate more tightly into your Windows network than ever before.

“What exactly is a directory service?” you ask. A directory is a place to store interesting (and sometimes not-so-interesting) information (Figure 1.1). A directory service includes both the entire directory and the method of storing it on the network so that it is available to any client or server.

Address

[image:42.612.94.444.339.603.2]

Hostname

(43)

The type of information that is stored in a directory falls into three basic categories:

Resources Resources are the items attached to the network and made available to users. A resource can be a server’s hard drive, an IP address, an application, a fax modem, a scanner, a printer, or any “thing” that can be used by a client workstation.

Services A service is a function on the network that makes resources shareable. Most services are simply network applications. These two cate-gories are typically related. For most services, there is an analogous resource, and for most resources, there is an analogous service. Sometimes, however, a resource or a service stands alone.

Accounts The final category in a directory is an account. An account is usually a logon ID and associated password used for access to the network. It is used to grant the right to use a service or a resource.

Now that we know what a directory service is, we now need to find out how the Active Directory fits into the picture. Active Directory offers a nearly ideal set of directory characteristics so that a single directory and logon is available to all users. It also allows administration to be centralized or distributed according to requirements. The directory and its inherent security can be extended and scaled from small to large enterprises. Simply put, the Active Directory allows your users to find the resources they need on the network, while simultaneously facilitating administration, flexibility, and scalability.

Why Should I Use the Active Directory?

At first, it can be difficult to see the need for a directory service when, on first inspection, your current infrastructure suffices. This is abetted by the fact that many IT professionals live by the tried and tested maxim “if it ain’t broke, don’t fix it.” Active Directory should only be implemented if it meets well-defined business requirements, and if it satisfies carefully thought-out tech-nical considerations. Once it is implemented, though, you will wonder how you ever lived without it. Some of the advantages of Active Directory include:

Inherent scalability Active Directory has been designed to provide reliable services that scale from the small office to the multinational corporation. Multiple indexes of the directory provide swift information retrieval even in large distributed environments.

Enhanced security Active Directory integrates with a number of security mechanisms. It includes support for Kerberos, Secure Sockets Layer (SSL), smart cards, and X.509 certificates.

(44)

name-space. This also implies that Active Directory can be easily integrated into an Internet or intranet environment.

Extensibility Active Directory provides a host of built-in functionality, including an inherent extensibility supplied through a definable schema and the Active Directory Services Interface (ADSI). Active Directory also provides tools for synchronizing with other directory services and managing identity information stored in multiple directory services.

Ease of administration Active Directory acts as publishing service for resources, allowing for centralized administration. The hierarchical direc-tory structure simplifies administrative tasks and allows for the delegation of authority.

Inherent flexibility and scalability provides almost limitless applications for Active Directory, whether it is as the backbone of your distributed secu-rity environment or as a framework for client management and support. With the adoption of Active Directory by software vendors, the benefits of the Windows 2000 directory services will not only be available to the sup-porting infrastructure, but to applications themselves.

Change and Configuration Management

A great deal of attention has been focused on the cost of owning computing platforms; in particular, client workstations. Microsoft has aggressively addressed this issue by providing a series of technologies for Windows 2000 that support change and configuration management (Figure 1.2). The term

change and configuration management encompasses all of the corrective,

con-figurative, and preventative tasks that an Administrator must perform to keep his user base productive, including the deployment of software to the desktop. As is typical in the computing world, fancy multibarreled words can be boiled down to very basic principles: Change and configuration manage-ment is quite simply desktop and user managemanage-ment and configuration.

(45)

After consulting customers and the IT sector, Microsoft realized that its change and configuration management feature set needed to meet at least the following requirements:

The ability to store user data centrally.

■ Support of a personalized computing environment; data and

appli-cations should follow the users as they roam around the network.

■ The ability to work on or offline.

Reduction of administrative overhead by providing the ability to

centrally configure clients by policy, including software deployment by policy.

■ Self-healing desktops that reduce support call incidents.

The ability to add/replace desktops without prestaging.

A number of factors have contributed to the increased costs associated with managing and owning a network and its infrastructure; more

demanding users, increasingly complex products, and a growing user base are just a few of them. Windows 2000 certainly does not break the mold when it comes to developing complex products, but it does provide an infrastructure to lower the cost of owning a Windows-based infrastructure.

Change and configuration management centers are the continuing requirement for Administrators to manage the change and configuration issues that arise during the support of their user base. Two main concepts that support the new change and configuration management techniques are IntelliMirror and remote operating system installation. IntelliMirror is a set of tools and technologies that increase availability, reduce support costs, and allow the users’ software, settings, and data to follow them. Three pillars support the IntelliMirror technology:

User data management Users can have access to their data whether they are online or offline. This feature leverages the Active Directory, Group Policy, folder redirection, disk quotas, and file synchronization—technolo-gies that increase data availability. In Microsoft parlance: “My data and documents follow me.”

User settings management Allows preferences to follow the user. The user’s personalized settings such as desktop arrangements and software and operating system settings follow the user. This feature includes the Active Directory, Group Policy, roaming profiles, and particular shell enhancements—technologies that increase computer availability. In Microsoft parlance: “My preferences follow me.”

(46)

that increase application availability. In Microsoft parlance: “My software follows me.”

NOTE

A word of caution, do not tell friends or family that your software, data, and preferences are following you. They could take it upon themselves to retire you to a room with soft padded walls.

The second concept, remote operating system installation, allows Administrators to build a functional, standardized workstation remotely. Providing a solid and flexible infrastructure for operating system deploy-ment is imperative for a successful operating system installation strategy.

A brief summary of some of the technologies used with IntelliMirror include (Figure 1.3):

Active Directory A scalable directory service that stores information about the network that can be accessed by users and Administrators alike. It can act as both an information source and a centralized administrative tool. Group Policy A technology that enables Administrators to precisely define the configuration of the users’ computing environment. It can sat-isfy such diverse requirements as setting security settings to application deployment. Group Policy can control both user- and machine-based con-figuration settings.

Offline Files and Folders A technology that allows users to access defined files and folders while offline. Entire mapped drives can even be accessed while offline. The Synchronization Manager can be used to synchronize offline resources.

Folder Redirection The ability to point a folder, such as My Documents, to another (network) location.

Distributed File System (DFS) This service can build a single namespace consisting of multiple shares on different servers. DFS provides the ability to load share and increase data availability.

Roaming User Profiles A centrally stored user profile that follows the user around the network.

Windows Installer A standardized, scalable installation service that is cus-tomizable, consistent, and provides diagnosis and self-repair functionality.

(47)

Group Policies

At times, it seems that as soon as your back is turned, more clients attach themselves to the network. The growing hunger of businesses to technologi-cally enable their workforce is creating a mounting headache for the

Administrator of today’s networks. Maintaining and enforcing a standardized configuration while allowing the users freedom to work unhindered is a jug-gling act that sometimes requires the Administrator to have too many balls in the air at once. The only way to ensure that the configuration of possibly thousands of workstations is maintained in a consistent manner is by allowing the network to enforce the rules for software deployment and other change and configuration issues. Policy-based management is one answer to Windows 2000 change and configuration management challenges.

Group policies can be used throughout Windows 2000 to define user and computer configuration settings such as scripts, software policies, security settings, application deployment, user settings, and document options. Using group policies, these settings can be controlled centrally and

[image:47.612.100.426.82.369.2]

(48)

applied across the business. Group Policy leverages the Active Directory and supports the IntelliMirror technology to control the scope and granu-larity of changes in configuration. By providing a well-managed desktop environment through group policies, Windows 2000 eases the resolution and elimination of change and configuration management issues.

The ability to control and manage the network in a scalable environ-ment ensures that small, medium, and large businesses have the tools to lower the cost of owning PCs and supporting users. The vast array of con-figurable settings ensure that there is a wealth of usage scenarios for Group Policy, with just a few of those possible being:

■ Install the accounting package on all computers in Finance.

Run acclogon.cmd when users in the Accounts department log on.

■ Do not save settings on exit for all consultants.

■ Disable the RunAs service for the whole organization except

Administrators.

Launch this Web page at user logon.

Windows 2000 Security

Windows 2000 Server serves up a great number of security enhancements compared to what was available in previous incarnations of the operating system. These enhancements include Public Key Infrastructure capabilities, the Kerberos v5 authentication protocol, smart card support, the Encrypted File System (EFS), and IPSec. These new additions to security are neces-sary to protect data as more organizations come to the realization that their information technology infrastructure is business critical. It can be very hard to quantify the benefits of an enhanced security infrastructure—that is, until it’s too late. Legacy security infrastructure and exploitable vulnera-bilities have the potential to leave the doors in your network invitingly ajar, allowing havoc to be wreaked on mission-critical systems.

In today’s ever-changing global environment, the more security that can be provided by a network operating system, the better off the organizations that use it will be. Security for Microsoft’s network operating system has undergone major surgery with the arrival of Windows 2000 Server. What has emerged from the operating theatre is a product family that includes extensible, standards-based, mission-critical security. Some of the new fea-tures include:

■ Multiple methods of authenticating internal and external users

Protection of data stored on disk drives using encryption

(49)

■ Per-property access control for objects

■ Smart card support for securing user credentials securely

■ Transitive trust relationships between domains

Public Key Infrastructure (PKI)

Why the Change?

The change in security in Windows 2000 Server is necessary as more organi-zations use the operating system for mission-critical applications. The more widely an operating system is used in industry, the more likely it is to become a target. The weaknesses of Windows NT came under constant attack as it gained popularity. One group, L0pht Heavy Industries, harshly highlighted the frailties of Windows NT’s password encryption for the LAN Manager hash. Due to the fact that the LAN Manager hash was always sent (by default) when a user logged in, L0pht produced a tool to crack the password. Microsoft made provisions for fixing the problem in a Service Pack release, but in Windows 2000 Server, it has replaced the default authentication with Kerberos v5 for an all-Windows 2000 domain controller based network—a system where pass-words are never transmitted along the network.

Alarming figures based on intrusion detection statistics indicate that the majority of security violations occur internal to the corporate network. Accordingly, emphasis has moved from protecting against “black hat” external hackers to securing the corporate network as a whole.

Differences in Windows 2000 Server Security

One of the enhancements to the security in Windows 2000 Server is the support for two authentication protocols, Kerberos v5 and NTLM (NT LAN Manager). Kerberos v5 is the default authentication method for Windows 2000 domains, and NTLM is provided for backward compatibility with Windows NT 4.0 and earlier operating systems. Transitive trust relation-ships—a feature of Kerberos v5—are established and maintained automati-cally. Transitive trusts rely on Kerberos v5, so they are applicable only to Windows 2000 Server-only domains.

Another security enhancement is the addition of the Encrypted File System (EFS). EFS allows users to encrypt and decrypt files on their

system on the fly. This provides an even higher degree of protection for files than was previously available using NTFS (NT File System) only.

The inclusion of IPSec (IP Security) in Windows 2000 Server enhances security by protecting the integrity and confidentiality of data as it travels over the network. It’s easy to see why IPSec is important; today’s networks consist of not only intranets, but also branch offices, remote access for travelers, and, of course (fade in scary music), the Internet.

(50)

available at all levels of the Active Directory. Smart cards are supported in Windows 2000 Server to provide an additional layer of protection for client authentication, as well as providing secure e-mail. The extra protection is derived from adversaries needing not only the smart card, but also the Personal Identification Number (PIN) of the user to activate the card—a fea-ture called two-factor authentication. Windows 2000 Server depends heavily on Public Key Infrastructure (PKI). PKI consists of several components: public keys, private keys, certificates, and certificate authorities (CAs).

Windows 2000 Network Services

The cliché that the world is getting smaller is used and derided on a daily basis, but that does not detract from the fact that it has become a truism. Communications, both data- and voice-based, have reduced the world to a global village. One of the factors that have hastened the arrival of the global village is the drive to well-connected networks. Operating systems such as Windows 2000 Server provide a number of advanced network services that facilitate reliable and scalable communication and connectivity. A few of the network services Windows 2000 offers include:

Certificate Services Several of the services available in the Windows NT 4.0 Option Pack are now included in Windows 2000 Server, including Certificate Services. Certificates are used most commonly to implement Secure Socket Layer communications on Web servers for the transmission of private information—your credit card number, for example. Certificate Services can also be used to make e-mail secure, provide digital signatures, and set up certification authorities that issue and revoke certificates.

DHCP Dynamic Host Control Protocol (DHCP) is certainly not new, but now interfaces with DNS and Active Directory. This feature illustrates an important point: Active Directory integration is pervasive throughout Windows 2000, and you’ll find it in the most unlikely places!

DNS Domain Name Services (DNS) have been included with Windows 2000 as the default namespace provider. Additional benefits include the adoption of Dynamic Domain Name Service (DDNS), allowing clients to update

details in DNS automatically.

Internet Authentication Service Internet Authentication Service (IAS) brings the ability to manage the authentication, accounting, authorization, and auditing of dial-up or virtual private network (VPN) clients. IAS uses the Remote Authentication Dial-In User Service (RADIUS). Setting up a VPN will allow you to provide secure network connections to users over the Internet, and IAS is a service used to manage these types of connections.

(51)

share an Internet connection with a small network with a service that pro-vides network address translation (NAT), addressing, and name resolution for other computers on the network.

Internet Information Services 5.0 The newest version of Microsoft’s Web services is much like IIS 4.0, but has a truckload of new features. These include support for Web Distributed Authoring and Versioning (WebDAV), Web Folders, integrated FrontPage Server Extensions, support for some of the latest Internet standards, FTP Restart, Browser Capabilities Component, Self-Tuning ASP, encoded ASP scripts, process throttling, and the list goes on.

Network Address Translation Network Address Translation (NAT) is a feature that is used on many routers to connect networks using private IP address ranges to the Internet. NAT, as its name implies, translates addresses on IP packets so that devices on the Internet return all packets to the computer or router running NAT. The NAT device then forwards the data to the client that initiated the communication. This service also pro-vides a layer of security, because a device on the Internet can only initiate communications with a host that has a routable IP address. Computers communicating behind a NAT device are much safer from outside attack than systems that have Internet routable IP addresses.

Quality of Service Windows Quality of Service (QoS) allows you to tune how applications are allotted bandwidth. With the increased use of audio and video over networks, it is necessary to ensure that enough bandwidth is available for these appli

Figure

Figure 1.1 Directory service structure.
Figure 1.3 IntelliMirror and associated technologies.
Figure 2.1 Tracing DNs through the Active Directory tree.
Figure 2.2 Multiple namespaces in a forest.
+7

References

Related documents

The DynaPass server is a MS Windows 2000 Server with Active Directory, containing all users that have been granted Remote Access rights independently of which service that is used.

The dissonance between sight and sound actualised and made visible the gap in time between the lived present of the unreturned soldiers where the Pacific War never ended, and

This second edition of the FIDIC Users’ Guide has been extended to include the Conditions of Contract for Plant and Design-Build, known as the 1999 Yellow Book.. It also reviews

This is what CZ stands for, and this is why CZ also offers healthcare services in addition to group health insurance that will assist you with ensuring the health of your

If the H-point couple distance, or seating package, is such that the H-point machine with 95 th percentile leg lengths will attain an ankle angle greater than 130 degrees with

EXCELLENCE EXPERTISE INNOVATION Tuberculosis Infection Prevention in Health Care Settings Jeffrey L.. Levin,

Ten years into the reign of Thorin the First, son of Thráin the Old, the King resolved to remove the royal house of Durin’s folk from Erebor to abide in the Grey Mountains.. At the

Step 1: Draw the configuration diagram.. • Problem 11: For the mechanism shown in figure link 2 rotates at constant angular velocity of 1 rad/sec construct the velocity polygon