Thursday, July 6, 2017

New Windows Server Setup

New Windows Server Setup
Notes from the field
July 6, 2017








As most of you know I like to stay technically astute and there's no better way to do that than to cover for a field tech that's on vacation.

Today I'm installing Windows Server 2016 on a new HPE ML30 Proliant Server.  The server hardware setup portion of the install went fine.  That process involved popping two hard drives into server.  The server did not come with a DVD-ROM reader so I quickly contacted another tech in the area and had him drop off his reader.  Since this is a small customer (less than 10 employees), I'll be configuring the server with RAID 1.  The process involve using HP's embedded raid array utility.  I selected both drives, each 1TB in size, which yield a new logical drive that's 995GB in size.


After RAID configuration, its time to install operating systems.  The OS install splash screen comes up and I choose Windows Server Standard 2016.  The small print for this option indicates it will install the OS without the graphical user interface (GUI).  I didn't see this up front and had to re-install to get GUI version.  This is necessary due to old Quickbooks database server that needs GUI for installation.  The other issue during the install was that Windows did not detect the new drive array and associated disk volume, so I had to go and download drives from HPE website.

New server is up and running.  I didn't expect that taking the first and default OS option would install the command line only version, so be on the lookout for that.

Tuesday, July 4, 2017

Network Management for Small Businesses That’s Simple and Secure

Network Management for Small Businesses That’s Simple and Secure: I welcome Michael Proper, ClearCenter CEO, to our blogging community and am excited to have him tell the HPE and ClearOS IT management and network story. Let’s be honest. Managing a network today for a small business can be a mess. You may splurge on a decent firewall appliance but then you’re force...

Introducing the HPE ProLiant MicroServer Gen10 Small Scale Server

Thursday, June 29, 2017

In Preparation of Ransomware Hit

Background
Ransomware happens when an unsuspecting user clicks on a link within an email message or download a small piece of software unknowingly from a website.  This software, often disguised as something legitimate, proceeds to encrypt all of the files on your computer system.  The latest variants event target the network drives if you are connected to a corporate or business network.  The result is that it encrypts all company files located on the network drive.  It spreads rapidly from computer to computer until all computers are infected and files are encrypted.


Users are left with a note on their computer desktop instructing them to purchase bitcoin and send the digital currency via email to the author of the ransomware.  After receipt of the email, the author sends a software key to the user to decrypt their files.  Beware that there are many cases where the author does not respond back with the key.  In this case you are left with nothing.


According to FBI...
Here are some tips for dealing with ransomware (primarily aimed at organizations and their employees, but some are also applicable to individual users):
  • Make sure employees are aware of ransomware and of their critical roles in protecting the
  • organization’s data.
  • Patch operating system, software, and firmware on digital devices (which may be made easier through a centralized patch management system).
  • Ensure antivirus and anti-malware solutions are set to automatically update and conduct regular scans.
  • Manage the use of privileged accounts—no users should be assigned administrative access unless absolutely needed, and only use administrator accounts when necessary.
  • Configure access controls, including file, directory, and network share permissions appropriately. If users only need read specific information, they don’t need write-access to those files or directories.
  • Disable macro scripts from office files transmitted over e-mail.
  • Implement software restriction policies or other controls to prevent programs from executing from common ransomware locations (e.g., temporary folders supporting popular Internet browsers, compression/decompression programs).
  • Back up data regularly and verify the integrity of those backups regularly.
  • Secure your backups. Make sure they aren’t connected to the computers and networks they are backing up.
source:  https://www.fbi.gov/investigate/cyber


What can you do...


The latest variants took advantage of unpatched Windows PCs.  Simply apply the latest security updates in order to ward off these variants.  


We also know that SMBv1 is the main culprit.  Microsoft actually discourage use of this protocol.  ZDNet recently posted an article relating to the subject.  


According to ZDnet (1) Two devastating global ransomware outbreaks, WannaCry and Petya, spread quickly because of a vulnerability in one of the internet's most ancient networking protocols, Server Message Block version 1 (aka SMBv1).
Your PCs that run Windows 10 are protected from that exploit, but that doesn't mean you'll be so lucky the next time.


In the interests of implementing a comprehensive, multi-layer security policy, Microsoft recommends that you disable the SMBv1 protocol completely. The world has already moved on to SMBv3, and there's no excuse for continuing to let that old and horribly insecure protocol run on your network.


To permanently remove SMBv1 support from Windows 10 do the following:


Open Control Panel (just start typing Control in the search box to find its shortcut quickly). Click Programs, and then click Turn Windows features on or off (under the Programs heading). Clear the check box for SMB 1.0/CIFS File Sharing Support, as shown here. That's it; you're protected.
(1) source: http://www.zdnet.com/article/windows-10-tip-stop-using-the-horribly-insecure-smbv1-protocol/?ftag=TRE-03-10aaa6b&bhid=113555250

Monday, May 20, 2013

Lingering Issues Can Kill Customer Satisfaction Rating


I recently met with one of our customers about our IT Service Delivery.  I went into the meeting thinking that GAD Group was going to get high marks for solving issues and responding to requests in a timely fashion.  After all, our status reports looked impressive showing great productivity numbers.  Additionally, we had previously taken care of some critical issues for this decision maker within the customer account.  So my thoughts were that the customer would just reap praise on us for our "excellent" work.

As the meeting progressed, The decision maker in the meeting squarely pointed to a support ticket that had been opened for several weeks with no resolution.  When they showed me the issue, in my mind, I remembered talking about the issue in one of our team conference calls or staff meeting.  I was totally surprised when they brought up the issue.  As I reviewed the ticket, I noticed the tech assigned to the issue was not persistent at all, didn't follow-up with the vendor, nor did he perform any research to see if he could come up with an alternative solution.

Consequently, I personally took care of the issue and followed up with the user to make sure they was happy with the solution.  I took responsibility for the issue and covered for the tech.

The lesson here is that customers make mental notes about things we think are trivial.  Lingering open issues get more attention than closed solutions/successes.  

Take a minute and review your customer's open support tickets, follow-up with the customer on the open ones and make sure you communicate that you're on top of the situation.  And remember, leverage your teammates for assistance and advice.  

Thursday, January 10, 2013

Business Data Backup Press Release

Press Release

GAD Group Technologies, Inc. Partners with Carbonite to deliver Business Data Backup Solution to Business Community.

BOLINGBROOK, IL - January 10, 2013

Carbonite - CARB (NASDAQ), provider of data backup software solutions to small and medium sized business, and GAD Group Technology, Inc., a leading provider of managed IT and professional services, today solidified a reseller partnership that will result in the delivery of Business Data Backup Solutions.

Our Business Data Backup Solution will enable businesses of all sizes to protect the most critical asset - Data.  While hardware come and go and software applications undergo many lifecycle changes, the data that reside on these platforms remains the most important asset that a business cannot afford to lose.  Business will have a choice to backup their data to both a local device or to a device located off premise (i.e. The Cloud).

The Business Data Backup Solution features:

  • Easy Setup - Start backing up all computers in just minutes
  • Automatic Backup - Business data automatically backed up nightly
  • Encrypted, Offsite Storage - Rest easy knowing files are encrypted and stored offsite at highly secure data centers.
  • Easy Restore - Get your files back - and get back to business quickly!
  • U.S. Based Customer Support - Count on GAD Group to manage solution and provide responsive customer support.
  • Unlimited computers - Backup your entire office for one flat, annual fee.
  • Windows Server Backup - Protect the content saved on your Windows Server safely to the cloud.
  • Protects Windows 7, XP, Server 2003 & Server 2008
  • Live Backup of Databases and Mail Servers
  • Fully customizable backup policies
  • User defined backup retention.
  • Data stored in SAS 70 Type II certified data centers
  • HIPAA security compliant
  • Peace of Mind - Carbonite protect more than 1 million systems

About GAD Group Technologies, Inc.

GAD GROUP TECHNOLOGY, INC. was established to meet the demand for cutting edge technology and sophisticated software applications by small and medium sized businesses, government municipalities and not-for-profit organizations with limited budgets for full time “IT Resources.”  We have over 50 years of combined experience in the area of Information Technology, Project Management, Office Automation, and Web Application Services. By conducting software research and development, network engineering, project management, technology security, as well as a host of other technology services,we can serve small to medium sized businesses, large corporation, and government municipalities.

Contact:
Sales Team
GAD Group Technology, Inc.
630-226-1013, sales@gadgroup.com

Friday, March 9, 2012

Dual NIC Traffic Prioritization

Scenario:  You have two network cards installed on your computer that's running Windows 7.  One is connected to a High Speed Internet Connection.  The other is connected to your corporate LAN.  You want all Internet traffic to go through the high speed Internet connection.  You want corporate email, business applications and access to corporate file servers to use the corporate LAN connection.

The best way to accomplish this is by configuring metrics on the network cards.  In a nutshell the operating system sends all traffic out through the network card that has the lowest metric setting.  Since I want my computer to use the Wireless Connection for High Speed Internet browsing, I'm going to configure this NIC with the lowest Metric.  Then I'll set the other LAN NIC to have a metric setting that is higher than the Wireless NIC.  See Screen shots below...

Screen 1 - Select Internet Protocol Version 4 then click properties

Screen 2 - Click on Advanced button


Screen 3 - Uncheck the Automatic metric box then enter your metric setting



Perform the above action on both NIC cards; setting the metric for the highest priority NIC with the lowest metric number.  Windows routing will take care to route your corporate LAN traffic based on the IP Address and Default Gateway Settings.

Enjoy...