|
|
 |

 |
|
Microsoft® Windows® 2000 Server Administrator's Companion, Second Edition
|
|
|
Author
|
|
Charlie Russel, Sharon Crawford, and Jason Gerend
|
|
|
Pages
|
1632
|
|
Disk
|
N/A
|
|
Level
|
Int/Adv
|
|
Published
|
08/14/2002
|
|
ISBN
|
9780735617858
|
|
Price
|
$69.99
To see this book's discounted price, select a reseller below.
|
|
|
|
|
 |
|
|
Index
A
A (address) records, 456, 500
abstract class, 422
access by policy
for mixed-mode domains, 1256-59
for native-mode domains, 1260-64
access by user, 1254-56
access control. See also ACLs (access control lists)
Macintosh, 819
NNTP virtual servers, 1132-33
overview of, 647-49
ownership and, 692
permissions, 692-94, 1106, 1124-25
resources controlled by, 691-92
SMTP virtual servers, 1138
access control entries (ACEs), 25
access control lists. See ACLs (access control lists)
"Access denied" error message, printers, 230
access permissions
FTP sites, 1124-25
Web sites, 1106
Accessibility Options, 69
Account Policies, 675, 683
Account tab, Action menu, 393-94
accounts. See user accounts
ACEs (access control entries), 25
ACLs (access control lists)
Active Directory and, 25
groups, 396
printers, 200
security implementation and, 18
ACPI (Advanced Configuration Power Interface), 100-101, 143
Action menu, 392-96
commands, 392
tabs and functions, 393-96
Active Directory
certificate storage, 656
data model, 25
DDNS and, 456
directory services and, 19
domains, 139
DSA and, 23-24
Global Catalogs, 27-28
ISA Server schema, 1180-82
locating files in, 358-59
migrating to, 11
name formats, 24
namespace, 150-51
naming contexts, 27
OUs, 139-40
Outlook Express support, 884
overview of, 19-20
partitions, 27
printer integration, 218-22
restoring, 1378
schema implementation, 25
security model, 25-27
sites, 139-40
structural domains, 139-40
synchronizing with Novell NDS, 767
terminology, 20-23
tree, 150-51
trust relationships, 140-42
Active Directory Domains and Trusts, 371-77
domain management, 375-77
domain modes, 372-74
functions of, 349
launching, 372
overview of, 371
trust relationships, 374-75
user principal name suffixes, 376
Active Directory Installation Wizard, 350-71
automatic DNS configuration, 360
child domains, 363
demoting domain controllers, 365-68
domain creation, 355-57
domain names, 357-58
forest creation, 364-65
functions of, 349
Global Catalog server, 370-71
identifying domain controllers, 368-70
installation options, 361
installation preparation, 351-53
launching, 353-55
locating files, 358-59
overview of, 350
permissions compatibility, 360-61
replica domain controllers, 362
tree creation, 364
upgrading domain controllers, 365
Active Directory Installation Wizard, screens
Configuring Active Directory, 368, 370
Database And Log Locations, 359
Domain Controller Type, 354-55
Network Credentials, 370
Remove Active Directory, 366
Shared System Volume, 359
Summary, 367
Active Directory objects, 378-86
computer objects, 398-99
delegating control, 389-90
group objects, 396-98
importing/exporting, 429-30
list of defaults, 384-85
moving, renaming, and deleting, 400-401
normal and advanced modes, 379-80
overview of, 21
types of, 378-79
user objects, 390-96
Active Directory Schema, 416-38
attributes of schema, 419-21
classes of schema, 422-24
display specifiers, 424-28
domain naming master role, 434-35
function of, 349
importing/exporting objects, 429-30
infrastructure master role, 437-38
launching, 417-19
Ldifde.exe utility, 428-31
overview of, 416
PDC emulator role, 431-33
RID master role, 435-37
schema master role, 433-34
security, 416-17
Active Directory Service Interfaces (ADSI), 19
Active Directory Sites and Services, 403-16
domain replication, 407-08
functions of, 349
launching, 408
overview of, 403-05
replication objects, 408-09
servers and connections, 410-12
site GPOs, 307
site link bridges, 415-16
site links, 413-15
sites, 405-06, 409-10
subnets, 412-13
updating names, 233
Active Directory Users and Computers, 377-401
Action menu, 392
adding users, 245-46
assigning rights, 254
changing domains, 380
configuring computers, 399
configuring groups, 398
configuring OUs, 386-88
configuring user accounts, 391-96
creating computers, 398-99
creating GPOs, 307
creating groups, 243-44, 396-97
creating user accounts, 260-61, 390-91
delegating control, 389-90
deleting groups, 244-45
deleting user accounts, 264-65
enabling/disabling user accounts, 264
finding user accounts, 265
function of, 349
group scope, 246
home folders for users, 270-71
launching, 377-78
managing OUs, 241-42
moving, renaming, and deleting objects, 400-401
moving user accounts, 266
overview of, 377
publishing printers, 400
publishing shared folders, 400
remote computer management, 399-400
renaming user accounts, 266-67
Reset Password option, 268
setting user account properties, 262-63
unlocking user accounts, 268-69
viewing objects, 378-86
adapter cards, vendor names, 1323
Add A New Replica dialog box, 592
Add Counters dialog box, 1291-92
Add Directory dialog box, 1014-15
Add Printer Wizard
AppleTalk printers, 199
local printers, 190-92
LPR printers, 198
Select The Printer Port screen, 835
shared printers, 193-94
TCP/IP printers, 194-95
Add Standalone Snap-In dialog box, 326
Add Standard TCP/IP Port Wizard, 195-96
Add Upgrade Package dialog box, 921
Add Volume Management Wizard, 618-19
Add/Remove Hardware Wizard
adding/removing devices, 108-09
troubleshooting devices, 109-10
Add/Remove Programs
applications, 972-74
NNTP Service, 1126
Office 2000, 976-77
RIS, 937-39
Terminal Services, 969-71
WINS servers, 513
Add/Remove Snap-In dialog box, 326, 681
address (A) records, 456, 500
address books, 849-53
adding LDAP directories, 852-53
adding PAB files, 852-53
configuring, 851-52
Contacts folder, 849
creating new folder, 850
directory service options, 1161
sharing with Outlook, 885-86
address database, Network Monitor, 1322-23
address names, Network Monitor, 1322
address reservations, DHCP, 476-77
Address Resolution Protocol (ARP), 451
Address tab, Action menu, 393
.ADM files, 1160
ADMIN$, special shares, 281
administration, 316-47
Administration Tools, 320-22
AT command, 345-47
connections. See CMAK (Connection Manager Administration Kit)
delegation of control, 340-41
event auditing, 333-39
IE (Internet Explorer). See IEAK (Internet Explorer Administration Kit)
MMC snap-ins for, 325-32, 349
scripts, 332, 1059
secondary logon, 317-20
Support Tools, 322-25
Task Scheduler, 341-45
administration, IIS
FTP sites, 1119
tools, 1057-59
WWW sites, 1085-86
administration models, remote access
access by policy for mixed-mode domains, 1256-59
access by policy for native-mode domains, 1260-64
access by user, 1254-56
Administration Tools, 320-22
list of, 320-21
local installation, 322
remote availability, 322
Administration Tools Setup Wizard, 322
Administration Web Site, 1143
administrative rights, domains, 39
Administrative Tools folder, Print Queue, 187
Administrator accounts
backup permissions and, 1361
passwords, 361
predefined user accounts, 257
renaming, 671
security of, 74, 267
administrators, use of delegation, 26-27
ADSI (Active Directory Service Interfaces), 19
adult-content filters, 879-80
Advanced Configuration Power Interface (ACPI), 100-101, 143
advanced mode, Active Directory Users and Computers, 379-80
Advanced Options dialog box, 68-69
Advanced RISC Computing (ARC), 1347
Advanced Security Setting dialog box, 689-90
Advanced TCP/IP Settings dialog box, 120
DNS Settings tab, 121-22
IP Settings tab, 120-21
Options tab, 124
WINS Settings tab, 122-23
AH (Authentication Header), 664-65
alerts, ISA Server, 1238-39
alerts, Performance Logs and Alerts
configuring, 1304-05
creating, 1304
permissions, 1305-07
saving settings, 1300
Alias (CNAME), resource record, 499
allocation units, 519
Analyzing System Security, 682
anonymous access
restrictions on, 1428
SMTP virtual servers and, 1138
Web sites and, 1109
answer files
creating, 89-97
OS images and, 947-48
antivirus software, 672
Apple Macintosh. See Macintosh Services
AppleTalk
configuring, 809-10
installing, 805-06
networks, 803
printing devices, 199, 835-36
protocol, 802-03
routing, 804, 806-09
Application Compatibility Toolkit, 962-63
Application Compatibility Updates, 960
application logs, 1285
application media pools, 597
application servers, 146-47
applications. See also software packages
categories, 912-13
compatibility issues, 959-63
disabling/not installing, 672
documenting, 50
installing, 971-77
NetWare-aware, 767-68
Office 2000, 976-77
properties, 918-20
publishing vs. assigning, 905-06
ARC (Advanced RISC Computing), 1347
architectural improvements, 137-44
Active Directory domains, 139
domain controllers and server roles, 137-38
hardware support, 142-43
sites, structural domains, and OUs, 139-40
software support, 143-44
trust relationships, 140-42
archiving event logs, 339, 1288
ARCServe (Computer Associates), 1430
ARP (Address Resolution Protocol), 451
arrays, disk, 1390. See also RAID (redundant array of independent disks)
arrays, ISA Server
creating, 1208-09
overview of, 1176
promoting stand-alone servers, 1210
removing servers, 1210-11
asymmetric encryption. See public-key encryption
asynchronous communication, 1034
AT command, 345-47
guidelines for, 346
scheduling tasks, 341
specifying user accounts, 345
structure of, 345-46
attributes
Active Directory, 21
adding to classes, 423
NetWare files vs. Windows files, 770
RADIUS, 1268
remote access policies, 1265
schema, 419-21
security templates, 674-75
Audit Object Access, 713-14
audit policies
accessing, 333-34
establishing, 712-13
auditing
event categories, 333, 712-13
event logs, 336-39
object access, 713-14
printer options for, 203-04
security logs, 714-15
security-related events, 648
settings, 334-36
turning on, 333-34
Auditing tab, Permissions dialog box, 1425
Authenticated Users, special identities, 293
authentication, 643-45
vs. authorization, 1252
FTP sites and, 1123
hardware enabled, 644
IAS, 1275
IPSec, 698, 705-06
Kerberos, 25
local computer certificates, 689-90
Macintosh Services, 813-15
mutual, 645
network, 685
NNTP virtual servers and, 1132-33
NTLM (NT LAN Manager) and, 661
overview of, 685-86
pass-through, 141
proof of identity and, 643
protocols for, 643-44
remote access servers and, 691, 1268
remote access settings, 1267
single sign-on, 645
sites and, 404
smart cards and, 686-89
SMTP virtual servers and, 1138
SSL handshake, 661-62
Web sites and, 1109-10
Authentication Header (AH), 664-65
Authentication Methods dialog box, 1110
authentication request, RADIUS, 1277
Authentication tab, Edit Dial-In Profile dialog box, 1267
Authoritative Restore, 1378-79
authorization
vs. authentication, 1252
DHCP servers, 475-76
by policies, 691
auto discovery, Web Proxy clients, 1232-35
Automatic Certificate Request Setup Wizard, 742-43
auxiliary class
Active Directory objects, 419
adding to structural class, 424
defined, 422
availability
clusters and, 559, 573-74
Dfs and, 581DHCP and, 460
mission-critical, 561
printer options for, 209
RAID levels and, 1395-96
Windows 2000, 10
B
back-to-back perimeter network, ISA Servers, 1177
backup domain controllers. See BDCs (backup domain controllers)
Backup Job Information dialog box, 1365-66
backup jobs
running, 1365-66
scheduling, 1366-68
Backup Log tab, 1362-66
Backup Operators group, 1361
Backup tab, 1360
Backup Type tab, 1362
Backup utility
Backup tab, 1360
disaster planning, 1375
ERDs and, 1344
limitations of, 1380-81
methods in, 1359
overview of, 1353
registry back up, 1429
Restore tab, 1372-73
backup window, 1356
Backup Wizard, 1369
Backup/Restore dialog box, 1089
backups, 1353-81. See also data protection and recovery
active files, 546
backup jobs, 1365-68
CAs, 735-36
configuring, 1362
data safety and, 615
disaster planning, 1375-76
disaster preparation, 1343
disaster recovery, 632-33
encrypted files, 1377
exchange servers, 1376-77
excluding files, 1363-65
file and folder access, 1361
IIS server, 1088-89
ISA Server, 1227-29
logs, 1362-63
media copies, 630-32
media selection, 1353-55
multiple drives and, 629-30
overview of, 1355
registry, 1428-32
Remote Storage and, 614
restoring data, 1372-75
restoring system state, 1377-79
restoring Windows, 1451
script selection, 1361
single drives and, 628-29
storage medium, 1361
third-party utilities, 1380-81
types of, 1356-58
upgrades and, 149
Bandwidth Allocation Protocol (BAP), 1267, 1269
bandwidth throttling, 1093, 1103
BAP (Bandwidth Allocation Protocol), 1267, 1269
BAP tab, Edit Dial-In Profile dialog box, 1267
bar codes, 597-98
Baseline Security Analyzer, 933
basic authentication, 1109
basic disks
converting to dynamic, 538-39
defined, 520
BDCs (backup domain controllers)
Active Directory and, 20
BDC/PDC synchronization, 149, 365
domain structure and, 39
domain upgrades and, 148, 160
offline domain backups, 149
BIND, 488
biometrics, 644
BIOS compatibility, 100-101
.BKF files, 1355, 1361
.BLG files, 1303
Block Policy Inheritance option, 304
boot disks
disaster preparation and, 1346-47
MS-DOS, 1347
remote, 958
system recovery and, 1439-40
boot log, 1448
Boot Logging option, 1448
booting
from CD-ROM, 70
from mirrored partition, 1441-42
boot.ini file, 1450-51
bottlenecks
disk activity and, 1314
monitoring, 1309
overview of, 1283-84
bridges
function of, 451
site link bridges, 415-16
brownouts, 1389
browsers
Configure Routing For Web Browser Applications link, 1202
customizing, 1157-59
managing printers from, 225-26
browsing vs. Browsing, 462-63
built-in groups
domain local, 249
global, 250
local, 248
business needs
cluster planning and, 562-63
identifying, 46-47
C
CA Properties dialog box
Exit Module tab, 739-40
Policy Module tab, 737-39
Security tab, 740-41
Storage tab, 740
caching, ISA Server
content downloads, 1221-23
overview of, 1174
policy for, 1203-05
reverse caching, 1211-13
size and location of, 1219-20
caching-only DNS servers, 509-10
CAL (Client Access License), 62
calendar, Web page, 878
capacity planning
server clusters and, 575-76
Terminal Services and, 968
capture buffer configuration, Network Monitor, 1321-22
capture filters, Network Monitor, 1326-28
address pair specification, 1327-28
pattern matching, 1328
protocol specification, 1327
capture triggers, Network Monitor, 1329-30
Capture window, Network Monitor, 1319-21
CAs (certification authorities), 653-55
backing up, 735-36
chain verification, 654
cross-root certification, 655
folder views, 733-34
hierarchy of, 653-54
issuing, 653
linking into a hierarchy, 750-52
permissions, 741
properties, 737-41
renewing, 737
restoring, 736
roles, 725-26
root CAs, 652
security of, 726-27
stand-alone CAs, 748-49
starting and stopping, 734
trusts, 654
types of, 724-25
catalogs, Indexing Service
cache configuration, 1016-18
configuring, 1013
corrupted, 1032
creating, 1012-13
defined, 1006
including/excluding directories, 1014-16
scanning indexes, 1018-19
CBC (cipher block chaining), 646
CD-based images, RIS operating system, 945-47
CD-ROM
backup storage on, 1355
booting from, 70
launching Setup from, 166
setup disks, 1346
Windows 2000 Service Pack, 323
CD-Rs, 1353-55
CD-RWs, 1355
certificate publishers, 721
Certificate Request Wizard, 655
certificate revocation lists. See CRLs (certificate revocation lists)
Certificate Services. See MCS (Microsoft Certificate Services)
certificate templates. See also security templates
features of, 723
list of, 722-23
overview of, 721
working with, 741-43
certificate trust and revocation, 743-48
adding CAs to CTL, 743-44
CRL distribution points, 745
distribution of trusted certificates, 745-47
managing CTLs, 747-48
publishing CRLs, 744
Certificate Trust List Wizard, 747-48
certificate trust lists (CTLs), 743-44, 747-48
certificates. See also MCS (Microsoft Certificate Services)
directories, 656
importing/exporting, 695-96
integrating with Active Directory, 9
issuing, 653-55, 742-43
obtaining, 686-87
public-key, 651-52
recovery agent, 711-12
registering, 655-56
renewing, 658, 737
requesting, 696-97, 749, 751-52
revoking, 656-58
snap-in for, 694, 749
software-based, 687
special purpose, 697-98
stored on local computer, 689-90
Certificates snap-in, 694, 749
certification authorities. See CAs (certification authorities)
Certification Authority Backup Wizard, 735-36
Certification Authority snap-in
backing up CAs, 735-36
folder views, 733-34
installing, 732-33
renewing CAs, 737
restoring CAs, 736
starting and stopping CAs, 734
Certreq utility, 753-54
Certsrv utility, 752-53
Certutil utility, 754
chain verification, CAs, 654
Change command
installing applications, 975
options of, 974-75
Check Server Wizard, 939-40
child domains
creating, 363
pass-through authentication, 141
CiDaemon, Indexing Service, 1006
cipher block chaining (CBC), 646
class A networks, 446
class B networks, 447
class C networks, 447
class D and E addresses, 447-48
classes
Active Directory, 419
schema, 422-24
clean install, 67, 1454-55
Client Access License (CAL), 62
Client Connection Manager, 994-1002
configuring connections, 998-1001
creating connections, 994-98
exporting/importing connections, 1001-02
Client Connection Manager Wizard, 995-96
Automatic Logon screen, 996
Connection Properties screen, 997
Create A Connection screen, 995-96
Icon And Program Group screen, 999
Screen Options screen, 997
Starting A Program screen, 998
Client Set dialog box, 1190-91
clients
domain upgrades and, 159-60
native mode and, 171
printer problems and, 227
software management for, 899
clients, IAS, 1276-77
clients, ISA Server
configuring, 1190-91
types of, 1174-75
clients, NetWare
selecting, 768-70
sharing resources, 768-69
clients, Outlook Express, 883
clients, RIS
configuring, 941-43
Group Policy settings, 943-44
viewing, 941
clients, Terminal Services. See Terminal Services Client Creator
clients, Windows 2000 servers, 5
cloning existing system, 97-99
clusters, 559-76
application scenarios, 560-61
defined, 559
DHCP servers, 481-82
optimum size of, 548-49
planning, 562-63
types of, 559-60
clusters, NLB
capacity, 566-67
concepts, 564-65
fault tolerance, 567, 1398
models, 565-66
optimization, 567-68
clusters, server
capacity, 575-76
concepts, 569-70
configuration, 573-75
failover and fall back, 573
fault tolerance, 1398
resources, 570-72
CMAK (Connection Manager Administration Kit), 1164-69
CMAK Wizard, 1165-68
deploying, 1168-69
installing, 1165
overview of, 1164-65
CMAK Wizard, 1165-68
CNAME (Alias), resource record, 499
color profile options, printers, 208
COM+ (Component Object Model), 8
command-line
administrative tasks window, 318-20
backups from, 1369-72
Dfs administration from, 593-94
improvements to, 347
MCS utilities, 752-54
setup parameters, 79-81
switches, 932
UNIX utilities, 793
comment frames, Network Monitor, 1324-25
communications
secure, 1111-16, 1138
synchronous vs. asynchronous, 1034
Windows 2000, 13
compatibility issues
applications, 959-63
mixed mode and, 169-70
Remote Storage and, 614
security templates and, 678
software and, 143-44
upgrades and, 159
Compatibility Modes, 960, 962
complete trust domain model, Windows NT, 155-56
Component Object Model (COM+), 8
components
IEAK and, 1160-61
Macintosh Services and, 804-05
manual installation and, 74-75
compression, 555
Computer Management snap-in, 327, 328
Computer Names screen, Setup Manager Wizard, 93
computers
backing up prior to upgrading, 149
configuring, 399
creating, 398-99
domain upgrade process and, 161-63
naming convention, 116
naming during installation, 78
renaming, 115
concepts. See terminology and concepts
configuration
devices. See device configuration
network settings. See networks, configuring
new server installations, 107-35
NWLink IPX/SPX, 124-25
storage, 125
TCP/IP. See TCP/IP configuration
tool. See Configure Your Server tool
troubleshooting, 1445-46
Configure DNS Server Wizard, 490
Configure Your Server tool, 125-29
Active Directory Installation Wizard and, 353-54
domain controllers, 126-27
first network server, 127-29
installing Terminal Services, 969
overview of, 125-26
shared folders and, 282-84
system status and, 366
conflict detection, DHCP servers, 484
Connection Manager Administration Kit. See CMAK (Connection Manager Administration Kit)
connection oriented protocols, 442
connection services
dial-up access. See dial-up remote access
IAS. See IAS (Internet Authentication Service)
remote access. See remote access
VPNs. See VPNs
connections
CMAK administration, 1164-65
creating, 411-12
dedicated lines, 1269
IPSec, 698, 706
SMTP virtual servers, 1137, 1138
Web sites, 1101
connections, Terminal Services
configuring, 998-1001
creating, 994-98
exporting/importing, 1001-02
properties, 989-90
connectivity
external, 49
printer problems and, 227
UNIX, 777-78, 784-87
consoles. See MMC (Microsoft Management Console); snap-ins
Contacts folder, Outlook, 849
content expiration, HTTP Headers, 1116
content ratings, HTTP Headers, 1117
content rules, ISA Server, 1194-96
Control subkey, HKLM\SYSTEM\CurrentControlSet, 1409
Convert command, 546-47
copy backups, 1358
Corporate Windows Update service, 85, 133
corpus, Indexing Service definitions, 1006
cost, RAID levels and, 1396
counter logs
adding counters to, 1299-1300
creating, 1299
file parameters, 1301-03
file types, 1303
overview of, 1298
permissions, 1305-07
counters
disk usage, 1314
memory and bottlenecks, 1309-10
network activity, 1315-16
paging, 1311
processor activity, 1312-13
counters, Performance Monitor, 1028-29
counters, System Monitor
adding, 1291
deleting, 1293
matching to graph lines, 1292-93
overview of, 1291
selecting, 1292
CPU
adding processors, 1452
Indexing Service and, 1009
message Queueing and, 1035
Terminal Services and, 967
Create A New Dfs Link dialog box, 589
Create A New Media Pool Properties dialog box, 605
Create New Attribute dialog box, 420
Create New Object dialog box, 391
Create New Schema Class dialog box, 422
Create Partition Wizard, 532-34, 536-37
Create Shared Folder Wizard, 818
Create Volume Wizard, 528-30
creator code, Mac OS X, 801, 824-26
CRLs (certificate revocation lists)
distribution points, 745
publishing, 744
revoking certificates, 656-58
CryptoAPI, 667-68
cryptographic service providers (CSPs), 668
cryptography
PKCS, 648
smart cards, 641-42
Windows applications and, 667-68
Cscript.exe, 332
CSPs (cryptographic service providers), 668
.CSV files, 339, 1288, 1303
CTLs (certificate trust lists), 743-44, 747-48
Custom Errors tab, Master Properties dialog box, 1117-18
D
daily backups, 1358
DAP (Directory Access Protocol), 19
data confidentiality, 645-46
data integrity, 646-47
data model, Active Directory, 25
data protection and recovery, 628-33. See also backups; EFS (Encrypting File System)
confidentiality, 645-46
disaster recovery, 632-33
integrity, 646-47
media copies, 630-32
multiple drive strategies, 629-30
Remote Storage and, 615
single drive strategies, 628-29
data storage, Outlook 2002, 847-49
data storage, registry, 1410-13
data types, 1410-11
disk-based keys, 1412
hive locations, 1412-13
volatile keys, 1411
data types
printers, 183, 230
registry, 1402, 1410-11
databases
backing up/restoring Dfs database, 593
compacting WINS database, 516-17
opening security database, 681
storing Active Directory database, 360
date configuration, 75
day-to-day operations. See administration
Dcpromo.exe, 354, 368
DDNS (Dynamic DNS), 456
dedicated lines, 1269
Default FTP site, 1071-72
Default NNTP Virtual Server Properties dialog box
General tab, 1130-31
newsgroup management, 1131-32
Security tab, 1132
Settings tab, 1131
default policy, 1253-54
default printer, 205default security templates, 676
Default Web Site, WWW Publishing Service, 1059-60
delegate assignment, Exchange Server, 863-64
Delegate Permissions dialog box, 864
delegated administration, 26-27
delegation of authority, DNS servers, 496-99
delegation of control, 340-41
Delegation of Control Wizard, 340, 389-90
Delivery tab, SMTP virtual servers, 1140-41
Demand Dial Interface Wizard, 1273-74
demand-dial interface
adding, 1273-74
VPN clients and, 1272
Deploy Software dialog box, 917
deploying
CMAK, 1168-69
IEAK, 1161-62
ISA Server, 1175-78
server and workstation function, 4
deployment planning, 45-53
business needs, 46-47
current setup, 48-50
future projections, 47-48
goal setting, 51-52
IT departments and, 50-51
IT needs, 46
overview of, 45
risk assessment, 52-53
DESCRIPTION subkey, HKLM\HARDWARE, 1407
destination sets, ISA Server
configuring, 1193-94
publishing, 1213-14
site and content rules and, 1196
device configuration, 108-14
adding/removing devices, 108-09
Device Manager and, 110-12
device properties, 112-13
manual installation and, 72
troubleshooting devices, 109-10, 113-14
device drivers
hardware, 9
MS-DOS vs. Windows, 594-95
Network Monitor, 1316-17
print servers, 216
printers, 206-07
Removable Storage, 595-96
signed, 143, 1449
troubleshooting, 1436
unsigned, 87
Windows 2000 support for, 143
Device Manager
accessing, 110
device properties, 112-13
toolbar icons, 111-12
troubleshooting devices, 113-14, 1445
Device Properties dialog box, 112-13
DEVICEMAP subkey, HKLM\HARDWARE, 1407
devices
adding/removing, 108-09
enabling/disabling, 111
printer options, 212-13
support in Windows 2000, 143
troubleshooting, 109-10
uninstalling, 111
Dfs (Distributed File System)
adding Dfs links, 589
advantages of, 580-82
clients and servers, 582-83
command-line administration, 593-94
concepts and terminology, 582-84
creating/opening Dfs roots, 587-88
database back up and restore, 593
fault tolerance of, 1397
NetBIOS or WINS and, 584
overview of, 12, 579
replication, 590-92, 950-51
setup, 587-92
stand-alone vs. domain based, 583-84
structure and topology, 585-87
Dfs clients, 582-83
Dfs database, 593
Dfs links
adding, 589
overview of, 585
replicas, 591-92
Dfs roots
creating/opening, 587-88
fault tolerance, 1397
overview of, 585
replicas, 590-91
Dfs servers, 583
DHCP (Dynamic Host Configuration Protocol)
availability, 460
directory services, 18-19
dynamic addressing, 118-19
installing on Window 2000 Server, 470-71
ISA Servers and, 1232-33
managing IP addresses, 459
moving between computers, 486-87
multiple servers, 459-60, 479-82
overview of, 458
DHCP Manager, 471
DHCP resource type, 571
DHCP servers
adding, 482-83
authorizing, 475-76
clustering, 481-82
conflict detection, 484
dynamic DNS updates, 477-79
lease duration, 474
lease management, 487-88
network design and, 468-70
options, 474-75
redundancy, 479-82
relay agents, 484-86
reservations, 476-77
scope creation, 471-74
scope modification, 483-84
Web Proxy auto discovery, 1234-35
dial-in constraints, remote access, 1266-67
Dial-In tab, Action menu, 395
dial-up entries, ISA Server, 1200
Dial-Up Networking, 1247-48
dial-up remote access, 1247-48
dictionary attacks, 642
differential backups, 1357
Diffie-Hellman, 701
digest authentication, 1109
digital IDs, 881-83, 891-92
Digital Signature Algorithm (DSA), 647
digital signatures
data integrity and, 646-47
e-mail and, 891-92
Directory Access Protocol (DAP), 19
Directory Security tab, FTP sites, 1125
Directory Security tab, Web sites, 1108-16
anonymous access and authentication, 1108-10
IP Address and DNS restrictions, 1111
secure communications, 1111-16
Directory Service Protocol (DSP), 19
directory services. See also Active Directory
address books options, 1161
certificates, 656
defined, 11
DHCP, 18-19
DNS, 18-19
FTP, 1125
Indexing Service catalogs, 1014-16
\Inetpub, 1059-60
LDAP, 852-53
local vs. remote virtual, 1066-67
SMTP, 1136
virtual, 1065-66, 1074-76
virtual vs. physical directories, 1070-71
Windows NT, 18-19
WINS, 18
X.500 and, 5
Directory Services Restore mode, 1378
Directory Synchronization Services. See MSDSS (Microsoft Directory Synchronization Services)
Directory System Agent (DSA), 23-24
directory-level administration, 1085, 1096-97
disaster planning, 1334-64
backups and, 1375-76
escalation procedures, 1340-41
iteration and, 1342
operating procedures, 1338-40
overview of, 1335-36
resource identification, 1337
response development, 1337-38
risk assessment, 1336-37
testing, 1341-42
disaster preparation, 1342-51
backups, 1343
boot disks, 1346-47
ERDs, 1343-45
fault tolerance, 1343
recovery console installation, 1348-49
recovery drives, 1350-51
recovery options, 1349-50
setup disks, 1346
disaster recovery, 632-33
Disk Administrator, 12, 522
disk arrays, 1390. See also RAID (redundant array of independent disks)
disk imaging, 98. See also SysPrep
disk management. See hard disks
Disk Management snap-in
accessing, 525
overview of, 522-23
partitioning/formatting disks, 125
disk partitioning, 71-72
Disk Probe (Dskprobe.exe), 324
disk quotas
enabling, 551-52
exporting/importing, 554
NTFS 5, 12-13
reports, 554
setting entries for users, 552-54
disk striping, 1035
disk-based keys, 1412
disks. See hard disks
display, System Monitor, 1293
Display Filter dialog box, 1330
display filters, Network Monitor, 1330-32
display specifiers, 424-28
defined, 424-25
modifying, 425-28
distinguished name (DN), 22-23
Distributed File System. See Dfs (Distributed File System)
distribution folders
creating, 82-83
hot fixes, 84-85
service packs, 83-84
distribution groups, 237, 397. See also groups
DN (distinguished name), 22-23
DNS (Domain Name System), 452-58
configuring, 121-22
DDNS and, 456
directory services, 18-19
domain namespace, 453
ISA Server and, 1233
as locating device, 11
name resolution, 453-55
restrictions for Web sites, 1111
reverse lookups, 455-56
root domains, 453
single internal/external namespace, 36-37
zone storage, 457-58
DNS forwarders, 507-08
DNS namespace
documenting prior to upgrades, 146
domain namespace, 453
planning for upgrade process, 150-51
single internal/external namespace, 36-37
DNS servers
Active Directory and, 351-53
automatic configuration, 360
caching-only, 509-10
configuring, 490-93
delegation of authority, 496-99
dynamic updates, 505-06
forwarders, 507-08
installing, 488-89
interoperability, 504-05
primary vs. secondary, 491
resource records, 499-502
root hints, 508-09
static addressing and, 119
subdomains, 496-99
Web Proxy auto discovery, 1233
WINS resolution and, 506
zone creation, 494-96
zone transfers, 502-04
DNS settings, TCP/IP configuration, 121-22
DNS zones
creating, 494-96
storing, 457-58
transferring, 502-04
Document List page, printers, 226
documentation, disaster planning, 1339
documentation, network, 145-48
account and resource domains, 146
application servers, 146-47
DNS namespaces, 146
domain controllers, 146
domain model, 145-46
hardware and software, 48
LAN Manager Replication Services, 147-48
trust relationships, 146
Windows NT 3.51 servers, 148
Windows NT RRAS servers, 147
documents
deleting stuck documents from printers, 232-33
fails to print, 229
moving between printers, 224-25
printing, 180-82
prints incorrectly, 228-29
Documents tab, Master Properties dialog box, 1108
domain controllers
Active Directory and, 20
changing identification of, 368-70
demoting, 365-68
documenting prior to upgrades, 146
improvements to, 137-38
multiple master and peer based, 39
promoting member and stand-alone servers to, 138
replicas, 362
setting up with Configure Your Server Tool, 126-27
special facts abouts, 129
upgrading PDCs to, 126-27
upgrading Windows NT 4, 365
domain local groups
assigning permissions to, 293
built-in, 249
strategy for using, 242-43
domain local scope, 238, 397
domain manager (Netdom.exe), 323
domain models, Windows NT, 151-56
complete trust, 155-56
documenting prior to upgrades, 145-46
multiple-master-domain, 153-55
single-domain, 151
single-master-domain, 151-53
Domain Name System. See DNS (Domain Name System)
domain names, 454
domain naming master role, 434-35
defined, 431
overview of, 434
seizing, 435
transferring, 434
domain structure
designing, 40-41
domains vs. OUs, 38-39
forests, 32-33multiple domains, 42-43
OUs, 41-42
security guidelines, 41
trees, 31-32
domain user accounts, 260-61
domains
accessing mixed-mode domains, 1256-59
accessing native-mode domains, 1260-64
Active Directory and, 139
Active Directory Domains and Trusts and, 377
Active Directory Installation Wizard and, 355-57
Active Directory Users and Computers and, 380
managers of, 375-76
membership in, 77
names, 357-58
operational modes, 169-72, 372-74
OUs vs., 240-41
planning, 30
replication. See replication
SMTP Service and, 1142-43
tree structure, 38-39
trust relationships, 374-75
upgrading, 146, 161
drive letter, changing, 549-50
driveletter$, special shares, 281
drivers. See device drivers
drives. See hard disks
DSA (Digital Signature Algorithm), 647
DSA (Directory System Agent), 23-24
Dsa.msc, 377
Dskprobe.exe (Disk Probe), 324
DSP (Directory Service Protocol), 19
dual booting, 63-65
FAT/FAT32 vs. NT, 547
issues with, 65
OSs and, 63-64
Windows 95/98 with Windows 2000 Professional, 165-66
dynamic addressing, 118-19
dynamic disks
advantages of, 524-25
converting basic disk to, 538-39
defined, 520
Dynamic DNS (DDNS), 456
Dynamic Host Configuration Protocol. See DHCP (Dynamic Host Configuration Protocol)
dynamic updates, DNS servers, 505-06
E
EAP (Extensible Authentication Protocol), 691
Edit Dial-In Profile dialog box, 1266
Authentication tab, 1267
Dial-In Constraints tab, 1266-67
Encryption tab, 1268
IP tab, 1267
Multilink and BAP tabs, 1267
Edit Rule dialog box, 869
Edit Rule Properties dialog box, 700
EFS (Encrypting File System)
data confidentiality and, 646
file/folder encryption/decryption, 709-10
recovering files, 710-12
recovery policy, 707-09
securing local data, 707
e-mail
attachments, 840
automatically processing, 880-81
junk e-mail and adult-content filters, 879-80
securing, 881-83
e-mail accounts
adding, 843-45
properties, 845
emergency repair disks. See ERDs (emergency repair disks)
emergency repair process, 1438-39. See also ERDs (emergency repair disks)
EMF (enhanced metafile)
printer data types, 183, 211
printer problems and, 230
Encapsulating Security Payload (ESP), 665
Encrypting File System. See EFS (Encrypting File System)
encryption
backing up encrypted files, 1377
best practices, 710
file system level, 555-57
public-key vs. symmetric key, 650-51
remote access settings, 1268
S/MIME messages, 659
Encryption tab, Edit Dial-In Profile dialog box, 1268
end-to-end, TCP packets, 442
end-to-end security, 698
enhanced metafile. See EMF (enhanced metafile)
enrollment agent certificate, 686
Enterprise CAs, 724
enterprise policy, ISA Server, 1189
enterprise root CAs, 725-26
enterprise subordinate CAs, 726
Enum subkey, HKLM\SYSTEM \CurrentControlSet, 1409
ERDs (emergency repair disks), 1343-45
creating, 1343-44
effective application of, 1345
emergency repair process and, 1439
registry back up and, 1429-30
error codes, HTTP status codes, 1118
error messages. See troubleshooting
ESP (Encapsulating Security Payload), 665
.ETL files, 1303
Eudora, 842
event auditing. See auditing
Event Detail tab, event properties, 1287
Event Header, 1286-87
Event Log, system security, 675, 683
event logs
archiving, 339
Fax Service, 896
filtering, 338
monitoring, 1057
searching, 337
setting size of, 338-39
viewing, 336-37
Event Viewer, 1284-89
archiving event logs, 339, 1288
event descriptions, 1287-88
Event Headers, 1286-87
event log options, 338-39
log files, 1285
NNTPSVC, 1046
overview of, 1284
set up errors, 107
SMTPSVC, 1044
snap-in, 1284
system problems, 1444
viewing logs on other computers, 1289
W3SVC, 1040
events
categories, 333, 712-13
descriptions, 1287-88
Eventvwr.msc, 1284. See also Event Viewer
Everyone group
domain local groups and, 249
printer permissions, 693
special identities, 293
.EVT files, 339, 1288
exception lists, Indexing Services, 1007-08
Exchange folders
modifying permissions, 864-66
offline access, 859-61
Exchange Server, 859-71
assigning delegates, 863-64
backing up, 1376-77
moderated folders, 869-71
modifying folder permissions, 864-66
offline folder access, 859-61
public folders, 866-69
sorting incoming mail by account, 864
synchronization settings, 861-63
Exclude Files tab, backup options, 1363-65
execute mode, Terminal Services, 972
exit modules, CAs, 720-21
Expiration Policy Wizard, NNTP Service, 1129
explicit (one-way) trusts, 374
explicit permissions, 290
Expression dialog box, 1332-33
Extend Volume Wizard, 539-40
extended partitions, 520, 535-37
extended volumes, 520, 539-41
Extensible Authentication Protocol (EAP), 691
F
Failed Requests folder, Certification Authority snap-in, 734
failover, 573, 574
fall back, server clusters, 573
FAT (File Allocation Table)
converting to NTFS, 546
dual booting and, 547
eliminating, 1057
file system formats, 534-35
file system selection, 60
permissions, 282
security of, 671
shares, 280, 282
fault tolerance, 1383-99
clustering, 1398-99
Dfs, 1397
DHCP servers, 468
disaster preparation and, 1343
MTTF/MTTR, 1383-84
multiple DNS servers, 502
NLB clusters, 567
power outages, 1389-90
power supply failure, 1385-86
RAID hardware vs. software, 1391
RAID hot-swap and hot-spare systems, 1397
RAID levels, 1391-96
remote storage devices, 630
voltage variations, 1387-89
Fax Service Management tool, 893-96
faxes
managing, 13, 893-96
sending, 896-97
File Allocation Table. See FAT (File Allocation Table)
File and Print Services for NetWare (FPNW), 757, 767
File and Printer Sharing For Microsoft Networks, 131-32, 1308-09
"File Not Found" errors, queries, 1025
file parameters, Performance Logs and Alerts, 1301-03
file replication service (FRS), 148, 581
File Server for Macintosh. See FSM (File Server for Macintosh)
File Server for Macintosh Properties dialog box
File Association tab, 826
Sessions tab, 827
File Share resource type, 571-72, 575-76
file sharing
accessing shares with Dfs, 580
memory optimization for, 131
removing unnecessary shares, 672
turning off, 1308-09
File Signature Verification utility, 1449
file systems
auditing events, 336
encryption, 555-57
FAT to NTFS conversion, 546
formatting options, 534-35
NTFS 5. See NTFS 5
selection, 60
support, 11-13
UNIX, 778-80, 788-92
File System, system security, 675, 683
file transfer protocol. See FTP (file transfer protocol)
file-level administration
IIS, 1097-98
overview of, 1085
file-level permissions, 635, 637-38
filename conversion, 88-89
files
adding to backups, 1361
backing up to, 1355
encrypting/decrypting, 709-10
excluding from backups, 1363-65
extensions, 911-12
filename conversion, 88-89
permissions, 280, 292, 295
recovering, 710-12
files, NetWare
file services for NetWare clients, 767
migrating to Windows 2000, 767
Filter, Indexing Service, 1006
Filter Options dialog box, 381
filters
Active Directory objects, 381
adult-content filters, 879-80
event logs, 338
Indexing Service, 1007-08, 1031
IPSec, 698, 704-05
PPTP filters for VPNs, 1270-71
URLScan Filter, 1052
find. See searches
Find dialog box, 337, 1416-17
Find Servers commands, 978
Find User, Contacts, And Groups dialog box, 265-66, 382-83
FindFast, Microsoft Office, 614
firewall clients, ISA Server
changing defaults, 1231-32
installing, 1235-36
overview of, 1174-75
routing configuration, 1201
firewalls
configuring for ISA Servers, 1197-99
SonicWall devices, 1172
Firewire (IEEE 1394), 143, 179
Flexible Single Master Operations (FSMO), 417
folder permissions, 280
Folder Redirection, 310-14
based on group membership, 312-13
conditions of, 310-11
redirecting to one location, 311-12
removing, 314
folders
accessing for backups, 1361
encrypting/decrypting, 709-10
permissions, 294
sharing. See shared folders
forests
creating, 364-65
designing, 40-41
multiple domains, 43
namespace for, 32-33
operation master roles in, 431
trees in, 364
forks, Mac OS X, 801-02
form media, printers, 215-16
formats
files systems, 534-35
partitions or volumes, 547-49
forms, Outlook 2002
basic, 856-58
storing and publishing, 858-59
forward lookup zones, 456, 494-95
forward lookups, 477
forwarders, DNS, 507-08
FPNW (File and Print Services for NetWare), 757, 767
Frame Viewer window, Network Monitor, 1318-19
frames, Network Monitor
Capture window, 1319-21
commenting, 1324-25
Frame Viewer window, 1318-19
overview of, 1317
printing captured frames, 1325-26
statistics, 1319-21
free media pools, 597
FrontPage extensions, 1081-82, 1093-95
FRS (file replication service), 148, 581
FSM (File Server for Macintosh)
installing, 812-13
overview of, 795, 804
permissions, 819-22
types and creator codes, 824-26
Volume Security area, 823-24
FSMO (Flexible Single Master Operations), 417
FTP (file transfer protocol)
sessions, 1043-44
UNIX connectivity and, 777
FTP Publishing Service, 1071-76
default sites, 1071-72
FTP Site Creation Wizard, 1072-74
site creation, 1072-73
site testing, 1073-74
virtual directories for FTP sites, 1074-76
FTP Site Creation Wizard, 1072-74
FTP sites, 1119-26
creating, 1072-73
default, 1071-72
directory properties, 1125
FTP Site tab, 1120-22
Home Directory tab, 1124-25
IIS administration for, 1119
Messages tab, 1124
permissions, 1076-79
properties, 1119-22
Security Accounts tab, 1122-23
starting, stopping, and pausing, 1080
testing, 1073-74
G
Gateway for NFS, 790
Gateway Service for NetWare. See GSNW (Gateway Service for NetWare) gateways
enabling NetWare, 765
function of, 450
gateway services vs. client services, 769-70
NetWare clients and, 759
GCs. See Global Catalogs (GCs)
General tab, Action menu, 392-93
Generic Application resource type, 572
Generic Service resource type, 572
geographical naming conventions, 34-35
Get Request message, HTTP, 1041
Getting Started Wizard, ISA Servers
Configure Cache Policy link, 1203-05
Configure Dial-Up Entries link, 1200
Configure Firewall Protection link, 1197-99
Configure Routing For Firewall And SecureNAT Clients link, 1201
Configure Routing For Web Browser Applications link, 1202
Configure Site And Content Rules link, 1195-96
default settings, 1187-88
ISA Server Security Configuration Wizard, 1196-97
policy configuration, 1189
Global Catalogs (GCs)
demoting, 367
domain controllers and, 129
finding objects, 27-28
setting GC servers, 370-71
site topology and, 157
universal groups listed in, 239
global groups
assigning permissions, 293
built-in, 250
strategy for using, 242-43
global scope, 238, 397
globally unique identifier (GUID), 21, 957
goal setting
cluster planning, 562-63
deployment planning, 51-52
GPCs (Group Policy Containers), 302
GPOs (Group Policy Objects)
creating, 307
disabling nodes, 309
finding existing, 307-08
link management, 309-10
overriding inheritance, 303-04
overview of, 301-02
setting scope, 305-07
storing data as, 300
trusted certificates and, 745-48
GPTs (Group Policy Templates), 302
Graph view, System Monitor, 1294
graphs
counters and, 1292-93
value of, 1307
group policies, 299-314
accessing, 302
adding packages with, 916-18
assigning logon scripts, 278
assigning rights to groups, 254
components of, 301-02
effectiveness of, 305
folder redirection, 310-14
GPO creation, 307
GPO links, 386
GPO scope, 305-07
Group Policy Editor and, 307-10
IE customization, 1147
implementation order, 304
inheritance, 303-04
issuing certificates, 742-43
OUs and, 240
overview of, 6, 299
refreshing, 310
RIS clients and, 943-44
security templates and, 673
service pack deployment, 932-33
slow link detection, 914-15
Software Installation and Maintenance, 85, 900
Group Policy Containers (GPCs), 302
Group Policy Editor, 307-10
disabling GPO node, 309
editing Group Policy components, 301
managing GPO links, 309-10
nodes of, 308
refreshing policies, 310
System Policy Editor and, 300
Group Policy Objects. See GPOs (Group Policy Objects)
Group Policy Templates (GPTs), 302
groups
access control, 647
adding users to, 245-46
built-in, 248-50
configuring, 398
creating, 243-44, 396-97
delegation of control, 340
deleting, 244-45
global and domain local, 242-43
local groups, 247
names, 242
network performance, 239
overview of, 237
printer priority options, 209-10
rights assignments, 253-54
scope of, 238-39, 246
server clusters and, 570
universal, 243
GSNW (Gateway Service for NetWare)
configuring, 764-66
installing, 762-63
overview of, 757
sharing printers and, 193
Guest accounts
accessing FSM volumes, 821-22, 824
disabling, 672
as predefined user account, 257
GUID (globally unique identifier), 21, 957
Next
Last Updated: August 29, 2002
|