{"id":211,"date":"2015-11-25T20:53:00","date_gmt":"2015-11-25T19:53:00","guid":{"rendered":"http:\/\/darko-keric.from.hr\/?p=211"},"modified":"2015-11-25T21:24:57","modified_gmt":"2015-11-25T20:24:57","slug":"dhpc-klaster-dnssec-iscsi-nlb-dac-workfolders","status":"publish","type":"post","link":"http:\/\/darko-keric.from.hr\/?p=211","title":{"rendered":"DHPC klaster, DNSSEC, iSCSI, NLB, DAC, WorkFolders&#8230;"},"content":{"rendered":"<p>DHCP ipv4 scope-advanced-split scope \u2013 add server x2 aktivacija scope-a kasnije<\/p>\n<p>ipv4 \u2013 new superscope \u2013 activate\u00a0\u00a0\u00a0 ipv4 \u2013 configure failover<\/p>\n<p>DNSSEC &#8211; DNS \u2013 SERVERDC-&gt;Forward Lookup Zones -&gt; desni klik DNSSEC \u2013 Sign the Zone<\/p>\n<p>GPO \u2013 Computer-&gt; Policies-&gt;Windows Setting-&gt;Name Resolution Policy -&gt; Suffix \u201eracunarstvo.edu\u201c + Enable DNSSEC + Require DNS clients to check that the name and address has been validated by the DNS server<\/p>\n<p>Portovi PS \u2013 get-dnsserver + dnscmd \/config \/socketpoolsize 3000 \u2013 restart servisa<\/p>\n<p>Cache\u00a0 PS \u2013 set-dnsservercache \u2013LockingPercent 75 \u2013 restart servisa<\/p>\n<p>Izrada GlobalNameZone<\/p>\n<p>PS \u2013 Add-DnsServerPrimaryZone \u2013Name Alegebra.edu \u2013ReplicationScope Forest<br \/>\nSet-DnsServerGlobalNameZone \u2013AlwaysQueryServer $true<br \/>\nAdd-DnsServerPrimaryZone \u2013 Name GlobalNames \u2013 ReplicationScope Forest<\/p>\n<p>+host zapis i a zapis<\/p>\n<p>iSCSI \u2013 configuration tab (kopirati string), dodati diskove -&gt; add <b>File and Storage Services-&gt; File and iSCSI Services<\/b> + <b>Multipath I\/O <\/b><\/p>\n<p><b>SM konzola -&gt; Task -&gt; iSCSI virtual disk location .. next,next &#8230; Select a method to identify the initiator<\/b> prozor IQN kopirati string + CHAP<\/p>\n<p>Na drugom serveru -&gt; iSCSI initiator Properties -&gt; 1. Configuration &#8211; &gt; CHAP, 2. Target server1.racunarstvo.edu\u201c -&gt; Connect &amp; Advanced: Enable CHAP log on<\/p>\n<p>SM \u2013 File and Storage services -&gt; Storage Pools -&gt; New Storage Pool -&gt; Virtual disk -&gt; New virtual disk &#8230; next,next &#8230; ReFS &amp; finish<\/p>\n<p>DeDuplikacija -&gt;AddRole \u2013 iSCSI -&gt; Data Deduplication -&gt; Finish, desni klik na volumen, configure Data DeDuplication. PS &#8211; <b>Start-DedupJob \u2013Volume F: -Type Optimization <\/b><\/p>\n<p><b>NetworkLoadBalance <\/b>\u2013 IIS + NLB -&gt; IIS Default web site c:\\website + desno providers NTLM move up<br \/>\nNLB klaster-&gt;Network Load Balacing Manager -&gt; Cluster -&gt; New, ime, ip, www, multicast. Rule remove, pa add 80, add 443. Desni klik na domenu -&gt; Add host to cluster<\/p>\n<p><b>DAC<\/b><\/p>\n<p>Add role <b>File Server resource Manager. <\/b>GPO Computer -&gt; Policy -&gt; Admin Templates -&gt; System -&gt; KDC, KDC support for claims&#8230; Enable i always. Urediti odjel usera, dodati grupe<\/p>\n<p>AD administrative center -&gt; DAC -&gt; <b>Claim Type<\/b>-&gt; New -&gt; department &amp; Display name Odjel, ni\u017ee add Uprava i Prodaja. <b>Resource Properties<\/b> Department i Confidentiality ENABLE &amp; Department properties add Uprava.<\/p>\n<p><b>Resource Property Lists, Global Resource Property Lists &lt;- provjerit jesu ovdje Confidentiality i Department<\/b><\/p>\n<p><b>File Server Resource Manager <\/b>&#8211; <b>Classification Management-&gt; Classification Properties <\/b><i>refresh<\/i><b>-&gt; Create Classification rule <\/b>odabrati folder i string \u201eTajno\u201c &amp; <b>Evaluation Type<\/b> -&gt; <b>Re-evaluate existing property values <\/b>&amp; uklju\u010diti <b>Overwrite the existing value<\/b>. Run Classification With All Rules Now<\/p>\n<p>Properties na datoteku &amp; Classification confidentiality, properties na folder i Classification Department<\/p>\n<p>DAC \u2013 Create Access Rule -&gt; <b>Target Resource<\/b> Edit, Central Access rule \u201eOdjel\u201c-&gt; Add condition: <b>Resource- Department-Equals-Value-Uprava<\/b> , zatim dodati Authenticated users u permission. Add condition:<\/p>\n<p><b>User-Odjel-Equals-Resource-Department <\/b><\/p>\n<p>DAC \u2013 Create Access Rule -&gt; <b>Target Resource<\/b> Edit, Central Access rule \u201eTajno\u201c\u00a0 Add Condition: <b>Resource-Confidentiality-Equals-Value-High<\/b> Permission na Authenticated modify, <b>User-Odjel-Equals-Value-Uprava &amp; Device-Group-Member of each-Value<\/b> &amp; dodati ra\u010dunala uprave<\/p>\n<p><b>New-&gt; Central Access Policy\u00a0 <\/b>\u201ezastita\u201c, Add \u201eOdjel\u201c, Add \u201eTajno\u201c<\/p>\n<p>GPO -&gt; Computer -&gt; Policies -&gt; Windows Settings -&gt; Security Settings -&gt; File system -&gt; <b>central access policy <\/b>Manage \u201eZastita\u201c Add<\/p>\n<p><b>Advanced Security Settings<\/b> for ShareDC. Kliknite na karticu <b>Central Policy<\/b> i zatim kliknite opciju <b>Change<\/b> -&gt; Zastita.<\/p>\n<p>Poruka: <b>Computer Configuration-&gt; Policies-&gt; Administrative Templates-&gt; System-&gt; Access Denied Assistance <\/b><\/p>\n<p>WorkFolders FileServerResourceManager &amp; WorkFolders feature<\/p>\n<p>PS &#8211; <b>New-SelfSignedCertificate \u2013DnsName \u201eServerdc.racunarstvo.edu\u201c \u2013 CertStoreLocation Cert:Localmachine\\My<\/b> &lt;-kopirati Thumbprint<\/p>\n<p><b>$cert= Get-Childitem \u2013Path cert:\\LocalMachine\\My\\OVDJE_ZALIJEPITE_OTISAK <\/b><\/p>\n<p><b>Export-Certificate \u2013Cert $cert \u2013Filepath C:\\Sharedc\\Serverdc.p7b \u2013Type P7B <\/b><\/p>\n<p>&nbsp;<\/p>\n<p>CMD -&gt; <b>netsh http add sslcert ipport=0.0.0.0:443 certhash=OVDJE_ZALIJEPITE_OTISAK_CERTIFIKATA appid={CE66697B-3AA0-49D1-BDBD-A25C8359FD5D} certstorename=MY <\/b><\/p>\n<p>WorkFolders -&gt; Task -&gt;\u00a0 New Sync share, odabrati mapu, Add Svi_korisnici, Isklju\u010dite opciju <b>Automatically lock screen and require a password, <\/b>create<\/p>\n<p>GPO: User -&gt; Policies -&gt; Admin Temp-&gt; Windows Components -&gt; Work Folders (Specify WF settings \u2013 enabled, url: serverdc.racunarstvo.edu i Force Automatic setup)<\/p>\n<p>Computer Configuration-&gt; Policies-&gt; Windows Settings-&gt; Security Settings-&gt; Public Key Policies \u2013 Trusted Root Certification Authorities -&gt; Import \u201eC:\\Sahre\\serverdc.p7b\u201c finish<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DHCP ipv4 scope-advanced-split scope \u2013 add server x2 aktivacija scope-a kasnije ipv4 \u2013 new superscope \u2013 activate\u00a0\u00a0\u00a0 ipv4 \u2013 configure failover DNSSEC &#8211; DNS \u2013 SERVERDC-&gt;Forward Lookup Zones -&gt; desni klik DNSSEC \u2013 Sign the Zone GPO \u2013 Computer-&gt; Policies-&gt;Windows &hellip; <a href=\"http:\/\/darko-keric.from.hr\/?p=211\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":348,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0},"categories":[6],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/darko-keric.from.hr\/?p=211\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DHPC klaster, DNSSEC, iSCSI, NLB, DAC, WorkFolders... - Sistemski in\u017eenjer\" \/>\n<meta property=\"og:description\" content=\"DHCP ipv4 scope-advanced-split scope \u2013 add server x2 aktivacija scope-a kasnije ipv4 \u2013 new superscope \u2013 activate\u00a0\u00a0\u00a0 ipv4 \u2013 configure failover DNSSEC &#8211; DNS \u2013 SERVERDC-&gt;Forward Lookup Zones -&gt; desni klik DNSSEC \u2013 Sign the Zone GPO \u2013 Computer-&gt; Policies-&gt;Windows &hellip; Continue reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"http:\/\/darko-keric.from.hr\/?p=211\" \/>\n<meta property=\"og:site_name\" content=\"Sistemski in\u017eenjer\" \/>\n<meta property=\"article:published_time\" content=\"2015-11-25T19:53:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2015-11-25T20:24:57+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"darko-keric\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/darko-keric.from.hr\/#website\",\"url\":\"https:\/\/darko-keric.from.hr\/\",\"name\":\"Sistemski in\\u017eenjer\",\"description\":\"System administrator\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/darko-keric.from.hr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/darko-keric.from.hr\/?p=211#webpage\",\"url\":\"http:\/\/darko-keric.from.hr\/?p=211\",\"name\":\"DHPC klaster, DNSSEC, iSCSI, NLB, DAC, WorkFolders... - Sistemski in\\u017eenjer\",\"isPartOf\":{\"@id\":\"https:\/\/darko-keric.from.hr\/#website\"},\"datePublished\":\"2015-11-25T19:53:00+00:00\",\"dateModified\":\"2015-11-25T20:24:57+00:00\",\"author\":{\"@id\":\"https:\/\/darko-keric.from.hr\/#\/schema\/person\/5e2f76737b07a700e0e2a108d173e612\"},\"breadcrumb\":{\"@id\":\"http:\/\/darko-keric.from.hr\/?p=211#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/darko-keric.from.hr\/?p=211\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/darko-keric.from.hr\/?p=211#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/darko-keric.from.hr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DHPC klaster, DNSSEC, iSCSI, NLB, DAC, WorkFolders&#8230;\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/darko-keric.from.hr\/#\/schema\/person\/5e2f76737b07a700e0e2a108d173e612\",\"name\":\"darko-keric\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/darko-keric.from.hr\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"http:\/\/0.gravatar.com\/avatar\/0400800f6ebec266fcb39a1cb31b0b0e?s=96&d=mm&r=g\",\"contentUrl\":\"http:\/\/0.gravatar.com\/avatar\/0400800f6ebec266fcb39a1cb31b0b0e?s=96&d=mm&r=g\",\"caption\":\"darko-keric\"},\"url\":\"http:\/\/darko-keric.from.hr\/?author=348\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/darko-keric.from.hr\/?p=211","og_locale":"en_US","og_type":"article","og_title":"DHPC klaster, DNSSEC, iSCSI, NLB, DAC, WorkFolders... - Sistemski in\u017eenjer","og_description":"DHCP ipv4 scope-advanced-split scope \u2013 add server x2 aktivacija scope-a kasnije ipv4 \u2013 new superscope \u2013 activate\u00a0\u00a0\u00a0 ipv4 \u2013 configure failover DNSSEC &#8211; DNS \u2013 SERVERDC-&gt;Forward Lookup Zones -&gt; desni klik DNSSEC \u2013 Sign the Zone GPO \u2013 Computer-&gt; Policies-&gt;Windows &hellip; Continue reading &rarr;","og_url":"http:\/\/darko-keric.from.hr\/?p=211","og_site_name":"Sistemski in\u017eenjer","article_published_time":"2015-11-25T19:53:00+00:00","article_modified_time":"2015-11-25T20:24:57+00:00","twitter_card":"summary","twitter_misc":{"Written by":"darko-keric","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/darko-keric.from.hr\/#website","url":"https:\/\/darko-keric.from.hr\/","name":"Sistemski in\u017eenjer","description":"System administrator","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/darko-keric.from.hr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"WebPage","@id":"http:\/\/darko-keric.from.hr\/?p=211#webpage","url":"http:\/\/darko-keric.from.hr\/?p=211","name":"DHPC klaster, DNSSEC, iSCSI, NLB, DAC, WorkFolders... - Sistemski in\u017eenjer","isPartOf":{"@id":"https:\/\/darko-keric.from.hr\/#website"},"datePublished":"2015-11-25T19:53:00+00:00","dateModified":"2015-11-25T20:24:57+00:00","author":{"@id":"https:\/\/darko-keric.from.hr\/#\/schema\/person\/5e2f76737b07a700e0e2a108d173e612"},"breadcrumb":{"@id":"http:\/\/darko-keric.from.hr\/?p=211#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/darko-keric.from.hr\/?p=211"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/darko-keric.from.hr\/?p=211#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/darko-keric.from.hr\/"},{"@type":"ListItem","position":2,"name":"DHPC klaster, DNSSEC, iSCSI, NLB, DAC, WorkFolders&#8230;"}]},{"@type":"Person","@id":"https:\/\/darko-keric.from.hr\/#\/schema\/person\/5e2f76737b07a700e0e2a108d173e612","name":"darko-keric","image":{"@type":"ImageObject","@id":"https:\/\/darko-keric.from.hr\/#personlogo","inLanguage":"en-US","url":"http:\/\/0.gravatar.com\/avatar\/0400800f6ebec266fcb39a1cb31b0b0e?s=96&d=mm&r=g","contentUrl":"http:\/\/0.gravatar.com\/avatar\/0400800f6ebec266fcb39a1cb31b0b0e?s=96&d=mm&r=g","caption":"darko-keric"},"url":"http:\/\/darko-keric.from.hr\/?author=348"}]}},"_links":{"self":[{"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/posts\/211"}],"collection":[{"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/users\/348"}],"replies":[{"embeddable":true,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=211"}],"version-history":[{"count":2,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/posts\/211\/revisions"}],"predecessor-version":[{"id":213,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/posts\/211\/revisions\/213"}],"wp:attachment":[{"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=211"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}