Posts

Posts uit april, 2008 tonen

Tools - CurrPorts

Afbeelding
CurrPorts is a nifty tool, that allows you to see which applications or services are listening on (occupying) what TCP or UDP ports. Also includes the option to kill processes etc. Download it here @ NirSoft . Today, I was trying to get the excellent Kiwi Syslog Daemon working on a server, but although the program said the service was started, nothing would appear on-screen or in the logs. It appeared the UDP 514 port was already occupied by another syslog service (from Eicon's DIVA monitor, in this case), so Kiwi's Syslog Service could not start. Thanks to CurrPorts, this could be detected quite easily. Regards, Rene

Laughing Matters - XADM: Directory Won't Start if System Date Later Than 2038

In this knowledge base article , Microsoft confirms a problem in Exchange 4.0 or 5.0. Event IDs 1121 and 5000 are logged when starting the Exchange server, which indicate that the Information Store service is not reachable (or not started). Cause: The Directory service will not start if the system date is later than January 17, 2038. There's no need to upgrade, however, because Microsoft is researching this problem and will post new information in the Microsoft Knowledge Base as it becomes available... :-) Regards, Rene

Lessons Learned - Cisco ASA 5505 and TCP request discarded

Hi there, Last week, we set up a Cisco ASA 5505 firewall in one of our customers' LAN. It should replace the ISA 2000 firewall over there, because we need to create a site-to-site tunnel to a PIX 515E on a remote location. All went fine with this ASA 5505, except that it would not pass any traffic from the internet to the LAN. From the inside out, all was OK. From the outside in, nothing would pass the firewall. The relevant config lines were as follows: static (inside,outside) tcp w.x.y.z 25 10.10.10.10 25 netmask 255.255.255.255 access-list outside01 permit tcp any host w.x.y.z eq 25 access-group outside01 in interface outside So, here we redirect all SMTP traffic on public interface with IP w.x.y.z to private host 10.10.10.10. Nothing much would happen. Internally, the SMTP host was listening, of course. From outside, the interface with IP w.x.y.z was pingable, of course. From the outside, configuring the ASA with SSH or HTTPS went fine. (So, traffic TO the

SSO for OWA 2007

Did some changes today to an existing Lotus Domino 6.x environment, in which user use iNotes (Domino Web Access) for accessing e-mail and calendar. This all worked fine, but as we are migrating from Domino/Notes to Exchange/Outlook, some modifications needed to be made to the web setup. We used a WebSphere plug-in from IBM, to automatically authenticate Windows users to the Domino-environment. This is done by using a ISAPI filter from IBM, configured in an IIS-website, with which incoming requests on - say - port 80 in IIS are re-routed to - again, say - port 81 on the Domino webserver. The ISAPI filter passes the username from the Windows environment to the Domino server, and thus authenticates the user there. Requirement is that the fully-distinguished Windows username (DOMAIN\Username) is known in the Domino-environment. By adding this fully-distinguished Windows username to the user's Domino full name, all this got to work. Very nice! But, as I said, we're migrating f

Testing Windows Live Writer

A few days ago, I mentioned testing blog.gears. Although this worked nice, I cannot get it back to work again. Probably, blog.gears is just a "coding example", but I am just guessing. So, did a little more searching for an offline blogger client for windows , and Google came up with Windows Live Writer . Looks nice, interface-wise... Works like a charm! Regards, Rene

Great tip for Dutch readers: onlinespamfilter.nl

Hi there, A great tip for Dutch readers: if your company is experiencing uncurable spam problems, try Onlinespamfilter.nl . Making onlinespamfilter.nl work is very simple: Have Jasper Toonen @ Onlinespamfilter.nl create a 30-day trial account for you; this will involve telling him at which IP address the scanned mail should be delivered; most of the times, this will be the public IP address of your private mail server on the LAN; Remove any existing MX-records from your domain; Add two MX-records for the scanning servers at onlinespamfilter.nl; C'est ca! Additional changes can be made to your firewall or mail server, but basically this is all that is required. The result of all this is a practically spam-free and virus-free mail flow! Really, almost no spam is coming thru. And although onlinespamfilter.nl's services are mainly to prevent spam for your domains, they do provide virus-scanning as well. (As Jasper says: spam filtering i

Another test, this time using blog.gears

How does this look? Just learned about Google Gears and blog.gears. Have been interested in an off-line blogger editor, and maybe this is the one I need. Anyway, let's have a look... Regards, Rene