<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Thomas Maurer (tm) &#187; School</title>
	<atom:link href="http://www.thomasmaurer.ch/category/school/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thomasmaurer.ch</link>
	<description>Just another private cloud weblog</description>
	<lastBuildDate>Mon, 06 Feb 2012 19:10:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Microsoft Cloud for SMB</title>
		<link>http://www.thomasmaurer.ch/2012/01/microsoft-cloud-for-smb/</link>
		<comments>http://www.thomasmaurer.ch/2012/01/microsoft-cloud-for-smb/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 18:29:51 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Exchange Online]]></category>
		<category><![CDATA[Exchange Server]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[InTune]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[Lync Online]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office365]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Sharepoint]]></category>
		<category><![CDATA[Sharepoint 2010]]></category>
		<category><![CDATA[SharePoint Online]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Microsoft Cloud]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[Office 365]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[Public Cloud]]></category>
		<category><![CDATA[Windows InTune]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=3052</guid>
		<description><![CDATA[Last year I did a little research project about Microsoft’s public cloud and how it cloud affect Small and Medium sized businesses. So I created a paper which should help Microsoft partners to decide how they can improve their services &#8230; <a href="http://www.thomasmaurer.ch/2012/01/microsoft-cloud-for-smb/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2012/01/microsoft-cloud-for-smb/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2012/01/microsoft-cloud-for-smb/" data-count="horizontal" data-text="Microsoft Cloud for SMB" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2012%2F01%2Fmicrosoft-cloud-for-smb%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2009/04/MicrosoftCloudforSMB.png" rel="lightbox[3052]"><img class="aligncenter size-medium wp-image-2777" title="MicrosoftCloudforSMB" src="http://www.thomasmaurer.ch/wp-content/uploads/2009/04/MicrosoftCloudforSMB-211x300.png" alt="MicrosoftCloudforSMB" width="211" height="300" /></a></p>
<p>Last year I did a little research project about Microsoft’s public cloud and how it cloud affect Small and Medium sized businesses. So I created a paper which should help Microsoft partners to decide how they can improve their services and solutions by using the Microsoft public cloud. I the paper I focused on Microsoft Office 365 and Windows Intune. This should be for the partner which do infrastructure solutions like Active Directory, Exchange and PC Management.</p>
<p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2011/10/MicrosoftCloudforSMBdoc.png" rel="lightbox[3052]"><img class="aligncenter size-medium wp-image-2791" title="MicrosoftCloudforSMBdoc" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/10/MicrosoftCloudforSMBdoc-300x189.png" alt="MicrosoftCloudforSMBdoc" width="300" height="189" /></a></p>
<p>You can download this paper from <a title="Skydrive" href="https://skydrive.live.com/redir.aspx?cid=7298a00d5b74ec3c&amp;resid=7298A00D5B74EC3C!767&amp;parid=7298A00D5B74EC3C!731" target="_blank">my Windows Live SkyDrive</a>.<br />
The paper includes a lot of text copied from Microsoft documents and websites, and research I did by myself. All the sources should be marked, but if you find anything which is not marked please feel free to contact me.</p>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-3052"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2012/01/microsoft-cloud-for-smb/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Install CentOS on Windows 8 Hyper-V</title>
		<link>http://www.thomasmaurer.ch/2012/01/install-centos-on-windows-8-hyper-v/</link>
		<comments>http://www.thomasmaurer.ch/2012/01/install-centos-on-windows-8-hyper-v/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 17:24:25 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Hosting]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows 8]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Windows Server 8]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[CentOS]]></category>
		<category><![CDATA[CentOS 6.x]]></category>
		<category><![CDATA[Hyper-V 3]]></category>
		<category><![CDATA[Linux]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=2584</guid>
		<description><![CDATA[For some courses at KTSI we need a CentOS to test some Linux spesific things like Apache and other stuff. The good thing, Windows 8 got Hyper-V and Hyper-V supports CentOS. With Version 3.2 oft the Linux Integration Services Microsoft &#8230; <a href="http://www.thomasmaurer.ch/2012/01/install-centos-on-windows-8-hyper-v/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2012/01/install-centos-on-windows-8-hyper-v/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2012/01/install-centos-on-windows-8-hyper-v/" data-count="horizontal" data-text="Install CentOS on Windows 8 Hyper-V" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2012%2F01%2Finstall-centos-on-windows-8-hyper-v%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p>For some courses at KTSI we need a CentOS to test some Linux spesific things like Apache and other stuff. The good thing, Windows 8 got Hyper-V and Hyper-V supports CentOS.</p>
<p>With Version 3.2 oft the Linux Integration Services Microsoft fixed also a bug which occurred in Windows 8.</p>
<ol>
<li>First download CentOS</li>
<li>Download the <a title="Linux Integration Services Version 3.2" href="http://www.microsoft.com/download/en/details.aspx?id=28188" target="_blank">Linux Integration Services Version 3.2 for Hyper-V</a></li>
<li>Start Hyper-V Manager and create a new Virtual Machine</li>
<li>Install CentOS 6.x<br />
<a href="http://www.thomasmaurer.ch/wp-content/uploads/2012/01/centos-hyper-v-01.png" rel="lightbox[2584]"><img class="aligncenter size-medium wp-image-3089" title="centos hyper-v " src="http://www.thomasmaurer.ch/wp-content/uploads/2012/01/centos-hyper-v-01-300x269.png" alt="centos hyper-v" width="300" height="269" /></a></li>
<li>Reboot the virtual machine</li>
<li>Login as root<br />
<a href="http://www.thomasmaurer.ch/wp-content/uploads/2012/01/centos-hyper-v-03.png" rel="lightbox[2584]"><img class="aligncenter size-medium wp-image-3092" title="centos hyper-v " src="http://www.thomasmaurer.ch/wp-content/uploads/2012/01/centos-hyper-v-03-300x232.png" alt="centos hyper-v" width="300" height="232" /></a></li>
<li>Mount the Linux Integration Services ISO from step 2</li>
<li>Now run the following commands in the virtual machine
<pre>sudo mount /dev/cdrom /media
sudo /media/install.sh
</pre>
<p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2012/01/centos-hyper-v-04.png" rel="lightbox[2584]"><img class="aligncenter size-medium wp-image-3093" title="centos hyper-v " src="http://www.thomasmaurer.ch/wp-content/uploads/2012/01/centos-hyper-v-04-300x232.png" alt="centos hyper-v" width="300" height="232" /></a></li>
<li>After you the Installation is completed you have to reboot the virtual machine again<br />
<a href="http://www.thomasmaurer.ch/wp-content/uploads/2012/01/centos-hyper-v-02.png" rel="lightbox[2584]"><img class="aligncenter size-medium wp-image-3091" title="centos hyper-v" src="http://www.thomasmaurer.ch/wp-content/uploads/2012/01/centos-hyper-v-02-300x232.png" alt="centos hyper-v" width="300" height="232" /></a></li>
<li>done <img src='http://www.thomasmaurer.ch/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </li>
</ol>
<p>&nbsp;</p>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-2584"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2012/01/install-centos-on-windows-8-hyper-v/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Building a new Hyper-V Private Cloud Lab</title>
		<link>http://www.thomasmaurer.ch/2011/11/building-a-new-hyper-v-private-cloud-lab/</link>
		<comments>http://www.thomasmaurer.ch/2011/11/building-a-new-hyper-v-private-cloud-lab/#comments</comments>
		<pubDate>Mon, 28 Nov 2011 19:08:20 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[ProLiant Server]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Server Core]]></category>
		<category><![CDATA[System Center]]></category>
		<category><![CDATA[System Center Virtual Machine Manager 2012]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Windows Server 2008 R2]]></category>
		<category><![CDATA[Windows Server 8]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[C200]]></category>
		<category><![CDATA[C200 M2]]></category>
		<category><![CDATA[Cisco C200 M2]]></category>
		<category><![CDATA[Cluster]]></category>
		<category><![CDATA[Hyper-V Lab]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[ML110]]></category>
		<category><![CDATA[ML110 G5]]></category>
		<category><![CDATA[Private Cloud]]></category>
		<category><![CDATA[Proliant]]></category>
		<category><![CDATA[SCVMM]]></category>
		<category><![CDATA[Servers]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=2913</guid>
		<description><![CDATA[Two years ago I created my first real IT Lab with some HP ProLiant ML110 G5. I used this in the past years to test new products and projects. The Lab at this time was very limited, no storage, no &#8230; <a href="http://www.thomasmaurer.ch/2011/11/building-a-new-hyper-v-private-cloud-lab/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2011/11/building-a-new-hyper-v-private-cloud-lab/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2011/11/building-a-new-hyper-v-private-cloud-lab/" data-count="horizontal" data-text="Building a new Hyper-V Private Cloud Lab" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2011%2F11%2Fbuilding-a-new-hyper-v-private-cloud-lab%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p>Two years ago I created my first real IT Lab with some HP ProLiant ML110 G5. I used this in the past years to test new products and projects. The Lab at this time was very limited, no storage, no cluster, not much RAM and weak CPU performance. Not much help if you work a lot with Hyper-V Clusters and System Center products.</p>
<p>I was looking around for some time now to find a cheap offer for new servers. In the last week I found a offer from Cisco with c200 M2 servers and I couldn&#8217;t resist to buy two of the for my Hyper-V Cluster nodes. The offer was a special deal which was even cheaper than building the servers by my own, at this point thanks to my former employer <a title="Atlantis Informatik AG" href="http://www.lantis.ch" target="_blank">Atlantis Informatik AG</a>.</p>
<p>Now what I will do is creating a new Hyper-V Cluster friendly environment with two Cisco C200 M2 Hyper-V nodes, one HP ML110 G5 as Storage Server and one of my old HP ML110 G5 servers as Hyper-V Server which all my Management servers and Active Directory will run on.</p>
<p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2011/11/Overview.png" rel="lightbox[2913]"><img class="aligncenter size-large wp-image-2914" title="Lab Overview" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/11/Overview-1024x724.png" alt="Lab Overview" width="584" height="412" /></a></p>
<p>If you want to know more about Hardware you can use for a Hyper-V Lab I recommend the posts of Carsten Rachfahl on <a title="hyper-v-server.de" href="http://www.hyper-v-server.de/management/meine-demo-hyper-v-infrastruktur-vom-techday-private-cloud/" target="_blank">hyper-v-server.de</a> (german).</p>
<h1>Hardware Configuration</h1>
<p><strong>Hyper-V nodes:</strong></p>
<p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2011/11/cisco-c200-m2.jpg" rel="lightbox[2913]"><img class="aligncenter size-medium wp-image-2920" title="cisco c200 m2" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/11/cisco-c200-m2-300x240.jpg" alt="cisco c200 m2" width="300" height="240" /></a></p>
<p>2x Cisco C200 M2 - Intel Xeon 5620 2.4GHz Quad Core, 16GB RAM, Remote Management, IPMI, 6 Networkports</p>
<p><strong>Storage Server:</strong></p>
<p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2011/11/ml110g5.jpg" rel="lightbox[2913]"><img class="aligncenter size-medium wp-image-2921" title="ml110g5" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/11/ml110g5-300x300.jpg" alt="ml110g5" width="300" height="300" /></a></p>
<p>1x HP ProLiant ML110 G5 &#8211; Intel Xeon E3110 3.0 GHz Dual Core, 8GB RAM, 4x 500GB Raid 10, 3 Networkports</p>
<p><strong>Management Hyper-V node:</strong></p>
<p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2011/11/ml110g5.jpg" rel="lightbox[2913]"><img class="aligncenter size-medium wp-image-2921" title="ml110g5" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/11/ml110g5-300x300.jpg" alt="ml110g5" width="300" height="300" /></a></p>
<p>1x HP ProLiant ML110 G5 &#8211; Intel Xeon E3110 3.0 GHz Dual Core, 8GB RAM</p>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-2913"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2011/11/building-a-new-hyper-v-private-cloud-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First KTSI Project done</title>
		<link>http://www.thomasmaurer.ch/2011/10/first-ktsi-project-done/</link>
		<comments>http://www.thomasmaurer.ch/2011/10/first-ktsi-project-done/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 15:02:57 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[InTune]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office365]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Microsoft Cloud]]></category>
		<category><![CDATA[Office 365]]></category>
		<category><![CDATA[partners]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[SMB]]></category>
		<category><![CDATA[Windows InTune]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=2790</guid>
		<description><![CDATA[Now after the something over three months I finished my first project for the 5th KTSI semester. As a project I created a overview of the Microsoft Cloud for Small and Medium sized businesses. I wrote about the big partner &#8230; <a href="http://www.thomasmaurer.ch/2011/10/first-ktsi-project-done/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2011/10/first-ktsi-project-done/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2011/10/first-ktsi-project-done/" data-count="horizontal" data-text="First KTSI Project done" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2011%2F10%2Ffirst-ktsi-project-done%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2009/04/MicrosoftCloudforSMB.png" rel="lightbox[2790]"><img class="aligncenter size-medium wp-image-2777" title="MicrosoftCloudforSMB" src="http://www.thomasmaurer.ch/wp-content/uploads/2009/04/MicrosoftCloudforSMB-211x300.png" alt="MicrosoftCloudforSMB" width="211" height="300" /></a></p>
<p>Now after the something over three months I finished my first project for the 5th KTSI semester. As a project I created a overview of the Microsoft Cloud for Small and Medium sized businesses. I wrote about the big partner and customer opportunity with Windows Intune and Office 365.</p>
<p>After I finished the review I may will publish this document on my blog.</p>
<p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2011/10/MicrosoftCloudforSMBdoc.png" rel="lightbox[2790]"><img class="aligncenter size-medium wp-image-2791" title="MicrosoftCloudforSMBdoc" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/10/MicrosoftCloudforSMBdoc-300x189.png" alt="MicrosoftCloudforSMBdoc" width="300" height="189" /></a></p>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-2790"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2011/10/first-ktsi-project-done/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KTSI: Tag der offenen Tür 2011</title>
		<link>http://www.thomasmaurer.ch/2011/07/ktsi-tag-der-offenen-tur-2011/</link>
		<comments>http://www.thomasmaurer.ch/2011/07/ktsi-tag-der-offenen-tur-2011/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 15:18:08 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[MindTouchCollaboration]]></category>
		<category><![CDATA[Statusboard]]></category>
		<category><![CDATA[Tag der offenen Tür]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=2295</guid>
		<description><![CDATA[Tomorrow (Saturday, 2. July 2011) you can visit the KTSI (Kantonale Technikerinnen- und Techniker-Schule für Informatik). Everyone is welcome and you can check-out some really cool projects like the MindTouchCollaboration multi-touch table, the web-based statusboard and a lot more. Where: &#8230; <a href="http://www.thomasmaurer.ch/2011/07/ktsi-tag-der-offenen-tur-2011/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2011/07/ktsi-tag-der-offenen-tur-2011/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2011/07/ktsi-tag-der-offenen-tur-2011/" data-count="horizontal" data-text="KTSI: Tag der offenen Tür 2011" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2011%2F07%2Fktsi-tag-der-offenen-tur-2011%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p>Tomorrow (Saturday, 2. July 2011) you can visit the <a title="KTSI" href="http://www.ktsi.ch" target="_blank">KTSI</a> (Kantonale Technikerinnen- und Techniker-Schule für Informatik). Everyone is welcome and you can check-out some really cool projects like the <a title="MindTouchCollaboration" href="http://mitoco.bynight.org/" target="_blank">MindTouchCollaboration</a> multi-touch table, the web-based <a title="statusboard.ch" href="http://www.statusboard.ch" target="_blank">statusboard</a> and a lot more.</p>
<p><img class="aligncenter size-full wp-image-2296" title="Multitouch" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/07/Multitouch.png" alt="Multitouch" width="274" height="211" /></p>
<p><img class="aligncenter size-full wp-image-2297" title="statusboard" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/07/statusboard.jpg" alt="" width="170" height="127" /></p>
<p>Where: KTSI, Gründenstrasse 46, 4132 Muttenz<br />
When: Saturday 2. July 08:30 &#8211; 12:00</p>
<p>More information: <a href="http://www.ktsi.ch">www.ktsi.ch</a></p>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-2295"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2011/07/ktsi-tag-der-offenen-tur-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DirectAccess for SMB and Lab environments – Design, Step by Step and Troubleshooting Guide</title>
		<link>http://www.thomasmaurer.ch/2011/06/directaccess-for-smb-and-lab-environments-%e2%80%93-design-step-by-step-and-troubleshooting-guide/</link>
		<comments>http://www.thomasmaurer.ch/2011/06/directaccess-for-smb-and-lab-environments-%e2%80%93-design-step-by-step-and-troubleshooting-guide/#comments</comments>
		<pubDate>Thu, 09 Jun 2011 16:44:46 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[DirectAccess]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Windows Server 2008 R2]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Design]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Gudie]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Microsoft DirectAccess]]></category>
		<category><![CDATA[next generation VPN]]></category>
		<category><![CDATA[SMB]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=2133</guid>
		<description><![CDATA[This is a modified document which I wrote for a Microsoft Workshop at KTSI. It&#8217;s a Desgin, Step by Step and a Troubleshooting Guide for Microsoft DirectAccess. This is made for SMB or LAB environments not for Enterprise Deployments. I &#8230; <a href="http://www.thomasmaurer.ch/2011/06/directaccess-for-smb-and-lab-environments-%e2%80%93-design-step-by-step-and-troubleshooting-guide/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2011/06/directaccess-for-smb-and-lab-environments-%e2%80%93-design-step-by-step-and-troubleshooting-guide/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2011/06/directaccess-for-smb-and-lab-environments-%e2%80%93-design-step-by-step-and-troubleshooting-guide/" data-count="horizontal" data-text="DirectAccess for SMB and Lab environments – Design, Step by Step and Troubleshooting Guide" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2011%2F06%2Fdirectaccess-for-smb-and-lab-environments-%25e2%2580%2593-design-step-by-step-and-troubleshooting-guide%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces1.jpg" rel="lightbox[2133]"><img class="aligncenter size-medium wp-image-2056" title="DirectAccess for SMB and Lab Environments " src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces1-300x170.jpg" alt="DirectAccess for SMB and Lab Environments " width="300" height="170" /></a>This is a modified document which <a title="DirectAccess Deployment done" href="http://www.thomasmaurer.ch/2011/05/directaccess-deployment-done/" target="_blank">I wrote for a Microsoft Workshop</a> at <a title="KTSI" href="http://www.ktsi.ch" target="_blank">KTSI</a>. It&#8217;s a Desgin, Step by Step and a Troubleshooting Guide for Microsoft DirectAccess. This is made for SMB or LAB environments not for Enterprise Deployments.</p>
<p>I hope this guide can help you deploy DirectAccess in your environment and you can enjoy DirectAccess like I do <img src='http://www.thomasmaurer.ch/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p><span id="more-2133"></span></p>
<h1>Design</h1>
<h2>Requirements</h2>
<p>Basically this is a project which is optimized for SMB environments. That means this design uses a minimum of servers to deploy Microsoft DirectAccess.</p>
<p>So what do you need for a DirectAccess environment.</p>
<ul>
<li>One or more DirectAccess servers running Windows Server 2008 R2 (with or without UAG) with two network adapters: one that is connected directly to the Internet and one that is connected to the intranet. DirectAccess servers must be a member of an AD DS domain.</li>
<li>On the DirectAccess server, at least two consecutive, public IPv4 addresses assigned to the network adapter that is connected to the Internet.</li>
<li>DirectAccess client computers that are running Windows 7 Enterprise or Windows 7 Ultimate. DirectAccess clients must be members of an AD DS domain.</li>
<li>At least one domain controller and DNS server that is running Windows Server 2008 SP2 or Windows Server 2008 R2. When UAG is used, DirectAccess can be deployed with DNS servers and domain controllers that are running Windows Server 2003 when NAT64 functionality is enabled.</li>
<li>A public key infrastructure (PKI) to issue computer certificates, and optionally, smart card certificates for smart card authentication and health certificates for NAP. For more information, see Public Key Infrastructure on the Microsoft Web site.</li>
<li>Without UAG, an optional NAT64 device to provide access to IPv4-only resources for DirectAccess clients. DirectAccess with UAG provides a built-in NAT64.</li>
<li>Activated IPv6 on the Servers you want to use with DirectAccess</li>
</ul>
<h2>Key elements</h2>
<ul>
<li><strong>DirectAccess client</strong>. A domain-joined computer running Windows 7 Enterprise, Windows 7 Ultimate, or Windows Server 2008 R2 that can automatically and transparently connect to an intranet through a DirectAccess server.</li>
<li><strong>DirectAccess server</strong>. A domain-joined computer running Windows Server 2008 R2 that accepts connections from DirectAccess clients and facilitates communication with intranet resources.</li>
<li><strong>Network location server</strong>. A server that a DirectAccess client uses to determine whether it is located on the intranet or the Internet.</li>
<li><strong>Certificate revocation list (CRL) distribution points</strong>. Servers that provide access to the CRL that is published by the certification authority (CA) issuing certificates for DirectAccess.</li>
</ul>
<h2>DirectAccess Connection Process</h2>
<ol>
<li>The DirectAccess client computer running Windows 7 Enterprise or Windows 7 Ultimate detects that it is connected to a network.</li>
<li>The DirectAccess client computer determines whether it is connected to the intranet. If it is, DirectAccess is not used. Otherwise, DirectAccess is used.</li>
<li>The DirectAccess client computer on the Internet connects to the DirectAccess server with IPv6 and IPsec. If a native IPv6 network is not available (and it probably will not be when the computer is connected to the Internet), the client uses the 6to4 or Teredo IPv6 transition technologies to send IPv4-encapsulated IPv6 traffic.</li>
<li>If a firewall or proxy server prevents the client computer using 6to4 or Teredo from reaching the DirectAccess server, the client automatically attempts to connect with the Internet Protocol over Secure Hypertext Transfer Protocol (IP-HTTPS) protocol. IP-HTTPS uses an IPv4-based Secure Sockets Layer (SSL) connection to encapsulate IPv6 traffic.</li>
<li>As part of establishing the IPsec session for the infrastructure tunnel to reach the intranet DNS server and domain controller, the DirectAccess client and server authenticate each other using computer certificates and computer account credentials.</li>
<li>If Network Access Protection (NAP) is enabled and configured for health validation, the DirectAccess client attempts to obtain a health certificate from a Health Registration Authority (HRA) on the intranet. The HRA forwards the DirectAccess client&#8217;s health status information to a NAP health policy server. The NAP health policy server processes the policies defined within the Network Policy Server (NPS) and determines whether the client is compliant with system health requirements. If so, the HRA obtains a health certificate for the DirectAccess client.</li>
<li>When the user logs on, the DirectAccess client establishes the intranet tunnel to access the resources of the intranet. The DirectAccess client and server authenticate each other using a computer certificate and user account credentials. IF NAP is being used, the DirectAccess client submits its health certificate for authentication.</li>
<li>The DirectAccess server forwards traffic between the DirectAccess client and the intranet resources to which the user has been granted access.</li>
</ol>
<p>From TechNet: <a href="http://technet.microsoft.com/en-us/library/dd637792(WS.10).aspx">http://technet.microsoft.com/en-us/library/dd637792(WS.10).aspx</a></p>
<p><strong>IMPORTANT:</strong> DirectAccess authenticates the computer before the user logs on. Typically, computer authentication grants access only to domain controllers and DNS servers. After the user logs on, DirectAccess authenticates the user, and the user can connect to any resources he or she is authorized to access.</p>
<h2>Separating Internet and Intranet Traffic</h2>
<p>DirectAccess is splitting Internet and Intranet Traffic. So if a client is out-side the company network it will not connected to the company network to get Internet Access.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces1.jpg" alt="" /></p>
<p>Picture from TechNet: <a href="http://technet.microsoft.com/en-us/library/dd637769(WS.10).aspx">http://technet.microsoft.com/en-us/library/dd637769(WS.10).aspx</a></p>
<h2>DirectAccess versus legacy VPN</h2>
<h3>Problems with VPN</h3>
<p>Traditionally, users connect to intranet resources with a VPN. However, using a VPN can be cumbersome because:</p>
<p>Connecting to a VPN takes several steps, and the user needs to wait for authentication. For organizations that check the health of a computer before allowing the connection, establishing a VPN connection can take several minutes.</p>
<ul>
<li>Any time users lose their Internet connection, they need to re-establish the VPN connection.</li>
<li>VPN connections can be problematic in some environments that filter out VPN traffic.</li>
<li>Internet performance is slowed if both intranet and Internet traffic goes through the VPN connection.</li>
</ul>
<p>Because of these inconveniences, many users avoid connecting to a VPN. Instead, they use application gateways, such as Microsoft Outlook® Web Access (OWA), to connect to intranet resources. With OWA, users can retrieve internal e-mail without establishing a VPN connection. However, users still need to connect to a VPN to open documents that are located on intranet file shares, such as those that are linked within an e-mail message.</p>
<p>TechNet: <a href="http://technet.microsoft.com/en-us/library/dd637766(WS.10).aspx">http://technet.microsoft.com/en-us/library/dd637766(WS.10).aspx</a></p>
<h3>DirectAccess Benefits</h3>
<ul>
<li>Seamless connectivity. DirectAccess is on whenever the user has an Internet connection, giving users access to intranet resources whether they are traveling, at the local coffee shop, or at home.</li>
<li>Remote management. IT administrators can connect directly to DirectAccess client computers to monitor them, manage them, and deploy updates, even when the user is not logged on. This can reduce the cost of managing remote computers by keeping them up-to-date with critical updates and configuration changes.</li>
<li>Improved security. DirectAccess uses IPsec for authentication and encryption. Optionally, you can require smart cards for user authorization. DirectAccess integrates with NAP to require that DirectAccess clients must be compliant with system health requirements before allowing a connection to the DirectAccess server. IT administrators can configure the DirectAccess server to restrict the servers that users and individual applications can access.</li>
</ul>
<p>TechNet: <a href="http://technet.microsoft.com/en-us/library/dd637814(WS.10).aspx">http://technet.microsoft.com/en-us/library/dd637814(WS.10).aspx</a></p>
<h3>DirectAccess and VPNs Working Together</h3>
<p>DirectAcces does not solve every problem or is a solution for everything. That&#8217;s why a lot of company could deploy a mixed system with DirectAccess and &#8220;legacy&#8221; VPN.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces2.jpg" alt="" /></p>
<p>Picture from TechNet: <a href="http://technet.microsoft.com/en-us/library/dd875517(WS.10).aspx">http://technet.microsoft.com/en-us/library/dd875517(WS.10).aspx</a></p>
<h2>Server and Clients for this Guide</h2>
<div>
<table style="border-collapse: collapse;" border="0">
<colgroup>
<col style="width: 310px;"></col>
<col style="width: 310px;"></col>
</colgroup>
<tbody>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border: solid #7ba0cd 1.0pt;"><strong>Server01</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">ADS, DNS, DHCP, ADCS</td>
</tr>
<tr style="background: #d3dfee;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>Server02</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">Fileserver, Network Location Server</td>
</tr>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>Server03</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">DirectAccess Server, CRL</td>
</tr>
<tr style="background: #d3dfee;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>Server04</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">External DNS Server</td>
</tr>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>Client01</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">Windows 7 Client</td>
</tr>
</tbody>
</table>
</div>
<p>&nbsp;</p>
<p>As mentioned in an earlier chapter, this is designed to use a minimum of servers. This is not Microsoft best practice, but it should be okay for lab environments and it shows what you need as a minimum.</p>
<h1>Overview</h1>
<h2>DirectAccess Overview</h2>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces3.jpg" alt="" /></p>
<h2>LAB Overview</h2>
<h3>Domains</h3>
<div>
<table style="border-collapse: collapse;" border="0">
<colgroup>
<col style="width: 310px;"></col>
<col style="width: 310px;"></col>
</colgroup>
<tbody>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border: solid #7ba0cd 1.0pt;"><strong>Internal</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">corp.pepsi.local</td>
</tr>
<tr style="background: #d3dfee;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>External</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">microsoft-engineering.ch</td>
</tr>
</tbody>
</table>
</div>
<p>Servers</p>
<div>
<table style="border-collapse: collapse;" border="0">
<colgroup>
<col style="width: 205px;"></col>
<col style="width: 205px;"></col>
<col style="width: 205px;"></col>
</colgroup>
<tbody>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border: solid #7ba0cd 1.0pt;"><strong>ADS-WIN-020-001</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">ADS, ADCS, DNS, DHCP</td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">10.10.XXX.XXX</td>
</tr>
<tr style="background: #d3dfee;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>NPS-WIN-020-003</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">Network Location Server, Fileserver</td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">10.10.XXX.XXX</td>
</tr>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>DAS-WIN-020-006</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">DirectAccess Server, CRL</td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">10.10.XXX.XXX</td>
</tr>
</tbody>
</table>
</div>
<p>All this Servers are Virtual Machines based on Microsoft Hyper-V 2008 R2, on the following Hyper-V Hosts.</p>
<h3>Hyper-V Hosts</h3>
<div>
<table style="border-collapse: collapse;" border="0">
<colgroup>
<col style="width: 307px;"></col>
<col style="width: 307px;"></col>
</colgroup>
<tbody>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border: solid #7ba0cd 1.0pt;"><strong>Hyperv01</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">10.10.XXX.XXX</td>
</tr>
<tr style="background: #d3dfee;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>Hyperv02</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">10.10.XXX.XXX</td>
</tr>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>Hyperv03</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">10.10.XXX.XXX</td>
</tr>
</tbody>
</table>
</div>
<h3>Groups</h3>
<div>
<table style="border-collapse: collapse; background: #a7bfde;" border="0">
<colgroup>
<col style="width: 307px;"></col>
<col style="width: 307px;"></col>
</colgroup>
<tbody>
<tr>
<td style="padding-left: 7px; padding-right: 7px; border: solid #7ba0cd 1.0pt;"><strong>DirectAccess_Clients</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">Computer Accounts for DirectAccess</td>
</tr>
</tbody>
</table>
</div>
<h3>Network Overview</h3>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces4.png" alt="" /></p>
<h3>Group Policies</h3>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces5.png" alt="" /></p>
<div>
<table style="border-collapse: collapse;" border="0">
<colgroup>
<col style="width: 307px;"></col>
<col style="width: 307px;"></col>
</colgroup>
<tbody>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border: solid #7ba0cd 1.0pt;"><strong>DirectAccess IPV6</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">Firewall Rule for ICMPv6 echo</td>
</tr>
<tr style="background: #d3dfee;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>Autoenrollment</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">Certificate Autoenrollment</td>
</tr>
<tr style="background: #a7bfde;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>DirectAccess Policy</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">Created by DirectAccess</td>
</tr>
<tr style="background: #d3dfee;">
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: solid #7ba0cd 1.0pt; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;"><strong>DirectAccess Policy</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: none; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">Created by DirectAccess</td>
</tr>
</tbody>
</table>
</div>
<h1>Step by Step Deployment</h1>
<h2>Make your Environment Ready</h2>
<h3>Active Directory Domain Services</h3>
<p>Installing the Active Directory Domain Service is nothing special, in our lab environment we used an already existing Active Directory Domain.</p>
<p>The only other thing you need is a Security Group for Active Directory Computer Accounts which are allowed to use DirectAccess.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces6.png" alt="" /></p>
<h3>Active Directory Certificate Services</h3>
<p>To use DirectAccess you need the Active Directory Certificate Services. If you don&#8217;t have a working PKI yet, you can use this step by step guide to deploy one.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces7.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces8.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces9.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces10.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces11.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces12.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces13.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces14.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces15.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces16.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces17.png" alt="" /></p>
<h3>DHCP Server</h3>
<p>There is just one thing you have to make sure, if you don&#8217;t have implemented IPv6 in your environment you need to disable DHCPv6 stateless mode. You can do this by <strong>choosing Disable DHCPv6 stateless mode for this server in the DHCP Configuration</strong> Wizard.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces18.png" alt="" /></p>
<h3>DNS Server</h3>
<p>Basically you just need the DNS Server and if you have installed your first Active Directory Server you already have the DNS role installed. There is no special configuration need at this moment; we just have to add some entries later.</p>
<h3>Creating a new Certificate Template</h3>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces19.png" alt="" /></p>
<p>Right click on <strong>Webserver</strong> and <strong>Duplicate Template</strong></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces20.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces21.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces22.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces23.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces24.png" alt="" /></p>
<p>On the <strong>Security</strong> tab you have to <strong>Allow Enroll</strong> Permissions for <strong>Domain Computers</strong> and <strong>Authenticated Users.<br />
</strong></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces25.png" alt="" /><strong><br />
</strong></p>
<p>After creating this Certificate Template you have to add this to your CA Template Folder by right click <strong>New</strong><br />
<span style="font-family: Wingdings;">à</span><br />
<strong>Certificate </strong>Template to Issue and now choose your Certificate in this case <strong>Webserver (DirectAccess).<br />
</strong></p>
<h3>Create IPv6 ICMP Firewall Group Policy</h3>
<p>DirectAccess can only work if the systems can ping each other over IPv6 so we have to create an ICMPv6  Inbound and Outbound rule on each system or we do this over Group Policy which is much simpler and quicker.</p>
<p>First open the Group Policy Management MMC and create a new Group Policy Object and edit this. In this case we all the Group Policy <strong>Object DirectAccess IPv6.<br />
</strong></p>
<p>In the Group Policy Management Editor now navigate to <strong>Computer Configuration / Policies / Windows Settings / Security Settings / Windows Firewall with Advanced Security / Windows Firewall with Advanced Security</strong>. Now under <strong>Inbound Rules</strong> we create a new rule in our case named <strong>Inbound ICMPv6 Echo Requests</strong>.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces26.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces27.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces28.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces29.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces30.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces31.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces32.png" alt="" /></p>
<p>After you have created the Inbound rule, you also have to create an Outbound rule with the same settings as the Inbound rule.</p>
<p>After you have created this Group Policy Object remember to add this to your domain.</p>
<h3>Remove ISATAP from DNS global block list</h3>
<p>To remove the ISATAP entry from the DNS global block list you can use the following command:</p>
<p style="margin-left: 36pt;"><span style="font-family: Lucida Console; font-size: 10pt;">Dnscmd /config /globalqueryblocklist wpad<br />
</span></p>
<p>This removes the value isatap from the registry key REG_MULTI_SZ &#8220;GlobalQueryBlockList&#8221; under:</p>
<p style="margin-left: 36pt;"><span style="font-family: Lucida Console; font-size: 10pt;">HKEY_LOCAL_MACHINE\SYSTEM\CurrentConrtolSet\Services\DNS\Parameters<br />
</span></p>
<p style="margin-left: 36pt;">&nbsp;</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces33.png" alt="" /></p>
<p>On the second DNS Server I did the same. I used Powershell Remoting to do that, you can also connect via Remote Desktop and run the command.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces34.png" alt="" /></p>
<p>With <strong>net stop iphlpsvc</strong> and <strong>net start iphpsvc</strong> you can restart the IP helper service on the DNS server.</p>
<p>More about ISATAP: <a href="http://en.wikipedia.org/wiki/ISATAP">http://en.wikipedia.org/wiki/ISATAP</a></p>
<h2>Certificate Revocation List</h2>
<p>Now if you work with certificates you need a CRL (Certificate Revocation List). We simply deploy this on our DirectAccess Server, you could use every other Server in your environment, but the server needs to be accessible from the Internet.</p>
<h4>Setup IIS-Website</h4>
<p>First we install the standard IIS role.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces35.png" alt="" /></p>
<p>&nbsp;</p>
<p>Now we add a Virtual Directory to the Default Website (<strong>right click</strong> on <strong>Default Web Site</strong> and <strong>Add Virtual Directory</strong>).</p>
<p>Under Physical path you need to add a path which the CA saves the Revocation List. So we will create a network share for this directory later.</p>
<p><a name="OLE_LINK1"></a>In our case we used C:\inetpub\wwwroot\crld</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces36.png" alt="" /></p>
<p>Now on the properties of this Virtual Directory you can now click on Directory Browsing.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces37.png" alt="" /></p>
<p>Now you can enable Directory Browsing by pressing <strong>Enable</strong> on the Actions menu.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces38.png" alt="" /></p>
<p>Now in <strong>the Configuration Editor</strong> we have also to add a setting for requestFiltering.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces39.png" alt="" /></p>
<p><strong>Under system.webServer/security/requestFiltering</strong> set <strong>allowDoubleEscaping</strong> to <strong>true</strong>.</p>
<h4>Create Share for CRL</h4>
<p>Create a share on the directory we used for our Virtual Directory (In our case we used C:\inetpub\wwwroot\crld).</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces40.png" alt="" /></p>
<p>And grant <strong>Full Control</strong> for the CA Computer account.</p>
<h3>CA Configuration</h3>
<p>Basically we now have to publish the CRL from the CA to the CRL webserver we just created. And Clients can check now the CRL from the Webserver over http.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces41.jpg" alt="" /></p>
<h4>Create External DNS Entries</h4>
<p>Create the following <strong>A Records</strong> for your external domain. In this case our external domain is microsoft-engineering.ch and we create a sub domain called <strong>clr.microsoft-engineering.ch</strong> and point to the external IP address which the CRL is available.</p>
<p>This is mostly done by our external Hosting Provider.</p>
<div>
<table style="border-collapse: collapse; background: #a7bfde;" border="0">
<colgroup>
<col style="width: 205px;"></col>
<col style="width: 205px;"></col>
<col style="width: 205px;"></col>
</colgroup>
<tbody>
<tr>
<td style="padding-left: 7px; padding-right: 7px; border: solid #7ba0cd 1.0pt;"><strong>crl.microsoft-engineering.ch</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">A Record</td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">234.234.233.121</td>
</tr>
</tbody>
</table>
</div>
<p>&nbsp;</p>
<p>You also have to create another A Record for DirectAccess.</p>
<div>
<table style="border-collapse: collapse; background: #a7bfde;" border="0">
<colgroup>
<col style="width: 205px;"></col>
<col style="width: 205px;"></col>
<col style="width: 205px;"></col>
</colgroup>
<tbody>
<tr>
<td style="padding-left: 7px; padding-right: 7px; border: solid #7ba0cd 1.0pt;"><strong>directaccess.microsoft-engineering.ch</strong></td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">A Record</td>
<td style="padding-left: 7px; padding-right: 7px; border-top: solid #7ba0cd 1.0pt; border-left: none; border-bottom: solid #7ba0cd 1.0pt; border-right: solid #7ba0cd 1.0pt;">234.234.233.121</td>
</tr>
</tbody>
</table>
</div>
<p>&nbsp;</p>
<p><strong>IMPORTANT:</strong> for the DirectAccess A Record you have to use the first external IP Address. If your external DirectAccess IP Addresses are 234.234.233.121 and 234.234.233.122 you create the A Record only for 234.234.233.121. Not for the second one and not for both.</p>
<h4>Configure CRL Distribution Point</h4>
<p>On the Server which has the CA role installed you start the <strong>Certification Authority</strong> Management Console.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces42.png" alt="" /></p>
<p>Right click Properties</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces43.png" alt="" /></p>
<p>Under the Extensions Tab, select the extension <strong>CRL Distribution Point (CDP)</strong>.</p>
<p>Now click on <strong>Add.. </strong>and add the external Connection first, by adding the external address:</p>
<p style="margin-left: 36pt;"><span style="font-family: Lucida Console; font-size: 10pt;">http://crl.microsoft-engineering.ch/crld/&lt;CaName&gt;&lt;CRLNameSuffix&gt;&lt;DeltaCRLAllowed&gt;.crl<br />
</span></p>
<p><strong>IMPORTANT</strong>: Do not forget the <strong>.crl</strong> at the end</p>
<p>Click OK and add the select the following checkboxes</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces44.png" alt="" /></p>
<p>Now add the second entry and this time for the internal connection to the network share.</p>
<p style="margin-left: 36pt;"><span style="font-family: Lucida Console; font-size: 10pt;">\\das-win-020-001\crld$\&lt;CaName&gt;&lt;CRLNameSuffix&gt;&lt;DeltaCRLAllowed&gt;.crl<br />
</span></p>
<p>Click OK and select the following checkboxes</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces45.png" alt="" /></p>
<h4>Verify the CRL Distribution</h4>
<p>If you now check the network share it should not see any file except the <strong>web.config</strong> file. If you now right click on <strong>Revoked Certificates / All Tasks / Publish</strong> it should publish two new files to the network share.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces46.png" alt="" /></p>
<p>&nbsp;</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces47.png" alt="" /></p>
<h4>Configure Auto Enrollment for Computer Certificates</h4>
<p>To configure Auto Enrollment for Computer Certificate we create another Group Policy. In this case we called this <strong>Autoenrollment</strong>.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces48.png" alt="" /></p>
<p>Navigate to <strong>Computer Configuration / Policies / Windows Settings / Security Settings /Public Key Policies<br />
</strong></p>
<p>Edit the<strong> Certificate Services Client – Auto-Enrollment<br />
</strong></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces49.png" alt="" /></p>
<p>Use the settings from the screenshot</p>
<p>Now run the Automatic Certificate Request Wizard</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces50.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces51.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces52.png" alt="" /></p>
<p>And don&#8217;t forget to add this new Group Policy to your Domain.</p>
<h3>Request Certificate for DirectAccess Server</h3>
<p>On the DirectAccess Server open a MMC and add the Snap-in <strong>Certificates</strong> for local <strong>Computer account</strong>.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces53.png" alt="" /></p>
<p>Now navigate to <strong>Certificates</strong> / <strong>Personal</strong> and click right on <strong>Certificates.</strong> Now click on All Tasks and Request Certificate.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces54.png" alt="" /></p>
<p>Now select your template in our case we called this Webserver (DirectAccess). You also need to add some information to this certificate.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces55.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces56.png" alt="" /></p>
<p>Add a <strong>Common Name</strong> and as alternative name <strong>DNS</strong> and use your public DirectAccess domain, for which you have created the A Record. In our example environment we used <strong>directaccess.microsoft-engineering.com</strong>.</p>
<p>After you have added this certificate it is recommended that you add a <strong>friendly name</strong> to this Certificate, so you can better find this certificate later.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces57.png" alt="" /></p>
<h3>Network Location Server</h3>
<p>The Network Location Server is basically just a webserver. In this environment we used a simple IIS installation on our fileserver, it could also be a SharePoint site or a existing website or installation of IIS.</p>
<p>With the Network Location Server DirectAccess clients check their location (Internal or external).</p>
<p>So basically this is has to be a server which is a member of the Domain and you IIS is installed or you can install the IIS server role. The server does not need to be reachable from external.</p>
<p>Now first add the DirectAccess webserver certificate to the Server. You can do the same as with the DirectAccess Server.</p>
<p><strong>IMPORTANT:</strong> in a productive environment, the Network Location Server should be high available. If the NLS is not available all DirectAccess clients will try to connect over the DirectAccess to the network, even if they are at the local company network.</p>
<p>Open the <strong>MMC</strong> and add the <strong>Certificate Snap-In</strong>. Request a new Certificate:</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces58.png" alt="" /></p>
<p>As on the DirectAccess server you have to add some information for the certificate.</p>
<p>Add a <strong>Common Name</strong> and as alternative name <strong>DNS</strong> and use your internal domain, for which you have created the A record. In our example environment we used <strong>corp.pepsi.local</strong>.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces59.png" alt="" /></p>
<p>Next step is to create <strong>an HTTPS binding</strong> for the site nls.corp.pepsi.local and create a <strong>DNS CNAME</strong> on your <strong>local DNS Server</strong> for <strong>nls.corp.pepsi.local</strong> which points to the Server where the NLS Website runs.</p>
<p>On this Server we now add a binging for HTTPS. Open <strong>the IIS Manager</strong> right click on the <strong>Default Website</strong>, or the Website you want to use for NLS, and <strong>Edit Bindings</strong>.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces60.png" alt="" /></p>
<p>Now Add Binding.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces61.png" alt="" /></p>
<p>Now later in the DirectAccess installation you need to add the URL for this website location (<a href="http://nls.corp.pepsi.local">http://nls.corp.pepsi.local</a>). The webserver needs to send back status code 200. Which means send back a simple OK.</p>
<h3>DirectAccess Server</h3>
<p>The Direct Access Server is a Windows Server 2008 R2 Server which has an internal and an external network interface. The external network interface must have two external IP addresses.</p>
<p>So you should have two network adapters, and it&#8217;s recommended two name them correctly, for example internal and external. We used DA1 for DirectAccess (external) and Local Area Network for the internal adapter.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces62.png" alt="" /></p>
<p>You also should set the DNS-Suffix for the internal connection.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces63.png" alt="" /></p>
<h2>Install DirectAccess</h2>
<p>After we finished all these requirements we are now ready to install the DirectAccess feature on our DirectAccess Server.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces64.png" alt="" /></p>
<p>Installing the feature <strong>DirectAccess Management Console</strong> will automatically add the feature <strong>Group Policy Management Console</strong>.</p>
<p>After you have installed the DirectAccess feature you should get the following console. By the way no reboot is needed.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces65.png" alt="" /></p>
<p>&nbsp;</p>
<h3>Step 1</h3>
<p>In Step 1 add the group with Computer Clients you have created in the Active Directory.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces66.png" alt="" /></p>
<h3>Step 2</h3>
<p>In Step 2 you define the network interfaces and certificates.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces67.png" alt="" /></p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces68.png" alt="" /></p>
<p>The first certificate is the CA certificate and the second one is the external certificate, in this case for directaccess.microsoft-engineering.ch.</p>
<h3>Step 3</h3>
<p>In Step 3 you define the Network Location Server</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces69.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces70.png" alt="" /></p>
<p>After the click of next it will automatically add the DNS Suffix of the Domain and the name of the Network Location Server.</p>
<p>You can now add the Infrastructure Servers which can access the DirectAccess clients. This could make sense for Management Server or WSUS Servers.</p>
<h3>Step 4</h3>
<p>In Step for you could add an additional end-to-end authentication.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces71.png" alt="" /></p>
<p>After you click on the finish button you will get an overview of all the settings.</p>
<p>If you now open the Group Policy Management Console you will see that DirectAccess has automatically created two new Group Policies.</p>
<p><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces72.png" alt="" /></p>
<h2>Everything Working</h2>
<p>After you are done and you don&#8217;t have any visible error, DirectAccess should work properly.</p>
<p>On your DirectAccess client you should have access to your company network all the time.</p>
<p>Even Internal DNS Request should work.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces73.png" alt="" /></p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces74.png" alt="" /></p>
<p>&nbsp;</p>
<h1>Basic Troubleshooting</h1>
<h2>Checks</h2>
<h3>Check for DirectAccess Group Policy</h3>
<p>With gpresult you can check on the client if the DirectAccess Group Policy is working on the client.</p>
<p style="margin-left: 36pt;"><span style="font-family: Lucida Console; font-size: 10pt;">gpresult /R<br />
</span></p>
<p>This shows all GPO&#8217;s deployed to the client.</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces75.png" alt="" /></p>
<p>If the GPO is not all ready deploy to the host you can run a gpupdate /force</p>
<h3>Check Connection</h3>
<p>With IPCONFIG you can check if there is a connection</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces76.png" alt="" /></p>
<p>You can see a Tunnel adapter with an IPv6 address beginning with 2001:</p>
<p>Also a ping to a domain client should work</p>
<p style="text-align: center;"><img src="http://www.thomasmaurer.ch/wp-content/uploads/2011/05/052411_1210_DirectAcces77.png" alt="" /></p>
<h2>Links and Documents</h2>
<p>DirectAccess Deployment and Troubleshooting Guides<br />
<a href="http://www.microsoft.com/downloads/en/details.aspx?displaylang=en&amp;FamilyID=647222d1-a41e-4cdb-ba34-f057fbc7198f">http://www.microsoft.com/downloads/en/details.aspx?displaylang=en&amp;FamilyID=647222d1-a41e-4cdb-ba34-f057fbc7198f</a></p>
<p>Technical Overview of DirectAccess in Windows 7 and Windows Server 2008 R2<br />
<a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=64966E88-1377-4D1A-BE86-AB77014495F4">http://www.microsoft.com/downloads/en/details.aspx?FamilyID=64966E88-1377-4D1A-BE86-AB77014495F4</a></p>
<p>Test Lab Guide: Demonstrate DirectAccess<br />
<a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=8D47ED5F-D217-4D84-B698-F39360D82FAC">http://www.microsoft.com/downloads/en/details.aspx?FamilyID=8D47ED5F-D217-4D84-B698-F39360D82FAC</a></p>
<p>Windows 7 and Windows Server 2008 R2 DirectAccess Executive Overview<br />
<a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=D8EB248B-8BF7-4798-A1D1-04D37F2E013C">http://www.microsoft.com/downloads/en/details.aspx?FamilyID=D8EB248B-8BF7-4798-A1D1-04D37F2E013C</a></p>
<p>Windows 7 and Windows Server 2008 R2 DirectAccess IT Infrastructure Compatibility<br />
<a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=25B453B4-2DB7-435D-88B5-5C3B81DE249C">http://www.microsoft.com/downloads/en/details.aspx?FamilyID=25B453B4-2DB7-435D-88B5-5C3B81DE249C</a><span style="color: blue; text-decoration: underline;"><br />
</span></p>
<p>Wikipedia ISATAP<br />
<a href="http://en.wikipedia.org/wiki/ISATAP">http://en.wikipedia.org/wiki/ISATAP</a></p>
<p>German DirectAccess Guide<br />
<a href="http://technikblog.rachfahl.de/technik/howto-einrichtung-von-directaccess/">http://technikblog.rachfahl.de/technik/howto-einrichtung-von-directaccess/</a></p>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-2133"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2011/06/directaccess-for-smb-and-lab-environments-%e2%80%93-design-step-by-step-and-troubleshooting-guide/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft WebMatrix and Microsoft WebPlatform Installer</title>
		<link>http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/</link>
		<comments>http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/#comments</comments>
		<pubDate>Thu, 14 Apr 2011 14:30:50 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Silverlight]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[SQL Server]]></category>
		<category><![CDATA[Visual Studio]]></category>
		<category><![CDATA[Visual Studio 2010]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[WebMatrix]]></category>
		<category><![CDATA[Webplatform Installer]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[ASP.NET]]></category>
		<category><![CDATA[create]]></category>
		<category><![CDATA[deploy]]></category>
		<category><![CDATA[HTML]]></category>
		<category><![CDATA[IIS Express]]></category>
		<category><![CDATA[Microsoft WebMatrix]]></category>
		<category><![CDATA[Microsoft Webplatform Installer]]></category>
		<category><![CDATA[MSSQL]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[Web Application]]></category>
		<category><![CDATA[WPI]]></category>
		<category><![CDATA[WPI 3.0]]></category>
		<category><![CDATA[XAMPP]]></category>
		<category><![CDATA[XHTML]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=1812</guid>
		<description><![CDATA[For a project at KTSI we needed a platform to quick deploy PHP and MySQL applications. There are a lot of solutions out there in the web, for example XAMPP. After testing some options I had a closer look at the &#8230; <a href="http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/" data-count="horizontal" data-text="Microsoft WebMatrix and Microsoft WebPlatform Installer" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2011%2F04%2Fmicrosoft-webmatrix-and-microsoft-webplatform-installer%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p><img class="aligncenter size-full wp-image-1813" title="microsoft webmatrix" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/microsoft-webmatrix.jpg" alt="Microsoft WebMatrix" width="190" height="190" />For a project at <a title="KTSI" href="http://www.ktsi.ch/" target="_blank">KTSI</a> we needed a platform to quick deploy PHP and MySQL applications. There are a lot of solutions out there in the web, for example <a title="XAMPP" href="http://www.apachefriends.org/en/index.html" target="_blank">XAMPP</a>. After testing some options I had a closer look at the<a title="Microsoft Webplatform Installer" href="http://www.microsoft.com/web/downloads/platform.aspx" target="_blank"> Microsoft WebPlatform Installer</a> and <a title="Microsoft WebMatrix" href="http://www.microsoft.com/web/webmatrix/" target="_blank">Microsoft WebMatrix</a>. Those two tools do exactly what I need. With the WebPlatform Installer you can easily install a local instance of IIS Express with ASP.NET, PHP, MSSQL and MySQL support with in 5-10 minutes.</p>
<p>But the coolest tool in my opinion is WebMatrix. Webmatrix lets developers create, manage and deploy Web Applications very very easy. And if you need to to more Webmatrix lets you also work with Visual Studio on the same project.</p>

<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/microsoft-webmatrix/' title='microsoft webmatrix'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/microsoft-webmatrix-150x150.jpg" class="attachment-thumbnail" alt="Microsoft WebMatrix" title="microsoft webmatrix" /></a>
<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/iismanager/' title='IISManager'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/IISManager-150x150.png" class="attachment-thumbnail" alt="IISManager" title="IISManager" /></a>
<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/mysql-windows/' title='mysql windows'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/mysql-windows-150x150.png" class="attachment-thumbnail" alt="mysql windows" title="mysql windows" /></a>
<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/phpmanager/' title='PHPManager'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/PHPManager-150x150.png" class="attachment-thumbnail" alt="PHPManager" title="PHPManager" /></a>
<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/webmatrix/' title='webmatrix'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/webmatrix-150x150.png" class="attachment-thumbnail" alt="webmatrix" title="webmatrix" /></a>
<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/webmatrix1/' title='webmatrix1'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/webmatrix1-150x150.png" class="attachment-thumbnail" alt="webmatrix1" title="webmatrix1" /></a>
<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/webmatrix2/' title='webmatrix2'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/webmatrix2-150x150.png" class="attachment-thumbnail" alt="webmatrix2" title="webmatrix2" /></a>
<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/webmatrix3/' title='webmatrix3'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/webmatrix3-150x150.png" class="attachment-thumbnail" alt="webmatrix3" title="webmatrix3" /></a>
<a href='http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/wpi/' title='WPI'><img width="150" height="150" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/04/WPI-150x150.png" class="attachment-thumbnail" alt="WPI" title="WPI" /></a>

<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-1812"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2011/04/microsoft-webmatrix-and-microsoft-webplatform-installer/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Import Evernote notes to OneNote 2010</title>
		<link>http://www.thomasmaurer.ch/2011/03/import-evernote-notes-to-onenote-2010/</link>
		<comments>http://www.thomasmaurer.ch/2011/03/import-evernote-notes-to-onenote-2010/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 14:13:15 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows Live]]></category>
		<category><![CDATA[Windows Phone]]></category>
		<category><![CDATA[Windows Phone 7]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Evernote]]></category>
		<category><![CDATA[Export]]></category>
		<category><![CDATA[Import]]></category>
		<category><![CDATA[Import Notes]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Office 2010]]></category>
		<category><![CDATA[Microsoft OneNote]]></category>
		<category><![CDATA[Microsoft OneNote 2010]]></category>
		<category><![CDATA[Microsoft OneNote for iPhone]]></category>
		<category><![CDATA[Microsoft OneNote for Windows Phone 7]]></category>
		<category><![CDATA[note]]></category>
		<category><![CDATA[Notes]]></category>
		<category><![CDATA[Office 2010]]></category>
		<category><![CDATA[OneNote]]></category>
		<category><![CDATA[OneNote 2010]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=1734</guid>
		<description><![CDATA[Since I work more and more with Windows 7 I had a look at Microsoft OneNote 2010. Before I used Evernote and I was happy with it. But as I saw OneNote and startet using it, I can&#8217;t think being &#8230; <a href="http://www.thomasmaurer.ch/2011/03/import-evernote-notes-to-onenote-2010/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2011/03/import-evernote-notes-to-onenote-2010/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2011/03/import-evernote-notes-to-onenote-2010/" data-count="horizontal" data-text="Import Evernote notes to OneNote 2010" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2011%2F03%2Fimport-evernote-notes-to-onenote-2010%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2011/03/Microsoft_OneNote_2010_Icon.png" rel="lightbox[1734]"><img class="aligncenter size-full wp-image-1735" title="Microsoft_OneNote_2010_Icon" src="http://www.thomasmaurer.ch/wp-content/uploads/2011/03/Microsoft_OneNote_2010_Icon.png" alt="Microsoft OneNote 2010" width="256" height="256" /></a>Since I work more and more with Windows 7 I had a look at <a title="Microsoft OneNote" href="http://office.microsoft.com/en-us/onenote/" target="_blank">Microsoft OneNote 2010</a>. Before I used <a title="Evernote" href="http://www.evernote.com" target="_blank">Evernote</a> and I was happy with it. But as I saw OneNote and startet using it, I can&#8217;t think being without it. There are alot of features I really love and OneNote 2010 is really nice integrated into Windows 7 and the Office products.</p>
<p>So if you wish to migrate from Evernote to Microsoft OneNote 2010 you can do that in diffrend ways.</p>
<ul>
<li>Import Notes via Outlook (send Evernote Notes via email and import them in Outlook via the Send to OneNote button)</li>
<li>Export Notes as HTML and Import Them Into OneNote</li>
<li>Import Notes via the OneNote Printer</li>
</ul>
<p>You can read a great HowTo on <a title="howtogeek.com" href="http://www.howtogeek.com/howto/25829/import-evernote-files-into-ms-onenote-2010/" target="_blank">howtogeek.com</a></p>
<p>Btw. Microsoft released also <a title="OneNote for iPhone" href="http://itunes.apple.com/us/app/microsoft-onenote/id410395246?mt=8" target="_blank">OneNote for iPhone</a></p>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-1734"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2011/03/import-evernote-notes-to-onenote-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MCITP</title>
		<link>http://www.thomasmaurer.ch/2010/12/mcitp/</link>
		<comments>http://www.thomasmaurer.ch/2010/12/mcitp/#comments</comments>
		<pubDate>Sat, 25 Dec 2010 21:36:05 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Windows Server 2008 R2]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Enterprise Administrator]]></category>
		<category><![CDATA[MCITP]]></category>
		<category><![CDATA[MCP]]></category>
		<category><![CDATA[MCTS]]></category>
		<category><![CDATA[Virtualization Administrator]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=1469</guid>
		<description><![CDATA[In the last 2 months I passed my first two MCITP (Microsoft Certified IT Professional) Certifications. The first was the new MCITP: Windows Server 2008 R2, Virtualization Administrator and the second was the MCITP: Enterprise Administrator. I am really happy &#8230; <a href="http://www.thomasmaurer.ch/2010/12/mcitp/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2010/12/mcitp/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2010/12/mcitp/" data-count="horizontal" data-text="MCITP" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2010%2F12%2Fmcitp%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p><img class="aligncenter size-full wp-image-1471" title="MCITP(rgb)_1085_1324" src="http://www.thomasmaurer.ch/wp-content/uploads/2010/12/MCITPrgb_1085_1324.png" alt="MCITP" width="325" height="60" /></p>
<p>In the last 2 months I passed my first two MCITP (<a href="http://www.microsoft.com/learning/en/us/certification/mcitp.aspx">Microsoft Certified IT Professional</a>) Certifications. The first was the new MCITP: Windows Server 2008 R2, Virtualization Administrator and the second was the MCITP: Enterprise Administrator. I am really happy it was hard work but I think it was worth it.</p>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-1469"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2010/12/mcitp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple Bean Machine program done in Powershell</title>
		<link>http://www.thomasmaurer.ch/2010/09/simple-bean-machine-program-done-in-powershell/</link>
		<comments>http://www.thomasmaurer.ch/2010/09/simple-bean-machine-program-done-in-powershell/#comments</comments>
		<pubDate>Wed, 29 Sep 2010 11:00:12 +0000</pubDate>
		<dc:creator>Thomas Maurer</dc:creator>
				<category><![CDATA[Fun]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KTSI]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[School]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[bean machine]]></category>
		<category><![CDATA[c++]]></category>
		<category><![CDATA[output]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[powershell bean machine]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[Windows Powershell]]></category>

		<guid isPermaLink="false">http://www.thomasmaurer.ch/?p=1073</guid>
		<description><![CDATA[In the last article I posted the C++ Code for a simple Bean Machine output. Now I did the same in Powershell. I know this is not really a fantastic Powershell script, but its good to show others how things &#8230; <a href="http://www.thomasmaurer.ch/2010/09/simple-bean-machine-program-done-in-powershell/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><div class='dd_post_share'><div class='dd_buttons'><div class='dd_button'><script type='text/javascript' src='https://apis.google.com/js/plusone.js'></script><g:plusone size='small' href='http://www.thomasmaurer.ch/2010/09/simple-bean-machine-program-done-in-powershell/'></g:plusone></div><div class='dd_button'><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.thomasmaurer.ch/2010/09/simple-bean-machine-program-done-in-powershell/" data-count="horizontal" data-text="Simple Bean Machine program done in Powershell" data-via="thomasmaurer" ></a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div class='dd_button'><iframe src='http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.thomasmaurer.ch%2F2010%2F09%2Fsimple-bean-machine-program-done-in-powershell%2F&amp;locale=en_US&amp;layout=button_count&amp;action=like&amp;width=92&amp;height=20&amp;colorscheme=light' scrolling='no' frameborder='0' style='border:none; overflow:hidden; width:92px; height:20px;' allowTransparency='true'></iframe></div></div><div style='clear:both'></div></div><div style='clear:both'></div><p><img class="aligncenter size-medium wp-image-621" title="Powershell Header" src="http://www.thomasmaurer.ch/wp-content/uploads/2010/05/Screen-shot-2010-05-30-at-13.08.42-300x70.png" alt="Powershell Header" width="300" height="70" /></p>
<p>In the last article I posted the <a title="C++ bean machine" href="http://www.thomasmaurer.ch/2010/09/simple-c-bean-machine-program-ktsi/" target="_blank">C++ Code for a simple Bean Machine output</a>. Now I did the same in Powershell. I know this is not really a fantastic Powershell script, but its good to show others how things get done in Powershell.</p>
<p>Like in the C++ bean machine it works like this:</p>
<p><img class="aligncenter size-medium wp-image-1069" title="Bean Machine" src="http://www.thomasmaurer.ch/wp-content/uploads/2010/09/Screen-shot-2010-09-28-at-13.23.14-300x160.png" alt="Bean Machine" width="300" height="160" />And the Output should look like this:</p>
<p><a href="http://www.thomasmaurer.ch/wp-content/uploads/2010/09/Screen-shot-2010-09-28-at-13.23.25.png" rel="lightbox[1073]"><img class="aligncenter size-medium wp-image-1070" title="Bean Machine output" src="http://www.thomasmaurer.ch/wp-content/uploads/2010/09/Screen-shot-2010-09-28-at-13.23.25-300x150.png" alt="Bean Machine output" width="300" height="150" /></a>And here is how you do this in Powershell:</p>
<pre>
#Config
[int]$ballCount = 100
[array]$box = @(0, 1, 2, 3, 4, 5)
[string]$line = " +-----+-----+-----+-----+-----+-----+-----+-----+-----+-----+-----+-->"
[string]$numbers = " 0     5     10     15     20     25     30     35     40     45     50"
[object]$random = New-Object  System.Random

#count
for([int]$i = 0; $i -lt $ballCount; $i++){
	[int]$counter = 0

	for([int]$j = 0; $j -lt 5; $j++){
	$leftorright = $random.next(0,2)
	$counter = $counter + $leftorright
	}
	$box[$counter] = $box[$counter] + 1
}

#Output
Write-Host $numbers
Write-Host $line
for ([int]$t = 0; $t -lt 6; $t++){
	[string]$Statusline = ""
	for ([int]$u = 0; $u -lt $box[$t]; $u++){
		[string]$Statusline += "#"
		}
	Write-Host $t "|" $Statusline $box[$t]
	Write-Host $line
}
</pre>
<!-- Social Buttons Generated by Digg Digg plugin v4.5.3.4, 
    Author : Yong Mook Kim
    Website : http://www.diggdigg2u.com --><div class="shr-publisher-1073"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.thomasmaurer.ch/2010/09/simple-bean-machine-program-done-in-powershell/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

