<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
	<title><![CDATA[Articles]]></title>
	<link><![CDATA[http://www.systemcentercentral.com/Articles/tabid/61/rss/1/CategoryId/2/Default.aspx]]></link>
	<description></description>
	<language>en-us</language>
	<copyright><![CDATA[Copyright 2009 System Center Central All Rights Reserved.]]></copyright>
	<lastBuildDate>Sat, 04 Sep 2010 01:39:31 GMT</lastBuildDate>
		<item>
			<title><![CDATA[Articles: MONITRING DMZ AND WORKGROUP COMPUTER WITH SCOM 2007 R2 USING CERTIFICATES (ERRORS 21007 AND 21016 AFTER APPROVING THE AGENT IN PENNDING MANGMENT) ]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/77779/Default.aspx]]></link>
			<description><![CDATA[<p>a new guide to help you monitor servers in your dmz or a workgroup with system center operation manger</p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3">By shahar nusbaum<span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></font></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Well there might be a few guides like this around the web and I have used most of them,</font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3"><font face="Calibri">But for the past 3 mounts I have been battling with this scenario where the agent would stay in "not monitor" state after been approved in the pending management pane and the agent had 21007 and 21016 events on the operations manger event log on the workgroup / dmz server <span style="mso-spacerun: yes"> </span>I wanted to monitor</font><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">. <o:p></o:p></span></font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3"><font face="Calibri">If you have a working gateway and after your approve the agents in pending mode and used to momcertimport with successful results and you <b><u>still</u></b> receive event id's like21007 and 21016 on the workgroup / DMZ agent this guide is for you.<span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></font></font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Well my solution is available for you here</font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Well first of all and very basic (but not for me) I have 2003 enterprise ca server so I used this guide to create my </font><span style="line-height: 115%; font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">certificate</span><font size="3" face="Calibri"> template</font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><span style="line-height: 115%; font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">To create a certificate template</span><font size="3" face="Calibri"> - </font><a href="http://technet.microsoft.com/en-us/library/bb735413.aspx"><font size="3" face="Calibri">http://technet.microsoft.com/en-us/library/bb735413.aspx</font></a></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">I flowed that guide to the letter and still those event id's and no communication to my gateway.</font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3"><span style="mso-spacerun: yes"> </span>Something was missing,<span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></font></font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3">The first change I noticed was that I now I had no option to save a certificate to local computer certificate store this of course is because of the server 2008 enrolment<span style="mso-spacerun: yes">  </span>pages that would need administrator right witch the internet explorer does not use<span style="mso-spacerun: yes">   </span><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></font></font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><span style="mso-no-proof: yes"><v:shapetype id="_x0000_t75" stroked="f" filled="f" path="m@4@5l@4@11@9@11@9@5xe" o:preferrelative="t" o:spt="75" coordsize="21600,21600"><v:stroke joinstyle="miter"></v:stroke><v:formulas><v:f eqn="if lineDrawn pixelLineWidth 0"></v:f><v:f eqn="sum @0 1 0"></v:f><v:f eqn="sum 0 0 @1"></v:f><v:f eqn="prod @2 1 2"></v:f><v:f eqn="prod @3 21600 pixelWidth"></v:f><v:f eqn="prod @3 21600 pixelHeight"></v:f><v:f eqn="sum @0 0 1"></v:f><v:f eqn="prod @6 1 2"></v:f><v:f eqn="prod @7 21600 pixelWidth"></v:f><v:f eqn="sum @8 21600 0"></v:f><v:f eqn="prod @7 21600 pixelHeight"></v:f><v:f eqn="sum @10 21600 0"></v:f></v:formulas><v:path o:connecttype="rect" gradientshapeok="t" o:extrusionok="f"></v:path><o:lock aspectratio="t" v:ext="edit"></o:lock></v:shapetype><v:shape id="_x0000_i1030" type="#_x0000_t75" style="width: 414.75pt; height: 349.5pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image001.png"></v:imagedata></v:shape></span><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">So in order to export the certificate to a file I had to use internet explorer </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3">There under tools -> internet options -> content<span style="mso-spacerun: yes">  </span></font></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">There is a certificates section. </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Click the certificate button and you can export your certificate from there </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Remember to export the private key after clicking the next batten leave this mark </font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><span style="mso-no-proof: yes"><v:shape id="תמונה_x0020_2" type="#_x0000_t75" o:spid="_x0000_i1029" style="width: 367.5pt; height: 117.75pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image003.png"></v:imagedata></v:shape></span></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><font face="Calibri"><font size="3">Don’t mark include all certificates it the certification path if possible <o:p></o:p></font></font></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><font face="Calibri"><font size="3">The momcertimport tool will not be able to import the certificate <br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
<o:p></o:p></font></font></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3"><b><u>We will deal with the root ca needed in the workgroup / DMZ server in a minute</u></b><b><u><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></u></b></font></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p><span style="text-decoration: none"><font size="3"> </font></span></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><o:p><span style="text-decoration: none"><font size="3" face="Calibri"> </font></span></o:p></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Then you can save your certificate to a pfx file and copy it to the server you want to monitor</font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Keep it in a shared folder for the duration of the install process because you will need it for the gateway server as well as the workgroup / DMZ server.</font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><o:p><font size="3" face="Calibri"> </font></o:p></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">One more certificate is needed before we can continue and again I used this guide </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><a href="http://technet.microsoft.com/en-us/library/bb735413.aspx"><font size="3" face="Calibri">http://technet.microsoft.com/en-us/library/bb735413.aspx</font></a><font size="3"><font face="Calibri"><span style="mso-spacerun: yes">  </span>I used the section called "<b><u>To</u></b></font></font><b><u><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt"> download the Trusted Root (CA) certificate"<br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
<o:p></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">Notice that you might not be able to get to the web site of your ca server form the workgroup computer so you can do that from your root management server and just save it in the folder were you saved your ca for the </span><font size="3" face="Calibri">workgroup / DMZ server</font><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt"> you wanted to monitor<o:p></o:p></span></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt"><o:p> </o:p></span></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">And on one last note before we begin: </span></u></b><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">while most guide say the certificate subject a.k.a the name filed </span><font size="3" face="Calibri">is fqdn don’t just push your domain name in the computer name. <br />
cheek before logon to the workgroup / DMZ server<span style="mso-spacerun: yes">  </span>and Go to start -> computer -> properties – check the full computer name and copy the exact name to your gateway host file if no dns resolution is available</font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><o:p><font size="3" face="Calibri"> </font></o:p></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">NOW FOR THE STEP BY STEP GUIDE </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><o:p><font size="3" face="Calibri"> </font></o:p></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr; mso-list: l0 level1 lfo1"><strong><span style="font-family: "Calibri","sans-serif"; font-size: 16pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore">1.<span style="font: 7pt "Times New Roman"">    </span></span></span></strong><b><u><span style="font-size: 12pt"><font face="Calibri">PREPERING TO INSTALL<span style="mso-spacerun: yes">  </span>THE AGENT ON THE WORKGROUP MECHINE</font></span></u></b><font face="Calibri"><b><span style="font-size: 12pt"><span style="mso-spacerun: yes">  </span><br />
</span></b><br />
<font size="3"><u><span style="mso-spacerun: yes"> </span>I recommend<span style="mso-spacerun: yes">  </span>you copy this folders<span style="mso-spacerun: yes">  </span>form your scom CD</u><span style="mso-spacerun: yes">  </span>to one folder you can move around in your environment, let's call that our "scomdmz" inside you will need this folders <br />
* SupportTools<br />
* agent<br />
<u>I recommend<span style="mso-spacerun: yes">  </span>you copy this files to that same folder</u><br />
* server_cert.pfx (certificate you created using a template for your workgroup / DMZ server)<br />
<br />
* </font></font><font size="3"><strong><span style="font-family: "Calibri","sans-serif"; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin">CA_certificate_chain.p7b (for the trusted Root (CA) certificate)<br />
move this file to your workgroup machine<span style="mso-spacerun: yes">  </span>(keep a copy of your </span></strong><font face="Calibri">server_cert.pfx</font></font><font size="3"><strong><span style="font-family: "Calibri","sans-serif"; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin"> to copy to your gateway server later<span style="mso-spacerun: yes">  </span>)<br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
</span></strong><strong><span style="font-family: "Calibri","sans-serif"; font-size: 16pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin"><o:p></o:p></span></strong></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr; mso-list: l0 level1 lfo1"><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face="Calibri">2.</font><span style="font: 7pt "Times New Roman"">     </span></span></span></b><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">INSTALLING THE AGENT ON THE WORKGROUP MECHINE<br />
<br />
</font></span></u></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">run the msi installation on your server<span style="mso-spacerun: yes">  </span>if there is no dns resolution for your gateway server ping –a the ip address to see if you get the name of your gateway server, <span style="mso-spacerun: yes"> </span>if not you will need to add your gateway server fqdn name to your host file – it's in c:\windows\system32\drivers\etc <br />
</font><span style="mso-no-proof: yes"><v:shape id="תמונה_x0020_1" type="#_x0000_t75" o:spid="_x0000_i1028" style="width: 369.75pt; height: 198pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image005.png"></v:imagedata></v:shape></span><br />
<br />
<font face="Calibri">(we use the example in our org…)<br />
<br />
I KNOW THIS IS A VERY BASIC STUFF RIGHT HERE – I want this guide to be able to apply even to those who don’t deal with this in a daily manner<br />
<br />
<span style="mso-spacerun: yes"> </span>now this to prevent any <b><u>human typing Mistake</u></b></font></span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> </font></span></u></b><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">write the fqdn gateway server in the host file copy & paste it to the management computer name I recommend also copy & paste to command line and telnet the computer name to your gateway on 5723 to check connectivity. <br />
Click next your almost home free…<br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
</span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o:p></o:p></span></u></b></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr; mso-list: l0 level1 lfo1"><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face="Calibri">3.</font><span style="font: 7pt "Times New Roman"">     </span></span></span></b><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">IMPORTING THE CERTIFICATES TO YOUR GATEWAY AND SERVER <br />
<br />
</font></span></u></b><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">THIS WILL BE SPLIT IN TO TWO PARTS <br />
<br />
<b><u>A.<span style="mso-spacerun: yes">  </span>IMPORTING THE CERTIFICATES ON YOUR DMZ SERVER YOU WANT TO MONITOR - </u></b><span style="mso-spacerun: yes"> </span><br />
<br />
<b><u><span style="mso-spacerun: yes"> </span>using the momcertimport tool <span style="mso-spacerun: yes"> </span></u></b><span style="mso-spacerun: yes"> </span><br />
-on the </span><font size="3">workgroup / DMZ server</font></font><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> go to start -> if 2008 type cmd if 2003 go to run type cmd<br />
<b><u>one thing very imported cheek</u></b> -<span style="mso-spacerun: yes">  </span>if you're on server 2008 check to see if your command prompt run with administrator rights (if not right click the icon before you press enter and<span style="mso-spacerun: yes">  </span>run it as administrator)<br />
</font><span style="mso-no-proof: yes"><v:shape id="תמונה_x0020_3" type="#_x0000_t75" o:spid="_x0000_i1027" style="width: 415.5pt; height: 57.75pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image007.png"></v:imagedata></v:shape></span><br />
<br />
<br />
<font face="Calibri">the tool is in the </font></span><font size="3" face="Calibri">SupportTools folder (the one we copied earlier if you flowed step one)</font><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> <br />
</font></span></u></b><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">so! The way to run this tool is simple get to it in the command prompt and the give the server certificate file like so <br />
c:\dmzfolder\</span><font size="3">SupportTools\i386\momcertimport <b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-spacerun: yes"> </span></span></b>server_cert.pfx type the password for the key and you will need to receive successfully<span style="mso-spacerun: yes">  </span>state message </font></font><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
</span></u></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
</span><font face="Calibri"><span style="font-size: 16pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">YOU GOT THIS FAR –</span><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"> you stop and started the health service like asked in the momcertimport tool after imported the certificate<span style="mso-spacerun: yes">  </span>and still receive those </span><font size="3">21007 and 21016 events<span style="mso-spacerun: yes">  </span>you will need to fallow this few steps</font></font><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
<br />
<span style="mso-spacerun: yes"><font face="Calibri"> </font></span><font face="Calibri"><u>What you need now is another certificate to be imported.<br />
</u><span style="mso-spacerun: yes">    </span>1.<span style="mso-tab-count: 1">     </span>Go to start mmc -> file -> add/remove snap-in…<br />
<span style="mso-spacerun: yes">    </span>2.<span style="mso-tab-count: 1">     </span>Add certificates add computer account, click next choose local<span style="mso-spacerun: yes">                                            </span>computer click ok and exit – it's all you need for the console<br />
<br />
<span style="mso-spacerun: yes">    </span>3. <span style="mso-tab-count: 1">    </span>Go to the </font></span><strong><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 8pt; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">Trusted Root Certification Authorities</span></strong><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> folder on the folder </font></span><strong><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 8pt; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">Certificates </span></strong><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">right click all tasks -> import… <br />
and import your </span><font size="3"><span style="mso-spacerun: yes"> </span><strong><span style="font-family: "Calibri","sans-serif"; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin">CA_certificate_chain.p7b</span></strong></font></font><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> we prepared in step 1 this guide<br />
and import it to the </font></span><strong><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 8pt; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">Trusted Root Certification Authorities</span></strong><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> folder <br />
the folder contains certificates that in most time already be in there <br />
but don’t skip this stage.<br />
<br />
</font></span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-no-proof: yes"><v:shape id="תמונה_x0020_5" type="#_x0000_t75" o:spid="_x0000_i1026" style="width: 405.75pt; height: 149.25pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image009.png"></v:imagedata></v:shape></span></u></b><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
<br />
</span></u></b><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">B. IMPORTING THE CERTIFICATES ON TO YOU GATEWAY SERVER –</font></span></u></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> again this is for all of you battling with<span style="mso-spacerun: yes">  </span>error id<span style="mso-spacerun: yes">  </span>21037 on your gateway (and of course any kind of lack of communication between the agent and your gateway server ) <br />
<br />
<span style="mso-spacerun: yes">    </span>1.<span style="mso-tab-count: 1">     </span>Go to start mmc -> file -> add/remove snap-in…<br />
<span style="mso-spacerun: yes">    </span>2.<span style="mso-tab-count: 1">     </span>Add certificates add computer account, click next choose local<span style="mso-spacerun: yes">                                            </span>computer click ok and exit – it's all you need for the console<br />
<span style="mso-spacerun: yes">    </span>3. Go to the </font></span><strong><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 8pt; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">Trusted Root Certification Authorities</span></strong><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> </font></span></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">and import your <br />
</font></span><font face="Calibri"><font size="3">server_cert.pfx we talked about in step one to that folder <br />
</font><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-spacerun: yes">   </span></span></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-spacerun: yes"> </span>3. Go to Personal folder and import it to that folder ass well </span></font><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
<span style="mso-no-proof: yes"><v:shape id="תמונה_x0020_6" type="#_x0000_t75" o:spid="_x0000_i1025" style="width: 359.25pt; height: 204pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image011.png"></v:imagedata></v:shape></span><br />
<br />
<br />
</span></u></b><font face="Calibri"><b><u><span style="font-size: 16pt">note: we are importing the certificates of the server that we want to monitor into our</span></u></b><u><span style="font-size: 16pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"> <b>gateway</b><span style="mso-spacerun: yes">  </span><strong><span style="font-family: "Calibri","sans-serif"; color: black; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin">Trusted Root Certification Authorities and to the personal folder</span></strong></span></u></font><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
<br />
<br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
<o:p></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr; mso-list: l0 level1 lfo1"><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face="Calibri">4.</font><span style="font: 7pt "Times New Roman"">     </span></span></span></b><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">CHEKING THE COUMNICATION -<br />
<br />
</font></span></u></b><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">after all the certificates have been imported to<span style="mso-spacerun: yes">  </span>the gateway server and to our soon to be monitored server, in order for this changes to take affect well have to do the fallowing steps <br />
<br />
restart health service known as system center management on your gateway <br />
restart health service known as system center management on your<span style="mso-spacerun: yes">  </span>root management server<br />
restart health service known as system center management on your dmz server </span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o:p></o:p></span></u></b></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o:p><span style="text-decoration: none"><font face="Calibri"> </font></span></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o:p><span style="text-decoration: none"><font face="Calibri"> </font></span></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">Check your DMZ server event viewer to see if the error id repeats <o:p></o:p></font></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">Some changes take time you might want to wait 5-10 minutes after 10 <o:p></o:p></font></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">Minutes you need restart the health service again on your DMZ server and cheek your event viewer for the id's if still receive restart the health service again on your root management server and your gateway server<br />
<br />
<br />
</span></u></b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">this is my solution and I would like to thank Yossi tali and </span><span style="font-size: 14pt">Gal Hutman<o:p></o:p></span></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><span style="font-size: 14pt"><font face="Calibri">For their help in finding this solution </font></span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
<o:p></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr"><br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
 </p>
<p> </p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/77779/Default.aspx" length="1301" type=""></enclosure>
			<pubDate>Thu, 19 Aug 2010 11:26:21 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/77779/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Monitoring DPM using OpsMgr, Cookdown & PowerShell ]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/77056/Default.aspx]]></link>
			<description><![CDATA[Monitor DPM data sources in Operations Manager R2 accurately and efficiently using PowerShell and cookdown.]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/77056/Default.aspx" length="40481" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Fri, 13 Aug 2010 15:05:00 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/77056/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Management Pack for IBM DB2]]></title>
			<link><![CDATA[http://www.nice.de/en/nice-products/nice-db2-management-pack-for-microsoft-scom]]></link>
			<description><![CDATA[<p>Efficiently monitor distributed IBM DB2 databases on Microsoft Windows from a central console.<br />
The NiCE DB2 Management Pack (NiCE DB2 MP) helps you increase RDBMS availability and performance and to lower the overall cost of maintaining your DB2 databases. It enables you to perform service-oriented management as well as incident management in your DB2 environment, supporting your business critical processes. <br />
To ensure always-on availability, the NiCE DB2 MP monitors key operational activities and events such as event logs and processes. Information from important system tables is collected to reflect DB2 activity.</p>
<p> </p>
<p>Free Evaluation Copies: https://portal.nice.de</p>]]></description>
			<enclosure url="http://www.nice.de/en/nice-products/nice-db2-management-pack-for-microsoft-scom" length="1301" type="application/pdf"></enclosure>
			<pubDate>Tue, 03 Aug 2010 11:21:52 GMT</pubDate>
			<guid>http://www.nice.de/en/nice-products/nice-db2-management-pack-for-microsoft-scom</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Full procedure on how to setup GSM Modem in SCOM on a VM Environment]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/72326/Default.aspx]]></link>
			<description><![CDATA[<p>Made by Sebastien Paquet, <br />
                                     I've never found any procedure on how to install the Scom paging system on a FULL Virtual environment (ESX).  Here is a great Step-by-step procedure that I have created for you ...  Click the Download buton!</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/72326/Default.aspx" length="1301" type=""></enclosure>
			<pubDate>Wed, 07 Jul 2010 14:40:08 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/72326/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Calculating Data Churn]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/68594/Default.aspx]]></link>
			<description><![CDATA[<p style="text-align: left; "> </p>
<table width="66%" border="0" cellpadding="1" cellspacing="1" align="left">
    <tbody>
        <tr>
            <td><img alt="Churn" width="92" height="140" src="http://www.systemcentercentral.com/Portals/0/blog-images/churn.jpg" /></td>
            <td>This article steps you through how to calculate the daily data churn on your DPM servers.  This will prove useful if you are looking at implementing DPM2DPM4DR, looking for suitable storage or if your just wondering how busy your DPM server is.</td>
        </tr>
    </tbody>
</table>
<p style="text-align: left; "> </p>
<p style="text-align: left; "> </p>
<p style="text-align: left; "> </p>
<p style="text-align: left; "> </p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/68594/Default.aspx" length="31481" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Thu, 10 Jun 2010 20:15:02 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/68594/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Authoring Custom Templates and Writing Custom UI]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/67911/Default.aspx]]></link>
			<description><![CDATA[<p> <span class="Apple-style-span" style="font-size: 16px; line-height: 18px; ">Management pack authoring templates are a useful way to add additional monitoring on an as-needed basis. A great example is the TCP port wizard – it would make no sense to monitor every TCP port out of the box, so OpsMgr provides a wizard for adding ports on a case by case basis.</span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;line-height:115%">So what if you would like to modify how one of the existing templates works or create your own? There is no documentation available that I have found that describes how to do this so that is what I’m setting out to do in this article. <o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;line-height:115%">Creating a custom template involves two main components: <o:p></o:p></span></p>
<ul style="margin-top:0in" type="disc">
    <li class="MsoNormal" style="mso-list:l0 level1 lfo2"><span style="font-size:
    12.0pt;line-height:115%">The template elements in a management pack. I’ve      attached a working sample and added lots of comments so please have a look      through.<br />
    <o:p></o:p></span></li>
    <li class="MsoNormal" style="mso-list:l0 level1 lfo2"><span style="font-size:
    12.0pt;line-height:115%"><span style="mso-spacerun:yes"> </span>A compiled      UI screen written in managed code (c# in this case). <o:p></o:p></span></li>
</ul>
<p class="MsoNormal"><span style="font-size:12.0pt;line-height:115%">A word of warning: the authoring console will not help with either of these.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;line-height:115%">Here are the steps you can use to create your custom UI screen:<o:p></o:p></span></p>
<ol style="margin-top:0in" start="1" type="1">
    <li class="MsoNormal" style="mso-list:l1 level1 lfo3"><span style="font-size:
    12.0pt;line-height:115%">Using Visual Studio, create a new class library<br />
    <o:p></o:p></span></li>
    <li class="MsoNormal" style="mso-list:l1 level1 lfo3"><span style="font-size:
    12.0pt;line-height:115%">Delete the class1.cs file that gets created by      default<o:p></o:p></span></li>
    <li class="MsoNormal" style="mso-list:l1 level1 lfo3"><span style="font-size:
    12.0pt;line-height:115%">Add references to the necessary OpsMgr DLLs. You      can find these in C:\Program Files\System Center Operations Manager 2007\      as well as the SDKBinaries folder within that folder.<o:p></o:p></span></li>
    <li class="MsoNormal" style="mso-list:l1 level1 lfo3"><span style="font-size:
    12.0pt;line-height:115%">Add a new User Control to the project named      EventDetailsPage<o:p></o:p></span></li>
    <li class="MsoNormal" style="mso-list:l1 level1 lfo3"><span style="font-size:
    12.0pt;line-height:115%">Double click on the user control to open the      designer screen. Add your UI widgets from the toolbox. I’ve added two text      boxes named txtEventID and txtEventSource.<o:p></o:p></span></li>
    <li class="MsoNormal" style="mso-list:l1 level1 lfo3"><span style="font-size:
    12.0pt;line-height:115%">Open the code view of your user control and make      the following changes by copying and pasting from the code that I’ve attached      to the article:<o:p></o:p></span>
    <ol style="margin-top:0in" start="1" type="a">
        <li class="MsoNormal" style="mso-list:l1 level2 lfo3"><span style="font-size:
        12.0pt;line-height:115%">Add all the “using” statements<o:p></o:p></span></li>
        <li class="MsoNormal" style="mso-list:l1 level2 lfo3"><span style="font-size:
        12.0pt;line-height:115%">Change the class to inherit from UIPage<o:p></o:p></span></li>
        <li class="MsoNormal" style="mso-list:l1 level2 lfo3"><span style="font-size:
        12.0pt;line-height:115%">Add the SavePageConfig() method<o:p></o:p></span></li>
    </ol>
    </li>
    <li class="MsoNormal" style="mso-list:l1 level1 lfo3"><span style="font-size:
    12.0pt;line-height:115%">Build the project<o:p></o:p></span></li>
    <li class="MsoNormal" style="mso-list:l1 level1 lfo3"><span style="font-size:
    12.0pt;line-height:115%">Copy the DLL that you’ve just compiled to the      OpsMgr program files folder.<o:p></o:p></span></li>
</ol>
<p class="MsoNormal"><span style="font-size:12.0pt;line-height:115%">Now you are ready to run your new template! <o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;line-height:115%">Import your management pack and go to the authoring templates. Your new template will show up in the list. When you run the wizard, your UI screen will allow the user to input values.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;line-height:115%">A note on how OpsMgr processes templates when you’re done with the wizard:</span></p>
<ul>
    <li><span style="font-size:12.0pt;line-height:115%"><o:p></o:p></span><span style="font-size:12.0pt;line-height:115%">OpsMgr replaces $TemplateConfig/ConfigValue$ variables in the implementation section of the template with the user-provided values.<br />
    <br type="_moz" />
    </span></li>
    <li><span style="font-size:12.0pt;line-height:115%"><o:p></o:p></span><span style="font-size:12.0pt;line-height:115%">Merges the implementation section into the management pack that you specified on the first wizard screen.<br />
    <br type="_moz" />
    </span></li>
    <li><span style="font-size:12.0pt;line-height:115%">Creates a <folder> for the template and puts every generated element in the folder using <folderitem>s. When you click on your template after running the wizard, OpsMgr uses this folder system to display previous output of the template. This is also how it knows what to delete if you delete template output. A side effect of this is that it is assumed that you will create elements with unique IDs for each run of the template. If you create non-unique elements, OpsMgr will effectively delete all runs of the template when any single run is deleted.</span></li>
</ul>
<p>
<p class="MsoListParagraph" style="margin-left:.25in"><span style="font-size:
12.0pt;line-height:115%">The sample UIPage I’ve attached barely scratches the surface of what is possible. Some fodder for future articles or your own exploration:<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in;
mso-list:l0 level1 lfo1"><span style="font-size:12.0pt;
line-height:115%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
Symbol"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">         </span></span></span><span style="font-size:12.0pt;line-height:115%">There is a built-in SDK connection available in the UIPage so you can populate drop-down lists with monitored computers for example<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in;
mso-list:l0 level1 lfo1"><span style="font-size:12.0pt;
line-height:115%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
Symbol"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">         </span></span></span><span style="font-size:12.0pt;line-height:115%">The UIPage has various properties that give you the context in which it is running such as a reference to the template itself<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in;
mso-list:l0 level1 lfo1"><span style="font-size:12.0pt;
line-height:115%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
Symbol"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">         </span></span></span><span style="font-size:12.0pt;line-height:115%">You can handle the user editing your template as well as just creating new ones<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in;
mso-list:l0 level1 lfo1"><span style="font-size:12.0pt;
line-height:115%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
Symbol"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">         </span></span></span><span style="font-size:12.0pt;line-height:115%">You can create custom UI for other workflows such as rules, monitors ,etc<o:p></o:p></span></p>
</p>
<p><span style="font-size:12.0pt;line-height:115%"><o:p></o:p></span></p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/67911/Default.aspx" length="1301" type="application/zip"></enclosure>
			<pubDate>Sun, 30 May 2010 00:20:37 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/67911/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Step By Step Protecting Windows Client using DPM]]></title>
			<link><![CDATA[http://owsug.ca/blogs/islamgomaa/archive/2010/05/26/Step-By-Step-Protecting-Windows-Client-using-DPM.aspx]]></link>
			<description><![CDATA[<h5>Step By Step Protecting Windows Client using DPM</h5>
<p>Microsoft System Center Data Protection Manager (DPM) 2010 allows you to protect client computers - desktops and laptops. Backup administrators can centrally configure data protection for the desktops and laptops in their environment. Additionally, administrators can give their end users the ability to define and manage their own backups. DPM 2010 enables end users to perform their own recoveries by leveraging the Previous Versions feature in Windows.</p>
<p> </p>
<p>In this article I will show how to protect client using DPM2010</p>
<p> </p>
<p>in the protection group tab , click on the left site on Create protection Group, that will open a window has two choices , backup servers or Backup Clients , in our case we are going to select Clients , then click Next</p>
<p>Note</p>
<p><em>If you want to add multiple computers, you can create a .txt file containing the computers you want to add. To add the computers, click <b>Add Multiple Computers</b>. You must enter each computer in the file on a new line. We recommend that you provide the fully qualified domain name (FQDN) of the target computers. For example, enter multiple computers in a .txt file as follows:</em></p>
<p><em>Comp1.abc.domaian.com <br />
Comp2.abc.domain.com <br />
Comp3.abc.domain.com</em></p>
<p><em>If DPM cannot find any of the computers that you specified in the .txt file or that you entered in the <b>Text file location</b> box, the failed set of computers is placed in a log file. Click the <b>Failed to add machines</b> link at the bottom of the page to open the log file.</em></p>
<p><a href="http://owsug.ca/blogs/islamgomaa/image_3F09EBCE.png"><img title="image" border="0" alt="image" src="http://owsug.ca/blogs/islamgomaa/image_thumb_3ACFEE3C.png" width="244" height="184" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" /></a></p>
<p> </p>
<p>in the Select Group Member window select the client that you wish  in my case I would like to backup W7D.gomaalab.local</p>
<p><a href="http://owsug.ca/blogs/islamgomaa/image_398B555D.png"><img title="image" border="0" alt="image" src="http://owsug.ca/blogs/islamgomaa/image_thumb_049E5020.png" width="244" height="183" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" /></a></p>
<p>On the <b>Specify Inclusions and Exclusions</b> page, specify the folders to include or exclude for protection on the selected computers.</p>
<p>a. Type the folder names in the <b>Folder</b> column using variables such as %programfiles%, or you can use the exact folder name. Select <b>Include</b> or <b>Exclude</b> for each entry in the <b>Rule</b> column.</p>
<p>b. Select <b>Allow users to specify protection members</b> to give your end users the choice to add more folders on the computer that they want to back up. However, the files and folders you have explicitly excluded as an administrator cannot be selected by the end user.</p>
<p>c. Under <b>File type exclusions</b> specify the file types to exclude using their file extensions, and then click <b>Next</b> to continue.</p>
<p> </p>
<p><a href="http://owsug.ca/blogs/islamgomaa/image_0E83418B.png"><img title="image" border="0" alt="image" src="http://owsug.ca/blogs/islamgomaa/image_thumb_79451615.png" width="244" height="184" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" /></a></p>
<p>in the select Data protection method,  select the  protection method that suite your need either short-term or long-term , then click Next</p>
<p><a href="http://owsug.ca/blogs/islamgomaa/image_4608DCAC.png"><img title="image" border="0" alt="image" src="http://owsug.ca/blogs/islamgomaa/image_thumb_471DC5CB.png" width="244" height="184" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" /></a></p>
<p>click next , and specify your short-term recovery goal</p>
<p>notice there is  new option to specify after how long DPM will raise an alert if the Client will not be available for backup, in my case I configured for 18 days </p>
<p><a href="http://owsug.ca/blogs/islamgomaa/image_290F920A.png"><img title="image" border="0" alt="image" src="http://owsug.ca/blogs/islamgomaa/image_thumb_4CE84397.png" width="244" height="183" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" /></a></p>
<p>On the <b>Allocate Storage</b> page, specify the size of data to be protected on the computer. I recommend that you co-locate multiple data sources to one DPM replica volume. Click <b>Next</b> to continue.</p>
<p><br />
Note</p>
<p>I recommend that you co-locate your data if you have a large number of client computers. You will not be able to protect 750 or more client computers with one DPM server without co-locating your data. I recommend that you do not co-locate if you have less than ten client computers in a protection group.</p>
<p> </p>
<p> </p>
<p> </p>
<p>in the summary window  click create Group then close</p>
<p><a href="http://owsug.ca/blogs/islamgomaa/image_0BD9C433.png"><img title="image" border="0" alt="image" src="http://owsug.ca/blogs/islamgomaa/image_thumb_56808C00.png" width="244" height="183" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" /></a></p>
<p> </p>
<p>Islam Gomaa</p>
<p>Islam @ IslamGomaa.com</p>]]></description>
			<pubDate>Sun, 06 Jun 2010 04:28:48 GMT</pubDate>
			<guid>http://owsug.ca/blogs/islamgomaa/archive/2010/05/26/Step-By-Step-Protecting-Windows-Client-using-DPM.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How to create an instance group in the MP Authoring console]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/67819/Default.aspx]]></link>
			<description><![CDATA[<p>Great step-by-step article from Jonathan Almquist [MSFT] on how to create an instance group and configure groupcalc in the MP authoring console.</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/67819/Default.aspx" length="73839" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Fri, 28 May 2010 02:40:25 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/67819/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How to create a computer group in the MP Authoring Console]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/67818/Default.aspx]]></link>
			<description><![CDATA[<p>Great step-by-step article from Jonathan Almquist [MSFT] on how to create a computer group and configure groupcalc in the MP authoring console.</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/67818/Default.aspx" length="72066" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Fri, 28 May 2010 03:58:03 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/67818/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Logon Process Monitoring for Citrix XenApp]]></title>
			<link><![CDATA[http://www.hermes-softlab.com/products/management_products/documents/white_paper/logon_process_monitoring_for_xenapp.pdf?utm_source=SCC&utm_medium=article&utm_term=Citrix&utm_content=static&utm_campaign=SCC]]></link>
			<description><![CDATA[<p>User logon is a complex and resource intensive process on a Citrix XenApp system. It is initiated when a XenApp farm load balancing algorithm selects the system where a published application or desktop, which a user has selected, will be started and ends when the application or desktop is running and the user is able to interact with it.<br />
<br />
There are a number of factors that have an impact on the logon process that can get further complicated if solutions that integrate into the logon process, such as User Workspace Management products, are used. All this is making the user logon process very hard to troubleshoot. Only a few of the best management tools can break down the logon process on a XenApp system into phases and measures their duration. Thus, troubleshooting the logon process is much easier, because you don't have to inspect the logon process as a whole; instead you concentrate only on the phase that is particularly slow.<br />
<br />
In <a href="http://www.hermes-softlab.com/products/management_products/documents/white_paper/logon_process_monitoring_for_xenapp.pdf?utm_source=SCC%2B&utm_medium=article%2BCitrix%20logon&utm_content=Citrix%2BXenApp&utm_campaign=SCC">the article</a>, you can find elements of each logon phase and possible reasons for their slow behavior: </p>
<ul>
    <li>Phase 1: User Profile Loading</li>
    <li>Phase 2: Applying Group Policy Objects (GPOs)</li>
    <li>Phase 3: User Environment Initialization and Active Setup</li>
    <li>Phase 4: Logon Script Execution.</li>
</ul>
<p><br />
Get more information in the article <a href="http://www.hermes-softlab.com/products/management_products/documents/white_paper/logon_process_monitoring_for_xenapp.pdf?utm_source=SCC%2B&utm_medium=article%2BCitrix%20logon&utm_content=Citrix%2BXenApp&utm_campaign=SCC">Logon Process Monitoring for Citrix XenApp</a> published on hermes.softlab.com.</p>]]></description>
			<pubDate>Thu, 06 May 2010 00:08:05 GMT</pubDate>
			<guid>http://www.hermes-softlab.com/products/management_products/documents/white_paper/logon_process_monitoring_for_xenapp.pdf?utm_source=SCC&amp;utm_medium=article&amp;utm_term=Citrix&amp;utm_content=static&amp;utm_campaign=SCC</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Exchange 2010 Override Example Walk through]]></title>
			<link><![CDATA[http://discussitnow.spaces.live.com/blog/cns!A4408C121568CAA4!6364.entry]]></link>
			<description><![CDATA[The Exchange 2010 has a suprise waiting for you.  It has a monitor that checks for the most recent updates to SCOM SP1 and R2.  If ANY agent in your environment is missing these updates, a medium priority critical alert will be generated.  The most recent SCOM MP already checks this on all agents and raises a medium priority warning.  In this guide I show you how to disable this monitor completely as well as how to create a over ride mp that will allow you to target this monitor to just Exchange 2010 servers.  Also the monitor in the Exchange 2010 is under the Availability parent monitor instead of configuration, where I really think it should be.]]></description>
			<pubDate>Fri, 28 May 2010 02:20:11 GMT</pubDate>
			<guid>http://discussitnow.spaces.live.com/blog/cns!A4408C121568CAA4!6364.entry</guid>
		</item>
		<item>
			<title><![CDATA[Articles: System Center Data Protection Manager 2010 Evaluation ]]></title>
			<link><![CDATA[http://owsug.ca/blogs/islamgomaa/archive/2010/04/20/System-Center-Data-Protection-Manager-2010-Evaluation.aspx]]></link>
			<description><![CDATA[<h4>Overview</h4>
<p><a name="Description"></a>Data Protection Manager 2010 is part of the System Center family of management products from Microsoft. It delivers unified data protection for Windows servers such as SQL Server, Exchange, SharePoint, Virtualization and file servers -- as well as Windows desktops and laptops. DPM is designed as a best-of-breed backup & recovery solution for Windows environments from Microsoft. DPM provides the best protection and most supportable restore scenarios of your Windows environment from disk, tape and cloud. Windows customers of all sizes can rely on Microsoft to provide a scalable and manageable protection solution that is cost-effective, secure and reliable. <br />
<br />
 </p>
<h4>Feature Summary</h4>
<ul>
    <li>Protection for Windows clients, while they are online or offline, with easy-to-use wizards for establishing protection, retention and alert schedules. A single DPM server can protect over 1,000 Windows clients, while end users are able to restore their own data using Windows Explorer or Microsoft Office.</li>
    <li>Protection of Microsoft Virtualization platforms, including Hyper-V R2 Live Migration / Cluster Shared Volume (CSV) configurations. DPM can also restore single-file items from host-based VM backups.</li>
    <li>Enhanced Protection for SQL Server, scaling to over 2,000 databases per DPM server, and offering auto-protection of new databases per SQL instance. DBA’s can now restore their own databases, through a self-service restore utility for SQL Server.</li>
    <li>Enhanced Protection of Exchange Server, scaling to over 40TB of email and support for Exchange 2010 Database Availability Groups (DAG), as well as CCR/SCR in Exchange 2007.</li>
    <li>Enhanced Protection for SharePoint, without the requirement for a recovery farm with SharePoint 2010, and scaling up to 25TB farms with over 1M items. New content databases are now auto-protected without administrator interaction.</li>
    <li>DPM 2010 is truly enterprise-ready, scaling to over 100 servers with over 80TB per DPM server, and includes new Auto-grow, Auto-heal, Auto-protect features for a lights-out reliable protection and recovery solution.</li>
</ul>
<h4>System Requirements</h4>
<ul>
    <li><b>Supported Operating Systems: </b>Windows Server 2008; Windows Server 2008 R2</li>
</ul>
<p>.NET Framework 3.5 with Service Pack 1 (SP1) <br />
Microsoft Visual C++ 2008 Redistributable Package <br />
Windows PowerShell 2.0 <br />
DPM 2010 must be installed on a Windows Server 2008 or Windows Server 2008 R2 64-bit computer that is located in an Active Directory domain that is running in 2003-mode or better. <br />
DPM 2010 can protect machines running 32-bit or 64-bit Windows Server 2003, 2003 R2, 2008 or 2008 R2, as well Windows XP, Windows Vista or Windows 7. <br />
If you are protecting data over a wide area network (WAN), there is a minimum network bandwidth requirement of 512 kilobits per second (Kbps).</p>
<p> </p>
<p><b><a href="http://technet.microsoft.com/en-ca/evalcenter/bb727240.aspx">Try Microsoft System Center Data Protection Manager 2010 RTM free for 180 days</a></b></p>]]></description>
			<pubDate>Sun, 06 Jun 2010 04:28:48 GMT</pubDate>
			<guid>http://owsug.ca/blogs/islamgomaa/archive/2010/04/20/System-Center-Data-Protection-Manager-2010-Evaluation.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: DPM 2010 - Bare Metal Recovery]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/64235/Default.aspx]]></link>
			<description><![CDATA[This article describes how you can perform Bare Metal Recovery backups in DPM 2010.  It is now much easier to do this and there is no need for the DPM System Recovery Tool which was required with DPM 2007.]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/64235/Default.aspx" length="33615" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Thu, 15 Apr 2010 20:09:56 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/64235/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Build you own DPM Appliance ]]></title>
			<link><![CDATA[http://owsug.ca/blogs/islamgomaa/archive/2010/04/12/Build-you-own-DPM-Appliance.aspx]]></link>
			<description><![CDATA[<p>One thing I have to say about DPM , it is requires a lot of  lot of disk space , if you are small medium business with large data storage to be backed up and want to implement DPM with less money of course , you need to consider to build your own DPM server.</p>
<p> </p>
<p>Building your own DPM server doesn't mean getting all the components and build a server as these old days,  this what you can do.</p>
<p>Dell offers the  PowerEdge R200 with 8 GB ram and mirrored SAS drive  with 10K RPM and QNAP offers  the TS-809U-RP Turbo NAS that offers  14 TB on RAID 5. combining both Hardware you can build your own DPM appliance for less than 6000 $.</p>
<p>ISlam Gomaa</p>
<p><a href="http://www.systemcentercentral.com/mailto:ISlam@IslamGomaa.com">ISlam @ IslamGomaa.com</a></p>]]></description>
			<pubDate>Wed, 14 Apr 2010 05:08:30 GMT</pubDate>
			<guid>http://owsug.ca/blogs/islamgomaa/archive/2010/04/12/Build-you-own-DPM-Appliance.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Creating custom dynamic computer groups based on registry keys on agents]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/63399/Default.aspx]]></link>
			<description><![CDATA[<p>by Kevin Holman, this is a great step-by-step on how to create a custom attribute based on a registry value, then how to create a dynamic group based on that value. Bookmarking here as I refer people to it frequently.</p>
<p>Click the Download button and you'll be redirected to the source.</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/63399/Default.aspx" length="53429" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Fri, 09 Apr 2010 01:13:48 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/63399/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How to restrict access to reports in Operations Manager 2007]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/62264/Default.aspx]]></link>
			<description><![CDATA[<p>by Mike Betts, this article demonstrates how to restrict access to reports in Operations Manager 2007 step-by-step.</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/62264/Default.aspx" length="1301" type="application/pdf"></enclosure>
			<pubDate>Thu, 01 Apr 2010 18:42:48 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/62264/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How to run a pre- and post-backup scripts with Microsoft System Center Data Protection Manager (DPM) 2007]]></title>
			<link><![CDATA[http://owsug.ca/blogs/islamgomaa/archive/2010/03/30/How-to-run-a-pre_2D00_-and-post_2D00_backup-scripts-with-Microsoft-System-Center-Data-Protection-Manager-_2800_DPM_2900_-2007.aspx]]></link>
			<description><![CDATA[<p>Today someone asked me does DPM can run a pre and Post backup jobs? , my answer  was NO because it is not straight forward from the GUI , but you can edit the <strong>ScriptingConfig.xml</strong> located in the protected server at <em>install path</em>\Microsoft Data Protection Manager\DPM\Scripting</p>
<p> </p>
<p>When DPM runs a protection job, ScriptingConfig.xml on the protected computer is checked. If a pre-backup script is specified, DPM runs the script and then completes the job. If a post-backup script is specified, DPM completes the job and then runs the script.</p>
<p>when I Say Protection Job that include “replica creation, express full backup, synchronization, and consistency check.”</p>
<p>This is the raw file in the Protected Server:</p>
<p><?xml version="1.0" encoding="utf-8"?> <ScriptConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://schemas.microsoft.com/2003/dls/ScriptingConfig.xsd">   </p>
<p><DatasourceScriptConfig DataSourceName="<em>Data source</em>">    </p>
<p><PreBackupScript<em>>”Path\Script Parameters</em>”  </PreBackupScript>    </p>
<p><PostBackupScript>"<em>Path\Script Parameters</em>” </PostBackupScript>     </p>
<p><TimeOut><em>30</em></TimeOut>   </p>
<p></DatasourceScriptConfig></p>
<p></ScriptConfiguration></p>
<p>in this example I am deleting  some files using the  “PreBackup.cmd" batch file prior to the backup job</p>
<p>protection the F: drive.</p>
<p><br />
 </p>
<p>example :</p>
<p><?xml version="1.0" encoding="utf-8"?> <br />
<ScriptConfiguration xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance""><font color="#b9b5c7">http://www.w3.org/2001/XMLSchema-instance"</font></a> xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema""><font color="#b9b5c7">http://www.w3.org/2001/XMLSchema"</font></a></p>
<p>xmlns="<a href="http://schemas.microsoft.com/2003/dls/ScriptingConfig.xsd""><font color="#b9b5c7">http://schemas.microsoft.com/2003/dls/ScriptingConfig.xsd"</font></a>></p>
<p>  <DatasourceScriptConfig DataSourceName="F:">  <br />
       <PreBackupScript> <br />
           "F:\PreBackup.cmd" <br />
       </PreBackupScript> <br />
<PreBackupCommandLine /></p>
<p><PostBackupScript/></p>
<p>  <TimeOut>90</TimeOut> <br />
  </DatasourceScriptConfig> <br />
</ScriptConfiguration></p>
<p> </p>
<p>For each data source, complete the DatasourceScriptConfig element as follows:</p>
<ol>
    <li>For the DataSourceName attribute, enter the data source volume (for file data sources) or name (for all other data sources). The data source name for application data should be in the form of <em>Instance\Database</em> for SQL, <em>Storage group name</em> for Exchange, <em>Logical Path\Component Name</em> for Virtual Server, and <em>SharePoint Farm\SQL Server Name\SQL Instance Name\SharePoint Config DB</em> for Windows SharePoint Services.</li>
    <li>In the PreBackupScript tag, enter the path and script name.</li>
    <li>In the PreBackupCommandLine tag, enter command-line parameters to be passed to the scripts, separated by spaces.</li>
    <li>In the PostBackupScript tag, enter the path and script name.</li>
    <li>In the PostBackupCommandLine tag, enter command-line parameters to be passed to the scripts, separated by spaces.</li>
    <li>In the TimeOut tag, enter the amount of time in minutes that DPM should wait after invoking a script before timing out and marking the script as failed.</li>
</ol>
<p>Note:</p>
<p>The backup job will not happen and will generates the following error in the following cases :</p>
<p>The configuration of the pre-backup script or the post-backup script XML for Volume F:\ is incorrect. (ID 30193 Details: Internal error code: 0x809909F4).</p>
<p>The execution of the pre-backup script for Volume F:\ returned an error. (ID 30189 Details: Internal error code: 0x809909F0) .</p>
<p><em><strong>“now chubby will be happy again”</strong></em></p>
<p>Thanks</p>
<p> </p>
<p>ISlam @ IslamGomaa.com</p>]]></description>
			<pubDate>Wed, 31 Mar 2010 05:51:42 GMT</pubDate>
			<guid>http://owsug.ca/blogs/islamgomaa/archive/2010/03/30/How-to-run-a-pre_2D00_-and-post_2D00_backup-scripts-with-Microsoft-System-Center-Data-Protection-Manager-_2800_DPM_2900_-2007.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How to Inactivate all active alerts in DPM 2007 SP1 ]]></title>
			<link><![CDATA[http://owsug.ca/blogs/islamgomaa/archive/2010/03/18/How-to-Inactivates-all-active-alerts-in-DPM-2007-SP1.aspx]]></link>
			<description><![CDATA[<p> </p>
<p>param ( <br />
[string[]]$dpmserverlist = @() <br />
) <br />
#region traps <br />
trap [Exception] { <br />
    writelog $("TRAP: DPMinactivateAlert: $Error") <br />
    $Error >> $logfile <br />
    $log = Get-EventLog -List | Where-Object { $_.Log -eq "Application" } <br />
    $log.Source = "DPMinactiveAlert" <br />
    $log.WriteEntry("TRAP: DPMinactiveAlert: $error", [system.Diagnostics.EventLogEntryType]::Error,9911) <br />
    writelog $Error <br />
    $Error.Clear() <br />
    exit 1 <br />
} <br />
#endregion <br />
#region functions <br />
function writelog <br />
{ <br />
    #write to console and logfile, pre-able with date time <br />
    param([array]$msg) <br />
    $dt = (Get-Date).ToString("MM/dd/yy HH:ss") <br />
    "$dt :: " >> $logfile <br />
    if ($debug) {Write-Host "$dt :: " -NoNewline} <br />
    for ($i = 0;$i -lt $msg.count;$i++) { <br />
        if ($debug) {Write-Host $msg[$i]} <br />
        $msg[$i] >> $logfile <br />
    } <br />
}</p>
<p>function LoadDPMsnapin { <br />
    #load PS snap-in if not already <br />
    param () <br />
    if (Get-PSSnapin | ?{$_.name -like "Microsoft.DataProtectionManager.PowerShell"}) { <br />
    } <br />
    else { <br />
        Add-PSSnapin -name Microsoft.DataProtectionManager.PowerShell <br />
    } <br />
} <br />
#endregion</p>
<p>#START <br />
$debug = $true <br />
$Error.clear() <br />
$version = "v1.1" <br />
[datetime]$now = Get-Date <br />
$format = "HH:mm:ss" <br />
LoadDPMsnapin <br />
$logfile = "{0}\DPMinactiveAlert.LOG" -f , (get-location) <br />
writelog "DPMinactivateAlert $version`n log output is written to $logfile`n`n" <br />
$srv = Connect-DPMServer $env:computername <br />
$alctl = $srv.AlertController <br />
$alctl.RefreshAlerts() <br />
Writelog ("Inactivating {0} alerts" -f $alctl.ActiveAlerts.Count ) <br />
#Don't log, alerts go to inactive and are still accessible <br />
#could filter on $a.ErrorInfo.RecommendedAction to be "None" <br />
if ($srv.GetProductInformation().version.major -gt 2 ){ <br />
    foreach ($a in $alctl.ActiveAlerts.Values) {$a.ResolveAlert()} <br />
} <br />
else { <br />
    foreach ($a in $alctl.ActiveAlerts) {$a.ResolveAlert()} <br />
} <br />
writelog "Done inactivating alerts!"</p>]]></description>
			<pubDate>Mon, 29 Mar 2010 13:01:02 GMT</pubDate>
			<guid>http://owsug.ca/blogs/islamgomaa/archive/2010/03/18/How-to-Inactivates-all-active-alerts-in-DPM-2007-SP1.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: DPM 2007 - iSCSI Dynamic Disks on Windows Server 2003 ]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/61616/Default.aspx]]></link>
			<description><![CDATA[<p>DPM 2007 supports the use of iSCSI dynamic disks on Windows Server 2003, however, it isn't quite as straight forward as it is in Windows Server 2008.  </p>
<p>In Windows Server 2008 you can add your iSCSI disks to the DPM server, make them dynamic and then add the disk into the DPM storage pool and you're done.  </p>
<p>In Windows Server 2003 you follow the same steps but when rebooted the server, you'll notice that all your iSCSI disks are offline.  The disks can be brought back online manually in disk management but this is not really a practical solution, the disks can also be brought online by opening the DPM console on the server, but again this solution is equally impractical.</p>
<p>To resolve the problem, change the start up type of the DPM service to Automatic.  By doing this, your iSCSI dynamic disks will be brought online automatically after reboot.</p>
<p>One final point thought though, if you are deploying DPM please consider using Windows Server 2008 x64 as the base Operating System as not only will you have better performance but you'll also be fully prepared to upgrade to DPM 2010 next year.  DPM 2010 will only be supported on Windows Server 2008 x64 so to avoid any upgrades, rebuilds and all the associated problems that cam with upgrading and rebuilding, use Server 2008 x64 if you can !</p>
<p>If you are a Small Medium Business looking for a non expensive backup storage solution, I recommend QNAP Appliance  specially TS-809U-RP Turbo NAS it support up to 8 disk 2 TB each and provide Total Throughput 114.9 MB/sec  on Read and 103.1 on Write.</p>
<p> </p>]]></description>
			<pubDate>Mon, 29 Mar 2010 03:57:19 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/61616/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Operations Manager 2007 Scenarios for Service Providers]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/60925/Default.aspx]]></link>
			<description><![CDATA[<p>Operations Manager 2007 introduces a number of key features for supporting large scale,multi tenant environments, with the two main features being the Gateway Server Role for adding smaller un-managed customer environments to an existing Service Provider Management Group and the Connected Management Group Scenario for multi-tiering existing customer Management Groups to a Service Provider Management Group.</p>
<p><b>Gateway Server Role Scenario</b></p>
<p>The Gateway Server role allows the Discovery Wizard in Operations Manager to discover target computers in workgroups, across one-way trusted and untrusted domains, and provides communication between the target computer and the Management Server. The security requirements of Operations Manager 2007 also bring PKI into a prominent role in many environments where it is has previously been underutilised or non-existent. </p>
<p>There are two primary goals for the gateway server:</p>
<p>1. Minimize the number of points of traffic between two secured environments, (for example, a Customer and Service Provider network)</p>
<p>2. Maximize the use of Kerberos based authentication when it is available, because the TCO associated with Kerberos is lower than with certificates.</p>
<p>Operations Manager introduces a more secure communication model than in its previous versions in that mutual authentication is now required by default between an agent and a management server, as well as between Gateway Servers and Management Servers. </p>
<p>Mutual authentication can be achieved via Kerberos in trusted scenarios where all machines are in the same Active Directory domain or in a domain with a two-way trust relationship. However, in cases where machines outside the trusted environment must be monitored, Kerberos authentication is not possible. In these cases, Operations Manager 2007 can utilize x.509 certificates for mutual authentication in a variety of scenarios. Certificates can be deployed to any Windows operating system that supports an Operations Manager 2007 agent.</p>
<p>The Gateway facilitates communication between the target agent-managed computers and a Management Server, easing management in un-trusted and distributed environments. It may be easiest to think of a Gateway as a management server that simply relays information received from agents to another management server. In real terms a gateway is effectively a management server without direct database access. When you approve a gateway, it appears as a management server in the Operations Console. </p>
<p>To ensure high availability, the Gateway Server on the customer site can be implemented with a secondary gateway to allow agents to failover in the event of the primary gateway becoming un-available also a gateway can be configured for failover to both a primary and secondary management server on the service provider side, allowing Gateway communication to continue in the event of a Management Server failure. The Gateway Server also does not require membership in an Active Directory domain, so it is perfect for the typical service provider scenario where quite often a customer site is separated from the Service Provider by some kind of security boundary. Alternatively, agent-managed computers can be configured to communicate directly to a management server while authenticating via certificates, this is suitable where you have a very small number of agents or where implementation of a Gateway Server is not possible.</p>
<p>Common Deployment Scenario for Multi Tenant Environments.</p>
<p>Gateway with Agent-managed Member Servers</p>
<p>In this scenario, monitoring of a remote, un-trusted AD domain is desired. All servers desired for management in the remote domain are members of the same AD domain as the Gateway Server. There is no trust relationship between the two domains. In this scenario, certificate authentication will be required only between the management server and gateway server, as no trust relationship exists. Agent-managed computers in the remote AD domain will be authenticated via Kerberos for communication with the Gateway Server. Thus, certificates must be secured for both the Management Server and Gateway Server in the remote domain.</p>
<p><img height="222" width="606" src="http://www.inframon.com/sp_opsmgr/gateway1.jpg" alt="Gateway Serevr Scenario 1" /></p>
<p>Gateway with Agent-managed Workgroup Servers</p>
<p>In this scenario, monitoring of a remote, un-trusted AD domain is desired. Some servers desired for management by the Gateway Server are members of a workgroup. In this scenario, certificate authentication will be required not only between the management server and gateway server, but also between the Gateway Server and agent-managed computers. </p>
<p><img height="223" width="606" src="http://www.inframon.com/sp_opsmgr/gateway2.jpg" alt="Gateway Scenario 2" /></p>
<p>Agent-managed Workgroup Servers - Gateway in Workgroup</p>
<p>In this scenario, monitoring of a remote, DMZ or workgroup environment is desired. An additional requirement to minimize the number of points of communication between the isolated environment and the Management Server exists, making deployment of a Gateway Server an appropriate choice. In this scenario, certificate authentication will be required not only between the management server and gateway server, but also between the Gateway Server and agent-managed computers.<b> </b></p>
<p><img height="222" width="606" src="http://www.inframon.com/sp_opsmgr/gateway3.jpg" alt="Gateway Scenario 3" /></p>
<p>While there is no programmed limit for the number of agents that can be managed within a single Management Group, information from live environments has established certain limits. Performance has been shown to degrade beyond 6,000 agents, so you should always plan for one Management Group for every 6,000 agents.</p>
<p>The official supported limit for the number of agents that can communicate to a gateway server is 1,500.<b> </b></p>
<p><b>Connected Management Groups Scenario</b></p>
<p>This deployment scenario is comprised of multiple management groups, each of which can be of the single or multiple server configurations type. This deployment scenario is exceptionally flexible and is mostly used to provide monitoring, alerting, and reporting services in complex environments.</p>
<p>This is extremely useful in the service provider scenario as it allows the connection to multiple instances of a Management Group that may exist on customer sites providing a "single pane of glass" for viewing critical alert data.</p>
<p><img height="736" width="554" src="http://www.inframon.com/sp_opsmgr/multiserver.jpg" alt="OpsMgr Multi-tenancy " /></p>
<p>Connecting management groups offers these additional services:</p>
<ul>
<li>Consolidated monitoring and alerting for greater than 6,000 agents</li>
<li>Consolidated monitoring across trust boundaries</li>
</ul>
<p>Operations Manager 2007 Server Roles</p>
<p>This configuration supports all Operations Manager server roles and makes use of the Operations Manager Connector Framework to enable bidirectional communication between the connected groups and local groups.</p>
<p>Common Uses</p>
<p>This deployment scenario can be used when the service provider requirement is to link to a complete Operations Manager Management Group on a customer site to allow a consolidated view of all monitored activity and consolidated management of that data.</p>
<p>There is no official limit on the number of Management Groups that you can connect to in this scenario.</p>
<p><b>High Level Architecture for Mixed Multi-Tenant Environment</b></p>
<p>In the case of many large service providers quite often the environment would be a mix of both connected and non-connected management groups, therefore a tiered architecture would be suitable.</p>
<p>This may consist of a master Management Group (or Local Management Group) which would host a roll up of alerts from all connected management groups and second management group which would be the collection point for all data from non-connected Management Groups.</p>
<p>Data Warehouse collection at the Master Management Group level would consist of purely Alert and Discovery Data and this would be the primary connection point for other Management Tools or any Ticketing System, this would also provide a high-level, global data collection point for customer facing scorecarding and reporting.</p>
<p>Any customer owned Management Groups would connect directly to this tier via the Microsoft Connector Framework (MCF), with performance and inventory data being collected locally on their sites. </p>
<p>A Second Management Group would be implemented as a connection point for any non-Management Group sites which would have local Gateway Servers for relaying data from local agents, this Management Group would also be connected to the Master Management Group via the MCF. This second tier would have Data Warehouse Collection Capabilities for Performance Metrics and Inventory Data and would provide a second data collection point for customer facing scorecarding and reporting.</p>
<p> The following diagram shows an example of how this architecture may look:</p>
<p><img height="588" width="916" src="http://www.inframon.com/sp_opsmgr/multimaster.jpg" alt="OpsMgr multi master" /></p>
<p><b>Connecting to other Management or Helpdesk Ticketing Systems</b></p>
<p>The Operations Manager 2007 R2 release saw the introductions of a number of free Interoperability connectors, these include HP Openview, Tivoli TEC, Remedy Helpdesk and a universal connector.</p>
<p>With the recent acquisition of Opalis Integration Center by Microsoft a number of other connection options have been added to the product such as Omnibus Netcool and HP Service Center.</p>
<p>Microsoft also has a close collaboration with EMC around the SMARTS network management toolset, which includes the purchase of some of the EMC SMARTS IP for addition to the next version of the product.  This collaboration has led to a recent release of a a bidirectional adapter package from Microsoft called the EMC Smarts Connector for Microsoft System Center Operations Manager 2007. The adapter will let Operations Manager users view Smarts topology and root-cause reports using their own interfaces. Smarts will also be able to suck in data from Operations Manager.</p>
<p>Operations Manager also comes with an extensive SNMP Trap collection feature allowing you to receive traps from any SNMP enabled system as well as being able to probe other systems ( via SNMP) for information.</p>
<p><b>Management Escalation</b></p>
<p>Operations Manager 2007 has a very extensive and flexible subscription based notification system which supports output to SMTP enabled mail systems, Microsoft Office or Live Communication Server (for delivery of messages to Office Communicator clients), GSM for SMS Text Messaging integration via a suitable GSM enabled device, as well as any command line supported medium.</p>
<p>This subscription mechanism supports a very granular and targeted alert stream, allowing you to alert down to a single object or alert over a variety of parameters (such as time raised, severity, business priority etc.). </p>
<p>Operations Manager also supports Alert Ageing which allows you to put a time expiry on un-answered alerts meaning that you can escalate them to higher tiers of Management or too other Operators.</p>
<p><b>Hardware Support for All Platforms</b></p>
<p>Microsoft has full support for Operations manager 2007 from most of the large Hardware Vendors such as HP, Dell, Fujitsu Siemens and IBM. Each of these vendors provide a full Operations Manager 2007 management Pack which typically integrates with the local hardware agent and contains Vendor specific knowledge in alerts generated.</p>
<p><b>Role based administration </b></p>
<p>Operations Manager 2007 can monitor many different types of applications in the enterprise and these applications can be administered by multiple teams. As the Operations Manager administrator, you can limit access to each team so they access only their monitoring data. Role-based security allows you to grant access to monitoring data, tools, and actions on a team-by-team basis.</p>
<p>Except for the Administrator role, you can add Active Directory security groups or individual accounts to any of these predefined roles. You can add Active Directory security groups only to the Administrator role.</p>
<p>Adding users or groups to a role mean that those individuals will be able to exercise the given role privileges across the scoped objects (including any inherited objects).</p>
<p>Operations Manager also allows you to create custom roles based on the Operator, Read-Only Operator, Author, and Advanced Operator profiles. When you create the role, you can further narrow the scope of groups, tasks, and views that the role can access. For example, you can create a role entitled "Exchange Operator" and narrow the scope to only Exchange-related groups, views, and tasks. User accounts assigned to this role will only be able to run Operator-level actions on Exchange-related objects.<b></b></p>
<p><b>Measuring and Displaying Customer Service Levels </b></p>
<p>One of the most challenging aspects of providing a managed service to a customer is being able to visualise the value of the service you are providing back to the customer in a format that can be consumed and understood by  any level of the business.</p>
<p>Operations Manager 2007 delivers the ability to define an IT service (or distributed application) by selecting the components that together deliver that IT service, along with their inter-relationships. For example, a web service may comprise of the web server, application pools, a database, and the servers that each are hosted on.  By monitoring a defined number of characteristics of each of those components, Operations Manager is able to determine both the health and performance of each component through 3 states:</p>
<ul>
<li>Healthy, indicating that the component being monitored is operating within expected parameters.</li>
<li>Warning, indicating a performance or health threshold has been exceeded, and that while the component is operating, attention is required to prevent service disruption or restore performance.</li>
<li>Critical, indicating that the component being monitored has entered an unhealthy state that requires immediate attention, and that the availability and performance of that component are compromised.</li>
</ul>
<p>This feature is one of the most powerful features of Operations Manager as it gives the ability to be able to group together all of the components that make up a service and in the event of an outage very quick root cause analysis of the source of an outage of performance problem can be identified by simply clicking on a problem path button.</p>
<p>This is also extremely useful to the service provider as it gives him the ability provide metrics back to the customer on the core services that he is being paid to manage through Operations Manager 2007 R2's in built Service Level Reporting capability.</p>
<p>The Service Level Reporting capability in Operations Manager 2007 R2 (also called "service level objectives" or SLOs) leverages this same functionality maintained in the Distributed Application concept to determine both availability and performance metrics for monitored IT services. It does this by calculating the overall time that the components that comprise that IT service remain in a particular state to arrive at the following metrics:</p>
<ul>
<li>Availability, calculated as the time the components that comprise the service are in a healthy or warming state. Only a critical state counts against the availability metric, since even if it is in a warning state the IT service is seen as being accessible by end users, (e.g., a web service may take a long time to respond, but it does eventually deliver a web page).</li>
<li>Performance, calculated as the time the components that comprise the IT services are in a healthy state. Both warning and critical states count against the performance metric, (e.g., if a database transaction is expected to complete in less than 300ms, and the actual transaction takes 2 seconds, then this will be seen as a performance impact).</li>
</ul>
<p>Once you have defined your Distributed Applications and Service Level Objectives you can use the in-built Service Level Report to display the results or can display the data in a much more effective format using the Service Level Dashboard.</p>
<p>The Service Level Dashboard for Operations Manager R2 is a free download from the Microsoft Solution Accelerator team which is an application built on Windows SharePoint Services 3.0. It is designed to work with an existing Operations Manager 2007 R2 infrastructure configured to monitor business-critical applications. The dashboard evaluates an application or group over a time period that the administrator selects during setup, determines whether it met the defined service level commitment, and displays summarized data about the service levels.</p>
<p>In Operations Manager 2007 R2, you define your service goals. The Service Level Dashboard evaluates each SLO over the defined dashboard time period and determines if it met the goal during that period. The dashboard displays each SLO and identifies its states, based on defined service level targets. </p>
<p>The following diagram illustrates, at a high-level, the process flow that occurs within the Service Level Dashboard environment:</p>
<p><img height="553" width="486" src="http://www.inframon.com/sp_opsmgr/sld.jpg" alt="OpsMgr SLD Setup" /></p>
<p>The Service Level Dashboard integrates with the Operations Manager Data Warehouse database and displays service level metrics on the Windows SharePoint Services interface. All the customized and personalized data associated with the Web Parts of the Service Level Dashboard is stored in the Windows SharePoint Services Content database.</p>
<p>The dashboard can summarize the current status and health of all defined SLOs against an application or group of objects. Key measures used to evaluate various aspects of the health of defined SLOs include such information as service level metrics, mean time to repair (MTTR), mean time between failures (MTBF), and service level trends.</p>
<p>As this Dashboard can be used in SharePoint or WSS, it can easily be imported into a public facing portal for on-line consumption by the customer.</p>
<p><b>Custom SLA Scorecarding</b></p>
<p>As the needs of the Service Provider often varies from some of the functionality that is provided from Operations Managers "out-of-the-box" availability and SLA Reporting, there is often a need to publish key data collected from Operations Manager in executive level dashboards and scorecards to give customers a "10,000" feet view of their environment so they understand the value the service provider is bringing in managing their infrastructure also key performance metrics can be presented allowing IT stakeholders within those businesses to make key decisions without the complication of having to run their own reporting infrastructure.</p>
<p>This extra level of reporting can easily be provided through extending Operations Managers reporting capability to utilise some of the new, native SQL 2008 reporting capabilities.</p>
<p>By using some of the new reporting controls now in SQL 2008, very effective, customer ready scorecards can be created which can easily be tied to an individual customer by using a combination of </p>
<p>Gordon McKenna - System Center Operations Manager MVP</p>
<p>Technical References:</p>
<p>Gateway Server and Certifcate-based Authorization Scenarios in Operations Manager 2007: <a href="http://www.systemcentercentral.com/Downloads/DownloadsDetails/tabid/144/IndexID/7885/Default.aspx">http://www.systemcentercentral.com/Downloads/DownloadsDetails/tabid/144/IndexID/7885/Default.aspx</a> </p>
<p>Tracking Service Levels with Operations Manager 2007 R2: <a href="http://download.microsoft.com/download/9/B/4/9B4829DC-55A5-46E7-9C9A-91B49EBB6320/SC_OpsMgr2007_R2-ServiceLevelMonitoring.pdf">http://download.microsoft.com/download/9/B/4/9B4829DC-55A5-46E7-9C9A-91B49EBB6320/SC_OpsMgr2007_R2-ServiceLevelMonitoring.pdf</a> </p>
<p>Service Level Dashboard for System Center Operations Manager 2007: <a href="http://technet.microsoft.com/en-us/library/dd630553.aspx">http://technet.microsoft.com/en-us/library/dd630553.aspx</a> </p>
<p> </p>]]></description>
			<pubDate>Wed, 17 Mar 2010 20:49:01 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/60925/Default.aspx</guid>
		</item>
	</channel>
</rss>
