<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
	<title><![CDATA[Articles]]></title>
	<link><![CDATA[http://www.systemcentercentral.com/Articles/tabid/61/rss/1/tag/Articles%20Operations_Manager/Default.aspx]]></link>
	<description></description>
	<language>en-us</language>
	<copyright><![CDATA[Copyright 2009 System Center Central All Rights Reserved.]]></copyright>
	<lastBuildDate>Sat, 04 Sep 2010 07:16:11 GMT</lastBuildDate>
		<item>
			<title><![CDATA[Articles: MONITRING DMZ AND WORKGROUP COMPUTER WITH SCOM 2007 R2 USING CERTIFICATES (ERRORS 21007 AND 21016 AFTER APPROVING THE AGENT IN PENNDING MANGMENT) ]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/77779/Default.aspx]]></link>
			<description><![CDATA[<p>a new guide to help you monitor servers in your dmz or a workgroup with system center operation manger</p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3">By shahar nusbaum<span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></font></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Well there might be a few guides like this around the web and I have used most of them,</font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3"><font face="Calibri">But for the past 3 mounts I have been battling with this scenario where the agent would stay in "not monitor" state after been approved in the pending management pane and the agent had 21007 and 21016 events on the operations manger event log on the workgroup / dmz server <span style="mso-spacerun: yes"> </span>I wanted to monitor</font><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">. <o:p></o:p></span></font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3"><font face="Calibri">If you have a working gateway and after your approve the agents in pending mode and used to momcertimport with successful results and you <b><u>still</u></b> receive event id's like21007 and 21016 on the workgroup / DMZ agent this guide is for you.<span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></font></font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Well my solution is available for you here</font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Well first of all and very basic (but not for me) I have 2003 enterprise ca server so I used this guide to create my </font><span style="line-height: 115%; font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">certificate</span><font size="3" face="Calibri"> template</font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><span style="line-height: 115%; font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">To create a certificate template</span><font size="3" face="Calibri"> - </font><a href="http://technet.microsoft.com/en-us/library/bb735413.aspx"><font size="3" face="Calibri">http://technet.microsoft.com/en-us/library/bb735413.aspx</font></a></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">I flowed that guide to the letter and still those event id's and no communication to my gateway.</font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3"><span style="mso-spacerun: yes"> </span>Something was missing,<span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></font></font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3">The first change I noticed was that I now I had no option to save a certificate to local computer certificate store this of course is because of the server 2008 enrolment<span style="mso-spacerun: yes">  </span>pages that would need administrator right witch the internet explorer does not use<span style="mso-spacerun: yes">   </span><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></font></font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><span style="mso-no-proof: yes"><v:shapetype id="_x0000_t75" stroked="f" filled="f" path="m@4@5l@4@11@9@11@9@5xe" o:preferrelative="t" o:spt="75" coordsize="21600,21600"><v:stroke joinstyle="miter"></v:stroke><v:formulas><v:f eqn="if lineDrawn pixelLineWidth 0"></v:f><v:f eqn="sum @0 1 0"></v:f><v:f eqn="sum 0 0 @1"></v:f><v:f eqn="prod @2 1 2"></v:f><v:f eqn="prod @3 21600 pixelWidth"></v:f><v:f eqn="prod @3 21600 pixelHeight"></v:f><v:f eqn="sum @0 0 1"></v:f><v:f eqn="prod @6 1 2"></v:f><v:f eqn="prod @7 21600 pixelWidth"></v:f><v:f eqn="sum @8 21600 0"></v:f><v:f eqn="prod @7 21600 pixelHeight"></v:f><v:f eqn="sum @10 21600 0"></v:f></v:formulas><v:path o:connecttype="rect" gradientshapeok="t" o:extrusionok="f"></v:path><o:lock aspectratio="t" v:ext="edit"></o:lock></v:shapetype><v:shape id="_x0000_i1030" type="#_x0000_t75" style="width: 414.75pt; height: 349.5pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image001.png"></v:imagedata></v:shape></span><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">So in order to export the certificate to a file I had to use internet explorer </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3">There under tools -> internet options -> content<span style="mso-spacerun: yes">  </span></font></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">There is a certificates section. </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Click the certificate button and you can export your certificate from there </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Remember to export the private key after clicking the next batten leave this mark </font></p>
<p dir="ltr" class="MsoNormal" style="text-align: left; margin: 0cm 0cm 10pt; unicode-bidi: embed; direction: ltr"><span style="mso-no-proof: yes"><v:shape id="תמונה_x0020_2" type="#_x0000_t75" o:spid="_x0000_i1029" style="width: 367.5pt; height: 117.75pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image003.png"></v:imagedata></v:shape></span></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><font face="Calibri"><font size="3">Don’t mark include all certificates it the certification path if possible <o:p></o:p></font></font></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><font face="Calibri"><font size="3">The momcertimport tool will not be able to import the certificate <br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
<o:p></o:p></font></font></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><font size="3"><b><u>We will deal with the root ca needed in the workgroup / DMZ server in a minute</u></b><b><u><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p></o:p></span></u></b></font></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span dir="rtl" lang="HE" style="font-family: "Arial","sans-serif"; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi"><o:p><span style="text-decoration: none"><font size="3"> </font></span></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><o:p><span style="text-decoration: none"><font size="3" face="Calibri"> </font></span></o:p></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Then you can save your certificate to a pfx file and copy it to the server you want to monitor</font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">Keep it in a shared folder for the duration of the install process because you will need it for the gateway server as well as the workgroup / DMZ server.</font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><o:p><font size="3" face="Calibri"> </font></o:p></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">One more certificate is needed before we can continue and again I used this guide </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><a href="http://technet.microsoft.com/en-us/library/bb735413.aspx"><font size="3" face="Calibri">http://technet.microsoft.com/en-us/library/bb735413.aspx</font></a><font size="3"><font face="Calibri"><span style="mso-spacerun: yes">  </span>I used the section called "<b><u>To</u></b></font></font><b><u><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt"> download the Trusted Root (CA) certificate"<br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
<o:p></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">Notice that you might not be able to get to the web site of your ca server form the workgroup computer so you can do that from your root management server and just save it in the folder were you saved your ca for the </span><font size="3" face="Calibri">workgroup / DMZ server</font><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt"> you wanted to monitor<o:p></o:p></span></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt"><o:p> </o:p></span></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">And on one last note before we begin: </span></u></b><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 9pt">while most guide say the certificate subject a.k.a the name filed </span><font size="3" face="Calibri">is fqdn don’t just push your domain name in the computer name. <br />
cheek before logon to the workgroup / DMZ server<span style="mso-spacerun: yes">  </span>and Go to start -> computer -> properties – check the full computer name and copy the exact name to your gateway host file if no dns resolution is available</font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><o:p><font size="3" face="Calibri"> </font></o:p></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font size="3" face="Calibri">NOW FOR THE STEP BY STEP GUIDE </font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><o:p><font size="3" face="Calibri"> </font></o:p></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr; mso-list: l0 level1 lfo1"><strong><span style="font-family: "Calibri","sans-serif"; font-size: 16pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore">1.<span style="font: 7pt "Times New Roman"">    </span></span></span></strong><b><u><span style="font-size: 12pt"><font face="Calibri">PREPERING TO INSTALL<span style="mso-spacerun: yes">  </span>THE AGENT ON THE WORKGROUP MECHINE</font></span></u></b><font face="Calibri"><b><span style="font-size: 12pt"><span style="mso-spacerun: yes">  </span><br />
</span></b><br />
<font size="3"><u><span style="mso-spacerun: yes"> </span>I recommend<span style="mso-spacerun: yes">  </span>you copy this folders<span style="mso-spacerun: yes">  </span>form your scom CD</u><span style="mso-spacerun: yes">  </span>to one folder you can move around in your environment, let's call that our "scomdmz" inside you will need this folders <br />
* SupportTools<br />
* agent<br />
<u>I recommend<span style="mso-spacerun: yes">  </span>you copy this files to that same folder</u><br />
* server_cert.pfx (certificate you created using a template for your workgroup / DMZ server)<br />
<br />
* </font></font><font size="3"><strong><span style="font-family: "Calibri","sans-serif"; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin">CA_certificate_chain.p7b (for the trusted Root (CA) certificate)<br />
move this file to your workgroup machine<span style="mso-spacerun: yes">  </span>(keep a copy of your </span></strong><font face="Calibri">server_cert.pfx</font></font><font size="3"><strong><span style="font-family: "Calibri","sans-serif"; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin"> to copy to your gateway server later<span style="mso-spacerun: yes">  </span>)<br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
</span></strong><strong><span style="font-family: "Calibri","sans-serif"; font-size: 16pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin"><o:p></o:p></span></strong></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr; mso-list: l0 level1 lfo1"><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face="Calibri">2.</font><span style="font: 7pt "Times New Roman"">     </span></span></span></b><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">INSTALLING THE AGENT ON THE WORKGROUP MECHINE<br />
<br />
</font></span></u></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">run the msi installation on your server<span style="mso-spacerun: yes">  </span>if there is no dns resolution for your gateway server ping –a the ip address to see if you get the name of your gateway server, <span style="mso-spacerun: yes"> </span>if not you will need to add your gateway server fqdn name to your host file – it's in c:\windows\system32\drivers\etc <br />
</font><span style="mso-no-proof: yes"><v:shape id="תמונה_x0020_1" type="#_x0000_t75" o:spid="_x0000_i1028" style="width: 369.75pt; height: 198pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image005.png"></v:imagedata></v:shape></span><br />
<br />
<font face="Calibri">(we use the example in our org…)<br />
<br />
I KNOW THIS IS A VERY BASIC STUFF RIGHT HERE – I want this guide to be able to apply even to those who don’t deal with this in a daily manner<br />
<br />
<span style="mso-spacerun: yes"> </span>now this to prevent any <b><u>human typing Mistake</u></b></font></span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> </font></span></u></b><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">write the fqdn gateway server in the host file copy & paste it to the management computer name I recommend also copy & paste to command line and telnet the computer name to your gateway on 5723 to check connectivity. <br />
Click next your almost home free…<br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
</span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o:p></o:p></span></u></b></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr; mso-list: l0 level1 lfo1"><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face="Calibri">3.</font><span style="font: 7pt "Times New Roman"">     </span></span></span></b><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">IMPORTING THE CERTIFICATES TO YOUR GATEWAY AND SERVER <br />
<br />
</font></span></u></b><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">THIS WILL BE SPLIT IN TO TWO PARTS <br />
<br />
<b><u>A.<span style="mso-spacerun: yes">  </span>IMPORTING THE CERTIFICATES ON YOUR DMZ SERVER YOU WANT TO MONITOR - </u></b><span style="mso-spacerun: yes"> </span><br />
<br />
<b><u><span style="mso-spacerun: yes"> </span>using the momcertimport tool <span style="mso-spacerun: yes"> </span></u></b><span style="mso-spacerun: yes"> </span><br />
-on the </span><font size="3">workgroup / DMZ server</font></font><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> go to start -> if 2008 type cmd if 2003 go to run type cmd<br />
<b><u>one thing very imported cheek</u></b> -<span style="mso-spacerun: yes">  </span>if you're on server 2008 check to see if your command prompt run with administrator rights (if not right click the icon before you press enter and<span style="mso-spacerun: yes">  </span>run it as administrator)<br />
</font><span style="mso-no-proof: yes"><v:shape id="תמונה_x0020_3" type="#_x0000_t75" o:spid="_x0000_i1027" style="width: 415.5pt; height: 57.75pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image007.png"></v:imagedata></v:shape></span><br />
<br />
<br />
<font face="Calibri">the tool is in the </font></span><font size="3" face="Calibri">SupportTools folder (the one we copied earlier if you flowed step one)</font><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> <br />
</font></span></u></b><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">so! The way to run this tool is simple get to it in the command prompt and the give the server certificate file like so <br />
c:\dmzfolder\</span><font size="3">SupportTools\i386\momcertimport <b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-spacerun: yes"> </span></span></b>server_cert.pfx type the password for the key and you will need to receive successfully<span style="mso-spacerun: yes">  </span>state message </font></font><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
</span></u></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
</span><font face="Calibri"><span style="font-size: 16pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">YOU GOT THIS FAR –</span><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"> you stop and started the health service like asked in the momcertimport tool after imported the certificate<span style="mso-spacerun: yes">  </span>and still receive those </span><font size="3">21007 and 21016 events<span style="mso-spacerun: yes">  </span>you will need to fallow this few steps</font></font><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
<br />
<span style="mso-spacerun: yes"><font face="Calibri"> </font></span><font face="Calibri"><u>What you need now is another certificate to be imported.<br />
</u><span style="mso-spacerun: yes">    </span>1.<span style="mso-tab-count: 1">     </span>Go to start mmc -> file -> add/remove snap-in…<br />
<span style="mso-spacerun: yes">    </span>2.<span style="mso-tab-count: 1">     </span>Add certificates add computer account, click next choose local<span style="mso-spacerun: yes">                                            </span>computer click ok and exit – it's all you need for the console<br />
<br />
<span style="mso-spacerun: yes">    </span>3. <span style="mso-tab-count: 1">    </span>Go to the </font></span><strong><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 8pt; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">Trusted Root Certification Authorities</span></strong><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> folder on the folder </font></span><strong><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 8pt; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">Certificates </span></strong><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">right click all tasks -> import… <br />
and import your </span><font size="3"><span style="mso-spacerun: yes"> </span><strong><span style="font-family: "Calibri","sans-serif"; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin">CA_certificate_chain.p7b</span></strong></font></font><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> we prepared in step 1 this guide<br />
and import it to the </font></span><strong><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 8pt; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">Trusted Root Certification Authorities</span></strong><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> folder <br />
the folder contains certificates that in most time already be in there <br />
but don’t skip this stage.<br />
<br />
</font></span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-no-proof: yes"><v:shape id="תמונה_x0020_5" type="#_x0000_t75" o:spid="_x0000_i1026" style="width: 405.75pt; height: 149.25pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image009.png"></v:imagedata></v:shape></span></u></b><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
<br />
</span></u></b><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">B. IMPORTING THE CERTIFICATES ON TO YOU GATEWAY SERVER –</font></span></u></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> again this is for all of you battling with<span style="mso-spacerun: yes">  </span>error id<span style="mso-spacerun: yes">  </span>21037 on your gateway (and of course any kind of lack of communication between the agent and your gateway server ) <br />
<br />
<span style="mso-spacerun: yes">    </span>1.<span style="mso-tab-count: 1">     </span>Go to start mmc -> file -> add/remove snap-in…<br />
<span style="mso-spacerun: yes">    </span>2.<span style="mso-tab-count: 1">     </span>Add certificates add computer account, click next choose local<span style="mso-spacerun: yes">                                            </span>computer click ok and exit – it's all you need for the console<br />
<span style="mso-spacerun: yes">    </span>3. Go to the </font></span><strong><span style="font-family: "Verdana","sans-serif"; color: black; font-size: 8pt; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi">Trusted Root Certification Authorities</span></strong><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri"> </font></span></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">and import your <br />
</font></span><font face="Calibri"><font size="3">server_cert.pfx we talked about in step one to that folder <br />
</font><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-spacerun: yes">   </span></span></b><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-spacerun: yes"> </span>3. Go to Personal folder and import it to that folder ass well </span></font><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
<span style="mso-no-proof: yes"><v:shape id="תמונה_x0020_6" type="#_x0000_t75" o:spid="_x0000_i1025" style="width: 359.25pt; height: 204pt; visibility: visible; mso-wrap-style: square"><v:imagedata o:title="" src="http://www.systemcentercentral.com/file:///C:/Users/Shaharn/AppData/Local/Temp/msohtmlclip1/01/clip_image011.png"></v:imagedata></v:shape></span><br />
<br />
<br />
</span></u></b><font face="Calibri"><b><u><span style="font-size: 16pt">note: we are importing the certificates of the server that we want to monitor into our</span></u></b><u><span style="font-size: 16pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"> <b>gateway</b><span style="mso-spacerun: yes">  </span><strong><span style="font-family: "Calibri","sans-serif"; color: black; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin">Trusted Root Certification Authorities and to the personal folder</span></strong></span></u></font><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br />
<br />
<br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
<o:p></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr; mso-list: l0 level1 lfo1"><b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face="Calibri">4.</font><span style="font: 7pt "Times New Roman"">     </span></span></span></b><b><u><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">CHEKING THE COUMNICATION -<br />
<br />
</font></span></u></b><font face="Calibri"><span style="font-size: 12pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">after all the certificates have been imported to<span style="mso-spacerun: yes">  </span>the gateway server and to our soon to be monitored server, in order for this changes to take affect well have to do the fallowing steps <br />
<br />
restart health service known as system center management on your gateway <br />
restart health service known as system center management on your<span style="mso-spacerun: yes">  </span>root management server<br />
restart health service known as system center management on your dmz server </span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o:p></o:p></span></u></b></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o:p><span style="text-decoration: none"><font face="Calibri"> </font></span></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o:p><span style="text-decoration: none"><font face="Calibri"> </font></span></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">Check your DMZ server event viewer to see if the error id repeats <o:p></o:p></font></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face="Calibri">Some changes take time you might want to wait 5-10 minutes after 10 <o:p></o:p></font></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><font face="Calibri"><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">Minutes you need restart the health service again on your DMZ server and cheek your event viewer for the id's if still receive restart the health service again on your root management server and your gateway server<br />
<br />
<br />
</span></u></b><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin">this is my solution and I would like to thank Yossi tali and </span><span style="font-size: 14pt">Gal Hutman<o:p></o:p></span></font></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt; unicode-bidi: embed; direction: ltr"><span style="font-size: 14pt"><font face="Calibri">For their help in finding this solution </font></span><b><u><span style="font-size: 14pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
<o:p></o:p></span></u></b></p>
<p dir="ltr" class="MsoNoSpacing" style="text-align: left; margin: 0cm 0cm 0pt 36pt; unicode-bidi: embed; direction: ltr"><br style="mso-special-character: line-break" />
<br style="mso-special-character: line-break" />
 </p>
<p> </p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/77779/Default.aspx" length="1301" type=""></enclosure>
			<pubDate>Thu, 19 Aug 2010 11:26:21 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/77779/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Monitoring DPM using OpsMgr, Cookdown & PowerShell ]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/77056/Default.aspx]]></link>
			<description><![CDATA[Monitor DPM data sources in Operations Manager R2 accurately and efficiently using PowerShell and cookdown.]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/77056/Default.aspx" length="40481" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Fri, 13 Aug 2010 15:05:00 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/77056/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Management Pack for IBM DB2]]></title>
			<link><![CDATA[http://www.nice.de/en/nice-products/nice-db2-management-pack-for-microsoft-scom]]></link>
			<description><![CDATA[<p>Efficiently monitor distributed IBM DB2 databases on Microsoft Windows from a central console.<br />
The NiCE DB2 Management Pack (NiCE DB2 MP) helps you increase RDBMS availability and performance and to lower the overall cost of maintaining your DB2 databases. It enables you to perform service-oriented management as well as incident management in your DB2 environment, supporting your business critical processes. <br />
To ensure always-on availability, the NiCE DB2 MP monitors key operational activities and events such as event logs and processes. Information from important system tables is collected to reflect DB2 activity.</p>
<p> </p>
<p>Free Evaluation Copies: https://portal.nice.de</p>]]></description>
			<enclosure url="http://www.nice.de/en/nice-products/nice-db2-management-pack-for-microsoft-scom" length="1301" type="application/pdf"></enclosure>
			<pubDate>Tue, 03 Aug 2010 11:21:52 GMT</pubDate>
			<guid>http://www.nice.de/en/nice-products/nice-db2-management-pack-for-microsoft-scom</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Full procedure on how to setup GSM Modem in SCOM on a VM Environment]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/72326/Default.aspx]]></link>
			<description><![CDATA[<p>Made by Sebastien Paquet, <br />
                                     I've never found any procedure on how to install the Scom paging system on a FULL Virtual environment (ESX).  Here is a great Step-by-step procedure that I have created for you ...  Click the Download buton!</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/72326/Default.aspx" length="1301" type=""></enclosure>
			<pubDate>Wed, 07 Jul 2010 14:40:08 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/72326/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Logon Process Monitoring for Citrix XenApp]]></title>
			<link><![CDATA[http://www.hermes-softlab.com/products/management_products/documents/white_paper/logon_process_monitoring_for_xenapp.pdf?utm_source=SCC&utm_medium=article&utm_term=Citrix&utm_content=static&utm_campaign=SCC]]></link>
			<description><![CDATA[<p>User logon is a complex and resource intensive process on a Citrix XenApp system. It is initiated when a XenApp farm load balancing algorithm selects the system where a published application or desktop, which a user has selected, will be started and ends when the application or desktop is running and the user is able to interact with it.<br />
<br />
There are a number of factors that have an impact on the logon process that can get further complicated if solutions that integrate into the logon process, such as User Workspace Management products, are used. All this is making the user logon process very hard to troubleshoot. Only a few of the best management tools can break down the logon process on a XenApp system into phases and measures their duration. Thus, troubleshooting the logon process is much easier, because you don't have to inspect the logon process as a whole; instead you concentrate only on the phase that is particularly slow.<br />
<br />
In <a href="http://www.hermes-softlab.com/products/management_products/documents/white_paper/logon_process_monitoring_for_xenapp.pdf?utm_source=SCC%2B&utm_medium=article%2BCitrix%20logon&utm_content=Citrix%2BXenApp&utm_campaign=SCC">the article</a>, you can find elements of each logon phase and possible reasons for their slow behavior: </p>
<ul>
    <li>Phase 1: User Profile Loading</li>
    <li>Phase 2: Applying Group Policy Objects (GPOs)</li>
    <li>Phase 3: User Environment Initialization and Active Setup</li>
    <li>Phase 4: Logon Script Execution.</li>
</ul>
<p><br />
Get more information in the article <a href="http://www.hermes-softlab.com/products/management_products/documents/white_paper/logon_process_monitoring_for_xenapp.pdf?utm_source=SCC%2B&utm_medium=article%2BCitrix%20logon&utm_content=Citrix%2BXenApp&utm_campaign=SCC">Logon Process Monitoring for Citrix XenApp</a> published on hermes.softlab.com.</p>]]></description>
			<pubDate>Thu, 06 May 2010 00:08:05 GMT</pubDate>
			<guid>http://www.hermes-softlab.com/products/management_products/documents/white_paper/logon_process_monitoring_for_xenapp.pdf?utm_source=SCC&amp;utm_medium=article&amp;utm_term=Citrix&amp;utm_content=static&amp;utm_campaign=SCC</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Exchange 2010 Override Example Walk through]]></title>
			<link><![CDATA[http://discussitnow.spaces.live.com/blog/cns!A4408C121568CAA4!6364.entry]]></link>
			<description><![CDATA[The Exchange 2010 has a suprise waiting for you.  It has a monitor that checks for the most recent updates to SCOM SP1 and R2.  If ANY agent in your environment is missing these updates, a medium priority critical alert will be generated.  The most recent SCOM MP already checks this on all agents and raises a medium priority warning.  In this guide I show you how to disable this monitor completely as well as how to create a over ride mp that will allow you to target this monitor to just Exchange 2010 servers.  Also the monitor in the Exchange 2010 is under the Availability parent monitor instead of configuration, where I really think it should be.]]></description>
			<pubDate>Fri, 28 May 2010 02:20:11 GMT</pubDate>
			<guid>http://discussitnow.spaces.live.com/blog/cns!A4408C121568CAA4!6364.entry</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Creating custom dynamic computer groups based on registry keys on agents]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/63399/Default.aspx]]></link>
			<description><![CDATA[<p>by Kevin Holman, this is a great step-by-step on how to create a custom attribute based on a registry value, then how to create a dynamic group based on that value. Bookmarking here as I refer people to it frequently.</p>
<p>Click the Download button and you'll be redirected to the source.</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/63399/Default.aspx" length="53429" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Fri, 09 Apr 2010 01:13:48 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/63399/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How to restrict access to reports in Operations Manager 2007]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/62264/Default.aspx]]></link>
			<description><![CDATA[<p>by Mike Betts, this article demonstrates how to restrict access to reports in Operations Manager 2007 step-by-step.</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/62264/Default.aspx" length="1301" type="application/pdf"></enclosure>
			<pubDate>Thu, 01 Apr 2010 18:42:48 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/62264/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Operations Manager 2007 Scenarios for Service Providers]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/60925/Default.aspx]]></link>
			<description><![CDATA[<p>Operations Manager 2007 introduces a number of key features for supporting large scale,multi tenant environments, with the two main features being the Gateway Server Role for adding smaller un-managed customer environments to an existing Service Provider Management Group and the Connected Management Group Scenario for multi-tiering existing customer Management Groups to a Service Provider Management Group.</p>
<p><b>Gateway Server Role Scenario</b></p>
<p>The Gateway Server role allows the Discovery Wizard in Operations Manager to discover target computers in workgroups, across one-way trusted and untrusted domains, and provides communication between the target computer and the Management Server. The security requirements of Operations Manager 2007 also bring PKI into a prominent role in many environments where it is has previously been underutilised or non-existent. </p>
<p>There are two primary goals for the gateway server:</p>
<p>1. Minimize the number of points of traffic between two secured environments, (for example, a Customer and Service Provider network)</p>
<p>2. Maximize the use of Kerberos based authentication when it is available, because the TCO associated with Kerberos is lower than with certificates.</p>
<p>Operations Manager introduces a more secure communication model than in its previous versions in that mutual authentication is now required by default between an agent and a management server, as well as between Gateway Servers and Management Servers. </p>
<p>Mutual authentication can be achieved via Kerberos in trusted scenarios where all machines are in the same Active Directory domain or in a domain with a two-way trust relationship. However, in cases where machines outside the trusted environment must be monitored, Kerberos authentication is not possible. In these cases, Operations Manager 2007 can utilize x.509 certificates for mutual authentication in a variety of scenarios. Certificates can be deployed to any Windows operating system that supports an Operations Manager 2007 agent.</p>
<p>The Gateway facilitates communication between the target agent-managed computers and a Management Server, easing management in un-trusted and distributed environments. It may be easiest to think of a Gateway as a management server that simply relays information received from agents to another management server. In real terms a gateway is effectively a management server without direct database access. When you approve a gateway, it appears as a management server in the Operations Console. </p>
<p>To ensure high availability, the Gateway Server on the customer site can be implemented with a secondary gateway to allow agents to failover in the event of the primary gateway becoming un-available also a gateway can be configured for failover to both a primary and secondary management server on the service provider side, allowing Gateway communication to continue in the event of a Management Server failure. The Gateway Server also does not require membership in an Active Directory domain, so it is perfect for the typical service provider scenario where quite often a customer site is separated from the Service Provider by some kind of security boundary. Alternatively, agent-managed computers can be configured to communicate directly to a management server while authenticating via certificates, this is suitable where you have a very small number of agents or where implementation of a Gateway Server is not possible.</p>
<p>Common Deployment Scenario for Multi Tenant Environments.</p>
<p>Gateway with Agent-managed Member Servers</p>
<p>In this scenario, monitoring of a remote, un-trusted AD domain is desired. All servers desired for management in the remote domain are members of the same AD domain as the Gateway Server. There is no trust relationship between the two domains. In this scenario, certificate authentication will be required only between the management server and gateway server, as no trust relationship exists. Agent-managed computers in the remote AD domain will be authenticated via Kerberos for communication with the Gateway Server. Thus, certificates must be secured for both the Management Server and Gateway Server in the remote domain.</p>
<p><img height="222" width="606" src="http://www.inframon.com/sp_opsmgr/gateway1.jpg" alt="Gateway Serevr Scenario 1" /></p>
<p>Gateway with Agent-managed Workgroup Servers</p>
<p>In this scenario, monitoring of a remote, un-trusted AD domain is desired. Some servers desired for management by the Gateway Server are members of a workgroup. In this scenario, certificate authentication will be required not only between the management server and gateway server, but also between the Gateway Server and agent-managed computers. </p>
<p><img height="223" width="606" src="http://www.inframon.com/sp_opsmgr/gateway2.jpg" alt="Gateway Scenario 2" /></p>
<p>Agent-managed Workgroup Servers - Gateway in Workgroup</p>
<p>In this scenario, monitoring of a remote, DMZ or workgroup environment is desired. An additional requirement to minimize the number of points of communication between the isolated environment and the Management Server exists, making deployment of a Gateway Server an appropriate choice. In this scenario, certificate authentication will be required not only between the management server and gateway server, but also between the Gateway Server and agent-managed computers.<b> </b></p>
<p><img height="222" width="606" src="http://www.inframon.com/sp_opsmgr/gateway3.jpg" alt="Gateway Scenario 3" /></p>
<p>While there is no programmed limit for the number of agents that can be managed within a single Management Group, information from live environments has established certain limits. Performance has been shown to degrade beyond 6,000 agents, so you should always plan for one Management Group for every 6,000 agents.</p>
<p>The official supported limit for the number of agents that can communicate to a gateway server is 1,500.<b> </b></p>
<p><b>Connected Management Groups Scenario</b></p>
<p>This deployment scenario is comprised of multiple management groups, each of which can be of the single or multiple server configurations type. This deployment scenario is exceptionally flexible and is mostly used to provide monitoring, alerting, and reporting services in complex environments.</p>
<p>This is extremely useful in the service provider scenario as it allows the connection to multiple instances of a Management Group that may exist on customer sites providing a "single pane of glass" for viewing critical alert data.</p>
<p><img height="736" width="554" src="http://www.inframon.com/sp_opsmgr/multiserver.jpg" alt="OpsMgr Multi-tenancy " /></p>
<p>Connecting management groups offers these additional services:</p>
<ul>
<li>Consolidated monitoring and alerting for greater than 6,000 agents</li>
<li>Consolidated monitoring across trust boundaries</li>
</ul>
<p>Operations Manager 2007 Server Roles</p>
<p>This configuration supports all Operations Manager server roles and makes use of the Operations Manager Connector Framework to enable bidirectional communication between the connected groups and local groups.</p>
<p>Common Uses</p>
<p>This deployment scenario can be used when the service provider requirement is to link to a complete Operations Manager Management Group on a customer site to allow a consolidated view of all monitored activity and consolidated management of that data.</p>
<p>There is no official limit on the number of Management Groups that you can connect to in this scenario.</p>
<p><b>High Level Architecture for Mixed Multi-Tenant Environment</b></p>
<p>In the case of many large service providers quite often the environment would be a mix of both connected and non-connected management groups, therefore a tiered architecture would be suitable.</p>
<p>This may consist of a master Management Group (or Local Management Group) which would host a roll up of alerts from all connected management groups and second management group which would be the collection point for all data from non-connected Management Groups.</p>
<p>Data Warehouse collection at the Master Management Group level would consist of purely Alert and Discovery Data and this would be the primary connection point for other Management Tools or any Ticketing System, this would also provide a high-level, global data collection point for customer facing scorecarding and reporting.</p>
<p>Any customer owned Management Groups would connect directly to this tier via the Microsoft Connector Framework (MCF), with performance and inventory data being collected locally on their sites. </p>
<p>A Second Management Group would be implemented as a connection point for any non-Management Group sites which would have local Gateway Servers for relaying data from local agents, this Management Group would also be connected to the Master Management Group via the MCF. This second tier would have Data Warehouse Collection Capabilities for Performance Metrics and Inventory Data and would provide a second data collection point for customer facing scorecarding and reporting.</p>
<p> The following diagram shows an example of how this architecture may look:</p>
<p><img height="588" width="916" src="http://www.inframon.com/sp_opsmgr/multimaster.jpg" alt="OpsMgr multi master" /></p>
<p><b>Connecting to other Management or Helpdesk Ticketing Systems</b></p>
<p>The Operations Manager 2007 R2 release saw the introductions of a number of free Interoperability connectors, these include HP Openview, Tivoli TEC, Remedy Helpdesk and a universal connector.</p>
<p>With the recent acquisition of Opalis Integration Center by Microsoft a number of other connection options have been added to the product such as Omnibus Netcool and HP Service Center.</p>
<p>Microsoft also has a close collaboration with EMC around the SMARTS network management toolset, which includes the purchase of some of the EMC SMARTS IP for addition to the next version of the product.  This collaboration has led to a recent release of a a bidirectional adapter package from Microsoft called the EMC Smarts Connector for Microsoft System Center Operations Manager 2007. The adapter will let Operations Manager users view Smarts topology and root-cause reports using their own interfaces. Smarts will also be able to suck in data from Operations Manager.</p>
<p>Operations Manager also comes with an extensive SNMP Trap collection feature allowing you to receive traps from any SNMP enabled system as well as being able to probe other systems ( via SNMP) for information.</p>
<p><b>Management Escalation</b></p>
<p>Operations Manager 2007 has a very extensive and flexible subscription based notification system which supports output to SMTP enabled mail systems, Microsoft Office or Live Communication Server (for delivery of messages to Office Communicator clients), GSM for SMS Text Messaging integration via a suitable GSM enabled device, as well as any command line supported medium.</p>
<p>This subscription mechanism supports a very granular and targeted alert stream, allowing you to alert down to a single object or alert over a variety of parameters (such as time raised, severity, business priority etc.). </p>
<p>Operations Manager also supports Alert Ageing which allows you to put a time expiry on un-answered alerts meaning that you can escalate them to higher tiers of Management or too other Operators.</p>
<p><b>Hardware Support for All Platforms</b></p>
<p>Microsoft has full support for Operations manager 2007 from most of the large Hardware Vendors such as HP, Dell, Fujitsu Siemens and IBM. Each of these vendors provide a full Operations Manager 2007 management Pack which typically integrates with the local hardware agent and contains Vendor specific knowledge in alerts generated.</p>
<p><b>Role based administration </b></p>
<p>Operations Manager 2007 can monitor many different types of applications in the enterprise and these applications can be administered by multiple teams. As the Operations Manager administrator, you can limit access to each team so they access only their monitoring data. Role-based security allows you to grant access to monitoring data, tools, and actions on a team-by-team basis.</p>
<p>Except for the Administrator role, you can add Active Directory security groups or individual accounts to any of these predefined roles. You can add Active Directory security groups only to the Administrator role.</p>
<p>Adding users or groups to a role mean that those individuals will be able to exercise the given role privileges across the scoped objects (including any inherited objects).</p>
<p>Operations Manager also allows you to create custom roles based on the Operator, Read-Only Operator, Author, and Advanced Operator profiles. When you create the role, you can further narrow the scope of groups, tasks, and views that the role can access. For example, you can create a role entitled "Exchange Operator" and narrow the scope to only Exchange-related groups, views, and tasks. User accounts assigned to this role will only be able to run Operator-level actions on Exchange-related objects.<b></b></p>
<p><b>Measuring and Displaying Customer Service Levels </b></p>
<p>One of the most challenging aspects of providing a managed service to a customer is being able to visualise the value of the service you are providing back to the customer in a format that can be consumed and understood by  any level of the business.</p>
<p>Operations Manager 2007 delivers the ability to define an IT service (or distributed application) by selecting the components that together deliver that IT service, along with their inter-relationships. For example, a web service may comprise of the web server, application pools, a database, and the servers that each are hosted on.  By monitoring a defined number of characteristics of each of those components, Operations Manager is able to determine both the health and performance of each component through 3 states:</p>
<ul>
<li>Healthy, indicating that the component being monitored is operating within expected parameters.</li>
<li>Warning, indicating a performance or health threshold has been exceeded, and that while the component is operating, attention is required to prevent service disruption or restore performance.</li>
<li>Critical, indicating that the component being monitored has entered an unhealthy state that requires immediate attention, and that the availability and performance of that component are compromised.</li>
</ul>
<p>This feature is one of the most powerful features of Operations Manager as it gives the ability to be able to group together all of the components that make up a service and in the event of an outage very quick root cause analysis of the source of an outage of performance problem can be identified by simply clicking on a problem path button.</p>
<p>This is also extremely useful to the service provider as it gives him the ability provide metrics back to the customer on the core services that he is being paid to manage through Operations Manager 2007 R2's in built Service Level Reporting capability.</p>
<p>The Service Level Reporting capability in Operations Manager 2007 R2 (also called "service level objectives" or SLOs) leverages this same functionality maintained in the Distributed Application concept to determine both availability and performance metrics for monitored IT services. It does this by calculating the overall time that the components that comprise that IT service remain in a particular state to arrive at the following metrics:</p>
<ul>
<li>Availability, calculated as the time the components that comprise the service are in a healthy or warming state. Only a critical state counts against the availability metric, since even if it is in a warning state the IT service is seen as being accessible by end users, (e.g., a web service may take a long time to respond, but it does eventually deliver a web page).</li>
<li>Performance, calculated as the time the components that comprise the IT services are in a healthy state. Both warning and critical states count against the performance metric, (e.g., if a database transaction is expected to complete in less than 300ms, and the actual transaction takes 2 seconds, then this will be seen as a performance impact).</li>
</ul>
<p>Once you have defined your Distributed Applications and Service Level Objectives you can use the in-built Service Level Report to display the results or can display the data in a much more effective format using the Service Level Dashboard.</p>
<p>The Service Level Dashboard for Operations Manager R2 is a free download from the Microsoft Solution Accelerator team which is an application built on Windows SharePoint Services 3.0. It is designed to work with an existing Operations Manager 2007 R2 infrastructure configured to monitor business-critical applications. The dashboard evaluates an application or group over a time period that the administrator selects during setup, determines whether it met the defined service level commitment, and displays summarized data about the service levels.</p>
<p>In Operations Manager 2007 R2, you define your service goals. The Service Level Dashboard evaluates each SLO over the defined dashboard time period and determines if it met the goal during that period. The dashboard displays each SLO and identifies its states, based on defined service level targets. </p>
<p>The following diagram illustrates, at a high-level, the process flow that occurs within the Service Level Dashboard environment:</p>
<p><img height="553" width="486" src="http://www.inframon.com/sp_opsmgr/sld.jpg" alt="OpsMgr SLD Setup" /></p>
<p>The Service Level Dashboard integrates with the Operations Manager Data Warehouse database and displays service level metrics on the Windows SharePoint Services interface. All the customized and personalized data associated with the Web Parts of the Service Level Dashboard is stored in the Windows SharePoint Services Content database.</p>
<p>The dashboard can summarize the current status and health of all defined SLOs against an application or group of objects. Key measures used to evaluate various aspects of the health of defined SLOs include such information as service level metrics, mean time to repair (MTTR), mean time between failures (MTBF), and service level trends.</p>
<p>As this Dashboard can be used in SharePoint or WSS, it can easily be imported into a public facing portal for on-line consumption by the customer.</p>
<p><b>Custom SLA Scorecarding</b></p>
<p>As the needs of the Service Provider often varies from some of the functionality that is provided from Operations Managers "out-of-the-box" availability and SLA Reporting, there is often a need to publish key data collected from Operations Manager in executive level dashboards and scorecards to give customers a "10,000" feet view of their environment so they understand the value the service provider is bringing in managing their infrastructure also key performance metrics can be presented allowing IT stakeholders within those businesses to make key decisions without the complication of having to run their own reporting infrastructure.</p>
<p>This extra level of reporting can easily be provided through extending Operations Managers reporting capability to utilise some of the new, native SQL 2008 reporting capabilities.</p>
<p>By using some of the new reporting controls now in SQL 2008, very effective, customer ready scorecards can be created which can easily be tied to an individual customer by using a combination of </p>
<p>Gordon McKenna - System Center Operations Manager MVP</p>
<p>Technical References:</p>
<p>Gateway Server and Certifcate-based Authorization Scenarios in Operations Manager 2007: <a href="http://www.systemcentercentral.com/Downloads/DownloadsDetails/tabid/144/IndexID/7885/Default.aspx">http://www.systemcentercentral.com/Downloads/DownloadsDetails/tabid/144/IndexID/7885/Default.aspx</a> </p>
<p>Tracking Service Levels with Operations Manager 2007 R2: <a href="http://download.microsoft.com/download/9/B/4/9B4829DC-55A5-46E7-9C9A-91B49EBB6320/SC_OpsMgr2007_R2-ServiceLevelMonitoring.pdf">http://download.microsoft.com/download/9/B/4/9B4829DC-55A5-46E7-9C9A-91B49EBB6320/SC_OpsMgr2007_R2-ServiceLevelMonitoring.pdf</a> </p>
<p>Service Level Dashboard for System Center Operations Manager 2007: <a href="http://technet.microsoft.com/en-us/library/dd630553.aspx">http://technet.microsoft.com/en-us/library/dd630553.aspx</a> </p>
<p> </p>]]></description>
			<pubDate>Wed, 17 Mar 2010 20:49:01 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/60925/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: TROUBLESHOOTING AGENTLESS EXCEPTION MONITORING (AEM) AND DESKTOP ERROR MONITORING (DEM) FEATURES ]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/60589/Default.aspx]]></link>
			<description><![CDATA[<p> by Satya Vel, this document describes the steps you need to take to ensure that the Microsoft Error Reporting and Windows Error Reporting are configured correctly.</p>
<p>Agentless Exception Monitoring (AEM) of System Center Operations Manager and System Center Desktop Error Monitoring (DEM) are identical features with the only difference being that AEM is shipped with Operations Manager 2007 and DEM is shipped with Microsoft Desktop Optimization Pack (MDOP) SKU’s.  These features leverage the Microsoft Error Reporting (formerly known as Dr. Watson) or Windows Error Reporting client applications for reporting the crash or hang.</p>
<div> </div>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/60589/Default.aspx" length="71208" type="application/vnd.openxmlformats-officedocument.word"></enclosure>
			<pubDate>Mon, 08 Mar 2010 13:33:52 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/60589/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Hybrid User Group Meeting this Friday 3/5/10 ATLSMUG and SCVUG]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/60381/Default.aspx]]></link>
			<description><![CDATA[<p>The Atlanta Southeast Management User Group and System Center Virtual User Group invites you to attend the next SMUG meeting scheduled for March 5th, 2010 for a day of great presentations, discussions, and networking.<br />
 </p>
<p>Because this is a hybrid user group meeting there are two ways to register.<br />
1. If you would like to use Live Meeting to attend the meeting remotely, register here <a href="http://www.clicktoattend.com/?id=146192"><font color="#669966">http://www.clicktoattend.com/?id=146192</font></a><br />
2. If you would like to go to the Alpharetta, GA Microsoft Campus to attend the meeting please register here, this will help us with planning for lunch requirements. <a href="https://www.usergroupsupportservices.com/UGEventView.ugss?EventID=8775"><font color="#669966">https://www.usergroupsupportservices.com/UGEventView.ugss?EventID=8775</font></a><br />
 </p>
<p>DATE & TIME<br />
March 5, 2010<br />
10:00 AM – 4:00 PM Eastern Time Zone<br />
 </p>
<p>Lunch provided by Prowess <a href="http://www.prowesscorp.com/"><font color="#669966">http://www.prowesscorp.com</font></a><br />
 </p>
<p>“At Prowess Consulting, we focus on providing technology marketing, technical writing, IT infrastructure, and managed services to Fortune 500 companies. We make businesses stronger by delivering the right information at the right time. We are trusted by the largest organizations to deliver results through innovative and customized solutions.”<br />
 </p>
<p>THE AGENDA<br />
 </p>
<p>9:45 AM 10:00 AM Opening and Introductions<br />
10:05 AM 11:00 AM Prowess Presentation <br />
11:05 AM 11:50 AM Introduction to Microsoft App-V and the Enterprise<br />
11:55 AM 12:40 PM SCCM R3 Features and Benefits <br />
12:45 PM 1:00 PM Break <br />
1:05 PM 1:50 PM Ed Wilson Powershell Best Practices <br />
1:55 PM 2:40 PM MP Authoring Resource Kit <br />
2:45 PM 3:40 PM What is SCUP and How Do I Use It? <br />
3:35 PM 4:00 PM Closing <br />
 </p>
<p>PRESENTER BIOGRAPHIES<br />
 </p>
<p>Steve Bucci<br />
Steve is a Senior Support Engineer with Microsoft System Center Support in Charlotte, NC. He supports Application Virtualization (App-V), Microsoft Enterprise Desktop Virtualization (MED-V), and Virtual Machine Manager (SCVMM). He has worked for Microsoft for the past 8 years.<br />
 </p>
<p>Brian Shaw<br />
Brian has been with Microsoft the past 2.5 years and is currently holding the position of Senior Support Escalation Engineer supporting SMS, Configuration Manager (SCCM), and WSUS. Brian has been supporting SMS for well over 10 years, starting with SMS 1.2. Brian is currently the CSS Beta Engineer supporting the development and release of SCCM R3.<br />
 </p>
<p>Ed Wilson<br />
Ed is a senior consultant at Microsoft and a well-known scripting expert. He is a Microsoft Certified Trainer who delivers popular scripting, networking, and administration workshops to Microsoft employees and customers worldwide. He’s written several books on Windows scripting, including Microsoft Windows Powershell Scripting Guide, Microsoft Windows Scripting Self-Paced Learning Guide, and Microsoft VBScript Step by Step. Ed holds more than 20 industry certifications, including MCSE and CISSP.<br />
 </p>
<p>Cory Delamarter<br />
[Unavailable at this time.]<br />
 </p>
<p>Jason Lewis<br />
Jason is a Program Manager on the System Center Configuration Management SE Team at Microsoft. He’s been with the team for over 5 years working on products such as Systems Management Server 2003 SP2 and R2, including the Custom Updates Publishing Tool (CUPT), Inventory Tool for Custom Updates (ITCU), System Center Updates Publisher (SCUP), and Configuration Manager 2007 R2. Jason also authors a blog at <a href="http://blogs.technet.com/jasonlewis"><font color="#669966">http://blogs.technet.com/jasonlewis</font></a> where he covers products that he’s working on including “FYI” and “How To” topics.</p>
<p>Thank you for your continued support!</p>
<p>Scott Moss<br />
Microsoft MVP (Operations Manager)<br />
Vice President Atlanta SMUG http://www.atlsmug.org<br />
President System Center Virtual user Group  http://systemcenterusergroup.org</p>]]></description>
			<pubDate>Tue, 02 Mar 2010 06:57:49 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/60381/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How to Build a CentOS Management Pack (3 part series)]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/59987/Default.aspx]]></link>
			<description><![CDATA[<p>by Robert Hearn[MSFT], this  3 part series includes everything you need to monitor CentOS with XPlat feature of Operations Manager 2007 R2.</p>
<ul>
    <li>In <a href="http://blogs.msdn.com/scxplat/archive/2010/01/05/building-a-centos-management-pack-part-1.aspx"><strong>part 1</strong></a> - basics of building a CentOS Management Pack,.</li>
    <li>In <a href="http://blogs.msdn.com/scxplat/archive/2010/01/15/building-a-centos-management-pack-part-2.aspx"><strong>part 2</strong></a>,  how to build the actual MPs.</li>
    <li>In part 3, MP installation and validation.</li>
</ul>
<p>To view the entire series at the source, click the Download button.</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/59987/Default.aspx" length="45448" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Thu, 18 Feb 2010 01:39:46 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/59987/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: OPSMGR 2007 RTM AND SP1 RC COMMAND LINE PARAMETERS (COMPLETE LIST)]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/59852/Default.aspx]]></link>
			<description><![CDATA[<p>This document is the complete list of all the command line parameters for OpsMgr 2007 server roles including Audit Collection. And the command line parameters for upgrading to Service Pack 1 (SP1) Release Candidate (RC). Should be functional for OpsMgr R2 installs as well.</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/59852/Default.aspx" length="48629" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Tue, 16 Feb 2010 15:12:55 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/59852/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Automatically Protect VMs using DPM 2010, PowerShell & OpsMgr]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/59422/Default.aspx]]></link>
			<description><![CDATA[This article demonstrates how you can use PowerShell scripts in Operations Manager to automatically protect virtual machines in Data Protection Manager 2010.]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/59422/Default.aspx" length="39260" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Fri, 12 Feb 2010 15:30:39 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/59422/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Creating SNMP Probe Based Monitors]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/58815/Default.aspx]]></link>
			<description><![CDATA[<p>Setting up a probe based SNMP monitor is quite simple; however, there does seem to be some confusion out there about what to use as the Parameter Name and how to call the value in the alert description. Hopefully this will clear things up but if you do still have questions after reading this blog entry please leave a comment or contact me using the link above.<br />
<br />
Before setting up the monitor you need to discover your SNMP device(s).<br />
<br />
Once your devices have been discovered you need to create your new SNMP probe based simple event monitor..<br />
<br />
<img title="Select Monitor" height="122" alt="Select Monitor" width="329" src="http://aquilaweb.com/blog/media/2/20080408-selectmonitor.JPG" /><br />
<br />
<br />
<br />
Then set the general properties for the monitor making sure your monitor target is set to SNMP Network Device..<br />
<br />
<img title="General Properties" height="427" alt="General Properties" width="533" src="http://aquilaweb.com/blog/media/2/20080408-generalproperties.JPG" /><br />
<br />
<br />
Next, set the object identifier for your first expression. This will be the OID of the object you are querying; in this case the temperature value from an environmental probe is being monitored..<br />
<br />
<img title="Object Identifier" height="231" alt="Object Identifier" width="481" src="http://aquilaweb.com/blog/media/2/20080408-1-discovery.JPG" /><br />
<br />
<br />
<br />
The next stage is to build your expression and this seems to be the part where most of the confusion is lying. To return the value of the OID you need to enter <b>/DataItem/SnmpVarBinds/SnmpVarBind[1]/Value</b> in the Parameter Name field. Then complete the expression by using the Operator and Value fields which are self explanatory..<br />
<br />
<img title="Build Expression" height="138" alt="Build Expression" width="538" src="http://aquilaweb.com/blog/media/2/20080408-1-filter.JPG" /><br />
<br />
<br />
Once completed, continue to follow the unit monitor wizard to build a second expression in the same way as the two previous steps above. Then comes mapping your monitor conditions to a health state - so, for example, put health state into Warning if the first event has been raised and put health state to healthy if the second event has been raised..<br />
<br />
<img title="Monitor Conditions" height="137" alt="Monitor Conditions" width="494" src="http://aquilaweb.com/blog/media/2/20080408-1-mapmonitor.JPG" /><br />
<br />
<br />
The last step is to configure the alert settings which are pretty straight forward until you decide that you would like the value of the OID query in the alert description. To return this value enter <b>$Data/Context/SnmpVarBinds/SnmpVarBind[1]/Value$<br />
</b>along with any other static text you may want..<br />
<br />
<img title="Alert Settings" height="389" alt="Alert Settings" width="520" src="http://aquilaweb.com/blog/media/2/20080408-1-alert.JPG" /><br />
<br />
<br />
I hope this is short but descriptive enough to help anyone struggling with setting up an SNMP probe based monitor. <br />
<br />
Happy Monitor Creating :-)<br />
<br />
 </p>]]></description>
			<pubDate>Sat, 23 Jan 2010 22:24:32 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/58815/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: Managing VMware Environments in Microsoft System Center Operations Manager 2007]]></title>
			<link><![CDATA[http://www.dell.com/downloads/global/power/ps4q09-20100113-Veeam.pdf]]></link>
			<description><![CDATA[<p>Full Article below:</p>
<p> </p>]]></description>
			<pubDate>Tue, 29 Dec 2009 20:27:51 GMT</pubDate>
			<guid>http://www.dell.com/downloads/global/power/ps4q09-20100113-Veeam.pdf</guid>
		</item>
		<item>
			<title><![CDATA[Articles: PKI: How to publish the CRL on a separate web server]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/55311/Default.aspx]]></link>
			<description><![CDATA[<p> <span class="Apple-style-span" style="font-family: 'Times New Roman'; font-size: medium; "><span class="Apple-style-span" style="font-family: Arial, Verdana, sans-serif; font-size: 12px; "> <span class="Apple-style-span" style="color: rgb(51, 51, 51); font-family: Verdana, Arial, Helvetica, sans-serif; line-height: 14px; ">By default, an issuing enterprise CA publishes its certificate revocation list (CRL) to locations within the forest. When you are using Internet-based client management with Configuration Manager, there are scenarios where you might need to publish the CRL on a separate server, outside the forest. These scenarios include the following:</span></span>
<div style="background-color: rgb(255, 255, 255); padding-top: 5px; padding-right: 5px; padding-bottom: 5px; padding-left: 5px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Arial, Verdana, sans-serif; font-size: 12px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-family: Verdana, Arial, Helvetica, sans-serif; line-height: 14px; ">
<ul type="disc">
    <li>Your Internet-based site systems are in the DMZ but the issuing CA for the client computers is in a separate forest in the intranet.  These Internet-based site systems will not be able to access the CRL for clients connecting over the Internet.</li>
    <li>Your Internet-based site systems are in the DMZ but the issuing CA for these servers is in a separate forest in the intranet.  When clients connect from the Internet and they are configured for CRL checking, they will not be able to access the CRL for the server certificates on the Internet-based site systems. </li>
</ul>
<p mce_keep="true" style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; ">In these Internet scenarios, it makes sense to publish a CRL that can be accessed over HTTP with an Internet FQDN.  If you already have a Web server in the DMZ that is configured for HTTP, it makes an ideal candidate because you just need to add an additional virtual directory - there's no need to add a host entry into your public DNS, or install and harden a new server to run IIS.  However, think twice about using a server running Internet-based site system roles because (with the exception of the fallback status point), these use HTTPS to help secure the server from unauthenticated access.  Certificate revocation lists cannot be accessed over HTTPS so to add HTTP access to one of your Internet-based site system servers would greatly increase the risk of an attacker connecting to this server.</p>
<p mce_keep="true" style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; ">Click the <strong>Download</strong> button at to view the entire article.</p>
</span></div>
</span></p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/55311/Default.aspx" length="41916" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Wed, 02 Dec 2009 02:38:44 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/55311/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: So, you installed System Center Operations Manager…what next?]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/55068/Default.aspx]]></link>
			<description><![CDATA[<p>by Kenneth Van Surksum, So, you decided to install System Center Operations Manager in your environment in order to start monitoring your environment. Or someone else installed Operations Manager for you, and it’s your job to start working with it. What should you do next?<br />
 </p>
<p>Click <strong>Download </strong>to read the entire article...</p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/55068/Default.aspx" length="544220" type="application/pdf"></enclosure>
			<pubDate>Tue, 01 Dec 2009 08:16:42 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/55068/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How to write monitors to target Logical or Physical Disks]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/54478/Default.aspx]]></link>
			<description><![CDATA[<p><span class="Apple-style-span" style="font-family: 'Trebuchet MS', Trebuchet, Arial, sans-serif; color: rgb(51, 51, 51); line-height: 20px; ">In this article, Kevin Holman explains how to write, and how not to write, logical and physical disk monitors in System Center Operations Manager and Essentials. </span></p>
<p><em><span class="Apple-style-span" style="font-family: 'Trebuchet MS', Trebuchet, Arial, sans-serif; color: rgb(51, 51, 51); line-height: 20px; ">Kevin writes</span></em><span class="Apple-style-span" style="font-family: 'Trebuchet MS', Trebuchet, Arial, sans-serif; color: rgb(51, 51, 51); line-height: 20px; ">: This is something a LOT of people make mistakes on – so I wanted to write a post on the correct way to do this properly, using a very common target as an example.<br />
<br />
When we write a monitor for something like “Processor\% Processor Time\_Total” and target “Windows Server Operating System”…. everything is very simple. “Windows Server Operating System” is a single instance target…. meaning there is only ONE “Operating System” instance per agent. “Processor\% Processor Time\_Total” is also a single instance counter…. using ONLY the “_Total” instance for our measurement. Therefore – your performance unit monitors for this example work just like you’d think.<br />
<br />
However – Logical Disk is very different. On a given agent – there will often be MULTIPLE instances of “Logical Disk” per agent, such as C:, D:, E:, F:, etc… We must write our monitors to take this into account. (<i><a href="http://blogs.technet.com/kevinholman/archive/2009/11/24/writing-monitors-to-target-logical-or-physical-disks.aspx" title="" target="_blank" style="color: rgb(22, 49, 111); text-decoration: underline; font-weight: bold; ">continue at source</a></i>)</span> </p>]]></description>
			<enclosure url="http://www.systemcentercentral.com/tabid/147/IndexId/54478/Default.aspx" length="37961" type="text/html; charset=utf-8"></enclosure>
			<pubDate>Thu, 26 Nov 2009 05:12:29 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/54478/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Articles: How-To: Configure OpsMgr R2 Service Level Tracking on Live Maps views]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/147/IndexId/52911/Default.aspx]]></link>
			<description><![CDATA[<p>The other day I got a question from a customer if it was possible to use Live Maps with the new OpsMgr R2 Service Level Tracking feature. The answer is simple, yes you can.</p>
<p>In this article I will give a step-by-step instruction how to configure Service Level Tracking on a Live Maps view and show the results using the Service Level Tracking report in OpsMgr and the Service Level Dashboard in SharePoint.</p>
<p><a target="_blank" href="http://blog.savision.com/livemapsblog.php/2009/11/18/how-to-configure-opsmgr-r2-service-level-tracking-on-live-maps-views"><img src="http://blog.savision.com/images/SLD_ReportDetail_Small.gif" style="display: block; float: none; margin-left: auto; margin-right: auto;" alt="" /></a></p>
<div name="extendedEntryBreak" id="extendedEntryBreak"> </div>
<p><a href="http://blog.savision.com/livemapsblog.php/2009/11/18/how-to-configure-opsmgr-r2-service-level-tracking-on-live-maps-views">(continue at source)</a></p>]]></description>
			<pubDate>Wed, 18 Nov 2009 21:04:52 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/147/IndexId/52911/Default.aspx</guid>
		</item>
	</channel>
</rss>
