Showing posts with label SBS. Show all posts
Showing posts with label SBS. Show all posts

Wednesday, August 27, 2008

Faxing in S BS 2003 [book excerpt]

Good morning - I am harry brelsford, author of the Windows Small Business Server 2003 Best Practices book and each day I am posting up a few pages for the community. I will do this until (1) SBS 2008 ships or (2) I run out of pages!

Today we look at Chapter 9 which is faxing with the shared fax service in SBS 2003.

enjoy...harrybbbb

Harry Brelsford, CEO at smb nation www.smbnation.com

Microsoft Small Business Specialist SBSC, MBA, MCSE, MCT, MCP, CNE, CLSE, CNP

PS - did u know I host an annual conference in Seattle each october for SBSers and SMB consultants? This year we help launch SBS 2008 and Essential Business Server (EBS) between October 4-6!

###

Chapter 9 Faxing


In working with SBS as both a user and consultant, I’ve noticed that the true value of some of its features can only be appreciated over time. SBS’s faxing capability is one such feature.


The faxing topic is appropriately placed here, later rather than sooner, because it is usually one of those features my clients suddenly discover well after the installation and deployment of the SBS solution. Whereas the main priorities out of the gate for most SBS sites are Internet connectivity, e-mail, and being secure, faxing is usually something I can demonstrate when things settle down and I have the client’s undivided attention. After other core SBS features, such as Outlook 2003, are accepted and widely used, the time is ripe to introduce faxing.


To balance my introduction of the faxing topic, full disclosure is necessary. I have some clients who view faxing as akin to religion. Implementing an electronic, network-based faxing solution, such as that found in SBS, acted as a key driver in their approval of the SBS network implementation project. And not only do I know this firsthand from selected clients, but I also know it from the e-mails you—the readers of my past SBS books—have sent me. Many of you commented at length how important faxing is in a small business environment networked with SBS. In fact, the dialog between reader and writer (that’s me) revealed a couple of interesting points:


• Faxing, when used, is considered very important.

• In general, SBSers were disappointed with the reliability and capability of the faxing application in the SBS 4.x era (late 1990s).






• SBSers in the past (specifically, the SBS 4.x era) have opted to deploy third-party faxing solutions, such as GFI Fax, instead of using the native faxing capabilities inside SBS.

• Readers also reported that they truly got what they paid for in fax modems. Those who went with the low-cost modems (often included with workstations) frequently experienced poor performance. Contrast that with the experience of those who invested in a superior fax modem such as the external V.Everything modem. For an investment of about $250 USD, the folks using the V.Everything modem found that they could achieve five 9’s or six sigma of reliability with the Shared Fax Service in SBS. It just flat out works!




The good news about the Shared Fax Service is that Microsoft listened over the years to the feedback on faxing within the SBS community. In the prior SBS 2000 release (the predecessor to SBS 2003), the fax application, is one area that received some of the greatest attention. And the results showed. Truth be told, it was actually a crack team of developers at Microsoft Israel who “rewrote” or reprogrammed the fax application from the ground up to take advantage of a more stable and robust Windows 2000 code base. This occurred in the summer of 2000. I share this historical insight with you because knowing how we got to where we’re at with faxing in SBS 2003 makes you wiser about the faxing function offered in SBS. That is, I’m providing historical context for ya! More important, if SBS previously lost your trust with respect to faxing, I think this release will restore that trust.


BEST PRACTICE: It’s the crime of the century. It’s the Shared Fax Service caper. It’s a big brother ripping off a little brother. What am I getting to? That the Shared Fax Service that was built for SBS 2000 just after the beginning of the new century was stolen by the Windows Server team for inclusion in the traditional Windows Server 2003 family. That’s right! The Shared Fax Service perfected for SBS was soooo good that it’s been, shall we say, borrowed for the other server products at Microsoft. In the world of intellectual property, there is certainly no greater compliment than theft, so the Fax Service


developed for SBS being co-opted for the other Microsoft Servers


operating systems is quite an affirmation of its value!


In the first part of the chapter, basic SBS faxing is defined as well as configured. You will also learn how to send and receive a fax. In the second half of the chapter, I discuss fax reporting and other advanced fax topics.

Tuesday, August 26, 2008

Beyond Remote Desktop in SBS 2003

Hi gang - I am Harry Brelsford, the author of Windows Small Business Server 2003 Best PRactices and I am writing this today from Ocean Shores WA where I am fitting in a few vacation days before fall!

Each day - I like to post up a few pages from my book for your reading pleasure. I will do this unitl SBS 2008 ships and my new Small Business Server 2008 Blueprint book is on the shelves (around November 12th).

Today is a guest column from Frank Ohlhorst, well-known industry media guy now at Ziff-Davis. He speakes towards looking beyond RDP or remote desktop in SBS 2003. This concludes Chapter 8 of my book.

cheers....harrybbbbb

Harry Brelsford | CEO at SMB Nation | www.smbnation.com

Microsoft Small Business Specialist SBSC, MBA, MCSE, MCT, CNE, CLSE, CNP, MCP

And don't forget my SMB Nation 2008 fall conference is just five weeks aways in Seattle where we host a SBS 2008 and EBS 2008 luanch party!

Beyond Remote Desktop, the path to remote control.


Frank J. Ohlhorst


Small Business Server 2003 does a wonderful job of bundling remote access capabilities, but there are some drawbacks to how the product goes about that.


First off, there are some minimum requirements that must be met for those features to be viable, namely having Windows XP professional on the client PCs. That requirement leaves those using earlier operating systems out in the cold. Another limitation is that Microsoft’s Remote Desktop Connection uses Terminal Services, in other words it is a remote session, not a remote control solution. That prevents sharing the desktop with a remote user, a key requirement


for training or troubleshooting problems remotely. To overcome those limitations, integrators can turn to several third party


vendors for remote control packages, ranging from Symantec’s PCanywhere to hosted services such as GoToMyPC.com, but selecting one of those products requires an additional expense, which can be a hard sell, especially as SBS2003


includes the “remote desktop connection” feature. Savvy integrators can turn to a freeware/open source product called VNC


(Virtual Network Computing), which can be downloaded from www.realvnc.com. What makes VNC unique (beyond it being free) is that it is a multiplatform


product, in other words you can control a windows system from a linux system or solaris system or vice versa and VNC is quite compact and easy to use. VNC is a two part product, there is a server component and viewer component. The server component is installed on the system to be controlled, while the remote user uses the viewer component to take control of a remote system. VNC is a barebones product, and just offers basic remote control capabilities, with that in mind there are a few tricks integrators need to know to use the product. First off, VNC will not search for a system on the network, you must know the destination system’s IP address. Secondly, you will need access to the internal network to connect to a system. That can be a problem, but one easily solved by


Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.


just using the included VPN server that comes with SBS2003. Once you have established a VPN connection, just input the IP Address of the target PC into the VNC viewer application, enter a password and the remote control session becomes active.


While third party products may offer more robust features, such as file transfer and search features, integrators will find that VNC fits the bill for most remote support needs and at a price that can’t be beat.


Summary


I started the chapter emphasizing how important it is for mobile workers to have robust remote connectivity. SBS 2003 is positioned very well to support these individuals with services such as the amazing RWW and an impressive update to OWA. You were educated on other mobility matters such as VPN and Terminal Services. So now it’s your moment to fly away and join the ranks of the upwardly mobile!


See you next chapter.

Monday, August 25, 2008

Advanced Mobility in SBS 2003

Happy late August Monday to y'all!
I am the author of Windows Small Business Server 2003 Best Practices and each day, out of the kindness of my heart (not!?!?) I post up a few pages of my book for you to read. I will do this until SBS 2008 ships this fall.
Today we explore advanced mobility topics at the end of Chapter 8.
cheers...harrybbbb
Harry Brlesford | ceo at SMB Nation | www.smbnation.com
Microsoft Small Business Specialist, SBSC, MBA, CNE, MCSE, MCT, CLSE, CNP, and MPC
ps - I host an annual SBS and SBSC conference in Seattle each October - this year we celebrate SBS 2008 - see u there?

Advanced Topics


How ‘bout an advanced bushel of “quick hitters” on mobility and remote connectivity before we move on to the next chapter? Cool!


• VPN and Terminal Services expectation management. Something I spend tons of time on in my SMB Consulting Best Practices book relates to VPN versus Terminal Services. An SBS customer will hear the VPN buzz word and ask you to come out to their house and set it up so that she can VPN into to SBS network back at the office. Upon completing your


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.






8-58

Section 2 ☛ Extending SBS 2003



duties, she is disappointed that “nothing changed” and the only evidence is a dancing green computer in the lower right. Turns out many custom­ers really want to use Terminal Services with its coolness of having a remote session, but they didn’t know to ask for it.



HTTP compression is enabled by default. One of the buzz words floating around building 43 in Redmond, where the Microsoft SBS development and marketing teams are housed, is HTTP Compression. HTTP compression speeds up OWA and is turned on by default in SBS 2003. To see for yourself, expand Advanced Management in the Server Management console. Expand SPRINGERSLTD (Exchange), Serv­ers, SPRINGERS1, HTTP. Right-click on Exchange Virtual Server and select Properties. Select the Settings tab. Observe that Compres­sion is set to High.



Shared Modem Service removed. I mentioned it earlier in the book





and it’s true. The Shared Modem Service, which facilitated outbound remote connectivity (such as dialing up a bulleting board system), can not be natively accomplished in SBS 2003. But leave it to Burl, the SBS consultant who works for me, to find a couple of third-party modem-sharing solutions: Spartacom (www.spartacom.com/products/ modemshare.htm) and DialOut/Server (www.pcmicro.com/ dialoutserver/).


BEST PRACTICE: So you’re thinking about pulling a fast one, eh? Not so fast, pardner. When you upgrade from SBS 2000 to SBS 2003, you lose the Shared Modem Service. So the old upgrade switch-a-roo won’t work, buddy boy. Sorry.


• KBase article 821438. As of this writing, you should put this on your SBS 2003 radar screen for RWW. This article, titled “FIX: Antivirus Programs May Cause Some Web Applications to Restart Unexpect­edly,” relates to SBS 2003 in that RWW might be affected by this (your antivirus program could impact RWW).




• License Ticks. This is an interesting question from SBS 2003 hands-on labs students, in nearly every town, related to RWW and licensing. Basically some folks were looking for a way to purchase few client access licenses (CALs) and have many folks log on remotely (essen­tially for free). The answer I received from a Microsoft product man­ager was “No and no!” The Windows authentication process during the RWW logon “ticks” against the SBS CAL count. You gotta pay full freight for the remote users.

• Third-party. Third-party mobile worker/remote connectivity solutions you could be aware of include Symantec’s infamous PCAnywhere (ver­sion 11, $199.95). A popular grassroots solution is VNC (www.realvnc.com) shareware that relies on contributions, t-shirt sales, and mouse pad sales). Take a look at GoToMy PC, which was acquired by Citrix in late December 2003 (see the CRN article at www.crn.com/ sections/BreakingNews/breakingnews.asp?ArticleID=46811). Also consider learning more about NetSupport 8.1 as a remote management tool (www.mcpmag.com/reviews/products/article.asp?Edit­orialsID=458). See Frank Ohlhorst’s column in a moment.




Next Steps


You guessed it. Forward to dig deeper into the remote connectivity area. There are entire books on remote connectivity, VPN, and the like. A quick search at Amazon revealed several capable books on VPN computing, such as Stephen Northcutt’s Inside Network Perimeter Security: The Definitive Guide to Firewalls, Virtual Private Networks (VPNs), Routers, and Intrusion Detection Systems (Que, ISBN: 0735712328).

Sunday, August 24, 2008

SBS 2003 and Terminal Servcies [book excerpt]

g’day folks - I am harrybbbb, the author of Windows Small Business Server 2003 Best Practices and I am delighted to give away my book - I am posting up a few pages per day until SBS 2008 ships!

Today we take a quick peek at Terminal Services in SBS 2003.

enjoy…harrybbbb

Harry Brelsford

CEO at SMB Nation www.smbnation.com, Microsoft Small Business Specialist, SBSC, MBA, CNE, MCSE, MCT, CLSE, CNP, MCP….whew!

ps - I am holding a raging SBS 2008 and Essential Business Server 2008 launch party in Seattle on October 4th…be there!

###

Terminal Services


An oldie but a goodie in the world of mobility and remote connectivity is Terminal Services. Funny how times change. My Small Business Server 2000 Best Practices book had an entire chapter dedicated to Terminal Services. This book has a mere section of discussion, as Terminal Services has become a well-established remote management tool that doesn’t warrant extensive discussion in the SBS 2003 time frame.


Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.


By default, Terminal Services is implemented in remote administration mode. This allows two users to connect remotely for administrative and management purposes without special licensing. Terminal Services has another mode called “application sharing mode” that is most commonly associated with a server machine (acting as a member server) dedicated to serving Terminal Services sessions to many remote mobile workers simultaneously.


BEST PRACTICE: I mentioned it early in the book and I’ll do so again. Never ever place Terminal Services in application sharing mode on the SBS 2003 server machine. Microsoft doesn’t give you the option to do this with SBS 2003 and please don’t delve deep under the hood to try and figure out how to do it!


With Terminal Services, you enjoy a remote computing session with the server, with only screen activity passed to the remote client computer. This results in a very “fast” remote computing experience, but it’s not as a network node. It’s kinda like PCAnywhere just pushing screens! But remember that in its native form (remote administration mode) in SBS 2003, Terminal Services is designed to manage the server machine (again, an additional member server would be the way for everyone to enjoy Terminal Services).


BEST PRACTICE: I’d be remiss if I didn’t honor the fact that Terminal Services has some funky licensing issues. Read the latest at www.microsoft.com/terminalservices.


You will work with Terminal Services again in Chapter 11 to manage the SBS 2003 network for SPRINGERS.

Saturday, August 23, 2008

Under the hood VPN looksy in SBS 2003

Happy HOT summer Saturday to you - at least if you are reading in North America!

I am the author fo Windows Small Business Server 2003 best Practices (SBS 2003) and I am posting up a few pages per day unitl SBS 2008 ships!

Today the topic is a under-the-hood lookat SBS 2003's VPN/ architecture. Enjoy!

cheers....harrybbbb

Harry Brelsford

CEO at smb nation, www.smbnation.com Microsoft Small Business Specialist (SBSC), MBA and other goodness like CNE, MCSE, MCT, CLSE, CNP

PS did u know I host a major rager SBS conference in early october in Seattle?

###

Under the Hood: VPN


So what’s the technical view of the VPN connection just made? Figure 8-32 shows the port-activity related to the VPN connection.


Figure 8-32


Observe that Port 1723 is being used for the VPN connection between a remote computer and SBS 2003.





Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


BEST PRACTICE: Regarding the day-to-day use of VPN connectivity in SBS 2003, I suggest you view this as a dial-on-demand approach. Whenever I’ve seen SBS sites that view the VPN area as full-time, 7/ 24 connectivity between branch offices, I’ve actively discouraged such thinking, because SBS isn’t positioned as a branch office solution. But it’s fine if a traveling Norm Hasborn needs to VPN into the SPRINGERS network to do some voodoo.


VPN and NAT-T


Finally, it’s beyond the scope of this text and it’s something I’ll pursue in the advanced SBS book later (with step-by-step procedures), but be advised there is an issue with respect to having VPN connections when you place a hardware-based firewall router out in front of SBS 2003 and want to tunnel into the SBS network (especially if you’re adhering to the best practice of a dual firewall). This area is NAT-T over IPSec across the firewall. Technically speaking, IPSec NAT Traversal (NAT-T) allows IPSec clients and server to work when behind a NAT. To use NAT-T, both the remote access VPN client and the remote access server must be IPSec NAT-T-capable. IPSec NAT-T provides UDP encapsulation of IPSec packets to enable Internet Key Exchange (IKE) and Encapsulating Security Payload (ESP)-protected traffic to pass through a NAT. IKE automatically detects that a NAT is present and uses User Datagram Protocol-Encapsulating Security Payload (UDP-ESP) encapsulation to enable ESP-protected IPSec traffic to pass through the NAT.


IPSec NAT-T is supported by the Windows Server 2003 family. As such, it’s supported in SBS 2003. Your next step might be to delve deeper into the issue with the Microsoft Press Windows Server 2003 Resource Kit or look up some articles on TechNet.

Friday, August 22, 2008

VPN and SBS 2003

Hello folks - I am the author of the Windows Small Buisness Server 2003 Best Practices book (ye olde purple book) and I am posting up a few pages per day because (1) I own the copyright and (2) I like helping folks!

Today we are deep into Chapter 8 discussing mobility and remote access. The topic is Virtual Private Networks (VPN) in SBS 2003.

BTW - I will keep postung up unitl SBS 2008 ships!

cheers...harrybbbb

Harry Brelsford

CEO at SMB Nation | www.smbnation.com

Microsoft Small Business Specialist (SBSC), MBA, MCSE, CNE, MCP, MCT, CLSE and CNP - man - I am tired from earning those titles!

ps - we are hosting the SBS 2008 and Essential Business Server EBS launch party in Seattle at our fall conference in early October...see ya there!

###

VPN Connectivity


Building on the high-level VPN discussion we had in Chapter 5, this section is gonna do the step-by-step thing to have Norm Hasborn VPN in from his trusty HP Evo N800c laptop.


BEST PRACTICE: If you have run the Remote Access Wizard, you can then run the Connect My Remote Computer to the Network link in RWW to install Connection Manager on the mobile laptop or home computer. Here is the key point. Connection Manager automates the process of establishing a VPN connection to the SBS


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


2003 network. Connection Manager can be used across any type of connection (such as dial-up modem).


Connection Manager can be installed three ways:


• Add User Wizard/Setup Computer Wizard: You can specify that Con­nection Manager should be installed for a user on a machine. Revert to discussion in the latter part of Chapter 4 to refresh your memory on this. This approach will place a shortcut on the client computer desktop to run Connection Manager and initiate the VPN session.

• Connection Manager diskette. Yes, diskettes still exist in SBS 2003! This diskette can be created and given to an employee to take home to easily set up the VPN connection to the SBS 2003 network. Create the Connection Manager diskette from the Create Remote Connection Disk link on the Manage Client Computers page under Standard Manage­ment in the Server Management Console.

• RWW: Pick Download Connection Manager from RWW, which is what we’ll do in the following procedure.




BEST PRACTICE: Connection Manager will only work with a FQDN that you’ve registered as a resource record with your ISP to point to the wild-side NIC card on the SBS 2003 server machine. If you want to use the wild-side IP address, you’ll have to configure the connection manually.


VPN Step-by-Step Procedure


Time to have Norm VPN into SPRINGERS!


1 Log on locally as NormH using the password Purple3300 on his laptop, NormLap.

2 Click Start, Internet to launch Internet Explorer.

3 Type springers1.springersltd.com/remote in the Address field.

4 Respond affirmatively to the security alerts (OK, Yes)




5. On the RWW logon screen, log on as NormH with the password Purple3300. But if you want to avoid the message in Figure 8-30, then deselect the I’m using a public or shared computer checkbox.


Figure 8-30


Microsoft will not allow Connection Manager to run on a public or shared computer.








6. Select Download Connection Manager. Click OK after reading the warning that you should ensure all users have strong passwords after you install Connection Manager.




7. Click Open on the File Download dialog box to open Connection Manager (sbspackage.exe).




8. Click Yes when asked if you want to install the connection to SBS 2003 in the Connect to Small Business Server dialog box. The installation process commences.




9. On the desktop, double-click on the Shortcut to Connect to Small Business Server.




10. Complete the Connect to Small Business Server logon box, as seen in Figure 8-31. Type NormH in the User name field, and Purple3300 in the Password field. Click Connect. Your computer will be regis­tered on the SBS network.




Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 8-31


Simple stuff, Maynard! Connecting via the Connection Manager approach shields users from having to manually configure the VPN stuff on their computer.





You have now established a VPN connection to the corporate network and the client computer acts as a “node” on the LAN at this point. The visual evidence of this will be a green dancing computer (connection icon) in the lower right corner of the screen. VPN connections are often appropriate to access network resources from afar and run business databases (where you truly need to be a network node).

Thursday, August 21, 2008

Remote Outlook Use in SBS 2003

Hi there - I am HArry Brelsford, the author of the Windows Small Business Server 2003 Best Practices book and each day a I post up a few pages for your reading pleasure. I will do this until SBS 2008 ships!

Today is the REMOTE USE of MICROSOFT OUTLOOK in an SBS 2003 world. Guess I am shouting for empahsis, eh?

Anyways - until tomorrow - harrybbbbb

Harry Brelsford |CEO at SMB NATION | www.smbnation.com

Microsoft Small Business Specialist (SBSC) and other non-sense like an MBA!

ps - I hold an annual conference each year in Seattle for SBSers...this year is early October to discuss SB S 2008 and EBS 2008.

###







Real Outlook 2003 Used Remotely


This section speaks to the ability to utilize your real Outlook 2003 client application across the Internet and connect to your SBS 2003 server machine. This might be used in lieu of OWA. There are two ways to make real Outlook speak to SBS 2003’s Exchange Server 2003 messaging application: VPN and RPC over HTTP. The VPN method is fairly straightforward. You simply establish a VPN connection (discussed in the next section below) and launch your Outlook 2003 client application. Your mailbox is then presented to you.


But a more hip, cool, and exciting way to remotely connect your Outlook 2003 client application to SBS 2003 is to use RPC over HTTP. RPC, which stands for “remote procedure call,” is how Outlook 2003 communicates over with Exchange Server 2003 on a local area network (LAN). The difference is that you are going to do it remotely over the Internet without having to first establish a VPN connection or present other authentication stuff like smart cards or security


tokens. This allows a remote worker to use real Outlook 2003 and get through the firewall.


BEST PRACTICE: Be advised there are some minimum requirements to using this cool messaging retrieval method. The client computer must be running Windows XP Professional with XP Service Pack 1 (SP1) and have the Microsoft Knowledge Base article 331320 updates installed. You must be running SBS 2003 (which includes Windows Server 2003 and Exchange Server 2003). The Exchange Server 2003 must be configured to allow connections via HTTP (fortunately, this is enabled by default in SBS 2003). You can see HTTP connection support in Exchange Server 2003 in SBS 2003 from Start, Server Management, Advanced Management, SPRINGERSLTD (Exchange), Servers, Springers1, Protocols, HTTP, Exchange Virtual Server. Notice the virtual server is configured and running (compare this to the POP3 virtual server that is not).


Given the baseline prerequisites have been met, complete the following procedure.


1 On the remote client computer (NormLap), have NormH log on locally with the password Purple3300.

2 Launch Outlook 2003 from Start, E-mail. If this is the first time you’ve launched Outlook 2003, complete the configuration screens to configure Exchange e-mail to point to SPRINGERS1 for the user Norm Hasborn.

3 Click Tools, E-mail accounts. The E-mail accounts wizard commences.

4 Select View or Change existing e-mail accounts and click Next.

5 Select the Exchange e-mail account on the E-mail Accounts page and click Change.

6 Click More Settings and select the Connections tab on the Microsoft Exchange properties dialog box.

7 Under Exchange over the Internet, select Connect to my Exchange mailbox using HTTP. This is shown in Figure 8-27.




Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 8-27


Selecting the option to connect over the Internet to your Exchange-based mailbox.





BEST PRACTICE: So let me guess. You don’t see the menu option in Step 7 above. If that is the case, you didn’t download and apply the patch specified above (331320). This can be found as www.microsoft.com/technet by entering 331320 in the Search field. The Microsoft search result should look similar to article page in Figure 8-28. Apply it now and restart the above procedure. See you back at Step 7, mate!


Notes:


Figure 8-28


Download and install this to complete the Outlook 2003 RPC over HTTP example.








8. Click on the Exchange Proxy Setting button.




9. Complete the Exchange Proxy Settings screen with https://spring­ers1.springersltd.com and verify the Connect using SSL only checkbox is selected. This is shown in Figure 8-29. Accept the default settings and click OK.




10. Click OK to close the Microsoft Exchange properties dialog box.




11. Click OK when notified you will need to restart Outlook.




12. Click Next on the E-mail Accounts wizard, followed by Finish.




13. Close and start Outlook again. Outlook 2003 will appear and ready for your use.




Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 8-29


Completing the final RPC over HTTP steps for Outlook 2003.





BEST PRACTICE: How ‘bout a little bit more discussion on RPC over HTTP. Try on this advanced stuff for size. As you might have guessed, Outlook 2003 is capable of wrapping an HTTP/HTTPS header around each MAPI RPC request. This gives Outlook 2003 the capability of communication to the Exchange Server using direct HTTP or HTTPS. With the correct configuration (such as you did above), this feature allows a rich client experience to a corporate mailbox server over the Internet (as you know by now) where no RPC ports or VPN are required. Where Exchange front-end servers have been deployed in the DMZ, these act as RPC/HTTP proxy servers to the back-ends on the corporate network (oops - I just went beyond the scope of SBS there).


The Windows RPC over HTTP feature provides an RPC client (in this case, Outlook 2003) with the ability to establish connections across the Internet by tunneling the RPC traffic over HTTP. Because standard RPC communication is not designed for use on the Internet and doesn’t work well with perimeter firewalls, RPC over HTTP makes it possible to use RPC clients in conjunction with perimeter firewalls (again, this is kinda beyond the scope of SBS). If the RPC client can make an HTTP connection to a remote computer running Internet Information Services (IIS), the client can connect to any available server on the remote network and execute remote procedure calls. Furthermore, the RPC client and server programs can connect across the Internet - even if both are behind firewalls on different networks.


So now for a real advanced issue! You and I have likely read popular trade journal media stories that the RPC stack on Windows (NT/ 2000/XP/2003) having been exploited by hackers (Blaster). Hell ­you might have seen it! So is RPC over HTTP vulnerable to this type of attack? Nope would be the official reply. Nope because only authenticated users are allowed access to RPC over HTTP. That’s why you’re prompted to log on in again when you try to get Outlook to connect to the Exchange server using RPC over HTTP. The cited exploit could only use anonymous access to RPC.


And that’s that!

Tuesday, August 19, 2008

Outlook Mobile Access (OMA) in SBS 2003

Hello-hello! I am Harry Brelsford, author of the Windows Small Business Server 2003 Best Practices book and each day I am posting up several pages from this purple book. I am delighted to report that we start the subject of Outlook Mobile Access (OMA) from Chapter 8 with today's post. Good stuff!

enjoy....harrybbb

Harry Brelsford | ceo at smb nation | www.smbnation.com

Microsoft Small Business Specialist (SBSC), MBA, MCSE, MCT, MCP, CNE, yadda yadda yadda

PS - did u know we are hosting a SBS conference in early october in Seattle?

###

Outlook Mobile Access


Back in Chapter 6, I wrote about forwarding e-mails to your cell phone. The forwarding works, but an even better solution is to use the newly included feature of Exchange 2003 and SBS 2003 called Outlook Mobile Access (OMA). OMA is simply OWA for web-enabled phones and PocketPC browsers. The basic features of OMA were formerly offered in Mobile Information Server 2002 and also in third party devices - now they are free!


During the SBS 2003 launch events, I met Kim Walker in Columbus, Ohio. Everyone has a gadget that they can’t live without and Kim’s addiction is e-mail on her cell phone. She has been using and managing third-party add-ins for several years and is promoting the feature to her clients. Kim has offered up some OMA info and best practices. She’s the OMA Momma and what follows in this section are her words! Go Kim!


Defining OMA


OMA offers a live text interface to your e-mail messages, calendars, tasks, and contacts. It replaces third-party add-ins at client computers or on additional servers. Therefore, it helps lower the total cost of ownership by reducing the need to deploy additional mobile server products in the corporate environment and by utilizing one mobile user device instead of multiple devices.


OMA supports Wireless Application Protocol (WAP) 2.x as well as XHTML browser-based devices, full HTML browsers and i-Mode devices such as mobile phones and personal digital assistants (PDAs).


OMA Server-Side


From the server-side, OMA setup is very simple. OMA is easier to manage than third party or desktop applications - everything is configured through Exchange System Manager. One important note is that in Standard Exchange Server 2003, OMA is disabled by default, but within SBS 2003 the default is OMA enabled (Figure 8-21).


Figure 8-21


The default Mobile Services Properties for Exchange has everything enabled.





Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Notice the section titled Enable unsupported devices. Many devices have not been fully tested by Microsoft and are not on the supported device list. By default this box is checked, allowing a user to access Exchange on theses untested devices. The user gets an error that says: The device type you are using is not supported. Press OK to continue. This is shown in Figure 8-22. Once you press OK on the device, the service is generally available.


Figure 8-22


This is a screenshot from a mobile phone showing a failed connection.





BEST PRACTICE: Keep the Enabled unsupported devices checkbox


selected.


You can grant OMA access on an individual case-by-case basis. Say Norm Hasborn, owner of SPRINGERS, gets a new cell phone and doesn’t tell you. If Outlook Mobile Access is disabled for him (see Figure 8-23), he might test out OMA and get an error. He won’t have OMA access until he calls you, the SBSer, for support.


Figure 8-23


You can disable Mobile Services for individual user.





BEST PRACTICE: If you decide to manually add a user e-mail alias rather than run a custom recipient policy, your user will get an error accessing OMA: Item no longer exists. The item you are attempting to access may have been deleted or moved.


OMA Client-Side


From the client-side OMA is also fairly simple. It does not have all of the bells and whistles some third-party software has had, but it is definitely functional. OMA is customized for low-bandwidth high-latency type environments, but it still has the same feature set. Reply still means reply. Decline a meeting still means decline a meeting.


Time to use the SPRINGERS methodology where you will send an e-mail, enter contact records, and perform other such tasks from OMA. OMA can be


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


accessed from a desktop computer as well - you don’t have to have a mobile device. In fact, if you are using your laptop in a location with a very slow connection, OMA will get you to your e-mail without any OWA overhead.


Sending an E-mail


Time for some step-by-step to have NormH check his e-mail.


1 From the mobile device, point your browser to the following address: http://springers1.springersltd.com/oma.

2 At the Authentication required screen, type NormH in the User field and click OK.

3 On the Password screen, enter Purple3300 and click OK.

4 If you get the device type not supported error (wording may vary), click OK.

5 You are taken to the Exchange Mailbox for the user (Figure 8-24). You can scroll (down arrow on cell phone) to see all of the Mailbox options (such as Calendar, Contacts, Tasks, etc.).




Figure 8-24


The OMA-based Mailbox on the mobile phone.





6. To read Norm’s inbox, press the 1 or the Go menu button.. This will bring you to his Inbox listing (Figure 8-25).


Figure 8-25


This is an Inbox on a mobile phone.





The asterisk on the first message in Figure 8-24 means that this is unread. Also notice the second message is the Standard SBS 2003 Server Performance report


-it might take a little while to read through on the small screen, but in a pinch it’s great. To read any message just select Go while highlighted or hit the corresponding number (there will not be numbers in standard Internet Explorer form a desktop). OMA provides full-featured e-mail functionality, including compose new, read, reply, reply all, forward, delete, flag, and mark as unread. From the details view of messages, you can browse to previous message or next message, close, or go home.


In the OMA calendar view, you can view today, next/previous day, or go to the day of your choice. For any OMA calendar item, you can accept, tentative, decline, reply, reply all, forward, delete, and view details.


Comparing OMA to Other Approaches


So how does OMA compare to cellular-provided desktop assistant programs? Functionality is similar, but the major advantage is that the phone now connects directly to the server. In order for one of the Desktop Assistant programs to


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


function, the desktop must remain turned on with the forwarding program running. This places the failure point at the desktop and also uses both LAN and Internet bandwidth.


How does OMA on a standard cell phone compare to a SmartPhone or blackberry device? Generally cell telephones have smaller screens, but as you can see from the screen shots, if the phone is set to a small text, it is still readable. It is not as easy to type a reply, but it is possible and you can still check messages anywhere.


One important difference between OMA browser access and synchronization devices is that the information is only accessible when the user is in cellular coverage. The data does not get stored on the phone, but can be viewed only in the browser while the user is authenticated to the server.


As of this writing, I dearly miss some of the tricks that third party software offered. One of these tricks is a text message/page notification of mail - a rule that tells the user to check the mailbox rather than forward the message. For now, you can use the forward message from Chapter 6 for specific messages. In the past I have used notifications to page me when I received a message of high importance or a server message (based on words in the subject) or by sender. I check my e-mail frequently, but if I was in a meeting it would alert me to an issue that might be critical.


Daily OMA Use


I use OMA all of the time. Personally, I have a separate folding keyboard that attaches to my cell phone - I can send and receive e-mails without pulling up my laptop, but when I don’t need it I still have a small form factor phone. Without a keyboard, you don’t want to type long e-mails or replies, but you could send a short message saying “YES” (literal telephone pad keystroke sequence is: yes - Y - 999, E - 33, S - 7777 - it’s the new Morse code). OMA is also great for checking calendar updates. While running from one meeting to another, you can quickly check to see if the upcoming meeting time or location has been moved.


Thanks, Kim, for the OMA expertise. Won’t you consider speaking on this at the SMB Nation conference in Fall 2004? I can’t resist sharing a photo from the Fall 2003 SBS hands-on lab tour where a student in San Francisco implemented OMA right in the class room (Figure 8-26).


Figure 8-26


Live from San Francisco! It’s OMA and SBS 2003.

Monday, August 18, 2008

OWA Security in SBS 2003

Happy Monday to u!

I am Harry Brelsford, the author Windows Small Business Server 2003 Best Practices and I am posting up a few pages per day to the Web (my blog) for your reading pleasure. This will continue until SBS 2008 ships!

So please enjoy a few pages today concerning OWA security in SBS 2003!

cheers…harrybbbb

Harry Brelsford

CEO at SMB Nation, www.smbnation.com, Microsoft Small Business Specialist (SBSC)

PS - I host a fantastic fall confernece in Seattle surrounding all this and more - everything SBS and Eseential Busienss Server (EBS)

###

OWA Security


There are a couple of security matters relating to OWA.


• Public vs. private computer. In Figure 8-18, you can see the OWA logon screen. A public or shared computer has a shorter time-out period (akin to the same setting in RWW). A private computer informs the Exchange server to tolerate a longer period of inactivity before enforcing a log off.

• HTTPS. I mentioned earlier but I need to mention again. When you configured SBS properly (that is, run the EICW and create the self-sign­ing certificate that is discussed in both Chapter 4 and 5), you’ll always




operate OWA under HTTPS. The translation for the BDM is that this is more secure and the data (in addition to the logon activity) is encrypted via PPTP. The port session related to this is shown in Figure 8-20.


Figure 8-20


Observe Port 443 making the OWA session operate under HTTPS.





Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


• Challenging. When you log on the old fashioned way or the local host way, you must complete the OWA logon. In SBS 2000, a local host OWA session did not issue this logon challenge. When you access OWA via RWW, you are not challenged for an OWA-specific logon because RWW passes logon authentication to OWA.


BEST PRACTICE: Always have your SBS users properly log off OWA when they leave an OWA session. The logoff button is found on the far right of the upper OWA toolbar. Not logging off lays the foundation for sinister behavior, such as someone clicking Back several times in Internet Explorer to get to your mailbox! LOG OFF!

Sunday, August 17, 2008

OWA - finer points in SBS 2003

Hello everyone - its sunday and I am posting up a few pages from Chapter 8 of my Windows Small Business Server 2003 Best PRactices book (the purple book) for your reading pleasure. Today we look at some of the finer points of Outlook Web Access (OWA) in SBS 2003. I will keep posting up book pages each day until SBS 2008 ships.

Thanks for reading - hope this helps!

cheers...harrybbbb

Harry Brelsford ceo at SMB Nation www.smbnation.com

I am a Microsoft Small Business Specialist (SBSC), MBA< MCSE< MCT< CNE, CLSE and CNP!

Did u know I host a raging SBS conference in Seattle in early october?

###

Meet OWA


Less talk, more look-see at this point. The new and improved OWA is presented in Figure 8-17 for your pleasure.


Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 8-17


Here is OWA in the SBS 2003 time frame. Notice in the Address that the URL identifies local host (running on the SBS server machine).





There are three ways to access OWA in SBS 2003.


• Old-fashioned. You’re probably familiar with this approach. Type the fully qualified domain name (FQDN) appended with the term “exchange” for the external interface (that’s the wild-side NIC card) on the SBS server machine) like springers1.springersltd.com/exchange. This approach assumes you have an “A” resource record registered in the DNS of your ISP that points to the wild-side NIC card. Of course, you could always point to the wild-side IP address in the following manner -207.202.238.215/exchange - and you’ll start the OWA authen­tication process.

• RWW. If necessary, revisit the RWW discussion early in this chapter where you learned to authenticate over the Internet. The RWW menu has the Read my company e-mail link to launch OWA. From the




outside, RWW is best accessed by FQDN/remote (spring­ers1.springersltd.com/remote).


• Local Host. In Figure 8-17, I hinted at the use of OWA on the SBS server machine. This is possible with the localhost/exchange address. This is an excellent way to read e-mail messages et. al. on the actual SBS server machine and avoid the MAPI conflict I discussed in Chap­ter 6 (see Figure 6-26).


There are two types of OWA experiences:


• Premium. If ya want the good stuff, you need to select the Premium radio button on the OWA logon screen.

• Basic. While providing fewer OWA features, selecting the Basic radio button results in a session that runs faster and is recommended for slow links.




Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


I compare OWA Premium and OWA Basic on a deeper level (focused on security) in Table 8-1.


Table 8-1: Security: OWA Premium versus Basic




Capability
Description
OWA Premium
OWA Basic

Logon page
This has a new custom­ized form for logging on to OWA. Includes cookie-based valid­ation where OWA cookie is invalid after user logs out or is inactive for a predefined amount of time (or eats the cookie - just kidding).
Yes -and allows you choice to use OWA Basic
Yes - but only allows use of OWA Basic

Clear credentials cache on logoff
After logofff all the credentials in IE SP1 credentials cache are cleared automatically.
Yes
No

Public/Share computer and Private computer logon options
To provide SBSers with more protection, two logon page security options can be used. You can set the private logon page with a longer period before user is logged off because of inactivity.
Yes
Yes

“Web Beacon” blocking
Users can control options for blocking external content in e-mail.
Yes
Yes

Attachment blocking
Administrator options restrict access to some or all attachments in messages.
Yes
Yes

Junk mail filtering
Options to set up safe-and blocked-sender lists.
Yes
Yes

Encrypted/ signed mail
Sending and receiving encrypted and/or signed e-mail is supported.
Yes. IE 6 on Micro­soft Windows 2000 or later.
No.





It’s time for Norm Hasborn to check his e-mail via OWA.


1 Log on to the remote computer (in my example: NormLap). I’ll assume you can log on as NormH (a local user) with the password Purple3300.

2 Launch Internet Explorer from Start, Internet. Type springers1.springersltd.com/exchange in the Address field. Note you can explore OWA via RWW on your own by repeating the RWW steps earlier in the chapter (from RWW, select Read my company e-mail). Here I want to expose you to the native OWA logon screen (RWW suppresses this screen, as I’ll discuss in the security section).

3 Click OK at the two Security Alert dialog boxes that appear (a third such box may appear if you didn’t install the SPRINGERS certifi­cate earlier in the chapter and requires Yes).

4 Complete the OWA logon screen similar to Figure 8-18. NormH is the user with the password Purple3300. The Client is Premium and the Security is Public or shared computer (I discuss security in the next section). Click Log On.




Figure 8-18


Norm Hasborn is logging on to OWA here. The session has flipped to HTTPS at this point.





Visit www.microsoft.com/technet for the latest updates for any Microsoft product.




1 OWA can be seen for NormH in Figure 8-19. Notice the e-mail in the figure relates to the alert you configured in the prior chapter (Chapter 7 on WSS) relating to the Breeder1.doc document. Cool!

2 Go ahead and horse around with OWA for a few minutes. When you’re done, log off via the Log Off button on the far right.




Figure 8-19


OWA time, baby!

Friday, August 15, 2008

Outlook Web Access (OWA) in Windows Small Business Server 2003 (SBS)

Call it a case of tomorrow's new today!

I am posting up my Outlook Web Access (OWA) introduction in the SBS 2003 realm today (Friday) because tomorrow (Saturday) I will be jammed with my niece's wedding here in San Francisco. What is interesting about this wedding is that it is an openly gay wedding which is now legal in the State of California and I am thrilled and excitred to see how this all plays out! I will post up a blog on my first experience at this type of wedding.

Back to the business at hand. I am the author of the Window Small Business Server 2003 Best Practices book (purple book) and I live on Bainbridge Island, WA. I am posting up a few pages of this SBS 2003 bok each and every day until SBS 2008 ships on November 12th (worldwide, multiple languages). Today - as I mentioned - we meet OWA.

cheers...harrybbbb

Harry Brelsford, CEO at smb nation, www.smbnation.com

Microsoft Small Business Specialist - SBSC

did u know we have a gr8t fall conference in sEattle in early October?!?! :)

###

Outlook Web Access


Meanwhile, back at the BBQ where the steaks are sizzling, another compelling SBS 2003 feature that “sizzles” in front of business decision makers (BDMs) is the massively improved Outlook Web Access (OWA). My infamous SBS customer, Bob in real estate, did back flips when I showed him the new OWA in SBS 2003. Why? For these reasons.


• Look and feel. The new OWA just looks more like “real” Outlook. That has been a major sticking point with Bob and other BDMs. It wasn’t so much like reading an e-mail message in past OWA releases


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


was that bothersome. Rather, things like calendar entries and contact records were downright rude!


• Feature creature. OWA, when compared to past OWA versions (apples to apples) and not compared to “real” Outlook (apples to oranges), is much richer. An example of improved features is the stronger integra­tion with Outlook and its rules and options (such as Privacy and Junk E-mail Prevention options now accessible via OWA).

• Sir Speedy. This OWA version boogies. Older OWA releases were slow and seconds of delay felt like hours to Type-A businessmen like Bob. It was so bad in the past that I set up Outlook Express with IMAP as per Chapter 6 to workaround the OWA slowness.

• Security improvements. I felt honor-bound to show my customers, such as Bob the BDM, some improvements to security. As an SBSer in the early 21st century, I’m trying to use every opportunity to talk up security (and no, this isn’t make-work or a self-employment act, but advice offered in a sincere way). See the security section below for details, but I’ll share one now: OWA natively runs under HTTPS when you configure the default configuration of SBS.




BEST PRACTICE: So are there any limitations with the new OWA? Yes, there are a few. A bright student in Mumbai/Bombay India SBS 2003 hands-on lab correctly taught me (the instructor) that OWA doesn’t display multiple mailboxes at the same time while real Outlook can. This is bothersome if you’re a BDM that uses multiple e-mail aliases to look larger than life in the business community and you travel extensively and need to use OWA from Internet cafés or your laptop in a hotel room. With OWA and multiple mailboxes, you’d need to log on multiple times (as the different e-mail account) and view each mailbox separately (e.g., jobs@springersltd.com).


Another student at the San Francisco, California, SBS 2003 hands-


on lab (October 2003) correctly pointed out that, when viewing a


Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.


contact record in a public folder in the new OWA, the New Message to Contact toolbar button is disabled. Translation: You can’t send an e-mail to a contact in a public folder with a single click using OWA. Rather, you have to manually copy and paste the SMTP e-mail address into a new message. He seemed really bothered by this (must have been having a bad SBS day).


Beatrice Mulzer from Cocoa Florida informs me that the search folder feature isn’t available in OWA.


I personally noticed that, when entering a contact record in OWA in the SBS 2003 time frame, that the Address, City, State, Zip fields (ACSZ) are divided in the UI for OWA (you have separate fields for ACSZ). But, in real Outlook 2003, ACSZ is entered into a single field and then parsed in the background.

Remote Desktop Protocol (RDP) in Windows Small Business Server 2003

Top of the morinng to ya! I am up and at 'em here in Seattle on the 520AM ferry enroute to the airport and some time in the San Francisco area...really starting to spend more time down there what with the hot technology sector (can u say SOMA?). So a quick post from Chapter 8 of my Windows Small Business Server 2003 Best Practices book - as u might know - I am posting up several pages per day from this book into the WILD for your reading pleasure. Why do I do this? Because I am a nice person! I will keep posting until SBS 2008 ships!

Today we explore the Remote desktop Protocol (RDP) in the mobility realm of SBS 2003.

cheers...harrybbbb

harry brelsford, smb nation's ceo www.smbnation.com

Microsoft Small Business Specialist (SBSC), MBA MCSE MCT CNE CLSE CNP

Did u know I host my big annual conference in early OCtober in Seattle!

###

Exploring RDP


Oops! I almost forgot some more stuff on RDP that I wanted to share (this has an advanced tone to it). RDP allows for separate virtual channels for carrying device communication and presentation data from the server, as well as encrypted client mouse and keyboard data. RDP uses its own video driver on the server-side to render display output by construction rendering information in network packets using the RDP protocol and sending them over the network to the client. On the client-side, it receives the rendering data and interprets them into the corresponding Win32 Graphic Display Interface (GDI) application programming interface (API) calls. On the input path, client mouse and keyboard messages are redirected from the client to the server. On the server-side, RDP uses its own virtual keyboard and mouse driver to receive these keyboard and mouse events.


Without encrypting the display protocol, it would be very easy to “sniff” the wire to discover the user’s passwords as they log on to the system. Allowing an administrator to log on using a non-encrypted protocol exposes the entire domain resources that are now vulnerable to hackers, especially if connecting over a public network without a VPN. It is both darn interesting and important to note


that protocols using “scrambling” to protect data are just as vulnerable to this


sort of attack as protocols that send data using clear text. The activity involved in sending and receiving data through the RDP stack is essentially the same as the seven-layer Open Standards Interconnection (OSI) model for the LANs on this planet. Data from an application or service to be transmitted is passed down through the protocol stacks, sectioned (sounds like a Ginsu knife commercial with slicing and dicing, eh?), directed to the channel (through MCS), encrypted, wrapped, framed, packaged onto the network protocol, and finally (really and truly) addressed and sent over the wire to the client. The returned data works the same way only in reverse, with the packet being stripped of its address, then unwrapped, decrypted, and so on (and on and on) until the data is presented to the application for use (Whew!). Key portions of the protocol stack modifications occur between the fourth and seventh layer, where the data is encrypted, wrapped and framed, directed to a channel and prioritized.


Lastly, every version of RDP uses RSA Security’s RC4 cipher, a stream cipher


designed to efficiently encrypt small amounts of varying data size. RC4 is designed for secure communications over networks and is also used in protocols such as SSL, which encrypts traffic to and from secure Web sites. By default, Windows XP Remote Desktop and Windows Server 2003 Remote Desktop and Terminal Services use high (128-bit) encryption to encrypt most data transmissions in both the client-to-server direction and the server-to-client direction.


BEST PRACTICE: Don’t forget the 128-bit encryption point raised here.


It is frequently brought up in technology conversations about SBS.

Thursday, August 14, 2008

RWW Security Summary in SBS 2003

Hello gang - today I have a shorter post-up from my Windows Small Business Server 2003 Best PRactices book - it is a summary of Remote Web Workplace security.

enjoy...harrybbbb

Harry Brelsford, ceo at smb nation, www.smbnation.com

did u know we have a raging conference comin' to Seattle in early October: SBS 2008 and EBS 2008 launch party!

Microsoft Small Business Specialist (SBSC) and MBA

###

RWW Security Summary


Before moving on and looking at Outlook 2003 remote approaches, oblige me and view the following RWW security summary:


• SSL connections required for access to the Web site.

• User authentication required for access to the Web site.

• Log out allows users to close sessions and clear any cached logon credentials.

• Timeout feature automatically closes sessions after a period of inactivity.




Visit www.microsoft.com/technet for the latest updates for any Microsoft product.




• Public or shared computer mode provides additional safety require­ments in those environments (browser version checking, shorter timeouts).

• Web site is throttled through IIS.

• Web site files are strongly ACL’ed (governed by the Access Control List) to prevent unauthorized editing.

• Remote Desktop connections are encrypted and send only mouse clicks and keystrokes over the connection.

• Reduces or eliminated the need for VPN connections at the business.




BEST PRACTICE: Use the above list as “talking points” when talking about RWW.

Wednesday, August 13, 2008

RWW under the hood in SBS 2003

Good evening folks - been a crazy busy day but I am honoring my commitment to post up several pages per day from my Windows Small Business Server 2003 Best Practices book (the purple book). I really like the part of Chapter 8 where we debunk, prove and otherwise party on with Remote Web Workplace.

Looking forward to SBS 2008 and more madness!

cheers...harrybbbb

Harry Brelsford, ceo at smb nation, www.smbnation.com

Microsoft Small Business Specialist, MBA, MCSE, CNE, MCT, MCP, CLSE and CNP - whew - I am tired!

ps - funky groovy fall conference is less than 60-days away in Seattle!

###

Under the Hood RWW Architecture


Specialists like specialist in the professional world, perhaps because there is an element of mutual respect. So when this SBS specialist (yours truly) needed some help digging deeper in this subject area, I went to fellow SBS 2003 hands-on lab instructor Beatrice Mulzer from Florida. Beatrice is an RWW nicher and provided the screen shots in this section showing a glimpse of how things work under the hood with RWW.


First off, it helps to see a Visio diagram that outlines the RWW architectural experience. This is shown in Figure 8-10.


Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.


Figure 8-10


This diagram outlines the RWW mechanics.





Now for the step-by-step figures that bring definition to the chart above.


Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 8-11


Initial connection to SBS 2003 external Web page over port 80. Note HTTP in the Address field of Internet Explorer.





BEST PRACTICE: Note the above figure (Figure 8-11) assumes that you have selected the Business Web option on the Web Services Configuration page in the EICW. We did NOT do this back in Chapter 4 for the purpose of SPRINGERS. But please heed this advice, as imparted to me by the Microsoft program manager who owns this area. IN THE REAL WORLD, Microsoft discourages you from opening port 80 in the EICW via the Business Web selection. Rather, they’d rather have the address for RWW typed by external users be the FQDN followed by /remote (e.g., springers1.springersltd.com/ remote). The /remote component of the address makes the external listening port become 443 and the address is appended to HTTPS.


Another real worldism for NOT opening port 80 if you can help it. Beside exposing your IIS root to the world (and Web search engine crawling), you also expose RWW to Web search engine crawling. This is something you probably don’t want to do, as it might be the source of future vulnerabilities and attacks (as of this writing, this hasn’t been exploited). A really interesting exercise to see this in action is to go to Google and search on the terms “remote web workplace” and view the results. You’ll see pages of hits returned with Remote Web Workplace highlighted. These are SBS 2003 sites that have opened port 80 (again, likely via the Business Web selection on the Web Services Configuration page in the EICW). Stunning how many RWW sites you’ll see.


Finally, if you must have port 80 open because you really do host a business Web site and you’ve accepted the risks, then please consider using a robots.txt file to restrict Web search engine crawling. Details on robots.txt at www.robotstxt.org/wc/robots.html and in Chapter 10.


Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 8-12


Approving the security certificate (SSL) pop-up to log on to Remote Web Workplace (this process started by selecting the Remote Web Workplace link). Note the port switch from port 80 to port 443. This would be the case when you’ve published your root page via the Business Web selection on Web Services Configuration in the EICW.





Figure 8-13


The SSL pop-up was approved and the RWW logon dialog box appears. Session traffic is over port 443 and the HTTP protocol has switched to HTTPS at this point.





Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 8-14


An RWW session underway with HTTPS and port 443.





BEST PRACTICE: Did you look closely at the above figure and see the entry titled “View Server Usage Report”? How did that appear? If you have run the Monitoring Configuration Wizard (which you will do in Chapter 12) and the user (in this case Beatrice) has permission to view the server usage reports, this option will appear on the RWW page.


Notes:


Figure 8-15


Internally accessing the WSS Home page (Intranet) over port 443 under RWW. Protocol is HTTPS. Note that external access to WSS is over 444 (which isn’t being depicted in this figure).





Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 8-16


When you click the Connect to my computer at work, port 4125 is used for the Remote Desktop session traffic (note port 4125 doesn’t become active and listen until you click this Connect to my computer at work button; listening actually occurs on port 443). This is in addition to port 443 that remains open (ports 4125 and 443 are simultaneously open under this scenario). At this juncture, some background voodoo is performed by SBS to authenticate you and prove you are who you say you are (that’s about as well as I can explain it in this introductory text).





BEST PRACTICE: A common question in the Fall 2003 SBS hands-on labs related to which ports on a hardware-based firewall/router needed to be opened to allow RWW traffic through. RWW uses the following ports for its entire experience: 443, 444, 4125. Port 80 would be used if you published the root page (not recommended). And by the way, the other SBS-related port you’ll need open is 1723 (VPN, which I discuss more later).


By the way, you can see the port 4125 setting for RWW in the


Registry at:


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SmallBusinessServer\RemoteUserPortal


and look at the Port key where the REG_DWORD value is 4125.


Another common question concerns whether you must first establish a VPN connection to drill down and take control of your Windows XP Pro workstation via Remote Desktop. The answer is no. You are using RDP over HTTP, not VPN tunneling to access the Windows XP Pro workstation.


So hopefully a few pictures here have saved over a thousand words. I thought that by starting with a diagram and then witnessing the port traffic, you could “feel” RWW first hand under the hood. More of this good stuff in my advanced SBS 2003 book in the second part of 2004.

Monday, August 11, 2008

Remote Web Workplace (RWW) in SBS

Good Monday to u. I am posting up several pages per day of my Windows Small Business Server 2003 Best Practices (SBS) book and today we getting further into the mobility chapter. Specifically - I introduce Remote Web Workplace aka RWW (tomorrow we will delve into some procedures on it).

cheers...harrybbb

Harry Brelsford, Author, Consultant and CEO at SMB Nation www.smbnation.com

Microsoft Small Business Specialist (SBSC), MBA, MCSE, MCT and other non-sense!

PS - did u know I hold a fall conference for SBSers in Seattle? :)

###

Remote Web Workplace


Not only does travel, which is “remote” by its very nature, allow you to learn firsthand the mobility solutions in SBS 2003, it affords the opportunity to meet SBSers worldwide who have different viewpoints to contribute. Across this book, such diverse insights have been interjected in a technical realm. Every day, SBSers worldwide are thinking of ways to work with SBS 2003 not imagined by the SBS development team in Redmond, Washington, or yours truly on Bainbridge Island. In this case, the insight is humorous, wherein some SBSer known only to the SBSers above, started pronouncing RWW as “arrr-wuuu­wuuu,” an admittedly silly saying that seems to have found traction.


BEST PRACTICE: Rumor has it that, in Redmond, this area is called RUP (rhymes with pup, like puppy). If you call Microsoft Product Support Services (PSS), you could say RUP and arrr-wuuu-wuuu, but your coworkers who overhear the telephone call might look at you kinda funny.


BEST PRACTICE: Two initial thoughts on RWW are important to carry forward. First, when you access the external Web page that is exposed on the external interface of your SBS server machine, it is a Welcome Web site that greets you. This assume you opened Port


Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.


80 by selecting Business Web on the Web Services Configuration page in the EICW (not recommended). This is NOT RWW at this point. Rather, you select RWW from the Remote Web Workplace link from the Welcome Web site. Better yet, you can access RWW by addressing it via the FQDN/remote (discussed more later). Second, a point of confusion amongst SBS 2003 hands-on lab attendees in the Fall of 2003 was that RWW offers only the ability to take remote control of your desktop at work. That’s only part of RWW. This will be revealed herein, but it’s good to have this little chat first. Forward!

Sunday, August 10, 2008

Mobility, Remote Access in SBS 2003

Good day to you loyal readers! I am posting up a few pages a day from my book Windows Small Business Server 2003 Best PRactices (purple book) and today we start Chapter 8 on Mobility and Remote Access in SBS.

Enjoy....harrybbbb

Harry Brlesford | CEO at SMB Nation | www.smbnation.com

Microsoft Small Business Specialist (SBSC), MBA CNE MCT MCSE and much more :)

check out our big fall conference in seattle in early october!!!! SBS 2008 and EBS 2008 launch party...

###

Chapter 8 Mobility and Remote Connectivity


Something that is huge in SBS 2003 is the emphasis on mobile computing or mobility. Such emphasis is well founded. Why? Because it’s mobile computing that’s almost single-handedly leading us out of the early 21st century “tech wreck” that followed the late 1990s boom in the dot-com and Y2K eras. Read for yourself in the article titled “PC Shipments Rise 15 Percent, Driven By Notebook Sales” (W. David Gardner, CRN, http://crn.channelsupersearch.com/ news/tech/45278.asp) and “Study: Notebook Sales Surpass Desktops In Retail Market” (Edward F. Moltzen, CRN, http://crn.channelsupersearch.com/news/ tech/43012.asp). I think you’ll agree that the evidence is proof positive that the era of the mobile worker has arrived. And the SBS development team is spot-on for recognizing the application of this trend in the small business space and making mobility a huge part of SBS 2003. This chapter reflects that mobility paradigm as it’s implemented in SBS 2003. A special emphasis is placed on Remote Web Workplace (RWW), which will start the chapter and move into exploring Outlook Web Access, Outlook Mobile Access, remote use of full Outlook, and VPN connectivity. Along the way, I’ll weave in the Springer Spaniels Limited (SPRINGERS) methodology and toss a few best practices your way.


Mobility and SBS 2003 Sizzle


Starting in early July 2003, you, I, and everyone else were allowed to start playing with SBS 2003 (in its release candidate form). I built a few machines with SBS 2003 (including virtual machines running VMWare that I discuss in Appendix D) and started giving public speeches and demonstrations to clients. Something that sparked my audiences was the sizzle surrounding mobility. My prize client, a real estate company, approved the upgrade to SBS 2003 on the


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


spot after seeing only a few screenshots of Remote Web Workplace. The company owner, having just opened a new office in Phoenix, Arizona, (the main office is in Bellevue, Washington), was impressed by the simplicity of RWW. Similar reactions have been observed when people first see the mobility components of SBS 2003. See let’s move on and take a look.


What You Already Know About RemoteConnectivity


Go easy on yourself, mate! You’re completed just over 50 percent of this book and you probably are stronger in SBS 2003 than you’re willing to admit. So take a bow and kindly accept my virtual honor bow directed your way. You’ve already been configuring the remote components in SBS 2003 as per the following list.


• Windows Configuration during SBS 2003 setup. Peek back to Figures 3-18 and 3-19 and recall the early part of the Microsoft Windows Small Business Server Setup wizard. It was here that critical networking com­ponents facilitating mobility in SBS 2003 were laid down. An example is the implementation of the Remote and Routing Access Service (RRAS) . Figure 3-20 in the setup chapter displays more mobility stuff that is occurring, including the installation of remote client connectiv­ity components which will be used later.


BEST PRACTICE: By the way, now is as good of time to have a little chat about Texas terminology as any. While I refer throughout the book to the EICW, the folks at Microsoft in Redmond prefer to use the ten dollar acronym version and call it the CEICW for Configure E-mail and Internet Connection Wizard. That’s just too much for me to pronounce, but we’re talking about the same thing. To each her own!


• Remote Access Wizard. Revisit Figures 4-19 and 4-20 to see the short but sweet Remote Access Wizard in action. It was here you configured the server-side VPN settings. VPN connectivity is discussed a tad later in this chapter.


BEST PRACTICE: Remember that you can rerun the EICW and the Remote Access Wizard again and again. You’re not locked into a “mistake” if, after reading this chapter and working with the mobility and remote access capabilities of SBS 2003, you decide you might try something different in the real world. One example of a change you might make is to re-rerun the Remote Access Wizard to allow direct dial-in access, because you have since added a modem to the SBS server machine (said modem wasn’t present when you created the SBS server machine). This dial-in setting was revealed back on Figure 4-19.


• Add User Wizard/Set Up Computer Wizard. You should certainly know these wizards by now and readily recall that you had a few mo­bility and interaction points. First, some users you have created may have been set up with the way cool Mobile User Template (although in the SPRINGERS methodology, you set up simple users and power us­


ers - read the BEST PRACTICE below).


Note when the user will add a user member of the RWW group (which includes all templates by default), you receive a welcome message that describes RWW. You also have the election to deploy the Connection Manager VPN package to clients during the client computer setup (Con­nection Manager is discussed in a different section later in the chapter).


• Remote Assistance. You may have already explored a tad and discov­ered client-side capabilities such as Windows XP Professional’s Remote Assistance capability. This is the “cry for help” button that users can push to ping you and have you take over their desktop in a “PCAnywhere-like manner” to solve their problem. I discuss PCAnywhere later in the chapter.


Mind if a little advanced Remote Assistance (Windows XP Pro) discussion is interjected here? Remote Assistance uses Remote Desktop Protocol (RDP). Windows Messenger sets up the remote assistance session using the server-based session invite logic. Because of this, there is an issue with NAT addresses. So Remote Assistance includes additional logic to deal with the NAT scenario.


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


This logic simply tries to complete the TCP connection from both clients. This way, if one of the clients is behind a NAT, the connection can still be created and remote assistance occurs. If both clients are behind a NAT, the connection will not be established. You can read more on this issue with three TechNet KBase articles: Q301527, Q301528, Q301529.


BEST PRACTICE: Fear not if you’ve set up users via the simple User Template back in Chapter 4 and you want these users to take advantage of the cool mobility features at a later date. There is a way to elevate the privileges for these users. See the discussion in Chapter 11 about the Change User Permissions Wizard (you’ll use this as part of the SPRINGERS methodology).

Saturday, August 9, 2008

Final Thoughts: WSS in SBS 2003

Hi gang - today we reach the end of Chapter 7 of Windows Small Business Server 2003 Best Practices - which focused on Windows SharePoint Services (WSS). I have a few random coolisms and then end by pointing you to 'day SharePoint man Bill English.

enjoy the read...harrybbbb

Harry Brelsford | CEO at SMB Nation | www.smbnation.com

Microsoft Small Business Specialist (SBSC) MBA, MCSE,MCT, CNE and other stuff!

###

Additional WSS Cool Stuff


Enough SPRINGERS step-by-step for a now. I want you to, in your free time, click around WSS and explore the following cool features (I will drill deeply into these areas in my advanced SBS book, so consider this a sneak peek!). You will want to use some or all of these cool things in the real world of SBSing to truly add value.


Documents


Granted, you’ve already worked a lot with documents in this chapter, but I highly recommend you delve deeper into the documents area to learn more. By clicking on Documents and Lists, you can see the types of documents that are suggested for storage in WSS. You will appreciate the descriptive text.


BEST PRACTICE: The incoming fax archive and its functionality to


the fax service (more in Chapter 9) is unique to SBS 2003.


Pictures


This link defines itself but you might use this area as a photo archive.


Notes:





Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Resources


Here are some pointers to some additional SharePoint resources. This chapter, while capable for launching you into using WSS in SBS 2003, is only a start. You have much work ahead of you to master WSS!


Bill English books


Buy anything written by Bill English, a leading SharePoint consultant and author (he is also a SharePoint MVP). You can search on his name and the word “SharePoint” at Amazon to find his latest offerings. As of this writing, his current book, The Administrator’s Guide to SharePoint Portal Server 2001 (Addison-Wesley), is being updated.


By the way, a quick search on Amazon on the term “SharePoint” resulted in a shocking lack of books on this super cool application area (as of late 2003). I’m sure that’ll be remedied within a few weeks as more books hit the stands.


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


And how could you forget that I’ll provide more and more SharePoint secrets in the context of SBS 2003 in my forthcoming advanced SBS 2003 book. Keep monitoring www.smbnation.com for details.


SharePoint Web sites


Because I’m such a fan of Bill English books, you can’t be too surprised that I’d recommend his excellent SharePoint Web site: www.sharepointknow­ledge.com. Microsoft’s own site for SharePoint is excellent at www.micro­soft.com/sharepoint. Searching on Google with the term “SharePoint” resulted in numerous hits including www.sharepointtips.com, www.sharepointcode.com, www.sharepointsample.com, and many other sites! Many of these sites are excellent resources (and the most current resources available).


SharePoint courses


During the depths of the technology recession in the early 21st century, some members of the SBS development team whispered in my ear that I should take the Microsoft Official Curriculum course for SharePoint. And given that it was August (read slow dog days of summer) and my billable hours were down, I went back to school to learn SharePoint. I was led to believe I’d be glad I did once SBS 2003 shipped. The advice was well-founded, because once SBS 2003 hit the streets, I felt I knew WSS reasonably well. You should heed the same advice and go take some courses on SharePoint. As of this writing, the SharePoint curriculum is being revised and you are encouraged to check the Microsoft training site at www.microsoft.com/traincert for the most current course listings. For the record, I took course 2095: Implementing Microsoft SharePoint Portal Server 2001, and I was very pleased (note this is the old SharePoint product).


Bill English delivers SharePoint courses and workshops. Check www.sharepointknowledge.com for his latest offerings. As of this writing, Bill is offering a summit (a four-day course typically in Orlando, Florida, or Anaheim, California, for $2,495) at www.sharepointsummit.com (Figure 7-29).


Notes:


Figure 7-29


Take in some sun in Orlando, Florida to attend the SharePoint Summit!





There is also a SharePoint Boot Camp offering in the US. Visit www.sharepointexperts.com for details.


Summary


This chapter had both a technical and business message focused on WSS. On the technical side, you worked with many primary elements of WSS including the document management and Intranet portal features. On the business side, you were exposed to some value-added thinking about how WSS can extend the SBS network and provide real solutions to real business problems, such as managing information inside a small business. WSS is one of the more important and popular features in SBS 2003, so you should use it to deliver your services as an SBSer to end users in the organization.

Friday, August 8, 2008

SQL Server with WSS in SBS 2003

TGIF! Today is Friday and I am posting up a few pages from my Windows Small Business Server 2003 Best PRactices book for your public consumption! I plan to post up until SBS 2008 ships!

The topic today is integrsating SQL Server with Windows SharePoint Srevices (WSS) in SBS.

enjoy...harrybbbb

Harry Brelsford, CEO at SMB Nation, www.smbnation.com

Micosoft Small Business Specialist (SBSC), MBA and other stuff!

PS - we are holding an amazing Windows Small Business Server 2008 (SBS 2008) and Essential Business Server 2008 (EBS) party in Seattle over the weekend of Oct 4-6...help us LAUNCH!

###

SharePoint and SQL Server 2000


And you thought I’d wait until the final section of the book to delve into SBS 2003 premium edition matters (fooled ya). There is a little bit of horse and cart going on here. I can’t really wait until the SQL Server 2000 chapter to address WSS and SQL Server, so here goes.


The Big Advantage


There is a building consensus in the SBS community that WSS will sell a helluva lot of SBS 2003 premium edition. Why? Because SQL Server 2000 is contained with the SBS 2003 premium edition. And with SQL Server 2000, you can do more stuff with WSS. The big advantage of using SQL Server 2000 with WSS relates to the searching capabilities.


BEST PRATICE: In other words, and I stress, the searching capabilities ARE NOT available if WSS is deployed with WMSDE/MSDE (which is the configuration in SBS 2003 standard edition). WSS without the


Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.


searching capability could be considered a half-baked Alaska without the flame!


There is little debate that the SBS premium edition is the better fit for organizations serious about WSS. Think about it. How enthusiastically would WSS be embraced if users hit a limitation on searching the document corpus? It would be a show stopper!


BEST PRACTICE: So you’re now completely sold on the SBS 2003 premium edition. But what if you purchased the SBS standard edition first and are just now coming to appreciate the mystical powers of SQL Server 2000? How can you get from point A (standard edition) to point B (premium edition) without raiding the piggy bank and spending the lunch money? Simple. Use Microsoft’s step-up vehicle that basically charges you the delta difference between the standard and premium prices (as of this writing that would be $900 USD). Full how-to-buy details at the Microsoft SBS site: www.microsoft.com/sbs.


As a journalist, I’m honor bound to share a few limitations of WSS. There is limited file type search support out of the box (assuming you are using SQL Server 2000 that provides searching capabilities). Search will only be natively performed against the following file types.


• .doc

• .xls

• .ppt

• .txt

• .htm




In a moment, I point you to some iFilters to extend WSS’s document support. Another limitation is that you can’t search sub-site content from a top-level site. And only one language per database is supported. The language issue is


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


especially important to SBSer as the majority of SBS sales are overseas (where mulitiple languages are often spoken in a single country).


SQL Server 2000 Configuration


To use SQL Server 2000 with WSS, you’ll first need to install it using the installation guidance provided to you from the How to Install link (which launches a document titled “Completing Setup for Microsoft Windows Small Business Server Premium Technologies”) on the SBS 2000 premium edition fifth Disc splash screen. (Chapter 13 of this book is also an ally of yours installing this database application.) You’ll perform the actual installation by clicking the Install Microsoft SQL Server 2000 and Install SQL Server 2000 Service Pack 3a on said fifth Disc splash screen.


If you have the SBS 2003 premium edition, you’re welcome to install SQL Server 2000 at this time or wait until you’ve read this book and return to this page to implement WSS with SQL Server (remember to dog ear this page - get the SPRINGERS pun!?!?).


After SQL Server 2000 has been installed, you need to configure it for WSS. This is also documented, starting on page four, of the “Completing Setup for Microsoft Windows Small Business Server Premium Technologies” document. Specifically, you will complete the steps to:


• Upgrade the instance of MSDE used for Windows SharePoint Services (page 4). See Figure 7-25 for a key configuration page in this configu­ration process.

• Install SP3a to the SHAREPOINT instance of SQL Server (page 5). Be sure to catch the note at the bottom of page 5 for stopping the MSSQL$SHAREPOINT service when you upgrade the instance (you really have to do this). Don’t forget to restart this service (and the MSSQLSERVER service) after you complete this configuration step.

• Review the SQL Server Collation Settings discussion (page 9).




Notes:


Figure 7-25


Selecting the Full-Text Search option is critical to invoking the advanced search capabilities in WSS when combined with SQL Server 2000. Please don’t miss this step.





So how about a before-and-after view (like weight loss ads in general interest magazines). Before you installed SQL Server 2000, if you went to SharePoint Central Administration on the SPRINGERS1 server machine and tried to configure full-text searching, you received the message seen in Figure 7-26. But as you can see in Figure 7-27, after SQL Server 2000 was installed configured, SQL Server 2000 is now providing the default engine for WSS, Full search capabilities are now enabled. Right on!


Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 7-26


Before. Look at the message on the far right column.





Figure 7-27


After. It’s SQL Server 2000-based search time, baby! When you click OK here, you will get a progress screen as the change is made.





Advanced Searching Topics


So now that you’re using the search capabilities of SQL Server 2000 with WSS, you might be interested in more factoids.


• Mechanics. WSS allows SBS users to search all Web site content on a virtual server basis. In SBS 2003, the WSS virtual server is titled “CompanyWeb.” Subwebs inherit the search settings from parent sites.

• Home page search field. When you integrate SQL Server 2000 with WSS, a new search field appears on the Home page in the upper right. This search field is not present prior to integrating SQL Server 2000 with WSS.

• IFilters. Did you notice a few pages back that the document search capabilities were Microsoft-centric (e.g., a Word document with the .doc extension). What would you do if you needed to search a third-party document such as an Adobe Acrobat PDF file? You would go to www.sharepointknowledge.com (a resource I discuss in the next major section) and click the IFilters link on the left. You would then see the IFilters and Protocols page (Figure 7-28) where numerous IFilters for Abode, AutoCad, WordPerfect, and lots of other file formats are listed (even ZIP files).




Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 7-28


This is your “go to resource” for IFilters that allows different document types to be searched in WSS when SQL Server 2000 is installed and configured.





The Case for SharePoint Portal Server


Microsoft’s SharePoint site is a great resource to compare WSS versus its big brother product, SharePoint Portal Server (SPS). There is an excellent white paper that allows you to decide when to deploy either of the SharePoint offerings. Visit www.microsoft.com/sharepoint/evaluationoverview.asp and download and read SharePointEvaluate.doc.


BEST PRACTICE: Time for a tad of plain Texas talk. WSS is going to be the best fit for SBSers in 99 percent of the cases. Why? Because SPS is really more oriented toward the enterprise with multiple sites, etc. SPS costs a lot of money ($5,619 USD) which is several times the cost of SBS 2003.


There was a time, in the spring of 2003, where it looked like the


cool stuff (like searching and robust document management) was


Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.


only going to be available with SPS. But Microsoft changed its mind


and put much of the cool stuff, the stuff important to SBSers, down


into the WSS product. Amen!


Current Topic: SharePoint versus Content Management Server


During the Spring 2003 GTM hands-on labs, students asked what some of the differences were between SharePoint and Content Management Server. Aside from pointing out feature and user interface differences, I replied that the difference was philosophical. SharePoint (WSS, SPS) can be viewed as an internal tool (although as you’ll see in Chapter 8, it can be accessed externally with Remote Web Workplace) and Content Management Server is focused externally to rapidly post content to public sites.


In mid-October 2003, CRN published an article that discusses the Content Management Server team joining the SPS group. If you’d like to read it, visit http://crn.channelsupersearch.com/news/crn/45155.asp. Synergy between the two products is another key point in that article.

Wednesday, August 6, 2008

Office and SBS Integration Points with Windows SharePoint Services (WSS)

Happy hump day - we are almost nearing the end of Chapter 3 in Windows Small Business Server 2003 Best Practices wherein we are studying Windows SharePoint Services. As you know - I am posting up a few pages per day from my book for your pleasure.

enjoy....harrybbbb

Harry Brelsford | ceo at smb nation | www.smbnation.com

Microsoft Small Business Specialist (SBSC), MBA, MCSE, MCT and other stuff!

###

SBS 2003 Integration with WSS


Those “dev dudes” on the SBS 2003 development team slipped in a few points of integration between SBS 2003 and WSS that need to be highlighted.


• Remote E-mail Access (under Links). This allows you to view your Exchange-based e-mail via Outlook Web Access (Chapters 6 and 8 dis­cuss this area more).

• Remote Server Management (under Links). This spawns a Terminal Services session to manage the SBS 2003 server machine (Chapters 4, 8, and 11 discuss this functionality more).

• Add User Wizard/Add Template wizard. Adding users and templates automatically get WSS roles

• Client and Server home page setting

• EICW: publishing intranet takes care of publishing the intranet virtual server in IIS

• Import Files Wizard from Import Files link from the Internal Web Site.




Office 2003 Integration with WSS


Something I plan to emphasis during the SMB Nation Summit worldwide tour in 2004 (www.smbnation.com) is the integration of Office 2003 with SBS 2003. Nowhere is this integration more apparent than how Office 2003 ties into WSS. In this section, I’ll discuss Shared Workspace, metadata promotion, and Meeting Workspaces and give examples of Access 2003 and FrontPage 2003 integration.


Note that I won’t dwell on another integration feature, Document Workspace sites, because that’s what we’ve basically been working with in this chapter. But for the record, Document Workspaces are clearly an Office 2003/WSS integration point.


Shared Workspace


You have already seen one such tie-in already. Revert back to Figure 7-11 and observe the Shared Workspace element on the right-side of the Word document.


This is one major way Office 2003 and WSS interact. A workspace is an area, hosted on a server (read SBS 2003), where colleagues can share documents, information, and hugs. The features of a shared workspace include document libraries, task lists, links lists, members list, and e-mail alerts. All shared workspace tasks can be performed in Office 2003 applications.


BEST PRACTICE: The Shared Workspace task pane opens automatically when you open an Office 2003 document that is stored in a WSS document library. In addition to displaying Web site data in the Members, Tasks, Documents and Links tabs, the Shared Workspace pane provides information about the active document on the Status and Document Information tabs:


The Status tab is pretty darn cool. It lists important information such as whether the document is up to date, in conflict with another member’s copy, and whether it is checked out. The Document Information tab tells you stuff like modified date, etc.


Metadata promotion


Another Office 2003 integration point with WSS is metadata promotion. To understand the context of this discussion, consider the following. In a traditional document management solution, each document has a profile. The document profile consists of descriptive fields with information about the document (i.e., what the document is about). These fields are called metadata.


BEST PRACTICE: You’ve likely worked with profiles and metadata at the document level for a long time and not necessarily even known it. How? Simply open any existing document from any Microsoft Office product (e.g., Word) and select File, Properties. The document property sheet that appears is a profile and the data in the fields (such as your name in the Author field) are metadata.


In a WSS document library, the columns of the document library (list columns) are the fields for the document profile. If you wish to add a field to the document profile for the library, you simply add a column to the WSS document library. The user-created columns of metadata fields automatically become populated


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


fields in the file properties of the document. It’s that easy! Whenever a user uploads a document to the library, she will be prompted to complete the metadata for the document. Note if you upload a document and make some off-line changes to the file properties of the document, said changes will be added as metadata in the document profile on the WSS document library.


BEST PRACTICE: I’m really starting to cross a boundary here and move into a discussion on InfoPath, an Office 2003 family member. InfoPath is an editor that looks kinda like Word and is a backend application that manages forms. These forms are akin to the file properties for a document except these forms use the data via XML to create much more meaningful metadata (a property sheet in Word just sits there).


For example, a company uses InfoPath and has a forms library with expense reports. The employee opens the new expense report form, enters data and saves it. This structured data is extracted by the accounting system.


More on this with specific procedures in my advanced SBS 2003 book.


Meeting Workspaces


A Meeting Workspace is a Web site for centralizing all the information and materials for one or more meetings. Prior to the meeting, attendees use the workspace to publish an agenda, attendee list, and relevant documents. During or after the meeting, the workspace can be used to publish meeting results and track tasks. A user is typically invited to the meeting via an e-mail request and they click a link to join. You will recall from the SBS 2000 Best Practices book in the Exchange Server chapter when I turned you on to Exchange Conferencing Server that this type of invitation with a link capability was present in that conferencing environment.


There are five types of Meeting Workspace templates in WSS:


• Blank Meeting Workspace. Requires customization to meet your requirements


Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.




• Basic Meeting Workspace. Includes all the basics elements to plan, organize, and track your meeting. Predefined lists (and associated Web Parts) include: Objectives, Attendees, and Agenda.

• Decision Meeting Workspace. Similar to the Basics Meeting Workspace but also focuses on the ability to review document and record decisions during the meeting. Additional lists beyond the “basics” in­clude Document Library, Tasks, and Decisions.

• Social Meeting Workspace. Oriented toward planning parties and social events. The lists include Attendees, Directions, Image/Logo, Things to Bring, Discussions, and Picture Library.

• Multipage Meeting Workspace. This is the same as the Basic Meet­ing Workspace but allows multiple pages.




You can create a Meeting Workspace either in WSS or via Outlook 2003. From WSS, simply click Create (from the top link bar) and select Sites and Workgroups beneath Web Pages. Then complete the information for the workspace site you want and click Create (when writing this I created a monthly meeting site for SPRINGERS and I encourage you to do the same). Then select a template on the Template Selection page (I selected the Decision Meeting Workspace). Click OK. And that’s it, Your screen should look similar to Figure 7-22.


Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 7-22


Something not widely emphasized in other SBS 2003 learning avenues, like the hands-on labs, is the Meeting Workspace capability of WSS. Use it!





BEST PRACTICE: The online help in WSS has excellent support for


Meeting Workspaces and I encourage you to delve deeper here.


Access 2003 Integration


First off, it’s big assumption time. I’m assuming that you’ve run (not walked) and installed Office 2003 on your client computer to track with me (you heard me mention this in other chapters such as Chapter 6 in the Exchange and Outlook discussion). That said, let me explain how one of the killer applications, Access 2003, integrates with WSS.


There are five integration points between Access 2003 and WSS:


• Export to WSS. Here you simply specify a site during the Access 2003 export keystroke sequence and the fields are mapped automatically.

• Import from WSS. This is a wizard-driven import of Lists and Views of Lists from WSS.




Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.




• Read/Write live link to WSS. Think of this as revisiting Dynamic Data Exchange (DDE) and Object Linking and Embedding (OLE).

• From WSS to Access 2003. WSS exports stuff to Access 2003. Access 2003 then creates a linked table and reports.

• Lookup field support. Full support for the database lookup function in WSS.




Excel 2003 integration


Something that’ll excite many readers is the simplicity with which you can send Excel 2003 data to a WSS list. You’ll do that right here, right now.





1. Log on as NormH at PRESIDENT with the password Purple3300.




2. Start Microsoft Excel 2003 from Start, All Programs, Microsoft Office, Microsoft Office Excel 2003.




3. In Excel 2003, create a simple spreadsheet with financial information.




As you’ll see in a moment, I created a quick-and-dirty DuPont ratio model (if you don’t know what that is, no worries - it’s an MBA thang!).




4. Select Data, List, Create List. The data is converted to a list.




5. Select Data, List, Publish List. As seen in Figure 7-23, on the Pub­lish List to SharePoint Site - Step 1 of 2 pages, complete the Address field to point to the Breeder1 site you created earlier (http:/ /companyweb/breeder1) and then select the Link to the new SharePoint list checkbox. In the Name field, give a descriptive title such as SPRINGERS DuPont Ratio Model and under Description type something like It’s Norm’s MBA in action!




Notes:


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


Figure 7-23


You are creating the list to publish to WSS.








6. Click Next.




7. Confirm the column format on the next page (Step 2 of 2) and click Finish.




8. Click OK when the Windows SharePoint Services dialog box notifies you the list was successfully created.




9. Launch Internet Explorer from Start, Internet. The Springer Span­iels Limited Home page appears.




10. Click Breeding Workspace under Links. Click Lists in the left col­umn. Select SPRINGERS DuPont Ratio model under Create List.




11. Observe the list in Figure 7-24. This is Excel 2003 data being pre­sented in WSS and it’s active. Go ahead and horse around here. Change values, insert a row, add data, and see how it affects the list in WSS and Excel 2003. Yee-haw!




Figure 7-24


This is a great way to integrate Office 2003 and WSS in SBS 2003. This example could be the basis for you to go forth and create an EIS (discussed in this chapter) on the SBS network.





BEST PRACTICE: Another cool SBS 2003 WSS and Office 2003 integration point involves looking at a list in a data sheet and copying and pasting stuff from Excel. Here is what I mean. Create a data sheet in WSS and click the List in Datasheet option. Then open Excel 2003 and create a business spreadsheet populated with business data. Then right-click on your Start toolbar and select Tile Windows Vertically. At this point, the data list in WSS and the business spreadsheet in Exchange will be lined up. Then drag and drop the business data from Excel into the data list in WSS. This integration method, only possible with Office 2003 or higher, is another way to transfer data and is very efficient.


Visit www.microsoft.com/technet for the latest updates for any Microsoft product.


An individual I know who uses this approach likes it because it allows you to see the Excel-based business data line up correctly in the WSS data list. Seeing is believing.


FrontPage 2003 integration


This integration point is very simple: good looks! FrontPage 2003 can best be integrated with WSS is to make the pages look better. Kinda like the popular American television show Extreme Makeover meets WSS in SBS 2003! More conservative folk would say it allows you to create professional-looking, high-quality pages. Enough said.


BEST PRACTICE: To the extent practicable, PLEASE try to have all of your client machines upgrade to Office 2003. I propose that the integration of WSS with Office 2003 is the “killer application” or a sufficient reason to undergo this upgrade. Am I all wet on this proposition? Then voice your opinion to me at sbs@nethealth­mon.com!


Note my advanced SBS 2003 book will have much more discussion on Office 2003 and even SBS-specific integration with WSS! Stay tuned.