--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/BY5PR04MB64059FD98E3EF848EA807A39CC4B9%40BY5PR04MB6405.namprd04.prod.outlook.com.
Another stab in the dark?
And I’m just throwing this out as I have never tried to do what the OP is asking.
How about File Server Resource Manager and a custom file screen for PDFs?
I see there is a run a command, so if there is a way to pass the file name to that command, maybe there is a command line switch for something other than Adobe Acrobat Reader (foxit or some other pdf reader) that will print a file. Looks like Adobe removed the command line print switch.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/1ADD796D2529E94DB4552E7C1F12A21A01BE87140C%40ATLEXCH04.byers.local.
Sysmon EventID #11 [FileCreate] (if not mentioned/considered already)?
System Monitor (Sysmon) is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log. It provides detailed information about process creations, network connections, and changes to file creation time.
Sysmon - Windows Sysinternals | Microsoft Docs
DonP
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/MN2PR04MB64169FBE0EF7DD1714D640E9CC509%40MN2PR04MB6416.namprd04.prod.outlook.com.
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/MN2PR04MB64165B08957E250CAE87248CCC529%40MN2PR04MB6416.namprd04.prod.outlook.com.
I had to move one of my domains from a private domain name to a public domain. My public and AD domain is - - -fay.com. Godaddy is hosting our publicly accessible website. The only reason to go from a private internal domain name to a public one is to allow me to buy a certificate for the internal website which is not exposed to the real world. Requirement of some practice management software.
I have two internal AD domains, - - -fay.com and dhc.lan I have conditional forwarders and trust relationships between the two domains. I can ping the workstations on - - -fay.com by fully qualified name with all the dots but not by NetBIOS name. Not particularly unexpected. The two servers I have on - - -fay.com I have entries in AD DNS on dhc.lan so I can ping them by NetBIOS name.
The blah blah blah is someone on the dhc.lan edits the website for - - -fay.com. She can get to Godaddy web hosting product and edit but cannot audit her changes by opening a browser on her dhc.lan workstation. I tried guessing what ip I might make over on the - - -fay.com internal AD DNS and www.- - -fay.com web page never comes up. Pings are successful. I have tried all three web page listed when I use mxtoolbox.com GoDaddy support said I have a www entry. None of the ip listed got me to the company external website. Yes I did dns cache flush and ipconfig/flushdns on both AD servers so new pings to www.- - -fay.com came up with a different ip each time I made an entry in the DNS manager over at AD - - -fay.com
Another thing to note. I have a dns entry for remote.- - -fay.com that pops up properly on mxtoolbox. That remote access has been killed. Too many foreign attacks coming in. Now we use Duo and VPN if someone needs to get in and look at internal resources. Anyhow when I do the mxtoolbox query for www.- - -fay.com it comes back with the same answer as a query to - - -fay.com. Does that mean that there isn’t technically a proper www entry at Godaddy’s DNS and they are just using some alias of some sort? Kind of like a http goes to https these days.
I suspect I may be silly trying obfuscate the domain name as I am blocking things at the firewall and the public DNS has no entries for our private internal AD domain.
Note that I am not doing any Azure. I am working old school low cost up to date with patches Windows servers, no expensive cloud computing, cloud domains, cloud O365.
Any browser query to https://www.- - -fay.com pops over to https://- - -fay.com. If www had proper entries at GoDaddy’s DNS manager then maybe it could work?
Sorry for the long ramble, trying to toss out all relevant or possibly relevant observations.
By the way if I know you and you are curious I can email you the real domain name. Technically I only “know” a few folks from the SBS groups.
Jim Behning
404-643-8863
I can’t parse these 2 sentences:
I have tried all three web page listed when I use mxtoolbox.com GoDaddy support said I have a www entry.
Whut?
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/00CAC7E9-1891-4C9D-8CF9-532AF0CB42A0%40hxcore.ol.
I think, if I understand things correctly, I would have just set up an AD Forward Lookup Zone for the public domain and set a DNS A for www to point to the internal server’s IP?
In SBS we’d have remote.domain.com point to the SBS LAN IP while outside the LAN it pointed to the WAN IP via hosted DNS.
A trusted third party certificate would be used for remote.domain.com without issue.
I’m not sure I’m understanding the reason behind establishing a full ADDS Forest/Domain for this purpose?
Philip Elder MCTS
Microsoft High Availability MVP
E-mail: Phili...@mpecsinc.ca
Phone: +1 (780) 458-2028
Web: www.mpecsinc.com
Blog: blog.mpecsinc.com
Twitter: Twitter.com/MPECSInc
Skype: MPECSInc.
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Jim Behning
Sent: January 12, 2022 11:03
To: ntsys...@googlegroups.com
Subject: [ntsysadmin] Split domain dns entries and conditional forwarders
I had to move one of my domains from a private domain name to a public domain. My public and AD domain is - - -fay.com. Godaddy is hosting our publicly accessible website. The only reason to go from a private internal domain name to a public one is to allow me to buy a certificate for the internal website which is not exposed to the real world. Requirement of some practice management software.
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/00CAC7E9-1891-4C9D-8CF9-532AF0CB42A0%40hxcore.ol.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/c3f66c36346b418f98ce5d089fa5919a%40smithcons.com.
Sites will have redirects for www to @. That’s probably what’s happening. Remove the redirect and set the site to default to www. Instead of @.
Philip Elder MCTS
Microsoft High Availability MVP
E-mail: Phili...@mpecsinc.ca
Phone: +1 (780) 458-2028
Web: www.mpecsinc.com
Blog: blog.mpecsinc.com
Twitter: Twitter.com/MPECSInc
Skype: MPECSInc.
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CALOTwGYbsJTOzWrxN2yFQw6%3DA2uyK%2BP%2BGC2Js%3DoMfR%2B2-CBZ5Q%40mail.gmail.com.
Concur.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Philip Elder
Sent: Wednesday, January 12, 2022 2:44 PM
To: ntsys...@googlegroups.com
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/f0658bc3952748f7a455eafcb16c395e%40MPECSInc.Ca.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/713093ef1a5c416bbe876022993c0402%40MPECSInc.Ca.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/f0658bc3952748f7a455eafcb16c395e%40MPECSInc.Ca.
Yes, and that’s what is in my explanation as far as the split DNS setup we received with SBS.
We still run with split DNS across the board unless we’re setting up a greenfield then we run with a public domain that’s set up for the purpose with a 10 year registration.
So, the site is hosted internally. That means that:
Our lab setup is not online at the moment otherwise I’d snip the DNS forward lookup zones (FLZs) to give a visual.
SSL certificates for www.MyDomain.Com and/or MyDomain.Com are moot in that it does not matter where the site is hosted internal or external so long as the DNS is split correctly.
If both Internet and Intranet are named the same: MyDomain.Com and the site is hosted @ (which is MyDomain.Com) then you’re in big trouble. There’s hoops to run through in order to get it to work, but both the same means MyDomain.Com = DC IP.
As to the site’s setup, I find folks that code sites like to have www redirected to @ (MyDomain.Com) and code the site accordingly. Thus, to flip the site to www.MyDomain.Com with a redirect for @ to same the folks that manage the site need to update their code.
I hope that makes things clearer?
Philip Elder MCTS
Microsoft High Availability MVP
E-mail: Phili...@mpecsinc.ca
Phone: +1 (780) 458-2028
Web: www.mpecsinc.com
Blog: blog.mpecsinc.com
Twitter: Twitter.com/MPECSInc
Skype: MPECSInc.
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com> On Behalf Of Jim Behning
Sent: January 12, 2022 12:51
To: ntsys...@googlegroups.com
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CALOTwGb2yUQzFtsq095gWHC48RrXpA13%3DP7xPn1oGycEBE%3DVjg%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/eb461b06eac04a86afc9d16c1fdcf831%40MPECSInc.Ca.
There should be an edit button on the right-hand side of the window
Click it.
Change the CNAME to an A record and change the value to the IP you want.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CALOTwGbxQ--oiZVDuqXxFLbWxADrF1jF2Zf4otcLqhULj0YDiQ%40mail.gmail.com.
Okay, I see the problem here.
Let’s back the truck up to the beginning.
Internet: DNS A/CNAMEs point to Web Site IP on the WAN port that publishes to the IIS/Apache/NGINX server hosted internally.
^^^
This does NOT get touched.
What is a SPLIT DNS?
Answer: It is where the INTERNAL DC/DNS setup gets split up into:
INTERNAL: MyDomain.Local
EXTERNAL: MyDomain.Com
BOTH of the above Forward Lookup Zones would be hosted on the internal domain’s Domain Controllers that host the DNS Role.
One does NOT touch the Internet DNS settings.
All of the configuration is done on the internal network’s DC/DNS servers.
I hope that makes things clearer?
Philip Elder MCTS
Senior Technical Architect
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CALOTwGbxQ--oiZVDuqXxFLbWxADrF1jF2Zf4otcLqhULj0YDiQ%40mail.gmail.com.
Hey Erich, I’ve not personally spent time with sysmon but it gets mentioned in InfoSec circles quite a bit and special mentions by SwiftOnSecurity GitHub - SwiftOnSecurity/sysmon-config: Sysmon configuration file template with default high-quality event tracing
Regards
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/MN2PR04MB64165B08957E250CAE87248CCC529%40MN2PR04MB6416.namprd04.prod.outlook.com.