RPC Client Access Logs - Throttling Policy
Trying to get useful information on who is being throttled by a specific policy.
Created the policy: New-ThrottlingPolicy -Name LimitMessagesSent -RecipientRateLimit 5 -ThrottlingPolicyScope Organization
Enabled RPC Client access logging: <add key="LoggingTag" value="ConnectDisconnect, Logon, Failures, ApplicationData, Warnings, Throttling" /> and bounced the service.
Forced the throttling by sending many emails.
Opened the log and found this:
2014-07-23T21:24:28.820Z,40,1,/o=Exch/ou=Monitoring Mailboxes/cn=Recipients/cn=HealthMailbox872ac0efb9c44ddf9d0d1d4f0e4dbb55,,Microsoft.Exchange.RpcClientAccess.Monitoring.dll,15.0.0.0,Cached,,,,ncacn_http,Client=Microsoft.Exchange.RpcClientAccess.Monitoring,,,,,00:00:00.0160000,"BS=Owner:Sid~CAMPUS\SM_6f8aaf3f77f94192a~Rca~false,Conn:1,MaxConn:40,MaxBurst:150000,Balance:149988.3,Cutoff:Unlimited,RechargeRate:900000,Policy:LimitMessagesSent,IsServiceAccount:False,LiveTime:00:02:00.0650494",,,
Makes no mention of the user that was throttled. How can I troubleshoot if I cannot see the user in the logs?
Thanks.
Hi
We need to assign this newly created throttling policy to the end users else it will not be effective.
The below commands will help you out.
Use below command to assign this newly created throttling policy to the user
Set-Mailbox MBXName -ThrottlingPolicy LimitMessagesSent
Run the below command to ensure that the throttling policy is assigned
Get-Mailbox MBXName | Select Throttling Policy
Remember to mark as helpful if you find my contribution useful or as an answer if it does answer your question.That will encourage me - and others - to take time out to help you Check out my latest blog posts on http://exchangequery.com
Similar Messages
-
RPC client access log and IIS log, difference??
RPC logging is in "C:\Program Files\Microsoft\Exchange Server\V14\Logging\RPC Client Access" by default.
And IIS logs is in "C:\inetpub\logs\LogFiles\W3SVC1" by default.
Just want to know which client will generate which Log?
For example, exchange server 2010 supports:
Outlook Web App
Outlook anywhere
Exchange ActiveSync
POP3 and IMAP4
Autodiscover
So far as I know, "exchange activesync" is always appear in IIS log. But outlook users(all in domain), most of them are always appear in RPC log, but sometime a few users appear in IIS log.
For example:(IIS log)
2014-03-31 00:01:51 172.23.0.100 POST /EWS/Exchange.asmx - 443 TEST\alice 172.26.0.41 Microsoft+Office/14.0+(Windows+NT+6.1;+Microsoft+Outlook+14.0.7116;+Pro) - 200 0 0 312
RPC log:
2014-03-31T00:42:09.964Z,1024,1,/o=first organization/ou=exchange administrative group(fydibohf23spdlt) /cn=recipients/cn=alice,,OUTLOOK.EXE,14.0.7108.5000,Cached,,,ncacn_http,,OwnerLogon,0,00:00:00.0156287,,
I want to understand the logging rules, please help?Hi, Steve:
Thanks very much for your reply. I have a question to your reply here.
RPC-->Outlook clients, and then EWS(includes Outlook 2011??) What's the difference between Outlook clients and Outlook 2011(I think it should be 2010?), but is that Outlook 2010 not belong to 'Outlook clients'?
Best Regards,
Ryo -
No new mail notification in Outlook - CAS Exchange RPC Client Access problem
Hi, we're facing this problem:
Users start complaining they suddenly don’t receive new mail notifications in Outlook (2010/2013) anymore
Inbox does not show the new mail either
When the user changes folders in outlook, the new mail does show in the Inbox folder
Restarting Outlook shows the new mail as well.
The same new e-mail arrives instantly (with notifications) in Owa and on mobile devices
Sometimes the new mail notification pops up after a longer period of time (from 30 seconds to 10 minutes). But more often not at all.
This issue seems to occur at random. We’ve been problem free for a week, and sometimes it comes back three times a day.
Clients running Outlook 2010, 2013 cached or online, on site and off site. So it seems server related, not client.
It was seen first around January 8th. We did not make any changes around that time that we can link to this problem.
Only one CAS server (EXCH1-RTD) shows this issue. CAS servers on other sites are ok
EXCH1-RTD has CAS and HUB transport roles. The same site has two mailbox only servers. EXCH2-RTD (mailbox server for normal mailboxes). And EXCH3-RTD (mailbox server for archive mailboxes)
No entries in the event logs that seems to be related
As the problem only occurs with Outlook clients, I suspected RPC issues. We cannot gracefully stop the “Microsoft Exchange RPC Client Access” service on EXCH1-RTD while the issue occurs. We
can only kill the process and restart the service, solving the issue instantly.
What we’ve tried until now:
Updated all Exchange servers from Exchange 2010 SP3 RU6 to RU8-v2 (server OS=W2K8R2)
Updated all Exchange servers to latest critical Windows updates
Recalculated requirements using MS Sizing tool. Upgraded EXCH1-RTD VM from 8GB and 2 vCPU (1 core/cpu) to 16GB
and 4vCPU (1 core/cpu)
Ran various perfmon counters and compared them with other Exchange servers, not finding any obvious anomalies.
Any ideas would be greatly appreciated!
RonHi Ron,
From your description, OWA works well, the issue is related to Outlook side. In your case, I recommend you use Outlook safe mode to determine whether the issue is related to add-ins. If the issue persists, you can create a new profile to check the result.
Hope this can be helpful to you.
Best regards,
Amy Wang
TechNet Community Support -
Microsoft Exchange RPC Client Access will not start.
A few days ago all my outlook clients were disconnected. Looking into it and the Microsoft Exchange RPC Client Access service had died. Tried several restarts of the system but the service will not go into a running state. It always says
Starting. But it is actually terminating and restarting. In the system log get Event 7031 - "The Microsoft Exchange RPC Client Access service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be
taken in 5000 milliseconds: Restart the service." I can't find anything else on the error in any log file. Some other info not sure if this related or not. The contentIndex are corrupt and will not rebuild. Get a state of "Failed"
with an error message of "The database has been dismounted." Also at time the system is very sluggish. Mostly right after a reboot for an hour or two. Details about the system are; Running Exchange 2013 SP1 on server 2012 R2. All
roles on one machine. About 20 mailboxes. Database is about 40gig. No VM, just a normal server. plenty of diskspace, memory and CPU. The system has been running fine for about a year. Also, mobile devices and OWA work fine. Mail flow
is fine. Outlook just can't connect.
Tried restoring the databases and logs from before the problem started but that did not help.
Not sure what to try from here.
ThanksHi,
Please check whether an unavailable Public Folder database is pointed to in your Exchange 2013 mailbox database as the default public folder database setting.
If there is no legacy public folder database and you are working in a pure Exchange 2013 environment, please remove the default public folder database setting on each Exchange 2013 Mailbox database that points to the deleted public folder database object
in ADSI Edit:
1. Open ADSIEdit, Connect to the Configuration container.
2. Expand Configuration, expand CN=Configuration,DC=Domain,DC=com.
3. Expand CN=Services -> CN=Microsoft Exchange -> CN=Domain -> CN=Administrative Groups -> CN=Exchange Administrative Group -> CN=Databases.
4. In the right hand pane you will see a list of databases. Right-click the listed database object -> Properties.
5. Check whether the msExchHomePublicMDB value is set to an unavailable value. If you see reference to the old database, please clear the value.
6. Click OK.
7. Check the rest of the databases to make sure that they are not populated in the same way.
For more information about this, please refer to:
http://support2.microsoft.com/kb/2962915/en-us
Regards,
Winnie Liang
TechNet Community Support -
JAX-RPC client access a JAX-WS services
Hello all,
There is a little problem I had with webservices and googling for a solution has not help so far.
I am accessing a JAX-WS webservice from a J2SE 1.4.2 JAX-RPC client application and getting a NoSuchMethodError error from one of the stubs at runtime. The method call is rather a HelloWorld concept but it has not been possible.
This are the step I took (I am using netbeans 6.0).
1. I downloaded the JAX-RPC plugin on netbeans
2. Download the stubs using the wsdl url. I am using the netbeans wizard for this process.
3. Write my code for get a handle to the endpoint. Using the ServiceFactory.loadClass().
4. Call the method on the
Can anyone please help me.To make things a little more clearer, this is a post of the error gotten at runtime...
java.lang.NoSuchMethodError: java.util.Collections.emptyList()Ljava/util/List;
at com.sun.xml.messaging.saaj.soap.MessageImpl.<clinit>(MessageImpl.java:755)
at com.sun.xml.messaging.saaj.soap.ver1_1.SOAPMessageFactory1_1Impl.createMessage(SOAPMessageFactory1_1Impl.java:47)
at com.sun.xml.rpc.soap.message.SOAPMessageContext.createMessage(SOAPMessageContext.java:137)
at com.sun.xml.rpc.client.StreamingSenderState.<init>(StreamingSenderState.java:30)
at com.sun.xml.rpc.client.StubBase._start(StubBase.java:92)
at mck.practise.oracle.plsql.PlsqlService_Stub.sayHello(PlsqlService_Stub.java:54)
at mck.practise.oracle.plsql.HelloWorld.sayRPCHello(HelloWorld.java:34)
at mck.practise.oracle.plsql.HelloWorld.main(HelloWorld.java:22)The suprising thing is that if I change the application's java platform from JDK 1.4 to Java 5 using the netbeans projects property window, everything works fine.
Can anyone still suggest on this.
Regards, -
How do I create a Client Access Log in to unique pages
I'm using DW8 on Mac OSX with MySQL & phpmyadmin. I've
created a simple log in page for room for one password and an enter
button. This works, but each name in my database goes to the same
destination page as set up in Server Behaviors under Log In Users
and I need them to go to separate pages, but can't find where to
input the separate links for each password.
Can anyone help with this?You might do something like this... on the destination page
you would have
this:
if user hank then do this
if user george then do this
Now you could, in your database have information that would
"customize" the
page... something like:
Hi <user name>!
You last visited us on <last visit date>.
Your order <order number> shipped on <order shipped
date>.
Etc...
"Gina Hanzsek" <[email protected]> wrote in
message
news:e404em$3kj$[email protected]..
> I'm using DW8 on Mac OSX with MySQL & phpmyadmin.
I've created a simple
> log in
> page for room for one password and an enter button. This
works, but each
> name
> in my database goes to the same destination page as set
up in Server
> Behaviors
> under Log In Users and I need them to go to separate
pages, but can't find
> where to input the separate links for each password.
> Can anyone help with this?
>
> -
Client Access Server Logs that capture Outlook Anywhere Connections
Do Exchange 2010 Client Access Servers log Outlook Anywhere connections? Since it's RPC over HTTP, I'm thinking these would be in the IIS logs but don't see any entries in those logs that pertain to Outlook Anywhere. What logs contain Outlook Anywhere connections?
I suspect I have a CAS server that isn't working properly pertaining to OA and need to be able to review some sort of logs to confirm.
ThanksARay,
Do the below basic checks-
Running the Test-OutlookConnectivity cmdlet. The cmdlet tests for Outlook Anywhere (RPC over HTTP) and TCP/IP connections. If the cmdlet
test fails, the output notes the step that failed.
Running the Outlook Anywhere connectivity test using the Exchange Remote Connectivity Analyzer (ExRCA). When you run this test, you get a detailed summary showing where the test failed and what steps you can take to fix issues.
Both tests try to log on through Outlook Anywhere after obtaining server settings from the Autodiscover service. End-to-end verification includes the following:
Testing for Autodiscover connectivity
Validating DNS
Validating certificates (whether the certificate name matches the Web site, whether the certificate has expired, and whether it's trusted)
Checking that the firewall is set up correctly (ExRCA checks overall firewall setup. The cmdlet tests for Windows firewall configuration.)
Confirming client connectivity by logging on to the user's mailbox
Regards,
ASP20 -
Getting Client IP address in Webcenter access log files
In addition to Understanding Webcenter Spaces Access Log File
I want to trace the IP address of the client machine from where webcenter spaces is being accessed.
How to capture this?
Please help.
-- Navin KYou can access one of two server logs:
If you embedded an HTTP Server in front of WebLogic (which is what Oracle recommends), then you have access information in OHS (which is just like Apace).
If you are using a managed server (or even the admin server) in WebLogic, same thing, different name/place (the http access log).
same discussions are going on in other thread -
How to get the IP adress of the user who have accessed Webcenter Spaces ? -
SCEP Client Activity Logs Files - Retention Policy?
In SCEP 2012....
1. Where are client activity log files stored?
2. What is the default retention policy?
I remember with FCS, I think the historical data was stored for 14 months (by default). Is that the same for SCEP?
Andrew MarcosLogs are in c:\program data\Microsoft\Microsoft Antimalware\Support.
Not sure on retention as I am working in non-persistent VDI's that get their logs reset after a log off!
Cheers
Paul | sccmentor.wordpress.com -
Exchange 2013 - Cleaning UP logs files (Client Access Server)
I have to client access server and it is running out of space
Is there anywhere in the C:\ drive where I can delete some space (e.g. log files)Hello,
If you refer to C:\inetpub\logs\LogFiles, you can delete them manually or use a Powershell script to delete them.
Here is the similar thread for your reference.
http://social.technet.microsoft.com/Forums/exchange/en-US/703dc324-721e-4c52-b43a-263b5543cfda/how-to-control-iis-logs-on-cas-server?forum=exchange2010
If you refer to other log files, please free let me know.
If you have any feedback on our support, please click
here
Cara Chen
TechNet Community Support -
How do we track client deployment via group policy by referring log files globally
How do we track client deployment via group policy by referring log file centrally?
need answer from both CM07/CM012 by using GPO
There is NO Centralized tracking for GPOs.
Garth Jones | My blogs: Enhansoft and
Old Blog site | Twitter:
@GarthMJ -
New client Throttling policy on Exchange 2010
Hello,
I have a user that issues some discovery searches. These searches are putting alot of strain on the Exchange 2010 server and affecting performance.
I would like to create a new throttling policy for this 1 user (I know that everything this 1 user will do using powershell will be throttled).
So not too sure what parameters I must modify to accomplish finishing the searches and not affecting too much the Exchange server.
Many thanks,
AlexisHi Alexis,
From your description, you want to throttle one user to use discovery search using throttling policy. If I have misunderstood your concern, please let me know.
Based on my knowledge, I'm afraid that we can't achieve it on Exchange 2010. In Exchange 2013, we can use the the following cmdlet to set it.
Set-ThrottlingPolicy <ThrottlingPolicyName> -DiscoveryMaxConcurrency xx
The DiscoveryMaxConcurrency parameter specifies the number of concurrent discovery search cmdlet executions that a user can have at the same time.
For more information, here is an article for your reference.
Set-ThrottlingPolicy
http://technet.microsoft.com/en-us/library/dd298094(v=exchg.150).aspx
Hope it helps.
Best regards,
Amy
Amy Wang
TechNet Community Support -
Hi everyone,
it's probably just me but I have tried real hard to get a simple AnyConnect setup working in a lab environment on my ASA 5505 at home, without luck. When I connect with the AnyConnect client I get the error message "User not authorized for AnyConnect Client access, contact your administrator". I have searched for this error and tried some of the few solutions out there, but to no avail. I also updated the ASA from 8.4.4(1) to 9.1(1) and ASDM from 6.4(9) to 7.1(1) but still the same problem. The setup of the ASA is straight forward, directly connected to the Internet with a 10.0.1.0 / 24 subnet on the inside and an address pool of 10.0.2.0 / 24 to assign to the VPN clients. Please note that due to ISP restrictions, I'm using port 44455 instead of 443. I had AnyConnect working with the SSL portal, but IKEv2 IPsec is giving me a headache. I have stripped down certificate authentication which I had running before just to eliminate this as a potential cause of the issue. When running debugging, I do not get any error messages - the handshake completes successfully and the local authentication works fine as well.
Please find the current config and debugging output below. I appreciate any pointers as to what might be wrong here.
: Saved
ASA Version 9.1(1)
hostname ASA
domain-name ingo.local
enable password ... encrypted
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4
xlate per-session deny tcp any6 any6
xlate per-session deny udp any4 any4 eq domain
xlate per-session deny udp any4 any6 eq domain
xlate per-session deny udp any6 any4 eq domain
xlate per-session deny udp any6 any6 eq domain
passwd ... encrypted
names
name 10.0.1.0 LAN-10-0-1-x
dns-guard
ip local pool VPNPool 10.0.2.1-10.0.2.10 mask 255.255.255.0
interface Ethernet0/0
switchport access vlan 2
interface Ethernet0/1
interface Ethernet0/2
interface Ethernet0/3
interface Ethernet0/4
interface Ethernet0/5
interface Ethernet0/6
interface Ethernet0/7
interface Vlan1
nameif Internal
security-level 100
ip address 10.0.1.254 255.255.255.0
interface Vlan2
nameif External
security-level 0
ip address dhcp setroute
regex BlockFacebook "facebook.com"
banner login This is a monitored system. Unauthorized access is prohibited.
boot system disk0:/asa911-k8.bin
ftp mode passive
clock timezone PST -8
clock summer-time PDT recurring
dns domain-lookup Internal
dns domain-lookup External
dns server-group DefaultDNS
name-server 10.0.1.11
name-server 75.153.176.1
name-server 75.153.176.9
domain-name ingo.local
object network obj_any
subnet 0.0.0.0 0.0.0.0
object network LAN-10-0-1-x
subnet 10.0.1.0 255.255.255.0
object network Company-IP1
host xxx.xxx.xxx.xxx
object network Company-IP2
host xxx.xxx.xxx.xxx
object network HYPER-V-DUAL-IP
range 10.0.1.1 10.0.1.2
object network LAN-10-0-1-X
access-list 100 extended permit tcp any4 object HYPER-V-DUAL-IP eq 3389 inactive
access-list 100 extended permit tcp object Company-IP1 object HYPER-V-DUAL-IP eq 3389
access-list 100 extended permit tcp object Company-IP2 object HYPER-V-DUAL-IP eq 3389
tcp-map Normalizer
check-retransmission
checksum-verification
no pager
logging enable
logging timestamp
logging list Threats message 106023
logging list Threats message 106100
logging list Threats message 106015
logging list Threats message 106021
logging list Threats message 401004
logging buffered errors
logging trap Threats
logging asdm debugging
logging device-id hostname
logging host Internal 10.0.1.11 format emblem
logging ftp-bufferwrap
logging ftp-server 10.0.1.11 / asa *****
logging permit-hostdown
mtu Internal 1500
mtu External 1500
ip verify reverse-path interface Internal
ip verify reverse-path interface External
icmp unreachable rate-limit 1 burst-size 1
icmp deny any echo External
asdm image disk0:/asdm-711.bin
no asdm history enable
arp timeout 14400
no arp permit-nonconnected
object network obj_any
nat (Internal,External) dynamic interface
object network LAN-10-0-1-x
nat (Internal,External) dynamic interface
object network HYPER-V-DUAL-IP
nat (Internal,External) static interface service tcp 3389 3389
access-group 100 in interface External
timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
aaa-server radius protocol radius
aaa-server radius (Internal) host 10.0.1.11
key *****
radius-common-pw *****
user-identity default-domain LOCAL
aaa authentication ssh console radius LOCAL
http server enable
http LAN-10-0-1-x 255.255.255.0 Internal
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec ikev2 ipsec-proposal DES
protocol esp encryption des
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal 3DES
protocol esp encryption 3des
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES
protocol esp encryption aes
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES192
protocol esp encryption aes-192
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES256
protocol esp encryption aes-256
protocol esp integrity sha-1 md5
crypto ipsec security-association pmtu-aging infinite
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES
crypto map External_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map External_map interface External
crypto ca trustpoint srv01_trustpoint
enrollment terminal
crl configure
crypto ca trustpoint asa_cert_trustpoint
keypair asa_cert_trustpoint
crl configure
crypto ca trustpoint LOCAL-CA-SERVER
keypair LOCAL-CA-SERVER
crl configure
crypto ca trustpool policy
crypto ca server
cdp-url http://.../+CSCOCA+/asa_ca.crl:44435
issuer-name CN=...
database path disk0:/LOCAL_CA_SERVER/
smtp from-address ...
publish-crl External 44436
crypto ca certificate chain srv01_trustpoint
certificate <output omitted>
quit
crypto ca certificate chain asa_cert_trustpoint
certificate <output omitted>
quit
crypto ca certificate chain LOCAL-CA-SERVER
certificate <output omitted>
quit
crypto ikev2 policy 1
encryption aes-256
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 policy 10
encryption aes-192
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 policy 20
encryption aes
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 policy 30
encryption 3des
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 policy 40
encryption des
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 enable External client-services port 44455
crypto ikev2 remote-access trustpoint asa_cert_trustpoint
telnet timeout 5
ssh LAN-10-0-1-x 255.255.255.0 Internal
ssh xxx.xxx.xxx.xxx 255.255.255.255 External
ssh xxx.xxx.xxx.xxx 255.255.255.255 External
ssh timeout 5
ssh version 2
console timeout 0
no vpn-addr-assign aaa
no ipv6-vpn-addr-assign aaa
no ipv6-vpn-addr-assign local
dhcpd dns 75.153.176.9 75.153.176.1
dhcpd domain ingo.local
dhcpd option 3 ip 10.0.1.254
dhcpd address 10.0.1.50-10.0.1.81 Internal
dhcpd enable Internal
threat-detection basic-threat
threat-detection scanning-threat shun except ip-address LAN-10-0-1-x 255.255.255.0
threat-detection statistics access-list
threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
dynamic-filter use-database
dynamic-filter enable interface Internal
dynamic-filter enable interface External
dynamic-filter drop blacklist interface Internal
dynamic-filter drop blacklist interface External
ntp server 128.233.3.101 source External
ntp server 128.233.3.100 source External prefer
ntp server 204.152.184.72 source External
ntp server 192.6.38.127 source External
ssl encryption aes256-sha1 aes128-sha1 3des-sha1
ssl trust-point asa_cert_trustpoint External
webvpn
port 44433
enable External
dtls port 44433
anyconnect image disk0:/anyconnect-win-3.1.02026-k9.pkg 1
anyconnect profiles profile1 disk0:/profile1.xml
anyconnect enable
smart-tunnel list SmartTunnelList1 mstsc mstsc.exe platform windows
smart-tunnel list SmartTunnelList1 putty putty.exe platform windows
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-client ssl-clientless
webvpn
anyconnect profiles value profile1 type user
username write.ingo password ... encrypted
username ingo password ... encrypted privilege 15
username tom.tucker password ... encrypted
class-map TCP
match port tcp range 1 65535
class-map type regex match-any BlockFacebook
match regex BlockFacebook
class-map type inspect http match-all BlockDomains
match request header host regex class BlockFacebook
class-map inspection_default
match default-inspection-traffic
policy-map type inspect dns preset_dns_map
parameters
message-length maximum client auto
message-length maximum 1500
id-randomization
policy-map TCP
class TCP
set connection conn-max 1000 embryonic-conn-max 1000 per-client-max 250 per-client-embryonic-max 250
set connection timeout dcd
set connection advanced-options Normalizer
set connection decrement-ttl
policy-map type inspect http HTTP
parameters
protocol-violation action drop-connection log
class BlockDomains
policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
inspect dns preset_dns_map dynamic-filter-snoop
inspect http HTTP
service-policy global_policy global
service-policy TCP interface External
smtp-server 199.185.220.249
privilege cmd level 3 mode exec command perfmon
privilege cmd level 3 mode exec command ping
privilege cmd level 3 mode exec command who
privilege cmd level 3 mode exec command logging
privilege cmd level 3 mode exec command failover
privilege cmd level 3 mode exec command vpn-sessiondb
privilege cmd level 3 mode exec command packet-tracer
privilege show level 5 mode exec command import
privilege show level 5 mode exec command running-config
privilege show level 3 mode exec command reload
privilege show level 3 mode exec command mode
privilege show level 3 mode exec command firewall
privilege show level 3 mode exec command asp
privilege show level 3 mode exec command cpu
privilege show level 3 mode exec command interface
privilege show level 3 mode exec command clock
privilege show level 3 mode exec command dns-hosts
privilege show level 3 mode exec command access-list
privilege show level 3 mode exec command logging
privilege show level 3 mode exec command vlan
privilege show level 3 mode exec command ip
privilege show level 3 mode exec command failover
privilege show level 3 mode exec command asdm
privilege show level 3 mode exec command arp
privilege show level 3 mode exec command ipv6
privilege show level 3 mode exec command route
privilege show level 3 mode exec command ospf
privilege show level 3 mode exec command aaa-server
privilege show level 3 mode exec command aaa
privilege show level 3 mode exec command eigrp
privilege show level 3 mode exec command crypto
privilege show level 3 mode exec command ssh
privilege show level 3 mode exec command vpn-sessiondb
privilege show level 3 mode exec command vpnclient
privilege show level 3 mode exec command vpn
privilege show level 3 mode exec command dhcpd
privilege show level 3 mode exec command blocks
privilege show level 3 mode exec command wccp
privilege show level 3 mode exec command dynamic-filter
privilege show level 3 mode exec command webvpn
privilege show level 3 mode exec command service-policy
privilege show level 3 mode exec command module
privilege show level 3 mode exec command uauth
privilege show level 3 mode exec command compression
privilege show level 3 mode configure command interface
privilege show level 3 mode configure command clock
privilege show level 3 mode configure command access-list
privilege show level 3 mode configure command logging
privilege show level 3 mode configure command ip
privilege show level 3 mode configure command failover
privilege show level 5 mode configure command asdm
privilege show level 3 mode configure command arp
privilege show level 3 mode configure command route
privilege show level 3 mode configure command aaa-server
privilege show level 3 mode configure command aaa
privilege show level 3 mode configure command crypto
privilege show level 3 mode configure command ssh
privilege show level 3 mode configure command dhcpd
privilege show level 5 mode configure command privilege
privilege clear level 3 mode exec command dns-hosts
privilege clear level 3 mode exec command logging
privilege clear level 3 mode exec command arp
privilege clear level 3 mode exec command aaa-server
privilege clear level 3 mode exec command crypto
privilege clear level 3 mode exec command dynamic-filter
privilege cmd level 3 mode configure command failover
privilege clear level 3 mode configure command logging
privilege clear level 3 mode configure command arp
privilege clear level 3 mode configure command crypto
privilege clear level 3 mode configure command aaa-server
prompt hostname context
no call-home reporting anonymous
call-home
profile CiscoTAC-1
no active
destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
destination address email [email protected]
destination transport-method http
subscribe-to-alert-group diagnostic
subscribe-to-alert-group environment
subscribe-to-alert-group inventory periodic monthly
subscribe-to-alert-group configuration periodic monthly
subscribe-to-alert-group telemetry periodic daily
Cryptochecksum:41a021a28f73c647a2f550ba932bed1a
: end
Many thanks,
IngoHi Jose,
here is what I got now:
ASA(config)# sh run | begin tunnel-group
tunnel-group DefaultWEBVPNGroup general-attributes
address-pool VPNPool
authorization-required
and DAP debugging still the same:
ASA(config)# DAP_TRACE: DAP_open: CDC45080
DAP_TRACE: Username: tom.tucker, aaa.cisco.grouppolicy = DfltGrpPolicy
DAP_TRACE: Username: tom.tucker, aaa.cisco.username = tom.tucker
DAP_TRACE: Username: tom.tucker, aaa.cisco.username1 = tom.tucker
DAP_TRACE: Username: tom.tucker, aaa.cisco.username2 =
DAP_TRACE: Username: tom.tucker, aaa.cisco.tunnelgroup = DefaultWEBVPNGroup
DAP_TRACE: Username: tom.tucker, DAP_add_SCEP: scep required = [FALSE]
DAP_TRACE: Username: tom.tucker, DAP_add_AC:
endpoint.anyconnect.clientversion="3.1.02026";
endpoint.anyconnect.platform="win";
DAP_TRACE: Username: tom.tucker, dap_aggregate_attr: rec_count = 1
DAP_TRACE: Username: tom.tucker, Selected DAPs: DfltAccessPolicy
DAP_TRACE: Username: tom.tucker, DAP_close: CDC45080
Unfortunately, it still doesn't work. Hmmm.. maybe a wipe of the config and starting from scratch can help?
Thanks,
Ingo -
SCCM 2012 R2 Clients are not retrieving policy
Hi - I know this question has been asked many times before - but I have tried almost everything and a no closer to solving the problem.
Background: Recently a SCCM 2012 SP1 single stand-alone site was upgraded to SCCM 2012 R2. The site is a single stand-alone primary site with a single DP, single MP, using mixed mode
(HTTP). The R2 upgrade ran without any problem and all SCCM components are showing as healthy.
A few test SCCM 2012 SP1 clients were upgraded to the R2 client using client-push.
However the upgraded clients are not retrieving policy from the Management Point. In the Actions Tab of the SCCM client, only Machine Policy Retrieval and User Policy Retrieval are available. But kicking of those actions does not
result in any of the advertised applications, Task Sequences becoming available. Infact Custom Client Settings are not being set either (e.g. Organisation Name in software Center).
I have checked and rechecked the following:
The upgrade of the client completed successfully (checked ccmsetup.log) and the version number went from 5.00.7804.1000 (SP1) to 5.00.7958.1000 (R2).
The MP health in the SCCM console is showing healthy.
The MP access URL's load correctly when run from SCCm client computers
“http://<ServerName>/sms_mp/.sms_aut?mplist” is ok
“http://<ServerName>/sms_mp/.sms_aut?mpcert” is ok
The SCCM clients are assigned to the site correctly – verified via the SCCM client and
ClientLocation.Log
ClientIDManager.Log is not showing any errors
CCMExec.log and ExecMgr.log don't show any advertisements being executed (Execmgr.log is almost empty and only has "Software ditrbution site settings policy does not yet exist on the client). If the client is not yest
registered this is expected behaviour")
The SCCM clients are Approved and NOT Blocked in SCCM
I have attempted to upgrade the SCCM client and also completely removed and reinstalled - and both have the same result (no client policy dpwnloaded)
I have also deleted the above clients completely from SCCM, Run divoery again and pushed the client to the machines again ...with the same result (SCCM client installs, assigns to correct site and then no policy downloaded)
SCCM 2012 Boundaries are configured correctly and assigned to Boundary Groups correctly
The SCCM client’s do not have the firewall enabled
Changed boundary from AD Site to Subnet to IP Address Range: Same issue exists
Uninstalled MP role and reinstalled it: same Issue exists
Tried to connect to SCCm client using 3rd party SCCM Client center tool but cannot connect
??? Not sure what else to try ???Hi all - sorry for the late response.
We managed to resolve the issue after logging a job with Microsoft Support.
The issue was that the SCCM 2012 R2 upgrade corrupted 2 tables in the SCCM Database - leading to corrupt SCCM client policies.
I am pasting the resolution email from Microsoft below:
(NOTE: This may not be the exact sypmtoms you are experiencing so do not implement this fix assuming it will fix your problem!)
ISSUE:
- All clients are unable to download policies from the server
CAUSE:
- Bad policies in the Database
RESOLUTION:
-Issue with PADbID - Run below query against SCCM DB to verify corrupt entries:
SELECT * FROM
ResPolicyMap WHERE machineid = 0 and PADBID IN (SELECT PADBID FROM PolicyAssignment WHERE BodyHash IS NULL)
Confirmed Bad policies entries in the SCCM database
Run below query to delete the bad policy after which we resolved the issue:
Delete FROM ResPolicyMap
WHERE machineid = 0 and PADBID IN (SELECT PADBID FROM PolicyAssignment WHERE BodyHash IS NULL)" -
Exchange 2007 Client Access and Receive Connector options not available (EMC)
We have a SBS2008 server with Exchange 2007
When I open the EMC and go to Server Configuration --> Client Access, none off the options are available (greyed out). OAW, OWA, ActiveSync are working without any problems. Outlook anywhere enabled shows False,when I try to reanable it I get the following
error message:
Summary: 1 item(s). 0 succeeded, 1 failed.
Elapsed time: 00:00:01
SERVERNAME
Failed
Error:
The Active Directory object for virtual directory 'IIS://SERVERNAME.domainname.local/W3SVC/3/ROOT/Rpc' on 'SERVERNAME' could not be created. This might be because the object already exists in Active Directory. Remove the object from Active Directory, then re-create
it.
Unexpected Error
Warning:
Outlook Anywhere will be enabled on your Client Access server after a configuration period of approximately fifteen minutes. To verify that Outlook Anywhere has been enabled, check the application event log on server SERVERNAME.
Exchange Management Shell command attempted:
enable-OutlookAnywhere -Server 'SERVERNAME' -ExternalHostname 'mail.domainname.net' -DefaultAuthenticationMethod 'Basic' -SSLOffloading $false
Elapsed Time: 00:00:01
Also the receive connectors are not visible from EMC, it's just blank under receive connectors, but mails are received without any problems.
Does someone know a way to resolve this?That worked!
I created a new account and placed it into the Exchange Organization Administrators role, now I'm able to see all the options normally.
I also re-added the original account to the EOA role but I still don't see the options there. When I go to Organization Configuration I also get the following error message:
You do not have permissions to read the security descriptors on CN=servername,CN=Server......DC=domainname, DC=local. It was running command 'get-ExchangeAdministrator'
So it must be a permissions issue. The strange thing is that under Exchange Administrators I can see my account and it has the role Exchange Organization Administrators.
Maybe you are looking for
-
Restoring my Macbook Pro system to a Time Machine back up?
Due to having issues turning on/off my a fairly new laptop, I had to reinstall my OS on to it. Before this occured I was backing up my computer onto a WD external hard drive via time machine. Now that the OS is reinstalled and my Macbook Pro is worki
-
Route Leaking between VRF:s (Shared services)
Hi, I'm a bit confused by this setup that i'm trying to achieve. The setup is classic though, I have one VRF for education (EDU), one for administrators (ADM) and then a shared VRF (GEM) like this: ip vrf ADM description *** ADMIN NET *** rd 2:2 expo
-
New directories missing from directory listing
I have Index Directory Enabled for my configuration of application (WLS 10.3). The listing appears when I navigate to the application index dir but any new directories don't appear even if I hit the reload button. I shouldn't have to restart the serv
-
I have nokia 6500 slide model phone. How I can enable unicode support for reading "jar" file in regional language, especilly in malayalam language
-
How do I get themes into my iPhoto 11? My iPhoto 11 won't print. I just reinstalled my iPhoto 11 and tried to print. It says there are no themes and it has to have at least one in order to print.