Server Farm Firewalling

Hi,
My name is Jay Kishan and I am currently working as a network administrator in my company. We have just finished first phase of implementing Server Farm in our Data Center i.e. all servers in a different VLAN and all users in a separate VLAN. (Actually we have 6 different VLANs for users based on what floor they reside on but lets just call it a single User VLAN).
Anyways, so now my manager wants me to put a firewall in between the Server VLAN and the User VLAN. We have around 80 servers running different applications. I think that by putting a firewall in between the two VLANs will have a performance hit since the throughput required between the two VLANs is way too much for a normal firewall to support.
I just want to know the best practice the industry follows for firewalling in a server farm and the main reasons for it. I am searching for some solution myself but would really appreciate any help. As far as I could find, only critical servers are placed behind a firewall in a separate VLAN and inbound and outbound traffic for that VLAN is passed through the firewall. Also, what is the best thing to do. Place a separate hardware firewall like ASA5510 or use FWSM in Cisco 6500.
Thanks in advance.
- Jay

Hi,My
name is Jay Kishan and I am currently working as a network
administrator in my company. We have just finished first phase of
implementing Server Farm in our Data Center i.e. all servers in a
different VLAN and all users in a separate VLAN. (Actually we have 6
different VLANs for users based on what floor they reside on but lets
just call it a single User VLAN).Anyways,
so now my manager wants me to put a firewall in between the Server VLAN
and the User VLAN. We have around 80 servers running different
applications. I think that by putting a firewall in between the two
VLANs will have a performance hit since the throughput required between
the two VLANs is way too much for a normal firewall to support.I
just want to know the best practice the industry follows for
firewalling in a server farm and the main reasons for it. I am
searching for some solution myself but would really appreciate any
help. As far as I could find, only critical servers are placed behind a
firewall in a separate VLAN and inbound and outbound traffic for that
VLAN is passed through the firewall. Also, what is the best thing to
do. Place a separate hardware firewall like ASA5510 or use FWSM in
Cisco 6500.Thanks in advance.- Jay
Hi Jay,
Best recoomended practice is used to have server behind the firewall, so that restricted access will be graneted via firewall on these servers,which can be achived via acl deployment on switches.But firewall will give addionalt feature for blocking with stateful inspection and stateful failovers.
The ASA supports firewalling/VPN/IPS/IDS/Content filtering so it is a fully featured security device and The FWSM is a module that goes into a 6500 chassis but it is important to note that it is only a firewall ie. it doesn't support IDS/IPS/VPN etc.
So upto your choice how want to segregate the vlan traffic using firewall.
Hope to Help !!
Ganesh.H
Remember to rate the helpful post

Similar Messages

  • SP 2013 - Error: This operation can be performed only on a computer that is joined to a server farm

    Hello Community!
    I am working with SharePoint 2013 and I built a farm inside the firewall.  Then a decision was made to move the two WFE's to the DMZ.  Since that time, whenever I try to access the site collections, I get the error below.  Other information: All
    the web applications are on port 80, but I'm not having any problem with accessing Central Administration which is on port 8080; the network team did screw up the DNS originally, but I'm told it's correct now; the two WFE's servers show in my Manage servers
    on the Farm interface 2X, once with the server name, once with the fully Qualified Domain Name, the ones with the FQDN shows a Services Running status of Not Configured.
    Has anyone else ever seen this error and if so please provide guidance and instruction for fixing the error.
    Thanks!
    Tom
    Server Error in '/' Application.
    This operation can be performed only on a computer that is joined to a server farm by users who have permissions in SQL Server
    to read from the configuration database. To connect this server to the server farm, use the SharePoint Products Configuration Wizard, located on the Start menu in Microsoft SharePoint 2010 Products.
    Description:
    An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the
    code.
    Exception Details: System.InvalidOperationException: This operation can be performed only on a computer that is joined to a server farm by users who have permissions in SQL Server to read from the configuration database. To connect this server
    to the server farm, use the SharePoint Products Configuration Wizard, located on the Start menu in Microsoft SharePoint 2010 Products.
    Source Error:
    An unhandled exception was generated during the   execution of the current web request. Information regarding the origin and   location of the exception can be identified
    using the exception stack trace   below.  
    Stack Trace:
    [InvalidOperationException: This operation can be   performed only on a computer that is joined to a server farm by users who   have permissions in SQL Server to read from the configuration
    database. To   connect this server to the server farm, use the SharePoint Products   Configuration Wizard, located on the Start menu in Microsoft SharePoint 2010   Products.]
         Microsoft.SharePoint.Utilities.SPUtility.AlternateServerUrlFromHttpRequestUrl(Uri   url) +262
         Microsoft.SharePoint.Administration.SPAlternateUrl.GetContextUri(HttpContext   ctx) +385
         Microsoft.SharePoint.SPAppRequestContext.InitCurrent(HttpContext context)   +1013
         Microsoft.SharePoint.SPAppRequestContext.get_Current() +175
         Microsoft.SharePoint.SPGlobal.CreateSPRequestAndSetIdentity(SPSite site,   String name, Boolean bNotGlobalAdminCode, String strUrl, Boolean   bNotAddToContext, Byte[] UserToken,
    SPAppPrincipalToken appPrincipalToken,   String userName, Boolean bIgnoreTokenTimeout, Boolean bAsAnonymous) +400
         Microsoft.SharePoint.SPRequestManager.GetContextRequest(SPRequestAuthenticationMode   authenticationMode) +120
         Microsoft.SharePoint.Administration.SPFarm.get_RequestAny() +370
         Microsoft.SharePoint.SPLanguageSettings.GetGlobalInstalledLanguages(Int32   compatibilityLevel) +39
         Microsoft.SharePoint.Administration.SPTemplateFileSystemWatcher.RefreshInstalledLocales()   +103
         Microsoft.SharePoint.Administration.SPTemplateFileSystemWatcher.Initialize()   +130
         Microsoft.SharePoint.ApplicationRuntime.SPRequestModule.System.Web.IHttpModule.Init(HttpApplication   app) +873
       System.Web.HttpApplication.RegisterEventSubscriptionsWithIIS(IntPtr   appContext, HttpContext context, MethodInfo[] handlers) +582
         System.Web.HttpApplication.InitSpecial(HttpApplicationState state,   MethodInfo[] handlers, IntPtr appContext, HttpContext context) +322
         System.Web.HttpApplicationFactory.GetSpecialApplicationInstance(IntPtr   appContext, HttpContext context) +384
         System.Web.Hosting.PipelineRuntime.InitializeApplication(IntPtr appContext)   +397
    [HttpException (0x80004005): This operation can be performed only on a computer that is joined to a server farm by users who have permissions in SQL Server to read from the configuration database. To
    connect this server to the server farm, use the SharePoint Products Configuration Wizard, located on the Start menu in Microsoft SharePoint 2010 Products.]
         System.Web.HttpRuntime.FirstRequestInit(HttpContext context) +646
         System.Web.HttpRuntime.EnsureFirstRequestInit(HttpContext context) +159
       System.Web.HttpRuntime.ProcessRequestNotificationPrivate(IIS7WorkerRequest   wr, HttpContext context) +771
    Version Information: Microsoft .NET Framework Version:4.0.30319; ASP.NET Version:4.0.30319.18010
    Tom Molskow - Senior SharePoint Architect - Microsoft Community Contributor 2011 and 2012 Award -
    Linked-In - SharePoint Gypsy

    Hi Tom,
    According to your description, my understanding is that you got an error when you moved your SharePoint.
    This error occurs when the SharePoint farm administrator cannot connect to your configuration database. Please verify the followings:
    Make sure that from the SharePoint front end and application servers that you can ping your SQL server.
    Make sure that your Farm account has permission to the configuration database.
    Lastly verify that your database didn't for some reasons go into recovery mode.
    once everything is fine and you are still having issues, restart the SQL host service on the SQL server. Once the service is restarted you will need to reboot Central Admin and then your front end servers.
    In addition, as you built your farm inside the firewall, please disable the firwall, or create rules for SQL Server service in the firwall on SQL server. More information about creating rules in firewall, please refer to the following posts:
    http://social.technet.microsoft.com/Forums/en-US/c5d4d0d0-9a3b-4431-8150-17ccfbc6fb82/can-not-create-data-source-to-an-sql-server
    http://www.mssqltips.com/sqlservertip/1929/configure-windows-firewall-to-work-with-sql-server/
    Here is a similar post for you to take a look at:
    http://social.technet.microsoft.com/Forums/en-US/ea54e26c-1728-48d4-b2c5-2a3376a1082c/this-operation-can-be-performed-only-on-a-computer-that-is-joined-to-a-server-farm-by-users-who-have?forum=sharepointgeneral
    I hope this helps.
    Thanks,
    Wendy
    Wendy Li
    TechNet Community Support

  • SharePoint 2013 - Server Error in '/' Application - This operation can be performed only on a computer that is joined to a server farm by users who have permissions in SQL Server to read from the configuration database

    Hi
    After I ran SharePoint configuration wizard successfully to upgrade to SharePoint 2013 / SP1.
    I can open Central Administration site just fine.
    but now when I open any Site collection,  I got this error.
    Server Error in '/' Application
    This operation can be performed only on a computer that is joined to a server farm by users who have permissions in SQL Server to read from the configuration database. To connect this server to the server farm, use the SharePoint Products Configuration
    Wizard, located on the Start menu in Microsoft SharePoint 2010 Products
    I have restarted all the servers:  SQL server, WFE and APP servers but still cann't get this resolve.
    Services on all servers are running,  IIS - application pools are running.
    Can someone help with where that could be a problem or if there is a solution.
    Thanks in advance for your comments or advices.
    Swanl

    Please verify the followings:
    Make sure that from the SharePoint front end and application servers that you can ping your SQL server.
    Make sure that your Farm account has permission to the configuration database.
    Lastly verify that your database didn't for some reasons go into recovery mode.
    once everything is fine and you are still having issues, restart the SQL host service on the SQL server.
    Once the service is restarted you will need to reboot Central Admin and then your front end servers.
    In addition, as you built your farm inside the firewall, please disable the firwall, or create rules for SQL Server service in the firwall on SQL server.
    More information about creating rules in firewall, please refer to the following posts: http://social.technet.microsoft.com/Forums/en-US/c5d4d0d0-9a3b-4431-8150-17ccfbc6fb82/can-not-create-data-source-to-an-sql-server http://www.mssqltips.com/sqlservertip/1929/configure-windows-firewall-to-work-with-sql-server/
    Here is a similar post for you to take a look at: http://social.technet.microsoft.com/Forums/en-US/ea54e26c-1728-48d4-b2c5-2a3376a1082c/this-operation-can-be-performed-only-on-a-computer-that-is-joined-to-a-server-farm-by-users-who-have?forum=sharepointgeneral 
    Please 'propose as answer' if it helped you, also 'vote helpful' if you like this reply.

  • Securing Server Farm

    Hi all,
    To securing server in data center, we have to deploy firewall and ips. My question is, do firewall and ips need to securing traffic between server (different subnet, like database server and application server) or just securing traffic between outside server farm and server farm ?
    Thanks

    It's up to you in the end but I would recommend having your database servers firewalled from anything else.
    The database servers are some of the most important servers in any company and they usually need the highest level of protection.
    When I was involved with an Oracle setup we had our database servers on their own vlan behind a firewall which was Oracle's recommendation. Only the application servers were allowed to initiate connections to them and there was no direct access to the database servers except for the admins.
    And if you have multiple database servers on the same vlan, if there is no need for them to communicate with each other you can also use private vlans to segregate them within the vlan.
    Jon

  • Upgrade server farm advice

    We would like to upgrade our network(see before.gif) that supports our server farm(about 25 servers made). Mostly web and SQL databases.
    Currently we have 2 2811 routers running BGP. Each is connected to a different ISP; one via T1, the other via FastEthernet 100Mb.
    The routers are then connected to an unmanaged switch(100Mb). The unmanaged switch is then connected to a Checkpoint firewall.
    The firewall is then connected to a second unmanaged switch. The servers are connected to this switch.
    As you can see there is no redundency besides the edge routers.
    Most importantly we would like to add redundency, increase the speeds, use vlans to seperate the servers.
    The 6500 route is a little to expensive. We were thinking a pair of 3760 switches that will connect directly to the firewalls(see after.gif).
    Advice? Suggestions?
    Thanks,

    The after.gif is a good network design.
    Planing redudancy at edge i.e. routers is a good idea. But according to your network design you need to configure GLBP if you want to use both T1 links.
    But when comming to firewall redundancy , I think its not ok., due to checkpoint licensing costs. If you has either pix or any other low cost firewall then it would'nt have been an issue.
    Comming to switch part you can take good switch like Cisco 3750 or Cisco 3560 and perform NLB on your servers by connecting multiple ports. That will increase the speed and redundancy can also be achived.
    Hope that helps.
    Regards
    Suresh Jain

  • Server farm upgrade advice

    We would like to upgrade our network that supports our server farm(about 25 servers made). Mostly web and SQL databases.
    attatched is a diagram.
    Currently we have 2 2811 routers running BGP. Each is connected to a different ISP; one via T1, the other via FastEthernet 100Mb.
    The routers are then connected to an unmanaged switch(100Mb). The unmanaged switch is then connected to a Checkpoint firewall.
    The firewall is then connected to a second unmanaged switch. The servers are connected to this switch.
    As you can see there is no redundency besides the external routers.
    Most importantly we would like to add redundency, flatten the network using MLS, increase the speeds, use vlans to seperate the servers, get rid of the checkpoint if possible.
    Can anyone give examples of configurations and models.
    Thanks

    Example configs would be impossible as every network is different. I suggest you read some design docs.
    http://cisco.com/en/US/netsol/ns656/networking_solutions_design_guidances_list.html#anchor3

  • When connecting to a server farm in sharepoint foundation 2013 cannot create new farm error: One or more types failed to load

    When trying to create a new server farm in the sharepoint foundation 2013 we get a following error :
    The local farm is not accessible. Cmdlets with FeatureDependencyId are not registered.
    PS C:\Users\Administrator> New-SPConfigurationDatabase
    cmdlet New-SPConfigurationDatabase at command pipeline position 1
    Supply values for the following parameters:
    DatabaseName: SharePoint_Config
    DatabaseServer: PC78\SQLEXPRESS,25111
    FarmCredentials
    Passphrase: *********
    New-SPConfigurationDatabase : One or more types failed to load. Please refer
    to the upgrade log for more details.
    At line:1 char:1
    + New-SPConfigurationDatabase
    + ~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo : InvalidData: (Microsoft.Share...urationDatabase:
    SPCmdletNewSPConfigurationDatabase) [New-SPConfigurationDatabase], SPUpgra
    deException
    + FullyQualifiedErrorId : Microsoft.SharePoint.PowerShell.SPCmdletNewSPCon
    figurationDatabase
    And the error log is shown below :
    Microsoft.SharePoint.Upgrade.SPUpgradeException: One or more types failed to load.
    Please refer to the upgrade log for more details.
    at Microsoft.SharePoint.Upgrade.SPActionSequence.LoadUpgradeActions()
    at Microsoft.SharePoint.Upgrade.SPActionSequence.get_ActionsInternal()
    at Microsoft.SharePoint.Upgrade.SPUtility.GetLatestTargetSchemaVersionByMajorVersion(Type typeActionSequence, Int32 majorVer)
    at Microsoft.SharePoint.Upgrade.SPUtility.get_CurrentSPSiteWssTargetSchemaVersion()
    at Microsoft.SharePoint.Administration.SPSiteCollection.Add(SPContentDatabase database, SPSiteSubscription siteSubscription, String siteUrl, String title, String description, UInt32 nLCID, Int32 compatibilityLevel, String webTemplate, String ownerLogin, String ownerName, String ownerEmail, Strin... b712a522-fa85-49eb-b59c-dedf55295504
    ...g secondaryContactLogin, String secondaryContactName, String secondaryContactEmail, String quotaTemplate, String sscRootWebUrl, Boolean useHostHeaderAsSiteName, Boolean overrideCompatibilityRestriction)
    at Microsoft.SharePoint.Administration.SPSiteCollection.Add(SPSiteSubscription siteSubscription, String siteUrl, String title, String description, UInt32 nLCID, Int32 compatibilityLevel, String webTemplate, String ownerLogin, String ownerName, String ownerEmail, String secondaryContactLogin, String secondaryContactName, String secondaryContactEmail, Boolean useHostHeaderAsSiteName)
    at Microsoft.SharePoint.Administration.SPAdministrationWebApplication.CreateDefaultInstance(SqlConnectionStringBuilder administrationContentDatabase, SPWebService adminService, IdentityType identityType, ... b712a522-fa85-49eb-b59c-dedf55295504
    ...String farmUser, SecureString farmPassword)
    at Microsoft.SharePoint.Administration.SPFarm.CreateAdministrationWebService(SqlConnectionStringBuilder administrationContentDatabase, IdentityType identityType, String farmUser, SecureString farmPassword)
    at Microsoft.SharePoint.Administration.SPFarm.CreateBasicServices(SqlConnectionStringBuilder administrationContentDatabase, IdentityType identityType, String farmUser, SecureString farmPassword)
    at Microsoft.SharePoint.Administration.SPFarm.Create(SqlConnectionStringBuilder configurationDatabase, SqlConnectionStringBuilder administrationContentDatabase, IdentityType identityType, String farmUser, SecureString farmPassword, SecureString masterPassphrase)
    at Microsoft.SharePoint.Administration.SPFarm.Create(SqlConnectionStringBuil... b712a522-fa85-49eb-b59c-dedf55295504
    ...der configurationDatabase, SqlConnectionStringBuilder administrationContentDatabase, String farmUser, SecureString farmPassword, SecureString masterPassphrase)
    at Microsoft.SharePoint.PowerShell.SPCmdletNewSPConfigurationDatabase.InternalProcessRecord()
    at Microsoft.SharePoint.PowerShell.SPCmdlet.ProcessRecord() b712a522-fa85-49eb-b59c-dedf55295504
    Error Category: InvalidData Target Object Microsoft.SharePoint.PowerShell.SPCmdletNewSPConfigurationDatabase Details NULL RecommendedAction NULL b712a522-fa85-49eb-b59c-dedf55295504
    Leaving ProcessRecord Method of New-SPConfigurationDatabase. e9ae5ba6-c499-0000-d35c-aee999c4cf01
    we are using server 2012 R2 and we don't have office 2010 installed

    Yes,SQL server is on the same server as SharePoint 
    SQL has both the permissions Securityadmin
    and  DBcreator roles on SQL Server.
    When we run those sharepoint management shell commands the database  will be created with the error
    msg (shown in attachment)

  • Create a SharePoint 2013 Appplication in C#,Error:This operation can be performed only on a computer that is joined to a server farm

    I want to create a sharepoint application in C#:
    SPFarm CurrentFarm = SPFarm.Local;
    SPWebApplicationBuilder webAppBlder = new SPWebApplicationBuilder(CurrentFarm);
    webAppBlder.UseNTLMExclusively = true;
    webAppBlder.AllowAnonymousAccess = false;
    webAppBlder.UseSecureSocketsLayer = false;
    SPWebApplication webApp = webAppBlder.Create();
    webApp.Provision();
    It's create a new application succeed,but when I view the site there is an error:
    This operation can be performed only on a computer that is joined to a server farm by users who have permissions in SQL Server to read from the configuration database. To connect this server to the server farm, use the SharePoint Products Configuration
    Wizard, located on the Start menu in Microsoft SharePoint 2010 Products.
    How can I fix this issue?
    ps:I had create some new application in sharepoint web site.It's all fine without any issue.
    The sharepoint server,sqlserver and the programs in the same machine.
    Besr regards

    Hi,
    I think below line is causing the error -
    SPWebApplicationBuilder webAppBlder = new SPWebApplicationBuilder(CurrentFarm);
    can you put that line within a try catch and see that causes an exception. If so,  you might try as below-
    SPSecurity.RunWithElevatedPrivileges(delegate()
    webAppBuilder = new SPWebApplicationBuilder(CurrentFarm);
    Hope this helps!
    Ram - SharePoint Architect
    Blog - SharePointDeveloper.in
    Please vote or mark your question answered, if my reply helps you

  • Do you need an additional slot for the RBS and does the RBS count as an additional hard drive in the Sharepoint 2013 Server farm?

    Hello Community
        If you have a clustered Sharepoint 2013 Server farm running RAID 10, on a
    clustered WS2012 R2 server that has 10 hard drive slots:
            (4) drives being part of the Sharepoint 2013 Server farm
            (1) drive for the Web App Server
            (5) are for hot swap if any of the production hard drives fail
        The question(s) is:
            - If the server only has 10 slots for hard drives are you still allowed to add a
    NAS/RBS drive and does the NAS/RBS drive get clustered also, or does this scenario require
    reducing the RAID level down to RAID 5 to allow for NAS/RBS hard drive?
            - Does the NAS/RBS hard drive need a hard drive for hot swap?
            - Does the NAS/RBS drive have to have Sharepoint 2013 Server or WS2012 R2 running on it?
            - Does the Web App Server have Sharepoint 2013 running or just WS2012 R2 running on it?
        Thank you
        Shabeaut

    RAID 10 requires a minimum of 4 hard drives. The LUN for RBS must be attached to the SQL Server, not SharePoint server, as a local drive. You just need to be running the minimum required OS for the version of SQL Server you're using.
    Do you mean Office Web Apps by "Web App Server"? If so, that cannot have SharePoint installed on it. Otherwise, if you're just referring to it as another SharePoint server, yes it would have SharePoint installed on it.
    Trevor Seward
    Follow or contact me at...
    &nbsp&nbsp
    This post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

  • Logging into a specific server in a terminal server farm

    We have several terminal server farms and in each farm we have the need for 1 user to always log into a specific server in the farm.   This is due to a little piece of sortware that is required for a device that only this one user has and
    the fact the it is licensed to only one server.   The user must use that server for it to work.  I want to include this server in the farm because it seems silly to have a server for only one user.    How can I point one PC/user
    to the same server in the farm all the time?  We are using the Connection Broker and NLB which seems to work just fine for all other users. 
    Thanks

    Hi Steve,
    What operating system version are you running on your servers?  Server 2008 R2?  Server 2012?
    When you configure a RDS farm to be load-balanced by the connection broker, all servers in the unique farm are intended to have the exact same applications installed.  The idea is the RDCB can redirect users to different servers as needed to balance
    the load, and that you may take any particular server (or servers, if you have enough) offline and your farm will still work.
    Now, there are always exceptions and I understand it would be nice if you could assign a user/app to a specific server to handle a case like yours.  For example, you would understand this particular user or app would not be load-balanced or highly
    available and if the one server was down it would not work, but other users/RemoteApps would be load-balanced as usual.  This is
    not a feature of the current versions of RDS.
    To do what you want the "best way" would require writing a custom plugin for RDCB.  In your custom plugin you would specifiy the load-balancing logic.  For example, when one of the "special" users logs on, your logic would direct them to the
    correct specific server, but when a regular user logs on you would allow the normal RDCB load-balancing logic to apply.  Please see here for more information:
    Terminal Services Session Broker Plug-in reference
    http://msdn.microsoft.com/en-us/library/windows/desktop/cc644962(v=vs.85).aspx
    Besides writing a custom plugin I suggest you consider the following workarounds:
    1. Instead of running the app under RDSH, run it in a Win7/Win8 VM pool if possible.  Either a pool of identical VMs or assign each user that needs to run the app to a dedicated VM.  Downside of this is added complexity, licensing for VDI,
    and an increase in hardware resources required to run the VMs.
    2. Have the user connect to the server using /admin.  You can change the permissions so that a specific group may connect using a /admin connection, without them being administrators.  Downside of this is that some features
    of RDSH are not present when connected as an administrative RDP session, and only two Active admin sessions are permitted.
    3. If running Server 2008 R2 you could set the server so that it does not participate in load balancing and have the users that need to run this special app connect directly to the server's ip address instead of to the farm name.  Downside of this
    is that you will get more uneven load distribution, however, it may not be that bad if you are balancing your initial connections using NLB and you have all of your regular users connecting to the farm name as usual.
    4. Have a separate server in each farm (not joined to the farm) just for this one app.  If possible they could be VMs with not much resources dedicated to each.  I know this is what you did not want to do, but I mention it because an
    extra base Windows Server license, one for each farm, is likely less additional cost than licensing the special software on
    all servers.  If you can run the app in VMs then the additional hardware cost of doing it this way is reduced.
    -TP

  • What is the maximun recommended number of probes, rservers, server-farms

    Team,
    What is the maximun recommended number of probes, rservers, server-farms, class-maps, policy-maps per context on an ACE module?
    Regards,
    John...

    John,
    A practical limit on ACE module is 4k each for probes, serverfarms, class-maps & policy-maps. Rserver instances can be up to 16K. These limits represent total per system. They may exist all in a single context if desired. These numbers will vary based on specific configuration requirements.
    For more specific guidance please reach out to your account team or technical marketing engineer.
    Other resource info can be found under Cisco Application Control Engine (ACE) Troubleshooting Guide -> ACE Module Resource Limits:
    http://docwiki.cisco.com/wiki/Cisco_Application_Control_Engine_%28ACE%29_Module_Troubleshooting_Guide%2C_Release_A2%28x%29_--_ACE_Module_Resource_Limits
    DocWiki for ACE:
    http://docwiki.cisco.com/wiki/ACE
    HTH.

  • Failed to detect if this server is joined to a server farm

    Hi,
    We run our intranet on a virtual server. the other day it crashed and we restored it from a previous point
    However when we launch the intranet we just get a an unexpected error has occurred. I am able to get into central admin but that's about it
    I though of maybe running the product config wizard but it get an error saying "failed to detect if this server is joined to a server farm. Possible reasons for this failure could be that you no longer have the appropriate permissions to the server
    farm, the database server hosting the server farm is in responsive, the configuration database is inaccessible or this server has been removed from the server farm"
    this is what the logs it tell you to look in says:

    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the server string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseParameterDatabaseHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseParameterDatabaseHelp is The configuration database name.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Common.CreateUniqueGuidString
    01/30/2014 10:03:01  1  INF          Leaving function Common.CreateUniqueGuidString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseDatabaseNameLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseDatabaseNameLabel is D&atabase name:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseValidationDatabaseNameLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseValidationDatabaseNameLabel is database name
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the database string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseParameterAdminContentDatabaseHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseParameterAdminContentDatabaseHelp is The Central Administration Web Application content database name.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Common.CreateUniqueGuidString
    01/30/2014 10:03:01  1  INF          Leaving function Common.CreateUniqueGuidString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is AdminContentDatabaseNameLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id AdminContentDatabaseNameLabel is Central Administration Web Application content database name:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is AdminContentDatabaseValidationDatabaseNameLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id AdminContentDatabaseValidationDatabaseNameLabel is Central Administration Web Application content database name
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the admincontentdatabase string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseParameterSqlAuthenticationUserHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseParameterSqlAuthenticationUserHelp is The SQL server user name used for SQL authentication.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseUsernameLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseUsernameLabel is Sql database user:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseValidationUsernameLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseValidationUsernameLabel is Sql database user
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the dbuser string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseParameterSqlAuthenticationPasswordHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseParameterSqlAuthenticationPasswordHelp is The SQL server password used for SQL authentication.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabasePasswordLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabasePasswordLabel is Sql database password:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseValidationPasswordLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseValidationPasswordLabel is Sql database password
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the dbpassword string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is FarmUserAccountHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id FarmUserAccountHelp is Server farm administrator user account.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseFarmUsernameLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseFarmUsernameLabel is &Username:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseValidationFarmUsernameLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseValidationFarmUsernameLabel is username
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the user string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is FarmUserAccountPasswordHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id FarmUserAccountPasswordHelp is Server farm administrator user account password.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseFarmPasswordLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseFarmPasswordLabel is &Password:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseValidationFarmPasswordLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseValidationFarmPasswordLabel is password
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the password string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is MasterPassphraseHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id MasterPassphraseHelp is Passphrase used to join the server farm. Note: this must be identical on all the server farm machines.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseMasterPassphraseLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseMasterPassphraseLabel is Passp&hrase:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseValidationMasterPassphraseLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseValidationMasterPassphraseLabel is passphrase
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the passphrase string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeOrParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ActiveDirectoryDomainParameterHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ActiveDirectoryDomainParameterHelp is Active Directory domain name used for the server farm.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseActiveDirectoryDomainLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseActiveDirectoryDomainLabel is Active Directory Do&main:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseValidationActiveDirectoryDomainLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseValidationActiveDirectoryDomainLabel is Active Directory Domain
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the addomain string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddExcludeParameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.AddExcludeParameter
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.AddExcludeParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddExcludeParameter
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ActiveDirectoryOrganizationUnitParameterHelp for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ActiveDirectoryOrganizationUnitParameterHelp is Active Directory organization unit name used for the server farm.
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseActiveDirectoryOrganizationUnitLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseActiveDirectoryOrganizationUnitLabel is Active Directory Or&ganizational Unit:
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseValidationActiveDirectoryOrganizationUnitLabel for language English (United States)
    01/30/2014 10:03:01  1  INF            Resource retrieved id ConfigurationDatabaseValidationActiveDirectoryOrganizationUnitLabel is Active Directory Organizational Unit
    01/30/2014 10:03:01  1  INF          Leaving function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF          Entering function Parameter.Parameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.Initialze
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.Initialze
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.Parameter
    01/30/2014 10:03:01  1  INF          Entering function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF            Creating the adorgunit string exposed parameter
    01/30/2014 10:03:01  1  INF          Leaving function StringExposedParameter.StringExposedParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddExcludeParameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.AddExcludeParameter
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.AddExcludeParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddExcludeParameter
    01/30/2014 10:03:01  1  INF          Entering function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF            Entering function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF            Leaving function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Leaving function Parameter.AddIncludeParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter create to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry create to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value create to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter disconnect to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry disconnect to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value disconnect to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter connect to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry connect to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value connect to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter server to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry server to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value server to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter database to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry database to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value database to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter dbuser to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry dbuser to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value dbuser to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter dbpassword to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry dbpassword to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value dbpassword to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter user to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry user to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value user to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter password to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry password to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value password to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter passphrase to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry passphrase to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value passphrase to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter addomain to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry addomain to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value addomain to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter adorgunit to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry adorgunit to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value adorgunit to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function Command.AddParameter
    01/30/2014 10:03:01  1  INF            Adding parameter admincontentdatabase to command configdb
    01/30/2014 10:03:01  1  INF            Entering function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF              Adding entry admincontentdatabase to collection.
    01/30/2014 10:03:01  1  INF              Adding object with value admincontentdatabase to the collection
    01/30/2014 10:03:01  1  INF            Leaving function CommandCollectionBase.Add
    01/30/2014 10:03:01  1  INF          Leaving function Command.AddParameter
    01/30/2014 10:03:01  1  INF          Entering function CommandCollectionBase.CommandCollectionBase
    01/30/2014 10:03:01  1  INF          Leaving function CommandCollectionBase.CommandCollectionBase
    01/30/2014 10:03:01  1  INF          Entering function Command.Command
    01/30/2014 10:03:01  1  INF          Leaving function Command.Command
    01/30/2014 10:03:01  1  INF          Entering function StringResourceManager.GetResourceString
    01/30/2014 10:03:01  1  INF            Resource id to be retrieved is ConfigurationDatabaseParameterNoInstallCheckHelp for language English (United States)

  • VIP still reachable even if primary server farm is down

    Hi,
    I want to make sure that the a VIP is not PING-able anymore when the primary server farm is down (all servers are down).
    For that I have the following configuration :
    serverfarm host NCL_FARM_TEST
    probe NCL_PROBE_HTTP
    rserver CHPAUN028 443
    inservice
    policy-map type loadbalance http first-match L7_POLICY_NCL_TEST_HTTP
    description *** Load balancing rule for test in http mode ***
    class L7_CLASS_TEST
    serverfarm NCL_FARM_TEST backup NCL_REDIRECT_FARM_SORRY
    compress default-method gzip
    insert-http Source-IP header-value "%is"
    insert-http Remote-Port header-value "%pd"
    ssl-proxy client NCL_SSL_CLIENT
    policy-map multi-match VIP_PROD_AND_TEST
    class L4_CLASS_NCL_TEST_HTTP
    loadbalance vip inservice
    loadbalance policy L7_POLICY_NCL_TEST_HTTP
    loadbalance vip icmp-reply active primary-inservice
    nat dynamic 2 vlan 115
    appl-parameter http advanced-options NCL_HTTP_PARAM
    While testing this feature, I realize that the VIP is still reachable (PING), even if the server in the farm is in PROBE_FAILED status (For test, I have only one srserver in the farm).
    Here is the server farm status, while PING is still possible :
    CH01AC03/P-115-A# sh serverfarm NCL_FARM_TEST detail
    serverfarm : NCL_FARM_TEST, type: HOST
    total rservers : 1
    active rservers: 0
    description : *** Test Server Farm ***
    state : INACTIVE
    predictor : ROUNDROBIN
    failaction : -
    back-inservice : 0
    partial-threshold : 0
    num times failover : 27
    num times back inservice : 28
    total conn-dropcount : 0
    Probe(s) :
    NCL_PROBE_HTTP, type = HTTP
    ----------connections-----------
    real weight state current total failures
    ---+---------------------+------+------------+----------+----------+---------
    rserver: CHPAUN028
    10.240.3.128:443 8 PROBE-FAILED 0 609 8
    description : -
    max-conns : - , out-of-rotation count : -
    min-conns : -
    conn-rate-limit : - , out-of-rotation count : -
    bandwidth-rate-limit : - , out-of-rotation count : -
    retcode out-of-rotation count : -
    In the documentation, the following is written regarding the command "vip loadbalance icmp-reply active primary-inservice" it is stated that the ACE shold discard ping packets if all servers in the primary server farm are down.
    I probably missed something, but what ?
    Here is the service-policy status :
    Policy-map : VIP_PROD_AND_TEST
    Status : ACTIVE
    Interface: vlan 1 115
    class: L4_CLASS_NCL_TEST_HTTP
    nat:
    nat dynamic 2 vlan 115
    curr conns : 0 , hit count : 56
    dropped conns : 0
    client pkt count : 809 , client byte count: 231750
    server pkt count : 1262 , server byte count: 1375334
    conn-rate-limit : 0 , drop-count : 0
    bandwidth-rate-limit : 0 , drop-count : 0
    loadbalance:
    L7 loadbalance policy: L7_POLICY_NCL_TEST_HTTP
    VIP ICMP Reply : ENABLED-WHEN-PRIMARY-SF-UP
    VIP State: INSERVICE
    Persistence Rebalance: ENABLED
    curr conns : 0 , hit count : 56
    dropped conns : 0
    client pkt count : 809 , client byte count: 231750
    server pkt count : 1262 , server byte count: 1375334
    conn-rate-limit : 0 , drop-count : 0
    bandwidth-rate-limit : 0 , drop-count : 0
    compression:
    bytes_in : 1052393
    bytes_out : 309229
    Compression ratio : 70.61%
    Parameter-map(s):
    NCL_HTTP_PARAM
    Thank you for any hints,
    Yves Haemmerli

    Gilles,
    I have effectively four diferent policy maps :
    - one for PROD when the client arrives withh HTTP
    - one for PROD when the client arrives with HTTPS
    - one for TEST when the client arrives with HTTP
    one for TEST when the client arrives with HTTPS
    However, the PROD and the TEST environemnts use different server farms. I am testing the icmp-reply feature on the TEST environment. In the TEST environment, both Layer-7 policy maps use the same server farm.
    Here are the four polici maps :
    policy-map type loadbalance http first-match L7_POLICY_NCL_PROD_HTTP
    description *** Load balancing rule for production in http mode ***
    class L7_CLASS_PROD
    serverfarm NCL_FARM_PROD backup NCL_REDIRECT_FARM_SORRY
    insert-http Source-IP header-value "%is"
    insert-http Remote-Port header-value "%pd"
    ssl-proxy client NCL_SSL_CLIENT
    class L7_CLASS_REDIRECT
    serverfarm NCL_REDIRECT_FARM_PROD_HTTP
    policy-map type loadbalance http first-match L7_POLICY_NCL_PROD_HTTPS
    description *** Load balancing rule for production in https mode ***
    class L7_CLASS_PROD
    serverfarm NCL_FARM_PROD backup NCL_REDIRECT_FARM_SORRY
    insert-http Source-IP header-value "%is"
    insert-http Remote-Port header-value "%pd"
    ssl-proxy client NCL_SSL_CLIENT
    class L7_CLASS_REDIRECT
    serverfarm NCL_REDIRECT_FARM_PROD_HTTPS
    policy-map type loadbalance http first-match L7_POLICY_NCL_TEST_HTTP
    description *** Load balancing rule for test in http mode ***
    class L7_CLASS_TEST
    serverfarm NCL_FARM_TEST backup NCL_REDIRECT_FARM_SORRY
    compress default-method gzip
    insert-http Source-IP header-value "%is"
    insert-http Remote-Port header-value "%pd"
    ssl-proxy client NCL_SSL_CLIENT
    class L7_CLASS_REDIRECT
    serverfarm NCL_REDIRECT_FARM_TEST_HTTP
    policy-map type loadbalance http first-match L7_POLICY_NCL_TEST_HTTPS
    description *** Load balancing rule for test in https mode ***
    class L7_CLASS_TEST
    serverfarm NCL_FARM_TEST backup NCL_REDIRECT_FARM_SORRY
    insert-http Source-IP header-value "%is"
    insert-http Remote-Port header-value "%pd"
    ssl-proxy client NCL_SSL_CLIENT
    class L7_CLASS_REDIRECT
    serverfarm NCL_REDIRECT_FARM_TEST_HTTPS
    Yves

  • The server farm account should not be used for other services

    I have created a new SharePoint Foundation 2013 Farm. I only used the Farm Configuration Wizard to create the Search Service Application, all other aspects of the Farm was created using PowerShell.
    The SharePoint Health Analyzer is reporting the following error:
    Title: The server farm account should not be used for other services.
    Severity: 1 - Error
    Category: Security
    Explanation: DOMAIN\FARM_ACCOUNT, the account used for the SharePoint timer service and the central administration site, is highly privileged and should not be used for any other services on any machines in the server farm.  The following services were
    found to use this account: Distributed Cache Service(Windows Service)
    Remedy: Browse to
    http://centraladminsite:port/_admin/FarmCredentialManagement.aspx and change the account used for the services listed in the explanation. For more information about this rule, see "http://go.microsoft.com/fwlink/?LinkID=142685".
    Now I understand how to change the account used to run the Distributed Cache Service, but my query is what account should I use in the least privelage model? I have setup the following 6 accounts as per TechNet guidelines (Link)
    and am not sure if one of these accounts should be used or if another account is required:
    SQL Server service account
    Setup user account
    Server farm account
    SharePoint Server Search service account
    Default content access account
    Application pool identity
    After reviewing the TechNet article again, I don't fully understand the section titled "Service application accounts". Is the article advising me to create a seperate account for each row in the table? e.g. 1 account for Business Data Connectivity
    Service, a different account for "Application Discovery and Load Balancer Service", another account for "App management" and another account for "Distributed Cache", so 4 extra accounts if I choose to install all of these services
    within the Farm?
    Also, what does the article mean when it says "Plan one set of an application pool and proxy group for each service application that you plan to implement."? How do I go about doing this?
    Kevin Evans

    After reviewing the TechNet article again, I don't fully understand the section titled "Service application accounts". Is the article advising me to create a seperate account for each row in the table? e.g. 1 account for Business Data Connectivity Service,
    a different account for "Application Discovery and Load Balancer Service", another account for "App management" and another account for "Distributed Cache", so 4 extra accounts if I choose to install all of these services within the Farm?
    Inder: Yes, It is suggested to have multiple service account for each service application. This increases security and dependencyof 1 account on multiple Service applications. Like below
    SQL Server service
    Local System account (default)
    Setup user
    Member of the Administrators group on the local computer
    Server farm
    Network Service (default)
    No manual configuration is necessary.
    SharePoint Server Search Service
    By default, this account runs as the Local System account.
    If you want to crawl remote content by changing the default content access account or by using crawl rules, change this to a domain user account. If you do not change this account to a domain user account, you cannot change the default content access account
    to a domain user account or add crawl rules to crawl this content. This restriction is designed to prevent elevation of privilege for any other process running as the Local System account.
    Default Content Access
    No manual configuration is necessary if this account is only crawling local farm content. If you want to crawl remote content by using crawl rules, change this to a domain user account, and apply the requirements listed for a server farm.
    Content Access
    Same requirement as the default content access account.
    Profile import Default Access
    Same requirements as server farm.
    Excel Services Unattended Service
    Must be a domain user account.
    http://technet.microsoft.com/en-us/library/cc263445%28v=office.15%29.aspx
    Also, what does the article mean when it says "Plan one set of an application pool and proxy group for each service application that you plan to implement."? How do I go about doing this?
    Inder: Each service account has a application pool and you can plan to use same application pool for multiple
    service accounts if required. These application pool are then consumed by proxy connection
    of each service application. On service application pool, you can see all the service applications and its proxy connection.
    If this helped you resolve your issue, please mark it Answered

  • My Firefox can't synchronize after updating to version 26. Our organization uses MS ISA server as firewall.

    Our organization uses MS ISA server as firewall.

    Can your IT check whether there are any error messages logged in ISA that might explain why the connection is not working (assuming it is a connection issue)?

Maybe you are looking for