Windows Server 2008 R2

Windows Server 2008 R2

Windows Server Core

  1. Because Microsoft longing for a pure Linux command line, Windows Server Core is proposed
  2. Use only command, but as long as configured ip and so on, this can be managed by another Server Server, but requires the same administrator password

Windows Server Desktop Experience

  1. In Server Manager , select the function (note not the role ), add telnet client and desktop experience
  2. Enter services.mscto start the service Theme
  3. Restart

Network Shortcuts

  1. include

    1. Network Discovery
    2. FTP
  2. operating

    FTP, for example

    In the desktop , right, select Create Shortcut , if it is FTP, enter ftp: // administrator: [email protected]

Shortcut command

  1. lusrmgr.msc Full name of local user manager microsoft console, open the Local Users and Groups console

lusrmgr.msc

  1. The default system is disabled Guest, Guest turned on, the user, click Guest , will disable the check mark removed Note: Starting Guest is very important, for white, when access to the shared directory, if you want no problems, be sure to activate Guest user
  1. secpol.msc Full name of security policy microsoft console

secpol

  1. Password Policy: Account Policies \ Password Policy
  2. Security Options (changed from the classic guests, necessary): Local Policies \ Security Options, (a lot of things) security settings found in the list of classic keyword, select guests only
  1. sysprep Remove the unique system data flag, a system for migration general, in the Hyper-V, sysprep operated as a virtual machine can quickly generate the parent virtual machine other subclasses (installed and the configuration of the same parent operating system)
  1. C:\Windows\System32\sysprep\sysprep.exe
  2. In the dialog box that appears, select General , because our aim is common migration (such as the user's system clearly SID ), and then click OK

sysprep

  1. When you start again, following interface will appear, because we get rid of something

sysprep reboot interface

  1. telnetFor testing network http + port problems

    1. Function in Server Manager to add telnet client
    2. telnet www.google.com 80 If nothing is returned is no problem, otherwise there is a problem
  2. dnsmgmt.msc dns service management console

Hyper-V use

  1. Install Hyper-V components, open the Start \ Administrative Tools \ Server Manager

Server Manager

  1. Right roles , add roles, has been the next step, in the following figure, select Hyper-V and then click Next

Add Hyper-V

  1. Open Hyper-V Manager

    1. Click New , select Virtual Machine

    2. Fill in the virtual machine name

    Virtual machine name

    1. In the configuration of the network time, if only one is not connected , the first placed, such as the establishment of good, go create a network adapter (bridge, private), if there are other connections, the demand set

    Network Configuration

    1. Connect the virtual hard disk , which is the name .vhd, etc. After the installation is complete, a large .vhd file, approximately 7 GB

    Connect Virtual Hard Disk

    1. The next step has been to

    2. Add card, click Virtual Network Manager , the pop-up window, select the external , internal , dedicated , click Add

    Virtual Network Manager

    1. External: Bridge is the card, the host is treated as a switch , then the virtual network to a host, the ip address on the original physical NIC to the virtual network adapter for the virtual machine, and the host, the use of the virtual card communication
  2. Parent difference disk, with shortcut commands -> sysprep View

    1. Click New , select the difference

    difference

    1. Configure the disk , select the parent class template vhd, is the use of sysprep command

    Screen Shot 2019-08-28 at 20.41.34

NTFS

  1. The target audience
  1. file
    1. read
    2. write
    3. carried out
    4. modify
    5. fully control
  2. folder
    1. read
    2. write
    3. carried out
    4. modify
    5. fully control
    6. Lists the contents of a folder
  3. Shared folder
    1. read
    2. write
    3. modify
  4. printer
  1. In addition to basic literacy execution, as well as special privileges , more fine-grained

  2. limit

    1. Support maximum 2TB hard drive
    2. Support 64GB single file

Shared folder

  1. Right folder sharing , select a specific user , enter the Everyone (read-only by default, you can choose to read \ write), can be determined

  2. When clients access the shared folder, logon sequence is 1. The current logged-on user; 2. Administrator 3. Guest + empty password , remember to lusrmgr.mscturn on the Guest

    Hide sharing

    1. Right property, at an additional share name$
    2. Where all drives are hidden by default shared
  3. Network sharing settings to control share, click on the left to change advanced sharing settings

shared

  1. In addition to point 3, click Local Area Connection

local connection

  1. Remove the Client for Microsoft Networks , the host can not see this shared
  2. Remove the Microsoft Network File and Printer Sharing , then other people can not see Share the machine

The domain controller (DC) and Active Directory (AD)

  1. Command to install the AD, the computer will be promoted to DC, note: in the absence promoted to DC, a local user can use, but promoted to DC, local users upgrade to become a domain user
    after, local users can not use

    1. dcpromo The full name Domain Controller promote installation AD, host promoted to DC, if it is created from scratch for the first time (in a poverty-stricken basis) do not need to select the Advanced, if it is not checked senior

    dcpromo

    1. The default is 2003, as DC represents
      the lowest level, if 2003 is> = 2003 can be used as after DC

    2003

    1. Oh equipped with the DNS to DC

    DC and DNS

    1. The following warning appears, click OK

    OK WARNING

    1. The following dialog box, the password used to restore Active Directory data set, which is the administrator of the domain

    Restore the database password

    1. Complete restart on the hook

      Complete restart on the hook

    2. DNS check whether the installation is successful, you only need to view the ip address, preferred to 127.0.0.1

      127.0.0.1

    3. Above DNS, right, should be changed to DC LAN ip address

    4. Domain controller netlogon service is enabled by default, this service for DNS, the working group is off by default, in order to work, we need to open
    5. Join a domain, the domain only need to check the settings in your computer, the username and password input field (different users can have 10 chances)

    DNS

    1. Advanced features the following figure

    Screen Shot 2019-08-29 at 14.52.04

NTDS (dynamic site service)

  1. The main consideration of the relationship between different physical domains and regions, carried out the Active Directory database synchronization between DC

  2. Auxiliary DC to create the best of his database replication from the primary DC in the database come (through the network or disk, if the disk then need to use the parent DC in ntdsutilthe production database snapshot, the resulting catalog copy to want to upgrade to the auxiliary DC computer on)

    1. ntdsutil Command
      1. activate instance ntds
      2. ifm
      3. create full c:\data\ c: \ target data is backed up

Guess you like

Origin www.cnblogs.com/megachen/p/11470259.html