Tuesday, April 06, 2010

การใช้ excel vlookup


ข้อกำหนดของ vlookup (ไม่แน่ใจว่า excel version ใหม่แก้หรือยัง)
- ต้องมีการเรียงลำดับจากน้อยไปหามากเอาไว้ก่อน
- column ที่ใช้ค้นหาของ table array จะต้องเป็น column ที่อยู่ซ้ายมือสุดเสมอ

 =VLOOKUP(ค่าที่ต้องการค้นหา,ตารางข้อมูล,หมายเลขของ column ตารางข้อมูลที่ต้องการนำข้อมูลมาแสดงเริ่มตั้งแต่ซ้ายสุดคือ 1 ไปเรื่อยๆ,not_exact_match)

- not_exact_match ส่วนใหญ่จะใช้ FALSE หรือ 0 ซึ่งหมายถึงต้องการให้ค้นหาแบบ exact match
- ถ้าใช้เป็น TRUE จะหมายถึง approximate match หมายความว่าถ้าค้นหาไม่เจอ vlookup จะหาค่าที่มากที่สุดที่น้อยกว่าค่าที่ต้องการค้นหา (ไม่ค่อยได้ใช้ True)

http://www.techonthenet.com/excel/formulas/vlookup.php


สำหรับ Excel แล้ว False = 0 และ True = 1

การอ้างถึงข้ามไฟล์ข้าม sheet ใช้ [Book2]Sheet1!

การตรึงใช้ $ สามารถตรึงได้ทั้ง row และ column เช่น $A$1 หรือจะใช้ Defind Name ก็ได้สะดวกดี

Friday, March 26, 2010

การเปลี่ยน Microsoft SQL Server 2000 Licensing Mode โดยไม่ต้อง install ใหม่

ปกติจะมีให้เลือก mode ตอน install ถ้าเลือกแล้วจะไม่สามารถเปลี่ยนได้ นอกจาก reinstall sql หรืออีกวิธีที่ง่ายกว่าคือไปแก้ที่ registry ดังนี้


HKLM\Software\Microsoft\Microsoft SQL Server\80\MSSQLLicenseInfo\MSSQL8.00\Mode

เปลี่ยนเป็น 0

เมื่อเข้าไปที่ Control Panel แล้วจะสามารถเลือก mode ได้ใหม่


Sunday, March 21, 2010

Group Policy Preferences

http://alsolorzano.com/blogs/tips__tricks/archive/2008/06/02/group-policy-preferences-in-a-windows-2003-domain-and-a-windows-2008-domain.aspx

การ Uninstall Application ที่ Install จาก Software Installation ของ GPO

มีอยู่ 3 แบบ

1. ถ้าใน Deployment Option ได้เลือกไว้ว่า Uninstall this application when it falls out of the scope management แล้วเราย้าย computer หรือ user ไปยัง OU อื่น มันจะ uninstall ให้เอง
2. ถ้าไม่ต้องการให้ application นี้ถูกติดตั้งลงในเครื่องใหม่เพิ่มจากเดิม แต่เครื่องที่เคย install ไปแล้วอนุญาติให้ใช้ต่อไปได้  ให้เลือก all task/ remove/ allow users to continue to use the software but prevent new installations.
3. ถ้าต้องการใช้ uninstall ออกไปทั้งหมดเลย ใช้เลือก all task/ remove/ immediately uninstall the software from user and computer.

Friday, March 19, 2010

การซื้อแอร์ และติดตั้ง

1. ตอนมาติดตั้งให้ทำ vaccum ให้ด้วย ต้องคุยกับที่ร้านตอนซื้อเพราะเสียเวลาทำพอสมควร
2. ใช้ท่อน้ำทิ้ง 4 หุน เพราะจะตันยาก
3. สายไฟเบอร์ 4 Yazaki หรือ Bangkok Cable เดินสายดินให้ด้วย ถ้าที่บ้านติด breaker กันดูดรวมทั้งบ้าน ให้แยก breaker main สำหรับแอร์ออกมาจาก bus bar แล้วต่อไปตรงจาก main breaker บ้านเพื่อไม่ให้ไฟดับทั้งบ้านเมื่อมีไฟรั่วจากแอร์
4. เติน breaker ย่อยของแอร์ เป็น breaker ธรรมดา ไว้ตัดไฟตอน service
5. ถ้าเป็นไปได้ ขอ turn ท่อน้ำยาให้ใช้ฉนวนแบบหนากว่าที่แถมมา ท่อเข้าท่อออกหุ้มฉนวนแยกจากกัน
6. ขอแถมรางเก็บท่อ และขายึดกำแพงด้วย ล้างแอร์ 2 ครั้ง
7. ใช้สว่าน hole saw เจาะกำแพงจะได้ไม่แตกมาก รูสวย
8. ตั้งถาดรับน้ำให้เอียงไปทางท่อน้ำทิ้งให้ถูกต้อง บางทีเอียงไปคนละฝั่ง
9. ซื้อแผ่นกรอก 3M Filtrete มาติดตรง filter จะได้ไม่ต้องล้างแอร์บ่อย ขนาด 15"x48" ประมาณ 240-290 บาท
10. เวลาช่างล้างแอร์ให้คุมให้ดีๆ อย่าให้ไปวัดน้ำยาแอร์ อาจจะทำให้รั่ว หรือ แอบทำให้รั่วได้
11. วันน้ำยาแอร์วัดเป็นความดันมีหน่วยเป็น ปอน์ดต่อตารางนิ้ว psi ไม่ใช่หน่วยน้ำหนัก ซื้อถังเล็กๆ
ประมาณ 800 บาท
12. ท่อน้ำทิ้งให้กะ slope ด้วย
13. การคำนวณค่าไฟแอร์ kilo-Watt(จาก plate ของแอร์) X ชั่วโมงที่เปิดในแต่ละวัน X ค่าไฟหน่วยละประมาณ 3 บาท = ค่าแอร์ต่อวัน เช่น 1.56kW x 3hr x 3baht = 14 บาท ต่อวัน หรือประมาณชั่วโมงละ 4-5 บาท

Sunday, March 14, 2010

IPTABLE

ถ้าต้องการ block ช่วง 221.0.0.0-221.255.255.255 ใช้คำสั่ง


sbin/iptables -I INPUT -s 221.0.0.0/255.0.0.0 -j DROP
หรือ
sbin/iptables -I INPUT -s 221.0.0.0/8 -j DROP

ถ้าใช้ /24 จะ block ตั้งแต่ 221.0.0.0-221.0.0.255


ถ้าต้องการระบุเป็นช่วงเช่น 192.168.1.100-192.168.1.200 จะต้องโหลด module ipt_iprange ใน kernel ด้วย
โดยใช้ modprobe หรือ recomplid kernel ด้วย iprange ในส่วนของ netfilter

Saturday, March 13, 2010

All about FSMO Roles and Remove Domain Controller

Understanding FSMO Roles in Active Directory
http://www.petri.co.il/understanding_fsmo_roles_in_ad.htm

Planning FSMO Roles in Active Directory
http://www.petri.co.il/planning_fsmo_roles_in_ad.htm

Determining FSMO Role Holders
http://www.petri.co.il/determining_fsmo_role_holders.htm

Transferring FSMO Roles
http://www.petri.co.il/transferring_fsmo_roles.htm

Seizing FSMO Roles
http://www.petri.co.il/seizing_fsmo_roles.htm

Forcibly Removing Active Directory from a DC – Retire a  Domain Controller
http://www.petri.co.il/forcibly_removing_active_directoy_from_dc.htm

Delete Failed DCs from Active Directory
http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Windows 2003 Domain Controller Rename
http://www.petri.co.il/windows_2003_domain_controller_rename.htm

Thursday, March 11, 2010

การยื่น แบบทาง Internet ของ ภ.ง.ด. 90

รายได้เป็นเงินเดือน อย่างเดียว ยื่น ภ.ง.ด. 91 และไม่ต้องไปสนใจ ภ.ง.ด. 90 ที่บริษัทออกให้
ถ้ามีรายได้อย่างอื่นด้วยนอกเหนือจากเงินเดือน ยื่น ภ.ง.ด. 90
เช่นกรณีทำงานเป็นพนักงานประจำและมีรายได้อื่นเป็นเงินปันผล ให้ยื่นแบบ ภ.ง.ด. 90

สำหรับการยื่น ภ.ง.ด. 90
- เงินเดือนกรอกใน ห้วข้อ 40(1) + หักณ ที่จ่าย
- เงินได้จากอย่างอื่น กรอกใน หัวข้อ 40(2) อย่าลืมใส่หักณ ที่จ่าย 3% ออกด้วย
- ในหน้าผู้จ่ายเงินได้ กรอกหมายเลขประจำตัวผู้เสียภาษีของ บริษัทที่จ่ายเงินให้เรา หรือหมายเลขบัตรประชาชนสำหรับกรณีที่ไม่ได้เป็นบริษัท ต้องใส่ทั้งของ 40(1) และ 40(2)
- ในหน้า ลดหย่อนและการคำนวนภาษี กรอก เงินหักประกันสังคม , เงินบริจาค

- เงินปันผลให้กรอกใน 40(4) ให้กดที่ link แก้ไข/เพิ่มเติม แล้วจะเปิดหน้าต่างใหม่ให้กรอก เงินปันผลที่ได้รับตามใบที่ได้จาก TSD ต้องกรอกให้ครบหมดทุกตัว หรือไม่ก็ไม่ต้องกรอกเลย

- ถ้าเป็นเงินปันผลจาก2.1 BOI ให้กรอกในช่องยกเว้นภาษี

ถ้าเป็นเงินปันผลจาก2.2,2.3,2.4 ให้กรอกในช่องไม่ได้รับเครดิตภาษี
นอกนั้นกรอกตามเอกสาร

- สามารถดูสรุปยอดภาษีที่ได้รับทั้งปีได้จาก www.tsd.co.th

Monday, March 08, 2010

ค่าธรรมเนียมซื้อขายบ้าน

ค่าธรรมเนียมหลังวันที่ 28 มีนาคม 2553 ที่ครมมีมติไม่ต่ออายุ

1.ค่าธรรมเนียมโอนบ้านและคอนโดฯ จาก 0.01% เป็น 2% (ปกติจะออกคนละครึ่ง)
2.ค่า จดจำนองจาก 0.01% เป็น 1% (กรณีกู้กับธนาคาร ถ้าซื้อสดไม่ต้องเสีย)
3.ภาษีธุรกิจเฉพาะในการซื้อขายอสังหาฯ จาก 0.11% เป็น 3.3% (ปกติผู้ขายออก)

Thursday, January 21, 2010

วิธีปลดล๊อค Zyxel 660HW Port 3 กับ 4


ไม่จำเป็นต้องใส่เอาไว้ใน autoexec.net


sys tripleplay portbase disable
sys tripleplay portbase save

Sunday, January 03, 2010

ปั๋มน้ำ

ปั๊มกลม
- เรียกว่าปั๋มอัตโนมัติ
- ทำงานโดย pressure switch
- มี bypass ให้น้ำไหลผ่านตัวได้เมื่อไฟดับ

ปั๋มเหลี่ยม
- เรียกว่าปั๊มแรงดันคงที่ แต่ความจริงน่าจะเรียกว่าปั๊มทำงานเต็มที่มากกว่า
- เริ่มทำงานโดย pressure switch
- แต่จะหยุดทำงานโดย flow switch
- ไม่มี bypass ในตัว

ปั๊มเหลี่ยม Invertor
- ปรับปรุงให้สามารถทำงานมากน้อยตามโหลด ไม่ต้องทำงานเต็มที่ตลอดเวลา ทำให้ประหยัดไฟ

การต่อปั๋ม
- ควรจะต่อ check valve ทั้งทางดูดและทางจ่ายด้วย
- ต่อทางจ่ายเพื่อป้องการ water hammer เมื่อปั๊มหยุดทำงาน
- ต่อทางดูดเพื่อป้องกันน้ำเล็ดรอดกลับเข้า tank
- เมื่อต่อ check valve แล้วจะรู้สึกได้ว่าปั๊มทำงานเองน้อยลง

Union
- ควรใช้ของท่อน้ำไทย
- เวลาซื้อให้ขันออกมาดูว่าจะมีแผ่นพลาสติกใสกับยางให้ครบ (หายบ่อย)
- ไม่ควรใช้กับท่อที่มี pressure สูงๆเช่นด้านจ่ายของปั๊ม(หลังปั๋ม)
- work เพราะไม่มีน้ำหยดตรงรอยต่อจริงๆ

การต่อท่อ
- ถ้าต้องการต่อกับพวกเกลียวทองเหลืองของ valve ต่างๆที่มีช่วงเกลียวสั้น ให้เจียร์เกลียวนอกของ PVC ออกหน่อยนึงก่อน เพื่อจะได้เข้าได้ลึกที่สุด
- หัวท่อ pvc ที่ต่อขึ้นมาจากพื้นทั้งหมดให้ใช้เป็นเกลียวในทองเหลืองเพื่อที่จะได้ถอดบำรุงรักษาได้โดยที่ไม่ต้องแย๊กพื้น อย่าต่อโดยการใช้กาว
- ควรต่อท่อขนาดเดียวกับ meter  และเดินทั้งบ้านด้วย 1" รวมถึงปั๊มและ tank ด้วย
- ควรมีตัวดักเศษกรวดที่ท่อด้วยถ้าสามารถหาซื้อได้
- PVC ควรซื้ออย่างหนา ตัวหนังสือสีทอง
- ท่อน้ำไทยมีขายหน้าแปลน PVC อีกข้างเป็นเกลียวนอกด้วย

Valve
- check valve ที่ใช้ตามบ้านทั่วไปมี 2 แบบคือแบบ spring กับแบบ swing
- swing ดีกว่าเพราะขัดข้องได้ยากกว่า และทนกว่า ไม่มีอาการ spring ล้าเมื่อใช้ไปนานๆ แต่หาซื้อได้ยากกว่า ทั่วไปจะเจอยี่ห้อ Kitz กับ Sanwa
- แบบ spring ข้อดีคือสามารถติดตั้งได้ทุกแนว
- แบบ swing ควรจะติดตั้งในแนวดิ่ง หรือถ้าติดตั้งในแนวราบให้เอียงท่อนิดหน่อยเพื่อให้ฝาปิดสามารถลงมาปิดได้สนิท ถ้าเอียงผิดจะทำให้ฝาปิดไม่สนิท
- check valve ไม่ได้ปัองกันน้ำไหลย้อนกลับได้สนิท 100% แต่จะลดแรงดันน้ำหลัง valve ลงให้เหลือแค่นิดเดียว และเมื่อเจอกับแรงดันน้ำที่มากกว่าทางด้านหลัง ก็จะทำให้น้ำไม่ไหลย้อนกลับทาง

สายยางรดน้ำต้นไม้
- ควรซื้อของยี่ห้อท่อน้ำไทย สีเขียว ขนาด 5/8"

http://www.pantip.com/cafe/home/topic/R7480894/R7480894.html
http://www.pantip.com/cafe/home/topic/R7482936/R7482936.html

Friday, December 25, 2009

คำส่ง VI ที่ใช้บ่อยๆ

ESC = เปลี่ยน mode
q = ออกจาก vi โดยจะต้องไม่มีการเปลี่ยนแปลงไฟล์มาก่อน
wq = save and exit
q! = บังคับออกจาก vi โดยที่ยกเลิกการแก้ไข
x = save

i = insert ตรง cursor
a = append หลัง cursor
x = ลบ 1 ตัวอักษรตรง cursor
o = เพิ่มบันทัดใหม่ด้านล่าง
O = เพิ่มบันทัดใหม่ด้านบน

/string = ค้นหาข้อความไปข้างหน้า

Change Dreambox Mac Address

telnet เข้า dreambox
ไปที่ /var/etc
แก้ไขไฟล์ init
เพิ่มบันทัดนี้ลงไป



#!/bin/sh
ifconfig eth
0 down
ifconfig eth
0 hw ether 00:09:34:2e:60:01
ifconfig eth
0 up



โดยแก้ไขเฉพาะ 3 ช่วงสุดท้ายของ dreambox แต่ละเครื่องไม่ให้ซ้ำกัน
สั่ง reboot เป็นอันเสร็จ


Saturday, November 21, 2009

Microsoft Security Essentials (MSE)

Download  free ได้จาก
http://www.microsoft.com/Security_Essentials/
โดยจะต้องตั้ง Region เป็น English ถึงจะสามารถ Download ได้

เปลี่ยน Auto Update Interval แต่รู้สึกว่าไม่ได้ผล
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Microsoft Antimalware/Signature Update
แก้ SignatureUpdateInterval เป็น 1 ชั่วโมง (1-24)

คำสั่ง Manual Update สามารถเอาไปใส่ไว้ใน Schedule Task ได้
สั่ง update จาก Microsoft
mpcmdrun -SignatureUpdate
สั่ง update offline จาก UNC path ให้ update จาก share drive ใน local network
mpcmdrun -SignatureUpdate -\\server\mseupdate
โดย definition file ที่ download มาได้ไม่ต้องแตกอะไรออกมา

Manual Download Definition ได้จาก
http://www.microsoft.com/security/portal/Definitions/ADL.aspx
หรือ direct download link
สำหรับ 32 bit
http://go.microsoft.com/fwlink/?LinkID=87342
สำหรับ 64 bit
http://go.microsoft.com/fwlink/?LinkID=87341

วิธีสุดท้าย กรณีที่ใช้ mpcmdrun ไม่ได้ผล คือใช้ schedule task สั่งให้ run ไฟล์ที่ mpam-fe.exe แบบตรงๆไปเลย ซึ่ง user ธรรมดาที่ไม่ใช้ admin ก็มีสิทธิที่จะ run update file นี้ได้

สามารถ ตั้งเวลาการ download update file ได้จากการใช้ wget + schedule task

Note
- ถ้าต้องการให้ wget replace ทับไฟล์เดิมโดยที่ไม่ต้องต่อท้ายด้วย .1 , .2 ให้ใช้ wget -N ซึ่งจะ download ก็ต่อเมื่อ timestamp ของไฟล์ใหม่กว่าไฟล์เดิมเท่านั้น
- wget --tries=5 ให้ retry 5 ครั้ง
- สรุปว่าใช้คำสั่ง wget --tries=5 -N http://go.microsoft.com/fwlink/?LinkID=87342
- schedule task สามารถสั่ง run ตอนที่เครื่อง sleep , hibernate ได้ด้วย และ user ที่ได้ตั้ง schedule เอาไว้ก็ไม่จำเป็นที่จะต้อง login อยู่ในขณะนั้นก็ได้เหมือนกัน

MSE Forum
http://social.answers.microsoft.com/Forums/en-US/category/mse
http://social.answers.microsoft.com/Forums/en-US/msestart/threads


Tuesday, November 17, 2009

Group Policy refresh interval

สามารถเปลี่ยนได้จาก

Computer Policy
Computer Configuration\Administrative Templates\System\Group Policy

User Policy
User Configuration\Administrative Templates\System\Group Policy

Default = 90 นาที + Random Offser 30 นาที เพื่อป้องการ overload


Monday, November 09, 2009

Firefox Extensions

Entension ที่น่าสนใจมีดังนี้

1. Tablang แก้ปัญหาที่ ff จะจำ lang เดียวกันทุกหน้าต่าง รวมถึง address bar ด้วย
http://tablang.mozdev.org/

2. xmarks เป็น bookmark sync กับ server ใน internet สามารถใช้ได้กับ firefox , ie , chrome
http://download.xmarks.com/download/all

3. Open Link in เอาใช้ใช้ Open Link in Backgroud Window
https://addons.mozilla.org/en-US/firefox/addon/379

Friday, October 30, 2009

OpenDocument

The most common filename extensions used for OpenDocument documents are:

.odt for word processing (text) documents
.ods for spreadsheets
.odp for presentations
.odg for graphics
.odf for formulae, mathematical equations

ซึ่ง OpenOffice support อยู่แล้ว
ส่วน Microsoft Office จะต้องลง ODF Plugin จาก SUN สามารถ download ได้จาก
http://www.sun.com/software/star/odf_plugin/

หรือ OpenXML/ODF Translator Add-in for Office
http://sourceforge.net/projects/odf-converter/

ส่วนโปรแกรมอื่นที่ support OpenDocument สามารถดูได้จาก
http://en.wikipedia.org/wiki/OpenDocument_software

Thursday, October 29, 2009

Disable Offline File via GPO

ทำทั้ง Computer Configuration และ User Configuration

โดยอยู่ที่ Administrative Template/Network/Offline File

Monday, October 26, 2009

วิธีการ set Proxy โดยใช้ GPO

การ set proxy (ระบุว่าจะให้ใช้ proxy ip:port อะไร)
User Configuration/Windows Settings/Internet Explorer Maintenance/Connection/Proxy Setting

Config Per Computer Setting
Computer Configuration/Administrative Template/Windows Component/Internet Explorer/Disable Changing Proxy setting
Computer Configuration/Administrative Template/Windows Component/Internet Explorer/Make Proxy Setting Per Machine

ห้าม user เปลี่ยน proxy
User Configuration/Administrative Template/Windows Component/Internet Explorer/Disable Changing Proxy setting

Endian สามารถตั้งค่า browser ได้โดยใช้ Automatic Configuration Script โดยการชี้ไปที่ http://[endian]/proxy.pac


Thursday, October 22, 2009

Dell Storage

PERC = PowerEdge Expandable RAID Controller


การ Config Raid ของ Dell PowerEdge
1. กด CTRL-R เพื่อเข้าหน้าจอ config
2. ไปที่ Vitrual Disk 0 กด F2 เลือก Delete VD เก่าออก
3. hilight ที่ No Configuration Present กด F2 เพื่อสร้าง VD ขึ้นมาใหม่
4. ที่ Raid Level สามารถเลือก Raid 0 , 1, 5 ได้
5. Physical Disk เลือก HD ที่จะเอาเข้ามาทำ Raid โดยการใช้ Spacebar กดเลือก
6. ที่ VD ที่สร้างขึ้นมาใหม่กด F2 เลือก Initialize / Fast Init
7. reboot เครื่อง

Note
- กรณีที่ HD เก่ามีข้อมูลอยู่แล้ว เช่นนำมาจากเครื่องอื่นที่ใช้ raid รุ่นเดียวกัน ให้ใช้การ Import Foreign disk จาก Dell Server Admin
- ถ้าระบบมี Raid 5 อยู่แล้วต้องการเพิ่ม HD ใหม่เข้าไปโดยไม่ต้องการให้เข้ากลุ่ม raid เดิม คือให้เป็น standalone disk จะต้องสร้าง VD ขึ้นมาใหม่เช่น VD 1 ให้เป็นชนิด Raid 0 แล้วเพิ่ม HD ลูกนี้เข้าไป เสร็จแล้วก็ทำ Init เป็นอันเสร็จ

Tuesday, September 29, 2009

Kaspersky Rescue Disk

Download ไฟล์สำเร็จรูปได้จาก
http://devbuilds.kaspersky-labs.com/devbuilds/RescueDisk/
เสร็จแล้วเอามา update datafile ให้ล่าสุดได้จาก wizard
มันจะสร้างไฟล์ใหม่ขึ้นมาให้เอง

Friday, September 04, 2009

Kaspersky Convert Activation Code to Keyfile

ในบางกรณีเราอาจอยากจะใช้ key file แทน activation code ที่ได้มาจากการซื้อแบบกล่อง retail ก็ได้ เช่น กรณีที่เอาตัว mod KIS ไปลงที่ server จะไม่มี ให้ใส่ activation code จึงต้องใช้ key file แทน มีวิธีแปลงได้ จากเวปนี้

https://activation.kaspersky.com/en/index.html

Sunday, August 23, 2009

Secure Installation of Microsoft SQL Server 2000

Concept คร่าว

1. Drive ที่เก็บ database เอาไว้ห้ามทำ Compression เอาไว้เพราะจะทำให้ sql ทำงานช้าลงมาก

2. run sql service โดยใช้ account ที่สร้างขึ้นมาใหม่โดยเฉพาะ โดยให้เป็น user ธรรมดา แล้ว SQL Server จะ assign permission ต่างๆที่จำเป็นให้เองตอน Install อย่า run sql server โดยใช้ Local System Account เด็ดขาด

3. Authentication Mode ให้ใช้ Windows Authentication Mode เพราะเป็นการบังคับให้ user ที่จะใช้งาน sql นั้นจะต้อง login เข้า domain ก่อน อย่าเลือก Mixed Mode โดยเด็ดขาด

4. ลง SQL SP4

5. ลง Post SP4 hotfix ล่าสุดคือ build 2282 download ได้จาก http://www.microsoft.com/downloads/details.aspx?familyid=a93f3cfe-18c9-4218-a551-13bf415e418a&displaylang=en

สำหรับ Post SP4 Analysis Service build 2174 download ได้จาก
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=9c9ab140-bdee-44df-b7a3-e6849297754a

สามารถ check build ของ sql server ล่าสุดได้จากเวป
http://www.bigdatabaselist.com/wiki/SQL_Server_Version_Builds

Note

- ถ้ามีปัญหาเกี่ยวกับ replicate olap ให้ add user account ที่ run sql ให้อยู่ใน olap administrator

วิธี Check version ของ SQL Server

สำหรับ SQL 2000 เปิด Query Analyzer แล้วใช้คำสั่ง 
SELECT  SERVERPROPERTY('productversion'), SERVERPROPERTY ('productlevel'), SERVERPROPERTY ('edition')

หรือ

Select @@version

 
The following table lists the Sqlservr.exe version number. 

ReleaseSqlservr.exe
RTM2000.80.194.0
SQL Server 2000 SP12000.80.384.0
SQL Server 2000 SP22000.80.534.0
SQL Server 2000 SP32000.80.760.0
SQL Server 2000 SP3a2000.80.760.0
SQL Server 2000 SP42000.8.00.2039
 

http://sqlserverbuilds.blogspot.com/


http://www.sqlteam.com/article/sql-server-versions


Saturday, August 15, 2009

Download Dell Utility DVD

Dell Systems Management Tools and Documentation (SMTD)
ใช้สำหรับ Install OS และโดยเตรียม partition ให้มองเห็น harddisk และลง Driver ล่าสุดให้
ข้อมูลของทั้ง Virtual Disk 0 จะหายไปให้ Backup เอาไว้ก่อน
ถ้ามีการใช้ Virtual Disk 1 ให้ดึงออกมาก่อนเผื่อข้อมูลหาย

Dell Systems Build and Update Utility (SUU)
เป็นแผ่นรวม BIOS และ Firmware รวมถึง Driver ด้วย ทั้งของ server เองและอุปกรณ์ต่อพ่องของ dell ที่ต่ออยู่กับ server นั้น
มันจะ scan หา BIOS, firmware, driver ของเครื่องทั้งหมด และเปรียบเทียบกับที่มีอยู่ในแผ่น
สามารถสั่ง update ได้พร้อมกันทีเดียว
ข้อควรระวังคือไม่ควร update firmware ของ harddisk อาจจะทำให้ข้อมูลหายหมด
http://ftp.us.dell.com/sysman แล้วค้นหาคำว่า SUU


Dell USB Key F6
http://ftp.us.dell.com/utility/USBKeyPrepA07.exe
- เอาไว้ใช้กับเครื่องที่ไม่มี Drive A: แล้วต้องมีการให้อ่านค่า Driver ของ PERC Raid Controller โดยการกด F6 ในระหว่างการ Install
- copy file driver ทั้งหมดใส่ลงใน folder FILE แล้ว run program

Dell CD ISO - Dell Systems Build and Update Utility
ใช้สำหรับ Install Windows 2000 Server

Dell Direct Download Link
http://ftp.us.dell.com/sysman/

Dell Online Diagnostics
http://ftp.us.dell.com/diags/dell-onlinediags-win32-2.15.0.169.exe

Note
- ไฟล์ ISO Image ของแต่ละ ISO ที่ download มาจะมีอยู่ 2 ไฟล์ จะต้องเอามารวมเข้าด้วยกันด้วยคำสั่ง

copy /b source1.iso + source2.iso out.iso

- บางทีต้องทำการ update ซ้ำหลายครั้งกว่าจะสมบูรณ์
- ไม่สามารถใช้ SUU update Windows XP ได้
- Install Windows Server 2000 จะต้อง download แผ่น version 5.3 มาใช้ และเป็นแผ่น CD เวลา install ให้ตอบว่า ไม่ต้องลง Dell Open Manage เพื่อที่จะได้ไม่ต้อง download แผ่น Open Manage 5.3 อีกแผ่น เพราะเสียเวลามาก
- Install Windows 2000 โดยให้อ่าน driver PERC5/i จาก usb โดยการกด F6 ไม่ได้ผล ต้องใช้แผ่น 5.3 ถึงจะ install ได้
- ใน bios ให้ set usb emulate type ไว้เป็น Floppy Disk
- Dell Open Manage สำหรับ Windows 2000 Server ที่จะใช้ได้คือ Version 5.5
- ไฟล์ของ Open Manage ที่จะเอามาลงจะเรียกว่า Mannode


Tuesday, August 11, 2009

Copy a Folder to Another Folder and Retain its Permissions

วิธีง่ายๆมี 2 วิธี ที่ฟรี

1. ใช้ xcopy
http://support.microsoft.com/kb/323007
เช่น
xcopy c:\olddocs c:\newdocs /O /X /E /H /K

2. robocopy จาก resource kit ของ Windows 2003
http://www.enterprisenetworkingplanet.com/netos/article.php/3719606
- ถ้าไฟล์ถูก lock เพราะว่ากำลังถูกใช้งานอยู่มันจะ สามารถทำงานต่อไปได้

copy folder ไปยังอีก server นึง สามารถใช้ \\ ร่วมด้วยได้
robocopy d:\userdata\bob e:\userdata_backup\bob /copyall /e

mirror ข้อมูล (สามารถ copy เฉพาะไฟล์ที่เปลี่ยนแปลงได้ด้วย) จะลบข้อมูลปลายทางด้วยถ้าต้นทางโดนลบไปแล้ว
robocopy d:\userdata\bob e:\userdata_backup\bob /copyall /mir

/R:0 ให้ข้ามไฟล์ที่ถูก lock ไป
/W:0 รอนานเท่าไหร่ถึงจะ retire

3. robocopy GUI 3.1.2
http://download.microsoft.com/download/f/d/0/fd05def7-68a1-4f71-8546-25c359cc0842/UtilitySpotlight2006_11.exe

Note
- อย่าลืมเปิด CMD ด้วย run as administrator ไม่งั้นจะ copy ไม่ได้

Thursday, August 06, 2009

Remote Control to Console Session

บางครั้งเราต้องการที่จะ Remote ไปควบคุม Console Session แต่จะเจอ error ว่า

"Can't remote control Session (ID 0) because Remote Control is disabled
on that session"

แก้โดยการใช้ command line mstsc.exe /console แล้วให้ connect กลับมาที่ server ใหม่จะสามารถ control console session ได้



mstsc.exe - when connecting to Server 2003-based system will begin a new interactive session independant of the console session

mstsc.exe - when connecting to XP or Vista will connect to the console session as virtual interactive sessions are not supported

mstsc.exe /console - connecting to a Server 2003-based system will enable you to connect to the 0 console session


Once connected to your server, whether console or other interactive session, you can launch the task manager > click on the Users tab > view interactive sessions 0, 1, 2 etcetera.


If you right-click on any of the listed sessions that are not your current session, the options you receive are:

- Connect
- Disconnect
- Log off
- Remote Control

By this method you can log off or connect to any existing session.

Example:

The user is logged on to the home server via mstsc.exe /console from their home computer (session ID 0). The user closes the mstsc window and leaves their session active with tasks running. The user then connects to the home server via mstsc.exe without the /console switch and is then given a new interactive session with ID 1.


Wishing to reconnect to her 0 session and logoff session 1, she:

1. Launches the task manager
2.Navigates to the Users tab
3.Right-clicks the ID 0 session
4.Clicks Connect > the view then changes to session 0 with full interactive capability.
- Session 1 still remains logged in but will show as Disconnected.
5.From session 0 she launches the task manager
6.Navigates to the Users tab
7.Right-clicks session 1 and clicks Logoff
- Session 1 is now gone and the only active session is the 0 console session which she is currently connected to.

Tuesday, July 28, 2009

Zyxel WAN Backup Link

Router 783H สามารถทำ WAN Backup Link ได้ โดยจะอยู่ในหัวข้อของ WAN

Backup Type
- DSL Link จะเช็กว่า adsl หลุดหรือเปล่า
- ICMP จะเช็กโดยการ ping ไปยัง WAN IP ทั้ง 3

Fail Tolerance
- Default = 2 คือจำนวนครั้งในการ ping ไปยัง WAN IP

Recovery Interval
- Default = 30 sec คือเวลาที่ใช้ในการเช็กว่า link up กลับคืนมาหรือยัง

Timeout
- เวลาที่ใช้ในการรอการตอบกลับจาก ping ทดสอบ WAN IP ที่ได้ set เอาไว้
- Default = 30 sec

Traffic Redirect
- ให้ใส่ IP ของ Backup Gateway ที่สำรองไว้ จะต้องมี IP อยู่ในวงเดียวกันถึงจะใช้งานได้ สามารถใช้ ip alias ร่วมด้วยได้
- เช่น router หลักใช้ 192.168.3.1 router สำรองก็จะต้องใช้ ip ของวง 192.168.3.x ด้วย โดยสามารถใช้เป็น ip alias ได้ คือ router สำรอง อาจจะมี ip หลักคือ 192.168.2.x ก็ได้
- ถ้าเปลี่ยนไปใช้ back link เมื่อไหร่ ภายนอกจะไม่สามารถ remote เข้ามาได้ แต่ภายใน สามารถทำงานได้อย่างปกติ

Sunday, June 14, 2009

3Com User and Password

3com Switch รุ่น 4500 , 5500 จะแบ่ง level ของ user ออกเป็นหลายระดับ สามารสร้างเพิ่มได้ และสามารถเปลี่ยนระดับของการ config คล้ายกับของ Cisco

ที่ใช้โดยทั่วไปคือ user admin
และเมื่อต้องการเข้าไป config ก็จะเปลี่ยน mode โดยใช้คำสั่ง system-view
เมื่อต้องการกลับออกมากด ctrl-z
สั่งอะไรไปแล้วอย่าลืมสั่ง save ด้วย

default แล้ว passwd จะยาว 10 ตัวอักษร สามารถเปลี่ยนความยาวได้จาก system-view
โดยใช้คำสั่ง password-control length 4 [เปลี่ยนให้มีความยาวอย่างน้อย 4 ตัวอักษร]

Saturday, June 13, 2009

GPO สำหรับ Internet Explorer และ Windows Explorer

ลบ Cache ทุกครั้งหลังจากปิด IE (User Config ก็มีด้วย)
Computer Config/Admin template/Internet Explorer/Internet Control Panel/Advance page/Empty Internet files ....



Turn Off inline autocomplete in windows explorer
User Config/admin template/Internet explorer/Internet setting/autocomplete

Turn on classic shell (อย่าใช้ไม่ work)
User Config/admin template/Windows Explorer/Windows Explorer

Tuesday, June 09, 2009

Sunday, June 07, 2009

วิธีการ Update Firmware ของ 3Com Switch 4500 , 5500

อย่างคร่าวๆ ถ้าละเอียดให้ไปอ่านเอาจาก Release Note version เก่าๆ (version ใหม่ๆไม่ได้บอกรายละเอียดของคำสั่งที่ใช้)

1. หลังจากที่ downlaod firmware ตัวใหม่มาแล้ว แตกไฟล์ออกมาจะพบกับไฟล์นามสกุลนี้คือ

.app เป็น switch application software
.btm เป็น switch boot ROM software
.web เป็น switch web file for http management

2. install tftp server แล้ว config ให้ไปมองที่ folder ที่เก็บไฟล์ที่แตกออกมา
3. telnet ไปที่ switch ใช้คำสั่ง dir เพื่อดูชื่อไฟล์อันเก่า และเนื้อที่ว่าง
4. ลบไฟล์เก่าออกเพื่อให้มีที่ว่างพอจะเก็บไฟล์ใหม่ทั้ง 3 ไฟล์ลงไป โดยใช้คำสั่ง
delete /unreserved flash:/[filename]
ทำจนครบทั้ง 3 ไฟล์แล้ว dir ดูอีกทีจะเห็นได้เนื้อที่ว่างเพิ่มขึ้น
5. ใช้ tftp ดึงไฟล์ใหม่มาจาก tftp server โดยคำสั่ง
tftp [ip tftp server] get [filename]
ทำจนครบ 3 ไฟล์
6. สั่งให้ switch ไปใช้ boot loader ตัวใหม่
boot boot-loader flash:/[filename.app]
7. สั่งให้ไปใช้ boot rom ตัวใหม่
boot bootrom flash:/[filename.btm]
8. สั่ง save เสร็จแล้วสั่ง reboot
9. telnet เข้าไปอีกครับ แล้วสั่งให้ใช้ web package ตัวใหม่
boot web-package [filename.web] main
10. สั่ง save และ reboot อีกครั้ง

http://support.3com.com/documents/switches/4500/Switch_4500_V3_03_00_Release_Notes.pdf

Friday, May 08, 2009

วิธี Audit file และ Folder

Concept
- Enable Audit Polocy สำหรับ audit file และ folder ต้องเลือก audit ที่ "Audit Object Access"
โดยไปที่ Computer Configuration/Windows Settings/Security Setting/Local Policy/Audit Policy/Audit Object Access เลือกว่าจะให้ audit กรณีไหน Failure , Success
-ไปที่ Object ที่ต้องการ audit เช่น file หรือ folder ก็ได้ click ขวาเลือก properties ไปที่แถบ Security กดปุ่ม Advanced ไปที่แถบ Audit แล้วใส่ User หรือ Group ที่ต้องการ Audit เสร็จแล้วเลือกว่าต้องการให้ audit กรณีไหนบ้างเช่น Delele file and folder และที่สำคัญ ห้ามเลือก Apply these auditing entries to objects and/or containers winthin this container only โดยเด็ดขาด ไม่งั้น มันจะไม่มีผลกับ object ที่อยู่ภายใน
- วิธีดู Event Log จะอยู่ใน Security Log แต่จะมีเยอะมาก จะต้องทำ Filter ดูเฉพาะ Source และ Category ที่ต้องการจะดูเท่านั้นเช่น Source = Security , Category = Object Access ถ้าจะดูว่าลบอะไรต้อง Click เข้าไปดูข้างใน

Note
- ต้องระวัง Log เต็มให้เพิ่มขนาด log ให้มีขนาดใหญ่พอที่จะเก็บข้อมูลได้นาน 1-2 เดือน
- สำหรับ Windows Server 2008
http://blogs.dirteam.com/blogs/jorge/archive/2008/04/29/auditing-in-windows-server-2008.aspx

การใช้ Filter สำหรับการหาไฟล์ที่ถูก Delete

1. Event ID ที่เกี่ยวข้องคือ 4663 , 4656
2. Event Level = Information
3. Event Sources = Microsoft-Windows-Security-Auditing
4. Task Catagory = File System
5. Keyword = Audit Success
6. เมื่อสร้าง Filter เสร็จแล้วสามารถ Save ให้เป็น Custom Filter ได้ด้วย

Friday, May 01, 2009

Noise Margin and Line Attenuation

Noise Margin (ยิ่งมากยิ่งดี)
5db or below =bad, no sync/intermittent sync
8db-13db = average - and no sync issues
14db-22db = very good
23db-28db = excellent
29db-35db = rare, can throw a rock at co/remote

Line Attenuation (ยิ่งน้อยยิ่งดี 0=node)
ต่ำกว่า 20 = rare, great copper lines, close to co/remote
20-30 = excellent
30-40 = very good
40-60 = average
60-65 = poor
65 and above will have issues

Monday, April 27, 2009

Transfer Domain from NSI to GoDaddy

ขั้นตอนสรุปคร่าวๆ

1. ไป unlock domain protect ที่ nsi ก่อน มันจะส่ง authorization code มาให้ (default มันจะ lock มาให้เลย)
2. หลังจากที่สมัครการย้าย Domain ที่ godaddy แล้ว มันจะส่ง Transaction ID และ Security Code ให้
3. ใน godaddy ไปที่ my account section domain transfer แล้วก็ไปใส่ transaction id , security code , authorization code
4. รอ 5 วัน ไม่จะเป็นต้องตอบรับหรือทำอะไร

---------------------
1. ขอเปลี่ยนอีเมลในส่วน Admin Contact เป็นที่ท่านสามารถเช็คได้ เพื่อความสะดวกในการย้ายโดเมนเน
 เนื่องจากต้องมีการคลิกยืนยันการย้ายโดเมนนะค่ะ

2. ขอ unlock โดเมนเนม

3. Request ให้ส่ค่า AuthCode มาให้ทาง email (บางที่ถ้าปลด lock จะส่ง AuthCode มาให้เองไม่ต้องขอ)

4. *** สำคัญมากค่ะ หากมีการตั้งค่า Protect Privacy ของโดเมนเนมไว้ รบกวนทางบริษัทที่ดูแล Disable ในส่วนนี้ด้วยค่ะ

ระหว่างการย้ายโดเมนเนมไม่มีผลต่อการออนไลน์หน้าเว็บไซต์เดิม (หากโดเมนเนมและเว็บไซต์ที่เดิยังไม่หมดอายุ)

-------------------------------------


Monday, April 20, 2009

การปลด lock google apps

บางกรณี Account บาง Account ใน Google Apps อาจจะถูก lock เองได้ (เช่นใส่ password ผิดหลายๆครั้งเป็นต้น)
ซึ่งจะทำให้ไม่สามารถรับส่ง mail ทาง pop กับ smtp ได้ แต่สามารถเข้าทาง webmail ได้
สามารถทำการปลด lock ได้โดยเข้าที่ที่นี่
https://www.google.com/a/[yourdoamin.com]/UnlockCaptcha


สำหรับ account gmail ปกติ สามารถปลด lock ได้จาก

https://www.google.com/accounts/DisplayUnlockCaptcha

ถ้าไม่ได้จริงๆให้เข้าที่นี่แทน สามารถปลด lock ได้ทั้ง gmail และ google apps
https://accounts.google.com/DisplayUnlockCaptchaV2

Sunday, April 19, 2009

SPF Records for Google Apps

SPF = Sender Policy Framework เอาไว้ระบุว่าสามารถส่ง mail ได้จาก server เครื่องไหนบ้างเพื่อป้องกันคนอื่นแอบส่ง email ในนามของ domain เราเอง คือทาง mail server ของผู้รับปลายทางจะสามารถตรวจสอบได้ว่า email ถูกส่งมาจาก mail server ของ domain เราจริงหรือไม่


สำหรับ Gmail แนะนำให้ใช้ค่าดังนี้
v=spf1 include:aspmx.googlemail.com ~all

แต่มีผู้พบข้อผิดพลาดแล้วรอการแก้ไขอยู่ โดย google แนะนำให้ใช้ค่านี้
v=spf1 include:_spf.google.com ~all

เมื่อรวมกับความต้องการที่อาจจะมีการส่ง mail form จาก web server จึงแนะนำให้ใช้ค่านี้แทน
v=spf1 a mx include:aspmx.googlemail.com include:_spf.google.com ~all

โดยที่
a = สามารถส่ง mail ได้จาก server ที่ระบุไว้ใน a record (ก็คือ web server นั่นเอง กรณีทั่วๆไป)
mx = สามารถส่ง mail ได้จาก server ที่ระบุไว้ใน mx record
~all = soft fail คือจะยอมให้ส่งได้ แต่อาจจะไปเข้าที่ spam แทน (สามารถ check ดูได้จาก full mail header)

-all = fail คือจะไม่ยอมให้ส่งเลย

- spf record = คือ record type เป็นชนิด txt ใน dns version ใหม่อาจจะรู้จัก record spf ได้เลย
- ถ้าดูใน dns zone เต็มๆจะเห็นเป็นเช่น example.com. IN TXT "v=spf1 -all"
- mail server ฝั่งรับจะเป็นฝ่าย check spf ว่าจะตัดสินใจรับ mail ที่ส่งมาแบบไหน

Validate SPF
http://www.kitterman.com/spf/validate.html

อ่านเพิ่มเติมได้ที่
http://old.openspf.org/wizard.html


http://www.zytrax.com/books/dns/ch9/spf.html


http://www.hybrid6.com/webgeek/2009/03/google-provides-incorrect-spf-record-info-for-google-apps.php

http://www.labnol.org/internet/authenticate-google-apps-email-with-spf/13877/

Note
- กรณีที่เข้า webmail.xxx.com จากภายในบริษัทไม่ได้ จะต้องไปเพิ่ม cname record ใน dns server ให้เป็น
webmail = ghs.xxx.com แล้วจะเข้าได้


การตรวจสอบ spf record
1. ใช้ nslookup set record type=txt
2. ส่ง blank mail ไปที่ spf-test@openspf.org หรือ check-auth@verifier.port25.com
รอการ reply กลับมา ดีที่ spf check ว่า pass

Tuesday, April 07, 2009

Using POP on multiple clients.

Leave mail on Server จะไม่มีผลเมื่อใช้ POP กับ Gmail
วิธีแก้ก็คือเพิ่ม recent: เข้าไปข้างหน้า username แล้วมันจะสามารถดึง mail ย้อนหลังได้ 30 วัน
แต่ต้องอย่าลืมเลือก enable Leave mail on Server เอาไว้ด้วย
แต่ยังมีข้อเสียคือ มันจะ download mail ที่เราเป็นคนส่งเองกลับมาด้วย
วิธีแก้ใจ outlook ให้สร้าง mail rule แล้วตั้งว่า do not download from server เอาไว้ สำหรับเมลที่ส่งจากตัวเอง

gmail แนะนำให้ใช้ imap แทน เพราะมีข้อดีเช่น สามารถ report spam ได้โดยการย้ายเมล์ไปไว้ใน folder spam แต่ imap ก็ยังมีความไม่สะดวกหลายอย่าง

smtps server = smtp.gmail.com:465
pops server = pop.gmail.com:995
imaps server = imap.gmail.com:993
smtps สำหรับ Outlook 2007 = port 587 TCP Outbound (encryption = TLS)

Wednesday, January 14, 2009

BOOT.INI ที่สามารถใช้ได้กับ partition เกือบทุกอัน

[Boot Loader]
timeout=30
Default=multi(0)disk(0)rdisk(0)partition(1)\Windows

[Operating Systems]
multi(0)disk(0)rdisk(0)partition(1)\Windows="1ST TRY THIS seleccione esto primero" /fastdetect
multi(0)disk(0)rdisk(1)partition(1)\Windows="2ND TRY THIS essayez ceci en deuzieme" /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\Windows="3RD TRY THIS wahlen Sie diesen Third" /fastdetect
multi(0)disk(0)rdisk(1)partition(2)\Windows="4TH TRY THIS selezioni questo fourth" /fastdetect
multi(0)disk(0)rdisk(0)partition(3)\Windows="5TH TRY THIS selecione este fifth" /fastdetect
multi(0)disk(0)rdisk(1)partition(3)\Windows="6TH TRY THIS seleccione este sexto" /fastdetect
multi(0)disk(0)rdisk(0)partition(4)\Windows="7TH TRY THIS essayez ceci en septieme" /fastdetect
multi(0)disk(0)rdisk(1)partition(4)\Windows="8TH TRY THIS wahlen Sie dieses achte" /fastdetect
C:\="9TH TRY THIS selezioni questo nono"
D:\="10TH TRY THIS selecione este decimo"

Monday, December 22, 2008

OpenVPN สามารถใช้งานหลัง NAT ได้ทั้งได้ Server และ Client

http://www.itdestination.com/articles/openvpn/

วิธีเพิ่ม RDP Listening Port ของ Terminal Server

How can I add a new RDP listening port to Windows 2000/2003 Terminal Server?

http://www.petri.co.il/add_a_new_rdp_listening_port_to_terminal_server.htm

Monday, December 15, 2008

Enabling the ISA Server 2004 VPN Server

การ set vpn ให้ connect จาก WindowsXP,2003,XP ไปยัง ISA Server ที่อยู่หลัง NAT ผ่าน PPTP หรือ L2TP ถ้า ISA Server มี IP จริงสามารถใช้ L2TP ได้แต่ถ้าไม่มี IP จริงแล้วใช้การ Forward port จะต้องใช้ PPTP แทน โดย forward port 1723 TCP มาที่ ISA ด้วย
http://www.isaserver.org/articles/2004vpnserver.html

Tuesday, December 09, 2008

Open Port for PPTP VPN

ถ้าต้องการใช้งาน PPTP ที่อยู่หลัง Firewall หรือ NAT ทำให้ไม่ได้รับ IP จริง จะต้องทำการ forward port หรือเปิด port ให้กับ port 1723 TCP จึงจะสามารถใช้งานได้

ส่วน L2TP VPN จะไม่สามารถใช้งานได้ถ้าอยู่หลัง NAT เพราะว่าจะต้องมี IP จริง

Tuesday, November 25, 2008

Remote Assistance for Corporate

ปกติแล้วการจะใช้งาน Remote Assistance นั้นจะต้องมีการ invite ก่อนเสมอ แต่สำหรับการใช้งานแบบ Helpdesk ภายในบริษัทนั้น เราสามารถใช้ GPO เข้ามาช่วยให้ไม่ต้องมีการ invite ก่อนก็ได้ โดยมีวิธีการดังนี้

1. ใช้ GPO ไปที่ Computer Configuration/Administrative Template/System/Remote Assistance และ Enable Offer Remote Assistance
2. เลือก Helper ที่จะสามารถ remote เข้ามาใช้งานหน้าเครื่องได้ โดยให้อยู่ใน format ดังนี้ DOMAIN\USERNAME โดยที่ User นั้นจะต้องเป็นสมาชิกของ Local Administrator
3. จากเครื่องของ Helper ให้ไปที่ Help and Support/Tool/Offer Remote Assistance แล้วใส่ IP หรือชื่อเครื่องที่ต้องการ Remote เข้าไป
4. ที่หน้าเครื่องของ user จะมี popup ขึ้นมาให้ถามว่าจะยอมให้ remote เข้ามาควบคุมหรือไม่

NOTE
- ยังไม่ได้ทดสอบให้แน่ใจ หลายๆอย่าง เช่น การ block remote assistance , firewall
- ถ้า user ที่ไม่ได้อยู่ใน list ของ helper เวลา remote ไปจะขึ้นว่า Permission Denied
- เครื่องที่ connect เข้าไปถ้าไม่ได้อยู่ใน domain เดียวกัน จะไม่สามารถ remote เข้าไปได้
- ใน helper list สามารถเพื่ม group ก็ได้ ไม่จำเป็นจะต้องเป็น user เท่านั้น เช่น DOMAIN\administrators ก็ได้เหมือนกัน
- GPO ที่อยู่ติดกับ Offer Remote Assistance ก็คือ Solicited Remote Assistance เราสามารถ Disable เอาไว้ได้ ไม่มีผลต่อการใช้ Remote Assistance ใน Corporate
- เมื่อ Enable Offer Remote Assistance ใน GPO แล้วจะทำให้ตัวเลือกของ Remote Assistance ที่อยู่ใน tab Remote ของ System ได้ถูก Enable เอาไว้ด้วย แต่ยังไม่ได้ลองว่า user จะสามารถส่ง Invite ออกไปทาง Msn หรือทาง Email ได้หรือเปล่า

http://www.petri.co.il/enable_remote_assistance_offering_in_xp_2003.htm
http://www.petri.co.il/offer_remote_assistance_in_windows_xp.htm

Sunday, November 02, 2008

Event ID 7000 (Service Control Manager Timeout)

To work around this problem, increase the default timeout value for the service control manager in the registry.


To increase the timeout value in the registry, follow these steps:


If the ServicesPipeTimeout value is not available, add the new DWORD value, and then set its value data to 60000 in the Control key. To do so, follow these steps: a. Locate and then click the following registry key:


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet

b. Click the Control subkey.

c. On the Edit menu, point to New, and then click DWORD Value.

d. Type ServicesPipeTimeout, and then press ENTER.

e. Right-click the ServicesPipeTimeout DWORD value, and then click Modify.

f. Click Decimal.

g. Type a value of 120000, and then click OK.

The value is 120000 milliseconds and is equivalent to 120 seconds or to one minute.


Note This change does not take effect until the computer is restarted.

Wednesday, August 27, 2008

Iphone Installer / Cydia Repositories

http://xsellize.com/installer

Tuesday, August 26, 2008

Arcserve Job Script and Job Template

Job Scripts

You can save any type of job as a script. The script contains the source, destination, and options that you selected, as well as the schedule information. It also contains any filters you created to include and exclude files and directories.

Creating a script has the following advantages:
1. You can re-use the same settings at a later time.
2. You can copy your settings to a different network machine running BrightStor ARCserve Backup.
3. You can quickly resubmit regularly executed jobs after a job has been accidentally deleted.

To use a script, go to the Job Status Manager and use the Add Job button. When you specify the job script name, all of the information that you set when you saved the job script will be used, including the files and directories and the scheduling information.

Create and Use Job Scripts

To create a script, perform the following procedure:
1. Set up the job.
Select the source, destination (if required), scheduling method, and any options or filters.
2. Click Start.
3. Fill in the requested security (and for backups, agent) information.
4. When the Submit Job dialog appears, click Save. (ปุ่ม save job ที่อยู่ทางด้านขวามือ ของ Dialog)
The Save Job Script dialog appears.
5. Give the script a name.
BrightStor ARCserve Backup scripts are stored in the BrightStor ARCserve Backup home directory by default, extension ".asx". You can specify a different directory in which to save your script. You can also provide a job description in the edit text box.
6. Click Save.

Note: You can also save job scripts using the Save or Save As options from the File menu.
To use a script, perform the following procedure:
1. Open the Job Status Manager.
2. Click Add Job. (ไม่ได้อยู่ใน menu แต่ให้ click ขาวในหน้า Job Status)
3. Specify the script file name.

Job Templates

A job template contains a series of settings such as the destination, options, and schedule information for the job. Similar to job scripts, a template can also contain any filters you created to include and exclude files and directories.

Job templates are different from job scripts because they provide the flexibility to repeat custom backup schedule settings on other BrightStor ARCserve machines. Because the job template does not retain the backup source information as the job script does, the template files can be copied and applied to any new server source running BrightStor ARCserve Backup. Job scripts, on the other hand, cannot be modified to accommodate new server sources.

You can choose from seven default job templates or you can create a custom template to meet your individual backup needs. The default job templates are designed to meet specific backup tasks such as rotation scheme, backup method, and GFS options. The default job templates can be accessed from the File menu when you choose the Open Job Template option.

Create Job Templates

You can create a custom job template that you can save for future jobs on any BrightStor ARCserve Backup machine.

To create a job template:
1. Open the Backup Manager by selecting Backup Manager from the Quick Start menu.
2. Make selections for your backup job by accessing the Source, Destination, and Schedule tabs.
3. Submit your job by clicking the Start button.
4. Click Save Template in the Submit Job dialog box to save your new job template with an .ast filename extension.

While default job templates are stored in the Templates/Jobs folder in the BrightStor ARCserve Backup directory, you can save your template in any directory you want. To open your custom job template on a local machine or from a remote server, access the File menu and choose the Open Job Template option. Once the job template is open, you can submit your job.

Zyxel Backup and Restore Config

ftp to zyxel with user root
for backup get rom-0
for restore put rom-0
zyxel will auto reboot

all information include ip address and user/password will change to new config

Thursday, August 07, 2008

ท่อ PVC

ท่อ PVC ให้ใช้ยี่ห้อท่อน้ำไทย

ท่อเดินเมนทั่วไป ชั้น 8.5 ขนาด 2 นิ้ว
ท่อเดิน ขึ้นบ้านทุกจุด 1 นิ้ว
พอจะออกมาที่ จุดก๊อก จึงลดโดยใช้ข้อลดเหลี่ยม
จาก 1 เป็น 1/2 นิ้วครับ

จุดที่มีการเปลี่ยนจากท่อ PVC เป็นเหล็ก
ต้องใช้ข้อต่อเกลียวใน แบบทองเหลือง ฝังในตัว PVC ครับ

ท่อน้ำทิ้ง ชั้น 5 ขนาด 2 นิ้ว
ท่อส้วม ชั้น 5 ขนาด 4 นิ้ว

ชั้น 8.5 หมายถึง ทนแรงดันได้ 8.5 kg/ ตารางซม. ครับ
ชั้น 5 หมายถึง ทนแรงดันได้ 5.0 kg/ตารง ซม. ครับ

ทุกๆ 1 kg หมายถึง เท่ากับ แรงดันที่เกิดจากน้ำสูง 10 เมตรครับ
ดังนั้น 8.5 หมายถึง ทนแรงดันได้ เท่ากับ การตั้งแท้งค์น้ำไว้สูง 85 เมตรครับ
ซึ่งยังไม่เห็นมีใครทำ

อย่างมาก 25 เมตรก็สูงลิบแล้ว

(ยกเว้นอาคารใหญ่ๆ) จะเป็นระบบท่ออีกอย่างหนึ่ง

เครดิต น้าพร@pantip

Tuesday, July 22, 2008

Note for Receriver

Astro ทอง ใช้ encryption แบบ NDS Version 1 หรือบางทีเรียกว่า VideoGuard

LNB ของ Astro เป็นแบบ Universion คือ LO = 09750 , HI = 10600, Threshold = 11700
LNB ของ UBC ใช้ LO/HI = 11300 , Threshold = 11700
LNB ของ C-band ใช้ 05150 ทั้ง LO/HI , Threhold = 11700

Tuesday, May 27, 2008

How to convert an IP address from the firewall log into a dotted IP address.

แบบที่ 1

SELECT
CAST(SourceIP / 256 / 256 / 256 % 256 AS VARCHAR) + '.' +
CAST(SourceIP / 256 / 256 % 256 AS VARCHAR) + '.' +
CAST(SourceIP / 256 % 256 AS VARCHAR) + '.' +
CAST(SourceIP % 256 AS VARCHAR) AS [Nice Source Ip], FirewallLog.*
From FirewallLog

แบบที่ 2 สร้าง Function เอาไว้ให้เรียกใช้งานได้ง่าย

set ANSI_NULLS ON
set QUOTED_IDENTIFIER ON
go

CREATE FUNCTION [dbo].[ConvertLongIP]
(
@LongIP bigint
)

RETURNS varchar(15)
AS
BEGIN

DECLARE @DotIP varchar(15),
@bin varbinary(4)
select @bin = cast(@LongIP as varbinary(4))
select @DotIP = cast(convert(int,substring(@bin,1,1)) as varchar(3)) + '.'
+ cast(convert(int,substring(@bin,2,1)) as varchar(3)) + '.'
+ cast(convert(int,substring(@bin,3,1)) as varchar(3)) + '.'
+ cast(convert(int,substring(@bin,4,1)) as varchar(3))
RETURN @DotIP
END

การลบข้อมูลใน SQL 2005 ที่เก่ากว่า 90 วัน

แบบที่ 1
DELETE FROM WebProxyLog where LogTime < (getdate() - 90) DELETE FROM FirewallLog where LogTime < (getdate() - 90) แบบที่ 2 ดีกว่า ลบได้แน่นอนกว่า delete from firewalllog where datediff(dd,logtime,getdate()) > 90
delete from webproxylog where datediff(dd,logtime,getdate()) > 90
select logtime from firewalllog where datediff(dd,logtime,getdate()) > 1

ได้ผล แต่ต้องรอ 2 วัน ดีกว่าการใช้ แบบที่ 1

ถ้าใช้ SQL Express Edition ที่ไม่มี Scheduler จะต้องใช้ Schedules Tasks ของ Windows แทนเช่น
sqlcmd -S .\ISALOG -d ISALOG d:\ISALOG\cleandatabase.sql
แล้วค่อยใส่คำสั่ง delete from ... ลงไปในไฟล์ cleandatabase.sql

-S = ชื่อ server , . หมายถึง localhost , \ISALOG คือชื่อ Instant
-d = ชื่อ database
-i = ชื่อ sql script

http://msdn.microsoft.com/en-us/library/aa258269(SQL.80).aspx

Monday, May 26, 2008

วิธี Block MSN หรือ Windows Live Messenger

Concept ใช้ได้กับ Firewall เกือบทุกตัว
ให้ Block MSN protocal ที่ใช้ port 1863 เพื่อเป็นการบังคับให้ MSN เปลี่ยนไปใช้ port 80 HTTP จากนั้นค่อยทำการ block signature ของ MSN นั่นก็คือการ Block Request URL ที่มี string gateway/gateway.dll เป็นส่วนประกอบ

การ Block Signature โดยใช้ ISA Firewall
1. ไปที่ rule ที่มี http protocal รวมถึง rule ที่ยอมให้ออกหมดทุก protocal (ทุก protocal หมายถึง ทุกอันที่ define เอาไว้ใน protocal definition ดังนั้นจึงรวม http protocal เข้าไปด้วย) แล้ว click ขวาเลือก Configure HTTP
2. ไปที่แถบ Signature กดปุ่ม Add ใส่ข้อมูลตามนี้
Name = Block MSN
Search in = Request URL
Signature = gateway/gateway.dll


Note
สรุป port และ URL ของบริการที่ MSN ใช้
http://support.microsoft.com/kb/927847

Tuesday, May 20, 2008

ISA 2004/2006 logging using local SQL 2005

การ Config ในส่วนของ SQL Server

- Install Microsoft SQL 2005 Express Edition
- ปัจจุบันออก SP3 แล้ว จะรวมมาใน package เลย
- ในหน้า Registration Information ให้เอา checkbox Hide advace configuration option เพื่อให้สามารถตั้งชื่อ Instant ได้ให้ชื่อว่า ISALOG
- Service Account ให้เลือกเป็น Local System ตรงนี้สำคัญมากว่าจะต้องทำให้ User ที่ใช้ run service ISA Firewall กับ SQL2005 เป็น User เดียวกันไม่งั้นจะ start SQL Log ไม่ได้ ในเวป isaserver.org เป็นกรณีที่ SQL Server เป็น Server คนละตัวกับ ISA Firewall แต่ในกรณีนี้เราต้องการให้อยู่บน server เดียวกัน ดังการการ setting จึงต่างกันนิดหน่อย
- เลือก Windows Authentication Mode
- Add User to the SQL Server Administrator Role จะเป็นการเพื่ม user ที่เป็นคน install sql 2005 ให้อยู่ใน administrator role ของ SQL 2005 จะเลือกหรือไม่ก็ได้ (เลือกเอาไว้ดีกว่า)
- หลังจาก Install เสร็จแล้ว ให้ไปดูที่ Service ของ Microsoft Firewall และ SQL Server (ISALOG) run ด้วย user เดียวกันคือ Loal System ถ้าไม่ตรงก็เปลี่ยนให้ตรงกัน
Note ถ้ามีปัญหา start SQL ไม่ได้แล้วถ้าไปดูใน eventlog จะเห็นว่า error มันเกิดจากการที่ user ที่ใช้ run service ไม่ผ่าน มันไม่ได้เป็น user เดียวกับที่ไปกำหนดให้ใช้ในตอน config log ของ ISA ด้วย สังเกตุได้จากในขั้นตอนนั้นใส่ user อะไรไปก็จะ Test ผ่านหมด
- Install Microsoft SQL Server Management Studio Express
- เปิด SQL Studio Express ขึ้นมาเพื่อสร้าง Database ISALOG เอาไว้ที่ Drive D: (ถ้าไม่กำหนดเอง มันสร้างไว้ที่ Drive C:) เพราะว่าต้องเก็บ log เอาไว้ 90 วันตามพรบ ใช้เนื้อที่มาก
- ที่ Object Explorer แตกออกมาให้เห็น Database แล้ว Click ขวาเลือก New Database ตั้งชื่อ Database = ISALOG
Owner = NT AUTHORITY\SYSTEM
Path = D:\ISALOG
- สร้าง Table FirewallLog และ WebProxyLog ขึ้นมาให้อยู่ใน Database ISALOG โดยใช้ script FWSRV.SQL และ W3PROXY.SQL ที่มีมาให้อยู่แล้วใน ISA2006 folder
- ไปที่ Menu File/Open แล้วเปิด fwsrv.sql และ w3proxy.sql พิมพ์เพิ่มเข้าไปข้างบนว่า
USE ISALOG
เพื่อเป็นการบอกให้สร้าง table เอาไว้ใน Database ISALOG แล้วสั่ง Execute
- ย้อนกลับไปดูใน Datbase ISALOG จะเห็นว่ามี table เพิ่มขึ้นมา 2 table คือ dbo.firewalllog และ dbo.webproxylog
- เปิด SQL Server Surface Area Configuration ขึ้นมาแล้วไปที่ Remote Connection เปลี่ยนจาก Local connection only เป็น Local and remote connection -> Using TCP/IP only
- เปิด SQL Server Configuration Manager ขึ้นมา ไปที่ Protocal for ISALOG -> ICP/IP = Enable
ไปแถบ IP Address แล้ว Enable ทุก IP Address , ลบ Dynamic Port ออกให้ว่างๆ, TCP Port ใส่ 1433 ทุกอัน , Enable = Yes ทุกอัน
- OK แล้ว Restart SQL Service
- ไม่จำเป็นต้อง assign permission อะไรใน Database ISALOG เพราะ system สามารถเขียนข้อมูลลงไปได้อยู่แล้ว

การ Config ใส่ส่วนของ ISA Server

- เปิด Edit System Policy(อยู่ใน Task Pane ของ Firewall Policy)/ Logging/ Remote Logging /
แถบ General -> Enable this configuration group
- ไปที่ Monitoring /Logging /Configure Firewall Loggin เลือก SQL Database / Option
Server = ชื่อของ ISA Firewall
Port = 1433
Database = ISALOG
Table = FirewallLog (หรือ WebProxyLog)
Uncheck Force data encryption เพราะเราใช้ Local Database ไม่ใด้ใช้ Remote Database
เลือก Use Windows authentication
User = อะไรก็ได้ ไม่มีผลเพราะใช้งานโดย Local System
Password = อะไรก็ได้ ไม่มีผลเพราะใช้งานโดย Local System
กด Test จะผ่าน

Testing
- เปิด SQL Studio Express ขึ้นไปแล้วไปที่ New Query พิมพ์ว่า
select * from dbo.firewalllog แล้วกดปุ่ม Execute จะเห็น log ที่เก็บไว้
- ทดสอบ Webproxylog พิมพ์ว่า
select * from dbo.webproxylog
- อย่าลืมให้เลือก Database ISALOG ตรง Dropdown ด้านซ้ายบนด้วย ไม่งั้นจะ error เพราะว่ากลายเป็นการ query จาก database อื่น

Note

- ISA 2004 ใช้ ODBC แต่ ISA 2006 ใช้ Direct Access to SQL
- อย่าทำ Compress Disk กับ drive ที่เก็บ data file ของ SQL เพราะจะทำให้ performance ตกลง 500%
- เว็ปที่มีประโยชน์เกี่ยวกับ ISA อีกเวปนึง
http://www.elmajdal.net/ISAServer/

Thursday, May 15, 2008

GFI Webmonitor V.4

White List - จะ bypass กฎทุกอย่างเช่น block hi5 แต่ถ้าใส่ user ที่ไม่ต้องการ block เอาไว้ใน white list แล้วจะเข้าได้ หรืออาจจะสามารถใส่ ip หรือ hostname ของ site ที่ต้องการเข้าก็ได้เช่น *.google.com, *.yahoo.com จะทำให้ site พวกนี้ผ่านกฎทุกกฎ ดังนั้นให้ใช้อย่างระมัดระวัง

Black List - ถ้ามีชื่ออยู่ใน black list จะห้ามทุกอย่าง

Web Filtering Policies - สามารถ Edit ได้ว่าต้องการให้ Filter content ไหนออกไปได้บ้าง อาจจะนำมาใช้กับ MSN ก็ได้(ไม่ได้ผลลองแล้ว) โดยทั่วไปจะใช้ไม่ให้เข้าเวปพวกที่มี Adult Content

Download Control Policies - สามารถเอาไว้ block ไม่ให้ download ไฟล์บางประเภทได้โดยดูจาก Content-type อาจจะเอามาประยุกต์ใช้ไม่ให้ download ไฟล์บางนามสกุลได้

Virus Scanning Policies - สามารถไปกำหนดให้ Scan Virus กับไฟล์ประเภทไหนบ้าง แล้วขึ้นจะให้ขึ้น Download Status Windows หรือเปล่า ถ้าเจอ Virus จะให้ทำยังไงเช่น delete หรือ warn

Whitelist = *.eset.com สำหรับ update nod32
Blacklist = *.hi5.com

Saturday, May 10, 2008

Schedule Task

ใน Run As ให้ใช้ NT AUTHORITY\SYSTEM โดยที่ไม่ต้อง set password จะทำให้ใช้ได้ตลอด ไม่ต้องกังวลเรื่องที่จะเปลี่ยน pasword แล้ว task ไม่ยอม run

Wednesday, April 30, 2008

SM Bus Controller Driver Download

SM Bus Controller
ต้องลง Intel® Chipset Software Installation Utility สามารถ download ได้จาก http://downloadcenter.intel.com/Product_Filter.aspx?ProductID=816

สำหรับ Sound Driver
Hotfix KB888111 UAA สำหรับ SP3 ยังไม่มี ต้องใช้ของ SP2 ไปก่อนโดยไปหลอกให้เห็นเป็น SP2 โดยการแก้ registry key HKLM\SYSTEM\ControlSet001\Control\Windows\CSDVersion = 200 จาก 300 แล้วค่อย install KB888111 สำหรับ SP2 แล้วค่อย install audio driver

Saturday, April 26, 2008

ISA2006 Backup and Restore

Backup ทั้งหมด

Export
1. เปิด ISA Server Management ขึ้นมา แล้ว right click ที่ ชื่อ ISA Server เลือก Export (Backup) ทำตาม Wizard
2. ถ้าต้องการ export user passwd ที่ได้มีการ set ไว้ใน ISA จะต้องติ๊กที่ Export confidential infomation ด้วย เพื่อให้เราใส่ passwd ในการ encrypt ข้อมูลเหล่านี้เพื่อความปลอดภัย
3. ถ้ามีการ set user เพื่อ delegate จะต้องเลือก Export user permission settings ด้วย

Import
1. การ import ก็ทำคล้ายกัน แต่จะมี option ให้เลือกว่าจะ Import หรือ Overwrite(restore)
- import ข้อมูลที่ import เข้ามาจะถูกเพื่มเข้าไปเข้าไปใน configuation (ข้อมูลปัจจุบันไม่หายทั้งหมด)
- overwrite(restore) จะเข้าไปทับข้อมูลปัจจุบันทั้งหมด(ข้อมูลปัจจุบันหายหมด) เอาไว้ใช้ในกรณีที่ ISA พัง

Note
ข้อมูลที่ Export ออกมาไม่สามารถเอาไปใช้ข้าม version กันได้เช่นระหว่าง Standard กับ Enterprise ใช้กันไม่ได้

Backup แค่บางส่วน
ให้เลือก object ที่ต้องการ backup แล้ว right click เลือก import/export หรืออาจจะเลือกจาก Task Pane ก็ได้

Monday, April 21, 2008

วิธีใช้ Windows Server 2008 แบบไม่หมดอายุ

1. เวลา Install ไม่ต้องใส่ Cdkey และ Disable Auto Activate
2. Disable Service SL UI Notification เพื่อจะได้ไปสามารถลบไฟล์ออกได้
3. Take Ownership ของไฟล์เหล่านี้
c:\windows\system32\SLLUA
c:\windows\system32\SLUI
c:\windows\system32\SLUINotify.dll
4. Restart และลบไฟล์เหล่านี้ออก หรือถ้าสามารถลบออกได้โดยไม่ต้อง Restart ก็ลบไปเลย
5. Restart และทดสอบโดยการตั้งเวลาล่วงหน้าไป 1 ปี และลอง Restart อีกที แล้วลองเข้า Windows Update ถ้าทำได้ปกติ ก็แสดงว่าผ่าน

Friday, April 18, 2008

Oracle Backup

การ Backup แบ่งเป็น

1. Logical Backup
คือการ export ข้อมูล ออกมาเก็บไว้ใน dump file ข้อดีคือง่าย และไม่ต้องปิดการใช้ฐานข้อมูลขณะที่ export ปกติจะ export ข้อมูลทั้งหมดของ user แต่สามารถเลือกให้ backup ทั้ง databast หรือแค่บาง table ก็ได้

ตัวอย่างคำสั่งที่ใส่ไว้ใน batch file เช่น

exp userid=[user]/[passwd] file=[database.dmp] log=[logfile.log] rows=y

"E:\Oracle Backup\rar.exe" a -df -m5 -agYYYY-MM-DD .\Backup\ *.dmp

2. Physical Backup
เป็นการ backup ไฟล์ที่ประกอบเป็นฐานข้อมูลจริงๆ ซึ่งประกอบไปด้วย
- Control File
- Data File
- Redo Log File
- Parameter File
- Password File
- Archive File
แบ่งออก 2 แบบ คือ Cold Backup กับ Hot Backup

Cold Backup หรือ Full Backup
ประกอบด้วย 3 step คือ
1. shutdown oracle ด้วย utillity ที่ชื่อว่า svrmgrl (สำหรับ oracle8i แต่ถ้าเป็น oracle9i จะสั่งจาก SQL*Plus ซึ่งจะต้อง login ด้วย role sysdba ซึ่งเปรียบเสมือน root ของ oracle มีสิทธิ์ทำได้ทุกอย่าง)
EX
SVRMGR> connect internal (เปรียบเสมือน root ของ oracle8i )
default password of internal = oracle
SVRMGR> shutdown immediate หรือ shutdown normal

2. copy file ฐานข้อมูลต่างๆข้างบนไปเก็บไว้ในที่ปลอดภัย
EX
copy oracle_file backup_media
อย่าลืมจด path ของไฟล์เหล่านั้นเอาไว้ด้วย เวลา restore คืนจะได้เอาไปใส่ไว้ได้ถูก path

3. startup oracle
EX
SVRMGR> startup

Hot Backup
เป็นการ copy file คล้ายกับ cold backup แต่ไม่ต้อง ปิดฐานข้อมูลก่อน แต่วิธีทำจะซับซ้อนกว่า และสามารถใช้กับฐานข้อมูลที่ทำงานแบบ Archive Mode ได้เท่านั้น

1. สั่งเริ่มต้นการทำ Hot Backup ของ tablespace โดยใช้คำสั่ง
SVRMRG> alter tablespace tablespace_name begin backup;
2. คัดลอกไฟล์ของ tablespace ที่สั่งทำ backup ไปเก็บไว้ยังดิสก์สำหรับสำรองข้อมูล โดยใช้คำสั่ง copy
3. สั่งหยุดการทำ Hot Backup ของ tablespace โดยใช้คำสั่ง
SVRMRG> alter tablespace tablespace_name end backup;
4. สั่งให้ฐานข้อมูล switch log file เพื่อให้เกิดการทำ checkpoint ขึ้นในฐานข้อมูล
SVRMRG> alter system switch logfile;

วิธีการหาที่อยู่ของไฟล์ที่ต้อง Backup

1. Data File
select file_id,file_name from dba_data_file;
หรือ
select file#,name from v$datafile;
2. Control File
select name from v$controlfile;
หรือ ดูจากไฟล์ initSID.ora ซึ่งเป็น parameter file ของฐานข้อมูลก็ได้ ตรงบันทัด CONTROL_FILE
SID คือ System Identifier หรือชื่อของฐานข้อมูล เช่นถ้าเรามี database ชื่อ SUN ก็จะมีชื่อ control file ว่า initSUN.ora
3. Redo Log File
select group#, member from v$logfile;

4. ดูว่ามีฐานข้อมูลอะไรบ้าง และสามารถทำ hot backup ได้หรือไม่
select name, created, log_mode from v$database;
ถ้า log_mode = archivelog แสดงว่าสามารถทำ hot backup ได้
ถ้า log_mode = noarchivelog แสดงว่าทำ hot backup ไม่ได้

5. ดูว่ามีไฟล์อะไรที่ถูกสั่งทำ hot backup บ้าง
select * from v$backup;

Note
- view จะขึ้นต้นด้วย v$ สามารถดูได้จาก Oracle Enterprise Manager (OEM) ใน Schema SYS ว่ามี view อะไรบ้าง เช่น v$parameter , v$pwfile_users, v$tablespace เป็นต้น
- OEM สามารถใช้ดูว่าใน oracle มี database อะไรอยู่บ้าง และใน DB นั้นมี user , tablespace, schema อะไรอยู่บ้างได้
- เราสามารถใช้ OEM ช่วยในการดูตำแหน่งของไฟล์ต่างๆได้ง่ายขึ้นเช่น
control file ดูได้จาก Storage/Controlfile
datafile ดูได้จาก Storage/Tablespaces/ชื่อของ tablespace ซึ่ง 1 tablespace อาจจะประกอบไปด้วยหลายๆไฟล์ก็ได้ , ต่างนามสกุลกันก็ได้
Redo Logfile ดูได้จาก Stroage/ Redo Log Groups

Tuesday, April 08, 2008

Zyxel add forward port more than 12 rules

โดย Default แล้วสามารถตั้งค่า forward port ใด้ใน Web Admin หรือ SMT คือ 12 rules แต่ถ้าใช้ CI จะสามารถ set ได้ถึง 24 rules ต่อ 1 server set มีได้ทั้งหมด 10 server set และสามารถ set ค่าได้แบบละเอียดคือ

- สามารถตั้งชื่อ rule ได้ -> คำสั่ง rulename เช่นเวป config จะเห็น rule แรกที่มีชื่อว่า DMZ อันเดียว
- Server Port Range -> คำสั่ง svrport
- Server IP -> คำสั่ง forwardip
- Internal Server Port Range -> คำสั่ง intport ไม่ได้ใช้
- Remote Host IP Range -> คำสั่ง remotehost ไม่ได้ใช้
- Lease Time
- Protocal

ตัวอย่างการตั้งค่า rule ที่ 13 ให้ forward port 3390 ไปที่ ip 192.168.15.1

ras> ip nat server load 1 # load server set 1
ras> ip nat server disp 1 # display rule of server set 1
ras> ip nat server edit 13 forwardip 192.168.15.1 # add forward to server 192.168.15.1
ras> ip nat server edit 13 svrport 3390 3390 # add server port 3390
ras> ip nat server edit 13 active yes # enable rule
ras> ip nat server save # ไม่ค่อยแน่ใจว่าทำเสร็จแล้วต้อง save หรือเปล่า
ถ้าไม่ได้ต้องใช้ autoexec.net
ถ้าทำผิดต้องการยกเลิกสั่ง
ras> ip nat server edit 13 clear # ล้างบันทัดที่ 13 ทั้งหมด ต้องทำใหม่ตั้งแต่ต้น

Sunday, March 30, 2008

FXS and FXO

FXS = Foreign eXchange Subscriber
เป็นส่วนเชื่อนต่อที่มีคุณสมบัติต่อไปนี้
1. มี Dial Tone
2. มี Battery สำรองไฟ
3. มีกระแสไฟของสัญญาณ Ringing ซึ่งจะถูกส่งมาจากชุมสายโทรศัพท์
บางครั้งจะเรียกว่า Plug on the wall หรือช่องต่อโทรศัพท์ที่มีอยู่ตามผนังนั่นเอง

FXO = Foreign eXchange Office
เป็นส่วนเชื่อมต่อที่มีอยู่บนตัวเครื่องโทรศัพท์ โดยจะรับสัญญาณที่มาจาก FXS เพื่อทำหน้าที่ในการ On Hook หรือ Off Hook เพื่อให้สัญญาณโทรศัพท์ที่ส่งมานั้นครบวงจร

การที่จะทำให้ระบบโทรศัพท์ใช้งานได้จะต้องมีการเชื่อมต่อระหว่าง FXS ที่มาจากชุมสายโทรศัพท์ หรือ PABX มาเชื่อมต่อเข้ากับ FXO ของเครื่องโทรศัพท์

การเชื่อมต่อที่ผิดเกิดจากการที่นำ FXS มาต่อกับ FXS หรือ FXO มาต่อกับ FXO เช่นการนำเครื่องโทรศัพท์ 2 เครื่องมาต่อกัน จะไม่สามารถใช้งานได้

ปกติแล้ว PABX จะแบ่งออกเป็น 2 ส่วนคือ
1. CO Line หรือสายนอก มีคุณสมบัติเป็น FXO Interface เอาไว้ใช้เชื่อมต่อกับสายนอกที่มาจากชุมสาย (FXS)
2. Extension หรือ สายใน ซึ่งเป็น FXS Interface เพื่อให้เครื่องโทรศัพท์ภายใน office มาต่อและสามารถใช้งานได้

VOIP Phone Adapter
เช่น Linksys PAP2T (2 FXS) จะใช้ได้กับ 2 หมายเลข ใช้กับเครื่องโทรศัพท์แบบทั่วไปได้

Voice Gateway
จะเหมือนกับ VoIP Phone Adapter เพียงแต่สามารถรองรับได้หลายหมายเลขกว่าเช่น 4 ports , 8 ports จะแยกเป็น FXO , FXS ขึ้นอยู่กับการใช้งาน เช่น Linksys SPA 3102

ไม่แน่ใจ
- fxs จะเอามาต่อกับ card ที่รับสายนอก(fxo) ของ pabx เพื่อเวลาโทรออกจะได้ออกจาก voip เสมือนว่า fxs เป็นสายนอกอีกอันหนึ่ง
- fxo จะเอามาต่อกับ card สายใน (fxs) ที่ออกจาก pabx เสมือนกับเป็นสายในหมายเลขหนึ่ง

Thursday, March 06, 2008

การเพิ่ม Custom Time Server เข้าไปในแถบ Internet Time ของ Windows XP, 2003

ไปที่ Register Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DateTime\Servers
เพิ่ม String Value = 3 ใส่ค่า pool.ntp.org
Default = 3

Monday, March 03, 2008

การใช้ KIS Block Internet Explorer

Kaspersky Internet Security V.6.0

เป็นการใช้ Firewall ใน Anti Hacker / Setting/ Rule of Applications/
เลือก iexplorer กดปุ่ม Edit ตรง HTTP, HTTPS ให้เปลี่ยนจาก Allow ไปเป็น Block

การตั้ง Exclude สำหรับ File Anti-Virus
อยู่ที่ Protection กด Setting / Trust Zone/ Exclusion Mask
ใส่ชื่อไฟล์หรือ folder ลงไปก็ได้ จะใส่แบบ Absolute หรือไม่ก็ได้ สามารใช้ widecard ร่วมด้วยก็ได้ เช่น
- ทุกๆไฟล์ที่อยู่ใน folder work ของทุกๆ folder ใส่เป็น work\*.*
- abc.* หรือ abc.12* ก็ได้

Group Policy Disable Error Reporting

Using GPO

Computer Configutation/Administrative Templates/Error Reporting
Display Error Notification = Disable
Advanced Error Reporting settings/Report operating system errors = Enable

Manual Setting

Control Panel/System/Advanced/Error Reporting

Saturday, March 01, 2008

การแก้ปัญหา Arcserve Backup Incomplete

Backup Incomplete

เกิดจากการที่ backup บางไฟล์ไม่สำเร็จ เนื่องจากโดน lock เอาไว้ แก้ได้โดยการใช้ Filter ที่อยู่ในหน้า backup เพื่อทำการ exclude ไฟล์ที่มีปัญหาออกไป โดยการ click ขวา แล้วเลือก Filter เลือก File Pattern หรือ Directory Pattern แล้วใส่ path เต็มๆของ file หรือ folder ลงไป เช่น ไฟล์ d:\work\mywork.txt หรือ folder d:\work

Note
- สำหรับ Directory Pattern นั้น ห้ามใส่ \ ปิดท้ายโดยเด็ดขาด เช่นห้ามใส่ว่า d:\work\

Saturday, February 23, 2008

Startup Delayer (Freeware)

มีประโยชน์มากเอาไว้ตั้งเวลา Delay startup program ตอน boot เครื่อง เช่นต้องรอให้โหลดอะไรบางอย่างเสร็จก่อนถึงจะ start program ได้

Saturday, January 26, 2008

Hostname Logger v 1.2 for ISA Server

ไม่ต้องเสียเงินซื้อ loghostname แล้วครับ มีให้ใช้ฟรีๆ ที่นี่เลย
http://www.elmajdal.net/ISAServer/HostLogger.aspx
http://www.elmajdal.net/ISAServer/

client ที่เป็น Secure Nat จะใช้ block Domain Name กับ URL Set ไม่ได้ผล เพราะ Secure Nat มันจะไม่ resolve IP ไปเป็น domain name ให้

Tuesday, January 22, 2008

Auto Logon with Domain Account

ปกติแล้วเครื่องที่เป็นสมาชิก Domain จะถูก Disable Auto Logon เอาไว้อยู่แล้ว จะต้องไปแก้ไข Registry HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

AutoAdminLogon = 1

DefaultDomainName = <ชื่อ Domain ของเราในแบบ Netbios> ### ก็คือที่แสดงอยู่ใน dropdown ที่จะให้เลือกตอน Logon นั่นเอง

DefaultUserName = <ชื่อ User ที่จะให้ Auto Logon> ### จะต้องเป็น Blank Password

Note
บางทีถ้าเปลี่ยน DefaultDomainName แล้วอาจจะทำให้ค่า AutoAdminLogon reset กลับไปเป็น 0 ได้ จะต้องเข้ามาทำซ้ำอีกครั้ง

เสร็จแล้วสั่ง RUN > control userpasswords2 แล้วเพิ่ม Domain User ที่ต้องการให้ Auto Logon เข้ามา
เลือก Group Membership ให้เป็น Administrators (ของ Local Computer) ทดสอบด้วยการ Restart

Note
- ถ้าต้องการให้ Autorun โปรแกรมหลังจากที่ Logon เสร็จสามารถทำ Shortcut ไปใส่เอาไว้ใน Startup ของ User นั้นๆได้

- ควรเพิ่มความปลอดภัยให้กับ User นี้โดยการกำหนด Workstation ที่จะสามารถ Logon ได้โดย Logon to Workstation และ User cannot change password.

Monday, January 21, 2008

Reverse Lookup Zones and Event ID 40961

Reverse DNS records, aka PTR records, are used when you have an IP address you need to resolve to a name. While it is not 100% necessary to create a reverse lookup zone in your Active Directory domain this is a popular error.

Event Type: Warning Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40961 Date: 1/1/2005 Time: 12:30:45PM User: N/A Computer: COMPUTERNAME Description: The Security System could not establish a secured connection with the server DNS/prisoner.iana.org. No authentication protocol was available.

So what is prisoner.iana.org? Well its a blackhole of sorts. RFC 1918 defines three zones called 10.in-addr.arpa, 16.172.in-addr.arpa, and 168.192.in-addr.arpa on three DNS servers called blackhole-1.iana.org, blackhole-2.iana.org and prisoner.iana.org containing these zones. When a client updates its DNS PTR record it will update the reverse lookup zone xxx.xxx.in-addr.arpa. If you have a reverse lookup zone configured, it will be successful. However if you do not have a reverse lookup zone, thanks to RFC 1918, it will try to register itself with prisoner.iana.org (or one of the other blackhole servers) and fail.

To resolve this issue create a reverse lookup zone. It is ok to ignore this warning but best practice would be to configure a reverse lookup zone.

Tuesday, January 08, 2008

GPO ที่น่าสนใจ

GPO ที่น่าสนใจ

1. User Configuration / Administrative Templates / System / Ctrl+Alt+Del / Remove Task Manager --> Disable

2. User Configuration / Administrative Templates / Control Panel / Prohibit Access to Control Panel --> Disable

3. User Configuration / Administrative Templates / Control Panel / Force Classic Control Panel Style --> Enable

4. User Configuration / Administrative Templates / Desktop / Remove My Computer Icon on the Desktop --> Disable

5. User Configuration / Administrative Templates / Windows Components / Windows Explorer / Remove the Folder Options menu item from the Tools menu --> Disable

6. User Configuration / Administrative Templates / Windows Components / Windows Explorer / Turn on Classic Shell

7. Computer Configuration / Windows Settings / Security Settings / Local Policies / Security Options / Shutdown: Allow system to be shut down without having to log on

8. Computer Configuration/ Windows Settings/ Security Setting / Security Option/ Account: Guest Account Status = Disable

9. Computer Configuration/ Windows Settings/ Security Setting / Security Option/ Account: Rename Administrator Account

10. Computer Configuration/ Windows Settings/ Security Setting / Security Option/ Account: Rename Guest Account

11. Users Configuation/Administrative Template/Windows Settings/Internet Explorer/
เกี่ยวกับ Auto Complete

Friday, January 04, 2008

Terminal Services Manager and Terminal Services Configuration

Windows Server 2003 ยอมให้มีใช้ Remote Desktop ได้พร้อมกัน 2 session เท่านั้น บางทีถ้า session ค้าง เนื่องมาจากการออกด้วยวิธีการ Disconnect แทนที่จะเป็น Logoff หรือด้วยเหตุผลอื่นเช่นต้องการ run โปรแกรมทิ้งเอาไว้ จะทำให้ session เต็ม เราสามารถที่จะ connect กลับไปยัง session ที่เปิดทิ้งเอาไว้ หรือ สามารถที่จะ Reset Sessess นั้นทิ้งไปได้

Option ต่างๆมีดังนี้

1. Connect
สั่ง Connect Session สามารถ Connect กับ Session ของใครก็ได้ที่เรารู้ password ถ้าเจ้าของ session ยัง logon อยู่ จะถูกแตะออกไปแทน แล้วเราจะเข้าไปแทนที่ session นั้นแทนโดยหลุดออกจาก session ของเราเอง

2. Disconnect
สั่ง Disconnect Session โดยที่ Application ต่างๆยังคงทำงานอยู่

3. Send Message
ส่งข้อความถึงกัน โดยขึ้นมาเป็น Popup Message

4. Remote Control (Shadow Session)
มีความสามารถเหมือน PcAnywhere จะสามารถเลือก option นี้ได้ก็ต่อเมื่อ อีก session ไม่ได้ Disconnect เท่านั้น และไม่สามารถเรียกได้จาก Console , สามารถตั้งได้ว่าเจ้าของ session ต้องให้ความยินยอมก่อน หรือไม่ก็ได้ (จาก Terminal Services Configuration) Defaule Hotkey คือ CTRL+* ที่กดจาก Keypad ถ้าใน Notebook จะกดไม่ได้ต้องไปเปลี่ยน * ให้เป็นอย่างอื่น

5. Reset
ลบ Session ที่ค้าง(ไม่ทำงาน, hang)อยู่ออก ใช้เมื่อ Session ค้างเท่านั้น นอกนั้นให้ใช้ logoff แทน

6. Status
ดู Session Stat Counter

7. Logoff
Logoff user ที่ค้างอยู่ออกจาก session

Note
รายละเอียดการใช้งานต่างๆสามารถอ่านได้ใน Help

Saturday, December 15, 2007

การเพิ่ม Time Server และเปลี่ยนแปลงความถึ่ของการ Synchronize

To synchronize more often

find the W32Time registry key given below modify the existing value called "SpecialPollInterval". If you don't see SpecialPollInterval listed in this section, you can create it as a new DWORD value. The value of this should be set to the number of Seconds between sync attempts. If you wanted to check once per day, the value would be 86400.

System Key: [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeTimeProvidersNtpClient]
Value Name: SpecialPollInterval
Data Type: REG_DWORD (DWORD Value)
Value Data: Seconds in Decimal

To add more time servers

first check to see if your version of Windows will let you simply type them in on the screen shown above. If so, this saves you the trouble and possible problems of editing the registry yourself.

If your version of Windows won't let you simply add them on the screen above, you may need to add them manually yourself. Find the registry key for DateTime Servers provided in full below and create a new string value. Name it the next number in sequence (usually '3') and set the data of the new value to equal the hostname or IP address of the time server.

You can also change the default server by setting the value of "(Default)" to the entry number of the required server.

System Key: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionDateTimeServers]
Value Name: (Default)
Data Type: REG_SZ (String Value)
Value Data: Server Hostname or IP Address

Friday, November 30, 2007

Rename Workstation Name in the domain.

ต้องใช้คำสั่ง netdom ที่ต้องลงเพิ่ม อยู่ใน Support\Tools ในแผ่น Windows XP CD.

รูปแบบคำสั่ง

netdom renamecomputer <ชื่อเก่า> /newname:<ชื่อใหม่>
/userd:<ชื่อโดเมนแบบ netbios>\<ชื่อ user ที่เป็น domain admin> /passwordd:*
/usero:<ชื่อlocal admin> /passwordo:*
/reboot:<เวลาที่รอก่อนจะ reboot>

ตัวอย่างคำสั่ง

netdom renamecomputer CIS /newname:IT
/userd:MYDOMAIN\MYADMIN /passwordd:*
/usero:administrator /passwordo:*
/reboot:30

* = รอให้ใส่ password
o = object = local
d = domain

Tuesday, November 20, 2007

Volume Shadow Service (VSS)

Concept คือ
1. สร้าง share ขึ้นบน Windows Server 2003
2. ไปที่ Drive Propertites ที่มีการสร้าง share แล้ว enable VSS เสร็จแล้วกำหนด schedule สำหรับ backup ว่าจะให้ทำตอนไหนบ้าง กันพื้นที่ไว้เท่าไหร่ (VSS จะ backup เฉพาะ folder ที่ได้ทำการ share เอาไว้เท่านั้น และจะทำการเรียกคืนจาก client ที่ได้ map share นั้นเอาไว้)
3. การเรียกคืน file , folder จะเรียกคืนได้จากเครื่องที่ได้เข้าถึง share โดยให้เลือก properties จะมีแถบ Old Version เพิ่มขึ้นมาให้เลือกว่าจะ restore version ไหนกลับคืนมา

Note
- ตรง Schedule จะแปลกหน่อยคือมีมาให้โดย default อยู่ 2 schedule ซื่งทำงานทั้งคู่ ต้อง click dropdown ลงมาถึงจะเห็น สามารถแก้ไข ลบออก หรือเพิ่ม schedule ใหม่เข้าไปก็ได้ซึ่งจะทำงานทุกอันที่ list ไว้

- The snapshot is taken if the "modified date" is newer than the last snapshot date.
- If the modified date is older than the last snapshot date, then no snapshot is taken.
- Example: the last snapshot was Monday at 7AM. It is now Tuesday at 3PM. A file with a Last Modified Date of Monday at 5PM will get copied, and a file with Last Modified Date of Sunday will not be copied.

Publishing Print Sever Behind ISA Firewall

ขั้นแรกต้อง Forward Port 9100 ที่ตัว Router ก่อน
สร้าง Protocal Definition ขึ้นมาโดยมีค่าดังนี้
Port = 9100
Protocal Type = TCP
Direction = Inbound
หลังจากนั้นก็สร้าง Access Rule ธรรมดา แล้วก็ add tcp/ip printer ธรรมดา

Sunday, November 04, 2007

Windows Time Synchronization

การ Synchronize ของ Windows 2003/2000/NT จะขึ้นอยู่กับ Windows Time Serivce (W32time)
Windows 2003 ใช้ NTP
Windows XP ใช้ SNTP/NTP
Windows 2000 ใช้ SNTP

Default time sync
Windows 2003 every 15 minutes
Windows XP every 7 days
Windows 2000 every 45 minutes จนกว่าจะสำเร็จ หลังจากนั้นทุกๆ 8 ชั่วโมง

เราต้องการที่จะทำให้ DC ของ Domain sync กับ Time Server ภายนอก แล้ว Workstation ทุกตัว Sync กับ DC อีกที

W32Time ใช้ Network Time Protocol (NTP) หรือ Simple Network Time Protocol (SNTP) ในการ synchronize Windows 2000/2003 network.
(The only available input to W32Time is NTP or SNTP) แต่ NTP จะมีความแม่นยำมากกว่า SNTP

EventID 29,38,47,50 แสดงถึงการที่ W32time ไม่สามารถ sync time ได้

Synchronizing a Windows 2003 domain controller or Windows XP client (SP2) to a time server

1. Stop W32time service
2. ตั้งเวลาของเครื่องให้ย้อนหลังกลับไป เพื่อทดสอบว่าเมื่อ w32time ทำงานปกติแล้ว เวลาจะถูกตั้งค่าอย่างถูกต้องหรือไม่
3. Define the authoritative time server and configure the windows 2003 domain controller or XP workstation for NTP client mode

โดย default แล้ว Windows 2003 และ Windows XP SP2 จะถูกกำหนดให้ sync time กับ external time server เอาไว้อยู่แล้ว แต่จะถูกตั้งค่าให้ทำงานใน mode Symmetric Active mode แต่ NTP time server จะตอบสนองเฉพาะกับ Client Mode เท่านั้น จึงต้องเปลี่ยน mode ก่อนโดย ไปที่ CMD แล้วสั่ง

w32tm /config /manualpeerlist:xxx.xxx.xxx.xxx,0x8 /syncfromflags:MANUAL

โดยที่ xxx.xxx.xxx.xxx คือ ip ของ NTP time server

4. เสร็จแล้วสั่งใช้ service w32time ทำงาน แล้วสั่ง w32tm /resync ใน CMD

ตรวจสอบดูเวลาของเครื่องว่าตรงหรือยัง

Note
0x1 = Instead of following the NTP specification, wait for the interval specified in the SpecialPollInterval entry before attempting to recontact this time source. Setting this flag decreases network usage, but it also decreases accuracy.

0x2 = Use this time source only as a fallback. If all time sources that are not fallbacks have failed, then the system selects one fallback time source at random and uses it.

0x4 = Set the local computer to operate in symmetric active mode in the association with this source.

0x8 = Set the local computer to operate in client mode in the association with this source.

Tuesday, October 09, 2007

ช่องความถี่

VHF Low (47MHz-68Mhz) => 2-4
FM (88MHz-108MHz)
S-Band Low (104MHz-174MHz)=> s1-s10
VHF High (174MHz-230MHz)=> 5-12
S-Band High (230MHz-300MHz)=> s11-s20
UHF Low (470MHz-582MHz)=> 21-34
UHF High (582MHz-862MHz)=> 35-69

Explanation of (L.O.) Local Oscillator Frequency

Explanation of (L.O.) Local Oscillator Frequency:

Suppose a signal comes from the satellite at a microwave frequency of 12 GHz but your typical receiver tunes up only to 1.75 GHz? (Also bear in mind that most cable will NOT happily pass frequencies much above 2GHz).
The function of the LNB is to reduce the frequency of the satellite signal. It does so by subtracting a frequency figure from the satellite signal frequency.
This figure is called the "Local Oscillator" frequency ("LO") of the LNB.
So an LNB with a LO of 10.25GHz will send a 12GHz satellite signal down the cable at 1.75GHz (just within range of your old receiver).
12GHz - 10.25GHz = 1.75GHz
Working in reverse, if your highest satellite frequency is 12.6 GHz then you will need an LNB with a LO of at least
12.6 - 1.75 = 10.85GHz
in order to reduce the satellite signal to a frequency that your receiver can "see" (1.75 GHz).
Now let's reverse the process again:
A "standard" LNB has a LO of 10.0GHz. So the highest satellite program frequency that your standard receiver can *see* is
1.75 + 10.0 = 11.75GHz
An "enhanced" LNB has a LO of 9.75 GHz
1.75 + 9.75 = 11.50GHz
A "universal LNB has TWO LOs. One is 9,75 (same as "enhanced") The other is 10.6 which is selected if it "hears" a 22kHz (just above audio) signal.
1.75 + 10.6 = 12.35GHz
Of course, if your receiver can accept signals up to 2.0 GHz then the highest acceptable signal frequency becomes
2.00 + 10.6 = 12.60GHz
And a receiver with a tuner that extends to 2.15GHz achieves
2.15 + 10.6 = 12.75GHz (which happens to be the top of the "Telecom" band!)
Now, you are still puzzled about the DBS LNB
This has a LO of (typically) 10.75GHz
So an old 1.75GHz receiver will get up to
1.75 + 10.75 = 12.50GHz
A final consideration has to be the LOWER limit on tuning:
Most old receivers can tune no lower than 0950 MHz (= 0.95GHz) whereas later ones might go down to 0.70GHz.
Check out the above calculations with these lower tuning range limits to see the overall tuning bandwidth for any receiver.
This is all very basic "sums" - nothing complex - so once you have a "picture" of what is happening, you can sketch little band plans for any combination of receiver annd LNB.
Once you know the value(s) of the LO(s) in the LNB and of the upper and lower tuning limits of the receiver in question, you can quickly figure out what can be received.
NOTE:
Older receivers *expect" an LNB with a 10.0 LO and the frequency display is arranged just for this. However, you can use an LNB with a different value LO. It just means that the *displayed* frequency will be incorrect.
Transponder  - LNB Local  = tuner frequency Frequency      Oscillator     12750 MHz                       Telecom/Astra 1F               DBS/Astra 1E       11700 MHz  - 10000 MHz = 1700                             Astra 1B                                            Astra 1A     Receiver tuning range without ADX                             Astra 1C                                        950  + 500 = 1450   Astra 1D                                                              Tuning range with ADX                                          10700 MHz  - 10000 MHz = 700  + 500 = 1200

An old standard receiver usually tunes from 950 to 1700 MHz.
The map above shows the limited tuning range of an old standard receiver with an old standard 10.0 GHz LNB. The addition of an ADX Channel Expander moves the Astra 1D frequencies up by 500 MHz into the tuning range of the receiver.

To receive all Astra channels from satellites D to B without using an ADX, a receiver would need a tuning range of 700 to 1700 MHz.



Transponder    LNB Local Frequency      Oscillator     12750 MHz  - 10600 MHz = 2150                                                       Telecom/Astra 1F                     Receiver tuning range for Hi band (22kHz on)                             DBS/Astra 1E                      - 10600 MHz = 1100 11700 MHz  -  9750 MHz = 1950                             Astra 1B                                            Astra 1A                              Receiver tuning range for Lo band (22kHz off)   Astra 1C                                            Astra 1D                                          10700 MHz  -  9750 MHz = 950

An Enhanced LNB has a local oscillator frequency of 9750 MHz.
The receiver now needs a tuning range of 950 to 1950 MHz as shown in the map above.

If a Universal LNB is used, its local oscillator can be switched from 9750 to 10600 MHz by sending a 22kHz signal up the cable. Some receivers have this facility built inside. Some will need an external signal-inserter box connected into the cable.

If the receiver has a range of 950 to 2150, it will be able to receive programmes on both Hi and Lo band.



Another possibility is to use an ADX-Plus. This has an internal switch which, when moved across, makes the ADX-Plus move the frequencies DOWN by 500 MHz instead of up.

So a channel at 12750 MHz is moved down like this:

12750 - 10600 - 500 = 1650 MHz (with an ADX-Plus)

which is well within the tuning range of an old standard receiver.

And the lowest channel receivable will be:

950 + 500 + 10600 = 12050 MHz (with 22kHz signal ON and ADX-Plus)

By fiddling with the ADX-Plus switch and the 22kHz signal inserter you can probably receive the full range of channels if you have a Universal LNB and a standard receiver!


Note: MHz (MegaHertz) = GHz (GigaHertz) x 1000
So 9750 MHz = 9.75 GHz
Please let me know if you have any other thoughts on this and maybe we can add it to the FAQs.
Astra broadcast frequencies range from 10700 Mhz (Astra 1D) through to
11700 Mhz (Astra 1B). So I need to calculate which of these frequencies
each of the two L.O.s on the LNB in conjunction with the tuning range
of the receiver, I can receive, thus:

L.O. 1 of 9750 Mhz

950 Mhz (lower tuning capabilities of receiver ) + 9750 Mhz (L.O. 1)
= 10700 Mhz
1700 Mhz (upper tuning cap. of receiver) + 9750 Mhz (L.O. 1) = 11450
Mhz.

Hence able to receive frequencies of 10700 Mhz to 11450 Mhz.

L.O. 2 of 10600 Mhz

950 Mhz (lower tuning capabilities of receiver ) + 10600 Mhz (L.O. 2)
= 11550 Mhz
1700 Mhz (upper tuning cap. of receiver) + 10600 Mhz (L.O. 2) = 12300
Mhz.

Hence able to receive frequencies of 11550 Mhz to 12300 Mhz.

Being an old crappy Amstrad SRD400, I presume my receiver isn't able to
signal the LNB to switch to the upper of the two L.O. frequencies, so I
can't access anything above 11450 Mhz. With a 22kHz signal inserter I should
therefore be able to access 11550Mhz - 12300Mhz?

You are doing OK so far.

However, this leaves a gap in the middle between 11450 and 11550 of
frequencies which I can't access! Presumably with an ADX (and 22kHz signal
inserter) I can shift those frequencies into tunable ranges?

Presumably, all I need now is an ADX and a 22kHz signal inserter in order to
receive all Astra frequencies (and then some ... )? Oh yes, and a Sky
subscription :-)

You don't really need a 22kHz signal inserter.

Would I be better off buying an ADX plus, so that I shift the
frequencies down rather than up? So as to ensure my receiver is happier
about it?

Yes, I would think so. There's nothing on the higher frequencies for your Amstrad to receive from Astra at 19.2 degrees East.
Sky Sports 3 would be the highest useful channel, with a couple of foreign stations just above that.


How much would I expect to pay for an ADX and 22kHz signal inserter?

If you have a Sky subscription they will post you an ADX-Plus for just £9.99.
Otherwise you can buy one for £12.95 upwards.


Many thanks for all your help. It all seems so much simpler now. Or have
I missed something?

Nope. I told you it was simple. People become frightened because they think it's too technical. The truth is that you simply need to be able to add and subtract - roughly to primary school level or lower! You don't need *any* technical knowledge. Just realise that there are various ways to add or subtract the frequencies. Specifically: there are various fixed values that you can use - Typically 10.00 GHz, 9.75 Ghz, 10.6 Ghz etc. for an LNB. Also +0.5GHz and -0.5GHz for an ADX-Plus Channel Expander, dependent on its internal switch position.

______________________________________________________
LNB Universal จะมี LO อยู่หลายค่า เช่น 2 ค่าสำหรับ KU Low Band กับ KU High Band คือ 9750 กับ 10600
ส่วน LNB 11300 เป็น LNB สำหรับ UBC จะมี LO อยู่ค่าเดียวคือ 11300
สังเกตว่าความถี่ช่องต่างกๆของ UBC จะมากกว่า 11300 เสมอ เมื่อนำมาหักล้างกันจะได้ออกมาเป็นความถี่ที่ Receiver จะสามารถรับได้ ถ้าใช้ LNB 10600 เมื่อเอามาหักล้างกันแล้วอาจจะเกินช่วงที่ Receiver สามารถรับได้

การเปลี่ยนค่า LO ของ LNB Universal ใช้สัญญาณ 22 KHz แต่มันจะทำโดยอัตโนมัติไม่จำเป็นต้องสั่งเอง
สาเหตุที่ต้องมีการหมุนองศาของหัว LNB เพราะว่าภายในจะมีแผ่นรับสัญญาณซึ่งจะวางตั้งฉากกันเพื่อรับสัญญาณจากทั้ง V และ H จึงต้องหมุน LNB เพื่อให้ขั้วรับสัญญาณได้ดีที่สุด

สรุป
- ค่า LNB C Band คือ 5150
- ค่า LNB KU Band คือ 9750,10600
- ค่า LNB UBC คือ 11300

Tuesday, October 02, 2007

Satellite Equipment

Splitter
คือตัวแยกสัญญาณ RF แบบปกติ ซึ่งสัญญาณจุด Out จะ Loss เท่ากันหมดทุก Port , splitter TV ธรรมดา ไม่ต้องมีการส่งสัญญาณย้อนกลับ ทำให้เอาไปใช้กับระบบดาวเทียมไม่ได้

Tap off
สัญญาณช่อง Tap จะ Loss มากกว่าช่อง Out ตัวอย่างเช่น Tap off 2 ทาง จะมี
1. ช่อง In = 1 ช่อง
2. ช่อง Out = 1 ช่อง Loss ประมาณ 3.5 dB
3. ช่อง Tap = 2 ช่อง Loss ประมาณช่องละ -10 dB (หรือแล้วแต่เลือก เช่น -15, -20, -25 dB)
ดังนั้น Tap off เหมาะใช้แยกสัญญาณต้นแหล่งที่ออกจาก Booster และสัญญาณยังแรงมากอยู่ จึงต้องใช้ Tap off ลดสัญญาณให้พอดี ก่อนเข้าโทรทัศน์ ส่วนช่อง Out ของ Tap off ใช้ต่อไปยัง Tap off หรือ Splitter ตัวต่อไป

Power Pass Splitter
เอาไว้ต่อระหว่าง LNB กับ Receiver ต่างจาก Splitter ธรรมดา คือไฟสามารถย้อนกลับจาก Out ไป In ได้ เหมาะใช้แยกรีซีฟเวอร์ หลาย ๆ เครื่อง เนื่องจาก Lnb ต้องการไฟเลี้ยงจากรีซีฟเวอร์ (Receiver ส่งสัญญาณคำสั่งไปสั่ง LNB ) โดยจะมีตัวไดโอดที่ต่ออยู่ในตัวสปลิทเตอร์ ทำหน้าที่กำหนดขั้วทางเดินของไฟ ขั้วไฟของสปลิทเตอร์แบบนี้ส่วนมาก จะออกแบบให้ไฟ + ผ่านเข้าทาง Output ไปออกทาง Input และทุกๆ Output จะต่อไดโอดไว้และรวมกันที่จุด Input ทั้งหมด ( แบบนี้เขาเรียก ALL PASS ) หรือยอมให้ไฟผ่านตัวมันได้ทุกทาง สปลิทเตอร์แบบนี้จะมีย่านความถี่คลอบคลุมไว้ค่อนข้างกว้างคือ ตั้งแต่ 5-2400 MHz ฉนั้นสปลิทเตอร์แบบนี้จึงสามารถใช้ได้ทั้งสัญญาณทีวีธรรมดา จนถึงย่านความถี่ดาวเทียม







DiSEqC (Digital Sattelite Equipment Control)
เป็นตัวอุปกรณ์ที่ใช้ทำหน้าที่ตัดต่อสลับเลือกสัญญาณจากตัว LNB เพื่อนำมาใช้งาน โดยมี IC ไมโครโปรเซสเซอร์ เป็นตัวอ่านคำสั่งจากเครื่องรับว่าสั่งให้สวิทไปทางใหน การจ่ายไฟเลี้ยงให้กับตัว LNB โดยปกติของสวิทแบบนี้จะจ่ายไฟเลี้ยงให้กับตัว LNB ที่ถุกเลือกเท่านั้น ถ้ามีการใช้ DiSEqC Switch ต่อกับ splitter เพื่อพ่วงกับ Receiver หลายๆตัวอาจจะทำให้สัญาณกวนกันได้



ดังนั้นการใช้ DiSEqC Switch จึงเป็นการเลือกสัญญาณจาก LNB หลายๆหัวจาก Receiver เครื่องเดียว
แต่การใช้ Multi switch จะเป็นการเลือกสัญญาณจาก LNB หลายๆหัวจาก Reveiver หลายๆเครื่องดูได้อิสระ



คำสั่งที่ออกมาจากหลังเครื่องReceiver คำสั่งพื้นฐานได้แก่
คำสั่ง 13/18 ใช้เลือก V(13v) หรือ H(18v)
คำสั่ง 0/22 Khz ใช้เลือก C(0Khz,Low Band) หรือ Ku(22Khz,High Band)
คำสั่ง DiSEqC 1.0 เลือก จาน fix แต่ละใบ
คำสั่ง DiSEqC 1.2 สั่ง Move จาน

Multi Switch คืออุปรณ์ ซึ่งเกิดจากการนำชุดคำสั่งข้างต้นไปประกอบกันหลายๆคำสั่ง ซับซ้อนกว่า DiSEqC switch ทำให้ต่อกับหลาย Reciever ได้


Spec ของพวก splitter แบบต่างๆ
http://www.9sats.com/product/product.php?cat=75&
วิธีการต่อ Multiswitch แบบต่างๆ
http://www.nics-sat.com/index.php?lay=show&ac=article&Id=326827&Ntype=6



LNB (Low-noise Block Converter)
สัญญาณที่มาจากดาวเทียมเป็นสัญญาณ Microwave ทำให้มี Loss สูงเวลาผ่านสายเคเบิล LNB จะทำหน้าที่แปลงสัญญาณความถี่สูง (GHz) ให้เป็นความถึ่ต่ำ (MHz) ทำให้มี loss น้อยลง เวลาซื้อ LNB จะต้องระบุว่าทำงานที่ความถึ่เท่าไหร่เช่น 11300 MHz เป็นต้น



Combiner
เป็นอุปกรณ์รวมสัญญาณ RF หลายๆช่องจาก Modulator ให้ออกมารวมกันอยู่ในสายเส้นเดียว เวลาเลือกซื้อต้องเลือกย่านความถึ่ด้วยว่าต้องการย่านไหนเช่น UHF, VHF, S-Band อย่างละกี่ช่อง ต้องดูเครื่องรับด้วยว่ารับได้ย่านละกี่ช่อง, Combiner แบ่งออกเป็น 2 ชนิดคือชนิด Passive ไม่ต้องใช้ไฟเลี้ยง กับแบบ Active จะต้องมีไฟเลี้ยงเพราะว่าได้เพิ่มวงจรในส่วนของ การขยายสัญญาณ , การกรองสัญญาณ เข้ามา ในบางกรณีถ้ามีจำนวนช่องน้อยๆสามารถใช้ splitter ต่อกลับทางก็ได้เหมือนกัน หรืออาจจะสามารถใช้ splitter ต่อกลับทางในการรวม combiner 2 ตัวที่ไม่มีช่องสำหรับ link กันก็ได้

Mixer
ใช้สำหรับรวมสัญญาณดาวเทียม (950-2250 MHz) กับ สัญญาณทีวีจากเสาอากาศ (40-860 MHz) ลงมาในสายเส้นเดียวกัน เช่นในกรณีรับบางช่องจาก CableTV แล้วเอามารวมกับรายการที่มาจากดาวเทียมอีกบางช่องเพื่อประหยัดค่าใช้จ่าย

Card Reader
UBC ใช้ Irdeto สังเกตุที่ตัว reader จะมี chip ความถี่ติดอยู่ด้วย
ASTRO ใช้ Mediaguard หรือ SECA2
SVT ใช้ VIAccess
ตัวอ่านบัตรของ Mediaguard กับ VIAccess สามารถเสียบในช่องเดียวกันได้ แต่อาจจะต้อง flash firmware หรือสลับสารแพรของตัวอ่านบัตร หรือกดปุ่ม Format ค้างเอาไว้

Booster
การส่งสัญญาณไปในสาย ช่องความถี่สูงจะ lost ไปได้ไวกว่าช่องความถี่ต่ำ การปรับ booster จึงต้องปรับ slope ให้ขยายช่องความถี่สูงมากกว่าความถี่ต่ำ

Line AMP Booster
เป็นบูสเตอร์ขยายสัญญาณ LNB ความถี่ 950-2050 MHz (DC 13-18V)ใช้ขยายสัญญาณในกรณีที่มีการเดินสายระหว่างจานดาวเทียมกับเครื่องรับ เป็นระยะไกล ๆ

Modulator
ใช้แปลงสัญญาณ AV จาก receiver ให้เป็น RF ปกติจะใช้ต่อกันหลายๆตัวแล้วเอาเข้า Combiner เพื่อที่จะได้สามารถส่งหลายๆช่องไปในสายเส้นเดียวได้

จาน Offset
หมายถึงจานที่ หน้าจานจะหันไม่ตรงตำแหน่งดาวเทียมตรงๆ จะทำมุมก้มกว่า (มุมกวาดเท่ากัน)รับสัญญาณโดยหัว LNB ไม่ได้อยู่ตรงกลางจาน เช่นจาน UBC เป็นต้น
จานที่ LNB อยู่กลางจานเรียกว่า Prime Focus