<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Murat Cudi Erenturk, Insights of an Architect </title><link>http://blogs.technet.com/b/erenturk/</link><description>This blog reflects my insights on IT trends, technology and processes. Ideas expressed here are my own and does not reflect opinions of Microsoft.  </description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Why do we need Service Manager when all I want is automation?</title><link>http://blogs.technet.com/b/erenturk/archive/2012/05/02/why-do-we-need-service-manager-when-all-want-is-automation.aspx</link><pubDate>Wed, 02 May 2012 08:57:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3495608</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3495608</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2012/05/02/why-do-we-need-service-manager-when-all-want-is-automation.aspx#comments</comments><description>&lt;p&gt;Organizations are seeking ways to reduce cost in IT&lt;br /&gt;operations on every possible way. One of the areas that seem promising is automation.&lt;br /&gt;In the past the only way to automate certain tasks were writing scripts to do&lt;br /&gt;certain tasks. However using scripts has its own problems:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;br /&gt;Writing a script is not a onetime event. A&lt;br /&gt;scripting solution is brittle and breaks easily when environment where scripts&lt;br /&gt;are running changes. Writing scripts that handles most of the possible exceptions&lt;br /&gt;is not an easy task and requires a lot of experience.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;Scripting is a development skill. You need to&lt;br /&gt;keep people in your team to write and maintain scripts. Different products used&lt;br /&gt;to have different scripting languages but thanks to Powershell, it is getting&lt;br /&gt;standardized over most of Microsoft products.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Microsoft has recently released System Center 2012 Orchestrator&lt;br /&gt;which is used to create workflows (called runbooks) in an easy way. Basically&lt;br /&gt;it helps IT pro&amp;rsquo;s visually create linked commands to do automated tasks. It can&lt;br /&gt;communicate with other systems through Integration packs and can be very&lt;br /&gt;powerful tool to fulfill your automation needs. If you need more information on&lt;br /&gt;orchestrator, you can start &lt;a href="http://technet.microsoft.com/en-us/library/hh420344.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The problem with automating tasks is not about the tool that&lt;br /&gt;you are using. It is related to the processes. When you are doing a task&lt;br /&gt;manually, it is easier for somebody else to follow on what you are doing and&lt;br /&gt;when. If something goes wrong, you can search for event logs on who logged on&lt;br /&gt;to systems and ask questions on their actions. However if it is automated&lt;br /&gt;(either through scripting or orchestrator) tracking what went wrong becomes&lt;br /&gt;much more difficult. In order to ease have a smooth operation, you need to have&lt;br /&gt;a more structured approach. For example you need to have a change a request for&lt;br /&gt;the automated task (such as cleaning up old computer accounts from Active&lt;br /&gt;Directory) recorded together with the results so that you can search for it later.&lt;br /&gt;Keeping these kind of records were a manual task in the past. However&lt;br /&gt;orchestrator has a Service manager Integration pack that you can do these kinds&lt;br /&gt;of requests automatically.&lt;/p&gt;
&lt;p&gt;The best way to implement automation in IT systems is to&lt;br /&gt;have Service manager 2012 to keep records of what operations are being done and&lt;br /&gt;even providing capabilities such as approvals to keep it under control. For&lt;br /&gt;example you can have a scheduled task in orchestrator that searches for old&lt;br /&gt;computer accounts in Active Directory weekly. If it finds such accounts it will&lt;br /&gt;create a change request in Service manager which goes through standard approval&lt;br /&gt;processes to IT administrator and after this approval a runbook in Orchestrator&lt;br /&gt;is triggered to actually delete the accounts and results recorded in the change&lt;br /&gt;request. You would be able to see reports on change requests on when deletion&lt;br /&gt;of certain computer accounts were requested, who approved it and when it was finished.&lt;/p&gt;
&lt;p&gt;Using System Center 2012 Service manager together with&lt;br /&gt;orchestrator will save you lot of time without losing control of your IT&lt;br /&gt;environment.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.myworldmaps.net/map.ashx/{4e8d0045-5c10-498e-b18e-dead445bf3d9}/ping" width="1" height="1" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3495608" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Service+Manager/">Service Manager</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Automation/">Automation</category></item><item><title>Cross-forest Exchange Migration, notes from the field Part 3, Coexistence</title><link>http://blogs.technet.com/b/erenturk/archive/2012/01/27/cross-forest-exchange-migration-notes-from-the-field-part-3-coexistence.aspx</link><pubDate>Fri, 27 Jan 2012 15:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3477547</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3477547</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2012/01/27/cross-forest-exchange-migration-notes-from-the-field-part-3-coexistence.aspx#comments</comments><description>&lt;p&gt;In the first part of this series I had an overview of&lt;br /&gt;Exchange migration which can be found &lt;a href="http://blogs.technet.com/b/erenturk/archive/2011/10/13/cross-forest-exchange-migration-notes-from-the-field-part-1.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the second part of this series I provided details on how&lt;br /&gt;to check for inconsistencies on user attributes and set for UPN which can be&lt;br /&gt;found &lt;a href="http://blogs.technet.com/b/erenturk/archive/2011/10/25/cross-forest-exchange-migration-notes-from-the-field-part-2-setting-upn.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In this part of the series I will give you details on how to&lt;br /&gt;setup the coexistence. So here are the steps to configure coexistence:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Conditional&lt;br /&gt;Forwarding: &lt;/b&gt;As you have 2 different forests you will need to have DNS name&lt;br /&gt;resolution between the domains. You can use DNS conditional forwarding feature&lt;br /&gt;to do this.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Trust&lt;br /&gt;relationship:&lt;/b&gt; some of the tools that would be needed for migration (Hint&lt;br /&gt;ADMT) will need Windows trusts to be configured between the 2 forests. You will&lt;br /&gt;also need to configure Windows trusts for cross-forest availability.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Directory&lt;br /&gt;synchronization:&lt;/b&gt; After you start migrating the users, you need to make sure&lt;br /&gt;users are available on both sides. The recommended approach is to use FIM to&lt;br /&gt;synchronize users, distribution groups and contacts. While you are configuring&lt;br /&gt;you need to plan for migrating the users through your migration planning and&lt;br /&gt;will need to configure the new object provisioning through FIM. (Ex: What will&lt;br /&gt;happen when a new user is created in old forest during coexistence)&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Control&lt;br /&gt;panel:&lt;/b&gt; remember our scenario. We are moving only Exchange functionality to&lt;br /&gt;the new forest. In this case you might consider using control panel to manage&lt;br /&gt;Exchange properties of the users. If this is the case you might have to do&lt;br /&gt;configuration on your Control Panel.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Coexistence&lt;br /&gt;Server:&lt;/b&gt; In order to migrate users and provide mail flow you can use an&lt;br /&gt;Exchange Server 2010 in the old forest. This will provide you with the new&lt;br /&gt;mailbox replication proxy functionality. You would also use this server&lt;br /&gt;together with the Exchange in new forest for providing availability services in&lt;br /&gt;cross-forest migration scenario. You would need to have certificate installed&lt;br /&gt;on this server that would be trusted by the new forest Exchange servers.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;E-mail&lt;br /&gt;address policies:&lt;/b&gt; In order to flow mail between two organizations you will&lt;br /&gt;need to configure secondary e-mail addresses for each side.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Send and&lt;br /&gt;receive connectors:&lt;/b&gt; These will be needed on both sides to enable mail flow&lt;br /&gt;between 2 Exchange organizations acting as a single organization.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Cross-forest&lt;br /&gt;Availability:&lt;/b&gt; During mailbox migration you may want to have each side of&lt;br /&gt;your Exchange servers to be able to query availability information for&lt;br /&gt;respective recipients. For more information have a look &lt;a href="http://blogs.technet.com/b/neiljohn/archive/2011/10/12/exchange-server-2010-cross-forest-delegation.aspx"&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Auto&lt;br /&gt;discovery:&lt;/b&gt; You will need to configure auto discovery services so that one&lt;br /&gt;you start migrating the users, they will be able to reconfigure themselves for&lt;br /&gt;the new forest. Please keep in mind that this will work for seamlessly for&lt;br /&gt;Outlook anywhere and ActiveSync but if you configure the coexistence server as&lt;br /&gt;your Internet facing CAS servers you will only get a redirect, which means&lt;br /&gt;migrated users will be prompted for authentication on new servers. You can use&lt;br /&gt;an Access gateway solution to provide seamless redirection when the mailbox has&lt;br /&gt;been moved and they are accessing through OWA.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These are the basic steps you will need to do configure&lt;br /&gt;Coexistence between 2 forests. &lt;img src="http://www.myworldmaps.net/map.ashx/{de39f25f-77a9-4895-8b3d-b97bb397a3e9}/ping" width="1" height="1" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3477547" width="1" height="1"&gt;</description></item><item><title>Cross-forest Exchange Migration, notes from the field Part 2, Setting UPN</title><link>http://blogs.technet.com/b/erenturk/archive/2011/10/25/cross-forest-exchange-migration-notes-from-the-field-part-2-setting-upn.aspx</link><pubDate>Tue, 25 Oct 2011 14:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3461281</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3461281</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/10/25/cross-forest-exchange-migration-notes-from-the-field-part-2-setting-upn.aspx#comments</comments><description>&lt;p&gt;In the first part of this series I had an overview of&lt;br /&gt;Exchange migration which can be found &lt;a href="http://blogs.technet.com/b/erenturk/archive/2011/10/13/cross-forest-exchange-migration-notes-from-the-field-part-1.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the second part of these series I will provide more about&lt;br /&gt;handling the transformation to UPN. When you decide to use e-mail addresses for&lt;br /&gt;your UPN, you will need to make sure that you create the UPN from the used&lt;br /&gt;e-mail address of the user. Although this may seem trivial it may not be.&lt;br /&gt;Generally you will want to create the UPN from user&amp;rsquo;s alias attribute and the E-mail&lt;br /&gt;domain. However alias attribute is populated only once during the mailbox&lt;br /&gt;creation and administrator can change the mail address of the user after it has&lt;br /&gt;been created. In order to identity these account we need a script to compare&lt;br /&gt;these values. The script will basically do the following:&lt;/p&gt;
&lt;p&gt;First read all the mailboxes in the organization and loop on&lt;br /&gt;them. Please note that you will need to put resultsize unlimited parameter to&lt;br /&gt;get the whole picture.&lt;/p&gt;
&lt;p&gt;get-mailbox&lt;br /&gt;-resultsize unlimited | foreach{&lt;/p&gt;
&lt;p&gt;Then you would need to get the e-mail addresses of the user&lt;br /&gt;inside the loop.&lt;/p&gt;
&lt;p&gt;for ($i=0;$i -lt&lt;br /&gt;$_.EmailAddresses.Count; $i++)&lt;/p&gt;
&lt;p&gt;Once you have the list, you will go through the list looking&lt;br /&gt;for address prefix SMTP which will give you the Primary SMTP address (Secondary&lt;br /&gt;ones will be given by smtp). Some of the users may have empty Email addresses&lt;br /&gt;so you need to check that condition also&lt;/p&gt;
&lt;p&gt;$address =&lt;br /&gt;$_.EmailAddresses[$i]&lt;/p&gt;
&lt;p&gt;$a=$address.AddressString.ToString()&lt;/p&gt;
&lt;p&gt;if&lt;br /&gt;($address.PrefixString -eq "SMTP" -and $a.length -gt 0 -and $a.indexof("@")&lt;br /&gt;-gt 0)&lt;/p&gt;
&lt;p&gt;Now that you have found the address you need to store it to&lt;br /&gt;be used after the loop.&lt;/p&gt;
&lt;p&gt;$Primary=$a.substring(0,$a.indexof("@"))&lt;/p&gt;
&lt;p&gt;Now lets check if this matches the alias attribute&lt;/p&gt;
&lt;p&gt;if&lt;br /&gt;([String]::Compare($_.Alias,$Primary,$True) -ne 0)&lt;/p&gt;
&lt;p&gt;You will generally have the necessary plumbing to write the&lt;br /&gt;results into a log file for easy consumption. The complete script can be found&lt;br /&gt;as an attachment to the blog. The script is provided as is without any warranty&lt;br /&gt;so use it at your own risk.&lt;/p&gt;
&lt;p&gt;After you have identified these users you will need to&lt;br /&gt;correct the alias attribute according to the primary SMTP address attribute.&lt;br /&gt;The script for this is left as an exercise to the user.&lt;/p&gt;
&lt;p&gt;You may be asking why we were so diligent about correcting&lt;br /&gt;the alias attribute instead of setting the attribute through a script. The&lt;br /&gt;reason is simple; writing scripts to touch large number of users requires&lt;br /&gt;careful testing.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;So now we need to do&lt;br /&gt;the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Create&lt;br /&gt;UPN suffixes:&lt;/b&gt; Creating UPN suffixes can easily be done through a single&lt;br /&gt;line of PowerShell. See &lt;a href="http://technet.microsoft.com/en-us/library/dd391925(WS.10).aspx"&gt;here&lt;/a&gt;&lt;br /&gt;for more details.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Populate&lt;br /&gt;UPN prefix for each user:&lt;/b&gt; You can use &lt;a href="http://admodify.codeplex.com/releases/view/6065"&gt;ADModify&lt;/a&gt; tool to do&lt;br /&gt;this.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;After this tasks your users will be able to use the same&lt;br /&gt;e-mail address as their logon names.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.myworldmaps.net/map.ashx/{d52a54bc-5c03-4dae-a5a2-8b519049087d}/ping" width="1" height="1" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3461281" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Exchange+Migration/">Exchange Migration</category></item><item><title>Cross-forest Exchange Migration, notes from the field Part 1, Overview</title><link>http://blogs.technet.com/b/erenturk/archive/2011/10/13/cross-forest-exchange-migration-notes-from-the-field-part-1.aspx</link><pubDate>Thu, 13 Oct 2011 06:58:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3459012</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3459012</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/10/13/cross-forest-exchange-migration-notes-from-the-field-part-1.aspx#comments</comments><description>&lt;p&gt;Exchange migration has always been a topic of interest for&lt;br /&gt;organizations. As more and more organizations depend on Exchange as their core&lt;br /&gt;infrastructure downtime during upgrades have been noticeable by the clients and&lt;br /&gt;need detailed planning. When there is a need to change the forest as a part of&lt;br /&gt;this upgrade, the problem becomes a complex migration exercise.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s take a hypothetical organization running Exchange 2007&lt;br /&gt;which wants to move to Exchange 2010 in a new forest. For the sake of argument&lt;br /&gt;lets say customer only wants to migrate exchange functionality to the new&lt;br /&gt;forest and the old forest will remain where Exchange will be uninstalled. When&lt;br /&gt;the number of clients involved is large, the mailbox move process can take&lt;br /&gt;longer than the organization can tolerate downtime and coexistence is needed.&lt;br /&gt;Coexistence can be defined as where you have 2 exchange organizations in 2&lt;br /&gt;different forests and it acts like a single organization. Here are important&lt;br /&gt;points to consider for kind of migration:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Mail&lt;br /&gt;flow:&lt;/b&gt; generally mail flow to and from Internet is done from the old&lt;br /&gt;organization during coexistence phase and mail between the organization is done&lt;br /&gt;with connectors in between.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Mail&lt;br /&gt;Access:&lt;/b&gt; For OWA users this will depend on where the mailbox is hosted at a&lt;br /&gt;given particular time. Exchange can provide redirection to the new environment,&lt;br /&gt;more on this later. For Outlook anywhere and ActiveSync users Autodiscover will&lt;br /&gt;need to be used in cross-forest configuration. In order for autodiscover to&lt;br /&gt;work you will need to have Outlook 2007 as a minimum on clients.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Availability:&lt;/b&gt;&lt;br /&gt;During coexistence you need to be able to query free/busy information. Exchange&lt;br /&gt;2010 supports several methods to get this information.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In order for these functions to work, you need do analysis&lt;br /&gt;on source forest:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Single&lt;br /&gt;sign on:&lt;/b&gt; During coexistence you will need an entry point that can connect&lt;br /&gt;to both forests and would receive credentials from clients only once.&lt;/li&gt;
&lt;li&gt;&lt;br /&gt;&lt;b&gt;Account&lt;br /&gt;names:&lt;/b&gt; If customers are using Domainname\username format to logon, this&lt;br /&gt;will need to change when Exchange moves to the new forest. One way to solve&lt;br /&gt;this problem will be to use UPN. Users accessing old forest can start using UPN&lt;br /&gt;and the new forest will also have the same UPN but different forest name. Generally&lt;br /&gt;you would want to have UPN the same as the e-mail of the user.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This part clearly shows you need to have a lot of&lt;br /&gt;preparation before you do the migration. We will focus on more details in later&lt;br /&gt;series.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.myworldmaps.net/map.ashx/{cb230c42-efb9-4fab-942a-0f6fcf5ede0a}/ping" width="1" height="1" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3459012" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Exchange/">Exchange</category></item><item><title>What are the trends in IT for 2011</title><link>http://blogs.technet.com/b/erenturk/archive/2011/08/01/what-are-the-trends-in-it-for-2011.aspx</link><pubDate>Mon, 01 Aug 2011 05:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3444425</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3444425</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/08/01/what-are-the-trends-in-it-for-2011.aspx#comments</comments><description>&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;So here are a couple of trends that will affect our lives for the near future:&lt;/p&gt;
&lt;ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Processing Power:&lt;/b&gt; Computer processing power doubles every 18 months. We know this as Moore&amp;rsquo;s law. There are signs that this will slow for the coming years.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Hand-held devices:&lt;/b&gt; Small devices are capable of delivering high computational power that was only available to desktop computers 5 years ago. These devices will have multi-core CPU&amp;rsquo;s delivering great performance in the coming years. We might expect to see 3D displays on these devices too.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Multi-core:&lt;/b&gt; We will see more multi-core processors but harnessing the computational power will depend on software algorithms and optimization. Heterogeneous cores promise performance and efficiency gains.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Mobile social networks: &lt;/b&gt;Social networks are already a large part of our lives. It will become more dominant as everybody will have mobile devices as a part of their lives.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Bandwidth:&lt;/b&gt; Digital bandwidth is doubling faster than processing power. Our average connectivity to Internet is growing at an incredible speed. Globally connection speeds above 5 Mbps was %22 and increased %3 year over year. Check &lt;a href="http://www.akamai.com/stateoftheinternet/"&gt;Akamai&lt;/a&gt; for detailed information.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Mobile Internet:&lt;/b&gt; More and more of Internet traffic is generated from mobile devices. The number has doubled and this trend is expected to continue.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Wireless bandwidth demand:&lt;/b&gt; The demand for bandwidth has grown while consumers expect to pay less for more available bandwidth. However mobile revenues are not reaching the levels needed for investment.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Storage Capacity:&lt;/b&gt; Digital data storage is doubling every 12 months. Current Information on Internet is estimated to contain close to 1.1 ZB (Zetabytes) of Information.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Storage vs bandwidth:&lt;/b&gt; When you look at disk drive capacity and consumer bandwidth, the rates are a little bit different. A good comparison can be seen &lt;a href="http://blog.backblaze.com/2011/06/22/price-gap-storage-vs-bandwidth/"&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Sensors:&lt;/b&gt; Sensors would be embedded in almost every object we use. One of the new protocols for communication to watch for is ANT+. More information can be found &lt;a href="http://www.thisisant.com/pages/technology/what-is-ant-plus"&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Micro Display technology:&lt;/b&gt; Micro displays are changing the world of physical displays. There were over 150 new pico-projector models released in 2010. Some interesting information can be found &lt;a href="http://picoprojector.org/"&gt;here&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;img src="http://www.myworldmaps.net/map.ashx/{528b317-0661-43f7-b132-3c31387f8ef8}/ping" width="1" height="1" /&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3444425" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/trends/">trends</category></item><item><title>Internet of Things, why should I care?</title><link>http://blogs.technet.com/b/erenturk/archive/2011/06/10/internet-of-things-why-should-i-care.aspx</link><pubDate>Fri, 10 Jun 2011 09:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3434749</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3434749</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/06/10/internet-of-things-why-should-i-care.aspx#comments</comments><description>&lt;p&gt;The idea of &lt;a href="http://en.wikipedia.org/wiki/Internet_of_things"&gt;Internet of things&lt;/a&gt; is not new. It&amp;rsquo;s all about different devices being connected to Internet, not to provide information directly to a user but to consume or provide information about itself. For example a &lt;a href="http://en.wikipedia.org/wiki/Digital_frame"&gt;digital photo frame&lt;/a&gt; can use Internet to download pictures from the Internet. The idea is that the person that views the picture may not be the one selecting which picture to display. Taking this idea forward, devices can talk to other devices on Internet. So the whole Internet Sea is shared between humans and devices. &lt;/p&gt;
&lt;p&gt;So when does this become interesting? Recent advances in technologies provide lots of systems to be aware of their surroundings. For example your Windows 7 phone has &lt;a href="http://msdn.microsoft.com/en-us/Video/gg153662"&gt;cameras&lt;/a&gt; and &lt;a href="http://accelerometer.codeplex.com/"&gt;accelerometers&lt;/a&gt; and can detect its orientation in your hand. With the help of software you it can tag the picture with the date/time and place (through GPS) when you are uploading it to a web site. So you are in a foreign country and you don&amp;rsquo;t know the language. You point your phone to the sign and in real time you see the same sign through your phone in your own language. There are actually &lt;a href="http://top10.com/mobilephones/news/2010/12/iphone_word_lens_camera_app_revolutionises_translation/"&gt;prototypes for these applications&lt;/a&gt; for other mobile platforms that are impressive. So basically we are connecting sensors from all around the world to Internet. (Information on RFID sensors can be found &lt;a href="http://gaoengineering.com/rfid/c/bloglist/rfid+sensors,0"&gt;here&lt;/a&gt; and development information can be seen &lt;a href="http://windowsteamblog.com/windows/b/developers/archive/2009/04/02/windows-7-sensor-and-location-net-interop-sample-library.aspx"&gt;here&lt;/a&gt;) I just want to stress how powerful this can be. Obviously there are privacy issues that needs to be taken care of but that&amp;rsquo;s a different topic.&lt;/p&gt;
&lt;p&gt;Microsoft announced &lt;a href="http://www.xbox.com/en-US/Kinect"&gt;Kinect&lt;/a&gt; for Xbox 360 a while ago. There have been lots of articles on how it would change the gaming experience.(One example can be seen &lt;a href="http://rww.readwriteweb.netdna-cdn.com/archives/could_kinect_control_your_internet_of_things.php"&gt;here&lt;/a&gt;) Apart from being used as a controller for games, it became very popular for other uses. There have been different projects (Examples can be seen &lt;a href="http://www.readwriteweb.com/archives/kinect_browser_navigation.php"&gt;here&lt;/a&gt;, &lt;a href="http://createdigitalmusic.com/2010/11/kinect-with-midi-with-microsofts-3d-camera/"&gt;here&lt;/a&gt; and &lt;a href="http://www.readwriteweb.com/archives/heres_what_you_can_build_with_kinect.php"&gt;here&lt;/a&gt;) all around the world for using Kinect for never before thought purposes. The reason for this popularity was that we had all necessary components except the software to tie everything together. Now that we can use the power of software to get information from the data coming from the sensors, a whole new world begins. I am sure we will see these kinds of solutions embedded more and more into our lives. &lt;/p&gt;
&lt;p&gt;Just to give you a few examples on potential applications, you would see Intelligent TV sets. It will open when you sit in front of them and you would be able to control them through your hand gestures (&lt;a href="http://www.techspot.com/news/43304-microsoft-adds-kinect-support-for-netflix.html"&gt;Netflix on Xbox 360 can do this Today&lt;/a&gt;), no searching for the lost remote controls anymore. In the near future except for high security areas, we will start seeing face recognition for access control. That means no use of passwords or maybe even keys for some uses. So you may have a home system where there will be a log of every major event. Your family members entering home, going out. If they are using an Internet enabled shoes for jogging you will see how fast they are going or even if they need help. &lt;/p&gt;
&lt;p&gt;So Internet of things is about to become reality for the majority and will change our lives in ways you will never have imagined. &lt;/p&gt;
&lt;p&gt;&lt;img height="1" width="1" src="http://www.myworldmaps.net/map.ashx/{c67c24b7-0e5c-4334-927e-6de2b5c2df41}/ping" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3434749" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Internet+of+things/">Internet of things</category></item><item><title>If you don’t care about Service Management, think again</title><link>http://blogs.technet.com/b/erenturk/archive/2011/05/21/if-you-don-t-care-about-service-management-think-again.aspx</link><pubDate>Sat, 21 May 2011 08:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3430784</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3430784</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/05/21/if-you-don-t-care-about-service-management-think-again.aspx#comments</comments><description>&lt;p&gt;Some of you may have heard about ITIL and MOF and being a technical person processes and governance may not be that much appealing to you. You may have been thinking It&amp;rsquo;s only for large enterprises with lots of money and time to implement processes. That view is changing lately. As datacenter management is becoming more and more complex, tracking activities and governance is becoming a concern. &lt;/p&gt;
&lt;p&gt;Microsoft has a service management solution based on System Center Service Manager. Although you might think it is a new product actually it has been in the works for quite some time and has been rewritten several times before releasing as a product. There are several good resources around how SCSM is aligned with MOF and processes but the real reason behind using these type of solutions is to keep track of all service management activates and creating reports on them. For example if you deploy a service pack to your servers and some of the servers do not boot, the first question you would ask is why didn&amp;rsquo;t we see this during our testing? So who did the testing, when did it happen and what was the result and where is it now? That&amp;rsquo;s where you need the service management or update management to be specific. You need a solution just like SCSM that will record a need for change (apply Service Pack) create and record a workflow of events (Approve for testing, assign to a person for testing and recording results, approve for pilot servers, record results and approve for distribution to all servers) so that you can come back later to see if everything was done properly. &lt;/p&gt;
&lt;p&gt;So far, what I have told is not interesting for some. I am just imposing more paperwork to you who are the already busy doing work. However there is a lot of maintenance work that a datacenter admin would need to do in terms of checking files, running scripts etc. What if there is a wizard behind the curtains that can read the change requests, do all the maintenance tasks and put the results back to the change request. That wizard is Opalis. Opalis is a workflow engine that has integration packs with lots of other systems and can read events, objects from them, act on them and return the results back to the other systems. It is like writing scripts without entering a single line of code. &lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s talk about an example. One of the common things a domain administrator will do is search for old computer accounts in the domain and delete them. This has to be done regularly in order to keep your Active Directory clean. From a service Management perspective this is a process that needs approval. You can have a policy in Opalis that will trigger every month and run a script to search for old computer accounts in the domain and create a text file with computer names in it. Then it will create a change request in Service Manager from a template you already have for this process. Service Manager will record the request and trigger a review activity for the admin that will send you (the Domain Admin) an e-mail saying that you are expected to approve the deletion of old computer accounts. Going to Service Manager, you check the list of computer names and approve the request. Opalis will happily see that can trigger another policy to run a script to read the file and delete the computer accounts in the domain and put the result of the activity in the change management request and if successful will close the request automatically. Now that makes everybody happy. IT management can view these change management activities in their reports and domain admins do not need to remember running these scripts.&lt;/p&gt;
&lt;p&gt;Service Management can actually make people&amp;rsquo;s lives easier when SCSM is used together with Opalis.&lt;/p&gt;
&lt;p&gt;&lt;img height="1" width="1" src="http://www.myworldmaps.net/map.ashx/{465230e3-2229-4103-a8a0-9c3179da982c}/ping" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3430784" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Service+Manager/">Service Manager</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Opalis/">Opalis</category></item><item><title>Microsoft iscsi target goes public</title><link>http://blogs.technet.com/b/erenturk/archive/2011/04/05/microsoft-iscsi-target-goes-public.aspx</link><pubDate>Tue, 05 Apr 2011 06:36:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3418645</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3418645</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/04/05/microsoft-iscsi-target-goes-public.aspx#comments</comments><description>&lt;p&gt;Some of you might not seen this announcement so I wanted to re-iterate the fact that Microsoft iscsi target is release to public.&amp;nbsp;This is an important milestone as it shows virtualization is becoming one of the tools that can solve business problems like branch office productivity providing low cost solutions. Detailed information can be found in &lt;a href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx/this blog" title="http://blogs.technet.com/b/josebda/archive/2011/04/04/microsoft-iscsi-software-target-3-3-for-windows-server-2008-r2-available-for-public-download.aspx"&gt;this blog&lt;/a&gt;. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3418645" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Hyper_2D00_V/">Hyper-V</category></item><item><title>Functional versus Performance problems</title><link>http://blogs.technet.com/b/erenturk/archive/2011/03/28/functional-versus-performance-problems.aspx</link><pubDate>Mon, 28 Mar 2011 17:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3416557</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3416557</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/03/28/functional-versus-performance-problems.aspx#comments</comments><description>&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;When there is a multi-component system, there may be cases where system is working partially. There are two basic classes of problems:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Functional Problems:&lt;/b&gt; These problems are where one or more parts of the systems are not providing the necessary functions. The problem is generally well defined and can be easily isolated. The problem solution approach is directed toward dependency isolation and remediation. When a functional problem arises, the troubleshooting should start with isolating the dependencies of the non-functional part. This may not be as obvious when you start. There may be hidden external dependencies that will only manifest themselves when they stop functioning. This is one of the reasons on why every component in a system should provide on their state change to a central repository together with a reason if possible. For example when Exchange store service stops, you see an entry in the event log. Searching earlier events you also see that Windows is having problems accessing a volume where your Exchange databases reside. So now that you have isolated your dependencies, you can check on the host connector cables, storage device connections etc. However most of the time, problem is not solved but converted to another problem class.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Performance problems:&lt;/b&gt; These problems are where system is providing the necessary functions but the performance is not as expected. Generally finding these problems are much harder than functional problems. The primary reason for this is in functional problems you simply have a state change where in performance problems you need to take a history of the level of functions according to a given metrics. Most of harder to detect problems start as performance problems and convert to functional problems which are much more visible. However due to operational constraints root cause analysis is not carried out and once functional problems are identified they are converted to performance problems and pressure to solve them drops. In order to identify performance problems you need historical data from all related systems and correlate them to find a difference in performance and isolate the component(s) that is causing the problem. Sometimes this is easy if your systems are not affecting each other. However if you have a highly available web site, you will need to check the performance starting from your network links to load balancers to web servers and to databases. In order to see what the problem is, you need performance counters or operational logs from all systems with a common time source. This may be event log entries from your services but also can be much more detailed logs you need to collect to see inner workings of the service that is being provided. You may also need to have triggers to start/stop collecting data or you may have mountains of data to store and to analyze. If one of the components cannot provide detailed logs you may not be able to solve the problem. Next time you are buying a cheap switch/router check on data collection and reporting capabilities and decide if you want to take the operational risk with a system in question.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;When you are designing a multi layered service, you need to have necessary data collection mechanisms with a common time source that can be triggered based on events and can be stored for enough time to provide the course of events leading to a performance problem. This way it will be much easier to track your performance problems when faced with hard to solve issues. &lt;img height="1" width="1" src="http://www.myworldmaps.net/map.ashx/{2f290388-8b6d-4e65-8068-a2bd640ed65f}/ping" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3416557" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Problem+Solving/">Problem Solving</category></item><item><title>Why not virtualize everything?</title><link>http://blogs.technet.com/b/erenturk/archive/2011/02/06/why-not-virtualize-everything.aspx</link><pubDate>Sun, 06 Feb 2011 13:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3385262</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3385262</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/02/06/why-not-virtualize-everything.aspx#comments</comments><description>&lt;p style="margin: 0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Virtualization is seen as a magic wand in server world. What ever your problem, lets virtualize and consolidate and your problems will be gone. This is far from truth. When you look at applications runninng on servers most of them are not designed to handle a lot of resources. When you want to use them above their design limits their either fail or use so much resources that performance drops. In that case you will mostly use more servers with smaller hardware footprint. These are good candidates for virtualization. However there may be other alternatives that can use physical hardware more efficiently and thus do not need to be virtualized.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;One of the examples is Terminal Services. When using 32-bit Terminal services on Windows server 2003, you are limited with memory and CPU that you can consume. Scaling terminal services depends on the applications thats being used platform is also key for scaling. Even if you increase Ram above 4&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;GB (say &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;8 GB), your numbers will not increase due to 32-bit architecture limits. In 32-bit Windows users can use up to 2 GB, the left is used by kernel. You can reduce the memory kernel down to 1 GB and this will provide 3 GB for user applications. However there are other kernel resources that need memory and you are likely to hit those limits in a Terminal services environment. One way to increase your number of users, is to have a server with 8 GB of RAM, use Hyper-V and create 2 virtual machines and install 32-bit terminal services on top to get twice as much users. However when terminal services is used with virtualization, due to the nature of the application performance may drop. New processors have features that can eliminate this problem but your performance will not increase twice as much. The other alternative would be to move to 64-bit terminal services (or Remote Desktop Services in Windows Server 2008 R2) and use physical hardware. This will both increase the number of users on a single box and increase your performance due to advances in the connection protocol (RDP). &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Somethimes perfecting a in-house business application can take time. The general tendency will be to keep the application as it is as long as possible and try to change the environment to gain advantage. However this is only a temporary measure. Technology is evolving to become more efficient and provide more features. However your applications should evolve and adapt to the new environment. Protecting an application can cost you more than you think.&lt;img width="1" src="http://www.myworldmaps.net/map.ashx/{af4e2391-6c36-478e-aa55-3249ed190c49}/ping" height="1" /&gt; &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3385262" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/RDP/">RDP</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Hyper_2D00_V/">Hyper-V</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Remote+Desktop+Services/">Remote Desktop Services</category></item><item><title>How to stress test terminal services with Windows Powershell</title><link>http://blogs.technet.com/b/erenturk/archive/2011/01/19/how-to-stress-test-terminal-services-with-windows-powershell.aspx</link><pubDate>Wed, 19 Jan 2011 14:06:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3381215</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3381215</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2011/01/19/how-to-stress-test-terminal-services-with-windows-powershell.aspx#comments</comments><description>&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;When you want to do scalability testing for your terminal services (or Remote Desktop Services on Windows Server 2008 R2) you need some automation to make this easier. There is &lt;/span&gt;&lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=c3f5f040-ab7b-4ec6-9ed3-1698105510ad"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Remote Desktop Load Simulation Tool&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; that you can use to test your environment. I tried to use this in one of my customers recently and had to &amp;hellip; enhance it to fit my needs. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Briefly the tool is using a COM API (RemoteUIControl.dll) to connect through the Remote Desktop protocol to send necessary commands and you can use a script to simulate user activity. You would need to install 3 sets of tools on 3 different parts to do the testing. Please be aware that the method I am about to tell is not supported or endorsed by Microsoft. Instead of using the tool components provided I decided to use the API to create my own test tools. You need RemoteUIControl.dll and RUIDCOM.exe on your test clients. You will need TSAccSessionAgent.exe running on your terminal servers. You can simply get the client components installed on your tester client and Server components installed on RDS servers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Now to start the testing you would require users, lots of them. (Image the movie Matrix, where Neo tells &amp;ldquo;We need guns lots of them&amp;rdquo;). You can simply run a Windows Powershell script to create test users. Here is a simple loop to do this on your Windows Server 2008 R2 DC (Note that you will need the modules to be loaded to use New-ADuser cmdlet to function):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;for ($i=1;$i -le&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;$NumberOfusers;$i++)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;{&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;$CN="RDS"+$i &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;$Password = ConvertTo-SecureString "12345678" -AsPlainText &amp;ndash;Force&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;$DN="CN=" + $CN + "," +$TargetOU&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;New-ADUser $CN -Path $TargetOU&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;-AccountPassword $password -Enabled $True&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Of course you would need to set the variables for your environment. After this is done, you will want to create a script that will run as a test user to create activity. I am leaving this as an exercise as there is pretty good vbscript example inside the tool I mentioned above. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;The next step will be to replicate those testers to create a simultaneously acting users to create load on your remote Desktop services. Here is a loop to do this. Please keep in mind that you do not need to run this on your DC and not even in the same script that is used to create users:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;for ($i=1;$i -le&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;$NumberOfusers;$i++)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;{&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$CN="RDS"+$i &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;[string[]]$Arglist="test2.vbs","-s:$Servername","-u:$CN","-p:$pwd","-d:$Domain","-f:1"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;Start-process -FilePath "c:\windows\system32\cscript.exe" -ArgumentList $ArgList&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;sleep -seconds 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 11.0pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;When you first run this script you will see several (depending on number of users) windows pop up and they will connect to your remote desktop the first time and new profiles will be created. This is a very intensive operation and if your numbers of users are high, will easily choke your server(s). That is the reason to have a sleep statement to slow this down. Some of the users may not be able to connect or finish the script that you provide. The next run will be much easier.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 11.0pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Finally if some of your connections are hanged you will need to terminate the processes on your client machine. This can be easily done by the following command:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;get-process -name ruidcom | foreach-object {$_.kill()}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;This is a very powerful command and should be used with caution. If you do not provide the name of the process, it will kill all the processes on your client which will instantly turn off your machine :)&lt;img height="1" width="1" src="http://www.myworldmaps.net/map.ashx/{b00ec8f9-6a00-473c-8056-f96c1545d82a}/ping" /&gt; &lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3381215" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Powershell/">Powershell</category></item><item><title>How do you control computer usage habits for children?</title><link>http://blogs.technet.com/b/erenturk/archive/2010/12/30/how-do-you-control-computer-usage-habits-for-children.aspx</link><pubDate>Thu, 30 Dec 2010 21:21:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3377893</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3377893</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/12/30/how-do-you-control-computer-usage-habits-for-children.aspx#comments</comments><description>&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;As most of you are on holiday, I wanted to share some insights on home computers&lt;/span&gt;&lt;span style="font-family: Wingdings; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-char-type: symbol; mso-symbol-font-family: Wingdings;"&gt;&lt;span style="mso-char-type: symbol; mso-symbol-font-family: Wingdings;"&gt;J&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;When you have more than one child like I do you always have competition for using the home computer. Competition is good as long as you have the necessary rules to facilitate smooth operation. Up until now, I had only one local account on our house computer running Windows 7 and the account. The user profile was locked down and only allowed for specific applications (read games) to run. However it had one major flaw. Any one child sitting in front of the computer can monopolize the time until a parent intervenes. This causes the all children except one to complain about how long the one at the computer is playing. So solution to that problem would need the following attributes:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;The computer should keep track of who is allowed to logon and when and for what duration. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;It should provide detailed logs around who is disallowed from logging on and how much time is remaining for a particular user. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;It should provide global settings that can be set from a central location. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;It should auto-install and create necessary information stores if necessary.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;It should discourage the usage for a long time so that others can use the computer but allow it after a certain time interval so that it gives credit for persistence.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;The computer is in workgroup so using domain based controls is not an option. You can not use a script in start menu startup as it would be too easy to detect. The best approach is to use run registry key for local users. However I used parental control feature of Windows 7 and regedit was not available inside the restricted user account. The workaround is to logon to an administrative account and load restricted users registry hive (ntuser.dat) and set the run registry key. I created a powershell script that would implement the above attributes. Do not forget that run will issue the command before explorer is started so environment variables will not be there and you would need the full path. Below is the line I exported from regedit. I purposefully did not provide full file as loading hive will give different names for different users:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;"LogoffTimer"="C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\Powershell.exe -windowstyle hidden c:\\windows\\logoffTimer.ps1"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;This line will run the powershell script logoffTimer.ps1 without showing a window to the user. The script starts when the user logs on and first checks if registry values are present. These are used for storing information around time used on last session, logon count, last logon time and time used for the day. It will create if values are not present. This way if you need to add another variable to the script you do not need to reset the registry.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;if (Test-RegistryValue "hkcu:\software\erenturk\LogoffTimer","UsedDailyMinutes"&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;-eq $False)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;new-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "UsedDailyMinutes" -value $UsedDailyMinutes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;else&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$UsedDailyMinutes=(Get-itemProperty -path hkcu:\software\erenturk\LogoffTimer -name "UsedDailyMinutes").UsedDailyMinutes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Next we check if a day has passed since last logon, if it did we reset counters in registry for a new day otherwise we check if daily quota is reached and log off if necessary. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;$lastLogonDelta=New-TimeSpan -start $LastLogon -end $now&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;$lastLogonDeltaDesc=GetTimeSpanDescription($lastLogonDelta)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;if ($LastLogon.day -eq $now.day)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;add-content $logfile "$username has logged on for $UsedDailyMinutes minutes Today, $DailyLogonCount times and last logged $lastLogonDeltaDesc ago"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;add-content $logfile "$username has used $usedSessionMinutes minutes session time on last logon"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$DailyLogonCount=$DailyLogonCount+1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;set-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "DailyLogonCount" -value $DailyLogonCount&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;else&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;if ($LoggingLevel -gt 2) {add-content $LogFile "INFO: Day has passed since logon, reseting counters"}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;set-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "DailyLogonCount" -value $DailyLogonCount&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;set-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "UsedDailyMinutes" -value $UsedDailyMinutes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;set-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "UsedSessionMinutes" -value $UsedSessionMinutes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;add-content $logfile "$username is logging first time today,last logged on $lastLogonDeltaDesc ago"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;If the user is logging on for a second time, we check if the session time is finished. This is implemented so that if user logs of before allowed time, he/she can logon immediately afterwards. This is generally needed for accidental logoffs. If their session time has finished, script will check for last logon and will not log you on before a certain time passes. This gives chance to other users to use the computers before the first one is allowed again. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;If user is finally allowed to log on, we create a loop that will awake every minute to see if time is finished and write the time left to log file, when it does writes the used minutes and logs off the user.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;$EndTime=$now.addMinutes($SessionTimeLeft)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;$TimeSpan=new-timespan $now $EndTime&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;while ($timeSpan -gt 0)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;$timeSpan = new-timespan $(get-date) $endTime&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;sleep -Seconds 60&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;$UsedDailyMinutes=$UsedDailyMinutes+1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;$usedSessionMinutes=$UsedSessionMinutes+1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;set-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "UsedDailyMinutes" -value $UsedDailyMinutes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;set-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "UsedSessionMinutes" -value $UsedSessionMinutes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;$Remaining=GetTimeSpanDescription($timeSpan)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;add-content $logfile "$Remaining remaining..."&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;$UsedDailyMinutes=$UsedDailyMinutes+1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;$usedSessionMinutes=$UsedSessionMinutes+1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;set-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "UsedDailyMinutes" -value $UsedDailyMinutes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;set-itemProperty -path hkcu:\software\erenturk\logoffTimer -name "UsedSessionMinutes" -value $UsedSessionMinutes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;add-content $logfile "Session time allowance is reached, user will be logged off"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 10pt;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;logoff&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;After I implemented the script and made the necessary rules, I was amazed to see how fast it was received by the children. You can find the script attached to the post. &lt;img height="1" width="1" src="http://www.myworldmaps.net/map.ashx/{0a4d40fa-7e04-4d0d-b439-9f16d3584041}/ping" /&gt;&lt;/span&gt;&lt;a name="_GoBack"&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3377893" width="1" height="1"&gt;</description><enclosure url="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-components-postattachments/00-03-37-78-93/LogOffTimer.zip" length="2051" type="application/x-zip-compressed" /><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Powershell/">Powershell</category></item><item><title>If you still have servers in all of your branches, think again</title><link>http://blogs.technet.com/b/erenturk/archive/2010/12/18/if-you-still-have-servers-in-all-of-your-branches-think-again.aspx</link><pubDate>Fri, 17 Dec 2010 22:54:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3375879</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3375879</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/12/18/if-you-still-have-servers-in-all-of-your-branches-think-again.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;If you have large distributed environments, you will have connected branches to your headquarters. More than a decade ago, these links had small bandwidth (around 64kbps) or even used X.25 like some of my customers. Generally links were unreliable and had a tendency to malfunction from time to time. Using backup lines were either prohibitively expensive or alternative technologies were in their infancy to be used reliably. Back then you needed servers in your branches and use caching on those servers so that you can resume your work in case your link goes down. Some of my customers had (and some still have) teams monitoring all the links (some over 1000 locations) and working with the ISP to resume service on some of them. My customers used to have large number of sites in Active Directory and file servers running on branch servers. You also needed backup software and tape drives on those machines to do local backup. When you work in these environments for some time you tend to attain a habit of keeping whatever you have and this blurs your vision of connectedness.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;During the last decade, link speeds and reliability have gone up considerably. You can use 3G wireless backup lines for your primary lines and link speeds have reached 1-5 Mbps for most of the places. Your mileage may vary but the point is link speeds have gone up at least 20 times (my home Internet connection speed has increased 40x times in this period) and you can attain high available lines with much less effort combining different technologies. Not only can you use higher bandwidth to connect your branches but you can have a different topology as well. Think of this as a slider where each point will enable different functionality as you increased your connected bandwidth. If you slightly increase your line bandwidth you can start taking backups from central location during nights or you can remove branch servers from your smaller branches. I did an analysis several years ago for one of my customers around what the optimal number of PC&amp;rsquo;s in branches need be to make it feasible to put branch servers. I included operational link costs, initial cost of the servers and an estimated maintenance cost for servers and came up with a magical number of 14. If branch had less than 14 PC&amp;rsquo;s customer placed no branch servers but serviced PC&amp;rsquo;s from central site instead. Of course your magical number may vary on your own conditions however the point is, the more you feel comfortable with the links the fewer servers you will need in branches. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;There are organizations that have created their topology over a decade ago and have not changed it since. Some still fear of unreliable links and keep Exchange servers in their branches. (One specific customer of mine has over 600 Exchange servers) Exchange Server is designed to be placed in central sites for the last two versions at least and it&amp;rsquo;s getting harder to deploy it in branches with each new version. Some customers refuse to use read only domain controllers (RODC) on the basis of the extra load it brings to the network. It may not be feasible to remove every branch server in your environment, however if you still have branch servers in all of your branches it is time to reconsider your server placement strategy. &lt;img height="1" width="1" src="http://www.myworldmaps.net/map.ashx/6e48f7df-9734-4ecf-922b-631c15678e2d/ping" /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;There is no point in trying to upgrade your software if you do not adapt yourself to the new perception of connectedness. Some of my customers are already using VPN over Internet between their central sites and branches and have reduced their branch servers with a goal of reaching down to a dozen locations that will have servers. Looking into the near future, we will be using IPSec VPN&amp;rsquo;s over IPv6 Internet for all of our client machines without even knowing which of branch servers is closest to you, so&lt;/span&gt;&lt;a name="_GoBack"&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt; start getting ready now. &lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3375879" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/branch/">branch</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Connectedness/">Connectedness</category></item><item><title>How will it affect your business if you do not embrace IPv6?</title><link>http://blogs.technet.com/b/erenturk/archive/2010/11/17/how-will-it-affect-your-business-if-you-do-not-embrace-ipv6.aspx</link><pubDate>Wed, 17 Nov 2010 13:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3369253</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3369253</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/11/17/how-will-it-affect-your-business-if-you-do-not-embrace-ipv6.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;If you are providing services to Internet, you should be watching the trends on Internet. There are various web sites providing information. The one I want to mention here is &lt;/span&gt;&lt;a href="http://techcrunch.com/2010/11/16/ten-questions-internet-execs-should-ask-and-answer/"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;ten questions Internet Execs should ask and answer&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Who are your potential customers? It turns out that USA, Russia, China, Brazil and India are the largest Internet markets. So let&amp;rsquo;s take a look at how they are doing in IPv6:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -18pt; margin: 0mm 0mm 0pt 38.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;United States: &lt;/b&gt;United States government has been &lt;/span&gt;&lt;/span&gt;&lt;a href="http://fcw.com/articles/2010/10/18/cybereye-gov-leads-on-ipv6.aspx"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;pushing IPv6&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt; for some time now. There are several Internet service providers already providing Ipv6 addresses.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; margin: 0mm 0mm 0pt 38.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;China:&lt;/b&gt; China started planning for Next generation Internet back in 2002. They have fully functional IPv6 backbone and they even provided a showcase with 2008 &lt;/span&gt;&lt;/span&gt;&lt;a href="http://ipv6.beijing2008.cn/en"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Olympic games which were provided from IPv6 infrastructure.&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt; (The link is IPv6). &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; margin: 0mm 0mm 0pt 38.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;India:&lt;/b&gt; India government has recently decided to implement IPv6. They will be using &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.cio.com/article/600112/India_Plans_to_Introduce_IPv6_By_2012"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Ipv6 by 2012 according to an IDC study.&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; margin: 0mm 0mm 0pt 38.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Brazil: &lt;/b&gt;Brazil has been using Internet through IPv6 for a couple of years. In fact south America has the fastest growing IPv6 address space in the world. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -18pt; margin: 0mm 0mm 10pt 38.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Russia:&lt;/b&gt; Use of IPv6 has been on the rise for Russia according to &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.h-online.com/newsticker/news/item/Google-Russia-and-France-are-ahead-in-IPv6-738131.html"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;research made by Google&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;This means that top 5 of largest Internet markets are ready to use IPv6. If you are interested in how much addresses are allocated in each country, there is a list you can check out &lt;/span&gt;&lt;a href="http://bgp.potaroo.net/iso3166/v6cc.html"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;How are they accessing your site? The fastest growing area is mobile devices. There are around 120 million subscribers using iphone+iTouch+ipad and adding 60 million each year assuming the rate is constant. In just 4 years Japan Social networking switched from desktops (83% desktop/17% mobile in 2006) to laptops (14% desktops/84% mobile in 2010). This means mobile operators will needs lots of IP addresses for those mobile devices and the trend will increase in the near future. Please keep in mind that nearly all mobile platforms currently support IPv6 addresses.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Implementing IPv6 is not the only option for mobile operators as they can still use IPv4 together with NAT. However using such technologies will break certain scenarios such as targeted advertising which is going to be a large market. As long as the infrastructure is ready there will be a shift to IPv6 addresses pretty quickly. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;When the end user is using IPv6, they will need extra services for accessing Ipv4 Internet sites. The overwhelmingly used technology is 6to4. This means, your potential customers will need to pass through gateways to access your Ipv4 sites. There will be different services in this space with various degrees of success. There will probably be some IPv4 islands which will not be accessible from IPv6 addresses. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;In a short time (probably starting in a year) mobile users will start having Ipv6 address. They will want to access IPv6 based services as they will not need to pay for 6to4 services or hit extra performance penalty. There will be a first mover&amp;rsquo;s advantage for web sites presenting IPv4 and Ipv6 addresses. The others will slowly or furiously (depending on your area of service) be getting fewer hits every day. For advertisers gathering IPv4 addresses used behind NAT will not provide detailed information so they will choose sites that could give them Ipv6 addresses. There will be less opportunity your site will be chosen for advertisements.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0mm 0mm 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Moving to Ipv6 is not going to happen overnight. However due to increase in mobile devices, Ipv6 will first be used by them. If you currently are or planning to provide services to mobile users, you need to start now or you will start losing customers and advertising income soon.&lt;img height="1" width="1" src="http://www.myworldmaps.net/map.ashx/3e7dd42a-d38d-4aca-a01e-e2a7e38cc00e/ping" /&gt;&lt;/span&gt;&lt;a name="_GoBack"&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3369253" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/IPv6/">IPv6</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Mobile+devices/">Mobile devices</category></item><item><title>If you are still not using 64-bit operating systems you should read this </title><link>http://blogs.technet.com/b/erenturk/archive/2010/11/06/if-you-are-still-not-using-64-bit-operating-systems-you-should-read-this.aspx</link><pubDate>Sat, 06 Nov 2010 12:13:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3366349</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3366349</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/11/06/if-you-are-still-not-using-64-bit-operating-systems-you-should-read-this.aspx#comments</comments><description>&lt;p style="margin: 0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;From time to time I meet customers that are using older operating systems that are not 64-bit. Before I go any further let me give you the perspective:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;X86 Platform:&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt; This is the original PC platform that we used to use back in 1980&amp;rsquo;s. It has a maximum support for 4 GB RAM.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;I64 Platform (Itanium):&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt; This is the 64-bit platform which appeared first on stage and was modeled after a different architecture. It has support for much higher memory but is only available on expensive hardware. Due to architectural differences it needs to emulate x86 instructions in software and old applications written for x86 run much slower.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 10pt 36pt; text-indent: -18pt; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;X64 Platform:&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt; This is the 64-bit platform that has now become mainstream. It is using a similar architecture with x86 and can run older applications on hardware. It does support much higher memory. The rest of this blog this is the platform that I will refer to when I use 64-bit.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;When we talk about the reason for not moving, it generally boils down to incompatible hardware or software that does not run properly under 64-bit operating systems. I have seen several customers using old fax add-on cards that is leaving them behind and several software that simply refuse to run. Maybe its time you should think of leaving fax as a communications technology. Some of the readers will jump saying that they depend on fax for their everyday operations. Although this seems like a valid reason for not moving to 64-bit, the point is there are valid alternatives both technically and politically that can be used that can help you use 64 bit systems. There is something more subtle but more important than this. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Organizations tend to use technology as long as it works and does not cause any trouble. These technologies become brittle in time and become obstacles to innovation to your business. The way we do business is changing for everyone starting from coffee shops to large enterprises. You can not keep selling the same services and products forever. Nowadays success for organizations is measured by how much profit you are generating from the new products and services you are offering. This means adapting to change should be in your DNA as a company. This includes both planned changes and abrupt changes. If you do not embrace the change, you are losing adaptability to new conditions. If you do not adapt to change, your competition will and you will less likely to be fit and finally you will be extinct. This is the most important lesson organizations should borrow from evolution. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Now the new problem organizations are facing is the rate of change which is increasing even faster each year. In order to remain competitive, you need to have a framework which makes technological change easier. See my earlier post on &lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.technet.com/b/erenturk/archive/2010/09/30/agile-organizations-and-cloud-computing.aspx"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;agile organizations&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;. You should choose the right technology and put necessary processes to track its usefulness. Measuring usefulness can be difficult when you think of implementing this but when you do you will see that most of the technologies are replaceable with better ones after some time even though they are still functioning and providing value. When you change your mind set on change in technology you need to invest on technologies that are modular enough to change when needed easily and seamlessly. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-US;" lang="EN-US"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;When you are investing in a new technology, you should definitely evaluate the contribution to your business. However you should also think about how adaptable the new technology is to the changing conditions. If it is not, account for this, during in your decision. If you don&amp;rsquo;t we will have the same conversation when you plan to implement IPv6 or any other disruptive technology on the horizion.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3366349" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Agile+organization/">Agile organization</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/64_2D00_bit/">64-bit</category></item><item><title>How is DNSSEC related to web site security?</title><link>http://blogs.technet.com/b/erenturk/archive/2010/10/24/securing-web-sites-and-dns.aspx</link><pubDate>Sun, 24 Oct 2010 11:45:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3363720</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3363720</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/10/24/securing-web-sites-and-dns.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;When you have a web site where Money is changing hands, customer trust has upmost importance. The moment you loose trust you loose your customers. You will need to invest on your security strategy in a multi layered fashion. Here is a short list (not a comprehensive one) of items you should keep in mind:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;SSL certificate:&lt;/b&gt; You will need too have a SSL web site certificate that you can get from a well trusted authority. As expected the most important thing you will want to look at is their assurances and operations. Asking for a web certificate with highest key length is not enough, its about what policiees are in place. The questions you would need to ask is when your private key gets comprimized, how fast is their CRL updated?, what measures are taken to prevent comprimise of their intermediate and what standards their are applying to their operations.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Securing the environment:&lt;/b&gt; You would definetely want to have a secure network, securely configured host and applications. There are plenty of documentation on how to secure your routers, firewalls, locking down your servers and IIS configuration. If you would like to have more informataion please provide feedback and I will provide more information on this one. Get yourself ready for &lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.technet.com/b/erenturk/archive/2010/10/22/why-do-i-need-to-care-for-ipv6.aspx"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;using IPv6&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;. If you are planning for a web site or if you already have one running on older system, consider moving to Windows Server 2008 R2.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Secure Operations: &lt;/b&gt;Securing the environment is only the first half of the story. You need to keep it that way. This means you need to monitor your servers, keep them up to date and upgrade them when necessary. Fully secured web server with no recent updates is sitting ducks ready to be used by criminals.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Secure your web application:&lt;/b&gt; Its sometimes overlooked to get security review for your web application in place. No matter how good developers&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;you have, you will need to get a security review from a security experts. This is also true on updating your web applications.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 10pt 36pt; text-indent: -18pt; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Intrusion prevention and detection: &lt;/b&gt;Even if you did everything to secure your environment you will need to watch for activities on your web site. You need early warning signs if there is something unusual happening. This would need delicate tuning as these devices can create a lot of noise which can easily become overwhelming.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;There are different standards that you would need to adhere to and you should also check them out. For example if you want to process credit cards you would need to look at &lt;/span&gt;&lt;a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;PCI DSS&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;. However there is one more important part that needs your attention which is DNS.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;DNS protocol has been around for a long time. When it was first introduced security was not a concern. However as Internet grew, attacks based on DNS has increased considerably. The worst part is that as DNS is distributed service you need to trust other entities to provide security for DNS service. When a client asks for a dns name, DNS server will ask several dns servers before returning and answer to the client. If anyone of these servers are comprimized, client is redirected to a different web server which may look just like the original web site but actually is planned to get your username and password or credit card numbers. The best way to solve this problem is a standard that has recently popularized namely DNSSEC (DNS System Security Extensions). &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;DNSSEC is specified in RFCs 4033-4035. It adds new operations to DNS server and client and 4 new DNS records (DNSKEY,RRSIG,NSEC and DS). DNSSec digitally signs all records in a DNSzone. A client will obtain the public&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;key and validate that the responses are authentic. So when a client asks a question to DNS servers the answer is digitally signed. Each time you hop from DNS server to DNS server you know that the answer is genuine as long as signature is valid. DNSSec is a feature of Windows Server 2008 R2 and Windows 7. If you want to learn more about DNSSec on Windows you can find more information &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee649277(WS.10).aspx"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;. Even clients that do not understand DNSSEC can stil use the DNS servers in question, albeit without reaping the benefits of validation.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;One of the most important blockers for wide DNSSEC implementation was top level DNS zones not being signed. As of the time of this writing most of the top level zones have been digitally signed. One of the most important zones is .com and is expected to be signed early next year. This will be a key milestone to make DNSSec mainstream. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;When you are planning your DNS Infrastrcuture, you should keep in mind the following about DNSSEC:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt; mso-list: l1 level1 lfo2;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Dynamic update is not supported. You should use DNSSec on your external DNS entries and not on your internal DNS where clients are using dynamic DNS.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt; mso-list: l1 level1 lfo2;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;DNSSec is not a lightweight protocol. You will need extra bandwidth and strong servers to handle DNSSec traffic.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 10pt 36pt; text-indent: -18pt; mso-list: l1 level1 lfo2;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Clients will need to understand DSSec messages, which will happen with new operating systems. Do not expect that all clients trying to access your web site is secured the moment you implement DNSSec on your servers.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;DNSSec will help secure Internet but it will need effort from all implementing parties. It would be necessary to start planning as soon not to be left behind.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;As always, feedbacks are welcome. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3363720" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/DNSSec/">DNSSec</category></item><item><title>Why do I need to care for IPv6?</title><link>http://blogs.technet.com/b/erenturk/archive/2010/10/22/why-do-i-need-to-care-for-ipv6.aspx</link><pubDate>Fri, 22 Oct 2010 05:20:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3363467</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3363467</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/10/22/why-do-i-need-to-care-for-ipv6.aspx#comments</comments><description>&lt;p class="PadderBetweenControlandBody" style="margin: 0in 0in 6pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: xx-small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;Internet is using myriad of network protocols, the most important one being IP or Internet Protocol. This is the layer in which network decides how to send a packet to a given destination. Currently we are using IPv4 which has been with us for quite some time now and as you can tell it is showing its age. There are a couple of pain points in IPv4 that can be solved by Ipv6:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Address Space: &lt;/b&gt;IPv4 was designed to have 4 billion address spaces. Back in 1980s this was a huge number given the fact that there were only a couple of addresses being used. However the number of public IP addresses has grown to the limit. In fact Network Address Translation (NAT) and Classless Inter Domain Routing (CIDR) were technologies used to alleviate the address depletion problem. Number Resource Organization (NRO) has announced that almost %95 of addresses have been used. This means that last IP address blocks will probably be distributed in one year. If you want to provide an application on the Internet, you will probably need to use an IPv6 endpoint. Ipv6 will have 128 bit addresses which will be much larger in address space and is currently being used in Asia. We may well abandon use of NAT altogether when IPv6 is in use which will greatly simplify network topologies and firewall configurations. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Security:&lt;/b&gt; When IPv4 was first designed, there was no security technologies needed. However as Internet grow security became an issue and different protocols were created to solve the problems. IPSec was one of the security protocols that have been widely used. The good news is that IPv6 was designed with IPSec from ground up. So as long as devices or servers are supporting IPv6, secure connection can be established easily between them.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Configuration:&lt;/b&gt; IPv4 addresses need to be configured either manually or with DHCP service running on the network. Using DHCP can be a problem if there is more than one on the same network. IPv6 has address auto configuration properties so that nodes can configure their own IP address and default gateway without DHCP.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Flow Priority:&lt;/b&gt; Prioritized real time delivery of data is a part of Ipv4 but has some limitations like lack of packet prioritization with encrypted packets. IPv6 fully supports these capabilities and has enhanced handling of flow priority.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Now that we have some understanding of what Ipv6 can bring to your organization let&amp;rsquo;s talk about how to get prepared for it. Internet backbone is already in the process of upgrade to Ipv6 and most of the work is done. The major part of the work needs to be done inside the organization. IPv4 has been used for so long that we expect every node (device and applications) to work seamlessly. However not every node will support use of Ipv6. You will first need to identify parts of your network that is not capable of using Ipv6. Then you will need to plan on replacing those nodes taking into account your device and application lifecycles. Most of the network devices are already Ipv6 ready. What I have been seeing is that applications are still in the process of upgrading to work with Ipv6. If you want to learn more about developing applications that work with IPv6 you can attend Microsoft PDC10 October 28-29 online or find the event closest to your home! See the map &lt;/span&gt;&lt;a href="http://www.microsoftpdc.com/Local?WT.mc_id=soc-n-mea-loc--services_murater"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;You do not need wait until all of your devices are capable of supporting IPv6. There are transitioning technologies that will help you interoperate IPv4 with Ipv6 technologies. When you first start you will probably have a small subnet working IPv6 and use these technologies to communicate with the rest of your internal network and Internet. Gradually you will expand your Ipv6 networks up to your network edge firewall. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Ipv6 is the future and there is clearly no escape from it. The more you postpone your planning the more you will fall behind in adapting to the new networking capabilities of IPv6. I will urge all of the readers to think about what can be done to embrace IPv6 in their environment and create awareness for the upcoming changes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;I would love to hear feedback on what you are thinking of the blogs you have been reading so far. Please provide ratings and suggestions so that I can provide better and relevant information to you. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3363467" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/IPv6/">IPv6</category></item><item><title>How do I keep my job and benefit from public cloud?</title><link>http://blogs.technet.com/b/erenturk/archive/2010/10/15/how-do-i-keep-my-job-and-benefit-from-public-cloud.aspx</link><pubDate>Fri, 15 Oct 2010 08:54:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3362180</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3362180</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/10/15/how-do-i-keep-my-job-and-benefit-from-public-cloud.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;There is lots of thinking going on around how the cloud will change our lives. Some of the things done by IT professional today will be handled by the cloud in the coming years. So what can IT professionals do&amp;nbsp;now so that they can be relevant to the business in the future? There are specific areas where local expertise will still matter. Here is a list:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Business knowledge: &lt;/b&gt;Organizations moving to the cloud would have more time focusing on business related issues. Successful IT pro will be more business oriented and less deep technical in nature. For example instead of focusing on how/when they will be moving mailboxes between sites, they will need to focus on compliance and policy related issues regarding messaging. Once these are set, they will be able to map the required settings for the messaging system either on premises or in the cloud.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Security:&lt;/b&gt; When organizations start moving some of their services to the cloud, there will be a period where some of the services will be provided by the cloud provider and some will be provided in house. It will be very important to provide secure communications between the services and clients. So edge security and network security will be a premium in skills requirements inside organizations. For example organizations would want different security measures accessing their own applications in the cloud versus any other parts of the World Wide Web. Compliance will mandate different security measures and network security will be a very important focus of IT departments.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Identity Management:&lt;/b&gt; When organizations shift on the Infrastructure Optimization model (&lt;a name="http://blogs.technet.com/b/erenturk/archive/2010/09/30/agile-organizations-and-cloud-computing.aspx" href="http://blogs.technet.com/b/erenturk/archive/2010/09/30/agile-organizations-and-cloud-computing.aspx" title="here"&gt;&lt;/a&gt;more information on this is&lt;a href="http://blogs.technet.com/b/erenturk/archive/2010/09/30/agile-organizations-and-cloud-computing.aspx" title="here"&gt; here&lt;/a&gt;) identity lifecycle management will be more important. They will need to define more policies around how identities are managed and secured. IT professionals will need to map how identities will use different resources according to given policies and plan their authorization. For example policy will mandate new-hire needs to have an e-mail account. IT pro&amp;rsquo;s will need to plan which security groups the new-hire should be a part of and what e-mail alias will be used for him/her. Then the actual provisioning can be done through on premise identity management solutions such as Forefront Identity Manager or cloud services.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt 0.25in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Organizations will be keeping some of their services in house for various reasons and those areas will still be areas where IT professionals will be needed. These will be vary among the different industries but IT professionals will still be an important part of the organizations for the foreseeable future.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3362180" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Infrastructure+optimization+model/">Infrastructure optimization model</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/IT+pro+Skills/">IT pro Skills</category></item><item><title>Agile organizations and cloud computing</title><link>http://blogs.technet.com/b/erenturk/archive/2010/09/30/agile-organizations-and-cloud-computing.aspx</link><pubDate>Thu, 30 Sep 2010 15:11:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3358971</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3358971</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/09/30/agile-organizations-and-cloud-computing.aspx#comments</comments><description>&lt;p class="MsoNormal" style="text-align: justify; margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;21th century will mainly be about embracing change. Organizations will need to adapt to change in market conditions. The faster an organization can change its products or services and generate income based on those services; more it will be likely to survive. As a part of this requirement, companies will more and more depend on IT to provide agility to fuel business value.&amp;nbsp;IT&amp;nbsp;&amp;nbsp;departments will need to restructure themselves to increase their capabilities to provide more value from their assets. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-align: justify; margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;In order for IT to prove itself as a strategic asset, it would need to mature in operations.&amp;nbsp; Microsoft is using &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-gb/infrastructure/default.aspx"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Infrastructure optimization model&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt; to measure how mature an IT organization is in different areas according to different set of criteria. This model has 4 stages for different areas of operation:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-align: justify; text-indent: -18pt; margin: 0cm 0cm 0pt 38.25pt; mso-add-space: auto; mso-list: l1 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Basic:&lt;/b&gt; This is stage one where there is no standardization, no automation and no integration among different systems.&amp;nbsp; It organization is generally in reactive mode trying to put out fires, and there is no standard procedure or best practices available to solve common day to day problems. &amp;nbsp;For example there is no centralized Identity store&amp;nbsp;such as &amp;nbsp;Active Directory and users are using local users to logon to their laptops.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify; text-indent: -18pt; margin: 0cm 0cm 0pt 38.25pt; mso-add-space: auto; mso-list: l1 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Standard:&lt;/b&gt; This is stage two where there is standardization on different processes. IT is still in reactive mode but problems are categorized and best practices available for common problems. However, measuring quality of IT services is still nonexistent or depends on manual data collection methods. &amp;nbsp;For example all users are defined in Active Directory but there is no integration with an HR system.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify; text-indent: -18pt; margin: 0cm 0cm 0pt 38.25pt; mso-add-space: auto; mso-list: l1 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Rationalized:&lt;/b&gt; This is stage 3 where processes are highly automated and there is integration with different systems. For example there is automation between the HR system and AD. When new employees are provisioned in HR system a user is created in AD. Note that in order for this to work, there needs to be consensus about what needs to be done when a new employee is hired for the company. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-align: justify; text-indent: -18pt; margin: 0cm 0cm 10pt 38.25pt; mso-add-space: auto; mso-list: l1 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Dynamic:&lt;/b&gt; This is stage 4 where change in processes are also under control. This is the&amp;nbsp;stage where&amp;nbsp;IT is providing insight for the business and acts as a strategic asset for the organization. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-align: justify; margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Most of the organizations do not realize how hard it is to change until the need arises. As you would guess it would need quite a lot of effort to move along from one stage to the next&amp;nbsp;and the hardest part is not implementing the technology but it is to change perception in the organization on how things get done. Any person talking to HR on why they need define identity lifecycle will quickly understand that installing and configuring Forefront Identity Manager alone&amp;nbsp;will not solve the issue. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-align: justify; margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;When organizations start seeing the benefits of moving from one stage to another, it will be easier to embrace the change. However this does not mean that change will be easy. It will take time to plan, test and implement the required processes using suitable Technologies. The good news is, using cloud technologies can ease the burden. Unfortunately cloud can mean different things to different people. From operational perspective there are 2 types of clouds:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-align: justify; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo2;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Public Cloud:&lt;/b&gt; These are companies providing cloud services. Generally you pay for their services as you use them. You would be &lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;alleviated&lt;/span&gt; from the necessity to acquire, provision and maintain assets for the service in question. Depending on the service, you would have means to control the availability and performance and change them when necessary.&amp;nbsp;Most of the time&amp;nbsp;organizations would be sharing resources with other&amp;nbsp;organizations of the cloud fabric. You can also choose to have your resources dedicated for your own use.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-align: justify; text-indent: -18pt; margin: 0cm 0cm 10pt 36pt; mso-list: l0 level1 lfo2;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Private Cloud: &lt;/b&gt;This is the cloud where you build your own cloud services to provide to your own organization. This is more suitable for organizations with large number of IT assets and IT is mature to manage these efficiently. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-align: justify; margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Small companies will not have the necessary IT to build private clouds and will&amp;nbsp;partly move to public cloud infrastructure. There will be concerns around technical and non-technical issues,&amp;nbsp;most&amp;nbsp;being solved in the near future. We will see companies using mixed infrastructures and balance will&amp;nbsp;gravitate toward public cloud where possible.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-align: justify; margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Larger organizations will have more complex requirements and may choose to&amp;nbsp;host&amp;nbsp;some of their services in the public cloud.&amp;nbsp;However private cloud will&amp;nbsp;also be a viable option&amp;nbsp;that we will see materializing for these organizations.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;When talking to the customers about the cloud, building a private cloud seems as a natural evolution of IT. However this is a delicate situation if&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;IT is not mature according to Infrastructure optimization model. Implementing the technology even in massive scale will not help&amp;nbsp;the organization&amp;nbsp;build a successful private cloud. You need the right skills with enough people to operate the cloud. You need an accepted business model inside the company to sustain the service levels. You need a management willing to &lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;continuously &lt;/span&gt;improve &lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;efficiency&lt;/span&gt;, provide new services and retire old ones when necessary. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-align: justify; margin: 0cm 0cm 10pt;"&gt;&lt;span style="font-size: small; font-family: Calibri;"&gt;Clearly organizations will need to evolve in the 21th century. They will need to change the way they do business. Cloud can help you change your business by providing services that can adapt to your business needs. However it will not help you create better value out of your business. Organization will need to transform itself to&amp;nbsp;provide more&amp;nbsp;value&amp;nbsp;leveraging cloud as necessary.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3358971" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Infrastructure+optimization+model/">Infrastructure optimization model</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Agile+organization/">Agile organization</category></item><item><title>Kurumsal ortamlarda MSN Messenger, Skype gibi uygulamaları Microsoft teknolojileriyle nasıl engellersiniz?</title><link>http://blogs.technet.com/b/erenturk/archive/2010/08/15/kurumsal-ortamlarda-msn-messenger-skype-gibi-uygulamalar-microsoft-teknolojileriyle-nas-l-engellersiniz.aspx</link><pubDate>Sun, 15 Aug 2010 15:46:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3350114</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3350114</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/08/15/kurumsal-ortamlarda-msn-messenger-skype-gibi-uygulamalar-microsoft-teknolojileriyle-nas-l-engellersiniz.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Kurumsal ortamlarda verimli &amp;ccedil;alışma değerlendirildiğinde, Internet &amp;uuml;zerinden kullanılan haberleşme teknolojileri &amp;uuml;zerinde kontrol uygulanması g&amp;uuml;ndeme gelir. Bu işlem y&amp;ouml;netici g&amp;ouml;z&amp;uuml;yle bakıldığında &amp;ccedil;ok basit gibi g&amp;ouml;z&amp;uuml;kmekle beraber teknik olarak zor bir problemdir. Bunun temel sebebi bu t&amp;uuml;r uygulamalar, gelişen g&amp;uuml;venlik teknolojilerine uyum sağlayacak şekilde evrimleşmişlerdir. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;İnternet&amp;rsquo;ten haberleşme bundan yıllar &amp;ouml;nce popular olduğunda kullanıcılar g&amp;uuml;venlik duvarı kullanmadığından her uygulama kendine ait portlar kullanarak Internet&amp;rsquo;e &amp;ccedil;ıkacak şekilde yazılmaktaydı. Kurumsal ortamlarda g&amp;uuml;venlik duvarlarıyla Internet gezginleri i&amp;ccedil;in kullanılan portlar dışındakiler kapatıldığında sorun &amp;ccedil;&amp;ouml;z&amp;uuml;lebiliyordu.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;İkinci nesil uygulamalar Internet gezginleri i&amp;ccedil;in kullanılan HTTP protok&amp;uuml;n&amp;uuml; kullanmaya başladılar. Hatta kurumsal ortamlarda kullanılan web proxy ge&amp;ccedil;iş kapılarını da kullanabiliyorlardı. G&amp;uuml;venlik duvarlarında bu portlar kapatıldığında Internet erişimi durduğundan başka &amp;ccedil;&amp;ouml;z&amp;uuml;mlere ihtiya&amp;ccedil; vardı. Kullanılabilecek y&amp;ouml;ntemlerden biri bu uygulamaların bağlantı kurduğu sunucuları bulup onlara erişimi kapatmaktı. Ancak d&amp;uuml;nya &amp;uuml;zerinde bu t&amp;uuml;r hizmetleri veren servis sağlayıcılar y&amp;uuml;ksek erişilebilirlik sebebiyle pek &amp;ccedil;ok yerde sunucu bulundurmakta ve bunların IP&amp;rsquo;leri de sıklıkla değişmekteydi. Dolayısıyla bug&amp;uuml;n IP&amp;rsquo;leri belirleyip kapatsanız bile, yarın MSN Messenger yada benzer bir uygulama başka sunucuları deneyerek Internet&amp;rsquo;e &amp;ccedil;ıkabiliyordu. Bu sorunu aşmak i&amp;ccedil;in HTTP protokol&amp;uuml;n&amp;uuml;n i&amp;ccedil;ini de tarayan g&amp;uuml;venlik duvarları gerekliydi. Bu işleme uygulama seviyesinde filtreleme deniyor. G&amp;ouml;nderilen paketlerin Internet gezgini mi ya da haberleşme uygulamaları mı olduğunu g&amp;ouml;nderilen isteğin başlık kısmından &amp;ouml;ğrenmek ve isteği engellemek m&amp;uuml;mk&amp;uuml;n hale geldi. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Bazı haberleşme uygulamaları, g&amp;uuml;venlik duvarı kısıtlamalarından kurtulmak i&amp;ccedil;in haberleşmeleri kriptolu yapılan HTTPS (SSL) protokol&amp;uuml;ne kaydırdılar. Bu durumda uygulama seviyesindeki paketlerin i&amp;ccedil;eriği şifrelendiği i&amp;ccedil;in g&amp;uuml;venlik duvarları &amp;ccedil;aresiz kalmışlardı. Kurumsal ortamlar i&amp;ccedil;in &amp;ccedil;ok tehlikeli olan zararlı kodlar kendilerini bilgisayarlara aktarırken bu y&amp;ouml;ntemleri kullanmaya başladığından tehlike b&amp;uuml;y&amp;uuml;kt&amp;uuml;. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;Bunun &amp;ccedil;&amp;ouml;z&amp;uuml;m&amp;uuml; olarak HTTPS inspection y&amp;ouml;ntemi gelişti. Bu y&amp;ouml;ntemde kullanıcı SSL kullanan bir siteye bağlanmak istediğinde g&amp;uuml;venlik duvarı ona kendi sertifikasyla cevap verip, Internet&amp;rsquo;teki siteye kendisi bağlanıyor. B&amp;ouml;ylece g&amp;uuml;venlik duvarı i&amp;ccedil;inden ge&amp;ccedil;en trafiği izleyebiliyor. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Yukarıda değinilen b&amp;uuml;t&amp;uuml;n teknolojiler Microsoft Threat Management Gateway (TMG) 2010 &amp;uuml;r&amp;uuml;n&amp;uuml; ile sağlanabilir. Bu ama&amp;ccedil;la Internet &amp;ccedil;ıkışında sadece HTTP/HTTPS trafiğine izin verecek şekilde ayar yapılması gereklidir. Diğer protokollerle &amp;ccedil;ıkış zaten g&amp;uuml;venlik sebebiyle &amp;ouml;zel durumlar haricinde tercih edilmemelidir. Daha sonra HTTP Inspection &amp;ouml;zelliği devreye alınarak HTTP header&amp;rsquo;lardan User-Agent i&amp;ccedil;erisinde ilgili uygulamanın imzası aranarak (&amp;Ouml;rneğin MSN messenger vs) bu isteklerin durdurulması ayarlanmalıdır. Son olarak eğer gerek duyulursa kurumsal ortamlarda bulunan sertifika makamından TMG sunucusuna bir sertifika verilerek bu sertifikaya istemcilerin g&amp;uuml;venmesi sağlanır ve belirli trafikler i&amp;ccedil;in HTTPS inspection devreye alınabilir. Bu &amp;ouml;zellik kurumsal ihtiya&amp;ccedil;lara g&amp;ouml;re &amp;ccedil;ok esnek bir şekilde ayarlanabilir ve &amp;ouml;zellikle kullanıcı bilgisayarlarına zararlı kodlar indirilmesi Malware Inspection &amp;ouml;zelliği sayesinde engellenir. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;Ayrıca TMG i&amp;ccedil;erisinde kategori tabanlı filtreleme &amp;ouml;zelliği sayesinde bu t&amp;uuml;r uygulamaların bağlandığı sitelere gidiş de engellenebilir. Kategori bilgileri s&amp;uuml;rekli g&amp;uuml;ncellendiğinden yukarıda değinilen g&amp;uuml;ncel tutma zorunluluğuna da gerek kalmaz. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;G&amp;uuml;n&amp;uuml;m&amp;uuml;zde kurumsal şirketlerin Internet&amp;rsquo;ten gelebilecek tehlikelere karşı kendilerini korumaları zorlaşmaktadır. Bu durumda Microsoft Threat Gateway &amp;uuml;r&amp;uuml;n&amp;uuml; kurumsal ortamların kapsamlı ihtiya&amp;ccedil;larına cevap verecek, esnek ve y&amp;uuml;ksek g&amp;uuml;venlikli &amp;ccedil;&amp;ouml;z&amp;uuml;mler &amp;uuml;retmek m&amp;uuml;mk&amp;uuml;nd&amp;uuml;r.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3350114" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Category+based+filtering/">Category based filtering</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/MSN+Messenger/">MSN Messenger</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/HTTP+Inspection/">HTTP Inspection</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Skype/">Skype</category></item><item><title>Microsoft Web TV Çözümleri (3. Kısım)</title><link>http://blogs.technet.com/b/erenturk/archive/2010/08/02/microsoft-web-tv-199-246-z-252-mleri-3-k-s-m.aspx</link><pubDate>Mon, 02 Aug 2010 05:40:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3347923</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3347923</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/08/02/microsoft-web-tv-199-246-z-252-mleri-3-k-s-m.aspx#comments</comments><description>&lt;h2 style="margin: 10pt 0in 0pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: medium;"&gt;&lt;span style="color: #17365d;"&gt;&lt;span style="font-family: Calibri;"&gt;IIS Medya servisleri &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Windows Server 2008 ve Silverlight ile tamamen web tabanlı yeni bir Web Tv &amp;ccedil;&amp;ouml;z&amp;uuml;m&amp;uuml; doğdu. &amp;Ccedil;&amp;ouml;z&amp;uuml;m tamamen IIS tabanlı olduğundan IIS Medya servisleri adını aldı. Yayın yapılan teknoloji de Smooth Streaming olarak adlandırıldı. Bu teknoloji silverlight istemcisinin http i&amp;ccedil;erisinden gelecek yayın a&amp;ccedil;ıklamasını alarak hangi &amp;ccedil;&amp;ouml;z&amp;uuml;n&amp;uuml;r&amp;uuml;kte yayınlar olduğunu anlamasıyla başlar. İstemci, sonrasında kendisine uygun bulduğu bant genişliğiyle ilk 2 saniyelik i&amp;ccedil;eriği indirir ve g&amp;ouml;stermeye başlar. Bu arada isteğin geliş hızı, &amp;uuml;st&amp;uuml;nde &amp;ccedil;alıştığı bilgisayarın CPU kullanımı gibi parametreleri değerlendirerek bir sonraki paketin ne kadar bant genişliği kullanması gerektiğine karar verir ve ger&amp;ccedil;ek zamanlı olarak yayının kalitesini kullanıcıya en uygun deneyimi yaşatacak şekilde ayarlar. Buna adaptif yayın teknolojisi denir. Ağ &amp;uuml;zerinden bakıldığında istemci web sayfasına erişiyormuş gibi g&amp;ouml;z&amp;uuml;k&amp;uuml;r. Oysa Silverlight aray&amp;uuml;z&amp;uuml; &amp;uuml;zerinden gelişmiş &amp;ouml;zelliklerle yayın izlemek m&amp;uuml;mk&amp;uuml;nd&amp;uuml;r. Bu &amp;ouml;zelliklerin başında yayın akışını kontrol yer alır. Sunucu &amp;uuml;zerinde ayarlandığı durumda istemci ger&amp;ccedil;ek zamanlı yayından kopup daha &amp;ouml;nceki zamana ait bir noktadan yayını almaya devam edebilir. Bu işlem sadece 2 saniyelik yayın paketi gerektirdiğinden Windows Media Services tarafında g&amp;ouml;r&amp;uuml;len yayın duraksamaları g&amp;ouml;r&amp;uuml;lmez. İstemci istediğinde ger&amp;ccedil;ek zamanlı yayının olduğu noktaya d&amp;ouml;nebilir. Bunun yanında yayını hızlı ya da yavaş izleme &amp;ouml;zelliği sunucunun aktaracağı i&amp;ccedil;eriğin i&amp;ccedil;inden anahtar kareleri &amp;ccedil;ekerek g&amp;ouml;ndermesiyle sağlanır. Ayrıca istenen her g&amp;ouml;r&amp;uuml;nt&amp;uuml; paketinin yanında ses paketi de istendiğinden IIS medya servisleriyle birden fazla sesi izlemek m&amp;uuml;mk&amp;uuml;nd&amp;uuml;r ve aynı şekilde birden fazla altyazı da kullanılabilir.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Genellikle http i&amp;ccedil;eriği http proxy sunucularından oluşan CDN (Content Delivery Network) &amp;uuml;zerinden m&amp;uuml;şterilere sunulur. B&amp;ouml;ylece i&amp;ccedil;erik sağlayıcı kendisine gelen yoğun istek taleplerini CDN &amp;uuml;zerindeki http proxy sunucularından ge&amp;ccedil;irerek kendisine gelmeden karşılanmasını sağlar. Microsoft&amp;rsquo;un CDN oluşturmak i&amp;ccedil;in yine IIS&amp;rsquo;in bir par&amp;ccedil;ası olan &lt;/span&gt;&lt;a href="http://learn.iis.net/page.aspx/570/application-request-routing-version-2-overview/"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;ARR (Advanced Request Routing)&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt; &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;teknolojisi kullanılabilir. Bu alt bileşen ile gelen istekler belirli kurallar &amp;ccedil;er&amp;ccedil;evesinde &amp;ouml;n belleklenebilir ve y&amp;ouml;nlendirilebilir. Y&amp;ouml;nlendirme işlemi i&amp;ccedil;in arka plandaki sunuculara sağlık kontrol&amp;uuml; ya da y&amp;uuml;k dengeleme yapılabilir. Bu sistem &amp;uuml;zerinden hem ger&amp;ccedil;ek zamanlı yayın yapılabildiği gibi hem de &amp;ouml;nceden kaydedilmiş i&amp;ccedil;eriğin aktarılması m&amp;uuml;mk&amp;uuml;nd&amp;uuml;r. Bu y&amp;ouml;n&amp;uuml;yle her iki ihtiyaca da cevap veriyor olması yatırım maliyetini d&amp;uuml;ş&amp;uuml;r&amp;uuml;r. Sistem y&amp;ouml;netimi Microsoft&amp;rsquo;un sağladığı platform &amp;ouml;zellikleriyle (&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/windows/dd320288.aspx"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Powershell&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;, Event forwarding) sağlanabildiği gibi daha gelişmiş ihtiya&amp;ccedil;lar i&amp;ccedil;in &lt;/span&gt;&lt;a href="http://www.microsoft.com/systemcenter/en/us/operations-manager.aspx"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;System Center Operations Manager&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; kullanılabilir.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-no-proof: yes;"&gt;&lt;v:shapetype coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f" id="_x0000_t75"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt;&lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;/span&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&lt;img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-83-79/6406.IISMedia.jpg" border="0" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Yayının ya da i&amp;ccedil;eriğin kriptolanması i&amp;ccedil;in WinDRM&amp;rsquo;in gelişmiş hali olan &lt;/span&gt;&lt;a href="http://www.microsoft.com/PlayReady/Overview.mspx"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Playready DRM&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; kullanılır. Bu sayede hem daha &amp;uuml;st d&amp;uuml;zey kriptolojik fonkisyonlar kullanılır hem de daha esnek i&amp;ccedil;erik koruma politikaları belirlenebilir. Silverlight istemci yayını ilk indirmeye başladığında Playready DRM&amp;rsquo;i algılayarak DRM sertifika sunucusuna bağlanır, gerekli yayın hakları ve sertifikayı indirerek yayını &amp;ccedil;&amp;ouml;zer. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;IIS medya servislerinin sağladığı zengin yayınlama formatı Smooth Streaming daha &amp;ouml;nceki s&amp;uuml;r&amp;uuml;mlerden farklıdır. İ&amp;ccedil;erik olarak daha &amp;ouml;ncekilerden farklı olarak hem VC-1 hem de H.264 kullanılabilir. Ancak yayının kullanıcılara eriştirilebilmesi i&amp;ccedil;in Smooth Streaming yayın formatına &amp;ccedil;evrilmesi gereklidir. Diğer formatlardaki i&amp;ccedil;eriğin gerekli yayın ya da i&amp;ccedil;erik formatına &amp;ccedil;evirilmesi i&amp;ccedil;in &lt;/span&gt;&lt;a href="http://www.microsoft.com/expression/products/EncoderPro_Overview.aspx"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Microsoft Expression Encoder&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; &amp;uuml;r&amp;uuml;n&amp;uuml; kullanılabilir. Bu &amp;uuml;r&amp;uuml;n ile hem VC-1 i&amp;ccedil;erik hem de H.264 i&amp;ccedil;eriği kodlanabilir. Ger&amp;ccedil;ek Zamanlı i&amp;ccedil;erik i&amp;ccedil;in bu &amp;uuml;r&amp;uuml;n&amp;uuml;n yanında donanım tabanlı encoder cihazları da kullanılabilir. Bu cihazlar uzun s&amp;uuml;reli yayın yapılacağı zaman sağladıkları y&amp;uuml;ksek erişilebilirlik &amp;ouml;zellikleriyle &amp;ouml;ne &amp;ccedil;ıkarlar. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;IIS medya servisleri Windows s&amp;uuml;r&amp;uuml;mlerinden bağımsız olarak geliştirilmeye devam etmektedir. &amp;Ccedil;ıkacak yeni s&amp;uuml;r&amp;uuml;m&amp;uuml;yle beraber mobil cihazlara da aynı platform &amp;uuml;zerinden yayın sunabilmenin yanı sıra, 3 boyutlu yayınlar ve IP TV altyapısı gibi pek &amp;ccedil;ok yeniliği de beraberinde getirecektir. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;IIS medya servisleri, Windows Server 2008 ve R2 &amp;uuml;st&amp;uuml;ne y&amp;uuml;klenebilen opsiyonel par&amp;ccedil;alar olup Internet&amp;rsquo;ten download edilebilir. Yeni bir teknoloji olmasına rağmen Smooth Streaming hem kalite hem getirdiği kolaylıklar a&amp;ccedil;ısından &amp;ccedil;ok &amp;ouml;nemli yenilikler getirmektedir ve geleceğin yayın standartları arasında şimdiden yerini almıştır.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3347923" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/IIS+Media+Services/">IIS Media Services</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Advanced+Request+Routing/">Advanced Request Routing</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Expression+Encoder/">Expression Encoder</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Powershell/">Powershell</category></item><item><title>Microsoft Web TV Çözümleri (2. Kısım)</title><link>http://blogs.technet.com/b/erenturk/archive/2010/07/14/microsoft-web-tv-199-246-z-252-mleri-2-k-s-m.aspx</link><pubDate>Wed, 14 Jul 2010 14:41:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3344173</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3344173</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/07/14/microsoft-web-tv-199-246-z-252-mleri-2-k-s-m.aspx#comments</comments><description>&lt;h2 style="margin: 10pt 0in 0pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: medium;"&gt;&lt;span style="color: #17365d;"&gt;&lt;span style="font-family: Calibri;"&gt;Yayınlama hakkında genel bilgiler&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Yayının &amp;ccedil;evrilmesi yayın kalitesinin belirlenmesinde anahtar rol&amp;uuml; oynar. Bazı i&amp;ccedil;erikler orjinal formatında g&amp;uuml;zel g&amp;ouml;r&amp;uuml;n&amp;uuml;rken, uygun filtreler kullanılmadan &amp;ccedil;evirim yapılırsa yeni formatında &amp;ccedil;ok k&amp;ouml;t&amp;uuml; sonu&amp;ccedil;lar verebilir. Yayının orjinal kalitesi &amp;ccedil;evirim sırasında arttırılamaz. Bu y&amp;uuml;zden genellikle 2000 yılından daha &amp;ouml;nce &amp;uuml;retilmiş olan (Dijital kamera ile &amp;ccedil;ekim yapılmamış i&amp;ccedil;erikler) i&amp;ccedil;erikler dijital formata aktarıldığında yeni i&amp;ccedil;erikler kadar g&amp;uuml;zel g&amp;ouml;z&amp;uuml;kmezler. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Yayının donmadan izlenebilmesi i&amp;ccedil;in yerine getirilmesi gereken pek &amp;ccedil;ok şart vardır. Hem sunucu ile istemci arasındaki bant genişliğinin yeterli olması, hem sunucuya erişen isteklerin belirli bir sayının altında olması hem de istemcinin indirilen i&amp;ccedil;eriği ger&amp;ccedil;ek zamanda decode/decrpt ederek ekranda g&amp;ouml;sterecek işlemci g&amp;uuml;c&amp;uuml;ne sahip olması gereklidir. &amp;Ouml;rneğin High Definition yayınlar, eski istemcilerde g&amp;ouml;sterilemeyecek kadar &amp;ccedil;ok işlemci g&amp;uuml;c&amp;uuml; gerektirirler.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Yayının geniş kitlelere erişmesi i&amp;ccedil;in yayının &amp;ccedil;oklanması gereklidir. Yayının yapıldığı sunucu &amp;ouml;beğine orijin sunucuları denir. Yayın orijin sunuculardan &amp;ccedil;oklayıcı sunuculara aktarılır. &amp;Ccedil;oklayıcı sunucularda istenildiği kadar &amp;ccedil;oğaltılarak son kullanıcıya ulaştırılır. &amp;Ouml;zellikle ger&amp;ccedil;ek zamanlı yayınlarda &amp;ccedil;oklayıcılardan sık&amp;ccedil;a yararlanılır. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2 style="margin: 10pt 0in 0pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: medium;"&gt;&lt;span style="color: #17365d;"&gt;&lt;span style="font-family: Calibri;"&gt;Windows Media Servisleri (WMS) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Microsoft tarafından piyasaya &amp;ccedil;ıkan ilk &amp;uuml;r&amp;uuml;n Windows Media Services oldu. Bu &amp;ccedil;&amp;ouml;z&amp;uuml;m 2000&amp;rsquo;li yılların başında &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/windows/windowsmedia/musicandvideo/hdvideo/hdvideo.aspx"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;High Definition (HD)&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; yayın teknolojisinin yaygınlaşmasına &amp;ouml;nc&amp;uuml;l&amp;uuml;k etmiştir. Bu teknoloji Microsoft&amp;rsquo;un geliştirdiği yayın depolama formatı olan Windows Media (WMV, WMA,ASF ya da ent&amp;uuml;stri standardı ismiyle VC-1) kullanır. İstemci tarafında Windows&amp;rsquo;la beraber gelen Windows Media Player i&amp;ccedil;inde bu depolama formatını algıladığından, kullanıcı Web sitesine gidip yayın&amp;rsquo;a tıkladığında yayın WMS sunucusu tarafından istemciye g&amp;ouml;nderilmeye başlanır, istemcide Windows Media Player tarafından işlenerek kullanıcıya g&amp;ouml;sterilir. Yayın başlamadan &amp;ouml;nce sunucu istemci ile arasında Internet&amp;rsquo;te ne kadar bant genişliği kullanılabileceği test edilir ve eğer yayın&amp;rsquo;ın birden fazla bant genişliği s&amp;uuml;r&amp;uuml;m&amp;uuml; varsa uygun olan se&amp;ccedil;ilerek istemciye g&amp;ouml;nderilmeye başlar. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Bu teknolojinin en b&amp;uuml;y&amp;uuml;k avantajı Windows&amp;rsquo;la beraber gelmesi ve ayrı bir yazılım kurulumu gerektirmeden kullanıcıya erişmesidir. Bununla beraber bu teknoloji yayın yapabilmek i&amp;ccedil;in &lt;/span&gt;&lt;/span&gt;&lt;a href="http://download.microsoft.com/download/9/5/E/95EF66AF-9026-4BB0-A41D-A4F81802D92C/%5bMS-RTSP%5d.pdf"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;RTSP&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; (UDP/TCP 554) protokol&amp;uuml;n&amp;uuml; kullanır. Bu protokol g&amp;uuml;n&amp;uuml;m&amp;uuml;z web protokolleri (HTTP) ile uyumsuz olduğundan firewall tarafından ge&amp;ccedil;irilmez. Bu y&amp;uuml;zden HTTP protokol&amp;uuml; &amp;uuml;zerinden ge&amp;ccedil;en bir s&amp;uuml;r&amp;uuml;m&amp;uuml; de yapılmıştır. Yayının http paketleri i&amp;ccedil;erisinden senkronizasyona bağlı olarak ge&amp;ccedil;mesi gerektiğinden yayının geliş hızına bağlı olarak duraksamalar g&amp;ouml;r&amp;uuml;lebilir.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Yayınların VC-1 formatıne &amp;ccedil;evrilme işlemi &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=5691ba02-e496-465a-bba9-b2f1182cdf24"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Windows Media Encoder&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; ile yapılabilabilir. Bu &amp;ccedil;evirme işlemi ger&amp;ccedil;ek zamanlı yapılabileceği gibi başka formattaki bir i&amp;ccedil;eriğin Windows Media formatına aktarılması ile de yapılabilir. İstenirse yayın DRM i&amp;ccedil;eriğe d&amp;ouml;n&amp;uuml;şt&amp;uuml;r&amp;uuml;lebilir. Bu ama&amp;ccedil;la WinDRM teknolojisi kullanılabilir. İ&amp;ccedil;erik kriptolandıktan sonra yayın sisteminden ge&amp;ccedil;irilmesi i&amp;ccedil;in ayrıca bir işlem yapılmasına gerek kalmaz. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Ger&amp;ccedil;ek zamanlı yayının kullanıcılara iletilmesi i&amp;ccedil;in &amp;ccedil;oklayıcı teknolojilere ihtiya&amp;ccedil; duyulur. &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/windows/windowsmedia/howto/articles/cache_proxy.aspx"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Windows Media Proxy Servisleri&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; kullanılabilir. B&amp;ouml;ylece hem origin sunucuları aynı anda gelen yayın isteklerini karşılamak zorunda kalmaz, hem de i&amp;ccedil;erik proxy sunucularda &amp;ouml;nbelleklendiğinden bu sunuculara gelinmesine gerek kalmaz. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Windows Media Servisleri halen Windows Server 2008/R2 işletim sistemi i&amp;ccedil;inde opsiyonel bir par&amp;ccedil;a olarak bulunmakta ve istendiğinde devreye alınarak kullanıma hazır hale getirilebilmektedir. End&amp;uuml;stride &amp;ccedil;ok kabul g&amp;ouml;rm&amp;uuml;ş ve kendini ispatlamış bir teknoloji olduğundan halen Web &amp;uuml;zerinde pek &amp;ccedil;ok sitedeki i&amp;ccedil;erik bu formatı kullanır. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3344173" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Windows+Media+Services/">Windows Media Services</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Media+Encoder/">Media Encoder</category></item><item><title>Microsoft Web TV Çözümleri (1. Kısım)</title><link>http://blogs.technet.com/b/erenturk/archive/2010/06/12/microsoft-web-tv-199-246-z-252-mleri-1-k-s-m.aspx</link><pubDate>Sat, 12 Jun 2010 20:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3337813</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3337813</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/06/12/microsoft-web-tv-199-246-z-252-mleri-1-k-s-m.aspx#comments</comments><description>&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Internet ilk pop&amp;uuml;ler olduğunda Internet&amp;rsquo;e bağlantı hızları yavaş olduğu i&amp;ccedil;in i&amp;ccedil;inde bolca yazının olduğu, tek t&amp;uuml;k resimlerin olduğu sayfalar vardı. Sonra bant genişliği arttık&amp;ccedil;a &amp;ouml;nce resimler arttı ve daha hareketli bir ortam oluştu. G&amp;uuml;n&amp;uuml;m&amp;uuml;zde artık bant genişlikleri Internet &amp;uuml;zerinden televizyon yayınlarının izlenmesine olanak verecek hale geldi. G&amp;ouml;rsel olarak televizyonda g&amp;ouml;rmeye alıştığımız zengin i&amp;ccedil;eriğin Internet ortamından benzer bir kalitede sunulması yeni teknolojilerin geliştirilmesini zorunlu kıldı. &amp;Ouml;n&amp;uuml;m&amp;uuml;zdeki birka&amp;ccedil; yıl i&amp;ccedil;inde Internet &amp;uuml;zerindeki b&amp;uuml;t&amp;uuml;n i&amp;ccedil;eriğin b&amp;uuml;y&amp;uuml;kl&amp;uuml;k olarak yaklaşık %80&amp;rsquo;inin g&amp;ouml;rsel yayın i&amp;ccedil;eriği olması beklenmektedir. Bu yazıda Microsoft tarafından geliştirilen yayın teknolojilerinden bahsetmek istiyorum.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2 style="margin: 10pt 0in 0pt;"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: medium;"&gt;&lt;span style="color: #17365d;"&gt;&lt;span style="font-family: Calibri;"&gt;Yayınlama teknolojileri s&amp;ouml;zl&amp;uuml;ğ&amp;uuml;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Yayınlama teknolojilerinden bahsetmeden &amp;ouml;nce bu end&amp;uuml;stride kullanılan terimlerden bahsetmek yerinde olur. Bir televizyon yayınını Internet &amp;uuml;zerinden yayınlayabilmek i&amp;ccedil;in &amp;ouml;ncelikle bir yayın formatına ihtiya&amp;ccedil; duyulur. Yayın formatı yayının ne kadar &amp;ccedil;&amp;ouml;z&amp;uuml;n&amp;uuml;rl&amp;uuml;kte ve hangi formattaki paketler halinde istemciye aktarılacağını ifade eder. &amp;Ouml;rnek yayın formatları arasında VC-1 ve H.264 sayılabilir. Bunun dışında yayının i&amp;ccedil;eriğinin ekranda g&amp;ouml;r&amp;uuml;nt&amp;uuml;lenmesi i&amp;ccedil;in de codec formatı &amp;ouml;nemlidir. Codec formatı i&amp;ccedil;eriğin dosya i&amp;ccedil;inde nasıl sıralandığını ve hangi sıkıştırma formatı ile hangi sırada a&amp;ccedil;ılacağını ifade eder. &amp;Ouml;rnek codec formatları arasında WMV, Mpg 2 ve Mpg 4 sayılabilir. Yayın sıkıştırılmış bir şekilde sunucudan istemciye aktarılır ve burada uygun codec tarafından g&amp;ouml;sterime hazır hale (decode işlemi) getirilerek ekranda g&amp;ouml;sterilir.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Bazı durumlarda yayınların orjinal kaynaktan alındıktan sonra kaydedilmesi, gerekiyorsa formatının değiştirilmesi ve istendiğinde g&amp;ouml;nderilmesi gereklidir. Bu durumda g&amp;ouml;sterimi yapılan yayına Video On Demand (İstendiğinde Video) denir. Bazı durumlarda yayının kaynaktan alınırken ger&amp;ccedil;ek zamanlı olarak formatının &amp;ccedil;evrilmesi ve hi&amp;ccedil; diske yazılmadan yayınlanması gerekir. Buna real time ya da Live Broadcasting (Canlı yayın) denir.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Yayınların belirli haklarla korunmasına Digital Rights Management (DRM) adı verilir. Bu işlem temelde dosyanın simetrik bir anahtarla kriptolanmasını, daha sonra bu anahtarın asimetrik ama &amp;ccedil;ok daha g&amp;uuml;cl&amp;uuml; bir kriptolama ile saklanması esasına dayanır. Bu ikinci kriptoyu a&amp;ccedil;mak i&amp;ccedil;in yayın ya da dosya başlangıcında yayının ya da dosyanın indirildiği yere erişilerek yetki kontrol&amp;uuml; yapılır ve ilgili anahtar indirilir. Kullanılan DRM teknolojisine ve yetkilendirmeye g&amp;ouml;re yetkiler değişiklik g&amp;ouml;sterebilir. Kripto konusunda gerekli ayarlamalar yapıldıktan sonra istemci uygulaması yayının kriptosunu a&amp;ccedil;arak (decrypt işlemi) ekranda g&amp;ouml;sterir.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Bir sonraki kısımda yayınlama hakkında genel bilgiler ve Windows Media services hakkında bilgiler vereceğim.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="TR" style="mso-ansi-language: TR;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3337813" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/erenturk/archive/tags/DRM/">DRM</category><category domain="http://blogs.technet.com/b/erenturk/archive/tags/Windows+Media+Services/">Windows Media Services</category></item><item><title>Merhaba</title><link>http://blogs.technet.com/b/erenturk/archive/2010/06/11/merhaba.aspx</link><pubDate>Fri, 11 Jun 2010 05:00:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3337529</guid><dc:creator>Murat Cudi Erentürk</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/erenturk/rsscomments.aspx?WeblogPostID=3337529</wfw:commentRss><comments>http://blogs.technet.com/b/erenturk/archive/2010/06/11/merhaba.aspx#comments</comments><description>&lt;p&gt;Microsoft T&amp;uuml;rkiye'de Altyapı mimarı olarak &amp;ccedil;alışıyorum. Hem &amp;uuml;r&amp;uuml;nler ve yeni teknolojilerle ilgili bilgileri, hem de işinizi kolaylaştıracak ipu&amp;ccedil;larını &amp;ouml;n&amp;uuml;m&amp;uuml;zdeki g&amp;uuml;nlerde buradan sizlerle paylaşmayı &amp;uuml;mit ediyorum. Yakın zamanda tekrar g&amp;ouml;r&amp;uuml;şmek &amp;uuml;zere.&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3337529" width="1" height="1"&gt;</description></item></channel></rss>