<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Brad&#039;s Tech Blog &#187; netsh</title>
	<atom:link href="http://bradstechblog.com/category/netsh/feed" rel="self" type="application/rss+xml" />
	<link>http://bradstechblog.com</link>
	<description>Microsoft technologies like: System Center Operations Manager, and whatever else comes up at the office.</description>
	<lastBuildDate>Sat, 13 Feb 2010 01:59:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Deploying SCOM Gateway server</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server</link>
		<comments>http://bradstechblog.com/scom/deploying-scom-gateway-server#comments</comments>
		<pubDate>Wed, 12 Nov 2008 21:17:23 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[netsh]]></category>
		<category><![CDATA[SCOM; Gateway]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=246</guid>
		<description><![CDATA[
Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server
Certificates need to be deployed (2 types of certificates)
The root CA needs to be installed on all management servers
A custom cert template needs to be created on the issuing CA for OpsMGR
The Custom [...]]]></description>
			<content:encoded><![CDATA[<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server</li>
<li class="MsoNormal">Certificates need to be deployed (2 types of certificates)</li>
<li class="MsoNormal">The root CA needs to be installed on all management servers</li>
<li class="MsoNormal">A custom cert template needs to be created on the issuing CA for OpsMGR</li>
<li class="MsoNormal">The Custom OpsMgr cert needs to be installed on all management servers</li>
<li class="MsoNormal">Run the momcertimport on all management server after the certs have been installed. This makes some specific registry changes for scom to help pick the correct cert.</li>
<li class="MsoNormal">Approve gateway server on RMS using a approval tool.</li>
<li class="MsoNormal">Manual install of agents on servers to be monitored</li>
<li class="MsoNormal">Approve agents in SCOM console</li>
</ol>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Download the PDF <a href="http://bradstechblog.com/wp-content/uploads/2008/11/deploying-scom-gateway-server2.pdf">deploying-scom-gateway-server2</a></p>
<p class="MsoNormal"> </p>
<p><!--martad--></p>
<p class="MsoNormal"><span id="more-246"></span></p>
<p class="MsoNormal"> </p>
<h3><a name="_Open_and_test"></a>Open and test ports</h3>
<p class="MsoNormal">Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">To test if the ports are open. Log on to gateway server. From a command prompt type</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><strong>telnet SRVNAME261 5723</strong></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">If you get a cursor at the top left corner then the port is open. Any other errors indicate that the port is still closed.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Do the same from the management server back to the gateway server.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><a name="_Import_a_trusted"></a></p>
<p class="MsoNormal"> </p>
<h3><a name="_Certificates_need_to"></a>Certificates need to be deployed (2 types of certificates)</h3>
<p class="MsoNormal"> </p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Root_certificate"></a><!--if !supportLists--><span><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Root certificate</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the root certificate for the management servers on the same domain as the CA server</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Logon on the management server. Open a web Brower and navigate to <span style="color: #000000; text-decoration: none;">http://SRVNAME342/certsrv/</span></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Download a CA certificate, certificate chain, or CRL</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Download CA Certificate chain</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on save. And save to a location of your choice. The default file name is certnew.p7b. This is fine. (you can use this cert for all your management servers and gateway server to skip the initial download on this servers if you like.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->To import the downloaded cert open the certificate MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on “Trusted Root Certification Authorities”</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->When the wizard opens navigate to the downloaded cert is certnew.p7b . You will need to change the file type to PKCS #7</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Accept the defaults and finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Do this on all management servers inside the domain</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the root certificate for the Gateway server that is not attached to the domain as the CA server.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Perform step one above to save certnew.p7b. Or use the same cert that was downloaded above. And copy to the gateway server. Then perform step 2 above.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Create_the_Custom"></a><!--if !supportLists--><span><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Create the Custom OpsMgr Certificate</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->To create the cert. We will use two consoles to do this. Certification Authority mmc and certificate templates mmc</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificate Templates and Certification Authority, and click on add again. And finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select Certificate Templates</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->In the Certificate Templates Console right click <strong>IPSec (Offline request)</strong> and then select <strong>duplicate template</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->General Tab</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Type a name</p>
<p class="MsoNormal" style="margin-left: 99pt;">Request Handling</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select <strong>Allow private key to be exported</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>CSPs…</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select Microsoft RSA SChannel Cryptographic provider for windows 2003 and Microsoft Enhanced Cryptographic provider 1.0 for windows 2000</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Extensions Tab</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select the Applications Policies and click on edit</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->remove <strong>IP security IKE intermediate</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on add..</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>Client Authentication and Server Authentication</strong>, and clink on ok twice.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Security Tab</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Users should have read</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Say ok and close.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Add_the_new"></a><!--if !supportLists--><span><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Add the new custom cert to the certificate authority</h3>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open the Certification Authority mmc console</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand it and right click on certificate templates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select new, certificate template to issue</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Scroll through the list until you find the one you just created. Select it and say ok.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->It should now show in the right window.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Deploy_the_Custom"></a><!--if !supportLists--><span><span>4.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Deploy the Custom OpsMgr Certificate to the management servers on the same domain as the CA (need to do the full steps individually for each server)</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Logon on the management server. Open a web Brower and navigate to http://SRVNAME342/certsrv/</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Request a certificate</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Create and submit a request to this CA</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select the custom Template</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>e.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter a name for the template. This is the full unc name of the server that you are going to install the cert on.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>f.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter the rest of the identity info if you like.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>g.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Under Key options select the csp that fits your operating system. select Microsoft RSA SChannel Cryptographic provider for windows 2003 and Microsoft Enhanced Cryptographic provider 1.0 for windows 2000</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>h.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Key size 1024</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Mark keys as exportable</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>j.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Check off <strong>Store cert in local computer cert store…</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>k.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Use full unc path as friendly name.</p>
<p class="MsoNormal" style="margin-left: 0.75in;"> </p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>l.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on submit, say yes.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>m.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Install this certificate</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>n.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>o.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>p.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>q.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>r.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>s.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>t.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You should see the new cert here.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"> </p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"> </p>
<p><!--martad--></p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><!--if !supportLists--><span><span>5.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Deploy the custom Certificate to the Gateway sever in the DMZ.</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Because the gateway is not part of the same domain as the CA. We need to create the certificate on a different server and export it to a usb drive or other storage device. Then manually copy it to the gateway server and import it.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->First create the cert from a server on the same domain as the CA. <a href="#_Deploy_the_Custom">Follow the steps in step 4 first</a>.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Next we will export the cert</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You should see the new cert here.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Right click on the cert and select <strong>All tasks, export</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->The export wizard will open, say next</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>x.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>Yes, export private key</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>enable strong protection</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter a password for the import. You will need this password when you export the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xiii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Specify a location and name to save it too.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xiv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->And finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy the cert to the gateway server. It will have a .pfx extension.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>All tasks, Import</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Browse to the cert you coppied over. You will need to change the file type to PFX to see the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>x.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>open, say next, enter password. </strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Check off <strong>Mark this key as exportable. </strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Say next, make sure the certificate store is <strong>personal</strong> , click next and finish.</p>
<p class="MsoNormal" style="margin-left: 99pt;"> </p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Run_the_momcertimport"></a><!--if !supportLists--><span><span>6.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Run the momcertimport utility</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->In this step we are going to use the same pfx certificate (the custom personal cert) that we created in step 4.<span> </span>This tool writes the certificate serial number to the registry. This will help OpsMgr components find the the proper certificate for authenticatin easily.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You will find the momcertimport utility on the install cd under supporttools\i386.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy momcertimport.exe and the pfs certificate into the same folder.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open a command prompt, navigate to the folder with both files and type the following command</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->C:\&gt;MOMCertImport.exe certfilename.pfx</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->There is NO response after the command is successfully initiated.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>e.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->So this on all SCOM management servers. RMS, MS, and Gateway</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Approve_the_Gateway"></a><!--if !supportLists--><span><span>7.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Approve the Gateway Server</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->We will use the gateway approval tool to achieve this. This will setup the gateway server as a management server in SCOM. Once done you can confirm this by looking in the SCOM console under administration, Device Management, Management Servers.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->The tool has to be run from c:\program Files\System Center Operations Manager 2007</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy Microsoft.EnterpriseManagement.GatewayApprovalTool.exe from the support tools directory to c:\program Files\System Center Operations Manager 2007</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open the command prompt and type the following command</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->microsoft.enterprisemanagement.gatewayapprovaltool.exe /managementservername=SRVNAME261.domainName.com /gatewayname=domainNamedmz22.domainNamedmz.com /action=create</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Next_you_now"></a><!--if !supportLists--><span><span>8.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Next you now ready to manually install the agents on the servers in the DMZ</h3>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Approve_the_agents"></a><!--if !supportLists--><span><span>9.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Approve the agents in the SCOM console.</h3>
<p class="MsoNormal"> </p>
<p class="MsoNormal" style="margin-left: 0.25in;"> </p>
<div class="MsoNormal" style="margin-left: 0.25in  mce_tmp="> &lt;&#8211;&gt;</div>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/deploying-scom-gateway-server/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Manage multiple DHCP scopes with netsh script</title>
		<link>http://bradstechblog.com/netsh/manage-multiple-dhcp-scopes-with-netsh-script</link>
		<comments>http://bradstechblog.com/netsh/manage-multiple-dhcp-scopes-with-netsh-script#comments</comments>
		<pubDate>Tue, 05 Aug 2008 13:40:38 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[DHCP]]></category>
		<category><![CDATA[Microsoft windows server]]></category>
		<category><![CDATA[netsh]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Scopes]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=64</guid>
		<description><![CDATA[Use a script to change the DNS lookups and Wins lookups options in DHCP on muliple scripts. Using the netsh command this can be done eaisly.
Tools needed&#8230;



Some knowledge of the netsh command
A text file with the ip address&#8217;s of the scopes to be modified
IP address&#8217;s of the DHCP servers to change
And a script of course.

The easiest [...]]]></description>
			<content:encoded><![CDATA[<p>Use a script to change the DNS lookups and Wins lookups options in DHCP on muliple scripts. Using the netsh command this can be done eaisly.</p>
<p>Tools needed&#8230;</p>
<p><!-smartads-></p>
<p><span id="more-64"></span></p>
<ol>
<li>Some knowledge of the netsh command</li>
<li>A text file with the ip address&#8217;s of the scopes to be modified</li>
<li>IP address&#8217;s of the DHCP servers to change</li>
<li>And a script of course.</li>
</ol>
<p>The easiest way to obtain the ip address&#8217;s of the scopes to modify is to log onto the DHCP server itself and open your support tools command prompt</p>
<p><strong><span style="text-decoration: underline;">Step 1.</span></strong></p>
<p>Go to <a title="netsh command line" href="http://technet2.microsoft.com/windowsserver/en/library/61427fbd-de1f-4c8a-b613-321f7a3cca6a1033.mspx?mfr=true" target="_blank">netsh command line</a> to understand more on this command. And make sure you create a test subnet to run my scripts agains to make sure this is right for you.</p>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">Step 2.</span></strong></p>
<blockquote><p><em>C:\Program Files\Support Tools&gt;</em><span style="color: #ff0000;">netsh dhcp server 172.x.x.x show scope &gt; c:\scope.txt</span></p></blockquote>
<p>At the command prompt enter the section above in red (insert the ip address of the DHCP server in place of 172.x.x.x. This will create a text file with the sope info on your c drive.</p>
<p> </p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/07/image-0316.png"><img class="aligncenter size-medium wp-image-65" title="image-0316" src="http://bradstechblog.com/wp-content/uploads/2008/07/image-0316-300x155.png" alt="" width="300" height="155" /></a></p>
<p> </p>
<p>You will now want to open scope.txt and clean it up. You only want the IP address&#8217;s of the scopes to be changed. the text file should be in the following format</p>
<blockquote><p><strong><span style="text-decoration: underline;"><img class="aligncenter size-medium wp-image-66" title="image-0317" src="http://bradstechblog.com/wp-content/uploads/2008/07/image-0317-281x300.png" alt="" width="205" height="195" /></span></strong></p>
<p><strong></strong> </p></blockquote>
<p><strong><span style="text-decoration: underline;">Step 3</span></strong></p>
<blockquote><p><span style="color: #ff0000;">for /f &#8220;tokens=1&#8243; %%a in (c:\scope.txt) DO netsh dhcp server 172.x.x.x scope %%a set optionvalue 006 IPADDRESS DNS_Address_1 DNS_Address_2 DNS_Adress_3</span></p></blockquote>
<blockquote>
<p style="TEXT-ALIGN: center"><span style="color: #ff0000;">172.x.x.x = Your DHCP server IP address</span></p>
<p style="TEXT-ALIGN: center"><span style="color: #ff0000;">DNS_Address_#= DNS server IP address&#8217;s</span></p>
</blockquote>
<p>Copy the above red text into a text file and save it as scope_edit.bat to the same folder as scope.txt. Run the bat file. This will run through each IP address changing the dns entires. does not append the scope option for DNS it overwrites it. However it will not effect any other options that are currently set.</p>
<blockquote><p>You can now use the same script to change your wins optin by changing optioncalue 006 to optionvalue 044</p></blockquote>
<p> </p>
<p> Good luck <img src='http://bradstechblog.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p> <br />
<strong></strong> </p>
<p><strong></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/netsh/manage-multiple-dhcp-scopes-with-netsh-script/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft DHCP: How to Export and import scopes between DHCP servers</title>
		<link>http://bradstechblog.com/netsh/export-and-inport-dhcp-scopes</link>
		<comments>http://bradstechblog.com/netsh/export-and-inport-dhcp-scopes#comments</comments>
		<pubDate>Thu, 31 Jul 2008 16:02:50 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[DHCP]]></category>
		<category><![CDATA[netsh]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[import]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Scopes]]></category>
		<category><![CDATA[Spilt Scopes]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=69</guid>
		<description><![CDATA[We are going to use Microsoft&#8217;s Netsh command to export and import DHCP scopes from one server and then import them to another.  We run a split scope on two servers for redundancy. So scope one serves the range 172.0.0.64 to 172.0.0.159 and the second server handles 172.0.0.160 to 172.0.0.255. While I was performing maintenance I [...]]]></description>
			<content:encoded><![CDATA[<p>We are going to use Microsoft&#8217;s Netsh command to export and import DHCP scopes from one server and then import them to another.  We run a split scope on two servers for redundancy. So scope one serves the range 172.0.0.64 to 172.0.0.159 and the second server handles 172.0.0.160 to 172.0.0.255. While I was performing maintenance I noticed that in some cases someone missed the creation of the second half of the scope. So to fix this I am going to run a script that will export the scopes. Then I will run another script to import them on the second server. Make sure after wards to modify the exclusion on the second server to be opposite so that they are not both serving the same half.</p>
<p><!-smartads-><br />
 <span id="more-69"></span></p>
<blockquote><p>note: the import and export command cannot be ran remotely</p>
<p>Replace 198.168.0.10  with your DHCP server IP address</p>
<p>Replace 198.168.1.0 198.168.2.0 198.168.3.0 with the IP scopes that you are exporting and importing.</p>
<p>Export the scopes for the DHCP server 1</p></blockquote>
<p><strong><em>Step 1</em></strong></p>
<ol>
<li>Log on to the server that you are exporting from.</li>
<li>open the command prompt</li>
<li>Run the following command from the command prompt on the DHCP server that have the scopes already created.</li>
</ol>
<blockquote><p>Netsh DHCP server 198.168.0.10 export c:\scope 198.168.1.0 198.168.2.0 198.168.3.0</p></blockquote>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/07/image-0318.png"><img class="aligncenter size-full wp-image-70" title="image-0318" src="http://bradstechblog.com/wp-content/uploads/2008/07/image-0318.png" alt="" width="500" height="109" /></a><a href="http://bradstechblog.com/wp-content/uploads/2008/07/image-0318.png"></a></p>
<p> </p>
<p><strong>Step 2</strong></p>
<p>Import the scopes to DHCP server 2  </p>
<ol>
<li>Copy the scope file to the second DHCP server. </li>
<li>Log on locally to the second DHCP server, open the command prompts and run the following command to import the scopes</li>
</ol>
<blockquote><p>Netsh DHCP server 198.168.0.10 import c:\scope 198.168.1.0 198.168.2.0 198.168.3.0</p></blockquote>
<p>Step 3</p>
<ol>
<li>Confirm that the scopes are now on the second server.</li>
<li>Modify the Exclusions if you have any. If this is a split scope then the exclusions should be opposite of each other on the two servers.</li>
</ol>
<p> </p>
<p>Good luck.<br />
<!-smartads-><br />
 </p>
<p> The following is from Technet <a href="http://technet2.microsoft.com/windowsserver/en/library/61427fbd-de1f-4c8a-b613-321f7a3cca6a1033.mspx?mfr=true">http://technet2.microsoft.com/windowsserver/en/library/61427fbd-de1f-4c8a-b613-321f7a3cca6a1033.mspx?mfr=true</a></p>
<blockquote>
<h4>import</h4>
<div class="intro">
<p>Imports a DHCP service configuration from a file to the local service.</p></div>
<h5>Syntax</h5>
<div class="intro">
<p><strong>import</strong> [<em>Path</em>]<em>FileName</em> {<strong>all</strong> | <em>ScopeList</em>]</div>
<h5>Parameters</h5>
<div class="intro">
<div class="definitionList">
<div class="definitionListItem">
<div class="term">[<em>Path</em>] <em>FileName</em></div>
<div class="definition">Required. Specifies, by name, the file from which the DHCP configuration will be imported. If the path, the file name, or both contain spaces, quotation marks must be used.</div>
</div>
<div class="definitionListItem">
<div class="term">{<strong>all </strong>| <em>ScopeList</em>}</div>
<div class="definition">Required. Specifies which scopes you want to import. The parameter <strong>all</strong> imports all scopes represented in the file you specify. The parameter <em>ScopeList</em> imports the scopes that correspond to the IP addresses you list. Each IP address in the list must be separated by spaces.</div>
</div>
</div>
</div>
<h5>Remarks</h5>
<div class="intro">
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td class="listBullet" valign="top">•</td>
<td class="listItem">This command works only on the local server.</td>
</tr>
<tr>
<td class="listBullet" valign="top">•</td>
<td class="listItem">While the <strong>import</strong> command runs, the DHCP service is stopped and does not respond to DHCP clients seeking new leases or lease renewals.</td>
</tr>
<tr>
<td class="listBullet" valign="top">•</td>
<td class="listItem">If the DHCP service has a large number of scopes or a large number of client address leases, this command can take a long time to run.</td>
</tr>
</tbody>
</table>
</div>
<h5>Examples</h5>
<div class="intro">
<p>In the first example, this command imports the complete DHCP service configuration from the file c:\Temp\Dhcpdb.</p>
<p>In the second example, this command imports the DHCP configuration for scopes 10.0.0.0 and 192.168.0.0 from the file c:\Temp\Dhcpdb</p>
<p>In the third example, this command imports the complete DHCP service configuration from the file c:\My Folder\Dhcp Configuration. Note that both the path and file name contain spaces, so quotation marks are used.</p>
<p><strong>import c:\Temp\Dhcpdb all</strong></p>
<p><strong>import c:\Temp\Dhcpdb 10.0.0.0 192.168.0.0</strong></div>
<p><strong>import &#8220;c:\My Folder\Dhcp Configuration&#8221; all</strong></p></blockquote>
<p><!--martad--></p>
<p><a href="http://bradstechblog.com"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/netsh/export-and-inport-dhcp-scopes/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
