Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

20411B-ENU-TrainerHandbook

.pdf
Скачиваний:
237
Добавлен:
01.05.2015
Размер:
16.48 Mб
Скачать

Administering Windows Server® 2012 12-9

Lab: Implementing Update Management

MCT

Scenario

 

A. Datum is a global engineering and manufacturing company with head office based in London, UK. An IT office and a data center are located in London to support the London location and other branch office locations. A. Datum has recently deployed a Windows Server 2012 server and client infrastructure.

A. Datum has been manually applying updates to servers in a remote location. This has resulted in

USE

difficulty identifying which servers have updates applied and which do not. This is a potential security

 

 

issue. You have been asked to automate the update process by extending A. Datum’s WSUS deployment

to include the branch office.

 

.ONLY

Objectives

 

After completing this lab, you will be able to:

 

• Implement the WSUS server role.

 

• Configure update settings.

 

 

 

 

• Approve and deploy an update by using WSUS.

 

 

Lab Setup

 

 

 

Estimated Time: 60 minutes

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Virtual machines

20411B-LON-DC1

 

 

 

20411B-LON-SVR1

 

 

 

20411B-LON-SVR4

 

 

 

20411B-LON-CL1

 

 

 

 

 

 

User Name

Adatum\Administrator

STUDENT

 

 

1.On the host computer, click Start, point to Administrative Tools, and then click Hyper-V ManagerUSE.

2.In Hyper-V® Manager, click 20411B-LON-DC1, and in the Actions pane, click Start. PROHIBITED

3.In the Actions pane, click Connect. Wait until the virtual machine starts.

4.Log on using the following credentials: o User name: Adatum\Administrator o Password: Pa$$w0rd

5.Perform steps 2 through 4 for 20411B-LON-SVR1, 20411B-LON-SVR4, and 20411B-LON-CL1.

12-10 Implementing Update Management

 

MCT

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Exercise 1: Implementing the WSUS Server Role

 

 

 

 

 

 

 

Scenario

 

USE

 

 

Your organization already has a WSUS server called LON-SVR1, which is located in the head office. You

 

 

 

 

 

 

 

 

need to install the WSUS server role on LON-SVR4 at a branch location. LON-SVR4 will use LON-SVR1 as

 

 

 

 

 

 

the source for Windows Update downloads. The installation on LON-SRV4 will use the Windows Internal

 

 

 

 

 

 

Database for the deployment.

 

 

 

 

 

 

 

The main tasks for this exercise are as follows:

 

ONLY

1.

Log on to LON-SVR4 as Adatum\Administrator with a password of

Pa$$w0rd.

 

 

 

 

2.

From Server Manager, install the Windows Server Update Services role with the WID Database and

 

 

 

 

 

 

.

 

 

 

WSUS Services Role Services. Also configure the updates location as C:\WSUSUpdates.

STUDENT

3.

Open the Windows Server Update Services console and complete the installation when prompted.

 

 

 

 

4.

On the Windows Server Update Services Configuration Wizard, click Cancel.

 

 

 

 

5.

Close the Update Services console.

 

 

 

 

 

1.

On LON-SVR4, complete the Windows Server Update Services Configuration Wizard, specifying the

 

 

 

 

 

 

 

following settings:

 

 

 

 

 

 

 

 

o Upstream Server: LON-SVR1.Adatum.com

 

 

 

 

 

 

 

 

o

No proxy server

 

 

 

 

 

 

 

 

o

Default languages

 

USE

 

 

 

o

Manual sync schedule

 

 

 

 

o

Begin initial synchronization

 

2.

In the Windows Server Update Services console, under Options, set the Computers to Use Group

 

 

 

Policy or registry settings on computers.

 

 

 

 

 

 

 

 

 

 

 

 

Results: After completing this exercise, you should have implemented the WSUS server role.

 

PROHIBITED

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Administering Windows Server® 2012 12-11

Exercise 2: Configuring Update Settings

MCT

Scenario

 

You need to configure the Group Policy settings to deploy automatic WSUS settings to client computers. With the WSUS role configured on LON-SVR4, you must ensure that the Research department has its own computer group in WSUS on LON-SVR4. You must also configure client computers in the Research OU to

use LON-SVR4 as their source for updates.

USE

The main tasks for this exercise are as follows:

.ONLY

1.

Configure WSUS groups.

2.

Configure Group Policy to deploy WSUS settings.

3.

Verify the application of Group Policy settings.

4.

Initialize Windows Update.

Task 1: Configure WSUS groups

1.

On LON-SVR4, if necessary, open the Windows Server Update Services console.

 

2.

Create a new computer group named Research.

 

1.

Switch to LON-DC1.

 

2.

Open Group Policy Management.

 

3.

Create and link a new GPO to the Research OU named WSUS Research, and configure the following

 

policy settings under the Windows Update node:

STUDENT

 

o Configure Automatic Updates: Auto download and schedule the install

 

o Microsoft Update service location: http://LON-SVR4.Adatum.com:8530

 

o Intranet statistics server: http://LON-SVR4.Adatum.com:8530

 

USE

 

o Client-side targeting group: Research

4.

Move LON-CL1 to the Research OU.

 

 

1.Switch to LON-CL1.

2.Restart LON-CL1.

3.On LON-CL1, log on as Adatum\Administrator with a password of Pa$$w0rd.

4.Open a command prompt by using the Run as Administrator option.

5.At the command prompt, run the following command:

Gpresult /r

6.In the output of the command, confirm that under Computer Settings, WSUS Research is listed under Applied Group Policy Objects.

PROHIBITED

12-12 Implementing Update Management

Task 4: Initialize Windows Update

1.On LON-CL1, at the command prompt, type the following command, and then press Enter:

MCT

 

 

Wuauclt.exe /reportnow /detectnow

USE

 

 

 

 

 

 

 

 

 

 

 

2.

Switch to LON-SVR4.

 

 

 

3.

In the Update Services console, expand Computers, All Computers, and then click Research.

 

 

 

4.

Verify that LON-CL1 appears in the Research Group. If it does not then repeat steps 1-3. It may take

 

 

 

 

 

several minutes for LON-CL1 to display.

 

 

 

5.

Verify that updates are reported as needed. If there are not updates reported, repeat steps 1-3. It may

 

 

take 10-15 minutes for updates to register.

 

 

 

 

 

 

 

 

 

Results: After completing this exercise, you should have configured update settings for client computers.

 

ONLY

 

 

 

 

 

 

 

 

PROHIBITED USE STUDENT .

 

 

 

 

Administering Windows Server® 2012 12-13

Exercise 3: Approving and Deploying an Update by Using WSUS

MCT

Scenario

 

After you have configured the Windows Update settings, you can now view, approve, and then deploy required updates. You have been asked to use LON-CL1 as a test case for the Research department. You will approve, deploy, and verify an update on LON-CL1 to confirm the proper configuration of the WSUS

environment.

USE

The main tasks for this exercise are as follows:

.ONLY

1.

Approve WSUS updates for the Research computer group.

2.

Deploy updates to LON-CL1.

3.

Verify update deployment to LON-CL1.

Task 1: Approve WSUS updates for the Research computer group

 

1.

On LON-SVR4, open the WSUS console.

 

2.

Approve the Security Update for Microsoft Office 2010 (KB2553371), 32-bit edition update for

 

the Research group.

 

Task 2: Deploy updates to LON-CL1

1.On LON-CL1, at the command prompt, type the following command, and then press Enter:

Wuauclt.exe /detectnow

2.Open Windows Update and then check for updates.

3.Click Install to install the approved update.

Task 3: Verify update deployment to LON-CL1

1.On LON-CL1, open Event Viewer.

2.Navigate to Applications and Services Logs\ Microsoft\Windows, and view the events under WindowsUpdateClient – Operational.

3.Confirm that events are logged in relation to the update.

Results: After completing this exercise, you should have approved and deployed an update by using

WSUS.

To prepare for the next module

When you finish the lab, revert all virtual machines back to their initial state. To do this, perform the following steps:

1.On the host computer, start Hyper-V Manager.

2.In the Virtual Machines list, right-click 20411B-LON-DC1, and then click Revert.

3.In the Revert Virtual Machines dialog box, click Revert.

4.Repeat steps 2 to 3 for 20411B-LON-SVR1, 20411B-LON-SVR4, and 20411B-LON-CL1.

PROHIBITED USE STUDENT

12-14 Implementing Update Management

Module Review and Takeaways

Review Questions

Question: A colleague has argued that all updates to the Windows operating system should be applied automatically when they are released. Do you recommend an alternative process?

Question: Your organization implements several applications that are not Microsoft applications. A colleague has proposed using WSUS to deploy application and operating system updates. Are there any potential issues with using WSUS?

Question: Why is WSUS easier to manage in an AD DS domain?

Tools

Tool

Use

Where to find it

 

 

 

WSUS Administration

Administer WSUS

Server Manager - Tools

console

 

 

 

 

 

Windows PowerShell WSUS

Administer WSUS from the

Windows PowerShell

cmdlets

command–line interface

 

 

 

 

PROHIBITED USE STUDENT .ONLY USE MCT

 

 

13-1

 

 

 

 

 

Module 13

 

MCT

 

USE

Monitoring Windows Server 2012

 

Contents:

 

 

.ONLY

Module Overview

13-1

Lesson 1: Monitoring Tools

13-2

Lesson 2: Using Performance Monitor

13-8

Lesson 3: Monitoring Event Logs

13-16

Lab: Monitoring Windows Server 2012

13-19

Module Review and Takeaways

13-25

 

 

Module Overview

When a system failure or an event that affects system performance occurs, you must be able to repair the problem or resolve the issue quickly and efficiently. With so many variables and possibilities in the modern

You can use performance-monitoring tools to identify components that require additional tuning and troubleshooting. By identifying components that require additional tuning, you can improve the efficiency of your servers.

network environment, the ability to determine the root cause quickly often depends on having an

STUDENT

effective performance-monitoring methodology and toolset.

 

Describe the monitoring tools for Windows Server® 2012. USE

Use Performance Monitor to view and analyze performance statistics of programs that are running on your servers.

Monitor event logs to view and interpret the events that occurred. PROHIBITEDObjectives

13-2 Monitoring Windows Server 2012

Lesson 1

Monitoring Tools

Windows Server2012 provides a range of tools to monitor an operating system and applications on a computer. You can use these tools to tune your system for efficiency and troubleshoot problems. You should use these tools and complement them where necessary with your own tools.

Lesson Objectives

After completing this lesson, you will be able to:

Describe Task Manager.

Describe Performance Monitor.

Describe Resource Monitor.

Describe Event Viewer.

.ONLY USE MCT

Processes. The Processes tab displays a list STUDENT of running programs, subdivided into

applications and internal Windows processes. For each running process, this tab displays a summary of processor and memory usage.

Performance. The Performance tab displays a USE summary of central processing unit (CPU) and

memory usage, and network statistics.

Users. The Users tab displays resource consumption on a per-user basis. You also can expand the user view to see more detailed information about the specific processes that a user is running.

Details. The Details tab lists all the running processes on the server, providing statistics about the CPU,PROHIBITED memory, and other resource consumption. You can use this tab to manage the running processes. For example, you can stop a process, stop a process and all related processes, and change the processes’

priority values. By changing a process’s priority, you determine how much CPU resource the process can consume. By increasing the priority, you allow the process to request for more CPU resource.

Services. The Services tab provides a list of the running Windows services, together with related information: whether the service is running and the processor identity value (PID) of the running service. You can start and stop services by using the list on the Services tab.

Primary Processor Counters
There are many counters that you can research and consider monitoring to meet your specific requirements.

Administering Windows Server® 2012 13-3

Overview of Performance Monitor

MCT

Performance Monitor enables you to view current

 

 

USE

performance statistics, or to view historical data

that is gathered by using data collector sets.

With Windows Server 2012, you can monitor

operating system performance through

performance objects and counters in the objects.

 

 

Windows Server 2012 collects data from counters

 

 

in various ways, including:

 

 

• A real-time snapshot value.

 

 

• The total since the last computer startup.

 

 

 

 

 

• An average over a specific time interval.

ONLY.

• An average of last values.

 

 

• The number per second.

 

 

A maximum value.

 

 

A minimum value.

STUDENT

 

 

Performance Monitor works by providing you with a collection of objects and counters that record data about computer resource usage.

CPU counters are a feature of the computer’s CPU that stores the count of hardware-related events. The primary processor counters include:

Processor > % Processor Time. This counter measures the percentage of elapsed time the processor

spends executing a nonidle thread. If the percentage is greater than 85 percent, the processor is USE overwhelmed and the server may require a faster processor. In other words, this counter displays the percentage of elapsed time that a given thread used the processor to run instructions. An instruction

is the basic unit of execution in a processor, and a thread is the object that executes instructions. Included in this count is code that handles some hardware interrupts and trap conditions.

Processor > Interrupts/sec. This counter displays the rate, in incidents per second, at which the PROHIBITED processor received and serviced hardware interrupts.

System > Processor Queue Length. This counter displays an approximate number of threads that each processor is servicing. The server does not have enough processor power if the value is more than two times the number of CPUs for an extended period. The processor queue length, sometimes referred to as processor queue depth, that this counter reports is an instantaneous value that is representative only of a current snapshot of the processor. Therefore, you must observe this counter over an extended period to notice data trends. Additionally, the System > Processor Queue Length counter reports a total queue length for all processors, not a length for each processor.

Workloads might require access to several different networks that must remain secure. Examples include
Primary Network Counters

13-4 Monitoring Windows Server 2012

computer. Virtual memory consists of space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory.

The Memory > Pages/sec counter measures the rate at which pages are read from or written to disk to resolve hard-page faults. If excessive paging results in a value that is greater than 1,000, there may be a memory leak. In other words, the Memory>Pages/sec counter displays the number of hard page faults per second. A hard page fault occurs when the requested memory page cannot be located in RAM because it exists currently in the paging file. An increase in this counter indicates that more paging is

USE MCT

Physical Disk > % Disk Time. This counter indicates how busy a particular disk is, and it measures the ONLY.

percentage of time that the disk was busy during the sample interval. A counter approaching 100

percent indicates that the disk is busy nearly all of the time, and a performance bottleneck is possibly STUDENT imminent. You may consider replacing the current disk system with a faster one.

Physical Disk > Avg. Disk Queue Length. This counter indicates how many disk requests are waiting to be serviced by the I/O manager in Windows® 7 at any given moment. If the value is larger than two

times the number of spindles, it means that the disk itself may be the bottleneck. The longer the queue is, the less satisfactory the disk throughput.occurring, which in turn suggests a lack of physical memory.

Most workloads require access to production networks to ensure communication with other applications and services, and to communicate with users. Network requirements include elements such as throughput and the presence of multiple network connections.

USE

Network Interface > Current Bandwidth. This counter indicates the current bandwidth being PROHIBITED consumed on the network interface in bits per second (bps). Most network topologies have maximum

potential bandwidths quoted in megabits per second (Mbps). For example, Ethernet can operate at bandwidths of 10 Mbps, 100 Mbps, 1 Gigabit per second (Gbps), and higher. To interpret this counter,connections for:

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]