Pages

Tuesday, June 9, 2020

Create Azure P2S VPN with Azure AD Authentication

You can use Azure Point-to-Site (P2S) VPN to connect to your Azure Virtual Network from an individual device. This helps remote workers to access resources inside the VNet. You can use certificates, RADIUS or Azure AD for user authentication.

Azure AD authentication is the most recent and easiest method to configure. With AAD authentication you can leverage additional security features like MFA and Conditional Access. It uses OpenVPN protocol for tunneling. Below is the method to configure P2S VPN using Azure AD.

Friday, May 15, 2020

Microsoft Endpoint Configuration Manager Firewall Ports

This is a downloadable spreadsheet which consists of all default firewall ports related to MECM infrastructure. Primary purpose of this document is to give MECM Admins a simple overview of firewall ports required for MECM.

Thursday, May 14, 2020

MECM Client Windows Updates Scan Failed with Error = 0x80244022

Today, I was informed by a customer regarding an MECM (Microsoft Endpoint Configuration Manager) updates deployment issue. Some machines haven't downloaded updates for months. 

To troubleshoot the issue I examined logs related to software updates in client.

Tuesday, May 12, 2020

Configure Azure Bastion to Connect to Virtual Machines

Azure Bastion is a service (PaaS) which provides the ability to connect (RDP/SSH) to Azure virtual machines directly over TLS. With Azure Bastion, you don’t need to configure a public IP address on the VM to connect through RDP or SSH. Also, you don’t need any additional agent or software installed on your machine or inside Azure VM since you connect to VM directly from the Azure portal. Only an HTML5 capable browser is sufficient.

Azure Bastion deployment is per virtual network. Therefore, once you deployed it to a virtual network, you can connect to any VM inside that virtual network.

Tuesday, October 9, 2018

LEDBAT Not Correctly Configured in Windows Server 2016

LEDBAT or Low Extra Delay Background Transfer is a TCP Congestion control mechanism available in Windows Server 2016 and Windows Server 2019. LEDBAT helps to utilize the entire bandwidth (e.g. for SCCM packages or Windows Updates) when the network is free and if some other task (e.g. Application) requires bandwidth, it will give priority for that task.

Today I tried to configure LEDBAT in my SCCM environment. It's just a simple task as ticking a checkbox in Distribution Point properties. But in the background it does not get configured correctly due to incorrect TCP Templates.