Minutes Waterloo Polaris Advisory Group May 16, 2001

Attendees:

Daniel Delattre Applied Health Science (AHS) Bernie Roehl ESAG Representative
Nevil Bromley Arts Ray White Information System and Technology (IST) (Chair)
Bruce Campbell Engineering Computing Stephen Sempson Science (Secretary)
Hon Tam Engineering Computing  

Invited guests:

Andrea Chappell LT3 Centre  

Regrets:

Tim Farrell IST Trevor Bain Environmental Studies (ES)
Jim Johnston MFCF Erick Engelke Engineering Computing

Submitted items:

Q: (Nevil) I initially had a question about the backups, but looking at Bruce's recent email, I find it more than thorough.
A: (Bruce) We have been using the campus wide backup, but the annual costs have been going up every year even though the price of hardware has been going down. Engineering has started doing backups to IDE drives in two parallel systems housed in separate buildings. These machines have been designed to be islands that are just using the 'Dump' command. Tapes in the past have been hit and miss. In September we will be looking at tapes agian. Currently we are seeing a 3:1 compression ration on the IDE's. Timing tests indicate 140G's in 12 hours. (Hoover was 37 hours, but is not a fair comparioson since it was backing up others at the same time). This system cannot compete with Hoover, which has daily's for two years back. The IDE backups can do a 6 month time frame with sparser backups in the past. A restore of 'Level 0' is approximately 24 hours for the whole Netapp system. Building the system cost about $4500, most of which was for the disk space (6 drives plus 2 700Mz machines).  In this scenario, one could have backup buddies, for off-site storage. Engineering is backup up Science on an older system. Controlling the proceedure is with a script, which indicates how many levels, and how many to keep.

(Bernie) What would be the restore mechanism?
(Bruce) One can use the snapshots on the Filer for recent 2 week period. More than that would be a manual process and require one to go to their respective consultants for help.

Q: (Daniel) Is there any backing up of the Nexus Domain Controllers (DC)?
A: (Hon) No, the DC's have redundancies inherent in the Active Directory (AD) structure which provide adequate availability and fault tolerance. AD uses multi-master replication, in which no single domain controller is the master domain controller. Domain controllers might hold different information for short periods of time until all of the domain controllers have synchronized their changes to AD. Other than that, one would need to keep copies of the .Dit files to recover a server.

(Bruce) Erick is working on something similar to a 'show rebuild' to facilitate this.
(Nevil) Does this include a backup of DHCP?
(Hon) Yes, stop one server, copy to where new server would use, and then done...

Q: (Nevil) The latest Sysctl seems to have 'unfixed' my latest Webweaver controls.
A: (Ray) There is a conflict between these two applications (Webweaver and Simul8) because of the spell checker. The default behaviour is that Simul8 will work but Webweaver will not. For changing individual workstations so that Webweaver works and Simul8 does not add the file C:\Polaris\Flags\Nosimul8 to the workstation and remove the C:\packages\sysapr01.001 update file so the next nightly _sysctl95 will replace the OCX file.


Information items:

(Andrea) I have been involved with the Electronic Classroom. Problems have started to arise with computers which have the network drops and projectors. They are completely insecure. People have been installing, with IST involved in some. There seems to be no real form of support. The best possibility which recently came up was 'Polaris.' We have recognized some issues ie. signing on and having an account with Polaris, and knowing what software is there. Hands on in advanced by the users would be good. We have no idea how the Professors' whould take to this. A survey has gone out with 4 yes, 4 no, and the rest of the 25 indifferent. This was out of 300 people emailed from Electronic Classroom.

(Ray) Polaris to Nexus would be a better choice.
(Bruce) Nexus would not require VLan capability for connections.
(Andrea) Greg is checking for VLan capabilities.
(Bruce) Most Engineering Faculty do have accounts in Polaris, some may be dormant though.
(Andrea) Accounts was really the big thing. AV will be taking care of this and has been in the past, so they will need accounts too.
(Hon) Yes, it is possible to have Windows 2000 administered across campus.

(Nevil) I added a new GPO, but it took some time for the Software to install. Is this normal?
(Ray) Yes, in this respect, it is a little like Polaris in that it must be done after the fact.

(Hon) We have been running IIS to redirect to the real Nexus web site, otherwise someone would get our DC's with webpages stating Not found. Now the issue is the security risks associated with running this service.

(Bruce) It is possible we could run our own redirect on port 80. That is to listen to all on port 80 and just pipe go here. Let us take a look at setting a web server.
(Daniel) Yes, and with security, how to install the patches, and who should install?
(Bruce) The general technique is to remove needless services.
(Ray) It would be a good idea to remove IIS.

(Nevil) What is the progress on Microsoft Photo Editor?
(Ray) I have the CD now, and will be working on this.

(Nevil) Are we planning that the software on the App Servers are only non-licenced 'free' softare?
(Hon) For the most part, yes. I would still like to see MSOffice on the DC's only. Using the AppFilers is good since the process is quicker for installing the software and at the same time gives the DC a break during the installation of multiple packages.



Created by: sempson@sciborg.uwaterloo.ca 2001/05/22
Revised by: sempson@sciborg.uwaterloo.ca 2001/05/29