Syed Jahanzaib Personal Blog to Share Knowledge !

June 19, 2014

SAN attached windows 2008 hangs on boot

Filed under: IBM Related, Microsoft Related — Tags: , , , — Syed Jahanzaib / Pinochio~:) @ 9:37 AM

Just for reference purpose:

Recently I was testing some disaster recovery scenario of restoring Server A to Server B with identical hardware using Symantec Backup EXEC 2014 Simplified Disaster Recovery [SDR]CD. The hardware specs were as follows …

IBM Xseries 3650 M4, with RAID1
Dual Q.Logic Fiber Channel cards Mode: QLE2560 connected with two FC switches for multi path and failover
32 GB RAM,
IBM v3700 storewize SAN Storage

The restore went fine , system boot fine for the first time with everything intact, but when I rebooted it again , it failed to boot and shows only cursor blinking,  As showed in the image below …


I tried to boot it several times but with no results. I then removed the FC cables from the server’s Qlogic FC cards, and this time windows booted fine.


I started the server without FC cables attached, then I removed the Windows MPIO features from ADD REMOVE FEATURES, and rebooted again with FC cables attached, and this time it works fine but showed duplicate SAN partitions. Then I applied IBM’s SSDM MPIO driver (MPIO_Win2008_x64_SDDDSM_64_2434-4_130816 for v3700 storewize)  and everything went fine 🙂

You may also want to read the IBM’s article.



Syed Jahanzaib

June 12, 2014

Mikrotik WAN monitoring script with multiple host check

Filed under: Mikrotik Related — Tags: , — Syed Jahanzaib / Pinochio~:) @ 2:31 PM


Recently I added a mikrotik’s base netwatch script on a network to monitor WAN link , and if no ping received from the the WAN host (Example:, the down script changes the backup link route to take priority over primary link. But the issue is NETWATCH is kind of un reliable method to check internet connectivity, because it can check only single host at a time, also if your wan link is week or heavily used resulting in few ping timed out which is sometimes common (for example 3 out of 10 replies misses) Netwatch sometimes consider the target link DOWN. the Netwatch gives a “DOWN” status immediately upon a missed ping – irregardless of the Timeout setting.

So to prevent that we must use a method via which we can check at least two or more hosts on Internet like IPS Gateway IP and any other reliable host like (or any other host in your particular region) , if it fails to receive at least 5 replies from each of host, then it will consider the link DOWN. If one host is working and second is down, it will also consider it as UP. kind of cross verification.If 2 out of 5 ping misses, it will still consider the link UP.

Multiple HOST check is recommended, Because if you are using single host check script or netwatch,then some times it can happen that ping reply is not receiving dueto various reason (either its down or isp have blocked ), but rest of internet is working fine, but even then the script/netwatch will consider the LINK is down dueto its single host check. That’s why multi host check is recommended.


ROS SCRIPT CODE: (Script name= monitor)

# Following script is copied from the Mikrotik forum.
# Thanks to mainTAP and rextended for sharing
# Modified few contents to suite local requirements and added descriptions
# Regard's / Syed Jahanzaib /

# Script Starts here...
# Internet Host to be checked You can modify them as per required, JZ
:local host1   ""
:local host2   ""

# Do not modify data below without proper understanding.
:local i 0;
:local F 0;
:local date;
:local time;
:global InternetStatus;
:global InternetLastChange;

# PING each host 5 times
:for i from=1 to=5 do={
if ([/ping $host1 count=1]=0) do={:set F ($F + 1)}
if ([/ping $host2 count=1]=0) do={:set F ($F + 1)}
:delay 1;

# If both links are down and all replies are timedout, then link is considered down
:if (($F=10)) do={
:if (($InternetStatus="UP")) do={
:log error "WARNING : The INTERNET link seems to be DOWN. Please Check";
:set InternetStatus "DOWN";

##     /ip route set [find comment="Default Route"] distance=3
##     /ip firewall nat disable [find comment="Your Rules, Example"]

:set date [/system clock get date];
:set time [/system clock get time];
:set InternetLastChange ($time . " " . $date);
} else={:set InternetStatus "DOWN";}
} else={

##      If reply is received , then consider the Link is UP
:if (($InternetStatus="DOWN")) do={
:log warning "WARNING :The INTERNET link have been restored";
:set InternetStatus "UP";

##     /ip route set [find comment="Default Route"] distance=1
##     /ip firewall nat enable  [find comment="Your Rules, Example"]

:set date [/system clock get date];
:set time [/system clock get time];
:set InternetLastChange ($time . " " . $date);
} else={:set InternetStatus "UP";}

# Script Ends Here.
# Thank you


Scheduler to run script auto

To add scheduler to run script after every 5 minutes (or as required), use following code

/system scheduler
add disabled=no interval=5m name="Monitor WAN connectivity Scheduler / JZ" on-event=monitor policy=ftp,reboot,read,write,policy,test,winbox,password,sniff,sensitive,api start-date=jun/12/2014 start-time=\

Don’t forget to change the script name monitor in above scheduler to match the name you set for the script.
Example: on-event=monitor


Define Static Routes for Monitoring Host – for Route Changing

If  you are using this script to change internet route to backup link, then you must define static routes for the host you are monitoring. So that your monitored hosts should always (forcefully) go via Primary Link.

/ip route
add comment="Force this HOST via Primary Link" disabled=no distance=1 dst-address= gateway= scope=30 target-scope=10
add comment="Force this HOST via Primary Link" disabled=no distance=1 dst-address= gateway= scope=30 target-scope=10

Note: Make sure to change gateway to primary internet link gateway.



Syed Jahanzaib

June 5, 2014

IBM Storewize v3700 SAN Duplicate partitions showing in Windows 2008

Filed under: Uncategorized — Tags: , , , — Syed Jahanzaib / Pinochio~:) @ 10:13 AM


Recently one of our IBM Xseries 3650 M4 server faced hardware failure related to local storage. Two partitions from IBM Storwize v3700 were assigned to this system, connected with 2 QLogic FC cards connected with 2 BROCADE fiber switches for fail over.

After doing re installation of Windows 2008 R2, SAN partitions were appearing duplicate. Windows MPIO feature was enabled but still partitions were twice appearing. After applying IBM base SDDDSM MPIO updated driver, problem got solved.

Subsystem Device Driver Device Specific Module (SDDDSM) is IBM’s multipath IO solution based on Microsoft MPIO technology, it’s a device specific module specifically designed to support IBM storage devices. Together with MPIO, it’s designed to support the multipath configuration environments in the IBM Storage.

Download link is as follosw. Just a small patch , apply and restart 🙂


Platform Windows Server 2008/2008
(R2 / 32bit /64bit)
SDDDSM v2.4.3.4-4
SDDDSM for Windows Server 2008
Byte Size 577711


Syed Jahanzaib

June 4, 2014

Radius Manager Dealer Panel

Filed under: Radius Manager — Tags: , , — Syed Jahanzaib / Pinochio~:) @ 1:38 PM

In Radius Manager, we have an option to add MANAGER (Dealer/Reseller) so that the Dealer/Reseller can have access to his own management panel (similar to ACP but with some limitations). The Dealer/Reseller can create new users, disable , add deposit/credit in user account, invoice access and stuff like this.

You can assign various permissions to the dealer as per requirements. Following is an example of creating NEW MANAGER with minimum rights.

Goto Managers , and select NEW Manager

As showed in the image below …


Assign necessary permissions, this is important 🙂


Permission Explanation:

• List users – Can list users.
• Register users – Can register new users.
• Edit users – Can edit basic user data (name, address etc.).
• Edit privileged user data – Allows editing privileged fields (credits, static IP).
• Delete users – Can delete users.
• List managers – Can list managers.
• Register managers – Can register new managers.
• Edit managers – Can edit managers.
• Delete managers – Can delete managers.
• List services – Can list services.
• Register services – Can register new services.
• Edit services – Can edit services.
• Delete services – Can delete services.
• Billing functions –
Can generate invoices.
• Allow negative balance – Can refill prepaid accounts even if the reseller account is in negative balance.
• Allow discount prices – Can form the service price freely (discount).
• Enable canceling invoices – Enable canceling invoices (enter negative amount in Add credits form to cancel an invoice).
• Access invoices – Can access invoicing functions.
• Access all invoices – Can access all invoices not only the own ones.
• Shown invoice totals – Display the totals in List invoices view.
• Edit invoices – Can enter the payment date for postpaid invoices.
• Access all users – Can access all users in the system.
• List online users – Can list online users.
• Disconnect users – Can disconnect users.

Card system and IAS

• Card system and IAS – Can access prepaid card and IAS system.
• Connection report – Can access CTS functions.
• Overall traffic report – Can access traffic report.
• Maintain APs – Can access AP functions.
Click the Update manager button to store the manager data.


Now by default this Dealer/Reseller will have zero balance, so he wont be able to add credits in users account (although he can create new accounts but these accounts are by by default EXPIRED, so in order to renew user account, the Dealer/Reseller MUST have deposit in his account)

Now add some AMOUNT in his account. Open Manager and edit that dealer.
As showed in the image below …



Now test it via login with dealer ID and add new user. by default the new user added will be expired, and the dealer must add credit in user account. (He can also add DEPOSIT, but then user have to himself login with his user id and password to user management panel and refresh his account (with the deposited amount added by dealer).

As showed in the image below …






Binding Dealer/Reseller to Use Only Specific Services

You can also bind specific Service with specific Dealer/Reseller too. for example You dont want Dealer A to use all services, instead you want to show him specific services only. Login to ACP using ADMIN, goto Services, Open your desired services that you do or dont want to to be displayed at Dealer/Reseller A panel,

As showed in the image below …



result can be seen here…


I will write more in some free time.


Syed Jahanzaib

Non Payment Reminder for Expired Users in RADIUS MANAGER 4.x.x

Filed under: Radius Manager — Tags: , — Syed Jahanzaib / Pinochio~:) @ 12:31 PM


As per requested by many friends, Following is an short guide on howto configure payment reminder for Expired users in DMASOFTLAB RADIUS MANAGER 4.x.x. I wrote this guide because its better to explain in details with snapshots here, rather then explaining to every individual.

This guide will demonstrate that if the user account is expired, he still can login to your Mikrotik / NAS, but when he will try to browse, he will be redirected to Non Payment page showing why his access is blocked. Please note that only HTTP request will be redirected, HTTPS is not supported. Example if some one tries to open HTTPS://WWW.GOOGLE.COM, he will see default browser error, but if some try to open HTTP://WWW.BBC.COM he will be properly redirected.

Scenario #1 :

[Simple one]

Mikrotik is used as NAS/pppoe server, all clients are connected to it via pppoe dialer/wifi routers.

  • LAN IP + Default DHCP Pool for customers =
  • Local Web Server IP which is hosting our web site + reminder page =
  • PPPoE IP Pool =
  • EXPIRED IP Pool to be created at Mikrotik =
  • WAN IP = [irrelevant]



In short, perform following steps …

  • Create a new / normal service according to your requirements, like1mb / 1 month limitation

  • in  Next expired service option, Select EXPIRED as Next Master Service, So when primary service expires, user service will be switched to this one.

[Note: EXPIRED service is already available in RM by default, but if you are unable to find it, then you can create it manually, just add new service with EXPIRED name and set ip pool accordingly, no expiration no speed limit, simple)

As showed in the image below …



Now Create a user in users section and assign it with the new service you just created in  above example  >  1mb / 1 month limitation



  • Add IP POOL for Expired Users

Add new IP Pool for EXPIRED pppoe users, when the user will expire, he will be assigned EXPIRED service, which will use this pool for these users

/ip pool
add name=expired ranges=


As showed in the image below …


  • Enable WEB PROXY and add rules

Now enable WEB PROXY and add deny/redirect rule so that we can redirect the EXPIRED users pool to any web server showing the non payment reminder page. You can also use EXTERNAL proxy to do the redirection like squid proxy. but in this guide i am showing only the mikrotik level things.

# First Enable Mikrotik Web-Proxy (You can use external proxy server also like SQUID)
/ip proxy
set always-from-cache=no cache-administrator=webmaster cache-hit-dscp=4 cache-on-disk=no enabled=yes max-cache-size=unlimited max-client-connections=600 max-fresh-time=3d max-server-connections=600 \
parent-proxy= parent-proxy-port=0 port=8080 serialize-connections=no src-address=

# Add rule to allow access to web server, otherwise user wont be able to access the reminder page. this rule must be on top.
/ip proxy access
add action=allow comment="Allow acess to web server so expired users can view the payment reminder page. it can be locally hosted or external (on internet) as well." disabled=no dst-address= \

# Now add rule to redirect expired ip pool users too local or external web server payment reminder page.
/ip proxy
add action=deny disabled=no dst-port="" redirect-to=

As showed in the image below …





Now add REDIRECT rule in FIREWALL/NAT section, and add only pppoe users pool in default NAT rule.
This is to make sure that users with expired users are redirected to web proxy which will be deny there request and redirect to web server reminder page.
and also add pppoe valid users pool in default NAT rule src-address, so that only valid pppoe users can browse the internet.

As showed in the image below …



Now when the client primary profile expires, it will switch to NEXT MASTER SERVICE which we configured to EXPIRED, thus he will get ip from EXPIRED pool, and then mikrotik will redirect to proxy which will deny its request and redirect to local payment reminder page.

As showed in the image below …


Additional Tip for those who uses Squid Proxy as well.


in squid.conf add these on before other ACL. (or on top)

acl expired-clients src
http_access deny expired-clients
deny_info http://web_server_ip/nonpayment/nonpayment.htm expired-clients

Note: Ideally web server should be on same subnet. Also make sure you allow access to web server it self otherwise page will not be display.

Another Example of code: web server ip address is , and expired pool is

#first allow access to web server

acl allowed_sites dst
http_access allow allowed_sites

# then block further access for expired users  and redirect them to expired clients
acl expired-clients src
http_access deny expired-clients
deny_info expired-clients


Syed Jahanzaib

Symantec Backup Exec Reference Notes


Last Updated: 25th June, 2014

Recently we upgraded our SAP infrastructure with new IBM xSeries server and also replace the old IBM tape library TS3200 with TS100. In previous Windows 2003, we were using classic NTBACKUP solution to take backup on TAPE library system, but with the new windows 2008 R2 upgrade, we found that that the tape drive support have been removed from the new Server Backup tool. Therefore we were looking for some reliable backup solution which can facilitate our tape library. Finally after searching a lot, we selected SYMANTEC BACKUP EXEC 2012 (with SP4 and latest patches) as our backup solution. Last year We tested its demo and it was fulfilling our requirements and fitting under our budget. I did it’s installation and it went smooth without any errors, but it took me few days to understand how it actually works. Its GUI interface looks pretty much simple and easy to navigate, but I found it very typical to configure Tape Library for auto loading function according to job/day.

Following is a short reference notes I am posting. I will keep updating with day to day tasks and issues I face and how I manage to solve them. Symantec have great number of guides, postings at there site too, but sometimes its hard to find the correct solution when its kinda urgent.




1- The VSS Writer timed out (0x800423f2), State: Failed during freeze operation (9) [4th June, 2014]

2-  Simplified Disaster Recovery: Howto exclude some Folders with SDR ON  [5th June, 2014]

3- Backup Exec (2012 SP4) Services Credentials Lost on every Reboot [6th June, 2014]

4- V-79-57344-42009 – Failed to load the configuration xml file,  [6th June, 2014]

5- Barcode Labeling   [10th June, 2014]

6- Exclude a sub-folder name “xyz” or end with .ft , from every where in specific folder/drive. [15thth July, 2014]

7- Remote Agent Service not starting at Client PC/Server / NDMP Port already in use error


1- The VSS Writer timed out (0x800423f2), State: Failed during freeze operation (9)

If backup failed with following error:

V-79-57344-6523314.0.1798.1364eng-systemstate-backupV-79-57344-65233ENRetailWindows_V-6.1.7601_SP-1.0_PL-0x2_SU-0x112_PT-0x3 – Snapshot Technology: Initialization failure on: “\\YOURSERVER\System?State”. Snapshot technology used: Microsoft Volume Shadow Copy Service (VSS).
Snapshot technology error (0xE000FED1): A failure occurred querying the Writer status. See the job log for details about the error.

Check the Windows Event Viewer for details.

Writer Name: COM+ Class Registration Database, Writer ID: {542DA469-D3E1-473C-9F4F-7847F01FC64F}, Last error: The VSS Writer timed out (0x800423f2), State: Failed during freeze operation (9).

Writer Name: Windows Management Instrumentation, Writer ID: {A6AD56C2-B509-4E6C-BB19-49D8F43532F0}, Last error: The VSS Writer timed out (0x800423f2), State: Failed during freeze operation (9).

The following volumes are dependent on resource: “C:” “E:” .
The snapshot technology used by VSS for volume C: – Microsoft Software Shadow Copy provider 1.0 (Version
The snapshot technology used by VSS for volume E: – Microsoft Software Shadow Copy provider 1.0 (Version

        Job ended: Wednesday, June 04, 2014 at 2:49:03 AM
Completed status: Failed
Final error: 0xe000fed1 – A failure occurred querying the Writer status. See the job log for details about the error.



issue this command and see if any writer is failing

vssadmin list writers


if System Writer is TIMED OUT, then simply a system restart would fix the error auto. In my case , windows applied some updates, and when I rebooted the server, it fixed the above issue.




2-  Simplified Disaster Recovery: Howto exclude some Folders with SDR ON

Symantec provide Simplified Disaster Recovery option which you can use to restore the whole backup to bare metal system (from scratch) using SDR boot CD. However SDR forces you to backup every critical components including boot drive, system state, or any folder that SDR thinks its critical. But sometimes even excluding a non-critical component can turn off the SDR (for example in my case I was excluding a ‘backup folder’ from G: drive and SDR was turning off , possibly it was thinking that the whole G: drive was critical component for SDR.

For Example:


So in order to forcefully exclude it, I had to use the following WORKAROUND by adding the drive entry in the REGISTRY manually. IMO, So pathetic that SYMANTEC have not added this option in its Backup Exec GUI, because playing with the windows registry can be very dangerous for normal administrators.

Here is an Example of the registry key. If folders from G: were to be excluded, create a new key called “User-Defined Exclusion Resources“.
Under this key create another empty key called “G:
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Backup Exec For Windows\Backup Exec\Engine\Simplified System Protection\User-Defined Exclusion Resources\G:

As showed in the image below …
b2 b2-2.

Now if you try to exclude any folder from the particular drive (in my example it was G:) , SDR will remain ON as showed in the image below ..

3- Backup Exec (2012 SP4) Services Credentials Lost on every Reboot

This was very annoying that on every reboot I had to enter my domain admin credentials in the Backup Exec Services Section Otherwise I receive “Failed to start service dueto Logon Failure”. It seems BE keeps forgetting the credentials or not storing them.


Make sure the account you are using to manage Backup Exec, must have Rights to logon as service (and few others, read the Symantec rights assignment article) add the account in your Domain controller group policy / local security policy / users right assignment. After addition, force update using gpupdate on both ends, first server then client,


To sort this issue, I used BEUTILITY provided with backup exec installation.

For Windows 2008 64bit, Goto C:\Program Files\Symantec\Backup Exec and Open BEUTILITY.EXE

Add your backup exec server in the list (known computers group ,

After adding, Right click on the Server and click con CHANGE SERVICE ACCOUNT

Enter your domain admin account or any account with equivalent rights and click OK,
As showed in the images below …





Now restart and check if the services are starting properly 🙂

At least this tricked worked for me



4- V-79-57344-42009 – Failed to load the configuration xml file [6th June, 2014]

Using Symantec backup Exec 2012 Sp4 , When I take full backup (SDR ON) , it completes successfully but with following error:

Job ended: Thursday, June 05, 2014 at 9:31:29 AM Completed status: Completed with exceptions

Backup- MYSERVER-79-57344-42009 – Failed to load the configuration xml file.
C:\Program Files\Symantec\Backup Exec\Catalogs\AGPSAPDEV\CatalogProcessTemporaryFolder\{6BCA5C76-6547-430D-A0D5-37251330D96D}\p2v.xml

To solve this, I applied Backup Exec 2012 Revision 1798 Hotfix 216746 and problem got solved. Download it and apply , Also dont forget to update the remote agents as well (via using BE GUI). I had to reboot the BE server also after applying this fix.


 5- BARCODE LABELING  [10th June, 2014]

In our company we have IBM TS3100 Library (which ahve 24 Cartridges slots). Using BE, I wanted to Auto Label every cartridge after the backup. I also used INVENTORY option, but it took much time. During the BE inventory process, the tape is taken from its slot, put into the tape drive to have their internal labels read and then returned to their slots.  This process is repeated for each tape and hence the inventory process for a TS3100 can take a long time. For my IBM TS3100 tape library with 24 tapes (only 5 Used) , an inventory of the 5 slots will take around 15-20 minutes. The tape library can identify a tape from its barcode label without having to read the internal label in the tape drive or doing other action.
When there is a need to update the status of the slots in the library in BE, you can use scan instead of inventory if you have barcode labels.  What scan will do is to read the barcode labels and it is done within a couple of seconds.  Otherwise, you would have to do an inventory
Some Snapshots.



You can download the BARCODE GENERATOR from following link.

Just make sure that you use only 8 Digits code, and the code must be end with L5 letter. (FOR IBM LTO5 drives)




For LTO5 cartridge sticker, I used following size for printing the above label.


Put your tapes with the new barcode labels and do a scan of the entire library.Make sure you don’t have a mix of tapes with and without barcode labels.


6- Exclude a sub-folder name “xyz” from every where in specific folder/drive. [25th June, 2014]

Recently I upgraded my file server from Windows 2003 NT.Backup to Windows 2008 R2 Backup Exec 2014. I have a following directory structure …


–  User1
–  Daily_Data
–  Junk_Data

–  User2
–  Daily_Data
–  Junk_Data

–  User3
–  Daily_Data
–  Junk_Data

and so on , users numbers are around 300. I want to exclude “Junk_Data” from every folder, Exclude them one by one is a lengthy task. I exclude Junk_Data from every sub folder by defining following criteria.

(which means for every user folder Exclude junk_data)


Exclude all sub-folders name end with .ft from every where in specific folder/drive. [15th July, 2014]

Lotus domino have every users folder design data which are not necessary to backup. to exclude every folder which have .ft in end, use following.



7- Remote Agent Service not starting at Client PC/Server / NDMP Port already in use error  [27/8/2014]

Today , when I tried to backup one of our server (Lotus Sametime), Backup exec could not browse the server, When I checked at client server, backup remote agent service was not starting giving following error.




because of conflict with NDMP port.

SOLUTION  . At client server goto C:\WINDOWS\system32\drivers\etc and open file name SERVICES

ADD this line.

ndmp          12000/tcp # Backup Exec Remote agent ndmp port changed / zaib

save and exit,

now start remote agent utility server and it will work :D, at least it did for me.





aacable at

%d bloggers like this: