﻿<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://owl.unipharm.com/mediawiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Danielc</id>
	<title>uniWIKI - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://owl.unipharm.com/mediawiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Danielc"/>
	<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php/Special:Contributions/Danielc"/>
	<updated>2026-09-01T12:15:49Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.35.4</generator>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Automatic_Email_Manager&amp;diff=14734</id>
		<title>Information Systems:Automatic Email Manager</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Automatic_Email_Manager&amp;diff=14734"/>
		<updated>2025-05-01T18:26:10Z</updated>

		<summary type="html">&lt;p&gt;Danielc: /* Overview */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
&lt;br /&gt;
Automatic Email Manager refers to software that periodically checks mailboxes (inboxes) and performs actions. It was acquired primarily to facilitate an important part of the SRFax workflow [http://owl.unipharm.local/mediawiki/index.php/Information_Systems:SRFax_(desktop_faxing)_Administration#Automatic_Email_Manager (the auto-printing of inbound faxes)], but it is a generic utility that can be used for other purposes.&lt;br /&gt;
&lt;br /&gt;
The software is installed on (172.30.18.17), under a perpetual license that was purchased from their site in May, 2018.&lt;br /&gt;
&lt;br /&gt;
 Your license name is: admin@unipharm.com&lt;br /&gt;
 The registration number is: 156285579-5619449231T-8263123240445380&lt;br /&gt;
&lt;br /&gt;
==Configuration==&lt;br /&gt;
The software should be intuitive to any technical admin and does not require elaborate documentation. &amp;quot;Your Accounts&amp;quot; contains the emails being checked. &amp;quot;Actions&amp;quot; contains the actions. RTFM for the rest.&lt;br /&gt;
&lt;br /&gt;
The monitored emails are (@unipharm.com):&lt;br /&gt;
* accountingautoprint&lt;br /&gt;
* faxangelac&lt;br /&gt;
* faxelaho&lt;br /&gt;
* faxreceiving&lt;br /&gt;
* faxrong&lt;br /&gt;
* faxstein&lt;br /&gt;
* datamon&lt;br /&gt;
&lt;br /&gt;
Note: These target email addresses are MDaemon accounts.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes==&lt;br /&gt;
* A second use of this software is for Accounting to forward emails with many attached PDFs to an AEM email to autoprint the attachements on that printer.&lt;br /&gt;
* Another use for this is to save attachments from emails received on the Data Monitor account (for Integrator) to a folder.&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:CheqMaster&amp;diff=14727</id>
		<title>Information Systems:CheqMaster</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:CheqMaster&amp;diff=14727"/>
		<updated>2025-03-13T16:17:29Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Overview=&lt;br /&gt;
Cheque Master a.k.a. Chequemaster is used to print cheques in A/P.&lt;br /&gt;
&lt;br /&gt;
We do not print cheques on the i (i.e ASW); instead we use a PC package that prints as well as keeping a cheque register.  The cheque is generated by ASW, but instead of printing, the spool file is sent to the IFS, where Cheque Master can read and process it.  When completed, the file is moved to an archive folder.&lt;br /&gt;
&lt;br /&gt;
==Technical Support==&lt;br /&gt;
&lt;br /&gt;
 Michael Guenzel (pronounced Gun zel, accent on second syllable)&lt;br /&gt;
 VisionCraft&lt;br /&gt;
 Suite 1600 Sun Life Plaza&lt;br /&gt;
 144 - 4th Avenue SW&lt;br /&gt;
 Calgary, Alberta, Canada   T2P 3N4&lt;br /&gt;
 Tel: (403) 232-6080 or (800) 265-6080&lt;br /&gt;
 Fax: (403) 547-6213&lt;br /&gt;
 mguenzel@visioncraft.com&lt;br /&gt;
&lt;br /&gt;
==iSeries Setup==&lt;br /&gt;
&lt;br /&gt;
Created an outq named CHEQUE in library QUSRSYS, which is not attached to a printer, but will be used to store the spool file until the cheques have printed.&lt;br /&gt;
&lt;br /&gt;
Created a folder named ChqMaster in the IFS, that contains the VISION programs, cheque printing files, and an archive folder of completed cheque files.&lt;br /&gt;
&lt;br /&gt;
Created a data file named APCHEQUE, that the spool files will be copied into. &lt;br /&gt;
&lt;br /&gt;
Changed the RPGLE program FLR128 (Cheque printout - Blank stock) to put the cheque spool file into the outq CHEQUE, with a status of HOLD.&lt;br /&gt;
&lt;br /&gt;
Changed the CLLE program FLC128 (Cheque printout – Blank stock) to copy the spool file to the file APCHEQUE, and then to ChqMaster in the IFS.&lt;br /&gt;
&lt;br /&gt;
==Cheque Printer==&lt;br /&gt;
The cheque printer is an HP LaserJet printer capable of printing MICR font. It is served on the network by superserver as '''chqprt'''. This device name is important for the program to recognize it.&lt;br /&gt;
&lt;br /&gt;
Cheqmaster is set to print to port LPT2 (via a setting in General Administration). Since this is a physical port, the CHEQUES2 bat file that is used to start Cheqmaster issues a &amp;lt;code&amp;gt;net use&amp;lt;/code&amp;gt; command to specify/spoof the network printer chqprt as existing on port LPT2. &lt;br /&gt;
&lt;br /&gt;
==Signatures==&lt;br /&gt;
&lt;br /&gt;
The signature tool (signature.exe) is on tech/common/iSeries/Vision AP Cheques/signature.  However, as it is a .net application, it will not currently run from a network drive, so it must be (temporarily) copied to a local drive. &lt;br /&gt;
&lt;br /&gt;
The first step is to print the Signature Template (the form to be used to scan in signatures).  Load the signature tool, and press the template button.  Select the printer, press Print, then OK.  &lt;br /&gt;
&lt;br /&gt;
Have the signing officers sign this sheet.  Note that in our test, the signature had to be approximately a quarter of an inch in from the side borders.  Scan the sheet as TIF, black and white, at 300 dpi.&lt;br /&gt;
&lt;br /&gt;
Go back into the signature tool.  Press the Graphic File Select button, highlight the scanned file, and press Open.  The template will appear in the box to the left.  Click on the black square to the upper left to select a signature.&lt;br /&gt;
&lt;br /&gt;
The selected signature will appear in the Signature box to the right.  Use the scroll bars to center it between the lines.  &lt;br /&gt;
&lt;br /&gt;
Go to the Signature ID box and select either the Top or Bottom Signature.  Press the Output File Select button.  The selections will be automatically set for current directory, with the correct file name for the chosen signature ID, and the correct type.  Press Save.  Note, however, that this does NOT save the object; it just does the preparation.  Press the Save button in the lower right corner to write the selected output file.&lt;br /&gt;
&lt;br /&gt;
Repeat for both the top and bottom signature.  When complete, copy visionB.bin and visionT.bin to the finance/vision folder on the iSeries.&lt;br /&gt;
&lt;br /&gt;
It is possible to adjust the positions of the signatures and the micr line.  Edit the text file MICR_ADJ.VCD to do this.  The first pair of numbers is the X and Y co-ordinates of the micr line, the middle pair is the top signature, and the last pair is the bottom signature.  ‘+’ means down or to the right.  ‘-‘ is up or to the left.  The unit of measure is 300th of an inch.  Be very careful to make no other changes to this file.&lt;br /&gt;
&lt;br /&gt;
==Print A/P Cheques==&lt;br /&gt;
&lt;br /&gt;
Create A/P payment proposal, and do any maintenance necessary.  When ready, do an option 8 – payment order.  This will generate cheques, but will not print them.  Instead the spool file will be copied to a shared folder, from where a PC cheque application will be able to print them.  &lt;br /&gt;
&lt;br /&gt;
Using explorer, double click on the drive mapped to finance/vision on BART.  Key in your user ID and password to allow you to access the application and cheque printing files.  This step only has to be done once a day.&lt;br /&gt;
&lt;br /&gt;
Click on the A/P Cheque icon, and print cheques.&lt;br /&gt;
&lt;br /&gt;
When the cheques have been successfully printed, go back to the iSeries.  Confirm and update the A/P payment proposal.  &lt;br /&gt;
&lt;br /&gt;
Eventually, the outq and the APCHEQUES data file will have to be cleared.&lt;br /&gt;
&lt;br /&gt;
==Potential Problems==&lt;br /&gt;
&lt;br /&gt;
====Signatures====&lt;br /&gt;
&lt;br /&gt;
If either the signatures or the micr line are not in the correct location, they can be moved.  See the section on ‘Signatures’ for instructions on how to this. &lt;br /&gt;
&lt;br /&gt;
====Load forms first====&lt;br /&gt;
&lt;br /&gt;
Cheque forms must be loaded before printing starts. If the cheque printer does not have cheque forms loaded, nothing will print. When this happens, cheques must be voided and recreated.&lt;br /&gt;
&lt;br /&gt;
====Error message when reading cheque file====&lt;br /&gt;
&lt;br /&gt;
Message is “An unrecoverable error occurred during the preview scanning of the current file – call Vision Craft at 403-232-6000 for assistance”. Only the person that creates the cheque file in ASW can print it with ChqMaster.  Whoever logged onto the computer (Windows logon) needs authority to the cheque files. Any IT person can go into iSeries Navigator and change the permissions on the cheque files.&lt;br /&gt;
&lt;br /&gt;
====Disappearing data / signatures (really a printing issue)====&lt;br /&gt;
&lt;br /&gt;
The transit # in the MICR line was changed in the test system to prepare for corporate clearing.  Nancy turned off signatures, printed cheques from an old test file, and they looked fine. A few minutes later, when Mary printed production cheques, they came out blank, except for variable data -- no headings, no company name, no MICR line. We reset the printer, and Mary backed out of Chqmaster and went back in, but she still got an unusual message about signatures. We thought it was okay for her to proceed. Everything looked okay (including transit #), except the production cheques were missing signatures.&lt;br /&gt;
&lt;br /&gt;
ANSWER: Mary got the message about the signatures because the file had already been printed. Chqmaster was flagging that a supervisor would need to be involved for signatures on the second run.&lt;br /&gt;
&lt;br /&gt;
The reason the headings, company name, MICR line, etc. were dropped on Mary's first cheque run -- a coincidence of timing. Between Mary's pressing F1 and printing the cheques, Nancy logged out of Chqmaster. The act of logging out deleted all the data that Mary's F1 had set up. In short, the printer was made unready to receive Chqmaster data.&lt;br /&gt;
&lt;br /&gt;
====User cannot print or connect to printer====&lt;br /&gt;
One of the steps in the CheqMaster routine is Initialize Printer, in which the program tries to connect to a printer on port LPT2. If this step doesn't work, the program was likely run via the executable, cheques.exe, rather than the batch file, which sets up the printer port first. Run CHEQUES2.bat instead.&lt;br /&gt;
&lt;br /&gt;
==Edit MICR code using Chqmaster menu==&lt;br /&gt;
&lt;br /&gt;
Log into Cheque Master. The program is cheques.exe, but the desktop icon is the easiest way to get in. Id and password are in CONFIGUR.VCD, which can be emailed to Michael Guenzel mguenzel@vision-craft.com in the event of a problem. First try restoring the contents of ChqMaster from the most recent backup.&lt;br /&gt;
&lt;br /&gt;
From the Main Menu, F6 Administration&lt;br /&gt;
&lt;br /&gt;
F3 Forms Maintenance: There will be 3 forms – CAD, USD, and Imp and three actions – add, change, delete.&lt;br /&gt;
&lt;br /&gt;
F2 Change / Select form (CAD)&lt;br /&gt;
&lt;br /&gt;
F8 Edit MICR line:  overtype field to be changed (e.g., change branch transit number 00900 to 30120)&lt;br /&gt;
&lt;br /&gt;
Press Enter&lt;br /&gt;
&lt;br /&gt;
F9 repeatedly to get out&lt;br /&gt;
&lt;br /&gt;
Print a test cheque&lt;br /&gt;
&lt;br /&gt;
=Technical Notes=&lt;br /&gt;
&lt;br /&gt;
* The cheque file is simply a text file with a .dat extension. It can be opened with Notepad to examine the cheque data for troubleshooting purposes. *DO NOT ALTER THE FILE UNDER ANY CIRCUMSTANCES.*&lt;br /&gt;
* The cheque file is placed on the IFS. Ensure that the user generating cheques has read/write privileges to the IFS share, otherwise the process will stop mid-way and no file will be available to print.&lt;br /&gt;
* Following the Windows 11 24H2 update, Legacy Console hosting has been disabled by default. However, Cheqmaster requires this feature to display correctly.&lt;br /&gt;
To resolve this, we need to log in with an administrator account on the affected user PCs and manually re-enable Legacy Console hosting by following these steps:&lt;br /&gt;
1.	Open Start &amp;gt; Settings &amp;gt; System &amp;gt; Optional features&lt;br /&gt;
2.	Click Add an optional feature&lt;br /&gt;
3.	Search for Legacy Console hosting and install it&lt;br /&gt;
&lt;br /&gt;
Tags: Cheque master, Chequemaster&lt;br /&gt;
[[Category: Software connected to IBM i]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14712</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14712"/>
		<updated>2024-10-09T21:36:49Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || Newvisionit! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || Cisco CBS250 || Candy Mezzanine || adminit || Newvisionit! || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| OTC-SWITCH || 172.30.16.20 || Cisco CBS350 || OTC-Picking Station || OTC-SWITCH || Gu20Da51NewEra ||&lt;br /&gt;
|-&lt;br /&gt;
| HABA-SWITCH || 172.30.16.21 || Cisco CBS350 || HABA-Picking Station || HABA-SWITCH || Gu20Da51NewEra ||&lt;br /&gt;
|-&lt;br /&gt;
| HHC-SWITCH || 172.30.16.26 || Cisco CBS350 || HHC-Picking Station || HHC-SWITCH || Gu20Da51NewEra ||&lt;br /&gt;
|-&lt;br /&gt;
| TEST-SWITCH || 172.30.16.23 || Cisco CBS350 || Outside Jeremy's office || TEST-SWITCH || Gu20Da51NewEra ||&lt;br /&gt;
|-&lt;br /&gt;
| DCTEST-SWITCH || 172.30.16.24 || Cisco CBS350 || Manager's Office in DC || DCTEST-SWITCH || Gu20Da51NewEra ||&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Information_Systems:MobiControl_Cloud&amp;diff=14673</id>
		<title>Information Systems:Information Systems:MobiControl Cloud</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Information_Systems:MobiControl_Cloud&amp;diff=14673"/>
		<updated>2024-05-08T22:52:01Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Step 1: Set Up Android Enterprise&lt;br /&gt;
&lt;br /&gt;
Enroll in Android Enterprise: Access the Google Play Console and sign up for an Android Enterprise account if you haven't already.&lt;br /&gt;
Create an Enterprise Service Account: Generate an enterprise service account, which will serve as the link between your MobiControl Cloud instance and Android Enterprise.&lt;br /&gt;
Link MobiControl Cloud with Android Enterprise: Navigate to the Android Enterprise section within the MobiControl Cloud console and follow the provided instructions to integrate your account. Ensure to input the generated service account credentials for authentication.&lt;br /&gt;
&lt;br /&gt;
Step 2: Configure Device Profiles&lt;br /&gt;
&lt;br /&gt;
Create Device Configuration Profiles: Within the MobiControl Cloud console, proceed to the &amp;quot;Profiles&amp;quot; or &amp;quot;Configurations&amp;quot; section and initiate the creation of a new configuration profile tailored for your barcode scanners.&lt;br /&gt;
Configure General Settings: Establish fundamental device parameters such as Wi-Fi configurations, VPN settings, and passcode policies.&lt;br /&gt;
Define App Policies: Specify which applications are permissible or prohibited on the barcode scanners. Additionally, set up app configurations for specific apps if required.&lt;br /&gt;
Establish Network Policies: Customize network settings to enable secure connectivity of the barcode scanners with your organization's resources.&lt;br /&gt;
Set Restrictions: Implement restrictions on device functionalities and features in accordance with your organization's security and compliance mandates.&lt;br /&gt;
&lt;br /&gt;
Step 3: Apply Profiles to Devices&lt;br /&gt;
&lt;br /&gt;
Create Device Groups: Group your barcode scanner devices logically based on factors like departments, locations, or other relevant criteria.&lt;br /&gt;
Assign Profiles: Select the appropriate configuration profiles you created earlier and allocate them to the respective device groups containing the barcode scanners. This ensures that the designated settings and policies are applied uniformly across the devices within each group.&lt;br /&gt;
&lt;br /&gt;
Recover&lt;br /&gt;
&lt;br /&gt;
go to enter the recovery menu.&lt;br /&gt;
&lt;br /&gt;
To do this on a SX5, while the device is powered off, long hold the power button + scan right until the first Datalogic logo appears, then release both.&lt;br /&gt;
&lt;br /&gt;
From the recovery menu follow the instructions on screen to factory reset the device.&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Information_Systems:MobiControl_Cloud&amp;diff=14672</id>
		<title>Information Systems:Information Systems:MobiControl Cloud</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Information_Systems:MobiControl_Cloud&amp;diff=14672"/>
		<updated>2024-05-07T23:27:03Z</updated>

		<summary type="html">&lt;p&gt;Danielc: Created page with &amp;quot;Step 1: Set Up Android Enterprise  Enroll in Android Enterprise: Access the Google Play Console and sign up for an Android Enterprise account if you haven't already. Create an...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Step 1: Set Up Android Enterprise&lt;br /&gt;
&lt;br /&gt;
Enroll in Android Enterprise: Access the Google Play Console and sign up for an Android Enterprise account if you haven't already.&lt;br /&gt;
Create an Enterprise Service Account: Generate an enterprise service account, which will serve as the link between your MobiControl Cloud instance and Android Enterprise.&lt;br /&gt;
Link MobiControl Cloud with Android Enterprise: Navigate to the Android Enterprise section within the MobiControl Cloud console and follow the provided instructions to integrate your account. Ensure to input the generated service account credentials for authentication.&lt;br /&gt;
&lt;br /&gt;
Step 2: Configure Device Profiles&lt;br /&gt;
&lt;br /&gt;
Create Device Configuration Profiles: Within the MobiControl Cloud console, proceed to the &amp;quot;Profiles&amp;quot; or &amp;quot;Configurations&amp;quot; section and initiate the creation of a new configuration profile tailored for your barcode scanners.&lt;br /&gt;
Configure General Settings: Establish fundamental device parameters such as Wi-Fi configurations, VPN settings, and passcode policies.&lt;br /&gt;
Define App Policies: Specify which applications are permissible or prohibited on the barcode scanners. Additionally, set up app configurations for specific apps if required.&lt;br /&gt;
Establish Network Policies: Customize network settings to enable secure connectivity of the barcode scanners with your organization's resources.&lt;br /&gt;
Set Restrictions: Implement restrictions on device functionalities and features in accordance with your organization's security and compliance mandates.&lt;br /&gt;
&lt;br /&gt;
Step 3: Apply Profiles to Devices&lt;br /&gt;
&lt;br /&gt;
Create Device Groups: Group your barcode scanner devices logically based on factors like departments, locations, or other relevant criteria.&lt;br /&gt;
Assign Profiles: Select the appropriate configuration profiles you created earlier and allocate them to the respective device groups containing the barcode scanners. This ensures that the designated settings and policies are applied uniformly across the devices within each group.&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14647</id>
		<title>Information Systems:Building Power</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14647"/>
		<updated>2024-01-17T23:34:24Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
uniPHARM uses a generator to provide power in the event of a hydro outage. As the generator requires time to start and become ready, there is a large UPS in the server room that provides the room and select outlets throughout the building with continuous power. &lt;br /&gt;
&lt;br /&gt;
==Design==&lt;br /&gt;
The attached JPG is a diagram of how electric power is organized in the Server room.  The rack closest to the door and the middle rack are fed power from the Liebert UPS which filters power from Hydro or in the event of a Hydro failure, the generator.  The rack farthest from the door containing the Power8 hardware has 2 different power feeds, one from the Liebert UPS and the other straight from Hydro.  The second feed from Hydro plugs into the Power8 UPS at the bottom of that rack.  The Power8 rack has each of its 2 feeds of power protected by a UPS so even if 1 UPS fails or drains, the other UPS will still provide electricity so that the Power8 will remain up.  The only way that the Power8 system will go down is if both UPS's fail AND we have Hydro AND generator failure.  Highly unlikely.  &lt;br /&gt;
==UPS==&lt;br /&gt;
The main UPS is a Liebert APS unit (12kVA,with max capacity of 20kVA),The warranty included with the purchase of the device will expire in January 2026. There is an Eaton (400ish VA) UPS in the rack dedicated to the Power server and its related components (disk enclosure etc.)&lt;br /&gt;
&lt;br /&gt;
The technical support number and account information for Liebert is on the top right side of the UPS.&lt;br /&gt;
&lt;br /&gt;
 Support for Liebert UPS&lt;br /&gt;
 * Support phone number: 1-800-543-2378&lt;br /&gt;
 * Support phone number (direct): +1-800-222-5877 (ext 2 for Liebert, ext 2 for Geist)&lt;br /&gt;
 * Device model: Nfinity Power System&lt;br /&gt;
 * Device serial number: 2316100003AU063&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 Support for Eaton UPS&lt;br /&gt;
 * 1-800-356-5737&lt;br /&gt;
&lt;br /&gt;
[[File:Server Room Power Diagram Jan 2015.jpg|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Web page of Liebert APS UPS==&lt;br /&gt;
IP:172.30.18.228&lt;br /&gt;
&lt;br /&gt;
Username: administrator&lt;br /&gt;
&lt;br /&gt;
Password: NewVisionIT2051!&lt;br /&gt;
&lt;br /&gt;
Alert message will send to: itgroup@unipharm.com&lt;br /&gt;
&lt;br /&gt;
Zabbix polls this agent via SNMP - both voltage and battery stats can be viewed.&lt;br /&gt;
&lt;br /&gt;
==Insights on the future of Liebert UPS==&lt;br /&gt;
(Jan 2024) Unipharm updated the UPS equipment, and the current model is Liebert APS. Considering that the equipment in the IT room may be migrated to the cloud in the future, we reduced the UPS battery from 20KVA to 12KVA. However, this model of equipment is scalable. If necessary in the future, we can purchase battery modules to expand it to 20KVA.&lt;br /&gt;
&lt;br /&gt;
[[Category: Power, Alarms, and Monitoring]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14646</id>
		<title>Information Systems:Building Power</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14646"/>
		<updated>2024-01-17T23:30:01Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
uniPHARM uses a generator to provide power in the event of a hydro outage. As the generator requires time to start and become ready, there is a large UPS in the server room that provides the room and select outlets throughout the building with continuous power. &lt;br /&gt;
&lt;br /&gt;
==Design==&lt;br /&gt;
The attached JPG is a diagram of how electric power is organized in the Server room.  The rack closest to the door and the middle rack are fed power from the Liebert UPS which filters power from Hydro or in the event of a Hydro failure, the generator.  The rack farthest from the door containing the Power8 hardware has 2 different power feeds, one from the Liebert UPS and the other straight from Hydro.  The second feed from Hydro plugs into the Power8 UPS at the bottom of that rack.  The Power8 rack has each of its 2 feeds of power protected by a UPS so even if 1 UPS fails or drains, the other UPS will still provide electricity so that the Power8 will remain up.  The only way that the Power8 system will go down is if both UPS's fail AND we have Hydro AND generator failure.  Highly unlikely.  &lt;br /&gt;
==UPS==&lt;br /&gt;
The main UPS is a Liebert Nfinity unit (12kVA,with max capacity of 20kVA). There is an Eaton (400ish VA) UPS in the rack dedicated to the Power server and its related components (disk enclosure etc.)&lt;br /&gt;
&lt;br /&gt;
The technical support number and account information for Liebert is on the top right side of the UPS.&lt;br /&gt;
&lt;br /&gt;
 Support for Liebert UPS&lt;br /&gt;
 * Support phone number: 1-800-543-2378&lt;br /&gt;
 * Support phone number (direct): +1-800-222-5877 (ext 2 for Liebert, ext 2 for Geist)&lt;br /&gt;
 * Device model: Nfinity Power System&lt;br /&gt;
 * Device serial number: 2316100003AU063&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 Support for Eaton UPS&lt;br /&gt;
 * 1-800-356-5737&lt;br /&gt;
&lt;br /&gt;
[[File:Server Room Power Diagram Jan 2015.jpg|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==web page of Liebert UPS==&lt;br /&gt;
IP:172.30.18.228&lt;br /&gt;
&lt;br /&gt;
Username: administrator&lt;br /&gt;
&lt;br /&gt;
Password: NewVisionIT2051!&lt;br /&gt;
&lt;br /&gt;
Alert message will send to: itgroup@unipharm.com&lt;br /&gt;
&lt;br /&gt;
Zabbix polls this agent via SNMP - both voltage and battery stats can be viewed.&lt;br /&gt;
&lt;br /&gt;
==Insights on the future of Liebert UPS==&lt;br /&gt;
(Jan 2024) Unipharm updated the UPS equipment, and the current model is Liebert APS. Considering that the equipment in the IT room may be migrated to the cloud in the future, we reduced the UPS battery from 20KVA to 12KVA. However, this model of equipment is scalable. If necessary in the future, we can purchase battery modules to expand it to 20KVA.&lt;br /&gt;
&lt;br /&gt;
[[Category: Power, Alarms, and Monitoring]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14645</id>
		<title>Information Systems:Building Power</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14645"/>
		<updated>2024-01-17T23:29:29Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
uniPHARM uses a generator to provide power in the event of a hydro outage. As the generator requires time to start and become ready, there is a large UPS in the server room that provides the room and select outlets throughout the building with continuous power. &lt;br /&gt;
&lt;br /&gt;
==Design==&lt;br /&gt;
The attached JPG is a diagram of how electric power is organized in the Server room.  The rack closest to the door and the middle rack are fed power from the Liebert UPS which filters power from Hydro or in the event of a Hydro failure, the generator.  The rack farthest from the door containing the Power8 hardware has 2 different power feeds, one from the Liebert UPS and the other straight from Hydro.  The second feed from Hydro plugs into the Power8 UPS at the bottom of that rack.  The Power8 rack has each of its 2 feeds of power protected by a UPS so even if 1 UPS fails or drains, the other UPS will still provide electricity so that the Power8 will remain up.  The only way that the Power8 system will go down is if both UPS's fail AND we have Hydro AND generator failure.  Highly unlikely.  &lt;br /&gt;
==UPS==&lt;br /&gt;
The main UPS is a Liebert Nfinity unit (12kVA,with max capacity of 20kVA). There is an Eaton (400ish VA) UPS in the rack dedicated to the Power server and its related components (disk enclosure etc.)&lt;br /&gt;
&lt;br /&gt;
The technical support number and account information for Liebert is on the top right side of the UPS.&lt;br /&gt;
&lt;br /&gt;
 Support for Liebert UPS&lt;br /&gt;
 * Support phone number: 1-800-543-2378&lt;br /&gt;
 * Support phone number (direct): +1-800-222-5877 (ext 2 for Liebert, ext 2 for Geist)&lt;br /&gt;
 * Device model: Nfinity Power System&lt;br /&gt;
 * Device serial number: 2316100003AU063&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 Support for Eaton UPS&lt;br /&gt;
 * 1-800-356-5737&lt;br /&gt;
&lt;br /&gt;
[[File:Server Room Power Diagram Jan 2015.jpg|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==web page of Liebert UPS==&lt;br /&gt;
IP:172.30.18.228&lt;br /&gt;
Username: administrator&lt;br /&gt;
Password: NewVisionIT2051!&lt;br /&gt;
Alert message will send to: itgroup@unipharm.com&lt;br /&gt;
&lt;br /&gt;
Zabbix polls this agent via SNMP - both voltage and battery stats can be viewed.&lt;br /&gt;
&lt;br /&gt;
==Insights on the future of Liebert UPS==&lt;br /&gt;
(Jan 2024) Unipharm updated the UPS equipment, and the current model is Liebert APS. Considering that the equipment in the IT room may be migrated to the cloud in the future, we reduced the UPS battery from 20KVA to 12KVA. However, this model of equipment is scalable. If necessary in the future, we can purchase battery modules to expand it to 20KVA.&lt;br /&gt;
&lt;br /&gt;
[[Category: Power, Alarms, and Monitoring]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14644</id>
		<title>Information Systems:Building Power</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14644"/>
		<updated>2024-01-17T23:19:51Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
uniPHARM uses a generator to provide power in the event of a hydro outage. As the generator requires time to start and become ready, there is a large UPS in the server room that provides the room and select outlets throughout the building with continuous power. &lt;br /&gt;
&lt;br /&gt;
==Design==&lt;br /&gt;
The attached JPG is a diagram of how electric power is organized in the Server room.  The rack closest to the door and the middle rack are fed power from the Liebert UPS which filters power from Hydro or in the event of a Hydro failure, the generator.  The rack farthest from the door containing the Power8 hardware has 2 different power feeds, one from the Liebert UPS and the other straight from Hydro.  The second feed from Hydro plugs into the Power8 UPS at the bottom of that rack.  The Power8 rack has each of its 2 feeds of power protected by a UPS so even if 1 UPS fails or drains, the other UPS will still provide electricity so that the Power8 will remain up.  The only way that the Power8 system will go down is if both UPS's fail AND we have Hydro AND generator failure.  Highly unlikely.  &lt;br /&gt;
==UPS==&lt;br /&gt;
The main UPS is a Liebert Nfinity unit (12kVA,with max capacity of 20kVA). There is an Eaton (400ish VA) UPS in the rack dedicated to the Power server and its related components (disk enclosure etc.)&lt;br /&gt;
&lt;br /&gt;
The technical support number and account information for Liebert is on the top right side of the UPS.&lt;br /&gt;
&lt;br /&gt;
 Support for Liebert UPS&lt;br /&gt;
 * Support phone number: 1-800-543-2378&lt;br /&gt;
 * Support phone number (direct): +1-800-222-5877 (ext 2 for Liebert, ext 2 for Geist)&lt;br /&gt;
 * Device model: Nfinity Power System&lt;br /&gt;
 * Device serial number: 2316100003AU063&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 Support for Eaton UPS&lt;br /&gt;
 * 1-800-356-5737&lt;br /&gt;
&lt;br /&gt;
[[File:Server Room Power Diagram Jan 2015.jpg|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==web page of Liebert UPS==&lt;br /&gt;
IP:172.30.18.228&lt;br /&gt;
Username: administrator&lt;br /&gt;
Password: NewVisionIT2051!&lt;br /&gt;
&lt;br /&gt;
Zabbix polls this agent via SNMP - both voltage and battery stats can be viewed.&lt;br /&gt;
&lt;br /&gt;
==Insights on the future of Liebert UPS==&lt;br /&gt;
(April 2021) This information originates from a conversation with both a tech support rep and a field agent (Jas) regarding the future of the UPS&lt;br /&gt;
&lt;br /&gt;
* Usually, 15 years is when they advise customers to ''start planning'' for a replacement. The Liebert is on its 14th year as of April 2021.&lt;br /&gt;
* The Nfinity line of UPS that we have is end of life, but the units are still solid. The replacement product line is Liebert APS.&lt;br /&gt;
* The current UPS is a modular, 20kVA-capable unit with 12kVA configured across 4 batteries that are independent of each other (or at least the whole thing is resilient to a 1-2 battery failure). &lt;br /&gt;
* Apparently, a possible improvement that could be implemented during replacement (would likely incur additional cost) is to decouple the UPS bypass switch/mechanism from the UPS, to make it easier to switch to hydro. A panel similar to a circuit breaker would be installed, with a large switch that would flip the power to hydro or back through UPS (and then hydro). However, when the agent was on-site, they were able to put the UPS into bypass mode without any interruption (they do this during maintenance visits), so I'm not sure what advantage this new design would have.&lt;br /&gt;
* Lithium-ion is starting to be introduced, but is not feasible/available yet for the type of UPS we would be getting. This is bound to change rapidly. The advantage to this is obviously better battery tech and smaller footprint.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Power, Alarms, and Monitoring]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14643</id>
		<title>Information Systems:Building Power</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Building_Power&amp;diff=14643"/>
		<updated>2024-01-17T23:19:25Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
uniPHARM uses a generator to provide power in the event of a hydro outage. As the generator requires time to start and become ready, there is a large UPS in the server room that provides the room and select outlets throughout the building with continuous power. &lt;br /&gt;
&lt;br /&gt;
==Design==&lt;br /&gt;
The attached JPG is a diagram of how electric power is organized in the Server room.  The rack closest to the door and the middle rack are fed power from the Liebert UPS which filters power from Hydro or in the event of a Hydro failure, the generator.  The rack farthest from the door containing the Power8 hardware has 2 different power feeds, one from the Liebert UPS and the other straight from Hydro.  The second feed from Hydro plugs into the Power8 UPS at the bottom of that rack.  The Power8 rack has each of its 2 feeds of power protected by a UPS so even if 1 UPS fails or drains, the other UPS will still provide electricity so that the Power8 will remain up.  The only way that the Power8 system will go down is if both UPS's fail AND we have Hydro AND generator failure.  Highly unlikely.  &lt;br /&gt;
==UPS==&lt;br /&gt;
The main UPS is a Liebert Nfinity unit (12kVA,with max capacity of 20kVA). There is an Eaton (400ish VA) UPS in the rack dedicated to the Power server and its related components (disk enclosure etc.)&lt;br /&gt;
&lt;br /&gt;
The technical support number and account information for Liebert is on the top right side of the UPS.&lt;br /&gt;
&lt;br /&gt;
 Support for Liebert UPS&lt;br /&gt;
 * Support phone number: 1-800-543-2378&lt;br /&gt;
 * Support phone number (direct): +1-800-222-5877 (ext 2 for Liebert, ext 2 for Geist)&lt;br /&gt;
 * Device model: Nfinity Power System&lt;br /&gt;
 * Device serial number: 2316100003AU063&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 Support for Eaton UPS&lt;br /&gt;
 * 1-800-356-5737&lt;br /&gt;
&lt;br /&gt;
[[File:Server Room Power Diagram Jan 2015.jpg|400px]]&lt;br /&gt;
[[File:Model-SN-Numbers-For-EatonUPS.jpg|400px]]&lt;br /&gt;
&lt;br /&gt;
==web page of Liebert UPS==&lt;br /&gt;
IP:172.30.18.228&lt;br /&gt;
Username: administrator&lt;br /&gt;
Password: NewVisionIT2051!&lt;br /&gt;
&lt;br /&gt;
Zabbix polls this agent via SNMP - both voltage and battery stats can be viewed.&lt;br /&gt;
&lt;br /&gt;
==Insights on the future of Liebert UPS==&lt;br /&gt;
(April 2021) This information originates from a conversation with both a tech support rep and a field agent (Jas) regarding the future of the UPS&lt;br /&gt;
&lt;br /&gt;
* Usually, 15 years is when they advise customers to ''start planning'' for a replacement. The Liebert is on its 14th year as of April 2021.&lt;br /&gt;
* The Nfinity line of UPS that we have is end of life, but the units are still solid. The replacement product line is Liebert APS.&lt;br /&gt;
* The current UPS is a modular, 20kVA-capable unit with 12kVA configured across 4 batteries that are independent of each other (or at least the whole thing is resilient to a 1-2 battery failure). &lt;br /&gt;
* Apparently, a possible improvement that could be implemented during replacement (would likely incur additional cost) is to decouple the UPS bypass switch/mechanism from the UPS, to make it easier to switch to hydro. A panel similar to a circuit breaker would be installed, with a large switch that would flip the power to hydro or back through UPS (and then hydro). However, when the agent was on-site, they were able to put the UPS into bypass mode without any interruption (they do this during maintenance visits), so I'm not sure what advantage this new design would have.&lt;br /&gt;
* Lithium-ion is starting to be introduced, but is not feasible/available yet for the type of UPS we would be getting. This is bound to change rapidly. The advantage to this is obviously better battery tech and smaller footprint.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Power, Alarms, and Monitoring]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14621</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14621"/>
		<updated>2024-01-13T20:24:09Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || Newvisionit! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || Cisco CBS250 || Candy Mezzanine || adminit || Newvisionit! || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| OTC-SWITCH || 172.30.16.20 || Cisco CBS350 || OTC-Picking Station || OTC-SWITCH || Gu20Da51NewEra ||&lt;br /&gt;
|-&lt;br /&gt;
| HABA-SWITCH || 172.30.16.21 || Cisco CBS350 || HABA-Picking Station || HABA-SWITCH || Gu20Da51NewEra ||&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Automatic_Email_Manager&amp;diff=14575</id>
		<title>Information Systems:Automatic Email Manager</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Automatic_Email_Manager&amp;diff=14575"/>
		<updated>2023-12-28T20:54:38Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
&lt;br /&gt;
Automatic Email Manager refers to software that periodically checks mailboxes (inboxes) and performs actions. It was acquired primarily to facilitate an important part of the SRFax workflow [http://owl.unipharm.local/mediawiki/index.php/Information_Systems:SRFax_(desktop_faxing)_Administration#Automatic_Email_Manager (the auto-printing of inbound faxes)], but it is a generic utility that can be used for other purposes.&lt;br /&gt;
&lt;br /&gt;
The software is installed on WDS(172.30.18.17), under a perpetual license that was purchased from their site in May, 2018.&lt;br /&gt;
&lt;br /&gt;
 Your license name is: admin@unipharm.com&lt;br /&gt;
 The registration number is: 156285579-5619449231T-8263123240445380&lt;br /&gt;
&lt;br /&gt;
==Configuration==&lt;br /&gt;
The software should be intuitive to any technical admin and does not require elaborate documentation. &amp;quot;Your Accounts&amp;quot; contains the emails being checked. &amp;quot;Actions&amp;quot; contains the actions. RTFM for the rest.&lt;br /&gt;
&lt;br /&gt;
The monitored emails are (@unipharm.com):&lt;br /&gt;
* accountingautoprint&lt;br /&gt;
* faxangelac&lt;br /&gt;
* faxelaho&lt;br /&gt;
* faxreceiving&lt;br /&gt;
* faxrong&lt;br /&gt;
* faxstein&lt;br /&gt;
* datamon&lt;br /&gt;
&lt;br /&gt;
Note: These target email addresses are MDaemon accounts.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes==&lt;br /&gt;
* A second use of this software is for Accounting to forward emails with many attached PDFs to an AEM email to autoprint the attachements on that printer.&lt;br /&gt;
* Another use for this is to save attachments from emails received on the Data Monitor account (for Integrator) to a folder.&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:3CX_IP-PBX_Administrator%27s_Guide&amp;diff=14573</id>
		<title>Information Systems:3CX IP-PBX Administrator's Guide</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:3CX_IP-PBX_Administrator%27s_Guide&amp;diff=14573"/>
		<updated>2023-11-29T23:02:44Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Administration Portal==&lt;br /&gt;
3CX Administration Web Portal:&lt;br /&gt;
&lt;br /&gt;
 URL: https://3cx.unipharm.local:5001&lt;br /&gt;
 Username: Administrator&lt;br /&gt;
 Password: NewTechIS21!&lt;br /&gt;
&lt;br /&gt;
==3CX Server Appliance==&lt;br /&gt;
 Username: root&lt;br /&gt;
 Password: NewVisionIT&lt;br /&gt;
==License==&lt;br /&gt;
Our 3CX license is '''Professional Perpetual''' with 16 simultaneous calls. Simultaneous calls includes internal/extension-to-extension calls, and both parked and queued calls. To date, our real world usage has never come close to reaching this. Nonetheless, the license can always be upgraded at a pro-rated cost.&lt;br /&gt;
::[[File:2021-03-31 11_25_29-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
&lt;br /&gt;
The license is renewed annually through TelData. &lt;br /&gt;
&lt;br /&gt;
==Configuration==&lt;br /&gt;
===Extensions===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;3&amp;quot;|Noteworthy Extensions&lt;br /&gt;
|-&lt;br /&gt;
|Extension&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===SIP Trunks===&lt;br /&gt;
A SIP trunk is what allows a PBX to make and receive outbound calls. A SIP trunk is configured for 1 or more channels (simultaneous calls). 3CX has 2 SIP trunk configurations:&lt;br /&gt;
* [[Information Systems: ThinkTel SIP Trunk | ThinkTel SIP Trunk]]&lt;br /&gt;
* [[Information Systems: RingOffice SIP Trunk | RingOffice SIP Trunk]]&lt;br /&gt;
&lt;br /&gt;
The ''SIP Trunks'' section in 3CX shows the following configuration:&lt;br /&gt;
:[[File:2021-03-31 11_51_37-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
* The order is alphabetical and does not imply call routing precedence; that is defined in ''Outbound Rules''&lt;br /&gt;
* As seen in the figure, only RingOffice has Register information. This characteristic differentiates the two SIP trunks: the RingOffice trunk does ''registration-based'' authentication, while ThinkTel is IP-based. [https://www.3cx.com/docs/sip-trunk-registration-authentication/ Read more about this here.] There is a slight benefit to Register-based authentication in that you can tell when the connection goes down (Register failed).&lt;br /&gt;
* The number of Sim calls is defined manually. It should match the number of channels of the SIP trunk service, but can be used to control usage (e.g. putting a max of 3 when there are really 6 usable channels will cause 3CX to use the next available trunk for the 4th sim call).&lt;br /&gt;
* The WebMeeting bridge is an internal and automatically configured trunk (can be ignored).&lt;br /&gt;
&lt;br /&gt;
===External Call Routing===&lt;br /&gt;
Calls to and from external numbers are routed according to the rules defined in the ''Inbound Rules'' and ''Outbound Rules'' sections. There are two main concepts:&lt;br /&gt;
&lt;br /&gt;
* DID mapping in ''Inbound Rules''&lt;br /&gt;
* Call routes in ''Outbound Rules''&lt;br /&gt;
&lt;br /&gt;
====Inbound Rules====&lt;br /&gt;
* DIDs (Direct Inward Dialing) are what we know as phone numbers (604-123-4567). They can be mapped in ''Inbound Rules'', either to local extensions, call queues, ring groups etc. Several DIDs can be mapped to the same internal target. For example, the toll-free and main company phone number map to the Customer Service call queue (technically the digital receptionist extension, but eventually routed there).&lt;br /&gt;
Part of the Inbound Rules page is shown here:&lt;br /&gt;
:[[File:2021-03-31 12_37_13-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
====Outbound Rules====&lt;br /&gt;
:[[File:2021-03-31 12_19_44-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
* Outbound rules specify the routes that outbound calls take. Notice that there is no 1:1 mapping of extensions to outbound routes. This is possible but absolutely unnecessary. Instead, the rules are catch-alls for other criteria (prefix, extension range). &lt;br /&gt;
* The prefix routes (9) are there to match the old phone system (where dialing 9 was necessary to &amp;quot;call out&amp;quot;). This is also still a common practice in many phone implementations, presumably as an extra validation measure for users i.e. to have users confirm their intent in dialing an external number.&lt;br /&gt;
* These rules are evaluated in order, from top down. This is why the 911 rule is at the top.&lt;br /&gt;
&lt;br /&gt;
===Call flow===&lt;br /&gt;
Call flow refers to the path a call takes through the system. The settings in Inbound and Outbound Rules define part of the flow, but it can be &lt;br /&gt;
&lt;br /&gt;
Most call flows are straightforward e.g. DID to local extension, voicemail if not available. &lt;br /&gt;
&lt;br /&gt;
===Voicemail===&lt;br /&gt;
Voicemail works as it does in other phone systems - there is a message center that users access to listen and otherwise manage their messages. This extension is 999. There are however, serveral additional enhancements related to voicemail:&lt;br /&gt;
&lt;br /&gt;
* Email notifications: Voicemails can be emailed, with a transcription of the text, an attached wav file of the audio message, or both. This is set per extension and is disabled by default.&lt;br /&gt;
* Voicemail transcription: Voicemail transcription transcribes voice messages to text so users can read instead of listen to the audio message. The functionality is set up system-wide in the 3CX settings, however, it needs to be enabled per-extension (for those that want it). It uses the Voice-to-Text service within Google Cloud Platform, and is billable monthly past the first 60 minutes (every month) of transcribed audio.&lt;br /&gt;
&lt;br /&gt;
====Customer Service Voicemail====&lt;br /&gt;
Extension ''501'' is used solely for &lt;br /&gt;
&lt;br /&gt;
====Google cloud services (GCP) integration====&lt;br /&gt;
3CX uses the following Google Cloud Platform services to provide special features:&lt;br /&gt;
* Firebase: Push notifications for 3CX mobile app ('''Android''' app only, Apple uses its own APNS)&lt;br /&gt;
* Cloud Speech API: Voicemail transcription (voice-to-text)&lt;br /&gt;
&lt;br /&gt;
 GCP Web Portal access:&lt;br /&gt;
 &lt;br /&gt;
 URL: https://console.cloud.google.com/&lt;br /&gt;
 Username: root@unipharm.com (uniPHARM Google account)&lt;br /&gt;
 Password: NewVisionIT&lt;br /&gt;
 Project name: UWD 3CX (use dropdown to select project)&lt;br /&gt;
 &lt;br /&gt;
 See the Billing section for Cloud Speech API billing. GCP gives a $400 credit for the first year, therefore during this first year, when looking at the billing, &amp;quot;One-time credits&amp;quot; may need to be toggled to see the actual billed usage that we would have paid.&lt;br /&gt;
 &lt;br /&gt;
 Firebase can be viewed in the section of the same name. However, integration with 3CX is just an API token to use the PUSH notification service, so this doesn't need regular maintenance unless changing the token.&lt;br /&gt;
&lt;br /&gt;
===Other Notes===&lt;br /&gt;
====Backup====&lt;br /&gt;
*( 3CX is being backed up to: &amp;lt;code&amp;gt;smb://superserver.unipharm.local/Tech/common/ConfigBackups/3CX&amp;lt;/code&amp;gt;. It should be here &amp;lt;code&amp;gt;\\superserver.unipharm.local\Tech\Logs And Backups&amp;lt;/code&amp;gt;, but spaces in the backup location path are not allowed (at least for SMB backups). This should be tweaked in the future. The last 20 backups are kept (auto-rotated). &lt;br /&gt;
* Because 3CX is both a virtual appliance and a fairly easy/small installation, there is no system image backup (would waste a Veeam license). A disaster recovery situation would then entail reinstallation of the 3CX virtual appliance and restoration of the backup config.&lt;br /&gt;
&lt;br /&gt;
[[Category: Phone System]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:3CX_IP-PBX_Administrator%27s_Guide&amp;diff=14572</id>
		<title>Information Systems:3CX IP-PBX Administrator's Guide</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:3CX_IP-PBX_Administrator%27s_Guide&amp;diff=14572"/>
		<updated>2023-11-29T23:01:20Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Administration Portal==&lt;br /&gt;
3CX Administration Web Portal:&lt;br /&gt;
&lt;br /&gt;
 URL: https://3cx.unipharm.local:5001&lt;br /&gt;
 Username: Administrator&lt;br /&gt;
 Password: NewTechIS21!&lt;br /&gt;
&lt;br /&gt;
==3CX Server Appliance==&lt;br /&gt;
Username: root&lt;br /&gt;
Password: NewVisionIT&lt;br /&gt;
==License==&lt;br /&gt;
Our 3CX license is '''Professional Perpetual''' with 16 simultaneous calls. Simultaneous calls includes internal/extension-to-extension calls, and both parked and queued calls. To date, our real world usage has never come close to reaching this. Nonetheless, the license can always be upgraded at a pro-rated cost.&lt;br /&gt;
::[[File:2021-03-31 11_25_29-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
&lt;br /&gt;
The license is renewed annually through TelData. &lt;br /&gt;
&lt;br /&gt;
==Configuration==&lt;br /&gt;
===Extensions===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;3&amp;quot;|Noteworthy Extensions&lt;br /&gt;
|-&lt;br /&gt;
|Extension&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===SIP Trunks===&lt;br /&gt;
A SIP trunk is what allows a PBX to make and receive outbound calls. A SIP trunk is configured for 1 or more channels (simultaneous calls). 3CX has 2 SIP trunk configurations:&lt;br /&gt;
* [[Information Systems: ThinkTel SIP Trunk | ThinkTel SIP Trunk]]&lt;br /&gt;
* [[Information Systems: RingOffice SIP Trunk | RingOffice SIP Trunk]]&lt;br /&gt;
&lt;br /&gt;
The ''SIP Trunks'' section in 3CX shows the following configuration:&lt;br /&gt;
:[[File:2021-03-31 11_51_37-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
* The order is alphabetical and does not imply call routing precedence; that is defined in ''Outbound Rules''&lt;br /&gt;
* As seen in the figure, only RingOffice has Register information. This characteristic differentiates the two SIP trunks: the RingOffice trunk does ''registration-based'' authentication, while ThinkTel is IP-based. [https://www.3cx.com/docs/sip-trunk-registration-authentication/ Read more about this here.] There is a slight benefit to Register-based authentication in that you can tell when the connection goes down (Register failed).&lt;br /&gt;
* The number of Sim calls is defined manually. It should match the number of channels of the SIP trunk service, but can be used to control usage (e.g. putting a max of 3 when there are really 6 usable channels will cause 3CX to use the next available trunk for the 4th sim call).&lt;br /&gt;
* The WebMeeting bridge is an internal and automatically configured trunk (can be ignored).&lt;br /&gt;
&lt;br /&gt;
===External Call Routing===&lt;br /&gt;
Calls to and from external numbers are routed according to the rules defined in the ''Inbound Rules'' and ''Outbound Rules'' sections. There are two main concepts:&lt;br /&gt;
&lt;br /&gt;
* DID mapping in ''Inbound Rules''&lt;br /&gt;
* Call routes in ''Outbound Rules''&lt;br /&gt;
&lt;br /&gt;
====Inbound Rules====&lt;br /&gt;
* DIDs (Direct Inward Dialing) are what we know as phone numbers (604-123-4567). They can be mapped in ''Inbound Rules'', either to local extensions, call queues, ring groups etc. Several DIDs can be mapped to the same internal target. For example, the toll-free and main company phone number map to the Customer Service call queue (technically the digital receptionist extension, but eventually routed there).&lt;br /&gt;
Part of the Inbound Rules page is shown here:&lt;br /&gt;
:[[File:2021-03-31 12_37_13-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
====Outbound Rules====&lt;br /&gt;
:[[File:2021-03-31 12_19_44-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
* Outbound rules specify the routes that outbound calls take. Notice that there is no 1:1 mapping of extensions to outbound routes. This is possible but absolutely unnecessary. Instead, the rules are catch-alls for other criteria (prefix, extension range). &lt;br /&gt;
* The prefix routes (9) are there to match the old phone system (where dialing 9 was necessary to &amp;quot;call out&amp;quot;). This is also still a common practice in many phone implementations, presumably as an extra validation measure for users i.e. to have users confirm their intent in dialing an external number.&lt;br /&gt;
* These rules are evaluated in order, from top down. This is why the 911 rule is at the top.&lt;br /&gt;
&lt;br /&gt;
===Call flow===&lt;br /&gt;
Call flow refers to the path a call takes through the system. The settings in Inbound and Outbound Rules define part of the flow, but it can be &lt;br /&gt;
&lt;br /&gt;
Most call flows are straightforward e.g. DID to local extension, voicemail if not available. &lt;br /&gt;
&lt;br /&gt;
===Voicemail===&lt;br /&gt;
Voicemail works as it does in other phone systems - there is a message center that users access to listen and otherwise manage their messages. This extension is 999. There are however, serveral additional enhancements related to voicemail:&lt;br /&gt;
&lt;br /&gt;
* Email notifications: Voicemails can be emailed, with a transcription of the text, an attached wav file of the audio message, or both. This is set per extension and is disabled by default.&lt;br /&gt;
* Voicemail transcription: Voicemail transcription transcribes voice messages to text so users can read instead of listen to the audio message. The functionality is set up system-wide in the 3CX settings, however, it needs to be enabled per-extension (for those that want it). It uses the Voice-to-Text service within Google Cloud Platform, and is billable monthly past the first 60 minutes (every month) of transcribed audio.&lt;br /&gt;
&lt;br /&gt;
====Customer Service Voicemail====&lt;br /&gt;
Extension ''501'' is used solely for &lt;br /&gt;
&lt;br /&gt;
====Google cloud services (GCP) integration====&lt;br /&gt;
3CX uses the following Google Cloud Platform services to provide special features:&lt;br /&gt;
* Firebase: Push notifications for 3CX mobile app ('''Android''' app only, Apple uses its own APNS)&lt;br /&gt;
* Cloud Speech API: Voicemail transcription (voice-to-text)&lt;br /&gt;
&lt;br /&gt;
 GCP Web Portal access:&lt;br /&gt;
 &lt;br /&gt;
 URL: https://console.cloud.google.com/&lt;br /&gt;
 Username: root@unipharm.com (uniPHARM Google account)&lt;br /&gt;
 Password: NewVisionIT&lt;br /&gt;
 Project name: UWD 3CX (use dropdown to select project)&lt;br /&gt;
 &lt;br /&gt;
 See the Billing section for Cloud Speech API billing. GCP gives a $400 credit for the first year, therefore during this first year, when looking at the billing, &amp;quot;One-time credits&amp;quot; may need to be toggled to see the actual billed usage that we would have paid.&lt;br /&gt;
 &lt;br /&gt;
 Firebase can be viewed in the section of the same name. However, integration with 3CX is just an API token to use the PUSH notification service, so this doesn't need regular maintenance unless changing the token.&lt;br /&gt;
&lt;br /&gt;
===Other Notes===&lt;br /&gt;
====Backup====&lt;br /&gt;
*( 3CX is being backed up to: &amp;lt;code&amp;gt;smb://superserver.unipharm.local/Tech/common/ConfigBackups/3CX&amp;lt;/code&amp;gt;. It should be here &amp;lt;code&amp;gt;\\superserver.unipharm.local\Tech\Logs And Backups&amp;lt;/code&amp;gt;, but spaces in the backup location path are not allowed (at least for SMB backups). This should be tweaked in the future. The last 20 backups are kept (auto-rotated). &lt;br /&gt;
* Because 3CX is both a virtual appliance and a fairly easy/small installation, there is no system image backup (would waste a Veeam license). A disaster recovery situation would then entail reinstallation of the 3CX virtual appliance and restoration of the backup config.&lt;br /&gt;
&lt;br /&gt;
[[Category: Phone System]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14564</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14564"/>
		<updated>2023-11-15T19:56:43Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || NewVisionIT! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || Cisco CBS250 || Candy Mezzanine || adminit || Newvisionit! || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| OCT-SWITCH || 172.30.16.20 || Cisco CBS350 || OCT-Picking Station || OCT-SWITCH || Gu20Da51NewEra ||&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14563</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14563"/>
		<updated>2023-11-15T19:56:16Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || NewVisionIT! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || Cisco CBS250 || Candy Mezzanine || adminit || Newvisionit! || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| OCT-SWITCH || 172.30.16.20 || Cisco CBS350 || OCT-Picking Station || OCT-SWITCH || Gu20Da51NewEra || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14562</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14562"/>
		<updated>2023-11-15T19:55:42Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || NewVisionIT! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || Cisco CBS250 || Candy Mezzanine || adminit || Newvisionit! || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| OCT-SWITCH || 172.30.16.20 || Cisco CBS350 || OCT-Picking Station || OCT-SWITCH || Gu20Da51nNewEra || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Datalogic_RF_gun&amp;diff=14532</id>
		<title>Information Systems:Datalogic RF gun</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Datalogic_RF_gun&amp;diff=14532"/>
		<updated>2023-10-25T18:15:33Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Overview=&lt;br /&gt;
=Hardware maintenance and repair=&lt;br /&gt;
- It is easiest to email rma.usa@datalogic.com or call 1-800-BAR-CODE (227-2633) and provide the following information:&lt;br /&gt;
&lt;br /&gt;
- Full company name:&lt;br /&gt;
&lt;br /&gt;
- Billing address (cannot accept a PO Box without a street address) provided information&lt;br /&gt;
&lt;br /&gt;
- Shipping address:&lt;br /&gt;
&lt;br /&gt;
•Product serial number(s) - &lt;br /&gt;
&lt;br /&gt;
•Problem description - &lt;br /&gt;
&lt;br /&gt;
•Contact (first/last name, e-mail, phone)&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Datalogic_RF_gun&amp;diff=14531</id>
		<title>Information Systems:Datalogic RF gun</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Datalogic_RF_gun&amp;diff=14531"/>
		<updated>2023-10-25T18:13:38Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Overview=&lt;br /&gt;
=Hardware maintenance and repair=&lt;br /&gt;
- It is easiest to email rma.usa@datalogic.com or call 1-800-BAR-CODE (227-2633) and provide the following information:&lt;br /&gt;
- Full company name&lt;br /&gt;
- Billing address (cannot accept a PO Box without a street address) provided information&lt;br /&gt;
- Shipping address&lt;br /&gt;
•Product serial number(s) - &lt;br /&gt;
•Problem description - &lt;br /&gt;
•Contact (first/last name, e-mail, phone)&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Datalogic_RF_gun&amp;diff=14530</id>
		<title>Information Systems:Datalogic RF gun</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Datalogic_RF_gun&amp;diff=14530"/>
		<updated>2023-10-25T18:13:28Z</updated>

		<summary type="html">&lt;p&gt;Danielc: /* Hardware maintenance and repair */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Overview=&lt;br /&gt;
==Hardware maintenance and repair==&lt;br /&gt;
- It is easiest to email rma.usa@datalogic.com or call 1-800-BAR-CODE (227-2633) and provide the following information:&lt;br /&gt;
- Full company name&lt;br /&gt;
- Billing address (cannot accept a PO Box without a street address) provided information&lt;br /&gt;
- Shipping address&lt;br /&gt;
•Product serial number(s) - &lt;br /&gt;
•Problem description - &lt;br /&gt;
•Contact (first/last name, e-mail, phone)&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Datalogic_RF_gun&amp;diff=14529</id>
		<title>Information Systems:Datalogic RF gun</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Datalogic_RF_gun&amp;diff=14529"/>
		<updated>2023-10-25T18:13:08Z</updated>

		<summary type="html">&lt;p&gt;Danielc: Created page with &amp;quot;=Overview= ===Hardware maintenance and repair=== - It is easiest to email rma.usa@datalogic.com or call 1-800-BAR-CODE (227-2633) and provide the following information: - Full...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Overview=&lt;br /&gt;
===Hardware maintenance and repair===&lt;br /&gt;
- It is easiest to email rma.usa@datalogic.com or call 1-800-BAR-CODE (227-2633) and provide the following information:&lt;br /&gt;
- Full company name&lt;br /&gt;
- Billing address (cannot accept a PO Box without a street address) provided information&lt;br /&gt;
- Shipping address&lt;br /&gt;
•Product serial number(s) - &lt;br /&gt;
•Problem description - &lt;br /&gt;
•Contact (first/last name, e-mail, phone)&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VMWare_Production_Infrastructure&amp;diff=14492</id>
		<title>Information Systems:VMWare Production Infrastructure</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VMWare_Production_Infrastructure&amp;diff=14492"/>
		<updated>2023-10-14T03:56:14Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Hardware=&lt;br /&gt;
uniPHARM purchased a pair of Lenovo x3650 M5 servers in March of 2018 from Anisoft to act as hosts for VMware.  The machine type of both servers is 8871-16A and the serial numbers are J121W8C and J121W8D.  Both servers do have identical hardware components and as of March 2018, they also have identical and current firmware.  Both servers have an Intel Xeon E5-2620 v4 processor populating the first socket.  The second socket for both servers is empty.  The Xeon has 8 cores and 16 threads.  Both machines came with an initial 16GB stick of memory in the first slot.  An additional 6 sticks of 8GB were installed into each server so that each has 64GBs of memory.  Be aware that the motherboard has specific requirements for where additional memory can be inserted.  The numerical order for which memory slots can be used is clearly displayed on the top side lid of the server.  If more memory is purchased and installed for these servers, the instructions on the top lid must be followed, or the memory will not be recognized correctly.  The memory slots labeled from 13 to 24 on the motherboard cannot be used until the second CPU socket has a processor.&lt;br /&gt;
&lt;br /&gt;
Each server has an ServeRAID M5210 controller that is attached to the motherboard.  For each M5210, there is also a RAID5 daughter card that is attached which provides additional capabilities.  The M5210 can control up to 24 drives for each server.  The initial purchase included 5 drives for each server that are 960GB SSDs.  Both of the M5210 controllers are configured with a RAID6 set containing the 5 SSDs.  The RAID6 volume can survive the failure of 2 drives before there is data loss.  There are no warm or cold spare drives available as of March 2018.  The total amount of storage space on each server is 2679GB.  The strip size is 256KB.  All parameters of the RAID6 set were set to default for the M5210 controller.  Each server also has a USB thumb drive that is plugged into the motherboard where the hypervisor software is installed.  The thumb drive is 2GB in size and is USB2.0.&lt;br /&gt;
&lt;br /&gt;
Each server has 4 network ports that use the Broadcom NetXtreme chip.  Each server has an additional network port that is for dedicated IMM2 access.  More on the IMM2 is below.  Each server has 2 USB and a VGA port on the front side and the back side.  The purchased configuration of each server did not include any riser cards for PCIe expansion cards so if there is a need for extra abilities, the riser cards are also required.  Each server has 2 power supplies which can share the load as well as take the entire electrical load should 1 fail.  Each server has different power sources feeding into each power supply.  The top, or number 2 power supply for each server, is fed from the right side PDU in the Power8 rack.  The bottom, or number 1 power supply, is fed from the left side PDU.  The PDU's are the &amp;quot;power strips&amp;quot; on each side of the rack where the right side gets power from the Leibert UPS and the left gets power from the Power8 UPS at the bottom of the rack.  This all means that in the event of a Hydro power failure, the servers will stay up and operational even if one out of two UPS's fails.  Both servers will immediately power off if there is a Hydro power failure AND BOTH UPS's also fail or run out of battery power.&lt;br /&gt;
&lt;br /&gt;
Both servers are located in the Power8 rack and are 2U in size.  The top server is at rack unit 18 and the bottom server is at rack unit 16.  Both servers can be pulled out on the rack rails and serviced while powered on.  The hard drives and power supplies are hot swappable but the memory is not.  Neither server has a CD-ROM drive so if a disc needs to be used, the only option is to plug in a USB optical drive.&lt;br /&gt;
&lt;br /&gt;
==Hardware - Network Port Map==&lt;br /&gt;
This list shows the layout of the network cables that connect the servers to the stacked core network switches in the Server Room.&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  2 goes to VMHost01 dedicated IMM2 port&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 14 goes to VMHost02 dedicated IMM2 port&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  3 goes to VMHost01 Management Port on eth2&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 15 goes to VMHost02 Management Port on eth2&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  4 goes to VMHost01 vMotion Port on eth3&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 16 goes to VMhost02 vMotion Port on eth3&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  5 goes to VMHost01 LAN1 Uplink on eth0&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 17 goes to VMHost01 LAN2 Uplink on eth1&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  6 goes to VMHost02 LAN1 Uplink on eth0&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 18 goes to VMHost02 LAN2 Uplink on eth1&lt;br /&gt;
&lt;br /&gt;
==Hardware Purchase Details==&lt;br /&gt;
The purchase order number for this project is 8226136 (dated Feb 13, 2018) with a vendor number of 20145 and invoices numbers 19253, 19254, 19256 dated March 14, 2018.&lt;br /&gt;
&lt;br /&gt;
==Hardware Support==&lt;br /&gt;
uniPHARM has a hardware maintenance contract with Lenovo to provide 24x7x365 onsite parts and labour with a 4 hour response time for the period of March 6, 2018 to March 5, 2021.  A renewal of this maintenance contract is expected in February of 2021 because the expected life span of these servers is 5 to 6 years.  Note that &amp;quot;maintenance&amp;quot; is not a good descriptor of the service.  If a hardware component fails, then the replacement of that part is provided by Lenovo at no cost and is installed by a Lenovo technician at no cost.  If uniPHARM adds in non-Lenovo parts they are not covered by the existing contract.  Additional Lenovo branded parts that are installed after initial purchase are covered under the existing contract.  If a non-Lenovo part is installed and causes damage to the server, the agreement becomes null and void.  The phone number for parts replacement and technical support under this contract is 1-800-426-7378.  This contract does not cover any VMware software.&lt;br /&gt;
&lt;br /&gt;
=IMM2=&lt;br /&gt;
The Integrated Management Module II is an out of band service used to control the x3650 server hardware.  It is comparable to the HMC for the Power8.  The IMM2 is on and active and accessible as long as the server has power feeding into the power supplies.  If both power supplies are unplugged, the IMM2 is not active and accessible.  The IMM2 resides on a small &amp;quot;SystemOnChip&amp;quot; on the motherboard and is served by a webserver within a small Linux OS within the SOC.  The IMM2 also has a dedicated network port that is only used by that function.  On smaller 1U servers the IMM2 shares the first Broadcom network port.&lt;br /&gt;
&lt;br /&gt;
The IP addresses assigned to each of the 2 IMM2's are 172.30.18.54 and 172.30.18.55.  The host names are bmvmhost01.unipharm.local and bmvmhost02.unipharm.local.  BM is a hold over from a previous IBM product called &amp;quot;Baseboard Management&amp;quot; and this naming convention is a continuation of that.  The username for both IMM2's is adminit and the password is visionit.  The IMM2's are not accessible from the public side of the firewall and need VPN access if logging in from outside the local network.&lt;br /&gt;
&lt;br /&gt;
* https://bmvmhost01.unipharm.local&lt;br /&gt;
* https://bmvmhost02.unipharm.local&lt;br /&gt;
&lt;br /&gt;
The IMM2 web interface is primarily used to control the hardware, alert for hardware failures and to provide a screen console for the server when no physical screen-keyboard-mouse is attached.  This is a critical function for troubleshooting or diagnosing software crashes no matter what OS or hypervisor is installed.  The console screen function can be presented using a ActiveX, or Java, or HTML5 app that is served from the IMM2 - no need to install any EXE on a laptop.  The Java client works consistently.  The IMM2 can power on or off the server and show very detailed information on temperatures, fan speeds, voltages and firmware levels of all components.  The IMM2 is also setup to email alerts to I.S. staff when hardware events occur such as a failed hard drive or power supply.  The IMM2 is also configured to call home to Lenovo when a hardware component fails in the same manner that the HMC connects to IBM when a Power8 hardware failure occurs.&lt;br /&gt;
&lt;br /&gt;
As of March 2018, the x3650 servers do have the latest available firmware and should not need any firmware updates unless Lenovo requires it for replacement parts.  If updated firmware is needed, it can be installed from within the IMM2 web interface.&lt;br /&gt;
&lt;br /&gt;
=vSphere ESXI Hosts=&lt;br /&gt;
The vSphere (ESX) hypervisor is installed on the USB thumb drive that is plugged into the internal motherboard port for each server.  The customized Lenovo version of the ESX installer was used as it is pre-compiled with all of the device drivers present in Lenovo branded hardware.  Each server, now known as a host, is set to only boot from that USB thumb drive.  The hypervisor operating system boots and loads into memory and is thusly ready to house and run virtual machines.&lt;br /&gt;
* Server with serial number J121W8C has a host name of vmhost01.unipharm.local&lt;br /&gt;
* The administrator username is root&lt;br /&gt;
* The administrator password is NewVisionIT2051!&lt;br /&gt;
* The management network is on eth2 which is the third network port on the back of the server&lt;br /&gt;
* The management network IP address is 172.30.18.19 subnet 255.255.248.0 gateway 172.30.16.1 and is configured to do DNS lookups to 172.30.18.13 and .14&lt;br /&gt;
* The management network is using the default VLAN&lt;br /&gt;
and&lt;br /&gt;
* Server with serial number J121W8D has a host name of vmhost02.unipharm.local&lt;br /&gt;
* The administrator username is root&lt;br /&gt;
* The administrator password is NewVisionIT2051!&lt;br /&gt;
* The management network is on eth2 which is the third network port on the back of the server&lt;br /&gt;
* The management network IP address is 172.30.18.20 subnet 255.255.248.0 gateway 172.30.16.1 and is configured to do DNS lookups to 172.30.18.13 and .14&lt;br /&gt;
* The management network is using the default VLAN&lt;br /&gt;
The web administration pages to directly access the ESX hypervisor and bypass vCenter are:&lt;br /&gt;
* https://vmhost01.unipharm.local&lt;br /&gt;
* https://vmhost02.unipharm.local&lt;br /&gt;
The above links that go directly to the hypervisor don't need to be used or accessed for day to day administration because all administrative tasks should be done within the vCenter user interface.  The above links only need to be accessed if vCenter is unavailable, down or broken.&lt;br /&gt;
&lt;br /&gt;
=vCenter Server Appliance=&lt;br /&gt;
During Stage 1 of the VCSA setup, the following settings were used&lt;br /&gt;
* The FQDN of the VCSA is vcsa.unipharm.local&lt;br /&gt;
* The IP address of the VCSA is 172.30.18.23&lt;br /&gt;
* The password for the VCSA is NewVisionIT@2051&lt;br /&gt;
* The password requires upper and lower case letters AND a number AND a special character but no spaces are allowed.&lt;br /&gt;
* The VCSA has an integrated, as in no external, Embedded Platform Services Controller&lt;br /&gt;
* The VCSA was deployed in &amp;quot;Tiny&amp;quot; mode and is using a thin provisioned virtual disk&lt;br /&gt;
During Stage 2 of the VCSA setup, on the SSO configuration screen, the following settings were used&lt;br /&gt;
* Single Sign-On domain name is vsphere.local&lt;br /&gt;
* Single Sign-On user name is administrator&lt;br /&gt;
* Single Sign-On password is NewVisionIT@2051&lt;br /&gt;
* Site name is uniPHARM&lt;br /&gt;
* SSH access was enabled&lt;br /&gt;
* The following link was used as a guide for the very confusing and badly designed SSO setup https://esxsi.com/2016/11/16/vcsa65/&lt;br /&gt;
Please note that if the VCSA virtual machine needs to be rebooted, it will take a good 5 minutes for the web page to be accessible and you may see a plain text page saying the interface is initializing so be patient as the appliance settles down after a reboot.&lt;br /&gt;
==vCenter Management==&lt;br /&gt;
* The URL for vCenter Flash site is https://vcsa.unipharm.local/vsphere-client/&lt;br /&gt;
* The URL for the vCenter HTML5 site is https://vcsa.unipharm.local/ui   &amp;lt;------ The HTML5 site is waaaaaaaaay better than the Flash site AND it has a dark mode them which is bananas.&lt;br /&gt;
* Username is  administrator@vsphere.local&lt;br /&gt;
* Password is  NewVisionIT@2051&lt;br /&gt;
* The URL for the vCenter Appliance Management site is https://vcsa.unipharm.local:5480&lt;br /&gt;
* The username is root and the password is NewVisionIT@2051&lt;br /&gt;
The virtualization infrastructure is designed according to VMware's best practices.  In vCenter, a datacenter has been created and called &amp;quot;uniPHARM Datacenter&amp;quot;.  It contains a cluster called &amp;quot;uniPHARM Cluster.  The cluster contains both hosts and any virtual machines are listed under the hosts.  The cluster was created with DRS and HA turned off to begin with, however they can be turned on a later time.  Each host has a single datastore and they are named VMHost01DataStore01 and VMHost02DataStore01.  Each datastore is the entire RAID6 set of 5 SSDs, totaling 2.62TB of usable space.  If, in the future, there is ever a need to add storage, the naming convention should continue with VMHost01DataStore02 or VMHost01DataStore03.&lt;br /&gt;
&lt;br /&gt;
===vCenter Management - vNetwork===&lt;br /&gt;
As mentioned above, each host has 4 gigabit network ports.  The network configuration for our VMware infrastructure is not complex, by VMware standards but the information below is critical to understanding how it has been designed:&lt;br /&gt;
* The first (vmnic0) and second (vmnic1) NICs are used for everyday ordinary network traffic going in or out from or to the virtual machines&lt;br /&gt;
* The first (vmnic0) NIC is connected to vSwitch2 and is labeled as &amp;quot;uniPHARM Production LAN&amp;quot; - imagine that an invisible virtual switch lies between the first NIC and the real physical switch in the Server Room&lt;br /&gt;
* The second (vmnic1) NIC is initially not configured to do anything as of March 2018 but it can be used for a second Production LAN or some sort of testing LAN or fail over if licensing permits&lt;br /&gt;
* The third (vmnic2) NIC is configured as a vmKernel port (172.30.18.19 &amp;amp; 20) connected to vSwitch0 acting as the &amp;quot;Management Network&amp;quot;&lt;br /&gt;
* The third (vmnic2) NIC and vSwitch0 are only used as a connection that vCenter uses to control the hosts and its setup is a best practice from VMware&lt;br /&gt;
* The fourth (vmnic3) NIC is configured as a vmKernel port (172.30.24.1 &amp;amp; 2) connected to vSwitch1 on VLAN 3 acting as the &amp;quot;vMotion Network&amp;quot; and is only used when a virtual motion needs to move from one host to another&lt;br /&gt;
It is CRITICALLY important that ANY vnic, vSwitch or vmKernel configuration changes that are made on one host are precisely repeated on the other host.  Having different vSwitch labels, for example, prevents vMotion from succeeding.  Our EPK license does not permit distributed switches so we have to do the configuration changes manually to each host.&lt;br /&gt;
&lt;br /&gt;
===VUM VMware Update Manager===&lt;br /&gt;
VUM has been configured with a dynamic baseline for the hosts and for the VCSA.  The best explanation of how VUM works is this link - https://www.youtube.com/watch?v=X_xGihAfLSo  Please note that the safest way to apply patches and updates to the hosts hypervisor is to vMotion all the VM's on one host to another and then to remediate the empty host, then vMotion all the VM's back and do the other host.  Since we only have 2 or 3 hosts and don't apply patches very often, this method (while time consuming) results in very little down time and a patched infrastructure.  An alternate method is to schedule a Saturday, for example where all the VM's can be gracefully shutdown and then when they are ALL off, use VUM to do a patch cycle of each host one at a time.&lt;br /&gt;
&lt;br /&gt;
If the VCSA itself needs to be updated, see this VMware KB article. https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.upgrade.doc/GUID-6751066A-5D4E-47AC-A6A4-5E90AEC63DAA.html  The VCSA should be updated and rebooted BEFORE applying any new patches or versions to a host.&lt;br /&gt;
&lt;br /&gt;
===vCenter Alarm Configuration===&lt;br /&gt;
vCenter has been configured to use a small number of alarms that email alerts when certain conditions are encountered.  The alarm configuration is done at the VCSA level in the hierarchy:&lt;br /&gt;
* &amp;quot;Host connection and Power State alarms when the Connection State is equal to Not Responding and the host is at Standby or Powered Off - then emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;Host CPU Usage&amp;quot; alarms a warning when CPU is above 75% for 10 minutes and a critical when the CPU is above 90% for 10 minutes - then emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;Virtual Machine CPU Usage&amp;quot; alarms a warning when a vCPU is above 90% for 20 minutes and alarms critical when vCPU is at 100% for 30 minutes - emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;Virtual Machine Memory Usage&amp;quot; alarms a warning when a memory is above 90% for 10 minutes and alarms critical when memory is above 95% for 10 minutes - emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;Datastore Usage On Disk&amp;quot; alarms a warning when datastore usage is above 80% and alarms critical when above 90% - emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;uniPHARM Alarm Network Unplugged&amp;quot; alarms when a NIC is unplugged - emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;uniPHARM Alarm VM Powered Off&amp;quot; alarms when a VM is powered off - emails DarrenF and NorwinU&lt;br /&gt;
&lt;br /&gt;
===Content Library===&lt;br /&gt;
Within vCenter, a content library called uniPHARM Content Library has been created.  The purpose of the library is to store ISO and OVF files that are used when creating new VM's so that an OS can be booted - remember that the VMHosts don't have attached CD-ROM drives.  Since creating new VM's is not a daily occurrence, the content library should be empty or mostly empty for the majority of the time in order to not consume storage space that is best served for VM's.  The content library can only be used for virtual machines created on VMHost01 because that is the datastore where the content library is located.  A newly created virtual machine on the other 2 hosts can't use the content library because it's not on shared storage.  Also be aware that IE11 cannot upload ISO files greater than 4GB in size, you have to use a different browser.  Please for the love of Bhudda, label what you are uploading to the Content Library so that others know what it is.&lt;br /&gt;
&lt;br /&gt;
=Virtual Machines=&lt;br /&gt;
A virtual machine is like a bucket.  The bucket contains a simulated processor, memory and a flat file that acts as a hard drive.  An OS can be installed inside the bucket and can be given a network connection which is also simulated.  The OS can't tell the difference between real hardware and simulated so it behaves normally.  The bucket that contains the simulated hardware and the OS install, sits on top of the hypervisor.  The hypervisor takes simulated hardware calls and maps them to real physical hardware so that each bucket can get a slice of processor and memory.  The real hardware can house many buckets and the contents of each bucket don't mix or interact preserving the containerization.  And finally buckets can be moved to different hardware without interrupting the OS contents via hocus pocus magic.&lt;br /&gt;
==VCSA==&lt;br /&gt;
The vCenter appliance VM was created with all the default settings as they were set by the ISO installer.  It currently has 2 vCPUs and is using 1.5GB of memory.  It has a very unique way of using 14 different thin provisioned VMDK files that act as its hard drives and is currently only using 25GB of real storage space.  The VM hardware version is 10.  This VM is very important to safe and healthy operation of our virtualization infrastructure.&lt;br /&gt;
&lt;br /&gt;
==XClarity==&lt;br /&gt;
XClarity is a software based virtual appliance from Lenovo that shows hardware inventory and does hardware alerting.  XClarity is a much more slimmed down modern packaged that is what IBM Director was supposed to be.  The OS for the VM is a Linux something where access by the user is restricted.  The VM is using 1 vCPU and 8GB of memory and is thin provisioned for 64GB of storage and is actually using only 12GB of storage.  The IP address assigned to the VM is 172.30.18.2 and the URL for the sit is :&lt;br /&gt;
* https://xclarity.unipharm.local/ui/login.html&lt;br /&gt;
The local login for the above URL is:&lt;br /&gt;
* Username - adminit&lt;br /&gt;
* Password - NewVisionIT2051&lt;br /&gt;
* Active Directory SSO is currently not working in XClarity 1.4&lt;br /&gt;
The XClarity 1.4 software appears to be fairly straight forward and is able to talk to all the IMM's for our current small fleet of Lenovo servers.  The software is set to email DarrenF and NorwinU if there is a hardware failure on any of the Lenovo servers.  These alerts are in addition and perform the same function as the IMM's on each machine and is strictly limited to hardware failures.  There is an excellent Android app that talks to XClarity over a VPN connection, however it requires that the XClarity appliance root and subordinate certificates be installed on the phone in order to gain access.  This is security overkill but DarrenF did install those certificates on his phone and the app is worth this effort though others are free to disagree.  This VM appliance was created from an OVA file on May 9, 2018.  As of May 2018, this VM is not being backed up by anything and doesn't really need to be because it can be recreated from the OVA file.  This VM is in no way business critical and can be powered off if needed.&lt;br /&gt;
* It was discovered after the setup of XClarity 1.4 was completed that there is a 2.0 that will be installed and configured again as a VM appliance at a later date.  Both versions are supported by Lenovo but because the software is the free version, uniPHARM has no support contract.&lt;br /&gt;
* XClarity cannot talk to the IMM on the old SuperServer hardware because the hardware is not on the XClarity HCL.  We are going to continue using SuperServer hardware for Veeam but XClarity cannot monitor that hardware.  XClarity also cannot monitor Lenovo desktops or laptops - only Lenovo servers, storage SANs and Lenovo switches.&lt;br /&gt;
&lt;br /&gt;
==Thermoprofile==&lt;br /&gt;
This is the first physical server to be converted into a virtual machine:&lt;br /&gt;
* Shrunk the 2 physical hard drives - C: from 150GB to 100GB and D: from 250GB to 150GB&lt;br /&gt;
* Configured the VM to use 1 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
This VM is ultimately going to go away because the applications on it (Spiceworks, KiwiSyslog, WDS/MDT need to be migrated onto a freshly made Windows Server 2012R2 VM where the OS license is re-used.  The conversion of the Windows Server 2008R2 physical machine is acting as a test case for more critical conversions.&lt;br /&gt;
* Thermoprofile VM had its applications (Spiceworks and KiwiSsylog + WDS) moved to a new VM called WDS.unipharm.local on Friday June 8, 2018.  The Thermoprofile VM was powered off and removed from the BackupExec jobs.  The VM was deleted on June 13, 2018.&lt;br /&gt;
&lt;br /&gt;
==Mail==&lt;br /&gt;
This is the third physical server to be converted into a virtual machine: &lt;br /&gt;
* The physical hard drive was thick provisioned and not shrunk&lt;br /&gt;
* Configured the VM to use 2 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
For more information on this server, please see the following link: http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Mail_Server&lt;br /&gt;
&lt;br /&gt;
==SuperServer==&lt;br /&gt;
This is the fourth physical server to be converted into a virtual machine: &lt;br /&gt;
* The physical hard drives were thick provisioned and shrunk during the conversion process&lt;br /&gt;
* The C: drive was configured to be 100GB, the D: was configured to be 1000GB and the E: was configured to be 500GB&lt;br /&gt;
* Configured the VM to use 2 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
For more information on this server, please see the following link: http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:SuperServer&lt;br /&gt;
&lt;br /&gt;
==WindowsXP JetDirect==&lt;br /&gt;
DarrenF created this VM a long time ago in VMware Workstation so that the HP JetDirect boxes at each picking station can be controlled, configured and setup correctly.  The JetDirect boxes are so old that their web administration pages only work with Microsoft Java, which only exists in a 2002 version of WindowsXP prior to SP1 or SP2.  The web administration page of the JetDirect boxes works in the same manner as pages for all the other network attached printers.  The admin page for the JetDirect boxes need to have the correct IP address and host name set plus other print and network options.  New Windows OS's like Windows 7 and 10 are not able to display the JetDirect web admin page because the version of Java it needs does not exist in newer versions of Windows.  Having a VM with an old version of Windows is the most convenient method if someone needs to configure a JetDirect box, otherwise, the VM can be left powered off.  This VM is only taking up 16GB of storage space.&lt;br /&gt;
&lt;br /&gt;
==Lucy==&lt;br /&gt;
This is the second physical server to be converted into a virtual machine:&lt;br /&gt;
* Shrunk the 2 physical hard drives - C: from 150GB to 75GB&lt;br /&gt;
* Configured the VM to use 2 vCPU and 4GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
* The VM does not have the serial ports that the physical machine had installed in its PCI slots&lt;br /&gt;
&lt;br /&gt;
==Smithers==&lt;br /&gt;
This is the fifth physical server to be converted into a virtual machine: &lt;br /&gt;
* The physical hard drive was thick provisioned and shrunk during the conversion process&lt;br /&gt;
* The C: drive was configured to be 150GB&lt;br /&gt;
* Configured the VM to use 2 vCPU and 16GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
The physical server that was Smithers, had a red coloured USB licensing dongle that was used for the Kofax scanning software.  Prior to the P2V, the licensing dongle was moved to the Gauss scanning station in Accounting.  The Gauss software &amp;quot;package&amp;quot; on the Smithers VM, plus both scanning desktops now point to the USB dongle in Accounting for licensing compliance.  The Smithers VM has no special USB pass-through because the USB dongle was moved prior to the P2V.  For more information on this server, please see the following link: http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Smithers&lt;br /&gt;
&lt;br /&gt;
==WDS==&lt;br /&gt;
This is a new virtual machine created (not converted) with a fresh Windows Server 2012R2 OS install for housing the Windows Deployment Service and Spiceworks and KiwiSyslog.  WDS is where desktop and laptop images are stored and downloaded from when a workstation does a PXE boot to install Windows.&lt;br /&gt;
* The virtual hard drive was thin provisioned at 70GB&lt;br /&gt;
* The C: drive was configured to be 100GB&lt;br /&gt;
* Configured the VM to use 1 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
&lt;br /&gt;
==UWDDC1==&lt;br /&gt;
This is a new virtual machine created (not converted) with a fresh Windows Server 2012R2 OS install to act as an Active Directory Domain Controller.&lt;br /&gt;
* The virtual hard drive was thin provisioned at 50GB&lt;br /&gt;
* The C: drive was configured to be 50GB&lt;br /&gt;
* Configured the VM to use 1 vCPU and 4GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
For more information on Active Directory, see the following link: (Yes, it shows UWDDC3, just ignore that, the documentation is valid and still correct)&lt;br /&gt;
http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:UWDDC3_Domain_Controller&lt;br /&gt;
&lt;br /&gt;
==UWDDC2==&lt;br /&gt;
This is a new virtual machine created (not converted) with a fresh Windows Server 2012R2 OS install to act as an Active Directory Domain Controller. &lt;br /&gt;
* The virtual hard drive was thin provisioned at 50GB&lt;br /&gt;
* The C: drive was configured to be 50GB&lt;br /&gt;
* Configured the VM to use 1 vCPU and 4GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
For more information on Active Directory, see the following link: (Yes, it shows UWDDC3, just ignore that, the documentation is valid and still correct) http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:UWDDC4_Domain_Controller&lt;br /&gt;
&lt;br /&gt;
==XTGUI==&lt;br /&gt;
This is a new virtual machine created (not converted) with a fresh Windows Server 2012R2 OS install to act as a server for the Iptor XT GUI. &lt;br /&gt;
* The virtual hard drive was thick provisioned at 40GB&lt;br /&gt;
* The C: drive was configured to be 40GB&lt;br /&gt;
* Configured the VM to use 2 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
&lt;br /&gt;
==3CX Server Appliance==&lt;br /&gt;
This is a new virtual machine created from an ISO file downloaded from the 3CX website.  The ISO is an automated install of Debian 64bit plus the 3CX software.  The purpose of this VM is to act as a software PBX intended to replace the physical Toshiba PBX hardware.  There is a Windows based version of 3CX, however it was deemed that using a prebuilt VM appliance was a better option.&lt;br /&gt;
* The virtual machine is configured with 1 vCPU, 4GB of memory and 50GB of thick provisioned disk space.  &amp;lt;-- Woops my bad sorry on the thick provisioned space.&lt;br /&gt;
* The virtual machine is using the VMXNET3 network interface on the Production LAN at 172.30.18.27&lt;br /&gt;
* As of September 2018, this VM is not being backed up in any way&lt;br /&gt;
* The virtual machine has the OpenVM Tools installed&lt;br /&gt;
* The virtual machine is located on VMHost03&lt;br /&gt;
* There is a special VM network that has been created on VMHost03 (only) so that this VM can use the Shaw coax internet connection.  Because of this unique network configuration, this VM cannot be vMotioned as the vSwitch is not present on VMHost01 or 02&lt;br /&gt;
&lt;br /&gt;
==Zabbix NMS VM Appliance==&lt;br /&gt;
This is a Linux based virtual appliance that is used for network monitoring, graphing and alerting.  The VM appliance is an LTS version of Ubuntu with the OSS package called Zabbix baked in.  The open-vm-tools package is present so vCenter can control this VM.  While this VM is not business critical, it took a lot of effort to setup and configure so try not to let it get wiped out with no backups.&lt;br /&gt;
* The virtual machine is configured with 2 vCPU, 4GB of memory and 40GB of thin provisioned disk space.&lt;br /&gt;
* The virtual machine is using the VMXNET3 network interface on the Production LAN at 172.30.18.13&lt;br /&gt;
* As of July 2019, this VM is not being backed up in any way&lt;br /&gt;
* The virtual machine has the OpenVM Tools installed&lt;br /&gt;
* The virtual machine is located on VMHost02&lt;br /&gt;
&lt;br /&gt;
=Third Host Used For Testing=&lt;br /&gt;
On Monday May 28, 2018 a third host server was added to the VMware cluster.  The hardware that was used was previously the &amp;quot;Smithers&amp;quot; server.  The machine is a Lenovo x3550 M5 and the machine type is a 5463-AC1 and the serial number is E2ZR351.  The server has 2 populated processor sockets and contains Intel Xeon E5-2620v3 processors.  It has 32GB of memory and has 2 SSD drives that have been put into a RAID0 array.  There are 4 network ports at the back of the server and they are used and setup in the same way as the original 2 hosts.  This third host has the same IMM2 and the URL and credentials are below:&lt;br /&gt;
* https://bmvmhost03.unipharm.local&lt;br /&gt;
* adminit&lt;br /&gt;
* abc123&lt;br /&gt;
The third host has the same build of ESX as the other 2 hosts and it is also installed on a USB thumb drive but the thumb drive in the third host is not a Lenovo part and is not covered under warranty.  The third host is also setup to boot directly from the thumb drive instead of the RAID0 SSD array.  The RAID0 array has been configured as VMHost03DataStore01 and is 440GB in size.  The root password for the installed hypervisor on the third host is the same compared to the other 2 hosts and the management IP used is 172.30.18.21 and the vMotion IP is 172.30.24.3.  The third host has an existing Lenovo maintenance agreement that expires on August 26, 2020.&lt;br /&gt;
&lt;br /&gt;
IMPORTANT INFORMATION: The purpose of the third host is for testing and housing a testing environment.  The third host is not meant to permanently house any VMs that are used in production.  If we care that a VM gets deleted because the datastore was blown away and recreated - then that VM never should have been on the third host.  The third host also has a different version of Intel Xeon processor compared to the other 2 hosts.  A 2620v3 versus a 2620v4.  This matters for doing a vMotion of a running VM either to or from the third host.  A vMotion of a powered on VM to or from the third host cannot happen until EVC mode is turned on for the entire cluster.  As of May 2018, EVC mode is disabled because enabling it requires an outage where all the VMs in the cluster are powered off and this linked procedure be followed https://kb.vmware.com/s/article/1013111 .  If a VM needs to vMotion to or from the third host, it must be powered off and it must fit within the 440GB datastore.&lt;br /&gt;
&lt;br /&gt;
=VMware Tools=&lt;br /&gt;
VMware Tools is a package of tools and drivers that most virtual machines need to have installed within the guest OS.  VMware Tools allows the hypervisor to talk and manipulate the virtual machine.  The tools package also contains many of the virtual hardware drivers that Windows needs to properly enumerate all the &amp;quot;fake&amp;quot; hardware.  For example, if a virtual machine is running Windows7, the OS will load the default VGA driver for the video card because natively Windows can't identify a virtualized video card.  Same deal for a virtualized network card, Windows won't and probably shouldn't load a built in Microsoft driver.  This is where VMware Tools comes in and provides those drivers for the OS.  When creating a virtual machine or converting a physical machine, the VMware Tools installer should be installed as soon as possible.  The installer can be triggered from the vSphere web interface.  The only exceptions to the rule that VMware Tools needs to be installed is if the virtual machine is an &amp;quot;appliance&amp;quot; or pre-built OVF deployment.&lt;br /&gt;
&lt;br /&gt;
=vCenter Standalone Converter=&lt;br /&gt;
The vCenter Standalone Converter is a badly named application that converts real physical computers into virtual machines running on a host.  The application is Windows based and is typically installed on an IT laptop or workstation.  The software creates a &amp;quot;triangle&amp;quot; where it talks to the source computer and the destination host.  To begin with the Converter needs the FQDN of the source computer and local administrator credentials.  AD administrator credentials are good enough if they are in the local admin group on the source machine.  The Converter then uses a WMI connection to figure out what hardware and OS is present on the source machine.  During the &amp;quot;Convert Machine&amp;quot; wizard, the Converter also opens a connection to the VCSA which manages the uniPHARM Cluster.  Once the Converter understands the source and destination, the user doing the conversion has a chance to customize certain options like how many vCPUs are in the converted VM and how much memory there is and whether or not the source machine is powered off at the end of the conversion.  &lt;br /&gt;
&lt;br /&gt;
At the end of the wizard the Converter creates an empty &amp;quot;shell&amp;quot; virtual machine on the chosen destination host and begins to copy the source hard drive(s) to it.  It is important to note that the drive copy is direct from the source to the destination and does not hop to the laptop controlling the conversion.  The hard drive copy process is using VSS in the context of converting Windows machines so the VMware best practice is to turn off any non-Microsoft services that are running prior to the conversion process to minimize any chance that VSS can't get a lock on a file.  It is also best practice to set the source machine in the convert wizard to power off at the end of the last sync so that the newly created VM can be up and running after the last sync and so that there is no duplicate IP address/name conflict.  According to VMware documentation, the same &amp;quot;magic&amp;quot; that makes a vMotion happen is used in the Converter to take running physical machines and turn them into running VMs with only a second or two of pause.&lt;br /&gt;
&lt;br /&gt;
When the Converter is finished copying the hard drive(s) and the last sync, the VM is set to either be up and running or powered off and ready to be powered on for the first time as a VM.  In the second scenario, when the converted VM is powered on for the first time, it will recognize a bunch of new hardware.  For example, an older IBM server would have a physical Broadcom NIC, when it is converted it will have a VMXNET NIC (and therefore use DHCP).  The Converter will inject all the drivers the newly converted VM will need to recognize all the different virtualised hardware.  There may be a need to do a reboot for a newly created VM as Windows typically asks for one when new hardware drivers are installed.  The person doing the conversion can also choose to have the Converter automatically install the VMware Tools package if needed.&lt;br /&gt;
&lt;br /&gt;
Be aware that the amount of time it takes to convert a physical machine to a VM is limited by network bandwidth.  All potential source machines are on the same switch stack as the VMHosts so that's as fast as it is going to be.  A source machine that has SSDs would be bottlenecked by a 1GB network connection, however an older slower source server with mechanical hard drives might not be.  In any case, there is a hard limit on how fast a 1GB connection can move data.  Also be aware that after the conversion process is finished and the VM is up and running, Windows may prompt to re-activate the OS license due to how much &amp;quot;hardware&amp;quot; has just changed.  Our servers are using volume licenses so there is no reason a re-activation should fail.&lt;br /&gt;
&lt;br /&gt;
The Converter application is currently installed on DarrenF's laptop, but can be installed on other I.S. laptops and is not tied to any licensing.  The Converter is free to use but can't do anything useful without vCenter.&lt;br /&gt;
&lt;br /&gt;
=VMware Licensing And Support=&lt;br /&gt;
uniPHARM has purchased a vSphere 6 Essentials Plus Kit that includes vCenter.  This means that the license entitles us to have a maximum of 3 hosts each having a maximum of 2 CPU sockets and we are entitled to 1 instance of vCenter.  The license is usable forever, but the attached technical support is renewed yearly.  The licenses and keys are available through the MyVMware portal at &lt;br /&gt;
* www.vmware.com&lt;br /&gt;
* Username is darrenf@unipharm.com&lt;br /&gt;
* Password is visionit&lt;br /&gt;
* Account number 114624681&lt;br /&gt;
* Customer number 9027898369&lt;br /&gt;
uniPHARM also owns a license for a very old version of VMware Server 2.0 and Workstation 9.0 which are both EOL and not usable.  While the current EPK licenses are installed correctly inside vCenter, if vCenter needs to be re-installed, the process is to run a licensing report from MyVMware, which generates a CSV file that is imported into vCenter.  The next step is to assign the vCenter license to itself and the vSphere licenses to the hosts.  VMware has announced that the End Of General support for vSphere 6.5 is November 15, 2021.  A support contract for version 6.5 would not be purchasable after that date and if we wanted support, we would be prompted to upgrade to 6.7 or later.  This end of general support date applies to the hypervisor install and the vCenter install.  Again, the licenses are perpetual and never expire, the support contract is renewable and does expire.&lt;br /&gt;
&lt;br /&gt;
=VM To Host Optimized Layout=&lt;br /&gt;
The following chart describes where a virtual machine should be located so as to balance the processing, memory and storage loads evenly among the 3 hosts in the cluster.  VM's can be moved around or shuffled from host to host when doing maintenance but this is the preferred layout of which hosts house which VM's. Changes to this chart will be documented in the change log at the bottom of this page.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;|VMHost01 !! style=&amp;quot;width: 15%&amp;quot;|VMHost02 !!  style=&amp;quot;width: 15%&amp;quot;|VMHost03&lt;br /&gt;
|-&lt;br /&gt;
| XClarity || SuperServer || 3CX Appliance&lt;br /&gt;
|-&lt;br /&gt;
| Lucy || UWDDC2 || TestServer1&lt;br /&gt;
|-&lt;br /&gt;
| Mail || VMware vCenter Server Appliance || UbuntuDevVM&lt;br /&gt;
|-&lt;br /&gt;
| Smithers || XTGUI || Windows7 Ent For Adobe LifeCycle&lt;br /&gt;
|-&lt;br /&gt;
| UWDDC1 || Zabbix NMS VM Appliance || WindowsXP Pro HP JetDirect&lt;br /&gt;
|-&lt;br /&gt;
| WDS ||  || Windows10 Ent Eval&lt;br /&gt;
|-&lt;br /&gt;
|  ||  || Windows10 Pro Eval&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Backups=&lt;br /&gt;
==Veeam==&lt;br /&gt;
As of May 2018, uniPHARM is evaluating Veeam Backup And Replication 9.5 as the platform used to do backups of VMware infrastructure and VM's.  This section is mostly a placeholder but the sub sections are full of relevant documentation.&lt;br /&gt;
===Hardware===&lt;br /&gt;
On December 20, 2010, uniPHARM purchased an IBM x3650 M3 server from Anisoft, with asset number 827.  The machine type is 7945-AC1 and the serial number is KQ128AR.  This machine (as of May 2018) has no IBM/Lenovo hardware maintenance agreement so if and when it has any sort of hardware failure of any kind, IBM/Lenovo will not come onsite with parts to repair.  This machine was used as the &amp;quot;SuperServer&amp;quot; until that OS was turned into a VM.  This machine does have an older IMM that can be accessed from the following URL and IP:&lt;br /&gt;
* http://bmveeam.unipharm.local&lt;br /&gt;
* Username  adminit&lt;br /&gt;
* Password  abc123&lt;br /&gt;
* IP 172.30.18.46&lt;br /&gt;
Because this machine has a very old IMM, it cannot be managed by XClarity.  As of May 2018, this machine has the latest firmware for the IMM and UEFI and hard drive controllers.  It contains 2 different hard drive controllers.  The ServeRAID M1015 and the ServeRAID M5015.  This machine has 16 slots for hard drives, numbered 0 to 15 and currently all the slots are populated with 15K-RPM spinning hard drives.  The hard drives in slots 0 and 1 are 136GB drives and 2 through 15 are 300GB drives.  The 136GB drives are in a RAID1 set and are used as the bootable C: drive with an install of Windows Server 2012R2.  The drives in slots 2 to 7 are in a RAID0 as well as drives 8 to 15 in another RAID0 on the second controller.  The M1015 and M5015 cannot create a JOBD or RAID0 across controllers because the controllers don't talk to each other.  In order to get the maximum amount of disk storage for Veeam, a striped Dynamic Disk was created in Windows as a layer on top of the 2 RAID0 sets to make 1 large D: that is 3.8TB.  A failure of any 1 hard drive in slots 2 through 15 will result in a LOSS OF ALL DATA on the D: drive.  The 136GB RAID1 set acting as the OS drive on C: can tolerate the failure of a single hard drive without data loss - a failure of both drives will result in data loss.  The above arrangement of hard drives is not a best practice, but is an acceptable risk given the nature of backups and budgets.&lt;br /&gt;
&lt;br /&gt;
This machine has a pair of 1GB network cards that are using QLogic drivers as QLogic bought out Broadcom and when Windows Server 2012R2 was installed in May of 2018, the QLogic drivers were installed, however the chips for the NICs are Broadcom.  Only the first NIC is being used on IP 172.30.18.9, however the second NIC can be used in a team to provide a 2GB connection with the core Server Room switches are replaced.  The older IMM is using a dedicated port on the back of the machine.  This server has 1 out of 2 processor sockets occupied with an 8 core Xeon E5620 and 8GB of memory.&lt;br /&gt;
&lt;br /&gt;
===Veeam Software Installation===&lt;br /&gt;
In May of 2018, Veeam Backup And Replication 9.5 was installed.  This package also installs the Express version of Microsoft SQL 2012 plus supporting files for SQL.  Along with Veeam Backup and Replication, Veeam Enterprise Manager and Veeam ONE were also installed as they come free with the perpetual license.  Veeam Enterprise Manager is a web based front end for the Veeam Console and has a subset of functions and features compared to the Console.  Veeam ONE is a reporting and BI tool that displays graphs and charts and statistics in regards to a VMware/Veeam environment.  While Veeam ONE is included free with the perpetual license, it is geared to much larger environments compared to ours - as in hundreds of hosts and thousands of VMs and lots and lots of storage.  The full Veeam Console should be also installed on an IT laptop so administrators can make configuration changes if needed without using remote desktop to the physical server.  This is very similar to how BackupExec worked.  The Veeam Backup And Replication package needs to use the administrator@vsphere.local account to access the VCSA and any subordinate VM's.  This account is critical to successful backups and if the password is changed, that change needs to also be changed within the credential manager inside Veeam.  The Active Directory domain administrator account is also used to access the remaining physical servers via the Veeam Agent, so if that password is changed, it also needs to be changed within the credential manager inside Veeam.&lt;br /&gt;
&lt;br /&gt;
===Veeam Licensing===&lt;br /&gt;
We will probably get perpetual licensing with renewable annual support&lt;br /&gt;
===What Is Veeam Backing Up?===&lt;br /&gt;
Veeam will be able to backup the VM's and itself and whatever few remaining physical servers that are still in use.&lt;br /&gt;
===Backup Strategy And Scheduled Jobs===&lt;br /&gt;
Placeholder something something something.&lt;br /&gt;
===How Veeam Uses Tape Hardware===&lt;br /&gt;
Placeholder something something something.&lt;br /&gt;
===Veeam Technical Support===&lt;br /&gt;
Put the terms of the support contract in here plus the phone number and expiry dates.&lt;br /&gt;
&lt;br /&gt;
=Change Log - Try And Record Any Major Configuration Or Software/Hardware Changes To The Infrastructure Here=&lt;br /&gt;
==2018==&lt;br /&gt;
# Both servers have their UEFI/BIOS set to only boot from the USB thumb drive&lt;br /&gt;
# Both servers have their UEFI/BIOS set to use maximum performance in the power settings as per this KB article https://www.ibm.com/support/home/docdisplay?lndocid=migr-5098137&lt;br /&gt;
# Initial ESX version installed on March 21, 2018 is 6.5.0 Build 7388607&lt;br /&gt;
# VMHost01DataStore01 created as the first datastore&lt;br /&gt;
# The local datastores are seen as non-ssd by ESX because they are behind a RAID controller and not part of a vSAN&lt;br /&gt;
# VCSA password is NewVisionIT@2051&lt;br /&gt;
# vcsa.unipharm.local is at 172.30.18.23&lt;br /&gt;
# VCSA virtual machine set to automatically start when the hypervisor on VMHost01 boots&lt;br /&gt;
# VCSA added to Active Directory as a computer object for SSO on March 22, 2018, located in the Servers OU&lt;br /&gt;
# Configed SSO according to https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.vcsa.doc/GUID-08EA2F92-78A7-4EFF-880E-2B63ACC962F3.html&lt;br /&gt;
# Added DarrenF and NorwinU AD user accounts as being able to log into VCSA web client&lt;br /&gt;
# vMotion IP on VMHost01 is 172.30.24.1  IP on VMHost02 is 172.30.24.2&lt;br /&gt;
# 8 minutes to vMotion 60GB Win7 cagepc as a test P2V on March 23, 2018 with no VLAN&lt;br /&gt;
# Created content library and uploaded the xclarity OVF and 3CX ISO files March 23, 2018&lt;br /&gt;
# Added VLAN 5 to vMotion Network - NorwinU configed physical switch to use VLAN 5 on ports 4 and 16 on Stacked Switch 1of4 March 23, 2018&lt;br /&gt;
# Changed VLAN 5 to 3 for some reason and changed the TCPIP stack for the vMotion Network for optimization&lt;br /&gt;
# Added DarrenF and NorwinU AD accounts as permitted Administrators to the entire VCSA hierarchy and got SSO working correctly&lt;br /&gt;
# Configured VUM to scan for updates each Monday of every week and email DarrenF&lt;br /&gt;
# Ran a VUM Remediation to install Spectre VIBs via the VUM wizard both hosts now at 6.5 build 7967591 March 26, 2018&lt;br /&gt;
# P2Ved the Thermoprofile physical server onto VMHost01 March 26, 2018&lt;br /&gt;
# Set the Thermoprofile VM to autostart on VMHost01 March 28, 2018&lt;br /&gt;
# Tweeked CPU usage alarm to have more time at 90 and 100% - updated documentation April 3, 2018&lt;br /&gt;
# P2Ved the Lucy physical server onto VMHost01 April 7, 2018&lt;br /&gt;
# P2Ved the Mail physical server onto VMHost01 April 15, 2018&lt;br /&gt;
# Logged into the VCSA PSC Controller and set the root password to never expire instead of expiring every 90 days April 25, 2018&lt;br /&gt;
# Set the administrator@vsphere.local account to expire its password every 9999 days April 25, 2018&lt;br /&gt;
# Turned on the BASH shell for the VCSA PSC and set the correct time zone for NTP April 25, 2018&lt;br /&gt;
# Downloaded the VMware trusted root CA certificate from https://vcsa.unipharm.local and installed that into the Trusted Root store on DarrenF's laptop so that the webclient is trusted by IE11 and makes uploading of ISO files to the Content Library possible using an SSO login May 3, 2018&lt;br /&gt;
# P2Ved the SuperServer physical server onto VMHost02 May 5, 2018&lt;br /&gt;
# Uploaded the ISO for Windows Server Standard 2012R2 to the Content Library May 7, 2018&lt;br /&gt;
# Created the XClarity VM appliance from an OVA file in the Content Library - May 9, 2018&lt;br /&gt;
# Created a VM for NancyN to use for Adobe LifeCycle - see the notes pane in the Flash client for details on this otherwise undocumented VM - May 16, 2018&lt;br /&gt;
# P2Ved the Smithers physical server onto VMHost01 May 19, 2018&lt;br /&gt;
# Added hardware that used to be the Smithers server as a third host to the cluster (VMHost03) May 28, 2018&lt;br /&gt;
# VMware support ticket 18814250705 for how to enable EVC mode opened and then closed with no changes because enabling EVC requires all VMs to be off May 30, 2018&lt;br /&gt;
# VMware support ticket 18815369505 for how to get a database backup from the VCSA to FTP opened May 30, 2018&lt;br /&gt;
# New VM created called WDS.unipharm.local with the purpose of housing the WDS feature and Spiceworks and KiwiSyslog - June 8, 2018&lt;br /&gt;
# New VMs created called UWDDC1 and UWDDC2 to act as Active Directory Domain Controllers - June 11, 2018&lt;br /&gt;
# Thermoprofile virtual machine deleted from the datastore on June 13, 2018&lt;br /&gt;
# XClarity virtual appliance deleted and then recreated using the version 2.0 OVA file&lt;br /&gt;
# Created new virtual machine called XTGUI with the purpose of it being used as a server for the Iptor DC1 GUI - June 21, 2018&lt;br /&gt;
# Created an internal backup of the VCSA and uploaded that to ftp.unipharm.com  - August 27, 2018&lt;br /&gt;
# Uploaded the VCSA upgrade ISO (6.5.0.22000-9451637) to VMHOST01DATASTORE01  - August 27, 2018&lt;br /&gt;
# Upgraded the VCSA to 6.5 U2C build 9451637- August 27, 2018&lt;br /&gt;
# Upgraded ESX hypervisors on hosts to 6.5 U2C build 9298722 - September 1, 2018&lt;br /&gt;
# Upgraded all VMware Tools installed in all Windows VM's to 10305 - September 1, 2018&lt;br /&gt;
# Changed configuration setting &amp;quot;VMkernal.BootHyperthreadingMitigation&amp;quot; from False to True on VMHost03 due to its older processor - September 5, 2018&lt;br /&gt;
# Cleared BIOS event logs on VMHost03 and undid the hyperthreading changes from above - September 5, 2018&lt;br /&gt;
# Created a new VM called 3CX Server Appliance from an ISO in the Content Library to be used as a PBX - September 26, 2018&lt;br /&gt;
# Created new virtual port groups on vSwitch2 on each host to enable VMs to be on Alt-Guest VLAN. The port group is tagged to VLAN 2. - September 28, 2018&lt;br /&gt;
# vMotion 3CX appliance to vmhost03 where I can play with it. -17:05, 28 September 2018 (PDT)&lt;br /&gt;
# Increased hard drive from 70GB to 100GB on the WDS virtual machine to accommodate new desktop images - October 19, 2018&lt;br /&gt;
# Created TestServer1 on VMHost03 - a Windows 2016 server for generic testing purposes. NetStore and TLAForm will be installed on it for testing with DC1.&lt;br /&gt;
# Created virtual switch VoIP LAN (VLAN 6). - November 29, 2018&lt;br /&gt;
# 3CX Server VM reinstalled and connected to VoIP VLAN. - November 29, 2018&lt;br /&gt;
# Created UbuntuTestVM VM, as a generic test VM that can be connected to different VLANs for various network testing / diagnostics purposes. - November 29, 2018&lt;br /&gt;
==2019==&lt;br /&gt;
# DarrenF created 2 VMs for Windows10 testing on April 4, 2019.  The VM's are on VMHost02.&lt;br /&gt;
# DarrenF removed an old snapshot for the XTGUI Server and for the vCenter VM on May 8, 2019.&lt;br /&gt;
# DarrenF made a backup of the VCSA on May 17, 2019 and saved the backup file to the SuperServer.&lt;br /&gt;
# DarrenF upgraded the VCSA from 6.5.0-22000 to 6.5.0.24000 on May 22, 2019 and finished that with a reboot.&lt;br /&gt;
# DarrenF upgraded all 3 hosts to ESX version 6.5.0-13635690 on May 24, 2019&lt;br /&gt;
# DarrenF upgraded the UEFI and IMM2 and DSA firmware on all 3 hosts on May 24, 2019.&lt;br /&gt;
# DarrenF upgraded the VMware Tools install on some VM's that could be rebooted during the day on May 27, 2019 - remaining VM's will be upgraded at a later date.&lt;br /&gt;
# DarrenF updated this documentation with information on which VM's should located on each host - May 27, 2019.&lt;br /&gt;
# DarrenF created a new VM for the Zabbix NMS VM Appliance using an ISO located in the Content Library - July 10, 2019&lt;br /&gt;
# DarrenF enabled SNMP on all three hosts and the VCSA so that Zabbix could monitor via SNMP - July 12, 2019.&lt;br /&gt;
[[Category: Virtualization]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VMWare_Production_Infrastructure&amp;diff=14489</id>
		<title>Information Systems:VMWare Production Infrastructure</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VMWare_Production_Infrastructure&amp;diff=14489"/>
		<updated>2023-08-19T21:14:51Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Hardware=&lt;br /&gt;
uniPHARM purchased a pair of Lenovo x3650 M5 servers in March of 2018 from Anisoft to act as hosts for VMware.  The machine type of both servers is 8871-16A and the serial numbers are J121W8C and J121W8D.  Both servers do have identical hardware components and as of March 2018, they also have identical and current firmware.  Both servers have an Intel Xeon E5-2620 v4 processor populating the first socket.  The second socket for both servers is empty.  The Xeon has 8 cores and 16 threads.  Both machines came with an initial 16GB stick of memory in the first slot.  An additional 6 sticks of 8GB were installed into each server so that each has 64GBs of memory.  Be aware that the motherboard has specific requirements for where additional memory can be inserted.  The numerical order for which memory slots can be used is clearly displayed on the top side lid of the server.  If more memory is purchased and installed for these servers, the instructions on the top lid must be followed, or the memory will not be recognized correctly.  The memory slots labeled from 13 to 24 on the motherboard cannot be used until the second CPU socket has a processor.&lt;br /&gt;
&lt;br /&gt;
Each server has an ServeRAID M5210 controller that is attached to the motherboard.  For each M5210, there is also a RAID5 daughter card that is attached which provides additional capabilities.  The M5210 can control up to 24 drives for each server.  The initial purchase included 5 drives for each server that are 960GB SSDs.  Both of the M5210 controllers are configured with a RAID6 set containing the 5 SSDs.  The RAID6 volume can survive the failure of 2 drives before there is data loss.  There are no warm or cold spare drives available as of March 2018.  The total amount of storage space on each server is 2679GB.  The strip size is 256KB.  All parameters of the RAID6 set were set to default for the M5210 controller.  Each server also has a USB thumb drive that is plugged into the motherboard where the hypervisor software is installed.  The thumb drive is 2GB in size and is USB2.0.&lt;br /&gt;
&lt;br /&gt;
Each server has 4 network ports that use the Broadcom NetXtreme chip.  Each server has an additional network port that is for dedicated IMM2 access.  More on the IMM2 is below.  Each server has 2 USB and a VGA port on the front side and the back side.  The purchased configuration of each server did not include any riser cards for PCIe expansion cards so if there is a need for extra abilities, the riser cards are also required.  Each server has 2 power supplies which can share the load as well as take the entire electrical load should 1 fail.  Each server has different power sources feeding into each power supply.  The top, or number 2 power supply for each server, is fed from the right side PDU in the Power8 rack.  The bottom, or number 1 power supply, is fed from the left side PDU.  The PDU's are the &amp;quot;power strips&amp;quot; on each side of the rack where the right side gets power from the Leibert UPS and the left gets power from the Power8 UPS at the bottom of the rack.  This all means that in the event of a Hydro power failure, the servers will stay up and operational even if one out of two UPS's fails.  Both servers will immediately power off if there is a Hydro power failure AND BOTH UPS's also fail or run out of battery power.&lt;br /&gt;
&lt;br /&gt;
Both servers are located in the Power8 rack and are 2U in size.  The top server is at rack unit 18 and the bottom server is at rack unit 16.  Both servers can be pulled out on the rack rails and serviced while powered on.  The hard drives and power supplies are hot swappable but the memory is not.  Neither server has a CD-ROM drive so if a disc needs to be used, the only option is to plug in a USB optical drive.&lt;br /&gt;
&lt;br /&gt;
==Hardware - Network Port Map==&lt;br /&gt;
This list shows the layout of the network cables that connect the servers to the stacked core network switches in the Server Room.&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  2 goes to VMHost01 dedicated IMM2 port&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 14 goes to VMHost02 dedicated IMM2 port&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  3 goes to VMHost01 Management Port on eth2&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 15 goes to VMHost02 Management Port on eth2&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  4 goes to VMHost01 vMotion Port on eth3&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 16 goes to VMhost02 vMotion Port on eth3&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  5 goes to VMHost01 LAN1 Uplink on eth0&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 17 goes to VMHost01 LAN2 Uplink on eth1&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port  6 goes to VMHost02 LAN1 Uplink on eth0&lt;br /&gt;
* Server Room Stacked Switch (1of4 - Top) Port 18 goes to VMHost02 LAN2 Uplink on eth1&lt;br /&gt;
&lt;br /&gt;
==Hardware Purchase Details==&lt;br /&gt;
The purchase order number for this project is 8226136 (dated Feb 13, 2018) with a vendor number of 20145 and invoices numbers 19253, 19254, 19256 dated March 14, 2018.&lt;br /&gt;
&lt;br /&gt;
==Hardware Support==&lt;br /&gt;
uniPHARM has a hardware maintenance contract with Lenovo to provide 24x7x365 onsite parts and labour with a 4 hour response time for the period of March 6, 2018 to March 5, 2021.  A renewal of this maintenance contract is expected in February of 2021 because the expected life span of these servers is 5 to 6 years.  Note that &amp;quot;maintenance&amp;quot; is not a good descriptor of the service.  If a hardware component fails, then the replacement of that part is provided by Lenovo at no cost and is installed by a Lenovo technician at no cost.  If uniPHARM adds in non-Lenovo parts they are not covered by the existing contract.  Additional Lenovo branded parts that are installed after initial purchase are covered under the existing contract.  If a non-Lenovo part is installed and causes damage to the server, the agreement becomes null and void.  The phone number for parts replacement and technical support under this contract is 1-800-426-7378.  This contract does not cover any VMware software.&lt;br /&gt;
&lt;br /&gt;
=IMM2=&lt;br /&gt;
The Integrated Management Module II is an out of band service used to control the x3650 server hardware.  It is comparable to the HMC for the Power8.  The IMM2 is on and active and accessible as long as the server has power feeding into the power supplies.  If both power supplies are unplugged, the IMM2 is not active and accessible.  The IMM2 resides on a small &amp;quot;SystemOnChip&amp;quot; on the motherboard and is served by a webserver within a small Linux OS within the SOC.  The IMM2 also has a dedicated network port that is only used by that function.  On smaller 1U servers the IMM2 shares the first Broadcom network port.&lt;br /&gt;
&lt;br /&gt;
The IP addresses assigned to each of the 2 IMM2's are 172.30.18.54 and 172.30.18.55.  The host names are bmvmhost01.unipharm.local and bmvmhost02.unipharm.local.  BM is a hold over from a previous IBM product called &amp;quot;Baseboard Management&amp;quot; and this naming convention is a continuation of that.  The username for both IMM2's is adminit and the password is visionit.  The IMM2's are not accessible from the public side of the firewall and need VPN access if logging in from outside the local network.&lt;br /&gt;
&lt;br /&gt;
* https://bmvmhost01.unipharm.local&lt;br /&gt;
* https://bmvmhost02.unipharm.local&lt;br /&gt;
&lt;br /&gt;
The IMM2 web interface is primarily used to control the hardware, alert for hardware failures and to provide a screen console for the server when no physical screen-keyboard-mouse is attached.  This is a critical function for troubleshooting or diagnosing software crashes no matter what OS or hypervisor is installed.  The console screen function can be presented using a ActiveX, or Java, or HTML5 app that is served from the IMM2 - no need to install any EXE on a laptop.  The Java client works consistently.  The IMM2 can power on or off the server and show very detailed information on temperatures, fan speeds, voltages and firmware levels of all components.  The IMM2 is also setup to email alerts to I.S. staff when hardware events occur such as a failed hard drive or power supply.  The IMM2 is also configured to call home to Lenovo when a hardware component fails in the same manner that the HMC connects to IBM when a Power8 hardware failure occurs.&lt;br /&gt;
&lt;br /&gt;
As of March 2018, the x3650 servers do have the latest available firmware and should not need any firmware updates unless Lenovo requires it for replacement parts.  If updated firmware is needed, it can be installed from within the IMM2 web interface.&lt;br /&gt;
&lt;br /&gt;
=vSphere ESXI Hosts=&lt;br /&gt;
The vSphere (ESX) hypervisor is installed on the USB thumb drive that is plugged into the internal motherboard port for each server.  The customized Lenovo version of the ESX installer was used as it is pre-compiled with all of the device drivers present in Lenovo branded hardware.  Each server, now known as a host, is set to only boot from that USB thumb drive.  The hypervisor operating system boots and loads into memory and is thusly ready to house and run virtual machines.&lt;br /&gt;
* Server with serial number J121W8C has a host name of vmhost01.unipharm.local&lt;br /&gt;
* The administrator username is root&lt;br /&gt;
* The administrator password is NewVisionIT2051!&lt;br /&gt;
* The management network is on eth2 which is the third network port on the back of the server&lt;br /&gt;
* The management network IP address is 172.30.18.19 subnet 255.255.248.0 gateway 172.30.16.1 and is configured to do DNS lookups to 172.30.18.13 and .14&lt;br /&gt;
* The management network is using the default VLAN&lt;br /&gt;
and&lt;br /&gt;
* Server with serial number J121W8D has a host name of vmhost02.unipharm.local&lt;br /&gt;
* The administrator username is root&lt;br /&gt;
* The administrator password is NewVisionIT&lt;br /&gt;
* The management network is on eth2 which is the third network port on the back of the server&lt;br /&gt;
* The management network IP address is 172.30.18.20 subnet 255.255.248.0 gateway 172.30.16.1 and is configured to do DNS lookups to 172.30.18.13 and .14&lt;br /&gt;
* The management network is using the default VLAN&lt;br /&gt;
The web administration pages to directly access the ESX hypervisor and bypass vCenter are:&lt;br /&gt;
* https://vmhost01.unipharm.local&lt;br /&gt;
* https://vmhost02.unipharm.local&lt;br /&gt;
The above links that go directly to the hypervisor don't need to be used or accessed for day to day administration because all administrative tasks should be done within the vCenter user interface.  The above links only need to be accessed if vCenter is unavailable, down or broken.&lt;br /&gt;
&lt;br /&gt;
=vCenter Server Appliance=&lt;br /&gt;
During Stage 1 of the VCSA setup, the following settings were used&lt;br /&gt;
* The FQDN of the VCSA is vcsa.unipharm.local&lt;br /&gt;
* The IP address of the VCSA is 172.30.18.23&lt;br /&gt;
* The password for the VCSA is NewVisionIT@2051&lt;br /&gt;
* The password requires upper and lower case letters AND a number AND a special character but no spaces are allowed.&lt;br /&gt;
* The VCSA has an integrated, as in no external, Embedded Platform Services Controller&lt;br /&gt;
* The VCSA was deployed in &amp;quot;Tiny&amp;quot; mode and is using a thin provisioned virtual disk&lt;br /&gt;
During Stage 2 of the VCSA setup, on the SSO configuration screen, the following settings were used&lt;br /&gt;
* Single Sign-On domain name is vsphere.local&lt;br /&gt;
* Single Sign-On user name is administrator&lt;br /&gt;
* Single Sign-On password is NewVisionIT@2051&lt;br /&gt;
* Site name is uniPHARM&lt;br /&gt;
* SSH access was enabled&lt;br /&gt;
* The following link was used as a guide for the very confusing and badly designed SSO setup https://esxsi.com/2016/11/16/vcsa65/&lt;br /&gt;
Please note that if the VCSA virtual machine needs to be rebooted, it will take a good 5 minutes for the web page to be accessible and you may see a plain text page saying the interface is initializing so be patient as the appliance settles down after a reboot.&lt;br /&gt;
==vCenter Management==&lt;br /&gt;
* The URL for vCenter Flash site is https://vcsa.unipharm.local/vsphere-client/&lt;br /&gt;
* The URL for the vCenter HTML5 site is https://vcsa.unipharm.local/ui   &amp;lt;------ The HTML5 site is waaaaaaaaay better than the Flash site AND it has a dark mode them which is bananas.&lt;br /&gt;
* Username is  administrator@vsphere.local&lt;br /&gt;
* Password is  NewVisionIT@2051&lt;br /&gt;
* The URL for the vCenter Appliance Management site is https://vcsa.unipharm.local:5480&lt;br /&gt;
* The username is root and the password is NewVisionIT@2051&lt;br /&gt;
The virtualization infrastructure is designed according to VMware's best practices.  In vCenter, a datacenter has been created and called &amp;quot;uniPHARM Datacenter&amp;quot;.  It contains a cluster called &amp;quot;uniPHARM Cluster.  The cluster contains both hosts and any virtual machines are listed under the hosts.  The cluster was created with DRS and HA turned off to begin with, however they can be turned on a later time.  Each host has a single datastore and they are named VMHost01DataStore01 and VMHost02DataStore01.  Each datastore is the entire RAID6 set of 5 SSDs, totaling 2.62TB of usable space.  If, in the future, there is ever a need to add storage, the naming convention should continue with VMHost01DataStore02 or VMHost01DataStore03.&lt;br /&gt;
&lt;br /&gt;
===vCenter Management - vNetwork===&lt;br /&gt;
As mentioned above, each host has 4 gigabit network ports.  The network configuration for our VMware infrastructure is not complex, by VMware standards but the information below is critical to understanding how it has been designed:&lt;br /&gt;
* The first (vmnic0) and second (vmnic1) NICs are used for everyday ordinary network traffic going in or out from or to the virtual machines&lt;br /&gt;
* The first (vmnic0) NIC is connected to vSwitch2 and is labeled as &amp;quot;uniPHARM Production LAN&amp;quot; - imagine that an invisible virtual switch lies between the first NIC and the real physical switch in the Server Room&lt;br /&gt;
* The second (vmnic1) NIC is initially not configured to do anything as of March 2018 but it can be used for a second Production LAN or some sort of testing LAN or fail over if licensing permits&lt;br /&gt;
* The third (vmnic2) NIC is configured as a vmKernel port (172.30.18.19 &amp;amp; 20) connected to vSwitch0 acting as the &amp;quot;Management Network&amp;quot;&lt;br /&gt;
* The third (vmnic2) NIC and vSwitch0 are only used as a connection that vCenter uses to control the hosts and its setup is a best practice from VMware&lt;br /&gt;
* The fourth (vmnic3) NIC is configured as a vmKernel port (172.30.24.1 &amp;amp; 2) connected to vSwitch1 on VLAN 3 acting as the &amp;quot;vMotion Network&amp;quot; and is only used when a virtual motion needs to move from one host to another&lt;br /&gt;
It is CRITICALLY important that ANY vnic, vSwitch or vmKernel configuration changes that are made on one host are precisely repeated on the other host.  Having different vSwitch labels, for example, prevents vMotion from succeeding.  Our EPK license does not permit distributed switches so we have to do the configuration changes manually to each host.&lt;br /&gt;
&lt;br /&gt;
===VUM VMware Update Manager===&lt;br /&gt;
VUM has been configured with a dynamic baseline for the hosts and for the VCSA.  The best explanation of how VUM works is this link - https://www.youtube.com/watch?v=X_xGihAfLSo  Please note that the safest way to apply patches and updates to the hosts hypervisor is to vMotion all the VM's on one host to another and then to remediate the empty host, then vMotion all the VM's back and do the other host.  Since we only have 2 or 3 hosts and don't apply patches very often, this method (while time consuming) results in very little down time and a patched infrastructure.  An alternate method is to schedule a Saturday, for example where all the VM's can be gracefully shutdown and then when they are ALL off, use VUM to do a patch cycle of each host one at a time.&lt;br /&gt;
&lt;br /&gt;
If the VCSA itself needs to be updated, see this VMware KB article. https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.upgrade.doc/GUID-6751066A-5D4E-47AC-A6A4-5E90AEC63DAA.html  The VCSA should be updated and rebooted BEFORE applying any new patches or versions to a host.&lt;br /&gt;
&lt;br /&gt;
===vCenter Alarm Configuration===&lt;br /&gt;
vCenter has been configured to use a small number of alarms that email alerts when certain conditions are encountered.  The alarm configuration is done at the VCSA level in the hierarchy:&lt;br /&gt;
* &amp;quot;Host connection and Power State alarms when the Connection State is equal to Not Responding and the host is at Standby or Powered Off - then emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;Host CPU Usage&amp;quot; alarms a warning when CPU is above 75% for 10 minutes and a critical when the CPU is above 90% for 10 minutes - then emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;Virtual Machine CPU Usage&amp;quot; alarms a warning when a vCPU is above 90% for 20 minutes and alarms critical when vCPU is at 100% for 30 minutes - emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;Virtual Machine Memory Usage&amp;quot; alarms a warning when a memory is above 90% for 10 minutes and alarms critical when memory is above 95% for 10 minutes - emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;Datastore Usage On Disk&amp;quot; alarms a warning when datastore usage is above 80% and alarms critical when above 90% - emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;uniPHARM Alarm Network Unplugged&amp;quot; alarms when a NIC is unplugged - emails DarrenF and NorwinU&lt;br /&gt;
* &amp;quot;uniPHARM Alarm VM Powered Off&amp;quot; alarms when a VM is powered off - emails DarrenF and NorwinU&lt;br /&gt;
&lt;br /&gt;
===Content Library===&lt;br /&gt;
Within vCenter, a content library called uniPHARM Content Library has been created.  The purpose of the library is to store ISO and OVF files that are used when creating new VM's so that an OS can be booted - remember that the VMHosts don't have attached CD-ROM drives.  Since creating new VM's is not a daily occurrence, the content library should be empty or mostly empty for the majority of the time in order to not consume storage space that is best served for VM's.  The content library can only be used for virtual machines created on VMHost01 because that is the datastore where the content library is located.  A newly created virtual machine on the other 2 hosts can't use the content library because it's not on shared storage.  Also be aware that IE11 cannot upload ISO files greater than 4GB in size, you have to use a different browser.  Please for the love of Bhudda, label what you are uploading to the Content Library so that others know what it is.&lt;br /&gt;
&lt;br /&gt;
=Virtual Machines=&lt;br /&gt;
A virtual machine is like a bucket.  The bucket contains a simulated processor, memory and a flat file that acts as a hard drive.  An OS can be installed inside the bucket and can be given a network connection which is also simulated.  The OS can't tell the difference between real hardware and simulated so it behaves normally.  The bucket that contains the simulated hardware and the OS install, sits on top of the hypervisor.  The hypervisor takes simulated hardware calls and maps them to real physical hardware so that each bucket can get a slice of processor and memory.  The real hardware can house many buckets and the contents of each bucket don't mix or interact preserving the containerization.  And finally buckets can be moved to different hardware without interrupting the OS contents via hocus pocus magic.&lt;br /&gt;
==VCSA==&lt;br /&gt;
The vCenter appliance VM was created with all the default settings as they were set by the ISO installer.  It currently has 2 vCPUs and is using 1.5GB of memory.  It has a very unique way of using 14 different thin provisioned VMDK files that act as its hard drives and is currently only using 25GB of real storage space.  The VM hardware version is 10.  This VM is very important to safe and healthy operation of our virtualization infrastructure.&lt;br /&gt;
&lt;br /&gt;
==XClarity==&lt;br /&gt;
XClarity is a software based virtual appliance from Lenovo that shows hardware inventory and does hardware alerting.  XClarity is a much more slimmed down modern packaged that is what IBM Director was supposed to be.  The OS for the VM is a Linux something where access by the user is restricted.  The VM is using 1 vCPU and 8GB of memory and is thin provisioned for 64GB of storage and is actually using only 12GB of storage.  The IP address assigned to the VM is 172.30.18.2 and the URL for the sit is :&lt;br /&gt;
* https://xclarity.unipharm.local/ui/login.html&lt;br /&gt;
The local login for the above URL is:&lt;br /&gt;
* Username - adminit&lt;br /&gt;
* Password - NewVisionIT2051&lt;br /&gt;
* Active Directory SSO is currently not working in XClarity 1.4&lt;br /&gt;
The XClarity 1.4 software appears to be fairly straight forward and is able to talk to all the IMM's for our current small fleet of Lenovo servers.  The software is set to email DarrenF and NorwinU if there is a hardware failure on any of the Lenovo servers.  These alerts are in addition and perform the same function as the IMM's on each machine and is strictly limited to hardware failures.  There is an excellent Android app that talks to XClarity over a VPN connection, however it requires that the XClarity appliance root and subordinate certificates be installed on the phone in order to gain access.  This is security overkill but DarrenF did install those certificates on his phone and the app is worth this effort though others are free to disagree.  This VM appliance was created from an OVA file on May 9, 2018.  As of May 2018, this VM is not being backed up by anything and doesn't really need to be because it can be recreated from the OVA file.  This VM is in no way business critical and can be powered off if needed.&lt;br /&gt;
* It was discovered after the setup of XClarity 1.4 was completed that there is a 2.0 that will be installed and configured again as a VM appliance at a later date.  Both versions are supported by Lenovo but because the software is the free version, uniPHARM has no support contract.&lt;br /&gt;
* XClarity cannot talk to the IMM on the old SuperServer hardware because the hardware is not on the XClarity HCL.  We are going to continue using SuperServer hardware for Veeam but XClarity cannot monitor that hardware.  XClarity also cannot monitor Lenovo desktops or laptops - only Lenovo servers, storage SANs and Lenovo switches.&lt;br /&gt;
&lt;br /&gt;
==Thermoprofile==&lt;br /&gt;
This is the first physical server to be converted into a virtual machine:&lt;br /&gt;
* Shrunk the 2 physical hard drives - C: from 150GB to 100GB and D: from 250GB to 150GB&lt;br /&gt;
* Configured the VM to use 1 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
This VM is ultimately going to go away because the applications on it (Spiceworks, KiwiSyslog, WDS/MDT need to be migrated onto a freshly made Windows Server 2012R2 VM where the OS license is re-used.  The conversion of the Windows Server 2008R2 physical machine is acting as a test case for more critical conversions.&lt;br /&gt;
* Thermoprofile VM had its applications (Spiceworks and KiwiSsylog + WDS) moved to a new VM called WDS.unipharm.local on Friday June 8, 2018.  The Thermoprofile VM was powered off and removed from the BackupExec jobs.  The VM was deleted on June 13, 2018.&lt;br /&gt;
&lt;br /&gt;
==Mail==&lt;br /&gt;
This is the third physical server to be converted into a virtual machine: &lt;br /&gt;
* The physical hard drive was thick provisioned and not shrunk&lt;br /&gt;
* Configured the VM to use 2 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
For more information on this server, please see the following link: http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Mail_Server&lt;br /&gt;
&lt;br /&gt;
==SuperServer==&lt;br /&gt;
This is the fourth physical server to be converted into a virtual machine: &lt;br /&gt;
* The physical hard drives were thick provisioned and shrunk during the conversion process&lt;br /&gt;
* The C: drive was configured to be 100GB, the D: was configured to be 1000GB and the E: was configured to be 500GB&lt;br /&gt;
* Configured the VM to use 2 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
For more information on this server, please see the following link: http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:SuperServer&lt;br /&gt;
&lt;br /&gt;
==WindowsXP JetDirect==&lt;br /&gt;
DarrenF created this VM a long time ago in VMware Workstation so that the HP JetDirect boxes at each picking station can be controlled, configured and setup correctly.  The JetDirect boxes are so old that their web administration pages only work with Microsoft Java, which only exists in a 2002 version of WindowsXP prior to SP1 or SP2.  The web administration page of the JetDirect boxes works in the same manner as pages for all the other network attached printers.  The admin page for the JetDirect boxes need to have the correct IP address and host name set plus other print and network options.  New Windows OS's like Windows 7 and 10 are not able to display the JetDirect web admin page because the version of Java it needs does not exist in newer versions of Windows.  Having a VM with an old version of Windows is the most convenient method if someone needs to configure a JetDirect box, otherwise, the VM can be left powered off.  This VM is only taking up 16GB of storage space.&lt;br /&gt;
&lt;br /&gt;
==Lucy==&lt;br /&gt;
This is the second physical server to be converted into a virtual machine:&lt;br /&gt;
* Shrunk the 2 physical hard drives - C: from 150GB to 75GB&lt;br /&gt;
* Configured the VM to use 2 vCPU and 4GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
* The VM does not have the serial ports that the physical machine had installed in its PCI slots&lt;br /&gt;
&lt;br /&gt;
==Smithers==&lt;br /&gt;
This is the fifth physical server to be converted into a virtual machine: &lt;br /&gt;
* The physical hard drive was thick provisioned and shrunk during the conversion process&lt;br /&gt;
* The C: drive was configured to be 150GB&lt;br /&gt;
* Configured the VM to use 2 vCPU and 16GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
The physical server that was Smithers, had a red coloured USB licensing dongle that was used for the Kofax scanning software.  Prior to the P2V, the licensing dongle was moved to the Gauss scanning station in Accounting.  The Gauss software &amp;quot;package&amp;quot; on the Smithers VM, plus both scanning desktops now point to the USB dongle in Accounting for licensing compliance.  The Smithers VM has no special USB pass-through because the USB dongle was moved prior to the P2V.  For more information on this server, please see the following link: http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Smithers&lt;br /&gt;
&lt;br /&gt;
==WDS==&lt;br /&gt;
This is a new virtual machine created (not converted) with a fresh Windows Server 2012R2 OS install for housing the Windows Deployment Service and Spiceworks and KiwiSyslog.  WDS is where desktop and laptop images are stored and downloaded from when a workstation does a PXE boot to install Windows.&lt;br /&gt;
* The virtual hard drive was thin provisioned at 70GB&lt;br /&gt;
* The C: drive was configured to be 100GB&lt;br /&gt;
* Configured the VM to use 1 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
&lt;br /&gt;
==UWDDC1==&lt;br /&gt;
This is a new virtual machine created (not converted) with a fresh Windows Server 2012R2 OS install to act as an Active Directory Domain Controller.&lt;br /&gt;
* The virtual hard drive was thin provisioned at 50GB&lt;br /&gt;
* The C: drive was configured to be 50GB&lt;br /&gt;
* Configured the VM to use 1 vCPU and 4GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
For more information on Active Directory, see the following link: (Yes, it shows UWDDC3, just ignore that, the documentation is valid and still correct)&lt;br /&gt;
http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:UWDDC3_Domain_Controller&lt;br /&gt;
&lt;br /&gt;
==UWDDC2==&lt;br /&gt;
This is a new virtual machine created (not converted) with a fresh Windows Server 2012R2 OS install to act as an Active Directory Domain Controller. &lt;br /&gt;
* The virtual hard drive was thin provisioned at 50GB&lt;br /&gt;
* The C: drive was configured to be 50GB&lt;br /&gt;
* Configured the VM to use 1 vCPU and 4GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
For more information on Active Directory, see the following link: (Yes, it shows UWDDC3, just ignore that, the documentation is valid and still correct) http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:UWDDC4_Domain_Controller&lt;br /&gt;
&lt;br /&gt;
==XTGUI==&lt;br /&gt;
This is a new virtual machine created (not converted) with a fresh Windows Server 2012R2 OS install to act as a server for the Iptor XT GUI. &lt;br /&gt;
* The virtual hard drive was thick provisioned at 40GB&lt;br /&gt;
* The C: drive was configured to be 40GB&lt;br /&gt;
* Configured the VM to use 2 vCPU and 8GB of memory&lt;br /&gt;
* Configured the VM to use a VMXNET3 and connect it to the Production LAN&lt;br /&gt;
* The VM hardware level is 13&lt;br /&gt;
&lt;br /&gt;
==3CX Server Appliance==&lt;br /&gt;
This is a new virtual machine created from an ISO file downloaded from the 3CX website.  The ISO is an automated install of Debian 64bit plus the 3CX software.  The purpose of this VM is to act as a software PBX intended to replace the physical Toshiba PBX hardware.  There is a Windows based version of 3CX, however it was deemed that using a prebuilt VM appliance was a better option.&lt;br /&gt;
* The virtual machine is configured with 1 vCPU, 4GB of memory and 50GB of thick provisioned disk space.  &amp;lt;-- Woops my bad sorry on the thick provisioned space.&lt;br /&gt;
* The virtual machine is using the VMXNET3 network interface on the Production LAN at 172.30.18.27&lt;br /&gt;
* As of September 2018, this VM is not being backed up in any way&lt;br /&gt;
* The virtual machine has the OpenVM Tools installed&lt;br /&gt;
* The virtual machine is located on VMHost03&lt;br /&gt;
* There is a special VM network that has been created on VMHost03 (only) so that this VM can use the Shaw coax internet connection.  Because of this unique network configuration, this VM cannot be vMotioned as the vSwitch is not present on VMHost01 or 02&lt;br /&gt;
&lt;br /&gt;
==Zabbix NMS VM Appliance==&lt;br /&gt;
This is a Linux based virtual appliance that is used for network monitoring, graphing and alerting.  The VM appliance is an LTS version of Ubuntu with the OSS package called Zabbix baked in.  The open-vm-tools package is present so vCenter can control this VM.  While this VM is not business critical, it took a lot of effort to setup and configure so try not to let it get wiped out with no backups.&lt;br /&gt;
* The virtual machine is configured with 2 vCPU, 4GB of memory and 40GB of thin provisioned disk space.&lt;br /&gt;
* The virtual machine is using the VMXNET3 network interface on the Production LAN at 172.30.18.13&lt;br /&gt;
* As of July 2019, this VM is not being backed up in any way&lt;br /&gt;
* The virtual machine has the OpenVM Tools installed&lt;br /&gt;
* The virtual machine is located on VMHost02&lt;br /&gt;
&lt;br /&gt;
=Third Host Used For Testing=&lt;br /&gt;
On Monday May 28, 2018 a third host server was added to the VMware cluster.  The hardware that was used was previously the &amp;quot;Smithers&amp;quot; server.  The machine is a Lenovo x3550 M5 and the machine type is a 5463-AC1 and the serial number is E2ZR351.  The server has 2 populated processor sockets and contains Intel Xeon E5-2620v3 processors.  It has 32GB of memory and has 2 SSD drives that have been put into a RAID0 array.  There are 4 network ports at the back of the server and they are used and setup in the same way as the original 2 hosts.  This third host has the same IMM2 and the URL and credentials are below:&lt;br /&gt;
* https://bmvmhost03.unipharm.local&lt;br /&gt;
* adminit&lt;br /&gt;
* abc123&lt;br /&gt;
The third host has the same build of ESX as the other 2 hosts and it is also installed on a USB thumb drive but the thumb drive in the third host is not a Lenovo part and is not covered under warranty.  The third host is also setup to boot directly from the thumb drive instead of the RAID0 SSD array.  The RAID0 array has been configured as VMHost03DataStore01 and is 440GB in size.  The root password for the installed hypervisor on the third host is the same compared to the other 2 hosts and the management IP used is 172.30.18.21 and the vMotion IP is 172.30.24.3.  The third host has an existing Lenovo maintenance agreement that expires on August 26, 2020.&lt;br /&gt;
&lt;br /&gt;
IMPORTANT INFORMATION: The purpose of the third host is for testing and housing a testing environment.  The third host is not meant to permanently house any VMs that are used in production.  If we care that a VM gets deleted because the datastore was blown away and recreated - then that VM never should have been on the third host.  The third host also has a different version of Intel Xeon processor compared to the other 2 hosts.  A 2620v3 versus a 2620v4.  This matters for doing a vMotion of a running VM either to or from the third host.  A vMotion of a powered on VM to or from the third host cannot happen until EVC mode is turned on for the entire cluster.  As of May 2018, EVC mode is disabled because enabling it requires an outage where all the VMs in the cluster are powered off and this linked procedure be followed https://kb.vmware.com/s/article/1013111 .  If a VM needs to vMotion to or from the third host, it must be powered off and it must fit within the 440GB datastore.&lt;br /&gt;
&lt;br /&gt;
=VMware Tools=&lt;br /&gt;
VMware Tools is a package of tools and drivers that most virtual machines need to have installed within the guest OS.  VMware Tools allows the hypervisor to talk and manipulate the virtual machine.  The tools package also contains many of the virtual hardware drivers that Windows needs to properly enumerate all the &amp;quot;fake&amp;quot; hardware.  For example, if a virtual machine is running Windows7, the OS will load the default VGA driver for the video card because natively Windows can't identify a virtualized video card.  Same deal for a virtualized network card, Windows won't and probably shouldn't load a built in Microsoft driver.  This is where VMware Tools comes in and provides those drivers for the OS.  When creating a virtual machine or converting a physical machine, the VMware Tools installer should be installed as soon as possible.  The installer can be triggered from the vSphere web interface.  The only exceptions to the rule that VMware Tools needs to be installed is if the virtual machine is an &amp;quot;appliance&amp;quot; or pre-built OVF deployment.&lt;br /&gt;
&lt;br /&gt;
=vCenter Standalone Converter=&lt;br /&gt;
The vCenter Standalone Converter is a badly named application that converts real physical computers into virtual machines running on a host.  The application is Windows based and is typically installed on an IT laptop or workstation.  The software creates a &amp;quot;triangle&amp;quot; where it talks to the source computer and the destination host.  To begin with the Converter needs the FQDN of the source computer and local administrator credentials.  AD administrator credentials are good enough if they are in the local admin group on the source machine.  The Converter then uses a WMI connection to figure out what hardware and OS is present on the source machine.  During the &amp;quot;Convert Machine&amp;quot; wizard, the Converter also opens a connection to the VCSA which manages the uniPHARM Cluster.  Once the Converter understands the source and destination, the user doing the conversion has a chance to customize certain options like how many vCPUs are in the converted VM and how much memory there is and whether or not the source machine is powered off at the end of the conversion.  &lt;br /&gt;
&lt;br /&gt;
At the end of the wizard the Converter creates an empty &amp;quot;shell&amp;quot; virtual machine on the chosen destination host and begins to copy the source hard drive(s) to it.  It is important to note that the drive copy is direct from the source to the destination and does not hop to the laptop controlling the conversion.  The hard drive copy process is using VSS in the context of converting Windows machines so the VMware best practice is to turn off any non-Microsoft services that are running prior to the conversion process to minimize any chance that VSS can't get a lock on a file.  It is also best practice to set the source machine in the convert wizard to power off at the end of the last sync so that the newly created VM can be up and running after the last sync and so that there is no duplicate IP address/name conflict.  According to VMware documentation, the same &amp;quot;magic&amp;quot; that makes a vMotion happen is used in the Converter to take running physical machines and turn them into running VMs with only a second or two of pause.&lt;br /&gt;
&lt;br /&gt;
When the Converter is finished copying the hard drive(s) and the last sync, the VM is set to either be up and running or powered off and ready to be powered on for the first time as a VM.  In the second scenario, when the converted VM is powered on for the first time, it will recognize a bunch of new hardware.  For example, an older IBM server would have a physical Broadcom NIC, when it is converted it will have a VMXNET NIC (and therefore use DHCP).  The Converter will inject all the drivers the newly converted VM will need to recognize all the different virtualised hardware.  There may be a need to do a reboot for a newly created VM as Windows typically asks for one when new hardware drivers are installed.  The person doing the conversion can also choose to have the Converter automatically install the VMware Tools package if needed.&lt;br /&gt;
&lt;br /&gt;
Be aware that the amount of time it takes to convert a physical machine to a VM is limited by network bandwidth.  All potential source machines are on the same switch stack as the VMHosts so that's as fast as it is going to be.  A source machine that has SSDs would be bottlenecked by a 1GB network connection, however an older slower source server with mechanical hard drives might not be.  In any case, there is a hard limit on how fast a 1GB connection can move data.  Also be aware that after the conversion process is finished and the VM is up and running, Windows may prompt to re-activate the OS license due to how much &amp;quot;hardware&amp;quot; has just changed.  Our servers are using volume licenses so there is no reason a re-activation should fail.&lt;br /&gt;
&lt;br /&gt;
The Converter application is currently installed on DarrenF's laptop, but can be installed on other I.S. laptops and is not tied to any licensing.  The Converter is free to use but can't do anything useful without vCenter.&lt;br /&gt;
&lt;br /&gt;
=VMware Licensing And Support=&lt;br /&gt;
uniPHARM has purchased a vSphere 6 Essentials Plus Kit that includes vCenter.  This means that the license entitles us to have a maximum of 3 hosts each having a maximum of 2 CPU sockets and we are entitled to 1 instance of vCenter.  The license is usable forever, but the attached technical support is renewed yearly.  The licenses and keys are available through the MyVMware portal at &lt;br /&gt;
* www.vmware.com&lt;br /&gt;
* Username is darrenf@unipharm.com&lt;br /&gt;
* Password is visionit&lt;br /&gt;
* Account number 114624681&lt;br /&gt;
* Customer number 9027898369&lt;br /&gt;
uniPHARM also owns a license for a very old version of VMware Server 2.0 and Workstation 9.0 which are both EOL and not usable.  While the current EPK licenses are installed correctly inside vCenter, if vCenter needs to be re-installed, the process is to run a licensing report from MyVMware, which generates a CSV file that is imported into vCenter.  The next step is to assign the vCenter license to itself and the vSphere licenses to the hosts.  VMware has announced that the End Of General support for vSphere 6.5 is November 15, 2021.  A support contract for version 6.5 would not be purchasable after that date and if we wanted support, we would be prompted to upgrade to 6.7 or later.  This end of general support date applies to the hypervisor install and the vCenter install.  Again, the licenses are perpetual and never expire, the support contract is renewable and does expire.&lt;br /&gt;
&lt;br /&gt;
=VM To Host Optimized Layout=&lt;br /&gt;
The following chart describes where a virtual machine should be located so as to balance the processing, memory and storage loads evenly among the 3 hosts in the cluster.  VM's can be moved around or shuffled from host to host when doing maintenance but this is the preferred layout of which hosts house which VM's. Changes to this chart will be documented in the change log at the bottom of this page.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;|VMHost01 !! style=&amp;quot;width: 15%&amp;quot;|VMHost02 !!  style=&amp;quot;width: 15%&amp;quot;|VMHost03&lt;br /&gt;
|-&lt;br /&gt;
| XClarity || SuperServer || 3CX Appliance&lt;br /&gt;
|-&lt;br /&gt;
| Lucy || UWDDC2 || TestServer1&lt;br /&gt;
|-&lt;br /&gt;
| Mail || VMware vCenter Server Appliance || UbuntuDevVM&lt;br /&gt;
|-&lt;br /&gt;
| Smithers || XTGUI || Windows7 Ent For Adobe LifeCycle&lt;br /&gt;
|-&lt;br /&gt;
| UWDDC1 || Zabbix NMS VM Appliance || WindowsXP Pro HP JetDirect&lt;br /&gt;
|-&lt;br /&gt;
| WDS ||  || Windows10 Ent Eval&lt;br /&gt;
|-&lt;br /&gt;
|  ||  || Windows10 Pro Eval&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Backups=&lt;br /&gt;
==Veeam==&lt;br /&gt;
As of May 2018, uniPHARM is evaluating Veeam Backup And Replication 9.5 as the platform used to do backups of VMware infrastructure and VM's.  This section is mostly a placeholder but the sub sections are full of relevant documentation.&lt;br /&gt;
===Hardware===&lt;br /&gt;
On December 20, 2010, uniPHARM purchased an IBM x3650 M3 server from Anisoft, with asset number 827.  The machine type is 7945-AC1 and the serial number is KQ128AR.  This machine (as of May 2018) has no IBM/Lenovo hardware maintenance agreement so if and when it has any sort of hardware failure of any kind, IBM/Lenovo will not come onsite with parts to repair.  This machine was used as the &amp;quot;SuperServer&amp;quot; until that OS was turned into a VM.  This machine does have an older IMM that can be accessed from the following URL and IP:&lt;br /&gt;
* http://bmveeam.unipharm.local&lt;br /&gt;
* Username  adminit&lt;br /&gt;
* Password  abc123&lt;br /&gt;
* IP 172.30.18.46&lt;br /&gt;
Because this machine has a very old IMM, it cannot be managed by XClarity.  As of May 2018, this machine has the latest firmware for the IMM and UEFI and hard drive controllers.  It contains 2 different hard drive controllers.  The ServeRAID M1015 and the ServeRAID M5015.  This machine has 16 slots for hard drives, numbered 0 to 15 and currently all the slots are populated with 15K-RPM spinning hard drives.  The hard drives in slots 0 and 1 are 136GB drives and 2 through 15 are 300GB drives.  The 136GB drives are in a RAID1 set and are used as the bootable C: drive with an install of Windows Server 2012R2.  The drives in slots 2 to 7 are in a RAID0 as well as drives 8 to 15 in another RAID0 on the second controller.  The M1015 and M5015 cannot create a JOBD or RAID0 across controllers because the controllers don't talk to each other.  In order to get the maximum amount of disk storage for Veeam, a striped Dynamic Disk was created in Windows as a layer on top of the 2 RAID0 sets to make 1 large D: that is 3.8TB.  A failure of any 1 hard drive in slots 2 through 15 will result in a LOSS OF ALL DATA on the D: drive.  The 136GB RAID1 set acting as the OS drive on C: can tolerate the failure of a single hard drive without data loss - a failure of both drives will result in data loss.  The above arrangement of hard drives is not a best practice, but is an acceptable risk given the nature of backups and budgets.&lt;br /&gt;
&lt;br /&gt;
This machine has a pair of 1GB network cards that are using QLogic drivers as QLogic bought out Broadcom and when Windows Server 2012R2 was installed in May of 2018, the QLogic drivers were installed, however the chips for the NICs are Broadcom.  Only the first NIC is being used on IP 172.30.18.9, however the second NIC can be used in a team to provide a 2GB connection with the core Server Room switches are replaced.  The older IMM is using a dedicated port on the back of the machine.  This server has 1 out of 2 processor sockets occupied with an 8 core Xeon E5620 and 8GB of memory.&lt;br /&gt;
&lt;br /&gt;
===Veeam Software Installation===&lt;br /&gt;
In May of 2018, Veeam Backup And Replication 9.5 was installed.  This package also installs the Express version of Microsoft SQL 2012 plus supporting files for SQL.  Along with Veeam Backup and Replication, Veeam Enterprise Manager and Veeam ONE were also installed as they come free with the perpetual license.  Veeam Enterprise Manager is a web based front end for the Veeam Console and has a subset of functions and features compared to the Console.  Veeam ONE is a reporting and BI tool that displays graphs and charts and statistics in regards to a VMware/Veeam environment.  While Veeam ONE is included free with the perpetual license, it is geared to much larger environments compared to ours - as in hundreds of hosts and thousands of VMs and lots and lots of storage.  The full Veeam Console should be also installed on an IT laptop so administrators can make configuration changes if needed without using remote desktop to the physical server.  This is very similar to how BackupExec worked.  The Veeam Backup And Replication package needs to use the administrator@vsphere.local account to access the VCSA and any subordinate VM's.  This account is critical to successful backups and if the password is changed, that change needs to also be changed within the credential manager inside Veeam.  The Active Directory domain administrator account is also used to access the remaining physical servers via the Veeam Agent, so if that password is changed, it also needs to be changed within the credential manager inside Veeam.&lt;br /&gt;
&lt;br /&gt;
===Veeam Licensing===&lt;br /&gt;
We will probably get perpetual licensing with renewable annual support&lt;br /&gt;
===What Is Veeam Backing Up?===&lt;br /&gt;
Veeam will be able to backup the VM's and itself and whatever few remaining physical servers that are still in use.&lt;br /&gt;
===Backup Strategy And Scheduled Jobs===&lt;br /&gt;
Placeholder something something something.&lt;br /&gt;
===How Veeam Uses Tape Hardware===&lt;br /&gt;
Placeholder something something something.&lt;br /&gt;
===Veeam Technical Support===&lt;br /&gt;
Put the terms of the support contract in here plus the phone number and expiry dates.&lt;br /&gt;
&lt;br /&gt;
=Change Log - Try And Record Any Major Configuration Or Software/Hardware Changes To The Infrastructure Here=&lt;br /&gt;
==2018==&lt;br /&gt;
# Both servers have their UEFI/BIOS set to only boot from the USB thumb drive&lt;br /&gt;
# Both servers have their UEFI/BIOS set to use maximum performance in the power settings as per this KB article https://www.ibm.com/support/home/docdisplay?lndocid=migr-5098137&lt;br /&gt;
# Initial ESX version installed on March 21, 2018 is 6.5.0 Build 7388607&lt;br /&gt;
# VMHost01DataStore01 created as the first datastore&lt;br /&gt;
# The local datastores are seen as non-ssd by ESX because they are behind a RAID controller and not part of a vSAN&lt;br /&gt;
# VCSA password is NewVisionIT@2051&lt;br /&gt;
# vcsa.unipharm.local is at 172.30.18.23&lt;br /&gt;
# VCSA virtual machine set to automatically start when the hypervisor on VMHost01 boots&lt;br /&gt;
# VCSA added to Active Directory as a computer object for SSO on March 22, 2018, located in the Servers OU&lt;br /&gt;
# Configed SSO according to https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.vcsa.doc/GUID-08EA2F92-78A7-4EFF-880E-2B63ACC962F3.html&lt;br /&gt;
# Added DarrenF and NorwinU AD user accounts as being able to log into VCSA web client&lt;br /&gt;
# vMotion IP on VMHost01 is 172.30.24.1  IP on VMHost02 is 172.30.24.2&lt;br /&gt;
# 8 minutes to vMotion 60GB Win7 cagepc as a test P2V on March 23, 2018 with no VLAN&lt;br /&gt;
# Created content library and uploaded the xclarity OVF and 3CX ISO files March 23, 2018&lt;br /&gt;
# Added VLAN 5 to vMotion Network - NorwinU configed physical switch to use VLAN 5 on ports 4 and 16 on Stacked Switch 1of4 March 23, 2018&lt;br /&gt;
# Changed VLAN 5 to 3 for some reason and changed the TCPIP stack for the vMotion Network for optimization&lt;br /&gt;
# Added DarrenF and NorwinU AD accounts as permitted Administrators to the entire VCSA hierarchy and got SSO working correctly&lt;br /&gt;
# Configured VUM to scan for updates each Monday of every week and email DarrenF&lt;br /&gt;
# Ran a VUM Remediation to install Spectre VIBs via the VUM wizard both hosts now at 6.5 build 7967591 March 26, 2018&lt;br /&gt;
# P2Ved the Thermoprofile physical server onto VMHost01 March 26, 2018&lt;br /&gt;
# Set the Thermoprofile VM to autostart on VMHost01 March 28, 2018&lt;br /&gt;
# Tweeked CPU usage alarm to have more time at 90 and 100% - updated documentation April 3, 2018&lt;br /&gt;
# P2Ved the Lucy physical server onto VMHost01 April 7, 2018&lt;br /&gt;
# P2Ved the Mail physical server onto VMHost01 April 15, 2018&lt;br /&gt;
# Logged into the VCSA PSC Controller and set the root password to never expire instead of expiring every 90 days April 25, 2018&lt;br /&gt;
# Set the administrator@vsphere.local account to expire its password every 9999 days April 25, 2018&lt;br /&gt;
# Turned on the BASH shell for the VCSA PSC and set the correct time zone for NTP April 25, 2018&lt;br /&gt;
# Downloaded the VMware trusted root CA certificate from https://vcsa.unipharm.local and installed that into the Trusted Root store on DarrenF's laptop so that the webclient is trusted by IE11 and makes uploading of ISO files to the Content Library possible using an SSO login May 3, 2018&lt;br /&gt;
# P2Ved the SuperServer physical server onto VMHost02 May 5, 2018&lt;br /&gt;
# Uploaded the ISO for Windows Server Standard 2012R2 to the Content Library May 7, 2018&lt;br /&gt;
# Created the XClarity VM appliance from an OVA file in the Content Library - May 9, 2018&lt;br /&gt;
# Created a VM for NancyN to use for Adobe LifeCycle - see the notes pane in the Flash client for details on this otherwise undocumented VM - May 16, 2018&lt;br /&gt;
# P2Ved the Smithers physical server onto VMHost01 May 19, 2018&lt;br /&gt;
# Added hardware that used to be the Smithers server as a third host to the cluster (VMHost03) May 28, 2018&lt;br /&gt;
# VMware support ticket 18814250705 for how to enable EVC mode opened and then closed with no changes because enabling EVC requires all VMs to be off May 30, 2018&lt;br /&gt;
# VMware support ticket 18815369505 for how to get a database backup from the VCSA to FTP opened May 30, 2018&lt;br /&gt;
# New VM created called WDS.unipharm.local with the purpose of housing the WDS feature and Spiceworks and KiwiSyslog - June 8, 2018&lt;br /&gt;
# New VMs created called UWDDC1 and UWDDC2 to act as Active Directory Domain Controllers - June 11, 2018&lt;br /&gt;
# Thermoprofile virtual machine deleted from the datastore on June 13, 2018&lt;br /&gt;
# XClarity virtual appliance deleted and then recreated using the version 2.0 OVA file&lt;br /&gt;
# Created new virtual machine called XTGUI with the purpose of it being used as a server for the Iptor DC1 GUI - June 21, 2018&lt;br /&gt;
# Created an internal backup of the VCSA and uploaded that to ftp.unipharm.com  - August 27, 2018&lt;br /&gt;
# Uploaded the VCSA upgrade ISO (6.5.0.22000-9451637) to VMHOST01DATASTORE01  - August 27, 2018&lt;br /&gt;
# Upgraded the VCSA to 6.5 U2C build 9451637- August 27, 2018&lt;br /&gt;
# Upgraded ESX hypervisors on hosts to 6.5 U2C build 9298722 - September 1, 2018&lt;br /&gt;
# Upgraded all VMware Tools installed in all Windows VM's to 10305 - September 1, 2018&lt;br /&gt;
# Changed configuration setting &amp;quot;VMkernal.BootHyperthreadingMitigation&amp;quot; from False to True on VMHost03 due to its older processor - September 5, 2018&lt;br /&gt;
# Cleared BIOS event logs on VMHost03 and undid the hyperthreading changes from above - September 5, 2018&lt;br /&gt;
# Created a new VM called 3CX Server Appliance from an ISO in the Content Library to be used as a PBX - September 26, 2018&lt;br /&gt;
# Created new virtual port groups on vSwitch2 on each host to enable VMs to be on Alt-Guest VLAN. The port group is tagged to VLAN 2. - September 28, 2018&lt;br /&gt;
# vMotion 3CX appliance to vmhost03 where I can play with it. -17:05, 28 September 2018 (PDT)&lt;br /&gt;
# Increased hard drive from 70GB to 100GB on the WDS virtual machine to accommodate new desktop images - October 19, 2018&lt;br /&gt;
# Created TestServer1 on VMHost03 - a Windows 2016 server for generic testing purposes. NetStore and TLAForm will be installed on it for testing with DC1.&lt;br /&gt;
# Created virtual switch VoIP LAN (VLAN 6). - November 29, 2018&lt;br /&gt;
# 3CX Server VM reinstalled and connected to VoIP VLAN. - November 29, 2018&lt;br /&gt;
# Created UbuntuTestVM VM, as a generic test VM that can be connected to different VLANs for various network testing / diagnostics purposes. - November 29, 2018&lt;br /&gt;
==2019==&lt;br /&gt;
# DarrenF created 2 VMs for Windows10 testing on April 4, 2019.  The VM's are on VMHost02.&lt;br /&gt;
# DarrenF removed an old snapshot for the XTGUI Server and for the vCenter VM on May 8, 2019.&lt;br /&gt;
# DarrenF made a backup of the VCSA on May 17, 2019 and saved the backup file to the SuperServer.&lt;br /&gt;
# DarrenF upgraded the VCSA from 6.5.0-22000 to 6.5.0.24000 on May 22, 2019 and finished that with a reboot.&lt;br /&gt;
# DarrenF upgraded all 3 hosts to ESX version 6.5.0-13635690 on May 24, 2019&lt;br /&gt;
# DarrenF upgraded the UEFI and IMM2 and DSA firmware on all 3 hosts on May 24, 2019.&lt;br /&gt;
# DarrenF upgraded the VMware Tools install on some VM's that could be rebooted during the day on May 27, 2019 - remaining VM's will be upgraded at a later date.&lt;br /&gt;
# DarrenF updated this documentation with information on which VM's should located on each host - May 27, 2019.&lt;br /&gt;
# DarrenF created a new VM for the Zabbix NMS VM Appliance using an ISO located in the Content Library - July 10, 2019&lt;br /&gt;
# DarrenF enabled SNMP on all three hosts and the VCSA so that Zabbix could monitor via SNMP - July 12, 2019.&lt;br /&gt;
[[Category: Virtualization]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14484</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14484"/>
		<updated>2023-08-02T18:25:46Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || NewVisionIT! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || Cisco CBS250 || Candy Mezzanine || adminit || Newvisionit! || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14460</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14460"/>
		<updated>2023-06-26T16:09:40Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || Newvisionit! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || Cisco CBS250 || Candy Mezzanine || adminit || Newvisionit! || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14428</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14428"/>
		<updated>2023-05-25T17:39:48Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || Newvisionit! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || 3Com 4200G? || Candy Mezzanine || adminit || Newvisionit! || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14383</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14383"/>
		<updated>2023-01-16T21:45:45Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
Domain name：rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password: windows login password&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
''Tips: how to generate a CSR on the server:https://www.bitdefender.com/support/How-to-create-a-Certificate-Signing-Request-(CSR)-on-Windows-Server-and-Mac-2237.html''&lt;br /&gt;
&lt;br /&gt;
'''Connection Authentication Policy'''&lt;br /&gt;
&lt;br /&gt;
The user must be added to the &amp;quot;RD-users&amp;quot; group in AD&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14382</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14382"/>
		<updated>2023-01-16T21:44:21Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
Domain name：rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
''Tips: how to generate a CSR on the server:https://www.bitdefender.com/support/How-to-create-a-Certificate-Signing-Request-(CSR)-on-Windows-Server-and-Mac-2237.html''&lt;br /&gt;
&lt;br /&gt;
'''Connection Authentication Policy'''&lt;br /&gt;
&lt;br /&gt;
The user must be added to the &amp;quot;RD-users&amp;quot; group in AD&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14381</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14381"/>
		<updated>2023-01-16T21:44:02Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
Domain name：rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
tips: how to generate a CSR on the server:https://www.bitdefender.com/support/How-to-create-a-Certificate-Signing-Request-(CSR)-on-Windows-Server-and-Mac-2237.html&lt;br /&gt;
&lt;br /&gt;
'''Connection Authentication Policy'''&lt;br /&gt;
&lt;br /&gt;
The user must be added to the &amp;quot;RD-users&amp;quot; group in AD&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14380</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14380"/>
		<updated>2023-01-16T21:43:54Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
Domain name：rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
tips: how to generate a CSR on the server:https://www.bitdefender.com/support/How-to-create-a-Certificate-Signing-Request-(CSR)-on-Windows-Server-and-Mac-2237.html&lt;br /&gt;
&lt;br /&gt;
'''Connection Authentication Policy'''&lt;br /&gt;
&lt;br /&gt;
The user must be added to the &amp;quot;RD-users&amp;quot; group in AD&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14379</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14379"/>
		<updated>2023-01-16T21:43:40Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
Domain name：rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
tips: how to generate a CSR on the server:https://www.bitdefender.com/support/How-to-create-a-Certificate-Signing-Request-(CSR)-on-Windows-Server-and-Mac-2237.html&lt;br /&gt;
'''Connection Authentication Policy'''&lt;br /&gt;
&lt;br /&gt;
The user must be added to the &amp;quot;RD-users&amp;quot; group in AD&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14378</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14378"/>
		<updated>2023-01-16T21:40:34Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
Domain name：rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
'''Connection Authentication Policy'''&lt;br /&gt;
&lt;br /&gt;
The user must be added to the &amp;quot;RD-users&amp;quot; group in AD&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14377</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14377"/>
		<updated>2023-01-16T21:40:06Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
'''Connection Authentication Policy'''&lt;br /&gt;
&lt;br /&gt;
The user must be added to the &amp;quot;RD-users&amp;quot; group in AD&lt;br /&gt;
&lt;br /&gt;
Domain name：rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14376</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14376"/>
		<updated>2023-01-16T21:39:59Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
'''Connection Authentication Policy'''&lt;br /&gt;
The user must be added to the &amp;quot;RD-users&amp;quot; group in AD&lt;br /&gt;
&lt;br /&gt;
Domain name：rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14375</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14375"/>
		<updated>2023-01-16T21:35:47Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14374</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14374"/>
		<updated>2023-01-16T21:35:38Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14373</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=14373"/>
		<updated>2023-01-16T21:35:27Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
'''SSL certificate'''&lt;br /&gt;
We purchased the SSL certificate from the network solution, and it will be automatically renewed every September. We need to generate a CSR on the server to activate the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14366</id>
		<title>Information Systems:LAN infrastructure at uniPHARM</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:LAN_infrastructure_at_uniPHARM&amp;diff=14366"/>
		<updated>2023-01-16T16:47:41Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This is the main page for the LAN (wired network configuration) at uniPHARM.&lt;br /&gt;
&lt;br /&gt;
==Switches==&lt;br /&gt;
This table outlines the physical network switches that make up the network.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! IP address || Switch model !! Location !! Username !! Password !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''coresw''' || 172.30.16.4 || Cisco CBS350 || Server room || adminit || Newvisionit! || '''Core switch.''' Stack of 3.&lt;br /&gt;
|-&lt;br /&gt;
| atpsw || 172.30.16.3 || 3Com 4200 || Server room || admin || visionit || Feeds data to POE injectors for Mirador temp. sensors '''(Retired)'''&lt;br /&gt;
|-&lt;br /&gt;
| accountingsw || 172.30.16.11 || Cisco SG350-28P || Accounting Wallmount Network Rack || adminit || NewVisionIT || POE, ~175W power budget&lt;br /&gt;
|-&lt;br /&gt;
| buyerswcisco || 172.30.16.18 || Cisco SG350-28P || Buying department closet || adminit || visionit|| -&lt;br /&gt;
|-&lt;br /&gt;
| itsw || 172.30.16.6 || 3Com 4200G || IT department ceiling tile. Yup. || admin || visionis || -&lt;br /&gt;
|-&lt;br /&gt;
| cagesw || 172.30.16.12 || 3Com 3870 || Computer lab || admin || visionit&lt;br /&gt;
|-&lt;br /&gt;
| dumpsw.unipharm.local || 172.30.16.7 || 3Com 4200G? || Electrical Room? || admin || visionds || -&lt;br /&gt;
|-&lt;br /&gt;
| pickingsw || 172.30.16.8 || 3Com 3870? || Rx picking zone network rack || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| receivingswcisco || 172.30.16.17 || Cisco SG350-28P || DC Manager's Office || adminit || visionit || -&lt;br /&gt;
|-&lt;br /&gt;
| wallsw || 172.30.16.9 || 3Com 4200G? || Candy Mezzanine || admin || visionns || Functions merely to bridge the physical wiring between Receiving area and core network&lt;br /&gt;
|-&lt;br /&gt;
| jeremymsw || 172.30.16.16 || TP-Link SG105E || Jeremy's office || admin || visionit || Used for testing Yealink, web-managed smart switch &lt;br /&gt;
|-&lt;br /&gt;
| itlabswcisco || 172.30.16.19 || Cisco SG350-10MP || IT Lab/Cage || adminit || visionit ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* External link to backdoor access and hidden menus for the 3com 3870 switches http://etherhack.wikia.com/wiki/3Com_3870&lt;br /&gt;
* There is a spare, ready to use 3com 3870 24 port switch located at the very bottom of the networking rack in the server room.  The switch has been reset to factory defaults and the username is admin and the password is blank.  The switch is ready to be put into the core stack if needed.&lt;br /&gt;
&lt;br /&gt;
==VLANs==&lt;br /&gt;
We started using VLANs in 2016, for the same reason why anyone would use VLANs - to manage/separate multiple networks using one physical switch infrastructure. The VLAN implementation being used is the standard 802.1q. The following table outlines the VLAN infrastructure.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! VLAN ID !! Name !! L3 Network / IP Range !! Description !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| '''1''' || Main LAN || 172.30.16.0/21 (172.30.16.1 - 172.30.23.255) || Default VLAN, untagged across the network for simplicity (so that every device doesn't have to be configured to talk this VLAN, or even be VLAN-aware at all). || Routed out Telus Fibre&lt;br /&gt;
|-&lt;br /&gt;
| '''2''' || Alt LAN (Staff/ guest BYOD, Shipping terminals) || 192.168.0.1/23 (192.168.0.1 - 192.168.1.254) || Colloquially known as the &amp;quot;Guest VLAN&amp;quot;, but staff wifi devices are not technically guest devices. Currently, shipping computers are on this network, but they should be moved to VLAN 7 when it is created. || Routed out Shaw Business Internet&lt;br /&gt;
|-&lt;br /&gt;
| '''3''' || vMotion LAN || ?? || Small network to isolate vMotion traffic between the 3 virtual hosts. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''4''' || Shaw WAN interfaces || Network of the Shaw static WAN IP (/32) || Network to isolate WAN traffic between Shaw modem and Sophos WAN interface from the rest of the network. Lots of ARP going on here! || -&lt;br /&gt;
|-&lt;br /&gt;
| '''5''' || Telus WAN interfaces || Network of our Telus WAN IPs (/27) || Network to isolate WAN traffic between Telus modem and Sophos WAN interface from the rest of the network. || -&lt;br /&gt;
|-&lt;br /&gt;
| '''6''' || VoIP LAN || 192.168.44.0/24 || Contains PBX and IP phones || Routed out Telus and Shaw (Sophos multipath) &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Helpful Stuff=&lt;br /&gt;
The command to view what MAC address(s) is in use on a port for the Cisco SG350 switch is as follows.  You will need to login to the switch via SSH in order to do this:&lt;br /&gt;
* show mac address-table interface gi1 (or ge1 sometimes too)&lt;br /&gt;
The port name is visible from the switches web interface and goes from gi1 to gi28 or ge1 to ge28.  Then cross checking the MAC address in Spiceworks for example will allow you to see who is plugged into what port - however all the Cisco switches should already have human readable labels attached to all in-use ports as of July 2019.&lt;br /&gt;
[[Category: Networking]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:UWDOSS_-_Open_Source_Development_Server&amp;diff=14365</id>
		<title>Information Systems:UWDOSS - Open Source Development Server</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:UWDOSS_-_Open_Source_Development_Server&amp;diff=14365"/>
		<updated>2023-01-06T22:29:21Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
uwdoss.unipharm.local is a production server VM that hosts InfoNext as well as the integrations database. The software components installed on this machine constitute the majority of the modernization stack uniPHARM is using for new development, with the other component being [[Information Systems:Iptor Integrator|Iptor Integrator]], integration middleware that exists on xtgui.unipharm.local&lt;br /&gt;
&lt;br /&gt;
The server runs '''Debian Linux'''.&lt;br /&gt;
&lt;br /&gt;
===History===&lt;br /&gt;
Prior to this server, uniPHARM ran strictly Windows Server for all server applications and workloads. However, there began to be a need for open-source software. For example, Moodle and Mediawiki have been in production since 2015. These are currently being hosted on Windows, using a pre-packaged WAMP stack that arguably is better-suited for development environments. It was decided a Linux server would be useful to uniPHARM's growing need and usage of open-source software.&lt;br /&gt;
&lt;br /&gt;
==Installed Software==&lt;br /&gt;
The major software components running on this server are:&lt;br /&gt;
* PostgreSQL relational database (no longer used)&lt;br /&gt;
* MariaDB (MySQL) relational database&lt;br /&gt;
* Apache web server - Hosts the Django application through mod_wsgi, as well as the static files (HTML/CSS/Javascript)&lt;br /&gt;
* Redis DB - In-memory cache for loading frequently used datasets (e.g. customer name and number)&lt;br /&gt;
* Python - To run Django, and other supporting scripts.&lt;br /&gt;
* Django, Django REST Framework, which are Python packages&lt;br /&gt;
* Other Python packages, such as venv and mysqlclient to help support the solution&lt;br /&gt;
&lt;br /&gt;
==Projects==&lt;br /&gt;
* InfoNext - extension of Infonet (company intranet)&lt;br /&gt;
* uwdpy - random scripts/utilities for housekeeping, reports. Replaced by Integrator, but this development environment may still be useful (Python is often quicker to get going with, and connectivity to IBM i is sufficient i.e. XML Toolkit, ODBC)&lt;br /&gt;
&lt;br /&gt;
==Server Administration==&lt;br /&gt;
 General Linux administration skills are required for the administration of this server. uniPHARM currently has these skills in-house.&lt;br /&gt;
This server does not have a GUI. Instead, command-line prompt through vSphere remote console or SSH can be used. Credentials for the user and admin user are as follows:&lt;br /&gt;
&lt;br /&gt;
 '''Generic user'''&lt;br /&gt;
   Username: unipharm&lt;br /&gt;
   Password: visionit&lt;br /&gt;
 &lt;br /&gt;
 '''Dev/admin user'''&lt;br /&gt;
   Username: uwddev&lt;br /&gt;
   Password: CH3CH3O&lt;br /&gt;
 &lt;br /&gt;
 '''Superuser (root)'''&lt;br /&gt;
   Root user: root&lt;br /&gt;
   Password: visionit&lt;br /&gt;
&lt;br /&gt;
====Software updates====&lt;br /&gt;
The software listed above are all installed as Debian packages and managed with apt/aptitude. The setup is such that there should be no issues doing upgrades and distribution upgrades using the standard Debian upgrade process (i.e. using &amp;lt;code&amp;gt;apt-get dist-update&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;apt-get upgrade&amp;lt;/code&amp;gt;, or the aptitude counterparts). &lt;br /&gt;
====Python Virtual Environment (venv)====&lt;br /&gt;
InfoNext uses a virtual environment (through the venv Python module), which is located in &amp;lt;code&amp;gt;/uwdapps/lib/.venv/inx&amp;lt;/code&amp;gt;. To activate a particular venv in a console/SSH session:&lt;br /&gt;
&amp;lt;code&amp;gt;source /root_path_of_venv/bin/activate&amp;lt;/code&amp;gt;&lt;br /&gt;
For InfoNext this is:&lt;br /&gt;
&amp;lt;code&amp;gt;source /uwdapps/env/bin/activate&amp;lt;/code&amp;gt;&lt;br /&gt;
uwdpy also has its own virtual environment.&lt;br /&gt;
====ODBC====&lt;br /&gt;
pyodbc is installed in the inx Python virtual environment. This is for facilitating direct connections to IBM Db2. A DSN for the connection to bart is configured in /etc/odbc.ini. However, this connection is not registered in Django.&lt;br /&gt;
&lt;br /&gt;
==Troubleshooting and how-to==&lt;br /&gt;
====Restart web server====&lt;br /&gt;
* To restart Apache: &amp;lt;code&amp;gt;sudo systemctl restart apache2&amp;lt;/code&amp;gt;&lt;br /&gt;
====Renew SSL certificate====&lt;br /&gt;
InfoNext uses a LetsEncrypt certificate for https. certbot is installed on this server to manage the cert (it was used to generate it as well). LetsEncrypt certs can use HTTP or DNS validation. For HTTP validation, the site must be accessible through HTTP. Since the site is not publicly accessible (only VPN and intranet), certbot renewal has been switched to DNS challenge using the DNSME (DNS Made Easy) certbot plugin. DNSME API credentials are stored in /home/unipharm/&lt;br /&gt;
* Enable nat rules on the firewall, DNAT rules have been established, can be found in SOPHOS-Network Protection-NAT, the name is InfoNext Server DNAT&lt;br /&gt;
* Run &amp;lt;code&amp;gt;certbot renew&amp;lt;/code&amp;gt; on linux server .&lt;br /&gt;
* Disable the DNAT and firewall rules.&lt;br /&gt;
&lt;br /&gt;
==Other Notes==&lt;br /&gt;
* This server is backed up using Veeam.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Servers]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:UWDOSS_-_Open_Source_Development_Server&amp;diff=14361</id>
		<title>Information Systems:UWDOSS - Open Source Development Server</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:UWDOSS_-_Open_Source_Development_Server&amp;diff=14361"/>
		<updated>2023-01-04T05:40:46Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
uwdoss.unipharm.local is a production server VM that hosts InfoNext as well as the integrations database. The software components installed on this machine constitute the majority of the modernization stack uniPHARM is using for new development, with the other component being [[Information Systems:Iptor Integrator|Iptor Integrator]], integration middleware that exists on xtgui.unipharm.local&lt;br /&gt;
&lt;br /&gt;
The server runs '''Debian Linux'''.&lt;br /&gt;
&lt;br /&gt;
===History===&lt;br /&gt;
Prior to this server, uniPHARM ran strictly Windows Server for all server applications and workloads. However, there began to be a need for open-source software. For example, Moodle and Mediawiki have been in production since 2015. These are currently being hosted on Windows, using a pre-packaged WAMP stack that arguably is better-suited for development environments. It was decided a Linux server would be useful to uniPHARM's growing need and usage of open-source software.&lt;br /&gt;
&lt;br /&gt;
==Installed Software==&lt;br /&gt;
The major software components running on this server are:&lt;br /&gt;
* PostgreSQL relational database (no longer used)&lt;br /&gt;
* MariaDB (MySQL) relational database&lt;br /&gt;
* Apache web server - Hosts the Django application through mod_wsgi, as well as the static files (HTML/CSS/Javascript)&lt;br /&gt;
* Redis DB - In-memory cache for loading frequently used datasets (e.g. customer name and number)&lt;br /&gt;
* Python - To run Django, and other supporting scripts.&lt;br /&gt;
* Django, Django REST Framework, which are Python packages&lt;br /&gt;
* Other Python packages, such as venv and mysqlclient to help support the solution&lt;br /&gt;
&lt;br /&gt;
==Projects==&lt;br /&gt;
* InfoNext - extension of Infonet (company intranet)&lt;br /&gt;
* uwdpy - random scripts/utilities for housekeeping, reports. Replaced by Integrator, but this development environment may still be useful (Python is often quicker to get going with, and connectivity to IBM i is sufficient i.e. XML Toolkit, ODBC)&lt;br /&gt;
&lt;br /&gt;
==Server Administration==&lt;br /&gt;
 General Linux administration skills are required for the administration of this server. uniPHARM currently has these skills in-house.&lt;br /&gt;
This server does not have a GUI. Instead, command-line prompt through vSphere remote console or SSH can be used. Credentials for the user and admin user are as follows:&lt;br /&gt;
&lt;br /&gt;
 '''Generic user'''&lt;br /&gt;
   Username: unipharm&lt;br /&gt;
   Password: visionit&lt;br /&gt;
 &lt;br /&gt;
 '''Dev/admin user'''&lt;br /&gt;
   Username: uwddev&lt;br /&gt;
   Password: CH3CH3O&lt;br /&gt;
 &lt;br /&gt;
 '''Superuser (root)'''&lt;br /&gt;
   Root user: root&lt;br /&gt;
   Password: visionit&lt;br /&gt;
&lt;br /&gt;
====Software updates====&lt;br /&gt;
The software listed above are all installed as Debian packages and managed with apt/aptitude. The setup is such that there should be no issues doing upgrades and distribution upgrades using the standard Debian upgrade process (i.e. using &amp;lt;code&amp;gt;apt-get dist-update&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;apt-get upgrade&amp;lt;/code&amp;gt;, or the aptitude counterparts). &lt;br /&gt;
====Python Virtual Environment (venv)====&lt;br /&gt;
InfoNext uses a virtual environment (through the venv Python module), which is located in &amp;lt;code&amp;gt;/uwdapps/lib/.venv/inx&amp;lt;/code&amp;gt;. To activate a particular venv in a console/SSH session:&lt;br /&gt;
&amp;lt;code&amp;gt;source /root_path_of_venv/bin/activate&amp;lt;/code&amp;gt;&lt;br /&gt;
For InfoNext this is:&lt;br /&gt;
&amp;lt;code&amp;gt;source /uwdapps/env/bin/activate&amp;lt;/code&amp;gt;&lt;br /&gt;
uwdpy also has its own virtual environment.&lt;br /&gt;
====ODBC====&lt;br /&gt;
pyodbc is installed in the inx Python virtual environment. This is for facilitating direct connections to IBM Db2. A DSN for the connection to bart is configured in /etc/odbc.ini. However, this connection is not registered in Django.&lt;br /&gt;
&lt;br /&gt;
==Troubleshooting and how-to==&lt;br /&gt;
====Restart web server====&lt;br /&gt;
* To restart Apache: &amp;lt;code&amp;gt;sudo systemctl restart apache2&amp;lt;/code&amp;gt;&lt;br /&gt;
====Renew SSL certificate====&lt;br /&gt;
InfoNext uses a LetsEncrypt certificate for https. certbot is installed on this server to manage the cert (it was used to generate it as well). LetsEncrypt certs can use HTTP or DNS validation. For HTTP validation, the site must be accessible through HTTP. Since the site is not publicly accessible (only VPN and intranet), certbot renewal has been switched to DNS challenge using the DNSME (DNS Made Easy) certbot plugin. DNSME API credentials are stored in /home/unipharm/&lt;br /&gt;
* Enable the DNAT and firewall rule in the firewall (or if already enabled, ensure that the 'Any IPv4' object is added to the Source of the rule)-in Sophos NAT-25.&lt;br /&gt;
* Run &amp;lt;code&amp;gt;certbot renew&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Disable the DNAT and firewall rules.&lt;br /&gt;
&lt;br /&gt;
==Other Notes==&lt;br /&gt;
* This server is backed up using Veeam.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Servers]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:New_Computer_Setup&amp;diff=14340</id>
		<title>Information Systems:New Computer Setup</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:New_Computer_Setup&amp;diff=14340"/>
		<updated>2022-11-18T20:15:50Z</updated>

		<summary type="html">&lt;p&gt;Danielc: /* Setup Steps */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This Page will give you brief information about what to do to set up a new computer. &lt;br /&gt;
&lt;br /&gt;
==Windows 10 Image== &lt;br /&gt;
Generally, Lenovo's laptop images are good so, there is no need to format and use a generic Windows 10 image. &lt;br /&gt;
&lt;br /&gt;
==Setup Steps== &lt;br /&gt;
# Select '''Canada''' in region and click '''Yes'''.&lt;br /&gt;
# In keyboard layout select '''US'''. &lt;br /&gt;
# Skip the second keyboard option. &lt;br /&gt;
# Connect with the internet, you can connect with the ethernet cable or connect to a Wifi. &lt;br /&gt;
# Create a local user with '''username: adminit Password: visionit''' or '''username: Unipharm Password: Unipharm''' and click '''next'''.&lt;br /&gt;
# Select '''NO in location''' option and click '''Accept'''.&lt;br /&gt;
# Select '''NO in Find my Device''' user can't connect to their MS account due to Group Policy, So, the option is pointless. &lt;br /&gt;
# Select '''Send Required diagnostic data''' and select '''Accept'''.&lt;br /&gt;
# Select '''NO in Improve inking and typing''' option and click '''Accept'''.&lt;br /&gt;
# Select '''NO for tailored experiences with diagnostic data''' and click '''Accept'''. This will not reduce the number of ads, but this option will not send data to Microsoft. &lt;br /&gt;
# Select '''NO for advertising ID''' and click '''Accept'''. &lt;br /&gt;
# Use '''Not now for Cortana'''. &lt;br /&gt;
# Now Windows is set up. It will take some minutes to complete the setup process.&lt;br /&gt;
&lt;br /&gt;
==Computer Name Notations== &lt;br /&gt;
After windows is setup up, We want to change the default computer name to a more appropriate name before we connect the computer to the Domain. The computer naming convention is as follow: &lt;br /&gt;
&amp;lt;u&amp;gt; ''Department'' &amp;lt;/u&amp;gt; '''''-''''' &amp;lt;u&amp;gt; ''User's full Firstname and last name initial'' &amp;lt;/u&amp;gt; '''''-''''' &amp;lt;u&amp;gt; ''number depending how many computer a user have'' &amp;lt;/u&amp;gt; For Example:'''''IT-JackM-01''''' OR '''''IT-JackM-02''''' OR '''''DC-Common-01''''' (Common Computers) If there are two people with same name, last name initials with help in identifying between them.&lt;br /&gt;
&lt;br /&gt;
===Notations===&lt;br /&gt;
 &lt;br /&gt;
 {| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Department !! Notation&lt;br /&gt;
|-&lt;br /&gt;
|  Finance|| FIN&lt;br /&gt;
|-&lt;br /&gt;
| warehouse || DC&lt;br /&gt;
|-&lt;br /&gt;
| Information Technology || IT&lt;br /&gt;
|-&lt;br /&gt;
| Purchasing || PUR&lt;br /&gt;
|-&lt;br /&gt;
| Buying || BUY&lt;br /&gt;
|-&lt;br /&gt;
| Customer Service || CS&lt;br /&gt;
|-&lt;br /&gt;
| Executives || EXC&lt;br /&gt;
|-&lt;br /&gt;
| Spare || SPARE&lt;br /&gt;
|-&lt;br /&gt;
| Others || UWD&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Softwares to install== &lt;br /&gt;
This section will guide through different software required on a machine. Not all machines require all software so, be decide where the computer will be deployed and install accordingly. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! No. !! Software !! Which Computer to Install !! Where to Find !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| 1. || Mocha TN5250 || All Computers || Can be found on superserver (\\superserver\UWD Software\MochaSoft) (registration: UNIPHARM / 040965) || ERP System (Green Screen)&lt;br /&gt;
|-&lt;br /&gt;
| 2. || ASW || All Computers || Can be found on superserver (\\superserver\UWD Software\ASW\ASW GUI\Disk1) || GUI Version of Mocha TN5250 &lt;br /&gt;
|-&lt;br /&gt;
| 3. || Chrome || All Computers || Can be found on superserver  (\\superserver\UWD Software\Chrome) || Google Chrome &lt;br /&gt;
|-&lt;br /&gt;
| 4. || Adobe Acrobat Reader || All Computers || Download from web || Just the free version &lt;br /&gt;
|-&lt;br /&gt;
| 5. || Microsoft Office Home &amp;amp; Business 2019 || All Computers || Can be found on superserver (\\superserver\UWD Software\Microsoft Office), Keys Can be found at (\\superserver\Tech\common\Business Case Documents\2020\MS Office Upgrade &amp;amp; Email Migration (Complete)\Microsoft Office 2019 Licence Keys copy.xlsx) || Read More about MS Office &lt;br /&gt;
|-&lt;br /&gt;
| 6. || ACR Trend Reader || Warehouse || Can be foundon superserver (\\Superserver\UWD Software\ACR TrendReader) || Reads Thermostat Temp&lt;br /&gt;
|-&lt;br /&gt;
| 7. || 3CX Client || Customer Service || Can be found on superserver (\\Superserver\UWD Software\3cx) || To make/receive calls from computer&lt;br /&gt;
|-&lt;br /&gt;
| 8. || VIP Doc View || All Computers || Can be found on Superserver (\\Superserver\UWD Software\Gauss\VIP DocView) || Scanning Liberary&lt;br /&gt;
|-&lt;br /&gt;
| 9. || SRFax || All Computers || Can be Found on Superserver (\\Superserver\UWD Software\SRFax Printer Driver) || Driver to convert doc for fax&lt;br /&gt;
|-&lt;br /&gt;
| 10. || Fixme.it || All Computers || Can be found on Superserver (\\Superserver\UWD Software\Techinline Fix Me Unattended Client) || Unattented clients for remove service &lt;br /&gt;
|-&lt;br /&gt;
| 11. || ACS Analyser || Managers || Can be found on Superserver (\\Superserver\UWD Software\ASW Analyzer Newest Version) || Database software need configuration&lt;br /&gt;
|-&lt;br /&gt;
| 12. || iBMi Access || Selective Computers || Can be found on Superserver (\\Superserver\UWD Software\IBMiAccess_v1r1_WindowsAP_English) || Utility software for IBMi&lt;br /&gt;
|-&lt;br /&gt;
| 13. || Vantage || Laptops || Can be found in MS Store || For lenovo updates&lt;br /&gt;
|-&lt;br /&gt;
| 14. || SEP || All Computers || NA || NA&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:New_Computer_Setup&amp;diff=14339</id>
		<title>Information Systems:New Computer Setup</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:New_Computer_Setup&amp;diff=14339"/>
		<updated>2022-11-18T20:15:35Z</updated>

		<summary type="html">&lt;p&gt;Danielc: /* Setup Steps */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This Page will give you brief information about what to do to set up a new computer. &lt;br /&gt;
&lt;br /&gt;
==Windows 10 Image== &lt;br /&gt;
Generally, Lenovo's laptop images are good so, there is no need to format and use a generic Windows 10 image. &lt;br /&gt;
&lt;br /&gt;
==Setup Steps== &lt;br /&gt;
# Select '''Canada''' in region and click '''Yes'''.&lt;br /&gt;
# In keyboard layout select '''US'''. &lt;br /&gt;
# Skip the second keyboard option. &lt;br /&gt;
# Connect with the internet, you can connect with the ethernet cable or connect to a Wifi. &lt;br /&gt;
# Create a local user with '''username: adminit Password: visionit''' or'''username: Unipharm Password: Unipharm''' and click '''next'''.&lt;br /&gt;
# Select '''NO in location''' option and click '''Accept'''.&lt;br /&gt;
# Select '''NO in Find my Device''' user can't connect to their MS account due to Group Policy, So, the option is pointless. &lt;br /&gt;
# Select '''Send Required diagnostic data''' and select '''Accept'''.&lt;br /&gt;
# Select '''NO in Improve inking and typing''' option and click '''Accept'''.&lt;br /&gt;
# Select '''NO for tailored experiences with diagnostic data''' and click '''Accept'''. This will not reduce the number of ads, but this option will not send data to Microsoft. &lt;br /&gt;
# Select '''NO for advertising ID''' and click '''Accept'''. &lt;br /&gt;
# Use '''Not now for Cortana'''. &lt;br /&gt;
# Now Windows is set up. It will take some minutes to complete the setup process.&lt;br /&gt;
&lt;br /&gt;
==Computer Name Notations== &lt;br /&gt;
After windows is setup up, We want to change the default computer name to a more appropriate name before we connect the computer to the Domain. The computer naming convention is as follow: &lt;br /&gt;
&amp;lt;u&amp;gt; ''Department'' &amp;lt;/u&amp;gt; '''''-''''' &amp;lt;u&amp;gt; ''User's full Firstname and last name initial'' &amp;lt;/u&amp;gt; '''''-''''' &amp;lt;u&amp;gt; ''number depending how many computer a user have'' &amp;lt;/u&amp;gt; For Example:'''''IT-JackM-01''''' OR '''''IT-JackM-02''''' OR '''''DC-Common-01''''' (Common Computers) If there are two people with same name, last name initials with help in identifying between them.&lt;br /&gt;
&lt;br /&gt;
===Notations===&lt;br /&gt;
 &lt;br /&gt;
 {| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Department !! Notation&lt;br /&gt;
|-&lt;br /&gt;
|  Finance|| FIN&lt;br /&gt;
|-&lt;br /&gt;
| warehouse || DC&lt;br /&gt;
|-&lt;br /&gt;
| Information Technology || IT&lt;br /&gt;
|-&lt;br /&gt;
| Purchasing || PUR&lt;br /&gt;
|-&lt;br /&gt;
| Buying || BUY&lt;br /&gt;
|-&lt;br /&gt;
| Customer Service || CS&lt;br /&gt;
|-&lt;br /&gt;
| Executives || EXC&lt;br /&gt;
|-&lt;br /&gt;
| Spare || SPARE&lt;br /&gt;
|-&lt;br /&gt;
| Others || UWD&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Softwares to install== &lt;br /&gt;
This section will guide through different software required on a machine. Not all machines require all software so, be decide where the computer will be deployed and install accordingly. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! No. !! Software !! Which Computer to Install !! Where to Find !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| 1. || Mocha TN5250 || All Computers || Can be found on superserver (\\superserver\UWD Software\MochaSoft) (registration: UNIPHARM / 040965) || ERP System (Green Screen)&lt;br /&gt;
|-&lt;br /&gt;
| 2. || ASW || All Computers || Can be found on superserver (\\superserver\UWD Software\ASW\ASW GUI\Disk1) || GUI Version of Mocha TN5250 &lt;br /&gt;
|-&lt;br /&gt;
| 3. || Chrome || All Computers || Can be found on superserver  (\\superserver\UWD Software\Chrome) || Google Chrome &lt;br /&gt;
|-&lt;br /&gt;
| 4. || Adobe Acrobat Reader || All Computers || Download from web || Just the free version &lt;br /&gt;
|-&lt;br /&gt;
| 5. || Microsoft Office Home &amp;amp; Business 2019 || All Computers || Can be found on superserver (\\superserver\UWD Software\Microsoft Office), Keys Can be found at (\\superserver\Tech\common\Business Case Documents\2020\MS Office Upgrade &amp;amp; Email Migration (Complete)\Microsoft Office 2019 Licence Keys copy.xlsx) || Read More about MS Office &lt;br /&gt;
|-&lt;br /&gt;
| 6. || ACR Trend Reader || Warehouse || Can be foundon superserver (\\Superserver\UWD Software\ACR TrendReader) || Reads Thermostat Temp&lt;br /&gt;
|-&lt;br /&gt;
| 7. || 3CX Client || Customer Service || Can be found on superserver (\\Superserver\UWD Software\3cx) || To make/receive calls from computer&lt;br /&gt;
|-&lt;br /&gt;
| 8. || VIP Doc View || All Computers || Can be found on Superserver (\\Superserver\UWD Software\Gauss\VIP DocView) || Scanning Liberary&lt;br /&gt;
|-&lt;br /&gt;
| 9. || SRFax || All Computers || Can be Found on Superserver (\\Superserver\UWD Software\SRFax Printer Driver) || Driver to convert doc for fax&lt;br /&gt;
|-&lt;br /&gt;
| 10. || Fixme.it || All Computers || Can be found on Superserver (\\Superserver\UWD Software\Techinline Fix Me Unattended Client) || Unattented clients for remove service &lt;br /&gt;
|-&lt;br /&gt;
| 11. || ACS Analyser || Managers || Can be found on Superserver (\\Superserver\UWD Software\ASW Analyzer Newest Version) || Database software need configuration&lt;br /&gt;
|-&lt;br /&gt;
| 12. || iBMi Access || Selective Computers || Can be found on Superserver (\\Superserver\UWD Software\IBMiAccess_v1r1_WindowsAP_English) || Utility software for IBMi&lt;br /&gt;
|-&lt;br /&gt;
| 13. || Vantage || Laptops || Can be found in MS Store || For lenovo updates&lt;br /&gt;
|-&lt;br /&gt;
| 14. || SEP || All Computers || NA || NA&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Xerox_printers&amp;diff=14330</id>
		<title>Information Systems:Xerox printers</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Xerox_printers&amp;diff=14330"/>
		<updated>2022-11-03T22:18:03Z</updated>

		<summary type="html">&lt;p&gt;Danielc: /* Xerox Device Agent Software */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;uniPHARM uses Xerox printers for office printing (as opposed to Lexmark printers used in the warehouse). These printers are under either lease or managed print service agreements. Our service provider is West-X Network Solutions, but technical support is still done with Xerox.&lt;br /&gt;
&lt;br /&gt;
==Inventory==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Printer hostname !! Model !! Serial !! Location / purpose !! Contract type&lt;br /&gt;
|-&lt;br /&gt;
| reccopier || Xerox VersaLink B405DN || 9HB368640 || Receiving area office || Managed Print Services &lt;br /&gt;
|-&lt;br /&gt;
| rtncopier || Xerox VersaLink B405DN || 9HB368638 || Returns department || Managed Print Services&lt;br /&gt;
|-&lt;br /&gt;
| elaho || Xerox Versa C60 || E2B110152 || 2nd-floor printing alcove || Leased&lt;br /&gt;
|-&lt;br /&gt;
| stein || Xerox AltaLink B8055 || Y4X849851 || 1st-floor [[:Category:uniPHARM Dictionary|dumps area]] || Leased&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Support info==&lt;br /&gt;
&lt;br /&gt;
* Contact number for leased printers (Xerox One Number): 1-800-275-9376&lt;br /&gt;
* Contact number for printers under Managed Print Services: 1-866-487-4239&lt;br /&gt;
* Contract end date: December 12,2023&lt;br /&gt;
* West-X: 604-668-2536&lt;br /&gt;
&lt;br /&gt;
==Administration==&lt;br /&gt;
===Xerox Fleet Management===&lt;br /&gt;
This is a useful portal site that Xerox provides for leased or managed printers&lt;br /&gt;
* https://office.services.xerox.com/FMP/LoginPage.aspx&lt;br /&gt;
* Username is darrenf@unipharm.com&lt;br /&gt;
* Password is NewVisionIT2051@!&lt;br /&gt;
&lt;br /&gt;
===Xerox Device Agent Software===&lt;br /&gt;
There is an application from Xerox called the Xerox Device Agent, installed on the WDS3(172.30.18.11) virtual machine.  This program sends the page meter reads for the copiers in Returns and Receiving to WestX for billing purposes.  This application consumes a lot of CPU time.  DarrenF tried for 4 months to get Xerox and its developers to figure out why a crappy little program uses so much CPU 24/7.  Xerox wasn't willing to acknowledge a problem or allow a conversation to happen with their in-house developers - so the support ticket was closed as unresolved.  The Xerox Device Agent software needs to continue to run and report billing data to WestX so if the CPU usage becomes a problem, try to get a new version of the app or open a new ticket with Xerox and prepare for pain.&lt;br /&gt;
&lt;br /&gt;
This was resolved, it was due to not having the newest version of the app provided by west X , running smooth now.&lt;br /&gt;
&lt;br /&gt;
===Xerox NeckBeard Support===&lt;br /&gt;
On June 13th, 2019, a Xerox technician was called onsite to fix the C60 that was not copying paper in the top feeder or from the glass.  He determined that the OS was corrupt and did a factory reset of the machine which wiped out all of its configuration settings.  He failed to notify anyone that he was doing a factory reset and he failed to create a backup clone file of the configuration to restore.  This caused a great deal of inconvenience and extra work that was not necessary if a clone file was available.  If this dumbfuckery ever happens again, there are saved clone files on the SuperServer in the following location : \\superserver.unipharm.local\Tech\Logs And Backups\Xerox Copier Clone Files\.  In that folder are clone files for all the leased and MPS copiers as of June 2019.  The 2 Xerox MFDs that are used by RonG and AngelaC cannot produce clone files.  In case you haven't caught on, a clone file is a file that contains all the settings that are configured on a printer, with the purpose of &amp;quot;cloning&amp;quot; itself onto another printer of the same model or the exact same one after some asshat decides to do something idiotic.&lt;br /&gt;
&lt;br /&gt;
Xerox support is very helpful, when called they respond within a day. They are willing to teach and leave extra supplies in case of emergent need. Recently the C60 needed to have maintenance, remember that the bottom drawer has a security screw, if need be to release the drawer and unjam the document, replace pick rollers.&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
* The Altalink, also under the service has temporary files that need to be cleared out regularly, this can be scheduled, and takes 20-60 minutes based on what you are clearing. &lt;br /&gt;
* Software update performed may 12 2021, with support, to resolve network  card restart issue. &lt;br /&gt;
&lt;br /&gt;
===Old printers===&lt;br /&gt;
This section is for reference purposes. These printers are no longer being used.&lt;br /&gt;
&lt;br /&gt;
There are 4 different Xerox copier models in use as of 2016.  The 7775 is located in the printing alcove on the second floor. The has 2 fax lines connected so that it can fax inbound and outbound at the same time.  The 7775 is leased and Xerox provides consumable toner and other supplies as part of the lease cost.  Xerox also provides technical support and repairs as part of the lease.  When requesting supplies, repairs or support you must provide the serial number which can be found on the copiers admin page.&lt;br /&gt;
&lt;br /&gt;
*[http://elaho.unipharm.local/ Elaho Administration Web GUI]&lt;br /&gt;
*admin&lt;br /&gt;
*1111&lt;br /&gt;
&lt;br /&gt;
At this time you must use edge/explorer for web administration. &lt;br /&gt;
&lt;br /&gt;
The WorkCentre 5855 is located next the Supervisors Office in the shipping area of the DC.  It has no colour capability but it does have the ability to fax inbound/outbound.  The supplies the 5855 uses are different from the 7775 and there is a much smaller and less complicated touch screen.  The 5855 is also on the same lease program as the 7775.&lt;br /&gt;
&lt;br /&gt;
*[http://stein.unipharm.local/ Stein Administration Web GUI]&lt;br /&gt;
*admin&lt;br /&gt;
*1111&lt;br /&gt;
&lt;br /&gt;
The WorkCentre 4265 copiers are located in the Receiving Office and the Returns Areas in the DC.  They are smaller copiers with fewer paper trays.  They both do have a single fax phone line attached and have very similar software capabilities compared to the 5855 and are on the same lease program as the 5855 and 7775.&lt;br /&gt;
&lt;br /&gt;
*[http://reccopier.unipharm.local/ Reccopier Administration Web GUI]&lt;br /&gt;
*[http://rtncopier.unipharm.local/ Rtncopier Administration Web GUI]&lt;br /&gt;
*admin&lt;br /&gt;
*1111&lt;br /&gt;
&lt;br /&gt;
The WorkCentre 6605 copiers are slightly smaller than the 4265s but otherwise perform and behave in the same way.  The 6605s were free from Xerox and are NOT on the lease program and toner and supplies DO need to be purchased for the 2 that are used by the payroll administrator and general manager.  Both of the 6605s are network and fax attached.&lt;br /&gt;
&lt;br /&gt;
[[Category: Printing]]&lt;br /&gt;
[[Category: Pages with Contact Information]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:3CX_IP-PBX_Administrator%27s_Guide&amp;diff=14328</id>
		<title>Information Systems:3CX IP-PBX Administrator's Guide</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:3CX_IP-PBX_Administrator%27s_Guide&amp;diff=14328"/>
		<updated>2022-10-31T20:45:55Z</updated>

		<summary type="html">&lt;p&gt;Danielc: /* Administration Portal */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Administration Portal==&lt;br /&gt;
3CX Administration Web Portal:&lt;br /&gt;
&lt;br /&gt;
 URL: https://3cx.unipharm.local:5001&lt;br /&gt;
 Username: Administrator&lt;br /&gt;
 Password: NewTechIS21!&lt;br /&gt;
&lt;br /&gt;
==License==&lt;br /&gt;
Our 3CX license is '''Professional Perpetual''' with 16 simultaneous calls. Simultaneous calls includes internal/extension-to-extension calls, and both parked and queued calls. To date, our real world usage has never come close to reaching this. Nonetheless, the license can always be upgraded at a pro-rated cost.&lt;br /&gt;
::[[File:2021-03-31 11_25_29-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
&lt;br /&gt;
The license is renewed annually through TelData. &lt;br /&gt;
&lt;br /&gt;
==Configuration==&lt;br /&gt;
===Extensions===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;3&amp;quot;|Noteworthy Extensions&lt;br /&gt;
|-&lt;br /&gt;
|Extension&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===SIP Trunks===&lt;br /&gt;
A SIP trunk is what allows a PBX to make and receive outbound calls. A SIP trunk is configured for 1 or more channels (simultaneous calls). 3CX has 2 SIP trunk configurations:&lt;br /&gt;
* [[Information Systems: ThinkTel SIP Trunk | ThinkTel SIP Trunk]]&lt;br /&gt;
* [[Information Systems: RingOffice SIP Trunk | RingOffice SIP Trunk]]&lt;br /&gt;
&lt;br /&gt;
The ''SIP Trunks'' section in 3CX shows the following configuration:&lt;br /&gt;
:[[File:2021-03-31 11_51_37-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
* The order is alphabetical and does not imply call routing precedence; that is defined in ''Outbound Rules''&lt;br /&gt;
* As seen in the figure, only RingOffice has Register information. This characteristic differentiates the two SIP trunks: the RingOffice trunk does ''registration-based'' authentication, while ThinkTel is IP-based. [https://www.3cx.com/docs/sip-trunk-registration-authentication/ Read more about this here.] There is a slight benefit to Register-based authentication in that you can tell when the connection goes down (Register failed).&lt;br /&gt;
* The number of Sim calls is defined manually. It should match the number of channels of the SIP trunk service, but can be used to control usage (e.g. putting a max of 3 when there are really 6 usable channels will cause 3CX to use the next available trunk for the 4th sim call).&lt;br /&gt;
* The WebMeeting bridge is an internal and automatically configured trunk (can be ignored).&lt;br /&gt;
&lt;br /&gt;
===External Call Routing===&lt;br /&gt;
Calls to and from external numbers are routed according to the rules defined in the ''Inbound Rules'' and ''Outbound Rules'' sections. There are two main concepts:&lt;br /&gt;
&lt;br /&gt;
* DID mapping in ''Inbound Rules''&lt;br /&gt;
* Call routes in ''Outbound Rules''&lt;br /&gt;
&lt;br /&gt;
====Inbound Rules====&lt;br /&gt;
* DIDs (Direct Inward Dialing) are what we know as phone numbers (604-123-4567). They can be mapped in ''Inbound Rules'', either to local extensions, call queues, ring groups etc. Several DIDs can be mapped to the same internal target. For example, the toll-free and main company phone number map to the Customer Service call queue (technically the digital receptionist extension, but eventually routed there).&lt;br /&gt;
Part of the Inbound Rules page is shown here:&lt;br /&gt;
:[[File:2021-03-31 12_37_13-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
====Outbound Rules====&lt;br /&gt;
:[[File:2021-03-31 12_19_44-3CX Phone System Management Console.png|400px]]&lt;br /&gt;
* Outbound rules specify the routes that outbound calls take. Notice that there is no 1:1 mapping of extensions to outbound routes. This is possible but absolutely unnecessary. Instead, the rules are catch-alls for other criteria (prefix, extension range). &lt;br /&gt;
* The prefix routes (9) are there to match the old phone system (where dialing 9 was necessary to &amp;quot;call out&amp;quot;). This is also still a common practice in many phone implementations, presumably as an extra validation measure for users i.e. to have users confirm their intent in dialing an external number.&lt;br /&gt;
* These rules are evaluated in order, from top down. This is why the 911 rule is at the top.&lt;br /&gt;
&lt;br /&gt;
===Call flow===&lt;br /&gt;
Call flow refers to the path a call takes through the system. The settings in Inbound and Outbound Rules define part of the flow, but it can be &lt;br /&gt;
&lt;br /&gt;
Most call flows are straightforward e.g. DID to local extension, voicemail if not available. &lt;br /&gt;
&lt;br /&gt;
===Voicemail===&lt;br /&gt;
Voicemail works as it does in other phone systems - there is a message center that users access to listen and otherwise manage their messages. This extension is 999. There are however, serveral additional enhancements related to voicemail:&lt;br /&gt;
&lt;br /&gt;
* Email notifications: Voicemails can be emailed, with a transcription of the text, an attached wav file of the audio message, or both. This is set per extension and is disabled by default.&lt;br /&gt;
* Voicemail transcription: Voicemail transcription transcribes voice messages to text so users can read instead of listen to the audio message. The functionality is set up system-wide in the 3CX settings, however, it needs to be enabled per-extension (for those that want it). It uses the Voice-to-Text service within Google Cloud Platform, and is billable monthly past the first 60 minutes (every month) of transcribed audio.&lt;br /&gt;
&lt;br /&gt;
====Customer Service Voicemail====&lt;br /&gt;
Extension ''501'' is used solely for &lt;br /&gt;
&lt;br /&gt;
====Google cloud services (GCP) integration====&lt;br /&gt;
3CX uses the following Google Cloud Platform services to provide special features:&lt;br /&gt;
* Firebase: Push notifications for 3CX mobile app ('''Android''' app only, Apple uses its own APNS)&lt;br /&gt;
* Cloud Speech API: Voicemail transcription (voice-to-text)&lt;br /&gt;
&lt;br /&gt;
 GCP Web Portal access:&lt;br /&gt;
 &lt;br /&gt;
 URL: https://console.cloud.google.com/&lt;br /&gt;
 Username: root@unipharm.com (uniPHARM Google account)&lt;br /&gt;
 Password: NewVisionIT&lt;br /&gt;
 Project name: UWD 3CX (use dropdown to select project)&lt;br /&gt;
 &lt;br /&gt;
 See the Billing section for Cloud Speech API billing. GCP gives a $400 credit for the first year, therefore during this first year, when looking at the billing, &amp;quot;One-time credits&amp;quot; may need to be toggled to see the actual billed usage that we would have paid.&lt;br /&gt;
 &lt;br /&gt;
 Firebase can be viewed in the section of the same name. However, integration with 3CX is just an API token to use the PUSH notification service, so this doesn't need regular maintenance unless changing the token.&lt;br /&gt;
&lt;br /&gt;
===Other Notes===&lt;br /&gt;
====Backup====&lt;br /&gt;
*( 3CX is being backed up to: &amp;lt;code&amp;gt;smb://superserver.unipharm.local/Tech/common/ConfigBackups/3CX&amp;lt;/code&amp;gt;. It should be here &amp;lt;code&amp;gt;\\superserver.unipharm.local\Tech\Logs And Backups&amp;lt;/code&amp;gt;, but spaces in the backup location path are not allowed (at least for SMB backups). This should be tweaked in the future. The last 20 backups are kept (auto-rotated). &lt;br /&gt;
* Because 3CX is both a virtual appliance and a fairly easy/small installation, there is no system image backup (would waste a Veeam license). A disaster recovery situation would then entail reinstallation of the 3CX virtual appliance and restoration of the backup config.&lt;br /&gt;
&lt;br /&gt;
[[Category: Phone System]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Server_Hardware_Inventory_and_Assessment_(2021)&amp;diff=14317</id>
		<title>Information Systems:Server Hardware Inventory and Assessment (2021)</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Server_Hardware_Inventory_and_Assessment_(2021)&amp;diff=14317"/>
		<updated>2022-10-18T17:50:07Z</updated>

		<summary type="html">&lt;p&gt;Danielc: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Server name !! Server model !! Server description !! CPU !! RAM installed (GB) !! Storage (GB) !! Storage controller !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| VMHost01 || X3650 M5 || ESXi virtualization host 1 || 1 x E5-2620 v4 || 64 (1x16, 6x8) || 5000 (6x1TB in RAID-5) || M5210 || -&lt;br /&gt;
|-&lt;br /&gt;
| VMHost02 || X3650 M5 || ESXi virtualization host 2 || 1 x E5-2620 v4 || 64 (1x16, 6x8) || 5000 (6x1TB in RAID-5) || M5210 || -&lt;br /&gt;
|-&lt;br /&gt;
| VMHost03 || X3550 M5 || ESXi virtualization host 3 || 2 x E5-2620 v3 || 64 (4x16) || 2000 (2x2000GB in RAID-1 || M5210 || -&lt;br /&gt;
|-&lt;br /&gt;
| UWDDC3 (former) || X3250 M5 || Former domain controller, physical server || E3-1230 || 16 || 2x128GB || - || -&lt;br /&gt;
|-&lt;br /&gt;
| UWDDC4 (former) || X3250 M5 || Former domain controller, physical server || E3-1230 || 16 || 2x128GB || - &lt;br /&gt;
|-&lt;br /&gt;
| Stewie || X3550 M4 || Unused || E5-2620 v2 || 8 || - || Can be replaced with 2xE5-2650 v2 = 16c/32t for very cheap!&lt;br /&gt;
|-&lt;br /&gt;
| Veeam || X3650 M3 || Currently a Veeam proof-of-concept machine. || E5620 || - || - || - || Should be an archive server. Should have more SSDs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
* Same-generation servers use the same hard drive caddies.&lt;br /&gt;
&lt;br /&gt;
==Ideas==&lt;br /&gt;
* Decommission old Superserver/Veeam machine.&lt;br /&gt;
* Decommission Stewie&lt;br /&gt;
* Add and reconfigure storage on VMHost03&lt;br /&gt;
* Reinstate UWDDC3/4 i.e. reinstall in the rack.&lt;br /&gt;
:* Create backup server out of one of these&lt;br /&gt;
:* Use the other as a play server&lt;br /&gt;
* Buy 32GB more memory for VMHost03 (https://www.axiomupgrades.com/productdetail/01KN301-AX/)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Servers]]&lt;br /&gt;
[[Category: I.T. Projects and Ideas]]&lt;/div&gt;</summary>
		<author><name>Danielc</name></author>
	</entry>
</feed>