Inside Windows 98

Previous chapterNext chapterContents


- 30 -

Using Remote Administration


If your Windows 98 machine participates in a networked environment of any appreciable size, remote administration of its operating system and network services will likely be an important asset. The ability to remotely administer a network computer from another computer can mean the difference between lengthy service calls and tech support and the quick resolution of problems.

Windows 98 builds upon the remote administration features of Windows 95 and enhances user-level security for remote access to the computer. This means that network user and group accounts can be assigned authority to remotely administer the Windows 98 computer, while all other users are restricted. For instance, if your Windows 98 machine participates in a Windows NT domain, you may want to grant the Domain Admins group remote administration access.

This chapter is targeted toward both the intermediate Windows 98 user and the Windows NT network administrator who must configure Windows 98 machines for the network. Many of the remote administration techniques and tools for Windows 98 work and coexist with the Windows NT network operating system and services.

What can be accomplished with remote administration of the Windows 98 computer? Some examples of remote administration scenarios follow:

These tasks can all be performed using the existing tools in Windows 98 or packaged with Windows 98 on the CD-ROM. This chapter covers the following remote administrative tools and procedures:

Enabling Remote Administration

Windows 98 can be configured to designate certain people to administer the computer remotely. Windows NT domain global groups and users can be individually assigned remote administrative control of the Windows 98 machine.

To view your Windows 98 machine's remote administration configuration, open the Password tool in Control Panel and click on the Remote Administration tab. Figure 30.1 shows the Remote Administration tab:

FIGURE 30.1 The Remote Administration tab with Remote Administration enabled and the Domain admins group given administration privileges.

By enabling Remote Administration, you give the specified groups and users the ability to administer the computer, using all of the methods detailed in this chapter, including network performance monitoring, remote Registry editing, and backups.

Check the check box to enable Remote Administration. Click the Add button and choose individual groups and users to add them to the Remote Administrators list. Typically, you will want to include the Domain admins group. You may also want to grant remote access permissions to the actual user(s) of the Windows 98 machine, but only if he normally administers the machine. For instance, if the user is simply trained to use office applications and has no other networking or computer experience, he doesn't need to be added to the Remote Administration list simply because it's his machine. Always be cautious in assigning Remote Administration privileges.

Using the Network Monitor Agent

Microsoft's Network Monitor Agent enables your Windows 98 computer's incoming and outgoing network traffic to be analyzed using special network monitoring tools. Although they aren't automatically installed, the Network Monitor Agent and protocol driver can be installed from the Windows 98 CD-ROM.

The protocol driver and related executable file enable you to monitor traffic statistics for NDIS 3.1-compliant protected-mode network adapters. You can use this protocol and software to monitor traffic not only on LANs and WANs, but also on the Microsoft Remote Access Server. Network Monitor Agent is particularly useful in troubleshooting network problems.

By using the Network Monitor Agent, you can configure your Windows 98 computer to allow remote network traffic monitoring using the Network Monitor tools, including Microsoft Systems Management Server. The Network Monitor Agent and protocols should not be confused with the Network Monitor tools, which are not included with Windows 98. This section details how to install the Network Monitor Agent and protocols and briefly introduces the Network Monitor tool.


NOTE: The Network Monitor Agent is also provided as a component in the Microsoft Systems Management Server, a separate retail network management tool.

The Network Monitor Agent

You can install the Network Monitor Agent in two ways. The first is to install both the agent and the protocol driver, which enables you to use the agent to monitor network traffic and to conduct troubleshooting. To perform this type of installation, follow these steps:

1. Click the Network icon in the Control Panel.

2. Click the Add button in the Configuration tab.

3. In the Select Network Component Type dialog box, click on Service in the list box and then click the Add button.

4. In the Select Network Service dialog box that appears, click the Have Disk button and enter the following path in the Install From Disk dialog box and then click OK:
TOOLS\RESKIT\NETADMIN\NETMON
5. When the Select Network Service dialog box reappears, click on the Microsoft Network Monitor Agent.

6. Click on the OK button. Windows 98 copies and installs the appropriate files.

7. Click on OK to close the Network dialog box and update the settings. Windows 98 prompts you to restart the computer.

The other method is to install only the protocol driver, in which you use the System Monitor application to monitor network performance. To install only the protocol driver, perform the following steps:

1. Click the Network icon in the Control Panel.

2. Click on the Add button in the Configuration tab.

3. In the Select Network Component Type dialog box, click on Protocol in the list box and then on the Add button.

4. In the Select Network Protocol dialog box that appears, click on the Have Disk button and enter the following path in the Install From Disk dialog box and then click OK:
TOOLS\RESKIT\NETADMIN\NETMON
5. When the Select Network Protocol dialog box reappears, click on the Microsoft Network Monitor Agent in the Models list box.

6. Click on the OK button. Windows 98 copies and installs the appropriate files.
7. Click on OK to close the Network dialog box and update the settings. Windows 98 prompts you to restart the computer.

The Network Monitor Agent can be run either as a service or as an executable file. To run it as a service, follow these steps:

1. Using the Registry Editor, select Hkey_Local_Machine\Software\ Microsoft\Windows\CurrentVersion\RunServicesOnce.

2. Select New from the Edit menu and then select String Value.

3. Enter a value for the label name. You could use nm_agent, for example.

4. Select the string value you just created, open the Edit menu, and click on Modify.

5. In the Value Data text box of the Edit String text box, enter nmagent.exe.

6. Click on the OK button and exit the Registry Editor.

Running the Network Monitor Agent

Running the Network Monitor Agent as a Windows 98 service ensures the availability of Network Monitor Agent at all times Windows 98 is running. If you would rather run Network Monitor Agent only when needed, you should run it as an executable.

You can run the Network Monitor Agent as an executable file by clicking on the Start button and selecting the Run option. Enter NMAGENT.EXE in the Run dialog box and click the OK button. The agent starts operation.

If you ever need to stop the Network Monitor Agent, click on the Start button and select Run. Enter nmagent -close in the dialog box and click on OK. The agent stops operation.

Note that the Network Monitor Agent does not provide a graphical interface or feedback and is not the same program as the Network Monitor tool in Windows NT and Microsoft System Management Server.

The Network Monitor Tool

If you are a Windows NT systems administrator, you may already have a working knowledge of the uses and capabilities of the Network Monitor tool in either Systems Management Server (SMS) or the scaled-down version offered with Windows NT Server 4.0. To remotely monitor your Windows 98 computer with the Network Monitor tool, you must use the one provided with SMS; the version included with Windows NT Server 4.0 monitors only the local NT Server.

The Network Monitor tool can be used to monitor network traffic information on the Windows 98 system with Network Monitor Agent installed and running. Some statistics the Network Monitor can capture and analyze follow:

Another benefit of using the Network Monitor is its information-capture and filtering features. Complex statistics reports can be designed on a per-computer basis and saved for future use. Figure 30.2 shows the Network Monitor tool at work.

FIGURE 30.2 The Network Monitor tool captures and filters network traffic information from a Network Monitor Agent-enabled remote computer. This can be a valuable method of troubleshooting network and bandwidth problems.

Using SNMP

If your network uses the Simple Network Management Protocol (SNMP) to provide management services, you can use the SNMP agent provided with Windows 98 to facilitate managing Windows 98 computers attached to the network. This section outlines the two basic methods of configuring SNMP: using the Windows System Policy Editor and editing the Windows Registry.

SNMP is a standard protocol for network management and makes remote administration much easier and more universal. The Windows 98 computer configured to use SNMP responds to remote SNMP queries and broadcasts event notifications to an SNMP console. Windows NT Server 4.0 includes tools that help configure remote systems that use SNMP. Many third-party network software packages and operating systems support SNMP. You are not limited to Windows NT Server 4.0's SNMP management; other packages and network operating systems offer SNMP management consoles.

Installing the Windows 98 SNMP Agent

After installation, the SNMP agent makes Windows 98 computers visible to your SNMP console. To install the SNMP agent, follow these steps:

1. Click on the Network icon in the Control Panel.

2. Click on the Add button in the Configuration tab.

3. In the Select Network Component Type dialog box, click on Service in the list box and then on the Add button.

4. In the Select Network Service dialog box that appears, click on the Have Disk button. Enter the following path in the Install From Disk dialog box and click OK:
TOOLSF\RESKIT\NETADMIN\SNMP
5. You are asked to reboot your computer. Do so before continuing with SMNP configuration.

Configuring SNMP

After installing the SNMP agent, your Windows 98 computer will be visible to the system administrator's SNMP console. SNMP configuration is accomplished by editing your Windows 98 computer's system policies. You can configure the SNMP agent by editing system policies using one of two methods:

Using the System Policy Editor

You can use the System Policy Editor on your Windows NT server to create a new system policy for your computer. The System Policy Editor, shown in Figure 30.3, is used to create user, group, and system policies for your Windows 98 computer. System policies help network administrators to define the level of usability of the Windows 98 machine, including network settings, network shares, and the level of control the user has over the Windows desktop. System policies override any user profiles on the Windows 98 machine.

FIGURE 30.3 The System Policy Editor is used to configure policies for users, groups, and computers on the network. It can be used to configure SNMP policies for a local or remote system.


NOTE: Windows NT Server 4.0 also includes a System Policy Editor that can be used to remotely configure computers on the existing Windows NT domain. If you are a Windows NT network administrator and want to create a system policy for your Windows 98 computer, the configuration steps are similar. For more information, view the online help in Windows NT.

Installing the System Policy Editor

If the System Policy Editor is not already installed on your Windows 98 machine, you will need to follow these steps to install it from the Windows 98 CD-ROM:

1. Open Control Panel and double-click on the Add/Remove Programs icon.

2. Choose the Windows Setup tab and click the Have Disk button.

3. Specify the following directory for the Policy Editor installation files on the Windows 98 CD-ROM:
TOOLS\RESKIT\NETADMIN\POLEDIT


4. Click OK to install.

5. Click OK to exit the Add/Remove Programs applet.

Creating a System Policy

To create an entry for your Windows 98 computer in the System Policy Editor, follow these steps:

1. Click on the System Policy Editor icon in the Administrative Tools menu on your NT server.

2. If an entry for the computer doesn't already exist, click the Add Computer icon or choose Add Computer from the Edit menu.

3. In the Add Computer dialog box, either type the network name of your Windows 98 computer or click Browse to find it on the network.

4. You should now have a new icon in your System Policy Editor corresponding to the computer you just added.

To use the System Policy Editor to configure SNMP settings on your remote Windows 98 computer (see Table 30.1 and Figure 30.4), double-click on the corresponding icon and open the System branch on the list; next click the SNMP and notice the options on the expanded branch.


TIP: The System Policy Editor is the easiest and safest way to configure the SNMP agent.

TABLE 30.1 System Policies to Set for the SNMP Agent

Policy What to Set
Communities Add the host or group of hosts that may query this SNMP agent. These are the hosts that may administer the SNMP agent.
Permitted Managers Add the IPX or IP addresses of the consoles that may display information about this computer.
Traps to Public Community Add the IPX or IP addresses of hosts in the public community to which traps should be sent.
Internet MIB (RFC 1156) Add the contact name and location for Internet MIB.

FIGURE 30.4 The policy created for the Windows 98 computer, being used to edit the system's SNMP properties.

Using the Registry Editor to Configure SNMP

You also can edit the Registry to set the SNMP policies. To do so, open the Registry Editor and follow these steps:

1. Select the key Hkey_Local_Machine\System\CurrentControlSet\ Services\SNMP\Parameters\TrapConfiguration.

2. Choose New from the Edit menu and select the Key item on the cascading menu.

3. Enter the name for the new community then press Enter.

4. Select New from the Edit menu and select the String Value item on the cascading menu. Enter a Value Name of 1 in the Name edit field that appears in the right-hand pane. Press Enter.

5. Select the new name in the right-hand pane. Choose Modify from the Edit menu.

6. In the Edit String dialog box that appears, enter the IPX or IP address for the SNMP console to which traps should be sent. Click on the OK button.

7. Repeat steps 4, 5, and 6 for each SNMP console to which you want traps sent.

8. Exit the Registry Editor.

Net Watcher


The Net Watcher application enables you to view shared resources on network computers and to perform certain actions in relation to these resources. The Net Watcher window shows you three types of resources (see Figure 30.5):

FIGURE 30.5 The Net Watcher window shows connections, shared folders, and open files on a remote computer.

You can select the resource you view from the View menu or by clicking buttons on the toolbar. By using the buttons on the toolbar or selecting options form the Administer menu, you can:

Before attempting to connect to a remote computer with Net Watcher, you should make sure that:

1. The remote computer has file and printer sharing enabled.

2. Your computer is running at least share-level security.

If the remote computer is also a Windows 98 computer, you can determine whether it has file and printer sharing enabled by using the Network applet in Control Panel. Likewise, you use the Network applet in Control Panel to configure your Windows 98 computer to run share-level security.


NOTE: On NetWare networks, two limitations apply. You can connect only to other computers that have enabled file and printer sharing for NetWare networks, and you cannot close files on remote computers.

Using the Password List Editor

Windows 98 uses PWL files to store lists of resources and their related passwords. As long as a password list file is unlocked, you can edit it with the Password List Editor. You must install the editor first, however, because it is not installed in the normal setup for Windows 98. To install the Password List Editor, follow these steps:

1. Open the Control Panel.

2. Click the Add/Remove Programs icon, select the Windows Setup tab, and click on the Have Disk button.

3. When the Install From Disk dialog box appears, click on the Browse button. Enter the following path and then click OK:
\TOOLS\RESKIT\NETADMIN\PWLEDIT


4. In the Have Disk dialog box, click Password List Editor in the list box, and then click Install. Windows 98 copies the appropriate files to your disk.

After you install the Password List Editor, running it presents a window that contains a list of all the password-protected services the computer accesses (see Figure 30.6). You cannot add resources or edit the actual passwords. You can, however, remove such services from a particular user's profile. Select the service in the list box and click the Remove button.

FIGURE 30.6 The Password List Editor enables you to edit the list of password-protected services available to individual users.

Editing Remote Registries

If you need to have complete control over a remote computer's Registry, you should access that computer by using the Registry Editor. (You can use the System Policy Editor to manage a remote Registry, but you get access only to a subset of the keys.)

To manage Registries from a remote location, you need to install the Remote Registry Service. To do this, perform the following steps:

1. Click on the Network icon in the Control Panel.

2. Click on the Add button in the Configuration tab.

3. In the Select Network Component Type dialog box, click on Service in the list box and then on the Add button.

4. In the Select Network Protocol dialog box that appears, click on the Have Disk button. Enter the following path in the Install From Disk dialog box and then click OK:
\TOOLS\RESKIT\NETADMIN\REMOTREG


5. When the Select Network Service dialog box reappears, click on the Microsoft Remote Registry in the Models list box.

6. Click the OK button. Windows 98 copies and installs the appropriate files.

7. Click OK to close the Network dialog box and update the settings. Windows 98 prompts you to restart the computer.

You must install the Remote Registry Service on both the administrative and the local computers. These two computers must have at least one network protocol in common. After installing the Remote Registry Service, you can connect to a remote Registry by following these steps:

1. Open the Registry Editor. (Type regedit in the Run box from the Start button, or the command prompt.)

2. Choose Connect Network Registry from the Registry menu.

3. In the dialog box, enter the name of the computer you want to administer remotely and click OK.

4. You may use the Registry Editor, shown in Figure 30.7, to administer the remote Registry just as you would the local Registry.

Figure 30.7 The Registry Editor can be used to remotely configure and administer the Windows 98 computer's Registry if both client and server machines have the Remote Registry Service installed.

Using the Network Neighborhood for Administration

The Network Neighborhood tool enables you to view information about other machines on your network, including network servers and other host machines. In the Network Neighborhood folder, you can complete certain administrative tasks for the computers shown.

When you right-click on any computer's icon and select Properties from the Context menu, you are shown the dialog box in Figure 30.8.

FIGURE 30.8 The properties shown in Network Neighborhood for the selected remote computer.

The buttons in this dialog box enable you to take the following actions:

Network Backup Agents

If you use network backup software, such as that provided by Arcada (Backup Exec) or Cheyenne (ARCServe), you can use the backup agents provided with Windows 98 to allow backup of individual workstations. To enable such backups, you first must install the agents on each workstation, which you can do during setup or from the Network icon in the Control Panel. To install the agents from the Control Panel, perform the following steps:

1. Open the Network icon in the Control Panel.

2. Click the Add button in the Configuration tab.

3. In the Select Network Component Type dialog box, click Service in the list box and then the Add button.

4. In the Select Network Service dialog box that appears, click on the manufacturer in the Manufacturers list box (either Arcada or Cheyenne) and the appropriate backup agent in the Network Services list box.

5. Click on the OK button.

6. When the Select Network Service dialog box reappears, click on the SNMP agent in the Models list box.

7. Click on the OK button. Windows 98 copies and installs the appropriate files.

8. Click on OK to close the Network dialog box and update the settings. Windows 98 prompts you to restart the computer.

Each backup agent must be configured to perform the operations you desire. While the Network dialog box is still open, select the Configuration tab and select the backup agent in the list box. Click on the Properties tab to display the property sheet for the agent. For both agents, it is important to set the controls to enable network backup to determine whether the Registry for the computer is backed up and to set an appropriate password. In addition, these property sheets enable you to select the folders that will be backed up and choose from some other agent-specific features.


Previous chapterNext chapterContents

© Copyright, Macmillan Computer Publishing. All rights reserved.