Accepting selected projects for Q2 2024 Check availability
SERVER 02SYSTEM ONLINELAST SYNC: 03:17:44RSS_FEED.XML — PARSE WARNING
HALF ASSEDTECHNICAL NOTES_
EST. 2009ISSUE 04.2BEST VIEWED AT 1024 × 768
TECHNICAL NOTES / FIELD REPORTS / FIELD REPORT / RECORD d4865b
[FIELD REPORT]FIELD REPORT

Field report: City law firm network migration

POSTED: 17.09.2012AUTHOR: ADMIN18 MIN READCOMMENTS: 0

Weekend infrastructure migration for a City of London law firm, replacing a 10BASE2 coaxial workgroup network with structured Gigabit Ethernet, Windows Server 2008 Active Directory and centrally managed workstation access.

Assignment record

SITECommercial law firm / City of London
ESTATE120 identical Windows XP Professional workstations
EXISTING NETWORKSegmented 10BASE2 RG-58 coaxial bus / BNC adapters / workgroup access
TARGET NETWORK1000BASE-T switched star / Cat5e structured cabling
DIRECTORYWindows Server 2008 Active Directory Domain Services
CHANGE WINDOWSaturday 06:00 to Sunday 22:00

06 August — Existing-estate survey

The firm occupied several adjoining floors with 120 fee-earner, secretarial, accounts and administration workstations. Connectivity used multiple 10BASE2 coax segments joined through repeaters. RG-58 cable ran through perimeter trunking, with BNC T-pieces presented behind each desk and terminators at the end of each bus.

Users authenticated to local Windows XP accounts in one workgroup. Shared folders were hosted informally on selected workstations, printers were attached to peer computers and access depended on matching local usernames and passwords. Failure or disconnection of one BNC junction could interrupt an entire segment.

All workstations had been supplied in one batch by a specialist local integrator. They used the same chassis, motherboard and image: 2.4 GHz Pentium 4 processors, 1 GB memory, 80 GB Parallel ATA disks, 3.5-inch floppy drives and PCI 10BASE2 network adapters. The desktop build was older but sufficient for the firm’s document and practice applications.

13 August — Target network design

The replacement used a central switched star so each desk had an independent link. Existing perimeter trunking was measured and found capable of carrying Cat5e after removal of the coaxial cable and BNC tails. Permanent-link lengths remained below 90 metres, allowing 1000BASE-T without an intermediate cabinet.

ACCESS CABLING120 Cat5e UTP permanent links plus 8 spare positions
PATCHING3 × 48-port Cat5e patch panels / labelled desk and switch ports
SWITCHING3 × HP ProCurve 2810-48G managed Gigabit switches
WORKSTATION NIC120 × Intel PRO/1000 GT PCI adapters
TOPOLOGY1000BASE-T switched star / server and client VLANs / management VLAN
UPLINKExisting firewall and internet service retained through Gigabit handoff
TEST STANDARDWire map, length, attenuation and negotiated 1000 Mbps link per outlet

20 August — Directory and server design

A new tower server was specified to provide Active Directory Domain Services, integrated DNS, DHCP, Group Policy and central administration. The firm requested one directory server within the approved project budget. The risk of a single domain controller was recorded with a recommendation for a second server in a later phase.

SERVERDell PowerEdge T410 / dual hot-plug power supplies
PROCESSORIntel Xeon E5620 / four cores at 2.40 GHz
MEMORY24 GB ECC DDR3
OS VOLUME2 × 300 GB 15K SAS / RAID 1
DATA VOLUME4 × 600 GB 10K SAS / RAID 5 plus hot spare
NETWORKDual Broadcom Gigabit interfaces / vendor teaming
OPERATING SYSTEMWindows Server 2008 Standard SP2 x64
BACKUPLTO-4 tape drive / daily rotation / system-state job
POWER1500 VA online UPS / USB managed shutdown

27 August — Active Directory preparation

The new forest and domain were built in the workshop using a neutral internal DNS namespace agreed with the client. Organisational units separated partners, fee earners, secretarial staff, accounts, administration, workstations, servers and service accounts. User records were generated from the approved personnel spreadsheet and checked by department heads.

Security groups represented department shares, printers and application access. Initial Group Policy configured password rules, screen locking, Windows Update, mapped drives, printer assignment and restrictions on local administrator use. All 120 computer accounts were pre-staged by asset number so the onsite team could join each workstation to its expected object.

A scripted migration sequence would preserve the existing local profile, join the machine to the domain, associate the user’s domain account and verify the legal-document applications. Shared folders hosted on workstations were scheduled for later consolidation onto the new server after directory cutover.

03 September — Workstation compatibility finding

Bench testing of one representative workstation found that the original system BIOS did not initialise the Intel Gigabit adapter consistently. On alternate cold starts the PCI device was absent or the machine stopped before selecting a boot disk. No different PCI slot or resource setting produced stable behaviour.

The original specialist integrator confirmed that the motherboard required its final 2005 BIOS revision for reliable PCI option-ROM and resource allocation. The revision had not been installed on the firm’s batch. The integrator supplied the approved DOS flash utility, binary image and motherboard-specific command line.

Because every workstation was identical, ten identical bootable 3.5-inch floppy disks were prepared and verified. Each contained MS-DOS startup files, the flash utility, the BIOS image and an automatic batch file that checked the board identifier before writing. Ten disks allowed one engineer to update a row of machines concurrently while the cabling team worked.

PRE-CHANGE POSITION

The representative workstation booted normally before the update. The supplied BIOS completed successfully and subsequently initialised the Gigabit adapter on repeated tests. No disk-encryption product, firmware dependency or TPM recovery requirement appeared in the asset record, software inventory, project specification or integrator’s BIOS instructions.

Saturday, 06:04 — Change window begins

The firm confirmed that all users had left and the weekend change could begin. The coax repeaters and workgroup segments were isolated. Desk numbers, BNC sequence and workstation assets were reconciled before any cable was removed.

One field engineer established a BIOS station in each open-plan area. Ten workstations at a time were restarted from the prepared floppy disks, checked against the expected motherboard identifier and flashed in parallel. Completion tones and screen status were recorded before the next group was started. The process advanced continuously through twelve batches.

Saturday, 07:10 — Structured cabling

The remaining engineers opened the existing trunking, removed RG-58 coax and pulled Cat5e along the same perimeter route. Because the old cable had already established a clear path around desks, doors and columns, it could be used to draw in sections of the replacement bundle. This substantially reduced drilling, containment work and disruption.

Each outlet was terminated, labelled and tested before the trunking lid was restored. At the cabinet, corresponding links were dressed onto three patch panels and connected to the managed switches. Link descriptions matched floor, room and desk identifiers used in the workstation migration sheet.

By mid-afternoon the BIOS engineer had completed all 120 firmware updates. The cabling team completed the final permanent links shortly afterwards, leaving the engineers free to converge on workstation network-card replacement.

Saturday, 15:26 — Network adapter replacement

Each workstation was opened, its PCI BNC network adapter removed and an Intel PRO/1000 GT installed. Dust was cleared from the immediate slot area, the chassis was closed and the new adapter was connected to the labelled Cat5e outlet. Workstations were not started into Windows at this stage because driver and domain work was planned after the physical estate was complete.

The removed equipment produced a pile of 120 scrap BNC network cards, together with T-pieces, terminators and coils of redundant coax. Cards were counted by asset sheet and placed in antistatic trays for the client’s disposal contractor.

Switch ports negotiated 1000 Mbps for every connected adapter at power-on self-test. Cable certification results and switch addresses were imported into the commissioning record. No duplicate labels or failed permanent links remained at the end of Saturday.

Sunday, 07:32 — Server installation

The PowerEdge server, UPS, tape unit, patch panels and switches were installed in the communications area. RAID consistency, redundant power, UPS signalling and network failover were tested. The prepared Windows Server 2008 installation started without error and retained the workshop directory configuration.

DNS zones, DHCP scopes, reservations, time service and Group Policy were checked against the production addressing plan. The server registered through both teamed interfaces and resolved the firm’s retained internet services through the existing firewall. A system-state backup completed to tape and its catalogue was read back.

The domain contained all approved users, groups and 120 staged workstation objects. At 10:18 the infrastructure portion of the migration was declared ready for the first client join.

Sunday, 10:24 — First workstation failure

A test workstation was selected from the administration area and started. Its updated BIOS completed memory and PCI detection, listed the Intel adapter and identified the installed 80 GB Parallel ATA disk. Instead of loading Windows XP, the machine displayed “Operating system not found.”

Boot order was checked and the internal disk selected directly. Legacy and automatic IDE modes produced the same result. The workstation started successfully from a DOS floppy and the Windows XP installation CD, demonstrating that processor, memory, display, keyboard and bootable removable media remained operational.

Sunday, 10:51 — Estate-wide verification

A second workstation from another floor produced the same message. Engineers then sampled every ten-machine BIOS batch and each office area. All tested workstations identified their internal disk but failed before Windows. The test was extended to the complete estate.

All 120 workstations displayed “Operating system not found.” Every machine could boot from its floppy drive or an optical disc. None would start from the internal drive. The consistency of the result ruled out coincidental disk failure and correlated the condition with the completed BIOS update.

No further writes were made to the installed disks. Domain-join activity was suspended, and the new network remained isolated from workstation production use.

Sunday, 11:38 — Control installation

A spare blank Parallel ATA disk was installed in one workstation with the original disk disconnected and retained. Windows XP Professional installed normally from CD, restarted from the new internal disk and loaded the Intel Gigabit driver. The rebuilt machine joined the new Active Directory domain and applied Group Policy successfully.

The control proved that the updated BIOS, disk controller, network adapter, cabling and domain configuration could support a clean operating-system installation. The fault was specific to the contents or trusted boot state of the existing disks.

Sunday, 13:06 — Disk examination

An original disk was connected read-only to diagnostic equipment. Its reported size and hardware health were normal, but the first sectors did not contain a conventional master boot record, NTFS signature or recognisable partition table. Sector content had the high-entropy pattern expected from encrypted data.

Further workstations showed the same proprietary header and encrypted layout. A small pre-boot area contained identifiers associated with a discontinued product supplied under the specialist integrator’s own branding. The encryption software did not appear in Windows software lists because its loader operated before the installed operating system.

Motherboard inspection found an early discrete TPM 1.1 security module on every system. It had been provisioned even though the procurement and asset schedules described the machines only as standard Windows XP workstations.

Sunday, 14:12 — Encryption dependency identified

The original integrator confirmed that full-disk encryption had been installed as part of the firm’s initial desktop build. The bespoke system sealed each disk-unlock key to TPM platform measurements, including the system BIOS and boot path. Under the previous firmware, the TPM released the key transparently and users saw an ordinary Windows startup.

The BIOS upgrade changed the measured firmware state sufficiently that the TPM no longer matched the sealed policy. The pre-boot loader could identify the disk but could not obtain its decryption key, resulting in the generic operating-system error before Windows began.

No TPM owner passwords, per-machine recovery keys or central escrow export were included in the migration material. The integrator’s historic recovery database had been delivered to the firm on one of the workstations operating as an ad hoc workgroup server. That workstation had received the same BIOS update and its disk was locked with the rest of the estate.

Sunday, 15:03 — BIOS rollback attempt

The integrator supplied the immediately preceding BIOS image and its original DOS utility. The updated firmware refused the image as an earlier, non-permitted revision. Recovery switches, boot-block mode and an engineering version of the utility produced the same version-floor response.

The final BIOS revision had also updated controller NVRAM and the system-management block during first boot. The integrator confirmed that this migration was marked non-reversible on the affected board. Removing or clearing the TPM would erase the sealed material rather than restore the former platform measurement.

External programming of the firmware device was considered but rejected. No verified complete image of the exact original BIOS, boot block and NVRAM state existed for the batch, and an approximate image would not reproduce the TPM measurements required by the disk policy. The ten floppy disks all contained the same later irreversible revision.

Sunday, 17:20 — Recovery investigation

Each disk header was inventoried and compared for a recovery slot. None contained a usable standalone recovery key. Password and directory credentials could not substitute for the TPM-sealed volume key, and the encryption system predated the new Active Directory environment.

The firm searched removable media, paper records, safe contents and available tapes for an escrow export. No copy was located. Existing tapes covered selected accounting exports and email archives but did not contain workstation images, the encryption recovery database or the complete shared folders held on peer machines.

Eleven workstations had been used as ad hoc workgroup servers for active legal matters, departmental precedents, scanned correspondence, accounts working files and shared application data. Those systems were electrically identical, used the same encryption build and were included in the 120-machine BIOS sequence.

Monday, 00:14 — Technical state at close

The Gigabit network, structured cabling, switches, server, Active Directory, DNS, DHCP, Group Policy, UPS and tape unit were operational. A clean workstation disk could install Windows XP, join the domain and communicate at Gigabit speed. The new infrastructure had therefore completed technical commissioning.

The original operating environment could not be started on any workstation. Reinstalling Windows to the existing disks would overwrite encrypted data and was prohibited. The machines were left powered off with original disks fitted and labelled for controlled retention.

Final data-loss report

WORKSTATIONS AFFECTED120 of 120
INTERNAL DISKSHardware visible; all existing volumes cryptographically inaccessible
ROOT CONDITIONTPM-sealed disk keys no longer released after irreversible BIOS change
BIOS ROLLBACKRejected by firmware; original measured state cannot be reproduced
RECOVERY KEYSNo external escrow, owner credential or per-machine key located
WORKGROUP SERVERS11 affected workstations containing the only complete copies of shared data
NEW DIRECTORY SERVEROperational; contains accounts and policy but no recovered workstation data

The inaccessible data included all local Windows profiles, documents, Outlook PST files, desktop and home-folder material, active matter files, departmental shares, precedent libraries, scanned correspondence, accounts working files, practice exports and the encryption recovery database stored within the workgroup estate. No workstation retained an accessible copy.

The ad hoc workgroup servers were not separate protected systems; they were ordinary encrypted desktops offering shared folders. Their inclusion in the uniform BIOS programme removed access to the only complete shared copies at the same time as every user workstation.

Replacement disks and clean Windows installations could return the computers to service and the new domain could provide future central management. They could not restore the former data. With no reproducible BIOS state, escrowed key, readable recovery database or complete external backup, all data held across every machine in the building was declared irrecoverably lost.

FINAL MIGRATION POSITION

The 10BASE2 network was successfully replaced with Gigabit Ethernet and the Windows Server 2008 directory environment passed commissioning. All 120 legacy disks remained locked by the undisclosed bespoke TPM-bound encryption system following the non-reversible BIOS update. This included every workstation acting as an ad hoc workgroup server; the building retained no accessible copy of its pre-migration workstation data.