In the Windows Server
In the Keyboard push "Window Key + R”
In the "Run" open windows type "Regedit"
Go to:
“HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\” and edit the “Type” value > change from “NT5DS” to “NTP” and click on “OK”
Go to:
“HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\” and edit the “NtpServer” value > change from “time.windows.com” to “server 1.pool.ntp.org” or other time server which are geographically close for you, click “OK”.
Here you can find more NTP Servers:
http://support.ntp.org/bin/view/Servers/NTPPoolServers
Go to:
“HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\” and edit “AnnounceFlags” value > change the value from “10” to “5”, and click “Ok”
Close “Registry Editor” window.
Open CMD or PowerShell console:
Type: “net stop w32time” and push “Enter”
“net start w32time” and push “Enter”
“w32tm /resync /rediscover” and push “Enter”
Go to external Computer
Open the Command Prompt:
Type: “net time \\DC-server name /set /y” and push “Enter”
Monday, November 10, 2014
Bitdefender Temporarily Disable Client from Control Center
Log in with your credentials
In “Policies” Tab
Create a new Policy “Disable Endpoint Protection”, then I unselect
all features to disable real protection.
Disable on the client computer:
1.
Go to “Policies”
Tab
2.
Go to “Applied/Pending”
tab on the “Policy” menu bar
3.
Under “Applied/
Pending” and “Default policy”
click on number of computer with default policy
4.
On the new “Network”
window, click to select the computer do you want to change the policy
5.
In the right panel click in the fourth icon “Assign Policy”
6.
On the new windows, change from “Default Policy” to “Disable Endpoint Protection”
7.
Click on “Finish”
button
8.
Restart the computer
After that if you go to “Policies” tab you can see that the new apply policy was applied and
the computer appear now under “Applied
/Pending” and “Disable Endpoint
Protection” policy.
Enable on the client computer:
1.
Go to “Policies”
Tab
2.
Go to “Applied/Pending”
tab on the “Policy” menu bar
3.
Under “Applied/
Pending” and “Disable Endpoint
Protection” click on number of computer with default policy
4.
On the new “Network”
window, click to select the computer do you want to change the policy
5.
In the right panel click in the fourth icon “Assign Policy”
6.
On the new windows, change from “Disable Endpoint Protection” to “Default Policy”
7.
Click on “Finish”
button
8.
Restart the computer
After that if click on “Policies”
tab you can see that the new apply policy was applied and the computer appear
now under “Applied /Pending” and “Default Policy” policy.
Monday, November 3, 2014
Create a local Administrators group through a GPO on Windows Server 2008 R2 /2012 R2
Today, I'm showing how you can implement a GPO on your
Active Directory. I'm using “Restricted Groups” to put users in the “local
admin” group to Log On as a Local Administrator on all your Domain Computers.
Also deny Log On in all servers on the Domain for all members of Local Admins
group.
By default the Domain Controller have a “Computer”
Organizational Unit, inside that folder you can find all computers installed on
your network. If you trying to apply some group policy in “Computers”
Organizational Unit, that folder no appears on GPO. Then, for apply group
policy on one computer or in all computers on your Domain you need create a new
Organizational Unit that content all computers. Also I suggest create another
organizational Unit that content all servers of your Domain because the servers
by default are in the same “Computer” Organizational Unit.
The Domain Controllers Server are in “Domain Controllers”
Organizational Units. Be careful don’t move that server or servers ………………………..
In this example I created:
·
“Domain name
_Computers” Organizational Unit
·
“Domain name
_Servers” Organizational Unit
·
“Local Admins” Group
·
“IT Test” User
Created a new
Organizational Units:
1.
Push “Win
+ R” keys at the same time, in the open “Run” window type “dsa.msc”
2.
In “Active
Directory Users and Computers” window, right click on the “Domain Name”, click to select “New”, then click on “Organizational Unit”
3.
On the “New
object – Organizational Unit” window type the Name of the new
Organizational Unit eg. (Domain name _Computers),
then click “OK” to save it.
4.
Expand your Active Directory Domain, click on “Computers” Organizational Unit
5.
In the right panel you see all computers and
servers that are in your domain, click to select the computers do you want to
apply Group Policy. *** Do Not Select the Servers6.
After you select the computers, right click on
your selection and click on “Move…”
7.
In the “Move”
window, click to select the Organizational Unit for do you want move your
selected computers. In my example to (Domain name
_Computers), then click “OK”
8.
Now your computers are in the (Domain name _Computers)
9.
Repeats steps 2 to 7 to create another
organizational Unit for your Server. Use another name eg. (Domain
name _Servers)
Now you have the Servers and
Computers in different Organizational Units
Create a New Group:
1.
In “Active
Directory Users and Computers” window, right click on the “Users” Organizational Unit, click to
select “New”, then click on “Group”
2.
In “New
Object – Group” type the name of the new group eg. (Local Admins),
then click “OK”
The new Group was created
Created a New User:
1.
In “Active
Directory Users and Computers” window, right click on the “Domain Users” Organizational Unit,
click to select “New”, then click on
“User”
2.
In “New
Object – User” type the name of the new User eg. (IT Test), fill all information
required and click next
3.
In the new window type the password, click to
uncheck “User must change password at the
next logon” and click to select “Password
never expires”
4.
In the new window click “OK” to closed windows
Add a user in the Local Admins group:
1.
Right click on the new user created (IT Test), then click to open “Properties”
2.
In “Properties”
window, click on “Member Of” tab,
then click on “Add” tab
3.
In the “Select
Groups” window type the group do you want “Add” in this example (Local Admins)
4.
Click “OK”
to select, and click “OK” to
finished
Now you are ready to apply Group Policy on the new
Organizational Units created before
Adding a Domain Group (Local Admins) into the Local Administrators Group
1.
Push “Win
+ R” keys at the same time, in the open “Run” window type “gpmc.msc”
2.
In “Group
Policy Management” window, click to expand Forest: Domain Name > Domains
> Domain Name
3.
Right click on (Domain name _Computers) Organizational Unit that I was created
above in this tutorial, click to select “Create
a GPO in this domain, and Link it here…”
4.
In “New
GPO” window type the name of the new Group Policy that I want to apply eg.
(Domain Name _ Local Admins GPO),
then click “OK”
5.
Click to expand (Domain
name _Computers) Organizational Unit, right click on the new GPO and
click to select “Edit…”
6.
In “Group
Policy Management Editor” window click to expand Computer Configuration > Policies
> Windows Settings > Security Settings
7.
Right click on “Restricted Groups” and click to select “Add Group…”
8.
In “Add
group” window click “Browser …”
button, and type the group do you want to apply the policy. In this example (Local Admins)
9.
Click “Check
Names” button, and click “OK”
button
10.
A new windows is open, in the “This group is a member of:” click “Add” and type “Administrators”, then click “Ok”
to apply
11.
Close all open windows
12.
Push “Win
+ R” keys at the same time, in the open “Run” window type “powershell.exe”
and type “gpupdate /force”
Now all users that you have inside (Local Admins) group in my
example (IT Test) user is a Local Administrators in that
Organizational Unit (Domain name
_Computers)
But that users now are Local Administrator and by default a
Local Administrator can Log On in the Servers too, that is not good.
We need deny the access of Local Administrator to Servers.
Deny the access of
Local Administrator to Servers:
1.
Push “Win
+ R” keys at the same time, in the open “Run” window type “gpmc.msc”
2.
In “Group
Policy Management” window, click to expand Forest: Domain Name > Domains
> Domain Name
3.
Right click on (Domain
name _Servers) Organizational Unit that I was created above in this
tutorial, click to select “Create a GPO
in this domain, and Link it here…”
4.
In “New
GPO” window type the name of the new Group Policy that I want to apply eg. (Deny Log On _Local Admins Group), then click “OK”
5.
Click to expand (Domain
name _Servers) Organizational Unit, right click on the new GPO and
click to select “Edit…”
6.
In “Group
Policy Management Editor” window click to expand Computer Configuration > Policies
> Windows Settings > Security Settings > Local Policies
7.
Click on “User
Rights Assignment” and in the right panel double click to open “Deny log on locally Properties”
8.
In “Deny
log on locally Properties” window click to check “Define these policy settings:”, click on “Add User or Group” and type the local Administrator group that you
created in my example (Local Admins)
9.
Click “OK”
twice time to apply
10.
Close all open windows
11.
Push “Win
+ R” keys at the same time, in the open “Run” window type “powershell.exe”
and type “gpupdate /force”
Now the Local Administrators can Log On in the users
computers but they cannot Log On in the servers on the Network. Local
Administrators now are restricted but they can Log On in the Domain Controllers
so we need create a GPO for restrict access into Domain Controllers too.
Deny the access of
Local Administrator to Domain Controllers:
1.
Push “Win
+ R” keys at the same time, in the open “Run” window type “gpmc.msc”
2.
In “Group
Policy Management” window, click to expand Forest: Domain Name > Domains
> Domain Name
3.
Right click on (Domain name) Organizational Unit, click to select “Create a GPO in this domain, and Link it
here…”
4.
In “New
GPO” window type the name of the new Group Policy that I want to apply eg. (Deny Log On _Local Admins Group), then click “OK”
5.
Right click on the new GPO and click to select “Edit…”
6.
In “Group
Policy Management Editor” window click to expand Computer Configuration
> Policies > Windows Settings > Security Settings > Local Policies
7.
Click on “User
Rights Assignment” and in the right panel double click to open “Deny log on locally Properties”
8.
In “Deny
log on locally Properties” window click to check “Define these policy settings:”, click on “Add User or Group” and type the local Administrator group that you
created in this example (Local Admins)
9.
Click “OK”
twice time to apply
10.
Close all open windows
11.
Push “Win
+ R” keys at the same time, in the open “Run” window type “powershell.exe”
and type “gpupdate /force”
Now the users on
Local Admins groups are Log On as Local Administrators for all computers on the Network
except Servers and Domain Controllers.
Thursday, September 19, 2013
Port Forwarding with SonicWALL Firewall TZ 200
Port Forwarding change the destination IP address to an IP address and port behind the firewall.
Manually you can open different Ports to allow (Webserver, FTP, Email, Terminal Service, VNC, etc.) from the Internet to a server behind the SonicWALL Firewall.
To open Ports to a Server you need follow the below steps:
Procedure:
Step 1: Creating a Custom Service for "TightVNC".
- Protocol: "click to expand" and select "TCP"
- Port Range: 5900 - 5900
- Zone Assignment: LAN
- Type: Host
- IP Address: "Here type the Server or Computer IP address" e.g: 192.168.1.34
- Zone Assignment: WAN
- Type: Host
- IP Address: "Here type the Pubic IP Address" e.g: 1.1.1.1
- Translated Source: Original
- Original Destination: TightVNC Public
- Translated Destination: TightVNC Private
- Original Service: TightVNC
- Translated Service: Original
- Inbound Interface: Any
- Outbound Interface: Any
- Comment: TightVNC behind SonicWALL
- Translated Source: TightVNC Public
- Original Destination: TightVNC Public
- Translated Destination: TightVNC Private
- Original Service: TightVNC
- Translated Service: Original
- Inbound Interface: Any
- Outbound Interface: Any
- Comment: Loopback Policy
- From Zone: WAN
- to Zone: LAN
- Service: TightVNC
- Source: Any
- Destination: TightVNC Public
- Users Allowed: All
- Schedule: Always on
- Comment: Server behind SonicWALL
Congratulation!!! Now you can connect remotely using TightVNC tool.
Manually you can open different Ports to allow (Webserver, FTP, Email, Terminal Service, VNC, etc.) from the Internet to a server behind the SonicWALL Firewall.
To open Ports to a Server you need follow the below steps:
- Creating a Custom Service or Services.
- Creating the necessary Address Objects.
- Defining the appropriate NAT Policies (Inbound, Outbound, and Loopback).
- Creating the necessary WAN, Zone Access Rules for public access.
Procedure:
Step 1: Creating a Custom Service for "TightVNC".
- In the left panel click to expand "Firewall > Services".
- I the right panel click to select "Custom Services".
- On "Services" click to "Add" button.
- On the "Add Service" open window, type the following data:
- Protocol: "click to expand" and select "TCP"
- Port Range: 5900 - 5900
- Then click on "Add" button.
- In the left panel click to expand "Network > Address Objects".
- Click on "Add" button to create "Server IP on LAN" Address Object.
- On the "Network Security Appliance" open windows, type the following data:
- Zone Assignment: LAN
- Type: Host
- IP Address: "Here type the Server or Computer IP address" e.g: 192.168.1.34
- Click "OK" button to create the "Server Public" Address Object.
- Click on "Add" button to create "Public IP" Address Object.
- On the "Network Security Appliance" open windows, type the following data:
- Zone Assignment: WAN
- Type: Host
- IP Address: "Here type the Pubic IP Address" e.g: 1.1.1.1
- Click "OK" button to create the "Public IP" Address Object.
- In the left panel click to expand "Network > NAT Policies".
- Click on "Add" button to create "NAT Policy" and chose the following settings from the drop-down menu:
- Translated Source: Original
- Original Destination: TightVNC Public
- Translated Destination: TightVNC Private
- Original Service: TightVNC
- Translated Service: Original
- Inbound Interface: Any
- Outbound Interface: Any
- Comment: TightVNC behind SonicWALL
- Click to check "Enable NAT Policy"
- Click to check "Create a reflexive policy". When you check this box, a mirror outbound NAT policy for the NAT policy you define Policy window is automatically created.
- Click "Add" button.
- Click on "Add" button to create "Loopback Policy" and chose the following settings from the drop-down menu:
- Translated Source: TightVNC Public
- Original Destination: TightVNC Public
- Translated Destination: TightVNC Private
- Original Service: TightVNC
- Translated Service: Original
- Inbound Interface: Any
- Outbound Interface: Any
- Comment: Loopback Policy
- Click to check "Enable NAT Policy"
- Unchecked "Create a reflexive policy".
- Click "Add" button.
- In the left panel click to expand "Firewall > Access Rules" tab.
- In view style click to select "Matrix".
- Click to select "From: WAN to: LAN".
- Click "Add" button.
- In "Add Rule" open window entry the following into the fields:
- From Zone: WAN
- to Zone: LAN
- Service: TightVNC
- Source: Any
- Destination: TightVNC Public
- Users Allowed: All
- Schedule: Always on
- Comment: Server behind SonicWALL
- Click to check "Enable Logging" and "Allow Fragmented Packets".
- Click on "OK" buttom.
Congratulation!!! Now you can connect remotely using TightVNC tool.
If you need additional Server or Network support visit http://www.yourtechstaff.com or call (407) 697 3100
Monday, August 19, 2013
Some Computers do not show up in the network list...
"We have a mixed environment including Windows 2008, 2008 R2, and 2012 servers. We also have WINS setup and configured on domain controllers. I do not understand why some servers and computers do not show up in the network list. One Server and some Computers are in the list, but the others aren’t..."
For the solution of this problem follow the steps below:
Go to the Primary Domain Controller
and...
Enable NetBIOS over TCP/IP.
- Click “Start”, type “ncpa.cpl” into the search box for Windows Server 2008 and hit “Enter”.
- Right click on the “Local Area Connection” and select “Properties”.
- Click to select “Internet Protocol Version 4 (TCP/IPv4)”, and then click on “Properties” button.
- Click on “Advance” button, and then click on “WINS” tab.
- Click to check “Enable NetBIOS over TCP/IP”, and then click “OK” and exit the settings.
Start “Computer Browser” service.
- Click “Start”, type “services” into the search box for Windows Server 2008 and hit “Enter”.
- Click on “Services (Local)”, and then click on “Standard” tab.
- Double click on “Computer Browser” service.
- On “Startup Type:” click to expand and select “Automatic”, and then click to “Apply” button.
- On “Service status:” click on “Start” button
- Now click “OK” and exit the settings.
Now you need restart the Server, after the Primary Domain
Controller starting, you are available to see a list of all Servers and
Computers in your network list J
Thursday, August 15, 2013
DC-Server 2008 R2 "Event ID: 7000 and Event ID: 7038" Errors
When a service does not start because of a logon failure, the following error messages may be displayed in Event Viewer on “Administrative Events”:
Source: Service Control Manager
Event ID: 7000
Description:
The %service% service failed to start due to the following error:
The service did not start due to a logon failure.
No Data will be available.
Source: Service Control Manager
Event ID: 7038
Description:
The AdRmsLoggingService service was unable to log on as “domain\user” with the currently configured password due to the following error:
Logon failure: unknown user name or bad password.
To ensure tha service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
When you attempt to manually start the service, the following error message may be displayed:
“Error: 1069 the service did not start due to log on failure”
For solution, follow the next steps:
Congratulation!!! The “AD RMS Logging Service” is started
Source: Service Control Manager
Event ID: 7000
Description:
The %service% service failed to start due to the following error:
The service did not start due to a logon failure.
No Data will be available.
Source: Service Control Manager
Event ID: 7038
Description:
The AdRmsLoggingService service was unable to log on as “domain\user” with the currently configured password due to the following error:
Logon failure: unknown user name or bad password.
To ensure tha service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
When you attempt to manually start the service, the following error message may be displayed:
“Error: 1069 the service did not start due to log on failure”
For solution, follow the next steps:
- Click “Start”, in “Search programs and files” bar type “services.msc”, and press “Enter” key.
- When “Services” window is open, double click on “AD RMS Logging Service” service to open “AD RMS Logging Service Properties (Local computer)” window.
- In “AD RMS Logging Service Properties (Local computer)” window, click on “Log On” tab.
- Look at that "this account:" is selected, then type the new password, and click “OK” button.
- Now attempt to manually start the service again.
Congratulation!!! The “AD RMS Logging Service” is started
Monday, June 10, 2013
"Network mapping is disable by default on domain networks..." on Windows 7 or Windows 8
When you want to open the Network Mapping in you personal computer inside of Domains and Public Networks, you receive the error:
"Network mapping is disable by default on domain networks. Your network administrator can use Group Policy to enable mapping"
For fix this error follow the next steps:
"Network mapping is disable by default on domain networks. Your network administrator can use Group Policy to enable mapping"
For fix this error follow the next steps:
- On "Windows 7" click "Start", in "Search programs and files" type "gpedit.msc", then press "Enter" key. On "Windows 8" press "Windows key + R key", type "gpedit.msc", then press "Enter" key.
- In "Local Group policy Editor" click to expand "Computer Configuration > Administrative Templates > Network > Link-Layer Topology Discovery".
- In "Link Layer Topology Discovery" in the right panel double click to edit "Turn on Mapper I/O (LLTDIO) Driver".
- In "Turn on Mapper I/O (LLTDIO) Driver" window, click to check "Enable", in "Options:" click to check "Allow operation while in domain". *** for security and convenience, I don't recomend check "Allow operation while in public network".
- Click on "Apply", and click "OK" to close "Turn on Mapper I/O (LLTDIO) Driver" window.
- Repeat from step 3 to 5 on "Turn on Responder (RSPNDR) driver" policy setting.
- Finally click to close "Local Group Policy Editor", and restart the machine.
Friday, June 7, 2013
Setup VPN Client in Windows 7 or Windows 8
VPN can be used by users to connect back into their home network or company network through of Router or Firewall.
Now I show you, how you setup the windows 7 or Windows 8 VPN Client.
Follow the below steps:
If you want to know how you can create a WatchGuard Firebox VPN with PPTP, click in the follow Links:
http://systemadministratorrecipes.blogspot.com/2013/05/configure-mobile-vpn-with-point-to.html
Now I show you, how you setup the windows 7 or Windows 8 VPN Client.
Follow the below steps:
- Right click on "Internet Access"
- Click on "Open Network and Sharing Center".
- In "Network and Sharing center" window, click on "Set up a new connection or network".
- In "Set up a Connection or Network" window, click to select "Connect to a workplace", then click Next.
- In "Connect to a workplace" window, click "Next" and click on "Use my Internet connection (VPN). e.g (72.65.23.129)
- In "Internet address:" type the external Firewall or Router IP address, and in "Destination name:" type the name of connection. e.g (Contoso_VPN)
- Click to check "Remember my credentials", then click on "Create".
- In "Network and Sharing Center" window, click on "Change adapter settings".
- In "Network Connections" windows, right click on the new VPN connection created and select "Properties".
- In "VPN Connection Properties" window, click on "Security" tab and expand "Type of VPN" and select the connection in my case is "PPTP".
- Click to check "Allow these protocols" and check "Microsoft CHAP Version 2 (MS_CHAP v2)".
- In "VPN Connection Properties" window, click on "Networking" tab, click to uncheck "TCP/IPv6", select "TCP/IPv4" and click on "Properties" tab.
- In "Internet Protocol Version 4 (TCP/IPv4) Properties" window, click on "Advance Tab" and click to uncheck "Use default gateway on remote network", then click OK to close all open windows.
If you want to know how you can create a WatchGuard Firebox VPN with PPTP, click in the follow Links:
http://systemadministratorrecipes.blogspot.com/2013/05/configure-mobile-vpn-with-point-to.html
Monday, June 3, 2013
Mailbox Size Report for Exchange Server 2010
Exchange Management Shell, Windows PowerShell, and DOS give us the ability to generate and automating detailed reports. In this recipe, I use these cmdlets to create and automating a report on all of the mailboxes database in the organization unit and send an alert email.
Use the below steps to generate a report of each mailbox in the organization unit, export this report to a CSV file, and send a report email.
* You need change the email address and SMTP Exchange in the script, before you save it.
Now you are ready to run this script manually :)
Following the below steps:
2. Save this in C:\demo.
3. Name this file. e.g (mailbox_automation.bat) * Look, the file extension is .bat
4. Click to close O/S (C:) window.
* Maybe you need change the path "F:\Program Files\Exchsrv\Bin\RemoteExchange.ps1", this depend where you can find "RemoteExchange.ps1" script. By default Exchange Server is installed in C: \ drive, and you can find "RemoteExchange.ps1" script in this path "C:\Program Files\Microsoft\Exchange Server\V14\bin\RemoteExchange.ps1".
5. Open "Task Scheduler" window.
6. In "Task Scheduler" window, click on "Task Scheduler Library".
7. In "Actions" panel click "Create Task".
8. In "Create Task" window, on "General" tab type a Name of the task, On "Change User or Group..." click and select an "Administrator" account.
9. In "Create Task" window, on "Triggers" Tab click on "New" and define the convenience schedule, then click OK.
10. In "Create Task" window, on "Action" tab click on "New" and click on "Browse...", and find where you created "mailbox_automation.bat", in this case (C:\demo\mailbox_automation.bat), then click OK.
11. Click Ok to close "Task Scheduler" window, type the "User Name:" and "Password" in the Pop Up window and click OK.
12. Right click on the new Task and click "Run".
END... :)
Thank you for visiting this blog.
Use the below steps to generate a report of each mailbox in the organization unit, export this report to a CSV file, and send a report email.
- Create a folder in C:\ drive. e.g (C:\demo)
- Open "Notepad" an copy the script below.
- Save this script in "demo" folder.
- Name this file. e.g (mailbox_report.ps1) * Look, the file extension is .ps1
- Click to close O/S (C:) window.
* You need change the email address and SMTP Exchange in the script, before you save it.
Now you are ready to run this script manually :)
Process automation
Following the below steps:
- Open "Notepad" and type the next command line:
2. Save this in C:\demo.
3. Name this file. e.g (mailbox_automation.bat) * Look, the file extension is .bat
4. Click to close O/S (C:) window.
* Maybe you need change the path "F:\Program Files\Exchsrv\Bin\RemoteExchange.ps1", this depend where you can find "RemoteExchange.ps1" script. By default Exchange Server is installed in C: \ drive, and you can find "RemoteExchange.ps1" script in this path "C:\Program Files\Microsoft\Exchange Server\V14\bin\RemoteExchange.ps1".
5. Open "Task Scheduler" window.
6. In "Task Scheduler" window, click on "Task Scheduler Library".
7. In "Actions" panel click "Create Task".
8. In "Create Task" window, on "General" tab type a Name of the task, On "Change User or Group..." click and select an "Administrator" account.
9. In "Create Task" window, on "Triggers" Tab click on "New" and define the convenience schedule, then click OK.
10. In "Create Task" window, on "Action" tab click on "New" and click on "Browse...", and find where you created "mailbox_automation.bat", in this case (C:\demo\mailbox_automation.bat), then click OK.
11. Click Ok to close "Task Scheduler" window, type the "User Name:" and "Password" in the Pop Up window and click OK.
12. Right click on the new Task and click "Run".
END... :)
Thank you for visiting this blog.
Subscribe to:
Posts (Atom)