Monday, April 8, 2013

Free Training for SmarterMail and SmarterTrack

SmarterTools offers FREE weekly training for new and existing customers that covers tasks such as installing products, first-time set up of products, complete walkthroughs of the concepts and ideas behind how a product works and more. SmarterTools offers separate training for both SmarterMail and SmarterTrack that benefit customers who install their own versions of these products or who use the hosted version of SmarterTrack.com.

SmarterMail Training

This training will cover the basic installation and configuration of your new mail server. Items covered include:

  • General system requirements and installation
  • Initial set-up and configuration
  • Adding a domain, then users to that domain
  • Sending and receiving an email
  • Anti-spam and anti-virus options
  • General feature discussion
  • Overview of licensed add-ons

SmarterTrack Training

This training will help with how SmarterTrack can be installed, configured and how communication flows through it. Items covered include:

  • General system requirements and installation
  • Initial set-up and configuration
  • General helpdesk concepts
  • Setting up a Department, Group and Employee
  • Adding Employees to Groups
  • Following a Ticket through SmarterTrack
  • General feature discussion
For training schedules and more information, visit the SmarterTraining web page (http://www.smartertools.com/support/smartertools-training.aspx).

Wednesday, January 9, 2013

SQL Server 2012 : Edition and Licensing Information

Microsoft’s new SQL Server 2012 release, code-named Denali, marks some significant changes in the SQL Server product lineup. Taking steps to simplify the platform's licensing options, Microsoft has retired the Datacenter Edition, Workgroup Edition and Small Business Edition previously available for SQL Server 2008 and 2008 R2.

SQL Server 2012 Express Edition
replaces the Microsoft Data Engine (MSDE) as the free version of SQL Server for application development and lightweight use. It’s a great tool for developing and testing applications and extremely small implementations, but that’s about as far as you can run with it.

SQL Server 2012 Web Edition
is a specialized version for use in web hosting environments that is nearly identical to Standard Edition. This edition is available only to Services Provider License Agreement customers, which means your hosting provider.

• 
SQL Server 2012 Standard Edition
remains the workhorse of the product line for serious database applications. It can handle up to 16 cores with an unlimited amount of RAM.

• 
SQL Server 2012 Business Intelligence Edition
is designed specifically to support business intelligence applications.

• 
SQL Server 2012 Enterprise Edition
is designed for mission critical data center operations and large data warehouses.

• 
SQL Server 2012 Developer Edition
is a great tool for developers needing the full features of SQL Server 2012 Enterprise Edition for use in a non-production environment. This product has the same functionality as Enterprise Edition and offers a direct upgrade path to convert Developer servers to production licensing.

Having trouble choosing an edition? The Microsoft article "Features Supported by the Editions of SQL Server 2012" offers a detailed look at each edition.

SQL Server 2012 Licensing


Now that you have a SQL version in mind, it’s time to talk pricing. There's no question that licensing is one of the trickiest aspects of any Microsoft product to figure out — it's often harder to understand the licensing than it is to figure out how to use the product and its features. Changes in editions, the new core-based licensing, and the different availability options that are brought about by new features have made SQL Server 2012 licensing more confusing than ever. Let's take a closer look:
  • SQL Server 2012 Standard
    can be licensed either per core or per server and Client Access License (CAL).
  • SQL Server 2012 Business
    is licensed only per server and CAL.
  • SQL Server 2012 Enterprise
    is licensed only per core.

In a virtual environment, each "virtual processor" or "logical processor" counts as one (1) core. For example, if you have a virtual server with four (4) processors, you will need a four (4) core license for your SQL version. SQL Server 2012's licensing requires that you purchase a minimum of four (4) core licenses with additional core licenses available in packs of two (2). This means you will pay for a four (4) core license even if you have a single, dual or tri-core virtual processor VM.


In a fully dedicated environment the structure is much the same. For example, if you have a single quad (4) core processor, you will need a four (4) core license or one (1) server + CALs license. With today’s 12- core+ processors, Microsoft knew you were getting a good deal with socket-based licensing on late SQL versions.

If you’re planning to use the standard edition of Microsoft SQL Server 2012 in your environment, you have a major choice to make: should you opt for the per server licensing or the per core licensing? Be sure to count your cores. Depending on the environment (dedicated or virtual) it may make sense to license by server and CALs rather than core-based licensing.

Microsoft SQL Server 2012 Core Factor Table*
Processor TypeCore Factor
All processors not mentioned below1
AMD Processors
(31XX, 32XX, 41XX, 42XX, 61XX, 62XX Series Processors with 6 or more cores)
0.75
Single-Core Processors4
Dual-Core Processors2

* This is an example of how to calculate core license requirements and the core factor table. The core factor table is subject to change. You can find the core factor table at any time, updated at the link below.

For more information on the SQL Server 2012 Core Factor Table, including how to determine and use the appropriate core factor when licensing SQL Server 2012 under the Per Core model, visit: http://go.microsoft.com/fwlink/?LinkID=229882

Licensing SQL Server for High Availability


One of the most compelling features in the upcoming SQL Server 2012 release is the new AlwaysOn Availability Groups, but Microsoft's use of the term AlwaysOn is a bit confusing. AlwaysOn actually refers to two separate but related technologies: AlwaysOn Failover Clustering and AlwaysOn Availability Groups. AlwaysOn Failover Clustering is essentially the same thing as SQL Server failover clustering in earlier releases. It entails running a SQL Server instance on a Windows failover cluster. However, the AlwaysOn Availability Groups feature is completely new to SQL Server 2012, and it brings several new availability enhancements to SQL Server. If you're using database mirroring, AlwaysOn Availability Groups could be a good reason to upgrade to SQL Server 2012.

What if I have a failover cluster that includes a dedicated backup server? Do I need to license this server as well? No, both Failover Clustering and AlwaysOn Availability Groups allow you to skip licensing the backup server if it is truly passive (i.e., only used when the primary system isn't active).

What about Enterprise solutions where SQL needs high-availability in a fault-tolerant dual hardware solution? Using redundant hardware, will you be required to double the licensing costs? No, fortunately not. This is where Microsoft observes some sympathy and considers these multi-hardware solutions as a single system, thus no additional SQL license costs. The catch is, Microsoft only requires you to license the "active" system. In the event of a failover, switching the licensing to "active" on the receiving server will suffice.

For more information about licensing SQL Server 2012, including what is new with this version, please visit Microsoft's SQL Server website.

Monday, July 30, 2012

Need for Speed: Why Page Load Times Are Important

We all know how frustrating it is when we have to wait even a second for a page to load. Consider your own surfing behavior: if a site is too slow, it's not long before you are back on the search results page choosing another link.

We don’t have much patience, if any at all, when it comes to waiting for a page to load. In fact, users want a site to load in a matter of milliseconds. According to Harry Shum, a Microsoft computer scientist, users will visit a website less if its loading time is slower than its competitors by 250 milliseconds, or one-quarter of a second.[1] That is less time than the blink of an eye.

Boost Search Engine Rankings


Fast and optimized websites lead to higher visitor engagement, retention and conversions, but page load times have become significantly more important now that they help to determine your website’s search engine ranking.

Until recently, Google determined page rank using two primary factors: relevance (how pertinent a page is to the actual search) and authority (the number and quality of inbound links to a website). In their continued quest to improve user experience on the web and deliver useful search results, Google decided to modify their search ranking algorithms to include site speed as a determining signal.

Why has Google become obsessed with speed? The following excerpt from Google's blog emphasizes how important page load times are on the Internet:
"At Google, we focus constantly on speed; we believe that making our websites load and display faster improves the user’s experience and helps them become more productive."
In other words, an optimized website is fast and makes users happy. If your site’s not fast, it can affect its overall ability to rank well on search engines. Obviously, Google has tons of ranking factors and site speed is merely one, but every little bit helps right?

Lower Operating Costs While Increasing Revenue


Still not convinced? If SEO isn't your goal, think of conversion rates.

When a site responds slowly, visitors spend less time there. If a user gets frustrated and leaves your site, your conversion rate drops. The slower your site is, the more potential customers you’re likely to lose.

Users aren’t used to waiting and expect they won’t have to. They have the luxury and ease of finding comparable products and services on another site, namely, your competition.

The bottom line is, faster sites create happy users and happy users become happy customers. Give the users what they want... it’s a mutually beneficial relationship.


[1] Lohr, S. For Impatient Web Users, an Eye Blink Is Just Too Long to Wait. New York Times. 26 February 2012.

Tuesday, September 27, 2011

A Guide to PCI Compliance

Most of you have heard the term “PCI Compliance” or “PCI DSS,” but what does this mean for you and your business? What are the steps necessary to obtain and maintain compliance?


The PCI Data Security Standard (DSS) is a set of requirements created by major credit card companies that applies to any organization that stores, processes or transmits credit card information. If any credit card information travels through either your website or your hosting environment, you will need to make sure that you maintain Payment Card Industry (PCI) compliance. Violations of the standard or any breach of credit card information can result in very serious fines, as well as more strict requirements for your solution. As everyone knows, stricter requirements almost always translates to more costs for you, and the financial and reputation repercussions can be catastrophic for many of small business owners. If you are new to this topic it may seem overwhelming and difficult to understand at first, but the long-term side effects of not taking the necessary steps towards compliance could possibly land you in the ever-growing unemployment line. The good news is achieving PCI compliance is not as difficult as it may appear.

  1. Divide your front-end and back-end servers into independent solutions
  2. The initial step to becoming compliant is to split your front-end (web) and back-end (database) servers into independent solutions. The reasoning behind this approach is that if there was ever a breach of your public-facing web server, the intruder would not have direct access to the information located and/or processed with your database server.
  3. Enable firewall policies
  4. After you have split into a minimum of two servers, you will want to have your hosting provider enable multiple layers of firewall policies restricting access to and from your now independent solutions. The first requirement regarding firewall policies is to restrict all access except port 80 and port 443.
  5. Remove all public access to your database server
  6. After the necessary firewall policies are implemented, you will connect to your public web server via a secure SSL/VPN connection. To connect to your private database server, you will first login to your web server and then establish a connection to your database server via the specified SQL port.
  7. Hire an Approved Scanning Vendor (ASV)
  8. After you have segregated your web and database server and implemented the necessary firewall policies, you will need to sign up with a third-party ASV of your choice for quarterly scans of your solution. To maintain compliance, you are required to pass a network vulnerability assessment scan every 90 days. The PCI Security Standards Council has a list of over 100 approved vendors that can perform vulnerability audits and help you automate this process. Prices for scanning and other compliance services vary significantly, so we suggest contacting multiple vendors to ensure you are receiving the best available pricing. You will find the Approved Scanning Vendors list at: https://www.pcisecuritystandards.org/approved_companies_providers/approved_scanning_vendors.php

Can I avoid being PCI compliant?

If you transfer the risk entirely to someone else who meets the PCI standard, such as PayPal, you can avoid having to being PCI compliant. However, your clients will have to interact directly with PayPal and their credit card information can never pass through your servers. If your website integrates with PayPal via an API, you are still liable for PCI compliance since your servers capture and transmit the credit card data.

What if my application does not store any credit card information?

PCI DSS applies to the handling of data while it is processed over your network, not just the storage of credit card information.

Is the PCI DSS a requirement or a recommendation?

If your business processes, stores or transmits any information listed on a credit or debit card, then you must comply with the PCI DSS Standard. If you are found negligent in the event of a breach, you are likely to face significant fines, higher costs through increased compliance requirements, larger merchant fees and/or potential suspension or cancellation from your credit card merchants.

If I pass the quarterly ASV scan, does that mean I am compliant?

ASVs are only a piece of the PCI puzzle. All merchants and service providers are required to complete a self-assessment questionnaire (SAQ) that serves as a statement of compliance. The questionnaire states that your organization has implemented the required controls described in the PCI Standard. You can download these SAQs from the PCI Security Standards Council's website
at: https://www.pcisecuritystandards.org/security_standards/documents.php?category=saqs

Does PCI compliance require a dedicated server environment?

A common misconception is that you are required to have a dedicated server to become PCI compliant. However, PCI compliance is obtainable in a virtual environment where the operating system is isolated and able to be secured according to the standard’s requirements.

Do you provide the required quarterly network scans?

The required scans will need to be completed by a third-party Approved Scanning Vendor (ASV), who will provide you with an independent, non-biased view of your network. We have partnered with Alert Logic (http://www.alertlogic.com/) to provide this service, but you are free to select from any of the approved vendors. If you choose Alert Logic as your ASV, tell them you are a HyperFive Web Hosting customer to ensure you receive the best available pricing.

Do you guarantee a PCI compliant solution?

We guarantee to provide you with a PCI-compliant solution for your hosting services. We also guarantee that if any issues are found by your selected ASV, we will work directly with you and your ASV to achieve compliance.

Tuesday, June 7, 2011

The Benefits of VPS Hosting

Web hosting providers offer many different types of plans for various business and personal hosting requirements, each with their own advantages and disadvantages. Most people start out with a basic shared hosting plan that lets them build a small website, but many outgrow this kind of limited hosting setup, especially when operating an online business. Many small business owners require more options and control over their hosting environment, but may not be ready to shoulder the commitment and expense of a dedicated server.

Between shared and dedicated hosting is virtual private server (VPS) hosting, which is significantly less expensive than a dedicated server and provides many more options for growing online businesses than shared hosting. Although they are sharing hardware, each VPS hosting account is assigned their own operating system so users can individually configure their server without disrupting the others.


There are five primary advantages to using a VPS account rather than a shared host:

Unlimited Websites

VPS hosting provides the ability to manage an unlimited number of websites. Common hardware sharing issues are eliminated since each is utilizing its own software.

Flexibility

Virtual private servers have the same functionality as a dedicated server including custom firewall configurations, the opening and closing of ports, root access, customizable services and the freedom to reboot at any time. Also, with administrator privileges users are able to install software and configure permissions to fit their needs and custom applications.

Security

Shared hosting is difficult to completely secure. If one account is hacked, all accounts on that server are open to damage. Since VPS accounts are isolated from one another, a security vulnerability within an account will not affect other accounts on the server.

Performance

Shared servers depend on the performance of other accounts. If one owner sends out mass-mails, this could overload the server negatively affecting all other accounts. On the other hand, since VPS accounts are independent they only use the resources dedicated to their account. A bad VPS neighbor only affects their own account.

Scalability

Virtual private servers were created to support high-traffic websites, extensive database applications and resource hungry sites. At any time, users can upgrade or downgrade their service with minimal downtime. Overall, VPS accounts have become popular due to the amount of money saved over time as opposed to the other options available on the market.

Still not sure if VPS is right for you?
HyperFive Web Hosting offers a free trial so you can experience the performance and control of VPS hosting, risk-free. Get started today!