Recommended Posts

I own a small business and run Windows Server 2008 R2 and about 7-8 workstations. The problem I've run into recently is odd network behavior on my workstation. For instance, every morning I come in and there's an X through all my shared network drives (not mapped but set in my user profile on the server) when they worked perfectly the previous day. I have to reboot the computer in order to get them back. I also started having an issue where websites would not load until I hit reload in the browser a bunch of times. I solved this one by changing the DNS server addresses on my workstation. I also have developed a problem printing to network printers until a reboot.

Just for information, my server address is 192.168.10.2 and the default gateway is 192.168.10.1. All my workstations have static IP's, for instance my personal workstation is 192.168.10.40

What could possibly have changed to make my network so messed up? I've noticed this behavior on 2 other workstations. Do I need to change some setting on the server in Administrative Tools? I barely ever touch the server so I don't know what could have gone wrong.

Link to comment
https://www.neowin.net/forum/topic/1119406-server-domain-problems/
Share on other sites

Hmm sounds odd, so it has been working in the past without the issues and all of a sudden they've started to happen?

The first thing i'd check tbh is the time on the DC, then look at each machine and ensure the same time is there, as it sounds abit like a credential failure, which can occur if times are out, usually anymore than 5 mins is considered a big chance difference in Active Directory.

Report back your findings, I wouldn't want to say do this and do that if it has worked in the past without any modifications occuring, would make sense for this to happen if you/someone has been playing around.

Yeah all of a sudden. The only change I did do was upgrade AVG Business Edition to the latest version. I just checked the time on the DC and it's exactly the same as my workstation. Your line of think does seem to make sense since this literally happens over night. Is there something I should do to make sure my time is properly synchronized with the DC at all times?

"I solved this one by changing the DNS server addresses on my workstation."

What did you change it too? the ONLY dns that a member of a domain should point to is the AD dns, normally in small setup this is the one DC they have. If you are pointing to your isp, googledns, opendns, etc. on the workstation even if added as secondary then yeah your going to have nothing but grief with your AD.

googledns does not know anything about your AD. Clients need to talk to AD dns, AD dns then forwards to googledns, isp dns, etc. or looks up from roots directly. If you were having issues with looking up websites, this tells me you have something wrong setup in your AD dns.

"I solved this one by changing the DNS server addresses on my workstation."

What did you change it too? the ONLY dns that a member of a domain should point to is the AD dns, normally in small setup this is the one DC they have. If you are pointing to your isp, googledns, opendns, etc. on the workstation even if added as secondary then yeah your going to have nothing but grief with your AD.

googledns does not know anything about your AD. Clients need to talk to AD dns, AD dns then forwards to googledns, isp dns, etc. or looks up from roots directly. If you were having issues with looking up websites, this tells me you have something wrong setup in your AD dns.

The website loading errors got to be so annoying that I changed them to 4.2.2.1 and 4.2.2.2

I know what you're saying and for years I pointed it to the AD DC by using 192.168.10.1. I could change it back but would that have anything to do with these other issues?

Sorry you NEED to point to your AD for dns - maybe there is something wrong with it resolves outside domains slow. FIX IT!!

How do you resolve your AD records if your not usnig its DNS? 4.2.2.2 does not know about it for damn sure.

If your AD is having issues with resolve outside domains - then you Need to FIX that. And yes not pointing to your AD dns could cause all kinds of issues like not being able to auth to stuff, stuff being disconnected, not being able to log in or taking a LONG time to, etc. etc.

Having issue finding the MS article that lists it as one of the top mistakes, but here

http://mcpmag.com/ar...ur-network.aspx

10 DNS Errors That Will Kill Your Network

1. TCP/IP Configuration Points to Public DNS Servers

This is by far the most common DNS error. Each network interface has a set of TCP/IP settings that lists the DNS servers used by that interface.

If the TCP/IP settings for a member computer specify the IP address of a public DNS server?perhaps at an ISP or DNS vendor or the company?s public-facing name server?the TCP/IP resolver won?t find Service Locator (SRV) records that advertise domain controller services, LDAP, Kerberos and Global Catalog. Without these records, a member computer can?t authenticate and get the information it needs to operate in the domain. It then acts like a teenager who can?t get the car keys, growing sullen and exhibiting a variety of bad behaviors.

I pointed my workstation DNS servers to the DC and website loading problems started immediately. When I went back to the ones listed above, everything went back to normal.

I just don't know how there can be any "DNS errors" when my Domain has worked fine for 10 years.

you need to learn active directory and dns....

cliffs:

dns....setup forwarders in your ad dns to your dns servers that are not having issues. uncheck use root hints if no forwarders are available.

clients use the ad dns server for all lookups. also the ad server points to its ip in tcpip properties, not the loop back.

post-118098-0-15402700-1352921254.jpg

"I just don't know how there can be any "DNS errors" when my Domain has worked fine for 10 years."

Well where are you forwarding your non authoritative zone lookups too on your AD dns? As sc302 points out on your AD dns you can have it either use root hints or your isp dns or some other dns server.

FACT!!! - All members of AD NEED!!! and Require to ONLY use your AD for dns, if they point or have multiple entries to other outside dns, then your going to have issues with your AD, plain simple FACT!! The only dns that knows anything about your AD is your AD dns, googledns sure and the hell does not have your srv records, nor does 4.2.2.2, etc. So if you ask them for stuff about your AD, your going to get back nxdomain. This is going to cause you NOTHING but pain!!!

Point your clients to your AD dns, and then work out why your AD dns can not resolve google.com, neowin.net, etc.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Not even an OLED display on the laptops. Also it seems that the laptop design isn't the same as the Surface Ultra model. Looks like bargain bin at high prices.
    • VirtualBox 7.2.10 by Razvan Serea VirtualBox is a powerful x86 and AMD64/Intel64 virtualization product for enterprise as well as home use. Targeted at server, desktop and embedded use, it is now the only professional-quality virtualization solution that is also Open Source Software. Presently, VirtualBox runs on Windows, Linux, macOS, and Solaris hosts and supports a large number of guest operating systems including but not limited to Windows (NT 4.0, 2000, XP, Server 2003, Vista, 7, 8, Windows 10 and Windows 11), DOS/Windows 3.x, Linux (2.4, 2.6, 3.x, 4.x, 5.x and 6.x), Solaris and OpenSolaris, OS/2, OpenBSD, NetBSD and FreeBSD. Some of the features of VirtualBox are: Modularity. VirtualBox has an extremely modular design with well-defined internal programming interfaces and a client/server design. This makes it easy to control it from several interfaces at once: for example, you can start a virtual machine in a typical virtual machine GUI and then control that machine from the command line, or possibly remotely. VirtualBox also comes with a full Software Development Kit: even though it is Open Source Software, you don't have to hack the source to write a new interface for VirtualBox. Virtual machine descriptions in XML. The configuration settings of virtual machines are stored entirely in XML and are independent of the local machines. Virtual machine definitions can therefore easily be ported to other computers. VirtualBox 7.2.10 changelog: VMM: Fixed issue when CentOS 10 VM was not booting due to the message "Fatal glibc error: CPU does not support x86-64-v3" (​github:gh-642) Devices/EFI: Fixed booting issue when ARM VM had less than 1024 MiB of RAM assigned (​github:gh-679) USB: Fixed issue when it was not possible to attach USB device to headless VM on Apple Silicon/macOS 26.4.1 (​github:gh-631) Storage: Fixed issue when VIRTIO-SCSI device was not recognized as SSD device by guest system (​github:gh-634) Network: Fixed issue in E1000 emulation code which triggered debug log creation (​github:gh-645) Network: Fixed issue in E1000 emulation code which prevented OS/2 guest from booting (​github:gh-683) Linux Host: Fixed issue when VMs could not be started due to kernel oops (​github:gh-639) Linux Host and Guest: Fixed issue when kernel modules were failing to build with openSUSE 16.0 kernel Linux Host and Guest: Added initial support for kernel 7.1 Linux Host and Guest: Added extra fixes for RHEL 9.8 kernel (​github:gh-676) Linux Host and Guest: Added possibility to build source code using NASM instead of YASM as the assembler (​github:gh-520) Linux Guest Additions: Added initial support for Extended Data Control Protocol for clipboard sharing with Plasma on Wayland guests (​github:gh-33) Linux Guest Additions: Added extra fixes for preventing vboxvideo kernel module build with kernel version 7.0 and newer (​github:gh-655) OS/2 Guest Additions: Fixed issue when Shared Folders automount and clipboard sharing stopped working (​github:gh-551) Download: VirtualBox 7.2.10 | 170.0 MB (Open Source) Download: VirtualBox 7.2.10 Extension Pack | 19.1 MB View: VirtualBox Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • OK, now ask yourself how are they going to enforce that law? By requiring every single adult to prove their age and provide their legal identity documents to an UNREGULATED 3rd party company that already has a long track record of multiple data breaches. Not to mention, parliament have voted AGAINST this ban, twice, and Starmer is going ahead anyway. So, where's the democracy here, because that looks like dictatorship to me. The solution here is parental responsibility, not government control. Run some public service announcements on TV and UK social media teaching parents how to setup parental controls. That's already been proven to actually work. But the, this is not and has NEVER been about keeping kids safe. It's about control and monitoring. Watching what you're doing online and controlling what you can see and what you can say.
    • Interesting read. I knew the adware was quite controversial at the time, however never realised to the point The Guardian wrote an article about Patchou. I just said no and enjoyed his creation, I’d probably be a lot more wary of something like that today though.
  • Recent Achievements

    • One Month Later
      Prasann earned a badge
      One Month Later
    • Week One Done
      Prasann earned a badge
      Week One Done
    • First Post
      Dys Topia earned a badge
      First Post
    • Collaborator
      vjlex earned a badge
      Collaborator
    • Reacting Well
      Dys Topia earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      525
    2. 2
      +Edouard
      180
    3. 3
      PsYcHoKiLLa
      105
    4. 4
      Steven P.
      89
    5. 5
      ATLien_0
      70
  • Tell a friend

    Love Neowin? Tell a friend!