Recommended Posts

I have installed Active Directory on Virtual Machine with Win2k8 Server, which is a domain controller. I am joining other computers i. e Laptops and Virtual Machines to the Domain.

There are few problems that i am facing,

1) I am able to join all the Laptops to domain, but i am not able to manage them using domain controller. When i right click on computer->Mangage computer, it shows an error

Computer \\Computername.domainname cannot be managed.The Network path was not found.

Surprisingly 1 of the Win 7 laptops is working fine, and i am able to manage it without making any changes. All others show the same error.

Changes that i have made so far are:

i) Under Network and Sharing Center -> Advance settings, I have enabled Network Discovery as well as File and Printer sharing.

ii) Turned windows as well as domain Firewall off.

Still getting the same error.

2) After joining the domain, laptops are not able to connect to other networks other then our local network.

3) I have setup a VPN on Server that is domain controller, I am able to connect to that VPN connection from these laptops but i am not able to ping the server, or any other VMs running under same network.

In case of VMs (all running Win 2k8) i am not having any of above mentioned issues. I am assuming there is some setting particularly in Win 7 that needs to be changes.

"2) After joining the domain, laptops are not able to connect to other networks other then our local network."

What does this mean? Makes no sense - do you mean wireless network, plugged into a wire somewhere else and don't get an IP. Can not access the internet, what other networks are you talking about?

Are you windows 7 laptops using dhcp from your DC? Are they static? Where do they point for dns?

So all the VMs are working - how does your VMs connect to your physical network - are you natting the connection or bridging?

Is your pinging issue while they are connected via vpn? So when they connect via vpn they are at another location or on your same network? Why would you connect to vpn if on your local network - and if they are remote I thought you said they can not connect to any other networks?

Keep in mind having adomain controller as a virtual machine is a bad idea. you can get time sync errors and other problems that creep up.

Can you ping your domain name?

Also when you remotely connect to a machine it should either be just the "machinename" or "machinename.domain" not "computer\\computer.domain"

All Laptops are using DHCP.

Before joining the Domain, I set the Preferred DNS of Laptops to the IP of the Domain Controller. Left the alternate DNS blank. Reverting it back to Auto DNS has solved the issue. Now i am able to connect to other Wifi connections and ping the router after joining VPN.

Other issues are still there.

Yes i am able to ping the workstations using machine name.

Dhcp from where?? Your DC? Or your router?

All member machines of a domain need to use the AD for dns - PERIOD!!!! you then need to setup your AD dns to either forward to your router for dns, isp or something outside like google or opendns. Or have it lookup direct from roots.

I could fire up a clean w7 box and join it to domain - there should be NOTHING you have to do on the pc to allow remote admin using the domain admin account. This gets added to local administrators on the box when it joins the domain.

But if the pc is not using your AD dns - it would be possible that it would not be able to verify authentication from the DC when you try and access it.

Your not running any sort of 3rd party firewall/security suite on the PCs are you?

just wondering...could Remote Registry have something to do with it? I know if you disable that service, you cannot manage remote PC's....just curious. And puzzled, lol! At least you have BudMan to help...he is the king! (Y)

yes remote registry could be an issue - but why would that be off?

What is more likely is he has basic configuration wrong - ie machines using his router or isp for dns vs his AD dns. This is common problem in the home lab, user has router for dhcp that hands out its own info gateway, dns point to it, it then forwards to ISP

If you want to run AD you should most likely disable router dhcp, turn on dhcp on your server and just point to your router as gateway in the dhcp scope. DNS needs to point to AD DC, and dhcp also helps with the registrations in dns for your member boxes. You then configure AD dns to forward or use root hints.

I would look to this sort of configuration problem before seeing if a default service on multiple machines has been disable - but sure it is quite possible that could be a problem.

There should be a group policy setting that makes sure this is set to automatic - but yeah he could check if for whatever reason this is not set to automatic and starting once you join a domain.

Remote Registry was off, But turning it on did not make any difference.

Yes, machines are using DNS provided by router (ISP). Based on the network structure we have, i do not want all the machines to be a part of AD, so i can not turn off the auto DNS function of Router.

To me it does not sounds to be the DNS issue, because i have 2 win 7 computers on my desk, both using same network configuration. After joining them to domain, 1 works perfectly fine, and i face all those issues with the second computer.

"Yes, machines are using DNS provided by router (ISP).

This is going to cause you NOTHING but ISSUES!!! All members of a domain NEED to point to the AD DNS - if they do not then they can not correctly resolve SRV records, etc..

All machines in your network can point to AD dns - even if they are NOT members of the domain, this is not going to hurt anything. Then your AD dns points to ISP or direct from roots.

Anyone that would point a AD member to non AD dns clearly has not even the most basic understanding of how DNS is integrated into AD.

http://mcpmag.com/articles/2004/05/01/10-dns-errors-that-will-kill-your-network.aspx

10 DNS Errors That Will Kill Your Network

1. TCP/IP Configuration Points to Public DNS Servers

This is by far the most common DNS error. Each network interface has a set of TCP/IP settings that lists the DNS servers used by that interface.

If the TCP/IP settings for a member computer specify the IP address of a public DNS server?perhaps at an ISP or DNS vendor or the company?s public-facing name server?the TCP/IP resolver won?t find Service Locator (SRV) records that advertise domain controller services, LDAP, Kerberos and Global Catalog. Without these records, a member computer can?t authenticate and get the information it needs to operate in the domain. It then acts like a teenager who can?t get the car keys, growing sullen and exhibiting a variety of bad behaviors.

This topic is now closed to further replies.
  • Posts

    • 1. Define "better". 2. It's still more expensive than equivalent PCs so... And there is not one Windows platform. This is the mistake ALL Apple oriented people make. Apple is one OEM. You could reasonably compare them to one PC OEM, say Dell or HP. But you can't compare them to ALL PC OEMs. Case in point, Apple has NO touch screen MacBooks. No tablet Macs. There are no rugged Macs. The variety of PC OEM design is insane. With Apple, you have... Apple. The problem is that you're starting with Apple as the definition of "good" then filtering out anything that isn't close to an existing Apple product, then trying to homogenise all of those left into a fictional product line and then ignore any innovations to create a minimal feature subset so you can say "See! Apple better!" PS: I was an Apple dev for 17 years and helped develop MacInTalk and disability solutions for Apple - and I have several Mac and MacBooks - so tread very carefully.
    • Major Xbox layoffs may claim South of Midnight developer Compulsion entirely by Pulasthi Ariyasinghe Microsoft has been making major changes in its gaming wing Xbox for a few months now, including the appointment of a new CEO, a large number of leadership changes, and strategy shifts. However, the company is seemingly also looking at initiating a major layoffs wave at Xbox and perhaps even a studio closure. The new report lands from Kotaku, Xbox first-party developer Compulsion Games is being shuttered soon by Microsoft. For those unfamiliar with the studio, it's the team behind Contrast (2013), We Happy Few (2018), and South of Midnight (2025). Its latest game was quite well received, even winning a Peabody Award for its writing. It even received a 9/10 in Neowin's own review, highlighting its engaging storyline, gorgeous world, and curious characters. The studio joined Xbox Game Studios in 2018, just as Microsoft announced it is acquiring Playground Games, Undead Labs, and Ninja Theory. Despite recent listings for new staff roles, according to the new report, Compulsion Games is being closed entirely, with over 90 staff being let go. Kotaku also added that the studio's leadership is in negotiations with Microsoft about this decision, but no official details have been revealed yet. The report lands just as two senior managers of Xbox leave their posts at Microsoft Gaming. Head of Xbox Game Studios Craig Duncan and chief of staff Louise O'Connor originally began their journey in Rare and have been a part of Xbox for over two decades. Dunkan has been responsible for games like Kinect Sports and Sea of Thieves, while O'Connor was primarily working on Rare's Everwild project before its cancelation. If this report about the studio shutdown is accurate, this may just be the start of a major new layoffs wave at Xbox Game Studios. There are also rumors of Arkane Studios being heavily affected. As always, take all these reports with a grain of salt until something official materializes from Microsoft or the studios.
    • The flaw with this analysis is that this laptop has a cellphone CPU in it. In the Intel world, that would be an N150 and those are everywhere, even in low end laptops. You can get an N150 based NUC with 16GB RAM and 256GB-512GB SSD... NOT soldered in... for < $500 Canadian (around US$360). The problem is two fold: tech bloggers/writers on most tech site (like this one, ironically) overvalue Apple and apparently aren't in the same earnings class as most regular people. As a result, we get breathless articles about how everyone needs a folding phone when most people just cannot afford one... or really need one. And we get Apple used as the baseline metric regardless of whether that comparison makes any sense. If Dell or HP released a retail laptop with a cellphone motherboard, you'd be all over them for doing that - but Apple does it and it's genius. I see articles suggesting what Samsung - a company that basically started the foldable phone market and has built them for eight years - needs to do to compete with Apple's unreleased, unspecced and unseen folding phone. Sorry, no - if the Neo (really creative name there BTW - still, better than the Go, the other "creative" product name everyone's using) encourages PC makers to make cellphone laptops using lower end ARM processors, we all lose. It's a step backwards and a capitulation to the fact that semiconductor makers and computer OEMs (and tech bloggers) have totally lost the plot.
    • Everyone should install this extension and ignore games that use AI. https://chromewebstore.google....nnigaaeelfkeomjcngmnh?pli=1 https://addons.mozilla.org/en-US/firefox/addon/ai-warning-for-steam/
  • Recent Achievements

    • One Year In
      ThatGuyOnline earned a badge
      One Year In
    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      127
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      74
  • Tell a friend

    Love Neowin? Tell a friend!