Jump to content

Recommended Posts

Posted

Hi there!

 

We have had a weird problem creep into the our school over the last few weeks, I'll try to explain but first a little bit of background info!

 

Over the summer (before these problems started) we installed SmoothWall, which is doing natting on our addresses to change them from 192. to 10. for when they leave the building.

 

The DNS over the summer had to be 'reconfigured' IP wise, because all of the IPs changed. We think we did this correctly, but please don't hesitate to tell us to 'suck eggs' we could have missed the obvious! :)

 

 

The problem

 

We are experiencing a seemingly random problem with certain IP addresses, when a PC around the building picks up one of these 'bad IP addresses' it cannot contact our server 13 however it can contact the other servers.

Doing a little bit of troubleshooting on the 'broken' machine gave me the following results;

 

 

Ping google.com (Success)

 

Tracert Server 13 (Failed)

 

Nslookup Server 13 (Success)

 

Remote Connection to Server 13 (Failed)

 

Run - Server 13 shares (Failed)

 

Map Network Drive - Sever 13 (Failed - however 'network' can see the server)

All of these above procedures work on all the other servers from that 'broken' machine.

 

We have also rebooted with no joy!

 

The 'fix'

 

To get round this problem, we exclude that specific IP from the DHCP and release renew on the 'problem machine', after a reboot the machine can access server 13 perfectly under all the tests.

 

We have now excluded over 20 IP addresses, only a small small amount, however this obviously isn't a permanent fix.

 

I am going to assign a 'bad IP' statically to a PC and see if I lose server 13 again as witnessed on the other PC and let you guys know, but in the mean time, anyone have any ideas!?

 

Kind regards

 

Ryan

Posted (edited)

Where's your DNS server? Does Server 13 have an entry in your DNS? Are clients set to look at your internal DNS server either manually or through DHCP?

 

Those would be the first things I'd check. I changes our IP range over the summer. It might be worth checking Server 13 and see if you made the same silly mistake I did - I forgot to update one or two servers with the new IP details :o (specifically in my case the subnet mask was too narrow).

 

 

EDIT: re-read the problem and a thought occurred. Do you have multiple DHCP servers? If so have they all been updated to hand out the correct IP settings? The problem sounds like a DHCP server sending out the wrong DNS or Subnet settings.

Edited by tmcd35
Posted (edited)
Where's your DNS server? Does Server 13 have an entry in your DNS? Are clients set to look at your internal DNS server either manually or through DHCP?

 

Those would be the first things I'd check. I changes our IP range over the summer. It might be worth checking Server 13 and see if you made the same silly mistake I did - I forgot to update one or two servers with the new IP details :o (specifically in my case the subnet mask was too narrow).

 

EDIT: re-read the problem and a thought occurred. Do you have multiple DHCP servers? If so have they all been updated to hand out the correct IP settings? The problem sounds like a DHCP server sending out the wrong DNS or Subnet settings.

 

 

Sorry I should have included a little more information;

 

Server 13 is a file server, it has no DNS or DHCP, and all of the server are correctly configured in regards to the IPs.

 

On a side note I have given the 'bad IP' to a different laptop and it's having the same problem, so it seems to be IP related.

 

Ryan

 

EDIT - On this laptop I have entered everything statically, so all the DNS/DHCP/GW e.t.c is 100% correct and we are still having the problem under that IP.

Edited by RJohnson91
Posted

Really need to see some worked examples. My guess would be those IP's full outside the range of the subnet mask, but it's purely a guess based on your description. Any chance of a cleaned up worked example. IP addresses of DNS server, gateway server, effected IP addresses (are they close together in the range?), IP address of storage server, DNS/GW/Subnet setting on storage server, DNS/GW/Subnet being given out by DHCP, etc.?

 

 

Other guess is more machine related. Have you trued a 'ipconfig /flushdns' on an effected machine? Or reset Winsock?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...