Jump to content

Recommended Posts

Posted
You said in your first post that you'd checked DHCP and you had 'plenty of addresses'. Have you double checked that the subnet is set correctly on your DHCP scope?

Have you any wired devices, and are they seeing any issues?

Can you ping your AD servers IP or the routers IP on a wired machine?

On a troublesome wireless machine, what IP info are you actually getting? How does this correspond to what you think should be set?

Can you ping your AD server IP and the router IP on a wireless machine?

Looking at your switches GUI, are you seeing any high load on any ports? Could there be a loop or a faulty device causing lots of traffic?

Does DNS look correct - can the machines resolve the domain, can they resolve the servers?

Have you fired up Wireshark - what type of traffic is actually creating the most packets in the list - where is it coming from?

 

It could well be an issue with bonjour - or that could be a red herring. Start simple and work upwards.

 

Hey Mate,

 

Yes the subnet is correct. Though after having another look at the address leases on DHCP this machine is .172 and when looking at .172 on DHCP the only difference is that the little computer icon has a Green Pen by it rather than a clock.... could this have anything to do with it!?!? We have a fair few addresses left around 170 addresses.

 

When the computer is Wireless no, even though when checking the ipconfig /all is correct and it knows the IP for DNS ,DHCP and router. Though when it is wired in it works fine and will ping all servers and can access the internet etc....

 

Our IP range is a bit like this

XX.XXX.4.1 - .7.254

All the servers start off from .4.1 - .4.8

printers are on static IP's also from .7.200 - .7.205

We do have static IP's for staff also which goes from .4.9 - .4.50 for Sims (though this machine isn't static) we user DHCP reservations for everything but the Servers which are set manually

 

So as long as it doesn't have any of those addresses it should be fine and as I say the address it's being given is .4.172 which is perfectly fine. This same computer was working ok yesterday, but that's what I'm finding one day they'll be fine next day they just won't connect and say Unidentified Network.

 

The IP settings I'm getting including things like the router, DNS and DHCP servers all look fine.

 

This may sound really bad but I have never accessed our switches they where put in place by a third party supplier well before I came into the school and have always just worked, they're not on static IP's and I wouldn't even know where to start to access their GUI.

 

DNS looks fine as far as I can see, I had @Epheylon help me with this a while back and everything been working well since.

 

I'll give Wireshark a go and see what it tells me, though I've never used the software.

Posted
Wireshark won't load it just brings up something called Xterminal?

 

Im guessing this is Mac OS? You will need XQuartz to run Wireshark, and then it can take up to 10 minutes on first run to load.

Posted
Im guessing this is Mac OS? You will need XQuartz to run Wireshark, and then it can take up to 10 minutes on first run to load.

I downloaded Quartz and it has been far longer than 10 minutes :/

Posted
Hey Mate,

 

 

Yes the subnet is correct. Though after having another look at the address leases on DHCP this machine is .172 and when looking at .172 on DHCP the only difference is that the little computer icon has a Green Pen by it rather than a clock.... could this have anything to do with it!?!? We have a fair few addresses left around 170 addresses.

 

 

When the computer is Wireless no, even though when checking the ipconfig /all is correct and it knows the IP for DNS ,DHCP and router. Though when it is wired in it works fine and will ping all servers and can access the internet etc....

 

 

Our IP range is a bit like this

XX.XXX.4.1 - .7.254

All the servers start off from .4.1 - .4.8

printers are on static IP's also from .7.200 - .7.205

We do have static IP's for staff also which goes from .4.9 - .4.50 for Sims (though this machine isn't static) we user DHCP reservations for everything but the Servers which are set manually

 

 

So as long as it doesn't have any of those addresses it should be fine and as I say the address it's being given is .4.172 which is perfectly fine. This same computer was working ok yesterday, but that's what I'm finding one day they'll be fine next day they just won't connect and say Unidentified Network.

 

 

The IP settings I'm getting including things like the router, DNS and DHCP servers all look fine.

 

 

This may sound really bad but I have never accessed our switches they where put in place by a third party supplier well before I came into the school and have always just worked, they're not on static IP's and I wouldn't even know where to start to access their GUI.

 

 

DNS looks fine as far as I can see, I had @Epheylon help me with this a while back and everything been working well since.

 

 

I'll give Wireshark a go and see what it tells me, though I've never used the software.

 

 

Ok so your subnet is set to 255.255.252.0 right?

 

 

The pen icon next to your DHCP scope suggests that DHCP has issued the lease, but it is also set to write this back to DNS - and it's not able to. That suggests that DHCP is set to "Automatically update DHCP client information in DNS" but you either haven't got a reverse look up zone set, or for some reason the server can't adjust the record. This could be part of your problem - but it might not. Have you got a reverse DNS zone setup? With a range of addresses amounting to over 1000 IPs, it is probably best to have one.

 

 

As long as DHCP isn't serving addresses it shouldn't DHCP sounds ok.

 

 

Grab Wireshark portable if you are having trouble and open it on a PC (probably much easier if you have a windows machine to hand). It runs out of a folder but does need to install one thing. Capture your (wired might be best to start with) nic traffic and ask about the type of packets you're seeing most. If there are lots and lots of broadcast 'whose got x please tell y' then we're starting to narrow things down a bit. Is x or y nearly always the same address? Narrowing down further...

 

 

I'd be looking closer at DNS personally.

Posted (edited)
Ok so your subnet is set to 255.255.252.0 right?

 

 

The pen icon next to your DHCP scope suggests that DHCP has issued the lease, but it is also set to write this back to DNS - and it's not able to. That suggests that DHCP is set to "Automatically update DHCP client information in DNS" but you either haven't got a reverse look up zone set, or for some reason the server can't adjust the record. This could be part of your problem - but it might not. Have you got a reverse DNS zone setup? With a range of addresses amounting to over 1000 IPs, it is probably best to have one.

 

 

As long as DHCP isn't serving addresses it shouldn't DHCP sounds ok.

 

 

Grab Wireshark portable if you are having trouble and open it on a PC (probably much easier if you have a windows machine to hand). It runs out of a folder but does need to install one thing. Capture your (wired might be best to start with) nic traffic and ask about the type of packets you're seeing most. If there are lots and lots of broadcast 'whose got x please tell y' then we're starting to narrow things down a bit. Is x or y nearly always the same address? Narrowing down further...

 

 

I'd be looking closer at DNS personally.

 

In my DNS server I have a folder called reverse lookup zones though I don't know whether or not that is the right thing to be looking at....? We have had major problems with our DNS since another technician filled in for me after three months of being away.

If you reckon it's our DNS I can assure you it probably is, problem being I have never played with DNS it's always just worked out of the box so to speak so I don't have a clue what to look at or do to test things in DNS.

 

Edit: Oh and yes that is our subnet.

Edited by abillybob
Posted

When I have set up DNS in the past on new servers and domains I've only ever added the Reverse lookup zones.

 

So in DNS you should have:

Forward Lookup Zones

+domain.sch

 

Reverse Lookup Zones

+backwards ip.in-addr.arpa (eg/ IP range is 10.16.4.* then the backwards is 4.16.10.in-addr.arpa)

 

Under all the forward you have the machine names. In the reverse you have the IP's...

Posted
In my DNS server I have a folder called reverse lookup zones though I don't know whether or not that is the right thing to be looking at....? We have had major problems with our DNS since another technician filled in for me after three months of being away.

If you reckon it's our DNS I can assure you it probably is, problem being I have never played with DNS it's always just worked out of the box so to speak so I don't have a clue what to look at or do to test things in DNS.

 

Edit: Oh and yes that is our subnet.

 

Under that folder is there any mention of your IP ranges (in reverse)? 4.x.x.in-addr.arpa, 5.x.x.in-addr.arpa, etc?

If you click on 4.x.x.in-addr.arpa, can you see your servers mentioned in the right hand pane?

 

Have you tried running an internal test on your DNS server?

Right click on the DNS server and click properties - then click the Monitoring tab. Try a simple test first, then try a recursive as well. do they both pass?

 

Out of interest - does your internal domain name end in .local ?

Posted (edited)
When I have set up DNS in the past on new servers and domains I've only ever added the Reverse lookup zones.

 

So in DNS you should have:

Forward Lookup Zones

+domain.sch

 

Reverse Lookup Zones

+backwards ip.in-addr.arpa (eg/ IP range is 10.16.4.* then the backwards is 4.16.10.in-addr.arpa)

 

Under all the forward you have the machine names. In the reverse you have the IP's...

 

Ok so in reverse I have:

Reverse Lookup Zones

+4.157.10.in-addr.arpa

 

and then inside that folder I have names of IP's and then under Data is says the DNS name of that device....? Is that right? I'm guessing so.

 

Under that folder is there any mention of your IP ranges (in reverse)? 4.x.x.in-addr.arpa, 5.x.x.in-addr.arpa, etc?

If you click on 4.x.x.in-addr.arpa, can you see your servers mentioned in the right hand pane?

 

Have you tried running an internal test on your DNS server?

Right click on the DNS server and click properties - then click the Monitoring tab. Try a simple test first, then try a recursive as well. do they both pass?

 

Out of interest - does your internal domain name end in .local ?

 

Thankyou all for being so patient with me, don't know what I'd do without EduGeek!!

 

Yes I can see the servers mentioned in the right hand pane. Though all it's showing is 10.157.4.X addresses there is no sign of 10.157.5.X 10.157.6.X or 10.157.7.X?? Could this be a problem? I also should mention I have two domain controllers both of which are DNS servers? They both have the exact same config except for the name of the server of course and both have different IP addresses.

 

Yes I've tested them and they have both passed.

Edited by abillybob
Posted
Ok so in reverse I have:

Reverse Lookup Zones

+4.157.10.in-addr.arpa

 

and then inside that folder I have names of IP's and then under Data is says the DNS name of that device....? Is that right? I'm guessing so.

 

The formatting is right - but does the data look correct? Is your server on 10.157.4.1 named correctly for example. Is the record for the workstation you are using correct? Does anything seem old and stale?

Posted
The formatting is right - but does the data look correct? Is your server on 10.157.4.1 named correctly for example. Is the record for the workstation you are using correct? Does anything seem old and stale?

 

Yup they're all named correctly, by looking through the records it all looks fine and as I would expect.

Posted
Who installed the solution for you? Would it be worth contacting them as a first port of call? You are normally only entitled to Aruba support if you have kept up with the annual licensing payments.
Posted
Who installed the solution for you? Would it be worth contacting them as a first port of call? You are normally only entitled to Aruba support if you have kept up with the annual licensing payments.

CIS although they're a private company after moving from being part of the LEA. Would cost us a small fortune now!

Posted
Yes I can see the servers mentioned in the right hand pane. Though all it's showing is 10.157.4.X addresses there is no sign of 10.157.5.X 10.157.6.X or 10.157.7.X?? Could this be a problem? I also should mention I have two domain controllers both of which are DNS servers? They both have the exact same config except for the name of the server of course and both have different IP addresses.

 

Yes I've tested them and they have both passed.

 

Are there no further folders under the reverse look Zone folder in DNS ie. 5.157.10.in-addr.arpa? If not perhaps your devices are struggling to reverse lookup other devices on IPs in the 10.157.5.x, 10.157.6.x and 10.157.7.x range? As your devices is increasing that could cause additional traffic over your network.

 

The wireshark screen grab you posted suggested a reasonable amount of UDP 3283 traffic which I had to look up... Port 3283 (tcp/udp) :: SpeedGuide Are you using Apple remote desktop heavily?

 

I'm afraid this is one of those issues that often takes a while to pin point the culprit.

Posted

Nope no further folders, do these need adding and if so how :~|

Screen Shot 2015-01-27 at 11.05.48.png

 

Not really as I have stated we do use a lot of Apple kit such as Mac's and iPads but it's only my laptop that has Apple Remote Desktop on it to control the Mac Server.

Posted

Because the ip has 4.157.10 it will only record dns records for computers in that range.

 

If you have 5.157.10 then you need to add a new reverse lookup zone for that range.... or modify the existing and remove the .4 so it will record any IPs with 157.10 in them.

Posted
Right Click reverse lookup zones, new zone. Follow wizard :)

 

Ok I have done that. Does this look better :) Do you guys reckon this may sort out my WiFi problems?

 

Screen Shot 2015-01-27 at 11.27.55.png

Posted
Nope no further folders, do these need adding and if so how :~|

[ATTACH=CONFIG]28780[/ATTACH]

 

Not really as I have stated we do use a lot of Apple kit such as Mac's and iPads but it's only my laptop that has Apple Remote Desktop on it to control the Mac Server.

 

Ok well the apple remote desktop stuff may well be a red herring then - especially if the machine you are using is using it.

 

To add a reverse lookup zone simply right click on Reverse Lookup Zones, New Zone, Primary Zone, Replicate to All DNS servers in the domain, IPv4 and then input the first three octets of your IP (ie. 10.157.5), default file name is fine, then allow dynamic updates (this might be why the pen was showing on some of your devices in DHCP). Then follow the same for 10.157.6.x and 10.157.7.x

 

Again - this might not be your issue, but should really be set with this amount of devices.

 

I think next, you need to get into a switch. Look at DHCP is there a device with the mac address ending 79:7a:75 - looking at wireshark, that is probably one of your netgear switches. If you can't find a IP to access your switches, can you use console to set an IP? Look at ports that are very busy - what is connected to them. You might be able to setup a mirror port, that will give you loads more info in your wireshark output which might help diagnose. If thats difficult, wireshark on your server might show up more issues than running it on a workstation on a switched network.

Posted
Ok I have done that. Does this look better :) Do you guys reckon this may sort out my WiFi problems?

 

[ATTACH=CONFIG]28783[/ATTACH]

 

That looks better. Are records being created within those zones if devices are getting IPs in those ranges? Ipcofig /release, ipconfig /renew a few of them.

Posted
That looks better. Are records being created within those zones if devices are getting IPs in those ranges? Ipcofig /release, ipconfig /renew a few of them.

Yes but only records are showing up in 10.157.6.X zone and not a fat lot is in there but a few but not compared to how much is using .6.X in DHCP.

 

There are no records in 10.157.5.X or 10.157.7.X even though I know we have things using that IP, why aren't they showing up?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...