Jump to content

Recommended Posts

Posted

Hi.

 

We are trying to resolve an issue with a DC in Domain A to resolve a broken 2 way transitive Domain Trust with Domain B.

 

Both domain controllers in Domain A are in VLAN 250. One is physical, one is virtual, both plugged into same switch (effectively), and both ports setup to be untagged on this VLAN (250).

 

Physical one cannot ping Firewall in Domain A, and cannot be pinged across VPN from Domain B.

Virtual one, CAN ping Firewall in Domain A, and can be pinged across VPN from Domain B, and vice versa (so this means my firewall config at both sides is working!).

 

I can ping so far, before getting stuck with Physical DC, and cannot reach the firewall. Tracert also fails getting to the firewall, but can reach the DG on the core switch.

Virtual DC can tracert and ping all the way to Domain A firewall and into Domain B and vice versa.

 

The only difference is that Physical DC has a NIC team setup, could this be causing an issue?

 

Cheers.

Posted
Hi.

 

We are trying to resolve an issue with a DC in Domain A to resolve a broken 2 way transitive Domain Trust with Domain B.

 

Both domain controllers in Domain A are in VLAN 250. One is physical, one is virtual, both plugged into same switch (effectively), and both ports setup to be untagged on this VLAN (250).

 

Physical one cannot ping Firewall in Domain A, and cannot be pinged across VPN from Domain B.

Virtual one, CAN ping Firewall in Domain A, and can be pinged across VPN from Domain B, and vice versa (so this means my firewall config at both sides is working!).

 

I can ping so far, before getting stuck with Physical DC, and cannot reach the firewall. Tracert also fails getting to the firewall, but can reach the DG on the core switch.

Virtual DC can tracert and ping all the way to Domain A firewall and into Domain B and vice versa.

 

The only difference is that Physical DC has a NIC team setup, could this be causing an issue?

 

Cheers.

 

Sounds odd..

 

I would on the phyiscal:

Ping DG

Ping another interface on the core switch

ping the fw, and watch for the traffic to see if its being dropped.

 

Without knowing a bit more I would say it could possibly be, FW config or mismatched subnet masks maybe. It's unlikely to be a nic team issue, as I would have expected the communication issues to be further reaching if there were fundamental comms issues with the nic of a dc

Posted
Sounds odd..

 

I would on the phyiscal:

Ping DG

Ping another interface on the core switch

ping the fw, and watch for the traffic to see if its being dropped.

 

Without knowing a bit more I would say it could possibly be, FW config or mismatched subnet masks maybe. It's unlikely to be a nic team issue, as I would have expected the communication issues to be further reaching if there were fundamental comms issues with the nic of a dc

 

Thanks,

 

From the physical DC. I can ping the DG of the VLAN its on. I can even ping my own PC, different VLAN and another switch.

Pinging the FW is where it falls down.

 

I have been told we have 2 core switches which host most of the fibre for the school. These are linked together in a trunk.

Two switches are in our server room and a redundant loop is in place, to the two cores, but it has spanning tree blocking any broadcasts.

 

I can ping only as far as the first core from the physical DC.

The virtual DC can ping to the second core then onto the firewall and out.

 

Does this explain it better.

 

Cheers

Posted

Hi,

 

Can you submit a copy of your routing table from your firewall and core switch?

Check to see if there isn't a rule on the firewall blocking ICMP or any other traffic from the physical DC.

Instead of using ping to communicate with the remote DC try and open an RDP session or something and see if that works.

What do the failed pings results return? Is it unreachable or timed out?

How are the 2 cores setup? Are they in a stack?

Posted
Thanks,

 

From the physical DC. I can ping the DG of the VLAN its on. I can even ping my own PC, different VLAN and another switch.

Pinging the FW is where it falls down.

 

I have been told we have 2 core switches which host most of the fibre for the school. These are linked together in a trunk.

Two switches are in our server room and a redundant loop is in place, to the two cores, but it has spanning tree blocking any broadcasts.

 

I can ping only as far as the first core from the physical DC.

The virtual DC can ping to the second core then onto the firewall and out.

 

Does this explain it better.

 

Cheers

 

In that case it may be the routing tables on your two cores are done statically (and incorrectly by the sound of it). Just a guess though, as FN-GM has said would really need to see routing tables to be able to manually trace the traffic path to work out whats going on.

Posted

After much fiddling this morning, changing the DC's IP address resolved the issue. Returning to its default IP, and the problem returned.

 

Eventually the issue was traced to a route on the FW! Sorted, thanks guys for your input :-)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...