_techie_ Posted August 21, 2015 Posted August 21, 2015 Hi. We are trying to resolve an issue with a DC in Domain A to resolve a broken 2 way transitive Domain Trust with Domain B. Both domain controllers in Domain A are in VLAN 250. One is physical, one is virtual, both plugged into same switch (effectively), and both ports setup to be untagged on this VLAN (250). Physical one cannot ping Firewall in Domain A, and cannot be pinged across VPN from Domain B. Virtual one, CAN ping Firewall in Domain A, and can be pinged across VPN from Domain B, and vice versa (so this means my firewall config at both sides is working!). I can ping so far, before getting stuck with Physical DC, and cannot reach the firewall. Tracert also fails getting to the firewall, but can reach the DG on the core switch. Virtual DC can tracert and ping all the way to Domain A firewall and into Domain B and vice versa. The only difference is that Physical DC has a NIC team setup, could this be causing an issue? Cheers.
Jamo Posted August 21, 2015 Posted August 21, 2015 Hi. We are trying to resolve an issue with a DC in Domain A to resolve a broken 2 way transitive Domain Trust with Domain B. Both domain controllers in Domain A are in VLAN 250. One is physical, one is virtual, both plugged into same switch (effectively), and both ports setup to be untagged on this VLAN (250). Physical one cannot ping Firewall in Domain A, and cannot be pinged across VPN from Domain B. Virtual one, CAN ping Firewall in Domain A, and can be pinged across VPN from Domain B, and vice versa (so this means my firewall config at both sides is working!). I can ping so far, before getting stuck with Physical DC, and cannot reach the firewall. Tracert also fails getting to the firewall, but can reach the DG on the core switch. Virtual DC can tracert and ping all the way to Domain A firewall and into Domain B and vice versa. The only difference is that Physical DC has a NIC team setup, could this be causing an issue? Cheers. Sounds odd.. I would on the phyiscal: Ping DG Ping another interface on the core switch ping the fw, and watch for the traffic to see if its being dropped. Without knowing a bit more I would say it could possibly be, FW config or mismatched subnet masks maybe. It's unlikely to be a nic team issue, as I would have expected the communication issues to be further reaching if there were fundamental comms issues with the nic of a dc
_techie_ Posted August 22, 2015 Author Posted August 22, 2015 Sounds odd.. I would on the phyiscal: Ping DG Ping another interface on the core switch ping the fw, and watch for the traffic to see if its being dropped. Without knowing a bit more I would say it could possibly be, FW config or mismatched subnet masks maybe. It's unlikely to be a nic team issue, as I would have expected the communication issues to be further reaching if there were fundamental comms issues with the nic of a dc Thanks, From the physical DC. I can ping the DG of the VLAN its on. I can even ping my own PC, different VLAN and another switch. Pinging the FW is where it falls down. I have been told we have 2 core switches which host most of the fibre for the school. These are linked together in a trunk. Two switches are in our server room and a redundant loop is in place, to the two cores, but it has spanning tree blocking any broadcasts. I can ping only as far as the first core from the physical DC. The virtual DC can ping to the second core then onto the firewall and out. Does this explain it better. Cheers
FN-GM Posted August 22, 2015 Posted August 22, 2015 Hi, Can you submit a copy of your routing table from your firewall and core switch? Check to see if there isn't a rule on the firewall blocking ICMP or any other traffic from the physical DC. Instead of using ping to communicate with the remote DC try and open an RDP session or something and see if that works. What do the failed pings results return? Is it unreachable or timed out? How are the 2 cores setup? Are they in a stack?
Jamo Posted August 23, 2015 Posted August 23, 2015 Thanks, From the physical DC. I can ping the DG of the VLAN its on. I can even ping my own PC, different VLAN and another switch. Pinging the FW is where it falls down. I have been told we have 2 core switches which host most of the fibre for the school. These are linked together in a trunk. Two switches are in our server room and a redundant loop is in place, to the two cores, but it has spanning tree blocking any broadcasts. I can ping only as far as the first core from the physical DC. The virtual DC can ping to the second core then onto the firewall and out. Does this explain it better. Cheers In that case it may be the routing tables on your two cores are done statically (and incorrectly by the sound of it). Just a guess though, as FN-GM has said would really need to see routing tables to be able to manually trace the traffic path to work out whats going on.
_techie_ Posted August 24, 2015 Author Posted August 24, 2015 After much fiddling this morning, changing the DC's IP address resolved the issue. Returning to its default IP, and the problem returned. Eventually the issue was traced to a route on the FW! Sorted, thanks guys for your input :-)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now