talksr Posted October 15, 2015 Posted October 15, 2015 Good morning, I am not quite sure what on earth has gone wrong here. We have two servers running on our domain. An FRDC running Ranger 8.0 on Windows 7 client computers. We then have a second server which is joined to the domain just as a member and serves as our antivirus and backup server. Both run server 2012. The FRDC has DHCP, DNS and Active Directory with a statically assigned IP of: 10.75.44.10. Its host name is stm-sr-001 The second server has a statically assigned IP of: 10.75.44.11, its host name is stm-sr-002. I am finding it impossible to rdc to the second server using it's hostname. If I try even from the FRDC, It connects me to a class room computer. It first says that the connection cannot be completed (when authenticating with the domain administrator account): If I use another domain account, it authenticates, and works, but loads up an RDC session for a class room computer: You will notice in the above screenshot, I have also pinged the hostname of the second server (from the first) and then tracerted it and found that the hostname is indeed a classroom computer. If I rcd the secondary server IP address from the FRDC, it works. What could be the problem here? I have attempted a DNS restart, DNS flush and bounce of both servers, but it has not made any difference.
mikkydoos Posted October 15, 2015 Posted October 15, 2015 (edited) Check your host records on your DC's. Are they replicating? Are your server IP's set to static in DNS? Any duplicate IP's Are you using Scavenging to clear DNS out? Edited October 15, 2015 by mikkydoos 1
3s-gtech Posted October 15, 2015 Posted October 15, 2015 If you're attempting to connect to one machine and it finds another, it's a DNS issue. Your DNS range should either have exceptions for the IP addresses of your static machines, or even better they sit in a range outside of your DHCP assignments so this can't happen even if the exceptions are lost. It looks like that classroom PC has grabbed the same IP address (10.75.44.11). I guess you only have one DHCP server - you need to check and re-check every setting in DHCP first.
talksr Posted October 15, 2015 Author Posted October 15, 2015 If you're attempting to connect to one machine and it finds another, it's a DNS issue. Your DNS range should either have exceptions for the IP addresses of your static machines, or even better they sit in a range outside of your DHCP assignments so this can't happen even if the exceptions are lost. It looks like that classroom PC has grabbed the same IP address (10.75.44.11). I guess you only have one DHCP server - you need to check and re-check every setting in DHCP first. What you put makes sense, but they are out of the DHCP scope. The DHCP scope is 10.75.44.20-219 and the respective server IPs are 10 and 11. I don't think there are any reservations in place, but as above, the scope starts at 20, and this is confirmed in the Address Pool.
mikkydoos Posted October 15, 2015 Posted October 15, 2015 What you put makes sense, but they are out of the DHCP scope. The DHCP scope is 10.75.44.20-219 and the respective server IPs are 10 and 11. I don't think there are any reservations in place, but as above, the scope starts at 20, and this is confirmed in the Address Pool. Pick through the IP's in both your Forward and Reverse lookups in DNS - on all your DC's. Look for any duplicates. It can't be anything else... unless its not using the DC for DNS but local inistead. 1
TIOAOA Posted October 15, 2015 Posted October 15, 2015 Can you RDP using the IP of the second server ?
talksr Posted October 15, 2015 Author Posted October 15, 2015 Pick through the IP's in both your Forward and Reverse lookups in DNS - on all your DC's. Look for any duplicates. It can't be anything else... unless its not using the DC for DNS but local inistead. Thanks for your helpful posts. In response to your first post: Are they replicating? - nope, we have just one FRDC, the secondary server is joined just as a normal member (like a client computer) Are your server IP's set to static in DNS? They are statically assigned, I was not aware that they could be set to static in DNS. Where could I check this? Any duplicate IP's - no duplicates, all client machines obtain IP via DHCP and scope is not in the range of IPs used by the servers. Are you using Scavenging to clear DNS out? No. In response to your last post: Forward Lookup Zones shows both primary and secondary server IPs (ending 10 and 11 respectively) as (same as Parent Folder) Host(A). Reverse Lookup Zones is empty and has Add a New Zone as title. "The Domain Name System (DNS) allows a DNS namespace to be divided into zones. Each Zone stores information about one or more contiguous DNS domains. To add a new zone, on the Action Menu, click New Zone."
talksr Posted October 15, 2015 Author Posted October 15, 2015 Yes, RDP via statically assigned IP to secondary server works no trouble at all, from any system on the network. RDP via hostname to the second server is where the problem lies.
mikkydoos Posted October 15, 2015 Posted October 15, 2015 Thanks for your helpful posts. In response to your first post: Are they replicating? - nope, we have just one FRDC, the secondary server is joined just as a normal member (like a client computer) Are your server IP's set to static in DNS? They are statically assigned, I was not aware that they could be set to static in DNS. Where could I check this? Any duplicate IP's - no duplicates, all client machines obtain IP via DHCP and scope is not in the range of IPs used by the servers. Are you using Scavenging to clear DNS out? No. In response to your last post: Forward Lookup Zones shows both primary and secondary server IPs (ending 10 and 11 respectively) as (same as Parent Folder) Host(A). [ATTACH=CONFIG]32692[/ATTACH] [ATTACH=CONFIG]32693[/ATTACH] Reverse Lookup Zones is empty and has Add a New Zone as title. "The Domain Name System (DNS) allows a DNS namespace to be divided into zones. Each Zone stores information about one or more contiguous DNS domains. To add a new zone, on the Action Menu, click New Zone." To set an A record to static - right click-->properties of the record---> untick 'delete this record when it becomes stale' I'd do an IPConfig on the problem server - check the DNS is pointing to the DC. If so... delete both DNS records on the DC, then on the other IPConfig /flushdns ---> IPConfig /registerdns Remember to refresh the DNS page every time you make a change so you see the correct settings.
talksr Posted October 15, 2015 Author Posted October 15, 2015 To set an A record to static - right click-->properties of the record---> untick 'delete this record when it becomes stale' I'd do an IPConfig on the problem server - check the DNS is pointing to the DC. If so... delete both DNS records on the DC, then on the other IPConfig /flushdns ---> IPConfig /registerdns Remember to refresh the DNS page every time you make a change so you see the correct settings. Thanks again for your help. Would I set the A record in the Forward Lookup Zone? (Sorry I am not very experienced on DNS). This is the result of the ipconfig on the problem server: In summary, it is pointing to the DC however, there is a ::! on the first line of DNS servers which seems odd - I have made it red below: C:\Users\administrator.STM>ipconfig /all Windows IP Configuration Host Name . . . . . . . . . . . . : stm-sr-002 Primary Dns Suffix . . . . . . . : stm.internal Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : stm.internal Ethernet adapter Ethernet 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : HP Ethernet 1Gb 2-port 330i Adapter #2 Physical Address. . . . . . . . . : 40-A8-F0-75-CE-E9 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Ethernet adapter Ethernet: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : HP Ethernet 1Gb 2-port 330i Adapter Physical Address. . . . . . . . . : 40-A8-F0-75-CE-E8 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::2896:b51:4fbc:2b61%12(Preferred) IPv4 Address. . . . . . . . . . . : 10.75.44.11(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 10.75.44.1 DHCPv6 IAID . . . . . . . . . . . : 306227440 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1D-52-3F-D9-40-A8-F0-75-CE-E8 DNS Servers . . . . . . . . . . . : ::1 10.75.44.10 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter isatap.{5F3F6239-7352-4206-8FA0-A6405D1A8774}: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2 Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter isatap.{BDDC1C94-374E-47C7-B32B-D898EB777C28}: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3 Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes C:\Users\administrator.STM>
mikkydoos Posted October 15, 2015 Posted October 15, 2015 Whats that ::1 ? If you set the record in Forward it will change in Reverse too.
talksr Posted October 15, 2015 Author Posted October 15, 2015 I may have found the cause of the DNS Servers . . . . . . . . . . . : ::1 10.75.44.10 I checked in IPv6 and there was ::1 entered for the DNS server. I don't know how that was put in there as it was not me. Have removed and currently bouncing.
talksr Posted October 15, 2015 Author Posted October 15, 2015 (edited) Whats that ::1 ? If you set the record in Forward it will change in Reverse too. Not sure, see my last post. I have removed it and bounced server, but DNS issue remains. Ok. After removing the ::1, and following through your following instructions: If so... delete both DNS records on the DC, then on the other IPConfig /flushdns ---> IPConfig /registerdns It is now working, so it looks like it was the mysterious ::1 which was causing this issue. Edited October 15, 2015 by talksr
talksr Posted October 15, 2015 Author Posted October 15, 2015 Good stuff m8. Glad to help Thanks again for your help and everyone's suggestions. To confirm, the cause was an entry in the IPv6 DNS area of: "::1" Once this was removed, and the server rebooted and DNS flushed, it behaved.
mikkydoos Posted October 15, 2015 Posted October 15, 2015 TBH, if you're not using IPv6, I'd turn it off, or set both values to Obtain Automatically
3s-gtech Posted October 15, 2015 Posted October 15, 2015 Don't turn off IPv6 on DCs though, they don't like that at all from experience. 1
sonofsanta Posted October 15, 2015 Posted October 15, 2015 If your DNS changed and you don't know how or why, run a virus scan. I've seen compromised servers get altered DNS settings before... 1
talksr Posted October 15, 2015 Author Posted October 15, 2015 I set both values to obtain automatically. That is what it was before. Not sure how that value got in there in the first place!
talksr Posted October 15, 2015 Author Posted October 15, 2015 Ok, one further problem I have found is the following: If I browse to the secondary server using its IP address: 10.75.244.11, no problem, I am able to see all of its shared folders. But if I browse via hostname: stm-sr-002, I am presented with the following error: \\stm-sr-002 is not accesible. You might not have permission to use this network resource. Contact the administrator of this server to find out if you have access permissions. Logon Failure: The target account name is incorrect. Any ideas on what could be causing this, as I am perfectly able to access the server from the same machine by just entering in the host name.
mikkydoos Posted October 15, 2015 Posted October 15, 2015 Ok, one further problem I have found is the following: If I browse to the secondary server using its IP address: 10.75.244.11, no problem, I am able to see all of its shared folders. But if I browse via hostname: stm-sr-002, I am presented with the following error: \\stm-sr-002 is not accesible. You might not have permission to use this network resource. Contact the administrator of this server to find out if you have access permissions. Logon Failure: The target account name is incorrect. Any ideas on what could be causing this, as I am perfectly able to access the server from the same machine by just entering in the host name. Flush your local DNS --> ipconfig /flushdns 1
talksr Posted October 15, 2015 Author Posted October 15, 2015 Flush your local DNS --> ipconfig /flushdns I tried that, but same error Tried it on the server also.
mikkydoos Posted October 15, 2015 Posted October 15, 2015 When you flush DNS you only really need to do it on the client. The client stores it's own local DNS records too, in case it can't contact the DC. I reckon a good thing for you to do would be to set up Scavenging on your DC. It will periodically delete any unused records and keep your DNS nice and tidy. What are you getting that error from --> Windows Explorer ? 1
mikkydoos Posted October 15, 2015 Posted October 15, 2015 Oh... and go into your DHCP... right click server option for your scope and double check that ::1 hasn't been entered in the DNS server option - for both IPv4 and IPv6. Also check that your PC hasn't got ::1 set for its DNS too.
Trojan Posted October 15, 2015 Posted October 15, 2015 Great article on DNS Scavenging: Don't be afraid of DNS Scavenging. Just be patient. - Microsoft Enterprise Networking Team - Site Home - TechNet Blogs 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now