robjduk Posted August 4, 2016 Posted August 4, 2016 Hello, Got a huge problem at the moment where half the machines dont load profiles or group policies but its not localised to a certain computer, switch, DC etc.... Long story short, all Windows servers are happy but found putting a search into Google for "spanning tree login issues" brings huge results. Have asked my support company to remove spanning tree in a vague hope it cures the issue. My question is does anyone think I could be right? They are not convinced but after 3 days they are no nearer fixing it and becomming desperate. Thanks
pantscat Posted August 4, 2016 Posted August 4, 2016 (edited) If spanning tree is configured correctly, it definitely won't cause the type or problems that you're seeing - and to be honest I've never really seen it cause any problems at all. If it's happened very suddenly without any configuration changes or devices being added to the network, it's likely to be either a network loop (e.g. someone has plugged both ends of a network cable into a switch - but spanning tree should stop this!), or it's a faulty piece of hardware connected to your network that is swamping your network with rubbish. Your support company should be able to look at your network infrastructure and the port statistics and get an insight into what is going on. [Edit] @mukz has a good point - start with the obvious! :-) Edited August 4, 2016 by pantscat
robjduk Posted August 4, 2016 Author Posted August 4, 2016 event logs say everything is peachy and not to worry but its all going wrong It just randomly happened one afternoon and really clutching at straws Even to the point where we went and unplugged the 20 computers we put in on the day it happened incase there was some WOL packets being sent out by the hardware.
pantscat Posted August 4, 2016 Posted August 4, 2016 Is there no pattern at all? Not affecting a particular network segment? Any other network performance issues?
pete Posted August 4, 2016 Posted August 4, 2016 (edited) What's DNS like? Does dcdiag /q and repadmin /replsum come back clean? What's your spanning tree root set to? (show spanning-tree on Procurve kit, probably similar on Cisco). Check the port counters on your core switch(es) - are you getting dodgy packets from anywhere? High amount of dropped packets from a particular edge switch? Ultimately if you can't pin it down you're going to have to remove uplinks between switches and test where it happens/never happens. Edited August 4, 2016 by pete
pantscat Posted August 4, 2016 Posted August 4, 2016 "show spanning-tree root" will do it for a Cisco switch. "show spanning-tree summary" - will show general info.
robjduk Posted August 4, 2016 Author Posted August 4, 2016 dcdiag and similar all come back clean and not a good switch person myself but have an HP certified guy in tomorrow. Other than that, no events in the logs, random computers accros the site including wireless clients on different vlans. Tried setting static addresses, disabling ip6, increasing the wait for network time to 90 seconds and nothing... honestly its mad. You login and its fine. Restart the machine and sign in with the same account and the desktop will not have redirected. Happening over 8.1 and 10 clients to both staff and student logins. Really put a downer on my summer so far Ta all so far. Just hope my engineer can shed a little light on it tomorrow for me.
mukz Posted August 4, 2016 Posted August 4, 2016 Question: have you changed any gpos around? Can u add a new machine to the network directly attached to the core switch and see if the issue replicates.
robjduk Posted August 5, 2016 Author Posted August 5, 2016 no gpo has changed other than changes to attempt to fix this. I will try plugging some directly into the core today but it sometimes happens to my VM's and im directly into the core ta all
ITGURU Posted August 14, 2016 Posted August 14, 2016 Are you using Spanning tree or not. If not, run a wireshark capture and filter for STP that will tell you what is broadcasting. I used this to turn STP off on all my switches as do not use it.
robjduk Posted August 14, 2016 Author Posted August 14, 2016 Turns out (and only just fixed)... it was some permission problem with DFS shares. Totally mental though as a user could sign in correctly one time but 2 minutes later on exactly the same account on exactly the same computer it would fail. - - - Updated - - - thanks for all suggestions by the way.
FN-GM Posted August 14, 2016 Posted August 14, 2016 I used this to turn STP off on all my switches as do not use it. You should never ever turn off spanning tree. If you have a loop it can bring down the entire LAN.
Michael Posted August 15, 2016 Posted August 15, 2016 I can't see why spanning tree would be the issue - as others have stated, if a storm is deliberately created by a loopback, you get absolutely nothing - no logons or anything as the network is busy. My gut instinct is DNS - how many DNS Servers are in your network?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now