Disease Posted September 6, 2016 Posted September 6, 2016 Hi all, Very strange network problem at the moment, we combined our admin and curriculum networks over the summer into 1 and now we seem to be having major network lag. We also added a new core switch and upgraded some links to 10GB. Ping times are fine, the problems I am having are with file access times, login and internet. You can log in eventually and when you get in a click on a folder you end up waiting for the folder to display the contents while the green bar moves slowly up, network printing is slow everything is just deathly slow. Any ideas as I am beginning to lose the little hair I had in the first place.
FN-GM Posted September 6, 2016 Posted September 6, 2016 It sounds like it could be a DNS issue, I would investigate that first. What switches do you have? Thanks 1
Gibson335 Posted September 6, 2016 Posted September 6, 2016 Yeah, I'd agree on DNS being the first thing to look at. 1
Disease Posted September 6, 2016 Author Posted September 6, 2016 HP Switches with the odd 3com, I should add that I moved to vlans and then back to everything in default vlan again during the summer (long story) so the gateways and subnet masks were all changed from /16 to /24 and then back to /16.
Davit2005 Posted September 6, 2016 Posted September 6, 2016 Few things to suggest. Something on default vlan, switching loop, spanning tree issues, once logged in try running %logonserver% and see if it resolves correctly to one of your DCs. If it takes a while to logon then could be an issue with that DC. If you changed vlans did you do anything with subnet mask or default gateways??
Blue_Cookeh Posted September 6, 2016 Posted September 6, 2016 Are all the clocks correct on your computers? Could be an authentication issue, too. Check: DNS Time Static IP config on your servers AD Replication health
Disease Posted September 6, 2016 Author Posted September 6, 2016 I changed all the subnet masks to /24 and the gateways to the vlan interface, and then changed them all back again to /16
Davit2005 Posted September 6, 2016 Posted September 6, 2016 (edited) Try running this on one of your DC/DNS servers. dcdiag /test:dns /v /s:SERVER . Along with the normal DCDIAG Edited September 6, 2016 by Davit2005 1
Disease Posted September 6, 2016 Author Posted September 6, 2016 Try running this on one of your DC/DNS servers. dcdiag /test:dns /v /s:SERVER . Along with the normal DCDIAG Ran those all tests passed, it's almost as if computers are having to discover everything for the first time.
Davit2005 Posted September 6, 2016 Posted September 6, 2016 Are these fresh built PC's or existing. Maybe a GPO causing issues, redirected profiles etc?? 1
FN-GM Posted September 6, 2016 Posted September 6, 2016 and then changed them all back again to /16 eeeek!! That range is massive! That can cause performance issues itself! 1
Disease Posted September 6, 2016 Author Posted September 6, 2016 Yeah it's the range given to us by the LA, I did introduce vlans this summer to break it up into smaller segments but had to change back after the LA internet would not work as it was dropping our vlan traffic. Now I have all this slowdown.
FN-GM Posted September 6, 2016 Posted September 6, 2016 (edited) Yeah it's the range given to us by the LA, I did introduce vlans this summer to break it up into smaller segments but had to change back after the LA internet would not work as it was dropping our vlan traffic. Now I have all this slowdown. I would look at getting a router or firewall to NAT the traffic then you can vlan to your hearts content. EDIT: Might be best to use a router avoid any issues with traffic being blocked. Edited September 6, 2016 by FN-GM
Gibson335 Posted September 6, 2016 Posted September 6, 2016 I would look at getting a router or firewall to NAT the traffic then you can vlan to your hearts content. +1 for this - best thing we did here.
Davit2005 Posted September 6, 2016 Posted September 6, 2016 I'm glad I haven't had any LA network contraints as yet in any educational support role for 7 years. The last school that we had our Internet connection through the LEA was backed off to Virgin, enough said lets just say the support was only marginally better than home user support or worse.
Disease Posted September 6, 2016 Author Posted September 6, 2016 I have a router, but not great on NAT, will have to have a read up on that. Thanks though.
FN-GM Posted September 6, 2016 Posted September 6, 2016 I have a router, but not great on NAT, will have to have a read up on that. Thanks though. What router is it?
Disease Posted September 6, 2016 Author Posted September 6, 2016 What router is it? I say router, I mean L3 switch HP 5406Rzl2
FN-GM Posted September 6, 2016 Posted September 6, 2016 I say router, I mean L3 switch HP 5406Rzl2 It probably won't support NAT. I have never seen a L3 switch that supports NAT. Usually you will need a router. 1
Blue_Cookeh Posted September 6, 2016 Posted September 6, 2016 I say router, I mean L3 switch HP 5406Rzl2 Create a point to point VLAN with a /30 subnet between your L3 switch and the county's router, then continue to VLAN to your heart's content, no need to faff with NAT. 1
Davit2005 Posted September 6, 2016 Posted September 6, 2016 (edited) Create a point to point VLAN with a /30 subnet between your L3 switch and the county's router, then continue to VLAN to your heart's content, no need to faff with NAT. I don't think this will work, it still needs to use NAT. All the internal IPs on different vlans need to map to one ip address the router will then send traffic back/to that one ip address where the NAT can do the rest. i.e. Many to one NAT adressing Edited September 6, 2016 by Davit2005
FN-GM Posted September 6, 2016 Posted September 6, 2016 I don't think this will work, it still needs to use NAT. All the internal IPs on different vlans need to map to one ip address the router will then send traffic back/to that one ip address where the NAT can do the rest. i.e. Many to one NAT adressing It should work in theory, however there might be other things configured on the country router that may break it. NAT will solve that. 1
Davit2005 Posted September 6, 2016 Posted September 6, 2016 It should work in theory, however there might be other things configured on the country router that may break it. NAT will solve that. Yep if there are any services inside i.e. webmail these may need a bit more work but not impossible.
ITGuyWestMidlands Posted September 7, 2016 Posted September 7, 2016 Assuming the subnets fall inside the current range. Otherwise the la router will need to know your internal networks in order to route to them
mukz Posted September 7, 2016 Posted September 7, 2016 (edited) Create a point to point VLAN with a /30 subnet between your L3 switch and the county's router, then continue to VLAN to your heart's content, no need to faff with NAT. +1 This is what we do, we then tell the LA what IPs from their given range need to be special and job done. Edited September 7, 2016 by mukz
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now