angrycomputingteacher Posted February 17, 2018 Posted February 17, 2018 Hi everyone, I'm having an issue with one of my machines. Its not getting group policies. When I run gpupdate /force I get the following error: Name resolution failure on current domain controller. I only have one domain controller that serves AD, DNS, Files and storage services, IIS and WDS. The machines DNS points to the DC just like all the other machines. I've even rebuilt the machine and changed its name but it still happens. All my other machines work fine. When I preform a nslookup of the domain name and the DC name the DNS request times out. Is there any way to fix this?
ZeroHour Posted February 17, 2018 Posted February 17, 2018 Do pings work properly? Although you have done a rebuilt what AV do you use?
angrycomputingteacher Posted February 17, 2018 Author Posted February 17, 2018 Do pings work properly? Although you have done a rebuilt what AV do you use? Yep, pings work correctly. I use Immunet AV.
ricki Posted February 17, 2018 Posted February 17, 2018 Some quick checks If you move the pc to another part of the network does it do the same. Have you tried another nice?
angrycomputingteacher Posted February 17, 2018 Author Posted February 17, 2018 It's a laptop. It doesn't work if its connected via WiFi or via Ethernet.
strawberry Posted February 17, 2018 Posted February 17, 2018 Can you resolve on the DC? Does the laptop resolve addresses using another DNS server? (nslookup http://www.bbc.co.uk 8.8.8.8)
TwistedHelixis Posted February 18, 2018 Posted February 18, 2018 This will probably be duplicate ip listed in dns and dhcp. Check dns in the server, find the laptop ip and see if you have another client with the same ip listed.
angrycomputingteacher Posted February 18, 2018 Author Posted February 18, 2018 The laptop can resolve DNS servers (internal and external) and can resolve websites. I've set up static IP addresses for the laptop.
Meldrew Posted February 18, 2018 Posted February 18, 2018 Try disabling IPv6 and see if that makes a difference? Edit: realised a name change has already been tried.
forkies Posted February 18, 2018 Posted February 18, 2018 What firewall settings are on the laptop, does it specify what network type it is. I assume as your rebuilt it, you manage to domain it, but can you try re-domaining the laptop. Also check event logs on the laptop to see if any more details available.
angrycomputingteacher Posted February 19, 2018 Author Posted February 19, 2018 Yep. I've wiped it and reloaded it. I've also disabled IPv6 on both the Wireless and Ethernet adapters. Windows Firewall is enabled on the machine and is using the normal settings. It's on a domain profile. Even when I disconnect it from the domain and connect it again, still no group policies are applied. It's really strange. I still get the same error in the event viewer.
LeMarchand Posted February 19, 2018 Posted February 19, 2018 The laptop can resolve DNS servers (internal and external) and can resolve websites. I've set up static IP addresses for the laptop. Yep. I've wiped it and reloaded it. I've also disabled IPv6 on both the Wireless and Ethernet adapters. Windows Firewall is enabled on the machine and is using the normal settings. It's on a domain profile. Even when I disconnect it from the domain and connect it again, still no group policies are applied. It's really strange. I still get the same error in the event viewer. [ATTACH=CONFIG]47751[/ATTACH] When I was getting those sort of errors everything was otherwise working fine, but as @TwistedHelixis said This will probably be duplicate ip listed in dns and dhcp. Check dns in the server, find the laptop ip and see if you have another client with the same ip listed. there were a load of duplicates in DNS.
angrycomputingteacher Posted February 20, 2018 Author Posted February 20, 2018 I've just removed all computers from DNS, removed the cache and restarted the DNS server but its still not working. There are no duplicates.
psydii Posted February 20, 2018 Posted February 20, 2018 re-enable ipv6. Disabling it is a desperate troubleshooting measure (which in this case didn't work) and can break other things. Are you still unable to resolve the DNS name of the DC? ping the DC's IP, then check the arp cache and confirm that mac address for the DC is as expected (assuming a flat network, if you have servers of different subnets your computer won't have an arp entry for the DC) I notice that your FQDN ends in a .internal; I wonder if there is some software on the problem PC that is getting confused by this. Try disabling the Bonjour /mdns service on the computer and rebooting. Also check the windows\system32\drivers\etc\hosts file - any odd entries in there? Is the DC your DNS server? Eitherway confirm the DC is actually listed in the DNS zone along with the appropriate service records. If the computer joined the domain correctly (check the computer object properties modified and pwdlastset date), then perhaps there is a policy applying to this machine that breaks it? Use GPMC to evaluate what GPOs apply and see if anything odd turns up. Finally I have seen some problems solved by clearing Local Group Policy. (This is a really long shot) See the section "How to reset all Group Policy objects using Command Prompt" on this page: https://www.windowscentral.com/how-reset-local-group-policy-objects-their-default-settings-windows-10
angrycomputingteacher Posted February 20, 2018 Author Posted February 20, 2018 I can ping myserver.domain.internal fine. I can also ping the DC by it's IP address. How do I check the ARP cache? Everything is on one subnet. No odd entries in the hosts file. Yes, my domain controller is everything (AD, DNS, WDS etc.). The DC is listed in the DNS zone. AD says pwdLastSet was 19th Feb 17. I'll try clearing local GPOs tomorrow. Need to leave now.
ricki Posted February 20, 2018 Posted February 20, 2018 Try this one https://support.microsoft.com/en-gb/help/2421599/windows-7-clients-intermittently-fail-to-apply-group-policy-at-startup
psydii Posted February 20, 2018 Posted February 20, 2018 Can the client browse: The share \\dc.yourdomain.internal\sysvol? How about \\yourdomain.internal\sysvol? Finally \\dc's_IPADDRESS\sysvol? Also we missed getting resultant set of policy from GPMC.
angrycomputingteacher Posted February 22, 2018 Author Posted February 22, 2018 The machine can browse all the shares. I'll updates you soon on the GPMC part.
angrycomputingteacher Posted February 23, 2018 Author Posted February 23, 2018 I've just checked on GP RSOP and it's not getting any domain policies. Just local ones.
psydii Posted February 23, 2018 Posted February 23, 2018 Can you confirm the pwdlastset property again?
angrycomputingteacher Posted February 24, 2018 Author Posted February 24, 2018 Can you confirm the pwdlastset property again? pwlastset is "19/02/2018 17:29:59 GMT Standard Time"
psydii Posted February 24, 2018 Posted February 24, 2018 Ok just checking that there was a typo the first time around. Unfortunately I am stumped. It has updated its account, it can browse the share, but it won’t apply any domain group policies either at boot , login or when gpudate /force is run. The only error is the one posted above. It occurs any time domain policies should be applied, again: boot, logon and at gpupdate. You can logon with non cached domain accounts. The machine has been wipe and re-imaged to no effect. Ok. Thought of something: Make a note of the AD OU that the computer account is in. Make a note of what groups the computer account is in. On the computer dis-join it from the domain. Then Rename the computer. Delete the computer account from ad. Delete the dns entry for the computer. Delete the dhcp lease for the computer. Reboot the computer. Confirm new name and lease on DNS and DHCP Servers. Rejoin the domain. Reboot and confirm group policies, the AD OU and the computer object’s group memberships.
angrycomputingteacher Posted February 24, 2018 Author Posted February 24, 2018 Ok just checking that there was a typo the first time around. Unfortunately I am stumped. It has updated its account, it can browse the share, but it won’t apply any domain group policies either at boot , login or when gpudate /force is run. The only error is the one posted above. It occurs any time domain policies should be applied, again: boot, logon and at gpupdate. You can logon with non cached domain accounts. The machine has been wipe and re-imaged to no effect. Ok. Thought of something: Make a note of the AD OU that the computer account is in. Make a note of what groups the computer account is in. On the computer dis-join it from the domain. Then Rename the computer. Delete the computer account from ad. Delete the dns entry for the computer. Delete the dhcp lease for the computer. Reboot the computer. Confirm new name and lease on DNS and DHCP Servers. Rejoin the domain. Reboot and confirm group policies, the AD OU and the computer object’s group memberships. Hmm, sounds like a plan. I'll try it on Monday.
angrycomputingteacher Posted February 26, 2018 Author Posted February 26, 2018 Hmm. I've just done what you have said and I pinged the laptop from the domain controller and the request times out every time.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now