googlemad Posted April 10, 2018 Posted April 10, 2018 We have a recurring problem roughly every 2 weeks and I'm really struggling to find out what is going on! Basically there is a website - the NHS ESR portal. You can now access it from anywhere at https://my.esr.nhs.uk, and will see a login page with a 'Access over the Internet has changed' message, a ping will resolve to 194.61.249.147 although won't actually 'ping' probably due to a firewall setting at the other end. If you're a NHS techie you'll know there is an additional network, N3, (or HSCN as it is going towards) for access to services only within a NHS network, so in our hospital if you go to the same URL, https://my.esr.nhs.uk it will point to a similar page but with a slightly different message at the top and routes through to a different IP (Can't remember the exact one off the top of my head but not the 194 one anyway). The problem we're having is as mentioned above every 2 weeks or so we suddenly get cut off from the N3 routed page and fail back to the Internet (194) site, which causes quite a few issues for certain departments as certain operations are only allowed via the more secure N3 route. Initially we thought this was maybe the firewall, something external, the network guys checked everything and then we found the resolution...as soon as we restarted our 3 internal (AD controllers) DNS servers and gave it 30mins-1hr it starts working successfully again for another 2 weeks before happening again! So I'm not sure what to try next, as it is really weird, with it being an external site we don't have any obvious records set up in DNS for it and the external DNS server settings are set to the correct ones as advised by N3 (194.72.7.137 and 194.72.7.142)
HPlum78 Posted April 10, 2018 Posted April 10, 2018 Hmmmm, so if you do a Nslookup from one of the DC's what is returned? Probably need to try this in both working and none working states. Could this be a cache issue? Have you done an Nslookup on both of the external NS servers when it is in both states? Just in case the records are ending up diferent. I am taking a guess that your internal clients point to the DC's for name resolution. Is the site behind any kind of LB? And when something happens (server reboot or the likes) is the LB nic being registered momentarily and then this address being cached potently. Theses are just my thoughts spewed out late night so if they help good if not its late and non sense! To be honest sounds to me like you have a good ol mystery there Scooby. Good luck. 1
themightymrp Posted April 11, 2018 Posted April 11, 2018 Have you tried running the Best Practises Analyzer from the DNS section of Windows Server Manager? Run the task on each of your DNS servers and see if it reports back any issues. 1
googlemad Posted April 17, 2018 Author Posted April 17, 2018 Still couldn't find anything obvious that was causing it so built a new DC and scrapped the dodgy one to see if that helps. The only difference is the 2 working DCs are Server 2012 R2 and the dodgy one was Server 2016, so we've made the new DC a Server 2012 R2 for consistency although that shouldn't really make that much of a difference considering the domain functional level is still 2008 R2 anyway!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now