SHimmer45 Posted June 13, 2018 Posted June 13, 2018 even if the firewall is turned off if a rule is not set to allow it will open the port it will be denied iirc
abillybob Posted June 13, 2018 Author Posted June 13, 2018 (edited) One thought if you're running the Unifi controller on the same host - the Unifi controller probably runs a TFTP server to push out firmware updates so that could be causing the problem, what happens if you disable the Unifi controller then restart the WDS service? At least just to rule it out if anything. Turned it off still the same problem can't access tftp from the client even if the firewall is turned off if a rule is not set to allow it will open the port it will be denied iirc Do you happen to know what port I should allow. That doesn't seem right though because when the Windows Firewall was blocking some ports for Unifi and I turned it off it worked then Edited June 13, 2018 by abillybob
SHimmer45 Posted June 14, 2018 Posted June 14, 2018 "The following UDP ports need to be open for WDS to work across a firewall: 67, 69, and 4011 for DHCP and TFTP; 64001 through 65000 (random ports from this range are used by TFTP and for multicasting); and 68 if DHCP authorization is required on the server" microsoft do a small util (portqry) which you run from a machine and point it at your server to see if ports are open worth checking this
abillybob Posted June 14, 2018 Author Posted June 14, 2018 Ok so something weird is going on. I came in this morning and a computer that was still pointing to PXE boot by accident had started up MDT and all was working fine this morning. I've just tried again on another computer, same VLAN and nothing again? Like seriously wtf! All I've done in-between is restart the server. I have WSUS on it also if that make any difference?
abillybob Posted June 14, 2018 Author Posted June 14, 2018 Also I've added those ports to the firewall but to no avail
abillybob Posted June 14, 2018 Author Posted June 14, 2018 Any other ideas I'm starting to rock in the corner of the room
SHimmer45 Posted June 14, 2018 Posted June 14, 2018 ports are open and being shown as accessible no from a client. when you say one worked when this morning did you leave it overnight and when you came in it was was on the MDT screen?. both the MDT and WDS servers can ping each other & can you ping them from the client that you are trying to PXE boot from.
abillybob Posted June 14, 2018 Author Posted June 14, 2018 ports are open and being shown as accessible no from a client. when you say one worked when this morning did you leave it overnight and when you came in it was was on the MDT screen?. both the MDT and WDS servers can ping each other & can you ping them from the client that you are trying to PXE boot from. Hi Mate Yes I've opened all the ports but nothing has changed I don't know how this other computer got onto the screen, I didn't purposely leave it on over night. The user turned it on in the morning and called me up asking what MDT was as it was displaying on their screen. Unfortunately I was working from home remotely for a couple of hours this morning so I stopped the WDS service and asked them to reboot which got them back into Windows but I couldn't check to see if other computers where working there and then. As soon as I got back into work I got hold of another computer started the WDS service back on and nothing again? But was definitely working this morning as he sent me pictures of the screen!! Nothing had changed all I did was stop and start the WDS service again. MDT and WDS are running on the same server, yes I can ping them and I can ping the DNS name of the server from the client.
abillybob Posted June 14, 2018 Author Posted June 14, 2018 The client machine just sits there looking for DHCP if that helps? Although if you boot the client computer into Windows the DHCP server does give it an IP address?
Ephelyon Posted June 14, 2018 Posted June 14, 2018 Even though you've tried booting a client on the same VLAN as the PXE server, I think it's still something to do with the way VLANs/routing is being handled by your switches. What I'd suggest is: grab a cr*ppy old hub (or cheapo unmanaged switch) from somewhere and hook your PXE server (or host if it's a VM) and a test workstation into that and see if the latter can boot from it. If they suddenly can, your problem is probably somewhere on the switching side. If they still can't, I'd say it's somewhere on the server side.
abillybob Posted June 14, 2018 Author Posted June 14, 2018 I can't do that. It's a virtual server which runs all the others on it. Doing so will take down the factory so I'm kind of stuck
SHimmer45 Posted June 14, 2018 Posted June 14, 2018 put money on the clients are taking and age to contact the DHCP and get a response back
dapaulio Posted June 14, 2018 Posted June 14, 2018 (edited) put money on the clients are taking and age to contact the DHCP and get a response back My initial thought was iphelper on your switch and dhcp options but if you have exhausted that option then A way to test this theory is press pause break button on your keyboard whilst pxe is getting a dhcp Wait say 20 seconds then press any key to continue Edited June 14, 2018 by dapaulio
dapaulio Posted June 14, 2018 Posted June 14, 2018 Your core switch will have vlans setup something like in my screenprint. (mines a HP switch) where an IP helper is required on the clients vlan you then need to go into dhcp and scope options of the same vlan and add option 66 and 67 like in the my other screen I hope this helps
Katy Posted June 14, 2018 Posted June 14, 2018 you then need to go into dhcp and scope options of the same vlan and add option 66 and 67 like in the my other screen I hope this helps To add to this, I've found that although option 66 is called "Boot Server Host Name" it only works if you put in the IP rather than hostname.
dapaulio Posted June 14, 2018 Posted June 14, 2018 To add to this, I've found that although option 66 is called "Boot Server Host Name" it only works if you put in the IP rather than hostname. Yes good shout I also found this
Davit2005 Posted June 15, 2018 Posted June 15, 2018 I can't do that. It's a virtual server which runs all the others on it. Doing so will take down the factory so I'm kind of stuck Could you test with a VM attached to the Virtual Switch? Even though it is virtual you should be able to set the option to boot from network, you can in ESXi for sure.
abillybob Posted June 15, 2018 Author Posted June 15, 2018 Okay. ESXi, is it? Or Hyper-V? Or Xen etc? Hyper-V put money on the clients are taking and age to contact the DHCP and get a response back I've tried it on several different clients all the same problem. Different branded computers too My initial thought was iphelper on your switch and dhcp options but if you have exhausted that option then A way to test this theory is press pause break button on your keyboard whilst pxe is getting a dhcp Wait say 20 seconds then press any key to continue How do I pause it? Doesn't give me a button to press?? [ATTACH=CONFIG]49341[/ATTACH] [ATTACH=CONFIG]49342[/ATTACH] Your core switch will have vlans setup something like in my screenprint. (mines a HP switch) where an IP helper is required on the clients vlan you then need to go into dhcp and scope options of the same vlan and add option 66 and 67 like in the my other screen I hope this helps Cheers already tried this though and can't get it to work. I have an IP helper in each VLAN going to use it pointing to my DHCP server and the WDS Server. I have tried configuring Option 66 & 67 using the hostname, fqdn, IP address. Nothing seems to change the outcome. Could you test with a VM attached to the Virtual Switch? Even though it is virtual you should be able to set the option to boot from network, you can in ESXi for sure. Good idea I'll give this a go and let you know the outcome
Ephelyon Posted June 15, 2018 Posted June 15, 2018 Hokay then. If you did want to try the "use a cr*ppy hub" option, you could always temporarily unteam one of your host NICs and connect it physically to this testing hub, then create a new External vSwitch in Hyper-V specifically for that NIC and then point your MDT VM at that vSwitch instead. Then connect a testing workstation to said hub to test it. That won't affect the rest of the virtual host running the factory then. That way, you'd eliminate whether it has anything to do with the VM's configuration specifically vs something switchy.
Katy Posted June 15, 2018 Posted June 15, 2018 How do I pause it? Doesn't give me a button to press?? Pause button on the keyboard on the client, it's at the top near Scroll Lock and Print Screen. If DHCP is being slow, hitting Pause while it tries to get an IP, waiting a bit then hitting Enter to resume will give it a bit more time to respond. (Obviously not a fix but a good troubleshooting item) 2
abillybob Posted June 15, 2018 Author Posted June 15, 2018 I have our Layer 3 Routing switch setup like this on the VLAN, 192.168.33.2 is the DHCP server and WDS is .3 --------interface Vlan207 ip address 192.168.33.254 255.255.255.0 ip helper-address 192.168.33.2 ip helper-address 192.168.33.3 -------- In DHCP scope I've tried setting the 66 hostname to "deploy.business.local" "deploy" "192.168.33.3" and I have tried each with option 67 checked and un-checked. I've also added it to Server options and tried that on/off but to no avail I don't get it how did it work the other day on that random computer but now won't work at all on any of them!! Grrrr!
abillybob Posted June 15, 2018 Author Posted June 15, 2018 Pause button on the keyboard on the client, it's at the top near Scroll Lock and Print Screen. If DHCP is being slow, hitting Pause while it tries to get an IP, waiting a bit then hitting Enter to resume will give it a bit more time to respond. (Obviously not a fix but a good troubleshooting item) Well you learn something new everyday! That has made it work... Seriously what on earth!! Is there any easy way to make the clients respond faster in order for them to pick up DHCP as it's a big pain in the rear to be pausing them all and things just to get them to boot. Weird thing is I have HP machines and Lenovo machines both of which do the same a pause for 10 seconds and a restart gets them to load!!
abillybob Posted June 15, 2018 Author Posted June 15, 2018 I've read that enabling Rapid Spanning Tree on the switch should fix it but not really sure what this does and wouldn't want to take things down? Do I enable this on just the core switch or also all the other switches?
Katy Posted June 15, 2018 Posted June 15, 2018 I had an issue with DHCP being slow in some areas.... unfortunately can't remember how I solved it
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now