Gongalong Posted August 19, 2021 Posted August 19, 2021 Hi folks, I'm after some help with a domain authing issue. As background, we have a small forest with a root domain, and two child domains. We use Hyper-V, and have two core servers where there are VMs for DCs in each of the three domains (all Windows Server 2019). We have a separate physical server which also runs VMs with another set of DCs for each of the three domains. Over the Summer hols we've had lots of electrical work which has meant shutting down the core servers. These were started up again today, but the electrical contractors unwittingly turned off the separate physical server. The separate server will need to be shut down next week anyway, as they do electrical work in that building. I'm not brilliant with DCs, and these were setup by a predecessor, but my understanding is that as we have two DCs in each domain they should still work if the other DC has been shut down. We have done brief maintenance before when one server has been shut down, and it has seemed to work, but it was brief. This doesn't seem to be the case though with one of the particular child domains as I can't access resources in that domain, and I can't logon to a PC in that domain. I have rebooted the DCs, and the servers I am trying to access, and still cannot get this particular child domain to work. I have had a look at the Event Viewer for a PC where I have tried to access shares in the problem domain, but it doesn't give any clear errors. When I try to RDP to a server in the domain I get an error relating to Network Level Authentication. I can see some errors on the problem DC in the AD log, but they seem to relate to being unable to contact the other DC, which is as expected. Any ideas how I can troubleshoot this? Thanks
HPlum78 Posted August 19, 2021 Posted August 19, 2021 So NLA errors seem about right for a domain that cannot be authed against. On the DC in the child domain that is not working has the DC actually started servicing the domain? Are there any 4013 events, there may also 2087/ 2088 events (from memory) my initial thoughts are DNS not being initialised, but happy to be wrong. 1
Gongalong Posted August 19, 2021 Author Posted August 19, 2021 I was digging through similar posts and found one that asked for a bunch of diagnostic information. I did an IPCONFIG and spotted that the DC is using an APIPA (Automatic Private IP Addressing) address (!). The reason being that there's a duplicate IP on the network. How?! I've used NBTSTAT to try and figure out what the machine is that has the address but I get a "NO HOST" response. I've used another tool to try and interrogate the IP and it's not giving me any information. How do I find out what this duplicate IP is being used by?
Gongalong Posted August 19, 2021 Author Posted August 19, 2021 I figure it out using nmap. Using that I spotted the devices were using Hikvision NICs. Hikvision = CCTV cameras. Some contractor must have added IP based cameras on the network without checking, and one of them was using the DC's IP address. Needless to say there will be words with them tomorrow. 2
HPlum78 Posted August 19, 2021 Posted August 19, 2021 Good work glad you have sorted it, yeah someone needs a tactical boot in the onions! 1
HPlum78 Posted August 19, 2021 Posted August 19, 2021 If you know that you are going to be without DCs for a while there are a few things that you can do to help you and your clients. You should probably move the FSMO roles to the remaining DC and there are a few reg keys that you can use to change the weights of certain aspects of DC priority and such likes. We have a procedure to follow when a DC is going to be out of service for a period of time. I will share the details if it would be useful. 2
Davit2005 Posted August 20, 2021 Posted August 20, 2021 I figure it out using nmap. Using that I spotted the devices were using Hikvision NICs. Hikvision = CCTV cameras. Some contractor must have added IP based cameras on the network without checking, and one of them was using the DC's IP address. Needless to say there will be words with them tomorrow. OMG what is the matter with these people, we had one unplug networking equipment to plug a monitor in once. Rushed over there to investigate the problem jus as the contractors were leaving the comms room. Lets jus say we were not pleased either. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now