Jump to content

Recommended Posts

Posted (edited)

Hello everyone,

Any ideas around this one would be appreciated.

Every Thursday a small company I help out get into work and have no internet on their machines that use the DC (SVR-01) as their DNS, as a test one machine has the router (BTBusiness one we have no real access to) as their secondary DNS and that one can still get internet.

The DC (SVR-01) can still be pinged and tracert but the Host that VM it is on (HYP-01) cannot be pinged or tracert, it as if it is no longer on the network. It cannot be pinged by machines or by the VM on it but machines can still ping and tracert the guest on it. I can also still get onto it externally with screen connect.

If you reboot the Hypervisor all returns back to normal and will remain normal till the next Thursday.

It used to do it on a Monday, then after some Windows updates on a weekend, the issue moved to a Thursday....I haven't been able to try a great deal, as the issue occurs very early hours on a Thursday morning, and they need to be up and running by 8am, so I have a tiny window in the morning to try stuff, then have to wait a week to see if it works.

The Host is a HP Micro server Gen10 and is running Server Core 2019 (Hyper-V) and the domain controller is Server 2019 Essentials.

Checked error logs and there are no obvious system logs just one warning at around the same time the issue starts on both the SVR and the HYP that DNS failed to resolve for screen connect.

Hoping to get together ideas from fresh eyes, my next test a friend suggested is to disable VMQ as there are reports of this causing random connectivity issues on HP servers - my only concern there is this is practically a scheduled issue.

 

EDIT: The host can still ping the guest while its having this issue but not vice versa.

Thanks in advance.

Edited by QwertyMash
Posted

Completely standard no additional configuration cisco switch that the landlord of the building had installed, this is partly why some of helping this little company is hard, there is a server room / comms room but the landlord doesn't allow access to it so its just stock single vlan configuration across the full switch, going up to the BT business router the ISP put in.

 

Hopefully nothing switch related as thats never been changed.

Posted

I did have an issue once where port-security was enabled on the cisco switch. This limits the number of MAC addresses that can connect via one port, to stop people spoofing MAC addresses and getting a copy of all the traffic. As a VM host has 1 MAC for itself, and the one for each VM, at a minimum, it showed up as either the Host or a VM was able to connect to the network, but not both, and it randomly swapped when rebooting.

 

If the Guest can't ping the host, that's probably not it though.

 

Network drivers on host and VM? Is there only 1 VM? Maybe install debian or something to have another VM to test that's a bit different.

 

Leave a ping -t running and see when it fails, or when both fail. At the same time? Exactly?

Posted

So if I've got this right -

 

BT Router, connecting into a Cisco switch which has been VLAN'ed per floor or company (which is fairly typical).

 

Your local company has a DC which is also acting as DNS/DHCP roles presumably? I'd suggest setting DNS forwarders to 8.8.8.8 and 8.8.4.4 which are Google DNS and are very reliable, unless there's a reason not to?

 

I'm not too concerned your cannot connect to the Hyper-V host, as clients are only connecting to your DC guest for authentication and possibly DNS/DHCP/File/Print (as a guess). I'm again presuming the Hyper-V host is literally just that and no other roles, which would be the correct method?

 

A few questions though -

 

Is the Hyper-V host standalone or domain joined?

 

How does the IP config on the Hyper-V host compared to the Guest DC?

 

And if you look at Task Scheduler on the Hyper-V host, is there anything in here?

Posted
So if I've got this right -BT Router, connecting into a Cisco switch which has been VLAN'ed per floor or company (which is fairly typical).

No sorry the switch is dedicated to his company.

 

 

Your local company has a DC which is also acting as DNS/DHCP roles presumably? I'd suggest setting DNS forwarders to 8.8.8.8 and 8.8.4.4 which are Google DNS and are very reliable, unless there's a reason not to?

 

The use the DC for DNS but not DHCP as I had no access to the router to disable its DHCP, I am currently in talks with the manager of the building to let me have access to it so I can disable DHCP and have the Domain Controller run DHCP.

The DNS forwarders are pointed to Googles DNS :)

 

I'm not too concerned your cannot connect to the Hyper-V host, as clients are only connecting to your DC guest for authentication and possibly DNS/DHCP/File/Print (as a guess). I'm again presuming the Hyper-V host is literally just that and no other roles, which would be the correct method?

 

Yeah it is just a Hyper-visor nothing else. And yes clients are only connecting to the DC for authentication, DNS and print.

 

A few questions though -

Is the Hyper-V host standalone or domain joined?

How does the IP config on the Hyper-V host compared to the Guest DC?

And if you look at Task Scheduler on the Hyper-V host, is there anything in here?

 

It is domain joined.

It is the same subnet, and default gateway, with the DC as DNS and its x.x.x.250 where as the guest OS IP is x.x.x.251

 

And the task scheduler just has the usual default stuff nothing else. Other than running Server core with the hypervisor role and being domain joined its practically stock.

 

 

 

Thank you very much

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...