Jump to content

Recommended Posts

Posted

Hi

 

Could someone help my brain has gone blank.

 

The network is a windows 2003 domain with xp clients. Its been running great guns for the last 18 months with no major hassle. In the last couple of weeks logons have started running slower and slower. Now some of my oldest machines are taking 4 minutes to log on.

 

I have tried nslook up on all my dns servers and everything appears ok.

 

I have checked the replication of dns and active directory and that appears ok.

 

I have done dc and net diag and the only error it comes up with is it fails on the wins server that I dont have.

 

I have tried pinging servers by name and ip and thats ok.

 

I have checked and the User Profile Hive Cleanup Service tool was deployed to the network ok.

 

I have had a look at the eventvwr and the only thing of any consequence coming up is the restrictions I have put into gpo to stop students using the intel graphics utilities.

 

I have set up verbose logging on a client and I have no big delays between entries. The only thing I have found is some entries re the User Profile Hive Cleanup Service saying something like cannot find and trasting as default. I am sorry I am at home now and cannot remember the exact woring.

 

I have tried removing the User Profile Hive Cleanup Service tool and that does appear to help a bit.

 

When the user logs on it appears to get stuck on applying user settings and once that is done the rest including the log on scripts go fast.

 

Has anyone got any ideas? Plus I have been looking at the setupapi.log do I have to look at any other log files for a clue at whats wrong.

 

Thanks for all your help.

 

Richard:(

Posted

if you've got a hub or a managed switch, you can packet sniff all the network traffic from a pc in question using another computer running wireshark configured with an ip filter connected to the same device.

 

managed switches often let you echo all traffic to one port. hubs do it by design. If you use an unmanaged switch you'll only see broadcast traffic and you want to see everything.

Posted
How big are your roaming profiles? As they grow they take longer and longer to load. Check them out. Some folder redirection, cookie deletion and recycle bin emptying may be in order.
Posted
How big are your roaming profiles? As they grow they take longer and longer to load. Check them out. Some folder redirection, cookie deletion and recycle bin emptying may be in order.

 

This.

 

Our number #1 culprit for slow logons used to be the Application Data folder being used as a dumping ground for cache or temporary files by poorly-written programs. We now redirect it to a network share.

Posted
Hi ... It might be worth checking your CPU usage on the server using task manager .. I had a problem a while ago with a corrupt application process hogging the CPU which was constantly on 100% .. That slowed down my logons as the CPU was busy doing something else all of the time ...
Posted (edited)

HI

 

I have used a program called policy reporter and enables the userenv logging and it says its definitely internet explorer branding.

 

reporter.JPG

 

I have checked and I have sp2 on my servers which all run windows 2003. I dont have roaming profiles, they load a default profile from the server and then all the settings are done with group policy.

 

I redirect the desktop, my documents, and the favorites folder.

 

The backbone of the network is fiber now and the same log on times are all over the school irrespective if you plug into the switch with the server on it or the far side of the school so I dont think its a backbone problem.

 

I have checked the servers and the cpu usage is between 15 and 55% and the bandwidth usage of the network cards is normally under 20%. I have run the raid testing on my main dc and the raids appear ok.

Edited by ricki
Posted

HI

 

I have just been reading about asyncronous logons and it says enabling it will speed up logons on windows xp.

 

"Configuring Synchronous Processing

 

Windows 2000 and Windows 2003 Server computers process foreground policy synchronously by default. Windows XP processes foreground policy asynchronously by default. In order to enable synchronous processing (at startup/logon) on Windows XP, you must ensure that the following policy is enabled (and disabled/not configured on Windows 2000/2003):

 

Computer Configuration\Administrative Templates\System\Logon\

"Always wait for the network at computer startup and logon"

 

This setting ensures that policy completes before the startup/logon is completed. The change to the default setting on Windows XP was designed to speed up startup and logon processing. However, when performing configurations that must take effect before the end-user has access to his/her desktop, synchronous processing must be enabled."

 

Does anyone use this and what sort of effect will this have on the network?

 

Richard

Posted

Attached the hotfixes I got to fix the same problem (I'd love to give credit to whoever sent them me, but I can't remember :()

 

As I remember, you'll need to search the MS knowledge base as you need to make a registry change to enable to the hotfix (for some reason!?)

IE7Hotfixes.zip

  • Thanks 1
Posted

Hi

 

I have just tried the fix and this one is not needed as it was meant to be fixed with windows xp sp3 that I have installed. I have read a couple of articles that say that sp3 with I have half rolled out in the school has a log on speed bug lols

 

Oh Lovely

 

Richard

Posted

Arr I have found why the asyncronis log on has not been used on the network waiting for the network adds 1 minute 20 secs to the log on times.

 

Richard

Posted

With 10 Servers to choose from you have plenty of potential reasons for your logon times to go through the roof.

 

If this has happened suddenly not steadly I would start with the obvious, check your login scripts.

 

Just one tiny typo or modification you did without checking it properly will kill your login times dead!

 

I recently answered a call from a client who's login times had gone through the roof and suspected a network issue.

I plugged in the Fluke In-Line Nettool and booted the machine and as described it hung.

The Fluke showed the machine was trying to resolve an http address but hadn't actually logged in yet.

Bingo! Checked the login script and somehow somebody had tried to map a drive letter to url instead of a UNC path!

 

Problem solved in less than 4 mins.

One quick rem statement and login back to 30 seconds again.

 

I love my Fluke Kit...

Posted
Computer Configuration > Administrative Templates > System

 

"Verbose vs normal status messages"

 

If you enable this, it gives you more info on what's happening at boot/logon (I personally left it on, the kids see the words change more and it appears "quicker" to them)

 

 

Ive been using XP for years and never knew about that! Thanks :)

 

The extra info flashes by a bit quick to read but it could be useful if it gets stuck on something. Shame it doesnt say exactly which GPO it is processing, think it does with Vista doesnt it?

Posted
We had a similar problem with XP clients, it was unrelated to GP - actually had some DNS issues with a rogue router handing out the wrong primary DNS IP. If the primary DNS didn't point to the main DC/DNS controller for us, it would hang at that point for ages. Soon as you switch it back, sorted. I had a KB article bookmarked somewhere but can't lay my hands on it at the moment...
Posted
Fluke In-Line Nettool sounds like a nice piece of kit but then I looked at the price. Ouch its expensive.

 

Richard

 

£2000 with the Voip Option and I just bought the Etherscope II with all the options as well ...

I would rather spend all the profits on test gear than give it to Gordon in taxes to waste on BSF and the Financal Sector Bail Outs....

Posted
Just a thought on slow logins ... do you have your DNS servers IP set in the workstations Primary DNS servers setting? This can make a hugh difference in login times if you havent ..
Posted
Might be worth changing to mandatory profiles, it only took me 30mins to do and cut our school wide login times by about 50%.
Posted

Probably not your issue but someone might find this relevant...

 

We were having logon speed issues at the start of lessons (after a final big switch from Windows 2000 to XP), after much investigating it was our application server which was suffering - we have as much software as possible run from a server rather than locally installed.

 

We have a single madatory profile which contained shortcuts to the networked apps.

 

AT logon Windows XP would look at/open every application pointed to from the start menu, so the app server was being hit by hundreds of requests for every available .exe.

 

The reason seemed to be that Windows XP was trying to populate its iconcache.db file - for Windows 2000 this was a system file on a given PC, for XP it's personal and PC specific.

 

XP stores the file in profile\local settings\application data, luckily a populated iconcache.db file will be downloaded from a mandatory profile even though it's in "Local Settings".

 

To further alleviate the problem, I've set the shortcuts to mostly be stored in the local alluser profile (having them in a single mandatory profile made management very easy).

 

This was compounded by the antivirus software scanning each .exe as it was opened - scarily we have one which is a few 100Mbytes, even though it was set not to !

 

(I think the av issue was it using actual server paths even though everything we have is accessed via DFS.)

  • Thanks 1
Posted

On the primary dc its got 127.0.0.1 as its dns.

 

I have been doing some checking of the other server and one of them is down to 8% free space so I am working on that now, but I will come back to this.

 

Richard

Posted (edited)

hmm,

 

We have our Primary DNS pointing to DNS 2 and secondary at itself, then Secondary DNS points to DNS 1 and secondary as itself. (needs to be changed really to involve our 3rd DC...)

 

It might be an idea, if you haven't already, to look into consolidating GPO's - the more individual GPO's it has to process the longer it takes, less GPO's quicker processing (I found), still have the same level of security and same bits and pieces going out, but this time in half the total number of GPO's... you could also look at comparing the times of two PC's which are slow whereby one has software deployed to it via GP/AD and the other doesn't. I never really looked into it much, but I've suspected for a while now that in our domain at least, PC's with assigned software installs are more sluggish than those which don't have software assigned.

 

@sidewinder, I don't remember Vista ever telling me what GPO it was currently processing, then again, not a lot of GPO's applied to my Vista machine. Windows 7 isn't telling me much in that way either. All 3 do tell you that they're applying the Default Domain Policy, that's the only one I've ever really seen.

Edited by DrPerceptron

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...