Guest richard_s Posted August 4, 2009 Posted August 4, 2009 Got a bit of a strange problem with a new domain that I am setting up and I am hoping that you can shed some light on it. I have just built a new Domain Controller running 2003 R2 but when I join a PC to the Domain it does not run any Group Policies or the Logon script yet the script and policies run fine on the server itself. I have checked the Event Logs and nothing is showing up and I am now at a complete loss as to what is happening.
azrael78 Posted August 4, 2009 Posted August 4, 2009 Stupid question - is the PC moved into an OU in which the policies are applied? The lack of event viewer items is disturbing, what does your winlogon.log file on the workstation say? Az
Guest richard_s Posted August 4, 2009 Posted August 4, 2009 The Logon script is applied by the Default Domain Policy and the other policies are applied to specific OU's. I have just looked for the Winlogon.log file and one has not been created on either of the 2 test machines.
Ignatius Posted August 4, 2009 Posted August 4, 2009 I ran into a similar problem yesterday with my test setup. I hadn't configured the correct permissions on the logon scripts. Definitely a "senior" moment! Dunno if it's relevant to your scenario?
Guest richard_s Posted August 4, 2009 Posted August 4, 2009 I have checked the permissions and all seems fine with them. The strange thing is that the script and policies run fine when I logon to the server.
kmount Posted August 4, 2009 Posted August 4, 2009 What happens when you try gpresult on the client? Checked the time's are in sync etc?
Guest richard_s Posted August 4, 2009 Posted August 4, 2009 What happens when you try gpresult on the client? Checked the time's are in sync etc? I get the following message come up: INFO: The user "*********\admin" does not have RSOP data. By the way all the times are within 5 seconds of each other.
kmount Posted August 4, 2009 Posted August 4, 2009 Couple of ideas from google, tried accessing the sysvol share from the client? The user "xxx\xxx" does not have RSOP data. - Petri.co.il forums by Daniel Petri
mac_shinobi Posted August 4, 2009 Posted August 4, 2009 Couple of ideas from google, tried accessing the sysvol share from the client? The user "xxx\xxx" does not have RSOP data. - Petri.co.il forums by Daniel Petri As per kmounts comment on the link at the bottom comment is as follows : *bump still stuck on this one guys.... On the PC I noticed when logged in I cant browse to \\domain.local\sysvol\domain.local Windows can't find the network path... however the user authenticates with the server ok on login... the dir is accessible from every other PC on the network. It has to be dns, but dns seems fine. I'm baffled, a reinstall of windows is not something I want to go through with this PC as it has a lot of old software and developing tools installed. **Finally solved this one, had to reinstall the TCP/IP NetBIOS Helper and all is working fine now.
tmcd35 Posted August 4, 2009 Posted August 4, 2009 Heres a possibility - is your DNS set up correctly? Does all the AD stuff appear correctly in DNS? I not it could be worth restarting your NETLOGON service on the server and giving it another go. I've had a similar problem here and that is what it ended up being.
Guest richard_s Posted August 4, 2009 Posted August 4, 2009 I decided to rebuild the server as I could afford anymore time trying to sort it out. Blame my boss for giving me such a short time to role this thing out
Guest richard_s Posted August 6, 2009 Posted August 6, 2009 UPDATE - Spent all of yesterday rebuilding this server and I'm still getting the same issues with it. I'm beginning to wonder wonder if it is not the OS but a hardware issue
azrael78 Posted August 6, 2009 Posted August 6, 2009 It does sound like DNS, or some kind of DNS-related issue if it can't see the full DNS path of the server. As Geoff suggested - run netdiag (with the /v switch) - post it here so we can see. Just to rule out DNS or NETBIOS issues - can you PING the server using the following: 1) DNS Name (domain.local) 2) NETBIOS Name (server) 3) IP Address I suspect you can do #2 and #3, but not #1 - which suggests DNS or that there's something far more quirky going on. HTH, Az
Guest richard_s Posted August 6, 2009 Posted August 6, 2009 Here is the Netdiag results from the server. I have had to remove Domain and server details I'm afraid but the info should be useful. Microsoft Windows [Version 5.2.3790] (C) Copyright 1985-2003 Microsoft Corp. C:\Documents and Settings\admin>netdiag .................................... Computer Name: XXXXXXXXXXXX DNS Host Name: xxxxxxxxxxxx.xxxxxxxxxxx.local System info : Windows 2000 Server (Build 3790) Processor : x86 Family 16 Model 2 Stepping 3, AuthenticAMD List of installed hotfixes : KB923561 KB924667-v2 KB925398_WMP64 KB925876 KB925902-v2 KB926122 KB927891 KB929123 KB930178 KB932168 KB933854 KB936782 KB938127 KB938464-v2 KB941569 KB943055 KB943460 KB943729 KB944338-v2 KB944653 KB945553 KB946026 KB948496 KB950762 KB950974 KB951066 KB951748 KB952004 KB952069 KB952954 KB954550-v5 KB954600 KB955069 KB955839 KB956572 KB956802 KB956803 KB957097 KB958644 KB958687 KB959426 KB960225 KB960803 KB961118 KB961371 KB961501 KB967715 KB968537 KB970238 KB971633 KB972260 KB972260-IE8 KB972636-IE8 KB973346 Q147222 Netcard queries test . . . . . . . : Passed [WARNING] The net card '1394 Net Adapter' may not be working because it has not received any packets. Per interface results: Adapter : Local Area Connection Netcard queries test . . . : Passed Host Name. . . . . . . . . : xxxxxxxxxxxx IP Address . . . . . . . . : 10.41.44.51 Subnet Mask. . . . . . . . : 255.255.252.0 Default Gateway. . . . . . : 10.41.44.1 Dns Servers. . . . . . . . : 10.41.44.51 AutoConfiguration results. . . . . . : Passed Default gateway test . . . : Failed No gateway reachable for this adapter. NetBT name test. . . . . . : Passed [WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenger Service', <20> 'WINS' names is missing. No remote names have been found. WINS service test. . . . . : Skipped There are no WINS servers configured for this interface. Global results: Domain membership test . . . . . . : Passed NetBT transports test. . . . . . . : Passed List of NetBt transports currently configured: NetBT_Tcpip_{2251ECC1-7E6A-4D3D-956B-C9E023119CCA} 1 NetBt transport currently configured. Autonet address test . . . . . . . : Passed IP loopback ping test. . . . . . . : Passed Default gateway test . . . . . . . : Failed [FATAL] NO GATEWAYS ARE REACHABLE. You have no connectivity to other network segments. If you configured the IP protocol manually then you need to add at least one valid gateway. NetBT name test. . . . . . . . . . : Passed [WARNING] You don't have a single interface with the <00> 'WorkStation Servi ce', <03> 'Messenger Service', <20> 'WINS' names defined. Winsock test . . . . . . . . . . . : Passed DNS test . . . . . . . . . . . . . : Passed PASS - All the DNS entries for DC are registered on DNS server '10.41.44.51' . Redir and Browser test . . . . . . : Passed List of NetBt transports currently bound to the Redir NetBT_Tcpip_{2251ECC1-7E6A-4D3D-956B-C9E023119CCA} The redir is bound to 1 NetBt transport. List of NetBt transports currently bound to the browser NetBT_Tcpip_{2251ECC1-7E6A-4D3D-956B-C9E023119CCA} The browser is bound to 1 NetBt transport. DC discovery test. . . . . . . . . : Passed DC list test . . . . . . . . . . . : Passed Trust relationship test. . . . . . : Skipped Kerberos test. . . . . . . . . . . : Passed LDAP test. . . . . . . . . . . . . : Passed Bindings test. . . . . . . . . . . : Passed WAN configuration test . . . . . . : Skipped No active remote access connections. Modem diagnostics test . . . . . . : Passed IP Security test . . . . . . . . . : Skipped Note: run "netsh ipsec dynamic show /?" for more detailed information The command completed successfully C:\Documents and Settings\admin>
Guest richard_s Posted August 6, 2009 Posted August 6, 2009 It does sound like DNS, or some kind of DNS-related issue if it can't see the full DNS path of the server. As Geoff suggested - run netdiag (with the /v switch) - post it here so we can see. Just to rule out DNS or NETBIOS issues - can you PING the server using the following: 1) DNS Name (domain.local) 2) NETBIOS Name (server) 3) IP Address I suspect you can do #2 and #3, but not #1 - which suggests DNS or that there's something far more quirky going on. HTH, Az I cannot do #1 but #2 and #3 are fine.
Geoff Posted August 6, 2009 Posted August 6, 2009 also try running dcdiag on your server and try running netdiag on a client too.
Guest richard_s Posted August 6, 2009 Posted August 6, 2009 You were close by saying it a DNS issue. I dug around and found that it was the DNS server address in the DHCP server settings that for some reason was reverting to 127.0.0.1.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now