jjohnsoncantell Posted April 14, 2011 Posted April 14, 2011 Guys, I have just completed an domain & server upgrade to 2k8r2. 2 old 2k3 servers demoted l/rebuilt and promoted back. The issue I'm having is the clients are taking a long time to start up and when they logon they can't get mapped drives via script. The event logs have 1054 errors saying it cant access the policy and gptinit errors where logon scripts aren't running. For some reason I can't access the scripts folder on dc01 which is the first dc. I can't access the c$ admin share or browse the server in network neighborhood. However I can browse and see the c$ share on dc02 which was the second to be promoted, I can see the sysvol of that server also. There don't seem to be any dhcp/dns issues as the servers can be pinged resolved and nslookup is working as expected. Is there any special security setting I have missed? I built both the servers in the same way too.. Thanks for any help! James
sukh Posted April 14, 2011 Posted April 14, 2011 Hi Can you check the permission for Sysvol for both DC's and check they are the same? Sukh
glennda Posted April 14, 2011 Posted April 14, 2011 Also check the replication service is running or us something like sonar to check replication status
jjohnsoncantell Posted April 14, 2011 Author Posted April 14, 2011 Thanks for the replies guys. I haven't checked the sysvol sukh, will do first thing when i get in. I think the reason i hadn't already checked that was because I couldn't even browse that server so I assumed it was a different issue. Never can tell with server though lol. I checked with repadmin and it reported that the replication had occurred. The annoying thing is that I wasn't aware of this problem before I bought the second dc in so I can't say whethe that had played a part in it.
bio Posted April 15, 2011 Posted April 15, 2011 definatly a sysvol issue. this may point in the right direction. bio..
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 will check all the above guys, for now ive attatched a dcdiag to see if you can see any issues. Jamesjj.txt
pantscat Posted April 15, 2011 Posted April 15, 2011 James - did you upgrade the schema on the domain before you started?
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 i did indeed... adprep/forestprep followed by adprep/domainprep
pantscat Posted April 15, 2011 Posted April 15, 2011 Ok - fair enough - just thinking out loud as it were. (BTW - the attachment isn't a DcDiag output.)
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 lol omg im a total muppet, heres the proper attachment...dcdig.txt
psydii Posted April 15, 2011 Posted April 15, 2011 (edited) I'm not a 2k8 expert, but here's where I'd start based off the info from dcdiag.txt: The one item in the dcdiag log that leaps out as a concern is 'DC01 failed test NCSecDesc' hopefully a sequential reboot of the DCs should clear it up, but if not the BPA might help guide you through the fix. Reboot DC1 and wait for replication to start working (watch it in the event log, it took about 20 minutes to report back ok last time according to dcdiag) Once DC1 has confirmed replication is ok.... Reboot DC2 and wait for replication to start working. Reboot a workstation and run your tests again. If the problem persists I'd then use the AD DS BPA, which may be a little more illuminating than dcdiag. Final thought: if you create a new user account on a DC (once replication is working) can you then log on to a workstation using that account? Edited April 15, 2011 by psydii
sukh Posted April 15, 2011 Posted April 15, 2011 post the results of the BPA. Also see Dcdiag fails for NCSecDesc test on Windows 2008 Domain Controllers Sukh
psydii Posted April 15, 2011 Posted April 15, 2011 edit: ninja'd Sukh's five seconds ( )with google suggests that the error I highlighted is probably unimportant, however for me 'best practice' is to configure one's system so that the diagnostic tools report back without error or warning, so it's still where I'd start. If a solution doesn't jump out to you (or someone else here doesn't provide a definitive answer) I would be very wary of making random changes to AD and sysvol in an attempt to fix it. If you've got the cash, an early call to MS PSS (c£200) could save you a lot of unnecessary work and stress. If that's not an immediate option, then try replicating the situation in a VM environment by restoring your last known good backup of your DCs into a clean VM and running the upgrade again (keeping the environment isolated from your live domain of course!) - from here you can mess around, fiddle, test and roll back without danger of making things worse. P.
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 i looked at that NCSecDes article also and i did look at running that during the dcpromo stage but i was never going to be using read only controllers so i didnt run it. Will run the bpa and post results. i cant help thinking its some sort of access issue. I should be able to browse dc01 via network neighborhood but i cant, it tells me i dont have permission to use the network resource. What could be causing that?
psydii Posted April 15, 2011 Posted April 15, 2011 The obvious answer is that you're not using an account that is authorised to access that resource. Once you've restarted the DC's and cleared out any errors from BPA, can you log on to a workstation using an account created after the upgrade? Are the clients XP or 7? If XP what does netdiag report? Not sure what tool replicates that functionality in Vista or 7.
sukh Posted April 15, 2011 Posted April 15, 2011 @psydii - It was a suggestion in case RODC were/are being used. The issue and root cause are unknown. Putting in a call to MSFT is the best option in any case. However, given this situation, turn-around for initial response will be 4 hours, then after that no guarantee and impact is minimal, i.e you have another DC, also no users are effected. But like I say, MSFT is you best contact or your support provider. However, the articles I normally post here do NOT always been YOU should do it. If they are specific then I will make sure I state that. In this case I suggested 'Also see'. I expect one to read any post/KB articles before making a change to the production enviornment or if they take the risk and not to then it's up to them. Changing settings on the infrasructure should be thought of carefully. Sukh
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 looks like the two largest files are 10mb each, which is some sort of log. The rest are anything up to 2mb
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 thats what i would assume that meant... Im pretty sure the problem is linked to dc01. When i did a reboot on dc02 i could view the network and see what was there but not the browse those machines, however as soon as dc02 came back up i could browse to the machines and see printers/shares
psydii Posted April 15, 2011 Posted April 15, 2011 @sukh I quite agree, I found that article just after you did and the initial version of my post I berated myself for not googling it before posting. The article's phrasing suggest to me that the error itself is not cause for concern, but whether root causes are related is one avenue for investigation. I do read the impact of this problem differently though: GP is not applying on at least 50% of clients properly and logons are very slow - in an environment where each workstation logs on/off 6+ times a day, to me that's a huge impact! After BPA results, the next big question is: Are the Clients Authenticating to the Domain properly? Which is what we'll find out with the new user test.
psydii Posted April 15, 2011 Posted April 15, 2011 @jjohnsoncantell After rebooting the servers in the order advised, are there unresolved errors in the event logs on either server? Could you clarify exactly what steps you took that provided evidence for the following statement: "When i did a reboot on dc02 i could view the network and see what was there but not the browse those machines, however as soon as dc02 came back up i could browse to the machines and see printers/shares" Specifically expanding around the following phrases "i could view the network" "see what was there" "but not browse those machines" Have the workstations been restarted and logon speeds tested following the DC reboots?
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 ok For example, i can browse network neighborhood and see a list of clients. I can browse into a client and see the printers & faxes/sheduled tasks. However, when i reboot dc02 i loose that ability even though dc01 is still up and running. As soon as the server has rebooted and back online i can again browse those clients as before. If i however go to browse dc01 at any time, i get the dc01 in not accessible error with a reason of network path not found.
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 i dont notice any red event errors in application, system, dfs, dns, file replication logs.
psydii Posted April 15, 2011 Posted April 15, 2011 Have you got an output from the AD DS BPA? Have you rebooted the client computer since the server reboots? Are you logged on as an Domain/Enterprise Administrator? What OS are the clients running? If XP what is the output of netdiag? Is DC02 your WINS server? Can you browse DC01 from DC02? I note from your DCDiag report that both DCs appear to agree that DC01 holds all the FSMO roles and that replication is working. I also note that no further indication that this assessment should be changed since reboot as the event log is showing without further errors.
jjohnsoncantell Posted April 15, 2011 Author Posted April 15, 2011 Yes i have rebooted the clients. Ive been logged onto the server with domain admin account and can browse from dc01-dc02 and vice versa and can see the sysvol and netlogon shares. The clients are running xpsp3. Wins isnt installed as far as im aware as we're only xpsp3 clients and above. Attatched is a readout of net diag from a problem client. Makes reference to spn issues. Thanks for your time helping me, its much appreciated!netdiag.txt
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now