dezt Posted April 15, 2011 Posted April 15, 2011 I'm having a bit of a nightmare at the moment, and hope someone can help. We had a dhcp server set up with a 192.168.x.x scope, this worked fine, but i've since found out that CLEO assign us a set of ip addresses which are in the 10.x.x.x range. So I have decided to move to the CLEO range of ip addresses by creating a new scope. I have setup all the scope options and when the clients pickup a new ip address it comes from the new scope, but I have an issue at the moment. In a group policy was the setting to set the DNS Server to the old 192.x.x.x address, so every PC now has a new ip address but when I do a nslookup it tries to go to 192.x.x.x I have done a bit of searching on the net and found where the setting was set and have removed it from the offending GPO, however, i've since found out that I can't do a gpupdate from the client as they are looking for the dns server to resolve the names. The only way around this I have found was to remove the DNSClient registry key from every PC, after this if I did a ipconfig /renew it would show my new ip address for the nslookup, and everything would resolve. I have then done a gpupdate /force and rebooted and everything seemed fine. That was until this morning, I have walked in and the DNSClient key has reappeared in the registry on some PC's, and it's showing the old 192.x.x.x dns setting rather than the new 10.x.x.x server. The strange thing is it isn't being applied through any of the group policies that i've looked at, so can't understand why it's coming back. Can someone please help me get rid of this setting. I finish today and then i'm on holiday for the next week, so really need to have this sorted by the end of the day.
sukh Posted April 15, 2011 Posted April 15, 2011 Hi Are you sure there are no other GPO's defining this? Do gpresults /z > c:\gp.txt and post/OM Are you sure DHCP is configured is configured properly, i.e the scopes? Check both the old and new for references to the old DNS server. Sukh
gshaw Posted April 15, 2011 Posted April 15, 2011 I usually set my DNS servers via DHCP scope options, have you got the new DNS address set there?
dezt Posted April 15, 2011 Author Posted April 15, 2011 I've set the DNS server in the scope options, and on some clients it works, but others put the dns server in from GPO, i can't see how as i've removed the setting, removed the registry key and run agpupdate /force to force the new policy on to the PC.
glennda Posted April 15, 2011 Posted April 15, 2011 I presume that the machines that are getting the GPO are in another OU with a seperate GPO giving them the DNS settings Do as Sukh says and post gpresults - this then will show what gpo's etc are being applied.
taff Posted April 15, 2011 Posted April 15, 2011 Have you checked that it's not set via the local policy? if the local policy is set, and the GPO(s) are "Not configured", then it will keep the local policy setting.
dezt Posted April 15, 2011 Author Posted April 15, 2011 Here's the gp.txt from a client that has picked up the old setting. GPO: Computers Setting: Software\Policies\Microsoft\Windows NT\DNSClient State: Enabled The gp.txt from a client that picked up the correct server didn't have this setting. The only difference I can see is the computers policy, which on one has the DNSClient, but on the other doesn't. Both PC's have had a gpupdate /force run yesterday and a reboot. After switching on today the setting is on one but not the other.
dezt Posted April 15, 2011 Author Posted April 15, 2011 the PC's don't have any local policies set, i ran rsop.msc and checked them, everything was empty. The strange thing is some computers in one ou will be ok, others will not. I've been round all 350 PC's and removed the setting manually and run a gpupdate /force so would have thought they would have brought the new setting down.
sukh Posted April 15, 2011 Posted April 15, 2011 @dezt - What I was looking for was for all the results from the out put. Also, if you can provide me or check your GPO settings in all your GPOs. You should be able to save this HTML and post/PM. I have only seen this once before and basicially the issue was with gpo tattooing. If you delete the DNS entry on the problematic PC, and do a gpupdate /force and/or reboot the machine, do the old DNS server entries come back? Sukh
dezt Posted April 15, 2011 Author Posted April 15, 2011 @sukh pm sent. When i delete the entry and do gpupdate /force, sometimes the settings come back, but on other PC's they don't. It's random.
glennda Posted April 15, 2011 Posted April 15, 2011 @sukh pm sent. When i delete the entry and do gpupdate /force, sometimes the settings come back, but on other PC's they don't. It's random. it sounds like there is a gp somewhere that is enforcing the dns setting. can you pm me a copy of gpresult from a machine without the problem and one with the problem?
p3dr0 Posted April 15, 2011 Posted April 15, 2011 hi if you have more than one DC check event logs for replication errors your changes might not be applied to another DC and pc's connecting to it will get old settings
dezt Posted April 15, 2011 Author Posted April 15, 2011 @glennda pm sent. @p3dr0 i've just looked at my other DC and the settings are correct in Group Policy.
glennda Posted April 15, 2011 Posted April 15, 2011 @glennda pm sent. @p3dr0 i've just looked at my other DC and the settings are correct in Group Policy. Just replied
p3dr0 Posted April 15, 2011 Posted April 15, 2011 have a look on that Group Policy does not apply when connecting remotely over a slow link: Group Policy your issue is really buggin me
dezt Posted April 15, 2011 Author Posted April 15, 2011 @p3dr0 reading that says that admin templates are always applied, even over a slow link. The issue's buggin you, i've been working on it for 3 days now, seriously thinking about going back to how things were before.
dezt Posted April 15, 2011 Author Posted April 15, 2011 If I was to change everything back to the 192.x.x.x addresses that we had, re set dns to 192.x.x.x and run gpupdate /force, would the correct settings be forced out? Or if I created a VM running dns and gave it an ip of 192.x.x.x would adding a host record for the DC and it's 10.x.x.x ip in there allow pc's to update the gpo?
p3dr0 Posted April 15, 2011 Posted April 15, 2011 you are right there, and i just have a bad feeling it will happened to one of our networks as we are thinking about updating our gpo's i dont know what to suggest maybe detailed logs will give you some more info: Userenv Logging Because Userenv tracks the Group Policy engine and registry-based Group Policy, it is the most frequently used log file for Group Policy troubleshooting. Userenv is especially useful in a Windows 2000 environment because you don't have the benefit of using Resultant Set of Policy (RSoP). Most of the questions that RSoP answers, are in the userenv log. To use userenv.log you need to first enable verbose logging. To enable verbose logging 1.Log onto the client computer as the administrator and run Regedit. 2.Locate the following key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon. 3.Right click Winlogon, select New, and then click DWORD Value. 4.Enter the following name for the DWORD Value: UserEnvDebugLevel. 5.Enter 30002 as the hexadecimal value. This writes the userenv into userenv.log, located in the \%windir%\debug directory. 6.Run "gpupdate /force" to ensure a full listing of total Group Policy processing. source: Fixing Group Policy problems by using log files: Group Policy
dezt Posted April 15, 2011 Author Posted April 15, 2011 Just to top things off, i've just noticed that when a pc is plugged into my switch for one of the it rooms, the switch stops functioning. what a great easter break i'm having. Maybe that's why the gpo wasn't updating in that room, i really hope so.
sukh Posted April 15, 2011 Posted April 15, 2011 If you are going to use logging, please set to 10002 (Hexadecimal).
sukh Posted April 15, 2011 Posted April 15, 2011 @dezt - If you have the issue again or has not been resolved, post back. Sukh
dezt Posted April 26, 2011 Author Posted April 26, 2011 Just got in today, the issue was still there. I've decided to set all my ip's back to my 192 range, and re-activate the 192 scope and deactivate the 10 scope. Hopefully after all the PC's have updated their gpo settings the issue will go away and I can then try again. Just got to switch on all the pc's in the school now.
dezt Posted June 1, 2011 Author Posted June 1, 2011 @sukh I've got back to this DHCP scope change now, after running the 192 scope since easter, everything seems to be going better now, the DNS settings are being pushed down by the DHCP scope, rather than GPO like they were. I've just got to change all the static ip's to the new range now and see how that goes. Fingers crossed.
sukh Posted June 1, 2011 Posted June 1, 2011 good, seems like it;s working....see how it goes throughout the day/week....if there's issues, post back.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now