RabbieBurns Posted May 28, 2012 Posted May 28, 2012 I am seeing this on my network a lot more than I should. 90% of my clients are wireless and i have been putting massive resources into resolving any possible wireless issues, but Im seeing these on a few too many desktops now which is starting to raise concerns. I have the FSMO PDC which is a physical box, and I have 2 virtual DC's which are on the same SAN but on 2 different hosts. What would i be looking for on my network which would cause a client to be unable to authenticate with either 3 of the DCs ?
FN-GM Posted May 28, 2012 Posted May 28, 2012 I would start looking at DNS. Does everything look healthy there? 1
soveryapt Posted May 28, 2012 Posted May 28, 2012 I had this for a while. I found out it was our AV software (Sophos) that was temporarily disabling the network cards on boot up which mean if you logged on too quickly, it didn't see the servers and reported that problem, but you waited another minute then it was able to log on. When this happens now, it only seems to be on laptops when someone has disable the wireless, so I don't know if that was the only issue, but it just seemed to be a time thing. 2
SYNACK Posted May 28, 2012 Posted May 28, 2012 Yea, check the network stack. It's likely to be IP based due to drivers taking too long to resolve an initial IP connection. With wireless make sure that the wireless profiles are machine based not using user credentials. You could also try something like this although it may have some side effects: Hi There, We had the same issues. This link might have the answer - /var/log/metasplo.it: Windows 7 wireless NIC not initializing before netlogon service
RabbieBurns Posted May 28, 2012 Author Posted May 28, 2012 I had this for a while. I found out it was our AV software (Sophos) that was temporarily disabling the network cards on boot up which mean if you logged on too quickly, it didn't see the servers and reported that problem, but you waited another minute then it was able to log on. When this happens now, it only seems to be on laptops when someone has disable the wireless, so I don't know if that was the only issue, but it just seemed to be a time thing. We use sophos. I haven't bothered updating the Enterprise Console in a while (4.7 i think atm) as the plan is to go with SCCM 2012 as soon as I get time. And as you say, the problem isn't consistent, a few tries after the machine starts up and it logs in OK. I wonder if it could be the same here. Do you have any other anecdotal evidence @FN-GM, DNS is fine, Ive made sure the 3 DC's are the only DNS servers. @SYNACK thanks, I will test that out. Not sure what would cause that on a wired client altough I will check to see if there are any startup scripts happening.
Michael Posted May 28, 2012 Posted May 28, 2012 Other factors as well as DNS could be the number of WAPs you have as well as the amount of memory in workstations. It's not difficult to do on wireless clients (if you're too quick to logon), but it's exceptionally rare on Ethernet connections in my experience. Wireless is slower than wired and of course a lack of memory just means clients have to work harder until it dynamically receives an IP from DHCP Server. I suppose other things to check are your servers. Are they replicating correctly? Opening up Active Directory Sites and Services and you can manually force them to replicate.
SYNACK Posted May 28, 2012 Posted May 28, 2012 Not sure what would cause that on a wired client altough I will check to see if there are any startup scripts happening. If you have STP turned on in the switches this is more likely and should be set to RSTP/Portfast. Also if you have intel GB NICs there is an advanced setting "Wait for Link" which should be set to "on" as otherwise the driver will not wait for IP connectivity at all by default. The default setting is 'auto' which is wrong and causes issues. Some other cards have simmilar settings and these can help hugely with initial network issues. The other thing to check is that the drivers are up to date and also if the machines have AMT/vPro you may need/want to upgrade the BIOS to the latest version as sometimes the managment stuff gets in the way of the network sensing at the exact wrong time. 1
Pete10141748 Posted May 28, 2012 Posted May 28, 2012 I see this sometimes as well, having mostly wireless laptop here. I've had problems with laptop wireless cards not picking up a signal until after logon creating all kinds of logon problems. Sophos can cause issues, another thing I've had to deal with here. It mght also help to make netlogon service in Win7 not dependant on user login; sc config netlogon depend= wlansvc/lanmanworkstation Run that as a batch file, or just type it into CMD while logged on as someone with admin rights. It seems to have helped here!
RabbieBurns Posted May 28, 2012 Author Posted May 28, 2012 Ive just ordered another 30 Aps to pretty much do 1 AP per classroom at the moment its 2 APs for every 3 classrooms. Ive also recently just audited all the channels as our system doesn't seem to adjust the channels of each AP automatically depending on the surroundings, even when set to channel "auto", and have removed hopefully some interderence from AP channel overlap. Regarding @Michael how would I check if they are replicating correctly ? Is SCOM something i should be looking at to help me audit the event logs of all my servers? @SYNACK thanks I have tried this method on a couple of troublesome devices, eg. our Dell Latitude ST slates which are up to date with the latest driver on the dell website. STP is enabled on all of our switches, I have not heard of RSTP/Portfast I dont think. The desktops experinecing issues seem to mainly be Dell Optiplex which are GBE but Im unsure of the chipet off the top of my head
bondbill2k2 Posted May 28, 2012 Posted May 28, 2012 I had this for a while. I found out it was our AV software (Sophos) that was temporarily disabling the network cards on boot up which mean if you logged on too quickly, it didn't see the servers and reported that problem, but you waited another minute then it was able to log on. When this happens now, it only seems to be on laptops when someone has disable the wireless, so I don't know if that was the only issue, but it just seemed to be a time thing. Had the same problem here now only occurs when disabling the wireless so I normly tell people who find their wireless turned off to flick it on the reboot.
soveryapt Posted May 28, 2012 Posted May 28, 2012 Nothing more anecdotal to add sadly. It was something I found out in a conversation with our LEA Technical Team who (until next week) look after the admin machines in the school, so I was trying to resolve an issue where the deputy head was logging on but not getting network drives, and this was because Sophos was doing the whole "lets turn the network cards off for this check" at startup, but left an extra 30seconds or so and it worked fine. Generally, by the time the staff member calls me up and I go to check on their laptop or the trolley laptops in question, I walk into the room and Sophos has done it's thing and they work when I log on with the test student / test staff account (I avoid using mine simply through the fact, for a majority I have logged on previously during deployment, so I have a few test accounts that I rotate to be sure they're not in the cache of the machine somewhere). I think the only other thing that caused this for me was when I had one laptop in particular that had simply decided it didn't want to take the GPO settings from the server anymore, but with a quite gpupdate /force, it rectified itself. It's quite rare that I do get the logon servers unavailable message, and it is more with the staff and students who can type quickly.
Michael Posted May 28, 2012 Posted May 28, 2012 Regarding @Michael how would I check if they are replicating correctly ? Is SCOM something i should be looking at to help me audit the event logs of all my servers? On your either of your DCs open Active Directory Sites and Services > Default-First-Site-Name > Servers. Expand SERVERNAME, then click on NTDS Settings. To the right, it should display . Right click this and select 'Replicate Now'. You should receive the message 'Active Directory Domain Services has replicated the connections.' Repeat this for all listed DCs, so you know it works both ways. If one of your replications fail (for whatever reason) the odds are it is DNS related. DNS rules everything in Windows Server.
psydii Posted May 28, 2012 Posted May 28, 2012 (edited) I think what you really need is this hotfix: Event ID 5719 and event ID 1129 may be logged when a non-Microsoft DHCP Relay Agent is used While you are at it try deploying the hotfixes listed here http://www.edugeek.net/forums/windows-7/95480-disabling-offline-files-server-2008-win-7-pro.html#post832973 (you probably wont need to disable offline files once this lot are installed - but you will want to stop automatic caching of redirected folders) Pick a group of laptops first as a control and monitor user happiness. Edited May 28, 2012 by psydii
witch Posted May 28, 2012 Posted May 28, 2012 Yea, check the network stack. It's likely to be IP based due to drivers taking too long to resolve an initial IP connection. With wireless make sure that the wireless profiles are machine based not using user credentials. You could also try something like this although it may have some side effects: I had the same issue on my network and I followed the first part of these instructions - "Fixing the netlogon Service" It worked like a charm and has almost eradicated the problem.I have not seen any side effects of any kind and I did this about 3 weeks ago. Give it a go! 1
cpjitservices Posted May 29, 2012 Posted May 29, 2012 If you have STP turned on in the switches this is more likely and should be set to RSTP/Portfast. Also if you have intel GB NICs there is an advanced setting "Wait for Link" which should be set to "on" as otherwise the driver will not wait for IP connectivity at all by default. The default setting is 'auto' which is wrong and causes issues. Some other cards have simmilar settings and these can help hugely with initial network issues. The other thing to check is that the drivers are up to date and also if the machines have AMT/vPro you may need/want to upgrade the BIOS to the latest version as sometimes the managment stuff gets in the way of the network sensing at the exact wrong time. I Agree, but be careful enabliong RSTP/Portfast - make sure your network is correctly configured the last thing you want is switch loops! I'd check your DNS settings on the sever that is rolling out your IP's via DHCP make sure the DNS settings are correct and are being configured properly.
RabbieBurns Posted May 29, 2012 Author Posted May 29, 2012 On your either of your DCs open Active Directory Sites and Services > Default-First-Site-Name > Servers. Expand SERVERNAME, then click on NTDS Settings. To the right, it should display . Right click this and select 'Replicate Now'. You should receive the message 'Active Directory Domain Services has replicated the connections.' Repeat this for all listed DCs, so you know it works both ways. If one of your replications fail (for whatever reason) the odds are it is DNS related. DNS rules everything in Windows Server. There is a lot of food for thought in this thread, but before I try anything else I would like to comment on @Michael here. I have gone to this location and am surprised to see old Domain Controllers that were demoted long ago. Although they have no NTDS info under them, they are still listed. Should i just delete them from here? Replicating from each of the 3 to their other 2 completed without errors.
Michael Posted May 29, 2012 Posted May 29, 2012 Yes - it is safe to delete old DCs from here. If they have no NTDS under them, it means they've been demoted as DCs. And if your servers replicated OK manually, then that's great news 1
RabbieBurns Posted May 29, 2012 Author Posted May 29, 2012 Thanks so can rule out DNS etc. Ill look at the HotFix's and the service dependencies, and sophos next 1
billyf Posted October 3, 2012 Posted October 3, 2012 Hey, i have been having this problem with netbook used my the children. How would i go about stopping Sophos from disabling the wireless cardsat startup? thanks
soveryapt Posted October 3, 2012 Posted October 3, 2012 Hey, i have been having this problem with netbook used my the children. How would i go about stopping Sophos from disabling the wireless cardsat startup? thanks You wouldn't. It's part of it's startup checks to make sure all is safe on the computer. All you need to do it just wait for 30 seconds or so before you log on and that should all be good. Failing that, if you have a hard key method to turn the wireless card off then back on (Be it a dedicated key or switch or an Fn + Key method). It's a bit of a bug bear, but to be honest, with the latest version of Sophos (done through updates) it's been a lot less noticeable.
morganw Posted October 3, 2012 Posted October 3, 2012 This might be worth a look. Windows 7 Clients intermittently fail to apply group policy at startup 1
ZeroHour Posted October 3, 2012 Posted October 3, 2012 This might be worth a look. Windows 7 Clients intermittently fail to apply group policy at startup Wow! thats a really useful thing to know.
soveryapt Posted October 4, 2012 Posted October 4, 2012 This might be worth a look. Windows 7 Clients intermittently fail to apply group policy at startup Well, even though it's not happened for a while, I'll set this just in case me thinks! lol ..
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now