RODC looses link to main domain
i got strange situation. there technical info below, if needed. in order avoid myself making boring introduce problem before (in couple of words).
thus, after every reboot or shutdown of rodc system, rodc cannot authenticate user. reported "there no servers can perform authentication request available" or that. users "allowed rodc password replication group" cannot access system. local users or groups absent (rodc). how fix? switch patch-cord 1 network adapter another, wait couple of seconds, , switch cord first adapter. voila! how work? happens when adapters changed?
now, configuration parameters. have win2008 r2 domain in 1 subnet (two domain controllers).
we have several identical win2008 r2 rodc in branch offices dns server , wsus replica server installed. same domain, other subnets (one subnet 1 branch), other sites (one site 1 branch).
on every rodc have 2 network adapters, setted different subnets: 1 branch network (for work) -- adapter 1, 1 hq network (for install, set etc.) -- adapter 2. in every network connection static ip address, net mask, default gateway , dns servers setted. different: every subnet own settings. in every moment 1 adapter connected, depending on server is: in branch office (working properly) or in hq office (maintenance).
when server stands in branch subnet (and site) adapter 1 connected. after shutdown or reboot server up, responding ping, available via rdp, reported address in dns (on hq) , wsus. cannot authenticate users, neither locally, nor through rdp. accordingly, seems me, problem domain services. when switch cord branch subnet adapter hq subnet adaprer, stop working (of course!). when switch cord branch subnet adapter start working including domain authentication! same situation when server stands in hq subnet (adapter 2 connected). after every reboot or shutdown server stops authenticate users until cord switched adapter 2 1 , turned back.
i cannot understand why stops working , how fixed. got "route print" , "ipconfig -all" in moment when authentication works , when not -- parameters identical. turned windows firewall off network types -- no change. people, please, understand what's going on? got many such rodc, , after every reboot have contact admins in branch offices in order ask him switch patch-cord. insane!
i see first problem multihomed dc can culprit confusing client ip used locate dc. suggest use 1 nic instead & disable other since multihoming of dc not recommended or practice. due dual nic 2 records published dns same machine & client instead of using correct record random record picked in round robin fashion & issues starts.
as aware, rodc registers site specific records in dns & 2 records published of same dc confusing clients. can follow below article configure selected ip used register or listen.
http://technet.microsoft.com/en-us/library/cc740071%28ws.10%29.aspx
make sure rodc point dns preferred dns server & other local dns server alternate dns server in nic. suggest updating nic & windows 2008 r2 dc latest service pack & patches can way proceed, since windows 2008 r2 sp1 has 800 fixes.
regards
awinish vishwakarma
my blog: http://awinish.wordpress.com
this posting provided as-is no warranties/guarantees , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment