RE: Cannot add workstation to domain when negotiating ISL on Cisco routers.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Robert Greene [MSFT] (a-robgre_at_online.microsoft.com)
Date: 08/05/04


Date: Thu, 05 Aug 2004 16:03:07 GMT

First, make sure that any End station ports are configured for Port Fast
and NOT SPANNING TREE on the switches.

If this is correct, on the workstation at a command prompt type the
following:

ping <Remote DC Name> -f -l 1492

it does not ping the more then likely your router is fragmenting packets.
Kerberos Packets by default use UDP. You can keep lowering the -l
parameter until you find where the pings start succeeding then use the
following article to configure Kerberos Over TCP to be used after packets
get so big:

244474 How to force Kerberos to use TCP instead of UDP
http://support.microsoft.com/?id=244474

Also Verify that the following Ports are allowed through the Router:

179442 How to Configure a Firewall for Domains and Trusts
http://support.microsoft.com/?id=179442

Best regards:

a-Robgre@online.microsoft.com

This posting is provided "AS IS"
with no warranties, and confers no rights



Relevant Pages

  • Re: DCPROMO RPC error
    ... Promote a Domain Controller over an IPSEC VPN - Kerberos over tcp - ... Kerberos uses connectionless UDP datagram packets. ... you change MaxPacketSize to a value of 1, you force the client to use TCP ...
    (microsoft.public.windows.server.active_directory)
  • Re: DCPROMO RPC error
    ... Over the weekend I was involved in Joining a Windows 2003 server in the US to our domain here in Sydney over an IPSEC VPN. ... Kerberos uses connectionless UDP datagram packets. ... Depending on the virtual private network hardware configuration, these larger packets have to be fragmented when going through a VPN. ... Because UDP is a connectionless protocol, fragmented UDP packets will be dropped if they arrive at the destination out of order.If you change MaxPacketSize to a value of 1, you force the client to use TCP to send Kerberos traffic through the VPN tunnel. ...
    (microsoft.public.windows.server.active_directory)
  • Re: IPTABLES configuration [help]
    ... INPUT allow related and established packets and ping packets. ... Delegate TCP and UDP to seperate chains. ... doesn't allow any UDP packets through to the ports. ... LOGDROP just LOG and DROP packets, ...
    (comp.os.linux.security)
  • Re: block CodeRed/Nimda at the firewall?
    ... I don't think it would help sending out icmp packets ... I only send UDP and TCP packets to the LOGREJECT ... I drop some of those early in my INPUT chain. ... I have a few ports where I DROP instead of using ...
    (comp.os.linux.security)
  • RE: IM Programs
    ... want to block these ports. ... you don't need an explicit deny for the other ports. ... Access-list 101 deny any tcp any any eq 5000 ... >Now, when applying these to your firewall, make sure the number ...
    (Security-Basics)