Re: Group Policy not applying

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 08/10/04


Date: Tue, 10 Aug 2004 04:09:08 GMT

Run netdiag on one of your domain computers to see if it shows any problems with
failed tests/warnings/errors relating to dns, dc discovery, kerberos, domain
membership/secure channel, etc. Also run gpresult on domain member as it will tell
the last time computer and user policy was applied and from what GPO's.It is highly
unusual to have domain controllers in a dmz [vpn might be a better solution] . If you
are using ipsec to secure communications through the firewall to the domain
controllers, that can cause problems as domain members can not use ipsec negotiation
for ESP/AH policies that involve communications with domain controllers. Anyhow see
the link below on what ports are required for AD to work through a firewall and pay
attention to the part about RPC and the challenges it makes and workarounds. It may
also help to view firewall logs for traffic dropped to and from domain controllers
and domain members. Looking in Event Viewer on all computers involved would also be
helpful. --- Steve

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B179442

"Curt Shaffer" <curt@chilitech.net> wrote in message
news:cf99m102g18@enews1.newsguy.com...
> I was given the task to implement SUS server on our network. I installed the
> server with SP1 and all went well. However I went over to the gpeditor and
> made the necessary changes and forced a refresh of the policy. It seems that
> the computers ignored the setting. I then tried to add some other random
> setting changes via GPO and they did not take either. Some of the previous
> policies are still working though. I turned on debugging on the workstation
> and I am getting the error: "Windows cannot obtain the domain controller
> name for you computer network. Return Value (59). It seems to be a DNS
> issue. I found a couple of suggestions on Google but nothing helped. There
> is a firewall between our workstations and Domain Controllers. We did this
> because we have people that need to access them from outside our company. I
> don't know if that is why this is happening and if so why do some policies
> work? Any suggestions/explanations?
>
> Thanks
>
> Curt
>
>



Relevant Pages

  • Re: XP Firewall setting for AD
    ... Generally you don't configure the Windows Firewall on the domain controllers ... computers used for domain administration and domain controllers if you are ... > Without configuration, Group Policies aren't being applied, WSUS also ...
    (microsoft.public.windowsxp.security_admin)
  • Groups not showing users
    ... I have a domain with 4 domain controllers in it. ... When I go into Active Directory Users & Computers and look at the properties ... of a group it doesn't show any members in the group even tho ...
    (microsoft.public.win2000.general)
  • Re: Black,Blue,andBlack again
    ... then me rebooting more times than I can count. ... seriously and have always used ZoneAlarm, ... This way in the past we have been able to stop our computers from being ... We have now tried using another firewall software called Sygate Personal ...
    (microsoft.public.security)
  • Re: Sharing a printer
    ... Here are general network troubleshooting steps. ... Problems sharing files between computers on a network are generally caused by 1) a misconfigured firewall or overlooked firewall; or 2) inadvertently running two firewalls such as the built-in Windows Firewall and a third-party firewall; and/or 3) not having identical user accounts and passwords on all Workgroup machines; 4) trying to create shares where the operating system does not permit it. ... On the assumption that you in fact do have a router that connects to the Internet and that your computers then connect to the router, then if you think that you have one IP for multiple computers then you probably are using a website tool such as http://whatismyip.com/ That shows the your public IP address -- the one that the rest of the world sees. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Networks : Workgroups and Domains. How Do I Use Them?
    ... in My Network Places, it may take some time for a network resource to show up. ... all of the computers must be on the same subnet. ... it depends on whether you have Simple File Sharing enabled or disabled. ... Problems sharing files between computers on a network are generally caused by 1) a misconfigured firewall or overlooked firewall; or 2) inadvertently running two firewalls such as the built-in Windows Firewall and a third-party firewall; and/or 3) not having identical user accounts and passwords on all Workgroup machines; 4) trying to create shares where the operating system does not permit it. ...
    (microsoft.public.windowsxp.network_web)