Re: R2 in-place upgrade bug ? ..HELP



Hi

- What errors are you seeing?
- Are you running RRAS in the DC?
- Running a multihomed DC is a bad idea, requires some registry hacking,
where's some descriptions:
http://support.microsoft.com/?id=292822
http://support.microsoft.com/?id=296379
http://support.microsoft.com/?id=246804
http://support.microsoft.com/?id=275554

For replication check these:
Application protocol Protocol Ports
Global Catalog Server TCP 3269
Global Catalog Server TCP 3268
LDAP Server TCP 389
LDAP Server UDP 389
LDAP SSL TCP 636
LDAP SSL UDP 636
IPsec ISAKMP UDP 500
NAT-T UDP 4500
RPC TCP 135
RPC randomly allocated high TCP ports TCP 1024 - 65536

Network Ports Used by Key Microsoft Server Products

http://www.microsoft.com/smallbusiness/support/articles/ref_net_ports_ms_prod.mspx

How to configure RPC dynamic port allocation to work with firewalls

http://support.microsoft.com/?kbid=154596

How to configure RPC to use certain ports and how to help secure those ports
by using IPsec

http://support.microsoft.com/kb/908472



You can use
Portqry.exe
http://support.microsoft.com/default.aspx?scid=kb;en-us;310099
PortQry version 2.0
http://support.microsoft.com/kb/832919/

--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"hboogz via WinServerKB.com" <u21743@uwe> wrote in message
news:63f9c18d1950a@xxxxxx
Morning to all -

I just spent the last 6 hours with dell gold software support team trying
to
figure out the following occurrence:

The upgraded R2 DC does not accept incoming connections, but it appears it
accepts certain connections. Particularly those related to directory
services.
e.g. telnet server ip 389 from the mail server works. \\serverip or
servername brings up the shared printers and folders perfectly.

outbound traffic and icmp works fine, inbound icmp returns a time out.

scenario:

Windows 2000 SP4 DC in-place upgrade to windows 2003 SP1 then upgrade to
R2.
connections to and from box were fine on 2003 sp1.
downgraded NIC drivers to match other r2 DC on identical server
hardware/model
installed new nic drivers and proset
upgraded to R2.
rebooted and noticed a ton of errors with services hanging upon boot.
checked connection to the box from workstations and servers, but all
requests
timed out.
i made sure ICF was disabled.
i disabled IPSEC and entered dword value for ProhibitIpSec - nothing
i then enabled ICF configured exceptions - explicitly allowing ICMP, and
still nothing.
reset the TCP/ip stack and winsock using netsh, nothing
servers has two nics, one of which is disabled. changed binding order so
active is on top -- nothing
reinstalled the binaries of windows 2003 sp1 and upgraded to r2 again --
nothing.

i'm at a lost of ideas and sure could use the vast resources the
contributors
of this group may have or know of.

**To make matters even more confusing, workstations located outside of
this
main office site that are connected via ipsec vpn can ping this server!!!

HELP

Thanks,

--
---
I do what i got to do in order to do what i want to do...

Message posted via http://www.winserverkb.com



.



Relevant Pages

  • Re: TCP/IP redundant connections
    ... The clients have persistent TCP connections to the server, ...
    (freebsd-hackers)
  • Re: freebsd-hackers Digest, Vol 233, Issue 3
    ... The clients have persistent TCP connections to the server, ... So I want to utilize IP-sharing and TCP-connection synchronization ...
    (freebsd-hackers)
  • Re: ADAM - The Server is not operational (Joe Kaplan, question for you)
    ... You can also increase the # of ephemeral ports. ... Microsoft Windows Server Division ... If different credentials are used under high load with ADSI, ... Unless there is some magic happening whereby connections are reused ...
    (microsoft.public.windows.server.active_directory)
  • Re: Component Efficiency
    ... Desktop OSes have TCP backlog limit of 5 outstanding ... TCP connection attempts, e.g. up to five clients may be ... simultaneously establishing connections. ... suitable for any kind of TCP server, ...
    (microsoft.public.win32.programmer.ole)
  • Re: AD Replication over SonicWall site-to-site VPN
    ... The MTU can be an Issue: ... Test your MTU from the problem server by pinging the gateway of your router: ... Kerberos authentication service to use TCP instead of UDP. ... there are no explicit prohibitions on any of the ports required. ...
    (microsoft.public.windows.server.active_directory)