Re: ADS Sites and Services issue

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi, Mick!

I've read your post again and again and all I can see is that your setup is
correct.

Do you have any problems with clients in other sites? Are subnets A and B in
your "Main Office"? If your first answer is "no" and second is "yes", then
you could change priority and weight of appropriate SRV resource records for
DCs from subnet A. Clients from subnet B should in this case authenticate on
domain controllers from subnet A. Clients from other sites should still
authenticate on their local DCs.

I would implement this solution as temporary one and then check network
traffic between client from subnet B and DC from subnet A to find exact
error.

Just an idea! ;)

HTH

Toni




<Mick.Bergman@xxxxxxxxx> wrote in message
news:1163691566.945751.161870@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
No ideas?

Mick.Bergman@xxxxxxxxx wrote:
Yes, subnet A and subnet B are both associated with the same site, and
the DCs are located within that site as well. That is why I'm stuck...
everything looks to be 100% correct but the workstations on subnet B
are authenticating with all the DCs, when they should only authenticate
with them if the two DCs in that site are not online.


T. Uranjek wrote:
Hi!

Did you create appropriate subnet objects id AD Sites and Services and
link
them to appropriate sites?

Toni

You should use Active Directory Sites and Services to perform these
steps.
<Mick.Bergman@xxxxxxxxx> wrote in message
news:1163616608.777945.225830@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I am running a domain with multiple sites, and 1 site has multiple
subnets (due to VLANs).

I put the servers in subnet A, and the workstations in subnet B. Both
are members of the same site in ADS, yet the workstations will query
any DC whether it is in the same site or located in another site.

From any of the servers (which are in subnet A, site A, same place as
the DCs), I query my domain name through nslookup and it only
responds
with the local DCs.

From any of the workstations (which are in subnet B, site A, separate
VLAN from my DCs), I query the domain and get every DC on our entire
network.

This causes a significant slowdown during login if the workstation is
returned a DC outside of our local network, and since one of our
sites
are out of country sometimes those other DCs are unavailable anyway
(internet/VPN is not perfectly stable 100% of the time).

Any ideas on what I am missing? I can't find anything on my end that
is
a mistake, although I'm sure I am missing something.

Thanks,
Mick




.



Relevant Pages

  • Re: logonserver
    ... The 2 sites are created in their respective subnets and replication is ... sometimes XP clients experience delays when logging in. ... as the IP Subnet Objects haven't been created properly and associated wtih ... objects associated with their respective Sites, and manually move the DCs. ...
    (microsoft.public.windows.server.networking)
  • Re: Choosing which DC to logon to
    ... For the sake of simplicity I mentioned I had 1 DC in the seperate subnet, ... two for domain logon etc. ... workstations are not allowed access to the subnet with 2 DC's.The ... Either let all clients get to the DCs freely or separate them into Sites ...
    (microsoft.public.windows.server.active_directory)
  • Re: client authentication
    ... I launch ADSS and made sure it was connected to ... the local DC I'm logged on to and saw the subnet in question listed... ... why I am getting these error messages on my DCs. ... and clients are unable to map to any of the existing sites under ADSS .I ...
    (microsoft.public.windows.server.active_directory)
  • Re: client authentication
    ... Have you verified that the site definition/subnet assignments have been ... I am getting these error messages on my DCs. ... have verified that the subnets for the all servers and clients are defined ... the mapping of its subnet to one of the existing sites. ...
    (microsoft.public.windows.server.active_directory)
  • Re: client authentication
    ... am getting these error messages on my DCs. ... clients are unable to map to any of the existing sites under ADSS .I have ... mapping of its subnet to one of the existing sites. ...
    (microsoft.public.windows.server.active_directory)