Re: GPO issue on 1 pc

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hello Herb,

The original problem was that the Computer Config part of all GPO's wasn't
being applied to the computer - I found this running the RSOP on that
computer.

After I posted my last message, that part did resolve itself and updates
were happening. But with that said, we have an internal website set as the
default home page for IE company wide. That laptop was not getting that part
of the GPO for whatever reason. As I left work tonight, that still was the
case. Even if they manually typed in the address they would receive Page
Cannot be found. Oddly enough everyone else in the company can get to it.
If that same user logs into another computer and opens IE - they get there
first try.

So why can't that hardware get to the webpage page?

Mike

"Herb Martin" wrote:


"Mike" <Mike@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D9890F6E-F130-4A4C-9870-A34E496034E6@xxxxxxxxxxxxxxxx
Herb,

Here's what I found ...

1. Saw there was a small problem with a few DC's with replicatication and
DNS - fix it.
2. I also had the enduser install UPHClean-Setup.msi to help with Event
ID
1517
3. DNS at all servers are accurate
4. DNS at the client in question - points to the correct servers
5. Client is in the correct OU (along with 200 other pcs) noone else has
this issue
6. After fixing the DC's replication/dns problems - the error msg i
stated
before (Windows cannot obtain the dc name for your computer ...) went
away.
7. DCDiag /c works perfect on each DC - no errors

And WARN messages either? (Always dump dcdiag output to a file so you
can review and search for problems using an editor, or post for others to
review.)

8. Computer Authentication - does happen with every login for the end
user,
we have a cmd box that appears on the desktop while the scripts run.
9. Something I didn't know - but now works - windows updates were not
getting to this pc. They are now.

What else would it be?

So what is the current problem if those errors went away, logons are
occuring, and updates being applied?

My first thoughts without knowing would be to complete all updates
and reboots, review and clear the DC System Logs, run "NetDiag /Fix"
on all DCs (just for luck), and perhaps post a sample "Ipconfig /all"
from a sample client if you are still having trouble.


"Mike" <Mike@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:0DD8D317-62EE-4CD0-9E6B-764CA915987C@xxxxxxxxxxxxxxxx
Well, ruling out the duplicate SID, which I don't believe it is
either -
just
wanted to ask the question - what would cause those errors to show up
since
the day the laptop was put into the domain?

I probably should have answered this the first time but you did ask about
the
clone thing <grin>

Windows cannot obtain the domain controller name for your computer
network.
(A socket operation was attempted to an unreachable host. ). Group
Policy
processing aborted.

DNS issues. Either of the DC(s) or the client.

Most likely the client is set (incorrectly) to use the wrong DNS server.

Internal DNS clients must be set to use ONLY the internal DNS server
which
can resolve the DCs and other resource records.

DCs should all be able to pass a complete "DCDiag /c" without FAIL or
WARN messages.

--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)






.



Relevant Pages

  • Re: GPO problems
    ... It was the ISA 2004 firewall client. ... DNS settings and network properties on the server and client computers. ... > Service of SBS is configured to be the DNS server on the problematic ...
    (microsoft.public.windows.server.sbs)
  • Re: Connect Computer - Not successful after Numerous Attempts
    ... Since that temporary account is used in the migration ... Client LAN connection is now configured to ONLY show ... the SBS server IP as the DNS server. ... Looks like all DNS records are in place as you ...
    (microsoft.public.windows.server.sbs)
  • Re: DHCP on router or server
    ... There are plenty of real instances of problems that many have seen, and have even been posted here, that have been caused by having non-AD DNS servers on a windows client. ... There is a difference between getting an answer of "record not found" and not getting an answer at all (a DNS server being down, timeout exceeded, etc.) If a server replies that a record does not exist, the DNS client will *not* query other servers. ... However I'm wondering if the router should be the one handing out DHCP ...
    (microsoft.public.windows.server.sbs)
  • Re: Linux and SBS
    ... ALL AD clients _must_ only have 'AD Aware' servers as DNS server entries. ... People seem to believe that in the case of setting a 'primary' and 'secondary' DNS server on a client negative queries to the primary will cause fallback to the secondary, ... your DHCP to point to SBS as the first DNS server. ...
    (microsoft.public.windows.server.sbs)
  • Re: EventID 5782
    ... domain controller for a forest and one Unix server. ... uses bind DNS on the unix server NOT Microsoft DNS. ... DDNS updates are allowed. ... provide steps on diabling client dynamic DNS register. ...
    (microsoft.public.windows.server.dns)