Re: Cannot join to domain over VPN

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"maverick" <maverick@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:30173848-C803-46A3-B057-6AD18137F2FE@xxxxxxxxxxxxxxxx
DNS, Ping everything is fine...all boiled down to this...article

support.microsoft.com/kb/314825

First time in ages that I have heard of anyone having a problem with
a low MTU on intermediate routers.

What was the MTU?
(Decrease the -l VALUE until you reach the threshold.)

Who owns the router? Tracert and Pathping might help with this.

Track down that beast and see if you can get the owner of it to fix it.

Or get your ISP to route around this.

Now I can join to the domain...but the replication fails all the
time...its
not able to replicate the full domain.Many objects are missing..
The full replication cycle is always left unfinished.

You would have to change ALL of the machines that communicate
dirrectly over this path. At a minimum your VPN routers.


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)

"Herb Martin" wrote:


"maverick" <maverick@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FEF10069-EE57-4876-AAEF-60E38D806AB4@xxxxxxxxxxxxxxxx
Hi All,

I have 2 Sites which are connected by VPN.I tried to install a DC at
site2,
and this machie which needs to point its DNS to the DC in Site1 is
correct
and pings and resolves fine.When I try to join this machine to the
domain,
it doesnt do it and comes up with 'Semaphore timeout'.

If the VPN is unfiltered, and the DNS is correct, the only think left is
reliability and speed & delay (latency). If you get these right then it
is just like being on the same LAN.

You seem to have a message suggesting timing problems (but sometimes
those come from failures too.)

I had a word with the network guy who confimred that all ports are wide
open, so shouldnt be a port/firewall
problem(clean portquery)..Changing MTU size and stuff also proved
futile.What do i do to get this to work?
Can somebody shed some light please?

Do you have ONLY the DOMAIN's DNS servers set it in the "new DC to
be" IP configuration? You must NOT mix the ISP or any other DNS server
into that list, even as alternate.

Show us your unedited "IPConfig /all" from both DC1 and DC2.

Try pathping to see what sort of timing issue you might have.

Try NSLookup and make sure you are resolving DNS from the (current) DC.

--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)





.



Relevant Pages

  • Re: NAT help?
    ... > a DNS problem, because I don't see that from inside? ... Does the "host" command work both on the NAT gateway as well on NATed ... client not), then check the network settings on the client side. ... You said you have MTU problems? ...
    (Fedora)
  • Re: Joes Twisted-up Network
    ... This information is intended for a network administrator. ... The following error occurred when DNS was queried for the service location ... > As long as the routers have compatible LAN IP addresses - eg. 192.168.1.1 ... > I would not enable DHCP on either of these routers. ...
    (microsoft.public.windows.server.networking)
  • Re: XP wont load web pages.
    ... I'm just wondering if it has DNS issues. ... it is Ethernet, then you will have an IP address and subnet mask - you say ... router (the IP address of the routers Ethernet port. ... If all of these are correct, we'll do a little ping / tracert. ...
    (uk.rec.motorcycles)
  • Re: Of interest to BT BT2700HGV/2WIRE users
    ... routers have so much RAM and ... such large buffers that the algorithms developed when buffer sizes were ... not realising that they are defeating the very mechanisms ... Doesn't directly help in analysing the OP's DNS problems, ...
    (uk.telecom.broadband)
  • Re: Joes Twisted-up Network
    ... How do you get these routers to work toghether in an AD DC enviroment ... I do not see a DNS option on the LAN side of these routers. ... >> seperate public IP's on each router for two servers. ... >> the XP machines get but the servers are crucial. ...
    (microsoft.public.windows.server.networking)