Re: Unable to browse shared folders on DC



Dear Ace:

Thanks alot for your concern ,I was able to solve the problem by disjoing
the computers from the domain and rejoin them ,it kept first saying (Access
Denied) ,but I created new computers accounts on the DC for the affected
machines ,disjoined them completely then added the MARINADC in the DNS
suffix tab ,restarted the computer then typed the name of the domain as
follows: MARINA.DC not MARINADC ,an authentication dialo apperared ,I
supplied the necessary credentials and then the message (Welcome to
MARINA.DC domain) magically appeared!

Now all I need to know is why that happened in the first place and how to
avoid it in the future ,so I guess i will answer all of your question.

The ipconfig /all's are incomplete unless you just did an ipconfig? If
possible, It would have been greatly helpful to see the full output which
provides much more additional information concerning your basic AD
infrastructure config, what DNS they are using, and other info. Also let
us know what the AD DNS domain name is please.
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\axxxxxxxiz>ipconfig?
'ipconfig?' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\axxxxxiz>ipconfig/all

Windows IP Configuration

Host Name . . . . . . . . . . . . : Axxxxxxxz
Primary Dns Suffix . . . . . . . : MARINADC
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : MARINADC

Ethernet adapter Local Area Connection 3:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : SiS 900 PCI Fast Ethernet
Adapter
Physical Address. . . . . . . . . : 00-E0-06-09-01-C8
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.52
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.4
DNS Servers . . . . . . . . . . . : 192.168.1.6


Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\isa admin>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : marina-isa
Primary Dns Suffix . . . . . . . : MARINA.DC
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : Yes
DNS Suffix Search List. . . . . . : MARINA.DC

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : HP NC373i Multifunction Gigabit
Server Ad
apter
Physical Address. . . . . . . . . : 00-1A-4B-E0-F0-52
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.4
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 192.168.1.6
2xx-xxx-xxx-18
C:\Documents and Settings\Administrator>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : marina-dc
Primary Dns Suffix . . . . . . . : MARINA.DC
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : MARINA.DC

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139 Family PCI Fast
Ethernet
NIC
Physical Address. . . . . . . . . : 00-19-DB-54-30-36
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.6
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.4
DNS Servers . . . . . . . . . . . : 127.0.0.1


C:\Documents and Settings\Administrator>


So you're using ISA, which is the 192.168.1.4 machine. What role is ISA
playing? Secure NAT, Web Caching and/or Firewall?

Secure NAT ,Web cashing and firewall

Is the ISA server also a DC? What version of ISA?
It's not a DC ,it's a WINS server also ,I am using 2004 Standard Edition.

Is this SBS?

Both the ISA and the DC running on 2003 Enterprise edition.

Getting an EventID 13516 usually indicates there were or are continuing
replication issues with AD. How many DCs are there?
Only one
Are you using the ISA firewall client? If so, possibly updating the client
may help.

EventID 1517 can be cleaned up by installing the UPHClean on all machines,
but that is not the answer to the issues you are having.
User Profile Hive Cleanup Service
http://www.microsoft.com/downloads/details.aspx?FamilyID=1B286E6D-8912-4E18-B570-42470E2F3582&displaylang=en

EventID 1030 and 1058 usually indicate issues with client-domain
communicaiton.


Hope that can help.

Thanks in advance





Ace Fekay [MVP]" <PleaseAskMe@xxxxxxxxxxxxxx> wrote in message
news:OFqbKpvWIHA.5164@xxxxxxxxxxxxxxxxxxxxxxx

In news:O6SyMdrWIHA.3556@xxxxxxxxxxxxxxxxxxxx,
Nightlegend <nightlegend@xxxxxxxxxxxxx> typed:
I disjoined a pc now from the domain ,tried to get it back in
,received (access denied) error when tried to join it back to the
domain!! it seems that not all the xp machines are affected ,some is
still
abale to browse the network shares ,and i can't understand that cause
all the mchines either Vista or XP is using static IPs not DHCP ,and
here's the IPCONFIG output for this machine:
IP :192.168.1.52
subnet:255.255.255.0
gateway:192.168.1.4 (isa server installed)

the out put for the DC is:
IP :192.168.1.6
subnet:255.255.255.0
gateway:192.168.1.4

here's the event log from the XP machine:

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1053
Date: 19-Jan-08
Time: 4:33:11 PM
User: NT AUTHORITY\SYSTEM
Computer: xxxxxx
Description:
Windows cannot determine the user or computer name. (The specified
domain either does not exist or could not be contacted. ). Group
Policy processing aborted.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 19-Jan-08
Time: 4:32:25 PM
User: NT AUTHORITY\SYSTEM
Computer: xxxxxxx
Description:
Windows saved user xxxxxxDC\Administrator registry while an
application or service was still using the registry during log off.
The memory used by the user's registry has not been freed. The
registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try
configuring the services to run in either the LocalService or
NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 19-Jan-08
Time: 4:18:23 PM
User: xxxxxx\Administrator
Computer: xxxxxx
Description:
Windows cannot query for the list of Group Policy objects. A message
that describes the reason for this was previously logged by the
policy engine.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1058
Date: 19-Jan-08
Time: 4:18:23 PM
User: xxxxxxDC\Administrator
Computer: xxxxxxx
Description:
Windows cannot access the file gpt.ini for GPO
CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=xxxxx,DC=DC.
The file must be present at the location
<\\xxxxxx.DC\sysvol\xxxxx.DC\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>.
(The specified network name is no longer available. ). Group Policy
processing aborted.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

and for the DC:


Event Type: Information
Event Source: NtFrs
Event Category: None
Event ID: 13516
Date: 1/19/2008
Time: 4:35:39 PM
User: N/A
Computer: xxxxxx-DC
Description:
The File Replication Service is no longer preventing the computer
xxxxx-DC from becoming a domain controller. The system volume has
been successfully initialized and the Netlogon service has been
notified that the system volume is now ready to be shared as SYSVOL.

Type "net share" to check for the SYSVOL share.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

I can see any errors or warinings posted on the event viewer ,so does
it help you to identify the cause of this problem ? and what can I do
to get this maachine back to domain? I have even added (everyone)
group to the (add workstation to domain) in the security policies but
with no use..I am really lost...please help me.

Thanks

The ipconfig /all's are incomplete unless you just did an ipconfig? If
possible, It would have been greatly helpful to see the full output which
provides much more additional information concerning your basic AD
infrastructure config, what DNS they are using, and other info. Also let
us know what the AD DNS domain name is please.

So you're using ISA, which is the 192.168.1.4 machine. What role is ISA
playing? Secure NAT, Web Caching and/or Firewall?

Is the ISA server also a DC? What version of ISA?

Is this SBS?

Getting an EventID 13516 usually indicates there were or are continuing
replication issues with AD. How many DCs are there?

Are you using the ISA firewall client? If so, possibly updating the client
may help.

EventID 1517 can be cleaned up by installing the UPHClean on all machines,
but that is not the answer to the issues you are having.
User Profile Hive Cleanup Service
http://www.microsoft.com/downloads/details.aspx?FamilyID=1B286E6D-8912-4E18-B570-42470E2F3582&displaylang=en

EventID 1030 and 1058 usually indicate issues with client-domain
communicaiton.

Ace







.



Relevant Pages

  • << INFO FOR WINDOWS UPDATE ISSUE - ISA Server 2000/Windows/Auto update on the v5 platform>&
    ... Some XP sp1 machines ... running with ISA in the egress filtering mode will get this issue. ... two NTLM authentication issues affecting WU v5 when WU uses web proxy requests to access Windows ... have heard that the “ReturnDeniedIfAuthenticated registry setting explained in http://support.microsoft.com/?id=297324 is part of the problem. ...
    (microsoft.public.backoffice.smallbiz)
  • << INFO FOR WINDOWS UPDATE ISSUE - ISA Server 2000/Windows/Auto update on the v5 platform>&
    ... Some XP sp1 machines ... running with ISA in the egress filtering mode will get this issue. ... two NTLM authentication issues affecting WU v5 when WU uses web proxy requests to access Windows ... have heard that the “ReturnDeniedIfAuthenticated registry setting explained in http://support.microsoft.com/?id=297324 is part of the problem. ...
    (microsoft.public.backoffice.smallbiz2000)
  • << INFO FOR WINDOWS UPDATE ISSUE - ISA Server 2000/Windows/Auto update on the v5 platform>&
    ... Some XP sp1 machines ... running with ISA in the egress filtering mode will get this issue. ... two NTLM authentication issues affecting WU v5 when WU uses web proxy requests to access Windows ... have heard that the “ReturnDeniedIfAuthenticated registry setting explained in http://support.microsoft.com/?id=297324 is part of the problem. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN with SBS Premuim
    ... Windows 2003 SP2 networking issues, and then re-ran the CEICW again this time ... I understand that after installing ISA 2004 on the SBS ... server, VPN does not work. ... if you installed SP2 on the SBS server without ...
    (microsoft.public.windows.server.sbs)
  • Re: Error (407) Proxy Authentication Required - Kindly Help!
    ... please do that and see if your app starts working. ... go into the ISA console and open the properties of the SBS ... >> Please run IPconfig /all on the server and the workstation and post ... > Connection-specific DNS Suffix. ...
    (microsoft.public.windows.server.sbs)