Re: Strange Logon Behaviour.



Would totally agree with Meinolf, dump the multihoming. RRAS is bad as well in this configuration.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.


"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message news:ff16fb661aba78cb65f9b4ad62cc@xxxxxxxxxxxxxxxxxxxxxxx
Hello Broonie,

Multihoming DC's and using it for RRAS is a bad solution which can result in exactly your problem. You should avoid this and move the RRAS to another member server so that the DC is only using eon ip address.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

On Feb 26, 11:11 am, Meinolf Weber [MVP-DS] <meiweb(nospam)@gmx.de>
wrote:

Hello brooni...@xxxxxxxxxxx,

Very often slow logons depend on DNS. Make sure to use only domain
internal DNS servers, please post an unedited ipconfig /all from one
problem client and the DC/DNS server.

Also make sure that for the computers following policy is configured:
Computer
Configuration, Administrative Templates, System, Logon, "Always wait
for
the network at computer startup and logon"
Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!!http://www.blakjak.demon.co.uk/mul_crss.htm
HI There,

I have a smallish domain with 3 DCs running Server 2003 (although
the functional level is still 2000). We have no roaming profiles but
when a user logs onto some machines for the first time the logon
process can take up tp 10 minute. For testing purposes i then delete
that users profile and logon to the same machine as them a second
time. This time the logon process is fine. We have a mix of XP and
Vista clients but thus far I've only seen this happen on XP.

Can anyone shed some light on the strange behaviour?

Cheers

Craig

Below is the ipconfig from the DC which is also the DNS server

Windows IP Configuration

Host Name . . . . . . . . . . . . : server2
Primary Dns Suffix . . . . . . . : *****.co.nz
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : Yes
DNS Suffix Search List. . . . . . : *****.co.nz
co.nz
PPP adapter RAS Server (Dial In) Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-53-45-00-00-00
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.211
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
Ethernet adapter Local Area Connection 3:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : HP NC1020 Gigabit Server
Adapter 32 PCI
Physical Address. . . . . . . . . : 00-18-71-4D-DC-ED
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.33
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.33
192.168.3.2
This is the IPconfig from one of the clients

Windows IP Configuration

Host Name . . . . . . . . . . . . : it-laptop
Primary Dns Suffix . . . . . . . : *****.co.nz
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : *****.co.nz
Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : *****.co.nz
Description . . . . . . . . . . . : Broadcom NetLink (TM)
Gigabit Ethern
et
Physical Address. . . . . . . . . : 00-17-A4-D0-DE-80
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.150
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.33
DNS Servers . . . . . . . . . . . : 192.168.1.33
192.168.3.2
Lease Obtained. . . . . . . . . . : Thursday, 26 February 2009
2:22:10 p
.m.
Lease Expires . . . . . . . . . . : Friday, 6 March 2009
2:22:10 p.m.
We don't have the "Always wait for the network at computer startup
and logon" policy set though.

I've also noticed that after I logon to a machine that's causing me
trouble policy from the command line
like gpresult and gpupdate take forever.
To add to my first post, this behaviour is also apparent on Vista
machines. It is also NOT on first logon
only that this happens as I previously stated - it hapens randomly
with different users.
Cheers




.



Relevant Pages

  • Re: ISA 2004 & SBS 2003
    ... NAT is configured through RRAS. ... This is what is making me think that it may be a configuration ... I decided to take your advice and reinstall the server ... tools hoping that reconfiguring with the wizards would correct whatever was ...
    (microsoft.public.windows.server.sbs)
  • Re: RRAS and RDP issue
    ... While the VPN configuration was not the issue, ... > look into the basic firewall setting in RRAS. ... > expand the server tree ) then expand the IP Routing ...
    (microsoft.public.windows.server.sbs)
  • Re: Preparing Network Connections... forever
    ... Windows IP Configuration ... "Replication Services" event log contained the same error as originally posted. ... The Security System detected an authentication error for the server ldap/Client-1DC.client-1.local. ... The failure code from authentication protocol Kerberos was "There are currently no logon servers ...
    (microsoft.public.windows.server.active_directory)
  • Re: Preparing Network Connections... forever
    ... Windows IP Configuration ... "Replication Services" event log contained the same error as originally posted. ... The Security System detected an authentication error for the server ldap/Client-1DC.client-1.local. ... The failure code from authentication protocol Kerberos was "There are currently no logon servers ...
    (microsoft.public.windows.server.active_directory)
  • Re: anonymous logon
    ... would be indicated by a large number of failed logon attempts using non default ... you have file and print sharing enabled on your server make sure it is disabled ... security option in Local Security Policy for additional restrictions for ... Management Console/servername/action/backup & restore configuration since if you ...
    (microsoft.public.win2000.security)

Loading