Conundrum with a new DC

13 views
Skip to first unread message

Kurt Buff

unread,
Nov 21, 2022, 3:10:33 PM11/21/22
to ntsys...@googlegroups.com
All,

I just stood up a new DC and transferred the /16 used in that location to the new site, and the DC resides in that site. The location is one that's been around for quite a while, but never had a DC before - it was using the DCs at the corporate office.

Sites and Services shows everything happy. Replication between DCs is happy as well.

I can see the sysvol on the new DC from the corporate office - dir \\newdc\sysvol and dir \\newdc\netlogon works - and so does browsing against the other DCs in our environment.

However, I've got some machines in that location that are not getting GPOs applied and are having printing problems and other issues because they can't browse the sysvol and netlogon shares on *ANY* DC, including the new one that location.

The host firewall on the DC is on, and allowing all traffic for the Domain profile, and the Domain profile is the active profile.

I've seen this once in our environment when we stood up a completely new location with a new DC, and I never did figure out the root cause, but it took weeks for it to resolve itself.

I've looked at the firewall appliance logs for both HQ and this location, and and am not seeing any traffic blocked by them. I've looked at the DC host firewall logs, and the machine that I'm working on shows in the DC logs with all traffic allowed, including icmp, tcp ports 88,389,445,etc.

I've rebooted the workstation in question several times, and that hasn't done anything.

I've examined the network settings on the workstation, and it says connected/unauthenticated. I changed the IP address to static, and rebooted, and then it said it was on a public network. I set it to Private, but that didn't make a difference

Just FYI: the workstation I'm working on now is getting its address from the old Windows DHCP server in this location, but AFAICT that shouldn't make any kind of difference.

I'm stumped.

Anyone have thoughts on this?

Thanks,
Kurt

Michael B. Smith

unread,
Nov 21, 2022, 3:17:03 PM11/21/22
to ntsys...@googlegroups.com

What is $env:LOGONSERVER?

 

Is replication to/from the site happy?

 

Thanks.

 

Regards,

Michael B. Smith

Managing Consultant

Smith Consulting, LLC

--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CADy1Ce7Mvs5w-Lq89pUXxu%3DHjZK6X78pjmSCXoY1PhcEDQTJGw%40mail.gmail.com.

Jim Kennedy

unread,
Nov 21, 2022, 3:17:21 PM11/21/22
to ntsys...@googlegroups.com

What does %logonserver% show?

 

From: ntsys...@googlegroups.com <ntsys...@googlegroups.com> On Behalf Of Kurt Buff
Sent: Monday, November 21, 2022 3:10 PM
To: ntsys...@googlegroups.com
Subject: [ntsysadmin] Conundrum with a new DC

 

All,

--

You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CADy1Ce7Mvs5w-Lq89pUXxu%3DHjZK6X78pjmSCXoY1PhcEDQTJGw%40mail.gmail.com.

CAUTION: This email originated from outside of the organization. Do not click any links or open any attachments unless you trust the sender and know the content is safe.

Mike

unread,
Nov 21, 2022, 3:18:46 PM11/21/22
to ntsys...@googlegroups.com
Some machines in the new location but not all of them? Anything in common between those two cohorts?

James Iversen

unread,
Nov 21, 2022, 3:20:08 PM11/21/22
to ntsys...@googlegroups.com
ARP cache?
James Iversen
Systems Analyst
IT Infrastructure



1899 Central Plaza East
Edmeston, NY 13335

nycm.com






From:        "Kurt Buff" <kurt...@gmail.com>
To:        ntsys...@googlegroups.com
Date:        11/21/2022 03:10 PM
Subject:        [ntsysadmin] Conundrum with a new DC
Sent by:        ntsys...@googlegroups.com





ATTENTION: This email was sent from someone outside of NYCM.
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ntsysadmin/CADy1Ce7Mvs5w-Lq89pUXxu%3DHjZK6X78pjmSCXoY1PhcEDQTJGw%40mail.gmail.com.


JD Power Award









Join us on Facebook at
www.facebook.com/NYCMInsurance.


***CONFIDENTIALITY NOTICE***

This email and any attachments to it are confidential and intended solely for the individual or entity to whom it is addressed. Any unauthorized review, use, disclosure or distribution is prohibited. If you have received this email in error, please contact the sender by reply email and destroy all copies of the original message.




Philip Elder

unread,
Nov 21, 2022, 3:22:23 PM11/21/22
to ntsys...@googlegroups.com

My local search foo is sucking right now. We have dealt with this but I need to dig in to figure out where my notes went.

 

https://community.spiceworks.com/topic/2263002-domain-network-comes-up-as-unauthenticated

http://www.chicagotech.net/WordPress/2019/01/29/network-connection-shows-as-unauthenticated/

^^^

I think it’s the machine password being out of sync with the DC(s). That seems to tweak the grey matter.

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

E-mail: Phili...@mpecsinc.ca

Phone: +1 (780) 458-2028

Web: www.mpecsinc.com

Blog: blog.mpecsinc.com

Twitter: Twitter.com/MPECSInc

Skype: MPECSInc.

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

 

Sent: Monday, November 21, 2022 13:10
To: ntsys...@googlegroups.com
Subject: [ntsysadmin] Conundrum with a new DC

 

All,

--

Kurt Buff

unread,
Nov 21, 2022, 3:22:24 PM11/21/22
to ntsys...@googlegroups.com
I'm logged into this machine with the LAPS credential.

$env:logonserver is \\workstation

Kurt

Kurt Buff

unread,
Nov 21, 2022, 3:25:07 PM11/21/22
to ntsys...@googlegroups.com
Just logged on with my non-privileged domain credentials, and the logon server is the local/new DC.

Kurt

On Mon, Nov 21, 2022 at 1:17 PM Michael B. Smith <mic...@smithcons.com> wrote:

Kurt Buff

unread,
Nov 21, 2022, 3:26:01 PM11/21/22
to ntsys...@googlegroups.com
Unknown at the moment - I'm working from home, supposed to be on PTO.

Supposedly it's a few machines

Michael B. Smith

unread,
Nov 21, 2022, 3:26:53 PM11/21/22
to ntsys...@googlegroups.com

Glen

unread,
Nov 21, 2022, 3:26:57 PM11/21/22
to ntsys...@googlegroups.com

Is newdc also a dns server?  Did you update the dhcp options for this site to prefer newdc as their primary dns server?

 

From: Kurt Buff
Sent: Monday, November 21, 2022 3:10 PM
To: ntsys...@googlegroups.com
Subject: [ntsysadmin] Conundrum with a new DC

 

All,

--

Kurt Buff

unread,
Nov 21, 2022, 3:27:27 PM11/21/22
to ntsys...@googlegroups.com
Nah - name resolvution works, and I can ping and test-netconneciton by IP address, plus I've rebooted several times.

Kurt Buff

unread,
Nov 21, 2022, 3:28:38 PM11/21/22
to ntsys...@googlegroups.com
Yes, new DC does DNS.

Didn't update old DHCP server yet. That's a good call.

Kurt


James Iversen

unread,
Nov 21, 2022, 3:28:40 PM11/21/22
to ntsys...@googlegroups.com
I've seen network Admins have to add DC's to IPHELPER in Cisco before they would be recognized by the general population.

Just another thought.






From:        "Kurt Buff" <kurt...@gmail.com>
To:        ntsys...@googlegroups.com
Date:        11/21/2022 03:26 PM
Subject:        Re: [ntsysadmin] Conundrum with a new DC
Sent by:        ntsys...@googlegroups.com





ATTENTION: This email was sent from someone outside of NYCM.
 
.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ntsysadmin/CADy1Ce6OKE5ifn9pF-J%3DmJLwARtn26irRRLEqg4uG9WyL7rc7g%40mail.gmail.com.

Kurt Buff

unread,
Nov 21, 2022, 3:28:55 PM11/21/22
to ntsys...@googlegroups.com
I'll look at thos.

Kurt

Kurt Buff

unread,
Nov 21, 2022, 3:41:53 PM11/21/22
to ntsys...@googlegroups.com
The output of these three looked clean to me:
   dcdiag /v > C:\temp\dcdiag.log
   repadmin /showrepl > C:\temp\showrepl.log
   repadmin /replsum > C:\temp\replsum.log

Tan them on the FSMO role holder.

Kurt

Kurt Buff

unread,
Nov 21, 2022, 3:51:37 PM11/21/22
to ntsys...@googlegroups.com
Just changed that, and rebooted the workstation to pick it up, which it did along with a different IP address.

Didn't make a difference, AFAICT.

Kurt

Kurt Buff

unread,
Nov 21, 2022, 4:01:23 PM11/21/22
to ntsys...@googlegroups.com
I just ran test-computersecurechannel from the workstation, and it returned true.

Kurt

On Mon, Nov 21, 2022 at 1:17 PM Michael B. Smith <mic...@smithcons.com> wrote:

Michael B. Smith

unread,
Nov 21, 2022, 4:05:29 PM11/21/22
to ntsys...@googlegroups.com

I would take a look at them on the new dc.

Kurt Buff

unread,
Nov 21, 2022, 4:10:42 PM11/21/22
to ntsys...@googlegroups.com
If I log on with my non-priv domain credential, I can browse netlogon and sysvol for the DCs, but 'gpupdate /force' for the computer is still failing, with this message:

gpupdate /force
Updating policy...

Computer policy could not be updated successfully. The following errors were encountered:

The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.
User Policy could not be updated successfully. The following errors were encountered:

The processing of Group Policy failed. Windows could not authenticate to the Active Directory service on a domain controller. (LDAP Bind function call failed). Look in the details tab for error code and description.

To diagnose the failure, review the event log or run GPRESULT /H GPReport.html from the command line to access information about Group Policy results.

In the System event log I see IDs 1129 followed by 1006, both for "Group Policy (Microsoft-Windows-GroupPolicy)", which have errors of "The network not is present or not started" and "Invalid credentials", respectively.

Kurt

On Mon, Nov 21, 2022 at 1:17 PM Michael B. Smith <mic...@smithcons.com> wrote:

Kurt Buff

unread,
Nov 21, 2022, 4:18:19 PM11/21/22
to ntsys...@googlegroups.com
They show clean from the new DC as well.

The only anomaly I see is this error for the workstation:

         An error event occurred.  EventID: 0xC000000E

            Time Generated: 11/21/2022   14:09:47

            Event String:

            While processing an AS request for target service krbtgt, the account WORKSTATION$ did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of 1). The requested etypes : 18  17  3. The accounts available etypes : 23  18  17. Changing or resetting the password of WORKSTATION$ will generate a proper key.

         An error event occurred.  EventID: 0xC000000E

However, I'm seeing that for any number of machines, and only about 4 out of 45 or so seem to have this problem.

Kurt

Michael B. Smith

unread,
Nov 21, 2022, 4:23:24 PM11/21/22
to ntsys...@googlegroups.com

Did you install the OOB DC patch from yesterday? (Or back out the November patch?)

Mike

unread,
Nov 21, 2022, 4:23:34 PM11/21/22
to ntsys...@googlegroups.com
Any chance the new DC is missing the OoB Kerberos RC4 update? (I would guess not but just would rule it out.)

Kurt Buff

unread,
Nov 21, 2022, 4:25:36 PM11/21/22
to ntsys...@googlegroups.com
I backed out the patch on Thursday.

Root cause of that message seems to be a GPO (configured long before I got here) that disables RC4 for the workstations.

Kurt

Kurt Buff

unread,
Nov 21, 2022, 4:26:48 PM11/21/22
to ntsys...@googlegroups.com
Never applied - I ran the updates in test last week, which included one of the DCs (the new one wasn't part of the test) and backed it out on the test DC after we saw problems with a few machines.

Kurt

Michael B. Smith

unread,
Nov 21, 2022, 4:34:51 PM11/21/22
to ntsys...@googlegroups.com

This still sounds like a secure channel issue (yes, I read where you tested it).

 

I’d reset it, just for grins and giggles. (That means I’m out of ideas.)

Kurt Buff

unread,
Nov 21, 2022, 4:35:47 PM11/21/22
to ntsys...@googlegroups.com
Well, so am I, so I'll do that reset, and see if it makes a difference.


Philip Elder

unread,
Nov 21, 2022, 4:57:08 PM11/21/22
to ntsys...@googlegroups.com

# Renew Domain Trust

# Machine Password

 

# Option 1

 

Test-ComputerSecureChannel

# ! FALSE = BROKEN

 

# TODO Fix it!

$Domain = "DOMAIN.Com"

$NETBIOS = "DOMAIN"

$DomainAdmin = "MyAdmin"

Test-ComputerSecureChannel -Credential "$($NETBIOS)\$($DomainAdmin)" -Repair

# True = #? Fixed

Test-ComputerSecureChannel

# True

 

# Option 2

 

# We have found that you can rejoin the domain by simply changing the domain from the full domain name (domain.company.org) to NetBIOS name (or vice-versa) in the system control panel.

# No need to reset the computer account.

 

<#

Michael Smith:

Is this about secure channels?

Has anyone tried a simple

# ? nltest /sc_reset

# ? netdom resetpwd

#>

 

# Sign in as local admin on Win10/Server

$Domain = "DOMAIN.Com"

$DomainAdmin = "MyAdmin"

Reset-ComputerMachinePassword -Credential "$($Domain)\$($DomainAdmin)"

 

# ! Live Test

 

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

E-mail: Phili...@mpecsinc.ca

Phone: +1 (780) 458-2028

Web: www.mpecsinc.com

Blog: blog.mpecsinc.com

Twitter: Twitter.com/MPECSInc

Skype: MPECSInc.

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

 

Kurt Buff

unread,
Nov 21, 2022, 5:05:23 PM11/21/22
to ntsys...@googlegroups.com
Didn't make a difference.

However, I shut down the DC, rebooted the workstation, and it's talking with a DC in another site/location, and group policies are applying.

I am *SO* effing confused.

Kurt

Kurt Buff

unread,
Nov 21, 2022, 5:37:33 PM11/21/22
to ntsys...@googlegroups.com
Since the problem disappeared with the DC shut down, I've been told to leave it shut down until the first of the year, to avoid further impact.

Can't even bring it up during off hours to troubleshoot.

So, I'll probably have to reanimate this thread later.

Kurt

Markus Klocker

unread,
Nov 22, 2022, 4:13:25 AM11/22/22
to ntsys...@googlegroups.com
really sounds like the gremlins are in some kind of cache.
do the affected machines point to the new dc as dns server?
did you try a "klist purge" on affected machines?
"arp -d" "Ipconfig /flushdns" just to get all things out what could go wrong.

    Markus

Kurt Buff

unread,
Nov 22, 2022, 4:32:22 AM11/22/22
to ntsys...@googlegroups.com
I just figured it out - I think. I literally woke from a dream a few minutes ago and figured it out.

This VM patched itself before joining the domain, which means it didn't get its patches from WSUS, and it was built last week. probably on Tuesday or Wednesday, and it wasn't until either Wednesday that it was promoted..

Therefore, it got the faulty 2019 patch, which was unapproved in WSUS.

The problem will be convincing the IT director to allow it to be turned back on and remove the patch.

Kurt

Markus Klocker

unread,
Nov 22, 2022, 5:09:25 AM11/22/22
to ntsys...@googlegroups.com
Install the fix instead and give it a try?
absolutely nasty stuff this 2022-11 CU ...

Kurt Buff

unread,
Nov 22, 2022, 8:40:04 AM11/22/22
to ntsys...@googlegroups.com
Not going to be approved. Not even sure they'll allow it to be turned on to remove the November patch.

Kurt

James Iversen

unread,
Nov 22, 2022, 9:03:25 AM11/22/22
to ntsys...@googlegroups.com

If it's a VM, remove the NIC...


From:        "Kurt Buff" <kurt...@gmail.com>
To:        ntsys...@googlegroups.com
Date:        11/22/2022 08:40 AM
Subject:        Re: [ntsysadmin] Conundrum with a new DC
Sent by:        ntsys...@googlegroups.com





ATTENTION: This email was sent from someone outside of NYCM.
 
.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ntsysadmin/CADy1Ce5W0iwBZRU4R%2ByEXC4VJcTOoTBLKS2m4hZ-z9Q%3D9KxjMA%40mail.gmail.com.

Mike

unread,
Nov 22, 2022, 9:51:20 AM11/22/22
to ntsys...@googlegroups.com
Obviously the IT Director has to approve turning it on to remove the patch…because now we are all invested in the mystery and need to know!

Henry Awad

unread,
Nov 22, 2022, 10:18:56 AM11/22/22
to ntsys...@googlegroups.com
The only problem with turning off a DC is sync skew. If it becomes too much out of sync then the other DCs will not sync up with it anymore. So keep that in mind. You might be better off decommissioning it and starting fresh later.

Jonathan Raper

unread,
Nov 22, 2022, 10:19:16 AM11/22/22
to ntsys...@googlegroups.com
#ApproveTheRemove is starting to trend on Twitter.

We will not be silenced.

We must know the truth: #WasItThePatch?

Thanks,

Jonboy


From: ntsys...@googlegroups.com <ntsys...@googlegroups.com> on behalf of Mike <craigs...@gmail.com>
Sent: Tuesday, November 22, 2022 9:51:07 AM
To: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
Subject: Re: [ntsysadmin] Conundrum with a new DC
 

Jonathan Raper

unread,
Nov 22, 2022, 10:22:08 AM11/22/22
to ntsys...@googlegroups.com
That, and you will have all kinds of errors on the rest of your DCs until this is resolved.

Leaving a DC off/disconnected for an extended period of time is a bad idea, IMO.

Thanks,

Jonboy


From: ntsys...@googlegroups.com <ntsys...@googlegroups.com> on behalf of Henry Awad <aw...@cua.edu>
Sent: Tuesday, November 22, 2022 10:18:42 AM
To: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
Subject: Re: [ntsysadmin] Conundrum with a new DC
 

Melvin Backus

unread,
Nov 22, 2022, 11:28:46 AM11/22/22
to ntsys...@googlegroups.com

Since the OOB is small, you could probably disconnect the network, push the update file via USB, etc., and patch it offline.

 

--
There are 10 kinds of people in the world...
         those who understand binary and those who don't.

 

¯\_()_/¯

Kurt Buff

unread,
Nov 22, 2022, 12:45:25 PM11/22/22
to ntsys...@googlegroups.com
Well, disconnect it from the network anyway.

And that's what they're doing.

Kurt

Reply all
Reply to author
Forward
0 new messages