Location: List Archives

List Archives

This forum is an archive of all posts to our mailing list over the past few years.  The forum is set read only therefore to contribute you will need to join our list community.  See more info about this here.

 

When subscribed to the list you should use your standard email client to send your posts to ActiveDir@mail.activedir.org.

List Archives

Subject: [ActiveDir] DFS referrals for NETLOGON and SYSVOL
Prev Next
You are not authorized to post a reply.

AuthorMessages
DavidCliffeUser is Offline

Posts:15

07/01/2009 4:55 PM  
Hi,

I have read the following (thank you Jorge):

http://blogs.dirteam.com/blogs/jorge/archive/2007/07/02/dc-locator-process-in-w2k-w2k3-r2-and-w2k8-part-3.aspx
http://technet2.microsoft.com/windowsserver/en/library/a9096e88-1634-4da6-b820-537341d349061033.mspx?mfr=true

...but am still seeing unexpected info the MUP cache ( using DFSUTIL ) for
an XP SP2 client in a Windows 2003 SP2 domain. The PreferLogonDC reg
setting has not been implemented at this time. The
SiteCostedReferrals setting *has* been implemented, although I'm not
certain it has any bearing on this situation.

The client machine and its subnet are verified via NLTEST and DFSUTIL to be
in a site where there is a single known-good DC. Authentication is taking
place with that expected DC, but client's MUP cache shows the active
targetset to be a DC in a completely different site. This happens randomly
for SYSVOL or NETLOGON, sometimes both. I have not taken a trace yet, but
wish to do so when time permits.

Since the client is verified to be inside a site where there is a known good
DC, shouldn't the referral have that DC at the top of the list, since it
covers that site?

Thanks,
DaveC

barbermjUser is Offline

Posts:13

07/01/2009 8:45 PM  
Hi David,



We had a very similar problem at one of our sites. We never really did
figure out why the DFS referral list did not have the local site DC at
the top. We went with the PreferLogonDC setting to take care of the
issue. That worked perfectly.



We did have the SiteCostedReferrals setting as well, but that does not
seem to effect the referral list that is sent back for finding SYSVOL.
I would be interested to hear if you figure out why the list is not
ordered correctly. I spent a ton of time looking through packet traces
to see the list getting sent back and could see it looking wrong.



Take care,



Matt Barber

Network Analyst

Morrisville State College

315-684-6053



From: activedir-owner@mail.activedir.org
[mailto:activedir-owner@mail.activedir.org] On Behalf Of David Cliffe
Sent: Wednesday, July 01, 2009 11:54 AM
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] DFS referrals for NETLOGON and SYSVOL



Hi,



I have read the following (thank you Jorge):



http://blogs.dirteam.com/blogs/jorge/archive/2007/07/02/dc-locator-proce
ss-in-w2k-w2k3-r2-and-w2k8-part-3.aspx

http://technet2.microsoft.com/windowsserver/en/library/a9096e88-1634-4da
6-b820-537341d349061033.mspx?mfr=true



...but am still seeing unexpected info the MUP cache ( using DFSUTIL )
for an XP SP2 client in a Windows 2003 SP2 domain. The PreferLogonDC
reg setting has not been implemented at this time. The
SiteCostedReferrals setting *has* been implemented, although I'm not
certain it has any bearing on this situation.



The client machine and its subnet are verified via NLTEST and DFSUTIL to
be in a site where there is a single known-good DC. Authentication is
taking place with that expected DC, but client's MUP cache shows the
active targetset to be a DC in a completely different site. This
happens randomly for SYSVOL or NETLOGON, sometimes both. I have not
taken a trace yet, but wish to do so when time permits.



Since the client is verified to be inside a site where there is a known
good DC, shouldn't the referral have that DC at the top of the list,
since it covers that site?



Thanks,

DaveC


ZJORZUser is Offline

Posts:282

07/02/2009 6:16 PM  
Did you install the "DFS Client Failback QFE"?



Met vriendelijke groeten / Kind regards,



Jorge de Almeida Pinto | Senior Technical Consultant | MVP IdA-DS |
Oxford Computer Group BeNeLux

(: +31 (0)6 26.26.62.80 | (: +31 (0)70 36.21.627 | 7: +31 (0)70
36.21.677
-: Sweelinckplein 9 (Unit 11), 2517 GK, Den Haag, The Netherlands
(Google
<http://maps.google.com/maps?f=q&hl=EN&geocode=&q=sweelinckplein+9+-+11+
(unit+11),+2517+GK,+Den+Haag,+The+Netherlands&sll=37.0625,-95.677068&ssp
n=50.291089,113.90625&ie=UTF8&z=16&g=sweelinckplein+9+-+11+(unit+11),+25
17+GK,+Den+Haag,+The+Netherlands> Maps) (Live
<http://maps.live.com/default.aspx?v=2&FORM=LMLTCC&cp=52.084005~4.285932
&style=r&lvl=14&tilt=-90&dir=0&alt=-1000&phx=0&phy=0&phscl=1&where1=Swee
linckplein%209%20-%2011%20(unit%2011)%2C%202517%20GK%2C%20Den%20Haag%2C%
20The%20Netherlands&encType=1> Maps)
<blocked::blocked::http://www.oxfordcomputergroup.com/>
www.oxfordcomputergroup.com | Expertise in Identity & Access Management

Registered nr Chamber of Commerce/KvK 32129259, VAT/BTW
NL8188.31.972.BO1

(MVP Profile <https://mvp.support.microsoft.com/profile/jorge1> ) (Blog
<http://blogs.dirteam.com/blogs/jorge/default.aspx> )



cid:image001.png@01C99800.BB23FE50



From: activedir-owner@mail.activedir.org
[mailto:activedir-owner@mail.activedir.org] On Behalf Of David Cliffe
Sent: Wednesday, July 01, 2009 17:54
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] DFS referrals for NETLOGON and SYSVOL



Hi,



I have read the following (thank you Jorge):



http://blogs.dirteam.com/blogs/jorge/archive/2007/07/02/dc-locator-proce
ss-in-w2k-w2k3-r2-and-w2k8-part-3.aspx

http://technet2.microsoft.com/windowsserver/en/library/a9096e88-1634-4da
6-b820-537341d349061033.mspx?mfr=true



...but am still seeing unexpected info the MUP cache ( using DFSUTIL )
for an XP SP2 client in a Windows 2003 SP2 domain. The PreferLogonDC
reg setting has not been implemented at this time. The
SiteCostedReferrals setting *has* been implemented, although I'm not
certain it has any bearing on this situation.



The client machine and its subnet are verified via NLTEST and DFSUTIL to
be in a site where there is a single known-good DC. Authentication is
taking place with that expected DC, but client's MUP cache shows the
active targetset to be a DC in a completely different site. This
happens randomly for SYSVOL or NETLOGON, sometimes both. I have not
taken a trace yet, but wish to do so when time permits.



Since the client is verified to be inside a site where there is a known
good DC, shouldn't the referral have that DC at the top of the list,
since it covers that site?



Thanks,

DaveC



__________ Information from ESET Smart Security, version of virus
signature database 4205 (20090701) __________



The message was checked by ESET Smart Security.



http://www.eset.com


gabriel/tfiUser is Offline

Posts:381

07/02/2009 10:07 PM  
Install SP3 for XP, if I recall well it includes this
http://support.microsoft.com/kb/898900 (that can be installed separately).

I strongly recommend SP3 for XP as it includes so many hot-fixes that
address several issues, “preventing” is always better than “curing”… ;-)



Regards – Gabriele.



From: activedir-owner@mail.activedir.org
[mailto:activedir-owner@mail.activedir.org] On Behalf Of David Cliffe
Sent: mercoledì 1 luglio 2009 17.54
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] DFS referrals for NETLOGON and SYSVOL



Hi,



I have read the following (thank you Jorge):



http://blogs.dirteam.com/blogs/jorge/archive/2007/07/02/dc-locator-process-i
n-w2k-w2k3-r2-and-w2k8-part-3.aspx

http://technet2.microsoft.com/windowsserver/en/library/a9096e88-1634-4da6-b8
20-537341d349061033.mspx?mfr=true



...but am still seeing unexpected info the MUP cache ( using DFSUTIL ) for
an XP SP2 client in a Windows 2003 SP2 domain. The PreferLogonDC reg
setting has not been implemented at this time. The SiteCostedReferrals
setting *has* been implemented, although I'm not certain it has any
bearing on this situation.



The client machine and its subnet are verified via NLTEST and DFSUTIL to be
in a site where there is a single known-good DC. Authentication is taking
place with that expected DC, but client's MUP cache shows the active
targetset to be a DC in a completely different site. This happens randomly
for SYSVOL or NETLOGON, sometimes both. I have not taken a trace yet, but
wish to do so when time permits.



Since the client is verified to be inside a site where there is a known good
DC, shouldn't the referral have that DC at the top of the list, since it
covers that site?



Thanks,

DaveC


DavidCliffeUser is Offline

Posts:15

07/02/2009 10:43 PM  
Jorge/Gabriele...this is interesting - are you suggesting the cause of this
behavior may be due to a prior failover (if that DC was down at one point in
time) and the client will not failback now even after reboot? (I'll have to
re-read about those bits)

Will try this out and post back.

Thanks,
DaveC

On Thu, Jul 2, 2009 at 5:03 PM, Gabriele Scolaro <gabro@gabro.net> wrote:

> Install SP3 for XP, if I recall well it includes this
> http://support.microsoft.com/kb/898900 (that can be installed separately).
>
> I strongly recommend SP3 for XP as it includes so many hot-fixes that
> address several issues, “preventing” is always better than “curing”… ;-)
>
>
>
> Regards – Gabriele.
>
>
>
> *From:* activedir-owner@mail.activedir.org [mailto:
> activedir-owner@mail.activedir.org] *On Behalf Of *David Cliffe
> *Sent:* mercoledì 1 luglio 2009 17.54
> *To:* ActiveDir@mail.activedir.org
> *Subject:* [ActiveDir] DFS referrals for NETLOGON and SYSVOL
>
>
>
> Hi,
>
>
>
> I have read the following (thank you Jorge):
>
>
>
>
> http://blogs.dirteam.com/blogs/jorge/archive/2007/07/02/dc-locator-process-in-w2k-w2k3-r2-and-w2k8-part-3.aspx
>
>
> http://technet2.microsoft.com/windowsserver/en/library/a9096e88-1634-4da6-b820-537341d349061033.mspx?mfr=true
>
>
>
> ...but am still seeing unexpected info the MUP cache ( using DFSUTIL ) for
> an XP SP2 client in a Windows 2003 SP2 domain. The PreferLogonDC reg
> setting has not been implemented at this time. The
> SiteCostedReferrals setting *has* been implemented, although I'm not
> certain it has any bearing on this situation.
>
>
>
> The client machine and its subnet are verified via NLTEST and DFSUTIL to be
> in a site where there is a single known-good DC. Authentication is taking
> place with that expected DC, but client's MUP cache shows the active
> targetset to be a DC in a completely different site. This happens randomly
> for SYSVOL or NETLOGON, sometimes both. I have not taken a trace yet, but
> wish to do so when time permits.
>
>
>
> Since the client is verified to be inside a site where there is a known
> good DC, shouldn't the referral have that DC at the top of the list, since
> it covers that site?
>
>
>
> Thanks,
>
> DaveC
>

You are not authorized to post a reply.
Forums >ActiveDir Mail List Archive >List Archives > [ActiveDir] DFS referrals for NETLOGON and SYSVOL



ActiveForums 3.7
Friends

Friends

VisualClickButoton
Members

Members

MembershipMembership:
Latest New UserLatest:mish
New TodayNew Today:2
New YesterdayNew Yesterday:5
User CountOverall:4858

People OnlinePeople Online:
VisitorsVisitors:61
MembersMembers:0
TotalTotal:61

Online NowOnline Now:

Ads

Copyright 2009 ActiveDir.org
Terms Of Use