Solved

Win2k policies / login scripts are not running at remote offices (different IP subnet)

Posted on 2004-03-23
11
203 Views
Last Modified: 2010-04-12
Hi there,

we have a Win2k Active Directory environment, with some old legacy NT4 servers still performing some things such as DNS etc.

I have a problem whereby our regional offices aren't having the global policy applied to them (or the login script specified by the same policy.)

I have a sneaky feeling it's all something to do with IP (WINS?) but I have only a basic understanding of it so don't really know where to start.

I will post 2 IPConfigs; my one from our office, and another one from one of the regional offices: -

Mine:
                IP Address. . . . . . . . . . . . : 10.10.50.1

      Subnet Mask . . . . . . . . . . . : 255.0.0.0

      Default Gateway . . . . . . . . . : 10.10.1.1

      DHCP Server . . . . . . . . . . . : 10.10.10.2

      DNS Servers . . . . . . . . . . . : 10.10.10.1
      Primary WINS Server . . . . . . . : 10.0.0.1

Regional:
                IP Address. . . . . . . . . . . . : 10.0.3.3

      Subnet Mask . . . . . . . . . . . : 255.255.255.0

      Default Gateway . . . . . . . . . : 10.0.3.254

      DHCP Server . . . . . . . . . . . : 10.0.3.254

      DNS Servers . . . . . . . . . . . : (external)
      Primary WINS Server . . . . . . . : 10.0.0.1

The only thing I can think of is that the subnet masks in the regions are too restrictive; but I think I remember changing this manually one day a looong time ago as a test and then basically couldn't log on.

Help!
0
Comment
Question by:dyl666
  • 3
  • 3
  • 2
  • +1
11 Comments
 
LVL 11

Accepted Solution

by:
kabaam earned 250 total points
ID: 10658267
mine:
the subnet mask indicates a network address of 10.0.0.0
therefore anything that gets entered in the zeros are looking like a local subnet client address.
basically the computers at regional are looked at as being local by your computer.
I think a redesign in subnetting of network would be needed.  

hth
Chad
0
 
LVL 16

Expert Comment

by:JammyPak
ID: 10658330
is everything besides group policy working?

I'm curious, because the setup is a bit unusual.

your computer thinks that all the regional ones on on it's local subnet, but the regional computers think yours is across a router. this would typically mean that packets can be routed in one direction, but not in the other.

you may want to try and standardize on Class B or C subnets across the company....
0
 

Author Comment

by:dyl666
ID: 10658359
Everything is working as far as I know (and I'm sure I'd be told pretty quickly :) ) - however I do believe they have a problem where it takes them ages to log on. As in about 30 - 60 seconds. It's not an issue as they don't log off so often but it is annoying when it happens. I assume it's related to the same sort of thing.
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 

Author Comment

by:dyl666
ID: 10658415
Chad:

"the subnet mask indicates a network address of 10.0.0.0
therefore anything that gets entered in the zeros are looking like a local subnet client address.
basically the computers at regional are looked at as being local by your computer."

I sort of understand what you're saying; and yet I don't understand why, if my computer (or presumably the server) thinks that the regional pc is local, it wouldn't apply the policy? I'm not questioning the validity of your answer at all, just saying I don't understand the implications!
0
 
LVL 11

Expert Comment

by:kabaam
ID: 10658537
There are two parts to an IP address.  The network ID and the node(PC) ID.
The subnet mask is used to identify what part of the IP address is network address.
When an IP address is accessed it compares to local subnet mask to determine if it is a local address or not.
If the address is not local subnet... it is sent out via Default gateway.  Local will stay on subnet.

your IP subnet of 255.0.0.0 identifies that the first block designates the network address.
Anything after that is the node or computer address.  Any IP starting with 10. ... is considered local.

How are these sites connected?  Is there a Domain controller in the regional site?
0
 
LVL 16

Expert Comment

by:JammyPak
ID: 10658571
"why, if my computer (or presumably the server) thinks that the regional pc is local, it wouldn't apply the policy?"

your pc may think it's local, but it's not. That means that instead of routing to get to it, it will try to find it on the local subnet...and it ain't there...so - host not found, policy not applied
0
 

Author Comment

by:dyl666
ID: 10658586
No, no domain controller, only workstations. They are connected via the internet (ADSL) and cisco PIX boxes.

So if I'm understand you correctly, either my subnet needs to change (but wouldn't that then render my WINS server [10.0.0.1] unreachable...?) or I need to change the IP addresses of all the regional pc's to (for example) 11.0.0.x?

Sorry for being a dufus : /
0
 
LVL 16

Assisted Solution

by:JammyPak
JammyPak earned 250 total points
ID: 10658622
yes, this may not be a minor change...

if you change your subnet mask, then you WINS server is no longer on yout network (logically)...so, if the WINS server is physically on your network, you won't be able to reach it anymore. You would need to use the same network address (ex. 10.10.x.x) for every host that is on the same subnet, and make sure that routing is setup for all the hosts that are not.
0
 
LVL 16

Expert Comment

by:JamesDS
ID: 10660379
Group policies don;t apply over a slow link

The default is 500k but the detection is done by ping timing so will likely vary

Change this setting in your default domain policy and it should work

Machine Policy:
Administrative Templates\System\Group Policy      Group Policy slow link detection

Defines a slow connection for purposes of applying and updating Group Policy.  If the rate at which data is transferred from the domain controller providing a policy update to the computers in this group is slower than the rate specified by this setting, the system considers the connection to be slow.  The system's response to a slow policy connection varies among policies. The program implementing the policy can specify the response to a slow link. Also, the policy processing settings in this folder lets you override the programs' specified responses to slow links.  To use this setting, in the Connection speed box, type a decimal number between 0 and 4,294,967,200 (0xFFFFFFA0), indicating a transfer rate in kilobits per second. Any connection slower than this rate is considered to be slow. If you type 0, all connections are considered to be fast.  If you disable this setting or do not configure it, the system uses the default value of 500 kilobits per second.  This setting appears in the Computer Configuration and User Configuration folders. The setting in Computer Configuration defines a slow link for policies in the Computer Configuration folder. The setting in User Configuration defines a slow link for settings in the User Configuration folder.  Also, see the Do not detect slow network connections and related policies in Computer Configuration\Administrative Templates\System\User Profile. Note: If the profile server has IP connectivity, the connection speed setting is used. If the profile server does not have IP connectivity, the SMB timing is used.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SQL SERVER 2000 mdf file defragmentation 4 56
Images sometimes not printed 6 484
Windows 16 350
DNS server query - zone verus cache 5 188
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
With User Account Control (UAC) enabled in Windows 7, one needs to open an elevated Command Prompt in order to run scripts under administrative privileges. Although the elevated Command Prompt accomplishes the task, the question How to run as script…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question