Solved

Clients won't login to local domain controller when WAN link is down

Posted on 2004-04-01
9
377 Views
Last Modified: 2006-11-17
I have a Win2K AD domain in a school district, and have multiple sites configured in AD, each with their own domain controller. These sites are connected physically by T1. When the T1 is up and operational, the clients login just fine, and by running a script, I can tell that they are authenticated by the local on-site domain controller. But when the WAN is down, they can't log in at all. The local DC's are configured as GC controllers, and each site has all their resources local. I designed it this way so they would be able to continue to work when the WAN link was unavailable. But it's not working. Something is still tying them to the main site, where the PDC emulator resides. Shouldn't I be able to log these clients in with local resources when the WAN is down?
0
Comment
Question by:David Goldsmith
  • 5
  • 4
9 Comments
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 10734881
Yes you should.

Are these all separate domains? Or is it the same domain but with a DC in each location?

Also, how are you binding the NICs in the DCs? I assume these are multihomed to allowed internet access or do they have a different gateway for that purpose?
0
 

Author Comment

by:David Goldsmith
ID: 10735357
Single domain, separate DC in each location. Servers not multi-homed, they have a gateway to get back to the District Office and on out to the internet.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 10735448
Is a DNS server operating locally on the local DCs? And are the clients using the local DNS if you check their IP info?
0
 

Author Comment

by:David Goldsmith
ID: 10735559
No local DNS, only primary DNS servers at main site. Is that it? I have to have DNS services running on each remote DC?
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 500 total points
ID: 10735645
Yes if you lose DNS capabilities you wont be able to log on. Set up a secondary DNS server at each local location (just put it on with the DC) and specify the secondary DNS server as an additional DNS server in the clients IP settings.
0
 

Author Comment

by:David Goldsmith
ID: 10735656
As I'm asking that question, it's becoming obvious to me that I would definitely need DNS at the site in order to route network requests internally...either that, or implement a local hosts file on the clients for internal requests.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 10735697
Depends on the number of clients you have at each location I guess. I would say if you have more than 5 to 10 use a DNS server...less headache.

Also a DNS server in each location should improve performance (as long as the local DNS server you implement is listed first in the clients IP settings with the remote second).
0
 

Author Comment

by:David Goldsmith
ID: 10735853
Thanks, that was a forehead slapper...I should have known that one...
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 10735943
Happens to all of us. :)
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A brief overview to explain gateways, default gateways and static routes OR NO - you CANNOT have two default gateways on the same server, PC or other Windows-based network device. In simple terms a gateway is formed when a computer such as a serv…
This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now