Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Problems using proxy server through vpn, plus DC error

Posted on 2004-10-13
7
Medium Priority
?
3,917 Views
Last Modified: 2010-05-18
We have users in Monaco (ahhh for the chance to go do some local tech support!), who lost internet connectivity to our proxy server in London at the weekend.  They get the error in IE of:

Appliance Error (configuration_error)
Your request could not be processed because of a configuration error: "No authority could be contacted for authentication."  

They are in a separate domain, and connect back through a VPN to us.  If the proxy server name in IE is changed to one local to them, they are fine.  

At the same time (over the weekend), I'm seeing these errors on our DC here in London, where the Monaco Domain can't be contacted.  These errors did not occur before the weekend.  Spooky coincidence??


Event Type:      Error
Event Source:      NETLOGON
Event Category:      None
Event ID:      5719
Date:            13/10/2004
Time:            12:16:29
User:            N/A
Computer:      LGLONA01
Description:
No Windows NT or Windows 2000 Domain Controller is available for domain<MonacoDomain>. The following error occurred:
There are currently no logon servers available to service the logon request.  
Data:

I'm currently poking through the suggestions on www.eventid.net for this error, but not finding a fix yet.  Anyone got any ideas?  cheers.
0
Comment
Question by:Danny Child
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 15

Expert Comment

by:harleyjd
ID: 12298196
What's going on with their domain controller? Sounds like Monaco can't see it, so noone else is going to be able to either.

I'd focus on the DC not your proxy.

Check the sysvol and netlogon folders are shared correctly. Check the DNS in Monaco. Fly out there and see it for yourself.

(surely I deserve the points just for that last suggestion) :)

0
 
LVL 23

Author Comment

by:Danny Child
ID: 12298902
ok, the Monaco server can open both the \\london\netlogon and \\london\sysvol shares.
Monaco can ping London, but not the other way around (I'm surprised pings work at all, I thought the VPN would kill them)

dns in monaco seems ok - the 2 servers it's set to use are:
itself - as primary
the london DC as secondary.

nslookups on www addresses work ok (though I get the occassional timeout).  I also tried reversing the order of the dns servers, and repeating the www lookups.  Still good.  

and harleyjd, when that plane ticket's in my hand, the points are all yours....

kinda looking like authentication to me, but hey, if I had the answers, I wouldn't be here!
0
 
LVL 15

Accepted Solution

by:
harleyjd earned 2000 total points
ID: 12299046
How is the vpn configured? IPSEC tunnel or PPTP back to your server or a RAS firewall?

Did you used to be able to ping monaco?

Has someone enabled some sort of firewall in monaco?

You have remote access to monaco, -if you can't ping it, how?

The trust between the sites is broken, I suspect it's monaco stopping london connecting somehow. Make sure those sysvol/netlogon shares are visible on the monaco server from monaco....

I really think you need to be onsite. Tell your boss "some guy on the internet said I had to go"

0
New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

 
LVL 23

Author Comment

by:Danny Child
ID: 12306637
harleyjd:
vpn - managed by 2 Netscreen 25 boxes, one at each end.  Pretty sure it's pptp.

pinging monaco?  dunno if it *used* to work, I'm the new guy round here

monaco firewall?  shouldn't be any changes.

remote access?  some machines, ie Mine, are permissioned to use the vpn, so I can pcAnywhere to it (and ping it), but the DC can't.  

trust between the sites?  I'll check it out, but I'm not exactly God's Gift to Trusts, so I'll go easy...  and yes, the monaco box can open \\LondonDC\netlogon.

running
repadmin /showreps <LondonDC> dc=<DomainName>,dc=com

show all is ok, but doesn't list the Monaco servers.  Methinks it should!

There's also plans underfoot to make all the Monaco users join our domain, so this is all gonna change anyway.   Thanks for all your help, this is really helping me get a handle on this.  
0
 
LVL 15

Expert Comment

by:harleyjd
ID: 12307091
ahhh...

If the DC cannot access the VPN, then the DC cannot authenticate anyone from the other domain as either the requests do not arrive, or the responses are blocked. This goes to the trust as well - it can't be verified if it can't communicate.

I'm not sure there should be replication between trusted DC's - I'm no gift either - so I'm not sure that the repadmin path is the right one.

I think it's really important that the 2 DC's have full and complete visibility of one another.

One other thought - check the routing on your PC vs the london server. Make sure there is a valid route for monaco on the server.

0
 
LVL 23

Author Comment

by:Danny Child
ID: 12379487
I'll keep on it.  We've set up a workaround to give the users a local proxy in monaco, so it looks like my trip there is off... sob.
harleyjd - thanks for all the excellent info.
0
 
LVL 15

Expert Comment

by:harleyjd
ID: 12379580
Well, I'm sorry I coulfn't get you the trip...
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
With its various features, Office 365 can not only help you with your day-to-day business tasks, it can also do wonders for your marketing campaign.
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question