Solved

Domain Policy Changes Automatically - Blocks access to DC

Posted on 2004-10-26
203 Views
Last Modified: 2010-04-19
Hi—

I recently setup a new Windows 2003 domain with about fifteen Windows XP SP1 workstations.  These PCs were migrated from a Windows 2000 domain.  I took the Windows 2003 Domain Controller Policy from another one of our networks with exactly the same setup, just a different domain name.  The network policies seem to work fine until several hours later when the users cannot access the DC (also our file server).  I double-checked the policy and block inheritance is checked, and the policy does not seem to change.  If I re-import the old policy and run gpupdate to refresh it, and the users login/logout it works fine again until a few hours later when access is blocked to the server.

I am not running any firewall software and the Windows XP firewall is disabled.  All PCs can see each other and connect at all times, even when they cannot connect to the DC.

Does anyone have any suggestions to resolve the problem, or determine the source of the problem?

Thanks for your help!

Bill
0
Question by:psuwtb
    4 Comments
     
    LVL 3

    Expert Comment

    by:kelo501
    Bill,

    If you have not already started useing it, download GPMC from microsoft downloads.  In there you can run a result of policy against and machine based on the current logged on user or anyother user.  http://www.microsoft.com/windowsserver2003/gpmc/default.mspx

    reset your machine so that it works wioth the steps above and run a report.
    then check in 90 min to see if the issue returns.  90 min is the defult gprefresh period.

    once the issue returns run the report again and compare the two reports.

    In most cases you will clearly see where the the change is comming from and can then change it.

    If you need help just post back...  

    Kelo501
    0
     

    Author Comment

    by:psuwtb
    Kelo501--

    Thanks for the advice but I was able to solve the problem on my own.  As part of the migration process, I left the old DC running.  The only difference between the new DC and the old one to the rest of the workstations, was a different IP address.  This causes numerous conflicts.  Once I removed the old DC was the network and changed it's IP and hostname, the problems resolved on there own.

    Bill
    0
     
    LVL 3

    Expert Comment

    by:kelo501
    Wow yea that will cause alot of issues.

    It is a good idea to leave the old server around for a bit just to mak sure but alway pull the network connection.

    Its the silly things that get us all the time.

    kelo
    0
     

    Accepted Solution

    by:
    Closed, 200 points refunded.

    modulo
    Community Support Moderator
    Experts Exchange
    0

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
    Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
    Want to pick and choose which updates you receive? Feel free to check out this quick video on how to manage your email notifications.
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!

    931 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now