[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

VLAN ACLs and Windows 2003 group policy replication - syslogs analysis

Posted on 2006-06-09
5
Medium Priority
?
488 Views
Last Modified: 2008-02-26
I have been analyzing a problem and I wanted another opinion.

VLAN A - group policy replication works fine.  There are no ACLs between here and the server.
VLAN B - group policy replication does not work.  There are ACLs between here and the server.

    I have analyzed the syslog messages for a computer in VLAN A and VLAN B.  There are no denies in any of the syslog messages.  The only thing I can find which is "odd" is a TCP RESET-O setting for the /88 (Kerberos) quite often with the traffic in both VLANS.  There is NATing going on in the environment.  I wanted to find out if any of you have run across this issue and had any advice.  If there was deny traffic, it would be an open and shut case.  There isn't so it seems that something is related to network side of things, but I'm not seeing immediate issues.  Thanks for your suggestions.

Awakenings
0
Comment
Question by:awakenings
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 

Author Comment

by:awakenings
ID: 16873139
The duration on the TCP RESET-O is 00:00:00 if that helps.
0
 
LVL 4

Expert Comment

by:tomerlei
ID: 16873946
Hi,
TCP RESET -O is when a server doesn't listen to a protocol, does it say which protocol or which server?
0
 

Author Comment

by:awakenings
ID: 16873974
Really...  I'll have the team check on this too.  The protocol is kerberos.  I'll have to follow up with this on Monday.
0
 

Author Comment

by:awakenings
ID: 16873979
Do you have a web site that explains all the TCP resets?
0
 
LVL 4

Accepted Solution

by:
tomerlei earned 2000 total points
ID: 16874233
TCP Reset-O means that the computer sent a query to a server in specific protocol and that server was not listening for this protocol, port 88 is the standard port that is being used by kereberos.
Does the event log says which server did he try to query?
From what you say i belive he tries to query your DC and for some reason the server does not reply to him.
And from what i understood your server is connected to two seperate VLANS right?
if it does, then how exactly it is connected? the server has two NICs or a 802.1q supporting NIC?
And what is the IP range that is being used in each vlan?
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question