Solved

Windows 2008 DC not allowing connections from different subnet

Posted on 2009-05-05
6
1,227 Views
Last Modified: 2013-12-04
Hi,

I recently built a new external Windows 2008 domain in a new forest at windows 2008 level. This domain is to be hosted externally to our internal domain, which is a windows 2003 domain level domain. I eventually plan to create a one way trust where the external domain trusts the internal domain. However, I am having communications issues between internal DCs and my new Windows 2008 DC. Below is the situation:

ExtServer1 - Win 2008 SP1 DC (located in "external subnet 1")
ExtServer2 - Win 2008 SP1 DNS member server (located in "external subnet 1")
ExtServer3 - Win 2003 SP2 ISA member server (located in "external subnet 1")

IntServer1 - Win 2003 SP2 DC (located in "internal subnet 10")
IntServer2 - Win 2003 SP2 DC (located in "internal subnet 11")
IntWporkstation1 - Win XP SP3 workstation (located in "internal subnet 12")

From ExtServer2: telnet ExtServer1 389 (works fine)
From ExtServer3: telnet ExtServer1 389 (works fine)

From IntServer1: telnet ExtServer1 389 (does not work)
From IntServer2: telnet ExtServer1 389 (does not work)
From IntWorkstation1: telnet ExtServer1 389 (does not work)

From IntServer1: telnet ExtServer2 53 (works fine)
From IntServer2: telnet ExtServer2 53 (works fine)
From IntWorkstation1: telnet ExtServer2 53 (works fine)

Basically, I can not access this DC "ExtServer1" from any other subnet. Access fromt he same subnet works fine. I have a full access from internal subnets to external subnets, so no network issues blocking access to this server. Also I can get to this subnet, as you can see from the tests to another member server in the "external" subnet domain.

I am new to windows 2008, but have seen a lot of changes int he windows firewall and security space. Can anyone point me int he right direction or tell me what could be the issue here? Once I have successfully able to communicate from my internal subnets to this DC, I can create my trust and be on my way with other tasks.

Thanks.
kineticexpert
0
Comment
Question by:kineticexpert
  • 4
  • 2
6 Comments
 

Author Comment

by:kineticexpert
ID: 24302685
Sorry, also to add to this. Prior to completing a DCPROMO on this windows 2008 server (ExtServer1), I was able to successfully copy across files to the server from any server/workstation in internal subnets (i.e. IntServer1, IntServer2, IntWorkstation1). However, now I can not access at all from the internal subnets as mentioned above.

So one would assume some policy has been applied since becoming a domain controller.

Thanks.
Adrian
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24302947
Have you checked the firewall settings on the 2008 DC?   I'd even disalbe it for a quick test too.
A network trace would really come in handy here.
You could also run portqry from the internal box to the 2008 DC and see what the results are from IntServer1 to ExtServer1
Thanks
Mike
0
 

Author Comment

by:kineticexpert
ID: 24303467
Hi Mike,
Thanks for the response. How would you suggesst I do a network trace? I have tried using network monitor, but have not been successful in trying to understand it.
I used portqry and got the below results.

=============================================

 Starting portqry.exe -n 10.48.128.50 -e 389 -p TCP ...

Querying target system called:

 10.48.128.50

Attempting to resolve IP address to a name...

Failed to resolve IP address to name

querying...

TCP port 389 (ldap service): FILTERED
portqry.exe -n 10.48.128.50 -e 389 -p TCP exits with return code 0x00000002.

Thanks.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Accepted Solution

by:
kineticexpert earned 0 total points
ID: 24303540
OK, I feel like an absolute tool right now. But I have fixed the network communications to this server from the internal subnets.
It ended up being a specific translation on the firewall:
ExtServer1 to IntServer2 was being translated

Not sure why it affected all internal networks from accessing ExtServer1, when it was specificallly only to one single server being translated.
Anyway, I beleive my issues are sorted.

Thanks.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24303631
well done!!
So now does that portqry come back as "listening"
Thanks
 
Mike
0
 

Author Comment

by:kineticexpert
ID: 24303811
yeah it does...
quite a handy little tool to use. I was relying on my network logs, which wasn't showing anything...so hence thought it was fine.
Thanks.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now