Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 343
  • Last Modified:

Network Discovery - Each network in the domain seems isolated after switching to Windows Server 2008 AD

We recently replaced our Windows Server 2003 Active Directory with a Windows Server 2008 one.

The problem we're facing is that suddenly each network seems isolated (in the Microsoft Windows Network domain) and workstations/servers can only see their own network (for example 192.168.2.* can only see PCs on the 192.168.2.* and so on).

This doesn't affect the overall network since most of the services between servers and workstations work fine but certain software rely on the Windows Network to discover PCs (most importantly McAfee ePolicy orchestrator).

I'm not pointing the Windows Server 2008 AD as the source of the problem but it immediately occurred after switching to the new AD.
0
fbmeit
Asked:
fbmeit
  • 4
  • 2
1 Solution
 
tigermattCommented:

The information you've given seems to imply that it is NetBIOS browsing which is failing. If most services are working and being routed correctly between subnets, then it is not a network issue.

Standard NetBIOS announcement broadcast traffic does not cross between subnets, so the browse list from one subnet will not present itself to another.

To resolve this issue, you'll need to install the WINS Server role onto one of your servers. You then point (through DHCP for dynamic addressed clients) all the workstations and servers at the WINS server, and you should find your browse list comes back properly.

I expect the migration of servers failed to migrate WINS, which would explain this issue.

-Matt
0
 
OriNetworksCommented:
Can you ping between subnets by ip address?

Maybe a firewall issue?
You can try temporarily disabling the upgraded servers firewall since on 2008 it is turned on by default.

What was doing the routing of traffic between the subnets before the upgrade?
0
 
fbmeitAuthor Commented:
We can ping between subnets with no problem and its not a WINS either.
The problem should be something on the active directory, as after the movement of FSMO roles from 2003 to 2008 the issue started.
0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 
tigermattCommented:

None of the 5 FSMO roles do any form of tracking of network browsing themselves, although it is quite common for the holder of the PDC Emulator role to be nominated the 'Master Browser' for the domain automatically.

On the PDC Emulator role holder, check the Computer Browser service is set to 'Automatic' and is Started. This maintains the browse lists so must be running at all times.

If you wish to obtain browsing across subnets - or you have some sort of routing device between two segments of the network - a WINS server is required because the broadcast traffic cannot cross the subnet-boundaries and is not relayed by any routers.

-Matt
0
 
fbmeitAuthor Commented:
Eventually the problem has nothing to do with Netbios, Nothing to do with WINS, the issue was resolved by enabling the Computer Browser service from windows services.
0
 
tigermattCommented:
"...the issue was resolved by enabling the Computer Browser service from windows services..."

That is what I stated in my comment http:#a24817880:

"...check the Computer Browser service is set to 'Automatic' and is Started..."
0
 
tigermattCommented:
Objecting per my last comment (http:#a24971334)
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

  • 4
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now