Win7, Remote Site, endless Logon

Hi Experts,

i have a Problem with a Win7 machine. Long story short: The machine has absolute no problem at the Headquarter, but at a remote site it needs endless until the logon screen appears and endless until the users desktop appears.

Short story long :-)
I dont want to affect your opinions, but i think it has something to do with the fact, that there is no DC at the remote site. The problem occurs only as domain member. when we take it out of the domain, it boots fast.
Some facts:
the user has no server profile
the sites are connected via IPsec
the client gets his ip via DHCP and has the SBS2003 at the HQ as prim. DNS
There is another DC at HQ but without DNS
There are other DCS at others sites, but cant be reached, no routing
I checked the AD sites&services, the site is created, the subnet is configured, there is a intersite-connection to HQ with lowest costs
I checked the RegKey  HKLM\system\curr.contr.set\services\netlogon\parameters\dynamicsitename
the value on the client is the site it should be
i checked the entries in DNS _ldap.tcp_.<sitename>._sites.dc._msdcs.domain.local
there are entries from the two dc at HQ
the windows logfile on both DC at HQ have an entry->
5792 Logon : the remote site has no LDAP entries, LDAP-Server from site HQ will govern this site due to replication costs

after endless logon there are entries in windows logfiles
event 6006 logon : GPClient needed 206 sec. to create session
event 6005 logon : GPClient needs some time to logon
event 6006 logon : GPClient needed 252 sec. to logon

the networkdrives from the startscript are connected and accessable

i checked gpupdate /force
it takes about a minute
ive seen gpupdate failed one time, after a (long :-) reboot it worked again

i checked viáriable logonserver, its the sbs2003 at HQ

i checked nblookup, works
i checked nslookup, works
i can ping across the tunnel everthing from everywhere

you can work with the machine after this long boot and logon periode as normal.
access shares and so on

a winXP machine on this site has no problems

can anybody help?
i can prioide drawings of the network, screenshots, anything you need

thanks in advance
LVL 5
deibelAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Andrew OakeleyConsultantCommented:
If there is no DC at the remote site, then I do not believe there is any reason to have that remote site in AD Sites and Services. Attach the subnet of the remote site to the HQ Site. This will ensure that the computers in the remote site always try the HQ domain controller (which they can route to) first.

Andy
0
deibelAuthor Commented:
ok, we dont have site dependend rules so i gave it a try
changed the subnet to HQ site, left the remote site in AD but with no subnets
replicated it to other dc

but it didnt help
boot and logon still endless

ich checked the regkey dynamicsitename again. its now HQ site
0
Andrew OakeleyConsultantCommented:
Does the workstation have IIS running on it?
Does it have a printer using the HP CUE DeviceDiscovery Service configured on it?
Is there anything else that could be looking for something on another site? Printer etc?
You say there is no server profile - what about folder redirection?
Anything in this thread look useful ? http://social.technet.microsoft.com/Forums/en-US/itprovistanetworking/thread/56310e15-32df-457a-bc38-4cc2fce0a5e5 
0
deibelAuthor Commented:
we finally opened a case at ms support
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
SBS

From novice to tech pro — start learning today.