Link to home
Start Free TrialLog in
Avatar of lasirius
lasirius

asked on

Windows Server 2012 shares crashing

Hi

I have a a network set up with Windows Server 2012 and about 35 users all on Windows 7 Professional. I recently added some shares to a set of pre-existing shares. After doing this each client began began losing their connection to the 2012 file server and the connection for the shares is lost. After the connection to the share drops it will come back within 2 or 3 minutes. This happens on a regular basis (every one hour) throughout the day. The error message ID in Event Viewer on the file server is 30623.
Avatar of McKnife
McKnife
Flag of Germany image

Hi.

The smb shares use port 445. Please monitor if 445 is continuously open by using this tool: portping http://www.tkolb.de/download/dl.php?download=portping_win.rar
Also see if the service called "server" is constantly running.
Avatar of lasirius
lasirius

ASKER

The Server service is running continuously but port 445 closes at the time of the crash.
Good, that's the problem. Please make sure that the service is really not crashing: open eventvwr and look into the system log for service manager events.
The service is not crashing. This is the only error in event viewer:

UNSVMFILE01      30620      Warning      Microsoft-Windows-SMBClient      Microsoft-Windows-SMBClient/Operational      1/8/2014 1:49:19 PM

I am not sure how to determine what is causing the port to close. Do you have any advice?
ASKER CERTIFIED SOLUTION
Avatar of McKnife
McKnife
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The first error is a 30623, then a 30620. I have posted the details for both errors below (while I have taken out some details for security). These errors do only appear while the problem is happening. I have not tried to recreate the shares or restarting the service, or any other modifications. Another detail is that I cannot ping the file server while the problem is occurring. Does this suggest that it is not an application layer problem, and probably a transport layer problem? I will have the person in control of the firewall look for any negative activity on port 445. Do you have any other advice?

Log Name:      Microsoft-Windows-SMBClient/Operational
Source:        Microsoft-Windows-SMBClient
Date:          1/7/2014 9:34:03 AM
Event ID:      30623
Task Category: None
Level:         Warning
Keywords:      (16)
User:          N/A
Computer:      
Description:
Connection to share \unsvmfile01\"I HAVE DELETED HERE" was lost. Status 0xC000020C
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-SMBClient" Guid="{988C59C5-0A1C-45B6-A555-0C62276E327D}" />
    <EventID>30623</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x2000000000000010</Keywords>
    <EventRecordID>14</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="3008" />
    <Channel>Microsoft-Windows-SMBClient/Operational</Channel>
    <Computer></Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="Object">0xfffffa800536b020</Data>
    <Data Name="OldState">0</Data>
    <Data Name="NewState">1</Data>
    <Data Name="Status">3221225996</Data>
    <Data Name="NameLength">29</Data>
    <Data Name="ObjectName">
  </EventData>
</Event>

Log Name:      Microsoft-Windows-SMBClient/Operational
Source:        Microsoft-Windows-SMBClient
Date:          1/7/2014 9:34:03 AM
Event ID:      30620
Task Category: None
Level:         Warning
Keywords:      (16),(2)
User:          N/A
Computer:    
Description:
Connection to server "" IP Address [fe80::551c:fe94:417b:fede%12]:445 was aborted.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-SMBClient" Guid="{988C59C5-0A1C-45B6-A555-0C62276E327D}" />
    <EventID>30620</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x2000000000000012</Keywords>
    <EventRecordID>1</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="3008" />
    <Channel>Microsoft-Windows-SMBClient/Operational</Channel>
    <Computer>""</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="VcEndpoint">0xfffffa80052f5e20</Data>
    <Data Name="RemoteAddressLength">28</Data>
    <Data Name="RemoteAddress">170001BD00000000FE80000000000000551CFE94417BFEDE0C000000</Data>
    <Data Name="ServerNameLength">12</Data>
    <Data Name="ServerName">""</Data>
  </EventData>
</Event>
> I have not tried to recreate the shares or restarting the service, or any other modifications.
You should try it.
> Another detail is that I cannot ping the file server while the problem is occurring
Interesting. Then the whole network connectivity breaks, not only the server service.
This is the first time that I am awarding points. Please do not let my 'B' grade for the solution distract you. Your help will assist me in solving the problem. Thank you!
I'm having a very similar problem with a client's 2012 server. You've accepted a solution, and awarded points for it, but you didn't say what you actually did to solve the problem. Any chance you might share that? This is very relevant for me right now.