Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 148
  • Last Modified:

SBS Server Crashed - Active Directory

Hi,

A client called me this morning saying their server had crashed.

They couldn't gain access to the server at all.

two users came in at 7.30am this morning and everything was working ok.

The MD came into the office about 9am connected his laptop and that's when the problems happened. I logged into the server remotely and noticed these problems.

first error in event viewer

The "Windows default" Policy Module logged the following warning: The Active Directory connection to SERVER.domain.local has been reestablished to SERVER.Domain.local

Services stopped and will not start

Cryptographic Services
DRF Namespace
MS Exchange EdgeSync
MS Exchange File Distribution
MS Exchange Forms Based
MS Exchange Information Store
MS Exchange RPC Client Access
MS EXchange system attendant
MS Exchange Throttling - says starting
MS Exchange Transport - says starting

Netlogon won't start
Network location awareness won't start

nor will windows time or worksation service

The internet works fine but the local network is down. I have uninstalled the LAN card and reinstalled but nothing.

In the bottom right the network card looks unplugged but under network and sharing centre it's enabled and online.

When i try and look for the server shares locally \\servername and press enter it get the error message 'windows cannot access \\servername

When I ping the server name from the server it brings back the IP6 address but I can ping the IP4 address of 192.168.5.2

We are running SBS2011 with exchange

Any issues as I am stuck?

Ryan
0
ryank85
Asked:
ryank85
  • 6
  • 6
1 Solution
 
Gareth GudgerCommented:
Is this virtualized by any chance? I have seen an issue with NIC drivers blowing up with corrupt VMTools....
0
 
ryank85Author Commented:
No not virtualised - I hope I don't need to reinstall the OS. I have run out of idea's now.

Its just strange that I can see the internet but the lan card is showing as disconnected.
0
 
Gareth GudgerCommented:
Any firewalls enabled on the server? Have you tried a different switch port? Does the server have a second NIC?

Is there by any chance an IP conflict on the network? Try rebooting the server. It will announce an IP conflict within a few minutes of booting.

Did the server lose its static IP? Switch to DHCP? What do you get if you run IPCONFIG from command line. Is it showing a 169.x.x.x.

TCP/IP could be hosed. You could try running NETSH WINSOCK RESET from the command line.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
ryank85Author Commented:
Hi,

The server has a local firewall - I will try and disable that

I have removed everything from the network, I only have the server which is connected directly into the router, it can see that ok.

It has a 2nd NIC and I have tried that, still nothing.

It kept all the static IP address settings however when I ran ipconfig it was pining the IP6 address and not the IP4 of 192.168.5.2 - when i disable the IP6 and ping servername its doesnt ping anything.

I will try the winsock now

Ryan
0
 
Gareth GudgerCommented:
I think you are confusing IPCONFIG with the PING command.

PING will always default to IPv6. If you need to PING with IPv4 just add the "-4" switch to the end. e.g. PING MYSERVERNAME -4

Check IPCONFIG to see what is listed as IP Address. If there is an IP conflict it will list 169. I believe.
0
 
ryank85Author Commented:
Hi All

We managed to get the server working again, basically the DNS Client Server was stopping all the other services from starting, even though this was started itself.

All is working apart from an issue with the DHCP, when I am logged into the Server I run this command 'ping servername -4' and I get the correct IP address of the server.

However when I am using RRAS I cannot see the server. DHCP Relay is setup in RRAS Setting etc as I have configured this ok in the past, I can't even ping the server address - 192.168.5.2

Errors in Event Viewer.

1) This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

2) The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

3) Possible Memory Leak.  Application ("C:\Windows\system32\mmc.exe" "C:\Windows\system32\dhcpmgmt.msc" ) (PID: 9168) has passed a non-NULL pointer to RPC for an [out] parameter marked [allocate(all_nodes)].  [allocate(all_nodes)] parameters are always reallocated; if the original pointer contained the address of valid memory, that memory will be leaked.

I have tried the fix on number 2 above and that doesn't work once the service has been restarted.

regards
Ryan
0
 
Gareth GudgerCommented:
Hmm, I don't think any of these errors are related to not being able to ping the server.

So, to clarify, when you enable RRAS no one can ping the server anymore?

Do you have the Windows Firewall enabled? If so, that will block ICMP ping requests by default.
0
 
ryank85Author Commented:
Correct no one can ping the server from remotely when the connect to the VPN. They can't even access the server shares or connect to exchange server from their outlook.

I am working remotely so it's hard to tell whether the dhcp is working correctly now as I have just created a new scope so the only addresses showing the leased section are for RRAS.

Ryan
0
 
Gareth GudgerCommented:
Does it ping internally?
0
 
ryank85Author Commented:
I can only dial into the server at the moment as all the client machines are off. Nslookup works ok on the server. I'll check this tomorrow.
0
 
ryank85Author Commented:
all appears to be working now. I cleared all the DNS Cache on the server and rebooted and all the remote users could access shares and outlook.

I will keep an eye on the error logs

thanks again for all your help.
0
 
Gareth GudgerCommented:
Awesome!
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

  • 6
  • 6
Tackle projects and never again get stuck behind a technical roadblock.
Join Now