SBS Server Crashed - Active Directory


A client called me this morning saying their server had crashed.

They couldn't gain access to the server at all.

two users came in at 7.30am this morning and everything was working ok.

The MD came into the office about 9am connected his laptop and that's when the problems happened. I logged into the server remotely and noticed these problems.

first error in event viewer

The "Windows default" Policy Module logged the following warning: The Active Directory connection to SERVER.domain.local has been reestablished to SERVER.Domain.local

Services stopped and will not start

Cryptographic Services
DRF Namespace
MS Exchange EdgeSync
MS Exchange File Distribution
MS Exchange Forms Based
MS Exchange Information Store
MS Exchange RPC Client Access
MS EXchange system attendant
MS Exchange Throttling - says starting
MS Exchange Transport - says starting

Netlogon won't start
Network location awareness won't start

nor will windows time or worksation service

The internet works fine but the local network is down. I have uninstalled the LAN card and reinstalled but nothing.

In the bottom right the network card looks unplugged but under network and sharing centre it's enabled and online.

When i try and look for the server shares locally \\servername and press enter it get the error message 'windows cannot access \\servername

When I ping the server name from the server it brings back the IP6 address but I can ping the IP4 address of

We are running SBS2011 with exchange

Any issues as I am stuck?

Who is Participating?
Gareth GudgerConnect With a Mentor Commented:
Hmm, I don't think any of these errors are related to not being able to ping the server.

So, to clarify, when you enable RRAS no one can ping the server anymore?

Do you have the Windows Firewall enabled? If so, that will block ICMP ping requests by default.
Gareth GudgerCommented:
Is this virtualized by any chance? I have seen an issue with NIC drivers blowing up with corrupt VMTools....
ryank85Author Commented:
No not virtualised - I hope I don't need to reinstall the OS. I have run out of idea's now.

Its just strange that I can see the internet but the lan card is showing as disconnected.
WEBINAR: GDPR Implemented - Tips & Lessons Learned

Join the WatchGuard team on Thursday, March 29th as we recount some valuable lessons learned in weighing the needs of a business against the new regulatory environment, look ahead at the two months left before implementation, and help you understand the steps you can take today!

Gareth GudgerCommented:
Any firewalls enabled on the server? Have you tried a different switch port? Does the server have a second NIC?

Is there by any chance an IP conflict on the network? Try rebooting the server. It will announce an IP conflict within a few minutes of booting.

Did the server lose its static IP? Switch to DHCP? What do you get if you run IPCONFIG from command line. Is it showing a 169.x.x.x.

TCP/IP could be hosed. You could try running NETSH WINSOCK RESET from the command line.
ryank85Author Commented:

The server has a local firewall - I will try and disable that

I have removed everything from the network, I only have the server which is connected directly into the router, it can see that ok.

It has a 2nd NIC and I have tried that, still nothing.

It kept all the static IP address settings however when I ran ipconfig it was pining the IP6 address and not the IP4 of - when i disable the IP6 and ping servername its doesnt ping anything.

I will try the winsock now

Gareth GudgerCommented:
I think you are confusing IPCONFIG with the PING command.

PING will always default to IPv6. If you need to PING with IPv4 just add the "-4" switch to the end. e.g. PING MYSERVERNAME -4

Check IPCONFIG to see what is listed as IP Address. If there is an IP conflict it will list 169. I believe.
ryank85Author Commented:
Hi All

We managed to get the server working again, basically the DNS Client Server was stopping all the other services from starting, even though this was started itself.

All is working apart from an issue with the DHCP, when I am logged into the Server I run this command 'ping servername -4' and I get the correct IP address of the server.

However when I am using RRAS I cannot see the server. DHCP Relay is setup in RRAS Setting etc as I have configured this ok in the past, I can't even ping the server address -

Errors in Event Viewer.

1) This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

2) The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

3) Possible Memory Leak.  Application ("C:\Windows\system32\mmc.exe" "C:\Windows\system32\dhcpmgmt.msc" ) (PID: 9168) has passed a non-NULL pointer to RPC for an [out] parameter marked [allocate(all_nodes)].  [allocate(all_nodes)] parameters are always reallocated; if the original pointer contained the address of valid memory, that memory will be leaked.

I have tried the fix on number 2 above and that doesn't work once the service has been restarted.

ryank85Author Commented:
Correct no one can ping the server from remotely when the connect to the VPN. They can't even access the server shares or connect to exchange server from their outlook.

I am working remotely so it's hard to tell whether the dhcp is working correctly now as I have just created a new scope so the only addresses showing the leased section are for RRAS.

Gareth GudgerCommented:
Does it ping internally?
ryank85Author Commented:
I can only dial into the server at the moment as all the client machines are off. Nslookup works ok on the server. I'll check this tomorrow.
ryank85Author Commented:
all appears to be working now. I cleared all the DNS Cache on the server and rebooted and all the remote users could access shares and outlook.

I will keep an eye on the error logs

thanks again for all your help.
Gareth GudgerCommented:
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.