Solved

One physical site with 2 subnets

Posted on 2014-11-18
16
232 Views
Last Modified: 2014-11-30
Hi there,
Running server 2008 ent R2 domain with 2 DC server 2008 and one  DC server 2012 ent datacenter all clients windows 8.1 x64.  On my physical site I was running 2 subnets 10.10.10.0/24 and 10.10.2.0/24.  Things were working fine. Till yesterday any computer attaining IP from subnet 10.10.2.0/24 is really really slow logging in, and the same computer would act accessing the network resources.  I also tried to rejoined to domain the computer which already had 10.10.2.0/24 IP, it says the domain does not exist.
Steps:
-I manually put the IP from subnet 10.10.10.0/24 and restarted the machine things were very well, no lagging while logging on, can access the network resources etc.
-I disabled the scope for 10.10.2.0/24 under superscope of DHCP server and re-added just to make sure the problem goes away, the problem persist while any computer gets the IP from this subnet.

I had no issues before.  This problem appeared recently.  Could it be the new DC server 2012 doing something odd?

Need help with this odd problem.
0
Comment
Question by:amanzoor
  • 9
  • 4
  • 2
  • +1
16 Comments
 

Accepted Solution

by:
KinnyAdelaide earned 300 total points
Comment Utility
Have you modified the router configurations recently? or checked if there is a problem with routing? I dont think its a layer 2 issue, could be layer 3 issue. Top of my mind, i can draw out other possibilities. But interesting, let me know the conclusion.
0
 
LVL 8

Assisted Solution

by:nader alkahtani
nader alkahtani earned 100 total points
Comment Utility
pathping command may help you to see where is the problem http://technet.microsoft.com/en-us/library/cc787365(v=ws.10).aspx
0
 
LVL 4

Assisted Solution

by:bominthu
bominthu earned 100 total points
Comment Utility
Are you able to ping DNS server (10.10.10.xxx) from 10.10.2.0/24 ?

I think it is routing/access-list issue between 10.10.2.0/24 and 10.10.10.0/24.
You need to look at your router or firewall setting.
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Kinny,
No changes in router were made.
Nadir,
Pingpath is fine even if the machine attains an IP from 10.10.2.0/24
Bominthu;
Yes I am able to ping the DNS and even the DHCP from the machine with IP 10.10.2.0/24

Guys its the really really slowness from this subnet.  Amazingly if I assign static IP from 10.10.10.0/24 the machines boost up with no slowness.
I thought DHCP logs would tell me something, but the funny thing is the machine gets the IP from 10.10.2.0/24 but after a long delay.  I had already removed any antivirus and firewalls from DHCP and the client to set aside the possible cause.
I am totally out of ideas.  Need help
0
 

Expert Comment

by:KinnyAdelaide
Comment Utility
DNS not looking up the DNS server properly. Maybe there is a fault in the records? Try capturing the packets from DNS and dhcp.
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Guys,
I corrected the sites and services with correct subnet it should be 10.10.2.0/23, I made a new scope under DHCP for 10.10.2.0/23.  Things work now my clients in 10.10.2.0/23 cannot access files from my server in 10.10.10.0/24.  Help me to configure routing on my switch please.
For now, I have put 2 IPs on my file server and DC to work so that my clients can access the files;
i.e 10.10.10.11 and 10.10.2.11.  But I do not want my DC to be multihomed.  Need help
0
 

Expert Comment

by:KinnyAdelaide
Comment Utility
Can u show us a topology of your network? Maybe one of us can accurately tell you what route is needed at which device. I think a static default route is needed on the switch. Would be  a good idea to show us your switch's routing table.
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Kinny,
Attached is the show run from my brocade, will showrun, vlan, and route from a client (windows8.1)  On my brocade I did not find any show ip route.
brocade6450.txt
0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Topology:
Cisco2911 ............>>>brocade 6450.........>>>>clients     (very simple)
router                           switch                                win8.1
0
 

Expert Comment

by:KinnyAdelaide
Comment Utility
In your IPV4 route on client. I can only see the 2.0 network with /23. Whereas your switch is in 10.0 network. I think your client needs a route to 10.0 network, /24, DGW to router interface. Next setup a IP route 0.0.0.0 0.0.0.0 {interface type & number to the router}. Right now I think link fault lies between your client and switch. Any other expert  thinks so too?
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Here is the show ip route from my cisco 2911 router:
router_2911#show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route, + - replicated route

Gateway of last resort is xx.xx.xx.xxx to network 0.0.0.0

S*    0.0.0.0/0 [1/0] via xx.xx.xx.xxx
      10.0.0.0/8 is variably subnetted, 6 subnets, 3 masks
C    10.10.2.0/23 is directly connected, GigabitEthernet0/0  <<<<.......if this is here why am I not able to see shared folders from 10.10.10.0/24?
L        10.10.3.254/32 is directly connected, GigabitEthernet0/0
C        10.10.10.0/24 is directly connected, GigabitEthernet0/0
L        10.10.10.254/32 is directly connected, GigabitEthernet0/0
C        10.10.11.0/24 is directly connected, GigabitEthernet0/1.801
L        10.10.11.254/32 is directly connected, GigabitEthernet0/1.801
      xx.0.0.0/8 is variably subnetted, 2 subnets, 2 masks
C        72.xx.xx.xxx/28 is directly connected, GigabitEthernet0/1.420
L        72.xx.xx.xxx/32 is directly connected, GigabitEthernet0/1.420
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Hi Kenny,
*************
In your IPV4 route on client. I can only see the 2.0 network with /23. Whereas your switch is in 10.0 network. I think your client needs a route to 10.0 network, /24, DGW to router interface. Next setup a IP route 0.0.0.0 0.0.0.0 {interface type & number to the router}. Right now I think link fault lies between your client and switch. Any other expert  thinks so too? *
*************************************************************
You are correct.  At this time my client(wind 8) can only access a server under 10.10.10.0/24 unless I put an IP from 10.10.2.0/23 on that server.  Some route etc needs to be put into brocade switch.  Where and how I need help.
Thanks
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Hi,
On the router what does this access 23 mean:
access-list 23 permit 10.10.10.0 0.0.0.7
0
 
LVL 8

Expert Comment

by:nader alkahtani
Comment Utility
That standard access list number 23 applied permit to subnet 10.10.10.0/29 255.255.255.248
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Nadir,
Does this access list allows my 10.10.10.0/24 and 10.10.2.0/23 subnets?  By looking at the 23 I am assuming my 10.10.2.0/23 is not allowed.  Can I put:
-access list 23 permit 10.10.2.0/23 255.255.253.254 ?  Need help
Thanks
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
Hi,
I can ping all my servers in subnet 10.10.10.0/24 from client with 10.10.2.61/23 address but cannot access shared folders unless I assign two IP's to that server, one from each subnet.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Roaming Profiles 8 57
Cisco vlan question 12 36
ESXi VLAN Lab 2 32
Password Expiry 9 18
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now