troubleshooting Question

Domain Controller internet connection is intermittently blocked

Avatar of Simplegrid Technology
Simplegrid Technology asked on
Windows NetworkingHardware FirewallsSwitches / Hubs
18 Comments1 Solution541 ViewsLast Modified:

Hope someone hear can help me solve this:

Here's the network layout:

Cable Modem --> Sonicwall TZ 200 --> Cisco 3560-X ---> ESXi Host --> hosting two VM's, a domain controller and a client.

Everyday, at what appears to be random times during the day, for different amounts of time, our office appears to lose internet connectivity.   the issue can last from anywhere from 5 minutes to over an hour.

Now, what I've found is that when this happens, the server isn't able to resolve any of the external DNS forwarders or the root hints.  Further investigation shows that when the issue is occurring, I can't ping any external address (e.g. or anything else) from the domain controller, which is also my DNS server.  When everything is normal, I can ping external addresses from the domain controller.

Regardless of whether the issue is occurring or not, I can always ping out from a client.  For example, on the ESXi host, I have my 2012 DC and a windows 7 client.  I can always ping out to from my client.  If I change my DNS settings on the client, I am able to browse the web again.

So the issue has something to do with the DC and it's connection being blocked.  I know the following:

1)  I can ping the gateway of my L3 switch (
2)  I can ping the internal interface of the firewall (
2a) I can ping the DC from my clients, and I can ping my clients from the DC
3)  Internal DNS looksup work properly, as I'm able to resolve internal names.
4)  Internet connectivity works, as I can RDP from an external location to that office, via IP address.
5)  I even tried pinging the default gateway of the FW, and I don't get a response when teh issue is occuring.

I've had Microsoft look at the DC/DNS server and they can't figure it out.  They've verified everything is working with DNS. They want me to change the IP address of the DC, which I'm planning to do tonight, but it's a real pain to do that.

I spoke with Sonicwall, now mind you the tech support guy wasn't good, so take all of this with a grain of salt, but he says that everything looks good on his end too, however he was running a packet capture at the time, and said that the pings were going through the firewall, but weren't being returned.  He says that nothing is blocking the DC.

Any thoughts on what else could be causing this?
Simplegrid Technology

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 18 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 18 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros