NLB, ADFS, DNS issues?

Posted on 2014-12-21
Medium Priority
Last Modified: 2015-01-05
Hello Experts,

I have a client that after site migration, users unable to be replicated to O365, password synchronization failed . IT team unable to ping VIP of Windows network load balancer.

As workaround, a DNS record pointing to a single ADFS server instead of VIP of WLB was created in the DNS zone . After creating a DNS record, email and dirsync was reestablished.  If we revert changes to original state [ADFS servers in a nlb using VIP address] email, users and password synchronization stops

Company runs ADFS server  [2008 R2 servers] and Exchange Hybrid, Windows 2008 Forest/domain fuctional level

Any ideas on why we are unable to ping VIP of Windows network load balancer? ADFS servers are in a DMZ network, before migration of site everything was ok, they did not change any IPs or any settings on the network load balancer, and the WIndows NLB is setup for multicast on the 2 nodes of the NLB

if the NLB cluster of ADFS was deployed is down, email, and users/password sync will stop, but if anything changed, why it stopped?

How can we fix this issue? do you believe is a DNS, ADFS, or office 365 issue or Windows network load balancer issue?

Should we upgrade ADFS servers to 2012 R2 to fix the Windows network load balancer issue[ if determined is NLB root cause]
Please, provide instructions step-by-step to fix this issue
Question by:Jerry Seinfield
1 Comment
LVL 29

Accepted Solution

Dan McFadden earned 2000 total points
ID: 40512589
Before any upgrading, my first instinct is to verify if there is a firewall blocking access to the VIP.  No ping, no sync, no access reeks of a security device not configured for a new service point.


Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Scripts are great for performing batch jobs against users, however sometimes the GUI is all you need.
Native ability to set a user account password via AD GPO was removed because the passwords can be easily decrypted by any authenticated user in the domain. Microsoft recommends LAPS as a replacement and I have written an article that does something …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

588 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question