Solved

Why domain-joined server was assigned with "guest or public network" profile?

Posted on 2016-08-23
7
69 Views
Last Modified: 2016-09-13
This is a newly-setup MS Windows 2012 R2 AD Domain. There are 2 DCs, both W2K12 R2. However, found that one of the DC and few other W2K12 R2 member servers (all are VMs) was assigned with "guest or public network" profile, instead of Domain network. On the network and connection center, it was shown with "unidentified network". Even logging on with a domain user (or admin), this seems like a local user account profile. for example, a domain user account logged on affected DC was given the user path of "c:\users\administrator folder. While the correct ones should be "c:\users\administrator.TS" folder (TS is the domain name). Btw, what's went wrong? What should I do to get them back to the right track?

I heard that may have to delay-start the NLA service? is that true?

Appreciate for your help, many thanks.
EE---DC01-firewall-shows-public-netw.jpg
EE---DC01---Network.jpg
EE---set-on-DC01.txt
EE---set-on-TSserver01.txt
0
Comment
Question by:MichaelBalack
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41767165
Do you have a connection specific DNS suffix assigned to the NIC? You can check this under the DNS tab for the connection (Network connections - properties of your adapter - IPV4 - advanced - dns).

If you don't have a suffix, assign one.
0
 
LVL 41

Expert Comment

by:Adam Brown
ID: 41767167
What are the two servers configured with for DNS? Both should be configured to look at the DC for DNS as the primary DNS server. If they have anything else, the firewall profile would reconfigure itself as being in an unknown network (because it isn't technically on the domain).
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 41767172
Hi Joseph,

Normally, none of the dns suffix is assigned. I shall assign it when on site 2 days to go.

Thanks for the prompted suggestion.
0
Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

 
LVL 1

Author Comment

by:MichaelBalack
ID: 41767183
Hi Adam,

Now I recall that there are 2 DCs, one located at site a, and another one at site b. Both sites are connected in WAN infra. The affected DC and few servers are located at site a, while the second DC located at site b.

All these servers and DCs are located behind a "local firewall", to a pair or routers, and then a "remote firewall" to the other site. On site a, there could be few updates on the local firewall that does not allow all the servers and DC access to site b.

Let's me confirm this and get back to you in 2 days' time.

thanks,
0
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 41767819
You've already often some good advice but as an aside, your profile folder names are not an indication or a proble,m.

Windows will always try to create a profile folder based on the username first, even for domain accounts. So "administrator" instead of "administrator.ts" is perfectly normal and NOT an indication of a problem.

It will append a dot-domain only if another folder with the same name already exists and has a mismatched ACL and isn't in the registry.  

And if a username.domain folder already exists, it'll start appending numbers.... such as username.000 and username.001

All in the name of preventing data loss. This is normal and expecfed.
0
 
LVL 1

Accepted Solution

by:
MichaelBalack earned 0 total points
ID: 41787124
Hi all,

I found an article on how to tackling the same issue. The solution is, restart the NLA (Network Location awareness) service, and the profile changes to be domain-based. In long run, changes this service to be "Delayed start", so as it will started after all other services started upon system startup.

By changing this way, the problem resolved.
0
 
LVL 1

Author Closing Comment

by:MichaelBalack
ID: 41795673
By restarting the nla service, problem no more
0

Featured Post

Database Solutions Engineer FAQs

In this series, we will discuss common questions received as a database Solutions Engineer at Percona. In this role, we speak with a wide array of MySQL and MongoDB users responsible for both extremely large and complex environments to smaller single-server environments.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Make the most of your online learning experience.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

635 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question