Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Why domain-joined server was assigned with "guest or public network" profile?

Posted on 2016-08-23
7
Medium Priority
?
183 Views
Last Modified: 2016-09-13
This is a newly-setup MS Windows 2012 R2 AD Domain. There are 2 DCs, both W2K12 R2. However, found that one of the DC and few other W2K12 R2 member servers (all are VMs) was assigned with "guest or public network" profile, instead of Domain network. On the network and connection center, it was shown with "unidentified network". Even logging on with a domain user (or admin), this seems like a local user account profile. for example, a domain user account logged on affected DC was given the user path of "c:\users\administrator folder. While the correct ones should be "c:\users\administrator.TS" folder (TS is the domain name). Btw, what's went wrong? What should I do to get them back to the right track?

I heard that may have to delay-start the NLA service? is that true?

Appreciate for your help, many thanks.
EE---DC01-firewall-shows-public-netw.jpg
EE---DC01---Network.jpg
EE---set-on-DC01.txt
EE---set-on-TSserver01.txt
0
Comment
Question by:MichaelBalack
7 Comments
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 41767165
Do you have a connection specific DNS suffix assigned to the NIC? You can check this under the DNS tab for the connection (Network connections - properties of your adapter - IPV4 - advanced - dns).

If you don't have a suffix, assign one.
0
 
LVL 44

Expert Comment

by:Adam Brown
ID: 41767167
What are the two servers configured with for DNS? Both should be configured to look at the DC for DNS as the primary DNS server. If they have anything else, the firewall profile would reconfigure itself as being in an unknown network (because it isn't technically on the domain).
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 41767172
Hi Joseph,

Normally, none of the dns suffix is assigned. I shall assign it when on site 2 days to go.

Thanks for the prompted suggestion.
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 
LVL 1

Author Comment

by:MichaelBalack
ID: 41767183
Hi Adam,

Now I recall that there are 2 DCs, one located at site a, and another one at site b. Both sites are connected in WAN infra. The affected DC and few servers are located at site a, while the second DC located at site b.

All these servers and DCs are located behind a "local firewall", to a pair or routers, and then a "remote firewall" to the other site. On site a, there could be few updates on the local firewall that does not allow all the servers and DC access to site b.

Let's me confirm this and get back to you in 2 days' time.

thanks,
0
 
LVL 60

Expert Comment

by:Cliff Galiher
ID: 41767819
You've already often some good advice but as an aside, your profile folder names are not an indication or a proble,m.

Windows will always try to create a profile folder based on the username first, even for domain accounts. So "administrator" instead of "administrator.ts" is perfectly normal and NOT an indication of a problem.

It will append a dot-domain only if another folder with the same name already exists and has a mismatched ACL and isn't in the registry.  

And if a username.domain folder already exists, it'll start appending numbers.... such as username.000 and username.001

All in the name of preventing data loss. This is normal and expecfed.
0
 
LVL 1

Accepted Solution

by:
MichaelBalack earned 0 total points
ID: 41787124
Hi all,

I found an article on how to tackling the same issue. The solution is, restart the NLA (Network Location awareness) service, and the profile changes to be domain-based. In long run, changes this service to be "Delayed start", so as it will started after all other services started upon system startup.

By changing this way, the problem resolved.
0
 
LVL 1

Author Closing Comment

by:MichaelBalack
ID: 41795673
By restarting the nla service, problem no more
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Windows Server 2003 introduced persistent Volume Shadow Copies and made 2003 a must-do upgrade.  Since then, it's been a must-implement feature for all servers doing any kind of file sharing.
If you try to migrate from Elastix to Issabel, you will face a lot of issues. These problems are inevitable but fortunately, you can fix them. In the guide below, I will explain how I performed the migration while keeping all data and successfully t…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question