Solved

Why does this happen?

Posted on 2016-11-08
12
38 Views
Last Modified: 2016-11-20
Problem: Boot GPO's fail to run.
Solution: MS has a reg fix, to make the GPO implementation wait until the network initialization completes.
https://support.microsoft.com/en-us/kb/2421599

I am having a discussion with a coworker, and the question is "Why is this happening?"  and how would I do further investigation on "Exactly what is going on?"

Note: Spanning tree on the switch is enabled, this is network wide, and there are no network errors.
0
Comment
Question by:loftyworm
  • 5
  • 4
  • 2
  • +1
12 Comments
 
LVL 117
ID: 41879084
if you force a GPO update on the Client, does it give you any error messages ?

have you also looked at the event logs on the DCs and Workstations ?
0
 
LVL 11

Author Comment

by:loftyworm
ID: 41879163
1) no error messages after boot.  the gpupdate /force works with no issues (because the network is up and all is working)
2) there is an event in the boot up event logs, that match the KB from MS, the GPO failed to run

One more addition as will, an updated Network driver (all drivers) has no effect (and flash of all bios)
Another symptom can be seen, when you login right away, the network drives all have that red X, but go away when you navigate them, again pointing at the network.

Perhaps I should look more closely at the spanning tree???  Could the network be holding up the NIC from starting?
0
 
LVL 117
ID: 41879251
GPO updates are working, and being applied to all workstations correctly ?

it's just this update which is not working ?

do you have a different network interface or switch to try ?
0
 
LVL 11

Author Comment

by:loftyworm
ID: 41879579
1) no they are not.  there are some specific boot GPO's that will not run.

No I don't.

But I think the issue is being missed.  I know how to fix it.  The question is why is this happening?
I am getting some beurocractic blowback, and I need to say "because this and this log says so", or something to that effect.  The windows event log shows there is an error, but not why the network card is not booting as fast as the OS.
0
 
LVL 117
ID: 41879585
Sorry, I'm a little confused, do GPO updates work in your organisation, ANY?

lets just park this specific update.
0
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 167 total points
ID: 41879670
... "but not why the network card is not booting as fast as the OS. "

The OS must get up and running before it can set the network settings for the network card to use.  So the OS will be up and running prior to the network card.

How are the switch ports configured?  Access, trunk, or dynamic?  Are the switch port/network card configured as fixed speed/fixed duplex or learn?
0
Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

 
LVL 117

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE)
Andrew Hancock (VMware vExpert / EE MVE) earned 167 total points
ID: 41879703
We experience this, with MDT deployments, on our new i7 Desktops, MDT BOOTS so fast, the network interface has not initialized, and therefore fails obtaining a DHCP lease, and MDT has already booted, and trying to map to Network Share. if we then wait 60 seconds, and hit Retry it works, but this does not help, as PXE/MDT deployments are supposed to be automatic!....

and this was with an Intel Network Interface on the motherboard, if we switched to the RealTek, it solved the issue for us!

Motherboard has two nics, strangely an Intel and Realtek, this is on a customer site, which has HPE networking.
0
 
LVL 45

Assisted Solution

by:Craig Beck
Craig Beck earned 166 total points
ID: 41879820
Spanning tree on the switch is enabled, this is network wide, and there are no network errors.

In Cisco-speak, we enable spanning-tree portfast to enable the port to forward frames instantly.  If STP is enabled and portfast isn't enabled, the device won't be able to pass any traffic for around 30s after the link is established.  This is why the wait for network GPO needs to be applied.
0
 
LVL 11

Accepted Solution

by:
loftyworm earned 0 total points
ID: 41888247
SO, I want to close this up.
This is not a spanning tree issue or even a switch issue.  I believe (70%) that this is a AV Symantec issue.  In essence, there is a 3rd party program that is controlling the network connection.  In this case the Symantec Firewall.  This is where the delay is coming from. I have past the political hurtle and am moving forward with the fix I originally stated.  TY all for you assistance.
0
 
LVL 117
ID: 41888341
no firewalls here on our workstations, and it happens!
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 41888521
Check portfast, Andrew :-)
0
 
LVL 11

Author Closing Comment

by:loftyworm
ID: 41894663
solution found
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now