We help IT Professionals succeed at work.

NIC connectivity after being added to Network Load Balance

Last Modified: 2019-03-14
Hello everyone, I am hoping someone might be able to help with an odd NLB issue we seem to be experiencing on our ADFS farm setup. This environment has been setup for at least a year and this issue could have been going on for a while without being noticed. Both servers are Hyper-V guests with two network cards attached and MAC Spoofing enabled on the second NIC (Cluster Operation Mode Unicast). The issue that we are having is that we are able to add ADFS-1 to the cluster with no issues, however when we add AFDS-2 into the cluster the Network Location Awareness (NLA) changes from Domain Network to Public Network (Images below). No errors are displayed as it joins the cluster, but the NLB NIC is no longer reachable on the network.

Host NIC: x.x.x.33
NLB NIC: x.x.x.151
NLB VIP: x.x.x.150

Host NIC: x.x.x.10
NLB NIC: x.x.x.152 (Unreachable after Joining to cluster)
NLB VIP: x.x.x.150

Before NLB Join
After NLB Join
I have already verified the IP configurations before and after the addition to the cluster and restarted NLA, and nothing has changed. When you drop the NIC from the cluster it returns to its normal state of Domain Network. I have also deleted the cluster completely and rejoin the servers in a different order but the same server/same NIC does the exact same thing. Anybody Expert ideas on where to go next?
Watch Question


It's likely to be down to the incorrect assignment of the cluster network to public, as I'm betting that is activating and/or restricting the Windows Firewall on server 2. Check your firewall settings to confirm if it is blocking traffic when on a 'public' network.

As for why it is deemed a public network in the first place, there can be a number of reasons. may not be worth worrying about it, just amend it :-)

try this:


Thank you for your comment Steve! Unfortunately this does not resolve the issue at hand and I had previously attempted the same procedure. The interface is still not accepting traffic after becoming part of the NLB Cluster. The only additional thing that could be of note would be the IPv4Connectivity in the Get-NetConnectionProfile (Seen Below)


can you send traffic out? have you checked if the firewall is on and can you turn it off to confirm if it is relevant or not?


I disabled the host NIC and the windows firewall service, I am unable to send traffic in or out of the NLB NIC while it is part of the cluster. While the host NIC was disable I also pulled the routing table to see if anything seemed to be amiss as well.

IPv4 Route Table
Active Routes:
Network Destination        Netmask               Gateway       Interface  Metric                                           x.x.x.1          x.x.x.152    261
x.x.x.0                                   On-link        x.x.x.152    261
x.x.x.150                      On-link        x.x.x.152    261
x.x.x.152                      On-link        x.x.x.152    261
x.x.255.255                 On-link        x.x.x.152    261                                  On-link    306                     On-link    306        On-link    306                                  On-link    306                                  On-link         x.x.x.152    261        On-link    306        On-link        x.x.x.152    261
Persistent Routes:
Network Address          Netmask  Gateway Address  Metric        x.x.x.1  Default        x.x.x.1  Default

IPv6 Route Table
Active Routes:
If Metric Network Destination      Gateway
1    306 ::1/128                  On-link
15    261 fe80::/64                On-link
15    261 fe80::59c9:cee:5a9a:d4af/128
1    306 ff00::/8                 On-link
15    261 ff00::/8                 On-link
Persistent Routes:

ADFS-2 is our primary ADFS server and cannot be offline for extended periods so I created a brand new VM from scratch on a completely different host with the same hardware configuration. The same issue is happening on the new VM as well.

Thank you again for taking the time!


I think that I may have found my own solution and will followup with the results for anyone else in the future after testing.

cool. what did you find?
This one is on us!
(Get your first solution completely free - no credit card required)

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.