PDA

View Full Version : win2k, advanced domain bomber


zhardoum
7th May 2001, 16:11
hmm,

As the more astute amongst you on here will know I have been doing battle with a mixed language / mixed server environment.

The battle still rages, and it appears the other side has the upper hand, and is about to beat me to a pulp with a dns error in my backside and a controller failure between the eyes.

Win2k PDC, 2 Nt4 BDC´s..

a pletheroe of standalones, a sco-unix box, a netware 4.11 server,

mixed workstations, 2k, nt4, 98, 95 etc..

Now, suddenly late last week the PDC suddenly without warning believes it is on a different domain from all the other machines, and won´t allow any logons at all. even from the BDC´s. Even though the domain name is the same for all.

The Bdc´s can not now join the domain, with an error that the bdc´s already exist on the domain, and that a sid error has occurred and it is necessary to reinstall the OS on the domain (yes you read right, necesary to reinstall the os on the domain, server I could understand, but domain?).

The PDC sits there quite happy, but in server manager all the other machines are greyed out, even though they share the same domain name.(and that is with or without show only domain members).

on the BDC´s the PDC is greyed out.

The users can not access most servers now, each hour more people loose network access, once logged out, they cannot log in.

The PDC is sitting as smug as a smug thing can, the first bdc is having an error log fit, spewing out every error known to man, and the other bdc (which is the exchnage server) has run away screaming, and is now sitting in a corner unable to authenticate with anyone, even itself, and is looking very miserable, (having now lost the entire companies email since last thursday)

The unix box, is having a field day, opening and closing access rights as it sees fit, and the netware box decided half an hour ago to completely ceases any print jobs at all.

I believe the coffee machine may be working but is showing signs of falling to the dark side to.

The site has the latest virus defence across all the servers and workstations, and until last week, the battle was nearly won, with it taking less than 1 min from boot to logged in state.

On friday it took over an hour for users to authenticate, now it just doesnt let people in at all.

and occasionally boots an existing user off with no warning just for the hell of it.

To rectify this, I am faced with finding the problem, before I can fix it, or wipe the lot, 9 servers, 1win2k, 6Nt, 1 sco, 1 netware, what joy..

having been delving into this since wednesday pm, I still haven´t found the route cause yet, but i believe active directory may be lurking in the darkness ready to cut my throat the second i blink the wrong way.

Including the fact that to wipe the lot will involve closing the entire office for a week, whilst i rebuild like mad.

Oh the joys of computing.

It was going so well, really solid performance and then explicabily for some reason things started playing funny buggers.

Times like this I wish I was an accountant.

or a pr exec!

Scarr
7th May 2001, 17:11
I dunno what to say, hope you don't have to resort to the re-install. Hopefully someone with more knowledge than me can shed some light on it.

KermitTheFrag
7th May 2001, 18:05
This happened at work. The BDCs go bloody crazy every few months. What we did was to yank everything off the network except the PDC and the BDCs, power everything down and then up again and run NewSID on the BDCs then `rejoin' them. I think theres a trust relation thats gone t1ts up somewhere.

This works 99% of the time but then again NT networking never worked properly...

You can get NewSID from here:-

http://www.sysinternals.com/ntw2k/source/newsid.shtml

WinNT domains are bitch-whores at the best of times. Thank god I only have to deal with UNIX these days!

HtH.

[addendum: if it's ADS thats causing it you're f*cked! Reinstall time most of the time!]

zhardoum
7th May 2001, 19:52
now that is odd.


well done that man, i am going into work at 5.00 am tomorrow and a new sid is a dam site less hassle than a full reinstall.

Thanks all for your help...



[Edited by zhardoum on 7th May 2001 at 20:56]

KermitTheFrag
7th May 2001, 23:23
Good luck. Hope it doesnt f*ck things up any more :D You know how much fun Windows can be :D

NewSID is my greatest friend after having to build 50 WinNT workstation installations in 2 days while at work between university semesters. I just gave our friendly PC manufacturer the image and he ghosted them while building and I ran NewSID on each one when we put them on the desks. Four of us deployed (including unboxing etc) 50 workstations in 2 hours after only 2 days prep and not one didnt work!!

The development work I do now isnt half as much fun.

Cabe
7th May 2001, 23:29
Damnit, i wish our IT bods at college would think of that, there alwasy moaing they have to set up PC's all the time, and they dont have time to sort out the internet connection.

[KEA]Chairman
8th May 2001, 13:32
Ghost multicast and newsid. Just stick a floppy in the drive and walk away.

Brilliant. Rebuild in ohhh 20 mins.

Hope it doesen't come to that for zhardoum though:)

Chairman

KermitTheFrag
8th May 2001, 13:42
Never tried ghost multicast. I'll see if I can leech a copy from somewhere tonight.

We normally build one image and give it to our manufacturer on a CD. He ghosts them on for us so we can be even more lazy and spend all day in these forums... :D :D

Cabe
8th May 2001, 13:44
Kermie, you got a junior tech job going at you place? :D

zhardoum
8th May 2001, 16:24
hmm update time..

The pair of BDC´s were so fragged up, they needed a complete rebuild.


Tried the Sid change and it worked fine, but they were beyond repair so needed a rebuild, but still the sid change worked fine without a hitch....unlike....


The PDC, which as its win2k has the Sid in its registry and threw a fit when it discovered its sid had changed, it comes up, goes down, comes up goes down, gets turned off.

So, after an 'eventful'day, I now have two nt4 servers rebuilt,(1 is exchange) and I am wondering which bleedin files I need of the backup tape to restore the users and groups both the NT and to exchange...

The win2k server is staying off until I decide what exactly to do with it - I am buying an english version so I can read the error logs without giving my self a bigger headache.

KermitTheFrag
8th May 2001, 17:04
Originally posted by Cabe
Kermie, you got a junior tech job going at you place? :D

Visit:- http://www.raytheon.co.uk/ and select flash/non-flash then job opportunities. There is a data admin job going at the moment that wont be much fun... :D. I'm being serious there as I'm doing the fecking data admin at the moment :(

If you wanna know what we do - visit this page :D

http://www.raytheon.co.uk/raytheonnoflash/sections/products/product_systems/weapons/weapons.htm

Zhardoum - thats a ****ter :( Three questions:-

1) Is the PDC storing the domain heirachy in ADS?

2) Why the hell are you using a Win2k server as a PDC? Is this because of Exchange 2k or some obscure reason?

3) Have you got a big enough axe?

> The win2k server is staying off until I decide what
> exactly to do with it - I am buying an english version so
> I can read the error logs without giving my self a bigger
> headache.

You didnt buy a cheapy international version did you? :D

Apologies if that made it worse - I've had a bad day judgement-wise today :(. Kicking £150k UNIX servers that go down doesnt cause them to get fixed... Kicking £150k UNIX servers and the boss finding out goes down even better...

[Edited by KermitTheFrag on 8th May 2001 at 18:09]

Afty
9th May 2001, 08:42
Kermit, what's the best deal you can get me on a Paveway and a couple AMRAAMs?

Do you get staff discount? Does your place take Mastercard?

If so I'm 5434 8729 8733 3587
Expiry Date 01/03
Issuer : Peoples Bank of Iraq

You can bring em to i8 if postage would be a bitch.

Thanks

P.S. Zhar, sorry to hear about your probs, never encountered that so I can't post anything constructive.

KermitTheFrag
9th May 2001, 08:47
ROFL :D :D :D

We could do with a "BUY" button on the web site I think :D

Afty
9th May 2001, 08:55
I mean. Where the *fcuk* is the shopping cart?

I'm sorry but any site that doesn't have a solid consistent user interface isn't getting my business, I'm off to find a better site.

http://www.saddamsseconds.com
http://www.fromrussiawithsemtex.ru
http://www.ukrainiansurplus.ru