Friday, June 19, 2020

Issues with Windows Domain Network and foreign sites

Hello,

Apologies in advance if the terminology I use is not correct, I'm a junior sysadmin that got propelled to senior sysadmin through lack of personnel.

I'm having a hard time trying to figure out the fault in our domain network as the network is not entirely available across multiple offices. To simplify here's the route:

Me (on site 1) > local core > Datacenter and main DC > Datacenter's ISP > Site 2 ISP > local router > local DC with DNS and DHCP > client PC

The site 1 DC is on a 10.200.10.0/16 subnet, site 2 DC is on a 10.25.1.0/23 subnet. Both DCs can communicate and the DC2 is correctly joined to our domain.

However once I start dealing with client PCs on both sides and other non-DC servers, I get nothing. The local domain controller itself can't even communicate with other domain controllers on the network. It sees the records thanks to the DNS but it can only communicate with the primary DC. Some examples:

Site 1 PC on 10.200.81.0/16 > Site 1 DC1: OK

Site 2 PC on 10.25.1.0/23> Site 2 DC: OK

Site 2 DC > Site 1 secondary DC on 10.200.10.0/16: Not OK

Site 2 DC on 10.25.1.0/23 > Site 1 app server on 10.200.10.0/16 subnet: Not OK

Site 2 Client PC > Site 1 app server: Not OK

Site 1 Client PC > Site 2 client PC: Not OK

As long as I use the local DC2 as a bridge I can work on client PCs, but other services, notably the client access to our other servers is starting to cause a lot of issues. At first we discovered a rogue DHCP that was messing up the domain connection on the client side (since then removed and cleaned up) but fixing that has not fixed anything other than the local DHCP configuration.

I have a suspicion that I missed a step or did something wrong when configuring the domain controller with DNS/DHCP since we have 3 other sites with an almost identical setup who are correctly connected to our domain network and can be reached between any 2 sites, which makes me doubt our datacenter provider missed something when creating the rules and routes for the new site.

Any ideas ?



No comments:

Post a Comment