RODC Failure...


hi,

so going absolutely crazy try configure rodc authenticate clients after credential caching has been done authentication done on rodc.

this doing, can 1 please tell me i'm doing wrong.

1.so configure clients ip dc dhcp , join clients dc. (tested , working)

2.then configure rodc on dc password retention policy , set rodc server new server vm. (tested , working)

3.then change rodc primary dns ip (127.0.0.1) , alternate dns dc ip.

4.then point clients use rodc primary dns ip , dc alternate dns ip

5.then turn off dc , test clients authenticate rodc, clients login network unknown , not domain network. @ point have checked clients ip other dhcp has given them because of changing primary dns of clients rodc ip.

as can see below w10, w8 , w7 computers , madmin, m1 , m2 clients allowed in password retention policy yet authentication happens @ dc, missing step.

could 1 kindly please let me know doing wrong.

thank much




hi tryllzhuud,

>>but network unknown , not domain network

for issue, suppose try following methods see if helps:

1>using ipconfig /flushdns to flush dns caches

2>open cmd console, run ipconfig /renew to re-obtain ip address 1 of problem machines check if works.

3>restart 1 of these problem machines check network settings see if in domain networks.

>> i have checked clients ip other dhcp has given them i

what ip address did these machine use currently? post ipconfig /all here further helps.

besides, consider using network capture tool analysis this:

for downloading, please navigate link below:

http://www.microsoft.com/en-sg/download/details.aspx?id=4865

in addition, there blog rodc authentication, further understanding authentication :

https://blogs.technet.microsoft.com/askds/2008/01/18/understanding-read-only-domain-controller-authentication/

if resolve using own solution, please share experience , solution here. beneficial other community members have similar questions.

if no, please reply , tell current situation in order provide further help.

best regards,

andy_pan


please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS