Jump to content

Home Domain. Need Help!

Shylidi

Alright guys. Here's what's going on.

 

I set up a Windows Active Directory environment to handle all the machines in my home. I have about 20 machines so authenticating against a Domain Controller is preferable to separate credentials on each machine.

 

Neither here nor there, that functionality works fine! But my GPOs do not propagate through the network. I suspect this is because of DNS.

 

I don't know how to set my pfsense router to direct all DNS requests to the DC, and I am fairly certain my DC isn't setup to handle DNS properly.

 

I have too manually direct the NICs of the machines to the DC in order to join the domain. I would like it if it would work without manual configuration.

 

I don't even know what info to post to help diagnose the issue, but any help would be appreciated! Hopefully we can get this figured out so I can rejoin my wife's devices to the domain. (She was frustrated that group policies blocked her Windows Hello sign in.)

 

If I can get this working and GPOs would work I would be a very happy man!

 

Thanks in Advance!

vSphere Cluster - 72 Cores - 512GB Memory - 6TB SSD RAW - 42TB HDD RAW - vSphere 7

resonance - Dell PowerEdge R730xd - 2x Intel E5-2667 v3 - 128GB DDR4 @ 2400MHz - NVIDIA RTX 5000 - 2x250GB Samsung 870 Pro - 2x1100W 80+ Plat - ESXi 7.0U3

kat - Dell PowerEdge R630 - 2x Intel E5-2690 v3 - 256GB DDR4 @ 2400MHz - NVIDIA TESLA P4 - 500GB PNY SSD - 4x1TB Crucial SSD - 2x750W 80+ Plat - ESXi 7.0U3

starlifter - Dell PowerEdge R720 - 2x Intel E5-2650 v2 - 96GB DDR3 @ 1333MHz - 2xNVIDIA GTX 970 + 1050Ti - 500GB SSD - 7x6TB HGST HDD - 2x1100W 80+ Plat - ESXi 7.0U3

ion - Dell PowerEdge R620 - 2x Intel E5-2650 v2 - 32GB DDR3 @ 1333MHz - NVIDIA QUADRO M2000 - 2x250GB Samsung 870 Pro -2x750W 80+ Plat - ESXi 7.0U3

 

Main Rig

Intel i7-5820K @ 4.6GHz

MSI X99S Krait SLI Edition

32GB Crucial Ballistix Sport DDR4 @ 2400MHz

Aorus GTX 1080Ti Waterforce Xtreme

Intel 280GB 900p

512GB Crucial NvMe

512GB Samsung 860 Evo

EVGA Supernova 850 G2

Thermaltake Core P5

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Shylidi said:

I don't know how to set my pfsense router to direct all DNS requests to the DC

You do this in the DHCP settings.

 

7 minutes ago, Shylidi said:

I am fairly certain my DC isn't setup to handle DNS properly.

Have you installed the DNS role?

 

 

I am not entirely sure GPOs need a DNS though. The machines can join the domain just fine, right? So if the joining and authentication doesn't need the DNS, then I don't see why GPOs would need it.

Are you sure you're applying the GPOs to the right OU, and have you run gpupdate afterwards (on the client)?

Link to comment
Share on other sites

Link to post
Share on other sites

I hope I remember to re-post on here when I wake up... Would love to put some additions to this post, but i'm too tired right now. 

Lets keep this tab open until I get home from work!

 

<brbafk>

---

 

ZBITS

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, LAwLz said:

You do this in the DHCP settings.

 

Have you installed the DNS role?

 

 

I am not entirely sure GPOs need a DNS though. The machines can join the domain just fine, right? So if the joining and authentication doesn't need the DNS, then I don't see why GPOs would need it.

Are you sure you're applying the GPOs to the right OU, and have you run gpupdate afterwards (on the client)?

I set it up under general settings. But when a machine connects to the network without manual configuration it says:

 

If the client does not log in within 30 seconds, they receive the following message:
"Windows cannot connect to the domain, either because the domain controller is down or otherwise unavailable, or because your computer account was not found."

Then later in the message it claims the computer is configured to pull DNS from 8.8.8.8 (googledns)

 

Not sure why that is happening.

 

Okay, so I have several mobile machines which if I have to set the DNS pointer to the server in Network Settings work fine. But if I take them to work, I am on a network with several layers of security, and the DNS will not work, and I have to change the settings back to default. I currently have to manually change the DNS pointer in Network Settings. If I set it up like the screenshot, I can connect to the domain (but I still don't get any GPOs.

 

I know how to set OU's and apply GPOs to the proper objects at work, so I think I'm doing it right in this case. (Who knows, I may be doing it wrong.)

 

Thanks for the reply!

ipconfig.png

vSphere Cluster - 72 Cores - 512GB Memory - 6TB SSD RAW - 42TB HDD RAW - vSphere 7

resonance - Dell PowerEdge R730xd - 2x Intel E5-2667 v3 - 128GB DDR4 @ 2400MHz - NVIDIA RTX 5000 - 2x250GB Samsung 870 Pro - 2x1100W 80+ Plat - ESXi 7.0U3

kat - Dell PowerEdge R630 - 2x Intel E5-2690 v3 - 256GB DDR4 @ 2400MHz - NVIDIA TESLA P4 - 500GB PNY SSD - 4x1TB Crucial SSD - 2x750W 80+ Plat - ESXi 7.0U3

starlifter - Dell PowerEdge R720 - 2x Intel E5-2650 v2 - 96GB DDR3 @ 1333MHz - 2xNVIDIA GTX 970 + 1050Ti - 500GB SSD - 7x6TB HGST HDD - 2x1100W 80+ Plat - ESXi 7.0U3

ion - Dell PowerEdge R620 - 2x Intel E5-2650 v2 - 32GB DDR3 @ 1333MHz - NVIDIA QUADRO M2000 - 2x250GB Samsung 870 Pro -2x750W 80+ Plat - ESXi 7.0U3

 

Main Rig

Intel i7-5820K @ 4.6GHz

MSI X99S Krait SLI Edition

32GB Crucial Ballistix Sport DDR4 @ 2400MHz

Aorus GTX 1080Ti Waterforce Xtreme

Intel 280GB 900p

512GB Crucial NvMe

512GB Samsung 860 Evo

EVGA Supernova 850 G2

Thermaltake Core P5

Link to comment
Share on other sites

Link to post
Share on other sites

2023 BOINC Pentathlon Event

F@H & BOINC Installation on Linux Guide

My CPU Army: 5800X, E5-2670V3, 1950X, 5960X J Batch, 10750H *lappy

My GPU Army:3080Ti, 960 FTW @ 1551MHz, RTX 2070 Max-Q *lappy

My Console Brigade: Gamecube, Wii, Wii U, Switch, PS2 Fatty, Xbox One S, Xbox One X

My Tablet Squad: iPad Air 5th Gen, Samsung Tab S, Nexus 7 (1st gen)

3D Printer Unit: Prusa MK3S, Prusa Mini, EPAX E10

VR Headset: Quest 2

 

Hardware lost to Kevdog's Law of Folding

OG Titan, 5960X, ThermalTake BlackWidow 850 Watt PSU

Link to comment
Share on other sites

Link to post
Share on other sites

54 minutes ago, Shylidi said:

If the client does not log in within 30 seconds, they receive the following message:
"Windows cannot connect to the domain, either because the domain controller is down or otherwise unavailable, or because your computer account was not found."

Then later in the message it claims the computer is configured to pull DNS from 8.8.8.8 (googledns)

 

Not sure why that is happening.

Because you haven't configured your DHCP server properly. You need to change it so that it points clients to your Windows DNS and not 8.8.8.8.

Go into your DHCP settings and change it from 8.8.8.8 to whatever your Windows server's IP is.

 

56 minutes ago, Shylidi said:

I know how to set OU's and apply GPOs to the proper objects at work, so I think I'm doing it right in this case. (Who knows, I may be doing it wrong.)

Are you sure your account and/or computer object is a member of the OU, to which you have applied the GPO?

Link to comment
Share on other sites

Link to post
Share on other sites

16 minutes ago, LAwLz said:

Because you haven't configured your DHCP server properly. You need to change it so that it points clients to your Windows DNS and not 8.8.8.8.

Go into your DHCP settings and change it from 8.8.8.8 to whatever your Windows server's IP is.

 

Are you sure your account and/or computer object is a member of the OU, to which you have applied the GPO?

Here's a screenshot from the pfsense router. The only DNS server is the windows DC.

2017-02-19 (2).png

 

I'm fairly certain I have the machines set up in the AD correctly. I can look into it later.

vSphere Cluster - 72 Cores - 512GB Memory - 6TB SSD RAW - 42TB HDD RAW - vSphere 7

resonance - Dell PowerEdge R730xd - 2x Intel E5-2667 v3 - 128GB DDR4 @ 2400MHz - NVIDIA RTX 5000 - 2x250GB Samsung 870 Pro - 2x1100W 80+ Plat - ESXi 7.0U3

kat - Dell PowerEdge R630 - 2x Intel E5-2690 v3 - 256GB DDR4 @ 2400MHz - NVIDIA TESLA P4 - 500GB PNY SSD - 4x1TB Crucial SSD - 2x750W 80+ Plat - ESXi 7.0U3

starlifter - Dell PowerEdge R720 - 2x Intel E5-2650 v2 - 96GB DDR3 @ 1333MHz - 2xNVIDIA GTX 970 + 1050Ti - 500GB SSD - 7x6TB HGST HDD - 2x1100W 80+ Plat - ESXi 7.0U3

ion - Dell PowerEdge R620 - 2x Intel E5-2650 v2 - 32GB DDR3 @ 1333MHz - NVIDIA QUADRO M2000 - 2x250GB Samsung 870 Pro -2x750W 80+ Plat - ESXi 7.0U3

 

Main Rig

Intel i7-5820K @ 4.6GHz

MSI X99S Krait SLI Edition

32GB Crucial Ballistix Sport DDR4 @ 2400MHz

Aorus GTX 1080Ti Waterforce Xtreme

Intel 280GB 900p

512GB Crucial NvMe

512GB Samsung 860 Evo

EVGA Supernova 850 G2

Thermaltake Core P5

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Shylidi said:

Here's a screenshot from the pfsense router. The only DNS server is the windows DC.

That's strange, but I still recommend you change it so that the DHCP points to your Windows server too.

You do that in the DHCP options.

Link to comment
Share on other sites

Link to post
Share on other sites

There was a setting in there set to 8.8.8.8!

 

Awesome!

 

I am at church right now so, I can't test the GPOs but I will when I get home!

vSphere Cluster - 72 Cores - 512GB Memory - 6TB SSD RAW - 42TB HDD RAW - vSphere 7

resonance - Dell PowerEdge R730xd - 2x Intel E5-2667 v3 - 128GB DDR4 @ 2400MHz - NVIDIA RTX 5000 - 2x250GB Samsung 870 Pro - 2x1100W 80+ Plat - ESXi 7.0U3

kat - Dell PowerEdge R630 - 2x Intel E5-2690 v3 - 256GB DDR4 @ 2400MHz - NVIDIA TESLA P4 - 500GB PNY SSD - 4x1TB Crucial SSD - 2x750W 80+ Plat - ESXi 7.0U3

starlifter - Dell PowerEdge R720 - 2x Intel E5-2650 v2 - 96GB DDR3 @ 1333MHz - 2xNVIDIA GTX 970 + 1050Ti - 500GB SSD - 7x6TB HGST HDD - 2x1100W 80+ Plat - ESXi 7.0U3

ion - Dell PowerEdge R620 - 2x Intel E5-2650 v2 - 32GB DDR3 @ 1333MHz - NVIDIA QUADRO M2000 - 2x250GB Samsung 870 Pro -2x750W 80+ Plat - ESXi 7.0U3

 

Main Rig

Intel i7-5820K @ 4.6GHz

MSI X99S Krait SLI Edition

32GB Crucial Ballistix Sport DDR4 @ 2400MHz

Aorus GTX 1080Ti Waterforce Xtreme

Intel 280GB 900p

512GB Crucial NvMe

512GB Samsung 860 Evo

EVGA Supernova 850 G2

Thermaltake Core P5

Link to comment
Share on other sites

Link to post
Share on other sites

The machines see the domain with default ip settings!

 

PROGRESS

 

Now I'm going to look into GPO updating and let you know how that goes!

vSphere Cluster - 72 Cores - 512GB Memory - 6TB SSD RAW - 42TB HDD RAW - vSphere 7

resonance - Dell PowerEdge R730xd - 2x Intel E5-2667 v3 - 128GB DDR4 @ 2400MHz - NVIDIA RTX 5000 - 2x250GB Samsung 870 Pro - 2x1100W 80+ Plat - ESXi 7.0U3

kat - Dell PowerEdge R630 - 2x Intel E5-2690 v3 - 256GB DDR4 @ 2400MHz - NVIDIA TESLA P4 - 500GB PNY SSD - 4x1TB Crucial SSD - 2x750W 80+ Plat - ESXi 7.0U3

starlifter - Dell PowerEdge R720 - 2x Intel E5-2650 v2 - 96GB DDR3 @ 1333MHz - 2xNVIDIA GTX 970 + 1050Ti - 500GB SSD - 7x6TB HGST HDD - 2x1100W 80+ Plat - ESXi 7.0U3

ion - Dell PowerEdge R620 - 2x Intel E5-2650 v2 - 32GB DDR3 @ 1333MHz - NVIDIA QUADRO M2000 - 2x250GB Samsung 870 Pro -2x750W 80+ Plat - ESXi 7.0U3

 

Main Rig

Intel i7-5820K @ 4.6GHz

MSI X99S Krait SLI Edition

32GB Crucial Ballistix Sport DDR4 @ 2400MHz

Aorus GTX 1080Ti Waterforce Xtreme

Intel 280GB 900p

512GB Crucial NvMe

512GB Samsung 860 Evo

EVGA Supernova 850 G2

Thermaltake Core P5

Link to comment
Share on other sites

Link to post
Share on other sites

Okay, now GPOs are applying to the DC, and no where else.

 

The DC has it's network drives mounted and listed, while other machines are not picking up that GPO.

 

Any ideas?

vSphere Cluster - 72 Cores - 512GB Memory - 6TB SSD RAW - 42TB HDD RAW - vSphere 7

resonance - Dell PowerEdge R730xd - 2x Intel E5-2667 v3 - 128GB DDR4 @ 2400MHz - NVIDIA RTX 5000 - 2x250GB Samsung 870 Pro - 2x1100W 80+ Plat - ESXi 7.0U3

kat - Dell PowerEdge R630 - 2x Intel E5-2690 v3 - 256GB DDR4 @ 2400MHz - NVIDIA TESLA P4 - 500GB PNY SSD - 4x1TB Crucial SSD - 2x750W 80+ Plat - ESXi 7.0U3

starlifter - Dell PowerEdge R720 - 2x Intel E5-2650 v2 - 96GB DDR3 @ 1333MHz - 2xNVIDIA GTX 970 + 1050Ti - 500GB SSD - 7x6TB HGST HDD - 2x1100W 80+ Plat - ESXi 7.0U3

ion - Dell PowerEdge R620 - 2x Intel E5-2650 v2 - 32GB DDR3 @ 1333MHz - NVIDIA QUADRO M2000 - 2x250GB Samsung 870 Pro -2x750W 80+ Plat - ESXi 7.0U3

 

Main Rig

Intel i7-5820K @ 4.6GHz

MSI X99S Krait SLI Edition

32GB Crucial Ballistix Sport DDR4 @ 2400MHz

Aorus GTX 1080Ti Waterforce Xtreme

Intel 280GB 900p

512GB Crucial NvMe

512GB Samsung 860 Evo

EVGA Supernova 850 G2

Thermaltake Core P5

Link to comment
Share on other sites

Link to post
Share on other sites

50 minutes ago, LAwLz said:

That's strange, but I still recommend you change it so that the DHCP points to your Windows server too.

You do that in the DHCP options.

There was a setting in there set to 8.8.8.8!

 

Awesome!

The machines see the domain with default ip settings!

 

PROGRESS

Okay, now GPOs are applying to the DC, and no where else.

 

The DC has it's network drives mounted and listed, while other machines are not picking up that GPO.

 

Any ideas?

vSphere Cluster - 72 Cores - 512GB Memory - 6TB SSD RAW - 42TB HDD RAW - vSphere 7

resonance - Dell PowerEdge R730xd - 2x Intel E5-2667 v3 - 128GB DDR4 @ 2400MHz - NVIDIA RTX 5000 - 2x250GB Samsung 870 Pro - 2x1100W 80+ Plat - ESXi 7.0U3

kat - Dell PowerEdge R630 - 2x Intel E5-2690 v3 - 256GB DDR4 @ 2400MHz - NVIDIA TESLA P4 - 500GB PNY SSD - 4x1TB Crucial SSD - 2x750W 80+ Plat - ESXi 7.0U3

starlifter - Dell PowerEdge R720 - 2x Intel E5-2650 v2 - 96GB DDR3 @ 1333MHz - 2xNVIDIA GTX 970 + 1050Ti - 500GB SSD - 7x6TB HGST HDD - 2x1100W 80+ Plat - ESXi 7.0U3

ion - Dell PowerEdge R620 - 2x Intel E5-2650 v2 - 32GB DDR3 @ 1333MHz - NVIDIA QUADRO M2000 - 2x250GB Samsung 870 Pro -2x750W 80+ Plat - ESXi 7.0U3

 

Main Rig

Intel i7-5820K @ 4.6GHz

MSI X99S Krait SLI Edition

32GB Crucial Ballistix Sport DDR4 @ 2400MHz

Aorus GTX 1080Ti Waterforce Xtreme

Intel 280GB 900p

512GB Crucial NvMe

512GB Samsung 860 Evo

EVGA Supernova 850 G2

Thermaltake Core P5

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×