Professional Documents
Culture Documents
Y
N
Escalate to
Router / switch Did that solve
N Network
working? the problem?
Engineering
Y
N
Y N Replication N
Issues
AD Service Client-DC
Network Trouble- Trouble-
Ping test to Issues shooting shooting
Network destination?
End
Windows XP? Y
Ping a
Check subnet
computer on Success?
N mask and default
another
gateway
subnet? DHCP client &
169.254.x.x IP N Y
address?
N
Y
N Not receiving
IP address Y
Confirm from DHCP
Host IP, Tracert / NetMon /
Subnet / DG, Wireshark
DNS config
Windows Run
Y Success? End
2003? NETDIAG
Y
Y
Success?
Is the primary (List of DC SRV
Configure correct records)
DNS server
DNS server
correct?
N
N Y
Return Y
Author: © 2009 Sean Deuby Active Directory Troubleshooting Client-DC Name Resolution
URL: http://adtroubleshooting.deuby.com
Version 1.0 (Assumes network testing passed)
AD Service
NTDS or
Trouble- ActiveDirectory_
Kerberos Netlogon SceCli
shooting DomainService N
Errors?
N
event?
N
Event?
N Sysvol?
(W2K8)
event?
N
Y Y Y
Group
Kerberos Policy Y
Many potential
Event Viewer Error Trouble- Trouble-
causes -
or Warning Y shooting shooting
On Your Own!
FRS On Your
N
Event? Own!
Check
EventID.Net / NTDS Site-related
Y
Search KCC? errors?
Y
N Y
Troubleshoot
Dcdiag FRS
/test:topology http://bit.ly/XD3jK
NTDS
Y & correct errors
Replication?
NTDS Y
Y
General?
Global
N Catalog Y
Global Trouble-
Catalog? shooting
On Your End
Own!
N
Authentication Gpresult /r
Problems Is client in the Or
expected site? Rsop.msc
N
NLTEST /
DSGETSITE
Group Policy
Any “trust” Y
Trouble-
messages in shooting
N system log? Confirm site
Is DC in the right subnet mapping
N against network
Y site?
charts
On Your
Does client have a Y Own!
session w/ DC? NLTEST / N Fix it!
Kerberos SC_QUERY:<domain>
Issues
Attempt reset:
NLTEST / Perform client
SC_RESET:<domain> network monitor
trace
Y
Reset computer
N Success?
account
Success? Y End
N Rejoin to domain
Author: © 2009 Sean Deuby Active Directory Troubleshooting Client-DC Name Resolution
URL: http://adtroubleshooting.deuby.com
Version 1.0 (Assumes client can communicate with a DC)
Y
Replication Verify site topology Trigger
Issues (all sites replication with failed
Fail any connected by site partner
Y
primary tests? links, site bridging (repadmin /replicate
disabled or for single partner, or
accounted for, repadmin /syncall for
etc.) all partners)
Run verbose failed N
(Assumes test
physical, network, (DCDIAG (SystemLog test
local-only errors /TEST:<test> /V) errors will mirror
have been & correct earlier check) Elapsed time Did that fix the
checked) problem(s) < (Site link problem?
interval)?
Is the source DC
Run DCDIAG in a different site? Did that fix the N
Y
problem?
Y
Y N Advanced
DCDIAG Check source DC’s replication
test descriptions at DNS configuration troubleshooting
http://bit.ly/4ueDz9 (dcdiag /test:dns /v) (e.g. lingering
& correct errors objects)
Y
End
Success?
Y
“Net
Windows
Y Stop
2008?
NTDS”
N N
Check DB Integrity:
NTDSUTIL,
FILE,
INTEGRITY Reboot into normal
N Success? Y
mode
End
Success?
Recoverable
Success? N
Errors?
Customer reports Y
GPO is not being
applied to client Y
Run GPMC,
review Results
report
Check:
Check:
Run RSOP.MSC - Security Filtering
- Scope of Management
on client, - Disabled GPO
- Replication
examine results - Inaccessible Data
- Group Policy Refresh
- Empty GPO
- Network Connectivity
Is the setting - WMI Filter
N
listed?
Check:
Check:
- GPO Inheritance
- Replication
- Replication
- Group Policy Refresh
- Group Policy Refresh End
-Operating System
- Asynchronous Processing
Support
- Client Side Extensions
- Slow Link
- Loopback Processing
Author: © 2009 Sean Deuby Active Directory Troubleshooting Group Policy Troubleshooting
URL: http://adtroubleshooting.deuby.com
Version 1.0 (http://bit.ly/9H6y2)
Kerberos
Issues
Logons
UDP Group PRINCIPAL_ NTLM
Clock skew failing in mixed
N fragmentation N Membership N UNKNOWN N N Fallback
Install errors? NT4 & Unix
N Problem? Overloads? Errors? Issues?
kerbtray.exe or env?
klist.exe
Y Y Y Y
Examine system
Authorization (not
log to determine
SPN Issue? N authentication)
why you can’t get
issue
a session ticket
Setspn.exe
End