networking - Linux clients and Windows Servers can connect but not windows clients

This is driving me insane because I can't make head or tails of it.

We have two DCs (W2K3 SP1) and I'v tried this once on each machine as a sanity check.

DHCP is being served by either one of the machines and all machines get an address no problem. The servers can connect/ping/browse to the www and so can all our linux clients. But NONE of our windows clients (all windows 7).

I can do anything within the network, I can even ping the firewall/router but nothing from the windows clients is leaving the confines of our subnet.

I don't get it. The linux and windows clients are both served from the same DHCP server, the gateway is the same, everything is the same.

Anyone care to take a shot at how to resolve this?

I tried adding explicit routes at the clients, but still no go.

Some points that might help:

This is behind a SonicWall firewall (which I absolutely despise).
The DCs are two VMs on two different boxes.
DHCP being provided by these VMs. There is maybe 1/2 dozen other VMs that act as web or database servers and they can all connect to the internet.
The issue happened this morning (my time is GMT +2) and I think its a result of issues on the VMs. The domain was built in what I can only kindly refer to as a patchy manner. Dealing with it is like running my cojones in a shredder.

Connection has proven to be an intermittent thing. On several of the Windows 7 clients, connection was restored for no obvious reason for a few minutes before it went away.

Nothing has been changed when it comes to domain policies for at least a few weeks now.

I can't think of anything else to add, but if there's something in specific, y'all just ask and I'll be more than happy to provide an answer.



@John Gardeniers

I'm at home now so I'll post it tomorrow when I get to the office, but I did that when I was there and the gateway and DNS servers are right. DNS resolution is correct.

This is the ipconfig /all output on one of the clients that started to work magically after I turned off the DHCP

Windows IP Configuration

Host Name . . . . . . . . . . . . : TAN-LEN-08

Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : tanasuk.lcl

Wireless LAN adapter Wireless Network Connection:

Connection-specific DNS Suffix . : tanasuk.lcl

Description . . . . . . . . . . . : Intel(R) WiFi Link 5100 AGN
Physical Address. . . . . . . . . : 00-21-5D-77-8F-D2
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::c864:eeb4:cb19:40cf%12(Preferred)
IPv4 Address. . . . . . . . . . . :
Subnet Mask . . . . . . . . . . . :
Lease Obtained. . . . . . . . . . : Monday, January 17, 2011 9:48:50 AM
Lease Expires . . . . . . . . . . : Monday, January 17, 2011 2:48:51 PM
Default Gateway . . . . . . . . . :
DHCP Server . . . . . . . . . . . :
DHCPv6 IAID . . . . . . . . . . . : 218112349
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-14-4F-8A-A2-00-22-15-EB-3B-2F

DNS Servers . . . . . . . . . . . :
Primary WINS Server . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8168C(P)/8111C(P) Family PCI-E
Gigabit Ethernet NIC (NDIS 6.20)
Physical Address. . . . . . . . . : 00-22-15-EB-3B-2F
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.tanasuk.lcl:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : tanasuk.lcl
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Obviously, the one I tagged with asterisks is the one we're looking at.

Its right, the gateway should be and is, the DNS servers are|6 everything is right.

The weird thing is that things started to work after DHCP server was turned off! In my exasperated attempts, I even tried a linux server (CentOS 5.3 dhcpd) with the exact same results.

Any idea guys? I'm stumped and I'd LOVE to know what the heck is going on.

Here is the ipconfig /all output off of one of the DCs/DNS servers

Windows IP Configuration

Host Name . . . . . . . . . . . . : TAN-SRV-DC2
Primary Dns Suffix . . . . . . . : tanasuk.lcl
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : tanasuk.lcl

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Citrix XenServer PV Ethernet Adapter
Physical Address. . . . . . . . . : A2-A9-A1-B4-FA-08
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . :
Subnet Mask . . . . . . . . . . . :
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . :

and this is off of my local linux laptop (ifconfig eth0)

eth0      Link encap:Ethernet  HWaddr 00:16:6f:55:07:e3  
RX packets:304 errors:0 dropped:0 overruns:0 frame:0
TX packets:61 errors:0 dropped:5 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:47811 (47.8 KB) TX bytes:12238 (12.2 KB)

Interrupt:22 Memory:bc007000-bc007fff

(less /etc/resolv.conf)

# Generated by NetworkManager

and (route -n output)

Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface U 1 0 0 eth1 U 0 0 0 virbr0 U 1000 0 0 eth1 UG 0 0 0 eth1

As you can see, this is insane!

There is something I have noticed since the problem has now become intermittent. Some Windows 7 laptops will connect, others will not and some will connect for a bit and then just forget.

They connect perfectly fine locally. And though they have a gateway defined, its almost as if they don't know how to reach it. Trying a tracert, I get a timeout from the first hop, but not so on the *nix clients (CentOS, several Ubuntu, several Mac OS X). Could this be a DNS issue? as in both DCs aren't synching properly?


