force GBA v.5 to join the domain with a certain domain controller

Hello world

I try to join a CBS c. 5.3 to the domain.  My acs in A location, I can join without problem using my account. When I try to join the ACS in location B to the same domain with the same account, it does not work.

I looked for the ad client debugging logs and noticed that the ACS in location B goes to some a domain controller. However, I would have expected the ACS to contact a different DC, located on the same site that GBA... This does not happen.

My question: how to determine what contact DC GBA? Is it possible to force HQ to reach by connecting a certain DC?

Thanks for any help or ideas?

IDA

Hello

Please check your sites and services in your DNS configuration to see if the right domain controllers are sent to the ACS when attempting to connect to the domain. This function is essential and allows to optimize the links that GBA chooses to join the domain.

The way this works is that ACS is trying to resolve dns records for the global catalog servers and domain controllers for the dns server configured in the initial installation script. Then the dns makes a decision based on the source ip address of the dns request and think that the ACS is in a specific site and returns the result which domain controllers and global catalogs is configured in this specific site.

Let me know if this helps.

Tarik Admani
* Please note the useful messages *.

Tags: Cisco Security

Similar Questions

  • Satellite P100: XP Pro Media Center - unable to join the domain

    Recently bought a P100 with XP Pro OS but I'm not to be able to join the field to work correctly. Normally, to create a new account on the SBS 2003 server, then from the PC "join the domain.

    Clues?
    Peter

    Hello

    You should better check the Small Business Server site. You will find FAQS:
    http://www.smallbizserver.NET/

    Also check this:
    http://www.experts-exchange.com/Operating_Systems/SBS_Small_Business_Server/Hot_Solutions_1.html

  • px12-350r unable to join the domain - what now?

    Hi all!

    I hope you can give me some advice because at the moment I'm in a really silly situation, being probably locked out of my Iomega px12-350r.

    Here is what happened:

    * The device was successfully linked to my domain name Microsoft AD and worked with this config at least a year.

    * I expanded the storage matrix, 2 days adding 2 drives. Everything went well and the end of the expansion, the new total disk space is displayed correctly in the web administration interface.

    * After this, I restarted the device. After the reboot, I couldn't connect to the device more using my domain account. This account had administrative rights on the NAS and I connected on the NAS using this account before.

    * I don't alter the domain infrastructure.

    * I know that the device cannot join the domain more because I enabled e-mail notifications and he continues to send me "unable to join the domain".

    I have already tried:

    * Connection using the usual accounts: doesn't seem to work once the device is connected to a domain.

    * Connection via SSH. Does not work, probably for the same reason as above.

    I wasn't yet:

    * The user manual mentions reset the admin password by pressing the reset on the back button. But this will only reset config (I'd be okay with it), or it will erase the data on the drives as well?

    I'm from the Germany. Despite having purchased a service plan 24 x 7 hotline support German will only redirect me to the hotline American which claim to do only office, no SIN px12. I'm kinda in the middle of nowhere now. ;-)

    Thanks for your help!

    Best regards

    Florian

    Hi André,.

    I fixed it without reboot - by chance.

    In a desperate attempt, I tried to connect using the domain administrator account - and it worked! I don't remember giving any px12 admin permissions to this user and I certainly don't connect to the device using this user before. But the account has permissions to create computer accounts in the ad, and in the moment when I logged in the computer account of the AD px12 updated password.

    I tell myself that the px12 has used the account admin for re - joining the domain. From the web interface, I could now do a sync AD and after that, all users of domain reworked.

    So, if anyone has the same problem, try connecting the device with any account that has administrative rights on the whole of the field, even if you have not used the account on the device before. It can work for you, too.

    Local accounts still do not work. I think that if the device is connected to a domain and the domain link is broken permanently, so it's only the reset button.

    Andrew Merci for your support!

    Best regards

    Florian

  • I cannot join the domain in my office with my home edition, Windows

    Anyone, please help me solve the problem please...

    I use Microsoft Windows Home Edition...

    I can't join the domain...

    If I open network connections, and then I click on advance and I choose network identification and then I click on edit, there is only the option of working group...

    But if I opened that there is two option in windows proffesional came... First area and the second is the working group...

    How do for pop up that way I can join domain in my office?

    I thank the of for anyone who can help me...

    Anyone, please help me solve the problem please...

    I use Microsoft Windows Home Edition...

    I can't join the domain...

    If I open network connections, and then I click on advance and I choose network identification and then I click on edit, there is only the option of working group...

    But if I opened that there is two option in windows proffesional came... First area and the second is the working group...

    How do for pop up that way I can join domain in my office?

    I thank the of for anyone who can help me...

    XP Home Edition is not supported to join a domain. XP Professional is.

  • Can not join the domain of the Hyper-V virtualized system

    Hello!
    I have a domain controller active directory (adserver) in my ws12 network, and I have another physical server (server) also runs ws12 who is able to join the domain, but the virtualized systems can not.
    DNS and other settings are ok (identical to what is implemented on the server) and made the flush and registerdns steps. I even tried to add the host name of the dc and the name of FQDN for hosts files.
    I type in the domain (gczinege) and I'm able to type in the username and password. After awhile the virtualized pc SAIS: could not join the domain - not found network path
    I feel there is something with the installation of hyper-v or network server.

    Thank you all.
    I solved the problem, first I was promoting to a domain controller and to be in the area and that the installation of hyper-v after everything went well.
    Best regards.
    g

  • Unable to join the domain on VM

    Hello - I just installed Workstation 12 on a machine and try to understand networking. We use the network configuration connection bridged, that seems to work for most. I give a static IP address to the virtual machine and am able to ping this IP from other computers, but I'm unable to join this virtual machine to the domain. All our DNS settings are configured correctly on the virtual computer. The error indicates it does not find our dns server when attempting to join the domain. What I'm missing here? Must the virtual machine use the host's IP as gateway or DNS? Shouldn't if we in bridged mode right?

    Thanks for any help!

    This has been resolved. I had to make the switch port that the host computer has been connected to a trunk instead of an access port port.

  • vMA unable to join the domain

    Hello


    I can't join the domain (windows-based).

    I want to join my vMA to the domain, but it is always the wrong password


    When I follow these steps on my vMA

    domainjoin-cli join < domain name > <-domain admin-user >


    He invites me authorization error so I tried with sudo


    VI-admin@VMA: sudo domainjoin-cli join < domain name > <-user-admin of the field: can I use to connect on my other computers >


    then he gives me a wrong password... my password is correct...

    I tried on two versions of vMA, 4.1 and 5.1/5.5

    any suggestions...

    Hey VirtualRay

    Your VMA has the same DNS settings in your area?

    So if you your vCenter Server ranging from ping vcenter01.mydomain.lan pings is returned correctly?

    If so, it should work

    1 from the vMA console, run the following command:

    sudo domainjoin-cli join

    2 when you are prompted, provide the password for the administrator of Active Directory.

    On successful authentication, the command adds vMA as a member of the domain. The command also adds entries in the file/etc/hosts with vmaHostname.domainname.

    3 restart vMA.

    Now you can add a target Active Directory at the VMAs. For the procedure to do this, see Add servers at VMAs targets.

    To check the settings of the domain of the vMA

    Since the vMA console, run the following command:

    sudo domainjoin-cli application

    The command displays the name of the domain for which vMA joined.

    :

  • Script to join the domain, the role of configuration, add permissions and activate/SNMP configuration

    So I'm writing a script to install our vSphere hosts to work with our monitoring software.  Right now, it's all done by hand and I would like if possible to automate it.  So far, I came up with this.  I get to step 5 and that's where it fails.  I can get it manually run the Get-VIAccount command, but in the script, it fails.

    These are my steps

    1. connect to an existing host and retrieve role properties.

    2. connect to the new host

    3 join the domain.

    4. disconnect the new host and reconnect with the credentials of domain

    5. get the domain account, role of research/create and add permissions to host

    6. enable and configure SNMP

    7 restart MGMT officers.

    #Variables

    $vmhost = "Host03".

    $domaintojoin = "Domaine.org".

    $domainAlias = "domain".

    # $usernametograntpermissions = "service.account".

    $rolename = 'team - account control service '.

    #Connect to host17 to retrieve the role privileges

    to connect-viserver host17

    #Extract of privileges for the role of vcenter Monitoring Service

    $privsforrole = get-viprivilege-role (get-ferrule-name $rolename)

    Server VI #disconnect

    disconnect-viserver *-confirm: $false

    VSphere hosts #Connect above (enter the credentials of the root when prompted)

    SE connect-viserver-Server host03

    #Join field

    Get-vmhostauthentication - VMhost ctcvsphere3 | Game-VMHostAuthentication-domain $domaintojoin - user %-% - JoinDomain-confirm password password: $false

    credentials of the #disconnect root

    disconnect-viserver *-confirm: $false

    #reconnect with the credentials of domain

    SE connect-viserver-Server ctcvsphere3-user username-password password % domain\username

    #Get domain account and add to the host

    $viAccount = get-VIAccount-DOMAIN-User - ID service.account

    # Get the role

    $viRole = get-ferrule-name $roleName

    If (-not $viRole) {}

    throw the "Role of the creation.

    New-ferrule-name $rolename - Server $vmhost

    Together-ferrule-role (Get-ferrule-name $rolename - Server $vmhost) - AddPrivilege (get-VIPrivilege-id $privsforrole - Server $vmhost)

    }

    # Add permissions on VMHost

    New-VIPermission-Director $viAccount-role $viRole - entity $vmHost

    all VIServers #disconnect

    Disconnect-VIServer *-confirm: $false

    }

    #Configure SNMP

    Get-vmhostsnmp | set-vmhostsnmp-enabled: $true

    Get-vmhostsnmp | game-vmhostsnmp - ReadOnlyCommunity 'SNMP.

    #Restart Mgmt officers

    Get-VMHostService - VMHost $vmhost | where {$_.} Key - eq "vpxa"} | Restart-VMHostService - Confirm: $falese - ErrorAction SilentlyContinue

    Here is my error:

    Get-VIAccount: 27/02/2014-16:03:11 VIAccount Get A general system

    rror occurred: access to the directory error

    C:\ps1\vmware\snmp1.ps1:42 char: 28

    + $viAccount = get-VIAccount < < < < - domain - User - ID SERVICE. ACCOUNT

    + CategoryInfo: NotSpecified: (:)) [Get-VIAccount], SystemError)

    + FullyQualifiedErrorId: Client20_VmHostServiceImpl_RetrieveUserGroups_Vi

    Error, VMware.VimAutomation.ViCore.cmdlets.Commands.PermissionManagement.GE

    tVIAccount

    Get-VIAccount: 27/02/2014-16:03:11 Get - VIAccount VIAccount with the id

    "service.account" was not found using the specified filters.

    C:\ps1\vmware\snmp1.ps1:42 char: 28

    + $viAccount = get-VIAccount < < < < - domain - User - ID SERVICE. ACCOUNT

    + CategoryInfo: ObjectNotFound: (:)) [Get-VIAccount], VimExceptio)

    n

    + FullyQualifiedErrorId: Core_OutputHelper_WriteNotFoundError, VMware.VimA

    utomation.ViCore.Cmdlets.Commands.PermissionManagement.GetVIAccount

    New-VIPermission: Impossible to validate the argument on the parameter "principal." The argument

    ent is null or empty. Provide an argument that is not null or empty, and then try

    the command again.

    C:\ps1\vmware\snmp1.ps1:56 tank: 40

    + New-VIPermission-main < < < < $viAccount - $viRole - entity role

    y $vmHost

    + CategoryInfo: InvalidData: (:)) [new VIPermission], ParameterBi)

    ndingValidationException

    + FullyQualifiedErrorId: ParameterArgumentValidationError, VMware.VimAutom

    ation.ViCore.Cmdlets.Commands.PermissionManagement.NewVIPermission

    The term 'catch' is not recognized as a cmdlet, function, script fi

    the, or an executable program. Check the spelling of the name, or if a path has been included

    DED, make sure the path is correct, and then try again.

    C:\ps1\vmware\snmp1.ps1:57 tank: 12

    + captures < < < < {}

    + CategoryInfo: ObjectNotFound: (catch: String) [], CommandNotFou

    ndException

    + FullyQualifiedErrorId: CommandNotFoundException

    Thanks in advance!

    Dimitar did a nice write-up of this phenomenon and a possible solution.

    See ESXi hosts to join a domain and licensing with PowerCLI

  • VCenter 5.1 does not start after joining the domain

    I have a VCenter Server 5.1 that I had to join the domain. The domain controller has died and I had to rebuild the domain from the ground controller. It is early in the generation of the environment and the user does not backup turns yet. The SQL database is on another virtual machine which I added to the domain and at least I think I have fixed the AD accounts on the SQL Server. I ping the SQL server machine vcenter server. I also have a Web server that uses the SQL Server and it works correctly. All thought that the web server uses a SQL account and not a Windows account. Having said that it's the VCenter error I get. I don't know where I can get more detailed logs. VCenter service dies as soon as I try to start it.

    Here's the log of events

    Application error event ID 1000

    Name of the failing application: vpxd.exe, version: 5.1.0.35539, time stamp: 0x514d6239

    Name of the failed module: vmacore.dll, version: 5.1.0.35539, time stamp: 0x514d5992

    Exception code: 0xc0000005 fault offset: 0x00000000000022f7 failed process id: 0xbd0

    Start time of application vulnerabilities: 0x01cefb39789687d1

    The failing application path: D:\Program Files\VMware\Infrastructure\VirtualCenter Server\vpxd.exe

    Path of the failing module: D:\Program Files\VMware\Infrastructure\VirtualCenter Server\vmacore.dll

    Report ID: bf5595b0-672c-11e3-958d-000c2944f450

    Just rebuilt the VCenter server, was faster than to try to fix it.

  • Unable to join the domain using customization comments vCD

    I have vCloud Director installed and running.  I created a vApp and edited the properties to allow customization of comments and more everything works so far but the computer will not join the domain.  I tried to use organization customization, as well as customize the TIME after deployment.  As soon as the server ends with the customization and is powered, I can log in and join the domain manually without any problem, I can't get comments customization to do that for me.   Its a Windows 2008 R2 server.  I found this entry at the end of the journal to customize-comments on the server:

    run the command netsh interface ip set dns 12 xxx.xxx.xxx.xxx static (it has the correct address for my DNS server) =

    The command has been successfully run, the output of the command:

    The configured DNS server is incorrect or does not exist

    Any thoughts?

    It is a farily well known problem.  For a join of field works in vCloud Director, you must have on your DHCP subnet.  Many people make using the vShield edge device that is located on the network of the Org.  The sysprep process runs before tools VMware is running (which applies to the satic IP address to the client).  It's sort of a situation or hen that the guest has ip when in sysprep, so the easy solution to make it work is DHCP.  Conversely, people did it is in port, a lab post script custization in vCD Manager who entered the field after the sysprep is made completely and the guest it's static IP.  Frankly, it's something of the order of operations that is causing the problem.  We are looking at this for other clients, but at the moment, what your options are

    (1) add DHCP to the subnet by using your own server DHCP OR vShield Edge

    (2) add a PostScript of customization to join the domain, it can be inserted into the comments thus customizaion area.

    Hope this helps you stop banging their heads on the wall

  • Discover the State of the agent (18) composer initialization error: could not join the domain (expected 815 seconds)

    Hi all

    My Active Directory, View Manager, composer and vmware vcenter are all on windows 2008 R2.

    I took a spanshot of Windows XP SP3 with DHCP setting, installed vmware tools, see agent installed, firewall disabled, the Member of domain etc.

    When I tried to clone the snapshot XP to several XPs with the pool creation process it get error in personalization with error, below

    *03/10/10 18:01:49 IST: View Composer agent State (18) initialization error: could not join the domain (expected 815 seconds)*.

    Help, please.

    Thank you

    Selim Desai

    VCP410

    Take a look at http://communities.vmware.com/message/1613937

    the solution has been http://support.microsoft.com/kb/944043/en-us

    André

  • Oh boy... Would physical left and P2V-cannot join the domain

    Hello

    I was basically testing function P2V and I left the physical server. No I want to regularize and actually use my PHYSICAL server - but I can't join the domain - I am tired to the subject he take off the field and put it back on. All the tips are greatly appreciated.

    Thank you

    When the two systems, the virtual and the physical, appear on the network with the eID of sam, it is possible that one of them will change the password secure between the domain member server and the domain controller. If the other is out of the game.

    As you say, he join the domain.

    AWo

    VCP 3 & 4

    Author @ vmwire.net

    \[:o]===\[o:]

    = You want to have this ad as a ringtone on your mobile phone? =

    = Send 'Assignment' to 911 for only $999999,99! =

  • How to test the domain controller security policy works or not?

    How to test the domain controller security policy works or not?

    So far, I put a security policy in the domain controller security policy, however, I do not affect client computers joined to the domain controller. and so far, if I apply the domain security policy work.

    LiuAlex

    Server must wonder about the Technet site.  http://social.technet.Microsoft.com/forums/en-us/home

  • "The relationship of trust between the Client and the domain controller has been lost."

    I had a client PC connected to a DC running 2003 SBServer.

    It was this error when he tried to connect with its domain account.

    "The relationship of trust between the Client and the domain controller has been lost."

    I had to connect as Administrator local and leave/re-join the domain with a different machine name.
    How can I fix the side Server?

    Hello

    The question you posted would be better suited to the TechNet community. Please visit the link below and validate the request.

    http://social.technet.Microsoft.com/forums/en-us/smallbusinessserver/threads

    Hope this information is useful.

  • the best practice is implemented Server Exchange and the domain controller in the same server

    the best practice is implemented in exchange server and the domain controller in the same server or
    put on another server

    Hello

    Your question of Windows 7 is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the public on the TechNet site. Please post your question in the following link for assistance:
    http://social.technet.Microsoft.com/forums

Maybe you are looking for