Branch Office Access

I use TMG as our companies Proxy as well as default gateway. I have recently installed 2 sonicwall tz105 devices, one located at our branch office and one located in our main office where the TMG server is located. The branch office uses this device for
internet access and a vpn tunnel to our main office. (At one time I had a ISA server at the branch location and it was the vpn tunnel to our main but this is a small 2 man office and keeping the isa server up to date was becoming a pain.) The branch office
has no problems accessing the main office. My problem is getting the main office to access the branch office. Right now if a client computer on the main network wants to access a server on the branch office the only way to accomplish this is to change the
client computers gateway from the tmg server ip to the sonicwall ip. This was not a problem in the past when I had 2 isa or tmg servers at both locations because the rules would pass the traffic to the branch office. I have tried putting rules in the TMG server
for traffic bound to the branch office network but nothing seems to work.
Should I be using tmg rules to accomplish this or do I need to go a different route such as dns or routing.
Thanks,

HI Gray,
Belwo are my suggestations.
Ensure all the client Default gateway is pointing to TMG, If you have any L3 Switch Devices before TMG Internal Interface then on L3 point Default gateway to TMG Internal Interface and on all client make Gateway as L3 Switch.
Create a network Subnet Set of Branch Office in TMG
In TMG Networking, You need to have a route relationship
Go to Networking, Create a new network Rule, From Branch Office Subnet to Internal as Route ( Not NAT). As route is bidirectional it will automatically route Internal to Branch Office
On Access Rule, Create Two Rules, Internal to Office Subnet and Office to Internal and allow all outbound Ports
Ensure, Your SonicWALL is Routing Traffic to Internal network to TMG External interface.

Similar Messages

  • Internet Access through TMG for all HO & Branch office

    Dear Experts!,
    I am new to the Forefront TMG 2010. Have requirement to implement internet access.
    Head office : 192.168.11.x/24 (192.168.11.1 is the TMG server)
    Branch Office 1: 192.168.12.x/24
    Branch Office 2 : 192.168.14.x/24
    Branch Office 2 : 192.168.16.x/24
    Forefront TMG 2010 standard edition.
    Having 3 NIC's two have different ISP network addresses and one has 192.168.11.1.
    Branch office are connected using MPLS network, the requirement is all branch site internet must be accessed through TMG 2010 server which is homed in Head Office. How to achieve ?
    What needs to be done in external firewall and in TMG for enabling internet access.
    Thanks!
    Regards, Ganesh, MCTS, MCP, ITILV2 This posting is provided with no warranties and confers no rights. Please remember to click Mark as Answer and Vote as Helpful on posts that help you. This can be beneficial to other community members reading the thread.

    Hi Ganesh,
    Hope this helps
    1 - If you wish to give internet as Proxy to users.
    Ensure the Below subnet is able to reach TMG Internal Interface that is 192.168.11.1
    Subnet
    Branch Office 1: 192.168.12.x/24
    Branch Office 2 : 192.168.14.x/24
    Branch Office 2 : 192.168.16.x/24
    Configuration
    Enable Proxy in TMG and configure Proper Ports as per your requirements
    On the Client IE – Ensure you put Proxy IP as TMG and Port configured in TMG configuration.
    Enable a Rule
    Access Rule
    Source : Internal
    Destination : External
    Ports : HTTP / HTTPS
    Users : Authenticated Users
    2 As normal Internet as Gateway to users
    You need to request your MPLS provider to change the Default Route of below subnet to 192.168.11.1. By doing this, all the internet request from the below subnet to internet will hit TMG.
    Subnet
    Branch Office 1: 192.168.12.x/24 Default Route 192.168.11.1
    Branch Office 2 : 192.168.14.x/24 Default Route 192.168.11.1
    Branch Office 2 : 192.168.16.x/24 Default Route 192.168.11.1
    IF you have any L3 Switch then you can also make Default gateway as L3 for all the subnet and from L3 device point it to TMG
    Enable a Rule
    Access Rule
    Source : Internal
    Destination : External
    Ports : HTTP / HTTPS
    Users : All Users ( Important )
    Two ISP
    In network Rules : You need to use NAT
    You will have a Rule which NATS internal to  External
    On external - Choose which ISP interface should be used  and Apply NAT rule

  • Auto deploying branch office printers with Direct Access

    Hello there
    I am implementing my first Direct Access topology and have a question. We will have branch offices with workstations deployed using Direct Access for administrative purposes. We have staff moving around from branch to branch with the goal to
    make logging on to the network and accessing resources for users as automated as possible. One of the questions I have regards auto configuring branch printers for users using Group Policy. The branch offices have workstations, printers and NAT modem/routers
    with DHCP - but no servers.
    If we have a stand alone network printer, how do we list that printer in Active Directory allowing the user to auto-configure it using group policy? If we install it on a server at Head Office, would the print job travel there first and then back to
    the branch? Obviously this is not ideal. Or can it be directed straight to the printer using a script or something?
    Alternatively we can install and share it on a branch workstation and list it in the directory, but would this not be same the problem as above? This is not ideal either as it would depend on the workstation being always on and available.
    Any input Direct Access gurus?
    Thanks in advance
    MIS5000

    Hi,
    Thanks for your post.
    We could have 2 possible solutions for natively deploy printers using Group Policy without the need for any scripting:
    1) Group Policy Preferences – available in Windows Server 2008 and later
    2) Print Management – available in Windows Server 2003 R2 and later
    http://blog.powershell.no/2009/11/08/deploying-printers-using-group-policy/
    Did you try to use the Print Management? You can share printers on a network and centralize print server and network printer management tasks using the Print Management Microsoft Management Console (MMC) snap-in. Print Management helps you to monitor print
    queues and receive notifications when print queues stop processing print jobs. It also enables you to migrate print servers and deploy printer connections using Group Policy.
    https://technet.microsoft.com/en-us/library/cc731857.aspx
    Meanwhile, if you have any Direct Access related issue, I think you may ask in network forums:
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/home?forum=winserverNIS
    Regards.
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • VPN CLient TO access HO through BRanch office

    We have a branch office using cisco 1841 , which makes vpn to HO (ASA 5505)
    , both (1841 and asa )have VPN CLient Configured .we need Branch office VPN software client users to Connect to HO netword.i have tried but iam missimg out some where. I've attached some configs of both devices.can any one help ASAP.

    Here is the URL for the Configuring and Managing Connection Entries for the VPN follow the steps for configuration which will help you :
    http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_user_guide_chapter09186a008015e271.html

  • Windows 8.1 laptop not connecting to domain in branch office

    We have a problem with a laptop. 
    It is installed in our Head office (The Netherlands), just like all other laptops by using an image.
    Tested and working on the domain.
    The user had to go to one of our branch offices (China) and when he connected there, the laptop just won't connect to the domain.
    When he plugged in the laptop, it keeps trying to connect it's directaccess.
    Other laptops (same image) immediately recognize the domain network, but this laptop just won't.
    I am able to ping everything on the local network (MPLS connection), from HQ to all Branch offices but not access them.
    I've tried changing the DNS settings, but without any result.
    Any suggestions?

    Hi,
    According to this tool's description, I think it should be helpful to check system current enviroment, such as network, certificates, etc. problem. Actually according to your description, I doubt it probably network enviroment of ISP problem, but we should
    find a way to verify our suspect. Then this tool would be convenient, it also would generate a trace log and it would be helpful with troubleshooting.
    The DirectAccess Client Troubleshooting Tool is a graphical application, based on the .NET Framework, which checks the health of a DirectAccess client by running various tests.  Built-in health tests: The following tests are currently implemented:
    Network interfaces Network location (NLS and NRPT DNS) IP connectivity (6to4, Teredo, IPHTTPS, entry point in a multisite setup, DNS) Windows Firewall (applied profile, Firewall outbound rules) Certificates (EKU Client Authentication, trust chain for AIA and
    CRL) IPsec infrastructure tunnel (Domain SysVol share) IPsec intranet tunnel (PING and HTTP probes) Additional features Run post-check script (PowerShell, VBScript, BAT or CMD file)
    Roger Lu
    TechNet Community Support

  • Branch Office Connectivity

    hi
    we have firewall setup in our main office with following setup:
    we are running DC on Windows 2008 Servers with MS Exchange 2010, lync 2010 and ip phone as well.
    planning to setup AD replication to our branch offices for network drive access and group policy update; kindly advice on this.
    Best Regards,
    Ramesh TP

    Hi
     i think you mean about best practice topology.
    First of all,you will add Additional Domain Controllers on your branch offices.Also This ADC will have DNS,DHCP role based.And will deploy a File server.
    Important point is structure you want to build.
    This is a detailed article about domain topologies, So please check this article about your questions;
    https://msdn.microsoft.com/en-us/library/cc749945.aspx?=255&MSPPError=-2147217396

  • Branch office web-to-go is not starting

    Hi,
    I have downloaded and installed the Oracle Lite Branch Office setup from server's webtogo/setup. But the webtogo in branch office PC is not starting. The htttp://localhost/webtogo and listener are not started even after executing the executables manually.
    The PATH variable is set correctly. The branch office PC has Windows XP.
    Regards,
    Aneesh

    Hi,
    webtogo -d option is giving following error.
    E:\mobileclient\bin>webtogo -d
    log9: [LOADING wtgos.dll BOAdminToolNative]
    log9: [BOAdminToolNative wtgos Loaded Successfully]
    log9: MODE_BRANCH CONNECT_STRING =jdbc:polite@:1160:
    log1: Translated JDK:'Cp1252' to IANA: 'WINDOWS-1252'
    log1: Mount point jdbc:polite@:1160:WEBTOGO oracle.lite.web.ifs.OMFS@145d068
    log9: java.sql.SQLException: [ODBC 08001] unable to connect to data source
    log9: at oracle.lite.poljdbc.LiteEmbJDBCConnection.jniDriverConnect(Native Met
    hod)
    log9: at oracle.lite.poljdbc.LiteEmbJDBCConnection.connect(Unknown Source)
    log9: at oracle.lite.poljdbc.LiteType2JDBCFactory.createConnection(Unknown Sou
    rce)
    log9: at oracle.lite.poljdbc.POLJDBCConnection.<init>(Unknown Source)
    log9: at oracle.lite.poljdbc.OracleConnection.<init>(Unknown Source)
    log9: at oracle.lite.poljdbc.POLJDBCDriver.connect(Unknown Source)
    log9: at java.sql.DriverManager.getConnection(Unknown Source)
    log9: at java.sql.DriverManager.getConnection(Unknown Source)
    log9: at oracle.lite.web.JupConnection.<init>(Unknown Source)
    log9: at oracle.lite.web.JupConfig.createConnection(Unknown Source)
    log9: at oracle.lite.web.JupConfig.getConnection(Unknown Source)
    log9: at oracle.lite.web.JupConfig.getStatement(Unknown Source)
    log9: at oracle.lite.web.JupServer.loadMimes(Unknown Source)
    log9: at oracle.lite.web.JupConfig.reload(Unknown Source)
    log9: at oracle.lite.web.JupConfig.initializeRM(Unknown Source)
    log9: at oracle.lite.web.JupConfig.initializeRM(Unknown Source)
    log9: at oracle.lite.web.JupServer.initialize(Unknown Source)
    log9: at oracle.lite.web.JupServer.listen(Unknown Source)
    log9: at oracle.lite.web.JupServer.main(Unknown Source)
    log-1: ============== Server Exception - Begin ==================
    java.sql.SQLException: [ODBC 08001] unable to connect to data source
    at oracle.lite.poljdbc.LiteEmbJDBCConnection.jniDriverConnect(Native Met
    hod)
    at oracle.lite.poljdbc.LiteEmbJDBCConnection.connect(Unknown Source)
    at oracle.lite.poljdbc.LiteType2JDBCFactory.createConnection(Unknown Sou
    rce)
    at oracle.lite.poljdbc.POLJDBCConnection.<init>(Unknown Source)
    at oracle.lite.poljdbc.OracleConnection.<init>(Unknown Source)
    at oracle.lite.poljdbc.POLJDBCDriver.connect(Unknown Source)
    at java.sql.DriverManager.getConnection(Unknown Source)
    at java.sql.DriverManager.getConnection(Unknown Source)
    at oracle.lite.web.JupConnection.<init>(Unknown Source)
    at oracle.lite.web.JupConfig.createConnection(Unknown Source)
    at oracle.lite.web.JupConfig.getConnection(Unknown Source)
    at oracle.lite.web.FileHandlerUtil.<init>(Unknown Source)
    at oracle.mobile.job.Scheduler.<init>(Unknown Source)
    at oracle.lite.web.JupConfig.initializeRM(Unknown Source)
    at oracle.lite.web.JupConfig.initializeRM(Unknown Source)
    at oracle.lite.web.JupServer.initialize(Unknown Source)
    at oracle.lite.web.JupServer.listen(Unknown Source)
    at oracle.lite.web.JupServer.main(Unknown Source)
    ================== Server Exception - End ====================
    Noticed that listener is not getting started,
    E:\mobileclient\bin>olsv2040 /start
    OliteService reports the following error:
    OliteService failed, Error Code: (0x5), Message: Access is denied.
    Internal message: StartService failed in CmdStartService function.
    Forgot to mention earlier,
    During installation of branch office client, I recieved following Warnings,
    1. Operating system message: Password doesnot meet minimum security requirements. Check the password length, complexity and history.
    2. No mapping between accounts and security ID was done.
    Thanks,
    Regards,
    Aneesh

  • Branch Office implementation

    where can I find a good white paper on 'Branch Office' arch. and implementation of Lite?

    Hi ,
    Oracle Lite -Branch Office not working as expected
    Lite Version- 5.0.2
    1.     The documentation says an odbc dsn should have been automatically created with a name of "USER_DBNAME” when sync with Mobile server
    2.     A blank "files available for download" page is display with no buttons and no file from url ‘http://BR/public/download’
    3.     Can’t see any application in the Branch office system
         Steps used to create/publish a branch office application
         We have three machines and their hostnames are
         M1 = Mobile Server + Mobile development kit Win2k
         M2 = Branch Office win2k
         M3 = Branch Office client win2k
    1) Install Mobile Server and mobile developer kit 5.0.2 on machine M1 2) Launch "Mobile Server Control Center" to machine M1
    3) Create user “Test”, Assign user "Test" System Privilege of
    "Administrator"
    4) Assign user "Test" to the "Branch Adminstrators" group
    5) Create a dummy application (Sample. jar).
    6) Launch packaging wizard on machine m1
    7) Select "Win32 Native" as your target
    8) created snapshots with scott.emp table
    9) Enter "Sample" in the client side database name field.
    10) Publish the application from machine M1
    11) Launch "Mobile Server Control Center" to machine m1
    12) from the applications tab of "Control Center" Select the
    "Sample” application
    13) Enter the database users password and save the change
    14) Select the "Access" link from the left nav and grant user
    "Test" access to the "Sample" application
    15) Select the "Files" link from the left nav then select the win32
    link.
    Check the public file box for file "Sample.jar" and save changes
    16) from machine M1 install branch office by downloading the software
    from machine M1.
    Download/install http://MO/webtogo/setup, select the "branch
    office" download
    17) From the M1 machine launch setup.exe
    18) Sign on as user Test, Press "next" to sync
    19) The documentation says an odbc dsn should have been automatically
    created with a name of "Test_Sample".
    Can see only DSN name “webtogo” which points to <<Dir>>\OLDB40 and file ‘Sample.odb’
    20) From the M1 machine launch the control center @ http://localhost/ 21) Sign on as user shekar , Press sync tab
    20) checked the M1 machine and it did not install my "Sample.jar" but can see ‘Sample.odb’
    21) Now attempt to configure the branch office client machine m1
    22) From machine M2 download the client software @ http://m1/public/download
    23) A blank "files available for download" page is display with no buttons and no file.

  • Branch Office CME design Verification

    Hi All,
    Please refer to the attached network diagram.
    I need to verify this can be implemented and would work.
    We have a branch office moving to a new location and they intend to keep their existing CME (for business reasons),  provided by their local service provider with ISDN line for calls to the PSTN. This is managed by the service provider and we have no access to it. However we would like to grant them connectivity to the existing corporate voice network via an IP VPN connection, which shall be put in place soon. This will enable  the branch make site to site calls within the corporate network
    With a SIP trunk between the internal and external CME, I intend to make all the phones register with the Call Manager, however on the call manager , set a route pattern for calls going out to the PSTN from this branch back to the internal CME and this will then be matched by a SIP dial peer  directing the call to the external CME out to the PSTN.
    My worry is with the delay  that might be introduced when making a PSTN call as the internal CME has to first contact the call manager in order to know where to send the call.
    So my questions are as follows,
    1. Is this solution feasible especially in terms of delay? If not,
    2. Are there any other ways to achieve the same scenario
    Thanks,
    Yomi

    Are the phones at the branch office going to register to the Internal CME? If so, all configuration for outbound dialing will be done on the Internal CME, not on UCM. ie. dial-peer on the Internal CME for outbound dialing. For phone connectivity back to UCM, you will have a SIP trunk between UCM and internal CME and that is perfectly acceptable. You "might" see some quality degradation but that is to be expected from Internet based WAN connectivity. If your RTT delay is greater than 150ms, then you might see some quality issues.

  • Branch Office DC Demand Dial VPN connection keeps failing

    here is me issue
    Our Branch Office DC is connected to Main Office DC with a Demand Dial Connection in RRAS Everything is connected fine for a little bit then its like the connection just gives out, it stays connected but i cannot ping the branch office DC with the local
    IP from the Main Office or access any network shares on it. When this happens i have to disconnect the server at the remote office and wait for it to reconnect im currently baffled as there are no Error LOGS to help me along and there doesnt seem to be anything
    that would be causing the issue for now until i get some answers as to what is going on i opened a command prompt on the DC here at the main office and i typed "ping 10.141.70.25 -t100" to monitor the connection more or less and when i see it timeout
    i reconnect it, i also have the networking tab open in task manager to monitor the LAN and RAS (Dial-In) Interface  the LAN doesnt seem too active but the RAS Interface does its got a constant network utilization of 0.28% and the Demand Dial interface
    on the remote office DC has a Utilization of 0.38% (Server Just disconnected as i was typing this and the utilization on the VPN connections on both servers went through the roof) heres the troubleshooting i have tried so far
    1. Rebooted both office DC`s at the same time
    2. Rebooted the branch office DC alone (this helped a little because the connection is staying active longer without fail)
    3. looked through all RRAS configuration on both servers to see if theres any mistakes by any other administrators (None Were Found)
    4. Used wireshark to see if there was anything interfering or that would cause this to happen (Nothing found)
    5. manually connected to the server in multiple ways like accessing network shares and remote management via MMC and manually making the servers replicate to see if any of that was causing issues and it wasnt
    My thoughts: im starting to think it may be a switch or something causing the connection issue at the branch office because the main office has all new routers and switches and just recently got a 100.00MBPS connection but nothing was affected for a good
    month so im not thinking it is the new connection or anything at the main office if theres something im overlooking here please let me know if some ipconfig /all results are needed i can provide them
    Viper Technologies Computer Repair Putting The Venomus Bite Back In Your Computer We Are Located In Antigonish ,NS Canada Check Us Out HTTP://WWW.VIPERTECHNOLOGIES.TK

    Hi,
    Are there any error messages on the event log ?
    Meanwhile, it is more network issue, i think you may ask in network forums:
    http://social.technet.microsoft.com/Forums/en-US/home?forum=winserverNIS
    Regards.
    Vivian Wang

  • Branch Office for Webtogo Apps

    Does Branch Office support Webtogo Apps? This would help with initial download times if a sync could be made to a Branch Office machine and then have local downloads by clients.

    I have a web-based Java servlet application. My application size is about 50MB of data/code and I would like to know if a Branch office configuration would help with sync times? Meaning, a central server would perform the sync with many Branch office machines located remotely. Then local clients would log into branch office machine and be able to access the web-based application and go offline if wanted.
    I installed a Branch Office machine but the Control Center does not have ability to create or manage Users or access to applications. Did I miss something?
    Thanks for your input,
    John

  • Branch Office without network

    Hi!
    We have been trying to use a branch office install on a single computer for concurrent access from multiple (local) clients.
    This works like a charm as long as the computer is on a network (dial-up up or LAN). When we disconnect from the network, new connections to the BO database tends to take several seconds.
    The BO machine OS is Windows NT or 2K
    I suspect this delay has something to do with the network connection. We have tried to install Microsft Loopback Adapter to remedy this. The result is that it is a little bit faster than before, but the delay is still there.
    Is the Branch Office multiuser listener bound to a specific network interface? If so can it be changed? Or does anyone have any other ideas...

    It is possible that a PC responds slowly when connecting to the a MU listener when the PC is not on the network. Check how the DSN is defined. Defining it as a localhost may speed up.
    MU Listener uses Windows sockets to open the connection.

  • Branch office setup with L3 switch and router with IOS security

    Hello,
    I am in the process of putting together a small branch office network and I am in need of some design advise. The network will support about 10-15 workstations/phones, 3-4 printers, and 4-5 servers. In addition we will eventually have up to 25-30 remote users connecting to the servers via remote access VPN, and there will also be 2-3 site-to-site IPSec tunnels to reach other branches.
    I have a 2911 (security bundle) router and 3560 IP Base L3 switch to work with. I have attached a basic diagram of my topology. My initial design plan for the network was to setup separate VLANs for workstation, phone, printer, and server traffic. The 3560 would then be setup with SVIs to perform routing between VLANs. The port between the router and switch would be setup as a routed port, and static routes would be applied on the switch and router as necessary. The thought behind this was that I'd be utilizing the switch backplane for VLAN routing instead instead of doing router-on-a-stick.
    Since there is no firewall between the switch and router my plan was to setup IOS firewalling on the router. From what I am reading ZBF is my best option for this. What I was hoping for was a way to set custom policies for each VLAN, but it seems that zones are applied per interface. Since the interface between the router and switch is a routed interface, not a trunk/subinterface(s), it doesn't seem like there would be a way for me to use ZBF to control traffic on different VLANs. From what I am gathering I would have to group all of my internal network into one zone, or I would have to scrap L3 switching all together and do router-on-a-stick if I want to be able to set separate policies for each VLAN. Am I correct in my thinking here?
    I guess what I am getting at is that I really don't want to do router-on-a-stick if I have a nice switch backplane to do all of the internal routing. At the same time I obviously need some kind of firewalling done on the router, and since different VLANs have different security requirements the firewalling needs to be fairly granular.
    If I am indeed correct in the above thinking what would be the best solution for my scenario? That is, how can I setup this network so that I am utilizing the switch to do L3 routing while also leveraging the firewall capabilities of IOS security?
    Any input would be appreciated.
    Thanks,
    Austin

    Thanks for the input.
    1. I agree, since I have only three to four printers, they need not be in a separate VLAN. I simply was compartmentalizing VLANs by function when I initially came up with the design.
    2. Here's a little more info on the phone situation. The phones are VoIP. The IP PBX is on premise, but they are currently on a completely separate ISP/network. The goal in the future is to converge the data and voice networks and setup PBR/route maps to route voice traffic out the voice ISP and data traffic out the other ISP. This leads up to #3. 
    3. The reason a router was purchased over a firewall was that ASA's cannot handle routing and dual ISPs very well. PBR is not supported at all on an ASA, and dual ISPs can only be setup in an active/standby state. Also, an ASA Sec+ does not have near the VPN capabilities that the 2911 security does. The ASA Sec+ would support only 25 concurrent IPSec connections while the 2911 security is capable of doing an upwards of 200 IPSec connections.
    Your point about moving the SVI's to a firewall to perform filtering between VLANs makes sense, however, wouldn't this be the same thing as creating subinterfaces on a router? In both cases you are moving routing from the switch backplane to the firewall/routing device, which is what I am trying to avoid.  

  • Slow Logons from branch office

    We just moved an office of ours in a branch office to another building. The office is in Miami and is normally connected to our Tampa main office via an MPLS connection. The connectivity to our Tampa office is down now because of issues with the MPLS provider
    but I have users still logging in to their desktops to access server resources in Miami. The issue is that logons in the Miami office are taking longer than normal even though the Miami site has a read/write DC with GC enabled on that DC. If I unplug
    the network cable the logon happens much quicker and then I can plug the cable back in and access the server with no issues. My assumption is that when unplugging the network cable the computer is logging on with the cached credentials on the computer instead
    of trying to access a DC for logon. I was under the assumption that since their is a read/write DC and GC server on site logons should not take forever even though the DC on site has no connectivity to the DC's in our main office here in Tampa. Am I missing
    something? Why would the logons take so long?
    Thanks in advance!
    Chad
    Chad Guiney

    Hi Chad,
    If site and subnet settings are configured correctly, I suggest you restart netlogon services on moved Domain Controller, then give it some time for replication and try to check the logon speed afterwards.
    More information for you:
    Moving a Domain Controller to a Different Site
    http://technet.microsoft.com/en-us/library/cc794722(v=WS.10).aspx
    Move a Server Object to a New Site
    http://technet.microsoft.com/en-us/library/cc816674(v=WS.10).aspx
    Best Regards,
    Amy
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Clients Not seeing DHCP server at branch office or not accepting ip offers (NO LOG REPORTS KIND OF IN THE DARK)

    Hi there i am having an issue that has popped up recently i have a DC at a branch office that is connected to the main office DC via a Persistent Demand Dial connection in RRAS. Everything was working properly according to me until i found out that the Network
    Admin who manages the branch office network failed to notify me that client machines weren't getting IP addresses from the DHCP server. This server was recently installed and wasn't fully implemented till about a week ago when i configured the Demand Dial
    connection in RRAS up until that point it just had a regular old VPN connection to the main office while we worked out the kinks with a few things. the things ive tried so far to get DHCP working are as followed
    1.Rebooted the branch office server (MULTIPLE TIMES)
    2. Uninstalled the DHCP Role and re-installed it....To my surprise 1 client managed to get a ip on its lan adapter after DHCP was re-installed but nothing else
    3. Disconnected the connection between the main office DC and the Branch office DC as i figured the main office DC DHCP server might be interfering with the branch office DC DHCP Server but nothing happened 
    4. Unauthorized and Reauthorized the main office DHCP server and the branch office DHCP server nothing changed
    5. sifted through multiple log files on both servers and found noting in fact DHCP logs are empty on both servers
    6. restored backups of the DHCP servers from when they were working
    7. came here cause im out of ideas and im pulling my hair out
    here are the current statistics from the problem server
    Start Time: 7/12/2014 2:02:10PM
    Up Time: 1Hours, 18 Minutes, 41 Seconds
    Discovers: 90
    Offers: 90
    Requests: 2
    Acks: 13
    Nacks: 0
    Declines: 0
    Releases: 0
    Total Scopes: 1
    Total Addresses 253
    In Use 2 (0%)
    Available: 251 (99%)
    Id like to add that RRAS was getting IP addresses from the problem server up until the point i uninstalled the role and re-installed it
    heres is a ipconfig /all from the problem server
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : MNB-DC
       Primary Dns Suffix  . . . . . . . : VTEACR.LOCAL
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : Yes
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : VTEACR.LOCAL
    PPP adapter Remote Router:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Remote Router
       Physical Address. . . . . . . . . :
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 10.141.70.25(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.255
       Default Gateway . . . . . . . . . :
       DNS Servers . . . . . . . . . . . : 10.141.70.10
       NetBIOS over Tcpip. . . . . . . . : Disabled
    Ethernet adapter Local Area Connection:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
       Physical Address. . . . . . . . . : 00-16-35-AB-D3-05
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::d9e:daa4:34dd:db44%10(Preferred)
       IPv4 Address. . . . . . . . . . . : 10.141.80.102(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : fe80::226:5aff:feb7:5b3c%10
                                           10.141.80.1
       DNS Servers . . . . . . . . . . . : ::1
                                           10.141.80.102
       NetBIOS over Tcpip. . . . . . . . : Enabled
    PPP adapter RAS (Dial In) Interface:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : RAS (Dial In) Interface
       Physical Address. . . . . . . . . :
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 169.254.238.243(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.255
       Default Gateway . . . . . . . . . :
       DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
                                           fec0:0:0:ffff::2%1
                                           fec0:0:0:ffff::3%1
       NetBIOS over Tcpip. . . . . . . . : Disabled
    Tunnel adapter Local Area Connection* 8:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.{427DF66B-3B30-40B1-B67E-B5587465C
    394}
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 9:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 02-00-54-55-4E-01
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 11:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.ziricom.com
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 12:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.VTEACR.LOCAL
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 13:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.{BE201060-A9B9-404A-8361-F8FFB82F5
    6F6}
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 14:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #5
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 15:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.VTEACR.LOCAL
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 16:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #7
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 19:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.ziricom.com
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    if anymore information is needed please let me know i have full access to everything on the network so its not a problem and i am able to remotely access the branch office DC and all computer and switches at any time of the day
    Viper Technologies Computer Repair Putting The Venomus Bite Back In Your Computer We Are Located In Antigonish ,NS Canada Check Us Out HTTP://WWW.VIPERTECHNOLOGIES.TK

    Hi,
    Does this issue occur on one client or multiple?
    Please check this article:
    http://technet.microsoft.com/en-us/library/cc757164(v=ws.10).aspx#BKMK_5
    Regards.
    Vivian Wang

Maybe you are looking for

  • My iPod touch got wet and I used the rice method to save it.

    After 3 days, I plugged it back in and it worked. But the problem is that the home and lock buttons don't work anymore. What can I do? It charges just fine but iTunes cannot detect it seems... So I can't backup my songs and all, which ***** consideri

  • PDF  sur Internet

    Bonjour Lorsque je veux publier un texte en PDF, (indépendament du format Reader 4 ou 9 )   je reçois le message"   The adobe acrobat/reader that is running can not be used to view Pdf files in a Web Browser J'ai adobe acrobat et reader  version 9, F

  • Get table ID for drill down (javascript functions)

    I want to implement some custom drill downs. When you click on a column to drill down, it uses the following javascript function: RTDr(saw_5_6,0,0) where in this case, "saw_5_6" is my current table. Since this is dynamically set and the table name ca

  • Content-Length Header Missing in Http Response

    Hi folks, Our application uses JSPs and Servlets. To solve a TCP level probelm, we would like to ensure that each response sent from the WebLogic Server includes a content-length header. All the pages are dynamic and therefore we cannot explicitly se

  • Set up acquisition at regular interval on ATI-MIO-16E-4

    I use labview 6.01 with an ATI-MIO-16E-4 and a scxi 1100 to aquire temperature readings. When I use AI aquire waveforms I can set the time at which I get data in a while loop at let say every second or every two seconds. When I use Ai Config, AI Star