Windows 7 Clients Talking 6to4 to 2008 Servers

Hi All,
I have a question (and maybe this is the designed behavior).  We have quite a few new Windows 7 clients that we didn't have in the past.  They are experiencing "slowness" issues communicating with 2008 Servers.  I've been doing some digging and it appears that all the Windows 7 PC's are attempting to talk to 2008 Servers via 6to4 rather than through the IPv4 addressing.  It seems many times they can't actually communicate via the DNS resolved 6to4 addressing and eventually fail back to using IPv4.  (At least I think this is what's happening but, it's taking upwards of 30 seconds for that to happen).  Obviously this is causing issues.  If I disable the 6to4 tunnel on the 2008 boxes, and then delete the nasty DNS entries that contain the 6to4 IPv6 2002:: addressing, the clients are happy and they talk IPv4 no delay.  Thoughts?

If your Windows 7 clients get public IP addresses they can and will use 6to4 if possible. This is mostly due to the fact how the clients are configured. The server has no control what protocol your clients may use if they have the option of using either IPv6 or IPv4.
Thus, disable IPv6 on your Windows 7 clients. That will get rid of this problem altogether.
Otherwise, if you don't want to use 6to4 (which isn't a good idea anyway unless you trust whoever is operating the anycast address 192.88.99.1) disable it on the clients. They shouldn't use the 6to4 unless you trust the 6to4 relay.
Same thing may apply to the teredo tunnel.
Otherwise, register for a public IPv6 address space and set it up in your LAN. Then all your clients will get normal IPv6 addresses and again, this should fix your problems. This should be the way to go eventually. Sooner or later you'll need IPv6 support in your network, thus why not start now?
You could of course use netsh on your clients to configure protocol preferences. If you don't like clients to register their IPv6 6to4 address in your DNS server, disable the DDNS update in the network properties.

Similar Messages

  • Invalid File Handle - Windows 7 clients talking to Mac OS 10.5.8  server

    Hello
    I have a file-sharing volume setup under 10.5.8 server - however with the addition of Window 7 clients i'm noticing lots of error whilst trying to copy to or from that volume {setup under SMB and AFP} via a windows machine...
    My Mac OS clients report no issues
    My windows clients report the '' Invalid File Handle''
    any fixes?
    many thanks in advance!

    http://www.laurentnomine.com/2009/09/invalid-file-handle-when-copying-files-from -os-x-leopard-10-5-to-vista7/

  • Remote desktop connection issue with an RDP client while connecting some 2008 servers and getting "unimplemented type in main loop"

    Hi
    For the working RDP server console we are getting the below PDU types only.
    // PDU Types
    RDP_PDU_DEMAND_ACTIVE = 1
    RDP_PDU_CONFIRM_ACTIVE = 3
    RDP_PDU_DEACTIVATE = 6
    RDP_PDU_DATA = 7
    Null PDU type = 0
    Where as for some windows 2003 servers getting "unimplemented type in main loop 13" instead of above mentioned PDU types.
    Could you please provide when we get this other PDU types ?
    Thanks & Regards,
    Pavan G

    Hello Pavan -
    I'll help you with this inquiry. By setting minencryptionlevel = 0 on server, are you able to get server->client unencrypted PDUs in network trace ? If yes, please send me the same by dropping a mail to dochelp @ Microsoft dot com.
    Thanks.
    Tarun Chopra | Escalation Engineer | Open Specifications Support Team

  • Windows VPN clients can't use network servers after 10.5.1 upgrade

    We have two Xserves, both formerly running 10.4.11. One is the OD master, the other a replica. The replica is also the VPN server, and is a DHCP server for the small number of IP addresses reserved for VPN clients.
    The OD master upgrade went fine. I completely reinstalled the OD replica, set the replica up again, and set up the VPN server. It supports L2TP/IPsec connections only.
    After the upgrade, Mac users running Tiger or Leopard can connect to the VPN server and connect to network services without any problems. Windows users can connect, but cannot actually USE anything on my office network. For example, if you try to connect to a web server either by fully qualified domain name or by hostname, the connection from the browser simply times out.
    In the Windows command line I can verify that I have an active connection by pinging and using the tracert command (equivalent of traceroute on UNIX). Hostname resolution works, too. But nothing happens when you try to open a web browser, which is mostly what my users need to do.
    It doesn't matter whether you're logging in with an OD user account or a local account defined solely on the VPN server. Same behavior in Windows.
    I had to take an older XServe running 10.4.11 out of our data center, move it to the office, and set it up on the same external network connection. 10.4.11 server works, 10.5.1 doesn't, from the same Windows client, set up exactly the same way.
    I've been through the hoops with Apple Enterprise support, who now tell me that Engineering kicked it back to them and told them they'd charge me $695 to get it fixed, because it's ostensibly custom configuration work. If that's true, why is Windows XP listed under L2TP/IPSec support on page 127 of the Leopard Network Services Admin guide? I don't want a custom fix, I just want it to work the way it's supposed to work. Or I want Apple to retract the claim that OS X Server is the best workgroup server solution for Macs and Windows.
    Anyone else encounter this problem or know of a fix?

    Had the same problems, started after i tried out the firewall in Leopard server.
    Seems that not all settings are reset even after turning the firewall off.
    To reset the firewall to its default setting:
    1 Disconnect the server from the Internet.
    2 Restart the server in single-user mode by holding down the Command-s keys during
    startup.
    3 Remove or rename the address groups file found at /etc/ipfilter/
    ipaddressgroups.plist.
    4 Remove or rename the ipfw configuration file found at /etc/ipfilter/ipfw.conf.
    5 Force-flush the firewall rules by entering the following in Terminal:
    $ ipfw -f flush
    6 Edit the /etc/hostconfig file and set IPFILTER=-YES-.
    7 Complete the startup sequence in the login window by entering exit:
    The computer starts up with the default firewall rules and firewall enabled. Use Server
    Admin to refine the firewall configuration.
    8 Log in to your server’s local administrator account to confirm that the firewall is
    restored to its default configuration.
    9 Reconnect your host to the Internet.
    This solved the problem for me...

  • Windows CE7 Client for SQL Server 2008

    I am trying to get a WinCE 7 device communicating with my Microsoft SQL Server 2008 database and am a little lost of how to do this. I do not want to have to develop any code, I already have code to update
    the DB, I just need to establish a connection.
    Has anyone been successful with this? I have tried making a new network connection but it was not successful. Any help would be appreciated
    Calvin

    What have you concretely done so far?
    It also strongly depends on you development environment.

  • Windows 7 client can't connect to Server 2008 R2 Print Server VM (ESXi 5.5)

    I have an issue today that is driving me bonkers.
    I recently came on-board to a company in my area as the system administrator and this network has everything and the kitchen sink wrong with the network layout, probably the worst I've seen and I'm slowly but surely fixing it day by day.....
    Well today I decided I was going to spin up another VM from a template and make a Print Server, seems harmless right? --- I thought so too, added all of the printers to the server and did test pages, all was dandy, but then I tried to add the printers to
    clients and other server and the real fun has begun, I'm truly perplexed now...
    I added a VM to my esxi 5.5 cluster at work that is a 2008 R2 server with only print management on it. I can map all of the printers on the network to the print server as-well as install the drivers correctly and I can resolve the IP and server name via
    DNS. I can test printers directly from the print server successfully printing out test pages however whenever I try to map printers you know from the directory in 'devices and printers' from any of the Windows 7 clients or any of the other 2003/2008 servers
    I get the classical "Windows cannot connect please check the network connection and make sure sure the printer is turned on". I disabled the windows firewall and I made the point to print GPO set to disabled and still no luck. Again I can print to
    all of the printers internally inside of the VM (so I know it communicating to all of the printers), I just can't connect to the printers listed in the directory on any of external desktop/client, it's like so annoying. spent about 6 hours until my brain just
    couldn't think anymore, was about to go BS on the VM.
    The only thing I can think of, as I was driving home, is that there is a GPO on one of the DC that has a desginated print server policy set. But prior to last week the forest leve was 2000 and now it's 2003. I just don't know Server 2000 enough to know if GPO's
    worked in the same way they do in 2003.
    Right now printers are connected to other servers in a ad hoc mentality it seems, there has never been a true print server.
    Anyone ever have this problem before?
    I'm truly puzzled...

    Hi Mid.Hudson-IT,
    Before we begin ,we should ensure we have configured the printer server correctly .
    Here is a link for reference of configuring the printer server .
    Print server role: Configuring a print server
    https://technet.microsoft.com/en-us/library/cc775791(v=ws.10).aspx
    "I can map all of the printers on the network to the print server as-well as install the drivers correctly and I can resolve the IP and server name via DNS"
    From this sentence ,I can`t figure out whether you have tried to ping the server both with the IP adress and name adress from the client ?
    If we can ping the print server from the client,we can ensure the connection to the printer server is good .
    Then we can try to install the printer driver directly to have a check .In the adress bar of Windows Explorer ,input "\\server name \the printer name"
    If we cannot ping the print server ,we should troubleshoot the network issue firstly.
    We also can check the event viewer for more information to troubleshoot this issue .
    Best regards

  • Windows 2008 Terminal Server "user must change password at next logon" problem with Windows 7 client.

    Hi,
    I have a fully patched Windows 2008 SP2 Terminal Server and a fully patched Windows 7 client.
    I have logged into the Windows 2008 SP2 Terminal Server server with a test account via RDC before.
    When I try to log in via RDC to the 2008 TS with a test account which has been marked with the setting "User must change password at next logon" I get the RDC message "You must change your password before logging on the first time.  For assistance, contact your system administrator or technical support."  I need to force the user to change their password once it has been issued, any ideas on how this can be done?
    Thanks,
    Dan

    This does not resolve my issue all the way. I'm having the same problem; When i'm "deploying" users, i always want the users to set their own passwords. Ok, so I then set the auth mode to "RDP Security layer". It seemed to work fine, and it does for that
    special purpose.
    Just like Daniel, my clients are connecting to our terminal server from several/different "customer-domains" So, they can't logon locally(on their local computer) and change their password, it has to be done THROUGH the terminal server.
    But if I turn on RDP Security Layer, users can't use remoteapp through tsgw they only get: "Your Remote Desktop Connection Failed because the remote computer cannot be authenticated" Any ideas?
    Also, our terminal servers is round robin based in a farm. So users connect to: tsfarm.domain.com(yes, public a-record which resolves to two internal adresses) This is because, we're using a wilcard *.domain.com as SSL certificate.
    But, when i'm using this, our clients sometimes get double auth when they login. I only get the double auth when tsfarm.domain.com resolves to server A, but the session broker wants the user to be on server B.(load balancing)
    This does not occur when SSL is enforced, any ideas?

  • Windows 2008 Server and Windows 8 clients

    Hey Guys,
    I have had this problem for sometime now and really need a solution. I have Windows 2008 Enterprise Server running about 200+ terminal services clients. All Windows XP clients are fine, Windows 7 clients have issues when they get an updated version of
    remote desktop client(to solve the issue we simply rollback the update), Windows 8 clients cannot connect and use out remote app. The issue stems from the newer version of remote desktop client (on windows 7 and embedded in windows 8) cannot connect to our
    terminal server and generates an error and immediately disconnects. The error says "
    Your computer can't connect to the remote computer because an error occurred on the remote computer that you want
    to connect to
    So my questions are, how can i update my Windows 2008 Terminal server version to support these clients, or do u have migrate to Windows 2012? Or is there a solution to my current problem which will allow my client to connect and use the remoteapps?

    Hi,
    Thank you for posting in Windows Server Forum.
    Please follow the below steps and verify result.
    LAN manager authentication level settings (Local security policy->Local Policies->Security Options->Network Security: LAN Manager Authentication level). 
    Try to change it to "Send NTLMv2 response only" 
    Snap:
    If still face the issue please install this Hotfix.
    RDS client computer cannot connect to the RDS server by using a remote desktop connection in Windows
    http://support.microsoft.com/kb/2752618/
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • How to restrict users working on Windows 7 clients from accessing Windows Explorer and other systems in the network through Group Policy with a domain controller running on Windows Server 2008 r2

    Dear All,
    We are having an infrastructure setup of around 500 client computers managed through group policy.
    Recently the domain controllers have been migrated from Windows Server 2003 to Server 2008 R2.
    Since this account requires extremely strict environment, we need to figure the solution for restricting the users from access anything locally.
    It would be great if you can assist me with the following query.
    How to restrict users logged on Windows 7 clients from accessing Windows Explorer and browsing other systems in the network through Group Policy with a domain controller running on Windows Server 2008 r2 ?
    Can we disable Network Tab on the left hand pane ?
    explorer.exe is blocked already, but users are able to enter the Windows Explorer by clicking on the name which is visible on the Start Menu.

    >   * explorer.exe is blocked already, but users are able to enter the
    >     Windows Explorer by clicking on the name which is visible on the
    >     Start Menu.
    You cannot block explorer.exe when you do not replace the shell - the
    desktop you see effectively IS explorer.exe...
    Your requirement sounds like you need a custom shell:
    http://gpsearch.azurewebsites.net/#2812
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Windows Storage Server 2008 - unzip with drag & drop from Windows 7 client fails

    Hello.
    As i asked this question in German and got no answer so i try it in English now.
    I have the following problem:
    We have a Windows SBS 2008, where we store our files. If somebody opens a ZIP-file on a network share from a Windows 7 Client (64 Bit) it is possible to drag & drop the content (multiple files) to a directory. So far everything works as expected.
    We now have an additional Windows Storage Server 2008 integrated in our domain (Buffalo Tera Station WS-QV8/R5), where we also store files. If somebody opens the same ZIP-file on a network share of this server from a Windows 7 Client and tries to drag &
    drop the content the following happens:
    1. only one file is extracted and to display the file a refresh of the explorer view is needed.
    2. when the drag & drop action is repeated a second file is extracted
    Not alle files are extracted and there is no error message or indication why this happens.
    The behaviour is reproducible from another Windows 7 Client (32 Bit).
    If we try to drag & drop the files from the ZIP-file on the Windows Storage Server network sahre to a directory on the SBS network share all files are extracted correctly.
    On the Windows Storage Server itself all files are extracted without problmems. Therefore it must be a problem with the combination of Windows Storage Server und Windows 7 Client accessing the files via network shares.
    Are there any ideas where this problem could be located? Has anybody the same phenomenon and maybe a solution for it?
    Thanks in advance
    Michael Pruss

    Hi Michael,
    Thank you for clarifying the issue for us.
    I am trying to involve someone familiar with this topic to further look at this issue. There might be some time delay. Appreciate your patience.
    Thank you for your understanding and support.
    Regards
    Kevin
    TechNet Subscriber Support
    If you are
    TechNet Subscription user and have any feedback
    on our support quality, please send your feedback here.
     

  • Grdi 10.2.0.4 on Windows 2008 Servers

    Hi all,
    Any mentions to when Oracle will release an update so we can install GRID agents on Windows 2008 servers. As of now, it will not advance past the installation windows.
    Thanks,
    JR

    I downloaded the 10.2.0.4 agent for 32 bit Windows and all went fine. Its better than installing 10.2.0.2 and applying upgrades. Whatever the case, that did the trick.

  • Windos 2008 KMS host can't activate Windows 8 clients

    Hi, I have a Windows 2008 R2 SP1 working as a KMS Host, i can activate Windows 7, Office 2010 and Office 2013 without problems, but, when I try to activate Windows 8 clients an error is showed: 0XC004F042, this same error code us registered in the service
    log of the KMS Host.
    Thanks in advanced for your help

    This error almost always means that the KMSclient has successfully contacted a valid KMShost, but, the KMShost does not have the required KMShost productkey installed (e.g. a Windows8 KMSclient contacted a KMShost, but that KMshost doesn't have the needed
    update/patch/productkeys installed).
    http://technet.microsoft.com/en-us/library/ff793399.aspx
    Here's a wiki article I threw together:
    http://social.technet.microsoft.com/wiki/contents/articles/22510.volume-activation-kms-mak-adba-avma.aspx
    Are you trying to activate Win8.0 or Win8.1?
    (the required update/patch/productkey, is different...)
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • I dont have data in "Client status summary" report for servers in server collection, but get data from our Windows 7?

    Hi,
    I dont have data in "Client status summary" report for servers in server collection, but get data from our Windows 7?
    So and idea of way I dont get data from or servers? Missing client setting for servers?
    /SaiTech

    Hi,
    I do see the server in Server collections in "Monitoring--Client Status--Client Activity" but not in reports like "Clients with failed client check details" i get "No Data Available"?
    /SaiTech

  • Best Windows VNC client for talking to Mac Desktop

    I am trying to display the screen of the secondary display of a Mac from a Netbook. Ideally, I want the functionality of the Mac "share screen" feature, in particular with this you can choose to view either one of the displays, or both together. Does anyone know of a Windows or Linux VNC client which does this? I have looked at a couple of clients (TightVNC and RealVNC) but they both show both displays in a horizontal scrollable screen. I'm also concerned about performance, in particular the impact on the remote machine i.e. the one using two screens. Are Windows VNC clients going to impose any more overhead than a remote Mac connected via "share screen".

    About the external monitor, should a physical one be attached to ?
    If not that would be nice to use it only w/ vnc
    btw: I opened a thread on tightvnc tracker , see you there :
    https://sourceforge.net/tracker/?func=detail&aid=2811360&group_id=14067&atid=364 067

  • Windows 7 Client 'sees' an old version of windows 2012 server share

    Hi All,
    I have a problem which seems to be a common theme looking at other threads. Here's the overview of the problem:-
    I have multiple windows 7 clients and a windows 8.1 client within a 2008 Server in a domain.
    I also have a Windows 2012R2 Server which is not joined to the domain. There is a Share on the 2012R2 which has the Caching Option turned off. Everyone full control on Share & File permissions.
    One of the Windows 7 machines in Explorer when it looks at
    \\2012server\share sees an old version of the folder. It seems that SMB 2 chaching is working too well. Not even pressing F5 or clicking View, Refresh updates windows explorer.
    It took a reboot to get the workstation to see the up to date contents of the share on the 2012 server.
    We don't seem to have that behaviour with that client against the 2008 server.
    I have seen this behaviour on another machine un-related to us at another location which was in a workgroup with a 2012 server and no domain.
    Questions:-
    Is there some sort of problem with Windows 7 workstations working against 2012 Servers in a non-domain setting or is it just Windows 7 against 2012 servers period?
    I understand that Windows 7 utilises SMB1 & SMB2. SMB2 introduced caching. If the server has turned off the share cache option should the client cache the contents of the share or the information about the files & folders & 'file not found'
    information?
    I want to open a file handle to a file on a network share so I can read and write data to it. But I also want to know that when I look at the folder to open the file I'm actually looking at the live version of the folder and files in the folder and
    not a cached version of the folder. If it's a cached version the file might be there already but I won't see it.
    Is there an API call that tells the client to get a fresh view of the server share so I can be absolutely sure that when I look for a file on the server I'm getting the correct answer and not one from cache.
    I first posted the question with the same subject "Windows 7 Client 'sees' an old version of windows 2012 server share" in the Windows 7 Networking Fourm
    https://social.technet.microsoft.com/Forums/en-US/23bf3627-987b-4c27-8062-85a284a2cda4/windows-7-client-sees-an-old-version-of-windows-2012-server-share?forum=w7itpronetworking and it was suggested I repost in here. Please do take the time to read
    the thread which will save time with suggestions that have already been covered.
    As the computers that can be affected by this problem are not mine I cannot enforce or guarantee that any of my 'client base' will apply any hotfixes. I will also not have the ability to tweak registry settings as I can't guarantee Admin Access.
    It seems that we need to go back to SMB1 as all the tweaks to SMB since those days have introduced problems with the basic requirement of sharing files from a share on a server for Read/Write purposes. I have tried turning a network back to SMB1 and that
    has resolved a lot of the issues but then I found a post/MS blog that states not to leave the network on SMB1
    The Caching option of the share had already been turned off. Surely Windows clients should not cache any information about the share but I think that is not the case.
    Thanks is advance
    Robert

    Hi Shaon,
    Thanks for looking into this.
    If this is a known issue, why isn't the hotfix rolled into a general windows update if this is a known problem? However this doesn't just affect domain joined workstations.
    Surely it's basic functionality for a networked computer to access files and folders on a network file server. It's what networks were invented for at the end of the day.
    I am unable to apply hotfixes to these computers that are having the problem due to the fact they are not mine but my customers.
    At one of my customers sites I disabled SMB2 from the server and network clients as well as disabling the network adapter power saving option. This seemed to resolve the issues that I saw on one client that seemed to be 30 minutes behind the rest of
    the network.  The hotfix you link to states that it is for Domain joined computers. At my customer site the PC's are not in a domain at all, just a workgroup with workstations and a 2012r2 server. Will the hotfix be applicable to non-domain machines?
    Also many clients seemed to loose the file handle to an open file on the server. I'll get them to turn SMB2 back on at some point after I send out some updates but all the problems I see seem to be caused by the caching functions in SMB2. SMB1 is good and
    stable. It's SMB2 that seems to be causing the problems as it was designed from the ground up for caching.
    Has this networking issue been resolved in Windows 8, 8.1 and 10?
    As I am unable to apply a hotfix to 1000's of PC's that are not mine, is there an API call or something where I can get the windows client to stop lying and get me the current state of a folder on the server?
    Will Turning off ClientSideCaching fix the issue? HKLM\SYSTEM\CurrentControlSet\Services\MrxSmb\Parameters\
    CSCEnabled
    Or will every machine need to be tuned individually according to the following guide:-
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/7bd9978c-69b4-42bf-90cd-fc7541ccb663/forum-faq-troubleshooting-network-file-copy-slowness?forum=winserverPN ?
    Robert

Maybe you are looking for

  • Latency issue Logic pro 9.1.3.

    Hey, At the same time as upgrading to Logic from Garageband I bought a Cakewalk Roland UA25EX ext usb soundcard because i was told i'd have latency issues if i used the caps lock keyboard for midi or direct input thru the input jack of my MacBookPro

  • A few questions about this "cure"

    Okay so we all get it.... click back and forth between music and iPhone.... how about some specifics? how long has everyone been waiting to let it connect to the server before clicking on something else? are u just clicking back and forth? couild i a

  • How do I get Adobe Professional 8 to work with Windows 7?

    I have a new computer with Windows 7 on it and when I try to install Adobe Professional 8 it says I need a Windows Vista Adobe PDF.dill file.  Where can I find this file?  I do not have Windows Vista.

  • Icc profile for deskjet 959c

    Is it possible to use another printer's ICC profile for lightroom? It seems that there is none for the above printer -- too old probably.

  • TestStand Report Customization

    I'm using TestStand 3.5 and LabVIEW8.  In a related exercise, I found that the file StationGlobals.ini contains a number of configurable options.  I used the TestStand sequence editor to update the Station Globals (I added some custom items).  I was