Networking

Windows Server 2008 R2 丟棄數據包

  • April 19, 2012

我的 WS2008R2 Active Directory + DNS + DHCP + NAT 配置似乎有奇怪的問題。它看起來是 DNS、NAT 和 LDAP 之間的某種問題。

第一個後果是某種丟包問題。每隔一段時間,伺服器(充當預設網關)將丟棄數據包,命令將返回“目標主機不可達”。我還沒有弄清楚原因。這似乎與 DNS 無關。

C:\Users\Administrator>ping serverfault.com

Pinging serverfault.com [64.34.119.12] with 32 bytes of data:
Reply from 10.0.0.1: Destination host unreachable.
Reply from 64.34.119.12: bytes=32 time=113ms TTL=49
Request timed out.
Reply from 64.34.119.12: bytes=32 time=113ms TTL=49

C:\Users\Administrator>ping 74.125.79.105

Pinging 74.125.79.105 with 32 bytes of data:
Reply from 10.0.0.1: Destination host unreachable.
Reply from 74.125.79.105: bytes=32 time=39ms TTL=49
Reply from 74.125.79.105: bytes=32 time=37ms TTL=49

C:\Users\Administrator>ping 74.125.79.105

Pinging 74.125.79.105 with 32 bytes of data:
Reply from 74.125.79.105: bytes=32 time=36ms TTL=49
Reply from 74.125.79.105: bytes=32 time=36ms TTL=49

所以DNS解析得很好……但有時10.0.0.1會丟包……只是因為?間歇性發生。這是在伺服器本身上進行的測試,但客戶端表現出幾乎相同的行為,除了 DNS 有時也會失敗。

C:\Users\[user]>ping google.com
Ping request could not find host google.com. Please check the name and try again.

C:\Users\[user]>ping google.com

Pinging google.com [74.125.79.105] with 32 bytes of data:
Request timed out.
Reply from 74.125.79.105: bytes=32 time=37ms TTL=49
Reply from 74.125.79.105: bytes=32 time=36ms TTL=49

這將導致 HTTP 404 錯誤、應用程序抱怨沒有網際網路連接、抱怨伺服器離線等。

例如,它也在報告

_ldap._tcp.Default-First-Site-Name._sites.[server].ad.[domain].net
No such name

任何幫助或提示將不勝感激。:)

更新: 一些伺服器資訊。

C:\Users\Administrator>ipconfig /all

Windows IP Configuration

  Host Name . . . . . . . . . . . . : [server]
  Primary Dns Suffix  . . . . . . . : ad.[domain].net
  Node Type . . . . . . . . . . . . : Mixed
  IP Routing Enabled. . . . . . . . : Yes
  WINS Proxy Enabled. . . . . . . . : No
  DNS Suffix Search List. . . . . . : ad.[domain].net

PPP adapter RAS (Dial In) Interface:

  Connection-specific DNS Suffix  . :
  Description . . . . . . . . . . . : RAS (Dial In) Interface
  Physical Address. . . . . . . . . :
  DHCP Enabled. . . . . . . . . . . : No
  Autoconfiguration Enabled . . . . : Yes
  IPv4 Address. . . . . . . . . . . : 10.0.0.12(Preferred)
  Subnet Mask . . . . . . . . . . . : 255.255.255.255
  Default Gateway . . . . . . . . . :
  NetBIOS over Tcpip. . . . . . . . : Enabled

Wireless LAN adapter Wireless Network Connection:

  Connection-specific DNS Suffix  . :
  Description . . . . . . . . . . . : Linksys WMP600N Wireless-N PCI Adapter wi
th Dual-Band
  Physical Address. . . . . . . . . : 00-25-9C-FF-C1-FC
  DHCP Enabled. . . . . . . . . . . : No
  Autoconfiguration Enabled . . . . : Yes
  IPv4 Address. . . . . . . . . . . : 192.168.1.100(Preferred)
  Subnet Mask . . . . . . . . . . . : 255.255.255.0
  Default Gateway . . . . . . . . . : 192.168.1.1
  DNS Servers . . . . . . . . . . . : 10.0.0.1
                                      127.0.0.1
  NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Local Area Connection:

  Connection-specific DNS Suffix  . :
  Description . . . . . . . . . . . : Realtek RTL8168C(P)/8111C(P) Family PCI-E
Gigabit Ethernet NIC (NDIS 6.20)
  Physical Address. . . . . . . . . : 00-19-66-88-6A-1F
  DHCP Enabled. . . . . . . . . . . : No
  Autoconfiguration Enabled . . . . : Yes
  IPv4 Address. . . . . . . . . . . : 10.0.0.1(Preferred)
  Subnet Mask . . . . . . . . . . . : 255.255.255.0
  Default Gateway . . . . . . . . . : 0.0.0.0
  DNS Servers . . . . . . . . . . . : 10.0.0.1
                                      127.0.0.1
  NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{B84CD253-70D3-49E5-88F9-102C6B7FCEC0}:

  Media State . . . . . . . . . . . : Media disconnected
  Connection-specific DNS Suffix  . :
  Description . . . . . . . . . . . : Microsoft ISATAP Adapter
  Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
  DHCP Enabled. . . . . . . . . . . : No
  Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 11:

  Media State . . . . . . . . . . . : Media disconnected
  Connection-specific DNS Suffix  . :
  Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
  Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
  DHCP Enabled. . . . . . . . . . . : No
  Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{D7DFBDDF-7295-43E8-AAD4-4910D79202A9}:

  Media State . . . . . . . . . . . : Media disconnected
  Connection-specific DNS Suffix  . :
  Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
  Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
  DHCP Enabled. . . . . . . . . . . : No
  Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{6E06F030-7526-11D2-BAF4-00600815A4BD}:

  Media State . . . . . . . . . . . : Media disconnected
  Connection-specific DNS Suffix  . :
  Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
  Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
  DHCP Enabled. . . . . . . . . . . : No
  Autoconfiguration Enabled . . . . : Yes

C:\Users\Administrator>route print
===========================================================================
Interface List
26...........................RAS (Dial In) Interface
15...00 25 9c ff c1 fc ......Linksys WMP600N Wireless-N PCI Adapter with Dual-Band
11...00 19 66 88 6a 1f ......Realtek RTL8168C(P)/8111C(P) Family PCI-E GigabitEthernet NIC (NDIS 6.20)
 1...........................Software Loopback Interface 1
12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
         0.0.0.0          0.0.0.0         On-link          10.0.0.1    266
         0.0.0.0          0.0.0.0      192.168.1.1    192.168.1.100    276
        10.0.0.0    255.255.255.0         On-link          10.0.0.1    266
        10.0.0.1  255.255.255.255         On-link          10.0.0.1     11
       10.0.0.12  255.255.255.255         On-link         10.0.0.12    306
      10.0.0.255  255.255.255.255         On-link          10.0.0.1    266
       127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
       127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
 127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
     192.168.1.0    255.255.255.0         On-link     192.168.1.100    276
   192.168.1.100  255.255.255.255         On-link     192.168.1.100    276
   192.168.1.255  255.255.255.255         On-link     192.168.1.100    276
       224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
       224.0.0.0        240.0.0.0         On-link          10.0.0.1    266
       224.0.0.0        240.0.0.0         On-link     192.168.1.100    276
       224.0.0.0        240.0.0.0         On-link         10.0.0.12    306
 255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
 255.255.255.255  255.255.255.255         On-link          10.0.0.1    266
 255.255.255.255  255.255.255.255         On-link     192.168.1.100    276
 255.255.255.255  255.255.255.255         On-link         10.0.0.12    306
===========================================================================
Persistent Routes:
 Network Address          Netmask  Gateway Address  Metric
         0.0.0.0          0.0.0.0      192.168.1.1  Default
===========================================================================

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination      Gateway
 1     51 ::1/128                  On-link
 1    306 ff00::/8                 On-link
===========================================================================
Persistent Routes:
 None

路由顯示兩個網關,都用於外部連接(網路目標 0.0.0.0)。如果一個沒有響應,則使用另一個。這就是為什麼一些隨機數據包被丟棄的原因。嘗試從您的有線介面 (10.0.0.1) 中刪除預設網關,這樣路由應該始終使用另一個網關。否則,您可以檢查客戶端到 0.0.0.0 的路由以及客戶端上的 dns 伺服器。

引用自:https://serverfault.com/questions/353810