<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx</link><description>Users were unable to connect to their shares. John discovered that the Cluster service wasn't started, and that any attempts to start it resulted in an error 1068. He attempted to ping the virtual server's IP address and it returned a "request timed out</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#3145829</link><pubDate>Sat, 01 Nov 2008 22:59:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3145829</guid><dc:creator>derekmoore333</dc:creator><description>&lt;p&gt;For one of the two machines the two machines, on which I had already tried to install a MS Cluster. I had to find this fix, in addition to the above to get RPC and Network connections back online. The second node RPC came online without these additional mods.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.eggheadcafe.com/software/aspnet/32648815/2003-server-r2--network.aspx"&gt;http://www.eggheadcafe.com/software/aspnet/32648815/2003-server-r2--network.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;1. ON DOMAIN CONTROLLER Group Policy for this SQL CLUSTER, Go to Computer Configuration - Windows Settings - Local Policies – User right Assignment- look for &amp;quot;Bypass traverse checking&amp;quot; Policy and add NETWORK SERVICE.&lt;/p&gt;
&lt;p&gt;2. ON LOCAL SQL SERVER, Open Windows Explorer and Go to \Windows\Registration folder - go to properties - Security tab -&lt;/p&gt;
&lt;p&gt;add the following accounts with permissions.&lt;/p&gt;
&lt;p&gt;a.Administrator - Full rights&lt;/p&gt;
&lt;p&gt;b.System - Full rights&lt;/p&gt;
&lt;p&gt;c.everyone - Read / Modify(WRITE) and List&lt;/p&gt;
&lt;p&gt;Then click &amp;quot;APPLY&amp;quot; and go to &amp;quot;General&amp;quot; tab and click on the &amp;quot;Advance&amp;quot;&lt;/p&gt;
&lt;p&gt;button. Here click the &amp;quot;Inheritance option&amp;quot; and finally click &amp;quot;OK&amp;quot;&lt;/p&gt;
&lt;p&gt;3. Open regedit&lt;/p&gt;
&lt;p&gt;a.go to &amp;quot;My Computer\HKEY_CLASSES_ROOT_\CLSID&amp;quot;. Right click on it and&lt;/p&gt;
&lt;p&gt;select &amp;quot;Permissions&amp;quot; and add &amp;quot;Authenticated Users&amp;quot; with &amp;quot;Full Permissions&amp;quot;&lt;/p&gt;
&lt;p&gt;b.Go to &amp;quot;My Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services&amp;quot;.&lt;/p&gt;
&lt;p&gt;Right click and select &amp;quot;Permissions&amp;quot; and add &amp;quot;Network Service&amp;quot; and &amp;quot;Local&lt;/p&gt;
&lt;p&gt;Service&amp;quot; with &amp;quot;Full Permissions&amp;quot;&lt;/p&gt;
&lt;p&gt;4.Finally go to &amp;quot;My&lt;/p&gt;
&lt;p&gt;Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs and set&lt;/p&gt;
&lt;p&gt;the &amp;quot;ObjectName&amp;quot; to &amp;quot;NT Authority\NetworkService&amp;quot;&lt;/p&gt;
&lt;p&gt;5.Reboot the promblematic server and check if the issue still exists.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3145829" width="1" height="1"&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#3031745</link><pubDate>Mon, 07 Apr 2008 18:23:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3031745</guid><dc:creator>g</dc:creator><description>&lt;p&gt;BRILLIANT! &amp;nbsp;Thanks for the leg work and making me look good to my director!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3031745" width="1" height="1"&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#2990458</link><pubDate>Wed, 12 Mar 2008 06:32:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2990458</guid><dc:creator>Steve Ferrarini</dc:creator><description>&lt;p&gt;Justin,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;Great information! &amp;nbsp;I almost passed by because of the title, but this was exactly what we needed.&lt;/p&gt;
&lt;p&gt;Thanks again for the investigative work, and making it available for us to find!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2990458" width="1" height="1"&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#2657920</link><pubDate>Tue, 18 Dec 2007 23:25:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2657920</guid><dc:creator>Phil Petersen</dc:creator><description>&lt;p&gt;Thanks. Thanks. Thanks. I've been fighting this problem for days and days at one of customers sites (away from home). Thanks for getting me home for the HOLIDAYS.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2657920" width="1" height="1"&gt;</description></item><item><title>RPC permissions on boot</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#2182941</link><pubDate>Tue, 16 Oct 2007 16:09:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2182941</guid><dc:creator>Rich Gautier</dc:creator><description>&lt;p&gt;You just saved me hours of work. &amp;nbsp;Thank you for your breakout of this problem. &amp;nbsp;It affected us during a security patch and reboot session this morning, even though it only affected some of our machines, the advice and underlying reasons were dead on.&lt;/p&gt;
&lt;p&gt;Thank you very much for sharing this info.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2182941" width="1" height="1"&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#2008324</link><pubDate>Fri, 21 Sep 2007 14:42:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2008324</guid><dc:creator>Mr Steve</dc:creator><description>&lt;p&gt;We had some issues with 2003 SP1 and the Time Service - after a reinstall of SP1 to fix the issue, we had the COM+ and RPC issue also. &amp;nbsp;In our case, the &amp;quot;Impersonate...&amp;quot; policy was never defined in the DCP. &amp;nbsp;Just performing the final restart now, and i'd just like to take the chance to backup Meir's comment that indeed - Justin - YOU ARE THE MAN!!! &amp;nbsp;:0)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2008324" width="1" height="1"&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1967386</link><pubDate>Sun, 16 Sep 2007 15:42:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1967386</guid><dc:creator>Michele Maran</dc:creator><description>&lt;p&gt;Thanks for the greats tips. Problem solved for me during Active Directory upgrade from win2k to win2k3.&lt;/p&gt;
&lt;p&gt;I remeber that installation of Norton Antivirus Client Server Suite ask me to change impersonate key of domain group policy years old.&lt;/p&gt;
&lt;p&gt;Thanks a lot&lt;/p&gt;
&lt;p&gt;Michele Maran from Italy&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1967386" width="1" height="1"&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1861863</link><pubDate>Thu, 30 Aug 2007 19:19:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1861863</guid><dc:creator>Meir</dc:creator><description>&lt;p&gt;Justin you're the man, you saved my weekend (after foolishly applying a malformed security policy).&lt;/p&gt;
&lt;p&gt;Your article is really helpful and important.&lt;/p&gt;
&lt;p&gt;I think the title &amp;quot;Cluster service failure after AD lockdown&amp;quot; is a bit illusive, it doesn't reflect the real context of the problem. it can happen actually on any domain member (SQL server services also failed) &lt;/p&gt;
&lt;p&gt;Thanks again!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1861863" width="1" height="1"&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1715801</link><pubDate>Tue, 07 Aug 2007 08:56:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1715801</guid><dc:creator>JL</dc:creator><description>&lt;p&gt;Just wanted to let you know you saved our bacon with this article. THANKS!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1715801" width="1" height="1"&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/b/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1692895</link><pubDate>Fri, 03 Aug 2007 17:13:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1692895</guid><dc:creator>Dan Capor</dc:creator><description>&lt;p&gt;Thank you Justin,&lt;/p&gt;
&lt;p&gt;This problem had plagued our network for a few months. I had only stumbled upon the temportary fix of setting each machine's RPC service to Local System Account, but it was just a bandaid on a gushing wound.&lt;/p&gt;
&lt;p&gt;Thank you, Thank you, Thank you.&lt;/p&gt;
&lt;p&gt;~Dan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1692895" width="1" height="1"&gt;</description></item></channel></rss>