<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx</link><description>Users were unable to connect to their shares. John discovered that the Cluster service wasn't started, and that any attempts to start it resulted in an error 1068. He attempted to ping the virtual server's IP address and it returned a "request timed out"</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#559010</link><pubDate>Sat, 16 Dec 2006 12:17:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:559010</guid><dc:creator>Jason Hartzell</dc:creator><description>&lt;p&gt;Mr Turner. Great article tons of good info could you though increase some of the text size? &lt;/p&gt;
&lt;p&gt;I appreciate the link Sir I will be visiting regularly.&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#559011</link><pubDate>Sat, 16 Dec 2006 12:20:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:559011</guid><dc:creator>justintu</dc:creator><description>&lt;p&gt;Thank you for visiting. &amp;nbsp;Text size will be increased with the next post. &amp;nbsp;Thanks for the suggestion. &lt;/p&gt;
&lt;p&gt;Justin Turner&lt;/p&gt;
</description></item><item><title>Cluster service failure update...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#565728</link><pubDate>Thu, 21 Dec 2006 09:52:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:565728</guid><dc:creator>Active Directory, Cluster and other fun stuff...</dc:creator><description>&lt;p&gt;Just a quick note to say that they did update KB 269229 with my comment about requiring the SERVICE account&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#600180</link><pubDate>Thu, 18 Jan 2007 00:41:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:600180</guid><dc:creator>JAlifrangis</dc:creator><description>&lt;p&gt;Yup, that fixed it,&lt;/p&gt;
&lt;p&gt;We have successfully recovered both our domain controllers using this fix.&lt;/p&gt;
&lt;p&gt;Appearantly someone on the development staff had changed the Impersonate Priviledge to work only for our service account, and not for the rest.&lt;/p&gt;
&lt;p&gt;Development for the lose!&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#600682</link><pubDate>Thu, 18 Jan 2007 02:11:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:600682</guid><dc:creator>justintu</dc:creator><description>&lt;p&gt;Nice to hear that it helped. &lt;/p&gt;
</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#728136</link><pubDate>Thu, 05 Apr 2007 13:13:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:728136</guid><dc:creator>Robert Dunn</dc:creator><description>&lt;p&gt;Thanks a million, your article has allowed us to get back up and running after a few hours of downtime. &amp;nbsp;Basically all we did was change the logon for the RPC, back to Local System. &amp;nbsp;So we now have network connectivity, Exchange and most importantly, Remote Desktop Connection, so we don't have to be lying on the floor at the local system in the server room :) &amp;nbsp;Now we can look at sorting the policy settings you mentioned, from the comfort of our own desks.&lt;/p&gt;
&lt;p&gt;Thanks again.&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#728319</link><pubDate>Thu, 05 Apr 2007 14:38:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:728319</guid><dc:creator>justintu</dc:creator><description>&lt;p&gt;Robert: &amp;nbsp;You're welcome. &amp;nbsp;I'm glad it helped.&lt;/p&gt;
</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#881209</link><pubDate>Fri, 04 May 2007 13:22:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:881209</guid><dc:creator>Tony Rogers</dc:creator><description>&lt;p&gt;Thankyou for an informative article. Your article saved me from having to do a server rebuild, as I had no idea what had gone wrong, until I came across this article on Google.&lt;/p&gt;
&lt;p&gt;This happened on SBS2003 in my case - and as I'm the only Administrator, I'm at a loss to understand how the users Administrator and SERVICE were ever removed from &amp;quot;Impersonate a client after authentication&amp;quot; as I don't remember doing it!!!&lt;/p&gt;
&lt;p&gt;Thanks again. :-)&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#881335</link><pubDate>Fri, 04 May 2007 14:10:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:881335</guid><dc:creator>justintu</dc:creator><description>&lt;P&gt;Thanks for the feedback Tony. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as how it happened: &amp;nbsp;Since you are the only Administrator, and don't remember doing, I would check for any rogue services or processes running.&lt;/P&gt;
&lt;P&gt;You may want to go to &lt;A href="http://safety.live.com/" target=_new rel=nofollow&gt;http://safety.live.com&lt;/A&gt; and do a virus scan. &amp;nbsp;Or maybe the settings got changed by importing one of the "High Security" templates that often get recommended by some of the security sites?&lt;/P&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1370272</link><pubDate>Tue, 26 Jun 2007 23:36:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1370272</guid><dc:creator>Teeka Leone</dc:creator><description>&lt;p&gt;Thank you for spelling out step by step how to fix my 'sick' Domain Controller. &amp;nbsp;I experienced EXACTLY what you outlined in this article and was able to fix it. &amp;nbsp;Thank you!!!!&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1692895</link><pubDate>Fri, 03 Aug 2007 17:13:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1692895</guid><dc:creator>Dan Capor</dc:creator><description>&lt;p&gt;Thank you Justin,&lt;/p&gt;
&lt;p&gt;This problem had plagued our network for a few months. I had only stumbled upon the temportary fix of setting each machine's RPC service to Local System Account, but it was just a bandaid on a gushing wound.&lt;/p&gt;
&lt;p&gt;Thank you, Thank you, Thank you.&lt;/p&gt;
&lt;p&gt;~Dan&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1715801</link><pubDate>Tue, 07 Aug 2007 08:56:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1715801</guid><dc:creator>JL</dc:creator><description>&lt;p&gt;Just wanted to let you know you saved our bacon with this article. THANKS!&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1861863</link><pubDate>Thu, 30 Aug 2007 19:19:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1861863</guid><dc:creator>Meir</dc:creator><description>&lt;p&gt;Justin you're the man, you saved my weekend (after foolishly applying a malformed security policy).&lt;/p&gt;
&lt;p&gt;Your article is really helpful and important.&lt;/p&gt;
&lt;p&gt;I think the title &amp;quot;Cluster service failure after AD lockdown&amp;quot; is a bit illusive, it doesn't reflect the real context of the problem. it can happen actually on any domain member (SQL server services also failed) &lt;/p&gt;
&lt;p&gt;Thanks again!&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#1967386</link><pubDate>Sun, 16 Sep 2007 15:42:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1967386</guid><dc:creator>Michele Maran</dc:creator><description>&lt;p&gt;Thanks for the greats tips. Problem solved for me during Active Directory upgrade from win2k to win2k3.&lt;/p&gt;
&lt;p&gt;I remeber that installation of Norton Antivirus Client Server Suite ask me to change impersonate key of domain group policy years old.&lt;/p&gt;
&lt;p&gt;Thanks a lot&lt;/p&gt;
&lt;p&gt;Michele Maran from Italy&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#2008324</link><pubDate>Fri, 21 Sep 2007 14:42:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2008324</guid><dc:creator>Mr Steve</dc:creator><description>&lt;p&gt;We had some issues with 2003 SP1 and the Time Service - after a reinstall of SP1 to fix the issue, we had the COM+ and RPC issue also. &amp;nbsp;In our case, the &amp;quot;Impersonate...&amp;quot; policy was never defined in the DCP. &amp;nbsp;Just performing the final restart now, and i'd just like to take the chance to backup Meir's comment that indeed - Justin - YOU ARE THE MAN!!! &amp;nbsp;:0)&lt;/p&gt;</description></item><item><title>RPC permissions on boot</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#2182941</link><pubDate>Tue, 16 Oct 2007 16:09:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2182941</guid><dc:creator>Rich Gautier</dc:creator><description>&lt;p&gt;You just saved me hours of work. &amp;nbsp;Thank you for your breakout of this problem. &amp;nbsp;It affected us during a security patch and reboot session this morning, even though it only affected some of our machines, the advice and underlying reasons were dead on.&lt;/p&gt;
&lt;p&gt;Thank you very much for sharing this info.&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#2657920</link><pubDate>Tue, 18 Dec 2007 23:25:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2657920</guid><dc:creator>Phil Petersen</dc:creator><description>&lt;p&gt;Thanks. Thanks. Thanks. I've been fighting this problem for days and days at one of customers sites (away from home). Thanks for getting me home for the HOLIDAYS.&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#2990458</link><pubDate>Wed, 12 Mar 2008 06:32:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2990458</guid><dc:creator>Steve Ferrarini</dc:creator><description>&lt;p&gt;Justin,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;Great information! &amp;nbsp;I almost passed by because of the title, but this was exactly what we needed.&lt;/p&gt;
&lt;p&gt;Thanks again for the investigative work, and making it available for us to find!&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#3031745</link><pubDate>Mon, 07 Apr 2008 18:23:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3031745</guid><dc:creator>g</dc:creator><description>&lt;p&gt;BRILLIANT! &amp;nbsp;Thanks for the leg work and making me look good to my director!&lt;/p&gt;</description></item><item><title>re: Cluster service failure after AD lockdown...</title><link>http://blogs.technet.com/justinturner/archive/2006/12/14/cluster-service-failure-after-ad-lockdown.aspx#3145829</link><pubDate>Sat, 01 Nov 2008 22:59:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3145829</guid><dc:creator>derekmoore333</dc:creator><description>&lt;p&gt;For one of the two machines the two machines, on which I had already tried to install a MS Cluster. I had to find this fix, in addition to the above to get RPC and Network connections back online. The second node RPC came online without these additional mods.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.eggheadcafe.com/software/aspnet/32648815/2003-server-r2--network.aspx"&gt;http://www.eggheadcafe.com/software/aspnet/32648815/2003-server-r2--network.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;1. ON DOMAIN CONTROLLER Group Policy for this SQL CLUSTER, Go to Computer Configuration - Windows Settings - Local Policies – User right Assignment- look for &amp;quot;Bypass traverse checking&amp;quot; Policy and add NETWORK SERVICE.&lt;/p&gt;
&lt;p&gt;2. ON LOCAL SQL SERVER, Open Windows Explorer and Go to \Windows\Registration folder - go to properties - Security tab -&lt;/p&gt;
&lt;p&gt;add the following accounts with permissions.&lt;/p&gt;
&lt;p&gt;a.Administrator - Full rights&lt;/p&gt;
&lt;p&gt;b.System - Full rights&lt;/p&gt;
&lt;p&gt;c.everyone - Read / Modify(WRITE) and List&lt;/p&gt;
&lt;p&gt;Then click &amp;quot;APPLY&amp;quot; and go to &amp;quot;General&amp;quot; tab and click on the &amp;quot;Advance&amp;quot;&lt;/p&gt;
&lt;p&gt;button. Here click the &amp;quot;Inheritance option&amp;quot; and finally click &amp;quot;OK&amp;quot;&lt;/p&gt;
&lt;p&gt;3. Open regedit&lt;/p&gt;
&lt;p&gt;a.go to &amp;quot;My Computer\HKEY_CLASSES_ROOT_\CLSID&amp;quot;. Right click on it and&lt;/p&gt;
&lt;p&gt;select &amp;quot;Permissions&amp;quot; and add &amp;quot;Authenticated Users&amp;quot; with &amp;quot;Full Permissions&amp;quot;&lt;/p&gt;
&lt;p&gt;b.Go to &amp;quot;My Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services&amp;quot;.&lt;/p&gt;
&lt;p&gt;Right click and select &amp;quot;Permissions&amp;quot; and add &amp;quot;Network Service&amp;quot; and &amp;quot;Local&lt;/p&gt;
&lt;p&gt;Service&amp;quot; with &amp;quot;Full Permissions&amp;quot;&lt;/p&gt;
&lt;p&gt;4.Finally go to &amp;quot;My&lt;/p&gt;
&lt;p&gt;Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs and set&lt;/p&gt;
&lt;p&gt;the &amp;quot;ObjectName&amp;quot; to &amp;quot;NT Authority\NetworkService&amp;quot;&lt;/p&gt;
&lt;p&gt;5.Reboot the promblematic server and check if the issue still exists.&lt;/p&gt;
</description></item></channel></rss>