|
Darren
- Thanks very much for your suggestion. It didn't solve the issue, but it did
provide some keywords that helped in further Google
searches.
Part
of the cause ended up being discarding of large ICMP packets by our Cisco VPN
Concentrator. In preparation for processing Group Policy, workstations send a
series of ping packets to a domain controller that have payloads of both 0
and 2048 bytes. The 0 byte packets got through fine, but the 2048 byte packets
got dropped because they are larger than the MTU and are thus fragmented. These
pings are used to determine if you have a slow link or fast link. Enabling
fragmented packets to pass the VPN Concentrator did the trick, and now Site GPs
are being applied along with other GPs.
I
still have no clue why the GP processing ended up pulling the logon script from
a different site. My suspicion is that the slow link processing code doesn't
know how to cleanly deal with failed responses from only some of the ping
packets. Whoever coded this section may have assumed that either all would
succeed and return a response time value or none would succeed. This is only
speculation because the Userenv.log file didn't reflect any processing of
group policy even though it clearly had occurred.
When I
have a few minutes I plan on submitting a detailed write-up to MyITForum so that
others will hopefully benefit from our research. Even knowing most of the
answers I couldn't find anything covering this situation in the KB articles.
Thanks again!
Jeff
Confidential
This e-mail and any files transmitted with it are the property of Belkin Corporation and/or its affiliates, are confidential, and are intended solely for the use of the individual or entity to whom this e-mail is addressed. If you are not one of the named recipients or otherwise have reason to believe that you have received this e-mail in error, please notify the sender and delete this message immediately from your computer. Any other use, retention, dissemination, forwarding, printing or copying of this e-mail is strictly prohibited. |
Title: [ActiveDir] Group Policy at the Site Level With Remote VPN Users - Wrong Site Applied
- Re: [ActiveDir] Group Policy at the Site Level With Remote ... Jeff Salisbury
- Re: [ActiveDir] Group Policy at the Site Level With Re... Steve Patrick
- RE: [ActiveDir] Group Policy at the Site Level With Re... Jeff Salisbury
