Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Changes to Security Are Not Immediately Applied

Status
Not open for further replies.

MaintenanceMadeEasy

Programmer
Jun 1, 2003
15
0
0
US
I am having many problems in Windows 2000 Advanced Server where changes to security settings is taking a very long time to be applied. I know that this delay is supposed to be normal for DNS related issues, but does that include the Active Directory as well?

Being that I am a small business, I have been setting up the Server to handle multiple functions that include DNS, Web, FTP and Exchange. The Server has plenty of power with dual Opteron Processors and a meg of memory. It is connected to the internet by DSL Line and all ports have been open to accommodate the related tasks (i.e. 80, 20, 21, 110, etc). The server is still in "development" and not yet seeing any loads from outside the office.

Everything is runs beautifully until I have to make some type of change to IIS or Active Directory. When I do, it takes anywhere from of few minutes to a few hours before I the changes actually occur. Here are 2 examples:

Example 1:

Changing or Adding a virtual FTP Site causes the IE to Hang and eventually display a message that the FTP File cannot be found when trying to access the site. The prompted User Logon window is never shown. Sometimes it will open the site, but fails to display any of the content.

Example 2:

I create a new user in Active Directory, along with a mailbox for exchange. If I try to access the mail box or connect to FTP, nothing happens, at least not immediately. Eventually, all of the settings will take effect and everything runs problem free.

Can anyone please tell me what am I missing here? How can I get these changes to immediately take effect after clicking the "Apply" button?

My thanks in advance.

Graham
 
i think this is an option, as i can not recall since it has been a while....hit the 'restart' button. it should be located at the top left of the sceen on a pull down menu.

 
Graham

You need to change the Group Policy refresh interval which is 90 minutes by default if you want to refresh it at another interval - but this will affect all the workstations too.

Interestingly, the two examples that you mentioned are anomalies!

Internet Explorer always tries to open an FTP site as anonymous. Try using:
Code:
ftp://username:password@newftp.yoursite.com
- in the address bar.
Remember that your username may well need to be in the form domain\username to work.

Also - before a refresh, Exchange will not actually create a mailbox unless one is required. Send the "new user" an eMail and a mailbox will appear in System Manager.

What you are doing is not unusual - Microsoft Small Business Server provides all the functionality you're discussing and more and it must run on one machine. see for details

hth

H


Hany Mustapha
Excellent Technology Solutions in the UK -
 
Hany,

Despite the awkwardness, I think that I have email working now. Many thanks for your help.

I am still however, having difficulty with the FTP Server failing to acknowledge a login. Entering the ID and Password in the browser path as you described didn't make any difference. It still failed to respond. Instead it displays an error message followed by an empty browser window 2 or 3 minutes later(which is locked up and has to be terminated from the Task Manager) .

The error message reads: Cannot find the file 'ftp://ftp.ABC.com/' (or one of its components). Make sure the path and filename are correct and that all required libraries are available.

I spent the weekend beating my head over the problem and discovered that the Service stops functioning if (1) the server is rebooted - OR - (2) The server is left running for several hours. I also checked the Services MMC. According to it, the FTP service is "Started", but yet it fails to acknowledge any logon requests. The only way I can get it to work is to open the IIS console and create a New (Dummy) FTP Site, which I immediately delete. Once I do this, everything continues to run beautifully until I either reboot the server or let it stand for several hours.

Does anyone have any ideas or suggestions for this?

Graham
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top