Access DFS takes 40 sec

Arjan Langendijk 1 Reputation point
2022-09-28T15:00:41.09+00:00

The client domain is having a forest trust with the domain where DFS is located.

When we access a DFS root using \domain.local\shares it takes 1 min before we get a response.

When we access the referal directly it takes 1-2 sec.

When I run a wireshark capture I see the client asking for _ldap._tcp.dc._msdcs.ictz.cloud: type SRV, class IN and receives using a conditional forwarder the records of the remove Domain controllers.

It then tries all the domain controllers

245545-image.png

It never receives an answer as the query is wrong??:

Filter: (&(&(&(DnsDomain=domain.local)(Host=client))(NtVer=0x20000016))(DnsHostName=client.clientdomain.nl))

It takes 40sec before we get a response

Anyone that can shine some light on this?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,642 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Scott Dawson 156 Reputation points
    2022-09-28T21:03:48.67+00:00

    I had an issue like this until I fixed my AD sites and services. Is there any chance your clients are hitting remote DCs or DCs without the DFS services and replicas installed? It’s easy to test…place a client in its own site and make a site link to the DC you know works.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.