Hello, I do not use an external DHCP Server, only the local IP address pool on our Juniper SA4500. Does it however make sense to do a tcpdump? Which filter is necessary (sorry, I do not have much experience in reading tcpdumps). What I have found is something in NC debug log: 00199,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:834 - '***' ************************************************************************************** 00158,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:835 - '***' Network Connect Service (dsNcService.exe) 00114,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:836 - '***' 00170,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:837 - '***' Thu Aug/19/2010 15:46:19 Mitteleuropische Sommerzeit 00148,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:838 - '***' Build Version: 6, 5, 0, 15551 00148,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:839 - '***' Product Version: 6, 5, 0, 15551 00145,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:840 - '***' Operating System: Windows 7 00131,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:841 - '***' Service Pack: 00158,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:842 - '***' Internet Explorer Version: 8.0.7600.16385 00134,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:843 - '***' User Name: SYSTEM 00128,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:859 - '***' mfc42.dll: 00166,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:865 - '***' msvcrt.dll: 7.0.7600.16385 (win7_rtm.090713-1255) 00130,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:871 - '***' wininet.dll: 00129,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:877 - '***' ws2_32.dll: 00199,09 2010/08/19 15:46:19.098 0 SYSTEM dsNcService.exe dsNcService p5228 t1468 dsWinLogserviceApiLib.cpp:880 - '***' ************************************************************************************** 00130,09 2010/08/19 15:46:19.098 3 SYSTEM dsNcService.exe dsNcService p5228 t1468 Service.cpp:199 - 'service' starting service dispatcher ... 00118,09 2010/08/19 15:46:19.114 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:927 - 'NCSys' Restore DNS Suffix 00134,09 2010/08/19 15:46:19.114 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1010 - 'NCSys' No backup DNS suffix found: rc:2. 00126,09 2010/08/19 15:46:19.114 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:2263 - 'NCSys' Changing strong host mode 00135,09 2010/08/19 15:46:19.114 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:2284 - 'NCSys' No backup strong mode:Backup1 e:2. 00141,09 2010/08/19 15:46:19.114 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 ncipc.cpp:72 - 'IpcConn' listening for IPC connections on port 4242 00143,09 2010/08/19 15:46:19.114 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsProtectedMode.cpp:105 - 'GetProcessIntegrityLevel' Returning with 3 00188,09 2010/08/19 15:46:19.114 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 SharedMemory.cpp:56 - 'CDsSharedMemory::CreateFileMapping' szName:Juniper:NcIpc:SharedMemory, Status:0, Creator:1. 00136,09 2010/08/19 15:46:54.333 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 ncipc.cpp:287 - 'IpcConn' client opening connection to service 00123,09 2010/08/19 15:46:54.333 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 session.cpp:1600 - 'session' disconnectAll called 00122,09 2010/08/19 15:46:54.333 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 tunnel.cpp:45 - 'ipsec' New tunnel being created .... 00158,09 2010/08/19 15:46:55.580 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:2118 - 'NCSys' Found RR NIC {9D699A21-F726-481A-8F0A-1EFDC80721BC}, i=17 00123,09 2010/08/19 15:46:55.580 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:2166 - 'NCSys' No need to adjust DNS. .... 00127,09 2010/08/19 15:47:01.487 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 tunnel.cpp:185 - 'ipsec' send kmp message 303 size 16 00124,09 2010/08/19 15:47:01.487 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 session.cpp:1201 - 'session' adapter is configured 00146,09 2010/08/19 15:47:01.503 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:2253 - 'rmon' interface 0x0000000B has address 192.168.1.10 00147,09 2010/08/19 15:47:01.503 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:2253 - 'rmon' interface 0x00000016 has address 10.209.252.26 00143,09 2010/08/19 15:47:01.503 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:2253 - 'rmon' interface 0x00000001 has address 127.0.0.1 00151,09 2010/08/19 15:47:01.503 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcVsta.cpp:266 - 'NcVista' GetInterfaceEntry: index:22 0:, auto:0,metric:1. 00146,09 2010/08/19 15:47:01.503 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcVsta.cpp:272 - 'NcVista' GetInterfaceEntry: index:22, nochange made. 00123,09 2010/08/19 15:47:01.503 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 session.cpp:1236 - 'session' Deny route count = 0 00123,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:1883 - 'rmon' If idx: 22, Metric: 1. 00119,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:636 - 'rmon' vista set metric 1. 00130,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:654 - 'rmon' vista add route metric 1 < 10. 00180,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:732 - 'rmon' Vista deleting the conflicting route to 0.0.0.0/0.0.0.0 gw 192.168.1.1 metric 20 00192,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:732 - 'rmon' Vista deleting the conflicting route to 192.168.1.0/255.255.255.0 gw 192.168.1.10 metric 276 00195,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:732 - 'rmon' Vista deleting the conflicting route to 192.168.1.10/255.255.255.255 gw 192.168.1.10 metric 276 00186,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:732 - 'rmon' Vista deleting the conflicting route to 224.0.0.0/240.0.0.0 gw 192.168.1.10 metric 276 00173,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:760 - 'rmon' adding route to 0.0.0.0/0.0.0.0 with gw 10.209.252.26, metric 1, if_id 22 00148,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 session.cpp:1286 - 'session' added route to dest = 0.0.0.0, mask = 0.0.0.0 00118,09 2010/08/19 15:47:01.519 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 session.cpp:1292 - 'session' route count = 1 00146,09 2010/08/19 15:47:01.534 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:2253 - 'rmon' interface 0x0000000B has address 192.168.1.10 00147,09 2010/08/19 15:47:01.534 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:2253 - 'rmon' interface 0x00000016 has address 10.209.252.26 00143,09 2010/08/19 15:47:01.534 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:2253 - 'rmon' interface 0x00000001 has address 127.0.0.1 00151,09 2010/08/19 15:47:01.534 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 0ms when stoping dns, status 3, old:1, cur:1. 00153,09 2010/08/19 15:47:01.799 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 250ms when stoping dns, status 3, old:2, cur:2. 00153,09 2010/08/19 15:47:02.064 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 500ms when stoping dns, status 3, old:2, cur:2. 00153,09 2010/08/19 15:47:02.329 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 750ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:02.594 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 1000ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:02.859 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 1250ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:03.124 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 1500ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:03.389 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 1750ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:03.654 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 2000ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:03.919 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 2250ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:04.184 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 2500ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:04.449 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 2750ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:04.714 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 3000ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:04.979 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 3250ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:05.244 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 3500ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:05.509 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 3750ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:05.774 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 4000ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:06.039 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 4250ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:06.304 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 4500ms when stoping dns, status 3, old:2, cur:2. 00154,09 2010/08/19 15:47:06.569 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 4750ms when stoping dns, status 3, old:2, cur:2. ... 00155,09 2010/08/19 15:47:13.987 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 11750ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:14.252 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 12000ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:14.517 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 12250ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:14.782 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 12500ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:15.047 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 12750ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:15.312 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 13000ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:15.577 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 13250ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:15.842 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 13500ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:16.107 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 13750ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:16.372 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 14000ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:16.637 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 14250ms when stoping dns, status 3, old:2, cur:2. 00155,09 2010/08/19 15:47:16.902 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1087 - 'NCSys' Wait 14500ms when stoping dns, status 3, old:2, cur:2. 00148,09 2010/08/19 15:47:17.167 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1108 - 'NCSys' Dns not stop in 14750ms, status 4, old2, cur:0. 00123,09 2010/08/19 15:47:17.370 1 SYSTEM dsNcService.exe dsNcService p5228 tDA8 dsNcSys.cpp:1121 - 'NCSys' Can't start dns: 420.. 00115,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:258 - 'rmon' system routes: ... 00118,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:260 - 'rmon' monitored routes: 00172,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:2032 - 'rmon' a.b.c.d/255.255.255.255 gw 192.168.1.1 via 0x0000000B metric 21 00157,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:2032 - 'rmon' 0.0.0.0/0.0.0.0 gw 10.209.252.26 via 0x00000016 metric 1 00117,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:262 - 'rmon' Excluded Routes: 00129,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 routemon.cpp:285 - 'rmon' starting the route monitor... 00119,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 session.cpp:468 - 'session' Tunnel setup done 00129,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 udp.cpp:33 - 'ipsec' Creating UDP socket 192.168.1.10:0 00182,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 engine.cpp:458 - 'ipsec' new ESP tunnel in:0x1E69FD5D, out:0x99E09FDB 192.168.1.10:0 -> a.b.c.d:4500 00127,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 tunnel.cpp:185 - 'ipsec' send kmp message 301 size 86 00133,09 2010/08/19 15:47:17.370 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 engine.cpp:87 - 'ipsec' IpsecEngine::setTunAdapter 00000000 00176,09 2010/08/19 15:47:17.385 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 session.cpp:805 - 'session' stored parameter section:DOUBLELOGON, name:PROGRESS, type:0, data:00b632fb 00176,09 2010/08/19 15:47:17.385 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 session.cpp:805 - 'session' stored parameter section:DOUBLELOGON, name:PROGRESS, type:0, data:00b632fb 00133,09 2010/08/19 15:47:17.448 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 engine.cpp:87 - 'ipsec' IpsecEngine::setTunAdapter 00B637B0 00127,09 2010/08/19 15:47:17.448 3 SYSTEM dsNcService.exe dsNcService p5228 tDA8 tunnel.cpp:185 - 'ipsec' send kmp message 303 size 13 ... There is a very long delay between 00136,09 2010/08/19 15:46:54.333 and 00136,09 2010/08/19 15:46:54.333 I don't really know what is happening here. Is the host checker policy applied at this moment?? Also very strange are the log entrys after 00151,09 2010/08/19 15:47:01.534 which take over 14 seconds ("stoping dns"). Whatever is happening here... I have attached the full debug log.
... View more