Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

[SDP 3][a203be4b-86ed-4705-a2df-e6aa82b0acf0] Cluster Network Diagnostic for Windows Server 2008 Enterprise


View products that this article applies to.

Summary

The Cluster Network Diagnostic collects data for troubleshooting Cluster Network issues in a Windows Server 2008 Enterprise environment. 

↑ Back to the top


More Information

The Cluster Network Diagnostic collects data either statically or interactively.

The Static Data Collection option collects static configuration information.

The Interactive Data Collection option allows the user to collect data while the issue is reproduced, and then also collects static configuration data.

The diagnostic generates a dialog box that prompts the user to start tracing. When the user clicks Next, the diagnostic enables NetFT ETL logging and network capturing by using NetMon 3.4. A stop tracing dialog box appears directly after logging starts. In the background, this diagnostic stops tracing by monitoring the event log for three event IDs. If any of the three are logged, data collection stops. The stop tracing dialog box remains present even if data collection stops. This lets the user stop tracing if necessary.

Information collected

Event logs - Failover Cluster
DescriptionFile name
Microsoft-Windows-FailoverClustering* (.csv .evtx .txt)
{ComputerName}_evt_FailoverClustering.*

Event logs - Networking
DescriptionFile name
Microsoft-Windows-NetworkProfile/Operational* (.csv .evtx .txt)
{ComputerName}_evt_NetworkProfile-Operational*

FailoverCluster feature
DescriptionFile name
Basic Failover Cluster information through the Clusmps.exe utility (on operating systems earlier than Windows Server 2008 R2)
{ComputerName}_cluster_mps_information.txt
Basic Failover Cluster information, including information from existing resources and groups through FailoverCluster PowerShell cmdlets (Windows Server 2008 R2 and later)
resultreport.xml

Cluster Dependency report generated by Get-ClusterResourceDependencyReport PowerShell cmdlet on Windows Server 2008 or later
{ComputerName}_DependencyReport.mht
Cluster Logs generated by Get-ClusterLog PowerShell cmdlet on Windows Server 2008 R2, Cluster.exe utility or from Windows\cluster\cluster.log on earlier versions of Windows
{ComputerName}_cluster.log
Cluster Resources information from Cluster.exe utility
{ComputerName}_ClusterResources.txt
Cluster resources properties by using PowerShell Get-ClusterResource cmdlet or Cluster.exe utility on earlier versions of Windows
{ComputerName}_ClusterProperties.txt
Information about Cluster Shared Volume
{ComputerName}_CSVInfo.HTM

File version information (Chksym)
DescriptionFile name
File version information from %ProgramFiles%\Microsoft iSNS Server\*.* and %windir%\system32\iscsi*.*
{ComputerName}_sym_MS_iscsi.*
File version information from %windir%\cluster\*.*
{ComputerName}_sym_ProgramFiles_sys.*
File version information from %windir%\cluster\*.*
{ComputerName}_sym_Cluster.*
File version information from %windir%\system32\*.dll
{ComputerName}_sym_System32_dll.*
File version information from %windir%\system32\*.exe
{ComputerName}_sym_System32_exe.*
File version information from %windir%\system32\*.sys
{ComputerName}_sym_System32_sys.*
File version information from %windir%\system32\drivers folder
{ComputerName}_sym_Drivers.*
File version information from %windir%\system32\Spool\*.*
{ComputerName}_sym_PrintSpooler.*
File version information from %windir%\syswow64 folder and subfolders
{ComputerName}_sym_SysWOW64_sys.*
File version information from %windir%\syswow64\drivers folder
{ComputerName}_sym_SysWOW64_sys.*
File version information from {Program Files (x86)}\*.sys folder and subfolders
{ComputerName}_sym_ProgramFilesx86_sys.*
File version information from {Program Files}\*.sys folder and subfolders
{ComputerName}_sym_ProgramFiles_sys.*
File version information from drivers currently running on the machine
{ComputerName}_sym_RunningDrivers.*
File version information from processes currently running on the machine
{ComputerName}_sym_Process.*

General information
DescriptionFile name
Basic system information, including machine name, service pack, computer model, processor name, and processor speed
resultreport.xml

List of installed updates and hotfixes installed
{ComputerName}_Hotfixes.*
Shows whether computer is running in a virtual environment and describes the virtualization environment
resultreport.xml

System information - MSInfo32 tool output
{ComputerName}_msinfo32.nfo
{ComputerName}_msinfo32.txt

Hyper-V role
DescriptionFile name
Hyper-V configuration and virtual machine information
{ComputerName}_HyperV-Info.HTM

IPsec
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec
HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT
HKLM\SYSTEM\CurrentControlSet\Services\IPsec
HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent
{ComputerName}_IPsec_reg_.TXT
IPsec information from command: netsh dynamic show all
{ComputerName}_IPsec_netsh_dynamic.TXT
IPsec information from command: netsh ipsec static exportpolicy
{ComputerName}_IPsec_netsh_LocalPolicyExport.ipsec
IPsec information from command: netsh static show all
{ComputerName}_IPsec_netsh_static.TXT
W8/WS2012 powershell output for the IPsec.
{ComputerName}_IPsec_info_pscmdlets.TXT

IPv6Check
DescriptionFile name
Networking adapt configuration from Windows Management Instrumentation (WMI)
{ComputerName}_Networking.TXT

IPv6To4Check
DescriptionFile name
IP configuration data from ipconfig command
{ComputerName}_Networking.TXT

Network capture
DescriptionFile name
Netsh Trace: CAB
{ComputerName}_nettrace.cab
Netsh Trace: Network Capture (ETL)
{ComputerName}_nettrace.etl
Network capture information from nmcap.exe output
{ComputerName}_netcap.cap

Registry keys
DescriptionFile name
HKLM\Cluster
{ComputerName}_reg_Cluster.hiv

Server manager and server roles information
DescriptionFile name
List of roles and features installed on Server media (Windows Server 2008 R2 and newer)
resultreport.xml


Servicing and related logs
DescriptionFile name
Output of dism.exe /online /cleanup-image /checkhealth
{ComputerName}_Dism-CheckHealth.txt


In addition to collecting the information that is described earlier, this diagnostic package can perform the following tasks:
  • Check for Symantec Endpoint Protection MR1/MR2
  • Check for evaluation media
  • Check whether Page Heap is enabled to one or more processes
  • Check whether driver verifier has been enabled for at least one driver
  • Check for ephemeral port usage
  • Check for ephemeral port usage
  • Detect Advanced Format drives
  • Detect native 4K drives on the system
  • Check whether KB982018 is installed, or if the files are outdated
  • Check whether EMC Replistor software is on the computer but KB975759 is not installed
  • Check for unsupported versions of Windows Vista and Windows Server 2008
  • Check whether DEP and PAE are enabled on a 32-bit system
  • Check whether Ultimaco Safeware disk encryption is installed and is the latest version
  • Check whether Telnet service is running under System account
  • Check for known issue with BIOS version of PowerEdge R910, R810, and M910
  • Check the value of SystemPages in Memory Management registry key
  • Detect whether this computer is a virtual machine running in Microsoft Azure
  • Detect Windows XP End-of-Support
  • Check whether cluster groups are in Offline or Failed state
  • Check for errors while gathering cluster information through the Get-ClusterNode cmdlet
  • Check whether the state of one or more cluster nodes is down or paused
  • Check whether Cluster service is not running or is offline
  • Check whether the Cluster Name Object (CNO) exists and is enabled in Active Directory Domain Services (AD DS)
  • Check whether Cluster Shared Volumes is configured to redirected access
  • Check whether Cluster Shared Volumes is configured for local access
  • Check whether Cluster Shared Volumes is configured to maintenance mode
  • Check whether Cluster Shared Volumes is configured to network access
  • Check for third-party virtualization solution from Xsigo
  • Check for LmCompatibilityLevel setting
  • Check firewall rules on cluster nodes with IPv6 enabled
  • Detect whether there are no orphan resources
  • Check whether FailoverCluster Crypto resource exists
  • Check for FailoverCluster missing dependent resources
  • Detect whether Cluster nodes have the correct CAU WMI namespace registered
  • Detect whether Cluster nodes have the correct MSCluster WMI namespace registered
  • Check for the presence of HKLM\Components registry keys that indicate a recent component installation
  • Check for the presence of Pending.XML in WinSxS folder
  • Check whether SYSTEM permissions in usbhub.sys
  • Run DISM to check servicing corruption
  • Check for event ID 5 from Windows Backup (KB 2182466)
  • Check for Veritas disk VXIO device states
  • Check the number of entries in FilesNotToBackup registry key
  • Check for Bitlocker Drive Encryption Fixed Data Drive Read-Only Policy
  • Detect the presence of vLite software though registry key
  • Check state of 'Application Compatibility Engine' policy
  • Check DNS Zones for top level CNAME records
  • Windows Firewall start mode check
  • Windows Firewall Running check
  • IPv6 check
  • IPv6 6To4 interface check
  • Check whether more than 32 GB of physical memory and operating system is Windows 2008 R2 Standard Edition
  • Check whether PMTU has been disabled on computer
  • Check for unexpected TcpIp registry settings (KB967224)
  • Check for excessive number of 6to4 adapters; this may decrease startup and logon performance
  • Check whether Tunnel.sys driver is missing a Windows Server 2008 R2 Server Core installation option
  • Check for problem related to Microsoft DHCP Relay Agent; this may cause slow startup (KB2459530)
  • Check HTTP Redirection on TSGateway
  • Check whether the SMB2 Client driver has been disabled
  • Check whether the SMB2 Server driver has been disabled
  • Check whether Opportunistic Locking has been disabled
  • Check whether InfoCacheLevel setting is configured to enable caching for all files and folders
  • Check whether McAfee HIPS 7.0 is installed
  • Event logs messages
  • Check whether there are any virtual machine with High CPU utilization
  • Check whether dynamic memory is enabled to one or more virtual machines
  • Check whether dynamic memory is enabled on one or more virtual machines with old Integration Services
  • Check for version mismatches of Integration Services
  • Check whether one or more virtual machines have virtual hard drives located on an disk with Advanced Format Drives (512e disks)
  • Check whether a %Component% Event trace log file was collected

References

For more information about the Microsoft Automated Troubleshooting Services and about the Support Diagnostics Platform, see the following Microsoft Knowledge Base article:

2598970 Information about Microsoft Automated Troubleshooting Services and Support Diagnostic Platform

↑ Back to the top


Keywords: kb

↑ Back to the top

Article Info
Article ID : 2861043
Revision : 1
Created on : 1/7/2017
Published on : 6/20/2014
Exists online : False
Views : 177