Permissions error in cluster

Francisco Alejandro Juan Ferrer 46 Reputation points
2021-03-05T21:06:00.553+00:00

Hi here, One companion was installed one month ago a HyperV cluster with 2 host. Seemed to be all ok, but today I just installed SCOM on physical servers, and this cluster shows an error. I checked on hyperv FailoverCluter console and It show this:

https://i.imgur.com/GRZouIv.png

Any idea? I checked if both host have access to AD ports, also I checked for permissions in AD, from both host and for cluster computer.. and I dont see anything. I compared to more clusters I have and I dont have idea what could be the problem.

Has Anyone seen this error before? Thanks!

System Center Virtual Machine Manager
Hyper-V
Hyper-V
A Windows technology providing a hypervisor-based virtualization solution enabling customers to consolidate workloads onto a single server.
2,536 questions
Windows Server Clustering
Windows Server Clustering
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Clustering: The grouping of multiple servers in a way that allows them to appear to be a single unit to client computers on a network. Clustering is a means of increasing network capacity, providing live backup in case one of the servers fails, and improving data security.
957 questions
{count} votes

5 answers

Sort by: Most helpful
  1. Sam Bruins 86 Reputation points
    2021-03-06T22:48:15.167+00:00

    Can you check the virtual cluster name in ad and see if the object “cluster_hv-pre” has hv-pre-02 in the security permission to update the object

    Also check the cluster dns name and make sure both nodes can update that.

    Did the account used to create the cluster have rights in the domain?

    1 person found this answer helpful.

  2. Xiaowei He 9,871 Reputation points
    2021-03-08T09:26:25.503+00:00

    Hi,

    1. Please check if the Cluster CNO exists in ADUC and is enabled. If yes, please try to add the CNO in the Computer OU, and give the full control permission to the CNO.

    75387-image.png

    1. Then, in the Cluster, please try to offline the CNO, and right click Repair CNO.

    75388-image.png

    Thanks for your time!
    Best Regards,
    Anne

    -----------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  3. Xiaowei He 9,871 Reputation points
    2021-03-11T09:11:53.307+00:00

    Hi,

    From your screenshot, I found the CNO isn't a computer account, it's a user account, CNO should be computer account like this:

    76600-image.png

    When you add the CNO in the cluster OU, please check "computer" here:

    76685-image.png

    Besides, please check if the cluster nodes can ping the DC.

    Thanks for your time!
    Best Regards,
    Anne


    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  4. Francisco Alejandro Juan Ferrer 46 Reputation points
    2021-03-11T16:05:00.283+00:00

    Dear friend, I just found this posst (yours too)

    https://learn.microsoft.com/en-us/answers/questions/120834/the-computer-object-associated-with-the-cluster-ne.html

    And port 464 was the f**ng problem. Mi fw has a rule to all AD ports but not 464.

    Very thanks my friend!

    1 person found this answer helpful.

  5. Francisco Alejandro Juan Ferrer 46 Reputation points
    2021-03-08T14:59:54.81+00:00

    Hi, thanks for your support. I just add permissions like u said me but when I bring Cluster Offline and I click "repair" this errores prompts: ![75486-2021-03-08-13-23-42-mremoteng-confconsxml-new-hype.png][1] The user who created cluster, its disabled on AD because he dont work with us anymore Like u can see on this pic, I give full access to cluter object in cluster OU. No idea what else I can try: ![75521-2021-03-08-14-11-00-mremoteng-confconsxml-dc1.png][2] Thanks again [1]: /api/attachments/75486-2021-03-08-13-23-42-mremoteng-confconsxml-new-hype.png?platform=QnA [2]: /api/attachments/75521-2021-03-08-14-11-00-mremoteng-confconsxml-dc1.png?platform=QnA