we have users who access network file shares the usual way over DFS and have tried directly to rule out the issue being DFS.
see attached they sometimes see "connecting to Ad.mydomain.net and the file server path
All users are on windows 10 22H2 - Office semi annual O365 (deployed through intune azureAD joined but no longer on the domain). So checkpoint endpoint vpn version 86.80 now is always running for every user otherwise can't access anything obviously.
We've expanded the timeout over 12 hours for the checkpoint this has also possibly caused a side effect where some users have DNS problems and have to do clear browser cache and flushDNS cmdline in order to access citrix workspace apps but that's a separate issue (stale vpn session as they don't reboot their desktops until the weekend for patching),
And I don't know if it's linked to that as we moved to intune built devices the last 6 months or so from domain joined to reduce teh attack vectors primary the reason for the desktops and laptops being on a workgroup and when users try to save files and its intermittent, they get slowness and some errors sometimes if its a complex linked macros The issue is now escalated and I am not sure if it's a netapp issue or because we're reliant on checkpoint running all the time to access our domain based services, we're currently migrating file shares to sharepoint online so you would think the load on the netapp servers has reduced substantially and the migration continues still continuing.
users workaround has been to get someone else to save the file after running the macro potentially in office or outside working from home or in another region.
Now I was wondering on what to do to trouleshoot we've tried disabling the webclient.exe locally didn't help. any ideas as the problem is potentially impacting other sites abroad too not just the UK, - some actions I was going to suggest to a manager who's looking into this now after it's been escalated - I am not in the infrastructure team just local support but would like to know if anyone has seen this
I believe they get a mydomain.ad.net loading bar too where it hangs there for a while too, which is an indication of slowness?
Would it be worth trying some of these Actions?
Change the office updates method for a test device
Rejoin a device to the domain
Run Network monitor and Process monitor
Consider disabling Antivirus/remove as a test
Use FW monitor
create a network TCP dump
any other actions you guys can recommend