#Requires -Version 5.1 <# JbTecWiz Support Centre -- generated fix script Fault : Failover Cluster event 1135 -- a node was removed from the active failover cluster membership Fix : Rule out the network and the NIC settings Source: https://jbtecwiz.com/support/srv-cluster-1135 Run as : Elevated PowerShell on each node Expect : 1 hour Risk : low Reversible : yes WHEN THIS IS THE RIGHT FIX No obvious time pattern. HOW TO UNDO IT Return SameSubnetDelay to 1000 and SameSubnetThreshold to 5 (the defaults for recent versions) if you changed them. This script walks the fix one step at a time and asks before each one. Steps with no command are things you do yourself -- it prints those and waits. Run with -DryRun to print without executing. -------------------------------------------------------------------- NO WARRANTY - USE AT YOUR OWN RISK This script is provided by JbTecWiz as-is and with no warranty of any kind, express or implied. You run it entirely at your own risk. JbTecWiz accepts no liability for any loss or damage arising from its use, including but not limited to data loss, downtime, or configuration changes that turn out to be wrong for your system. You are responsible for reading this script before running it, for satisfying yourself that it suits the machine in front of you, and for having a working backup first. Some steps cannot be undone. -------------------------------------------------------------------- #> [CmdletBinding()] param( # Print every step and command without running anything. [switch]$DryRun, # Do not ask before each step. Read the script first if you use this. [switch]$Unattended ) $ErrorActionPreference = 'Stop' $script:Failed = 0 function Write-Rule { param([string]$Text) Write-Host '' Write-Host ('-' * 70) -ForegroundColor DarkGray if ($Text) { Write-Host $Text -ForegroundColor Cyan } } function Show-Prose { param([string]$Text, [string]$Colour = "Gray") if (-not $Text) { return } $words = $Text -split "\s+"; $line = " " foreach ($w in $words) { if (($line.Length + $w.Length) -gt 74) { Write-Host $line -ForegroundColor $Colour; $line = " " } $line += "$w " } if ($line.Trim()) { Write-Host $line -ForegroundColor $Colour } } function Invoke-Step { param( [int]$Number, [string]$Do, [string]$Why, [scriptblock]$Command, [switch]$Manual, [string]$Shell = "powershell" ) Write-Rule " Step $Number of 6" Show-Prose $Do "White" if ($Why) { Write-Host ""; Show-Prose $Why "DarkGray" } if ($Manual) { Write-Host '' Write-Host ' -> Do this yourself, then press Enter to carry on.' -ForegroundColor Yellow if (-not $Unattended -and -not $DryRun) { [void](Read-Host) } return } Write-Host '' foreach ($l in ($Command.ToString().Trim() -split "`n")) { Write-Host (" " + $l.Trim()) -ForegroundColor Green } Write-Host '' if ($DryRun) { Write-Host " (dry run -- not executed)" -ForegroundColor DarkGray; return } if (-not $Unattended) { $a = Read-Host " Run this step? [Y]es / [S]kip / [Q]uit" if ($a -match "^[Qq]") { Write-Host " Stopped at your request."; exit 0 } if ($a -match "^[Ss]") { Write-Host " Skipped." -ForegroundColor DarkGray; return } } try { & $Command } catch { $script:Failed++ Write-Host (" Step $Number failed: " + $_.Exception.Message) -ForegroundColor Red Show-Prose "The rest of the fix may depend on this. Read the write-up before carrying on." "Red" if (-not $Unattended) { $c = Read-Host " Carry on anyway? [y/N]" if ($c -notmatch "^[Yy]") { exit 1 } } } } Write-Rule Write-Host ' Failover Cluster event 1135 -- a node was removed from the active failover cluster membership' -ForegroundColor White Write-Host ' Rule out the network and the NIC settings' -ForegroundColor Cyan Write-Host '' Write-Host ' Risk: low Reversible 1 hour' Write-Host '' Show-Prose 'No warranty. Use at your own risk - JbTecWiz accepts no liability. Read it before you run it, and have a backup.' 'DarkYellow' Write-Rule if (-not $Unattended -and -not $DryRun) { $go = Read-Host ' Ready? [y/N]' if ($go -notmatch "^[Yy]") { Write-Host " Nothing was changed."; exit 0 } } Invoke-Step -Number 1 -Do 'Collect the cluster log around the eviction -- it records the heartbeat misses in detail.' -Command { Get-ClusterLog -TimeSpan 15 -Destination C:\temp } Invoke-Step -Number 2 -Do 'Turn off power management on every cluster NIC.' -Why 'A NIC allowed to sleep will drop heartbeats on an otherwise idle network, which produces exactly this event at unpredictable times.' -Command { Get-NetAdapter | Get-NetAdapterPowerManagement | Where-Object AllowComputerToTurnOffDevice -eq 'Enabled' } Invoke-Step -Number 3 -Do 'Disable it where enabled.' -Command { Set-NetAdapterPowerManagement -Name 'Cluster' -AllowComputerToTurnOffDevice Disabled } Invoke-Step -Number 4 -Do 'Exclude cluster traffic and the cluster directories from antivirus on-access scanning.' -Manual Invoke-Step -Number 5 -Do 'Check the cluster network configuration is sane -- at least one network dedicated to cluster communication.' -Command { Get-ClusterNetwork | Format-Table Name, Role, Address, State -AutoSize } Invoke-Step -Number 6 -Do 'Only if the physical network is known-good and cannot be improved, relax the heartbeat thresholds.' -Why 'This is a last resort. It makes the cluster slower to detect a genuine node failure -- it hides the symptom rather than fixing the cause.' -Command { (Get-Cluster).SameSubnetDelay = 1000 (Get-Cluster).SameSubnetThreshold = 10 } Write-Rule " Confirm it worked" Show-Prose 'No further 1135 events over a full week.' 'White' Write-Host '' if (-not $DryRun) { Get-WinEvent -FilterHashtable @{LogName='System'; Id=1135} -MaxEvents 20 | Format-Table TimeCreated, Message -AutoSize } Write-Rule if ($script:Failed -gt 0) { Write-Host (" Finished with " + $script:Failed + " failed step(s).") -ForegroundColor Yellow Show-Prose 'Read the full write-up at https://jbtecwiz.com/support/srv-cluster-1135' 'Yellow' } else { Write-Host ' Finished.' -ForegroundColor Green } Write-Host '' Show-Prose 'To undo: Return SameSubnetDelay to 1000 and SameSubnetThreshold to 5 (the defaults for recent versions) if you changed them.' 'DarkGray' Write-Rule