The tools were pretty old. From the 3.5 installs we had here. Upgrade was from that to 4.1.
From the logs, it appears that the cluster resources never fully got moved from node01 to node 02 or at least node 01 thought it was still the owner when it came back up. The last event log show a duplicate IP on the network. I know there's quite a few, but I posted the logs below in sequence if you'd like to see them.
We are using a heartbeat network.
-----------------------------------------------------------------------
Event ID: 1129 Source: FailoverClustering Node: ClusterNode02
Cluster network 'Cluster Network 1' is partitioned. Some attached failover cluster nodes cannot communicate with each other over the network. The failover cluster was not able to determine the location of the failure. Run the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapter. Also check for failures in any other network components to which the node is connected such as hubs, switches, or bridges.
-----------------------------------------------------------------------
Event ID: 1126 Source: FailoverClustering Node: ClusterNode02
Cluster network interface 'ClusterNode 02 - Local Area Connection' for cluster node 'ClusterNode 02' on network 'Cluster Network 1' is unreachable by at least one other cluster node attached to the network. The failover cluster was not able to determine the location of the failure. Run the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapter. Also check for failures in any other network components to which the node is connected such as hubs, switches, or bridges.
-----------------------------------------------------------------------
Event ID: 1135 Source: FailoverClustering Node: ClusterNode02
Cluster node 'ClusterNode 01' was removed from the active failover cluster membership. The Cluster service on this node may have stopped. This could also be due to the node having lost communication with other active nodes in the failover cluster. Run the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapters on this node. Also check for failures in any other network components to which the node is connected such as hubs, switches, or bridges.
-----------------------------------------------------------------------
Event ID: 1177 Source: FailoverClustering Node: ClusterNode02
The Cluster service is shutting down because quorum was lost. This could be due to the loss of network connectivity between some or all nodes in the cluster, or a failover of the witness disk.
Run the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapter. Also check for failures in any other network components to which the node is connected such as hubs, switches, or bridges.
-----------------------------------------------------------------------
Event ID: 1564 Source: FailoverClustering Node: ClusterNode02
File share witness resource 'File Share Witness (\\shareSvr\share$)' failed to arbitrate for the file share '\\shareSvr\share$'. Please ensure that file share '\\shareSvr\share$' exists and is accessible by the cluster.
-----------------------------------------------------------------------
Event ID: 1561 Source: FailoverClustering Node: ClusterNode02
The cluster service has determined that this node does not have the latest copy of cluster configuration data. Therefore, the cluster service has prevented itself from starting on this node.
Try starting the cluster service on all nodes in the cluster. If the cluster service can be started on other nodes with the latest copy of the cluster configuration data, this node will be able to subsequently join the started cluster successfully.
If there are no nodes available with the latest copy of the cluster configuration data, please consult the documentation for 'Force Cluster Start' in the failover cluster management snapin, or the 'forcequorum' startup option. Note that this action of forcing quorum should be considered a last resort, since some cluster configuration changes may well be lost.
-----------------------------------------------------------------------
Event ID: 1126 Source: FailoverClustering Node: ClusterNode01
Cluster network interface 'ClusterNode02 - Local Area Connection' for cluster node 'ClusterNode02' on network 'Cluster Network 1' is unreachable by at least one other cluster node attached to the network. The failover cluster was not able to determine the location of the failure. Run the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapter. Also check for failures in any other network components to which the node is connected such as hubs, switches, or bridges.
-----------------------------------------------------------------------
Event ID: 1126 Source: FailoverClustering Node: ClusterNode01
Cluster network 'Cluster Network 1' is partitioned. Some attached failover cluster nodes cannot communicate with each other over the network. The failover cluster was not able to determine the location of the failure. Run the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapter. Also check for failures in any other network components to which the node is connected such as hubs, switches, or bridges.
-----------------------------------------------------------------------
Event ID: 1135 Source: FailoverClustering Node: ClusterNode01
Cluster node 'ClusterNode02' was removed from the active failover cluster membership. The Cluster service on this node may have stopped. This could also be due to the node having lost communication with other active nodes in the failover cluster. Run the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapters on this node. Also check for failures in any other network components to which the node is connected such as hubs, switches, or bridges.
-----------------------------------------------------------------------
Event ID: 1069 Source: FailoverClustering Node: ClusterNode01
Cluster resource 'File Share Witness (\\shareSvr\share$)' in clustered service or application 'Cluster Group' failed.
-----------------------------------------------------------------------
Event ID: 1564 Source: FailoverClustering Node: ClusterNode01
File share witness resource 'File Share Witness (\\shareSvr\share$)' failed to arbitrate for the file share '\\SshareSvr\share$$'. Please ensure that file share '\\shareSvr\share$' exists and is accessible by the cluster.
-----------------------------------------------------------------------
Event ID: 1069 Source: FailoverClustering Node: ClusterNode01
Cluster resource 'Cluster IP Address' in clustered service or application 'Cluster Group' failed.
-----------------------------------------------------------------------
Event ID: 1205 Source: FailoverClustering Node: ClusterNode01
The Cluster service failed to bring clustered service or application 'Cluster Group' completely online or offline. One or more resources may be in a failed state. This may impact the availability of the clustered service or application.
-----------------------------------------------------------------------
Event ID: 1069 Source: FailoverClustering Node: ClusterNode01
Cluster resource 'IPv4 Static Address 1 (ClusterResource01)' in clustered service or application 'ClusterResource01' failed.
-----------------------------------------------------------------------
Event ID: 1205 Source: FailoverClustering Node: ClusterNode01
Cluster IP address resource 'BAN FrontEnd' cannot be brought online because a duplicate IP address '192.168.8.27' was detected on the network. Please ensure all IP addresses are unique.
-----------------------------------------------------------------------
Event ID: 1205 Source: FailoverClustering Node: ClusterNode01
The Cluster service failed to bring clustered service or application 'ClusterResource01' completely online or offline. One or more resources may be in a failed state. This may impact the availability of the clustered service or application.