Question

Windows 2000 DC DNS needs help

Asked by: haident

I am expereincing lots of connectivity issues in a small Win 2000 domain with Win XP Pro workstations.

The server has been in place for a long time and I do not have access to the individual who set it up, but it appears that the DNS server is the problem. The ISP is Birch and for some crazy reason the DC machine is named viper.birch.net, but the domain is named hance. DHCP is coming from the Birch DSL router, which I do not yet have a password for so that I could turn this off and use the DC server provide DHCP. In the meantime I have given the workstations static IP addresses and given them the DC server's IP for their DNS server.

When I look at the the DNS on the server there is one foward lookup zone, but it doesn't seem to have the records that should be there (services like kerberos, kpassword, ldap, etc. are missing) Accordingly, I don't think there is any way the workstations can access the Active Directory, and this is what is causing the connectivity problems.

I don't know if this is something that can be fixed at all due to the wierd naming of the machine, or if the DNS zone can be reconfigured to work. If it can be fixed does this mean manually adding the missing records, or is there something that will do this for me?

See dcdiag.exe /v below:

Domain Controller Diagnosis

Performing initial setup:
   * Verifying that the local machine viper, is a DC.
   * Connecting to directory service on server viper.
   * Collecting site info.
   * Identifying all servers.
   * Found 1 DC(s). Testing 1 of them.
   Done gathering initial info.

Doing initial required tests
   
   Testing server: Default-First-Site-Name\VIPER
      Starting test: Connectivity
         * Active Directory LDAP Services Check
         VIPER's server GUID DNS name could not be resolved to an
         IP address.  Check the DNS server, DHCP, server name, etc
         Although the Guid DNS name

         (2aad8f3a-7a0f-4c36-83d6-777487074608._msdcs.hance) couldn't be

         resolved, the server name (viper.birch.net) resolved to the IP address

         (192.168.1.3) and was pingable.  Check that the IP address is

         registered correctly with the DNS server.
         ......................... VIPER failed test Connectivity

Doing primary tests
   
   Testing server: Default-First-Site-Name\VIPER
      Skipping all tests, because server VIPER is
      not responding to directory service requests
      Test omitted by user request: Topology
      Test omitted by user request: CutoffServers
      Test omitted by user request: OutboundSecureChannels
   
   Running enterprise tests on : hance
      Starting test: Intersite
         Skipping site Default-First-Site-Name, this site is outside the scope

         provided by the command line arguments provided.
         ......................... hance passed test Intersite
      Starting test: FsmoCheck
         GC Name: \\viper.birch.net
         Locator Flags: 0xe00001fd
         PDC Name: \\viper.birch.net
         Locator Flags: 0xe00001fd
         Time Server Name: \\viper.birch.net
         Locator Flags: 0xe00001fd
         Preferred Time Server Name: \\viper.birch.net
         Locator Flags: 0xe00001fd
         KDC Name: \\viper.birch.net
         Locator Flags: 0xe00001fd
         ......................... hance passed test FsmoCheck

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2006-06-02 at 09:31:21ID21872707
Tags

0xe00001fd

,

domain

,

fixing

Topic

Windows 2000 Operating System

Participating Experts
4
Points
500
Comments
13

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. DC replication across DSL lines.
    Ok, simple question. I have a 2k GC/DC in my main office. I want it to synch up with another DC in another city. Both offices use DSL to connect to the Internet. How do I do this? I've looked through sites and services, but I don't see any place to specify an IP that i...
  2. Win2003 AD - DNS/Kerberos/LDAP problems on DC i…
    I have a Win2003 DC in a child domain that is having AD problems. It manifested itself when I examined the default domain GPO. What I discovered is this: 1. When I run netdiag, it fails the following tests- DNS, Kerberos and LDAP. Below is the output from the command [NET...
  3. PDC DNS issues
    We have been having some serious issues with our Primary Domain Controller (Win 2k3). I believe I have found the root of the issue, but am unsure how to resolve it. For some reason, my PDC is not adding a DNS suffix to itself. This holds true when I try to change the Operatio...
  4. Exchange 2003 ENT does not find secnd DC/GC server
    Hi Guys I have 2 DC (win2k3), 1 exchange 2003 ent. in my network. 2 DCs are also DHCP and DNS. (A and B is name of the 2 DCs) A DC is PDC and Exchange works happily with A DC but not with B DC. If somehow A DC is not responding exchange will stop working, I can see that ou...
  5. Demoting a DC thats is also a GC
    Hi, I'm about to demote a Server 2003 Standard DC that is also a GC. I have two other servers that are DC's which hold the FMSO roles as well as GC roles, DNS and DHCP. Do I need to remove the GC role from the server before running dcpromo to demote it?

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: Debsyl99Posted on 2006-06-02 at 10:06:56ID: 16818377

Hi,
If you check the server name in system properties - network identification, what's the full computer name? It sounds like it's in a different domain to the workstations - and hance is what? A disparate single label domain? Very confusing! It looks like this was set up by someone who didn't have a clue what they were doing. How many workstations are there?

Deb :))

 

by: kshaysPosted on 2006-06-02 at 11:28:50ID: 16819017

Boy, sounds like a real mess to say the least.

Have you tried to delete the forward and reverse lookup zones and then recreate them as active directory integrated for starters?

kshays :)

 

by: kpradPosted on 2006-06-02 at 14:59:51ID: 16820657

so there is a forward lookup zone and there is also the Alias CNAME  (guid) as it says in the dcdiag.
can you ping the FQDN ?
where is the DC pointing to for DNS?
it should point to itself and the ISP info if any like DNS address should be added as forwarder.
you should be able to ping the GUID as well as the domain name.
if the guid exists and is not pingable, you could delete the existing guid and stop & start the netlogon service on the DC, the guid should be registered.
check the full computer name of the domain ( should not have a single label or disjointed name space)
does the zone allow dynamic update if not enable it.
is there a .zone as well in DNS if so then delete the .zone'
i have also seen cases where in ppl have deleted the root hints so also check the root hints.
you can always uninstall and reinstall DNS, and recreate the zone. since its a small domain should not be much of a hassle.

can you also run netdiag /v and dcdiag /v and check for errors or failures.
you could also run netdiag /fix and any minor things would be fixed.

can you also post any errors in the eventvwr and any login errors.
thanks.
kprad

 

by: haidentPosted on 2006-06-02 at 16:10:18ID: 16821025

network identification:

Full computer name - viper.birch.net

Domain - hance

Yes, its a single label domain.
I can ping viper.birch.net sucessfully.
The DC points to itself for DNS.
The ISP DNS servers are set-up as forwarders, and root hints are intact.
The DNS zone is set to allow dynamic update.
There is no "." zone.

In the event viewer there are netlogon warnings that state: Dynamic registration or deregistration of one or more DNS records failed because no DNS servers are available.

I suppose that I can't really screw this up more than it already is, but I am reluctant to uninstall DNS as I am now only reomotely connecting to the server.

 

by: Debsyl99Posted on 2006-06-03 at 03:45:28ID: 16822948

This IS a mess. I'm trying to get my head round what you've got here. If you open up active directory users and computers on viper - there's the domain object at the top of the tree - what's it's full name?
Then if you right click the domain object - click operations masters - where are each of the roles pointing for rid, pdc and infrastructure? If you check the full computername for one of the workstations in system properties - what is it?

When you create a dc you can't give it a name that consists of characters like "." - so by rights if the dc is in a domain it should be in the birch.net domain. Where hance comes into it is what I'm having trouble figuring out. The errors that you're getting though are consistent with having a single label domain - never a good idea at all, although this is fixable so long as you're not going to expand the domain.
Information about configuring Windows for domains with single-label DNS names
http://support.microsoft.com/kb/300684

 

by: haidentPosted on 2006-06-03 at 07:44:40ID: 16823467

The domain object at the top of the active direcotry tree is "hance"

In operations masters all (rid, pdc and infrastructure) point to "viper.birch.net"

full computer name for a workstation  - "HANCE-DESKTOP01.hance"

 

by: haidentPosted on 2006-06-03 at 12:34:46ID: 16824475

I followed the KB referenced above using method 1 to resolve the single label domain by editing the UpdateTopLevelDomainZones value in the registry, but I am not sure what benefical effect(s) should be obvious after doing this? Is there some amount of time that needs to pass for the DNS to be updated? Can I force this to occur more quickly?

I am still experiencing the same connectivity issues: logging on to the domain is very slow, as though the workstation tries and finally decides it is really not connected to the domain, shares from the DC server do not automatically reconnect after loggin on, and the printer shared from the server is not available until the shares are reconnected manually.

 

by: Debsyl99Posted on 2006-06-03 at 20:09:12ID: 16825763

I've got to admit - I'm at a loss as how to fix this other than to rebuild the domain which is probably not what you want to hear. But I can't imagine any other way of getting this stable. One dc managing a single label domain that it doesn't actually appear to be a member of? If there's only one dc and not too many workstations then I'd advocate starting it from scratch - at least that way here'd be much less work to do over the long term - ie short term pain for long term gain. Right now it's not working - and I can't see a way of fixing it as it is. However I've asked for a couple of second opinions on this - let's see what they think.

 

by: Jay_Jay70Posted on 2006-06-04 at 04:18:47ID: 16826810

>>>>>>>The ISP is Birch and for some crazy reason the DC machine is named viper.birch.net, but the domain is named hance.

DING DING DING! here is a nice big spanner in your works! What in the world was this guy thinking - youa re confusing the heck out of your server, your domain and your clients! poor old suckers!

quickest solution i can see here and the route i would be taking is similar to what Deb has already mentioned

1. Demote your Domain Controller
2. Decide on a Domain Name!!! then Name your Server appropriately
3. Repromote your Server with the new Domain Name - by this stage your Server FQDN should match that of your domain name!
   NB - let DCPROMO look after your DNS, delete any zones that you have and leave it as a standard clean install of DNS, when you run DCPROMO it will ask to configure DNS and you will find it creates a much more stable structure for you....
   NB - Make sure you add your ISP DNS servers as forwarders in yoru FLZ
4. Get the password for the router.. either that or do a hard reset and start a new, hell, buy a new router if you need to, Get DHCP off your router completely and let windows handle it


Run your diags and see what condition your Domain is now in, i think you will find that suddenly a lot more things are working the way they should!

Thats just my opinion - sorry if i sounded blunt i just typed that as if i were directing myself :) I personally wouldnt spend any more time trying to troubleshoot a mess like this, so much more efficient to heal the wound completely rather than stick a band aid on it - you are going to have to rebuild this at some stage

good luck and all the best

Jay

 

by: Jay_Jay70Posted on 2006-06-29 at 15:50:48ID: 17014300

haident how did you go with this mate? did you end up rebuilding?

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...