Solved

A domain controller for your domain could not be contacted

Posted on 2000-02-23
31
1,286 Views
Last Modified: 2013-12-14
I have setup 2 standalone NT servers.
I add them to the domain from the network properties page of the respective servers. Using create a computer account in the domain.
It says welcome to domain kursus, and ask for a reboot.
After rebooting it says "topic" and I log in.
I have remembered to remove them from the server manager and even waited a whole day after doing the syncronisation.

It is highlighted in server manager as been online but when I try to view properties for it, it responds with: Access Denied.

The other way around I can see the properties fine from the standalone server except for the other standalone server.

I have even tried renaming the one server because I thought it might be some leftovers in the DC's list.
0
Comment
Question by:Ravelin
  • 15
  • 6
  • 4
  • +5
31 Comments
 
LVL 23

Expert Comment

by:Tim Holman
ID: 2550469
You need a domain controller if you're adding machines to a domain !
Does IP work OK ?
Are these machines connected with a crossover cable ?
Member servers need a domain...
0
 
LVL 2

Expert Comment

by:ABCStore
ID: 2551387
Delete those machines from PDC using server manager, then re-add them again manually
0
 

Expert Comment

by:Teck
ID: 2552088
What service pack is installed? In technet there is an article about this. Unfortunately I can not find the Q number at the moment. It says to reinstall the service pack. We had a similar situation here on a couple workstations and this resolved the issue.
0
 

Author Comment

by:Ravelin
ID: 2552306
I already have 1 PDC and 2 BDC's for the domain.
I can ping the machines fine no problem there, and they even show up in server manager.
I have tried to remove one of them from the domain and keep it powered off for a whole day, even renaming it to be sure that there are no problems regarding name mistakes and SID and stuff.
There is installed SP5 on all the servers several times to make sure.
Thanks for the comments BTW
0
 

Author Comment

by:Ravelin
ID: 2552310
BTW machines are connected through a 100Mbit switch.
0
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 2552382
If you can, reboot the PDC - I had a problem recently establishing a trust between two PDCs and upon rebooting one, the problem went away.  (Actually, I had them bring their entire domain down, then turn the PDC on then the BDC and I was then able to establish the trust).  The error I had been recieving was "No Domain Server available to validate your password".
0
 
LVL 1

Expert Comment

by:BareFoot
ID: 2552571
Have you added the Domain Admins group to the local Administrators group in the standalone servers?

It sounds like it could be a permissions problem.
0
 

Author Comment

by:Ravelin
ID: 2553530
leew : I might try that but will have to find a suitable time for this ofcourse.

BareFoot : No I haven't but I definatly will try that.
0
 
LVL 1

Expert Comment

by:omere
ID: 2559207
What _exactly_ is the problem, except for you not being able to manage them using server manager (remotely) - because the answer to that problem is, as BareFoot said, adding the Domain Admins to the administrators group.

Do you have ANOTHER problem?
0
 

Author Comment

by:Ravelin
ID: 2563071
I can't add the domain admin group to the local administrators group, because as soon as I join the domain and restart it says that it cannot find the domain controller and therefore I can't get to the SAM database.

However strangely enough, I have no problem accessing the SAM database from the domain when the server is set to be in a workgroup.
0
 
LVL 1

Accepted Solution

by:
omere earned 140 total points
ID: 2563256
Try typing:
nbtstat -a [pdc_name]
from the server your are trying to add to the domain.

See if you get back a listing containing a domain record (1C or 1B,
I forget).

Check if you have an lmhosts file inside winnt\system32\drivers\etc.

If you do, make sure it has no content that has anything to do with this case (i.e., #DOM for the domain in question)
0
 

Expert Comment

by:VampireD
ID: 2563831
You need either LMHOSTS or WINS to do domain resolution.

Is this setup?
0
 

Author Comment

by:Ravelin
ID: 2564179
During a nbtstat -a here is some of the suspecious looking entries.

What I don't understand are these statements:

Domain  <1C> GROUP  Conflict

And this one?

Inet~Services  <1C> GROUP  Conflict


I have both Wins and LMHOST in place.
0
 

Author Comment

by:Ravelin
ID: 2564226
I have stopped all IIS services on the PDC and now only
DOMAIN <1C> GROUP Conflict

I think the solution is nearing, please respond since I am starting on a new job on Wednesday and would like to have this cleared out before I leave....
0
 

Author Comment

by:Ravelin
ID: 2564249
As an additional info the Wins database list the following on the domain name:
DOMAIN[1bh]    IP_PDC

DOMAIN[00h]    IP_WIN95CLIENT

DOMAIN[1Ch]    IP_BDC

DOMAIN[1Eh]    IP_WORKSTATION

Hope somebody can find the error in some of this...
0
Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

 

Author Comment

by:Ravelin
ID: 2564297
Holy smokes it worked!!!
Ofcourse I have no idea of what did it, but I still have one last stand-alone server, where I will go more systematicly forward.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 2564307
1C registers the computer as a domain controller.
1B registers it as the domain master browser (which only a domain controller can be)
00 Registers the workstation service
1E is there to facilitate browser elections

You SHOULD find a 1C in there for IP_PDC.

If the PDC is not working/not visible, you won't be able to add machines to the domain, as you can only do this with a PDC, not a BDC.

The 1C conflicts you've been picked up suggests there are two domain controllers with the same name.

Weird.

Is your WINS server multihomed ?
Are your PDC / BDCs multimhomed - in which case do their WINS entries reflect this ?
There are issues with this, such as NetBIOS can only be bound to one interface per machine...

Can you add other machines to the domain OK ?

From a failing machine, can you NBTSTAT to view resources on the domain controller OK - ie NBTSTAT -a PDC, or NBTSTAT -A PDC's_ipaddress

It may help if you remove and reinstall NetBIOS on failing machines (control panel > network).



 
0
 

Author Comment

by:Ravelin
ID: 2564441
It was the conflict appearently.
I disabled all IIS related services and it worked.

Thanks alot for the help...
0
 

Author Comment

by:Ravelin
ID: 2564444
Worked a little further on it, and it worked.
I don't know what exeactly caused the problem but it is fixed now.
0
 
LVL 1

Expert Comment

by:omere
ID: 2566248
Out of curiosity, did you have another IP address bound for usage for IIS? i.e., a virtual ip-based host (as opposed to name-based).
0
 

Author Comment

by:Ravelin
ID: 2568247
I don't know what you mean.
It was reached on the same IP as the normal server IP...


It still says conflict under the domain?? Shouldn't it say Registered?
0
 
LVL 1

Expert Comment

by:omere
ID: 2570931
You can bind several IP addresses to one NIC in order
to allow virtual hosting (i.e., you would register several domain names on the zone file (DNS), then have each one point to another IP address. That way the HTTPD server would know what address it needs to host by the IP address used to reach it - today virtual name-based hosting is more common anyhow).

Post your relevant WINS entries again, plus
nbtstat -a output.
0
 

Author Comment

by:Ravelin
ID: 2571750
Sorry I didn't see Tim's question...

None of my systems are multihomed.
I can do the nbtstat -a PDC fine, but it does list that conflict :-(

I do not however have anything else but TCP/IP installed on any of the machines.
Do I HAVE to have netbeui installed on the PDC which is WINS and DHCP at the same time?

To my knowledge there isn't a server name conflict.

I haven't tried to remove and add others because i am afraid it won't work. And as said I don't work there anymore, so it isn't as easy to fix.
I would just try to know whats causing this.

When you say Netbios, do you then mean netBEUI?
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 2572451
>It says welcome to domain kursus, and >ask for a reboot.
>After rebooting it says "topic" and I >log in.

Going back a bit - so when you add the computer to domain kursus, and reboot, the domain 'topic' is listed instead ?

When I say NetBIOS, I mean NetBIOS - it sits on top of either TCP/IP, NetBEUI or NWLink to perform 'day-to-day' SMB operations.

It's a component you can add and remove within the network applet.
0
 

Author Comment

by:Ravelin
ID: 2574242
When I start the server up in a workgroup there isn't a problem finding the domain controller, at least viewing the users in the domain.
When I then afterwards add it to the domain it says welcome to the XXXX domain.

When I then reboot as it ask for and log in, it says: "A domain controller for your domain could not be contacted" and a little more on the error message saying that I have been logged on using cached credentials.

The only place I can see Netbios is on the bindings tab under wins client -> NIC
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 2575847
Network control panel, services, NetBIOS interface.
0
 

Author Comment

by:Ravelin
ID: 2584972
But what I don't understand is, shouldn't NT be able to run on strictly TCP/IP?

BTW it is installed on the PDC.

I installed a BDC a week ago in a completely different site, where it had no problems joining my domain over the internet.

Well, I think I'll let it hang.
I don't work there anymore as said earlier.

Thanks for trying.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 2586981
You need a NetBIOS interface on an NT machine in order for it to talk to other Microsoft machines.
This interface can run on TCP/IP, NWLink and NetBEUI.
0
 

Author Comment

by:Ravelin
ID: 2598301
Thanks for clearing it up :-)

No news on what can cause that conflict?
0
 
LVL 2

Expert Comment

by:ABCStore
ID: 2598884
Honestly, I don't see any relationship between "Access Denied" and lmhosts file... Very strange answer. Tim?
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 2599811
I have no idea why that answer was accepted - Ravelin ?

To get to the cause of the conflict, look in the event viewer for msg 4319 or 4320, or any NetBT related event message for that matter.

Although NBTSTAT -N may show a conflict, it won't give you the IP address of the failing machine, which you need to decipher from hexadecimal entries in the event log.

There are also potential issues with WINS.

If a WINS entry is static, yet the client still has WINS enabled, you'll also get a conflict.

If you want to progress this line of thought, please post up another question, or contact community support to get your points back and stick the event msg up here.

0

Featured Post

Free book by J.Peter Bruzzese, Microsoft MVP

Are you using Office 365? Trying to set up email signatures but you’re struggling with transport rules and connectors? Let renowned Microsoft MVP J.Peter Bruzzese show you how in this exclusive e-book on Office 365 email signatures. Better yet, it’s free!

Join & Write a Comment

When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup". After a while, you have entered a loop for Auto repair which does not fix anything and you will be in a  panic as all your work w…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now