W2K - AD - DNS issues

Posted on 2003-11-12
Medium Priority
Last Modified: 2010-03-19
I am having DNS issues with my Active Directory installation on a W2K Advance Server.

The primary domain controller passes the netdiag and dcdiag tests.  But it fails the RegisterInDNS test. It advises that there are DNS configuration errors.

Current network set up - primary domain controller running AD and DNS, secondary domain controller running AD.  Active Directory replication and synchronization is working between the two DCs.

On the primary, the DNS has foward and reverse lookup zones plus a cache zone(which I don't believe it needs to be there).  The network is set up as an Intranet - no Internet resolving needs to be done on this server.

In the forward lookup zone the folders _msdcs, _sites, _tcp, and _udp are there.  The "." zone is not there.

In the reverse lookup zone the in-add-apr records are all there.

Here is the problem - when adding a new computer/user (W2K Pro) to the domain, you can sign-on to the domain.  

Signed on as the network administrator to the domain when you go to add a network user to a local group, the domain drop list shows the domain, you can select the domain, and the user list displays.

After you select the user you want to add and click the OK button an error message pops up and says the object is not available.

Then the domain listing on the local PC grays-out.  The network user is not added to the local group.

Has anyone seen this before?  Please advise.  Thanks!

Question by:tjheroff
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 2
LVL 79

Expert Comment

ID: 9738655
Perhaps one of these articles will help:
Windows 2000 DNS - Diagnosing Name Resolution Problems
FQDN = Fully Qualified Domain Name

Windows 2000 DNS - Solving other common DNS problems

LVL 56

Expert Comment

ID: 9741789
What do you have for the DNS settings under network properties on the server? It should have itself and your other server only listed there.

Author Comment

ID: 9742375
I only have the server itself. The secondary dns server field is empty. I will add the other AD server's IP address and let you know.  Thanks!
Get real performance insights from real users

Key features:
- Total Pages Views and Load times
- Top Pages Viewed and Load Times
- Real Time Site Page Build Performance
- Users’ Browser and Platform Performance
- Geographic User Breakdown
- And more


Author Comment

ID: 9742495
This is the result:
   Starting test: RegisterInDNS
      Please verify that the network connections of this computer are

      configured with correct IP addresses of the DNS servers to be used for

      name resolution.  If the DNS resolver is configured with its own IP

      address and the DNS server is not running locally the DcPromo will be

      able to install and configure local DNS server, but it will be isolated

      from the existing DNS infrastructure (if any). To prevent this either

      configure local DNS resolver to point to existing DNS server or manually

      configure the local DNS server (when running) with correct root hints.
      ......................... emcp1 passed test RegisterInDNS

LVL 56

Expert Comment

ID: 9742526
That looks good, how long does it take to register a new PC or user now?

Author Comment

ID: 9742938
No problem adding the PC or user to the network.  But the issue above still displays:

"Signed on as the network administrator to the domain when you go to add a network user to a local group, the domain drop list shows the domain, you can select the domain, and the user list displays.

After you select the user you want to add and click the OK button an error message pops up and says the object is not available. "

But this time it does add the user in the CN=username, etc. format after hitting apply the format changes to domain\username.

In the Event Viewer on the primary domain - Event ID 7062 appears numerous times.

Author Comment

ID: 9743038
On the primary using dcdiag it fails the following tests with these results:

Replications - emcp2 dsbind fails error 1722
OutboundSecureChannels emcp2, ldap fails error 58 and error 31

Author Comment

ID: 10393812

Please close this thread, none of the suggestions helped.  I had to call in a consultant.

Thank you.

Accepted Solution

tjheroff earned 0 total points
ID: 10575581
Dear KaBaaM,

Please refund the 500 points to me, thank you.

If memory serves me correctly, the consultant reinstalled Active Directory - DNS integrated on the secondary domain controller as a primary.


Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Downtime reduced, data recovered by utilizing an Experts Exchange Business Account Challenge The United States Marine Corps employs more than 200,000 active-duty Marines with operations in four continents, all requiring complex networking system…
This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question