Solved

W2K - AD - DNS issues

Posted on 2003-11-12
10
508 Views
Last Modified: 2010-03-19
I am having DNS issues with my Active Directory installation on a W2K Advance Server.

The primary domain controller passes the netdiag and dcdiag tests.  But it fails the RegisterInDNS test. It advises that there are DNS configuration errors.

Current network set up - primary domain controller running AD and DNS, secondary domain controller running AD.  Active Directory replication and synchronization is working between the two DCs.

On the primary, the DNS has foward and reverse lookup zones plus a cache zone(which I don't believe it needs to be there).  The network is set up as an Intranet - no Internet resolving needs to be done on this server.

In the forward lookup zone the folders _msdcs, _sites, _tcp, and _udp are there.  The "." zone is not there.

In the reverse lookup zone the in-add-apr records are all there.

Here is the problem - when adding a new computer/user (W2K Pro) to the domain, you can sign-on to the domain.  

Signed on as the network administrator to the domain when you go to add a network user to a local group, the domain drop list shows the domain, you can select the domain, and the user list displays.

After you select the user you want to add and click the OK button an error message pops up and says the object is not available.

Then the domain listing on the local PC grays-out.  The network user is not added to the local group.

Has anyone seen this before?  Please advise.  Thanks!
 


0
Comment
Question by:tjheroff
  • 6
  • 2
10 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 9738655
Perhaps one of these articles will help:
Windows 2000 DNS - Diagnosing Name Resolution Problems
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/cnet/cncf_imp_zvri.asp
FQDN = Fully Qualified Domain Name

Windows 2000 DNS - Solving other common DNS problems
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/cnet/cncf_imp_ibxf.asp

0
 
LVL 55

Expert Comment

by:andyalder
ID: 9741789
What do you have for the DNS settings under network properties on the server? It should have itself and your other server only listed there.
0
 

Author Comment

by:tjheroff
ID: 9742375
I only have the server itself. The secondary dns server field is empty. I will add the other AD server's IP address and let you know.  Thanks!
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 

Author Comment

by:tjheroff
ID: 9742495
This is the result:
   Starting test: RegisterInDNS
      Please verify that the network connections of this computer are

      configured with correct IP addresses of the DNS servers to be used for

      name resolution.  If the DNS resolver is configured with its own IP

      address and the DNS server is not running locally the DcPromo will be

      able to install and configure local DNS server, but it will be isolated

      from the existing DNS infrastructure (if any). To prevent this either

      configure local DNS resolver to point to existing DNS server or manually

      configure the local DNS server (when running) with correct root hints.
     
      ......................... emcp1 passed test RegisterInDNS

0
 
LVL 55

Expert Comment

by:andyalder
ID: 9742526
That looks good, how long does it take to register a new PC or user now?
0
 

Author Comment

by:tjheroff
ID: 9742938
No problem adding the PC or user to the network.  But the issue above still displays:

"Signed on as the network administrator to the domain when you go to add a network user to a local group, the domain drop list shows the domain, you can select the domain, and the user list displays.

After you select the user you want to add and click the OK button an error message pops up and says the object is not available. "

But this time it does add the user in the CN=username, etc. format after hitting apply the format changes to domain\username.

In the Event Viewer on the primary domain - Event ID 7062 appears numerous times.
0
 

Author Comment

by:tjheroff
ID: 9743038
On the primary using dcdiag it fails the following tests with these results:

Replications - emcp2 dsbind fails error 1722
OutboundSecureChannels emcp2, ldap fails error 58 and error 31
0
 

Author Comment

by:tjheroff
ID: 10393812
Moderator,

Please close this thread, none of the suggestions helped.  I had to call in a consultant.

Thank you.
0
 

Accepted Solution

by:
tjheroff earned 0 total points
ID: 10575581
Dear KaBaaM,

Please refund the 500 points to me, thank you.

If memory serves me correctly, the consultant reinstalled Active Directory - DNS integrated on the secondary domain controller as a primary.



0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question