Windows Server 2003 DNS setup connecting 2 root servers via VPN

Here is my unique situation.  I joined my 2003 server to an existing 2003 AD domain making it a DC in that AD domain.  The connection I used to join the domain is a VPN connection from my root server to the other root server.  Replication took place and everything looks fine from what I can tell.  I have the DNS, users, domain comtrollers, all that info.

When I try and add an additional server to the AD domain, MY root server is not responding and the domain says it is not available at this time.  Why isn't my root server acting like a root server for the AD domain if it replicated with the other root server and has the same setup?  Please help.  Thank You
George ColesNetwork LeadAsked:
Who is Participating?
 
jamesreddyConnect With a Mentor Commented:
Let me try to clarify a couple things.  Maybe you can asnwer a few questions.

1.  Do BOTH sides of your network (both sides of the VPN) have a GC and a DNS server that is also an Active Directory controller?

2.  The error message you are getting, does that occur on both sides of the VPN or just the new one?

3.  Have you tried logging on as the Domain Administrator?

If you can log on as the domain administrator, but not as any other user, this is a classic symptom of not seeing a Global Catalog server as the GC is needed to authenticate everyone except Domain Administrators.

Try to take a little time and lay out your network for us.  I think at the moment, the details are sketchy.  Let's try this...does it resemble the following:


Original Network

     ADC (GC)-----------VPN----------------New ADC with GC and DNS
      / \                                                                /  \
    /     \                                                            /      \
Network A                                                      Network B



Do you have a GC in both network A and network B?  A DNS server?  And ADC (Active Directory Controller)?


Let's start there...

James


0
 
jamesreddyCommented:
What speed is your VPN connection?  If it is slower, and your network is setup to detect slow network links, you will need to disable that function for feature to work properly.
0
 
jamesreddyCommented:
Oh...wait a minute...you mean why is the NEW root server not acting like a root server?  You may need to setup a  seperate site and also configure the second DC as a Global Catalog server.
0
 
George ColesNetwork LeadAuthor Commented:
Thanks for your reply.  My root server is in a new site and I made it a GC.  When I try to login it is still telling me "The system cannot log you on now because the domain MYDOMAIN is not available".  Are you saying that I should add a second root server and make that a GC?  Thanks
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.