Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Systems fail to log onto domain controller

Posted on 2004-08-07
7
Medium Priority
?
852 Views
Last Modified: 2010-04-11
I noticed this past week that while rebooting one of the domain controllers serveral of the clients lost thier connection and tried to log on and could not. Shouldn't the other DC take over when one is offline?  Some systems didn't have a problem at all but about 10 were not polling the other dc. All systems are on the same subnet.  dcdiag shows no errors, replication looks fine with no errors regarding ntfrs in the event viewer. All failing systems could ping both dc's.

I need to make sure that all systems can poll and log onto the other dc. Anyone know how I can test and/or fix this issue?

DC's are win2k SP4 and clients are XP pro.

Thanks in advance!
0
Comment
Question by:zenportafino
  • 4
  • 2
7 Comments
 
LVL 85

Expert Comment

by:oBdA
ID: 11744252
Is your other DC a Global Catalog? If not, enable it on the second one as well; no GC available, no login ...
HOW TO: Create or Move a Global Catalog in Windows 2000
http://support.microsoft.com/?kbid=313994
0
 
LVL 5

Expert Comment

by:dgroscost
ID: 11744684
You should not make a Domain Controller a Gloal Catalog if it is running running the Infrastructure role as well (unless you only have 1 DC in your environment)

Keep that in mind.
0
 
LVL 1

Author Comment

by:zenportafino
ID: 11744906
I only have two and they are both Global catalog servers as well.  I've heard many times in books not to put the Infrastructure role on the same systems as a GCS yet I've never known anyone to have a problem with it.  How do the two roles together prevent a logon?
0
Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

 
LVL 1

Author Comment

by:zenportafino
ID: 11744908
Also, if only one is a GCS and goes down, doesn't that create it's own logon issue - no more GCS available?
0
 
LVL 85

Accepted Solution

by:
oBdA earned 2000 total points
ID: 11746267
In most surroundings, and probably in yours as well, you can ignore the infruastructure master bit:
====8<----[KB223346]----
[...]
Two exceptions to the "do not place the infrastructure master on a global catalog server" rule are:
* Single domain forest: In a forest that contains a single Active Directory domain, there are no phantoms, and so the infrastructure master has no work to do. The infrastructure master may be placed on any domain controller in the domain.
[...]
====8<----[KB223346]----

FSMO Placement and Optimization on Windows 2000 Domain Controllers
http://support.microsoft.com/?kbid=223346

The next thing to check is if the other DC is advertising itself as being one, that is, if it creates the necessary SRV entries in your DNS (just not to leave out the obvious: you do have a DNS server running on the other machine?). In addition, check if the DNS settings in the TCP/IP properties on your DCs are correct.
In short:
On your first DC you created, make sure its own IP address (not 127.0.0.1!) is listed in the TCP/IP properties *only*; no other DNS server entries there. On your second DC, let the primary DNS entry point to your first DC as well, the secondary one to its own IP address.
On your domain members, make sure they have the first DC as primary DNS, the second one as secondary DNS.
Here's some addittonal reading material:

Frequently Asked Questions About Windows 2000 DNS and Windows Server 2003 DNS
http://support.microsoft.com/?kbid=291382

Best practices for DNS client settings in Windows 2000 Server and in Windows Server 2003
http://support.microsoft.com/?kbid=825036

Troubleshooting Common Active Directory Setup Issues in Windows 2000
http://support.microsoft.com/?kbid=260371

How to Verify the Creation of SRV Records for a Domain Controller
http://support.microsoft.com/?kbid=241515

How Domain Controllers Are Located in Windows
http://support.microsoft.com/?kbid=247811

How Domain Controllers Are Located in Windows XP
http://support.microsoft.com/?kbid=314861
0
 
LVL 1

Author Comment

by:zenportafino
ID: 11749148
Thanks OBda for setting me straight on the Infrastructure+GCS no no.  I know that both dc's have the correct dns addresses confiugured as well.  I'll look into artical 241515 to verify tht the srv folders have the correct info.  

Last week early on I noticed that when I would open up dns on the 2nd DC, the 1rst dc's dns folders wouldn't open in the dns mmc.  I re booted the 2nd dc and I could see the 1rst again.

We have a broadcom dual input adapter on our dell 1650 (dc1) with two cables - one going into the servers switch and the other cable going into the clients switch. It shares the same IP for both.  I hate this thing cause I have no idea how it works.  Everyone at work says it's always been there yet no one knows how to configure or troubleshoot it.  I am suspicious of this set up yet I don't know how to rule out if it is the problem or not.

0
 
LVL 1

Author Comment

by:zenportafino
ID: 11780761
Thanks OBda.  The information is good to know and I've added it to my own set of "tools" for troubleshooting logons.  I learned some good stuff from it.  

The NIC has a probing feature that can mess itself if only two ports are using it.  I disabled the probing and have not had a client fail to logon yet.  When it happens again I'll be using the above methods to isolate where the issue might be.

Thanks again.
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Sometimes clients can lose connectivity with the Lotus Notes Domino Server, but there's not always an obvious answer as to why it happens.   Read this article to follow one of the first experiences I had with Lotus Notes on a client's machine, my…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

926 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question