[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

_msdcs, _sites, _TCP, _udp no showing after NT4 PDC Upgrade to Win2k Srv.

Posted on 2004-10-21
24
Medium Priority
?
520 Views
Last Modified: 2010-04-13
I have recently upgraded a NT4.0 PDC to Windows 2k using the following steps:
(This is a single domain install,  we have only one domain. Simple)

1.  Installed a new NT4.0 BDC Server on the LAN.
2.  Synchronized NT4 Domain.
3.  Took the newly installed NT4 BDC off LAN and moved it to a test hub (no connection to company LAN).
4.  Promoted the newly BDC to PDC on the test hub.
5.  Installed Win2k srv with Active Directory (Mixed Mode).
6.  I did use proper naming conventions:  mycompanyname.net (I am following steps in a MS SRV 2K BOOK)
7.  The installation process completed successfully with all accounts being there.

Now:

Issues:

1.  The Win2k DC is showing no _msdcs, _sites, _TCP, _udp under DNS Fwd zone.  Don't know why!
2.  My Test environment on the hub has no access to internet/ISP. Is that OK?
3.  In NT4.0 I can do manual domain synchronization through server manager, can I do that from Win2K server in Mixed mode.  How?
4.  Once my configuration and testing is completed with this 2K DC,  can I demote the live existing PDC on company network to BDC and bring my New 2K DC to the live network.  (I have not seen this done or recommended by Microsoft therefore I am assuming the answer is no).  Just curious.
5.  In DNS MMC, do I need to remove "." zone and configure forwarders in order to use my ISP's DNS.  Don't want to confuse internal browsers in the office.

Sorry about all the question... and thank you at the same time.


0
Comment
Question by:abastanpour
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 13
  • 11
24 Comments
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12371547

1. Is the DNS running on your 2000 Server? It needs to be really since AD requires DNS to support Dynamic Update. The zone should be Primary Active Directory Integrated on there. To check Dynamic Update run "ipconfig /registerdns" from the command prompt.

2. Yep, no problem.

3. Sort of, although Synchronization is instant in a single site.

4. No. You cannot demote a PDC to BDC, only promote a BDC to PDC. To sort out the upgraded domain you would probably be best with:

 - Add a new NT 4 BDC to the network
 - Promote the BDC to PDC
 - Upgrade the PDC to Windows 2000 and Launch the AD Wizard
 - Upgrade the remaining BDCs afterwards

5. The "." zone makes you server thinks it knows everything about everything on the internet (. is the root zone), so definately delete that. Forwarders aren't essential, you can stick with Root Hints if you prefer.

All Internal clients and servers should refer to your Internal DNS for everything to work.

I would strongly advise that you do not use public DNS names (like .net) for your Private network, instead use something like mycompany.local. This can prevent complicating things later on.

Please post again with the rough config of your 2000 Server if it still can't query DNS.
0
 

Author Comment

by:abastanpour
ID: 12373669
Greetings;

1.  The DNS is installed.  I still don't have _msdcs, _sites, _TCP, _udp under DNS Fwd zone after running ipconfig /registerdns.  Everything I read sys it should be there.. Hmmmm!
Under DNS MMC, I am seeing "Cashed Lookups".  Is that normal?

5.  If no forwarders have been set in DNS, then would my clients be able to browse the internet like they do now?  We are using our ISP's DNS.  (our DNS Setting are obtained via DHCP)  

This is a rough config of my server:

My NT 4 Domain is called DHP.  I am using a nonpublic domain name, dhpassociate.net.
After the upgrade to 2k I used AD Wizard to create:
1.  Create a new domain tree
2.  Create a new forest of domain tree
Than went on installing DNS and completed that.
That's as far as I got since my DNS is not showing _msdcs, _sites, _TCP, _udp under DNS Fwd zone.



0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12373880

1. No DNS API Errors?

If not I'd delete the zone, and re-add it ensuring it's AD Integrated.

Did DCPromo complete successfully?

5. Yes - Without forwarders DNS will use the Root Hints file, these are the IP Addresses of the Top Level Domain Name Servers, they will tell your DNS where to get answers to it's questions. The only time it won't use this file is if the zone "." exists. You should be able to see the Root Hints option under your DNS Config. If it is greyed out then something is wrong.
0
Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

 
LVL 71

Expert Comment

by:Chris Dent
ID: 12373891

Can you also confirm the Domain name you've assigned to AD? You can mask it, I'm only after the format you've used.
0
 

Author Comment

by:abastanpour
ID: 12374043
I don't see any API errors.
The only issue I see under system events is:

Event ID 5781
Source: Netlogon

Dynamic registration or deregistration of one or more DNS records failed because no DNS servers are available.

What would be the best way for me to confirm the AD doming name?
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12374098

Okay, there's definately something up with your DNS, as if you didn't ready know ;)

Try:

ipconfig /all

It should have a Primary DNS Suffix listed there (along with the host name).

Otherwise, open up AD Users and Computers, it'll have the domain name listed there too (just expand the tree on the left a bit if you can't see it).
0
 

Author Comment

by:abastanpour
ID: 12374206
Oh, OK.

I have been there already.  The primary DNS suffix has been there.  I just checked it again with both methods.  Ipconfig /all shows  my primary DNS suffix as dhpassociate.net

Hummm... Very interesting...!  

0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12374268

That's good enough for now.

Now in order for DNS to work we need a Forward Lookup Zone called dhpassociate.net, is that there?
0
 

Author Comment

by:abastanpour
ID: 12374299
Yes there is one there..
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12374349

Okay, delete it. Then add a new primary (AD integrated) zone with the same name.

On occasion the zone files become corrupt - this can appear as anything from TTLs not working to Updates not working.

After that select the Properties for the zone, on General confirm that it's AD Integrated. That the Dynamic Updates box is set to "Only Secure Updates".

Confirm that the server is using only it's own IP Address as DNS, then at the command prompt try ipconfig /registerdns

See if it added an A Record and an NS Record for the domain. Then check for those _ folders again.
0
 

Author Comment

by:abastanpour
ID: 12374436
Ok, let me make sure I understand this.

I need to delete dhpassociate.net under the forward zone, than create a new "Zone" which the wizard should walk me through it.  Correct?
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12374466

Correct. Just to ensure the existing zone isn't corrupt. Then use the wizard to create a new forward lookup zone with the same name.
0
 

Author Comment

by:abastanpour
ID: 12374526
Deleted and recreated the Zone.
Under the static IP configuration for this server, the DNS Preferred servers were pointing at the ISP.  I have changed it to point at itself.
Did the Ipconfig /registerdns.
Let's see what happens...



0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12374540
Okay, it should be okay.. make sure you keep a bit of an eye on the System and DNS Logs in Event Viewer.
0
 

Author Comment

by:abastanpour
ID: 12374853
OK

I am showing  _sites, _TCP, _udp, but no _msdcs.  

0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12374980

Getting there though ;)

Check for DNS API Errors in System, and more general DNS errors in the DNS Log.

Any NTDS type errors in the Directory Service log?
0
 

Author Comment

by:abastanpour
ID: 12379718
OK.. Looking good.
The _msdcs is there now.  
The only error I see is in the system event log and its:

Event ID 5781
Source: Netlogon

Dynamic registration or deregistration of one or more DNS records failed because no DNS servers are available.

I getting this message every 2 hrs.  Not sure why..
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12379800

That one on the server itself?

Is there just the Servers IP as the Primary Name Server in TCP/IP Configuration? Or do you have a secondary one there too?

If it's not that simple then we can turn on logging for the NetLogon service. It might be on already of couse, to check look for:

%Windir%\debug\netlogon.log
0
 

Author Comment

by:abastanpour
ID: 12379900
The IP Configuration on the server is pointing Primary DNS to itself and I do have a WINS entry.  When you say the name server, are you talking about the WINS?


The netlogon.log is blank.  There are no entries in it.
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12379927

Nope, DNS is a Name Server. Sorry, I should stick to the same names ;)

Looks like Netlogon logging is disabled... to enable it you do the following from the command prompt:

nltest /dbflag:2080ffff
net stop netlogon
net start netlogon

To disable it again you do:

nltest /dbflag:0
net stop netlogon
net start netlogon

That should add a bit more information about what the NetLogon service is trying to register in DNS.
0
 

Author Comment

by:abastanpour
ID: 12380088
I have a lot of entry in the netlogon.log now. :)
Man, I don't understand why netlogon was disabled!  After all, I upgraded form a working NT4 PDC.

Also;
In static configuration of the sever, I did know that you had to have the primary DNS set to point at itself. Originally my Static DNS setting where set to point at the ISP.
These are little steps that my book did not cover.

Also,
I took a laptop plugged it into my test environment to see if I could long into the Win2k server.  And it worked nicely.
However, when I took the laptop off the test network and tried to log into the company network.  I got a message saying the computer account for this system is missing.  I check server manager and it's there!  This message worries me, because if for some reason my Upgrade to win2k is not successful, than I may incounter computer account issues throughout the office if I go back to NT 4.0 domain.

0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 12380225

It'll mess with the Computer Account when you move it between domains (the domains are different now).

It should be fine with the other upgrade.

To check that out to be certain you could...

1. Rebuild your test server as a BDC on live again
2. Take it off live and add it to test, promoting it to PDC
3. Add your laptop (or a test computer account) to the NT 4 Test domain
4. Perform the Upgrade to AD
5. Check access from the computer

It'll definately make you nice and familiar with the upgrade procedure ;)
0
 

Author Comment

by:abastanpour
ID: 12380954
I will practice more, that's for sure.
This computer account issue is worrying me again, because.. Say:

1.  I take one freshly synchronized BDC off the company network and put it on the side.
2.  Upgrade the Company PDC to Win2k AD Mixed mode.
3.  Then for some reason I the upgrade is not successful and I had to take the Win2k off the network.
At this point my only Disaster Recovery would be to bring the Offline BDC back and promote it to PDC.
But, then all my Computer accounts are not going to work.  
I am thinking correctly about this.. ?!

Oh, before I forget: Thank you for helping this solo-net admin.  Thank you :)
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 200 total points
ID: 12381019

That's correct yes, you'd have to re-add them all, but then it is a disaster recovery option.

Your set-up doesn't seem too complex though, so I don't think you'll run into any problems that will demand you roll back to NT. Better safe than sorry of course.

Hopefully the testing phase you're in now (a very sensible plan by the way - too often omitted) will continue to help eliminate or quickly handle any problems you might run into.

Helping is a pleasure ;)
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
With its various features, Office 365 can not only help you with your day-to-day business tasks, it can also do wonders for your marketing campaign.
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question