Link to home
Start Free TrialLog in
Avatar of wtrdog
wtrdog

asked on

DNS Server Error 4007

The following two errors occur back to back on our 2003 Server.

"The DNS server was unable to open zone mydomain.local in the Active Directory from the application directory partition DomainDnsZones.mydomain.local. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code."


"The DNS server was unable to open zone _msdcs.mydomain.local in the Active Directory from the application directory partition ForestDnsZones.mydomain.local. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code."

When the server was originally installed the domain was going to be mydomain.local.  This was changed when there were some issues while trying to transfer the FSMO roles from the existing 2000 Server.  We renamed the new server to mydomain.com and these errors show up in the DNS Server Event Viewer under ID 4007
Avatar of Jay_Jay70
Jay_Jay70
Flag of Australia image

Hi wtrdog,

just to check, when you recreated the zones, did you create them with the now correct domain name?
Avatar of wtrdog
wtrdog

ASKER

Hey again.. Yes I did..
Just to be straight.. all I deleted was the Forward and the Reverse Zones and readded those to correct the other problem.
yup that s fine,

can you post the actual event viewer code and source so i can narrow it down please

if you run dcdiag also, what fails?
Avatar of wtrdog

ASKER

Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4007
Date:            5/18/2006
Time:            10:02:42 PM
User:            N/A
Computer:      MYSERVER
Description:
The DNS server was unable to open zone myserver.local in the Active Directory from the application directory partition DomainDnsZones.nyserver.local. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 0d 00 00 00               ....    

Is this what you need?

Avatar of wtrdog

ASKER

DCDIAG RESULTS

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests
   
   Testing server: Default-First-Site-Name\MYSERVER
      Starting test: Connectivity
         ......................... MYSERVER passed test Connectivity

Doing primary tests
   
   Testing server: Default-First-Site-Name\MYSERVER
      Starting test: Replications
         ......................... MYSERVER passed test Replications
      Starting test: NCSecDesc
         ......................... MYSERVER passed test NCSecDesc
      Starting test: NetLogons
         ......................... MYSERVER passed test NetLogons
      Starting test: Advertising
         ......................... MYSERVER passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... MYSERVER passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... MYSERVER passed test RidManager
      Starting test: MachineAccount
         ......................... MYSERVER passed test MachineAccount
      Starting test: Services
         ......................... MYSERVER passed test Services
      Starting test: ObjectsReplicated
         ......................... MYSERVER passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... MYSERVER passed test frssysvol
      Starting test: frsevent
         ......................... MYSERVER passed test frsevent
      Starting test: kccevent
         ......................... MYSERVER passed test kccevent
      Starting test: systemlog
         ......................... MYSERVER passed test systemlog
      Starting test: VerifyReferences
         ......................... MYSERVER passed test VerifyReferences
   
   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
   
   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
   
   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
   
   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
   
   Running partition tests on : MYDOMAIN
      Starting test: CrossRefValidation
         ......................... MYDOMAIN passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... MYDOMAIN passed test CheckSDRefDom
   
   Running enterprise tests on : MYDOMAIN.com
      Starting test: Intersite
         ......................... MYDOMAIN.com passed test Intersite
      Starting test: FsmoCheck
         ......................... MYDOMAIN.com passed test FsmoCheck
excellent, can you right lcik on your zones, choose zone types and make sure its AD integrated for me
Avatar of wtrdog

ASKER

Yes.. both Forward and Reverse are AD Intergrated
basically that error is DNS starting before DNS is ready.... your IP settings, do they point to yourself for primary DNS?
Avatar of wtrdog

ASKER

Yes and there is only one entry in there for DNS and it is pointing at itself.
ha sorry just read my last message - genius cough cough

meant that it means DNS is starting before Active Directory is ready....!
Avatar of wtrdog

ASKER

Fixed..

Went digging through the Registry and found two instances of the domain it was referring to..

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DNSServer\Zones

There were two additional entries other than the one domain that I am now on. I deleted both of the .local that the error was talking about and it rebooted just fine with no errors.

Please repost this so I can award then close so there will be a solution posted.


ASKER CERTIFIED SOLUTION
Avatar of Jay_Jay70
Jay_Jay70
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks for this...been looking for this solution for 3 days.