Solved

Domain DNS server can't find the AD DNS zones for the foerst

Posted on 2006-06-12
9
250 Views
Last Modified: 2006-11-18
I have a forest with two domains.  The servers are 2000 and 2003.  Recently, the main server that contained the AD-integrated zone data for one of the domains crashed and had to be replaced.  This server was one of two DC that were both Global Catalog servers for this domain.  I created a new server, ran the metadata cleanup brought the server online with a different name and IP address to avaid any conflicts in AD.  

My problem now is that I cannot create an AD-integrated DNS zone on either of the DCs in the Domain.  When I try I get an error that the type is wrong.  I have manually created the GUID records in the main AD-integrated DNS on the first domain to try and force the connection to work but no dice.  

DCdiag shows a slew of RPC server errors which suggests Name/service resolution errors.  This even when I have created a secondary DNS zone from the AD-integrated zone.

Any poiters on this would be greatly appreciated.

0
Comment
Question by:freymish
9 Comments
 
LVL 70

Expert Comment

by:Chris Dent
ID: 16892402

This bit puzzles me a little:

> secondary DNS zone from the AD-integrated zone

It sort of makes me wonder about the error you mentioned earlier on.

What exactly are you trying to make into an AD Integrated Zone? It just sounds a little like you're trying to make a Secondary Zone into an AD Integrated Zone?

If that's not the case can you post the error messages exactly as you have them on the screen for DNS?

Chris
0
 
LVL 4

Author Comment

by:freymish
ID: 16893383
What I meant by:
"secondary DNS zone from the AD-integrated zone"
is that I created a standard secondary zone on a DNS server in the 2nd AD Domain using the AD-Integrated DNS server in the first domain as the Master.

When I tried to create an AD integrated zone on this DC, the error I got was:

"The zone type cannot be created.
The zone type is invalid."

It is significant to note that the server on which I am trying to create the AD integrated zone, cannot connect to the DNS server which holds the FSMO roles. I can ping it by name and number, but I cannot connect to it using the DNS MMC plugin.  This even in light of the fact that I have listed the target servwer as the DNS Primary lookup server on the machine in question.
0
 
LVL 4

Author Comment

by:freymish
ID: 16893577
OK, I have deleted all zones from all servers to start over from scratch.

First I created AD integrated zones for domain1 and domain2 on the server that holds the FSMO roles and they showed up fine with all the service record entries and the like for domain1 and service record entries for the DC on dc1.domain2.   On dc1.domain2 I have created AD-integrated zones for both domains, but no service records show up,  nor do the _mscds, _sites,_tcp_udp, etc.. Maybe if I can solve this problem the others will fall into place.

Meanwhile, I am upping the points because people are starting to encounter issues associated with this.  

Please Help!
0
 
LVL 33

Expert Comment

by:NJComputerNetworks
ID: 16893819
" On dc1.domain2 I have created AD-integrated zones for both domains, but no service records show up,  nor do the _mscds, _sites,_tcp_udp, etc..   "   How does the TCP/Ip settings look on the DC1.domain2?  Where do you have DNS pointing to?  To the what DNS server?    
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 70

Expert Comment

by:Chris Dent
ID: 16893909

If you have a Forest presumably one of your domains is the Parent and the other the child?

The questions NJ has asked are really important though..

Chris
0
 
LVL 4

Author Comment

by:freymish
ID: 16894961
First at the main server in Domain1 (call it DC1.Domain1.example.com) and next to itself.  

As for the parent /child... the parent is Domain1.excample.com and the child is Domain2.example.com
0
 
LVL 4

Author Comment

by:freymish
ID: 16916771
I finally got this working.  I deleted all zones on all DNS servers and waited for AD to do its replication.  I then created the AD-integrated zones on the DC/DNS server in the primary domain and configured it to replicate to all DNS servers in both domains.  On the other DNS servers I made sure the Primary DNS server in the IP configuration was the Forest DNS server and sat back and waited.  Eventually the replication was successful and all is working fine now.

Call this case closed.

Thaks,

Freymish
0
 

Accepted Solution

by:
CetusMOD earned 0 total points
ID: 17125782
PAQed with points refunded (400)

CetusMOD
Community Support Moderator
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Preface Having the need * to contact many different companies with different infrastructures * do remote maintenance in their network required us to implement a more flexible routing solution. As RAS, PPTP, L2TP and VPN Client connections are no…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now