Solved

Need DNS Help BAD!

Posted on 2006-07-17
28
629 Views
Last Modified: 2008-01-09
I have 2 Servers and a MESS of a DNS... Here are the dcdiag results and if it would be better to demote the second server and promote it again let me know because nobody here has been able to fix this problem.

Server:

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\Administrator>dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SERVER
      Starting test: Connectivity
         ......................... SERVER passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SERVER
      Starting test: Replications
         ......................... SERVER passed test Replications
      Starting test: NCSecDesc
         ......................... SERVER passed test NCSecDesc
      Starting test: NetLogons
         ......................... SERVER passed test NetLogons
      Starting test: Advertising
         ......................... SERVER passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... SERVER passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... SERVER passed test RidManager
      Starting test: MachineAccount
         ......................... SERVER passed test MachineAccount
      Starting test: Services
         ......................... SERVER passed test Services
      Starting test: ObjectsReplicated
         ......................... SERVER passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... SERVER passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... SERVER failed test frsevent
      Starting test: kccevent
         ......................... SERVER passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 07/17/2006   11:28:29
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 07/17/2006   11:28:42
            (Event String could not be retrieved)
         ......................... SERVER failed test systemlog
      Starting test: VerifyReferences
         ......................... SERVER passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : domain
      Starting test: CrossRefValidation
         ......................... domainpassed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... domainpassed test CheckSDRefDom

   Running enterprise tests on : domain.com
      Starting test: Intersite
         ......................... domain.com passed test Intersite
      Starting test: FsmoCheck
         ......................... domain.com passed test FsmoCheck
0
Comment
Question by:ITRick
  • 13
  • 11
  • 4
28 Comments
 

Author Comment

by:ITRick
ID: 17122828
Server2:


Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SERVER2
      Starting test: Connectivity
         ......................... SERVER2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SERVER2
      Starting test: Replications
         ......................... SERVER2 passed test Replications
      Starting test: NCSecDesc
         ......................... SERVER2 passed test NCSecDesc
      Starting test: NetLogons
         Unable to connect to the NETLOGON share! (\\SERVER2\netlogon)
         [SERVER2] An net use or LsaPolicy operation failed with error 1203, No
network provider accepted the given network path..
         ......................... SERVER2 failed test NetLogons
      Starting test: Advertising
         Warning: DsGetDcName returned information for \\server.domain.com, wh
en we were trying to reach SERVER2.
         Server is not responding or is not considered suitable.
         ......................... SERVER2 failed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... SERVER2 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... SERVER2 passed test RidManager
      Starting test: MachineAccount
         ......................... SERVER2 passed test MachineAccount
      Starting test: Services
         ......................... SERVER2 passed test Services
      Starting test: ObjectsReplicated
         ......................... SERVER2 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... SERVER2 passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... SERVER2 failed test frsevent
      Starting test: kccevent
         ......................... SERVER2 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 07/17/2006   11:04:30
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 07/17/2006   11:04:37
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 07/17/2006   11:05:35
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 07/17/2006   11:05:35
            (Event String could not be retrieved)
         ......................... SERVER2 failed test systemlog
      Starting test: VerifyReferences
         ......................... SERVER2 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : domain
      Starting test: CrossRefValidation
         ......................... domainpassed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... domainpassed test CheckSDRefDom

   Running enterprise tests on : domain.com
      Starting test: Intersite
         ......................... domain.com passed test Intersite
      Starting test: FsmoCheck
         ......................... domain.com passed test FsmoCheck

0
 

Author Comment

by:ITRick
ID: 17122846
Server2 Dcdiag /test:dns Results:

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SERVER2
      Starting test: Connectivity
         ......................... SERVER2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SERVER2

DNS Tests are running and not hung. Please wait a few minutes...

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : domain

   Running enterprise tests on : domain.com
      Starting test: DNS
         Test results for domain controllers:

            DC: server2.domain.com
            Domain: domain.com


               TEST: Forwarders/Root hints (Forw)
                  Error:Both root hints and forwarders are not configured. Pleas
e configure either forwarders or roothints

         Summary of DNS test results:

                                            Auth Basc Forw Del  Dyn  RReg Ext
               ________________________________________________________________
            Domain: domain.com
               server2                      PASS PASS FAIL PASS PASS PASS n/a

         ......................... domain.com failed test DNS

0
 
LVL 13

Expert Comment

by:Kini pradeep
ID: 17125033
how are the DNS set up ?
is the DNS AD intgrated ?
do the DNS servers point to themselves for dns and point to the other for secondary ?
the clients should point to the DNS ?DC in the site.
any ISP or trusted domain ip addresses should be added as forwarders.
 can you run dcdiag /v (verbose mode) and netdiag /v (verbose) and paste the out put ?
0
 
LVL 13

Expert Comment

by:Kini pradeep
ID: 17125048
can you check for errors in FRS logs ?
when you type net share on the command prompt of both dc's and check whether the netlogon and sysvol are shared on both dc's. if not chk for FRS errors.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17126181
need some background.....what happened, has this ever worked? just two DC's? what has happened in the last week with your DC's?
0
 

Author Comment

by:ITRick
ID: 17126450
The story:

I had 1 Server running with Exchange and SQL also web sites. This was at the main location. They opened a second location... I installed a 2nd server called server2 and installed AD and attached it to the main location. Everything worked fine until I wanted to setup DFS. At this point it didn't work so someone told me to download Sonar to see what's going on. I installed it on both servers. The reselts were Server could see itself, but not Server2 and Server2 could see itself and server. Someone told me here that I need DNS on server2. So I installed it and thats when everything went NUTS. Now I can't fix it or find someone to help me fix it. So I'm posting here.

Here is the setup:

Server
Exchange
SQL
Web Sites
192.168.0.10
Linksys Tunnel setup between both location
Dedicated Line both locations with 5 Statics at each end.

Server2
Nothing running on it but a small program they use to do sales (DOS)
192.168.1.10
Linksys Tunned setup
Dedicated Line

Antivirus Turned off until problems are fixed.

No Firewalls running and when you go to see if its off and click on settings a window pops up and says "Windows Firewall cannot run because another program or service is running that might use the network address translation component (Ipnat.sys)"

So that's the story behind this mess I have.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17127828
did you mean you installed AD and then connected up....or did install the DC as an additional one in that domain letting AD replicate?
0
 

Author Comment

by:ITRick
ID: 17129357
I was told to add it as a another DC to a Domain. I needed users to replicate between both servers.
The main server had AD the server2 was a stand alone then I added AD to connect to the main server.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17129601
ah good good, though we may have been on different wave lengths for a second!

if possible i would like to demote your second server and get DNS sorted out on one DC first, then we can repromote your other DC, does that sound ok to you?
0
 

Author Comment

by:ITRick
ID: 17130791
Yes sounds good... I've never demoted a server before what steps do I take? And are there any question I will have to answer while demoting?

0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17134590
you simply run dcpromo on the second server, it will ask you if its the last DC in the domain, say no of course, that removes AD completely from that machine

once you have that one gone and are down to one DC, recreate your DNS zones and run dcidag. we can go from there
0
 

Author Comment

by:ITRick
ID: 17145755
I get a message trying to do this:

This Domain controller is a Global Catalog Server. Global Catalogs are used to process user logons. You should make sure other Global catalogs are accessible to users of this domain before removing active directory from this computer.

0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17150687
thats fine, as long as your other DC is a GC then use the DCPROMO /FORCEREMOVAL switch,

then you need to follow this
http://www.petri.co.il/delete_failed_dcs_from_ad.htm
0
 

Author Comment

by:ITRick
ID: 17154213
How do I find out which is a GC?
I can't loose the users and I've heard removing a server will distroy all users and passwords
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17154745
you can check under sites and services - if the old one was your first then it will be a GC

thats not an issue with users.....your DC's arent replicating anyway, your first one will be fine
0
 

Author Comment

by:ITRick
ID: 17170939
Well seems nothing is going for me.

Error:

The Operation Failed Because:

Active Directory could not find another domain controller to transfer the remaining data in directory partition.
0
 
LVL 13

Expert Comment

by:Kini pradeep
ID: 17171311
well do you get this error when trying to demote the dc2 ?
does that directory partition show DC=forestdnszones,dc=xxx,dc=xxx
if thats the case then open the DNS snapin, and right click on the zone created, under properties somewhere there is an option where in you can specify whether it would replicate to all the DC's dns servers in the forest or domain, change that to all the DNS servers in the domain.

what about the other DC is it also a GC ?
what is the reason they have not replicated ?
use repadmin /showreps it should show the last sucessful replication time as well as the reason that it failed replication. I also see that FRS is having a problem. does net share show sysvol and netlogon shared ?
if not then the server would not behave as a DC and hence would fail any LDAP query.
there are other ways to demote the server as well, for example there is product options in the registry under which if you change the product type to
1. LanmanNT (DC)
2. ServerNT (member server)
3. WinNT ( work station)
now if you change the product type to ServerNT and reboot the box it would not behave as a DC, after which you can do a metadata cleanup on the DC1 and then run a DCpromo on the DC2 (promote it to a DUMMY domain and then gracefully demote it) this would remove any traces of the previous domain then you can take a backup from DC1, restore it to a location and use Dcpromo /adv and install from media after which the machines would replicate. if DC1 already has DNS as AD integrated just install DNS on 2 and the dns info gets replicated along when both DC's replicate.no need of creating any zones.

Note: It is always good to keep a system state backup handy when making a change in configuration.
0
 

Author Comment

by:ITRick
ID: 17171460
All I'm trying to do is get these 2 servers talking again... Even since I installed DNS on 2nd server everything went down the tubes.

The problem started when DFS wouldn't work. I ran Sonic to see what the problem was and server 1 couldn't see server2 but Server2 could see itself and server1.

I wish that I could just remove DNS from second server and delete all entries in Server1 in DNS and just fix it, but we know that's too easy and Microsoft wouldn't allow "Easy"

0
 

Author Comment

by:ITRick
ID: 17171475
BTW... The reason for DNS on server2 is someone told me for DFS to work I need to install DNS on server2.

Something is just not setup right somewhere. And this information just seems like too much work. I quess this is what happens when Microsoft tries to copy Novell with AD.

0
 
LVL 13

Expert Comment

by:Kini pradeep
ID: 17171482
well if you want to fix this try to find the root cause,
firts find out how many days its been since last sucessful replication ? and why the replication is failing. if they have not replicated beyond the tombstone then removal of the problem server would be the only option.
check why the replication is failing ?
in dns on both servers find whether both Dc's have registered their guids , the alias CNAME.
find out what error replication is failing on, in ADUC do both DC account show under the DC OU.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17172240
didnt think it would demote gracefully.....try the forceremoval switch
0
 

Author Comment

by:ITRick
ID: 17172427
Got this warning message:


This Domain Controller is a DNS Server. If you remove Active Directory from this computer, all of the DNS data that is stored in Active Directory-intergrated zones will be lost. If you remove Active Directory from this DNS Server, Update the configurations of all computers on your network that refer to IP address of this DNS Server with the IP address of a new DNS Server.

Do you want to continue removing Active Directory from this computer?
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17172479
indeed
0
 

Author Comment

by:ITRick
ID: 17193233
I'm shaking... LOL

When I do this forceremoval switch am I going to loose anything?  Users?  
Something has to screw up after doing this.
If I do this step what do I need to be prepaired for next?
Is cleanup going to be a mess?
How to connect both servers again?

Just want to know what I'm getting into ahead of time before I run this.

0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17197417
:) its ok i know the feeling

your additional DC which is causing all you greif, holds a replica of the original DC's AD DB. You cant kill anything by removing the replica......

the cleanup process takes about 2 mins and is command line based :)

once cleaned we repromote

Unless i cam missing something here this should be painless.....
0
 

Author Comment

by:ITRick
ID: 17241237
Ok... Back from some time off.

What are the steps that I need to do so when I force the removal I can start right away to bring it back online?
0
 
LVL 48

Accepted Solution

by:
Jay_Jay70 earned 500 total points
ID: 17247157
once you have forced the removal then you need to clean

http://www.petri.co.il/delete_failed_dcs_from_ad.htm

you also need to remove, DNS records, Sites and Services Records etc etc etc....

then you can repromote
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17283805
all went well i take it?
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Domain and Forest functional levels 11 63
formating cluster disk 6 63
heat agent push through GPO 2 34
Auto-Enrollment Group Policy 2 37
Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now