Solved

Problems with W2K Active Directory Domain

Posted on 2007-03-26
5
339 Views
Last Modified: 2010-03-05
I have 2 Windows 2K Servers, with Active Directory. Let's call them BU and EZ. The EZ server (W2K Advanced Server) was the first one I installed so it has the 5 roles. The BU server (W2K Server) was the second and I put it into the same domain. Let's call "NEW" to the domain.

In the EZ server I don't see anything when I get into the DHCP and WINS consoles, giving an error when I double-click the link to them: MMC; snap-in failed to initialize. Name -not available- CLSID: ..... (the same CLSID for both console loading moments). I can access the DNS (Active Directory integrated) without any problem.
Frequently I have NTP problems with this error in the Event Viewer' System Log: "The NTP server didn't respond"; it occurs each 8 hours, with Event ID: 11 and source: w32time.

In the BU server I have may errors related to the EZ server. For example, in many times I can't see the Global Catalog Server (EZ), but not all the time. It neither can contact the NTP server that is the EZ server.
These are the events I get in the Event Viewer' System Log:
- Event ID: 8021, Source: Browser, Description: The browser was unable to retrieve a list of servers from the browser master \\EZ on the network \Device\NetBT_Tcpip_{D54D3D99-7D8C-432F-B289-9D7454B3201B}. The data is the error code.
- Event ID: 11, Source: w32time, Description: The NTP server  didn't respond (periodically come back again)
- Event ID: 8003, Source: MRrxSmb, Description: The master browser has received a server announcement from the computer EZ that believes that it is the master browser for the domain on transport NetBT_Tcpip_{D54D3D99-7D8C-432F-B2. The master browser is stopping or an election is being forced.
These events occured in 12 minutos long.
Ocassional I also see errors with the NetLogon, and from time to time (months between them) I see a Disk error related with the Paging memory.

Can anybody help me with this?
0
Comment
Question by:fsaieg
  • 3
5 Comments
 
LVL 22

Expert Comment

by:rickhobbs
ID: 18798168
Download and run dcdiag from Microsoft and post the results.
0
 
LVL 11

Expert Comment

by:AnthonyP9618
ID: 18804205
From a command prompt on each of the DCs run:

dcdiag /v > C:\dcdiag.txt

Post the results from the file here...
0
 

Author Comment

by:fsaieg
ID: 18805723
Thanks for the answer. Here you are:

First Server BU:

Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.

C:\Documents and Settings\Administrator.NEW>DCDIAG /V

Domain Controller Diagnosis

Performing initial setup:
   * Verifying that the local machine bu, is a DC.
   * Connecting to directory service on server bu.
   * Collecting site info.
   * Identifying all servers.
   * Found 2 DC(s). Testing 1 of them.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\BU
      Starting test: Connectivity
         * Active Directory LDAP Services Check
         * Active Directory RPC Services Check
         ......................... BU passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\BU
      Starting test: Replications
         * Replications Check
         ......................... BU passed test Replications
      Test omitted by user request: Topology
      Test omitted by user request: CutoffServers
      Starting test: NCSecDesc
         * Security Permissions Check for
           CN=Schema,CN=Configuration,DC=new,DC=com,DC=ar
         * Security Permissions Check for
           CN=Configuration,DC=new,DC=com,DC=ar
         * Security Permissions Check for
           DC=new,DC=com,DC=ar
         ......................... BU passed test NCSecDesc
      Starting test: NetLogons
         * Network Logons Privileges Check
         ......................... BU passed test NetLogons
      Starting test: Advertising
         The DC BU is advertising itself as a DC and having a DS.
         The DC BU is advertising as an LDAP server
         The DC BU is advertising as having a writeable directory
         The DC BU is advertising as a Key Distribution Center
         The DC BU is advertising as a time server
         ......................... BU passed test Advertising
      Starting test: KnowsOfRoleHolders
         Role Schema Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         Role Domain Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         Role PDC Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         Role Rid Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         ......................... BU passed test KnowsOfRoleHolders
      Starting test: RidManager
         * Available RID Pool for the Domain is 2602 to 1073741823
         * ez.new.com.ar is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 2102 to 2601
         * rIDNextRID: 2111
         * rIDPreviousAllocationPool is 2102 to 2601
         ......................... BU passed test RidManager
      Starting test: MachineAccount
         * SPN found :LDAP/bu.new.com.ar/new.com.ar
         * SPN found :LDAP/bu.new.com.ar
         * SPN found :LDAP/BU
         * SPN found :LDAP/bu.new.com.ar/NEW
         * SPN found :LDAP/03a4a9f8-fcdc-48b8-96a9-8bfefb0036e0._msdcs.newportcargo.com.ar
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/03a4a9f8-fcdc-48b8-96a9-8bfefb0036e0/new.com.ar
         * SPN found :HOST/bu.new.com.ar/new.com.ar
         * SPN found :HOST/bu.new.com.ar
         * SPN found :HOST/BU
         * SPN found :HOST/bu.new.com.ar/NEW
         * SPN found :GC/bu.new.com.ar/new.com.ar
         ......................... BU passed test MachineAccount
      Starting test: Services
         * Checking Service: Dnscache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: RpcSs
         * Checking Service: RPCLOCATOR
         * Checking Service: w32time
         * Checking Service: TrkWks
         * Checking Service: TrkSvr
         * Checking Service: NETLOGON
         * Checking Service: Dnscache
         * Checking Service: NtFrs
            SMTPSVC Service is stopped on [BU]
         ......................... BU failed test Services
      Test omitted by user request: OutboundSecureChannels
      Starting test: ObjectsReplicated
         BU is in domain DC=new,DC=com,DC=ar
         Checking for CN=BU,OU=Domain Controllers,DC=new,DC=com,DC=ar in domain DC=new,DC=com,DC=ar on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=BU,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar in domain CN=Configuration,DC=new,DC=com,DC=ar on 1 servers
            Object is up-to-date on all servers.
         ......................... BU passed test ObjectsReplicated
      Starting test: frssysvol
         * The File Replication Service Event log test
         The SYSVOL has been shared, and the AD is no longer
         prevented from starting by the File Replication Service.
         ......................... BU passed test frssysvol
      Starting test: kccevent
         * The KCC Event log test
         Found no KCC errors in Directory Service Event log in the last 15 minutes.
         ......................... BU passed test kccevent
      Starting test: systemlog
         * The System Event log test
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/28/2007   01:01:41
            Event String: Driver Brother DCP-110C USB Printer required for printer __192.168.0.4_Brother DCP-110C USB Printer (Copiar 2) is unknown. Contact the administrator to install the driver before you log in again.
         An Error Event occured.  EventID: 0x00000452
            Time Generated: 03/28/2007   01:01:41
            Event String: The printer could not be installed.
         ......................... BU failed test systemlog

   Running enterprise tests on : new.com.ar
      Starting test: Intersite
         Skipping site Default-First-Site-Name, this site is outside the scope
         provided by the command line arguments provided.
         ......................... new.com.ar passed test Intersite
      Starting test: FsmoCheck
         GC Name: \\ez.new.com.ar
         Locator Flags: 0xe00001fd
         PDC Name: \\ez.new.com.ar
         Locator Flags: 0xe00001fd
         Time Server Name: \\bu.new.com.ar
         Locator Flags: 0xe00001f8
         Preferred Time Server Name: \\bu.new.com.ar
         Locator Flags: 0xe00001f8
         KDC Name: \\bu.new.com.ar
         Locator Flags: 0xe00001f8
         ......................... new.com.ar passed test FsmoCheck

C:\Documents and Settings\Administrator.NEW>

Now, Server EZ:

Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.

C:\Documents and Settings\Administrator.EZ.000>dcdiag /v

Domain Controller Diagnosis

Performing initial setup:
   * Verifying that the local machine ez, is a DC.
   * Connecting to directory service on server ez.
   * Collecting site info.
   * Identifying all servers.
   * Found 2 DC(s). Testing 1 of them.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\EZ
      Starting test: Connectivity
         * Active Directory LDAP Services Check
         * Active Directory RPC Services Check
         ......................... EZ passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\EZ
      Starting test: Replications
         * Replications Check
         ......................... EZ passed test Replications
      Test omitted by user request: Topology
      Test omitted by user request: CutoffServers
      Starting test: NCSecDesc
         * Security Permissions Check for
           CN=Schema,CN=Configuration,DC=new,DC=com,DC=ar
         * Security Permissions Check for
           CN=Configuration,DC=new,DC=com,DC=ar
         * Security Permissions Check for
           DC=new,DC=com,DC=ar
         ......................... EZ passed test NCSecDesc
      Starting test: NetLogons
         * Network Logons Privileges Check
         ......................... EZ passed test NetLogons
      Starting test: Advertising
         The DC EZ is advertising itself as a DC and having a DS.
         The DC EZ is advertising as an LDAP server
         The DC EZ is advertising as having a writeable directory
         The DC EZ is advertising as a Key Distribution Center
         The DC EZ is advertising as a time server
         The DS EZ is advertising as a GC.
         ......................... EZ passed test Advertising
      Starting test: KnowsOfRoleHolders
         Role Schema Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         Role Domain Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         Role PDC Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First
-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         Role Rid Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First
-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar
         ......................... EZ passed test KnowsOfRoleHolders
      Starting test: RidManager
         * Available RID Pool for the Domain is 2602 to 1073741823
         * ez.new.com.ar is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 1102 to 1601
         * rIDNextRID: 1151
         * rIDPreviousAllocationPool is 1102 to 1601
         ......................... EZ passed test RidManager
      Starting test: MachineAccount
         * SPN found :LDAP/ez.new.com.ar/new.com.ar
         * SPN found :LDAP/ez.new.com.ar
         * SPN found :LDAP/EZ
         * SPN found :LDAP/ez.new.com.ar/NEW
         * SPN found :LDAP/8ff23483-e5ae-4ba9-9ff4-a6a462d2af4f._msdcs.newportcargo.com.ar
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/8ff23483-e5ae-4ba9-9ff4-a6a462d2af4f/new.com.ar
         * SPN found :HOST/ez.new.com.ar/new.com.ar
         * SPN found :HOST/ez.new.com.ar
         * SPN found :HOST/EZ
         * SPN found :HOST/ez.new.com.ar/NEW
         * SPN found :GC/ez.new.com.ar/new.com.ar
         ......................... EZ passed test MachineAccount
      Starting test: Services
         * Checking Service: Dnscache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: RpcSs
         * Checking Service: RPCLOCATOR
         * Checking Service: w32time
         * Checking Service: TrkWks
         * Checking Service: TrkSvr
         * Checking Service: NETLOGON
         * Checking Service: Dnscache
         * Checking Service: NtFrs
         ......................... EZ passed test Services
      Test omitted by user request: OutboundSecureChannels
      Starting test: ObjectsReplicated
         EZ is in domain DC=new,DC=com,DC=ar
         Checking for CN=EZ,OU=Domain Controllers,DC=new,DC=com,DC=ar in domain DC=new,DC=com,DC=ar on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=EZ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=new,DC=com,DC=ar in domain CN=Configuration,DC=new,DC=com,DC=ar on 1 servers
            Object is up-to-date on all servers.
         ......................... EZ passed test ObjectsReplicated
      Starting test: frssysvol
         * The File Replication Service Event log test
         The SYSVOL has been shared, and the AD is no longer
         prevented from starting by the File Replication Service.
         There are errors after the SYSVOL has been shared.
         The SYSVOL can prevent the AD from starting.
         An Warning Event occured.  EventID: 0x800034C4
            Time Generated: 03/21/2007   09:00:14
            Event String: The File Replication Service is having trouble enabling replication from BU to EZ for
c:\winnt\sysvol\domain using the DNS name bu.new.com.ar. FRS will keep retrying.
 Following are some of the reasons you would see this warning.

 [1] FRS can not correctly resolve the DNS name bu.new.com.ar from this computer.
 [2] FRS is not running on bu.new.com.ar.
 [3] The topology information in the ActiveDirectory for this replica has not yet replicated to all the Domain Controllers.

 This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.
         An Warning Event occured.  EventID: 0x800034C5
            Time Generated: 03/21/2007   09:21:01
            Event String: The File Replication Service has enabled replication from BU to EZ for c:\winnt\sysvol\domain after repeated retries.
         ......................... EZ passed test frssysvol
      Starting test: kccevent
         * The KCC Event log test
         Found no KCC errors in Directory Service Event log in the last 15 minutes.
         ......................... EZ passed test kccevent
      Starting test: systemlog
         * The System Event log test
         Found no errors in System Event log in the last 60 minutes.
         ......................... EZ passed test systemlog

   Running enterprise tests on : new.com.ar
      Starting test: Intersite
         Skipping site Default-First-Site-Name, this site is outside the scope
         provided by the command line arguments provided.
         ......................... new.com.ar passed test Intersite
      Starting test: FsmoCheck
         GC Name: \\ez.new.com.ar
         Locator Flags: 0xe00001fd
         PDC Name: \\ez.new.com.ar
         Locator Flags: 0xe00001fd
         Time Server Name: \\ez.new.com.ar
         Locator Flags: 0xe00001fd
         Preferred Time Server Name: \\ez.new.com.ar
         Locator Flags: 0xe00001fd
         KDC Name: \\ez.new.com.ar
         Locator Flags: 0xe00001fd
         ......................... new.com.ar passed test FsmoCheck

C:\Documents and Settings\Administrator.EZ.000>

Thanks for being answering !!
0
 
LVL 22

Accepted Solution

by:
rickhobbs earned 125 total points
ID: 18808631
It appears you either have DNS issues or the File Replication Service is not running on bu.new.com.ar

First, the DNS
The original DC has DNS setup on it.  In the Network card, the only DNS listed should be itself.  In the DNS manager, the external DNS name servers should be entered under the Forwarders tab.   The only DNS for the new DC should be the first DCs IP address.

As for the FRS service,  it is definitely running.  It is listed in the services in the first DCDiag.

So it is probably the DNS!
0
 
LVL 22

Expert Comment

by:rickhobbs
ID: 19111727
Thanks!  Glad I could help!
0

Join & Write a Comment

INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
Synchronize a new Active Directory domain with an existing Office 365 tenant
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now