Solved

Can not create Mailbox (GAL issue)

Posted on 2008-06-23
18
562 Views
Last Modified: 2012-06-21
I have looked up this error code and everything points to issues with the GAL.  In the ESM, there is a mailbox that doesn't have a network user anymore. When I go to right click on the name, after 2 mins I get this same error. error 0xc007054b Domain not valid.

I am not able to create any new Mailbox either. When try to create  a new user in AD it tells me it can't verify uniqueness of name because the GAL can't be reached.

Global Catalog IS checked on the DC for NTDS properties. However this is an alias name of 21CE9160-7378-4A3C-B3D1-B0713FDD3391._msdcs.(domain name).   This name is NOT pingable.

0
Comment
Question by:MushroomStamp
  • 11
  • 7
18 Comments
 
LVL 23

Expert Comment

by:TheCleaner
Comment Utility
0
 

Author Comment

by:MushroomStamp
Comment Utility
I can't use Sembee's solution. The problem with that is, in ESM>Recipient Update Services>, there are 2 entries. RUS(Enterprise Configuration) and RUS (CompanyName). both have proper entries pointing to "Grant" server (our only DC). However, lets say they weren't, when you open the properties and try to <Browse> to find the DC, there is no visible network list to choose from. So I cant' point it to anything even if I want to.

Here's a kicker... I can ping Grant, Exchange is working (people still send/recieve), Remote Logon to exchange box no longer works via Name or IP.  
0
 

Author Comment

by:MushroomStamp
Comment Utility
I ran DCDIAG from exchange and this is what i got.  Where is it pulling that absurd host name from?

Testing server: Default-First-Site-Name\GRANT
   Starting test: Connectivity
      The host 21ce9160-7378-4a3c-b3d1-b0713fdd3391._msdcs.CompanyName.WoodlandPark could not be resolved to an
      IP address.  Check the DNS server, DHCP, server name, etc
      Although the Guid DNS name (21ce9160-7378-4a3c-b3d1-b0713fdd3391._msdcs.CompanyName.WoodlandPark) couldn't be
      resolved, the server name (grant.Sturman.WoodlandPark) resolved to the IP address (10.10.1.125) and was pingable.
      Check that the IP address is registered correctly with the DNS server.
      ......................... GRANT failed test Connectivity
0
 
LVL 23

Expert Comment

by:TheCleaner
Comment Utility
That's the unique GUID and should be listed as an Alias(CNAME) under DNS under the _msdcs.domain.com zone in DNS.

If it isn't there then you can create one there as a CNAME, using the GUID and then browse to Grant at the bottom and choose that one.
0
 

Author Comment

by:MushroomStamp
Comment Utility
I tried that. Under Forward LUZ there is MyDomain. Under the domain is the _msdcs folder. Inside that is an Alias record with the quid. This didnt' seem to change a thing though.

on the Exchange server, I listed the DNS Cache and saw 4 records that didn't resolve they were _ldap._tcp.grant.DOMAIN
_ldap._tcp.gc._msdcs.DOMAIN
_ldap._tcp.default-first-site-name._sites.grant.DOMAIN
_ldap._tcp.default-first-site-name._sites.gc._msdcs.DOMAIN

becasue I didnt' even see these entries in the DNS server, as a test I put them in the HOST file and now resolve. I know this isn't proper and if they are needed, I have NO IDEA how they suddenly dissapeared. This was all working fine till this past weekend.
0
 

Author Comment

by:MushroomStamp
Comment Utility
I found that all the SRV records are gone from DNS server. I put in the ones for LDAP (tcp/udp) and I can now create users on teh network again. I still can't create Mailbox's. I think because there are no .GC. entries in teh DNS server the global catalog can't be referenced. I dont' know how these records got removed, but I can't find a reference on how manually add the Global Catalog refernces in DNS. I tried turning GC off then on again in hopes it would regenerate the records, but no go. Anyone know how and exactly what the GC entries should be?
0
 
LVL 23

Expert Comment

by:TheCleaner
Comment Utility
Don't worry about manually recreating them.  Instead, on the DC, do:

netdiag /fix

then

ipconfig /registerdns

and that should create the necessary records.

Let me know.
0
 

Author Comment

by:MushroomStamp
Comment Utility
I do not see any new records created on DNS. Here is the log file from NetDiag
netdiag.log
0
 

Author Comment

by:MushroomStamp
Comment Utility
On the exchange I did a display of DNS and see this. Odd there are two same entries and one works and one doesn't. This was after I flushed the dns cache to get  a fresh read.

_ldap._tcp.gc._msdcs.sturman.woodlandpark
----------------------------------------
Record Name . . . . . : _ldap._tcp.gc._msdcs.sturman.woodlandpark
Record Type . . . . . : 1
Time To Live  . . . . : 556216
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 10.10.1.125


_ldap._tcp.gc._msdcs.sturman.woodlandpark
----------------------------------------
Name does not exist.
0
Do email signature updates give you a headache?

Do you feel like all of your time is spent managing email signatures? Too busy to visit every user’s desk to make updates? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today!

 
LVL 23

Accepted Solution

by:
TheCleaner earned 500 total points
Comment Utility
The problem appears to be the below in the netdiag.log

Testing DNS
   [FATAL] File \config\netlogon.dns contains invalid DNS entries.        [FATAL] No DNS servers have the DNS records for this DC registered.

The DNS registration is disabled for this interface

--------------

Try this:

1.  On the DC
2.  Go to the NICs installed (are there more than 1 by the way?  It didn't appear there was, but still)
3.  Under TCP/IP properties go to the DNS tab...at the bottom the "Register this connection's addresses in DNS" should be checked...is it?
4.  Make sure DNS addresses at the top of this tab are accurate
5.  If you have a "DNS Suffix for this connection" make sure the "Use this connection's DNS suffix in DNS registration" is checked
6.  do an "ipconfig /registerdns" again and then look in the system log a few minutes later and see if there are any errors posted.  Also check the eventvwr DNS logs.
7.  Do a  "netdiag /test:dns /fix" and post those results

Are the DNS servers AD integrated?  If so, is there more than 1 DC?
0
 

Author Comment

by:MushroomStamp
Comment Utility
Ok, here is some more data plus a screenshot. It should be able to explain what I see and you most likely will readily see what is missing.
netlogon.dns.log
DCdiag.log
DNS.JPG
0
 

Author Comment

by:MushroomStamp
Comment Utility
Ok, I checked the register box on DNS tab. There are 3 DNS server entries. 2 are the DNS servers from ISP and 1 is itself 10.10.1.125.  The only thing in DNS eventvwr logs are entries when DNS service starts and the Scavage cyle.  The netdiag fix test displays a dozen failures, however they are all failed to register on the 1 DNS entry for the NIC which is the ISP DNS server.
0
 

Author Comment

by:MushroomStamp
Comment Utility
Ok, I moved the 10.10.1.125 to the top of the list on the nic, ran the netdiag fix. It generated a bunch of entries on the DNS server (good thing).  Will this order affect grabbing DNS from the ISP?
0
 

Author Comment

by:MushroomStamp
Comment Utility
Everything Seems to be working now. :)  I am concerned though about the order of the DNS servers.  Let me know what you think. THANK you for all your help in trouble shooting this.
0
 
LVL 23

Expert Comment

by:TheCleaner
Comment Utility
You shouldn't have the DNS entries for the ISP at all under the NIC.  Those should be in DNS as Forwarders.  The idea is that you check locally for DNS resolution, if it can't be found locally it is sent on to the ISP (for internet browsing, etc.)

The only thing under the local DNS in TCP/IP properties should be local DNS servers.
0
 
LVL 23

Expert Comment

by:TheCleaner
Comment Utility
BTW, your ISP probably was wondering what just happened when you tried to register all your SRV records with them (prior to you moving 10.10.1.125 to the top).
0
 

Author Comment

by:MushroomStamp
Comment Utility
There forwarders were/are pointing to the ISP already. So i guess it was a bit redundant. Thanks so much!
0
 
LVL 23

Expert Comment

by:TheCleaner
Comment Utility
Welcome...glad it was resolved.
0

Featured Post

The problems with reply email signatures

Do you wish that you could place an email signature under a reply? Well, unfortunately, you can't. That great Exchange/Office 365 signature you've created will just appear at the bottom of an email chain. What a pain! Is there really no way to solve this? Well, there might be...

Join & Write a Comment

Utilizing an array to gracefully append to a list of EmailAddresses
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
how to add IIS SMTP to handle application/Scanner relays into office 365.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now