Solved

Can not create Mailbox (GAL issue)

Posted on 2008-06-23
18
564 Views
Last Modified: 2012-06-21
I have looked up this error code and everything points to issues with the GAL.  In the ESM, there is a mailbox that doesn't have a network user anymore. When I go to right click on the name, after 2 mins I get this same error. error 0xc007054b Domain not valid.

I am not able to create any new Mailbox either. When try to create  a new user in AD it tells me it can't verify uniqueness of name because the GAL can't be reached.

Global Catalog IS checked on the DC for NTDS properties. However this is an alias name of 21CE9160-7378-4A3C-B3D1-B0713FDD3391._msdcs.(domain name).   This name is NOT pingable.

0
Comment
Question by:MushroomStamp
  • 11
  • 7
18 Comments
 
LVL 23

Expert Comment

by:TheCleaner
ID: 21855611
0
 

Author Comment

by:MushroomStamp
ID: 21856448
I can't use Sembee's solution. The problem with that is, in ESM>Recipient Update Services>, there are 2 entries. RUS(Enterprise Configuration) and RUS (CompanyName). both have proper entries pointing to "Grant" server (our only DC). However, lets say they weren't, when you open the properties and try to <Browse> to find the DC, there is no visible network list to choose from. So I cant' point it to anything even if I want to.

Here's a kicker... I can ping Grant, Exchange is working (people still send/recieve), Remote Logon to exchange box no longer works via Name or IP.  
0
 

Author Comment

by:MushroomStamp
ID: 21860232
I ran DCDIAG from exchange and this is what i got.  Where is it pulling that absurd host name from?

Testing server: Default-First-Site-Name\GRANT
   Starting test: Connectivity
      The host 21ce9160-7378-4a3c-b3d1-b0713fdd3391._msdcs.CompanyName.WoodlandPark could not be resolved to an
      IP address.  Check the DNS server, DHCP, server name, etc
      Although the Guid DNS name (21ce9160-7378-4a3c-b3d1-b0713fdd3391._msdcs.CompanyName.WoodlandPark) couldn't be
      resolved, the server name (grant.Sturman.WoodlandPark) resolved to the IP address (10.10.1.125) and was pingable.
      Check that the IP address is registered correctly with the DNS server.
      ......................... GRANT failed test Connectivity
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 23

Expert Comment

by:TheCleaner
ID: 21860776
That's the unique GUID and should be listed as an Alias(CNAME) under DNS under the _msdcs.domain.com zone in DNS.

If it isn't there then you can create one there as a CNAME, using the GUID and then browse to Grant at the bottom and choose that one.
0
 

Author Comment

by:MushroomStamp
ID: 21861145
I tried that. Under Forward LUZ there is MyDomain. Under the domain is the _msdcs folder. Inside that is an Alias record with the quid. This didnt' seem to change a thing though.

on the Exchange server, I listed the DNS Cache and saw 4 records that didn't resolve they were _ldap._tcp.grant.DOMAIN
_ldap._tcp.gc._msdcs.DOMAIN
_ldap._tcp.default-first-site-name._sites.grant.DOMAIN
_ldap._tcp.default-first-site-name._sites.gc._msdcs.DOMAIN

becasue I didnt' even see these entries in the DNS server, as a test I put them in the HOST file and now resolve. I know this isn't proper and if they are needed, I have NO IDEA how they suddenly dissapeared. This was all working fine till this past weekend.
0
 

Author Comment

by:MushroomStamp
ID: 21865131
I found that all the SRV records are gone from DNS server. I put in the ones for LDAP (tcp/udp) and I can now create users on teh network again. I still can't create Mailbox's. I think because there are no .GC. entries in teh DNS server the global catalog can't be referenced. I dont' know how these records got removed, but I can't find a reference on how manually add the Global Catalog refernces in DNS. I tried turning GC off then on again in hopes it would regenerate the records, but no go. Anyone know how and exactly what the GC entries should be?
0
 
LVL 23

Expert Comment

by:TheCleaner
ID: 21865274
Don't worry about manually recreating them.  Instead, on the DC, do:

netdiag /fix

then

ipconfig /registerdns

and that should create the necessary records.

Let me know.
0
 

Author Comment

by:MushroomStamp
ID: 21865362
I do not see any new records created on DNS. Here is the log file from NetDiag
netdiag.log
0
 

Author Comment

by:MushroomStamp
ID: 21865413
On the exchange I did a display of DNS and see this. Odd there are two same entries and one works and one doesn't. This was after I flushed the dns cache to get  a fresh read.

_ldap._tcp.gc._msdcs.sturman.woodlandpark
----------------------------------------
Record Name . . . . . : _ldap._tcp.gc._msdcs.sturman.woodlandpark
Record Type . . . . . : 1
Time To Live  . . . . : 556216
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 10.10.1.125


_ldap._tcp.gc._msdcs.sturman.woodlandpark
----------------------------------------
Name does not exist.
0
 
LVL 23

Accepted Solution

by:
TheCleaner earned 500 total points
ID: 21865820
The problem appears to be the below in the netdiag.log

Testing DNS
   [FATAL] File \config\netlogon.dns contains invalid DNS entries.        [FATAL] No DNS servers have the DNS records for this DC registered.

The DNS registration is disabled for this interface

--------------

Try this:

1.  On the DC
2.  Go to the NICs installed (are there more than 1 by the way?  It didn't appear there was, but still)
3.  Under TCP/IP properties go to the DNS tab...at the bottom the "Register this connection's addresses in DNS" should be checked...is it?
4.  Make sure DNS addresses at the top of this tab are accurate
5.  If you have a "DNS Suffix for this connection" make sure the "Use this connection's DNS suffix in DNS registration" is checked
6.  do an "ipconfig /registerdns" again and then look in the system log a few minutes later and see if there are any errors posted.  Also check the eventvwr DNS logs.
7.  Do a  "netdiag /test:dns /fix" and post those results

Are the DNS servers AD integrated?  If so, is there more than 1 DC?
0
 

Author Comment

by:MushroomStamp
ID: 21866203
Ok, here is some more data plus a screenshot. It should be able to explain what I see and you most likely will readily see what is missing.
netlogon.dns.log
DCdiag.log
DNS.JPG
0
 

Author Comment

by:MushroomStamp
ID: 21866414
Ok, I checked the register box on DNS tab. There are 3 DNS server entries. 2 are the DNS servers from ISP and 1 is itself 10.10.1.125.  The only thing in DNS eventvwr logs are entries when DNS service starts and the Scavage cyle.  The netdiag fix test displays a dozen failures, however they are all failed to register on the 1 DNS entry for the NIC which is the ISP DNS server.
0
 

Author Comment

by:MushroomStamp
ID: 21866499
Ok, I moved the 10.10.1.125 to the top of the list on the nic, ran the netdiag fix. It generated a bunch of entries on the DNS server (good thing).  Will this order affect grabbing DNS from the ISP?
0
 

Author Comment

by:MushroomStamp
ID: 21866585
Everything Seems to be working now. :)  I am concerned though about the order of the DNS servers.  Let me know what you think. THANK you for all your help in trouble shooting this.
0
 
LVL 23

Expert Comment

by:TheCleaner
ID: 21868918
You shouldn't have the DNS entries for the ISP at all under the NIC.  Those should be in DNS as Forwarders.  The idea is that you check locally for DNS resolution, if it can't be found locally it is sent on to the ISP (for internet browsing, etc.)

The only thing under the local DNS in TCP/IP properties should be local DNS servers.
0
 
LVL 23

Expert Comment

by:TheCleaner
ID: 21868924
BTW, your ISP probably was wondering what just happened when you tried to register all your SRV records with them (prior to you moving 10.10.1.125 to the top).
0
 

Author Comment

by:MushroomStamp
ID: 21869355
There forwarders were/are pointing to the ISP already. So i guess it was a bit redundant. Thanks so much!
0
 
LVL 23

Expert Comment

by:TheCleaner
ID: 21874539
Welcome...glad it was resolved.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange 2013 POP3 2 27
Passive Exchange Mailbox Database copy is failed and suspended, so how? 4 32
Exchange powershell help 2 29
Unified EndPoint Management 1 25
Utilizing an array to gracefully append to a list of EmailAddresses
This article explains how to install and use the NTBackup utility that comes with Windows Server.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question