Solved

Major active directory failure of Domain Controller...

Posted on 2008-10-02
6
1,302 Views
Last Modified: 2012-05-05
Error Log Listed below...

I can still log in with admin accounts and DNS and IIS is still working. When attempting to access Active Dir. I receive error...
Naming information cannot be located because:
The specified domain does not exist or could not be contacted.
Also...
The directory Schema is not accessable because:
An invalid directory name was passed
For this reason the new menu my be inaccurate and extention snapins ,y not work properly...

How can this recovered...there was some mention someware of reversing the data that was hidden and tombstone time...

C:\Program Files\Support Tools>dcdiag.exe

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\CLI-PDC-01
      Starting test: Connectivity
         ......................... CLI-PDC-01 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\CLI-PDC-01
      Starting test: Replications
         [Replications Check,CLI-PDC-01] A recent replication attempt failed: From MAIL to CLI-PDC-01
            Naming Context: DC=ForestDnsZones,DC=cli-pdc-01,DC=computerlogistics,DC=us
            The replication generated an error (1256):
            The remote system is not available. For information about network troubleshooting, see Windows Help.
            The failure occurred at 2008-10-02 18:46:12.
            The last success occurred at 2006-02-25 12:57:32.
            22710 failures have occurred since the last success.
         [MAIL] DsBindWithSpnEx() failed with error 1722,
         The RPC server is unavailable..
         [Replications Check,CLI-PDC-01] A recent replication attempt failed:
            From MAIL to CLI-PDC-01
            Naming Context: DC=DomainDnsZones,DC=cli-pdc-01,DC=computerlogistics,DC=us
            The replication generated an error (1256):
            The remote system is not available. For information about network troubleshooting, see Windows Help.
            The failure occurred at 2008-10-02 18:46:12.
            The last success occurred at 2006-02-25 13:40:45.
            22710 failures have occurred since the last success.
         [Replications Check,CLI-PDC-01] A recent replication attempt failed:
            From MAIL to CLI-PDC-01
            Naming Context: CN=Schema,CN=Configuration,DC=cli-pdc-01,DC=computerlogistics,DC=us
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2008-10-02 18:46:54.
            The last success occurred at 2006-02-25 12:57:32.
            22709 failures have occurred since the last success.
            The source remains down. Please check the machine.
         [Replications Check,CLI-PDC-01] A recent replication attempt failed: From MAIL to CLI-PDC-01
            Naming Context: CN=Configuration,DC=cli-pdc-01,DC=computerlogistics,DC=us
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2008-10-02 18:46:33.
            The last success occurred at 2006-02-25 13:33:05.
            22710 failures have occurred since the last success.
            The source remains down. Please check the machine.
         [Replications Check,CLI-PDC-01] A recent replication attempt failed:
            From MAIL to CLI-PDC-01
            Naming Context: DC=cli-pdc-01,DC=computerlogistics,DC=us
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2008-10-02 18:46:12.
            The last success occurred at 2006-02-25 13:37:22.
            22710 failures have occurred since the last success.
            The source remains down. Please check the machine.
         REPLICATION-RECEIVED LATENCY WARNING
         CLI-PDC-01:  Current time is 2008-10-02 19:15:09.
            DC=ForestDnsZones,DC=cli-pdc-01,DC=computerlogistics,DC=us
               Last replication recieved from MAIL at 2006-02-25 12:57:32.
               WARNING:  This latency is over the Tombstone Lifetime of 180 days
!
            DC=DomainDnsZones,DC=cli-pdc-01,DC=computerlogistics,DC=us
               Last replication recieved from MAIL at 2006-02-25 13:40:45.
               WARNING:  This latency is over the Tombstone Lifetime of 180 days
!
            CN=Schema,CN=Configuration,DC=cli-pdc-01,DC=computerlogistics,DC=us
               Last replication recieved from MAIL at 2006-02-25 12:57:32.
               WARNING:  This latency is over the Tombstone Lifetime of 180 days
!
            CN=Configuration,DC=cli-pdc-01,DC=computerlogistics,DC=us
               Last replication recieved from MAIL at 2006-02-25 13:33:05.
               WARNING:  This latency is over the Tombstone Lifetime of 180 days
!
            DC=cli-pdc-01,DC=computerlogistics,DC=us
               Last replication recieved from MAIL at 2006-02-25 13:37:22.
               WARNING:  This latency is over the Tombstone Lifetime of 180 days
!
         ......................... CLI-PDC-01 passed test Replications
      Starting test: NCSecDesc
         ......................... CLI-PDC-01 passed test NCSecDesc
      Starting test: NetLogons
         [CLI-PDC-01] An net use or LsaPolicy operation failed with error 1203,
No network provider accepted the given network path..
         ......................... CLI-PDC-01 failed test NetLogons
      Starting test: Advertising
         Fatal Error:DsGetDcName (CLI-PDC-01) call failed, error 1355
         The Locator could not find the server.
         ......................... CLI-PDC-01 failed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... CLI-PDC-01 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... CLI-PDC-01 passed test RidManager
      Starting test: MachineAccount
         Could not open pipe with [CLI-PDC-01]:failed with 1203: No network prov
ider accepted the given network path.
         Could not get NetBIOSDomainName
         Failed can not test for HOST SPN
         Failed can not test for HOST SPN
         * Missing SPN :(null)
         * Missing SPN :(null)
         ......................... CLI-PDC-01 failed test MachineAccount
      Starting test: Services
         Could not open Remote ipc to [CLI-PDC-01]:failed with 1203: No network
provider accepted the given network path.
         ......................... CLI-PDC-01 failed test Services
      Starting test: ObjectsReplicated
         ......................... CLI-PDC-01 passed test ObjectsReplicated
      Starting test: frssysvol
         [CLI-PDC-01] An net use or LsaPolicy operation failed with error 1203,
No network provider accepted the given network path..
         ......................... CLI-PDC-01 failed test frssysvol
      Starting test: frsevent
         ......................... CLI-PDC-01 failed test frsevent
      Starting test: kccevent
         Failed to enumerate event log records, error No network provider accept
ed the given network path.
         ......................... CLI-PDC-01 failed test kccevent
      Starting test: systemlog
         Failed to enumerate event log records, error No network provider accept
ed the given network path.
         ......................... CLI-PDC-01 failed test systemlog
      Starting test: VerifyReferences
         ......................... CLI-PDC-01 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : cli-pdc-01
      Starting test: CrossRefValidation
         ......................... cli-pdc-01 passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... cli-pdc-01 passed test CheckSDRefDom

   Running enterprise tests on : cli-pdc-01.computerlogistics.us
      Starting test: Intersite
         ......................... cli-pdc-01.computerlogistics.us passed test Intersite
      Starting test: FsmoCheck
         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355
         A Global Catalog Server could not be located - All GC's are down.
         Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355
         A Primary Domain Controller could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1355
         A Good Time Server could not be located.
         Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1355
         A KDC could not be located - All the KDCs are down.
         ......................... cli-pdc-01.computerlogistics.us failed test FsmoCheck

C:\Program Files\Support Tools>
0
Comment
Question by:computerlogistics
6 Comments
 
LVL 6

Expert Comment

by:Hardeep_Saluja
ID: 22631236
Hello computerlogictic,

On the DC do "net share" , i think your sysvol and netlogon will not be shared in this scenario
If it does not.. You have 2 DC's >  MAIL and CLI-PDC-01
Take backup of Sysvol from DC which has good data
Follow Kb 315457: (this part):

On all domain controllers except the reference domain controller, configure the FRS to be non-authoritative. To do this, follow these steps: 1. Click Start, click Run, type regedit, and then click OK.  
2. Locate and then click the BurFlags entry under the following registry subkey:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtFrs\Parameters\Cumulative Replica Sets\GUID
GUID is the GUID of the domain system volume replica set that is shown in the following registry subkey:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtFrs\Parameters\Replica Sets\GUID
3. On the Edit menu, point to New, and then click DWORD Value.  
4. Type D2 for the name of the DWORD, and then press ENTER.

Do D4 on a DC which has all data in sysvol and do D4 on server which is problematic
Make sure to stop frs service before you do so .. and after you change the value to d4 or d2.. restart frs service

This should take care of your issue
Please let me know,
Thanks
Hardeep

0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 250 total points
ID: 22632108

> Do D4 on a DC which has all data in sysvol and do D4 on server which is problematic
 
Hardeep, your instructions are not clear. D4 is Authoritative restore mode. This is the KB article that clearly documents the process described above:

http://support.microsoft.com/kb/290762

But I really don't think that will help in the slightest.

This is important:

>                WARNING:  This latency is over the Tombstone Lifetime of 180 days

And:

> The last success occurred at 2006-02-25 12:57:32

Which server currently holds the FSMO roles?

Chris
0
 
LVL 4

Expert Comment

by:lscapa
ID: 22634207
See http://support.microsoft.com/kb/234790 for locating your FSMO roles. Also run the MPSreports for Directory Services and post the zip it'll show in depth information of replication states, shares, sysvol and other really good stuff to know in this situation. Provide it from both DC's. It will provide domain information but no passwords or other sensitive information.
http://www.microsoft.com/downloads/details.aspx?familyid=cebf3c7c-7ca5-408f-88b7-f9c79b7306c0&displaylang=en
Make sure you get the one for Directory Services...
0
 
LVL 4

Assisted Solution

by:ckozloski
ckozloski earned 250 total points
ID: 22636467
Looks like your replication failed and the server tombstoned on you. You will need to transfer FMSO roles to another DC in your domain.

I had a problem like this and the tombstoned server was up enough to transfer the GC over to another server. Then I dcpromo'd the culprit down and reinstalled AD. It replicated and fixed the problem.

Don't know if you'll be able to do that, but it might be worth a shot.
0
 
LVL 6

Expert Comment

by:Hardeep_Saluja
ID: 23138659
Hiiii .. any update or any other information you require, please let me know
Hope above information helped :)
0

Join & Write a Comment

As companies replace their old PBX phone systems with Unified IP Communications, many are finding out that legacy applications such as fax do not work well with VoIP. Fortunately, Cloud Faxing provides a cost-effective alternative that works over an…
Resolve DNS query failed errors for Exchange
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now