Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Active directory is not fully functioning.

Posted on 2008-10-25
20
600 Views
Last Modified: 2012-05-05
dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\dc1
      Starting test: Connectivity
         ......................... dc1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\dc1
      Starting test: Replications
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: DC=CBAuto,DC=Pri
            The replication generated an error (8524):
            The DSA operation is unable to proceed because of a DNS lookup failure.
            The failure occurred at 2008-10-25 11:56.48.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
            The guid-based DNS name 8625fa52-da96-4011-bfe3-062699c54942._msdcs.MYDOMAIN
            is not registered on one or more DNS servers.
         [dc2] DsBind() failed with error 1722,
         The RPC server is unavailable..
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: CN=Configuration,DC=CBAuto,DC=Pri
            The replication generated an error (8524):
            The DSA operation is unable to proceed because of a DNS lookup failure.
            The failure occurred at 2008-10-25 11:56.50.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
            The guid-based DNS name 8625fa52-da96-4011-bfe3-062699c54942._msdcs.MYDOMAIN
            is not registered on one or more DNS servers.
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: CN=Schema,CN=Configuration,DC=CBAuto,DC=Pri
            The replication generated an error (8524):
            The DSA operation is unable to proceed because of a DNS lookup failure.
            The failure occurred at 2008-10-25 11:56.53.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
            The guid-based DNS name 8625fa52-da96-4011-bfe3-062699c54942._msdcs.MYDOMAIN
            is not registered on one or more DNS servers.
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: DC=DomainDnsZones,DC=CBAuto,DC=Pri
            The replication generated an error (1256):
            The remote system is not available. For information about network troubleshooting, see Windows Help.
            The failure occurred at 2008-10-25 11:56.48.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: DC=ForestDnsZones,DC=CBAuto,DC=Pri
            The replication generated an error (1256):
            The remote system is not available. For information about network troubleshooting, see Windows Help.
            The failure occurred at 2008-10-25 11:56.48.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
         ......................... dc1 passed test Replications
      Starting test: NCSecDesc
         ......................... dc1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... dc1 passed test NetLogons
      Starting test: Advertising
         ......................... dc1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... dc1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... dc1 passed test RidManager
      Starting test: MachineAccount
         * dc1 is not a server trust account
         * dc1 is not trusted for account delegation
         ......................... dc1 failed test MachineAccount
      Starting test: Services
            TrkWks Service is stopped on [dc1]
            TrkSvr Service is stopped on [dc1]
         ......................... dc1 failed test Services
      Starting test: ObjectsReplicated
         ......................... dc1 passed test ObjectsReplicated
      Starting test: frssysvol
         Error: No record of File Replication System, SYSVOL started.
         The Active Directory may be prevented from starting.
         ......................... dc1 passed test frssysvol
      Starting test: kccevent
         ......................... dc1 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   10:57:46
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   10:59:46
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   10:59:46
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:14:53
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:14:53
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:29:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:29:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:44:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:44:56
            (Event String could not be retrieved)
         ......................... dc1 failed test systemlog

   Running enterprise tests on : MYDOMAIN
      Starting test: Intersite
         ......................... MYDOMAIN passed test Intersite
      Starting test: FsmoCheck
         ......................... MYDOMAIN passed test FsmoCheck

0
Comment
Question by:sj77
  • 10
  • 6
  • 2
  • +2
20 Comments
 

Author Comment

by:sj77
ID: 22804463
dc2 died without being demoted. btw.
0
 
LVL 17

Expert Comment

by:JohnGerhardt
ID: 22804477
You need to get rid of the dead DC
Try..
http://support.microsoft.com/kb/216498
0
 
LVL 17

Expert Comment

by:JohnGerhardt
ID: 22804479
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 

Author Comment

by:sj77
ID: 22804904
Removing FRS metadata for the selected server.
Unable to find server reference on "CN=dc2,CN=Servers,CN=Default-First-Site-Na
me,CN=Sites,CN=Configuration,DC=MYDOMAIN,DC=DOMAIN-SUFFIX".
LDAP error 0x5e(94 (No result present in message).)
The attempt to remove the FRS settings on CN=dc2,CN=Servers,CN=Default-First-S
ite-Name,CN=Sites,CN=Configuration,DC=MYDOMAIN,DC=DOMAIN-SUFFIX failed because "Element not
found.";
metadata cleanup is continuing.
"CN=dc2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=MYDOMAIN,DC=DOMAIN-SUFFIX" removed from server "DC1"
metadata cleanup:
0
 

Author Comment

by:sj77
ID: 22804962

C:\>dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Connectivity
         ......................... DC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Replications
         ......................... DC1 passed test Replications
      Starting test: NCSecDesc
         ......................... DC1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DC1 passed test NetLogons
      Starting test: Advertising
         ......................... DC1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... DC1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... DC1 passed test RidManager
      Starting test: MachineAccount
         * DC1 is not a server trust account
         * DC1 is not trusted for account delegation
         ......................... DC1 failed test MachineAccount
      Starting test: Services
            TrkWks Service is stopped on [DC1]
            TrkSvr Service is stopped on [DC1]
         ......................... DC1 failed test Services
      Starting test: ObjectsReplicated
         ......................... DC1 passed test ObjectsReplicated
      Starting test: frssysvol
         Error: No record of File Replication System, SYSVOL started.
         The Active Directory may be prevented from starting.
         ......................... DC1 passed test frssysvol
      Starting test: kccevent
         ......................... DC1 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   14:57:46
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   14:59:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   14:59:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:14:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:14:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:29:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:29:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   15:42:51
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   15:42:51
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0xC0000021
            Time Generated: 10/25/2008   15:43:32
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0000021
            Time Generated: 10/25/2008   15:43:32
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0000021
            Time Generated: 10/25/2008   15:43:32
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0000021
            Time Generated: 10/25/2008   15:43:32
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:40
            (Event String could not be retrieved)
         ......................... DC1 failed test systemlog

   Running enterprise tests on : MYDOMAIN
      Starting test: Intersite
         ......................... MYDOMAIN passed test Intersite
      Starting test: FsmoCheck
         ......................... MYDOMAIN passed test FsmoCheck
c:\
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22805044
Is your FRS service started? What errors are you getting in your Event Log?
0
 

Author Comment

by:sj77
ID: 22805172
FRS IS started.

Event Type:      Error
Event Source:      NTDS General
Event Category:      Global Catalog
Event ID:      1126
Date:            10/25/2008
Time:            3:57:01 PM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      DC1
Description:
Active Directory was unable to establish a connection with the global catalog.
 
Additional Data
Error value:
8430 The directory service encountered an internal failure.
Internal ID:
3200c89
 
User Action:
Make sure a global catalog is available in the forest, and is reachable from this domain controller.  You may use the nltest utility to diagnose this problem.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
 

Author Comment

by:sj77
ID: 22805182
Event Type:      Warning
Event Source:      NTDS General
Event Category:      Global Catalog
Event ID:      1655
Date:            10/25/2008
Time:            3:57:01 PM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      DC1
Description:
Active Directory attempted to communicate with the following global catalog and the attempts were unsuccessful.
 
Global catalog:
\\DC1.MYDOMAIN.LOCAL
 
The operation in progress might be unable to continue. Active Directory will use the domain controller locator to try to find an available global catalog server.
 
Additional Data
Error value:
5 Access is denied.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22805227
Look over this link. Is this server a GC? Run a netdiag /fix.

http://www.eventid.net/display.asp?eventid=1126&eventno=656&source=NTDS%20General&phase=1
0
 

Author Comment

by:sj77
ID: 22805289
The DC is a GC.  

Did dcdiag /fix & then stopped and started netlogon.

DCdiag again:

C:\>dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Connectivity
         ......................... DC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Replications
         ......................... DC1 passed test Replications
      Starting test: NCSecDesc
         ......................... DC1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DC1 passed test NetLogons
      Starting test: Advertising
         ......................... DC1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... DC1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... DC1 passed test RidManager
      Starting test: MachineAccount
         * DC1 is not a server trust account
         * DC1 is not trusted for account delegation
         ......................... DC1 failed test MachineAccount
      Starting test: Services
            TrkWks Service is stopped on [DC1]
            TrkSvr Service is stopped on [DC1]
         ......................... DC1 failed test Services
      Starting test: ObjectsReplicated
         ......................... DC1 passed test ObjectsReplicated
      Starting test: frssysvol
         Error: No record of File Replication System, SYSVOL started.
         The Active Directory may be prevented from starting.
         ......................... DC1 passed test frssysvol
      Starting test: kccevent
         ......................... DC1 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:29:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:29:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   16:42:51
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:44:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:44:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:59:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:59:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   17:14:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   17:14:40
            (Event String could not be retrieved)
         ......................... DC1 failed test systemlog

   Running enterprise tests on : MYDOMAIN.LOCAL
      Starting test: Intersite
         ......................... MYDOMAIN.LOCAL passed test Intersite
      Starting test: FsmoCheck
         ......................... MYDOMAIN.LOCAL passed test FsmoCheck
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22805316
Run this commnad dcdiag /test:MachineAccount. Make sure that DC1 is pointing to itself for DNS. Go into AD and see if you see DC1 in the Domain Controllers OU.

http://support.microsoft.com/kb/833436

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_2003_Active_Directory/Q_23353722.html
0
 
LVL 5

Expert Comment

by:sensored2008
ID: 22806483
what is the ipconfig for both DC1 and DC2
0
 
LVL 21

Expert Comment

by:snusgubben
ID: 22806769
Starting test: MachineAccount
         * DC1 is not a server trust account
         * DC1 is not trusted for account delegation
         ......................... DC1 failed test MachineAccount

Try to run this command from a command prompt:

nltest /sc_change_pwd:<DomainName>

If you receive a Not a server trust account error:

Open ADSI edit (Adsiedit.msc):

Expand Domain.

Expand DC=<DomainName>,DC=<DomainSuffix>.

Expand CN=Domain Controllers.

In the right-hand pane, right-click the domain controller object and press Properties.

Select the Attributes tab.

In the Select a property to view drop-down box, press userAccountControl. Please post what value you got here.

Type 532480 into the Edit Attribute text box and press the Set button.

Close ADSI Edit.

Shutdown and restart your domain controller

Run dcdiag to see if it helped.


SG



0
 

Accepted Solution

by:
sj77 earned 0 total points
ID: 22808412
Got M$ involved.  According to them, IPv6 and member server was the culprit.  Somehow both of these screwed up DNS.

Thanks for the suggestions.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22808797
I thought this was a 2003 server.
0
 

Author Comment

by:sj77
ID: 22809033
It is Win2k3.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22809444
Did you install IPv6?
0
 

Author Comment

by:sj77
ID: 22811792
No.
0
 

Author Comment

by:sj77
ID: 22811804
I promoted a 2008 box to DC so I'm assuming it was installed somehow during that.  (The 2008 box died btw.)
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22811948
OK I see now. I'm glad everything is working.

0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question