Solved

Active directory is not fully functioning.

Posted on 2008-10-25
20
597 Views
Last Modified: 2012-05-05
dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\dc1
      Starting test: Connectivity
         ......................... dc1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\dc1
      Starting test: Replications
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: DC=CBAuto,DC=Pri
            The replication generated an error (8524):
            The DSA operation is unable to proceed because of a DNS lookup failure.
            The failure occurred at 2008-10-25 11:56.48.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
            The guid-based DNS name 8625fa52-da96-4011-bfe3-062699c54942._msdcs.MYDOMAIN
            is not registered on one or more DNS servers.
         [dc2] DsBind() failed with error 1722,
         The RPC server is unavailable..
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: CN=Configuration,DC=CBAuto,DC=Pri
            The replication generated an error (8524):
            The DSA operation is unable to proceed because of a DNS lookup failure.
            The failure occurred at 2008-10-25 11:56.50.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
            The guid-based DNS name 8625fa52-da96-4011-bfe3-062699c54942._msdcs.MYDOMAIN
            is not registered on one or more DNS servers.
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: CN=Schema,CN=Configuration,DC=CBAuto,DC=Pri
            The replication generated an error (8524):
            The DSA operation is unable to proceed because of a DNS lookup failure.
            The failure occurred at 2008-10-25 11:56.53.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
            The guid-based DNS name 8625fa52-da96-4011-bfe3-062699c54942._msdcs.MYDOMAIN
            is not registered on one or more DNS servers.
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: DC=DomainDnsZones,DC=CBAuto,DC=Pri
            The replication generated an error (1256):
            The remote system is not available. For information about network troubleshooting, see Windows Help.
            The failure occurred at 2008-10-25 11:56.48.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
         [Replications Check,dc1] A recent replication attempt failed:
            From dc2 to dc1
            Naming Context: DC=ForestDnsZones,DC=CBAuto,DC=Pri
            The replication generated an error (1256):
            The remote system is not available. For information about network troubleshooting, see Windows Help.
            The failure occurred at 2008-10-25 11:56.48.
            The last success occurred at 2008-10-16 17:45.55.
            213 failures have occurred since the last success.
         ......................... dc1 passed test Replications
      Starting test: NCSecDesc
         ......................... dc1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... dc1 passed test NetLogons
      Starting test: Advertising
         ......................... dc1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... dc1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... dc1 passed test RidManager
      Starting test: MachineAccount
         * dc1 is not a server trust account
         * dc1 is not trusted for account delegation
         ......................... dc1 failed test MachineAccount
      Starting test: Services
            TrkWks Service is stopped on [dc1]
            TrkSvr Service is stopped on [dc1]
         ......................... dc1 failed test Services
      Starting test: ObjectsReplicated
         ......................... dc1 passed test ObjectsReplicated
      Starting test: frssysvol
         Error: No record of File Replication System, SYSVOL started.
         The Active Directory may be prevented from starting.
         ......................... dc1 passed test frssysvol
      Starting test: kccevent
         ......................... dc1 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   10:57:46
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   10:59:46
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   10:59:46
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:14:53
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:14:53
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:29:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:29:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:44:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   11:44:56
            (Event String could not be retrieved)
         ......................... dc1 failed test systemlog

   Running enterprise tests on : MYDOMAIN
      Starting test: Intersite
         ......................... MYDOMAIN passed test Intersite
      Starting test: FsmoCheck
         ......................... MYDOMAIN passed test FsmoCheck

0
Comment
Question by:sj77
  • 10
  • 6
  • 2
  • +2
20 Comments
 

Author Comment

by:sj77
ID: 22804463
dc2 died without being demoted. btw.
0
 
LVL 17

Expert Comment

by:JohnGerhardt
ID: 22804477
You need to get rid of the dead DC
Try..
http://support.microsoft.com/kb/216498
0
 
LVL 17

Expert Comment

by:JohnGerhardt
ID: 22804479
0
 

Author Comment

by:sj77
ID: 22804904
Removing FRS metadata for the selected server.
Unable to find server reference on "CN=dc2,CN=Servers,CN=Default-First-Site-Na
me,CN=Sites,CN=Configuration,DC=MYDOMAIN,DC=DOMAIN-SUFFIX".
LDAP error 0x5e(94 (No result present in message).)
The attempt to remove the FRS settings on CN=dc2,CN=Servers,CN=Default-First-S
ite-Name,CN=Sites,CN=Configuration,DC=MYDOMAIN,DC=DOMAIN-SUFFIX failed because "Element not
found.";
metadata cleanup is continuing.
"CN=dc2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=MYDOMAIN,DC=DOMAIN-SUFFIX" removed from server "DC1"
metadata cleanup:
0
 

Author Comment

by:sj77
ID: 22804962

C:\>dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Connectivity
         ......................... DC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Replications
         ......................... DC1 passed test Replications
      Starting test: NCSecDesc
         ......................... DC1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DC1 passed test NetLogons
      Starting test: Advertising
         ......................... DC1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... DC1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... DC1 passed test RidManager
      Starting test: MachineAccount
         * DC1 is not a server trust account
         * DC1 is not trusted for account delegation
         ......................... DC1 failed test MachineAccount
      Starting test: Services
            TrkWks Service is stopped on [DC1]
            TrkSvr Service is stopped on [DC1]
         ......................... DC1 failed test Services
      Starting test: ObjectsReplicated
         ......................... DC1 passed test ObjectsReplicated
      Starting test: frssysvol
         Error: No record of File Replication System, SYSVOL started.
         The Active Directory may be prevented from starting.
         ......................... DC1 passed test frssysvol
      Starting test: kccevent
         ......................... DC1 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   14:57:46
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   14:59:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   14:59:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:14:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:14:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:29:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:29:56
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   15:42:51
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   15:42:51
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0xC0000021
            Time Generated: 10/25/2008   15:43:32
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0000021
            Time Generated: 10/25/2008   15:43:32
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0000021
            Time Generated: 10/25/2008   15:43:32
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0000021
            Time Generated: 10/25/2008   15:43:32
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   15:44:40
            (Event String could not be retrieved)
         ......................... DC1 failed test systemlog

   Running enterprise tests on : MYDOMAIN
      Starting test: Intersite
         ......................... MYDOMAIN passed test Intersite
      Starting test: FsmoCheck
         ......................... MYDOMAIN passed test FsmoCheck
c:\
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22805044
Is your FRS service started? What errors are you getting in your Event Log?
0
 

Author Comment

by:sj77
ID: 22805172
FRS IS started.

Event Type:      Error
Event Source:      NTDS General
Event Category:      Global Catalog
Event ID:      1126
Date:            10/25/2008
Time:            3:57:01 PM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      DC1
Description:
Active Directory was unable to establish a connection with the global catalog.
 
Additional Data
Error value:
8430 The directory service encountered an internal failure.
Internal ID:
3200c89
 
User Action:
Make sure a global catalog is available in the forest, and is reachable from this domain controller.  You may use the nltest utility to diagnose this problem.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
 

Author Comment

by:sj77
ID: 22805182
Event Type:      Warning
Event Source:      NTDS General
Event Category:      Global Catalog
Event ID:      1655
Date:            10/25/2008
Time:            3:57:01 PM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      DC1
Description:
Active Directory attempted to communicate with the following global catalog and the attempts were unsuccessful.
 
Global catalog:
\\DC1.MYDOMAIN.LOCAL
 
The operation in progress might be unable to continue. Active Directory will use the domain controller locator to try to find an available global catalog server.
 
Additional Data
Error value:
5 Access is denied.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22805227
Look over this link. Is this server a GC? Run a netdiag /fix.

http://www.eventid.net/display.asp?eventid=1126&eventno=656&source=NTDS%20General&phase=1
0
 

Author Comment

by:sj77
ID: 22805289
The DC is a GC.  

Did dcdiag /fix & then stopped and started netlogon.

DCdiag again:

C:\>dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Connectivity
         ......................... DC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Replications
         ......................... DC1 passed test Replications
      Starting test: NCSecDesc
         ......................... DC1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DC1 passed test NetLogons
      Starting test: Advertising
         ......................... DC1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... DC1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... DC1 passed test RidManager
      Starting test: MachineAccount
         * DC1 is not a server trust account
         * DC1 is not trusted for account delegation
         ......................... DC1 failed test MachineAccount
      Starting test: Services
            TrkWks Service is stopped on [DC1]
            TrkSvr Service is stopped on [DC1]
         ......................... DC1 failed test Services
      Starting test: ObjectsReplicated
         ......................... DC1 passed test ObjectsReplicated
      Starting test: frssysvol
         Error: No record of File Replication System, SYSVOL started.
         The Active Directory may be prevented from starting.
         ......................... DC1 passed test frssysvol
      Starting test: kccevent
         ......................... DC1 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:29:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:29:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 10/25/2008   16:42:51
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:44:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:44:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:59:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   16:59:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   17:14:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC0002720
            Time Generated: 10/25/2008   17:14:40
            (Event String could not be retrieved)
         ......................... DC1 failed test systemlog

   Running enterprise tests on : MYDOMAIN.LOCAL
      Starting test: Intersite
         ......................... MYDOMAIN.LOCAL passed test Intersite
      Starting test: FsmoCheck
         ......................... MYDOMAIN.LOCAL passed test FsmoCheck
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22805316
Run this commnad dcdiag /test:MachineAccount. Make sure that DC1 is pointing to itself for DNS. Go into AD and see if you see DC1 in the Domain Controllers OU.

http://support.microsoft.com/kb/833436

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_2003_Active_Directory/Q_23353722.html
0
 
LVL 5

Expert Comment

by:sensored2008
ID: 22806483
what is the ipconfig for both DC1 and DC2
0
 
LVL 21

Expert Comment

by:snusgubben
ID: 22806769
Starting test: MachineAccount
         * DC1 is not a server trust account
         * DC1 is not trusted for account delegation
         ......................... DC1 failed test MachineAccount

Try to run this command from a command prompt:

nltest /sc_change_pwd:<DomainName>

If you receive a Not a server trust account error:

Open ADSI edit (Adsiedit.msc):

Expand Domain.

Expand DC=<DomainName>,DC=<DomainSuffix>.

Expand CN=Domain Controllers.

In the right-hand pane, right-click the domain controller object and press Properties.

Select the Attributes tab.

In the Select a property to view drop-down box, press userAccountControl. Please post what value you got here.

Type 532480 into the Edit Attribute text box and press the Set button.

Close ADSI Edit.

Shutdown and restart your domain controller

Run dcdiag to see if it helped.


SG



0
 

Accepted Solution

by:
sj77 earned 0 total points
ID: 22808412
Got M$ involved.  According to them, IPv6 and member server was the culprit.  Somehow both of these screwed up DNS.

Thanks for the suggestions.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22808797
I thought this was a 2003 server.
0
 

Author Comment

by:sj77
ID: 22809033
It is Win2k3.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22809444
Did you install IPv6?
0
 

Author Comment

by:sj77
ID: 22811792
No.
0
 

Author Comment

by:sj77
ID: 22811804
I promoted a 2008 box to DC so I'm assuming it was installed somehow during that.  (The 2008 box died btw.)
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22811948
OK I see now. I'm glad everything is working.

0

Featured Post

Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

Join & Write a Comment

Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now