DNS issue on AD domain
Posted on 2008-11-18
Hello, I have an active directory set up that is extremly simple... Or so I thought. The AD serves approximatley 60 or so workstations and 8 or so member servers.
There is only one DC, the DC is running DNS.
Every so often I get errors on workstations that won't process GPO's because, well:
>Group Policy Infrastructure failed due to the error listed below.
>The specified domain either does not exist or could not be contacted.
>Note: Due to the GP Core failure, none of the other Group Policy components processed their policy. >Consequently, status information for the other components is not available
When I sit at my DC/DNS server and run dcdiag everything comes up green.
When I run netdiag /q I get DNS failure:
[WARNING] The DNS entries for this DC are not registered correctly on DNS server '192.168.10.51'. Please wait for 30 minutes for DNS server replication.
When I run a netdiag /fix I get:
[FIX] re-register DC DNS entry 'mydomainname.com.' on the DNS server '192.168.10.51' succeed.
FIX PASS - netdiag re-registered missing DNS entriesfor this DC successfully on server '192.168.10.51'.
[FATAL No DNS servers have the DNS records for this DC registered.
I wonder what I am missing. It says it fixes but then is still broken?
I have to assume that the errors I get on workstations and servers such as:
-Windows cannot determine the user or computer name. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.
-Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.
I dont get these errors on every workstation/server on my domain, in fact most have no issues at all. There is also nothing common amongst the devices getting these issues, some are servers, some are workstations, some are on one subnet, some are on another, different OS's different hardware.
I am at a loss and do not know enough about DNS to fix this on my own.
Also on my DNS MMC I get DNS errors such as this:
Source:DNS Event ID 3000 - The DNS server has encountered numerous run-time events. To determine the initial cause of these run-time events, examine the DNS server event log entries that precede this event. To prevent the DNS server from filling the event log too quickly, subsequent events with Event IDs higher than 3000 will be suppressed until events are no longer being generated at a high rate.
Source:DNS Event ID 4015 - The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly. The extended error debug information (which may be empty) is "". The event data contains the error.
Source:DNS Event ID 4004 - The DNS server was unable to complete directory service enumeration of zone .. This DNS server is configured to use information obtained from Active Directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be empty) is "". The event data contains the error.
I get 4004 errors for each zone it cannot load.
Can anyone assist?