• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 880
  • Last Modified:

DCPROMO DNS error

Experts,

I want add win2008 as additional dc so first I ran adprep/forestprep and /domain prep on win2003 and it wen succesfully, then I did dcpromo on win2008 went through wizard and at end I am getting attached error, can someone please help me out.

Thank you so kindly.
ErrorDNS2-14-2009-2-09-36-PM.jpg
0
Nirav04
Asked:
Nirav04
  • 6
  • 6
1 Solution
 
Mike KlineCommented:
I haven't run into this error, so I'll see what I can find.  There is some discussion here:
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/a1e66bf9-1785-4580-bdba-2470c84e768b/
 
0
 
Nirav04Author Commented:
After clicking ok on this error I rebooted all the DC's and attached is the screenshots of logs, looks like it is working okay, how can I check for sure.

DNSLogs.jpg
0
 
Nirav04Author Commented:
FRS, and directory services screenshots

Directoryservicelog.jpg
FRSLog.jpg
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 
Mike KlineCommented:
13508 with the 13509 is fine, if the509's were not there then that would need to be investigated.
Did you make this new 2008 box a Global Catalog too?
Run a dcdiag to check for errors.
Verify that your 2008 server and SRV records for it are in DNS.
You can check the dcpromo.log file too.
You can also forcre replication through sites and services or using repadmin.  Create a test account on the 2003 box just to verify again (make sure it appears in aduc on the 2008 box)
I think you are going to be ok here.
Thanks
Mike
0
 
Nirav04Author Commented:
I ran DCdiag on 2008

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = ADV-DC1
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\ADV-DC1
      Starting test: Connectivity
         ......................... ADV-DC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\ADV-DC1
      Starting test: Advertising
         ......................... ADV-DC1 passed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... ADV-DC1 passed test FrsEvent
      Starting test: DFSREvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... ADV-DC1 failed test DFSREvent
      Starting test: SysVolCheck
         ......................... ADV-DC1 passed test SysVolCheck
      Starting test: KccEvent
         ......................... ADV-DC1 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... ADV-DC1 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... ADV-DC1 passed test MachineAccount
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=ForestDnsZones,DC=col,DC=cmpminc,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=DomainDnsZones,DC=col,DC=cmpminc,DC=com
         ......................... ADV-DC1 failed test NCSecDesc
      Starting test: NetLogons
         ......................... ADV-DC1 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... ADV-DC1 passed test ObjectsReplicated
      Starting test: Replications
         ......................... ADV-DC1 passed test Replications
      Starting test: RidManager
         ......................... ADV-DC1 passed test RidManager
      Starting test: Services
         ......................... ADV-DC1 passed test Services
      Starting test: SystemLog
         An Error Event occurred.  EventID: 0x000016AD
            Time Generated: 02/14/2009   16:34:25
            Event String:
            The session setup from the computer NAS-01 failed to authenticate. T
he following error occurred:
         ......................... ADV-DC1 failed test SystemLog
      Starting test: VerifyReferences
         ......................... ADV-DC1 passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : col
      Starting test: CheckSDRefDom
         ......................... col passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... col passed test CrossRefValidation

   Running enterprise tests on : col.cmpminc.com
      Starting test: LocatorCheck
         ......................... col.cmpminc.com passed test LocatorCheck
      Starting test: Intersite
         ......................... col.cmpminc.com passed test Intersite

Some errors can you please help
0
 
Mike KlineCommented:
Looks like  you need to run the adprep /rodcprep switch too (even though you don't have an RODC)
 
http://smtp25.blogspot.com/2008/08/replicating-directory-changes-in.html
 
running adprep /rodcprep  won't do any damage (it is safe to run)
Thanks
Mike
0
 
Nirav04Author Commented:
mkline, So far I have done following
There were two 2003 DC, added one 2008DC rebooted all DC's then turned of server1(FSMO ROLES) to check client PC can login to 2008 dc it was succesfull. I turned server1(FSMO) back on then ran dcpromo on second DC (2003) and demoted went succesfull, so now I have two DC's one 2003(FSMO role holder) and second DC 2008.
Now I need to run adprep/rodcprep on 2003(FSMO) correct?
This will not create any issues since I have 2003 server on domain? and in near future when I add another 2008 DC transfer FSMO to 2008 and raise domain function level to 2008?
Just need to make sure.
Can you also tell me what are this errors:
Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... ADV-DC1 passed test FrsEvent

and this

Starting test: DFSREvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... ADV-DC1 failed test DFSREvent

0
 
Mike KlineCommented:
Because you have that 13509 event you don't have to worry about those 13508 sysvol warnings
http://technet.microsoft.com/en-us/library/bb727056.aspx#EMAA
"A single FRS event ID 13508 does not mean anything is broken or not working, as long as it is followed by FRS event ID 13509, which indicates that the problem was resolved."
/rodcprep should not cause issues
Thanks
Mike
0
 
Nirav04Author Commented:
Thank you for taking time. I also found this which basically says if I do not plan to run RODC then just ignore this errors, it is on third paragraph
http://technet.microsoft.com/en-us/library/cc754463.aspx
0
 
Mike KlineCommented:
Yeah you can safely ignore them if you want,  either way is ok.  If the errors start to annoy you then you can run the /rodcprep later
0
 
Nirav04Author Commented:
Thank you very much.
0
 
Mike KlineCommented:
No problem, glad to help out and great job on getting a 2008 domain controller into your live network!!
Thanks
Mike
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

  • 6
  • 6
Tackle projects and never again get stuck behind a technical roadblock.
Join Now