Avatar of mpeacockbc
mpeacockbc
Flag for Canada asked on

Exchange 2007 SP1 System Attendant Not Starting (auto or manual)

Hi All
I have been working on this issue for a few hours now and could do with some more ideas!

Topology:
Windows Server 2003 R2 - "DC01" - DC, DNS, DHCP, WINS, Global Catalog
Windows Server 2003 R2 - "EX01" - Exchange 2007, MS CRM
Windows Server 2003 R2 - "SQL01" - MS SQL 2005

Issue: Originally I noticed that the Exchange Management Console MMC wasnt working. When i start it up, it tells me that it cant find the Domain Controller.
(yet I logged in with a domain account, I can ping bot the IP and DNS name of DC01, and %logonserver% is DC01)

After some reading i found this could be caused by the system attendant not running - I checked and it wasnt. Attempting to restart it results in a failure and the event:

MSExchangeSA
Event ID: 1005
Unexpected error The specified domain either does not exist or could not be contacted. Facility: Win32 ID no: c007054b Microsoft Exchange System Attendant  occurred.

Then:
1004
Microsoft Exchange System Attendant failed to start.

After some more reading I found that this could be because it cant find the Global Catalog server - so I checked and DC01 is enabled as a catalog server.

A few moments later in teh EX01 event log, the following event is logged:

MSExchangeADAccess
2080
Process STORE.EXE (PID=4964). Exchange Active Directory Provider has discovered the following servers with the following characteristics:
 (Server name | Roles | Enabled | Reachability | Synchronized | GC capable | PDC | SACL right | Critical Data | Netlogon | OS Version)
In-site:
DC01.headoffice.valley.local      CDG 1 7 7 1 0 1 1 7 1
 Out-of-site:
 
Looking at this, it has found a GC capable DC!

Side Note:
Yesterday we had a small issue with the DNS server not having any records in it - which I suspect was because of a change made to the scavanging settings last week. I have disabled scavenging and the all of the network devices have reregistered their dns entries.

So im thinking that there could be some other issue preventing the communication with the DC.

Users are still able to send and receive email - the only issue i have so far is not being able to access the MMC console for Exchange. (and wouldnt you know it - I have mailbox admin to do today!).

Only one error on the DC01 DNS event log :
DNS
4015
The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly. The extended error debug information (which may be empty) is "". The event data contains the error.

which I have found means that DNS started before AD - therefore couldnt connect.

I have tried flushing the DNS cache and re-registering the DNS for EX01 - no change.

Any pointers or ideas would be appreciated.
Both server have been restarted (as of this morning - no change)

Thanks in advance.
Matt
ExchangeWindows Server 2003

Avatar of undefined
Last Comment
mpeacockbc

8/22/2022 - Mon
mpeacockbc

ASKER
I should also add that my ldap._tcp._msdcs.<etc> and _gc._tcp._msdcs.<etc> (SRV) records exist in the DNS server.

mpeacockbc

ASKER
Some additional information;

exact error from the MMC when trying to load the mailboxes;

--------------------------------------------------------
Microsoft Exchange Error
--------------------------------------------------------
The following error(s) were reported while loading topology information:

get-ExchangeServer
Failed
Error:
Could not find any Domain Controller in domain headoffice.valley.local.

Domain controller not found in the domain "headoffice.valley.local".

get-UMServer
Failed
Error:
Could not find any Domain Controller in domain headoffice.valley.local.

Domain controller not found in the domain "headoffice.valley.local".
mpeacockbc

ASKER
running NetDiag on my exchange server looks like the DNS is ok - but running it on my DC returns that it isnt registered properly!

NET DIAG Results from DC01
------------------------------------------------------------------
Netcard queries test . . . . . . . : Passed
Per interface results:
    Adapter : Team NICS
        Netcard queries test . . . : Passed
        Host Name. . . . . . . . . : DC01
        IP Address . . . . . . . . : 192.168.<local IP DC01>
        Subnet Mask. . . . . . . . : 255.255.255.0
        Default Gateway. . . . . . : 192.168.<local IP GATEWAY>
        Dns Servers. . . . . . . . : 192.168.<local IP DC01>
        AutoConfiguration results. . . . . . : Passed
        Default gateway test . . . : Passed
        NetBT name test. . . . . . : Passed
        WINS service test. . . . . : Skipped
            There are no WINS servers configured for this interface.
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
   List of NetBt transports currently configured:
        NetBT_Tcpip_{0FDD70C0-33C2-4026-845A-6845BDDCF72C}
    1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Failed
    [WARNING] The DNS entries for this DC are not registered correctly on DNS server '192.168.0.12'. Please wait for 30 minutes for DNS server replication.
    [FATAL] No DNS servers have the DNS records for this DC registered.
Redir and Browser test . . . . . . : Passed
    List of NetBt transports currently bound to the Redir
        NetBT_Tcpip_{0FDD70C0-33C2-4026-845A-6845BDDCF72C}
    The redir is bound to 1 NetBt transport.
    List of NetBt transports currently bound to the browser
        NetBT_Tcpip_{0FDD70C0-33C2-4026-845A-6845BDDCF72C    The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Skipped
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
    No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Skipped
    Note: run "netsh ipsec dynamic show /?" for more detailed information
The command completed successfully


NET DIAG Results from EX01
------------------------------------------------------------------

Netcard queries test . . . . . . . : Passed
    [WARNING] The net card 'TEAM : LAN_Team - Intel(R) PRO/1000 PT Server Adapter' may not be working.
Per interface results:
   Adapter : LAN_Team (AFT)
        Netcard queries test . . . : Passed
        Host Name. . . . . . . . . : EX01
        IP Address . . . . . . . . : 192.168.<local IP address EX01>
        Subnet Mask. . . . . . . . : 255.255.255.0
        Default Gateway. . . . . . : 192.168.<local IP address Gateway>
        Primary WINS Server. . . . : 192.168.<local IP address DC01>
        Dns Servers. . . . . . . . : 192.168.<local IP address DC01>
        AutoConfiguration results. . . . . . : Passed
        Default gateway test . . . : Passed
        NetBT name test. . . . . . : Passed
            No names have been found.
        WINS service test. . . . . : Passed
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
   List of NetBt transports currently configured:
        NetBT_Tcpip_{C230840C-14FD-4D60-929F-AF0DDDAB3CF8}
    1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
    [WARNING] You don't have a single interface with the <00> 'WorkStation Service', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
Redir and Browser test . . . . . . : Failed
   List of NetBt transports currently bound to the Redir
        NetBT_Tcpip_{C230840C-14FD-4D60-929F-AF0DDDAB3CF8}
    The redir is bound to 1 NetBt transport.
   List of NetBt transports currently bound to the browser
        NetBT_Tcpip_{C230840C-14FD-4D60-929F-AF0DDDAB3CF8}
    The browser is bound to 1 NetBt transport.
    [FATAL] Cannot send mailslot message to 'VALLEY*' via browser. [ERROR_INVALID_FUNCTION]
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Passed
   Secure channel for domain 'VALLEY' is to '\\DC01'.
kerberos test. . . . . . . . . . . : Failed
    [FATAL] Cannot lookup package Kerberos.
    The error occurred was: (null)
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
   No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Skipped
    Note: run "netsh ipsec dynamic show /?" for more detailed information
The command completed successfully

I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
SOLUTION
Speshalyst

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
mpeacockbc

ASKER
The more I look into this issue, it looks like a DC problem in the DNS.

Running DCDiag informs me that the site\DC is not registered to an IP address in DNS.

I am going to try my luck following this avenue but will update this question/thread as I learn more.

ASKER CERTIFIED SOLUTION
mpeacockbc

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.