Solved

What is the impact of Reloading a zone on DNS server

Posted on 2009-04-01
10
821 Views
Last Modified: 2012-05-06
I have been battling a very strange situation of trying to simply add another Domain controller to the network. When I run DCPROMO everything seems to go well, but I am missing OU's and content from the OU's that have replicated. On the new server called newDC this is the error under DNS event.  

The DNS server was unable to open zone CCL.local in the Active Directory from the application directory partition DomainDnsZones.CCL.local. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code.

On the current Domain controller with DNS installed, If I reload the zone, what impact will that have on all DNS entries?
Does anyone have any ideas?
0
Comment
Question by:camoIT
  • 4
  • 4
  • 2
10 Comments
 
LVL 70

Expert Comment

by:Chris Dent
ID: 24039529

> If I reload the zone, what impact will that have on all DNS entries?

None, they should have been written back to AD anyway. A reload would occur whenever you restarted the DNS service or the server anyway.

You might consider running DCDiag / NetDiag considering some of the issues you describe.

Chris
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24039564
Are you running AD integrated DNS?
How is that server configured for DNS (Is it pointing to itself for primary DNS or pointing to another DC for primary DNS)
Are there 4015 errors in your logs?
No issues if you reload the zone.
Thanks
Mike
0
 
LVL 2

Author Comment

by:camoIT
ID: 24039627
Mike / Chris

I am the NA. As you can see there is only one Domain Controller. Windows 2003 Stnd R2.

I purchased a new server HP PRoliant DL360 and loaded Windows 2003 Stnd R2, to add to the domain, then promote, then sending back the original DC to D_LL :)

I am receiving 4001, 4007 event ID's.
 Question: The moment I set foot in here, I purchased and installed Backup Exec 12.5 and have everything backed up to tape. Is there a way I can recreate the domain without loosing SIDS, if running this promotion fails??
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 24039702

Recreating the domain is unlikely to be necessary except where we're suffered from a really catestrophic failure.

If it's having problems promoting DCDiag, NetDiag and browsing the Event Logs are the best starting points. They will quickly highlight the most serious errors that may need to be given a little attention.

Chris
0
 
LVL 2

Author Comment

by:camoIT
ID: 24040010
Application Logs on Domain Controller
1.MS DTC could not correctly process a DC Promotion/Demotion event. MS DTC will continue to function and will use the existing security settings. Error Specifics: %1

2. MS DTC could not correctly process a DC Promotion/Demotion event. MS DTC will continue to function and will use the existing security settings. Error Specifics: d:\nt\com\complus\dtc\dtc\adme\uiname.cpp:9351, Pid: 1216
No Callstack,
 CmdLine: C:\WINDOWS\system32\msdtc.exe

DNS Server
3.The DNS server was unable to complete directory service enumeration of zone conexsys.net.  This DNS server is configured to use information obtained from Active Directory for this zone and is unable to load the zone without it.  Check that the Active Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be empty) is "". The event data contains the error. 4004

4.The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly. The extended error debug information (which may be empty) is "". The event data contains the error. 4015

0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 70

Expert Comment

by:Chris Dent
ID: 24040034

These are on your new DC aren't they? Anything on the current one?

Chris
0
 
LVL 2

Author Comment

by:camoIT
ID: 24040072
These events are from the current DC

On the new DC that is failing...These are the logs
The DNS server was unable to open zone domain.local in the Active Directory from the application directory partition DomainDnsZones.domain.local. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code. 4007

The DNS server was unable to open zone 100.168.192.in-addr.arpa in the Active Directory. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code. 4001

The File Replication Service has enabled replication from AD to ADSERVER for c:\windows\sysvol\domain after repeated retries.

0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 24040109

Okay, so can we also see:

RepAdmin /ShowReps

And if you could run DCDiag and NetDiag the output would be helpful :)

Chris
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 24040124
We had 4015s on some of our DCs and what we did was point the DCs to each other for primary DNS to prevent the race condition.
DC1
Points to DC2 for primary DNS and points to itself as secondary
DC2
Points to DC1 for primary DNS and points to itself as secondary
Have you tried demoting and promoting the box again?
Thanks
Mike
0
 
LVL 2

Author Closing Comment

by:camoIT
ID: 31565309
Thanks for your help in resolving this issue
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now