[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

New Users unable to login to WIn2003 based domain.

Posted on 2009-04-29
12
Medium Priority
?
185 Views
Last Modified: 2012-05-06
Hi ,

I have an issue. in our DNS servers whatever the User ID that I have create those users are unable to login to client M/c, In my organization all the client M/c are running in WinXp. DNS server is configured in WIn2003. previously it was working fine. all the users who are already been created can login to domain. But the new users are unable to login to domain. can someone suggest me. here we have two DNS servers. IP is 10.16.1.20 & 21 all are active directory intergrated zone configured. But when i check the zone information in -msdsc zone zore records are not replicatied properly. In .20 SOA record value is 323 & in .21 SOA record is 303. I have applied dnslint command on both servers & founded on .20 everything is fine but in .21 when i tested with IP dns name is not resolved & showing SOA record is missing. But i have applied NSlookup command on .21 its resolving name. SO cant find out what the cause.

Please anyone suggest me how to solve the issue. As new joinees are not able to login to our domain by accessing any client M/c .

Please update me asap.

Thanks,

Biplab
0
Comment
Question by:biplabmukherjee
  • 7
  • 5
12 Comments
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24265983
Do you have a seperate zone for the msdcs folder? Your msdcs folder should be listed under your domain.com zone and not a seperate zone. If it is then your zone is delegated which means you must manually update the records or you can delete both the msdcs zone and the domain.com zone then recreate the domain.com zone so the msdcs folder will be placed back under the domain.com zone.
0
 

Author Comment

by:biplabmukherjee
ID: 24266024
Yes msdsc folder is listed under domain.com zone in both DNS servers. Just now I have check the replication topology using repadmin CLI utility & also have checked with replication mornitor its showing RPC servers is unavailable. 1722( Error code) ( 10.16.1.21). on .21. i have check on both DNS servers RPC services & FRS services are running.  What should I do? under that domain zone there is ( -msdcs, _sites, _tcp, _udp,domaindnszones, -forestdnszones are listed. ) Do you mean I have delete the domain.com zone on both DNS servers & re-created again. ? Plz advise.
0
 
LVL 59

Assisted Solution

by:Darius Ghassem
Darius Ghassem earned 2000 total points
ID: 24266064
No, if the msdcs folder is listed under the domain.com zone then you are good. Run a netdiag and a ipconfig /all. One more a netdiag /test:dns
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:biplabmukherjee
ID: 24266148
Executed but doesnt help anything. I am just enclosing the result of repadmin /showreps result  may it will help u to troubleshoot.

 C:\Documents and Settings\biplab-a>repadmin /showreps
INDIA\K2I-DC-01
DC Options: IS_GC
Site Options: (none)
DC object GUID: 9f05c1ac-aa47-4379-b3cb-7ccb5cf00076
DC invocationID: f7e6cb22-80ba-4ba9-ad9f-1dc8da2deb0a

==== INBOUND NEIGHBORS ======================================

DC=k2,DC=local
    INDIA\K2I-DC-02 via RPC
        DC object GUID: 8746a08d-3dfc-408f-a440-e2aef41043a3
        Last attempt @ 2009-04-30 06:28:59 failed, result 1722 (0x6ba):
            The RPC server is unavailable.
        638 consecutive failure(s).
        Last success @ 2009-04-03 18:47:16.
    USA\K2C-DC-01 via RPC
        DC object GUID: 7f81bb9e-54b4-4a8d-b3e6-64af179e443f
        Last attempt @ 2009-04-30 06:29:03 was successful.

CN=Configuration,DC=k2,DC=local
    INDIA\K2I-DC-02 via RPC
        DC object GUID: 8746a08d-3dfc-408f-a440-e2aef41043a3
        Last attempt @ 2009-04-30 06:28:17 failed, result 1722 (0x6ba):
            The RPC server is unavailable.
        638 consecutive failure(s).
        Last success @ 2009-04-03 18:24:03.
    USA\K2C-DC-01 via RPC
        DC object GUID: 7f81bb9e-54b4-4a8d-b3e6-64af179e443f
        Last attempt @ 2009-04-30 06:29:02 was successful.

CN=Schema,CN=Configuration,DC=k2,DC=local
    INDIA\K2I-DC-02 via RPC
        DC object GUID: 8746a08d-3dfc-408f-a440-e2aef41043a3
        Last attempt @ 2009-04-30 06:28:38 failed, result 1722 (0x6ba):
            The RPC server is unavailable.
        638 consecutive failure(s).
        Last success @ 2009-04-03 18:24:03.
    USA\K2C-DC-01 via RPC
        DC object GUID: 7f81bb9e-54b4-4a8d-b3e6-64af179e443f
        Last attempt @ 2009-04-30 06:29:03 was successful.

DC=DomainDnsZones,DC=k2,DC=local
    INDIA\K2I-DC-02 via RPC
        DC object GUID: 8746a08d-3dfc-408f-a440-e2aef41043a3
        Last attempt @ 2009-04-30 06:28:17 failed, result 1256 (0x4e8):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
        638 consecutive failure(s).
        Last success @ 2009-04-03 18:34:32.
    USA\K2C-DC-01 via RPC
        DC object GUID: 7f81bb9e-54b4-4a8d-b3e6-64af179e443f
        Last attempt @ 2009-04-30 06:29:04 was successful.

DC=ForestDnsZones,DC=k2,DC=local
    INDIA\K2I-DC-02 via RPC
        DC object GUID: 8746a08d-3dfc-408f-a440-e2aef41043a3
        Last attempt @ 2009-04-30 06:28:17 failed, result 1256 (0x4e8):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
        639 consecutive failure(s).
        Last success @ 2009-04-03 18:24:04.
    USA\K2C-DC-01 via RPC
        DC object GUID: 7f81bb9e-54b4-4a8d-b3e6-64af179e443f
        Last attempt @ 2009-04-30 06:29:04 was successful.

Source: INDIA\K2I-DC-02
******* 17 CONSECUTIVE FAILURES since 2009-04-30 02:33:47
Last error: 1722 (0x6ba):
            The RPC server is unavailable.
0
 
LVL 59

Assisted Solution

by:Darius Ghassem
Darius Ghassem earned 2000 total points
ID: 24266175
Usually the RPC errors are DNS related. What did the test say when you ran them?
0
 

Author Comment

by:biplabmukherjee
ID: 24266256
After executing netdiag LDAP test was failed " its howing [FATAL] Cannot open an LDAP session to K2I-dc-02 AT 10.16.1.21. But while executing netdiag /test:dns all results are passed . DNS test also passed showing meesage" All the DNS entries for DC are registered on DNS servers . But while executing only netdiag command its showing LDAP test faild to 10.16.1.21. even i also execute repadmin /showconn with all DNS servers in India & US its connected accept ( 10.16.1.21) K2I-DC-02 " the RPC server is unavailable"
0
 

Author Comment

by:biplabmukherjee
ID: 24295415
Can anyone help me out about this situation.? Since it has been long time no one has been responded. Please reply back ASAP.
0
 
LVL 59

Assisted Solution

by:Darius Ghassem
Darius Ghassem earned 2000 total points
ID: 24332056
I'm sorry I have been real sick. On 10.16.1.21. are you getting any errors?
0
 

Author Comment

by:biplabmukherjee
ID: 24332839
I have checked its only issue with 10.16.1.20. This server since not replicated to any of the DC in forest. either in india site or US site. But 10.16.1.21 is replicatiing to all DC in forest.
0
 

Author Comment

by:biplabmukherjee
ID: 24334335
Hi dariusg

I am enclosing the attachment. Please take a look , may it will help you.

Thanks,

Biplab
DNS.JPG
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 2000 total points
ID: 24360060
If you have other DCs then it might be easier just to demote the server then re-promote it.
0
 

Author Closing Comment

by:biplabmukherjee
ID: 31576192
really helpfull to troubleshoot the problem
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
As many of you are aware about Scanpst.exe utility which is owned by Microsoft itself to repair inaccessible or damaged PST files, but the question is do you really think Scanpst.exe is capable to repair all sorts of PST related corruption issues?

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question