Link to home
Start Free TrialLog in
Avatar of _the_reverend
_the_reverend

asked on

Cant login with secondary domain controller windows server 2003

Ive created a secondary domain controller, until now, Ive done this:


1. Installed 2003 server, joined the domain and runned DCPROMO
2. Ive installed and configure DHCP and DNS.
3.Ive checked that both servers are global catalog servers.

My Primary Sever ip is 10.0.0.1, and my secondary is 10.0.0.5
All clients have DNS 10.0.0.1 and 10.0.0.5 (configured through DHCP)

Ive made a test disconnecting the primary domain controller, and after rebooting all client computers are unable to login, they can only login with user credentials already used in that client.

Can you help me?
Thank you.

Avatar of Bruno PACI
Bruno PACI
Flag of France image

Hi,

Can you verify that the SYSVOL share exists on the second DC. A new DC does not bring up the SYSVOL share until it has successfully finished an Active Directory replication, and by the way it also refuse to authenticate anyone.

Did you install the "Support Tools" and check the result of DCDIAG and NETDIAG commands ? These commands will show you a precise report of Active Directory status.
(the support tools are on the Windows 2003 CD).

Have a nice day


Hi there. As mentioned by PaciB, a DCDIAG and NETDIAG should root out any issues on the DCs.
Have you confirmed that the new IP config (ie both DNS servers listed) is actually applying to your clients? Did you configure these options on both scopes? If your first DC was also a DHCP server, your clients will continue to try to contact it to renew the lease. They won't automatically go through a full broadcast DORA process and speak to the new DHCP server until 50% (i think) of the existing lease has passed. From memory, they'll try to contact the source DHCP server, if they can't, then they continue with their existing lease, and therefore not get the config you have put on the new server. Just a thought.
Avatar of _the_reverend
_the_reverend

ASKER

Ive Attached the results of both diagnostics, but I dont understand them completley and as how to correct those tests that didnt pass.
Thank you.
dcdiag.txt
netdiag.txt
ASKER CERTIFIED SOLUTION
Avatar of bluntTony
bluntTony
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thank you, that did it, we used a virtual IP (.8) to avoid SPAMERS using our SMTP server. Dont know how exactly but that was the reason. Why can this virtual ip cause problems to the DC?
Thank you.
Hi,

Your DC is a multi-homed server, meaning it has several netcards et several IP addresses.
You must ensure that your DC has NOT registered itself in DNS with bad IP, like these on the "Realtek NIC" : 201.134.44.xxx

If your DC is register in DNS with a IP address that is not reachable from clients you can have trouble like you described. As an exemple let's suppose your secondary DC is registered in DNS with multiple IP addresses : 10.0.0.5 (the good one) and 201.134.44.172 (a bad address coming from the Realtek NIC).
When your first DC is offline, clients request the secondary DNS 10.0.0.5 asking for another DC for the ponderosa.local domain.
The DNS only knows one other DC : monterrey5.ponderosa.local... But it has multiple addresses for this DC. So the DNS server choose one of the addresses for monterrey5 and give it to the client.
Let's suppose the DNS choosed 201.134.44.172. The client cannot reach the DC on this address. The the client suppose this DC is offline and ask the DNS for one more DC but there is no more DC in the list.

You can check which IP addresses are returned by the DNS server byt typing these two commands several times :

IPCONFIG /FLUSHDNS
PING monterrey5.ponderosa.local

The first command force the client to empty its DNS cache
Now that the DNS cache is empty, the second command force the client to request the DNS server.

Doing this several times you will have several answers. In normal situation all the answer should give you the same IP address. If not then you DNS is polluted with bad IP addresses and you have to fix the IP configuration on the DC.

Have a nice day.