User's PC unable to login to domain on backup AD server

I have 2 AD servers (one master) on Windows 2008 STD, but when the master AD is down, user PCs are unable to login to the domain on the backup AD server.

The master and backup AD are defined in AD. User's PC are pointing to the AD servers for DNS and WINS (AD servers run DNS and WINS as well). All User PCs are Win XP Pro SP3.

Any suggestions where I should start looking at ? Thanks.
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Michael OrtegaSales & Systems EngineerCommented:
So are you saying that all your XP clients have DNS configured to point at Primary DNS - AD server 1 and Secondardy DNS - AD server 2? Are any XP clients working? All addresses handed out through DHCP server or are they Static? If DHCP, does the AD server in question hold that role?

Are you getting good replication between AD servers? Have you checked by running DCDIAG on AD server 2?


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Henrik JohanssonSystems engineerCommented:
To be correct, there's no such thing as backup AD. All DCs are multi-master. Backup DC (BDC) is an old NT4 term that doesn't exist when talking about native AD.

First thing is that clients nead to point on both DC/DNS servers for redundancy. As I understand it, that's already done.
Also check that there's no external (ISP or routers) as DNS servers on the client as it will give issues.

If clients are correctly configured, it sounds like a replication issue between the two DCs. The DCs should point on both itself and the other as DNS servers, not only itself.
Is there any issues reported by dcdiag command line tool on the DCs? Anything in the DC's eventlog?
Krzysztof PytkoSenior Active Directory EngineerCommented:
If you use DHCP server, please modify option no 006. You have to type 2 DNS servers (DC1 and DC2). If one of them will be unavailable, then clients will proceed with another one
The Ultimate Tool Kit for Technolgy Solution Provi

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy for valuable how-to assets including sample agreements, checklists, flowcharts, and more!

Krzysztof PytkoSenior Active Directory EngineerCommented:
I hope, you have DHCP server on separate machine. If not, you have to configure it also on DC2
Darius GhassemCommented:
Make sure both DCs are Global catalogs. When you have your DC go down that holds FSMO roles you will see this type of issues since the FSMO roles are not searchable. Seizing these roles should fix the problem but this will make the DC that holds these roles unusable and would have to be demoted then promoted again

First try to make sure that the second DC is a GC.

Run dcdiag to check for errors to see if you have exsiting problems with replication.
sidartraAuthor Commented:

I came across a setting "enable Password cache" (?) while setting up AD2 so I am clarifying if this needs to be enabled for users to login.

PCs are getting DNS resolved correctly and can access Internet etc (DNS1 -> AD1, DNS2 -> AD2).

PCs are using sttaic IP. Both AD servers are global catalog.

I will test again this weekend. Any other comments welcomed. Thanks.
Krzysztof PytkoSenior Active Directory EngineerCommented:
It looks like internal DNS problem. Could you tell me please how is your DC2 DNS configured (forwarding etc.)?
Henrik JohanssonSystems engineerCommented:
It's possibly that it's a replication issue between the two DCs..
Any errors in output from dcdiag command tool on DCs?
Darius GhassemCommented:
Please post dcdiag. Make sure both are GCs. When your fsmo roles are down then you will see issues like this as well.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.