Solved

Stub Zone Problems 2008 R2 DNS Servers (windows 2008 r2 dns stub zone validation error: Please try again later))

Posted on 2010-09-08
6
5,506 Views
Last Modified: 2012-05-10
I'm trying to setup a Trust between domains but before I can do that I need to setup a Stub Zone on both DC/DNS servers on both domains.

I can setup a Stub Zone on the new DNS/DC to our old DNS/DC server but I can't setup a Stub Zone on our old network to point to the new network.  Everytime I try to setup a Stub Zone it gives me the windows 2008 r2 dns stub zone validation error: Please try again later).

I don't know what could be causing this to work on one server and not another.  Already checked the obvious firewall issue and basic TCP/IP connectivity between servers.
0
Comment
Question by:ChocolateRain
  • 3
  • 2
6 Comments
 
LVL 29

Expert Comment

by:Rich Weissler
ID: 33631598
Do you have IPSec and DNSSec configured on the new domain?

Any 'interesting' errors in the DNS Log on either DCs?
0
 
LVL 1

Author Comment

by:ChocolateRain
ID: 33631683
I didn't setup IPSec or DNSSec on the new domain controller.  

On the old DC I have a Warning Event when i run the DNS BPA tool but i don't have any warnings or errors in the event log for the old DC/DNS server.

The warning on this old server is: Title:
DNS: Valid network interfaces should precede invalid interfaces in the binding order

Severity:
Warning

Date:
9/8/2010 2:23:40 PM

Category:
Configuration

Issue:
A disabled or invalid adapter precedes a valid adapter in the network interface binding order list.

Impact:
The binding order determines when network interfaces will be used to make network connections by the computer. A disabled adapter high in the binding order can degrade performance.

Resolution:
Click Start, click Network, click Network and Sharing Center, and then click Manage Network Connections to move all disabled and invalid interfaces to the bottom of the binding order list.

More information about this best practice and detailed resolution procedures: http://go.microsoft.com/fwlink/?LinkId=121966

This is a funny error message to receive since there are no other adapters in this machine (it is a virtual machine btw).
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 33631712
Have you went here to check the binding order?

Click Start, click Network, click Network and Sharing Center, and then click Manage Network Connections to move all disabled and invalid interfaces to the bottom of the binding order list.

Make sure that your primary NIC is listed first.
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 1

Author Comment

by:ChocolateRain
ID: 33631985
There is only 1 network connection under the standard options as well as the Binding options.
0
 
LVL 29

Accepted Solution

by:
Rich Weissler earned 500 total points
ID: 33632439
Okay, this is a weird one.
I'm sure you've already checked them a hundred times, but double check:
a. you aren't miskeying the IP address of the remote DNS server.
b. confirm the remote DNS server is authoritative for the zone you are attempting to configure the stub for.

If both of those check out...  granting Zone Transfer permissions shouldn't be necessary, but on the new DC, grant zone transfer to the old DC.  Like I said, that shouldn't make a difference, but... ya know... this is a weird one.

This VM, it's the old DC?  Hyper-V or VMWare?  Are the new DCs virtual too?  On the same hosts?
0
 
LVL 1

Author Comment

by:ChocolateRain
ID: 33637891
I have 3 old DCs that all do this when trying to connect to the new DC.

Everything is virtualized using VMware.

I got it working by checking the allow Zone Transfers box and had to select the "Allow Zone Transfers" and select the option box "To Any Server".  If I tried to isolate this by Hostname, FQDN or IP address it errored out.

Can you see why I'm getting rid of the old domain?

=]
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now