Solved

Windows Server 2008 DC Not a DC?

Posted on 2010-11-16
16
849 Views
Last Modified: 2012-05-10
Hi,
I recently promoted a Win2k8 Server to a DC while part of a Win2k3 environment. It promoted as it should have. Active Directoy Users and Computers etc. was all there. I then removed the Win2k3 DC from the domain and now I can't join anything to the domain because it can't find a DC. I've checked DNS and it looks good. Can't create a new user because RPC server is unavailable. Anyone know where to start? Nobody can get to shares, printers etc.
Thanks
0
Comment
Question by:Jeffrey
  • 10
  • 6
16 Comments
 

Author Comment

by:Jeffrey
ID: 34151207
Also, in NTDS Settings I don't have a tab to make it a Global Catalog although I did that fromt he Win2k3 server prior to demoting it.
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34151214
Is the 2008 DC the only DC?
Do you have the firewall enabled on the 2008 server?
Did you transfer all the FSMO roles?
Are the clinets pointing to the 2008 for DNS?
Is the 2008 DC a Global Catalog server?

Can you run DCDiag and post the results?
0
 

Author Comment

by:Jeffrey
ID: 34151311
Thanks for you message KenMcF,

Yes, the 2008 "now" the only DC

Firewall is "off" and all inbound/outbound rules enabled

Yes FSMO was transferred prior to removal of win2k3 dc

2008 is a GC, that tab wouldn't display until a few minutes ago

Yes, all pointing to it for DNS
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34151320
Can you post DCDiag from that servr?
0
 

Author Comment

by:Jeffrey
ID: 34151346
Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\Administrator.SDC>dcdiag

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = aquaman
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\AQUAMAN
      Starting test: Connectivity
         ......................... AQUAMAN passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\AQUAMAN
      Starting test: Advertising
         Fatal Error:DsGetDcName (AQUAMAN) call failed, error 1355
         The Locator could not find the server.
         ......................... AQUAMAN failed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... AQUAMAN passed test FrsEvent
      Starting test: DFSREvent
         ......................... AQUAMAN passed test DFSREvent
      Starting test: SysVolCheck
         ......................... AQUAMAN passed test SysVolCheck
      Starting test: KccEvent
         An error event occurred.  EventID: 0xC0000466
            Time Generated: 11/16/2010   16:27:14
            Event String:
            Active Directory Domain Services was unable to establish a connectio
n with the global catalog.
         ......................... AQUAMAN failed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... AQUAMAN passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... AQUAMAN passed test MachineAccount
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=DomainDnsZones,DC=seadwelling,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=ForestDnsZones,DC=seadwelling,DC=com
         ......................... AQUAMAN failed test NCSecDesc
      Starting test: NetLogons
         ......................... AQUAMAN passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... AQUAMAN passed test ObjectsReplicated
      Starting test: Replications
         ......................... AQUAMAN passed test Replications
      Starting test: RidManager
         ......................... AQUAMAN passed test RidManager
      Starting test: Services
         ......................... AQUAMAN passed test Services
      Starting test: SystemLog
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 11/16/2010   15:33:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the
name of a domain controller. This could be caused by a name resolution failure.
Verify your Domain Name System (DNS) is configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 11/16/2010   15:38:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the
name of a domain controller. This could be caused by a name resolution failure.
Verify your Domain Name System (DNS) is configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 11/16/2010   15:43:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the
name of a domain controller. This could be caused by a name resolution failure.
Verify your Domain Name System (DNS) is configured and working correctly.
         An error event occurred.  EventID: 0xC004000B
            Time Generated: 11/16/2010   15:48:51
            Event String:
            The driver detected a controller error on \Device\Harddisk2\DR2.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   15:48:55
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   15:53:55
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   15:58:56
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   16:03:57
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   16:08:57
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   16:13:58
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         An error event occurred.  EventID: 0xC004000B
            Time Generated: 11/16/2010   16:17:29
            Event String:
            The driver detected a controller error on \Device\Harddisk2\DR2.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   16:18:59
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   16:23:59
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         An error event occurred.  EventID: 0x00000406
            Time Generated: 11/16/2010   16:29:00
            Event String:
            The processing of Group Policy failed. Windows attempted to retrieve
 new Group Policy settings for this user or computer. Look in the details tab fo
r error code and description. Windows will automatically retry this operation at
 the next refresh cycle. Computers joined to the domain must have proper name re
solution and network connectivity to a domain controller for discovery of new Gr
oup Policy objects and settings. An event will be logged when Group Policy is su
ccessful.
         ......................... AQUAMAN failed test SystemLog
      Starting test: VerifyReferences
         ......................... AQUAMAN passed test VerifyReferences


   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : seadwelling
      Starting test: CheckSDRefDom
         ......................... seadwelling passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... seadwelling passed test CrossRefValidation

   Running enterprise tests on : seadwelling.com
      Starting test: LocatorCheck
         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355
         A Global Catalog Server could not be located - All GC's are down.
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error
         1355
         A Good Time Server could not be located.
         Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1355
         A KDC could not be located - All the KDCs are down.
         ......................... seadwelling.com failed test LocatorCheck
      Starting test: Intersite
         ......................... seadwelling.com passed test Intersite

C:\Users\Administrator.SDC>
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34151356
Can you post the output of
ipconfig /all
0
 

Author Comment

by:Jeffrey
ID: 34151376
Also, just noticed on a desktop that that when browsing the domain it shows at SDC and in active directory it's seadwelling.com...

Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\Administrator.SDC>ipconfig/all

Windows IP Configuration

   Host Name . . . . . . . . . . . . : aquaman
   Primary Dns Suffix  . . . . . . . : seadwelling.com
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : seadwelling.com

Ethernet adapter Primary:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Broadcom BCM5709C NetXtreme II GigE (NDIS
 VBD Client) #2
   Physical Address. . . . . . . . . : 84-2B-2B-00-5E-67
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::9405:33d7:1a2e:fa56%15(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.6(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.14
   DHCPv6 IAID . . . . . . . . . . . : 344206123
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-14-2D-D3-6B-84-2B-2B-00-5E-65

   DNS Servers . . . . . . . . . . . : ::1
                                       192.168.1.6
                                       192.168.1.7
                                       192.168.1.14
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{96B2FAAF-34D1-4D64-88BE-6DFD5169C6E3}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

C:\Users\Administrator.SDC>
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34151405
Just to cleanup I would remove 192.168.1.7 and 192.168.1.14
 from your DNS settings.

Can you open DNS manager and verify you have the seadwelling.com
 forward lookup zone.

Run DCDiag /fix

Look throught the event logs and you should see something like this in the directory services log.

http://www.windowsitpro.com/content/content/39959/event1119.gif
0
 

Author Comment

by:Jeffrey
ID: 34151407
192.168.1.6 win2k8 DC
192.168.1.7 former win2k3 DC
192.168.1.14 Router

Just checked, although I'm hesitant to restart the win2k8 DC I logged out to check and the log in prompt is SDC\username not seadwelling as Active Directory is.
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34151423
SDC is the netbios name of the domain. The FQDN is seadwelling.com
To verify you can go into system properties and look at the full computername.
0
 

Author Comment

by:Jeffrey
ID: 34151459
Checked directory services event log and no trace of the 1119 entry

Removed .7 and .14 from dns as suggested

Yes, there is a seadwelling.com forward lookup zone and it contains very recent changes

Ran dcdiag /fix
0
 

Author Comment

by:Jeffrey
ID: 34151465
i don't see a reference to SDC on the win2k8 Domain Controller, just seadwelling.com
0
 

Author Comment

by:Jeffrey
ID: 34151534
was able to create a new user in AD, but can't use it with a computer that has logged onto domain before, says domain is unavailable.
0
 
LVL 27

Accepted Solution

by:
KenMcF earned 500 total points
ID: 34151560
From the DCDiag it looks like one issue is the sysvol. Can you see if it is shared
net share
you should see sysvol and netlogon

If you do not follow the steps in this link to restore them.

http://msdn.microsoft.com/en-us/library/cc507518(VS.85).aspx
0
 

Author Comment

by:Jeffrey
ID: 34151608
I noticed that it was not present after the dc upgrade so i copied it over manually, will look at the msdn instructions though.
0
 

Author Comment

by:Jeffrey
ID: 34151693
net share displays sysvol and netlong shares

loads of 1054 and 8003 in the event log
0

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
ACTIVE DIRECTORY 4 25
ADFS 3.0 and UPN Problem 6 16
Need help in modifying an existing script 5 13
VMware Black Screen 13 31
Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now