Avatar of itmandan
itmandan asked on

cannot join domain or login with credentials

I have a sbs 2003 server and I used disk clean up to compress some files on the c drive and now I cant join a computer to a domain because it says the specified server cannot perform the requested operation and the ones who are already on the domain cant access the networked folders it asks them for their credentials and when they input them it states that the user name has already been tried and the domain controller cannot be found to verify the information. what is happening? any help would be greatly appreciated.
SBSMicrosoft Legacy OSWindows OS

Avatar of undefined
Last Comment
YarnoSG

8/22/2022 - Mon
abhijitwaikar

Make sure the DC advertising itself as domain controller,
Run below tests to verfiy the DC and post result.
dcdiag /q
netdiag /q
Netdom query dc - it will show all DCs in network.
netdom query fsmo - check FSMO roles are ok from the DC

On the workstation, check that:
-Date & Time are the same as the domain (closer than 5 mn)
-It has the DC as primary dns server
-you try to join the domain with the FQDN name (mydomain.com)

Matthias Abt

Don't forget to add clients using the website http://connectcomputer with SBS Domains.
ASKER
itmandan

I have tried to add clients using the http://connectcomputer with the SBS domain but no luck.
Your help has saved me hundreds of hours of internet surfing.
fblack61
Matthias Abt

What about the event logs of the server? Somewhere must be a failure notice.

Please tell us about the results abhijitwaikar asked before:
dcdiag /q
netdiag /q
Netdom query dc
netdom query fsmo

Check if all services are started (DHCP, DNS, Netlogon ...)
ASKER
itmandan

this is where i think it started  
event viewer
Matthias Abt

No, that are only exchange errors, that's a result of network (or domain) problems. What about
dcdiag /q
netdiag /q
Netdom query dc
netdom query fsmo

Check if all services are started (DHCP, DNS, Netlogon ...)
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER
itmandan

but I am having problems with the domain, on some of these computers it says it can't located allstarmetals.local but here is a snap of dcdiag

 dcdiag
and sorry to sound like a noob but how do you run Netdom query dc? from the run or command prompt?
Matthias Abt

From the commandline
ASKER
itmandan

sorry no dice, wont let me
. netdom query dc
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
Matthias Abt

Could be, that netdom is part of the windows server 2003 ressource kit, in 2008 it's included.
ASKER
itmandan

ah, well I look for the resource kit if I got it.
Matthias Abt

please download the support tools also on your way ;).
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER
itmandan

I downloaded the server admin tools but I couldn't find a resource disk that came with the server documentation that would allow me to run netdom query dc. also I spoke with someone else and they were saying that it could be the server is loosing its trust relationship with the workstations.
Matthias Abt

if the server is losing trust relationship with existing clients, there should be no problem adding new clients.

If possible, try to remove and reintegrate existing clients with connection problems, but have a closer look at the eventlog of the server and clients before doing so. I saw an issues with kerberos at the screenshot from dcdiag, could be caused by a DNS Problem.

Think about: you used the disc cleanup to compress files, what about searching for compressed files and uncompress them?

What about services that should be started and did not start automaticly at all? Can you have a look at the services for that?

I remember to have the exchange issues at a customer site without using the cleanup, last thing to solve these issues was a migration to sbs 2008...
ASKER
itmandan

yes I have recieved a Kerberos error, I also did a uncompress of all the files ( “compact /u /s /a /q /i *.*) that are compressed in all volumes then did a defrag a couple of times on the OS volume. but here is a look at the Kerberos error
 Kerberos
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
Matthias Abt

Do you have two machines with the same same name in your network? Please double Check your DNS if there are two entries with the same name and different IP Adresses, check the forward lookup zone and the reverse zone for duplicated names and different ip adresses!
Matthias Abt

And have a look at the hosts file at c:\windows\systems32\drivers\etc if there is something that is not matching your network...
ASKER
itmandan

I also get this error on the DNS
 dns
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER
itmandan

and this is what i have on the hosts file in the server

Untitled36.png
Matthias Abt

Hosts File is normal.
DNS Error can be normal if it only comes up after a restart because AD is started after DNS Service.

Is the Binding of your DNS Server set to the NIC? Are the SRV Entries set correct and did you check the entries for same names with different ip adresses?

The 2003 Ressource Kit can be downloaded at http://www.microsoft.com/downloads/en/details.aspx?DisplayLang=en&FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd
ASKER
itmandan

Im not sure where the SRV Entries would be located in the DNS and about the binding of DNS with the NIC is that on the server or Client side?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
Matthias Abt

The SRV Entries can be found in the subtrees of _msdcs.allstartmetals.local and the other subtrees like _tcp _sites _udp etc.

To check the bindings, just right click on server1 at the DNS Console. DNS Server must use the internal NIC of your Server.
ASKER
itmandan

checked the bindings and i believe it looks right where it says the Interfaces tab 192.168.0.2 which is the IP of the server. Now on the SRV entries, I am not sure what I am looking for. is it the host offering this service section, should it display as: server1.allstarmetals.local. ?

here is a picture of what Im talking about.
 Host offering
Matthias Abt

Looks correct.

When connection a new client  to the domain:
1. Add the Computer account using the sbs console.
2. Be sure:
 2.1 that only one NIC is active on the client PC
 2.2 Client only uses DNS of the SBS Server (192.168.0.2), nothing else is possible.
 2.3 that the command nslookup connectcomputer returns the ip adress of the server
3. Open http://servername/connectcomputer with Internet Explorer from the client and follow the assistent

If it's still not possible and you get an error from the client, see http://support.microsoft.com/kb/838431/en-us
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER
itmandan

I am getting a error that nslookup couldn't find the server ip address 192.168.0.2
here is a pic
 ns lookup
Matthias Abt

Can you make a screenshot of the command "ipconfig /all" please?
ASKER
itmandan

here is the screen shot
40.png
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
Matthias Abt

Please remove the DNS Server with IP Adress 4.2.2.2.

In a SBS Network, only the SBS Server or a second DC with activ DNS Role can be DNS Server for the Clients.

You can add a forwarder to the DNS Server to IP 4.2.2.2.
ASKER
itmandan

I have added a forwarder
 forwarder
but when i take of the 4.2.2.2 alternate from the server I get no internet access
 no access
Matthias Abt

The Screenshot is a XP Client and it is not a member of the domain, right? If so, why:
---
but when i take of the 4.2.2.2 alternate from the server I get no internet access
---

What Details can you see by clicking "more informations"? Do you have any proxy Server defined? Please open a CMD and type nslookup google.com and post the result of this command.

Do you have a . DNS Zone in your DNS Server defined?
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER
itmandan

when I ran into connectivity issues on the network I unjoined this computer from the network thinking maybe it just needs to be re-joined, but it wouldn't allow it.

to the second part, is that through the server console?
Matthias Abt

Yes, check the list of forward zones of the DNS Service on SBS Server if there is a . Zone. If so, no one could be able ro resolve any Internet Service because the SBS thinks, he is the Big Master for all Zones, no need to ask any other DNS Server.

If there is another DNS Server added to the clients, it should sometimes work to access the internet and sometimes not.

Do you have deleted the computer account for that client on the SBS Server and re-added it?
ASKER
itmandan

im not quite sure what you mean by .Zone in the DNS or where exactly in the DNS it would be located. there is no other DNS server located on the network

and I have deleted the computer and re-added it on the SBS previously with no luck.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Matthias Abt

Have a look at the attached image to see what i mean with a . Zone in DNS Server.

Could you please check the result of the nslookup command from the server and the client? There seems to be something completly wrong with your DNS to me.
point-zone.jpg
Matthias Abt

seems to be an error with the uploaded image, sorry.
point-zone.jpg
ASKER
itmandan

here is what my nslookup sayson the server

45.png
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
Matthias Abt

nslookup google.com
ASKER
itmandan

here is what I get ns lookup google.com
Matthias Abt

You only have the SBS Server as DNS in your NIC settings? If so, everything is OK.

And the result from the client you used yesterday? But be sure that there is only the SBS as DNS Server in NIC settings!
If you got no response, please disable the Firewall and test again.
Your help has saved me hundreds of hours of internet surfing.
fblack61
ASKER
itmandan

here is what I got on the client side with the dns pointing to the server nslookup client
Matthias Abt

Something is blocking the client to use the SBS Server as DNS Server. And there is something wrong with the client, no alternate DNS Server is listed, but it uses ip 4.2.2.2. Sure that cabling is correct?

Do you have any piece of software on this client that manipulates NIC Settings or is something hidden behind the advanced settings?
ASKER
itmandan

something is wrong with the DNS, all my clients have alternate 4.2.2.2 dns and the ones that don't can't connect to the internet or the cant ping server by name.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER CERTIFIED SOLUTION
Matthias Abt

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
YarnoSG

as abhijitwaikar has already suggested:

check the TIME on both the client and the server before trying to join the domain... if they are off by more than 5 minutes, the transaction will fail  We just had a daylight savings cusp..... you could be off by an hour and not even know it.