Link to home
Start Free TrialLog in
Avatar of Ravi Singh
Ravi Singh

asked on

DNS of ADC is not working

Hello Experts,

NSLOOKUP is not working on my additional domain controller.

Can you help me to rectify this problem.

Thanks,
Ravi Pratap
Avatar of Krzysztof Pytko
Krzysztof Pytko
Flag of Poland image

How did you set up ADC NIC's properties in DNS section? Do you have there 127.0.0.1 ? If so, change it to your DC01 IP address or (if you installed and configured DNS on ADC) its IP address and check once again.

Regards,
Krzysztof
Avatar of Ravi Singh
Ravi Singh

ASKER

I have configured static ip address on my ADC tcp/ip and configuration of ADC TCP/IP is below mentioned :-

IP :- 10.x.x.x /23 bit

Prefferred DNS :-  ADC IP address

Alternate DNS :- DC IP address

After that running nslookup,it's show :-

DNS request time out .
         time out was 2 second
******** Can't fine server name for address ADC IP address : Time Out
Default Server : unknown
Address : ADC IP address

But when i placed DC IP address in Preffered DNS setting

NSlookup is running properly with default DC address.

Waiting for your quick response

Thanks,
Ravi

OK, looks like you have no DNS service on ADC installed :)
Windows Server 2003 doesn't install it automatically on ADCs :). Go to "Manage your Server" and add DNS role there. Configure it as ActiveDirectory-Integrated and then everything would work fine :)

Let me know

Krzysztof
Dear Expert,

I have already configured DNS integrated with AD.Before 0ne week it was working fine.

But last 3 to 4 days DNS of ADC is not working properly.

What steps shall I take to rectify our existing DNS in our ADC server.

Waiting for your promt response.

Kind Regards,
Ravi Pratap
ASKER CERTIFIED SOLUTION
Avatar of Krzysztof Pytko
Krzysztof Pytko
Flag of Poland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
If you have more than 1 NIC in your DNS Server you will have to properly configure your DNS properties with the appropriate Listener configuration.
Hi All,

When we run netdiag /fix:dns below mentioned is the output :-

C:\Program Files\Support Tools>netdiag /fix:dns

Usage: netdiag [/Options]>
   /q - Quiet output (errors only)
   /v - Verbose output
   /l - Log output to NetDiag.log
   /debug - Even more verbose.
   /d:<DomainName> - Find a DC in the specified domain.
   /fix - fix trivial problems.
   /DcAccountEnum - Enumerate DC machine accounts.
   /test:<test name>  - tests only this test. Non - skippable tests will still b
e run
   Valid tests are :-
        Ndis - Netcard queries Test
        IpConfig - IP config Test
        Member - Domain membership Test
        NetBTTransports - NetBT transports Test
        Autonet - Autonet address Test
        IpLoopBk - IP loopback ping Test
        DefGw - Default gateway Test
        NbtNm - NetBT name Test
        WINS - WINS service Test
        Winsock - Winsock Test
        DNS - DNS Test
        Browser - Redir and Browser Test
        DsGetDc - DC discovery Test
        DcList - DC list Test
        Trust - Trust relationship Test
        Kerberos - Kerberos Test
        Ldap - LDAP Test
        Route - Routing table Test
        Netstat - Netstat information Test
        Bindings - Bindings Test
        WAN - WAN configuration Test
        Modem - Modem diagnostics Test
        Netware - Netware Test
        IPX - IPX Test
        IPSec - IP Security Test
   /skip:<TestName> - skip the named test.  Valid tests are:
        IpConfig - IP config Test
        Autonet - Autonet address Test
        IpLoopBk - IP loopback ping Test
        DefGw - Default gateway Test
        NbtNm - NetBT name Test
        WINS - WINS service Test
        Winsock - Winsock Test
        DNS - DNS Test
        Browser - Redir and Browser Test
        DsGetDc - DC discovery Test
        DcList - DC list Test
        Trust - Trust relationship Test
        Kerberos - Kerberos Test
        Ldap - LDAP Test
        Route - Routing table Test
        Netstat - Netstat information Test
        Bindings - Bindings Test
        WAN - WAN configuration Test
        Modem - Modem diagnostics Test
        Netware - Netware Test
        IPX - IPX Test
        IPSec - IP Security Test

C:\Program Files\Support Tools>

Netdiag / fix
yes I have run Netdiag /fix and below mentioned the output :-

C:\Program Files\Support Tools>netdiag /fix

....................................

    Computer Name: ISADC-02
    DNS Host Name: ISADC-02.ABC.com
    System info : Microsoft Windows Server 2003 (Build 3790)
    Processor : x86 Family 15 Model 6 Stepping 4, GenuineIntel
    List of installed hotfixes :
        KB2079403
        KB2115168
        KB2121546
        KB2124261
        KB2141007
        KB2158563
        KB2160329
        KB2183461-IE8
        KB2229593
        KB2259922
        KB2279986
        KB2286198
        KB2296011
        KB2345886
        KB2347290
        KB2360131-IE8
        KB2360937
        KB2378111
        KB2387149
        KB2388210
        KB2416451
        KB915800-v9
        KB923561
        KB924667-v2
        KB925398_WMP64
        KB925876
        KB925902-v2
        KB926122
        KB927891
        KB929123
        KB930178
        KB932168
        KB933854
        KB936357
        KB938127
        KB941569
        KB943055
        KB943460
        KB943729
        KB944338-v2
        KB944653
        KB945553
        KB946026
        KB948496
        KB950760
        KB950762
        KB950974
        KB951748
        KB952004
        KB952069
        KB952954
        KB953298
        KB954155
        KB954550-v5
        KB955069
        KB955759
        KB956572
        KB956744
        KB956802
        KB956803
        KB956844
        KB958469
        KB958644
        KB958869
        KB959426
        KB960225
        KB960803
        KB960859
        KB961118
        KB961501
        KB967715
        KB967723
        KB968389
        KB969059
        KB970238
        KB970430
        KB971032
        KB971468
        KB971513
        KB971657
        KB971737
        KB971961
        KB971961-IE8
        KB972270
        KB973037
        KB973507
        KB973540
        KB973687
        KB973815
        KB973869
        KB973904
        KB973917-v2
        KB974112
        KB974318
        KB974392
        KB974571
        KB975025
        KB975467
        KB975558_WM8
        KB975560
        KB975562
        KB975713
        KB976662-IE8
        KB977290
        KB977816
        KB977914
        KB978037
        KB978338
        KB978542
        KB978601
        KB978695
        KB978706
        KB979309
        KB979482
        KB979559
        KB979683
        KB979687
        KB979907
        KB980195
        KB980218
        KB980232
        KB980436
        KB981322
        KB981332-IE8
        KB981350
        KB981550
        KB981793
        KB981957
        KB982132
        KB982214
        KB982381
        KB982381-IE8
        KB982632-IE8
        KB982666
        KB982802
        Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

    Adapter : Local Area Connection

        Netcard queries test . . . : Passed

        Host Name. . . . . . . . . : ISADC-02
        IP Address . . . . . . . . : 10.x.x.x
        Subnet Mask. . . . . . . . : 255.255.254.0
        Default Gateway. . . . . . : 10.x.x.x
        Dns Servers. . . . . . . . : 10.x.x.x(ADC IP Address)
                                     10.x.x.x(DC IP Address)
                                     4.2.2.2(ISP DNS)
                                     202.138.103.100(ISP DNS)


        AutoConfiguration results. . . . . . : Passed

        Default gateway test . . . : Passed

        NetBT name test. . . . . . : Passed
        [WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenge
r Service', <20> 'WINS' names is missing.

        WINS service test. . . . . : Skipped
            There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
    List of NetBt transports currently configured:
        NetBT_Tcpip_{FC56C83D-943E-45E1-A453-505CA3AD78FC}
    1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed
    [WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
    PASS - All the DNS entries for DC are registered on DNS server '10.x.x.x' and other DCs also have some of the names registered.


Redir and Browser test . . . . . . : Passed
    List of NetBt transports currently bound to the Redir
        NetBT_Tcpip_{FC56C83D-943E-45E1-A453-505CA3AD78FC}
    The redir is bound to 1 NetBt transport.

    List of NetBt transports currently bound to the browser
        NetBT_Tcpip_{FC56C83D-943E-45E1-A453-505CA3AD78FC}
    The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Passed
    Secure channel for domain 'ABC' is to '\\ISERVDC.ABC.com'.


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed
    [WARNING] Failed to query SPN registration on DC 'ISERVADC.ABC.com'.


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
    No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

    Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully

And below mentioned is the dcdiag output :-

C:\Program Files\Support Tools>dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\ISADC-02
      Starting test: Connectivity
         ......................... ISADC-02 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\ISADC-02
      Starting test: Replications
         [Replications Check,ISADC-02] A recent replication attempt failed:
            From ISERVADC to ISADC-02
            Naming Context: DC=ForestDnsZones,DC=ABC,DC=com
            The replication generated an error (1256):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
            The failure occurred at 2010-12-28 22:18:43.
            The last success occurred at 2010-10-21 22:37:23.
            1632 failures have occurred since the last success.
         [ISERVADC] DsBindWithSpnEx() failed with error 1722,
         The RPC server is unavailable..
         [Replications Check,ISADC-02] A recent replication attempt failed:
            From ISERVADC to ISADC-02
            Naming Context: DC=DomainDnsZones,DC=ABC,DC=com
            The replication generated an error (1256):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
            The failure occurred at 2010-12-28 22:18:43.
            The last success occurred at 2010-10-21 22:37:23.
            1632 failures have occurred since the last success.
         [Replications Check,ISADC-02] A recent replication attempt failed:
            From ISERVADC to ISADC-02
            Naming Context: CN=Schema,CN=Configuration,DC=ABC,DC=com
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2010-12-28 22:19:05.
            The last success occurred at 2010-10-21 22:37:23.
            1632 failures have occurred since the last success.
            The source remains down. Please check the machine.
         [Replications Check,ISADC-02] A recent replication attempt failed:
            From ISERVADC to ISADC-02
            Naming Context: CN=Configuration,DC=ABC,DC=com
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2010-12-28 22:18:43.
            The last success occurred at 2010-10-21 22:37:23.
            1632 failures have occurred since the last success.
            The source remains down. Please check the machine.
         [Replications Check,ISADC-02] A recent replication attempt failed:
            From ISERVADC to ISADC-02
            Naming Context: DC=ABC,DC=com
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2010-12-28 22:19:26.
            The last success occurred at 2010-10-21 22:37:26.
            1633 failures have occurred since the last success.
            The source remains down. Please check the machine.
         ......................... ISADC-02 passed test Replications
      Starting test: NCSecDesc
         ......................... ISADC-02 passed test NCSecDesc
      Starting test: NetLogons
         ......................... ISADC-02 passed test NetLogons
      Starting test: Advertising
         ......................... ISADC-02 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... ISADC-02 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... ISADC-02 passed test RidManager
      Starting test: MachineAccount
         ......................... ISADC-02 passed test MachineAccount
      Starting test: Services
         ......................... ISADC-02 passed test Services
      Starting test: ObjectsReplicated
         ......................... ISADC-02 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... ISADC-02 passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... ISADC-02 failed test frsevent
      Starting test: kccevent
         ......................... ISADC-02 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 12/28/2010   21:32:01
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 12/28/2010   22:20:58
            (Event String could not be retrieved)
         ......................... ISADC-02 failed test systemlog
      Starting test: VerifyReferences
         ......................... ISADC-02 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : ABC
      Starting test: CrossRefValidation
         ......................... iservices passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... iservices passed test CheckSDRefDom

   Running enterprise tests on : iservices.com
      Starting test: Intersite
         ......................... iservices.com passed test Intersite
      Starting test: FsmoCheck
         ......................... iservices.com passed test FsmoCheck
Dear Expert,

Is thier any update to do further rectification regarding failure of replication,systemlog and frsevent.

Waiting for promt response with solution.

Kind Regards,
Ravi Pratap
Dear Expert,

Please look into this question on urgent basis.

Thanks,
Ravi Pratap
Dear Expert,

Is their any update regarding the above mentioned problem.

Please do the needful on urgent basis due to this my production is hampering.

Waiting for your promt response.

Kind Regards,
Ravi Pratap
"Dns Servers. . . . . . . . : 10.x.x.x(ADC IP Address)
                                     10.x.x.x(DC IP Address)
                                     4.2.2.2(ISP DNS)
                                     202.138.103.100(ISP DNS)"

why do you have set up ISP's DNS servers in server NIC's properties? You should have only your internal DNS servers set up there. Configure Forwarders in DNS management console using ISP's DNS servers. It could cause problems in your network.

Please remove ISP's DNS servers from server NIC's properties. Leave there only your domain DNS servers.

If you need assistance, let me know.

Krzysztof
Good Solution