?
Solved

Windows 2003 can't find domain

Posted on 2011-03-10
6
Medium Priority
?
375 Views
Last Modified: 2012-06-22
Our System...
We have a SBS 2003 box running our network but this concerns a 2003 box that is secondary
domain control, terminal server, fax server, print server, and Autodesk Vault on SQL 2005 express.

How I got into this mess...
We had an auto update from MS (sql 2005 express SP4) which disabled Autodesk Vault.
SP4 can't be uninstalled so I had to uninstall Vault and SQL. Unfortunately they wouldn't reinstall.
Our vendor advised us that the server would need a rebuild in order to reinstall the product. At this
point the server was working fine, just Vault wasn't working. Then I did the dumb thing. I restored the
server from a backup tape to it's state before the problem (which by now was 10 days old)

The problem...
Everything appeared to work fine except that the server cannot find the domain. I can see the network
and mapped drives ok but not much else works. No internet access, ipconfig /renew give "...no adapter
in permissible state". Netdiag says winsock test faileddns, test failed, dc discovery test failed,
trust relationship test failed, ldap test failed. Obviously active directory isn't working either since it
can't see the domain.

If I just get this talking to the domain again I think I'm actually in good shape and the original software
issue will be resolved as well.
0
Comment
Question by:RogerC70
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 35099081
Sounds like your AD state is very broken. My advice would be to dcpromo the machine in questoin to demote it from thinking it is a domain controller.

On the SBS side of things, go in and manually remove the server from AD and use ntdsutil to clean up the metadata.

Then join the machine to the domain as a member server. Since your AD is still intact and the rest of your backup succeeded, the SIDs should all still be the same and *most* everything should snap back and start working.

Then, if you so choose, you can re-dcpromo the server as a secondary DC (although personally with that many other roles running, I *don't* recommend it...)

-Cliff
0
 

Author Comment

by:RogerC70
ID: 35099117
Hi Cliff,
Thanks for responding. I tried dcpromo but it fails because it can't see the domain controller. The error message suggests making it a member of a workgroup but this isn't an available option either.
0
 

Author Comment

by:RogerC70
ID: 35099142
Also dcpromo has a message support for specified socket type does not exist in this address family. Forgot to mention I've already tried winsock repairs with the usual netsh int ip... and netsh winsock reset.
0
Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

 
LVL 59

Accepted Solution

by:
Cliff Galiher earned 2000 total points
ID: 35099177
If you have a spare switch, plug the machine into that switch (aka completely isolated) then make sure that its DNS settings only point to itself. It should then see itself as a DC and allow it to demote. This clearly won't replicate back to SBS hence the need to clean up manually, but should *eventually* get you back to a consistent state.

-Cliff
0
 

Author Comment

by:RogerC70
ID: 35099195
I'll try that thanks Cliff.
0
 

Author Closing Comment

by:RogerC70
ID: 35176335
Thanks for your help Cliff, sorry for taking so long to get back on this.
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Ready to improve network connectivity? Watch this webinar to learn how SD-WANs and a one-click instant connect tool can boost provisions, deployment, and management of your cloud connection.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've often see, or have been asked, the question about the difference between the Exchange 2010 SP1 version, available as part of Small Business Server (SBS) 2011, and the “normal” Exchange 2010 SP1 Standard. The answer to the question is relativ…
I work for a company that primarily works with small businesses as their outsourced IT vendor. As such the majority of these customers utilize some version of Small Business Server. Due to the economics of running a small business, many of these cus…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question