Solved

Windows 2003 can't find domain

Posted on 2011-03-10
6
365 Views
Last Modified: 2012-06-22
Our System...
We have a SBS 2003 box running our network but this concerns a 2003 box that is secondary
domain control, terminal server, fax server, print server, and Autodesk Vault on SQL 2005 express.

How I got into this mess...
We had an auto update from MS (sql 2005 express SP4) which disabled Autodesk Vault.
SP4 can't be uninstalled so I had to uninstall Vault and SQL. Unfortunately they wouldn't reinstall.
Our vendor advised us that the server would need a rebuild in order to reinstall the product. At this
point the server was working fine, just Vault wasn't working. Then I did the dumb thing. I restored the
server from a backup tape to it's state before the problem (which by now was 10 days old)

The problem...
Everything appeared to work fine except that the server cannot find the domain. I can see the network
and mapped drives ok but not much else works. No internet access, ipconfig /renew give "...no adapter
in permissible state". Netdiag says winsock test faileddns, test failed, dc discovery test failed,
trust relationship test failed, ldap test failed. Obviously active directory isn't working either since it
can't see the domain.

If I just get this talking to the domain again I think I'm actually in good shape and the original software
issue will be resolved as well.
0
Comment
Question by:RogerC70
  • 4
  • 2
6 Comments
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 35099081
Sounds like your AD state is very broken. My advice would be to dcpromo the machine in questoin to demote it from thinking it is a domain controller.

On the SBS side of things, go in and manually remove the server from AD and use ntdsutil to clean up the metadata.

Then join the machine to the domain as a member server. Since your AD is still intact and the rest of your backup succeeded, the SIDs should all still be the same and *most* everything should snap back and start working.

Then, if you so choose, you can re-dcpromo the server as a secondary DC (although personally with that many other roles running, I *don't* recommend it...)

-Cliff
0
 

Author Comment

by:RogerC70
ID: 35099117
Hi Cliff,
Thanks for responding. I tried dcpromo but it fails because it can't see the domain controller. The error message suggests making it a member of a workgroup but this isn't an available option either.
0
 

Author Comment

by:RogerC70
ID: 35099142
Also dcpromo has a message support for specified socket type does not exist in this address family. Forgot to mention I've already tried winsock repairs with the usual netsh int ip... and netsh winsock reset.
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 56

Accepted Solution

by:
Cliff Galiher earned 500 total points
ID: 35099177
If you have a spare switch, plug the machine into that switch (aka completely isolated) then make sure that its DNS settings only point to itself. It should then see itself as a DC and allow it to demote. This clearly won't replicate back to SBS hence the need to clean up manually, but should *eventually* get you back to a consistent state.

-Cliff
0
 

Author Comment

by:RogerC70
ID: 35099195
I'll try that thanks Cliff.
0
 

Author Closing Comment

by:RogerC70
ID: 35176335
Thanks for your help Cliff, sorry for taking so long to get back on this.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction At 19:33 (UST) on Tuesday 21st September the long awaited email arrived with the subject title of “ANNOUNCING THE AVAILABILITY OF WINDOWS SBS 7 PREVIEW”.  It was time to drop whatever I was doing and dedicate as much bandwidth as possi…
This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Small Business Server 2011. NOTE: This guide has been written using the preview version of SBS2011 therefore some of the screens may …
A short film showing how OnPage and Connectwise integration works.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

937 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now