Link to home
Start Free TrialLog in
Avatar of GSLElectric
GSLElectric

asked on

DNS error

I have a new AD site that isn't replicating I'm getting several DNS errors


Event ID 4015
The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly. The extended error debug information (which may be empty) is "". The event data contains the error.
Avatar of Rich Weissler
Rich Weissler

(I might suggest adding this to the Active Directory Zone too... )

Please confirm some assumptions:
  When you say a new AD Site, do you mean a new AD Integrated Zone?
  Or did you just put a DC in a new Site, and the existing Integrated Zones aren't replicating?  (In which case, I assume you are also getting other replication errors in logs beyond DNS?)
Avatar of GSLElectric

ASKER

I just ran dcdiag and there does seem to be some replication issues.  my zone should be AD integrated, but how would I double check?

      Starting test: Connectivity
         ......................... GSLENG passed test Connectivity

Doing primary tests

   Testing server: Eng\GSLENG
      Starting test: Replications
         [Replications Check,GSLENG] A recent replication attempt failed:
            From GSLPROV1 to GSLENG
            Naming Context: DC=ForestDnsZones,DC=gslelectric,DC=com
            The replication generated an error (1256):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
            The failure occurred at 2011-03-10 13:51:02.
            The last success occurred at 2011-03-07 16:51:01.
            67 failures have occurred since the last success.
         [Replications Check,GSLENG] A recent replication attempt failed:
            From GSLPROV1 to GSLENG
            Naming Context: DC=DomainDnsZones,DC=gslelectric,DC=com
            The replication generated an error (1256):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
            The failure occurred at 2011-03-10 13:51:02.
            The last success occurred at 2011-03-07 16:51:01.
            67 failures have occurred since the last success.
         [Replications Check,GSLENG] A recent replication attempt failed:
            From GSLPROV1 to GSLENG
            Naming Context: CN=Schema,CN=Configuration,DC=gslelectric,DC=com
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2011-03-10 13:52:27.
            The last success occurred at 2011-03-07 16:51:01.
            67 failures have occurred since the last success.
            [GSLPROV1] DsBindWithSpnEx() failed with error 1722,
            The RPC server is unavailable..
            The source remains down. Please check the machine.
         [Replications Check,GSLENG] A recent replication attempt failed:
            From GSLPROV1 to GSLENG
            Naming Context: CN=Configuration,DC=gslelectric,DC=com
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2011-03-10 13:51:44.
            The last success occurred at 2011-03-07 16:51:01.
            67 failures have occurred since the last success.
            The source remains down. Please check the machine.
         [Replications Check,GSLENG] A recent replication attempt failed:
            From GSLPROV1 to GSLENG
            Naming Context: DC=gslelectric,DC=com
            The replication generated an error (1722):
            The RPC server is unavailable.
            The failure occurred at 2011-03-10 13:51:02.
            The last success occurred at 2011-03-07 16:51:01.
            67 failures have occurred since the last success.
            The source remains down. Please check the machine.
         REPLICATION-RECEIVED LATENCY WARNING
         GSLENG:  Current time is 2011-03-10 14:13:52.
            DC=ForestDnsZones,DC=gslelectric,DC=com
               Last replication recieved from GSLLVDELL at 2011-03-07 15:57:54.
               Last replication recieved from GSLPHX at 2011-03-07 15:57:53.
               Last replication recieved from GSLPROV1 at 2011-03-07 16:51:01.
            DC=DomainDnsZones,DC=gslelectric,DC=com
               Last replication recieved from GSLLVDELL at 2011-03-07 15:57:53.
               Last replication recieved from GSLPHX at 2011-03-07 15:57:53.
               Last replication recieved from GSLPROV1 at 2011-03-07 16:51:01.
            CN=Schema,CN=Configuration,DC=gslelectric,DC=com
               Last replication recieved from GSLDR at 2011-03-07 15:57:51.
               Last replication recieved from GSLLVDELL at 2011-03-07 15:57:52.
               Last replication recieved from GSLPHX at 2011-03-07 15:57:52.
               Last replication recieved from GSLPROV1 at 2011-03-07 16:51:01.
            CN=Configuration,DC=gslelectric,DC=com
               Last replication recieved from GSLDR at 2011-03-07 16:43:21.
               Last replication recieved from GSLLVDELL at 2011-03-07 15:57:52.
               Last replication recieved from GSLPHX at 2011-03-07 15:57:51.
               Last replication recieved from GSLPROV1 at 2011-03-07 16:51:01.
            DC=gslelectric,DC=com
               Last replication recieved from GSLDR at 2011-03-07 16:49:00.
               Last replication recieved from GSLLVDELL at 2011-03-07 15:57:53.
               Last replication recieved from GSLPHX at 2011-03-07 15:57:53.
               Last replication recieved from GSLPROV1 at 2011-03-07 16:51:01.
         REPLICATION-RECEIVED LATENCY WARNING
          Source site:
         CN=NTDS Site Settings,CN=lasvegas,CN=Sites,CN=Configuration,DC=gslelect
ric,DC=com
          Current time: 2011-03-10 14:14:13
          Last update time: 2011-03-07 15:14:52
          Check if source site has an elected ISTG running.
          Check replication from source site to this server.
         REPLICATION-RECEIVED LATENCY WARNING
          Source site:
         CN=NTDS Site Settings,CN=phx,CN=Sites,CN=Configuration,DC=gslelectric,D
C=com
          Current time: 2011-03-10 14:14:13
          Last update time: 2011-03-07 15:43:59
          Check if source site has an elected ISTG running.
          Check replication from source site to this server.
         REPLICATION-RECEIVED LATENCY WARNING
          Source site:
         CN=NTDS Site Settings,CN=sandy,CN=Sites,CN=Configuration,DC=gslelectric
,DC=com
          Current time: 2011-03-10 14:14:13
          Last update time: 2011-03-07 16:33:56
          Check if source site has an elected ISTG running.
          Check replication from source site to this server.
         ......................... GSLENG passed test Replications
      Starting test: NCSecDesc
         ......................... GSLENG passed test NCSecDesc
      Starting test: NetLogons
         ......................... GSLENG passed test NetLogons
      Starting test: Advertising
         Warning: GSLENG is not advertising as a time server.
         ......................... GSLENG failed test Advertising
      Starting test: KnowsOfRoleHolders
         Warning: GSLPROV1 is the Schema Owner, but is not responding to DS RPC
Bind.
         [GSLPROV1] LDAP search failed with error 58,
         The specified server cannot perform the requested operation..
         Warning: GSLPROV1 is the Schema Owner, but is not responding to LDAP Bi
nd.
         Warning: GSLPROV1 is the Domain Owner, but is not responding to DS RPC
Bind.
         Warning: GSLPROV1 is the Domain Owner, but is not responding to LDAP Bi
nd.
         Warning: GSLPROV1 is the PDC Owner, but is not responding to DS RPC Bin
d.
         Warning: GSLPROV1 is the PDC Owner, but is not responding to LDAP Bind.

         Warning: GSLPROV1 is the Rid Owner, but is not responding to DS RPC Bin
d.
         Warning: GSLPROV1 is the Rid Owner, but is not responding to LDAP Bind.

         Warning: GSLPROV1 is the Infrastructure Update Owner, but is not respon
ding to DS RPC Bind.
         Warning: GSLPROV1 is the Infrastructure Update Owner, but is not respon
ding to LDAP Bind.
         ......................... GSLENG failed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... GSLENG failed test RidManager
      Starting test: MachineAccount
         ......................... GSLENG passed test MachineAccount
      Starting test: Services
         ......................... GSLENG passed test Services
      Starting test: ObjectsReplicated
         ......................... GSLENG passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... GSLENG passed test frssysvol
      Starting test: frsevent
         ......................... GSLENG passed test frsevent
      Starting test: kccevent
         ......................... GSLENG passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:36
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:36
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:36
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:36
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:36
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:37
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:37
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:37
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:37
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:37
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:38
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:38
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:38
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:38
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   13:42:38
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC25A001D
            Time Generated: 03/10/2011   14:11:09
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000612
            Time Generated: 03/10/2011   14:12:02
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:06
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:06
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:06
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:06
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:07
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:07
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:07
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:07
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:07
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:08
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:08
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:08
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:08
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:08
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 03/10/2011   14:13:09
            (Event String could not be retrieved)
         ......................... GSLENG failed test systemlog
      Starting test: VerifyReferences
         ......................... GSLENG passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : gslelectric
      Starting test: CrossRefValidation
         ......................... gslelectric passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... gslelectric passed test CheckSDRefDom

   Running enterprise tests on : gslelectric.com
      Starting test: Intersite
         ......................... gslelectric.com passed test Intersite
      Starting test: FsmoCheck
         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355
         A Global Catalog Server could not be located - All GC's are down.
         Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355
         A Primary Domain Controller could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 135
5
         A Good Time Server could not be located.
         ......................... gslelectric.com failed test FsmoCheck

C:\Documents and Settings\Administrator.GSLELECTRIC>
ASKER CERTIFIED SOLUTION
Avatar of Andrej Pirman
Andrej Pirman
Flag of Slovenia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
so should you  not have it point to public at all on the DNS or should you have it point to privat first and then public as secondary?  If it is the only DNS at the site should it point to itselft and then have a secondary server from a different site as the second DNS server?

I did confirm that SYSvol is visible.  I will run the netdiag /fix
> my zone should be AD integrated, but how would I double check?
  Within the dnsmgmt tool, select the zone, and pull up properties... On the General Tab, there is a field for Type -- and it should say Active Directory -- Integrated.

First impression looking at the dcdiag -- last replication was Monday evening (3/7/11).  Confirm network communication is good now?  Looks like even RPC connections to non-local DCs are failing... (PING, and/or attempt to map drive to the remote servers from the local one, etc?)
this is the results of the netdiag/fix.  I'm able to ping the domain controller at the other site, but for whatever reason from the main site I'm unable to ping the server at the remote site.?

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\Administrator.GSLELECTRIC>netdiag /fix

....................................

    Computer Name: GSLENG
    DNS Host Name: gsleng.gslelectric.com
    System info : Microsoft Windows Server 2003 R2 (Build 3790)
    Processor : x86 Family 6 Model 23 Stepping 6, GenuineIntel
    List of installed hotfixes :
        KB2079403
        KB2115168
        KB2121546
        KB2141007
        KB2229593
        KB2259922
        KB2296011
        KB2345886
        KB2347290
        KB2360937
        KB2378111
        KB2387149
        KB2393802
        KB2416451
        KB2419635
        KB2423089
        KB2440591
        KB2443105
        KB2443685
        KB2467659
        KB2476687
        KB2478953
        KB2478960
        KB2478971
        KB2479628
        KB2482017
        KB2482017-IE8
        KB2483185
        KB2485376
        KB923561
        KB925398_WMP64
        KB925876
        KB925902-v2
        KB926122
        KB927891
        KB929123
        KB932168
        KB933854
        KB935966
        KB936357
        KB938127
        KB941569
        KB943055
        KB944338-v2
        KB944653
        KB945553
        KB946026
        KB948496
        KB950762
        KB950974
        KB951748
        KB952004
        KB952069
        KB952954
        KB953298
        KB954155
        KB955759
        KB956572
        KB956744
        KB956802
        KB956803
        KB956844
        KB958469
        KB958644
        KB958869
        KB959426
        KB960803
        KB960859
        KB961063
        KB961501
        KB967715
        KB967723
        KB968389
        KB969059
        KB970430
        KB971029
        KB971032
        KB971657
        KB971737
        KB971961
        KB971961-IE8
        KB972270
        KB973507
        KB973540
        KB973815
        KB973869
        KB973904
        KB974112
        KB974318
        KB974392
        KB974571
        KB975025
        KB975467
        KB975558_WM8
        KB975560
        KB975562
        KB975713
        KB976662-IE8
        KB977816
        KB977914
        KB978338
        KB978542
        KB978601
        KB978695
        KB978706
        KB979309
        KB979482
        KB979687
        KB979907
        KB980195
        KB980232
        KB980436
        KB981322
        KB981332-IE8
        KB981350
        KB982132
        KB982214
        KB982381-IE8
        KB982632-IE8
        Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

    Adapter : Local Area Connection 2

        Netcard queries test . . . : Passed

        Host Name. . . . . . . . . : gsleng
        IP Address . . . . . . . . : 10.1.20.10
        Subnet Mask. . . . . . . . : 255.255.255.0
        Default Gateway. . . . . . : 10.1.20.254
        Dns Servers. . . . . . . . : 10.1.20.10
                                     10.1.2.7


        AutoConfiguration results. . . . . . : Passed

        Default gateway test . . . : Passed

        NetBT name test. . . . . . : Passed
        [WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenge
r Service', <20> 'WINS' names is missing.

        WINS service test. . . . . : Skipped
            There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
    List of NetBt transports currently configured:
        NetBT_Tcpip_{A39AF527-5C53-4D09-A5D6-25D12B93AC78}
    1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed
    [WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
    PASS - All the DNS entries for DC are registered on DNS server '10.1.20.10'
and other DCs also have some of the names registered.


Redir and Browser test . . . . . . : Passed
    List of NetBt transports currently bound to the Redir
        NetBT_Tcpip_{A39AF527-5C53-4D09-A5D6-25D12B93AC78}
    The redir is bound to 1 NetBt transport.

    List of NetBt transports currently bound to the browser
        NetBT_Tcpip_{A39AF527-5C53-4D09-A5D6-25D12B93AC78}
    The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Failed
    [FATAL] Secure channel to domain 'GSLELECTRIC' is broken. [ERROR_NO_LOGON_SE
RVERS]


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed
    [WARNING] Failed to query SPN registration on DC 'gslprov1.gslelectric.com'.

    [WARNING] Failed to query SPN registration on DC 'gsllvdell.gslelectric.com'
.
    [WARNING] Failed to query SPN registration on DC 'gslphx.gslelectric.com'.
    [WARNING] Failed to query SPN registration on DC 'gsldr.gslelectric.com'.


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
    No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

    Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully

C:\Documents and Settings\Administrator.GSLELECTRIC>netdiag /fix
I ran Nediag /fix again because I did find a few issue with my tcip configuration on the nic.  I can ping remote server both by name and IP.  The only test that fails is the trust relationship?




DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Failed
    [FATAL] Secure channel to domain 'GSLELECTRIC' is broken. [ERROR_NO_LOGO
RVERS]


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
    No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

    Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully
> I'm able to ping the domain controller at the other site, but for
> whatever reason from the main site I'm unable to ping the server at the remote site.?

Confirm that this means:
 From your workstation, you are able to ping GSLPROV1.
 From GSLENG, you are unable to ping GSLPROV1.

Are you able to confirm a network communication problems between sites?  (And/Or a routing problem?)

When you indicate that you 'have a new AD site' -- do you mean you recently added a site within Active Directory Sites and Services, and one of these DCs is within that site?  If that is the case, can you provide more information about what sites exist, what DCs are in each site, and what site connectors exist and connect which sites?