[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Problem with Users Accounts

Posted on 2011-04-28
27
Medium Priority
?
693 Views
Last Modified: 2012-06-21
Hi guys, I've been experiencing a problem with some of my user accounts over the past 10days or so. Initially, I thought it was an isolated situation however, the problem had repeated itself severally in the past days and I'm beginning to wonder what might be wrong.

Here is the problem:
Some of my users just suddenly start experiencing identity related issues after signing on to their PCs. The incidents includes - MS Outlook and Internet Explorer pops a login window when started. When they try to access a network location they receive a window also asking them to logon. Sometimes this problem goes away in a few minutes such that by the time a support staff gets to the user's desk, the problem is no longer there. However, when the problem persists, support staffs usually do either or both of the following to resolve it: remove the affected PC from the domain, restart it and join it back to the domain OR log the user out, delete the User's account from Active Directory users and computers MMC console, recreate the user account. However, this still doesn't prevent the problem from occurring a day or two later with the same user account.

In addition, some of the other PC's name on the domain suddenly changes. This happens only on Windows 7 PCs though. For example, say a Windows 7 PC that was a domain member which was originally named Stev07 suddenly changes name the next morning to HP-USER!

NB: When I check the log on by ISA Server, I notice that when IE start demanding a login, the requests are logged for Anonymouse users anonymous Internet access is not permitted on this network!

What do you think might be wrong here please? Kindly bail me out of this one guys.

Some background:
I run a network spread across two locations linked by Microwave Radios (I'd call them location A and location B respectively)
Location A has two Domain controllers (I'd call them DC1 and DC2), which are both Windows Server 2003 boxes. DC2 also host Exchange 2003 (I know this is not recommended only learnt this after the action and since it didn't seem to be an issue, left it alone). Most of the PCs in Location A are Windows XP Pro PCs and point at DC1 as the primary DNS and DCs 2 and 3 as Secondary and Tertiary DNS respectively

Location B has a domain controller DC3 which runs Windows Server 2008. Most of the PCs in Location B are Windows 7 Pro PCs. All PCs in Loc B point to DC3 as the Primary DNS server and DCs 1 and 2 as their Secondary and Tertiary DNS servers respectively.

All PCs and Servers are shutdown at the close of work
0
Comment
Question by:enlconsortium
  • 11
  • 9
  • 7
27 Comments
 
LVL 15

Expert Comment

by:JBond2010
ID: 35482508
The first thing to do would be to run DCdiag on the the Domain Controllers. Can you please do this and post the output information.


Thank you,

JBond2010
0
 
LVL 17

Expert Comment

by:aoakeley
ID: 35482526
> All PCs and Servers are shutdown at the close of work

Are your DC's in sync? if all servers are shut down every day they could very well be out of sync in sone way.
- Are there any errors in the FRS event logs?
- Are your AD Sites and services setup correctly with the corrct subnets etc?

Not sure about the computer names changing.. but the rest of it sounds like user and computer accounts not replicating properly between the DC's. As a quick test if you create a user on each dc (call it userdc1, userdc2, userdc3 created on each dc individually) do all the users replicate to all DC's?

Andy
0
 

Author Comment

by:enlconsortium
ID: 35482646
Thanks guys for your response.
@ JBond2010, please find attached text file for result of dcdiag run
@ aoakeley, yes, there are errors in FRS log (see below)
What exactly am I looking out for with the AD Sites and Services?

Yes, creating the three user accounts across the three DCs, they to all DCs replicated after a about 2 to 5 seconds (but the PDC took a little longer, about 30 - 60 seconds).

Below is the text of the FRS log entry (this log is from the PDC)


Event Type:      Error
Event Source:      NtFrs
Event Category:      None
Event ID:      13568
Date:            27/04/2011
Time:            5:11:39 PM
User:            N/A
Computer:      ENLAPAPA1
Description:
The File Replication Service has detected that the replica set "DOMAIN SYSTEM VOLUME (SYSVOL SHARE)" is in JRNL_WRAP_ERROR.
 
 Replica set name is    : "DOMAIN SYSTEM VOLUME (SYSVOL SHARE)"
 Replica root path is   : "c:\windows\sysvol\domain"
 Replica root volume is : "\\.\C:"
 A Replica set hits JRNL_WRAP_ERROR when the record that it is trying to read from the NTFS USN journal is not found.  This can occur because of one of the following reasons.
 
 [1] Volume "\\.\C:" has been formatted.
 [2] The NTFS USN journal on volume "\\.\C:" has been deleted.
 [3] The NTFS USN journal on volume "\\.\C:" has been truncated. Chkdsk can truncate the journal if it finds corrupt entries at the end of the journal.
 [4] File Replication Service was not running on this computer for a long time.
 [5] File Replication Service could not keep up with the rate of Disk IO activity on "\\.\C:".
 Setting the "Enable Journal Wrap Automatic Restore" registry parameter to 1 will cause the following recovery steps to be taken to automatically recover from this error state.
 [1] At the first poll, which will occur in 5 minutes, this computer will be deleted from the replica set. If you do not want to wait 5 minutes, then run "net stop ntfrs" followed by "net start ntfrs" to restart the File Replication Service.
 [2] At the poll following the deletion this computer will be re-added to the replica set. The re-addition will trigger a full tree sync for the replica set.
 
WARNING: During the recovery process data in the replica tree may be unavailable. You should reset the registry parameter described above to 0 to prevent automatic recovery from making the data unexpectedly unavailable if this error condition occurs again.
 
To change this registry parameter, run regedit.
 
Click on Start, Run and type regedit.
 
Expand HKEY_LOCAL_MACHINE.
Click down the key path:
   "System\CurrentControlSet\Services\NtFrs\Parameters"
Double click on the value name
   "Enable Journal Wrap Automatic Restore"
and update the value.
 
If the value name is not present you may add it with the New->DWORD Value function under the Edit Menu item. Type the value name exactly as shown above.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.



On the other two DCs ,DC2 and DC3 in my original scenario, there are similar warnings  but no error, below is the text of the warnings:


Event Type:      Warning
Event Source:      NtFrs
Event Category:      None
Event ID:      13508
Date:            28/04/2011
Time:            9:02:08 AM
User:            N/A
Computer:      ENLAPAPA3
Description:
The File Replication Service is having trouble enabling replication from ENLAPAPA1 to ENLAPAPA3 for c:\windows\sysvol\domain using the DNS name enlapapa1.enl.com. FRS will keep retrying.
 Following are some of the reasons you would see this warning.
 
 [1] FRS can not correctly resolve the DNS name enlapapa1.enl.com from this computer.
 [2] FRS is not running on enlapapa1.enl.com.
 [3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers.
 
 This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 05 00 00 00               ....    





Log Name:      File Replication Service
Source:        NtFrs
Date:          4/28/2011 8:25:41 AM
Event ID:      13508
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      ENLAPAPA5-1.enl.com
Description:
The File Replication Service is having trouble enabling replication from ENLAPAPA1 to ENLAPAPA5-1 for c:\windows\sysvol\domain using the DNS name enlapapa1.enl.com. FRS will keep retrying.
 Following are some of the reasons you would see this warning.
 
 [1] FRS can not correctly resolve the DNS name enlapapa1.enl.com from this computer.
 [2] FRS is not running on enlapapa1.enl.com.
 [3] The topology information in the Active Directory Domain Services for this replica has not yet replicated to all the Domain Controllers.
 
 This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="NtFrs" />
    <EventID Qualifiers="32768">13508</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2011-04-28T07:25:41.000Z" />
    <EventRecordID>350</EventRecordID>
    <Channel>File Replication Service</Channel>
    <Computer>ENLAPAPA5-1.enl.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data>ENLAPAPA1</Data>
    <Data>ENLAPAPA5-1</Data>
    <Data>c:\windows\sysvol\domain</Data>
    <Data>enlapapa1.enl.com</Data>
    <Binary>D5040000</Binary>
  </EventData>
</Event>
dcdiag-result.txt
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 15

Expert Comment

by:JBond2010
ID: 35482721
@ enlconsortium, as you can see there are a number of errors. Pay particular attention to these errors and begin to correct them. It tells you in the error report how to correct them.

[2] The NTFS USN journal on volume "\\.\C:" has been deleted.
 [3] The NTFS USN journal on volume "\\.\C:" has been truncated. Chkdsk can truncate the journal if it finds corrupt entries at the end of the journal.

[5] File Replication Service could not keep up with the rate of Disk IO activity on "\\.\C:".
 Setting the "Enable Journal Wrap Automatic Restore" registry parameter to 1 will cause the following recovery steps to be taken to automatically recover from this error state.

WARNING: During the recovery process data in the replica tree may be unavailable. You should reset the registry parameter described above to 0 to prevent automatic recovery from making the data unexpectedly unavailable if this error condition occurs again.
 
To change this registry parameter, run regedit.
 
Click on Start, Run and type regedit.
 
Expand HKEY_LOCAL_MACHINE.
Click down the key path:
   "System\CurrentControlSet\Services\NtFrs\Parameters"
Double click on the value name
   "Enable Journal Wrap Automatic Restore"
and update the value.
 
If the value name is not present you may add it with the New->DWORD Value function under the Edit Menu item. Type the value name exactly as shown above.
0
 
LVL 17

Expert Comment

by:aoakeley
ID: 35482745
You need to follow the instructions to fix the JRNL_WRAP_ERROR. Do this on the FSMO role holder. It will delete all other SYSVOL replicas and re-replicate from the master.

AD sites and services should have a site for each subnet. Sounds to me like you have all servers and subnets in the one site. Though don;t try fixing this until you have fixed the JRNL WRAP
here is some basic info: http://www.activewin.com/win2000/step_by_step/active_directory/adsites.shtml 

0
 
LVL 17

Expert Comment

by:aoakeley
ID: 35482762
beaten by Bond, Jbond !
0
 
LVL 15

Expert Comment

by:JBond2010
ID: 35482793
lol;)
0
 

Author Comment

by:enlconsortium
ID: 35483100
Ok, thanks guys, let me try these out and get back to you
0
 
LVL 17

Expert Comment

by:aoakeley
ID: 35483144
on very rare occasions I hvae had the JRNL_WRAP fix go tits up and you lose all your policies.. if this happens use this to get out of jail http://support.microsoft.com/kb/290762 

have fun :)
0
 
LVL 15

Expert Comment

by:JBond2010
ID: 35483176
@ enlconsortium, your welcome:)
0
 
LVL 15

Expert Comment

by:JBond2010
ID: 35483192
@ enlconsortium, now you can see the importantance of running DCdiag before doing anything else. This will tell you the overall condition Active Directory is in.
0
 

Author Comment

by:enlconsortium
ID: 35483917
Yeah, u right. Thanks all.
Your recommendation was helpful. DC1 and DC2 seem to be ok. Pasted the result of dcdiag for both below. However, running dcdiag on DC3 had A LOT of errors.
@ aoakeley, I read through the page @ d provided link but still unsure about a few things:
Yes, the 3 DCs are in the same site. So I need to separate DC3 into a new site. I've created this new site but hadn't moved DC3 just yet since I was sure:
1. How to configure the connection between the two sites
2. If there are additional steps I might need to take after configuring the connection between the two sites. All machines in the two sites are within the same subnet and IPs manually assigned (but IP assignment is done by site so a range of IPs belong to Loc A and another to Loc B but both Loc have the same subnet mask)

I'm sorry if I sound dumb, but hadn't really done this before!
0
 
LVL 15

Expert Comment

by:JBond2010
ID: 35484004
You configure connection between 2 site through Active Directory Sites and Services. You configure and add the sites and then the subnets. The subnet masks on the 2 sites will have to be different for eg: 192.168.1.0 would be say Head Office and then 192.168.2.0 would be the Branch Office.
0
 
LVL 17

Accepted Solution

by:
aoakeley earned 1200 total points
ID: 35484046
Don't do the sites until you have fixed the JRNL WRAP issue. Have you done the following and waited 15 mins for it to fix itself up?

Click on Start, Run and type regedit.
 
Expand HKEY_LOCAL_MACHINE.
Click down the key path:
   "System\CurrentControlSet\Services\NtFrs\Parameters"
Double click on the value name
   "Enable Journal Wrap Automatic Restore"
and update the value.
0
 
LVL 15

Assisted Solution

by:JBond2010
JBond2010 earned 800 total points
ID: 35484101
Do not make any configuration changes until you have the errors resolved. As for my previous comment

WARNING: During the recovery process data in the replica tree may be unavailable. You should reset the registry parameter described above to 0 to prevent automatic recovery from making the data unexpectedly unavailable if this error condition occurs again.
 
To change this registry parameter, run regedit.
 
Click on Start, Run and type regedit.
 
Expand HKEY_LOCAL_MACHINE.
Click down the key path:
   "System\CurrentControlSet\Services\NtFrs\Parameters"
Double click on the value name
   "Enable Journal Wrap Automatic Restore"
and update the value.
 
If the value name is not present you may add it with the New->DWORD Value function under the Edit Menu item. Type the value name exactly as shown above.
0
 
LVL 15

Expert Comment

by:JBond2010
ID: 35484121
Also, it is adviceable to run chkdsk, if you have not done so already.

 [3] The NTFS USN journal on volume "\\.\C:" has been truncated. Chkdsk can truncate the journal if it finds corrupt entries at the end of the journal.
0
 

Author Comment

by:enlconsortium
ID: 35491248
Hi guys, sorry I'm just returning. Had power surge incident and was distracted from solving this problem for a while.

@ aoakeley, already did the "Enable Journal Wrap Automatic Restore" and even repeated it today again after I got done resolving my surge issues. I had to repeat it cause the issues seem to be repeating itself as almost all my users started having the logon issues described earlier. I observed that the only user group that don't seem to exhibit this problem are Administrators. Does that make sense to you guys?
Anyways, a few minutes after repeating the steps again today, the issue seemed resolved. However I still have a bunch of errors when I ran dcdiag. See below for the result of dcdiag for DC1 and DC2 (as described in my scenario above), however, because the result of dcdiag for DC3 is too long, I directed output to file, so see the attached file.

@ JBond2010, yeah I did reset the value of "Enable Journal Wrap Automatic Restore" back to 0 after restarting ntfrs
No, I have not done the site tingy. Right now DC3 doesn't seem to be replicating with any of the others. Really getting on my nerves. Any fresh ideas?
I'm considering demoting DC3 and promoting it again later. Do you think that is a smart idea?


DCDIAG RESULT FOR DC1


C:\Documents and Settings\t.adeosun>DCDIAG

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Burma\ENLAPAPA1
      Starting test: Connectivity
         ......................... ENLAPAPA1 passed test Connectivity

Doing primary tests

   Testing server: Burma\ENLAPAPA1
      Starting test: Replications
         ......................... ENLAPAPA1 passed test Replications
      Starting test: NCSecDesc
         ......................... ENLAPAPA1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... ENLAPAPA1 passed test NetLogons
      Starting test: Advertising
         ......................... ENLAPAPA1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... ENLAPAPA1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... ENLAPAPA1 passed test RidManager
      Starting test: MachineAccount
         ......................... ENLAPAPA1 passed test MachineAccount
      Starting test: Services
         ......................... ENLAPAPA1 passed test Services
      Starting test: ObjectsReplicated
         ......................... ENLAPAPA1 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... ENLAPAPA1 passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... ENLAPAPA1 failed test frsevent
      Starting test: kccevent
         ......................... ENLAPAPA1 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0xC000001A
            Time Generated: 04/29/2011   14:08:34
            Event String: While processing an AS request for target service
         ......................... ENLAPAPA1 failed test systemlog
      Starting test: VerifyReferences
         ......................... ENLAPAPA1 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : enl
      Starting test: CrossRefValidation
         ......................... enl passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... enl passed test CheckSDRefDom

   Running enterprise tests on : enl.com
      Starting test: Intersite
         ......................... enl.com passed test Intersite
      Starting test: FsmoCheck
         ......................... enl.com passed test FsmoCheck


DCDIAG RESULT FOR DC2



C:\Documents and Settings\t.adeosun>DCDIAG

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Burma\ENLAPAPA3
      Starting test: Connectivity
         ......................... ENLAPAPA3 passed test Connectivity

Doing primary tests

   Testing server: Burma\ENLAPAPA3
      Starting test: Replications
         ......................... ENLAPAPA3 passed test Replications
      Starting test: NCSecDesc
         ......................... ENLAPAPA3 passed test NCSecDesc
      Starting test: NetLogons
         ......................... ENLAPAPA3 passed test NetLogons
      Starting test: Advertising
         ......................... ENLAPAPA3 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... ENLAPAPA3 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... ENLAPAPA3 passed test RidManager
      Starting test: MachineAccount
         ......................... ENLAPAPA3 passed test MachineAccount
      Starting test: Services
         ......................... ENLAPAPA3 passed test Services
      Starting test: ObjectsReplicated
         ......................... ENLAPAPA3 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... ENLAPAPA3 passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... ENLAPAPA3 failed test frsevent
      Starting test: kccevent
         ......................... ENLAPAPA3 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 04/29/2011   13:42:35
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 04/29/2011   13:42:36
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 04/29/2011   13:42:37
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 04/29/2011   13:42:37
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 04/29/2011   13:42:38
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 04/29/2011   13:42:39
            (Event String could not be retrieved)
         ......................... ENLAPAPA3 failed test systemlog
      Starting test: VerifyReferences
         ......................... ENLAPAPA3 passed test VerifyReferences

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : enl
      Starting test: CrossRefValidation
         ......................... enl passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... enl passed test CheckSDRefDom

   Running enterprise tests on : enl.com
      Starting test: Intersite
         ......................... enl.com passed test Intersite
      Starting test: FsmoCheck
         ......................... enl.com passed test FsmoCheck

dcdiag-result.txt
0
 
LVL 17

Assisted Solution

by:aoakeley
aoakeley earned 1200 total points
ID: 35491494
I am reading this on my phone, but I would hazard a guess that dc3 is having some dns or connectivity issues. But if it has been out of sync for a long time then you are correct demoting and re promoting it is probably your quickest resolution. Once all dcdiag are good, sort out your sites.

Until all dc are in sync you will continue to have issues
0
 

Author Comment

by:enlconsortium
ID: 35492649
Ok, I just demoted DC3. Will keep you updated. However, there is a long holiday ahead and I might not be able to get back to you guys till next week Tuesday.
0
 
LVL 15

Expert Comment

by:JBond2010
ID: 35492706
No problem:)
0
 
LVL 17

Expert Comment

by:aoakeley
ID: 35495534
sweet :)
0
 

Author Comment

by:enlconsortium
ID: 35511766
Ok guys, DC3 had been taken down and currently the symptoms are gone. You guys are the bomb! Thanks.
However, I ran dcdiag on DC1 and DC2 and still got some error, which I've pasted below for your advice.

Additionally, I want to still return DC3. Any advice on how to ensure I do it right?


Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Burma\ENLAPAPA1
      Starting test: Connectivity
         ......................... ENLAPAPA1 passed test Connectivity

Doing primary tests

   Testing server: Burma\ENLAPAPA1
      Starting test: Replications
         ......................... ENLAPAPA1 passed test Replications
      Starting test: NCSecDesc
         ......................... ENLAPAPA1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... ENLAPAPA1 passed test NetLogons
      Starting test: Advertising
         ......................... ENLAPAPA1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... ENLAPAPA1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... ENLAPAPA1 passed test RidManager
      Starting test: MachineAccount
         ......................... ENLAPAPA1 passed test MachineAccount
      Starting test: Services
         ......................... ENLAPAPA1 passed test Services
      Starting test: ObjectsReplicated
         ......................... ENLAPAPA1 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... ENLAPAPA1 passed test frssysvol
      Starting test: frsevent
         ......................... ENLAPAPA1 passed test frsevent
      Starting test: kccevent
         ......................... ENLAPAPA1 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:16
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:17
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:18
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:18
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:41:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:41:46
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:41:46
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:41:47
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:41:47
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:41:48
            (Event String could not be retrieved)
         ......................... ENLAPAPA1 failed test systemlog
      Starting test: VerifyReferences
         ......................... ENLAPAPA1 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : enl
      Starting test: CrossRefValidation
         ......................... enl passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... enl passed test CheckSDRefDom

   Running enterprise tests on : enl.com
      Starting test: Intersite
         ......................... enl.com passed test Intersite
      Starting test: FsmoCheck
         ......................... enl.com passed test FsmoCheck




==================================================
Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Burma\ENLAPAPA3
      Starting test: Connectivity
         ......................... ENLAPAPA3 passed test Connectivity

Doing primary tests

   Testing server: Burma\ENLAPAPA3
      Starting test: Replications
         ......................... ENLAPAPA3 passed test Replications
      Starting test: NCSecDesc
         ......................... ENLAPAPA3 passed test NCSecDesc
      Starting test: NetLogons
         ......................... ENLAPAPA3 passed test NetLogons
      Starting test: Advertising
         ......................... ENLAPAPA3 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... ENLAPAPA3 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... ENLAPAPA3 passed test RidManager
      Starting test: MachineAccount
         ......................... ENLAPAPA3 passed test MachineAccount
      Starting test: Services
         ......................... ENLAPAPA3 passed test Services
      Starting test: ObjectsReplicated
         ......................... ENLAPAPA3 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... ENLAPAPA3 passed test frssysvol
      Starting test: frsevent
         ......................... ENLAPAPA3 passed test frsevent
      Starting test: kccevent
         ......................... ENLAPAPA3 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x000016AD
            Time Generated: 05/03/2011   11:26:19
            Event String: The session setup from the computer OPS05 failed
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:30
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:30
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:31
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:31
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:33
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:33
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:34
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:34
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:40
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:41
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:42
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 05/03/2011   11:40:42
            (Event String could not be retrieved)
         ......................... ENLAPAPA3 failed test systemlog
      Starting test: VerifyReferences
         ......................... ENLAPAPA3 passed test VerifyReferences

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : enl
      Starting test: CrossRefValidation
         ......................... enl passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... enl passed test CheckSDRefDom

   Running enterprise tests on : enl.com
      Starting test: Intersite
         ......................... enl.com passed test Intersite
      Starting test: FsmoCheck
         ......................... enl.com passed test FsmoCheck
0
 
LVL 15

Assisted Solution

by:JBond2010
JBond2010 earned 800 total points
ID: 35511998
It should be fine to repromote the DC with the same name or you could use a different name. Make sure to go though all the steps in the link I provided below.

http://support.microsoft.com/kb/555846


Regards,

JBond2010
0
 
LVL 17

Expert Comment

by:aoakeley
ID: 35512785
those DCdiag look fine... just some errors from old errors in the logs.

Make sure you set the DNS on the NIC of DC3 to point to DNS on DC1 or DC2 and run DCPROMO and you should be fine. (enough TLS's in that sentence for you?!)

Andy
0
 

Author Closing Comment

by:enlconsortium
ID: 35738263
Thanks guys
0
 
LVL 15

Expert Comment

by:JBond2010
ID: 35738400
Your welcome:)
0
 
LVL 17

Expert Comment

by:aoakeley
ID: 35738633
:)
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question