Active Directory cannot connect to Global Catalog

carlsilver
carlsilver used Ask the Experts™
on
We have 2 servers

1 x Domain Controler, GC, DNS, DHCP etc

1 x Exchange & File Server

I can no longer create users or mailboxes on the Exchange Server. Both servers running Server 2008 R2 Enterprise.

Attached is a screenshot of the error i am getting in the event log on the domain controller.

 Error
DCDIAG also throws up errors when run on the DC/GC.

 
Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = DC01
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\DC01
      Starting test: Connectivity
         ......................... DC01 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\DC01
      Starting test: Advertising
         ......................... DC01 passed test Advertising
      Starting test: FrsEvent
         ......................... DC01 passed test FrsEvent
      Starting test: DFSREvent
         ......................... DC01 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... DC01 passed test SysVolCheck
      Starting test: KccEvent
         A warning event occurred.  EventID: 0x80000677
            Time Generated: 05/17/2011   13:56:27
            Event String:
            Active Directory Domain Services attempted to communicate with the f
ollowing global catalog and the attempts were unsuccessful.
         An error event occurred.  EventID: 0xC0000466
            Time Generated: 05/17/2011   13:56:27
            Event String:
            Active Directory Domain Services was unable to establish a connectio
n with the global catalog.
         A warning event occurred.  EventID: 0x80000677
            Time Generated: 05/17/2011   14:06:30
            Event String:
            Active Directory Domain Services attempted to communicate with the f
ollowing global catalog and the attempts were unsuccessful.
         An error event occurred.  EventID: 0xC0000466
            Time Generated: 05/17/2011   14:06:30
            Event String:
            Active Directory Domain Services was unable to establish a connectio
n with the global catalog.
         ......................... DC01 failed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... DC01 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... DC01 passed test MachineAccount
      Starting test: NCSecDesc
         ......................... DC01 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DC01 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... DC01 passed test ObjectsReplicated
      Starting test: Replications
         ......................... DC01 passed test Replications
      Starting test: RidManager
         ......................... DC01 passed test RidManager
      Starting test: Services
         ......................... DC01 passed test Services
      Starting test: SystemLog
         A warning event occurred.  EventID: 0x00001696
            Time Generated: 05/17/2011   14:03:07
            Event String:
            Dynamic registration or deregistration of one or more DNS records fa
iled with the following error:
         An error event occurred.  EventID: 0x00000457
            Time Generated: 05/17/2011   14:04:26
            Event String:
            Driver Zebra P120i Card Printer USB required for printer Zebra P120i
 Card Printer USB is unknown. Contact the administrator to install the driver be
fore you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 05/17/2011   14:04:29
            Event String:
            Driver CutePDF Writer required for printer CutePDF Writer is unknown
. Contact the administrator to install the driver before you log in again.
         ......................... DC01 failed test SystemLog
      Starting test: VerifyReferences
         ......................... DC01 passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : *DOMAIN*
      Starting test: CheckSDRefDom
         ......................... *DOMAIN* passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... *DOMAIN* passed test CrossRefValidation

   Running enterprise tests on : *DOMAIN*.local
      Starting test: LocatorCheck
         ......................... *DOMAIN*.local passed test LocatorCheck
      Starting test: Intersite
         ......................... *DOMAIN*.local passed test Intersite

Open in new window

Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
It looks like an DNS problem, on the Exchange server is the DNS server correct?
Can you Ping the Domain Controller by Name?
Is there an _GC DNS record in your DNS Server?
I've added an screen shot from our DNS record with the _GC revering to the Server with the AD installed and the Global Catalog enabled.
DNS.jpg
Top Expert 2011

Commented:
Open an elevated CMD, type nltest /server:DC01 /dsgetdc:domainName /gc /force, and then press ENTER.
 
If the domain controller is able to contact the global catalog, the command output indicates the name of a domain controller that is configured as the global catalog server.
 
If there is any error in the output, please let us know the detailed error message.
Acronis in Gartner 2019 MQ for datacenter backup

It is an honor to be featured in Gartner 2019 Magic Quadrant for Datacenter Backup and Recovery Solutions. Gartner’s MQ sets a high standard and earning a place on their grid is a great affirmation that Acronis is delivering on our mission to protect all data, apps, and systems.

Top Expert 2011

Commented:

Author

Commented:
Hi, please see attached screenshot
 DNS
Top Expert 2011

Commented:
Do you have any entries under the GC folder?

Author

Commented:
See attached image
17-05-2011-14-38-32.jpg

Author

Commented:
Added a _gc DNS entry and i can now create users/emails in Exchange. Many Thanks :D

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial