SBS 2011 DNS Error

Posted on 2011-10-14
Last Modified: 2012-08-14
We are unable to access the Internet (although we could previously) on a SBS 2011 Server.
We are getting this error in our DNS log. And advice most welcome.
Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4004
Date:            14/10/2011
Time:            15:12:33
User:            N/A
Computer:      SERVER.xxxxxx.local Description:
The DNS server was unable to complete directory service enumeration of zone  This DNS server is configured to use information obtained from Active Directory for this zone and is unable to load the zone without it.  Check that the Active Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be empty) is "". The event data contains the error.

For more information, see Help and Support Center at
0000: 2a 23 00 00              

Question by:cybis1
    LVL 8

    Expert Comment

    The address space is for reverse DNS entries. So you can resolve an IP address to a DNS name, instead of the other way around you normally use DNS for. The address space is always written backwards, 192.168.16 in your case. You don't often need reverse DNS, so you could probably just ignore this error message. I'm relatively certain that it would not be causing your Internet access issues. Make sure the DNS server service is up and running and try pinging random websites (, etc.) and if it can resolve the IP's for those sites, that is not your problem & you are chasing an irrelevant error.

    To fix the error, just create the zone in your DNS and let it populate things on it's own.

    For more reverse DNS info check out
    LVL 24

    Expert Comment

    As per Microsoft: "The DNS Server service uses Active Directory to store DNS data, and it encountered a Lightweight Directory Access Protocol (LDAP) error while querying the directory. This error could be caused by either a time-out or a temporary interruption of service".

    If the 4004 and 4015 events only appear at start up, you get these events because your zones are stored in AD and it seems you only have one Domain Controller. AD cannot start with DNS, and when DNS starts, because AD has not started, DNS cannot load the zones in AD. The error goes away if you have two or more DCs with DNS installed, or if you use standard primary zones.
    LVL 2

    Expert Comment

    You said you can't access the internet. Could you be more specific? Can you ping your gateway router? Can you ping anything outside your network by IP?, By name? Run ipconifg, is your gateway device set correctly?
    Just trying to get more clear about whether or not this is DNS related.
    LVL 1

    Author Comment

    sorry - didn't explain this very wel..  We can't acess the internet with iIE v8 or 9, nor firefox. Iif we ping a DNS name in a command box, we get a reply. So the DNS is resolving the name within a command box.  It may be the DNS errors listed above  aren't related to the problem.

    IIE8 was working fine before we did a whole load of windows updates on the server.  After the updates we can't use a browser.  So the we tried upgrading IE to version 9 and tring firefos - but both with no sucess.

    DNS is definatly set to the IP address of the SBS 2011 server (itself) and not using  We have tried this with DNS forwarders and without.
    LVL 8

    Accepted Solution

    Personally I prefer to use as the first DNS server on my DC's. That way it can still find DNS so that AD will run if an IP gets changed or something.

    The DNS server itself should have the root hints enabled, which will point to proper DNS out on the Internet.

    When pinging stuff from the command line, are you trying internal names, external names, or both? I'm assuming external or both & that they are resolving the correct IP's for the moment.

    Assuming DNS is working fine from the command line, that shouldn't be a problem for web browsing. My first thought is a firewall blocking the web browser. IE could be messed up via some GPO's but not really Firefox, so I wouldn't look at GPO's for the moment.

    Do you or your ISP use a proxy server or any sort?
    Do you have a firewall installed or enabled on the server or at the edge of your network?

    Microsoft took out telnet in Vista or Windows 7 (don't remember about server versions offhand) I think, but you should be able to install it, or use putty.

    Try "telnet 80" or get Putty & try and connect up to port 80 using the telnet protocol. If either method connects at all (may not get any data, but as long as you don't get a can't connect error), it's probably not a firewall.
    LVL 1

    Author Comment

    Thanks.  This didn't solveit, but made me think about the firewall setup - which did  turn out to be the problem.  It was setup for it's future site, and the IP address is was trying to get out on, wasn't valid for our in house connection.

    So thanks for making me think laterally.


    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    There have been a lot of times when we have seen the need to enter a large number of DNS entries in a forward lookup zone. The standard procedure would be to launch the DNS Manager console, create the Zone and start adding new hosts using the New…
    Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now