Windows XP clients cannot find logon script when last 2003 DC is offline

I apologize for the lengthy title but I wanted to be as clear as possible. We are currently preparing to raise our domain and forest level to 2008. One of the our steps is to disconnect the last 2003 DC to verify that all applications and network access still works. The problem is that most, not all, XP users experience a really long log on time. In the Event Viewer is an error that says "Could not execute the following script \\old dc name\netlogon\slgreen.vbs. The network path was not found." Why would these PC's not pickup the folder from the 2008 DC's? Is there a setting on the 2008 DC's that I am missing? The netlogon and sysvol folders with the scripts do appear on the 2008 DC's.
Damon RodriguezDirector of Business TechnologyAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Krzysztof PytkoSenior Active Directory EngineerCommented:
Have you verified if your clients get appropriate DNS servers list from DHCP? Have you updated it within option 006 in DHCP server?

Can you also post here an output of

dcdiag /e /c /v >c:\dcdiag.log

from your DC, please?

Regards,
Krzysztof
Damon RodriguezDirector of Business TechnologyAuthor Commented:
Yes we changed hat months ago but I did verify that they are pointed to the correct DNS servers. I have attached the results of the dcdiag. Please note that dc03 is the server that is currently off.

Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   * Verifying that the local machine 420DC01, is a Directory Server. 
   Home Server = 420DC01

   * Connecting to directory service on server 420DC01.

   * Identified AD Forest. 
   Collecting AD specific global data 
   * Collecting site info.

   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=slgreen,DC=prv,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
   The previous call succeeded 
   Iterating through the sites 
   Looking at base site object: CN=NTDS Site Settings,CN=SLGWESTCHESTER,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
   Getting ISTG and options for the site
   Looking at base site object: CN=NTDS Site Settings,CN=SLGCONNECTICUT,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
   Getting ISTG and options for the site
   Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
   Getting ISTG and options for the site
   * Identifying all servers.

   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=slgreen,DC=prv,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
   The previous call succeeded....
   The previous call succeeded
   Iterating through the list of servers 
   Getting information for the server CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv 
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=420DC03,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv 
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv 
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=DRDC01,CN=Servers,CN=SLGWESTCHESTER,CN=Sites,CN=Configuration,DC=slgreen,DC=prv 
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   * Identifying all NC cross-refs.

   Ldap search capabality attribute search failed on server 420DC03, return

   value = 81
   Got error while checking if the DC is using FRS or DFSR. Error:

   Win32 Error 81The VerifyReferences, FrsEvent and DfsrEvent tests might fail

   because of this error. 

   * Found 4 DC(s). Testing 4 of them.

   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\420DC02

      Starting test: Connectivity

         * Active Directory LDAP Services Check
         Determining IP4 connectivity 
         * Active Directory RPC Services Check
         ......................... 420DC02 passed test Connectivity

   
   Testing server: Default-First-Site-Name\420DC03

      Starting test: Connectivity

         * Active Directory LDAP Services Check
         Server 420DC03 resolved to these IP addresses: 192.168.20.4, but none

         of the addresses could be reached (pinged). Please check the network.

         Error: 0x2b02 "Error due to lack of resources."

         This error more often means that the targeted server is shutdown or

         disconnected from the network.

         Got error while checking LDAP and RPC connectivity. Please check your

         firewall settings.

         ......................... 420DC03 failed test Connectivity

   
   Testing server: Default-First-Site-Name\420DC01

      Starting test: Connectivity

         * Active Directory LDAP Services Check
         Determining IP4 connectivity 
         * Active Directory RPC Services Check
         ......................... 420DC01 passed test Connectivity

   
   Testing server: SLGWESTCHESTER\DRDC01

      Starting test: Connectivity

         * Active Directory LDAP Services Check
         Determining IP4 connectivity 
         * Active Directory RPC Services Check
         ......................... DRDC01 passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\420DC02

      Starting test: Advertising

         The DC 420DC02 is advertising itself as a DC and having a DS.
         The DC 420DC02 is advertising as an LDAP server
         The DC 420DC02 is advertising as having a writeable directory
         The DC 420DC02 is advertising as a Key Distribution Center
         The DC 420DC02 is advertising as a time server
         The DS 420DC02 is advertising as a GC.
         ......................... 420DC02 passed test Advertising

      Starting test: CheckSecurityError

         * Dr Auth:  Beginning security errors check!
         Found KDC 420DC01 for domain slgreen.prv in site Default-First-Site-Name
         Checking machine account for DC 420DC02 on DC 420DC01.
         * SPN found :LDAP/420DC02.slgreen.prv/slgreen.prv
         * SPN found :LDAP/420DC02.slgreen.prv
         * SPN found :LDAP/420DC02
         * SPN found :LDAP/420DC02.slgreen.prv/SLGREEN
         * SPN found :LDAP/63934314-f859-401a-8921-8a8791602244._msdcs.slgreen.prv
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/63934314-f859-401a-8921-8a8791602244/slgreen.prv
         * SPN found :HOST/420DC02.slgreen.prv/slgreen.prv
         * SPN found :HOST/420DC02.slgreen.prv
         * SPN found :HOST/420DC02
         * SPN found :HOST/420DC02.slgreen.prv/SLGREEN
         * SPN found :GC/420DC02.slgreen.prv/slgreen.prv
         Checking for CN=420DC02,OU=Domain Controllers,DC=slgreen,DC=prv in domain DC=slgreen,DC=prv on 2 servers
            Object is up-to-date on all servers.
         Source DC 420DC03 has possible security error (1722).  Diagnosing...

               Found KDC 420DC01 for domain slgreen.prv in site Default-First-Site-Name
               Checking time skew between servers:
               	420DC03
               	420DC02
               	420DC01
               Error 2184 querying time on DC 420DC03.  Ignoring this DC and

               continuing...

               Time is in sync:  0 seconds different.
               Checking machine account for DC 420DC03 on DC 420DC01.
               Could not open pipe with [420DC03]:failed with 67:

               The network name cannot be found.

               Could not get NetBIOSDomainName

               Failed can not test for HOST SPN

               Failed can not test for HOST SPN

               * SPN found :LDAP/420DC03.slgreen.prv/slgreen.prv
               * SPN found :LDAP/420DC03.slgreen.prv
               * SPN found :LDAP/420DC03
               * SPN found :LDAP/a5608bf2-9596-4e4a-957d-0880b0542cb9._msdcs.slgreen.prv
               * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/a5608bf2-9596-4e4a-957d-0880b0542cb9/slgreen.prv
               * SPN found :HOST/420DC03.slgreen.prv/slgreen.prv
               * SPN found :HOST/420DC03.slgreen.prv
               * SPN found :HOST/420DC03
               * SPN found :GC/420DC03.slgreen.prv/slgreen.prv
               Checking for CN=420DC03,OU=Domain Controllers,DC=slgreen,DC=prv in domain DC=slgreen,DC=prv on 1 servers
                  Object is up-to-date on all servers.
               * Security Permissions check for all NC's on DC 420DC03.
               * Security Permissions Check for

                 DC=ForestDnsZones,DC=slgreen,DC=prv
               * Security Permissions Check for

                 DC=DomainDnsZones,DC=slgreen,DC=prv
               * Security Permissions Check for

                 CN=Schema,CN=Configuration,DC=slgreen,DC=prv
               * Security Permissions Check for

                 CN=Configuration,DC=slgreen,DC=prv
               * Security Permissions Check for

                 DC=slgreen,DC=prv
         Ignoring DC 420DC03 in the convergence test of object

         CN=420DC02,OU=Domain Controllers,DC=slgreen,DC=prv, because we cannot

         connect!

         Checking for CN=420DC02,OU=Domain Controllers,DC=slgreen,DC=prv in domain DC=slgreen,DC=prv on 3 servers
            Object is up-to-date on all servers.
         ......................... 420DC02 failed test CheckSecurityError

      Starting test: CutoffServers

         * Configuration Topology Aliveness Check
         * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for DC=DomainDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for CN=Schema,CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         ......................... 420DC02 passed test CutoffServers

      Starting test: FrsEvent

         * The File Replication Service Event log test 
         ......................... 420DC02 passed test FrsEvent

      Starting test: DFSREvent

         The DFS Replication Event Log. 
         Skip the test because the server is running FRS.

         ......................... 420DC02 passed test DFSREvent

      Starting test: SysVolCheck

         * The File Replication Service SYSVOL ready test 
         File Replication Service's SYSVOL is ready 
         ......................... 420DC02 passed test SysVolCheck

      Starting test: FrsSysVol

         * The File Replication Service SYSVOL ready test 
         File Replication Service's SYSVOL is ready 
         ......................... 420DC02 passed test FrsSysVol

      Starting test: KccEvent

         * The KCC Event log test
         Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
         ......................... 420DC02 passed test KccEvent

      Starting test: KnowsOfRoleHolders

         Role Schema Owner = CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Domain Owner = CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role PDC Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Rid Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         ......................... 420DC02 passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         Checking machine account for DC 420DC02 on DC 420DC02.
         * SPN found :LDAP/420DC02.slgreen.prv/slgreen.prv
         * SPN found :LDAP/420DC02.slgreen.prv
         * SPN found :LDAP/420DC02
         * SPN found :LDAP/420DC02.slgreen.prv/SLGREEN
         * SPN found :LDAP/63934314-f859-401a-8921-8a8791602244._msdcs.slgreen.prv
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/63934314-f859-401a-8921-8a8791602244/slgreen.prv
         * SPN found :HOST/420DC02.slgreen.prv/slgreen.prv
         * SPN found :HOST/420DC02.slgreen.prv
         * SPN found :HOST/420DC02
         * SPN found :HOST/420DC02.slgreen.prv/SLGREEN
         * SPN found :GC/420DC02.slgreen.prv/slgreen.prv
         ......................... 420DC02 passed test MachineAccount

      Starting test: NCSecDesc

         * Security Permissions check for all NC's on DC 420DC02.
         * Security Permissions Check for

           DC=ForestDnsZones,DC=slgreen,DC=prv
            (NDNC,Version 3)
         * Security Permissions Check for

           DC=DomainDnsZones,DC=slgreen,DC=prv
            (NDNC,Version 3)
         * Security Permissions Check for

           CN=Schema,CN=Configuration,DC=slgreen,DC=prv
            (Schema,Version 3)
         * Security Permissions Check for

           CN=Configuration,DC=slgreen,DC=prv
            (Configuration,Version 3)
         * Security Permissions Check for

           DC=slgreen,DC=prv
            (Domain,Version 3)
         ......................... 420DC02 passed test NCSecDesc

      Starting test: NetLogons

         * Network Logons Privileges Check
         Verified share \\420DC02\netlogon
         Verified share \\420DC02\sysvol
         ......................... 420DC02 passed test NetLogons

      Starting test: ObjectsReplicated

         420DC02 is in domain DC=slgreen,DC=prv
         Checking for CN=420DC02,OU=Domain Controllers,DC=slgreen,DC=prv in domain DC=slgreen,DC=prv on 3 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv in domain CN=Configuration,DC=slgreen,DC=prv on 3 servers
            Object is up-to-date on all servers.
         ......................... 420DC02 passed test ObjectsReplicated

      Starting test: OutboundSecureChannels

         * The Outbound Secure Channels test
         ** Did not run Outbound Secure Channels test because /testdomain: was

         not entered

         ......................... 420DC02 passed test OutboundSecureChannels

      Starting test: Replications

         * Replications Check
         [Replications Check,420DC02] A recent replication attempt failed:

            From 420DC03 to 420DC02

            Naming Context: DC=ForestDnsZones,DC=slgreen,DC=prv

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

            

            The failure occurred at 2011-12-15 13:57:21.

            The last success occurred at 2011-12-11 14:56:58.

            95 failures have occurred since the last success.

         [Replications Check,420DC02] A recent replication attempt failed:

            From 420DC03 to 420DC02

            Naming Context: DC=DomainDnsZones,DC=slgreen,DC=prv

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

            

            The failure occurred at 2011-12-15 13:57:21.

            The last success occurred at 2011-12-11 14:56:58.

            95 failures have occurred since the last success.

         [Replications Check,420DC02] A recent replication attempt failed:

            From 420DC03 to 420DC02

            Naming Context: CN=Schema,CN=Configuration,DC=slgreen,DC=prv

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2011-12-15 13:58:03.

            The last success occurred at 2011-12-11 14:56:57.

            95 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,420DC02] A recent replication attempt failed:

            From 420DC03 to 420DC02

            Naming Context: CN=Configuration,DC=slgreen,DC=prv

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2011-12-15 13:57:42.

            The last success occurred at 2011-12-11 14:56:57.

            95 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,420DC02] A recent replication attempt failed:

            From 420DC03 to 420DC02

            Naming Context: DC=slgreen,DC=prv

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2011-12-15 13:57:21.

            The last success occurred at 2011-12-11 15:09:27.

            95 failures have occurred since the last success.

            The source remains down. Please check the machine.

         ......................... 420DC02 failed test Replications

      Starting test: RidManager

         * Available RID Pool for the Domain is 24245 to 1073741823
         * 420DC01.slgreen.prv is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 23245 to 23744
         * rIDPreviousAllocationPool is 21745 to 22244
         * rIDNextRID: 22053
         ......................... 420DC02 passed test RidManager

      Starting test: Services

         * Checking Service: EventSystem
         * Checking Service: RpcSs
         * Checking Service: NTDS
         * Checking Service: DnsCache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... 420DC02 passed test Services

      Starting test: SystemLog

         * The System Event log test
         ......................... 420DC02 failed test SystemLog

      Starting test: Topology

         * Configuration Topology Integrity Check
         * Analyzing the connection topology for DC=ForestDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for DC=DomainDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for CN=Schema,CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         ......................... 420DC02 passed test Topology

      Starting test: VerifyEnterpriseReferences

         ......................... 420DC02 passed test

         VerifyEnterpriseReferences

      Starting test: VerifyReferences

         The system object reference (serverReference)

         CN=420DC02,OU=Domain Controllers,DC=slgreen,DC=prv and backlink on

         CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv

         are correct. 
         The system object reference (serverReferenceBL)

         CN=420DC02,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=slgreen,DC=prv

         and backlink on

         CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv

         are correct. 
         The system object reference (frsComputerReferenceBL)

         CN=420DC02,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=slgreen,DC=prv

         and backlink on CN=420DC02,OU=Domain Controllers,DC=slgreen,DC=prv are

         correct. 
         ......................... 420DC02 passed test VerifyReferences

      Starting test: VerifyReplicas

         ......................... 420DC02 passed test VerifyReplicas

   
   Testing server: Default-First-Site-Name\420DC03

      Skipping all tests, because server 420DC03 is not responding to directory

      service requests.

      Test omitted by user request: Advertising

      Test omitted by user request: CheckSecurityError

      Test omitted by user request: CutoffServers

      Test omitted by user request: FrsEvent

      Test omitted by user request: DFSREvent

      Test omitted by user request: SysVolCheck

      Test omitted by user request: KccEvent

      Test omitted by user request: KnowsOfRoleHolders

      Test omitted by user request: MachineAccount

      Test omitted by user request: NCSecDesc

      Test omitted by user request: NetLogons

      Test omitted by user request: ObjectsReplicated

      Test omitted by user request: OutboundSecureChannels

      Test omitted by user request: Replications

      Test omitted by user request: RidManager

      Test omitted by user request: Services

      Test omitted by user request: SystemLog

      Test omitted by user request: Topology

      Test omitted by user request: VerifyEnterpriseReferences

      Test omitted by user request: VerifyReferences

      Test omitted by user request: VerifyReplicas

   
   Testing server: Default-First-Site-Name\420DC01

      Starting test: Advertising

         The DC 420DC01 is advertising itself as a DC and having a DS.
         The DC 420DC01 is advertising as an LDAP server
         The DC 420DC01 is advertising as having a writeable directory
         The DC 420DC01 is advertising as a Key Distribution Center
         The DC 420DC01 is advertising as a time server
         The DS 420DC01 is advertising as a GC.
         ......................... 420DC01 passed test Advertising

      Starting test: CheckSecurityError

         * Dr Auth:  Beginning security errors check!
         Found KDC 420DC01 for domain slgreen.prv in site Default-First-Site-Name
         Checking machine account for DC 420DC01 on DC 420DC01.
         * SPN found :LDAP/420DC01.slgreen.prv/slgreen.prv
         * SPN found :LDAP/420DC01.slgreen.prv
         * SPN found :LDAP/420DC01
         * SPN found :LDAP/420DC01.slgreen.prv/SLGREEN
         * SPN found :LDAP/bea2e4db-774d-414a-b997-6fbcf425778f._msdcs.slgreen.prv
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/bea2e4db-774d-414a-b997-6fbcf425778f/slgreen.prv
         * SPN found :HOST/420DC01.slgreen.prv/slgreen.prv
         * SPN found :HOST/420DC01.slgreen.prv
         * SPN found :HOST/420DC01
         * SPN found :HOST/420DC01.slgreen.prv/SLGREEN
         * SPN found :GC/420DC01.slgreen.prv/slgreen.prv
         Source DC 420DC03 has possible security error (1722).  Diagnosing...

               Found KDC 420DC01 for domain slgreen.prv in site Default-First-Site-Name
               Checking time skew between servers:
               	420DC03
               	420DC01
               Error 2184 querying time on DC 420DC03.  Ignoring this DC and

               continuing...

               Time is in sync:  0 seconds different.
               Checking machine account for DC 420DC03 on DC 420DC01.
               Could not open pipe with [420DC03]:failed with 67:

               The network name cannot be found.

               Could not get NetBIOSDomainName

               Failed can not test for HOST SPN

               Failed can not test for HOST SPN

               * SPN found :LDAP/420DC03.slgreen.prv/slgreen.prv
               * SPN found :LDAP/420DC03.slgreen.prv
               * SPN found :LDAP/420DC03
               * SPN found :LDAP/a5608bf2-9596-4e4a-957d-0880b0542cb9._msdcs.slgreen.prv
               * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/a5608bf2-9596-4e4a-957d-0880b0542cb9/slgreen.prv
               * SPN found :HOST/420DC03.slgreen.prv/slgreen.prv
               * SPN found :HOST/420DC03.slgreen.prv
               * SPN found :HOST/420DC03
               * SPN found :GC/420DC03.slgreen.prv/slgreen.prv
               Checking for CN=420DC03,OU=Domain Controllers,DC=slgreen,DC=prv in domain DC=slgreen,DC=prv on 1 servers
                  Object is up-to-date on all servers.
               * Security Permissions check for all NC's on DC 420DC03.
               * Security Permissions Check for

                 DC=ForestDnsZones,DC=slgreen,DC=prv
               * Security Permissions Check for

                 DC=DomainDnsZones,DC=slgreen,DC=prv
               * Security Permissions Check for

                 CN=Schema,CN=Configuration,DC=slgreen,DC=prv
               * Security Permissions Check for

                 CN=Configuration,DC=slgreen,DC=prv
               * Security Permissions Check for

                 DC=slgreen,DC=prv
         Ignoring DC 420DC03 in the convergence test of object

         CN=420DC01,OU=Domain Controllers,DC=slgreen,DC=prv, because we cannot

         connect!

         Checking for CN=420DC01,OU=Domain Controllers,DC=slgreen,DC=prv in domain DC=slgreen,DC=prv on 3 servers
            Object is up-to-date on all servers.
         ......................... 420DC01 failed test CheckSecurityError

      Starting test: CutoffServers

         * Configuration Topology Aliveness Check
         * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for DC=DomainDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for CN=Schema,CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         ......................... 420DC01 passed test CutoffServers

      Starting test: FrsEvent

         * The File Replication Service Event log test 
         ......................... 420DC01 passed test FrsEvent

      Starting test: DFSREvent

         The DFS Replication Event Log. 
         Skip the test because the server is running FRS.

         ......................... 420DC01 passed test DFSREvent

      Starting test: SysVolCheck

         * The File Replication Service SYSVOL ready test 
         File Replication Service's SYSVOL is ready 
         ......................... 420DC01 passed test SysVolCheck

      Starting test: FrsSysVol

         * The File Replication Service SYSVOL ready test 
         File Replication Service's SYSVOL is ready 
         ......................... 420DC01 passed test FrsSysVol

      Starting test: KccEvent

         * The KCC Event log test
         Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
         ......................... 420DC01 passed test KccEvent

      Starting test: KnowsOfRoleHolders

         Role Schema Owner = CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Domain Owner = CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role PDC Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Rid Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         ......................... 420DC01 passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         Checking machine account for DC 420DC01 on DC 420DC01.
         * SPN found :LDAP/420DC01.slgreen.prv/slgreen.prv
         * SPN found :LDAP/420DC01.slgreen.prv
         * SPN found :LDAP/420DC01
         * SPN found :LDAP/420DC01.slgreen.prv/SLGREEN
         * SPN found :LDAP/bea2e4db-774d-414a-b997-6fbcf425778f._msdcs.slgreen.prv
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/bea2e4db-774d-414a-b997-6fbcf425778f/slgreen.prv
         * SPN found :HOST/420DC01.slgreen.prv/slgreen.prv
         * SPN found :HOST/420DC01.slgreen.prv
         * SPN found :HOST/420DC01
         * SPN found :HOST/420DC01.slgreen.prv/SLGREEN
         * SPN found :GC/420DC01.slgreen.prv/slgreen.prv
         ......................... 420DC01 passed test MachineAccount

      Starting test: NCSecDesc

         * Security Permissions check for all NC's on DC 420DC01.
         * Security Permissions Check for

           DC=ForestDnsZones,DC=slgreen,DC=prv
            (NDNC,Version 3)
         * Security Permissions Check for

           DC=DomainDnsZones,DC=slgreen,DC=prv
            (NDNC,Version 3)
         * Security Permissions Check for

           CN=Schema,CN=Configuration,DC=slgreen,DC=prv
            (Schema,Version 3)
         * Security Permissions Check for

           CN=Configuration,DC=slgreen,DC=prv
            (Configuration,Version 3)
         * Security Permissions Check for

           DC=slgreen,DC=prv
            (Domain,Version 3)
         ......................... 420DC01 passed test NCSecDesc

      Starting test: NetLogons

         * Network Logons Privileges Check
         Verified share \\420DC01\netlogon
         Verified share \\420DC01\sysvol
         ......................... 420DC01 passed test NetLogons

      Starting test: ObjectsReplicated

         420DC01 is in domain DC=slgreen,DC=prv
         Checking for CN=420DC01,OU=Domain Controllers,DC=slgreen,DC=prv in domain DC=slgreen,DC=prv on 3 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv in domain CN=Configuration,DC=slgreen,DC=prv on 3 servers
            Object is up-to-date on all servers.
         ......................... 420DC01 passed test ObjectsReplicated

      Starting test: OutboundSecureChannels

         * The Outbound Secure Channels test
         ** Did not run Outbound Secure Channels test because /testdomain: was

         not entered

         ......................... 420DC01 passed test OutboundSecureChannels

      Starting test: Replications

         * Replications Check
         [Replications Check,420DC01] A recent replication attempt failed:

            From 420DC03 to 420DC01

            Naming Context: DC=ForestDnsZones,DC=slgreen,DC=prv

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

            

            The failure occurred at 2011-12-15 13:58:55.

            The last success occurred at 2011-12-11 14:57:26.

            95 failures have occurred since the last success.

         [Replications Check,420DC01] A recent replication attempt failed:

            From 420DC03 to 420DC01

            Naming Context: DC=DomainDnsZones,DC=slgreen,DC=prv

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

            

            The failure occurred at 2011-12-15 13:58:55.

            The last success occurred at 2011-12-11 14:57:26.

            95 failures have occurred since the last success.

         [Replications Check,420DC01] A recent replication attempt failed:

            From 420DC03 to 420DC01

            Naming Context: CN=Schema,CN=Configuration,DC=slgreen,DC=prv

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2011-12-15 13:59:38.

            The last success occurred at 2011-12-11 14:57:26.

            95 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,420DC01] A recent replication attempt failed:

            From 420DC03 to 420DC01

            Naming Context: CN=Configuration,DC=slgreen,DC=prv

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2011-12-15 13:59:16.

            The last success occurred at 2011-12-11 14:57:26.

            95 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,420DC01] A recent replication attempt failed:

            From 420DC03 to 420DC01

            Naming Context: DC=slgreen,DC=prv

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2011-12-15 13:58:55.

            The last success occurred at 2011-12-11 15:09:30.

            95 failures have occurred since the last success.

            The source remains down. Please check the machine.

         ......................... 420DC01 failed test Replications

      Starting test: RidManager

         * Available RID Pool for the Domain is 24245 to 1073741823
         * 420DC01.slgreen.prv is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 23745 to 24244
         * rIDPreviousAllocationPool is 22245 to 22744
         * rIDNextRID: 22509
         ......................... 420DC01 passed test RidManager

      Starting test: Services

         * Checking Service: EventSystem
         * Checking Service: RpcSs
         * Checking Service: NTDS
         * Checking Service: DnsCache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... 420DC01 passed test Services

      Starting test: SystemLog

         * The System Event log test
         ......................... 420DC01 failed test SystemLog

      Starting test: Topology

         * Configuration Topology Integrity Check
         * Analyzing the connection topology for DC=ForestDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for DC=DomainDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for CN=Schema,CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         ......................... 420DC01 passed test Topology

      Starting test: VerifyEnterpriseReferences

         ......................... 420DC01 passed test

         VerifyEnterpriseReferences

      Starting test: VerifyReferences

         The system object reference (serverReference)

         CN=420DC01,OU=Domain Controllers,DC=slgreen,DC=prv and backlink on

         CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv

         are correct. 
         The system object reference (serverReferenceBL)

         CN=420DC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=slgreen,DC=prv

         and backlink on

         CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv

         are correct. 
         The system object reference (frsComputerReferenceBL)

         CN=420DC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=slgreen,DC=prv

         and backlink on CN=420DC01,OU=Domain Controllers,DC=slgreen,DC=prv are

         correct. 
         ......................... 420DC01 passed test VerifyReferences

      Starting test: VerifyReplicas

         ......................... 420DC01 passed test VerifyReplicas

   
   Testing server: SLGWESTCHESTER\DRDC01

      Starting test: Advertising

         The DC DRDC01 is advertising itself as a DC and having a DS.
         The DC DRDC01 is advertising as an LDAP server
         The DC DRDC01 is advertising as having a writeable directory
         The DC DRDC01 is advertising as a Key Distribution Center
         The DC DRDC01 is advertising as a time server
         The DS DRDC01 is advertising as a GC.
         ......................... DRDC01 passed test Advertising

      Starting test: CheckSecurityError

         * Dr Auth:  Beginning security errors check!
         Found KDC DRDC01 for domain slgreen.prv in site SLGWESTCHESTER
         Checking machine account for DC DRDC01 on DC DRDC01.
         * SPN found :LDAP/DRDC01.slgreen.prv/slgreen.prv
         * SPN found :LDAP/DRDC01.slgreen.prv
         * SPN found :LDAP/DRDC01
         * SPN found :LDAP/DRDC01.slgreen.prv/SLGREEN
         * SPN found :LDAP/2368aa6d-6afc-4adf-ae05-bb6e8d17bdbf._msdcs.slgreen.prv
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/2368aa6d-6afc-4adf-ae05-bb6e8d17bdbf/slgreen.prv
         * SPN found :HOST/DRDC01.slgreen.prv/slgreen.prv
         * SPN found :HOST/DRDC01.slgreen.prv
         * SPN found :HOST/DRDC01
         * SPN found :HOST/DRDC01.slgreen.prv/SLGREEN
         * SPN found :GC/DRDC01.slgreen.prv/slgreen.prv
         [DRDC01] No security related replication errors were found on this DC!

          To target the connection to a specific source DC use

         /ReplSource:<DC>.

         ......................... DRDC01 passed test CheckSecurityError

      Starting test: CutoffServers

         * Configuration Topology Aliveness Check
         * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for DC=DomainDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for CN=Schema,CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the alive system replication topology for DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         ......................... DRDC01 passed test CutoffServers

      Starting test: FrsEvent

         * The File Replication Service Event log test 
         ......................... DRDC01 passed test FrsEvent

      Starting test: DFSREvent

         The DFS Replication Event Log. 
         Skip the test because the server is running FRS.

         ......................... DRDC01 passed test DFSREvent

      Starting test: SysVolCheck

         * The File Replication Service SYSVOL ready test 
         File Replication Service's SYSVOL is ready 
         ......................... DRDC01 passed test SysVolCheck

      Starting test: FrsSysVol

         * The File Replication Service SYSVOL ready test 
         File Replication Service's SYSVOL is ready 
         ......................... DRDC01 passed test FrsSysVol

      Starting test: KccEvent

         * The KCC Event log test
         Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
         ......................... DRDC01 passed test KccEvent

      Starting test: KnowsOfRoleHolders

         Role Schema Owner = CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Domain Owner = CN=NTDS Settings,CN=420DC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role PDC Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Rid Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=420DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=slgreen,DC=prv
         ......................... DRDC01 passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         Checking machine account for DC DRDC01 on DC DRDC01.
         * SPN found :LDAP/DRDC01.slgreen.prv/slgreen.prv
         * SPN found :LDAP/DRDC01.slgreen.prv
         * SPN found :LDAP/DRDC01
         * SPN found :LDAP/DRDC01.slgreen.prv/SLGREEN
         * SPN found :LDAP/2368aa6d-6afc-4adf-ae05-bb6e8d17bdbf._msdcs.slgreen.prv
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/2368aa6d-6afc-4adf-ae05-bb6e8d17bdbf/slgreen.prv
         * SPN found :HOST/DRDC01.slgreen.prv/slgreen.prv
         * SPN found :HOST/DRDC01.slgreen.prv
         * SPN found :HOST/DRDC01
         * SPN found :HOST/DRDC01.slgreen.prv/SLGREEN
         * SPN found :GC/DRDC01.slgreen.prv/slgreen.prv
         ......................... DRDC01 passed test MachineAccount

      Starting test: NCSecDesc

         * Security Permissions check for all NC's on DC DRDC01.
         * Security Permissions Check for

           DC=ForestDnsZones,DC=slgreen,DC=prv
            (NDNC,Version 3)
         * Security Permissions Check for

           DC=DomainDnsZones,DC=slgreen,DC=prv
            (NDNC,Version 3)
         * Security Permissions Check for

           CN=Schema,CN=Configuration,DC=slgreen,DC=prv
            (Schema,Version 3)
         * Security Permissions Check for

           CN=Configuration,DC=slgreen,DC=prv
            (Configuration,Version 3)
         * Security Permissions Check for

           DC=slgreen,DC=prv
            (Domain,Version 3)
         ......................... DRDC01 passed test NCSecDesc

      Starting test: NetLogons

         * Network Logons Privileges Check
         Verified share \\DRDC01\netlogon
         Verified share \\DRDC01\sysvol
         ......................... DRDC01 passed test NetLogons

      Starting test: ObjectsReplicated

         DRDC01 is in domain DC=slgreen,DC=prv
         Checking for CN=DRDC01,OU=Domain Controllers,DC=slgreen,DC=prv in domain DC=slgreen,DC=prv on 3 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=DRDC01,CN=Servers,CN=SLGWESTCHESTER,CN=Sites,CN=Configuration,DC=slgreen,DC=prv in domain CN=Configuration,DC=slgreen,DC=prv on 3 servers
            Object is up-to-date on all servers.
         ......................... DRDC01 passed test ObjectsReplicated

      Starting test: OutboundSecureChannels

         * The Outbound Secure Channels test
         ** Did not run Outbound Secure Channels test because /testdomain: was

         not entered

         ......................... DRDC01 passed test OutboundSecureChannels

      Starting test: Replications

         * Replications Check
         * Replication Latency Check
         REPLICATION-RECEIVED LATENCY WARNING

         DRDC01:  Current time is 2011-12-15 14:28:51.

            DC=ForestDnsZones,DC=slgreen,DC=prv
               Last replication received from 420DC03 at 
          2011-12-11 14:57:26 
               Latency information for 21 entries in the vector were ignored.
                  21 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            DC=DomainDnsZones,DC=slgreen,DC=prv
               Last replication received from 420DC03 at 
          2011-12-11 14:57:26 
               Latency information for 21 entries in the vector were ignored.
                  21 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            CN=Schema,CN=Configuration,DC=slgreen,DC=prv
               Last replication received from 420DC03 at 
          2011-12-11 14:57:26 
               Latency information for 33 entries in the vector were ignored.
                  33 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            CN=Configuration,DC=slgreen,DC=prv
               Last replication received from 420DC03 at 
          2011-12-11 14:57:26 
               Latency information for 33 entries in the vector were ignored.
                  33 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            DC=slgreen,DC=prv
               Last replication received from 420DC03 at 
          2011-12-11 15:09:30 
               Latency information for 32 entries in the vector were ignored.
                  32 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
         ......................... DRDC01 passed test Replications

      Starting test: RidManager

         * Available RID Pool for the Domain is 24245 to 1073741823
         * 420DC01.slgreen.prv is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 22745 to 23244
         * rIDPreviousAllocationPool is 22745 to 23244
         * rIDNextRID: 22790
         ......................... DRDC01 passed test RidManager

      Starting test: Services

         * Checking Service: EventSystem
         * Checking Service: RpcSs
         * Checking Service: NTDS
         * Checking Service: DnsCache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... DRDC01 passed test Services

      Starting test: SystemLog

         * The System Event log test
         ......................... DRDC01 failed test SystemLog

      Starting test: Topology

         * Configuration Topology Integrity Check
         * Analyzing the connection topology for DC=ForestDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for DC=DomainDnsZones,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for CN=Schema,CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for CN=Configuration,DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         * Analyzing the connection topology for DC=slgreen,DC=prv.
         * Performing upstream (of target) analysis.
         * Performing downstream (of target) analysis.
         ......................... DRDC01 passed test Topology

      Starting test: VerifyEnterpriseReferences

         ......................... DRDC01 passed test

         VerifyEnterpriseReferences

      Starting test: VerifyReferences

         The system object reference (serverReference)

         CN=DRDC01,OU=Domain Controllers,DC=slgreen,DC=prv and backlink on

         CN=DRDC01,CN=Servers,CN=SLGWESTCHESTER,CN=Sites,CN=Configuration,DC=slgreen,DC=prv

         are correct. 
         The system object reference (serverReferenceBL)

         CN=DRDC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=slgreen,DC=prv

         and backlink on

         CN=NTDS Settings,CN=DRDC01,CN=Servers,CN=SLGWESTCHESTER,CN=Sites,CN=Configuration,DC=slgreen,DC=prv

         are correct. 
         The system object reference (frsComputerReferenceBL)

         CN=DRDC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=slgreen,DC=prv

         and backlink on CN=DRDC01,OU=Domain Controllers,DC=slgreen,DC=prv are

         correct. 
         ......................... DRDC01 passed test VerifyReferences

      Starting test: VerifyReplicas

         ......................... DRDC01 passed test VerifyReplicas

   
      Starting test: DNS

         

         DNS Tests are running and not hung. Please wait a few minutes...

            
               Starting test: DNS

                     
                        Starting test: DNS

                              
                                 Starting test: DNS

                                    See DNS test in enterprise tests section for results
                                    ......................... DRDC01 passed

                                    test DNS

                           See DNS test in enterprise tests section for results
                           ......................... 420DC03 failed test DNS

                  See DNS test in enterprise tests section for results
                  ......................... 420DC02 passed test DNS

         See DNS test in enterprise tests section for results
         ......................... 420DC01 passed test DNS

   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : slgreen

      Starting test: CheckSDRefDom

         ......................... slgreen passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... slgreen passed test CrossRefValidation

   
   Running enterprise tests on : slgreen.prv

      Starting test: DNS

         Test results for domain controllers:

            
            DC: 420DC02.slgreen.prv

            Domain: slgreen.prv

            

                  
               TEST: Authentication (Auth)
                  Authentication test: Successfully completed
                  
               TEST: Basic (Basc)
                  The OS

                  Microsoft Windows Server 2008 R2 Standard  (Service Pack level: 1.0)

                  is supported.

                  NETLOGON service is running

                  kdc service is running

                  DNSCACHE service is running

                  DNS service is running

                  DC is a DNS server

                  Network adapters information:

                  Adapter

                  [00000013] HP Network Teaming Virtual Miniport Driver:

                     MAC address is F4:CE:46:84:0A:34
                     IP Address is static 
                     IP address: 192.168.20.5
                     DNS servers:

                        192.168.20.6 (420dc01.slgreen.prv.) [Valid]
                        192.168.20.5 (420DC02) [Valid]
                        127.0.0.1 (420DC02) [Valid]
                  The A host record(s) for this DC was found
                  The SOA record for the Active Directory zone was found
                  The Active Directory zone on this DC/DNS server was found primary
                  Root zone on this DC/DNS server was not found
                  
               TEST: Forwarders/Root hints (Forw)
                  Recursion is enabled
                  Forwarders Information: 
                     209.191.129.1 (<name unavailable>) [Valid] 
                     209.191.129.65 (<name unavailable>) [Valid] 
                     4.2.2.1 (<name unavailable>) [Valid] 
                     4.2.2.2 (<name unavailable>) [Valid] 
                  
               TEST: Delegations (Del)
                  Delegation information for the zone: slgreen.prv.
                     Delegated domain name: _msdcs.slgreen.prv.
                        DNS server: 420dc01.slgreen.prv. IP:192.168.20.6 [Valid]
                  
               TEST: Dynamic update (Dyn)
                  Test record dcdiag-test-record added successfully in zone slgreen.prv
                  Warning: Failed to delete the test record dcdiag-test-record in zone slgreen.prv
                  [Error details: 9505 (Type: Win32 - Description: Unsecured DNS packet.)]
                  
               TEST: Records registration (RReg)
                  Network Adapter

                  [00000013] HP Network Teaming Virtual Miniport Driver:

                     Matching CNAME record found at DNS server 192.168.20.6:
                     63934314-f859-401a-8921-8a8791602244._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.6:
                     420DC02.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.6:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _gc._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.slgreen.prv

                     Matching CNAME record found at DNS server 192.168.20.5:
                     63934314-f859-401a-8921-8a8791602244._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.5:
                     420DC02.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.5:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _gc._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.slgreen.prv

                     Matching CNAME record found at DNS server 192.168.20.5:
                     63934314-f859-401a-8921-8a8791602244._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.5:
                     420DC02.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.5:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _gc._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.slgreen.prv

         
            
            DC: 420DC03.slgreen.prv

            Domain: slgreen.prv

            

                  
               TEST: Authentication (Auth)
                  Error: Authentication failed with specified credentials
                  [Error details: 67 (Type: Win32 - Description: The network name cannot be found.) - Add connection failed]
                  
               TEST: Basic (Basc)
                  Error: No LDAP connectivity
                  Error: No WMI connectivity
                  [Error details: 0x800706ba (Type: HRESULT - Facility: Win32, Description: The RPC server is unavailable.) - Connection to WMI server failed]
                  No host records (A or AAAA) were found for this DC

         
            
            DC: 420DC01.slgreen.prv

            Domain: slgreen.prv

            

                  
               TEST: Authentication (Auth)
                  Authentication test: Successfully completed
                  
               TEST: Basic (Basc)
                  The OS

                  Microsoft Windows Server 2008 R2 Enterprise  (Service Pack level: 1.0)

                  is supported.

                  NETLOGON service is running

                  kdc service is running

                  DNSCACHE service is running

                  DNS service is running

                  DC is a DNS server

                  Network adapters information:

                  Adapter

                  [00000013] HP Network Teaming Virtual Miniport Driver:

                     MAC address is 00:21:5A:AC:92:60
                     IP Address is static 
                     IP address: 192.168.20.6
                     DNS servers:

                        192.168.20.5 (420DC02) [Valid]
                        192.168.20.6 (420dc01.slgreen.prv.) [Valid]
                        127.0.0.1 (420dc01.slgreen.prv.) [Valid]
                  The A host record(s) for this DC was found
                  The SOA record for the Active Directory zone was found
                  The Active Directory zone on this DC/DNS server was found primary
                  Root zone on this DC/DNS server was not found
                  
               TEST: Forwarders/Root hints (Forw)
                  Recursion is enabled
                  Forwarders Information: 
                     209.191.129.1 (<name unavailable>) [Valid] 
                     209.191.129.65 (<name unavailable>) [Valid] 
                     4.2.2.1 (<name unavailable>) [Valid] 
                     4.2.2.2 (<name unavailable>) [Valid] 
                     8.8.4.4 (<name unavailable>) [Valid] 
                     8.8.8.8 (<name unavailable>) [Valid] 
                  
               TEST: Delegations (Del)
                  Delegation information for the zone: slgreen.prv.
                     Delegated domain name: _msdcs.slgreen.prv.
                        DNS server: 420dc01.slgreen.prv. IP:192.168.20.6 [Valid]
                  
               TEST: Dynamic update (Dyn)
                  Test record dcdiag-test-record added successfully in zone slgreen.prv
                  Warning: Failed to delete the test record dcdiag-test-record in zone slgreen.prv
                  [Error details: 9505 (Type: Win32 - Description: Unsecured DNS packet.)]
                  
               TEST: Records registration (RReg)
                  Network Adapter

                  [00000013] HP Network Teaming Virtual Miniport Driver:

                     Matching CNAME record found at DNS server 192.168.20.5:
                     bea2e4db-774d-414a-b997-6fbcf425778f._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.5:
                     420DC01.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _kerberos._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.5:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _gc._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.5:
                     _ldap._tcp.pdc._msdcs.slgreen.prv

                     Matching CNAME record found at DNS server 192.168.20.6:
                     bea2e4db-774d-414a-b997-6fbcf425778f._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.6:
                     420DC01.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.6:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _gc._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.pdc._msdcs.slgreen.prv

                     Matching CNAME record found at DNS server 192.168.20.6:
                     bea2e4db-774d-414a-b997-6fbcf425778f._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.6:
                     420DC01.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.6:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _gc._tcp.Default-First-Site-Name._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.pdc._msdcs.slgreen.prv

         
            
            DC: DRDC01.slgreen.prv

            Domain: slgreen.prv

            

                  
               TEST: Authentication (Auth)
                  Authentication test: Successfully completed
                  
               TEST: Basic (Basc)
                  The OS

                  Microsoft Windows Server 2008 R2 Standard  (Service Pack level: 1.0)

                  is supported.

                  NETLOGON service is running

                  kdc service is running

                  DNSCACHE service is running

                  DNS service is running

                  DC is a DNS server

                  Network adapters information:

                  Adapter

                  [00000013] HP Network Teaming Virtual Miniport Driver:

                     MAC address is D8:D3:85:BA:63:50
                     IP Address is static 
                     IP address: 192.168.10.7
                     DNS servers:

                        192.168.20.6 (420dc01.slgreen.prv.) [Valid]
                        192.168.10.7 (DRDC01) [Valid]
                        127.0.0.1 (DRDC01) [Valid]
                  The A host record(s) for this DC was found
                  The SOA record for the Active Directory zone was found
                  The Active Directory zone on this DC/DNS server was found primary
                  Root zone on this DC/DNS server was not found
                  
               TEST: Forwarders/Root hints (Forw)
                  Recursion is enabled
                  Forwarders Information: 
                     209.191.129.1 (<name unavailable>) [Valid] 
                     209.191.129.65 (<name unavailable>) [Valid] 
                  
               TEST: Delegations (Del)
                  Delegation information for the zone: slgreen.prv.
                     Delegated domain name: _msdcs.slgreen.prv.
                        DNS server: 420dc01.slgreen.prv. IP:192.168.20.6 [Valid]
                  
               TEST: Dynamic update (Dyn)
                  Test record dcdiag-test-record added successfully in zone slgreen.prv
                  Warning: Failed to delete the test record dcdiag-test-record in zone slgreen.prv
                  [Error details: 9505 (Type: Win32 - Description: Unsecured DNS packet.)]
                  
               TEST: Records registration (RReg)
                  Network Adapter

                  [00000013] HP Network Teaming Virtual Miniport Driver:

                     Matching CNAME record found at DNS server 192.168.20.6:
                     2368aa6d-6afc-4adf-ae05-bb6e8d17bdbf._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.6:
                     DRDC01.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.SLGWESTCHESTER._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.SLGWESTCHESTER._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _kerberos._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.20.6:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _gc._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.20.6:
                     _ldap._tcp.SLGWESTCHESTER._sites.gc._msdcs.slgreen.prv

                     Matching CNAME record found at DNS server 192.168.10.7:
                     2368aa6d-6afc-4adf-ae05-bb6e8d17bdbf._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.10.7:
                     DRDC01.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._tcp.SLGWESTCHESTER._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.SLGWESTCHESTER._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.10.7:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _gc._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.SLGWESTCHESTER._sites.gc._msdcs.slgreen.prv

                     Matching CNAME record found at DNS server 192.168.10.7:
                     2368aa6d-6afc-4adf-ae05-bb6e8d17bdbf._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.10.7:
                     DRDC01.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.76dd4b8b-607d-4787-8e69-cd323d5bf346.domains._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._udp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kpasswd._tcp.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._tcp.SLGWESTCHESTER._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.SLGWESTCHESTER._sites.dc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _kerberos._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.gc._msdcs.slgreen.prv

                     Matching A record found at DNS server 192.168.10.7:
                     gc._msdcs.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _gc._tcp.SLGWESTCHESTER._sites.slgreen.prv

                     Matching  SRV record found at DNS server 192.168.10.7:
                     _ldap._tcp.SLGWESTCHESTER._sites.gc._msdcs.slgreen.prv

         
         Summary of test results for DNS servers used by the above domain

         controllers:

         

            DNS server: 192.168.10.7 (DRDC01)

               All tests passed on this DNS server

               Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered 
               
            DNS server: 192.168.20.5 (420DC02)

               All tests passed on this DNS server

               Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered 
               
            DNS server: 192.168.20.6 (420dc01.slgreen.prv.)

               All tests passed on this DNS server

               Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered 
               DNS delegation for the domain  _msdcs.slgreen.prv. is operational on IP 192.168.20.6

               
            DNS server: 209.191.129.1 (<name unavailable>)

               All tests passed on this DNS server

               
            DNS server: 209.191.129.65 (<name unavailable>)

               All tests passed on this DNS server

               
            DNS server: 4.2.2.1 (<name unavailable>)

               All tests passed on this DNS server

               
            DNS server: 4.2.2.2 (<name unavailable>)

               All tests passed on this DNS server

               
            DNS server: 8.8.4.4 (<name unavailable>)

               All tests passed on this DNS server

               
            DNS server: 8.8.8.8 (<name unavailable>)

               All tests passed on this DNS server

               
         Summary of DNS test results:

         
                                            Auth Basc Forw Del  Dyn  RReg Ext
            _________________________________________________________________
            Domain: slgreen.prv

               420DC02                      PASS PASS PASS PASS WARN PASS n/a  
               420DC03                      FAIL FAIL n/a  n/a  n/a  n/a  n/a  
               420DC01                      PASS PASS PASS PASS WARN PASS n/a  
               DRDC01                       PASS PASS PASS PASS WARN PASS n/a  
         
         ......................... slgreen.prv failed test DNS

      Starting test: LocatorCheck

         GC Name: \\420DC01.slgreen.prv

         Locator Flags: 0xe00031fd
         PDC Name: \\420DC01.slgreen.prv
         Locator Flags: 0xe00031fd
         Time Server Name: \\420DC01.slgreen.prv
         Locator Flags: 0xe00031fd
         Preferred Time Server Name: \\420DC01.slgreen.prv
         Locator Flags: 0xe00031fd
         KDC Name: \\420DC01.slgreen.prv
         Locator Flags: 0xe00031fd
         ......................... slgreen.prv passed test LocatorCheck

      Starting test: FsmoCheck

         GC Name: \\420DC01.slgreen.prv

         Locator Flags: 0xe00031fd
         PDC Name: \\420DC01.slgreen.prv
         Locator Flags: 0xe00031fd
         Time Server Name: \\420DC01.slgreen.prv
         Locator Flags: 0xe00031fd
         Preferred Time Server Name: \\420DC01.slgreen.prv
         Locator Flags: 0xe00031fd
         KDC Name: \\420DC01.slgreen.prv
         Locator Flags: 0xe00031fd
         ......................... slgreen.prv passed test FsmoCheck

      Starting test: Intersite

         Doing intersite inbound replication test on site SLGWESTCHESTER: 
            Locating & Contacting Intersite Topology Generator (ISTG) ... 
               The ISTG for site SLGWESTCHESTER is: DRDC01. 
            Checking for down bridgeheads ... 
               Bridghead Default-First-Site-Name\420DC02 is up and replicating

               fine. 
               Bridghead SLGWESTCHESTER\DRDC01 is up and replicating fine. 
            Doing in depth site analysis ... 
               All expected sites and bridgeheads are replicating into site

               SLGWESTCHESTER. 
         Skipping site SLGCONNECTICUT, this site is outside the scope provided

         by the command line arguments provided. 
         Doing intersite inbound replication test on site

         Default-First-Site-Name: 
            Locating & Contacting Intersite Topology Generator (ISTG) ... 
               The ISTG for site Default-First-Site-Name is: 420DC02. 
            Checking for down bridgeheads ... 
               Bridghead \ is up and replicating fine. 
               Bridghead Default-First-Site-Name\ is up and replicating

               fine. 
            Doing in depth site analysis ... 
               All expected sites and bridgeheads are replicating into site

               Default-First-Site-Name. 
         .........................  passed test Intersite

Open in new window

dcdiag.txt
miketisdaleconsultingCommented:
I'm sure you've already thought of this based on the steps already done, however have you verified that wherever the logon scripts are defined (via User properties in AD, or via Group Policy) that the logon scripts are referenced based on either \\[domainname]\netlogon\[scriptname] or just [scriptname] rather than \\[servername]\netlogon\[scriptname]. If the logon script is properly replicating to the new 2008 DCs (which it sounds like is correct), then it is typically would be either how the script is referenced (such as just outlined) or due to the new domain controllers not being listed with A records for the domain name itself in the DNS server.
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Damon RodriguezDirector of Business TechnologyAuthor Commented:
Actually it is referring to the script by \\servername\netlogon
[scriptname] not domain name. I did think that might be a little odd so I am researching that angle as we speak...write...whatever.
Ayman BakrSenior ConsultantCommented:
If the scripts are explicitly being called using the servername then this will lead you to a single point of failure. As your server went down, your user's logon took considerable time trying to contact that server, but to no avail - to fail at the end.

You need to modify all these references to point to your domain rather than a specific server name. This will transfer you towards a fault tolerant structure where any DC available can answer the call for the script.
Damon RodriguezDirector of Business TechnologyAuthor Commented:
This would probably be true if it affected everyone. As it is, it only affects XP users, and not all of them. Windows 7 users aren't getting this error at all.
Ayman BakrSenior ConsultantCommented:
Well does it really depend on the machine? The login script will run on the user account. Therefore I would suggest that you see how the policy for the users who have a problem is calling the script vs. how it is called for the other users.

Better still you can check with one of the XP users to log on a Windows 7 machine and see if he has the same problem.
Damon RodriguezDirector of Business TechnologyAuthor Commented:
Mutawadi - I tried logging in to those PC's with a test account and was able to replicate it on the same XP machines but there were no issues or errors on the Win 7 machines or the XP machines that have no issue.

Do you know where this setting resides?
Ayman BakrSenior ConsultantCommented:
I would like you to take the following verification steps:

1. To see how is it set up in GPO I quote here:
Logon scripts can also be configured in Group Policy. However, Group Policy only applies to clients with Windows 2000 or above. The setting in Group Policy is "User Configuration", "Windows Settings", "Scripts (Logon/Logoff)", "Logon". Best practice is to copy the file you want for the Logon script to the Windows clipboard, open the "Logon" setting in the Group Policy editor, press the "Show Files..." button, and paste the desired file in the dialog. You can select the file and edit it in this dialog as well. This is easier than navigating in Windows Explorer to the folder where Group Policy Logon scripts are saved

If you see that it is configured by server name then correct it. If you didnt set it through group policy but by the user's profile then check the user's profile tab.

If everything looks fine then check whether all your DCs have the same files in their Netlogon. If not then there might be an FRS issue.

Next Check the advanced settings of the TCP/IP configuration and verify that the correct DNS config is available on the problematic machines.

If still not resolved check to see whether the TCP/IP NetBIOS Helper Service is started or not on the problematic machine.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Damon RodriguezDirector of Business TechnologyAuthor Commented:
Mutawadi you had the right answer.

Apparently the network admin added a path to the script to a gpo for wireless access and applied it to all the computers instead of just the Laptop OU.

Thanks all for your input on this.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.