Server 2K /DNS/AD

I am cryng "Uncle!"  About 2 weeks ago our server quit serving.  When I dove into the problem the DNS and WINS were both missing from the server.  How they became MIA is still an unknown.  I thought I had successfully reinstalled the DNS and WINS but there have been pesky issues all along.  We have a Hardware Firewall - Watchguard  Firebox "Edge" that the server (pe600sc) connects to and the rest of the computers are suppose to be connected from the server to firewall.  After much tweaking and testing I thought I had it all configured correctly except that on the NIC card I had to list the Watchguard Firebox as the Primary DNS as well as it being the Gateway while the true primary DNS, (PE600SC) had to be listed as alternative DNS.  If I switched the order - no internet connection for any computer. (No DNS server found)

To complicate matters late last week I was trying to figure this out and must have replaced something in the DNS stuff so I no longer have access to Active Directory.

I tried to do Recovery Console but kept getting blue screen /fatal error (no, I didn't write the # down). But I also did not disconnect the ethernet cable from server to see if logging on w/o connections to firewall etc. would make the program run.

I have tried the nltest/SC_CHANGE_PWD:,domain name> and that portion was successful. Burt when I went to the second command:
netdom reset p3600sc /domain:ns1.acousticalresources
it failed saying that the specified domain could not be contacted or does not exist.

I cannot Bind to AD.

When I run dcdiag I get error 1323, then when I add user name & password to dcdiag I receive Error 31 "Filename, Directory name or Volume Label Syntax is incorrect.

For some reason I cannot attach a file to this request (Netdiag.log)            
 I don't know whether it is because the server is so old and the IE connection is IE 6.0 and it won't update IE because the server is too old

We have 6 client computers all running Windows XP Pro.

Thanks for your help - I am hoping it is something easier than reformatting the  harddrive/server and starting over.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

ARserviceAuthor Commented:
Here is the netdiag.log file
I noticed it has some of our ISP provider's DNS stuff in it which I have NOT ever entered into the DNS.  On the Watchguard we have external function, but those DNS #'s are not what is showing up on this report.  
I thought I would go add the #'s found in the report (listed as under "Forwarders" but the check box to add forwarders is grayed out/non-functional.

The DNS NAMES listed are used for Outlook mail POP3 & SMPT authorization.

Hope this gives some better insight into the mess.
Here is how you should be able to fix your problem:

1)  Connect server and all workstatoins directly to the Watchguard trusted side (e.g. ALL systems access Internet by using the Watchguard as the gateway)

2)  If I am understanding correctly, the server is a (the) domain controler.  If necessary, uninstall then reinstall DNS service to be sure it is solidly in place.  If you need WINS, so the same for it.

3)  Set IP on server so server points to itself *and only to itself* for DNS.

4)  Set DHCP so all workstations point to the server as primary DNS, to WINS if you are using it, and to Watchguard as gateway.  If you want to you can use another device for secondary DHCP provided DNS.

5)  Reboot all workstations or run ipconfig /refresh so new DHCP settings take affect.

All problems should go away.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Brian PiercePhotographerCommented:
I'll just add that ALL machines - not just the server must point to the server as the one-and-only DNS server. You will need to set up a forwarder in DNS to point to the gateway or external DNS server to resolve external names

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

ARserviceAuthor Commented:
We do not use DHCP - only Static IP addresses

Yes, server is the DC and only DC.

The watchguard has one port for the server to connect and one port for the router to connect .

Any trick to unistalling DNS?  Do I just open up the MMC and click on the server / Stop it, then delete it?
Brian PiercePhotographerCommented:
Why do you use static IPs ?

One of the problems is that you'll manually have to check EACH and EVERY machine to make sure that the DNS server and default gateway are set correctly....

DHCP has a lot going for it....
ARserviceAuthor Commented:
Seveal years ago a couple Laptops & docking stations for them kept losing connections/trust whenever they were disconnected so I gave up and gave everyone a static IP.

I am reading article now and will follow steps as soon as I am able to take over the server from use by employees.  

Hopefully, this is all I need to do is uninstall/reinstall DNS / to only be the server.
ARserviceAuthor Commented:
OK, the DNS is now working with the solo DNS
HOWEVER - I still cannot get into Active Directory
Same Error 31 about not being able to bind  - no server.
All client computers have connectivity to internet and their email, so that helps alot, but can not get them joined to any domain until it can find or bind or whatever it wants to do to get back the access back to active directory.
Any suggestions on how to do this?
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Legacy OS

From novice to tech pro — start learning today.