Failed to ping or bind to the Infrastructure Master FSMO role holder

I have this error in scom

"Failed to ping or bind to the Infrastructure Master FSMO role holder"

I searched in the internet to know this error but I didn't know what to do .

I just found a link"" that states I should open  the AD MP Events view.

I read the management pack of the active directory in this site :

I found the following but that didn't help me

failed to ping or bind to the Infrastructure Master FSMO role holder


Active Directory Windows 2000 and Windows Server 2003 - Active Directory Availability

Event Number equals 20007.

Event Type equals Warning.

Source Name equals AD Op Master Response.


I don't know what to do regarding this warning,it is repeated occasionally
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Syed_M_UsmanSystem AdministratorCommented:

please provide below info

1) how many DC's you have
2) os of all DC
3) forest /domain functional level

if you run below commands what is the putput, please upload santized


1)netdom /query fsmo
3)repadmin /showrepl
omzeyadAuthor Commented:
1) how many DC's you have
 2 DC

2) os of all DC
windows server 2008 service pack 1

3) forest /domain functional level
 i will check

I will upload the output of the command
omzeyadAuthor Commented:
domain functional level is windows server 2008 R2

forest functional level is Windows Server 2008
10 Tips to Protect Your Business from Ransomware

Did you know that ransomware is the most widespread, destructive malware in the world today? It accounts for 39% of all security breaches, with ransomware gangsters projected to make $11.5B in profits from online extortion by 2019.

Syed_M_UsmanSystem AdministratorCommented:
if you run below commands what is the putput, please upload santized


1)netdom /query fsmo
3)repadmin /showrepl
omzeyadAuthor Commented:
I have already attached it ,  God will .I will attached it again
Syed_M_UsmanSystem AdministratorCommented:

1) ......................... DC failed test NCSecDes.... You can safely ignore refer to

2) ......................... DC failed test Services........You can safely ignore refer to

with regards to your orignal post look like you have connectivity issues with DC to network.
can you upoad orignal screen shot after santiziing your domainname only?

Plz also check forewall settings of your DC.....

Take your full DC backup and check if below can help you

Caution : I never tested above......
Syed_M_UsmanSystem AdministratorCommented:
Could you please check the pther DC is not behind the firewall???
omzeyadAuthor Commented:
dear usman

what do you mean by santiziing my domain name

anyway this is the screen shot of the fsmo and repadmin command

Syed_M_UsmanSystem AdministratorCommented:
your FSMO holder is up and running.
you dont have any replication issues.

with regards to dcdiag i already replied you.

regards to your question plz try to trouble shot DC connectivity, i would like to know is there any firewall between two dc's?

i tried to simulate your error in my LAB this comes when a firewall preventing ICMP packets. in my case this error comes on NON FSMO HOLDER, please confirm where you see this error? on fsmo holder or non fsmo holder...
omzeyadAuthor Commented:
I appreciate your support

I will ask the infrastructure department because they are responsible for the firewall,
I think this is the case ,because this error sometimes happened not always .

the windows  firewall is already closed

do you think that I must install Microsoft network monitor on the domain controller to see what happened in network ,would that affect the performance of the domain controller
Syed_M_UsmanSystem AdministratorCommented:
1) Win 2008 has three levels of firewall, i would suggest you turn on firewall for Public and Private networks...

2) could you please confirm where you recives this error? on DC1 or Dc2

3) WHAT TYPE OF  FIREWALL YOU ARE USING, plz tell me the model and brand

please draw connection typlogy between two Dc's

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
omzeyadAuthor Commented:
all I know that fortigate is used ,and all servers are located in vlan1 and workstation are located in vlan2  ,I'm sure that dc and adc are in the same vlan .no firewall between them

I think that may be the infrastructure department edit some rules and cause that error to generate ,therefore I need to install a network monitoring tool to know what happened but I'm afraid that  it may affect the performance of the domain ,I can't make the monitor record all connections  until a problem happened and I don't know when it will happen.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.