Solved

DCDiag errors on first 2008R2 DC in windows 2003R2 domain

Posted on 2012-03-30
12
485 Views
Last Modified: 2012-04-02
Hello,

Please see the attached DCdiag results I just got from the first 2008R2 DC I introduced into my 2003R2 domain.  I made sure to prep the domain before adding the 08 server, so those steps were covered.  I'm just wondering if this is anything I need to worry about.  I have tested, retested, and tested again, adding user accounts, and adding DNS entries between my DC's and replication works fine.  

Thanks,
dcdiag.txt
0
Comment
Question by:lbtoadmin
  • 7
  • 3
  • 2
12 Comments
 
LVL 17

Assisted Solution

by:Anuroopsundd
Anuroopsundd earned 333 total points
ID: 37788176
do you have some local security software or firewall running?
0
 

Author Comment

by:lbtoadmin
ID: 37788183
Now that you mention it, Kaspersky enpoint security is on there with the firewall enabled; however that local network is trusted.  I'll disable the firewall and run it again.  Good point!
0
 

Author Comment

by:lbtoadmin
ID: 37788209
Here is the new one..is this what I should see from now on?  

Also, should I not have the kasperky or Windows firewall turned on?
dcdiag1002.txt
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37788227
you missed the screenshot..

if you like to enable firewall on DC then
Enable program exceptions for lsass.exe and ntfrs.exe.exe which are found under %windir%\system32.

Enable port exceptions for ports 53 (TCP and UDP), 88 (TCP and UDP), 123 (UDP), 135 (TCP), 137 (TCP), 389 (UDP), 464 (TCP and UDP) and 636 (TCP).

http://www.windowsnetworking.com/kbase/WindowsTips/Windows2003/AdminTips/Security/EnablingWindowsFirewallondomaincontrollers.html
0
 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37788236
Got the text file... atleast DC is working better...
0
 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37788250
errors that are showing are coming from the system log.. as your server was not working properly... all other tests are passing now.

Ones the replication is completed.
clear your logs..reboot your server and keep your security application disabled before reboot.
0
 

Author Comment

by:lbtoadmin
ID: 37788534
It still says the following for the FRSEvent:

    Starting test: FrsEvent

         There are warning or error events within the last 24 hours after the

         SYSVOL has been shared.  Failing SYSVOL replication problems may cause

         Group Policy problems.

And this for the NCSecDesc:
Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=test,DC=lbto,DC=org
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=test,DC=lbto,DC=org

Will the FRSevent clear out?  Also, what should I do for the NCSecDesc error?

I do this test on my 2003DC's and the only error I see is the FRSEvent on my 2003DC that does not have any fsmo roles.  The primary that has all of the fsmo roles does not have any errors
0
 
LVL 17

Assisted Solution

by:Anuroopsundd
Anuroopsundd earned 333 total points
ID: 37788551
Please give the system some time to replicate. also a reboot will be good now so that it starts the replication properly. as your server was not able to properly communicate earlier.
Just make sure you disable the security service before reboot and it should not start at startup. else again the issue may come back.
0
 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37788601
There are warning or error events within the last 24 hours after the

also these can be earlier error from the even viewer.. you have to clear all logs from event viewer.
0
 
LVL 40

Accepted Solution

by:
footech earned 167 total points
ID: 37790717
Just wanted to say that the Windows Firewall should be automatically configured according to the roles that you have set up on the 2008 R2 server, so you shouldn't have to do any manual configuration.  I recommend having it on.

The NCSecDesc errors are expected if you haven't run "adprep /rodcprep".  They can be ignored if you don't plan on adding a RODC to your environment, or you can just run the adprep command so you don't encounter them anymore.
http://support.microsoft.com/kb/967482
0
 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37790722
as per the Author he already did the adprep.
" I made sure to prep the domain before adding the 08 server."
but offcourse their is no harm incase their are still some errors.
Hopefully most of the things are up as the last dcdiag showed that replication was working and most of the checks were passed.
0
 
LVL 40

Expert Comment

by:footech
ID: 37790804
There are several different adprep commands.  The /rodc switch is not needed to add a 2008 R2 DC, and many people skip it as they don't plan on adding a RODC, but it results in the errors seen when running DCDIAG.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article runs through the process of deploying a single EXE application selectively to a group of user.
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question