Link to home
Start Free TrialLog in
Avatar of BradLMComputers
BradLMComputers

asked on

Error: Specified domain either does not exist or could not be contacted DFS Namespace

I am trying to create a namespace in DFS management on 2008 r2 , i am getting that error. Error: Specified domain either does not exist or could not be contacted.  I did have some trouble with dns after domoteing a DC, DNS thought it was still a name server and gc, etc.

Dont know what i am doing wrong now, When i pung \\domainname.suffix i get the new dc's ip address but DFS management will bomb out instantly after creating the namespace.

Any ideas

PS We went from a 2003 r2 domain level, to a 2008 r2 domain level. Old dc Windows Server 2003 Enterprise 64 bit, new Standard 2008 R2 64
Avatar of Leon Fester
Leon Fester
Flag of South Africa image

run "NSLOOKUP domainname.suffix"
It should return the IP addresses of all the Domain Controllers.
If you see the old DC's IP address then you'll need to do a cleanup of the old DNS records in the following locations:
Forward lookup zone
Reverse lookup zone
_msdcs zone
also check the Name Servers tab on your DNS console.
Avatar of BradLMComputers
BradLMComputers

ASKER

This is what i got out of dc diag actually

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = GHDC1
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\GHDC1
      Starting test: Connectivity
         The host 5ddb5d23-e100-4580-9223-2708aacf84ce._msdcs.GlenHaven.domain
         could not be resolved to an IP address. Check the DNS server, DHCP,
         server name, etc.
         Got error while checking LDAP and RPC connectivity. Please check your
         firewall settings.
         ......................... GHDC1 failed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\GHDC1
      Skipping all tests, because server GHDC1 is not responding to directory
      service requests.


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : GlenHaven
      Starting test: CheckSDRefDom
         ......................... GlenHaven passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... GlenHaven passed test CrossRefValidation

   Running enterprise tests on : GlenHaven.domain
      Starting test: LocatorCheck
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error
         1355
         A Good Time Server could not be located.
         ......................... GlenHaven.domain failed test LocatorCheck
      Starting test: Intersite
         ......................... GlenHaven.domain passed test Intersite
Carry out these tasks with domain admin access on GHDC1:

NET STOP W32TIME
NET START W32TIME
NET STOP NETLOGON
NET START NETLOGON

Reset Secure Channel - netdom reset "GHDC1" /d:GlenHaven.domain /userd:GlenHaven\administrator passwordd:password
NETDOM QUERY FSMO  -> This should be reporting that all 5 roles are hosted on GHDC1. If not let us know!

Run NSLOOKUP . Still having problems? Then I would also make your DC sync with an external NTP source. Your firewall will need to allow SNTP traffic.

Follow this guide: Set your Time sync with external NTP Source on Windows server.

Obtain valid Time servers on the internet from this website


Then Run NSLOOKUP Again! Let us know the results
Your locator records are not being found.

Did you delete any old records for the deleted domain controller or any other servers?
run the following commands to on each domain controller to re-register all your DNS records:
ipconfig /registerdns
nltest /dsregdns

Run the netdom checks as suggested, if the roles are not all held by a working DC then you'll need to seize the FSMO roles.
http://support.microsoft.com/kb/255504
getting this now

   Running partition tests on : GlenHaven

   Running enterprise tests on : GlenHaven.domain
      Starting test: DNS
         Test results for domain controllers:

            DC: GHDC1.GlenHaven.domain
            Domain: GlenHaven.domain


               TEST: Dynamic update (Dyn)
                  Warning: Failed to delete the test record dcdiag-test-record i
n zone GlenHaven.domain

               GHDC1                        PASS PASS PASS PASS WARN PASS n/a
         ......................... GlenHaven.domain passed test DNS

C:\Windows\system32>dcdiag /test:dns

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = GHDC1
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\GHDC1
      Starting test: Connectivity
         ......................... GHDC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\GHDC1

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... GHDC1 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : GlenHaven

   Running enterprise tests on : GlenHaven.domain
      Starting test: DNS
         Test results for domain controllers:

            DC: GHDC1.GlenHaven.domain
            Domain: GlenHaven.domain


               TEST: Dynamic update (Dyn)
                  Warning: Failed to delete the test record dcdiag-test-record i
n zone GlenHaven.domain

               GHDC1                        PASS PASS PASS PASS WARN PASS n/a
         ......................... GlenHaven.domain passed test DNS

C:\Windows\system32>dcdiag

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = GHDC1
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\GHDC1
      Starting test: Connectivity
         ......................... GHDC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\GHDC1
      Starting test: Advertising
         Warning: GHDC1 is not advertising as a time server.
         ......................... GHDC1 failed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... GHDC1 passed test FrsEvent
      Starting test: DFSREvent
         ......................... GHDC1 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... GHDC1 passed test SysVolCheck
      Starting test: KccEvent
         ......................... GHDC1 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... GHDC1 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... GHDC1 passed test MachineAccount
      Starting test: NCSecDesc
         ......................... GHDC1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... GHDC1 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... GHDC1 passed test ObjectsReplicated
      Starting test: Replications
         ......................... GHDC1 passed test Replications
      Starting test: RidManager
         ......................... GHDC1 passed test RidManager
      Starting test: Services
         ......................... GHDC1 passed test Services
      Starting test: SystemLog
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:22:37
            Event String:
            Driver Brother HL-5370DW series required for printer Brother HL-5370
DW series is unknown. Contact the administrator to install the driver before you
 log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:22:37
            Event String:
            Driver Brother PC-FAX v.2.1 required for printer Brother PC-FAX v.2.
1 is unknown. Contact the administrator to install the driver before you log in
again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:22:38
            Event String:
            Driver Brother MFC-8480DN Printer required for printer Brother MFC-8
480DN Printer is unknown. Contact the administrator to install the driver before
 you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:22:41
            Event String:
            Driver Send To Microsoft OneNote 2010 Driver required for printer Se
nd To OneNote 2010 is unknown. Contact the administrator to install the driver b
efore you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:23:55
            Event String:
            Driver Brother MFC-8480DN Printer required for printer Brother MFC-8
480DN Printer is unknown. Contact the administrator to install the driver before
 you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:23:55
            Event String:
            Driver Brother HL-5370DW series required for printer Brother HL-5370
DW series is unknown. Contact the administrator to install the driver before you
 log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:23:56
            Event String:
            Driver Brother PC-FAX v.2.1 required for printer Brother PC-FAX v.2.
1 is unknown. Contact the administrator to install the driver before you log in
again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:23:56
            Event String:
            Driver Send To Microsoft OneNote 2010 Driver required for printer Se
nd To OneNote 2010 is unknown. Contact the administrator to install the driver b
efore you log in again.
         An error event occurred.  EventID: 0xC00A0038
            Time Generated: 04/23/2012   12:25:16
            Event String:
            The Terminal Server security layer detected an error in the protocol
 stream and has disconnected the client. Client IP: 24.222.114.110.
         A warning event occurred.  EventID: 0x000003F6
            Time Generated: 04/23/2012   12:25:23
            Event String:
            Name resolution for the name dns.msftncsi.com timed out after none o
f the configured DNS servers responded.
         A warning event occurred.  EventID: 0x8000001D
            Time Generated: 04/23/2012   12:36:40
            Event String:
            The Key Distribution Center (KDC) cannot find a suitable certificate
 to use for smart card logons, or the KDC certificate could not be verified. Sma
rt card logon may not function correctly if this problem is not resolved. To cor
rect this problem, either verify the existing KDC certificate using certutil.exe
 or enroll for a new KDC certificate.
         A warning event occurred.  EventID: 0x00009016
            Time Generated: 04/23/2012   12:36:40
            Event String:
            No suitable default server credential exists on this system. This wi
ll prevent server applications that expect to make use of the system default cre
dentials from accepting SSL connections. An example of such an application is th
e directory server. Applications that manage their own credentials, such as the
internet information server, are not affected by this.
         A warning event occurred.  EventID: 0x00009016
            Time Generated: 04/23/2012   12:36:40
            Event String:
            No suitable default server credential exists on this system. This wi
ll prevent server applications that expect to make use of the system default cre
dentials from accepting SSL connections. An example of such an application is th
e directory server. Applications that manage their own credentials, such as the
internet information server, are not affected by this.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:47:11
            Event String:
            Driver Brother HL-5370DW series required for printer Brother HL-5370
DW series is unknown. Contact the administrator to install the driver before you
 log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:47:11
            Event String:
            Driver Brother PC-FAX v.2.1 required for printer Brother PC-FAX v.2.
1 is unknown. Contact the administrator to install the driver before you log in
again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:47:12
            Event String:
            Driver Brother MFC-8480DN Printer required for printer Brother MFC-8
480DN Printer is unknown. Contact the administrator to install the driver before
 you log in again.
         An error event occurred.  EventID: 0x00000457
            Time Generated: 04/23/2012   12:47:16
            Event String:
            Driver Send To Microsoft OneNote 2010 Driver required for printer Se
nd To OneNote 2010 is unknown. Contact the administrator to install the driver b
efore you log in again.
         An error event occurred.  EventID: 0xC0002719
            Time Generated: 04/23/2012   12:58:47
            Event String:
            DCOM was unable to communicate with the computer 24.222.0.33 using a
ny of the configured protocols.
         An error event occurred.  EventID: 0xC0002719
            Time Generated: 04/23/2012   12:59:08
            Event String:
            DCOM was unable to communicate with the computer 8.8.4.4 using any o
f the configured protocols.
         An error event occurred.  EventID: 0xC0002719
            Time Generated: 04/23/2012   12:59:34
            Event String:
            DCOM was unable to communicate with the computer 8.8.8.8 using any o
f the configured protocols.
         A warning event occurred.  EventID: 0x0000000C
            Time Generated: 04/23/2012   13:14:57
            Event String:
            Time Provider NtpClient: This machine is configured to use the domai
n hierarchy to determine its time source, but it is the AD PDC emulator for the
domain at the root of the forest, so there is no machine above it in the domain
hierarchy to use as a time source. It is recommended that you either configure a
 reliable time service in the root domain, or manually configure the AD PDC to s
ynchronize with an external time source. Otherwise, this machine will function a
s the authoritative time source in the domain hierarchy. If an external time sou
rce is not configured or used for this computer, you may choose to disable the N
tpClient.
         ......................... GHDC1 failed test SystemLog
      Starting test: VerifyReferences
         ......................... GHDC1 passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : GlenHaven
      Starting test: CheckSDRefDom
         ......................... GlenHaven passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... GlenHaven passed test CrossRefValidation

   Running enterprise tests on : GlenHaven.domain
      Starting test: LocatorCheck
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error
         1355
         A Good Time Server could not be located.
         ......................... GlenHaven.domain failed test LocatorCheck
      Starting test: Intersite
         ......................... GlenHaven.domain passed test Intersite

C:\Windows\system32>
i got the name space created after adding the _msdcs.glenhaven.domain zone to dns since the other was greyed, out but  now after the error about i have all users cannot log on. Slow respponse times on dns , all around Nightmare
IT's the time service  and there is probably a skew between clients and server
PDC will not function and no logons will occur until resolved. (manually configure the AD PDC to synchronize with an external time source)

Ensure the time service is running, and follow that guide i posted for external NTP timesource and make sure it is set to "Automatic" via services.msc

After you have done that

w32tm /resync /rediscover

then

w32tm /query /source
ASKER CERTIFIED SOLUTION
Avatar of jeremymcp
jeremymcp
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hey all. I had the same error in my lab environment. My recent changes were adding a DC, moving FSMO roles, changing forest and domain functional levels, then moving the FSMO roles and functional levels back, and then decommissioning that DC I added.

Anyhow, what resolved this for me was running the following command:

dfsutil /spcflush

dfsutil /pktflush

After that I was able to access DFS Management for the namespace.
BitBro's Solution is what worked for me.

dfsutil /spcflush

dfsutil /pktflush

Open in new window