Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Restored Windows 2008 Domain Controller Cannot Communicate with Parent Domain

Posted on 2012-12-21
8
681 Views
Last Modified: 2013-01-09
Hi,

I have a client with a parent domain and a child domain. The child domain only has a single DC that has been corrupted and is looking like it is unrecoverable (ticket created with Microsoft).

Unfortunately they only have a valid backup from 2 weeks ago, which was restored successfully yesterday evening. We can log onto the child domain successfully, but not onto the parent domain.

Are there any steps that I can run through to help repair the relationship between this child DC and the parent domain?
0
Comment
Question by:cpadm
8 Comments
 
LVL 1

Author Comment

by:cpadm
ID: 38712714
For the clarity of any solutions, let's name the domains as follows:

Parent domain:  ParDom.local
Child Domain:    ChilDom.local
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 38712744
How did you restore? What sort of backup?

A Back up and restore of a domain controller is generally a total waste of time.

Never have a domain with only one DC.  Your best resolution to a dead DC is always to kill it and build a new one. That of course is far far easier if you have multiple domain controllers in the domain.
0
 
LVL 11

Expert Comment

by:Venugopal N
ID: 38712755
You are not able to login parent domain, from the DC in child domain?
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 1

Author Comment

by:cpadm
ID: 38712810
@Neilsr

Q: How did you restore? What sort of backup?
A: It was a Veeam backup and restore of the whole virtual machine.

@Venurajav

Q: You are not able to login parent domain, from the DC in child domain?
A: Correct, communication from parent-to-child and child-to-parent domain is failing. I can log on to the child domain.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 38712891
Run a dcdiag post results
0
 
LVL 3

Expert Comment

by:gaurav2rawat
ID: 38713033
Check the secure connections using nltest check dns records if proper also run dcdiag /q and post the results here
0
 
LVL 37

Assisted Solution

by:Neil Russell
Neil Russell earned 150 total points
ID: 38713094
Veam backup of a DC is, to be honest, not a good idea.  Active directory does an aweful lot that is time dependant, passwords automaticaly updated for machines in the background, communication between DC's in domains and forest, all time sensitive.

You have now got a DC that is 2 weeks older than everything else expects it to be.  Not good.
0
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 350 total points
ID: 38717814
You can refer below link to reset the secure channel of child Dc however can you post the dcdiag /q and ipconfig /all details of parent and child DC to get the clear view of the issue.

The secure channel (SC) reset on domain controller
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/d7dbbf0c-7216-47e7-b0a9-efb413000c6f/

Also ensure that dns is set correctly for child domain as below.
DNS Design Options in a Multi-Domain Forest - How to create a Parent-Child DNS Delegation, and How to Configure DNS to create a new Tree in the Forest
http://msmvps.com/blogs/acefekay/archive/2010/10/01/dns-parent-child-dns-delegation-how-to-create-a-dns-delegation.aspx
http://abhijitw.wordpress.com/2012/03/03/best-practices-for-dns-client-settings-on-domain-controller/

Also, disable local windows firewall service, by default it is enabled in vista/windows 2008 and above. Check the network connectivity and latency.
Disable Windows Firewall: http://technet.microsoft.com/en-us/library/cc766337(WS.10).aspx

Active Directory and Active Directory Domain Services Port Requirements
http://technet.microsoft.com/en-us/library/dd772723%28WS.10%29.aspx


See this too.

The Sysvol and Netlogon Shares Are Missing After You Restore a Domain Controller from Backup:http://support.microsoft.com/kb/316790

Hope this helps
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question