Solved

Restored Windows 2008 Domain Controller Cannot Communicate with Parent Domain

Posted on 2012-12-21
8
678 Views
Last Modified: 2013-01-09
Hi,

I have a client with a parent domain and a child domain. The child domain only has a single DC that has been corrupted and is looking like it is unrecoverable (ticket created with Microsoft).

Unfortunately they only have a valid backup from 2 weeks ago, which was restored successfully yesterday evening. We can log onto the child domain successfully, but not onto the parent domain.

Are there any steps that I can run through to help repair the relationship between this child DC and the parent domain?
0
Comment
Question by:cpadm
8 Comments
 
LVL 1

Author Comment

by:cpadm
ID: 38712714
For the clarity of any solutions, let's name the domains as follows:

Parent domain:  ParDom.local
Child Domain:    ChilDom.local
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 38712744
How did you restore? What sort of backup?

A Back up and restore of a domain controller is generally a total waste of time.

Never have a domain with only one DC.  Your best resolution to a dead DC is always to kill it and build a new one. That of course is far far easier if you have multiple domain controllers in the domain.
0
 
LVL 11

Expert Comment

by:Venugopal N
ID: 38712755
You are not able to login parent domain, from the DC in child domain?
0
 
LVL 1

Author Comment

by:cpadm
ID: 38712810
@Neilsr

Q: How did you restore? What sort of backup?
A: It was a Veeam backup and restore of the whole virtual machine.

@Venurajav

Q: You are not able to login parent domain, from the DC in child domain?
A: Correct, communication from parent-to-child and child-to-parent domain is failing. I can log on to the child domain.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 38712891
Run a dcdiag post results
0
 
LVL 3

Expert Comment

by:gaurav2rawat
ID: 38713033
Check the secure connections using nltest check dns records if proper also run dcdiag /q and post the results here
0
 
LVL 37

Assisted Solution

by:Neil Russell
Neil Russell earned 150 total points
ID: 38713094
Veam backup of a DC is, to be honest, not a good idea.  Active directory does an aweful lot that is time dependant, passwords automaticaly updated for machines in the background, communication between DC's in domains and forest, all time sensitive.

You have now got a DC that is 2 weeks older than everything else expects it to be.  Not good.
0
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 350 total points
ID: 38717814
You can refer below link to reset the secure channel of child Dc however can you post the dcdiag /q and ipconfig /all details of parent and child DC to get the clear view of the issue.

The secure channel (SC) reset on domain controller
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/d7dbbf0c-7216-47e7-b0a9-efb413000c6f/

Also ensure that dns is set correctly for child domain as below.
DNS Design Options in a Multi-Domain Forest - How to create a Parent-Child DNS Delegation, and How to Configure DNS to create a new Tree in the Forest
http://msmvps.com/blogs/acefekay/archive/2010/10/01/dns-parent-child-dns-delegation-how-to-create-a-dns-delegation.aspx
http://abhijitw.wordpress.com/2012/03/03/best-practices-for-dns-client-settings-on-domain-controller/

Also, disable local windows firewall service, by default it is enabled in vista/windows 2008 and above. Check the network connectivity and latency.
Disable Windows Firewall: http://technet.microsoft.com/en-us/library/cc766337(WS.10).aspx

Active Directory and Active Directory Domain Services Port Requirements
http://technet.microsoft.com/en-us/library/dd772723%28WS.10%29.aspx


See this too.

The Sysvol and Netlogon Shares Are Missing After You Restore a Domain Controller from Backup:http://support.microsoft.com/kb/316790

Hope this helps
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
active directory 6 76
Managing Email size limits in Exchange 2010 SP3 2 35
No login server available 4 24
Office 365 Single Sign On 2 14
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now