Experts, I've been fighting a new problem all night. Googling around for different answers has not led me down a path that has led to resolution yet.
I'll get right to the symptoms:
- In a 2012 virtual environment, (DCs are server 2012) - any new DC that's stood up does not create the SYSVOL/NETLOGON shares.
- These are completely new DCs, in the same AD site.
- There are no problems with replication. "repadmin /replsummary" shows me that everything is fine between every server.
- "dcdiag" is showing an error on each of the new DCs:
Testing server: SITE\SERVERNAME
Starting test: Advertising
Warning: DsGetDcName returned information for
\\WORKINGSERVER.DOMAIN.COM, when we were trying to reach NEWSERVER.
SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.
Starting test: DFSREvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
Starting test: NetLogons
Unable to connect to the NETLOGON share! (\\NEWSERVER\netlogon)
[NEWSERVER] An net use or LsaPolicy operation failed with error 67,
The network name cannot be found..
- All other tests check fine with "dcdiag".
- I have one working DC (original), that does not experience these issues. This is on any newly promoted DC (I've stood up about 5 new ones that I've been troubleshooting).
For troubleshooting, here are a few steps I've already accomplished.
-- I know DNS is supposed to have the DNS pointing to itself as primary / and secondary to another DC, but for testing I've got all of the new servers currently pointing a single DNS entry to the working server.
-- I've demoted cleaned out AD metadata using ntdsutil / adsiedit / sites & services, then repromoted a couple of the new DCs.
-- DNS checks fine, in that the new servers are creating correct entries in _msdcs.domain.com, as well as the forward lookup zone for the domain.
I really am at a loss here, as I don't understand why this is happening. I would completely understand if these were servers that may have existed before in the domain, but they're not - every new server I stand up and promote to be a DC is showing this exact same problem.
Would anybody happen to have any ideas?